2019-05-27 13:55:01 +07:00
|
|
|
// SPDX-License-Identifier: GPL-2.0-or-later
|
2006-08-21 18:08:13 +07:00
|
|
|
/*
|
|
|
|
* Cryptographic API for algorithms (i.e., low-level API).
|
|
|
|
*
|
|
|
|
* Copyright (c) 2006 Herbert Xu <herbert@gondor.apana.org.au>
|
|
|
|
*/
|
|
|
|
|
2018-04-09 20:54:46 +07:00
|
|
|
#include <crypto/algapi.h>
|
2006-09-21 08:39:29 +07:00
|
|
|
#include <linux/err.h>
|
2006-08-21 18:08:13 +07:00
|
|
|
#include <linux/errno.h>
|
2015-04-22 12:25:53 +07:00
|
|
|
#include <linux/fips.h>
|
2006-08-21 18:08:13 +07:00
|
|
|
#include <linux/init.h>
|
|
|
|
#include <linux/kernel.h>
|
2006-08-06 18:16:34 +07:00
|
|
|
#include <linux/list.h>
|
2006-08-21 18:08:13 +07:00
|
|
|
#include <linux/module.h>
|
2006-08-06 20:10:45 +07:00
|
|
|
#include <linux/rtnetlink.h>
|
include cleanup: Update gfp.h and slab.h includes to prepare for breaking implicit slab.h inclusion from percpu.h
percpu.h is included by sched.h and module.h and thus ends up being
included when building most .c files. percpu.h includes slab.h which
in turn includes gfp.h making everything defined by the two files
universally available and complicating inclusion dependencies.
percpu.h -> slab.h dependency is about to be removed. Prepare for
this change by updating users of gfp and slab facilities include those
headers directly instead of assuming availability. As this conversion
needs to touch large number of source files, the following script is
used as the basis of conversion.
http://userweb.kernel.org/~tj/misc/slabh-sweep.py
The script does the followings.
* Scan files for gfp and slab usages and update includes such that
only the necessary includes are there. ie. if only gfp is used,
gfp.h, if slab is used, slab.h.
* When the script inserts a new include, it looks at the include
blocks and try to put the new include such that its order conforms
to its surrounding. It's put in the include block which contains
core kernel includes, in the same order that the rest are ordered -
alphabetical, Christmas tree, rev-Xmas-tree or at the end if there
doesn't seem to be any matching order.
* If the script can't find a place to put a new include (mostly
because the file doesn't have fitting include block), it prints out
an error message indicating which .h file needs to be added to the
file.
The conversion was done in the following steps.
1. The initial automatic conversion of all .c files updated slightly
over 4000 files, deleting around 700 includes and adding ~480 gfp.h
and ~3000 slab.h inclusions. The script emitted errors for ~400
files.
2. Each error was manually checked. Some didn't need the inclusion,
some needed manual addition while adding it to implementation .h or
embedding .c file was more appropriate for others. This step added
inclusions to around 150 files.
3. The script was run again and the output was compared to the edits
from #2 to make sure no file was left behind.
4. Several build tests were done and a couple of problems were fixed.
e.g. lib/decompress_*.c used malloc/free() wrappers around slab
APIs requiring slab.h to be added manually.
5. The script was run on all .h files but without automatically
editing them as sprinkling gfp.h and slab.h inclusions around .h
files could easily lead to inclusion dependency hell. Most gfp.h
inclusion directives were ignored as stuff from gfp.h was usually
wildly available and often used in preprocessor macros. Each
slab.h inclusion directive was examined and added manually as
necessary.
6. percpu.h was updated not to include slab.h.
7. Build test were done on the following configurations and failures
were fixed. CONFIG_GCOV_KERNEL was turned off for all tests (as my
distributed build env didn't work with gcov compiles) and a few
more options had to be turned off depending on archs to make things
build (like ipr on powerpc/64 which failed due to missing writeq).
* x86 and x86_64 UP and SMP allmodconfig and a custom test config.
* powerpc and powerpc64 SMP allmodconfig
* sparc and sparc64 SMP allmodconfig
* ia64 SMP allmodconfig
* s390 SMP allmodconfig
* alpha SMP allmodconfig
* um on x86_64 SMP allmodconfig
8. percpu.h modifications were reverted so that it could be applied as
a separate patch and serve as bisection point.
Given the fact that I had only a couple of failures from tests on step
6, I'm fairly confident about the coverage of this conversion patch.
If there is a breakage, it's likely to be something in one of the arch
headers which should be easily discoverable easily on most builds of
the specific arch.
Signed-off-by: Tejun Heo <tj@kernel.org>
Guess-its-ok-by: Christoph Lameter <cl@linux-foundation.org>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: Lee Schermerhorn <Lee.Schermerhorn@hp.com>
2010-03-24 15:04:11 +07:00
|
|
|
#include <linux/slab.h>
|
2006-08-21 18:08:13 +07:00
|
|
|
#include <linux/string.h>
|
|
|
|
|
|
|
|
#include "internal.h"
|
|
|
|
|
2006-08-06 18:16:34 +07:00
|
|
|
static LIST_HEAD(crypto_template_list);
|
|
|
|
|
2014-07-03 02:37:30 +07:00
|
|
|
static inline void crypto_check_module_sig(struct module *mod)
|
|
|
|
{
|
2015-04-22 10:28:46 +07:00
|
|
|
if (fips_enabled && mod && !module_sig_ok(mod))
|
2014-07-03 02:37:30 +07:00
|
|
|
panic("Module %s signature verification failed in FIPS mode\n",
|
2015-04-23 13:48:05 +07:00
|
|
|
module_name(mod));
|
2014-07-03 02:37:30 +07:00
|
|
|
}
|
|
|
|
|
2006-08-06 18:16:34 +07:00
|
|
|
static int crypto_check_alg(struct crypto_alg *alg)
|
2006-08-21 18:08:13 +07:00
|
|
|
{
|
2014-07-03 02:37:30 +07:00
|
|
|
crypto_check_module_sig(alg->cra_module);
|
|
|
|
|
2019-06-03 12:40:58 +07:00
|
|
|
if (!alg->cra_name[0] || !alg->cra_driver_name[0])
|
|
|
|
return -EINVAL;
|
|
|
|
|
2006-08-21 18:08:13 +07:00
|
|
|
if (alg->cra_alignmask & (alg->cra_alignmask + 1))
|
|
|
|
return -EINVAL;
|
|
|
|
|
2018-08-08 04:18:40 +07:00
|
|
|
/* General maximums for all algs. */
|
|
|
|
if (alg->cra_alignmask > MAX_ALGAPI_ALIGNMASK)
|
2006-08-21 18:08:13 +07:00
|
|
|
return -EINVAL;
|
|
|
|
|
2018-08-08 04:18:40 +07:00
|
|
|
if (alg->cra_blocksize > MAX_ALGAPI_BLOCKSIZE)
|
|
|
|
return -EINVAL;
|
|
|
|
|
|
|
|
/* Lower maximums for specific alg types. */
|
2018-04-09 20:54:46 +07:00
|
|
|
if (!alg->cra_type && (alg->cra_flags & CRYPTO_ALG_TYPE_MASK) ==
|
|
|
|
CRYPTO_ALG_TYPE_CIPHER) {
|
|
|
|
if (alg->cra_alignmask > MAX_CIPHER_ALIGNMASK)
|
|
|
|
return -EINVAL;
|
|
|
|
|
|
|
|
if (alg->cra_blocksize > MAX_CIPHER_BLOCKSIZE)
|
|
|
|
return -EINVAL;
|
|
|
|
}
|
|
|
|
|
2006-08-21 18:08:13 +07:00
|
|
|
if (alg->cra_priority < 0)
|
|
|
|
return -EINVAL;
|
|
|
|
|
2017-12-29 23:00:46 +07:00
|
|
|
refcount_set(&alg->cra_refcnt, 1);
|
2015-04-09 16:40:35 +07:00
|
|
|
|
2019-06-03 12:40:58 +07:00
|
|
|
return 0;
|
2006-08-06 18:16:34 +07:00
|
|
|
}
|
|
|
|
|
2015-07-09 06:17:15 +07:00
|
|
|
static void crypto_free_instance(struct crypto_instance *inst)
|
|
|
|
{
|
|
|
|
if (!inst->alg.cra_type->free) {
|
|
|
|
inst->tmpl->free(inst);
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
inst->alg.cra_type->free(inst);
|
|
|
|
}
|
|
|
|
|
2006-09-21 08:39:29 +07:00
|
|
|
static void crypto_destroy_instance(struct crypto_alg *alg)
|
|
|
|
{
|
|
|
|
struct crypto_instance *inst = (void *)alg;
|
|
|
|
struct crypto_template *tmpl = inst->tmpl;
|
|
|
|
|
2015-07-09 06:17:15 +07:00
|
|
|
crypto_free_instance(inst);
|
2006-09-21 08:39:29 +07:00
|
|
|
crypto_tmpl_put(tmpl);
|
|
|
|
}
|
|
|
|
|
2009-08-31 12:56:54 +07:00
|
|
|
static struct list_head *crypto_more_spawns(struct crypto_alg *alg,
|
|
|
|
struct list_head *stack,
|
|
|
|
struct list_head *top,
|
|
|
|
struct list_head *secondary_spawns)
|
|
|
|
{
|
|
|
|
struct crypto_spawn *spawn, *n;
|
|
|
|
|
2015-11-16 21:37:14 +07:00
|
|
|
spawn = list_first_entry_or_null(stack, struct crypto_spawn, list);
|
|
|
|
if (!spawn)
|
2009-08-31 12:56:54 +07:00
|
|
|
return NULL;
|
|
|
|
|
2015-11-16 21:37:14 +07:00
|
|
|
n = list_next_entry(spawn, list);
|
2009-08-31 12:56:54 +07:00
|
|
|
|
|
|
|
if (spawn->alg && &n->list != stack && !n->alg)
|
|
|
|
n->alg = (n->list.next == stack) ? alg :
|
2015-11-16 21:37:14 +07:00
|
|
|
&list_next_entry(n, list)->inst->alg;
|
2009-08-31 12:56:54 +07:00
|
|
|
|
|
|
|
list_move(&spawn->list, secondary_spawns);
|
|
|
|
|
|
|
|
return &n->list == stack ? top : &n->inst->alg.cra_users;
|
|
|
|
}
|
|
|
|
|
2015-04-02 21:31:22 +07:00
|
|
|
static void crypto_remove_instance(struct crypto_instance *inst,
|
|
|
|
struct list_head *list)
|
2006-09-21 08:39:29 +07:00
|
|
|
{
|
2007-04-08 18:31:36 +07:00
|
|
|
struct crypto_template *tmpl = inst->tmpl;
|
2006-09-21 08:39:29 +07:00
|
|
|
|
2007-04-08 18:31:36 +07:00
|
|
|
if (crypto_is_dead(&inst->alg))
|
|
|
|
return;
|
2006-09-21 08:39:29 +07:00
|
|
|
|
2007-04-08 18:31:36 +07:00
|
|
|
inst->alg.cra_flags |= CRYPTO_ALG_DEAD;
|
2007-11-17 21:09:38 +07:00
|
|
|
if (hlist_unhashed(&inst->list))
|
|
|
|
return;
|
|
|
|
|
2007-04-08 18:31:36 +07:00
|
|
|
if (!tmpl || !crypto_tmpl_get(tmpl))
|
|
|
|
return;
|
|
|
|
|
|
|
|
list_move(&inst->alg.cra_list, list);
|
|
|
|
hlist_del(&inst->list);
|
|
|
|
inst->alg.cra_destroy = crypto_destroy_instance;
|
|
|
|
|
2009-08-31 12:56:54 +07:00
|
|
|
BUG_ON(!list_empty(&inst->alg.cra_users));
|
2007-04-08 18:31:36 +07:00
|
|
|
}
|
|
|
|
|
2011-09-27 12:22:08 +07:00
|
|
|
void crypto_remove_spawns(struct crypto_alg *alg, struct list_head *list,
|
|
|
|
struct crypto_alg *nalg)
|
2007-04-08 18:31:36 +07:00
|
|
|
{
|
2009-08-31 12:56:54 +07:00
|
|
|
u32 new_type = (nalg ?: alg)->cra_flags;
|
2007-04-08 18:31:36 +07:00
|
|
|
struct crypto_spawn *spawn, *n;
|
|
|
|
LIST_HEAD(secondary_spawns);
|
2009-08-31 12:56:54 +07:00
|
|
|
struct list_head *spawns;
|
|
|
|
LIST_HEAD(stack);
|
|
|
|
LIST_HEAD(top);
|
2006-09-21 08:39:29 +07:00
|
|
|
|
2009-08-31 12:56:54 +07:00
|
|
|
spawns = &alg->cra_users;
|
2007-04-08 18:31:36 +07:00
|
|
|
list_for_each_entry_safe(spawn, n, spawns, list) {
|
|
|
|
if ((spawn->alg->cra_flags ^ new_type) & spawn->mask)
|
2006-09-21 08:39:29 +07:00
|
|
|
continue;
|
|
|
|
|
2009-08-31 12:56:54 +07:00
|
|
|
list_move(&spawn->list, &top);
|
2007-04-08 18:31:36 +07:00
|
|
|
}
|
2006-09-21 08:39:29 +07:00
|
|
|
|
2009-08-31 12:56:54 +07:00
|
|
|
spawns = ⊤
|
|
|
|
do {
|
|
|
|
while (!list_empty(spawns)) {
|
|
|
|
struct crypto_instance *inst;
|
|
|
|
|
|
|
|
spawn = list_first_entry(spawns, struct crypto_spawn,
|
|
|
|
list);
|
|
|
|
inst = spawn->inst;
|
|
|
|
|
|
|
|
BUG_ON(&inst->alg == alg);
|
|
|
|
|
|
|
|
list_move(&spawn->list, &stack);
|
|
|
|
|
|
|
|
if (&inst->alg == nalg)
|
|
|
|
break;
|
|
|
|
|
|
|
|
spawn->alg = NULL;
|
|
|
|
spawns = &inst->alg.cra_users;
|
2017-12-30 03:30:19 +07:00
|
|
|
|
|
|
|
/*
|
|
|
|
* We may encounter an unregistered instance here, since
|
|
|
|
* an instance's spawns are set up prior to the instance
|
|
|
|
* being registered. An unregistered instance will have
|
|
|
|
* NULL ->cra_users.next, since ->cra_users isn't
|
|
|
|
* properly initialized until registration. But an
|
|
|
|
* unregistered instance cannot have any users, so treat
|
|
|
|
* it the same as ->cra_users being empty.
|
|
|
|
*/
|
|
|
|
if (spawns->next == NULL)
|
|
|
|
break;
|
2009-08-31 12:56:54 +07:00
|
|
|
}
|
|
|
|
} while ((spawns = crypto_more_spawns(alg, &stack, &top,
|
|
|
|
&secondary_spawns)));
|
|
|
|
|
|
|
|
list_for_each_entry_safe(spawn, n, &secondary_spawns, list) {
|
|
|
|
if (spawn->alg)
|
|
|
|
list_move(&spawn->list, &spawn->alg->cra_users);
|
|
|
|
else
|
2015-04-02 21:31:22 +07:00
|
|
|
crypto_remove_instance(spawn->inst, list);
|
2006-09-21 08:39:29 +07:00
|
|
|
}
|
|
|
|
}
|
2011-09-27 12:22:08 +07:00
|
|
|
EXPORT_SYMBOL_GPL(crypto_remove_spawns);
|
2006-09-21 08:39:29 +07:00
|
|
|
|
2008-08-03 20:15:23 +07:00
|
|
|
static struct crypto_larval *__crypto_register_alg(struct crypto_alg *alg)
|
2006-08-06 18:16:34 +07:00
|
|
|
{
|
|
|
|
struct crypto_alg *q;
|
2008-08-03 20:15:23 +07:00
|
|
|
struct crypto_larval *larval;
|
2006-09-21 08:39:29 +07:00
|
|
|
int ret = -EAGAIN;
|
|
|
|
|
|
|
|
if (crypto_is_dead(alg))
|
2008-08-03 20:15:23 +07:00
|
|
|
goto err;
|
2006-09-21 08:39:29 +07:00
|
|
|
|
|
|
|
INIT_LIST_HEAD(&alg->cra_users);
|
|
|
|
|
2008-08-03 20:15:23 +07:00
|
|
|
/* No cheating! */
|
|
|
|
alg->cra_flags &= ~CRYPTO_ALG_TESTED;
|
|
|
|
|
2006-09-21 08:39:29 +07:00
|
|
|
ret = -EEXIST;
|
2006-08-06 18:16:34 +07:00
|
|
|
|
2006-08-21 18:08:13 +07:00
|
|
|
list_for_each_entry(q, &crypto_alg_list, cra_list) {
|
2006-08-06 18:16:34 +07:00
|
|
|
if (q == alg)
|
2008-08-03 20:15:23 +07:00
|
|
|
goto err;
|
|
|
|
|
2009-01-28 10:09:59 +07:00
|
|
|
if (crypto_is_moribund(q))
|
|
|
|
continue;
|
|
|
|
|
2008-08-03 20:15:23 +07:00
|
|
|
if (crypto_is_larval(q)) {
|
|
|
|
if (!strcmp(alg->cra_driver_name, q->cra_driver_name))
|
|
|
|
goto err;
|
|
|
|
continue;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (!strcmp(q->cra_driver_name, alg->cra_name) ||
|
|
|
|
!strcmp(q->cra_name, alg->cra_driver_name))
|
|
|
|
goto err;
|
|
|
|
}
|
|
|
|
|
|
|
|
larval = crypto_larval_alloc(alg->cra_name,
|
|
|
|
alg->cra_flags | CRYPTO_ALG_TESTED, 0);
|
|
|
|
if (IS_ERR(larval))
|
|
|
|
goto out;
|
|
|
|
|
|
|
|
ret = -ENOENT;
|
|
|
|
larval->adult = crypto_mod_get(alg);
|
|
|
|
if (!larval->adult)
|
|
|
|
goto free_larval;
|
|
|
|
|
2017-12-29 23:00:46 +07:00
|
|
|
refcount_set(&larval->alg.cra_refcnt, 1);
|
2008-08-03 20:15:23 +07:00
|
|
|
memcpy(larval->alg.cra_driver_name, alg->cra_driver_name,
|
|
|
|
CRYPTO_MAX_ALG_NAME);
|
|
|
|
larval->alg.cra_priority = alg->cra_priority;
|
|
|
|
|
|
|
|
list_add(&alg->cra_list, &crypto_alg_list);
|
|
|
|
list_add(&larval->alg.cra_list, &crypto_alg_list);
|
|
|
|
|
2018-11-29 21:42:26 +07:00
|
|
|
crypto_stats_init(alg);
|
2018-09-19 17:10:54 +07:00
|
|
|
|
2010-02-16 19:25:21 +07:00
|
|
|
out:
|
2008-08-03 20:15:23 +07:00
|
|
|
return larval;
|
|
|
|
|
|
|
|
free_larval:
|
|
|
|
kfree(larval);
|
|
|
|
err:
|
|
|
|
larval = ERR_PTR(ret);
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
|
|
|
void crypto_alg_tested(const char *name, int err)
|
|
|
|
{
|
|
|
|
struct crypto_larval *test;
|
|
|
|
struct crypto_alg *alg;
|
|
|
|
struct crypto_alg *q;
|
|
|
|
LIST_HEAD(list);
|
|
|
|
|
|
|
|
down_write(&crypto_alg_sem);
|
|
|
|
list_for_each_entry(q, &crypto_alg_list, cra_list) {
|
2009-01-28 10:09:59 +07:00
|
|
|
if (crypto_is_moribund(q) || !crypto_is_larval(q))
|
2008-08-03 20:15:23 +07:00
|
|
|
continue;
|
|
|
|
|
|
|
|
test = (struct crypto_larval *)q;
|
|
|
|
|
|
|
|
if (!strcmp(q->cra_driver_name, name))
|
|
|
|
goto found;
|
|
|
|
}
|
|
|
|
|
2017-05-14 02:05:19 +07:00
|
|
|
pr_err("alg: Unexpected test result for %s: %d\n", name, err);
|
2008-08-03 20:15:23 +07:00
|
|
|
goto unlock;
|
|
|
|
|
|
|
|
found:
|
2009-01-28 10:09:59 +07:00
|
|
|
q->cra_flags |= CRYPTO_ALG_DEAD;
|
2008-08-03 20:15:23 +07:00
|
|
|
alg = test->adult;
|
|
|
|
if (err || list_empty(&alg->cra_list))
|
|
|
|
goto complete;
|
|
|
|
|
|
|
|
alg->cra_flags |= CRYPTO_ALG_TESTED;
|
|
|
|
|
|
|
|
list_for_each_entry(q, &crypto_alg_list, cra_list) {
|
|
|
|
if (q == alg)
|
|
|
|
continue;
|
2006-09-21 08:39:29 +07:00
|
|
|
|
|
|
|
if (crypto_is_moribund(q))
|
|
|
|
continue;
|
|
|
|
|
|
|
|
if (crypto_is_larval(q)) {
|
2006-08-06 18:23:26 +07:00
|
|
|
struct crypto_larval *larval = (void *)q;
|
|
|
|
|
2007-10-02 21:27:29 +07:00
|
|
|
/*
|
|
|
|
* Check to see if either our generic name or
|
|
|
|
* specific name can satisfy the name requested
|
|
|
|
* by the larval entry q.
|
|
|
|
*/
|
2006-09-21 08:39:29 +07:00
|
|
|
if (strcmp(alg->cra_name, q->cra_name) &&
|
|
|
|
strcmp(alg->cra_driver_name, q->cra_name))
|
|
|
|
continue;
|
|
|
|
|
|
|
|
if (larval->adult)
|
|
|
|
continue;
|
2006-09-21 08:35:17 +07:00
|
|
|
if ((q->cra_flags ^ alg->cra_flags) & larval->mask)
|
|
|
|
continue;
|
2006-08-06 18:23:26 +07:00
|
|
|
if (!crypto_mod_get(alg))
|
|
|
|
continue;
|
2006-09-21 08:39:29 +07:00
|
|
|
|
2006-08-06 18:23:26 +07:00
|
|
|
larval->adult = alg;
|
2006-09-21 08:39:29 +07:00
|
|
|
continue;
|
2006-08-06 18:23:26 +07:00
|
|
|
}
|
2006-09-21 08:39:29 +07:00
|
|
|
|
|
|
|
if (strcmp(alg->cra_name, q->cra_name))
|
|
|
|
continue;
|
|
|
|
|
|
|
|
if (strcmp(alg->cra_driver_name, q->cra_driver_name) &&
|
|
|
|
q->cra_priority > alg->cra_priority)
|
|
|
|
continue;
|
|
|
|
|
2009-08-31 12:56:54 +07:00
|
|
|
crypto_remove_spawns(q, &list, alg);
|
2006-08-21 18:08:13 +07:00
|
|
|
}
|
2006-08-06 18:23:26 +07:00
|
|
|
|
2008-08-03 20:15:23 +07:00
|
|
|
complete:
|
|
|
|
complete_all(&test->completion);
|
2006-08-06 18:23:26 +07:00
|
|
|
|
2008-08-03 20:15:23 +07:00
|
|
|
unlock:
|
|
|
|
up_write(&crypto_alg_sem);
|
|
|
|
|
|
|
|
crypto_remove_final(&list);
|
2006-08-21 18:08:13 +07:00
|
|
|
}
|
2008-08-03 20:15:23 +07:00
|
|
|
EXPORT_SYMBOL_GPL(crypto_alg_tested);
|
2006-08-06 18:16:34 +07:00
|
|
|
|
2011-09-27 12:23:07 +07:00
|
|
|
void crypto_remove_final(struct list_head *list)
|
2006-09-21 08:39:29 +07:00
|
|
|
{
|
|
|
|
struct crypto_alg *alg;
|
|
|
|
struct crypto_alg *n;
|
|
|
|
|
|
|
|
list_for_each_entry_safe(alg, n, list, cra_list) {
|
|
|
|
list_del_init(&alg->cra_list);
|
|
|
|
crypto_alg_put(alg);
|
|
|
|
}
|
|
|
|
}
|
2011-09-27 12:23:07 +07:00
|
|
|
EXPORT_SYMBOL_GPL(crypto_remove_final);
|
2006-09-21 08:39:29 +07:00
|
|
|
|
2008-08-03 20:15:23 +07:00
|
|
|
static void crypto_wait_for_test(struct crypto_larval *larval)
|
|
|
|
{
|
|
|
|
int err;
|
|
|
|
|
|
|
|
err = crypto_probing_notify(CRYPTO_MSG_ALG_REGISTER, larval->adult);
|
|
|
|
if (err != NOTIFY_STOP) {
|
|
|
|
if (WARN_ON(err != NOTIFY_DONE))
|
|
|
|
goto out;
|
|
|
|
crypto_alg_tested(larval->alg.cra_driver_name, 0);
|
|
|
|
}
|
|
|
|
|
2015-10-19 17:23:57 +07:00
|
|
|
err = wait_for_completion_killable(&larval->completion);
|
2008-08-03 20:15:23 +07:00
|
|
|
WARN_ON(err);
|
2018-08-30 22:00:14 +07:00
|
|
|
if (!err)
|
|
|
|
crypto_probing_notify(CRYPTO_MSG_ALG_LOADED, larval);
|
2008-08-03 20:15:23 +07:00
|
|
|
|
|
|
|
out:
|
|
|
|
crypto_larval_kill(&larval->alg);
|
|
|
|
}
|
|
|
|
|
2006-08-06 18:16:34 +07:00
|
|
|
int crypto_register_alg(struct crypto_alg *alg)
|
|
|
|
{
|
2008-08-03 20:15:23 +07:00
|
|
|
struct crypto_larval *larval;
|
2006-08-06 18:16:34 +07:00
|
|
|
int err;
|
|
|
|
|
2017-01-13 18:54:08 +07:00
|
|
|
alg->cra_flags &= ~CRYPTO_ALG_DEAD;
|
2006-08-06 18:16:34 +07:00
|
|
|
err = crypto_check_alg(alg);
|
|
|
|
if (err)
|
|
|
|
return err;
|
|
|
|
|
|
|
|
down_write(&crypto_alg_sem);
|
2008-08-03 20:15:23 +07:00
|
|
|
larval = __crypto_register_alg(alg);
|
2006-08-06 18:16:34 +07:00
|
|
|
up_write(&crypto_alg_sem);
|
|
|
|
|
2008-08-03 20:15:23 +07:00
|
|
|
if (IS_ERR(larval))
|
|
|
|
return PTR_ERR(larval);
|
|
|
|
|
|
|
|
crypto_wait_for_test(larval);
|
|
|
|
return 0;
|
2006-08-06 18:16:34 +07:00
|
|
|
}
|
2006-08-21 18:08:13 +07:00
|
|
|
EXPORT_SYMBOL_GPL(crypto_register_alg);
|
|
|
|
|
2006-09-21 08:39:29 +07:00
|
|
|
static int crypto_remove_alg(struct crypto_alg *alg, struct list_head *list)
|
|
|
|
{
|
|
|
|
if (unlikely(list_empty(&alg->cra_list)))
|
|
|
|
return -ENOENT;
|
|
|
|
|
|
|
|
alg->cra_flags |= CRYPTO_ALG_DEAD;
|
|
|
|
|
|
|
|
list_del_init(&alg->cra_list);
|
2009-08-31 12:56:54 +07:00
|
|
|
crypto_remove_spawns(alg, list, NULL);
|
2006-09-21 08:39:29 +07:00
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
2006-08-21 18:08:13 +07:00
|
|
|
int crypto_unregister_alg(struct crypto_alg *alg)
|
|
|
|
{
|
2006-09-21 08:39:29 +07:00
|
|
|
int ret;
|
|
|
|
LIST_HEAD(list);
|
2010-02-16 19:25:21 +07:00
|
|
|
|
2006-08-21 18:08:13 +07:00
|
|
|
down_write(&crypto_alg_sem);
|
2006-09-21 08:39:29 +07:00
|
|
|
ret = crypto_remove_alg(alg, &list);
|
2006-08-21 18:08:13 +07:00
|
|
|
up_write(&crypto_alg_sem);
|
|
|
|
|
|
|
|
if (ret)
|
|
|
|
return ret;
|
|
|
|
|
2017-12-29 23:00:46 +07:00
|
|
|
BUG_ON(refcount_read(&alg->cra_refcnt) != 1);
|
2006-08-21 18:08:13 +07:00
|
|
|
if (alg->cra_destroy)
|
|
|
|
alg->cra_destroy(alg);
|
|
|
|
|
2006-09-21 08:39:29 +07:00
|
|
|
crypto_remove_final(&list);
|
2006-08-21 18:08:13 +07:00
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_unregister_alg);
|
|
|
|
|
2012-01-18 06:34:26 +07:00
|
|
|
int crypto_register_algs(struct crypto_alg *algs, int count)
|
|
|
|
{
|
|
|
|
int i, ret;
|
|
|
|
|
|
|
|
for (i = 0; i < count; i++) {
|
|
|
|
ret = crypto_register_alg(&algs[i]);
|
|
|
|
if (ret)
|
|
|
|
goto err;
|
|
|
|
}
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
|
|
|
|
err:
|
|
|
|
for (--i; i >= 0; --i)
|
|
|
|
crypto_unregister_alg(&algs[i]);
|
|
|
|
|
|
|
|
return ret;
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_register_algs);
|
|
|
|
|
|
|
|
int crypto_unregister_algs(struct crypto_alg *algs, int count)
|
|
|
|
{
|
|
|
|
int i, ret;
|
|
|
|
|
|
|
|
for (i = 0; i < count; i++) {
|
|
|
|
ret = crypto_unregister_alg(&algs[i]);
|
|
|
|
if (ret)
|
|
|
|
pr_err("Failed to unregister %s %s: %d\n",
|
|
|
|
algs[i].cra_driver_name, algs[i].cra_name, ret);
|
|
|
|
}
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_unregister_algs);
|
|
|
|
|
2006-08-06 18:16:34 +07:00
|
|
|
int crypto_register_template(struct crypto_template *tmpl)
|
|
|
|
{
|
|
|
|
struct crypto_template *q;
|
|
|
|
int err = -EEXIST;
|
|
|
|
|
|
|
|
down_write(&crypto_alg_sem);
|
|
|
|
|
2014-07-03 02:37:30 +07:00
|
|
|
crypto_check_module_sig(tmpl->module);
|
|
|
|
|
2006-08-06 18:16:34 +07:00
|
|
|
list_for_each_entry(q, &crypto_template_list, list) {
|
|
|
|
if (q == tmpl)
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
|
|
|
list_add(&tmpl->list, &crypto_template_list);
|
|
|
|
err = 0;
|
|
|
|
out:
|
|
|
|
up_write(&crypto_alg_sem);
|
|
|
|
return err;
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_register_template);
|
|
|
|
|
2019-01-18 12:58:11 +07:00
|
|
|
int crypto_register_templates(struct crypto_template *tmpls, int count)
|
|
|
|
{
|
|
|
|
int i, err;
|
|
|
|
|
|
|
|
for (i = 0; i < count; i++) {
|
|
|
|
err = crypto_register_template(&tmpls[i]);
|
|
|
|
if (err)
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
return 0;
|
|
|
|
|
|
|
|
out:
|
|
|
|
for (--i; i >= 0; --i)
|
|
|
|
crypto_unregister_template(&tmpls[i]);
|
|
|
|
return err;
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_register_templates);
|
|
|
|
|
2006-08-06 18:16:34 +07:00
|
|
|
void crypto_unregister_template(struct crypto_template *tmpl)
|
|
|
|
{
|
|
|
|
struct crypto_instance *inst;
|
hlist: drop the node parameter from iterators
I'm not sure why, but the hlist for each entry iterators were conceived
list_for_each_entry(pos, head, member)
The hlist ones were greedy and wanted an extra parameter:
hlist_for_each_entry(tpos, pos, head, member)
Why did they need an extra pos parameter? I'm not quite sure. Not only
they don't really need it, it also prevents the iterator from looking
exactly like the list iterator, which is unfortunate.
Besides the semantic patch, there was some manual work required:
- Fix up the actual hlist iterators in linux/list.h
- Fix up the declaration of other iterators based on the hlist ones.
- A very small amount of places were using the 'node' parameter, this
was modified to use 'obj->member' instead.
- Coccinelle didn't handle the hlist_for_each_entry_safe iterator
properly, so those had to be fixed up manually.
The semantic patch which is mostly the work of Peter Senna Tschudin is here:
@@
iterator name hlist_for_each_entry, hlist_for_each_entry_continue, hlist_for_each_entry_from, hlist_for_each_entry_rcu, hlist_for_each_entry_rcu_bh, hlist_for_each_entry_continue_rcu_bh, for_each_busy_worker, ax25_uid_for_each, ax25_for_each, inet_bind_bucket_for_each, sctp_for_each_hentry, sk_for_each, sk_for_each_rcu, sk_for_each_from, sk_for_each_safe, sk_for_each_bound, hlist_for_each_entry_safe, hlist_for_each_entry_continue_rcu, nr_neigh_for_each, nr_neigh_for_each_safe, nr_node_for_each, nr_node_for_each_safe, for_each_gfn_indirect_valid_sp, for_each_gfn_sp, for_each_host;
type T;
expression a,c,d,e;
identifier b;
statement S;
@@
-T b;
<+... when != b
(
hlist_for_each_entry(a,
- b,
c, d) S
|
hlist_for_each_entry_continue(a,
- b,
c) S
|
hlist_for_each_entry_from(a,
- b,
c) S
|
hlist_for_each_entry_rcu(a,
- b,
c, d) S
|
hlist_for_each_entry_rcu_bh(a,
- b,
c, d) S
|
hlist_for_each_entry_continue_rcu_bh(a,
- b,
c) S
|
for_each_busy_worker(a, c,
- b,
d) S
|
ax25_uid_for_each(a,
- b,
c) S
|
ax25_for_each(a,
- b,
c) S
|
inet_bind_bucket_for_each(a,
- b,
c) S
|
sctp_for_each_hentry(a,
- b,
c) S
|
sk_for_each(a,
- b,
c) S
|
sk_for_each_rcu(a,
- b,
c) S
|
sk_for_each_from
-(a, b)
+(a)
S
+ sk_for_each_from(a) S
|
sk_for_each_safe(a,
- b,
c, d) S
|
sk_for_each_bound(a,
- b,
c) S
|
hlist_for_each_entry_safe(a,
- b,
c, d, e) S
|
hlist_for_each_entry_continue_rcu(a,
- b,
c) S
|
nr_neigh_for_each(a,
- b,
c) S
|
nr_neigh_for_each_safe(a,
- b,
c, d) S
|
nr_node_for_each(a,
- b,
c) S
|
nr_node_for_each_safe(a,
- b,
c, d) S
|
- for_each_gfn_sp(a, c, d, b) S
+ for_each_gfn_sp(a, c, d) S
|
- for_each_gfn_indirect_valid_sp(a, c, d, b) S
+ for_each_gfn_indirect_valid_sp(a, c, d) S
|
for_each_host(a,
- b,
c) S
|
for_each_host_safe(a,
- b,
c, d) S
|
for_each_mesh_entry(a,
- b,
c, d) S
)
...+>
[akpm@linux-foundation.org: drop bogus change from net/ipv4/raw.c]
[akpm@linux-foundation.org: drop bogus hunk from net/ipv6/raw.c]
[akpm@linux-foundation.org: checkpatch fixes]
[akpm@linux-foundation.org: fix warnings]
[akpm@linux-foudnation.org: redo intrusive kvm changes]
Tested-by: Peter Senna Tschudin <peter.senna@gmail.com>
Acked-by: Paul E. McKenney <paulmck@linux.vnet.ibm.com>
Signed-off-by: Sasha Levin <sasha.levin@oracle.com>
Cc: Wu Fengguang <fengguang.wu@intel.com>
Cc: Marcelo Tosatti <mtosatti@redhat.com>
Cc: Gleb Natapov <gleb@redhat.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
2013-02-28 08:06:00 +07:00
|
|
|
struct hlist_node *n;
|
2006-08-06 18:16:34 +07:00
|
|
|
struct hlist_head *list;
|
2006-09-21 08:39:29 +07:00
|
|
|
LIST_HEAD(users);
|
2006-08-06 18:16:34 +07:00
|
|
|
|
|
|
|
down_write(&crypto_alg_sem);
|
|
|
|
|
|
|
|
BUG_ON(list_empty(&tmpl->list));
|
|
|
|
list_del_init(&tmpl->list);
|
|
|
|
|
|
|
|
list = &tmpl->instances;
|
hlist: drop the node parameter from iterators
I'm not sure why, but the hlist for each entry iterators were conceived
list_for_each_entry(pos, head, member)
The hlist ones were greedy and wanted an extra parameter:
hlist_for_each_entry(tpos, pos, head, member)
Why did they need an extra pos parameter? I'm not quite sure. Not only
they don't really need it, it also prevents the iterator from looking
exactly like the list iterator, which is unfortunate.
Besides the semantic patch, there was some manual work required:
- Fix up the actual hlist iterators in linux/list.h
- Fix up the declaration of other iterators based on the hlist ones.
- A very small amount of places were using the 'node' parameter, this
was modified to use 'obj->member' instead.
- Coccinelle didn't handle the hlist_for_each_entry_safe iterator
properly, so those had to be fixed up manually.
The semantic patch which is mostly the work of Peter Senna Tschudin is here:
@@
iterator name hlist_for_each_entry, hlist_for_each_entry_continue, hlist_for_each_entry_from, hlist_for_each_entry_rcu, hlist_for_each_entry_rcu_bh, hlist_for_each_entry_continue_rcu_bh, for_each_busy_worker, ax25_uid_for_each, ax25_for_each, inet_bind_bucket_for_each, sctp_for_each_hentry, sk_for_each, sk_for_each_rcu, sk_for_each_from, sk_for_each_safe, sk_for_each_bound, hlist_for_each_entry_safe, hlist_for_each_entry_continue_rcu, nr_neigh_for_each, nr_neigh_for_each_safe, nr_node_for_each, nr_node_for_each_safe, for_each_gfn_indirect_valid_sp, for_each_gfn_sp, for_each_host;
type T;
expression a,c,d,e;
identifier b;
statement S;
@@
-T b;
<+... when != b
(
hlist_for_each_entry(a,
- b,
c, d) S
|
hlist_for_each_entry_continue(a,
- b,
c) S
|
hlist_for_each_entry_from(a,
- b,
c) S
|
hlist_for_each_entry_rcu(a,
- b,
c, d) S
|
hlist_for_each_entry_rcu_bh(a,
- b,
c, d) S
|
hlist_for_each_entry_continue_rcu_bh(a,
- b,
c) S
|
for_each_busy_worker(a, c,
- b,
d) S
|
ax25_uid_for_each(a,
- b,
c) S
|
ax25_for_each(a,
- b,
c) S
|
inet_bind_bucket_for_each(a,
- b,
c) S
|
sctp_for_each_hentry(a,
- b,
c) S
|
sk_for_each(a,
- b,
c) S
|
sk_for_each_rcu(a,
- b,
c) S
|
sk_for_each_from
-(a, b)
+(a)
S
+ sk_for_each_from(a) S
|
sk_for_each_safe(a,
- b,
c, d) S
|
sk_for_each_bound(a,
- b,
c) S
|
hlist_for_each_entry_safe(a,
- b,
c, d, e) S
|
hlist_for_each_entry_continue_rcu(a,
- b,
c) S
|
nr_neigh_for_each(a,
- b,
c) S
|
nr_neigh_for_each_safe(a,
- b,
c, d) S
|
nr_node_for_each(a,
- b,
c) S
|
nr_node_for_each_safe(a,
- b,
c, d) S
|
- for_each_gfn_sp(a, c, d, b) S
+ for_each_gfn_sp(a, c, d) S
|
- for_each_gfn_indirect_valid_sp(a, c, d, b) S
+ for_each_gfn_indirect_valid_sp(a, c, d) S
|
for_each_host(a,
- b,
c) S
|
for_each_host_safe(a,
- b,
c, d) S
|
for_each_mesh_entry(a,
- b,
c, d) S
)
...+>
[akpm@linux-foundation.org: drop bogus change from net/ipv4/raw.c]
[akpm@linux-foundation.org: drop bogus hunk from net/ipv6/raw.c]
[akpm@linux-foundation.org: checkpatch fixes]
[akpm@linux-foundation.org: fix warnings]
[akpm@linux-foudnation.org: redo intrusive kvm changes]
Tested-by: Peter Senna Tschudin <peter.senna@gmail.com>
Acked-by: Paul E. McKenney <paulmck@linux.vnet.ibm.com>
Signed-off-by: Sasha Levin <sasha.levin@oracle.com>
Cc: Wu Fengguang <fengguang.wu@intel.com>
Cc: Marcelo Tosatti <mtosatti@redhat.com>
Cc: Gleb Natapov <gleb@redhat.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
2013-02-28 08:06:00 +07:00
|
|
|
hlist_for_each_entry(inst, list, list) {
|
2006-09-21 08:39:29 +07:00
|
|
|
int err = crypto_remove_alg(&inst->alg, &users);
|
2014-12-05 13:00:10 +07:00
|
|
|
|
2006-09-21 08:39:29 +07:00
|
|
|
BUG_ON(err);
|
2006-08-06 18:16:34 +07:00
|
|
|
}
|
|
|
|
|
|
|
|
up_write(&crypto_alg_sem);
|
|
|
|
|
hlist: drop the node parameter from iterators
I'm not sure why, but the hlist for each entry iterators were conceived
list_for_each_entry(pos, head, member)
The hlist ones were greedy and wanted an extra parameter:
hlist_for_each_entry(tpos, pos, head, member)
Why did they need an extra pos parameter? I'm not quite sure. Not only
they don't really need it, it also prevents the iterator from looking
exactly like the list iterator, which is unfortunate.
Besides the semantic patch, there was some manual work required:
- Fix up the actual hlist iterators in linux/list.h
- Fix up the declaration of other iterators based on the hlist ones.
- A very small amount of places were using the 'node' parameter, this
was modified to use 'obj->member' instead.
- Coccinelle didn't handle the hlist_for_each_entry_safe iterator
properly, so those had to be fixed up manually.
The semantic patch which is mostly the work of Peter Senna Tschudin is here:
@@
iterator name hlist_for_each_entry, hlist_for_each_entry_continue, hlist_for_each_entry_from, hlist_for_each_entry_rcu, hlist_for_each_entry_rcu_bh, hlist_for_each_entry_continue_rcu_bh, for_each_busy_worker, ax25_uid_for_each, ax25_for_each, inet_bind_bucket_for_each, sctp_for_each_hentry, sk_for_each, sk_for_each_rcu, sk_for_each_from, sk_for_each_safe, sk_for_each_bound, hlist_for_each_entry_safe, hlist_for_each_entry_continue_rcu, nr_neigh_for_each, nr_neigh_for_each_safe, nr_node_for_each, nr_node_for_each_safe, for_each_gfn_indirect_valid_sp, for_each_gfn_sp, for_each_host;
type T;
expression a,c,d,e;
identifier b;
statement S;
@@
-T b;
<+... when != b
(
hlist_for_each_entry(a,
- b,
c, d) S
|
hlist_for_each_entry_continue(a,
- b,
c) S
|
hlist_for_each_entry_from(a,
- b,
c) S
|
hlist_for_each_entry_rcu(a,
- b,
c, d) S
|
hlist_for_each_entry_rcu_bh(a,
- b,
c, d) S
|
hlist_for_each_entry_continue_rcu_bh(a,
- b,
c) S
|
for_each_busy_worker(a, c,
- b,
d) S
|
ax25_uid_for_each(a,
- b,
c) S
|
ax25_for_each(a,
- b,
c) S
|
inet_bind_bucket_for_each(a,
- b,
c) S
|
sctp_for_each_hentry(a,
- b,
c) S
|
sk_for_each(a,
- b,
c) S
|
sk_for_each_rcu(a,
- b,
c) S
|
sk_for_each_from
-(a, b)
+(a)
S
+ sk_for_each_from(a) S
|
sk_for_each_safe(a,
- b,
c, d) S
|
sk_for_each_bound(a,
- b,
c) S
|
hlist_for_each_entry_safe(a,
- b,
c, d, e) S
|
hlist_for_each_entry_continue_rcu(a,
- b,
c) S
|
nr_neigh_for_each(a,
- b,
c) S
|
nr_neigh_for_each_safe(a,
- b,
c, d) S
|
nr_node_for_each(a,
- b,
c) S
|
nr_node_for_each_safe(a,
- b,
c, d) S
|
- for_each_gfn_sp(a, c, d, b) S
+ for_each_gfn_sp(a, c, d) S
|
- for_each_gfn_indirect_valid_sp(a, c, d, b) S
+ for_each_gfn_indirect_valid_sp(a, c, d) S
|
for_each_host(a,
- b,
c) S
|
for_each_host_safe(a,
- b,
c, d) S
|
for_each_mesh_entry(a,
- b,
c, d) S
)
...+>
[akpm@linux-foundation.org: drop bogus change from net/ipv4/raw.c]
[akpm@linux-foundation.org: drop bogus hunk from net/ipv6/raw.c]
[akpm@linux-foundation.org: checkpatch fixes]
[akpm@linux-foundation.org: fix warnings]
[akpm@linux-foudnation.org: redo intrusive kvm changes]
Tested-by: Peter Senna Tschudin <peter.senna@gmail.com>
Acked-by: Paul E. McKenney <paulmck@linux.vnet.ibm.com>
Signed-off-by: Sasha Levin <sasha.levin@oracle.com>
Cc: Wu Fengguang <fengguang.wu@intel.com>
Cc: Marcelo Tosatti <mtosatti@redhat.com>
Cc: Gleb Natapov <gleb@redhat.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
2013-02-28 08:06:00 +07:00
|
|
|
hlist_for_each_entry_safe(inst, n, list, list) {
|
2017-12-29 23:00:46 +07:00
|
|
|
BUG_ON(refcount_read(&inst->alg.cra_refcnt) != 1);
|
2015-07-09 06:17:15 +07:00
|
|
|
crypto_free_instance(inst);
|
2006-08-06 18:16:34 +07:00
|
|
|
}
|
2006-09-21 08:39:29 +07:00
|
|
|
crypto_remove_final(&users);
|
2006-08-06 18:16:34 +07:00
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_unregister_template);
|
|
|
|
|
2019-01-18 12:58:11 +07:00
|
|
|
void crypto_unregister_templates(struct crypto_template *tmpls, int count)
|
|
|
|
{
|
|
|
|
int i;
|
|
|
|
|
|
|
|
for (i = count - 1; i >= 0; --i)
|
|
|
|
crypto_unregister_template(&tmpls[i]);
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_unregister_templates);
|
|
|
|
|
2006-08-06 18:16:34 +07:00
|
|
|
static struct crypto_template *__crypto_lookup_template(const char *name)
|
|
|
|
{
|
|
|
|
struct crypto_template *q, *tmpl = NULL;
|
|
|
|
|
|
|
|
down_read(&crypto_alg_sem);
|
|
|
|
list_for_each_entry(q, &crypto_template_list, list) {
|
|
|
|
if (strcmp(q->name, name))
|
|
|
|
continue;
|
|
|
|
if (unlikely(!crypto_tmpl_get(q)))
|
|
|
|
continue;
|
|
|
|
|
|
|
|
tmpl = q;
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
up_read(&crypto_alg_sem);
|
|
|
|
|
|
|
|
return tmpl;
|
|
|
|
}
|
|
|
|
|
|
|
|
struct crypto_template *crypto_lookup_template(const char *name)
|
|
|
|
{
|
2014-11-25 07:32:38 +07:00
|
|
|
return try_then_request_module(__crypto_lookup_template(name),
|
|
|
|
"crypto-%s", name);
|
2006-08-06 18:16:34 +07:00
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_lookup_template);
|
|
|
|
|
|
|
|
int crypto_register_instance(struct crypto_template *tmpl,
|
|
|
|
struct crypto_instance *inst)
|
|
|
|
{
|
2008-08-03 20:15:23 +07:00
|
|
|
struct crypto_larval *larval;
|
|
|
|
int err;
|
2006-08-06 18:16:34 +07:00
|
|
|
|
|
|
|
err = crypto_check_alg(&inst->alg);
|
|
|
|
if (err)
|
2015-04-09 17:09:55 +07:00
|
|
|
return err;
|
|
|
|
|
2006-08-06 18:16:34 +07:00
|
|
|
inst->alg.cra_module = tmpl->module;
|
2011-09-27 12:21:26 +07:00
|
|
|
inst->alg.cra_flags |= CRYPTO_ALG_INSTANCE;
|
2006-08-06 18:16:34 +07:00
|
|
|
|
|
|
|
down_write(&crypto_alg_sem);
|
|
|
|
|
2008-08-03 20:15:23 +07:00
|
|
|
larval = __crypto_register_alg(&inst->alg);
|
|
|
|
if (IS_ERR(larval))
|
2006-08-06 18:16:34 +07:00
|
|
|
goto unlock;
|
|
|
|
|
|
|
|
hlist_add_head(&inst->list, &tmpl->instances);
|
|
|
|
inst->tmpl = tmpl;
|
|
|
|
|
|
|
|
unlock:
|
|
|
|
up_write(&crypto_alg_sem);
|
|
|
|
|
2008-08-03 20:15:23 +07:00
|
|
|
err = PTR_ERR(larval);
|
|
|
|
if (IS_ERR(larval))
|
|
|
|
goto err;
|
|
|
|
|
|
|
|
crypto_wait_for_test(larval);
|
|
|
|
err = 0;
|
2006-09-21 08:39:29 +07:00
|
|
|
|
2006-08-06 18:16:34 +07:00
|
|
|
err:
|
|
|
|
return err;
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_register_instance);
|
2011-11-08 16:09:17 +07:00
|
|
|
|
2015-04-02 21:39:40 +07:00
|
|
|
int crypto_unregister_instance(struct crypto_instance *inst)
|
2011-11-08 16:09:17 +07:00
|
|
|
{
|
2015-04-02 21:31:22 +07:00
|
|
|
LIST_HEAD(list);
|
2011-11-08 16:09:17 +07:00
|
|
|
|
|
|
|
down_write(&crypto_alg_sem);
|
|
|
|
|
2015-04-02 21:39:40 +07:00
|
|
|
crypto_remove_spawns(&inst->alg, &list, NULL);
|
2015-04-02 21:31:22 +07:00
|
|
|
crypto_remove_instance(inst, &list);
|
2011-11-08 16:09:17 +07:00
|
|
|
|
|
|
|
up_write(&crypto_alg_sem);
|
|
|
|
|
2015-04-02 21:31:22 +07:00
|
|
|
crypto_remove_final(&list);
|
2011-11-08 16:09:17 +07:00
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_unregister_instance);
|
2006-08-06 18:16:34 +07:00
|
|
|
|
2006-09-21 08:39:29 +07:00
|
|
|
int crypto_init_spawn(struct crypto_spawn *spawn, struct crypto_alg *alg,
|
2007-04-08 18:31:36 +07:00
|
|
|
struct crypto_instance *inst, u32 mask)
|
2006-09-21 08:39:29 +07:00
|
|
|
{
|
|
|
|
int err = -EAGAIN;
|
|
|
|
|
2019-01-07 03:46:06 +07:00
|
|
|
if (WARN_ON_ONCE(inst == NULL))
|
|
|
|
return -EINVAL;
|
|
|
|
|
2006-09-21 08:39:29 +07:00
|
|
|
spawn->inst = inst;
|
2007-04-08 18:31:36 +07:00
|
|
|
spawn->mask = mask;
|
2006-09-21 08:39:29 +07:00
|
|
|
|
|
|
|
down_write(&crypto_alg_sem);
|
|
|
|
if (!crypto_is_moribund(alg)) {
|
|
|
|
list_add(&spawn->list, &alg->cra_users);
|
|
|
|
spawn->alg = alg;
|
|
|
|
err = 0;
|
|
|
|
}
|
|
|
|
up_write(&crypto_alg_sem);
|
|
|
|
|
|
|
|
return err;
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_init_spawn);
|
|
|
|
|
2009-07-08 14:55:52 +07:00
|
|
|
int crypto_init_spawn2(struct crypto_spawn *spawn, struct crypto_alg *alg,
|
|
|
|
struct crypto_instance *inst,
|
|
|
|
const struct crypto_type *frontend)
|
|
|
|
{
|
|
|
|
int err = -EINVAL;
|
|
|
|
|
2010-05-03 10:08:15 +07:00
|
|
|
if ((alg->cra_flags ^ frontend->type) & frontend->maskset)
|
2009-07-08 14:55:52 +07:00
|
|
|
goto out;
|
|
|
|
|
|
|
|
spawn->frontend = frontend;
|
|
|
|
err = crypto_init_spawn(spawn, alg, inst, frontend->maskset);
|
|
|
|
|
|
|
|
out:
|
|
|
|
return err;
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_init_spawn2);
|
|
|
|
|
2015-05-11 16:47:39 +07:00
|
|
|
int crypto_grab_spawn(struct crypto_spawn *spawn, const char *name,
|
|
|
|
u32 type, u32 mask)
|
|
|
|
{
|
|
|
|
struct crypto_alg *alg;
|
|
|
|
int err;
|
|
|
|
|
|
|
|
alg = crypto_find_alg(name, spawn->frontend, type, mask);
|
|
|
|
if (IS_ERR(alg))
|
|
|
|
return PTR_ERR(alg);
|
|
|
|
|
|
|
|
err = crypto_init_spawn(spawn, alg, spawn->inst, mask);
|
|
|
|
crypto_mod_put(alg);
|
|
|
|
return err;
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_grab_spawn);
|
|
|
|
|
2006-09-21 08:39:29 +07:00
|
|
|
void crypto_drop_spawn(struct crypto_spawn *spawn)
|
|
|
|
{
|
2009-07-09 10:34:06 +07:00
|
|
|
if (!spawn->alg)
|
|
|
|
return;
|
|
|
|
|
2006-09-21 08:39:29 +07:00
|
|
|
down_write(&crypto_alg_sem);
|
|
|
|
list_del(&spawn->list);
|
|
|
|
up_write(&crypto_alg_sem);
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_drop_spawn);
|
|
|
|
|
2009-07-08 14:55:52 +07:00
|
|
|
static struct crypto_alg *crypto_spawn_alg(struct crypto_spawn *spawn)
|
2006-09-21 08:39:29 +07:00
|
|
|
{
|
|
|
|
struct crypto_alg *alg;
|
|
|
|
struct crypto_alg *alg2;
|
|
|
|
|
|
|
|
down_read(&crypto_alg_sem);
|
|
|
|
alg = spawn->alg;
|
|
|
|
alg2 = alg;
|
|
|
|
if (alg2)
|
|
|
|
alg2 = crypto_mod_get(alg2);
|
|
|
|
up_read(&crypto_alg_sem);
|
|
|
|
|
|
|
|
if (!alg2) {
|
|
|
|
if (alg)
|
|
|
|
crypto_shoot_alg(alg);
|
|
|
|
return ERR_PTR(-EAGAIN);
|
|
|
|
}
|
|
|
|
|
2009-07-08 14:55:52 +07:00
|
|
|
return alg;
|
|
|
|
}
|
|
|
|
|
|
|
|
struct crypto_tfm *crypto_spawn_tfm(struct crypto_spawn *spawn, u32 type,
|
|
|
|
u32 mask)
|
|
|
|
{
|
|
|
|
struct crypto_alg *alg;
|
|
|
|
struct crypto_tfm *tfm;
|
|
|
|
|
|
|
|
alg = crypto_spawn_alg(spawn);
|
|
|
|
if (IS_ERR(alg))
|
|
|
|
return ERR_CAST(alg);
|
|
|
|
|
2006-12-17 06:05:58 +07:00
|
|
|
tfm = ERR_PTR(-EINVAL);
|
|
|
|
if (unlikely((alg->cra_flags ^ type) & mask))
|
|
|
|
goto out_put_alg;
|
|
|
|
|
2007-01-24 16:50:26 +07:00
|
|
|
tfm = __crypto_alloc_tfm(alg, type, mask);
|
2006-09-21 08:39:29 +07:00
|
|
|
if (IS_ERR(tfm))
|
2006-12-17 06:05:58 +07:00
|
|
|
goto out_put_alg;
|
|
|
|
|
|
|
|
return tfm;
|
2006-09-21 08:39:29 +07:00
|
|
|
|
2006-12-17 06:05:58 +07:00
|
|
|
out_put_alg:
|
|
|
|
crypto_mod_put(alg);
|
2006-09-21 08:39:29 +07:00
|
|
|
return tfm;
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_spawn_tfm);
|
|
|
|
|
2009-07-08 14:55:52 +07:00
|
|
|
void *crypto_spawn_tfm2(struct crypto_spawn *spawn)
|
|
|
|
{
|
|
|
|
struct crypto_alg *alg;
|
|
|
|
struct crypto_tfm *tfm;
|
|
|
|
|
|
|
|
alg = crypto_spawn_alg(spawn);
|
|
|
|
if (IS_ERR(alg))
|
|
|
|
return ERR_CAST(alg);
|
|
|
|
|
|
|
|
tfm = crypto_create_tfm(alg, spawn->frontend);
|
|
|
|
if (IS_ERR(tfm))
|
|
|
|
goto out_put_alg;
|
|
|
|
|
|
|
|
return tfm;
|
|
|
|
|
|
|
|
out_put_alg:
|
|
|
|
crypto_mod_put(alg);
|
|
|
|
return tfm;
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_spawn_tfm2);
|
|
|
|
|
2006-08-06 18:23:26 +07:00
|
|
|
int crypto_register_notifier(struct notifier_block *nb)
|
|
|
|
{
|
|
|
|
return blocking_notifier_chain_register(&crypto_chain, nb);
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_register_notifier);
|
|
|
|
|
|
|
|
int crypto_unregister_notifier(struct notifier_block *nb)
|
|
|
|
{
|
|
|
|
return blocking_notifier_chain_unregister(&crypto_chain, nb);
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_unregister_notifier);
|
|
|
|
|
2007-01-01 14:37:02 +07:00
|
|
|
struct crypto_attr_type *crypto_get_attr_type(struct rtattr **tb)
|
2006-08-06 20:10:45 +07:00
|
|
|
{
|
2007-08-29 18:27:26 +07:00
|
|
|
struct rtattr *rta = tb[0];
|
2007-01-01 14:37:02 +07:00
|
|
|
struct crypto_attr_type *algt;
|
|
|
|
|
|
|
|
if (!rta)
|
|
|
|
return ERR_PTR(-ENOENT);
|
|
|
|
if (RTA_PAYLOAD(rta) < sizeof(*algt))
|
|
|
|
return ERR_PTR(-EINVAL);
|
2007-08-29 18:27:26 +07:00
|
|
|
if (rta->rta_type != CRYPTOA_TYPE)
|
|
|
|
return ERR_PTR(-EINVAL);
|
2007-01-01 14:37:02 +07:00
|
|
|
|
|
|
|
algt = RTA_DATA(rta);
|
|
|
|
|
|
|
|
return algt;
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_get_attr_type);
|
|
|
|
|
|
|
|
int crypto_check_attr_type(struct rtattr **tb, u32 type)
|
|
|
|
{
|
|
|
|
struct crypto_attr_type *algt;
|
|
|
|
|
|
|
|
algt = crypto_get_attr_type(tb);
|
|
|
|
if (IS_ERR(algt))
|
|
|
|
return PTR_ERR(algt);
|
|
|
|
|
|
|
|
if ((algt->type ^ type) & algt->mask)
|
|
|
|
return -EINVAL;
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_check_attr_type);
|
|
|
|
|
2007-12-07 19:18:17 +07:00
|
|
|
const char *crypto_attr_alg_name(struct rtattr *rta)
|
2007-01-01 14:37:02 +07:00
|
|
|
{
|
2006-08-06 20:10:45 +07:00
|
|
|
struct crypto_attr_alg *alga;
|
|
|
|
|
2007-01-01 14:37:02 +07:00
|
|
|
if (!rta)
|
|
|
|
return ERR_PTR(-ENOENT);
|
|
|
|
if (RTA_PAYLOAD(rta) < sizeof(*alga))
|
2006-08-06 20:10:45 +07:00
|
|
|
return ERR_PTR(-EINVAL);
|
2007-08-29 18:27:26 +07:00
|
|
|
if (rta->rta_type != CRYPTOA_ALG)
|
|
|
|
return ERR_PTR(-EINVAL);
|
2006-08-06 20:10:45 +07:00
|
|
|
|
|
|
|
alga = RTA_DATA(rta);
|
|
|
|
alga->name[CRYPTO_MAX_ALG_NAME - 1] = 0;
|
|
|
|
|
2007-12-07 19:18:17 +07:00
|
|
|
return alga->name;
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_attr_alg_name);
|
|
|
|
|
2009-07-08 16:53:16 +07:00
|
|
|
struct crypto_alg *crypto_attr_alg2(struct rtattr *rta,
|
|
|
|
const struct crypto_type *frontend,
|
|
|
|
u32 type, u32 mask)
|
2007-12-07 19:18:17 +07:00
|
|
|
{
|
|
|
|
const char *name;
|
|
|
|
|
|
|
|
name = crypto_attr_alg_name(rta);
|
|
|
|
if (IS_ERR(name))
|
2013-01-22 18:29:26 +07:00
|
|
|
return ERR_CAST(name);
|
2007-12-07 19:18:17 +07:00
|
|
|
|
2009-07-08 16:53:16 +07:00
|
|
|
return crypto_find_alg(name, frontend, type, mask);
|
2006-08-06 20:10:45 +07:00
|
|
|
}
|
2009-07-08 16:53:16 +07:00
|
|
|
EXPORT_SYMBOL_GPL(crypto_attr_alg2);
|
[CRYPTO] aead: Add authenc
This patch adds the authenc algorithm which constructs an AEAD algorithm
from an asynchronous block cipher and a hash. The construction is done
by concatenating the encrypted result from the cipher with the output
from the hash, as is used by the IPsec ESP protocol.
The authenc algorithm exists as a template with four parameters:
authenc(auth, authsize, enc, enckeylen).
The authentication algorithm, the authentication size (i.e., truncating
the output of the authentication algorithm), the encryption algorithm,
and the encryption key length. Both the size field and the key length
field are in bytes. For example, AES-128 with SHA1-HMAC would be
represented by
authenc(hmac(sha1), 12, cbc(aes), 16)
The key for the authenc algorithm is the concatenation of the keys for
the authentication algorithm with the encryption algorithm. For the
above example, if a key of length 36 bytes is given, then hmac(sha1)
would receive the first 20 bytes while the last 16 would be given to
cbc(aes).
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2007-08-30 15:24:15 +07:00
|
|
|
|
|
|
|
int crypto_attr_u32(struct rtattr *rta, u32 *num)
|
|
|
|
{
|
|
|
|
struct crypto_attr_u32 *nu32;
|
|
|
|
|
|
|
|
if (!rta)
|
|
|
|
return -ENOENT;
|
|
|
|
if (RTA_PAYLOAD(rta) < sizeof(*nu32))
|
|
|
|
return -EINVAL;
|
|
|
|
if (rta->rta_type != CRYPTOA_U32)
|
|
|
|
return -EINVAL;
|
|
|
|
|
|
|
|
nu32 = RTA_DATA(rta);
|
|
|
|
*num = nu32->num;
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_attr_u32);
|
2006-08-06 20:10:45 +07:00
|
|
|
|
2016-06-29 17:04:13 +07:00
|
|
|
int crypto_inst_setname(struct crypto_instance *inst, const char *name,
|
|
|
|
struct crypto_alg *alg)
|
|
|
|
{
|
|
|
|
if (snprintf(inst->alg.cra_name, CRYPTO_MAX_ALG_NAME, "%s(%s)", name,
|
|
|
|
alg->cra_name) >= CRYPTO_MAX_ALG_NAME)
|
|
|
|
return -ENAMETOOLONG;
|
|
|
|
|
|
|
|
if (snprintf(inst->alg.cra_driver_name, CRYPTO_MAX_ALG_NAME, "%s(%s)",
|
|
|
|
name, alg->cra_driver_name) >= CRYPTO_MAX_ALG_NAME)
|
|
|
|
return -ENAMETOOLONG;
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_inst_setname);
|
|
|
|
|
2019-01-04 11:16:25 +07:00
|
|
|
void *crypto_alloc_instance(const char *name, struct crypto_alg *alg,
|
|
|
|
unsigned int head)
|
2006-08-06 20:10:45 +07:00
|
|
|
{
|
|
|
|
struct crypto_instance *inst;
|
2009-07-07 13:07:37 +07:00
|
|
|
char *p;
|
2006-08-06 20:10:45 +07:00
|
|
|
int err;
|
|
|
|
|
2009-07-07 13:07:37 +07:00
|
|
|
p = kzalloc(head + sizeof(*inst) + sizeof(struct crypto_spawn),
|
|
|
|
GFP_KERNEL);
|
|
|
|
if (!p)
|
2006-08-06 20:10:45 +07:00
|
|
|
return ERR_PTR(-ENOMEM);
|
|
|
|
|
2009-07-07 13:07:37 +07:00
|
|
|
inst = (void *)(p + head);
|
|
|
|
|
2016-06-29 17:04:13 +07:00
|
|
|
err = crypto_inst_setname(inst, name, alg);
|
|
|
|
if (err)
|
2006-08-06 20:10:45 +07:00
|
|
|
goto err_free_inst;
|
|
|
|
|
2009-07-07 13:07:37 +07:00
|
|
|
return p;
|
|
|
|
|
|
|
|
err_free_inst:
|
|
|
|
kfree(p);
|
|
|
|
return ERR_PTR(err);
|
|
|
|
}
|
2006-08-06 20:10:45 +07:00
|
|
|
EXPORT_SYMBOL_GPL(crypto_alloc_instance);
|
|
|
|
|
2007-04-16 17:48:54 +07:00
|
|
|
void crypto_init_queue(struct crypto_queue *queue, unsigned int max_qlen)
|
|
|
|
{
|
|
|
|
INIT_LIST_HEAD(&queue->list);
|
|
|
|
queue->backlog = &queue->list;
|
|
|
|
queue->qlen = 0;
|
|
|
|
queue->max_qlen = max_qlen;
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_init_queue);
|
|
|
|
|
|
|
|
int crypto_enqueue_request(struct crypto_queue *queue,
|
|
|
|
struct crypto_async_request *request)
|
|
|
|
{
|
|
|
|
int err = -EINPROGRESS;
|
|
|
|
|
|
|
|
if (unlikely(queue->qlen >= queue->max_qlen)) {
|
2017-10-18 14:00:33 +07:00
|
|
|
if (!(request->flags & CRYPTO_TFM_REQ_MAY_BACKLOG)) {
|
|
|
|
err = -ENOSPC;
|
2007-04-16 17:48:54 +07:00
|
|
|
goto out;
|
2017-10-18 14:00:33 +07:00
|
|
|
}
|
|
|
|
err = -EBUSY;
|
2007-04-16 17:48:54 +07:00
|
|
|
if (queue->backlog == &queue->list)
|
|
|
|
queue->backlog = &request->list;
|
|
|
|
}
|
|
|
|
|
|
|
|
queue->qlen++;
|
|
|
|
list_add_tail(&request->list, &queue->list);
|
|
|
|
|
|
|
|
out:
|
|
|
|
return err;
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_enqueue_request);
|
|
|
|
|
2015-07-08 10:55:30 +07:00
|
|
|
struct crypto_async_request *crypto_dequeue_request(struct crypto_queue *queue)
|
2007-04-16 17:48:54 +07:00
|
|
|
{
|
|
|
|
struct list_head *request;
|
|
|
|
|
|
|
|
if (unlikely(!queue->qlen))
|
|
|
|
return NULL;
|
|
|
|
|
|
|
|
queue->qlen--;
|
|
|
|
|
|
|
|
if (queue->backlog != &queue->list)
|
|
|
|
queue->backlog = queue->backlog->next;
|
|
|
|
|
|
|
|
request = queue->list.next;
|
|
|
|
list_del(request);
|
|
|
|
|
2015-07-08 10:55:30 +07:00
|
|
|
return list_entry(request, struct crypto_async_request, list);
|
2007-04-16 17:48:54 +07:00
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_dequeue_request);
|
|
|
|
|
2007-11-20 16:26:06 +07:00
|
|
|
static inline void crypto_inc_byte(u8 *a, unsigned int size)
|
|
|
|
{
|
|
|
|
u8 *b = (a + size);
|
|
|
|
u8 c;
|
|
|
|
|
|
|
|
for (; size; size--) {
|
|
|
|
c = *--b + 1;
|
|
|
|
*b = c;
|
|
|
|
if (c)
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
void crypto_inc(u8 *a, unsigned int size)
|
|
|
|
{
|
|
|
|
__be32 *b = (__be32 *)(a + size);
|
|
|
|
u32 c;
|
|
|
|
|
crypto: algapi - make crypto_xor() and crypto_inc() alignment agnostic
Instead of unconditionally forcing 4 byte alignment for all generic
chaining modes that rely on crypto_xor() or crypto_inc() (which may
result in unnecessary copying of data when the underlying hardware
can perform unaligned accesses efficiently), make those functions
deal with unaligned input explicitly, but only if the Kconfig symbol
HAVE_EFFICIENT_UNALIGNED_ACCESS is set. This will allow us to drop
the alignmasks from the CBC, CMAC, CTR, CTS, PCBC and SEQIV drivers.
For crypto_inc(), this simply involves making the 4-byte stride
conditional on HAVE_EFFICIENT_UNALIGNED_ACCESS being set, given that
it typically operates on 16 byte buffers.
For crypto_xor(), an algorithm is implemented that simply runs through
the input using the largest strides possible if unaligned accesses are
allowed. If they are not, an optimal sequence of memory accesses is
emitted that takes the relative alignment of the input buffers into
account, e.g., if the relative misalignment of dst and src is 4 bytes,
the entire xor operation will be completed using 4 byte loads and stores
(modulo unaligned bits at the start and end). Note that all expressions
involving misalign are simply eliminated by the compiler when
HAVE_EFFICIENT_UNALIGNED_ACCESS is defined.
Signed-off-by: Ard Biesheuvel <ard.biesheuvel@linaro.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2017-02-05 17:06:12 +07:00
|
|
|
if (IS_ENABLED(CONFIG_HAVE_EFFICIENT_UNALIGNED_ACCESS) ||
|
crypto: algapi - annotate expected branch behavior in crypto_inc()
To prevent unnecessary branching, mark the exit condition of the
primary loop as likely(), given that a carry in a 32-bit counter
occurs very rarely.
On arm64, the resulting code is emitted by GCC as
9a8: cmp w1, #0x3
9ac: add x3, x0, w1, uxtw
9b0: b.ls 9e0 <crypto_inc+0x38>
9b4: ldr w2, [x3,#-4]!
9b8: rev w2, w2
9bc: add w2, w2, #0x1
9c0: rev w4, w2
9c4: str w4, [x3]
9c8: cbz w2, 9d0 <crypto_inc+0x28>
9cc: ret
where the two remaining branch conditions (one for size < 4 and one for
the carry) are statically predicted as non-taken, resulting in optimal
execution in the vast majority of cases.
Also, replace the open coded alignment test with IS_ALIGNED().
Cc: Jason A. Donenfeld <Jason@zx2c4.com>
Signed-off-by: Ard Biesheuvel <ard.biesheuvel@linaro.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2017-02-15 04:51:02 +07:00
|
|
|
IS_ALIGNED((unsigned long)b, __alignof__(*b)))
|
crypto: algapi - make crypto_xor() and crypto_inc() alignment agnostic
Instead of unconditionally forcing 4 byte alignment for all generic
chaining modes that rely on crypto_xor() or crypto_inc() (which may
result in unnecessary copying of data when the underlying hardware
can perform unaligned accesses efficiently), make those functions
deal with unaligned input explicitly, but only if the Kconfig symbol
HAVE_EFFICIENT_UNALIGNED_ACCESS is set. This will allow us to drop
the alignmasks from the CBC, CMAC, CTR, CTS, PCBC and SEQIV drivers.
For crypto_inc(), this simply involves making the 4-byte stride
conditional on HAVE_EFFICIENT_UNALIGNED_ACCESS being set, given that
it typically operates on 16 byte buffers.
For crypto_xor(), an algorithm is implemented that simply runs through
the input using the largest strides possible if unaligned accesses are
allowed. If they are not, an optimal sequence of memory accesses is
emitted that takes the relative alignment of the input buffers into
account, e.g., if the relative misalignment of dst and src is 4 bytes,
the entire xor operation will be completed using 4 byte loads and stores
(modulo unaligned bits at the start and end). Note that all expressions
involving misalign are simply eliminated by the compiler when
HAVE_EFFICIENT_UNALIGNED_ACCESS is defined.
Signed-off-by: Ard Biesheuvel <ard.biesheuvel@linaro.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2017-02-05 17:06:12 +07:00
|
|
|
for (; size >= 4; size -= 4) {
|
|
|
|
c = be32_to_cpu(*--b) + 1;
|
|
|
|
*b = cpu_to_be32(c);
|
crypto: algapi - annotate expected branch behavior in crypto_inc()
To prevent unnecessary branching, mark the exit condition of the
primary loop as likely(), given that a carry in a 32-bit counter
occurs very rarely.
On arm64, the resulting code is emitted by GCC as
9a8: cmp w1, #0x3
9ac: add x3, x0, w1, uxtw
9b0: b.ls 9e0 <crypto_inc+0x38>
9b4: ldr w2, [x3,#-4]!
9b8: rev w2, w2
9bc: add w2, w2, #0x1
9c0: rev w4, w2
9c4: str w4, [x3]
9c8: cbz w2, 9d0 <crypto_inc+0x28>
9cc: ret
where the two remaining branch conditions (one for size < 4 and one for
the carry) are statically predicted as non-taken, resulting in optimal
execution in the vast majority of cases.
Also, replace the open coded alignment test with IS_ALIGNED().
Cc: Jason A. Donenfeld <Jason@zx2c4.com>
Signed-off-by: Ard Biesheuvel <ard.biesheuvel@linaro.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2017-02-15 04:51:02 +07:00
|
|
|
if (likely(c))
|
crypto: algapi - make crypto_xor() and crypto_inc() alignment agnostic
Instead of unconditionally forcing 4 byte alignment for all generic
chaining modes that rely on crypto_xor() or crypto_inc() (which may
result in unnecessary copying of data when the underlying hardware
can perform unaligned accesses efficiently), make those functions
deal with unaligned input explicitly, but only if the Kconfig symbol
HAVE_EFFICIENT_UNALIGNED_ACCESS is set. This will allow us to drop
the alignmasks from the CBC, CMAC, CTR, CTS, PCBC and SEQIV drivers.
For crypto_inc(), this simply involves making the 4-byte stride
conditional on HAVE_EFFICIENT_UNALIGNED_ACCESS being set, given that
it typically operates on 16 byte buffers.
For crypto_xor(), an algorithm is implemented that simply runs through
the input using the largest strides possible if unaligned accesses are
allowed. If they are not, an optimal sequence of memory accesses is
emitted that takes the relative alignment of the input buffers into
account, e.g., if the relative misalignment of dst and src is 4 bytes,
the entire xor operation will be completed using 4 byte loads and stores
(modulo unaligned bits at the start and end). Note that all expressions
involving misalign are simply eliminated by the compiler when
HAVE_EFFICIENT_UNALIGNED_ACCESS is defined.
Signed-off-by: Ard Biesheuvel <ard.biesheuvel@linaro.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2017-02-05 17:06:12 +07:00
|
|
|
return;
|
|
|
|
}
|
2007-11-20 16:26:06 +07:00
|
|
|
|
|
|
|
crypto_inc_byte(a, size);
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_inc);
|
|
|
|
|
2017-07-24 17:28:03 +07:00
|
|
|
void __crypto_xor(u8 *dst, const u8 *src1, const u8 *src2, unsigned int len)
|
2007-11-20 16:26:06 +07:00
|
|
|
{
|
crypto: algapi - make crypto_xor() and crypto_inc() alignment agnostic
Instead of unconditionally forcing 4 byte alignment for all generic
chaining modes that rely on crypto_xor() or crypto_inc() (which may
result in unnecessary copying of data when the underlying hardware
can perform unaligned accesses efficiently), make those functions
deal with unaligned input explicitly, but only if the Kconfig symbol
HAVE_EFFICIENT_UNALIGNED_ACCESS is set. This will allow us to drop
the alignmasks from the CBC, CMAC, CTR, CTS, PCBC and SEQIV drivers.
For crypto_inc(), this simply involves making the 4-byte stride
conditional on HAVE_EFFICIENT_UNALIGNED_ACCESS being set, given that
it typically operates on 16 byte buffers.
For crypto_xor(), an algorithm is implemented that simply runs through
the input using the largest strides possible if unaligned accesses are
allowed. If they are not, an optimal sequence of memory accesses is
emitted that takes the relative alignment of the input buffers into
account, e.g., if the relative misalignment of dst and src is 4 bytes,
the entire xor operation will be completed using 4 byte loads and stores
(modulo unaligned bits at the start and end). Note that all expressions
involving misalign are simply eliminated by the compiler when
HAVE_EFFICIENT_UNALIGNED_ACCESS is defined.
Signed-off-by: Ard Biesheuvel <ard.biesheuvel@linaro.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2017-02-05 17:06:12 +07:00
|
|
|
int relalign = 0;
|
|
|
|
|
|
|
|
if (!IS_ENABLED(CONFIG_HAVE_EFFICIENT_UNALIGNED_ACCESS)) {
|
|
|
|
int size = sizeof(unsigned long);
|
2017-07-24 17:28:03 +07:00
|
|
|
int d = (((unsigned long)dst ^ (unsigned long)src1) |
|
|
|
|
((unsigned long)dst ^ (unsigned long)src2)) &
|
|
|
|
(size - 1);
|
crypto: algapi - make crypto_xor() and crypto_inc() alignment agnostic
Instead of unconditionally forcing 4 byte alignment for all generic
chaining modes that rely on crypto_xor() or crypto_inc() (which may
result in unnecessary copying of data when the underlying hardware
can perform unaligned accesses efficiently), make those functions
deal with unaligned input explicitly, but only if the Kconfig symbol
HAVE_EFFICIENT_UNALIGNED_ACCESS is set. This will allow us to drop
the alignmasks from the CBC, CMAC, CTR, CTS, PCBC and SEQIV drivers.
For crypto_inc(), this simply involves making the 4-byte stride
conditional on HAVE_EFFICIENT_UNALIGNED_ACCESS being set, given that
it typically operates on 16 byte buffers.
For crypto_xor(), an algorithm is implemented that simply runs through
the input using the largest strides possible if unaligned accesses are
allowed. If they are not, an optimal sequence of memory accesses is
emitted that takes the relative alignment of the input buffers into
account, e.g., if the relative misalignment of dst and src is 4 bytes,
the entire xor operation will be completed using 4 byte loads and stores
(modulo unaligned bits at the start and end). Note that all expressions
involving misalign are simply eliminated by the compiler when
HAVE_EFFICIENT_UNALIGNED_ACCESS is defined.
Signed-off-by: Ard Biesheuvel <ard.biesheuvel@linaro.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2017-02-05 17:06:12 +07:00
|
|
|
|
|
|
|
relalign = d ? 1 << __ffs(d) : size;
|
|
|
|
|
|
|
|
/*
|
|
|
|
* If we care about alignment, process as many bytes as
|
|
|
|
* needed to advance dst and src to values whose alignments
|
|
|
|
* equal their relative alignment. This will allow us to
|
|
|
|
* process the remainder of the input using optimal strides.
|
|
|
|
*/
|
|
|
|
while (((unsigned long)dst & (relalign - 1)) && len > 0) {
|
2017-07-24 17:28:03 +07:00
|
|
|
*dst++ = *src1++ ^ *src2++;
|
crypto: algapi - make crypto_xor() and crypto_inc() alignment agnostic
Instead of unconditionally forcing 4 byte alignment for all generic
chaining modes that rely on crypto_xor() or crypto_inc() (which may
result in unnecessary copying of data when the underlying hardware
can perform unaligned accesses efficiently), make those functions
deal with unaligned input explicitly, but only if the Kconfig symbol
HAVE_EFFICIENT_UNALIGNED_ACCESS is set. This will allow us to drop
the alignmasks from the CBC, CMAC, CTR, CTS, PCBC and SEQIV drivers.
For crypto_inc(), this simply involves making the 4-byte stride
conditional on HAVE_EFFICIENT_UNALIGNED_ACCESS being set, given that
it typically operates on 16 byte buffers.
For crypto_xor(), an algorithm is implemented that simply runs through
the input using the largest strides possible if unaligned accesses are
allowed. If they are not, an optimal sequence of memory accesses is
emitted that takes the relative alignment of the input buffers into
account, e.g., if the relative misalignment of dst and src is 4 bytes,
the entire xor operation will be completed using 4 byte loads and stores
(modulo unaligned bits at the start and end). Note that all expressions
involving misalign are simply eliminated by the compiler when
HAVE_EFFICIENT_UNALIGNED_ACCESS is defined.
Signed-off-by: Ard Biesheuvel <ard.biesheuvel@linaro.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2017-02-05 17:06:12 +07:00
|
|
|
len--;
|
|
|
|
}
|
|
|
|
}
|
2007-11-20 16:26:06 +07:00
|
|
|
|
crypto: algapi - make crypto_xor() and crypto_inc() alignment agnostic
Instead of unconditionally forcing 4 byte alignment for all generic
chaining modes that rely on crypto_xor() or crypto_inc() (which may
result in unnecessary copying of data when the underlying hardware
can perform unaligned accesses efficiently), make those functions
deal with unaligned input explicitly, but only if the Kconfig symbol
HAVE_EFFICIENT_UNALIGNED_ACCESS is set. This will allow us to drop
the alignmasks from the CBC, CMAC, CTR, CTS, PCBC and SEQIV drivers.
For crypto_inc(), this simply involves making the 4-byte stride
conditional on HAVE_EFFICIENT_UNALIGNED_ACCESS being set, given that
it typically operates on 16 byte buffers.
For crypto_xor(), an algorithm is implemented that simply runs through
the input using the largest strides possible if unaligned accesses are
allowed. If they are not, an optimal sequence of memory accesses is
emitted that takes the relative alignment of the input buffers into
account, e.g., if the relative misalignment of dst and src is 4 bytes,
the entire xor operation will be completed using 4 byte loads and stores
(modulo unaligned bits at the start and end). Note that all expressions
involving misalign are simply eliminated by the compiler when
HAVE_EFFICIENT_UNALIGNED_ACCESS is defined.
Signed-off-by: Ard Biesheuvel <ard.biesheuvel@linaro.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2017-02-05 17:06:12 +07:00
|
|
|
while (IS_ENABLED(CONFIG_64BIT) && len >= 8 && !(relalign & 7)) {
|
2017-07-24 17:28:03 +07:00
|
|
|
*(u64 *)dst = *(u64 *)src1 ^ *(u64 *)src2;
|
crypto: algapi - make crypto_xor() and crypto_inc() alignment agnostic
Instead of unconditionally forcing 4 byte alignment for all generic
chaining modes that rely on crypto_xor() or crypto_inc() (which may
result in unnecessary copying of data when the underlying hardware
can perform unaligned accesses efficiently), make those functions
deal with unaligned input explicitly, but only if the Kconfig symbol
HAVE_EFFICIENT_UNALIGNED_ACCESS is set. This will allow us to drop
the alignmasks from the CBC, CMAC, CTR, CTS, PCBC and SEQIV drivers.
For crypto_inc(), this simply involves making the 4-byte stride
conditional on HAVE_EFFICIENT_UNALIGNED_ACCESS being set, given that
it typically operates on 16 byte buffers.
For crypto_xor(), an algorithm is implemented that simply runs through
the input using the largest strides possible if unaligned accesses are
allowed. If they are not, an optimal sequence of memory accesses is
emitted that takes the relative alignment of the input buffers into
account, e.g., if the relative misalignment of dst and src is 4 bytes,
the entire xor operation will be completed using 4 byte loads and stores
(modulo unaligned bits at the start and end). Note that all expressions
involving misalign are simply eliminated by the compiler when
HAVE_EFFICIENT_UNALIGNED_ACCESS is defined.
Signed-off-by: Ard Biesheuvel <ard.biesheuvel@linaro.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2017-02-05 17:06:12 +07:00
|
|
|
dst += 8;
|
2017-07-24 17:28:03 +07:00
|
|
|
src1 += 8;
|
|
|
|
src2 += 8;
|
crypto: algapi - make crypto_xor() and crypto_inc() alignment agnostic
Instead of unconditionally forcing 4 byte alignment for all generic
chaining modes that rely on crypto_xor() or crypto_inc() (which may
result in unnecessary copying of data when the underlying hardware
can perform unaligned accesses efficiently), make those functions
deal with unaligned input explicitly, but only if the Kconfig symbol
HAVE_EFFICIENT_UNALIGNED_ACCESS is set. This will allow us to drop
the alignmasks from the CBC, CMAC, CTR, CTS, PCBC and SEQIV drivers.
For crypto_inc(), this simply involves making the 4-byte stride
conditional on HAVE_EFFICIENT_UNALIGNED_ACCESS being set, given that
it typically operates on 16 byte buffers.
For crypto_xor(), an algorithm is implemented that simply runs through
the input using the largest strides possible if unaligned accesses are
allowed. If they are not, an optimal sequence of memory accesses is
emitted that takes the relative alignment of the input buffers into
account, e.g., if the relative misalignment of dst and src is 4 bytes,
the entire xor operation will be completed using 4 byte loads and stores
(modulo unaligned bits at the start and end). Note that all expressions
involving misalign are simply eliminated by the compiler when
HAVE_EFFICIENT_UNALIGNED_ACCESS is defined.
Signed-off-by: Ard Biesheuvel <ard.biesheuvel@linaro.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2017-02-05 17:06:12 +07:00
|
|
|
len -= 8;
|
|
|
|
}
|
2007-11-20 16:26:06 +07:00
|
|
|
|
crypto: algapi - make crypto_xor() and crypto_inc() alignment agnostic
Instead of unconditionally forcing 4 byte alignment for all generic
chaining modes that rely on crypto_xor() or crypto_inc() (which may
result in unnecessary copying of data when the underlying hardware
can perform unaligned accesses efficiently), make those functions
deal with unaligned input explicitly, but only if the Kconfig symbol
HAVE_EFFICIENT_UNALIGNED_ACCESS is set. This will allow us to drop
the alignmasks from the CBC, CMAC, CTR, CTS, PCBC and SEQIV drivers.
For crypto_inc(), this simply involves making the 4-byte stride
conditional on HAVE_EFFICIENT_UNALIGNED_ACCESS being set, given that
it typically operates on 16 byte buffers.
For crypto_xor(), an algorithm is implemented that simply runs through
the input using the largest strides possible if unaligned accesses are
allowed. If they are not, an optimal sequence of memory accesses is
emitted that takes the relative alignment of the input buffers into
account, e.g., if the relative misalignment of dst and src is 4 bytes,
the entire xor operation will be completed using 4 byte loads and stores
(modulo unaligned bits at the start and end). Note that all expressions
involving misalign are simply eliminated by the compiler when
HAVE_EFFICIENT_UNALIGNED_ACCESS is defined.
Signed-off-by: Ard Biesheuvel <ard.biesheuvel@linaro.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2017-02-05 17:06:12 +07:00
|
|
|
while (len >= 4 && !(relalign & 3)) {
|
2017-07-24 17:28:03 +07:00
|
|
|
*(u32 *)dst = *(u32 *)src1 ^ *(u32 *)src2;
|
crypto: algapi - make crypto_xor() and crypto_inc() alignment agnostic
Instead of unconditionally forcing 4 byte alignment for all generic
chaining modes that rely on crypto_xor() or crypto_inc() (which may
result in unnecessary copying of data when the underlying hardware
can perform unaligned accesses efficiently), make those functions
deal with unaligned input explicitly, but only if the Kconfig symbol
HAVE_EFFICIENT_UNALIGNED_ACCESS is set. This will allow us to drop
the alignmasks from the CBC, CMAC, CTR, CTS, PCBC and SEQIV drivers.
For crypto_inc(), this simply involves making the 4-byte stride
conditional on HAVE_EFFICIENT_UNALIGNED_ACCESS being set, given that
it typically operates on 16 byte buffers.
For crypto_xor(), an algorithm is implemented that simply runs through
the input using the largest strides possible if unaligned accesses are
allowed. If they are not, an optimal sequence of memory accesses is
emitted that takes the relative alignment of the input buffers into
account, e.g., if the relative misalignment of dst and src is 4 bytes,
the entire xor operation will be completed using 4 byte loads and stores
(modulo unaligned bits at the start and end). Note that all expressions
involving misalign are simply eliminated by the compiler when
HAVE_EFFICIENT_UNALIGNED_ACCESS is defined.
Signed-off-by: Ard Biesheuvel <ard.biesheuvel@linaro.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2017-02-05 17:06:12 +07:00
|
|
|
dst += 4;
|
2017-07-24 17:28:03 +07:00
|
|
|
src1 += 4;
|
|
|
|
src2 += 4;
|
crypto: algapi - make crypto_xor() and crypto_inc() alignment agnostic
Instead of unconditionally forcing 4 byte alignment for all generic
chaining modes that rely on crypto_xor() or crypto_inc() (which may
result in unnecessary copying of data when the underlying hardware
can perform unaligned accesses efficiently), make those functions
deal with unaligned input explicitly, but only if the Kconfig symbol
HAVE_EFFICIENT_UNALIGNED_ACCESS is set. This will allow us to drop
the alignmasks from the CBC, CMAC, CTR, CTS, PCBC and SEQIV drivers.
For crypto_inc(), this simply involves making the 4-byte stride
conditional on HAVE_EFFICIENT_UNALIGNED_ACCESS being set, given that
it typically operates on 16 byte buffers.
For crypto_xor(), an algorithm is implemented that simply runs through
the input using the largest strides possible if unaligned accesses are
allowed. If they are not, an optimal sequence of memory accesses is
emitted that takes the relative alignment of the input buffers into
account, e.g., if the relative misalignment of dst and src is 4 bytes,
the entire xor operation will be completed using 4 byte loads and stores
(modulo unaligned bits at the start and end). Note that all expressions
involving misalign are simply eliminated by the compiler when
HAVE_EFFICIENT_UNALIGNED_ACCESS is defined.
Signed-off-by: Ard Biesheuvel <ard.biesheuvel@linaro.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2017-02-05 17:06:12 +07:00
|
|
|
len -= 4;
|
|
|
|
}
|
|
|
|
|
|
|
|
while (len >= 2 && !(relalign & 1)) {
|
2017-07-24 17:28:03 +07:00
|
|
|
*(u16 *)dst = *(u16 *)src1 ^ *(u16 *)src2;
|
crypto: algapi - make crypto_xor() and crypto_inc() alignment agnostic
Instead of unconditionally forcing 4 byte alignment for all generic
chaining modes that rely on crypto_xor() or crypto_inc() (which may
result in unnecessary copying of data when the underlying hardware
can perform unaligned accesses efficiently), make those functions
deal with unaligned input explicitly, but only if the Kconfig symbol
HAVE_EFFICIENT_UNALIGNED_ACCESS is set. This will allow us to drop
the alignmasks from the CBC, CMAC, CTR, CTS, PCBC and SEQIV drivers.
For crypto_inc(), this simply involves making the 4-byte stride
conditional on HAVE_EFFICIENT_UNALIGNED_ACCESS being set, given that
it typically operates on 16 byte buffers.
For crypto_xor(), an algorithm is implemented that simply runs through
the input using the largest strides possible if unaligned accesses are
allowed. If they are not, an optimal sequence of memory accesses is
emitted that takes the relative alignment of the input buffers into
account, e.g., if the relative misalignment of dst and src is 4 bytes,
the entire xor operation will be completed using 4 byte loads and stores
(modulo unaligned bits at the start and end). Note that all expressions
involving misalign are simply eliminated by the compiler when
HAVE_EFFICIENT_UNALIGNED_ACCESS is defined.
Signed-off-by: Ard Biesheuvel <ard.biesheuvel@linaro.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2017-02-05 17:06:12 +07:00
|
|
|
dst += 2;
|
2017-07-24 17:28:03 +07:00
|
|
|
src1 += 2;
|
|
|
|
src2 += 2;
|
crypto: algapi - make crypto_xor() and crypto_inc() alignment agnostic
Instead of unconditionally forcing 4 byte alignment for all generic
chaining modes that rely on crypto_xor() or crypto_inc() (which may
result in unnecessary copying of data when the underlying hardware
can perform unaligned accesses efficiently), make those functions
deal with unaligned input explicitly, but only if the Kconfig symbol
HAVE_EFFICIENT_UNALIGNED_ACCESS is set. This will allow us to drop
the alignmasks from the CBC, CMAC, CTR, CTS, PCBC and SEQIV drivers.
For crypto_inc(), this simply involves making the 4-byte stride
conditional on HAVE_EFFICIENT_UNALIGNED_ACCESS being set, given that
it typically operates on 16 byte buffers.
For crypto_xor(), an algorithm is implemented that simply runs through
the input using the largest strides possible if unaligned accesses are
allowed. If they are not, an optimal sequence of memory accesses is
emitted that takes the relative alignment of the input buffers into
account, e.g., if the relative misalignment of dst and src is 4 bytes,
the entire xor operation will be completed using 4 byte loads and stores
(modulo unaligned bits at the start and end). Note that all expressions
involving misalign are simply eliminated by the compiler when
HAVE_EFFICIENT_UNALIGNED_ACCESS is defined.
Signed-off-by: Ard Biesheuvel <ard.biesheuvel@linaro.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2017-02-05 17:06:12 +07:00
|
|
|
len -= 2;
|
|
|
|
}
|
2007-11-20 16:26:06 +07:00
|
|
|
|
crypto: algapi - make crypto_xor() and crypto_inc() alignment agnostic
Instead of unconditionally forcing 4 byte alignment for all generic
chaining modes that rely on crypto_xor() or crypto_inc() (which may
result in unnecessary copying of data when the underlying hardware
can perform unaligned accesses efficiently), make those functions
deal with unaligned input explicitly, but only if the Kconfig symbol
HAVE_EFFICIENT_UNALIGNED_ACCESS is set. This will allow us to drop
the alignmasks from the CBC, CMAC, CTR, CTS, PCBC and SEQIV drivers.
For crypto_inc(), this simply involves making the 4-byte stride
conditional on HAVE_EFFICIENT_UNALIGNED_ACCESS being set, given that
it typically operates on 16 byte buffers.
For crypto_xor(), an algorithm is implemented that simply runs through
the input using the largest strides possible if unaligned accesses are
allowed. If they are not, an optimal sequence of memory accesses is
emitted that takes the relative alignment of the input buffers into
account, e.g., if the relative misalignment of dst and src is 4 bytes,
the entire xor operation will be completed using 4 byte loads and stores
(modulo unaligned bits at the start and end). Note that all expressions
involving misalign are simply eliminated by the compiler when
HAVE_EFFICIENT_UNALIGNED_ACCESS is defined.
Signed-off-by: Ard Biesheuvel <ard.biesheuvel@linaro.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2017-02-05 17:06:12 +07:00
|
|
|
while (len--)
|
2017-07-24 17:28:03 +07:00
|
|
|
*dst++ = *src1++ ^ *src2++;
|
2007-11-20 16:26:06 +07:00
|
|
|
}
|
crypto: algapi - make crypto_xor() and crypto_inc() alignment agnostic
Instead of unconditionally forcing 4 byte alignment for all generic
chaining modes that rely on crypto_xor() or crypto_inc() (which may
result in unnecessary copying of data when the underlying hardware
can perform unaligned accesses efficiently), make those functions
deal with unaligned input explicitly, but only if the Kconfig symbol
HAVE_EFFICIENT_UNALIGNED_ACCESS is set. This will allow us to drop
the alignmasks from the CBC, CMAC, CTR, CTS, PCBC and SEQIV drivers.
For crypto_inc(), this simply involves making the 4-byte stride
conditional on HAVE_EFFICIENT_UNALIGNED_ACCESS being set, given that
it typically operates on 16 byte buffers.
For crypto_xor(), an algorithm is implemented that simply runs through
the input using the largest strides possible if unaligned accesses are
allowed. If they are not, an optimal sequence of memory accesses is
emitted that takes the relative alignment of the input buffers into
account, e.g., if the relative misalignment of dst and src is 4 bytes,
the entire xor operation will be completed using 4 byte loads and stores
(modulo unaligned bits at the start and end). Note that all expressions
involving misalign are simply eliminated by the compiler when
HAVE_EFFICIENT_UNALIGNED_ACCESS is defined.
Signed-off-by: Ard Biesheuvel <ard.biesheuvel@linaro.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2017-02-05 17:06:12 +07:00
|
|
|
EXPORT_SYMBOL_GPL(__crypto_xor);
|
2007-11-20 16:26:06 +07:00
|
|
|
|
2015-04-20 12:39:00 +07:00
|
|
|
unsigned int crypto_alg_extsize(struct crypto_alg *alg)
|
|
|
|
{
|
2015-05-28 21:07:56 +07:00
|
|
|
return alg->cra_ctxsize +
|
|
|
|
(alg->cra_alignmask & ~(crypto_tfm_ctx_alignment() - 1));
|
2015-04-20 12:39:00 +07:00
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_alg_extsize);
|
|
|
|
|
2016-01-23 12:51:01 +07:00
|
|
|
int crypto_type_has_alg(const char *name, const struct crypto_type *frontend,
|
|
|
|
u32 type, u32 mask)
|
|
|
|
{
|
|
|
|
int ret = 0;
|
|
|
|
struct crypto_alg *alg = crypto_find_alg(name, frontend, type, mask);
|
|
|
|
|
|
|
|
if (!IS_ERR(alg)) {
|
|
|
|
crypto_mod_put(alg);
|
|
|
|
ret = 1;
|
|
|
|
}
|
|
|
|
|
|
|
|
return ret;
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_type_has_alg);
|
|
|
|
|
2018-11-29 21:42:21 +07:00
|
|
|
#ifdef CONFIG_CRYPTO_STATS
|
2018-11-29 21:42:26 +07:00
|
|
|
void crypto_stats_init(struct crypto_alg *alg)
|
|
|
|
{
|
|
|
|
memset(&alg->stats, 0, sizeof(alg->stats));
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_stats_init);
|
|
|
|
|
2018-11-29 21:42:21 +07:00
|
|
|
void crypto_stats_get(struct crypto_alg *alg)
|
|
|
|
{
|
|
|
|
crypto_alg_get(alg);
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_stats_get);
|
|
|
|
|
|
|
|
void crypto_stats_aead_encrypt(unsigned int cryptlen, struct crypto_alg *alg,
|
|
|
|
int ret)
|
|
|
|
{
|
|
|
|
if (ret && ret != -EINPROGRESS && ret != -EBUSY) {
|
2018-11-29 21:42:25 +07:00
|
|
|
atomic64_inc(&alg->stats.aead.err_cnt);
|
2018-11-29 21:42:21 +07:00
|
|
|
} else {
|
2018-11-29 21:42:24 +07:00
|
|
|
atomic64_inc(&alg->stats.aead.encrypt_cnt);
|
|
|
|
atomic64_add(cryptlen, &alg->stats.aead.encrypt_tlen);
|
2018-11-29 21:42:21 +07:00
|
|
|
}
|
|
|
|
crypto_alg_put(alg);
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_stats_aead_encrypt);
|
|
|
|
|
|
|
|
void crypto_stats_aead_decrypt(unsigned int cryptlen, struct crypto_alg *alg,
|
|
|
|
int ret)
|
|
|
|
{
|
|
|
|
if (ret && ret != -EINPROGRESS && ret != -EBUSY) {
|
2018-11-29 21:42:25 +07:00
|
|
|
atomic64_inc(&alg->stats.aead.err_cnt);
|
2018-11-29 21:42:21 +07:00
|
|
|
} else {
|
2018-11-29 21:42:24 +07:00
|
|
|
atomic64_inc(&alg->stats.aead.decrypt_cnt);
|
|
|
|
atomic64_add(cryptlen, &alg->stats.aead.decrypt_tlen);
|
2018-11-29 21:42:21 +07:00
|
|
|
}
|
|
|
|
crypto_alg_put(alg);
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_stats_aead_decrypt);
|
|
|
|
|
|
|
|
void crypto_stats_akcipher_encrypt(unsigned int src_len, int ret,
|
|
|
|
struct crypto_alg *alg)
|
|
|
|
{
|
|
|
|
if (ret && ret != -EINPROGRESS && ret != -EBUSY) {
|
2018-11-29 21:42:25 +07:00
|
|
|
atomic64_inc(&alg->stats.akcipher.err_cnt);
|
2018-11-29 21:42:21 +07:00
|
|
|
} else {
|
2018-11-29 21:42:24 +07:00
|
|
|
atomic64_inc(&alg->stats.akcipher.encrypt_cnt);
|
|
|
|
atomic64_add(src_len, &alg->stats.akcipher.encrypt_tlen);
|
2018-11-29 21:42:21 +07:00
|
|
|
}
|
|
|
|
crypto_alg_put(alg);
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_stats_akcipher_encrypt);
|
|
|
|
|
|
|
|
void crypto_stats_akcipher_decrypt(unsigned int src_len, int ret,
|
|
|
|
struct crypto_alg *alg)
|
|
|
|
{
|
|
|
|
if (ret && ret != -EINPROGRESS && ret != -EBUSY) {
|
2018-11-29 21:42:25 +07:00
|
|
|
atomic64_inc(&alg->stats.akcipher.err_cnt);
|
2018-11-29 21:42:21 +07:00
|
|
|
} else {
|
2018-11-29 21:42:24 +07:00
|
|
|
atomic64_inc(&alg->stats.akcipher.decrypt_cnt);
|
|
|
|
atomic64_add(src_len, &alg->stats.akcipher.decrypt_tlen);
|
2018-11-29 21:42:21 +07:00
|
|
|
}
|
|
|
|
crypto_alg_put(alg);
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_stats_akcipher_decrypt);
|
|
|
|
|
|
|
|
void crypto_stats_akcipher_sign(int ret, struct crypto_alg *alg)
|
|
|
|
{
|
|
|
|
if (ret && ret != -EINPROGRESS && ret != -EBUSY)
|
2018-11-29 21:42:25 +07:00
|
|
|
atomic64_inc(&alg->stats.akcipher.err_cnt);
|
2018-11-29 21:42:21 +07:00
|
|
|
else
|
2018-11-29 21:42:24 +07:00
|
|
|
atomic64_inc(&alg->stats.akcipher.sign_cnt);
|
2018-11-29 21:42:21 +07:00
|
|
|
crypto_alg_put(alg);
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_stats_akcipher_sign);
|
|
|
|
|
|
|
|
void crypto_stats_akcipher_verify(int ret, struct crypto_alg *alg)
|
|
|
|
{
|
|
|
|
if (ret && ret != -EINPROGRESS && ret != -EBUSY)
|
2018-11-29 21:42:25 +07:00
|
|
|
atomic64_inc(&alg->stats.akcipher.err_cnt);
|
2018-11-29 21:42:21 +07:00
|
|
|
else
|
2018-11-29 21:42:24 +07:00
|
|
|
atomic64_inc(&alg->stats.akcipher.verify_cnt);
|
2018-11-29 21:42:21 +07:00
|
|
|
crypto_alg_put(alg);
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_stats_akcipher_verify);
|
|
|
|
|
|
|
|
void crypto_stats_compress(unsigned int slen, int ret, struct crypto_alg *alg)
|
|
|
|
{
|
|
|
|
if (ret && ret != -EINPROGRESS && ret != -EBUSY) {
|
2018-11-29 21:42:25 +07:00
|
|
|
atomic64_inc(&alg->stats.compress.err_cnt);
|
2018-11-29 21:42:21 +07:00
|
|
|
} else {
|
2018-11-29 21:42:24 +07:00
|
|
|
atomic64_inc(&alg->stats.compress.compress_cnt);
|
|
|
|
atomic64_add(slen, &alg->stats.compress.compress_tlen);
|
2018-11-29 21:42:21 +07:00
|
|
|
}
|
|
|
|
crypto_alg_put(alg);
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_stats_compress);
|
|
|
|
|
|
|
|
void crypto_stats_decompress(unsigned int slen, int ret, struct crypto_alg *alg)
|
|
|
|
{
|
|
|
|
if (ret && ret != -EINPROGRESS && ret != -EBUSY) {
|
2018-11-29 21:42:25 +07:00
|
|
|
atomic64_inc(&alg->stats.compress.err_cnt);
|
2018-11-29 21:42:21 +07:00
|
|
|
} else {
|
2018-11-29 21:42:24 +07:00
|
|
|
atomic64_inc(&alg->stats.compress.decompress_cnt);
|
|
|
|
atomic64_add(slen, &alg->stats.compress.decompress_tlen);
|
2018-11-29 21:42:21 +07:00
|
|
|
}
|
|
|
|
crypto_alg_put(alg);
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_stats_decompress);
|
|
|
|
|
|
|
|
void crypto_stats_ahash_update(unsigned int nbytes, int ret,
|
|
|
|
struct crypto_alg *alg)
|
|
|
|
{
|
|
|
|
if (ret && ret != -EINPROGRESS && ret != -EBUSY)
|
2018-11-29 21:42:25 +07:00
|
|
|
atomic64_inc(&alg->stats.hash.err_cnt);
|
2018-11-29 21:42:21 +07:00
|
|
|
else
|
2018-11-29 21:42:24 +07:00
|
|
|
atomic64_add(nbytes, &alg->stats.hash.hash_tlen);
|
2018-11-29 21:42:21 +07:00
|
|
|
crypto_alg_put(alg);
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_stats_ahash_update);
|
|
|
|
|
|
|
|
void crypto_stats_ahash_final(unsigned int nbytes, int ret,
|
|
|
|
struct crypto_alg *alg)
|
|
|
|
{
|
|
|
|
if (ret && ret != -EINPROGRESS && ret != -EBUSY) {
|
2018-11-29 21:42:25 +07:00
|
|
|
atomic64_inc(&alg->stats.hash.err_cnt);
|
2018-11-29 21:42:21 +07:00
|
|
|
} else {
|
2018-11-29 21:42:24 +07:00
|
|
|
atomic64_inc(&alg->stats.hash.hash_cnt);
|
|
|
|
atomic64_add(nbytes, &alg->stats.hash.hash_tlen);
|
2018-11-29 21:42:21 +07:00
|
|
|
}
|
|
|
|
crypto_alg_put(alg);
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_stats_ahash_final);
|
|
|
|
|
|
|
|
void crypto_stats_kpp_set_secret(struct crypto_alg *alg, int ret)
|
|
|
|
{
|
|
|
|
if (ret)
|
2018-11-29 21:42:25 +07:00
|
|
|
atomic64_inc(&alg->stats.kpp.err_cnt);
|
2018-11-29 21:42:21 +07:00
|
|
|
else
|
2018-11-29 21:42:24 +07:00
|
|
|
atomic64_inc(&alg->stats.kpp.setsecret_cnt);
|
2018-11-29 21:42:21 +07:00
|
|
|
crypto_alg_put(alg);
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_stats_kpp_set_secret);
|
|
|
|
|
|
|
|
void crypto_stats_kpp_generate_public_key(struct crypto_alg *alg, int ret)
|
|
|
|
{
|
|
|
|
if (ret)
|
2018-11-29 21:42:25 +07:00
|
|
|
atomic64_inc(&alg->stats.kpp.err_cnt);
|
2018-11-29 21:42:21 +07:00
|
|
|
else
|
2018-11-29 21:42:24 +07:00
|
|
|
atomic64_inc(&alg->stats.kpp.generate_public_key_cnt);
|
2018-11-29 21:42:21 +07:00
|
|
|
crypto_alg_put(alg);
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_stats_kpp_generate_public_key);
|
|
|
|
|
|
|
|
void crypto_stats_kpp_compute_shared_secret(struct crypto_alg *alg, int ret)
|
|
|
|
{
|
|
|
|
if (ret)
|
2018-11-29 21:42:25 +07:00
|
|
|
atomic64_inc(&alg->stats.kpp.err_cnt);
|
2018-11-29 21:42:21 +07:00
|
|
|
else
|
2018-11-29 21:42:24 +07:00
|
|
|
atomic64_inc(&alg->stats.kpp.compute_shared_secret_cnt);
|
2018-11-29 21:42:21 +07:00
|
|
|
crypto_alg_put(alg);
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_stats_kpp_compute_shared_secret);
|
|
|
|
|
|
|
|
void crypto_stats_rng_seed(struct crypto_alg *alg, int ret)
|
|
|
|
{
|
|
|
|
if (ret && ret != -EINPROGRESS && ret != -EBUSY)
|
2018-11-29 21:42:25 +07:00
|
|
|
atomic64_inc(&alg->stats.rng.err_cnt);
|
2018-11-29 21:42:21 +07:00
|
|
|
else
|
2018-11-29 21:42:24 +07:00
|
|
|
atomic64_inc(&alg->stats.rng.seed_cnt);
|
2018-11-29 21:42:21 +07:00
|
|
|
crypto_alg_put(alg);
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_stats_rng_seed);
|
|
|
|
|
|
|
|
void crypto_stats_rng_generate(struct crypto_alg *alg, unsigned int dlen,
|
|
|
|
int ret)
|
|
|
|
{
|
|
|
|
if (ret && ret != -EINPROGRESS && ret != -EBUSY) {
|
2018-11-29 21:42:25 +07:00
|
|
|
atomic64_inc(&alg->stats.rng.err_cnt);
|
2018-11-29 21:42:21 +07:00
|
|
|
} else {
|
2018-11-29 21:42:24 +07:00
|
|
|
atomic64_inc(&alg->stats.rng.generate_cnt);
|
|
|
|
atomic64_add(dlen, &alg->stats.rng.generate_tlen);
|
2018-11-29 21:42:21 +07:00
|
|
|
}
|
|
|
|
crypto_alg_put(alg);
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_stats_rng_generate);
|
|
|
|
|
|
|
|
void crypto_stats_skcipher_encrypt(unsigned int cryptlen, int ret,
|
|
|
|
struct crypto_alg *alg)
|
|
|
|
{
|
|
|
|
if (ret && ret != -EINPROGRESS && ret != -EBUSY) {
|
2018-11-29 21:42:25 +07:00
|
|
|
atomic64_inc(&alg->stats.cipher.err_cnt);
|
2018-11-29 21:42:21 +07:00
|
|
|
} else {
|
2018-11-29 21:42:24 +07:00
|
|
|
atomic64_inc(&alg->stats.cipher.encrypt_cnt);
|
|
|
|
atomic64_add(cryptlen, &alg->stats.cipher.encrypt_tlen);
|
2018-11-29 21:42:21 +07:00
|
|
|
}
|
|
|
|
crypto_alg_put(alg);
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_stats_skcipher_encrypt);
|
|
|
|
|
|
|
|
void crypto_stats_skcipher_decrypt(unsigned int cryptlen, int ret,
|
|
|
|
struct crypto_alg *alg)
|
|
|
|
{
|
|
|
|
if (ret && ret != -EINPROGRESS && ret != -EBUSY) {
|
2018-11-29 21:42:25 +07:00
|
|
|
atomic64_inc(&alg->stats.cipher.err_cnt);
|
2018-11-29 21:42:21 +07:00
|
|
|
} else {
|
2018-11-29 21:42:24 +07:00
|
|
|
atomic64_inc(&alg->stats.cipher.decrypt_cnt);
|
|
|
|
atomic64_add(cryptlen, &alg->stats.cipher.decrypt_tlen);
|
2018-11-29 21:42:21 +07:00
|
|
|
}
|
|
|
|
crypto_alg_put(alg);
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(crypto_stats_skcipher_decrypt);
|
|
|
|
#endif
|
|
|
|
|
2006-08-21 18:08:13 +07:00
|
|
|
static int __init crypto_algapi_init(void)
|
|
|
|
{
|
|
|
|
crypto_init_proc();
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
static void __exit crypto_algapi_exit(void)
|
|
|
|
{
|
|
|
|
crypto_exit_proc();
|
|
|
|
}
|
|
|
|
|
|
|
|
module_init(crypto_algapi_init);
|
|
|
|
module_exit(crypto_algapi_exit);
|
|
|
|
|
|
|
|
MODULE_LICENSE("GPL");
|
|
|
|
MODULE_DESCRIPTION("Cryptographic algorithms API");
|