162306a36Sopenharmony_ci// SPDX-License-Identifier: GPL-2.0-or-later
262306a36Sopenharmony_ci/*
362306a36Sopenharmony_ci * Glue code for the SHA256 Secure Hash Algorithm assembly implementation
462306a36Sopenharmony_ci * using NEON instructions.
562306a36Sopenharmony_ci *
662306a36Sopenharmony_ci * Copyright © 2015 Google Inc.
762306a36Sopenharmony_ci *
862306a36Sopenharmony_ci * This file is based on sha512_neon_glue.c:
962306a36Sopenharmony_ci *   Copyright © 2014 Jussi Kivilinna <jussi.kivilinna@iki.fi>
1062306a36Sopenharmony_ci */
1162306a36Sopenharmony_ci
1262306a36Sopenharmony_ci#include <crypto/internal/hash.h>
1362306a36Sopenharmony_ci#include <crypto/internal/simd.h>
1462306a36Sopenharmony_ci#include <linux/types.h>
1562306a36Sopenharmony_ci#include <linux/string.h>
1662306a36Sopenharmony_ci#include <crypto/sha2.h>
1762306a36Sopenharmony_ci#include <crypto/sha256_base.h>
1862306a36Sopenharmony_ci#include <asm/byteorder.h>
1962306a36Sopenharmony_ci#include <asm/simd.h>
2062306a36Sopenharmony_ci#include <asm/neon.h>
2162306a36Sopenharmony_ci
2262306a36Sopenharmony_ci#include "sha256_glue.h"
2362306a36Sopenharmony_ci
2462306a36Sopenharmony_ciasmlinkage void sha256_block_data_order_neon(struct sha256_state *digest,
2562306a36Sopenharmony_ci					     const u8 *data, int num_blks);
2662306a36Sopenharmony_ci
2762306a36Sopenharmony_cistatic int crypto_sha256_neon_update(struct shash_desc *desc, const u8 *data,
2862306a36Sopenharmony_ci				     unsigned int len)
2962306a36Sopenharmony_ci{
3062306a36Sopenharmony_ci	struct sha256_state *sctx = shash_desc_ctx(desc);
3162306a36Sopenharmony_ci
3262306a36Sopenharmony_ci	if (!crypto_simd_usable() ||
3362306a36Sopenharmony_ci	    (sctx->count % SHA256_BLOCK_SIZE) + len < SHA256_BLOCK_SIZE)
3462306a36Sopenharmony_ci		return crypto_sha256_arm_update(desc, data, len);
3562306a36Sopenharmony_ci
3662306a36Sopenharmony_ci	kernel_neon_begin();
3762306a36Sopenharmony_ci	sha256_base_do_update(desc, data, len, sha256_block_data_order_neon);
3862306a36Sopenharmony_ci	kernel_neon_end();
3962306a36Sopenharmony_ci
4062306a36Sopenharmony_ci	return 0;
4162306a36Sopenharmony_ci}
4262306a36Sopenharmony_ci
4362306a36Sopenharmony_cistatic int crypto_sha256_neon_finup(struct shash_desc *desc, const u8 *data,
4462306a36Sopenharmony_ci				    unsigned int len, u8 *out)
4562306a36Sopenharmony_ci{
4662306a36Sopenharmony_ci	if (!crypto_simd_usable())
4762306a36Sopenharmony_ci		return crypto_sha256_arm_finup(desc, data, len, out);
4862306a36Sopenharmony_ci
4962306a36Sopenharmony_ci	kernel_neon_begin();
5062306a36Sopenharmony_ci	if (len)
5162306a36Sopenharmony_ci		sha256_base_do_update(desc, data, len,
5262306a36Sopenharmony_ci				      sha256_block_data_order_neon);
5362306a36Sopenharmony_ci	sha256_base_do_finalize(desc, sha256_block_data_order_neon);
5462306a36Sopenharmony_ci	kernel_neon_end();
5562306a36Sopenharmony_ci
5662306a36Sopenharmony_ci	return sha256_base_finish(desc, out);
5762306a36Sopenharmony_ci}
5862306a36Sopenharmony_ci
5962306a36Sopenharmony_cistatic int crypto_sha256_neon_final(struct shash_desc *desc, u8 *out)
6062306a36Sopenharmony_ci{
6162306a36Sopenharmony_ci	return crypto_sha256_neon_finup(desc, NULL, 0, out);
6262306a36Sopenharmony_ci}
6362306a36Sopenharmony_ci
6462306a36Sopenharmony_cistruct shash_alg sha256_neon_algs[] = { {
6562306a36Sopenharmony_ci	.digestsize	=	SHA256_DIGEST_SIZE,
6662306a36Sopenharmony_ci	.init		=	sha256_base_init,
6762306a36Sopenharmony_ci	.update		=	crypto_sha256_neon_update,
6862306a36Sopenharmony_ci	.final		=	crypto_sha256_neon_final,
6962306a36Sopenharmony_ci	.finup		=	crypto_sha256_neon_finup,
7062306a36Sopenharmony_ci	.descsize	=	sizeof(struct sha256_state),
7162306a36Sopenharmony_ci	.base		=	{
7262306a36Sopenharmony_ci		.cra_name	=	"sha256",
7362306a36Sopenharmony_ci		.cra_driver_name =	"sha256-neon",
7462306a36Sopenharmony_ci		.cra_priority	=	250,
7562306a36Sopenharmony_ci		.cra_blocksize	=	SHA256_BLOCK_SIZE,
7662306a36Sopenharmony_ci		.cra_module	=	THIS_MODULE,
7762306a36Sopenharmony_ci	}
7862306a36Sopenharmony_ci}, {
7962306a36Sopenharmony_ci	.digestsize	=	SHA224_DIGEST_SIZE,
8062306a36Sopenharmony_ci	.init		=	sha224_base_init,
8162306a36Sopenharmony_ci	.update		=	crypto_sha256_neon_update,
8262306a36Sopenharmony_ci	.final		=	crypto_sha256_neon_final,
8362306a36Sopenharmony_ci	.finup		=	crypto_sha256_neon_finup,
8462306a36Sopenharmony_ci	.descsize	=	sizeof(struct sha256_state),
8562306a36Sopenharmony_ci	.base		=	{
8662306a36Sopenharmony_ci		.cra_name	=	"sha224",
8762306a36Sopenharmony_ci		.cra_driver_name =	"sha224-neon",
8862306a36Sopenharmony_ci		.cra_priority	=	250,
8962306a36Sopenharmony_ci		.cra_blocksize	=	SHA224_BLOCK_SIZE,
9062306a36Sopenharmony_ci		.cra_module	=	THIS_MODULE,
9162306a36Sopenharmony_ci	}
9262306a36Sopenharmony_ci} };
93