162306a36Sopenharmony_ci// SPDX-License-Identifier: GPL-2.0-or-later 262306a36Sopenharmony_ci/* 362306a36Sopenharmony_ci * Linux/arm64 port of the OpenSSL SHA256 implementation for AArch64 462306a36Sopenharmony_ci * 562306a36Sopenharmony_ci * Copyright (c) 2016 Linaro Ltd. <ard.biesheuvel@linaro.org> 662306a36Sopenharmony_ci */ 762306a36Sopenharmony_ci 862306a36Sopenharmony_ci#include <asm/hwcap.h> 962306a36Sopenharmony_ci#include <asm/neon.h> 1062306a36Sopenharmony_ci#include <asm/simd.h> 1162306a36Sopenharmony_ci#include <crypto/internal/hash.h> 1262306a36Sopenharmony_ci#include <crypto/internal/simd.h> 1362306a36Sopenharmony_ci#include <crypto/sha2.h> 1462306a36Sopenharmony_ci#include <crypto/sha256_base.h> 1562306a36Sopenharmony_ci#include <linux/module.h> 1662306a36Sopenharmony_ci#include <linux/string.h> 1762306a36Sopenharmony_ci#include <linux/types.h> 1862306a36Sopenharmony_ci 1962306a36Sopenharmony_ciMODULE_DESCRIPTION("SHA-224/SHA-256 secure hash for arm64"); 2062306a36Sopenharmony_ciMODULE_AUTHOR("Andy Polyakov <appro@openssl.org>"); 2162306a36Sopenharmony_ciMODULE_AUTHOR("Ard Biesheuvel <ard.biesheuvel@linaro.org>"); 2262306a36Sopenharmony_ciMODULE_LICENSE("GPL v2"); 2362306a36Sopenharmony_ciMODULE_ALIAS_CRYPTO("sha224"); 2462306a36Sopenharmony_ciMODULE_ALIAS_CRYPTO("sha256"); 2562306a36Sopenharmony_ci 2662306a36Sopenharmony_ciasmlinkage void sha256_block_data_order(u32 *digest, const void *data, 2762306a36Sopenharmony_ci unsigned int num_blks); 2862306a36Sopenharmony_ciEXPORT_SYMBOL(sha256_block_data_order); 2962306a36Sopenharmony_ci 3062306a36Sopenharmony_cistatic void __sha256_block_data_order(struct sha256_state *sst, u8 const *src, 3162306a36Sopenharmony_ci int blocks) 3262306a36Sopenharmony_ci{ 3362306a36Sopenharmony_ci sha256_block_data_order(sst->state, src, blocks); 3462306a36Sopenharmony_ci} 3562306a36Sopenharmony_ci 3662306a36Sopenharmony_ciasmlinkage void sha256_block_neon(u32 *digest, const void *data, 3762306a36Sopenharmony_ci unsigned int num_blks); 3862306a36Sopenharmony_ci 3962306a36Sopenharmony_cistatic void __sha256_block_neon(struct sha256_state *sst, u8 const *src, 4062306a36Sopenharmony_ci int blocks) 4162306a36Sopenharmony_ci{ 4262306a36Sopenharmony_ci sha256_block_neon(sst->state, src, blocks); 4362306a36Sopenharmony_ci} 4462306a36Sopenharmony_ci 4562306a36Sopenharmony_cistatic int crypto_sha256_arm64_update(struct shash_desc *desc, const u8 *data, 4662306a36Sopenharmony_ci unsigned int len) 4762306a36Sopenharmony_ci{ 4862306a36Sopenharmony_ci return sha256_base_do_update(desc, data, len, 4962306a36Sopenharmony_ci __sha256_block_data_order); 5062306a36Sopenharmony_ci} 5162306a36Sopenharmony_ci 5262306a36Sopenharmony_cistatic int crypto_sha256_arm64_finup(struct shash_desc *desc, const u8 *data, 5362306a36Sopenharmony_ci unsigned int len, u8 *out) 5462306a36Sopenharmony_ci{ 5562306a36Sopenharmony_ci if (len) 5662306a36Sopenharmony_ci sha256_base_do_update(desc, data, len, 5762306a36Sopenharmony_ci __sha256_block_data_order); 5862306a36Sopenharmony_ci sha256_base_do_finalize(desc, __sha256_block_data_order); 5962306a36Sopenharmony_ci 6062306a36Sopenharmony_ci return sha256_base_finish(desc, out); 6162306a36Sopenharmony_ci} 6262306a36Sopenharmony_ci 6362306a36Sopenharmony_cistatic int crypto_sha256_arm64_final(struct shash_desc *desc, u8 *out) 6462306a36Sopenharmony_ci{ 6562306a36Sopenharmony_ci return crypto_sha256_arm64_finup(desc, NULL, 0, out); 6662306a36Sopenharmony_ci} 6762306a36Sopenharmony_ci 6862306a36Sopenharmony_cistatic struct shash_alg algs[] = { { 6962306a36Sopenharmony_ci .digestsize = SHA256_DIGEST_SIZE, 7062306a36Sopenharmony_ci .init = sha256_base_init, 7162306a36Sopenharmony_ci .update = crypto_sha256_arm64_update, 7262306a36Sopenharmony_ci .final = crypto_sha256_arm64_final, 7362306a36Sopenharmony_ci .finup = crypto_sha256_arm64_finup, 7462306a36Sopenharmony_ci .descsize = sizeof(struct sha256_state), 7562306a36Sopenharmony_ci .base.cra_name = "sha256", 7662306a36Sopenharmony_ci .base.cra_driver_name = "sha256-arm64", 7762306a36Sopenharmony_ci .base.cra_priority = 125, 7862306a36Sopenharmony_ci .base.cra_blocksize = SHA256_BLOCK_SIZE, 7962306a36Sopenharmony_ci .base.cra_module = THIS_MODULE, 8062306a36Sopenharmony_ci}, { 8162306a36Sopenharmony_ci .digestsize = SHA224_DIGEST_SIZE, 8262306a36Sopenharmony_ci .init = sha224_base_init, 8362306a36Sopenharmony_ci .update = crypto_sha256_arm64_update, 8462306a36Sopenharmony_ci .final = crypto_sha256_arm64_final, 8562306a36Sopenharmony_ci .finup = crypto_sha256_arm64_finup, 8662306a36Sopenharmony_ci .descsize = sizeof(struct sha256_state), 8762306a36Sopenharmony_ci .base.cra_name = "sha224", 8862306a36Sopenharmony_ci .base.cra_driver_name = "sha224-arm64", 8962306a36Sopenharmony_ci .base.cra_priority = 125, 9062306a36Sopenharmony_ci .base.cra_blocksize = SHA224_BLOCK_SIZE, 9162306a36Sopenharmony_ci .base.cra_module = THIS_MODULE, 9262306a36Sopenharmony_ci} }; 9362306a36Sopenharmony_ci 9462306a36Sopenharmony_cistatic int sha256_update_neon(struct shash_desc *desc, const u8 *data, 9562306a36Sopenharmony_ci unsigned int len) 9662306a36Sopenharmony_ci{ 9762306a36Sopenharmony_ci struct sha256_state *sctx = shash_desc_ctx(desc); 9862306a36Sopenharmony_ci 9962306a36Sopenharmony_ci if (!crypto_simd_usable()) 10062306a36Sopenharmony_ci return sha256_base_do_update(desc, data, len, 10162306a36Sopenharmony_ci __sha256_block_data_order); 10262306a36Sopenharmony_ci 10362306a36Sopenharmony_ci while (len > 0) { 10462306a36Sopenharmony_ci unsigned int chunk = len; 10562306a36Sopenharmony_ci 10662306a36Sopenharmony_ci /* 10762306a36Sopenharmony_ci * Don't hog the CPU for the entire time it takes to process all 10862306a36Sopenharmony_ci * input when running on a preemptible kernel, but process the 10962306a36Sopenharmony_ci * data block by block instead. 11062306a36Sopenharmony_ci */ 11162306a36Sopenharmony_ci if (IS_ENABLED(CONFIG_PREEMPTION) && 11262306a36Sopenharmony_ci chunk + sctx->count % SHA256_BLOCK_SIZE > SHA256_BLOCK_SIZE) 11362306a36Sopenharmony_ci chunk = SHA256_BLOCK_SIZE - 11462306a36Sopenharmony_ci sctx->count % SHA256_BLOCK_SIZE; 11562306a36Sopenharmony_ci 11662306a36Sopenharmony_ci kernel_neon_begin(); 11762306a36Sopenharmony_ci sha256_base_do_update(desc, data, chunk, __sha256_block_neon); 11862306a36Sopenharmony_ci kernel_neon_end(); 11962306a36Sopenharmony_ci data += chunk; 12062306a36Sopenharmony_ci len -= chunk; 12162306a36Sopenharmony_ci } 12262306a36Sopenharmony_ci return 0; 12362306a36Sopenharmony_ci} 12462306a36Sopenharmony_ci 12562306a36Sopenharmony_cistatic int sha256_finup_neon(struct shash_desc *desc, const u8 *data, 12662306a36Sopenharmony_ci unsigned int len, u8 *out) 12762306a36Sopenharmony_ci{ 12862306a36Sopenharmony_ci if (!crypto_simd_usable()) { 12962306a36Sopenharmony_ci if (len) 13062306a36Sopenharmony_ci sha256_base_do_update(desc, data, len, 13162306a36Sopenharmony_ci __sha256_block_data_order); 13262306a36Sopenharmony_ci sha256_base_do_finalize(desc, __sha256_block_data_order); 13362306a36Sopenharmony_ci } else { 13462306a36Sopenharmony_ci if (len) 13562306a36Sopenharmony_ci sha256_update_neon(desc, data, len); 13662306a36Sopenharmony_ci kernel_neon_begin(); 13762306a36Sopenharmony_ci sha256_base_do_finalize(desc, __sha256_block_neon); 13862306a36Sopenharmony_ci kernel_neon_end(); 13962306a36Sopenharmony_ci } 14062306a36Sopenharmony_ci return sha256_base_finish(desc, out); 14162306a36Sopenharmony_ci} 14262306a36Sopenharmony_ci 14362306a36Sopenharmony_cistatic int sha256_final_neon(struct shash_desc *desc, u8 *out) 14462306a36Sopenharmony_ci{ 14562306a36Sopenharmony_ci return sha256_finup_neon(desc, NULL, 0, out); 14662306a36Sopenharmony_ci} 14762306a36Sopenharmony_ci 14862306a36Sopenharmony_cistatic struct shash_alg neon_algs[] = { { 14962306a36Sopenharmony_ci .digestsize = SHA256_DIGEST_SIZE, 15062306a36Sopenharmony_ci .init = sha256_base_init, 15162306a36Sopenharmony_ci .update = sha256_update_neon, 15262306a36Sopenharmony_ci .final = sha256_final_neon, 15362306a36Sopenharmony_ci .finup = sha256_finup_neon, 15462306a36Sopenharmony_ci .descsize = sizeof(struct sha256_state), 15562306a36Sopenharmony_ci .base.cra_name = "sha256", 15662306a36Sopenharmony_ci .base.cra_driver_name = "sha256-arm64-neon", 15762306a36Sopenharmony_ci .base.cra_priority = 150, 15862306a36Sopenharmony_ci .base.cra_blocksize = SHA256_BLOCK_SIZE, 15962306a36Sopenharmony_ci .base.cra_module = THIS_MODULE, 16062306a36Sopenharmony_ci}, { 16162306a36Sopenharmony_ci .digestsize = SHA224_DIGEST_SIZE, 16262306a36Sopenharmony_ci .init = sha224_base_init, 16362306a36Sopenharmony_ci .update = sha256_update_neon, 16462306a36Sopenharmony_ci .final = sha256_final_neon, 16562306a36Sopenharmony_ci .finup = sha256_finup_neon, 16662306a36Sopenharmony_ci .descsize = sizeof(struct sha256_state), 16762306a36Sopenharmony_ci .base.cra_name = "sha224", 16862306a36Sopenharmony_ci .base.cra_driver_name = "sha224-arm64-neon", 16962306a36Sopenharmony_ci .base.cra_priority = 150, 17062306a36Sopenharmony_ci .base.cra_blocksize = SHA224_BLOCK_SIZE, 17162306a36Sopenharmony_ci .base.cra_module = THIS_MODULE, 17262306a36Sopenharmony_ci} }; 17362306a36Sopenharmony_ci 17462306a36Sopenharmony_cistatic int __init sha256_mod_init(void) 17562306a36Sopenharmony_ci{ 17662306a36Sopenharmony_ci int ret = crypto_register_shashes(algs, ARRAY_SIZE(algs)); 17762306a36Sopenharmony_ci if (ret) 17862306a36Sopenharmony_ci return ret; 17962306a36Sopenharmony_ci 18062306a36Sopenharmony_ci if (cpu_have_named_feature(ASIMD)) { 18162306a36Sopenharmony_ci ret = crypto_register_shashes(neon_algs, ARRAY_SIZE(neon_algs)); 18262306a36Sopenharmony_ci if (ret) 18362306a36Sopenharmony_ci crypto_unregister_shashes(algs, ARRAY_SIZE(algs)); 18462306a36Sopenharmony_ci } 18562306a36Sopenharmony_ci return ret; 18662306a36Sopenharmony_ci} 18762306a36Sopenharmony_ci 18862306a36Sopenharmony_cistatic void __exit sha256_mod_fini(void) 18962306a36Sopenharmony_ci{ 19062306a36Sopenharmony_ci if (cpu_have_named_feature(ASIMD)) 19162306a36Sopenharmony_ci crypto_unregister_shashes(neon_algs, ARRAY_SIZE(neon_algs)); 19262306a36Sopenharmony_ci crypto_unregister_shashes(algs, ARRAY_SIZE(algs)); 19362306a36Sopenharmony_ci} 19462306a36Sopenharmony_ci 19562306a36Sopenharmony_cimodule_init(sha256_mod_init); 19662306a36Sopenharmony_cimodule_exit(sha256_mod_fini); 197