[PATCH nvme-7.3 v2 4/4] nvme-fabrics: add helper for DH-CHAP secret options

Sagi Grimberg sagi at grimberg.me
Sun Aug 30 14:23:30 PDT 2026



On 27/08/2026 16:04, raoxu wrote:
> From: Xu Rao <raoxu at uniontech.com>
>
> The dhchap_secret and dhchap_ctrl_secret options have a distinct string
> lifetime because their values are authentication material.  The temporary
> string must be checked for the DHHC-1 representation and discarded with
> kfree_sensitive() when validation fails before ownership is transferred.
>
> Add nvmf_parse_dhchap_secret() to keep match_strdup(), DHHC-1 validation,
> failure cleanup, replacement of the old value and successful ownership
> transfer in one scope.  Both secret options use the same helper because
> their parsing and ownership rules are identical.
>
> Keep the existing replacement semantics for an already stored valid secret;
> this patch only moves the parsing and temporary allocation lifetime into
> the helper.
>
> No functional change is intended.
>
> Suggested-by: Christoph Hellwig <hch at lst.de>
> Reviewed-by: Sagi Grimberg <sagi at grimberg.me>
> Signed-off-by: Xu Rao <raoxu at uniontech.com>
> ---
>   drivers/nvme/host/fabrics.c | 48 ++++++++++++++++++-------------------
>   1 file changed, 24 insertions(+), 24 deletions(-)
>
> diff --git a/drivers/nvme/host/fabrics.c b/drivers/nvme/host/fabrics.c
> index 24385e777307..dc8883d85f45 100644
> --- a/drivers/nvme/host/fabrics.c
> +++ b/drivers/nvme/host/fabrics.c
> @@ -725,6 +725,25 @@ static int nvmf_parse_string_option(substring_t *args, char **dst)
>   	return 0;
>   }
>   
> +static int nvmf_parse_dhchap_secret(substring_t *args, char **secret)
> +{
> +	char *value;
> +
> +	value = match_strdup(args);
> +	if (!value)
> +		return -ENOMEM;
> +
> +	if (strlen(value) < 11 || strncmp(value, "DHHC-1:", 7)) {
> +		pr_err("Invalid DH-CHAP secret %s\n", value);
> +		kfree_sensitive(value);
> +		return -EINVAL;
> +	}
> +
> +	kfree(*secret);
> +	*secret = value;
> +	return 0;

Looks very similar to nvmf_parse_string_option... Would this be better? 
-- static int nvmf_parse_dhchap_secret(substring_t *args, char **secret) 
{ int ret; ret = nvmf_parse_string_option(args, secret); if (ret) return 
ret; if (strlen(*secret) < 11 || strncmp(*secret, "DHHC-1:", 7)) { 
pr_err("Invalid DH-CHAP secret %s\n", *secret); 
kfree_sensitive(*secret); return -EINVAL; } return 0; } --



More information about the Linux-nvme mailing list