Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .wolfssl_known_macro_extras
Original file line number Diff line number Diff line change
Expand Up @@ -890,6 +890,8 @@ WOLFSSL_ALT_NAMES_NO_REV
WOLFSSL_ARM32_BUILD
WOLFSSL_ARM32_PRIVILEGE_MODE
WOLFSSL_ARMASM_NEON_NO_TABLE_LOOKUP
WOLFSSL_ARMASM_SHA3_NO_NEON
WOLFSSL_ARMASM_SHA512_NO_NEON
WOLFSSL_ARM_ARCH_NEON_64BIT
WOLFSSL_ASCON_UNROLL
WOLFSSL_ASN_EXTRA
Expand Down Expand Up @@ -1287,6 +1289,7 @@ __ARCH_STRNCAT_NO_REDIRECT
__ARCH_STRNCMP_NO_REDIRECT
__ARCH_STRNCPY_NO_REDIRECT
__ARCH_STRSTR_NO_REDIRECT
__ARMEB__
__ARM_ARCH
__ARM_ARCH_7M__
__ARM_ARCH_PROFILE
Expand Down
6 changes: 6 additions & 0 deletions configure.ac
Original file line number Diff line number Diff line change
Expand Up @@ -4242,6 +4242,12 @@ then
ENABLED_AESSIV=yes
fi

if test "$ENABLED_FIPS" != "no" && test "$HAVE_FIPS_VERSION" -ge 7 && \
{ test "$ENABLED_AESSIV" = "yes" || test "$ENABLED_AESEAX" = "yes"; }
then
AC_MSG_ERROR([AES-SIV and AES-EAX are not in the FIPS module boundary: drop --enable-aessiv, --enable-aeseax, --enable-chrony or --enable-all-nonfips-crypto from a FIPS v7 build.])
fi

# AES-GCM-SIV (RFC 8452)
AC_ARG_ENABLE([aesgcm-siv],
[AS_HELP_STRING([--enable-aesgcm-siv],[Enable AES-GCM-SIV (RFC 8452) (default: disabled)])],
Expand Down
2 changes: 2 additions & 0 deletions doc/ASM_AND_MATH_DEFINES.md
Original file line number Diff line number Diff line change
Expand Up @@ -420,6 +420,8 @@ kernel-module builds, `WC_C_DYNAMIC_FALLBACK` keeps a C path available.
| `WOLFSSL_ARMASM_INLINE` | Use the `*_asm_c.c` inline-assembly variants instead of the `.S` files. Needed when the toolchain will not assemble `.S`, and used for FIPS on ARMv7. |
| `WOLFSSL_ARMASM_NO_HW_CRYPTO` | No ARMv8 Crypto Extensions (no AES/SHA instructions) |
| `WOLFSSL_ARMASM_NO_NEON` | No NEON |
| `WOLFSSL_ARMASM_SHA512_NO_NEON` | 32-bit Arm: SHA-512 uses its scalar body; implied by `WOLFSSL_ARMASM_NO_NEON` |
| `WOLFSSL_ARMASM_SHA3_NO_NEON` | 32-bit Arm: SHA-3 uses its scalar body; implied by `WOLFSSL_ARMASM_NO_NEON` |
| `WOLFSSL_ARMASM_THUMB2` | Thumb-2 encoding (Cortex-M, ARMv7-M) |
| `WOLFSSL_ARM_ARCH=<n>` | Architecture level: `4`, `6`, `7`… Gates instruction availability. |
| `WOLFSSL_AARCH64_BUILD` | Aarch64 target |
Expand Down
48 changes: 41 additions & 7 deletions linuxkm/Kbuild
Original file line number Diff line number Diff line change
Expand Up @@ -154,16 +154,34 @@ ifeq "$(ENABLED_LINUXKM_PIE)" "yes"

ifndef NO_PIE_FLAG
ifeq ($(KERNEL_ARCH),arm)
ifneq "$(HAVE_INTCMP)" "yes"
$(error $$NO_PIE_FLAG is unset -- supply NO_PIE_FLAG=1 for target kernel <5.11, else supply NO_PIE_FLAG=0.)
ifeq "$(and $(VERSION),$(PATCHLEVEL))" ""
$(error $$VERSION or $$PATCHLEVEL is unset; supply NO_PIE_FLAG=1 for a target kernel before 5.11, else NO_PIE_FLAG=0.)
endif
ifeq ($(intcmp $(VERSION),5,1,0,0),1)
NO_PIE_FLAG := 1
$(info Note: disabling -fPIE to avoid R_ARM_REL32 on pre-5.11 target kernel.)
ifeq "$(HAVE_INTCMP)" "yes"
ifeq ($(intcmp $(VERSION),5,1,0,0),1)
NO_PIE_FLAG := 1
$(info Note: disabling -fPIE to avoid R_ARM_REL32 on pre-5.11 target kernel.)
else
ifeq ($(intcmp $(VERSION),5,0,1,0)-$(intcmp $(PATCHLEVEL),11,1,0,0),1-1)
NO_PIE_FLAG := 1
$(info Note: disabling -fPIE to avoid R_ARM_REL32 on pre-5.11 target kernel.)
else
NO_PIE_FLAG := 0
endif
endif
else
ifeq ($(intcmp $(VERSION),5,0,1,0)-$(intcmp $(PATCHLEVEL),11,1,0,0),1-1)
# GNU make before 4.4 has no $(intcmp), so the pre-5.11 versions are
# enumerated: major 0 to 4, or major 5 with minor 0 to 10.
ifneq ($(filter 0 1 2 3 4,$(VERSION)),)
NO_PIE_FLAG := 1
$(info Note: disabling -fPIE to avoid R_ARM_REL32 on pre-5.11 target kernel.)
else ifeq "$(VERSION)" "5"
ifneq ($(filter 0 1 2 3 4 5 6 7 8 9 10,$(PATCHLEVEL)),)
NO_PIE_FLAG := 1
$(info Note: disabling -fPIE to avoid R_ARM_REL32 on pre-5.11 target kernel.)
else
NO_PIE_FLAG := 0
endif
else
NO_PIE_FLAG := 0
endif
Expand Down Expand Up @@ -275,6 +293,19 @@ $(obj)/wolfcrypt/src/port/arm/%-asm_c.o: ccflags-remove-y += -mgeneral-regs-only
$(obj)/wolfcrypt/src/port/arm/%.o: OBJECT_FILES_NON_STANDARD := y
endif

# The 32-bit Arm kernel builds soft-float with a baseline -march; the port asm
# needs the ARMv8-A crypto and NEON instructions accepted, as above.
ifeq ($(CONFIG_ARM),y)
# --noexecstack keeps the GNU-stack note on an object whose whole body is
# compiled out, such as the SHA-3 assembly under WC_SHA3_NO_ASM.
$(obj)/wolfcrypt/src/port/arm/%.o: asflags-y := $(WOLFSSL_ASFLAGS) -march=armv8-a -mfpu=crypto-neon-fp-armv8 -Wa,--noexecstack
# The kernel builds with -msoft-float; NEON in a C file needs softfp, as
# arch/arm/lib/Makefile does for xor-neon.o.
$(obj)/wolfcrypt/src/port/arm/%-asm_c.o: ccflags-y += -march=armv8-a -mfpu=crypto-neon-fp-armv8 -mfloat-abi=softfp
$(obj)/wolfcrypt/src/port/arm/%-asm_c.o: ccflags-remove-y += -mgeneral-regs-only
$(obj)/wolfcrypt/src/port/arm/%.o: OBJECT_FILES_NON_STANDARD := y
endif

ifndef READELF
READELF := readelf
endif
Expand All @@ -291,6 +322,8 @@ ifndef OBJCOPY
OBJCOPY := objcopy
endif

# 32-bit Arm asm keeps its constant tables in .text, so the OBJECT check below
# skips wolfCrypt's text sections; x86 and arm64 keep theirs in rodata.
RENAME_PIE_TEXT_AND_DATA_SECTIONS := \
if [[ "$(quiet)" != "silent_" ]]; then \
echo -n ' Checking wolfCrypt for unresolved symbols and forbidden relocations... '; \
Expand Down Expand Up @@ -383,7 +416,8 @@ RENAME_PIE_TEXT_AND_DATA_SECTIONS := \
next; \
} \
else if ($$4 == "OBJECT") { \
if (! ($$7 in wolfcrypt_data_sections)) { \
if (! ($$7 in wolfcrypt_data_sections) && \
! ($$7 in wolfcrypt_text_sections)) { \
if ((other_sections[$$7] == ".printk_index") || \
(($$8 ~ /^_entry\.[0-9]+$$|^kernel_read_file_str$$/) && \
(other_sections[$$7] == ".data.rel.ro.local"))) \
Expand Down
31 changes: 22 additions & 9 deletions linuxkm/arm64_vector_register_glue.c
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
/* arm64_vector_register_glue.c: glue logic to claim and release the FPSIMD
* and NEON registers on arm64
* and NEON registers on arm64, and the NEON registers on 32-bit Arm
*
* Copyright (C) 2006-2026 wolfSSL Inc.
*
Expand All @@ -23,22 +23,35 @@
/* included by linuxkm/module_hooks.c */
#ifndef WC_SKIP_INCLUDED_C_FILES

#if !defined(WOLFSSL_USE_SAVE_VECTOR_REGISTERS) || !defined(CONFIG_ARM64)
#error arm64 vector register glue included in non-vectorized or non-arm64 project.
#if !defined(WOLFSSL_USE_SAVE_VECTOR_REGISTERS) || \
(!defined(CONFIG_ARM64) && !defined(CONFIG_ARM))
#error arm vector register glue included in non-vectorized or non-arm project.
#endif

#ifndef CONFIG_KERNEL_MODE_NEON
/* Without this option the kernel exports no kernel_neon_begin() and
* may_use_simd() is always false (linux-6.6.99 fpsimd.c:1904, simd.h:46). */
#error wolfSSL linuxkm on arm64 requires CONFIG_KERNEL_MODE_NEON.
#error wolfSSL linuxkm on arm requires CONFIG_KERNEL_MODE_NEON.
#endif

#if LINUX_VERSION_CODE >= KERNEL_VERSION(6, 19, 0)
#if defined(CONFIG_ARM64) && LINUX_VERSION_CODE >= KERNEL_VERSION(6, 19, 0)
/* Written against the void kernel_neon_begin() of linux-6.6.99. 6.19
* changes that signature and has not been read here. */
#error arm64 vector register glue does not yet support kernel_neon_begin() with a state buffer (6.19+).
#endif

#if defined(CONFIG_ARM) && LINUX_VERSION_CODE >= KERNEL_VERSION(6, 4, 0)
/* From 6.4 may_use_simd() tests only in_hardirq(), but kernel_neon_begin()
* also BUGs on irqs_disabled() (linux-6.16.12 vfpmodule.c); test it too. */
#define wc_svr_arm_neon_usable() (may_use_simd() && !irqs_disabled())
#elif defined(CONFIG_ARM)
/* Before 6.4 kernel_neon_begin() BUGs on in_interrupt() (linux-6.1.62
* vfpmodule.c): NEON is refused in softirq, allowed with interrupts off. */
#define wc_svr_arm_neon_usable() may_use_simd()
#else
#define wc_svr_arm_neon_usable() may_use_simd()
#endif

#ifdef DEBUG_VECTOR_REGISTER_ACCESS_FUZZING
#error DEBUG_VECTOR_REGISTER_ACCESS_FUZZING is not implemented by the arm64 vector register glue.
#endif
Expand Down Expand Up @@ -119,7 +132,7 @@ __must_check int wc_can_save_vector_registers_x86(void)
if (st->depth > 0)
ret = (st->inhibit_at == 0);
else
ret = may_use_simd() ? 1 : 0;
ret = wc_svr_arm_neon_usable() ? 1 : 0;
preempt_enable();

return ret;
Expand Down Expand Up @@ -160,8 +173,8 @@ __must_check int wc_save_vector_registers_x86(enum wc_svr_flags flags)
return 0;
}

/* Outermost claim. The bottom-half disable below is what holds the CPU,
* taken by kernel_neon_begin() or wc_svr_arm64_pin_bh(). */
/* Outermost claim: kernel_neon_begin() or wc_svr_arm64_pin_bh() holds the
* CPU with bottom halves off; 32-bit Arm before 6.4 disables preemption. */
if (flags & WC_SVR_FLAG_INHIBIT) {
wc_svr_arm64_pin_bh(st);
st->depth = 1;
Expand All @@ -172,7 +185,7 @@ __must_check int wc_save_vector_registers_x86(enum wc_svr_flags flags)
return 0;
}

if (! may_use_simd()) {
if (! wc_svr_arm_neon_usable()) {
if (flags & WC_SVR_FLAG_MAYBE_INHIBIT) {
/* Held without the registers: nested claims are refused. */
wc_svr_arm64_pin_bh(st);
Expand Down
6 changes: 6 additions & 0 deletions linuxkm/linuxkm_memory.c
Original file line number Diff line number Diff line change
Expand Up @@ -64,6 +64,10 @@ static const struct reloc_layout_ent {
[WC_R_AARCH64_LDST64_ABS_LO12_NC] = { "R_AARCH64_LDST64_ABS_LO12_NC", 0b00000000001111111111110000000000, 32, .is_signed = 0, .is_relative = 0, .is_pages = 0, .is_pair_lo = 1, .is_pair_hi = 0 },
[WC_R_AARCH64_PREL32] = { "R_AARCH64_PREL32", ~0UL, 32, .is_signed = 1, .is_relative = 1, .is_pages = 0, .is_pair_lo = 0, .is_pair_hi = 0 },
[WC_R_ARM_ABS32] = { "R_ARM_ABS32", ~0UL, 32, .is_signed = 0, .is_relative = 0, .is_pages = 0, .is_pair_lo = 0, .is_pair_hi = 0 },
/* ARM-mode BL and B: signed 24-bit word offset in bits 23 to 0, emitted
* by a 32-bit Arm kernel built without CONFIG_THUMB2_KERNEL. */
[WC_R_ARM_CALL] = { "R_ARM_CALL", 0b00000000111111111111111111111111, 32, .is_signed = 1, .is_relative = 1, .is_pages = 0, .is_pair_lo = 0, .is_pair_hi = 0 },
[WC_R_ARM_JUMP24] = { "R_ARM_JUMP24", 0b00000000111111111111111111111111, 32, .is_signed = 1, .is_relative = 1, .is_pages = 0, .is_pair_lo = 0, .is_pair_hi = 0 },
[WC_R_ARM_PREL31] = { "R_ARM_PREL31", 0b01111111111111111111111111111111, 32, .is_signed = 1, .is_relative = 1, .is_pages = 0, .is_pair_lo = 0, .is_pair_hi = 0 },
[WC_R_ARM_REL32] = { "R_ARM_REL32", ~0UL, 32, .is_signed = 1, .is_relative = 1, .is_pages = 0, .is_pair_lo = 0, .is_pair_hi = 0 },
[WC_R_ARM_THM_CALL] = { "R_ARM_THM_CALL", 0b00000111111111110010111111111111, 32, .is_signed = 1, .is_relative = 1, .is_pages = 0, .is_pair_lo = 0, .is_pair_hi = 0 },
Expand Down Expand Up @@ -413,6 +417,8 @@ ssize_t wc_reloc_normalize_segment(
break;

case WC_R_ARM_ABS32:
case WC_R_ARM_CALL:
case WC_R_ARM_JUMP24:
case WC_R_ARM_PREL31:
case WC_R_ARM_REL32:
case WC_R_ARM_THM_CALL:
Expand Down
2 changes: 2 additions & 0 deletions linuxkm/linuxkm_memory.h
Original file line number Diff line number Diff line change
Expand Up @@ -52,6 +52,8 @@ enum wc_reloc_type {
WC_R_AARCH64_LDST64_ABS_LO12_NC,
WC_R_AARCH64_PREL32,
WC_R_ARM_ABS32,
WC_R_ARM_CALL,
WC_R_ARM_JUMP24,
WC_R_ARM_PREL31,
WC_R_ARM_REL32,
WC_R_ARM_THM_CALL,
Expand Down
42 changes: 28 additions & 14 deletions linuxkm/linuxkm_wc_port.h
Original file line number Diff line number Diff line change
Expand Up @@ -201,6 +201,12 @@
#define WOLFSSL_DEBUG_PRINTF_FN printk
#endif

#ifdef CONFIG_ARM
/* Exported by arch/arm/kernel/traps.c; asmlinkage is empty for C here and
* linux/linkage.h is not included yet at this point in the header. */
void __div0(void);
#endif

#ifndef WOLFSSL_LINUXKM_USE_MUTEXES
struct wolfSSL_Mutex;
extern int wc_lkm_LockMutex(struct wolfSSL_Mutex* m);
Expand Down Expand Up @@ -256,6 +262,11 @@
#if !defined(CONFIG_ARM) && !defined(CONFIG_ARM64)
#error ARM SIMD extensions requested, but CONFIG_ARM* is not set.
#endif
/* A kernel module runs privileged, so the 32-bit Arm feature test reads
* ID_ISAR5 directly instead of the userspace getauxval() path. */
#if defined(CONFIG_ARM) && !defined(WOLFSSL_ARM32_PRIVILEGE_MODE)
#define WOLFSSL_ARM32_PRIVILEGE_MODE
#endif
#define WOLFSSL_LINUXKM_SIMD
#define WOLFSSL_LINUXKM_SIMD_ARM
#ifndef WOLFSSL_USE_SAVE_VECTOR_REGISTERS
Expand Down Expand Up @@ -816,7 +827,7 @@
/* x86 and arm64 share one interface: both glue files keep the wc_*_x86
* names, so callers and the PIE redirect table are the same. */
#if defined(WOLFSSL_USE_SAVE_VECTOR_REGISTERS) && \
(defined(CONFIG_X86) || defined(CONFIG_ARM64))
(defined(CONFIG_X86) || defined(CONFIG_ARM64) || defined(CONFIG_ARM))

extern __must_check int wc_linuxkm_allocate_svr_states(void);
extern void wc_linuxkm_free_svr_states(void);
Expand All @@ -843,10 +854,11 @@
#include <crypto/internal/simd.h>
#endif
#endif
#else /* CONFIG_ARM64 */
#else /* CONFIG_ARM64 || CONFIG_ARM */
/* arch/arm64/include/asm/simd.h, and may_use_simd() with it,
* arrived in 4.14; the module otherwise accepts 3.16 and up. */
#if LINUX_VERSION_CODE < KERNEL_VERSION(4, 14, 0) && \
#if defined(CONFIG_ARM64) && \
LINUX_VERSION_CODE < KERNEL_VERSION(4, 14, 0) && \
!defined(WC_DEBUG_FORCE_KERNEL_SETTINGS)
#error arm64 vector registers need may_use_simd(), added in 4.14.
#endif
Expand Down Expand Up @@ -978,10 +990,6 @@
#define RESTORE_VECTOR_REGISTERS_MAYBE_INHIBITED() wc_restore_vector_registers_x86(WC_SVR_FLAG_MAYBE_INHIBIT)
#endif

#elif defined(WOLFSSL_USE_SAVE_VECTOR_REGISTERS) && defined(CONFIG_ARM)

#error kernel module 32-bit ARM SIMD is not yet tested or usable.

#elif (defined(WOLFSSL_USE_SAVE_VECTOR_REGISTERS) && \
(!defined(SAVE_VECTOR_REGISTERS) || \
!defined(SAVE_VECTOR_REGISTERS2) || \
Expand Down Expand Up @@ -1234,6 +1242,11 @@
#ifndef __ARCH_MEMCMP_NO_REDIRECT
typeof(memcmp) *memcmp;
#endif
#ifdef CONFIG_ARM
/* The kernel's divide-by-zero reporter, for the EABI division
* helpers the container defines (arch/arm/kernel/traps.c). */
void (*__div0)(void);
#endif
#ifndef __ARCH_MEMCPY_NO_REDIRECT
typeof(memcpy) *memcpy;
#endif
Expand Down Expand Up @@ -1361,13 +1374,14 @@

#ifdef WOLFSSL_USE_SAVE_VECTOR_REGISTERS

#if defined(CONFIG_X86) || defined(CONFIG_ARM64)
#if defined(CONFIG_X86) || defined(CONFIG_ARM64) || \
defined(CONFIG_ARM)
typeof(wc_linuxkm_allocate_svr_states) *wc_linuxkm_allocate_svr_states;
typeof(wc_can_save_vector_registers_x86) *wc_can_save_vector_registers_x86;
typeof(wc_linuxkm_free_svr_states) *wc_linuxkm_free_svr_states;
typeof(wc_restore_vector_registers_x86) *wc_restore_vector_registers_x86;
typeof(wc_save_vector_registers_x86) *wc_save_vector_registers_x86;
#elif !defined(WC_DEBUG_FORCE_KERNEL_SETTINGS) /* !CONFIG_X86 && !CONFIG_ARM64 */
#elif !defined(WC_DEBUG_FORCE_KERNEL_SETTINGS) /* !CONFIG_X86 && !CONFIG_ARM64 && !CONFIG_ARM */
#error WOLFSSL_USE_SAVE_VECTOR_REGISTERS is set for an unimplemented architecture.
#endif /* arch */

Expand Down Expand Up @@ -1744,7 +1758,7 @@
#define get_current WC_PIE_INDIRECT_SYM(get_current)

#if defined(WOLFSSL_USE_SAVE_VECTOR_REGISTERS) && \
(defined(CONFIG_X86) || defined(CONFIG_ARM64))
(defined(CONFIG_X86) || defined(CONFIG_ARM64) || defined(CONFIG_ARM))
#define wc_linuxkm_allocate_svr_states WC_PIE_INDIRECT_SYM(wc_linuxkm_allocate_svr_states)
#define wc_can_save_vector_registers_x86 WC_PIE_INDIRECT_SYM(wc_can_save_vector_registers_x86)
#define wc_linuxkm_free_svr_states WC_PIE_INDIRECT_SYM(wc_linuxkm_free_svr_states)
Expand Down Expand Up @@ -2091,7 +2105,8 @@
#if !defined(BUILDING_WOLFSSL)
/* some caller code needs these. */
#if defined(WOLFSSL_USE_SAVE_VECTOR_REGISTERS)
#if defined(CONFIG_X86) || defined(CONFIG_ARM64)
#if defined(CONFIG_X86) || defined(CONFIG_ARM64) || \
defined(CONFIG_ARM)
WOLFSSL_API __must_check int wc_can_save_vector_registers_x86(void);
WOLFSSL_API __must_check int wc_save_vector_registers_x86(enum wc_svr_flags flags);
WOLFSSL_API void wc_restore_vector_registers_x86(enum wc_svr_flags flags);
Expand All @@ -2101,9 +2116,9 @@
#ifndef REENABLE_VECTOR_REGISTERS
#define REENABLE_VECTOR_REGISTERS() wc_restore_vector_registers_x86(WC_SVR_FLAG_INHIBIT)
#endif
#elif !defined(WC_DEBUG_FORCE_KERNEL_SETTINGS) /* !CONFIG_X86 && !CONFIG_ARM64 */
#elif !defined(WC_DEBUG_FORCE_KERNEL_SETTINGS) /* !CONFIG_X86 && !CONFIG_ARM64 && !CONFIG_ARM */
#error WOLFSSL_USE_SAVE_VECTOR_REGISTERS is set for an unimplemented architecture.
#endif /* !CONFIG_X86 && !CONFIG_ARM64 */
#endif /* !CONFIG_X86 && !CONFIG_ARM64 && !CONFIG_ARM */
#endif /* WOLFSSL_USE_SAVE_VECTOR_REGISTERS */
#ifdef WC_LINUXKM_USE_HEAP_WRAPPERS
WOLFSSL_API extern void *wc_linuxkm_malloc(size_t size);
Expand Down Expand Up @@ -2276,7 +2291,6 @@
{
return wc_lkm_UnlockMutex(m);
}

#endif /* !WC_CONTAINERIZE_THIS */
#endif

Expand Down
8 changes: 4 additions & 4 deletions linuxkm/lkcapi_sha_glue.c
Original file line number Diff line number Diff line change
Expand Up @@ -4275,7 +4275,7 @@ static ssize_t wc_get_random_bytes_user(struct iov_iter *iter) {
ret = wc_rng_bank_default_checkout(&current_default_wc_rng_bank);
if (ret) {
pr_emerg_ratelimited("ERROR: wc_rng_bank_default_checkout() in "
"wc_get_random_bytes_user() returned %ld.\n", ret);
"wc_get_random_bytes_user() returned %zd.\n", ret);
return -EIO; /* no fallthrough to native randomness */
}

Expand Down Expand Up @@ -4322,7 +4322,7 @@ static ssize_t wc_get_random_bytes_user(struct iov_iter *iter) {
if (unlikely(ret != 0)) {
if (ret != -WC_NO_ERR_TRACE(EINTR)) {
pr_emerg_ratelimited(
"ERROR: %s: wc_linuxkm_drbg_generate() returned %ld.\n",
"ERROR: %s: wc_linuxkm_drbg_generate() returned %zd.\n",
__func__, ret);
}
break;
Expand Down Expand Up @@ -4378,7 +4378,7 @@ static ssize_t wc_extract_crng_user(void __user *buf, size_t nbytes) {
ret = wc_rng_bank_default_checkout(&current_default_wc_rng_bank);
if (ret) {
pr_emerg_ratelimited("ERROR: wc_rng_bank_default_checkout() in "
"wc_extract_crng_user() returned %ld.\n", ret);
"wc_extract_crng_user() returned %zd.\n", ret);
return -EIO; /* no fallthrough to native randomness */
}

Expand Down Expand Up @@ -4424,7 +4424,7 @@ static ssize_t wc_extract_crng_user(void __user *buf, size_t nbytes) {
if (unlikely(ret != 0)) {
if (ret != -WC_NO_ERR_TRACE(EINTR)) {
pr_emerg_ratelimited(
"ERROR: %s: wc_linuxkm_drbg_generate() returned %ld.\n",
"ERROR: %s: wc_linuxkm_drbg_generate() returned %zd.\n",
__func__, ret);
}
break;
Expand Down
Loading
Loading