________________________________
From: Pratik Senapati <[email protected]>
Sent: Friday, October 09, 2026 12:25
To: [email protected] <[email protected]>
Cc: Ji, Kai <[email protected]>
Subject: [PATCH v1 1/1] crypto/openssl: filter legacy ciphers from capability 
list

When the legacy provider is unavailable, DES ciphers were still
reported as supported, causing runtime failures when applications
attempted to use them.

Add openssl_pmd_caps_init() to build a filtered capability list at
device init, excluding DES-CBC and DES-DOCSISBPI based on legacy
provider availability. Add a warning when DES algorithms are
unavailable.

Signed-off-by: Pratik Senapati <[email protected]>
---
 drivers/crypto/openssl/openssl_pmd_private.h |  2 ++
 drivers/crypto/openssl/rte_openssl_pmd.c     |  3 +-
 drivers/crypto/openssl/rte_openssl_pmd_ops.c | 29 +++++++++++++++++++-
 3 files changed, 32 insertions(+), 2 deletions(-)

diff --git a/drivers/crypto/openssl/openssl_pmd_private.h 
b/drivers/crypto/openssl/openssl_pmd_private.h
index ab40012d61..71d78459ee 100644
--- a/drivers/crypto/openssl/openssl_pmd_private.h
+++ b/drivers/crypto/openssl/openssl_pmd_private.h
@@ -21,6 +21,8 @@

 /** OPENSSL PMD LOGTYPE DRIVER */
 extern int openssl_logtype_driver;
+/** Initialize filtered capability list based on legacy provider availability 
*/
+extern void openssl_pmd_caps_init(void);
 #define RTE_LOGTYPE_OPENSSL_DRIVER openssl_logtype_driver
 #define OPENSSL_LOG(level, ...)  \
         RTE_LOG_LINE_PREFIX(level, OPENSSL_DRIVER, "%s() line %u: ", \
diff --git a/drivers/crypto/openssl/rte_openssl_pmd.c 
b/drivers/crypto/openssl/rte_openssl_pmd.c
index 2319c7cfa9..275078050a 100644
--- a/drivers/crypto/openssl/rte_openssl_pmd.c
+++ b/drivers/crypto/openssl/rte_openssl_pmd.c
@@ -37,7 +37,7 @@ static void ossl_legacy_provider_load(void)
         /* Load Multiple providers into the default (NULL) library context */
         legacy = OSSL_PROVIDER_load(NULL, "legacy");
         if (legacy == NULL) {
-               OPENSSL_LOG(ERR, "Failed to load Legacy provider");
+               OPENSSL_LOG(WARNING, "Failed to load Legacy provider");
                 return;
         }

@@ -3941,6 +3941,7 @@ cryptodev_openssl_create(const char *name,
          * unless the legacy provider explicitly loaded. e.g. DES
          */
         ossl_legacy_provider_load();
+       openssl_pmd_caps_init();

         return 0;

diff --git a/drivers/crypto/openssl/rte_openssl_pmd_ops.c 
b/drivers/crypto/openssl/rte_openssl_pmd_ops.c
index d927cc5228..3dc1ee11a2 100644
--- a/drivers/crypto/openssl/rte_openssl_pmd_ops.c
+++ b/drivers/crypto/openssl/rte_openssl_pmd_ops.c
@@ -929,6 +929,7 @@ static const struct rte_cryptodev_capabilities 
openssl_pmd_capabilities[] = {
         RTE_CRYPTODEV_END_OF_CAPABILITIES_LIST()
 };

+static struct rte_cryptodev_capabilities 
openssl_pmd_caps_active[RTE_DIM(openssl_pmd_capabilities)];
 const char *ml_kem_type_names[] = {
         NULL,
         "ML-KEM-512",
@@ -943,6 +944,29 @@ const char *ml_dsa_type_names[] = {
         "ML-DSA-87",
 };

+/** Initialize active capability list, filtering unsupported entries. */
+void
+openssl_pmd_caps_init(void)
+{
+       uint32_t i, j = 0;
+
+       for (i = 0; openssl_pmd_capabilities[i].op != 
RTE_CRYPTO_OP_TYPE_UNDEFINED; i++) {
+               const struct rte_cryptodev_capabilities *cap = 
&openssl_pmd_capabilities[i];
+
+               if (cap->op == RTE_CRYPTO_OP_TYPE_SYMMETRIC &&
+                               cap->sym.xform_type == 
RTE_CRYPTO_SYM_XFORM_CIPHER &&
+                               (cap->sym.cipher.algo == 
RTE_CRYPTO_CIPHER_DES_CBC ||
+                                cap->sym.cipher.algo == 
RTE_CRYPTO_CIPHER_DES_DOCSISBPI)) {
+                       EVP_CIPHER *des_cbc = EVP_CIPHER_fetch(NULL, "DES-CBC", 
"provider=legacy");
+                       if (des_cbc == NULL)
+                               continue;
+                       EVP_CIPHER_free(des_cbc);
+               }
+               openssl_pmd_caps_active[j++] = *cap;
+       }
+       openssl_pmd_caps_active[j] = openssl_pmd_capabilities[i];
+}
+
 /** Configure device */
 static int
 openssl_pmd_config(__rte_unused struct rte_cryptodev *dev,
@@ -1014,7 +1038,10 @@ openssl_pmd_info_get(struct rte_cryptodev *dev,
         if (dev_info != NULL) {
                 dev_info->driver_id = dev->driver_id;
                 dev_info->feature_flags = dev->feature_flags;
-               dev_info->capabilities = openssl_pmd_capabilities;
+               if (openssl_pmd_caps_active[0].op == 
RTE_CRYPTO_OP_TYPE_UNDEFINED)
+                       dev_info->capabilities = openssl_pmd_capabilities;

It seems  fallback also advertises DES even when DES is unavailable, which 
defeats the filtering during that window. Would it be better fix to initialize 
the filtered list before the device can be queried; then this fallback should 
not be needed.

+               else
+                       dev_info->capabilities = openssl_pmd_caps_active;
                 dev_info->max_nb_queue_pairs = internals->max_nb_qpairs;
                 /* No limit of number of sessions */
                 dev_info->sym.max_nb_sessions = 0;
--
2.43.0

Reply via email to