GnuTLS with kernel TLS, and forgectrl.tls-records

The gnutls bbappend builds GnuTLS with --enable-ktls and installs
/etc/gnutls/config with ktls = true, so after the handshake the kernel
seals and opens forgectrl's HTTPS records (the kernel side is
meta-openglow's CONFIG_TLS and patch 0016). It also backports GnuTLS
dc016daf: 3.8.4 hands the kernel the record sequence number where a TLS
1.2 ChaCha20-Poly1305 connection's IV belongs, so every such connection
failed the kernel's first decryption. forgectrl is the only program on
the image that links GnuTLS.

forgectrl.tls-records, in its own module (suite/tlsrec.py), reads the
result from the outside with openssl s_client on loopback: a desktop
offer (AES-GCM first) gets ChaCha20-Poly1305 over TLS 1.3 and 1.2 and the
kernel takes both directions' keys; an AES-128-GCM-only offer, three
times over each protocol, gets it, the kernel takes its keys, and the
CAAM's job-ring interrupt counts the records; a TLS 1.2 CBC-only offer
connects and stays in GnuTLS (the control for the kernel's counters);
every copy of the panel page equals the plain-HTTP copy byte for byte,
with no decrypt error; the kernel's drivers are
rfc7539(chacha20-neon,poly1305-neon) and ctr-aes-caam with ghash-ce.

Proof: on the image before these fixes the test failed on both bugs it
names (the TLS 1.2 ChaCha20 page arrived empty with a decrypt error; the
AES-GCM pages arrived damaged); on image 20260927224418 it passes. The
unit suite (500 tests) and the coverage lint (0 uncovered paths) pass on
the host.
This commit is contained in:
ScottW514
2026-09-27 20:01:31 -04:00
parent cd84786fc5
commit 11031ad87f
6 changed files with 281 additions and 0 deletions
@@ -0,0 +1,42 @@
From dc016daf1af41d0285c61d3c65332b43d0ca577a Mon Sep 17 00:00:00 2001
From: Alexander Sosedkin <asosedkin@redhat.com>
Date: Tue, 3 Mar 2026 19:47:25 +0100
Subject: [PATCH] ktls: fix ChaCha20-Poly1305 IV passing for TLS 1.2
Upstream-Status: Backport [https://gitlab.com/gnutls/gnutls/-/commit/dc016daf1af41d0285c61d3c65332b43d0ca577a]
Signed-off-by: Alexander Sosedkin <asosedkin@redhat.com>
---
lib/system/ktls.c | 6 ++----
1 file changed, 2 insertions(+), 4 deletions(-)
diff --git a/lib/system/ktls.c b/lib/system/ktls.c
index a4c2a60df0..d531cfb85a 100644
--- a/lib/system/ktls.c
+++ b/lib/system/ktls.c
@@ -679,10 +679,9 @@ int _gnutls_ktls_set_keys(gnutls_session_t session,
assert(cipher_key.size ==
TLS_CIPHER_CHACHA20_POLY1305_KEY_SIZE);
- /* for TLS 1.2 IV is generated in kernel */
if (version == GNUTLS_TLS1_2) {
crypto_info.info.version = TLS_1_2_VERSION;
- memcpy(crypto_info.iv, seq_number,
+ memcpy(crypto_info.iv, iv.data,
TLS_CIPHER_CHACHA20_POLY1305_IV_SIZE);
} else {
crypto_info.info.version = TLS_1_3_VERSION;
@@ -854,10 +853,9 @@ int _gnutls_ktls_set_keys(gnutls_session_t session,
assert(cipher_key.size ==
TLS_CIPHER_CHACHA20_POLY1305_KEY_SIZE);
- /* for TLS 1.2 IV is generated in kernel */
if (version == GNUTLS_TLS1_2) {
crypto_info.info.version = TLS_1_2_VERSION;
- memcpy(crypto_info.iv, seq_number,
+ memcpy(crypto_info.iv, iv.data,
TLS_CIPHER_CHACHA20_POLY1305_IV_SIZE);
} else {
crypto_info.info.version = TLS_1_3_VERSION;
--
GitLab
@@ -0,0 +1,9 @@
# Copyright 2026 514 LLC d/b/a OpenGlow
# Written by Scott Wiederhold
# SPDX-License-Identifier: MIT
#
# GnuTLS's system-wide configuration. Kernel TLS on: after the handshake
# the kernel seals and opens the records. A connection on a cipher that
# kernel TLS does not take stays in user space.
[global]
ktls = true
@@ -0,0 +1,31 @@
# Copyright 2026 514 LLC d/b/a OpenGlow
# Written by Scott Wiederhold
# SPDX-License-Identifier: MIT
# Kernel TLS. GnuTLS runs the handshake, then gives the connection's keys
# to the socket, and the kernel seals and opens every record after that:
# ChaCha20-Poly1305 in NEON, AES-GCM with its AES on the CAAM crypto
# engine and its GHASH in NEON (the kernel options are in the BSP's
# kernel fragment). --enable-ktls builds the support in; /etc/gnutls/config
# turns it on, because the library leaves it off without that line. A
# connection on a cipher that kernel TLS does not take (AES-256-CCM, the
# CBC suites) stays in GnuTLS. forgectrl is the only program on the image
# that links GnuTLS (curl and Python use OpenSSL). The other build options
# are in conf/distro/forgefirm.conf.
#
# The backport: 3.8.4 hands the kernel the record sequence number where the
# connection's IV belongs for ChaCha20-Poly1305 over TLS 1.2, so every such
# connection fails the kernel's first decryption. Fixed upstream after 3.8.4.
FILESEXTRAPATHS:prepend := "${THISDIR}/files:"
SRC_URI:append:class-target = " file://config \
file://0001-ktls-fix-ChaCha20-Poly1305-IV-passing-for-TLS-1.2.patch"
EXTRA_OECONF:append:class-target = " --enable-ktls"
do_install:append:class-target() {
install -d ${D}${sysconfdir}/gnutls
install -m 0644 ${WORKDIR}/config ${D}${sysconfdir}/gnutls/config
}
FILES:${PN}:append:class-target = " ${sysconfdir}/gnutls/config"