Re: [PATCH crypto 2/2] crypto: safexcel - Map AEAD buffers with accurate DMA directions

From: Ralf Lici

Date: Wed Sep 23 2026 - 03:40:32 EST


Hi Herbert,

On Wed, 23 Sep 2026 15:30:13 +1000, Herbert Xu <herbert@xxxxxxxxxxxxxxxxxxx> wrote:
> On Tue, Sep 15, 2026 at 01:32:12PM +0200, Ralf Lici wrote:
> >
> > +static int safexcel_map_aead(struct device *dev, struct scatterlist *sgl,
> > + int nents, unsigned int output_offset,
> > + unsigned int output_len, bool inplace)
> > +{
> > + struct scatterlist *sg;
> > + unsigned int offset = 0;
> > + int i;
> > +
> > + for_each_sg(sgl, sg, nents, i) {
> > + enum dma_data_direction dir;
> > +
> > + dir = safexcel_aead_dma_dir(offset, sg->length, output_offset,
> > + output_len, inplace);
> > + sg_dma_address(sg) = dma_map_page(dev, sg_page(sg), sg->offset,
> > + sg->length, dir);
> > + if (dma_mapping_error(dev, sg_dma_address(sg)))
> > + goto err_unmap;
> > + sg_dma_len(sg) = sg->length;
> > + offset += sg->length;
> > + }
> > +
> > + return nents;
> > +
> > +err_unmap:
> > + safexcel_unmap_aead(dev, sgl, i, output_offset, output_len, inplace);
> > + return 0;
> > +}
>
> Is this assuming that the SG list actually contains one entry for
> each type of data? What if the input is completely linear, i.e.,
> the AD, cipher and tag are all described by a single SG entry?
>
> In IPsec this is often the case.
>

No, the regions do not need to occupy separate sg entries, the patch
selects the direction conservatively for the whole entry.

For a completely linear in-place request, the entry overlaps the output
range and is therefore mapped DMA_BIDIRECTIONAL. For an out-of-place
request, the source is mapped DMA_TO_DEVICE. For example, a single
destination entry covering:

[ AAD | ciphertext | tag ]

has a logical output range covering only:

[ ciphertext | tag ]

Since the entry also contains the preserved AAD prefix, it is classified
as mixed and mapped DMA_BIDIRECTIONAL. The same applies if an entry
extends beyond the end of the output range.

Only entries wholly outside the output range use DMA_TO_DEVICE, while
only entries wholly contained within an out-of-place output range use
DMA_FROM_DEVICE.

--
Ralf Lici
Mandelbit Srl