Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 11 Jul 2015 19:04:07 +0200
From:      Fabian Keil <freebsd-listen@fabiankeil.de>
To:        freebsd-current@freebsd.org
Cc:        "Matthew D. Fuller" <fullermd@over-yonder.net>, "George V. Neville-Neil" <gnn@FreeBSD.org>, svn-src-head@freebsd.org
Subject:   geli AES-XTS provider attachment broken after r285336 (was: svn commit: r285336 - in head/sys: netipsec opencrypto)
Message-ID:  <4308d5d9.790ffd96@fabiankeil.de>
In-Reply-To: <20150711044843.GG96394@over-yonder.net>
References:  <201507091816.t69IGawf097288@repo.freebsd.org> <20150711044843.GG96394@over-yonder.net>

next in thread | previous in thread | raw e-mail | index | archive | help

[-- Attachment #1 --]
"Matthew D. Fuller" <fullermd@over-yonder.net> wrote:

> On Thu, Jul 09, 2015 at 06:16:36PM +0000 I heard the voice of
> George V. Neville-Neil, and lo! it spake thus:
> > New Revision: 285336
> > URL: https://svnweb.freebsd.org/changeset/base/285336
> > 
> > Log:
> >   Add support for AES modes to IPSec.  These modes work both in software only
> >   mode and with hardware support on systems that have AESNI instructions.
> 
> With (apparently) this change, I can trigger a panic at will by
> running
> 
> % geli onetime -e AES-XTS -d /dev/ada0s1

Thanks for the heads-up.

As it wasn't obvious to me: the commit broke attachment
of AES-XTS providers in general.

Reverting it lets my test system boot again.

Fabian

[-- Attachment #2 --]
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iEYEARECAAYFAlWhTIEACgkQBYqIVf93VJ30wgCfeJfieZG4lWyq5rB0iOhTIPq3
gPgAn0WalnZhAi5hZmRBVAKmQUKqbmML
=u6CM
-----END PGP SIGNATURE-----

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?4308d5d9.790ffd96>