________________________________ From: Pratik Senapati <[email protected]> Sent: Friday, October 09, 2026 12:25 To: [email protected] <[email protected]> Cc: Ji, Kai <[email protected]> Subject: [PATCH v1 1/1] crypto/openssl: filter legacy ciphers from capability list When the legacy provider is unavailable, DES ciphers were still reported as supported, causing runtime failures when applications attempted to use them. Add openssl_pmd_caps_init() to build a filtered capability list at device init, excluding DES-CBC and DES-DOCSISBPI based on legacy provider availability. Add a warning when DES algorithms are unavailable. Signed-off-by: Pratik Senapati <[email protected]> --- drivers/crypto/openssl/openssl_pmd_private.h | 2 ++ drivers/crypto/openssl/rte_openssl_pmd.c | 3 +- drivers/crypto/openssl/rte_openssl_pmd_ops.c | 29 +++++++++++++++++++- 3 files changed, 32 insertions(+), 2 deletions(-) diff --git a/drivers/crypto/openssl/openssl_pmd_private.h b/drivers/crypto/openssl/openssl_pmd_private.h index ab40012d61..71d78459ee 100644 --- a/drivers/crypto/openssl/openssl_pmd_private.h +++ b/drivers/crypto/openssl/openssl_pmd_private.h @@ -21,6 +21,8 @@ /** OPENSSL PMD LOGTYPE DRIVER */ extern int openssl_logtype_driver; +/** Initialize filtered capability list based on legacy provider availability */ +extern void openssl_pmd_caps_init(void); #define RTE_LOGTYPE_OPENSSL_DRIVER openssl_logtype_driver #define OPENSSL_LOG(level, ...) \ RTE_LOG_LINE_PREFIX(level, OPENSSL_DRIVER, "%s() line %u: ", \ diff --git a/drivers/crypto/openssl/rte_openssl_pmd.c b/drivers/crypto/openssl/rte_openssl_pmd.c index 2319c7cfa9..275078050a 100644 --- a/drivers/crypto/openssl/rte_openssl_pmd.c +++ b/drivers/crypto/openssl/rte_openssl_pmd.c @@ -37,7 +37,7 @@ static void ossl_legacy_provider_load(void) /* Load Multiple providers into the default (NULL) library context */ legacy = OSSL_PROVIDER_load(NULL, "legacy"); if (legacy == NULL) { - OPENSSL_LOG(ERR, "Failed to load Legacy provider"); + OPENSSL_LOG(WARNING, "Failed to load Legacy provider"); return; } @@ -3941,6 +3941,7 @@ cryptodev_openssl_create(const char *name, * unless the legacy provider explicitly loaded. e.g. DES */ ossl_legacy_provider_load(); + openssl_pmd_caps_init(); return 0; diff --git a/drivers/crypto/openssl/rte_openssl_pmd_ops.c b/drivers/crypto/openssl/rte_openssl_pmd_ops.c index d927cc5228..3dc1ee11a2 100644 --- a/drivers/crypto/openssl/rte_openssl_pmd_ops.c +++ b/drivers/crypto/openssl/rte_openssl_pmd_ops.c @@ -929,6 +929,7 @@ static const struct rte_cryptodev_capabilities openssl_pmd_capabilities[] = { RTE_CRYPTODEV_END_OF_CAPABILITIES_LIST() }; +static struct rte_cryptodev_capabilities openssl_pmd_caps_active[RTE_DIM(openssl_pmd_capabilities)]; const char *ml_kem_type_names[] = { NULL, "ML-KEM-512", @@ -943,6 +944,29 @@ const char *ml_dsa_type_names[] = { "ML-DSA-87", }; +/** Initialize active capability list, filtering unsupported entries. */ +void +openssl_pmd_caps_init(void) +{ + uint32_t i, j = 0; + + for (i = 0; openssl_pmd_capabilities[i].op != RTE_CRYPTO_OP_TYPE_UNDEFINED; i++) { + const struct rte_cryptodev_capabilities *cap = &openssl_pmd_capabilities[i]; + + if (cap->op == RTE_CRYPTO_OP_TYPE_SYMMETRIC && + cap->sym.xform_type == RTE_CRYPTO_SYM_XFORM_CIPHER && + (cap->sym.cipher.algo == RTE_CRYPTO_CIPHER_DES_CBC || + cap->sym.cipher.algo == RTE_CRYPTO_CIPHER_DES_DOCSISBPI)) { + EVP_CIPHER *des_cbc = EVP_CIPHER_fetch(NULL, "DES-CBC", "provider=legacy"); + if (des_cbc == NULL) + continue; + EVP_CIPHER_free(des_cbc); + } + openssl_pmd_caps_active[j++] = *cap; + } + openssl_pmd_caps_active[j] = openssl_pmd_capabilities[i]; +} + /** Configure device */ static int openssl_pmd_config(__rte_unused struct rte_cryptodev *dev, @@ -1014,7 +1038,10 @@ openssl_pmd_info_get(struct rte_cryptodev *dev, if (dev_info != NULL) { dev_info->driver_id = dev->driver_id; dev_info->feature_flags = dev->feature_flags; - dev_info->capabilities = openssl_pmd_capabilities; + if (openssl_pmd_caps_active[0].op == RTE_CRYPTO_OP_TYPE_UNDEFINED) + dev_info->capabilities = openssl_pmd_capabilities; It seems fallback also advertises DES even when DES is unavailable, which defeats the filtering during that window. Would it be better fix to initialize the filtered list before the device can be queried; then this fallback should not be needed. + else + dev_info->capabilities = openssl_pmd_caps_active; dev_info->max_nb_queue_pairs = internals->max_nb_qpairs; /* No limit of number of sessions */ dev_info->sym.max_nb_sessions = 0; -- 2.43.0

