[Bug 275306] 14.0-RELEASE: ossl(4) causes data corruption on encrypted ZFS filesystems/volumes
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Mon, 27 Nov 2023 22:54:34 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=275306 --- Comment #14 from Mark Johnston <markj@FreeBSD.org> --- (In reply to Daniel Austin from comment #12) Ok, thank you. It seems that the probe order is somewhat arbitrary: if you load ossl.ko from loader.conf, you may or may not end up using ossl(4) once the system boots up. GENERIC kernels have aesni(4) as well, and the kernel will use whichever happens to have been probed first. I was able to reproduce the panic and have a patch which fixes the problem in my testing. We'll have it released with some other 14.0 errata later this week. I do not have a solution for the data errors, I apologize. Anything that was written to an aes-gcm encrypted dataset using ossl on 14.0 cannot be trusted. (Prior to 14.0, having ossl.ko loaded didn't matter since it didn't implement any ciphers used by OpenZFS.) -- You are receiving this mail because: You are the assignee for the bug.