162306a36Sopenharmony_ci/* SPDX-License-Identifier: GPL-2.0-or-later */
262306a36Sopenharmony_ci/*
362306a36Sopenharmony_ci * SM4 Cipher Algorithm, using ARMv8 Crypto Extensions
462306a36Sopenharmony_ci * as specified in
562306a36Sopenharmony_ci * https://tools.ietf.org/id/draft-ribose-cfrg-sm4-10.html
662306a36Sopenharmony_ci *
762306a36Sopenharmony_ci * Copyright (C) 2022, Alibaba Group.
862306a36Sopenharmony_ci * Copyright (C) 2022 Tianjia Zhang <tianjia.zhang@linux.alibaba.com>
962306a36Sopenharmony_ci */
1062306a36Sopenharmony_ci
1162306a36Sopenharmony_ci#include <linux/module.h>
1262306a36Sopenharmony_ci#include <linux/crypto.h>
1362306a36Sopenharmony_ci#include <linux/kernel.h>
1462306a36Sopenharmony_ci#include <linux/cpufeature.h>
1562306a36Sopenharmony_ci#include <asm/neon.h>
1662306a36Sopenharmony_ci#include <asm/simd.h>
1762306a36Sopenharmony_ci#include <crypto/b128ops.h>
1862306a36Sopenharmony_ci#include <crypto/internal/simd.h>
1962306a36Sopenharmony_ci#include <crypto/internal/skcipher.h>
2062306a36Sopenharmony_ci#include <crypto/internal/hash.h>
2162306a36Sopenharmony_ci#include <crypto/scatterwalk.h>
2262306a36Sopenharmony_ci#include <crypto/xts.h>
2362306a36Sopenharmony_ci#include <crypto/sm4.h>
2462306a36Sopenharmony_ci
2562306a36Sopenharmony_ci#define BYTES2BLKS(nbytes)	((nbytes) >> 4)
2662306a36Sopenharmony_ci
2762306a36Sopenharmony_ciasmlinkage void sm4_ce_expand_key(const u8 *key, u32 *rkey_enc, u32 *rkey_dec,
2862306a36Sopenharmony_ci				  const u32 *fk, const u32 *ck);
2962306a36Sopenharmony_ciasmlinkage void sm4_ce_crypt_block(const u32 *rkey, u8 *dst, const u8 *src);
3062306a36Sopenharmony_ciasmlinkage void sm4_ce_crypt(const u32 *rkey, u8 *dst, const u8 *src,
3162306a36Sopenharmony_ci			     unsigned int nblks);
3262306a36Sopenharmony_ciasmlinkage void sm4_ce_cbc_enc(const u32 *rkey, u8 *dst, const u8 *src,
3362306a36Sopenharmony_ci			       u8 *iv, unsigned int nblocks);
3462306a36Sopenharmony_ciasmlinkage void sm4_ce_cbc_dec(const u32 *rkey, u8 *dst, const u8 *src,
3562306a36Sopenharmony_ci			       u8 *iv, unsigned int nblocks);
3662306a36Sopenharmony_ciasmlinkage void sm4_ce_cbc_cts_enc(const u32 *rkey, u8 *dst, const u8 *src,
3762306a36Sopenharmony_ci				   u8 *iv, unsigned int nbytes);
3862306a36Sopenharmony_ciasmlinkage void sm4_ce_cbc_cts_dec(const u32 *rkey, u8 *dst, const u8 *src,
3962306a36Sopenharmony_ci				   u8 *iv, unsigned int nbytes);
4062306a36Sopenharmony_ciasmlinkage void sm4_ce_cfb_enc(const u32 *rkey, u8 *dst, const u8 *src,
4162306a36Sopenharmony_ci			       u8 *iv, unsigned int nblks);
4262306a36Sopenharmony_ciasmlinkage void sm4_ce_cfb_dec(const u32 *rkey, u8 *dst, const u8 *src,
4362306a36Sopenharmony_ci			       u8 *iv, unsigned int nblks);
4462306a36Sopenharmony_ciasmlinkage void sm4_ce_ctr_enc(const u32 *rkey, u8 *dst, const u8 *src,
4562306a36Sopenharmony_ci			       u8 *iv, unsigned int nblks);
4662306a36Sopenharmony_ciasmlinkage void sm4_ce_xts_enc(const u32 *rkey1, u8 *dst, const u8 *src,
4762306a36Sopenharmony_ci			       u8 *tweak, unsigned int nbytes,
4862306a36Sopenharmony_ci			       const u32 *rkey2_enc);
4962306a36Sopenharmony_ciasmlinkage void sm4_ce_xts_dec(const u32 *rkey1, u8 *dst, const u8 *src,
5062306a36Sopenharmony_ci			       u8 *tweak, unsigned int nbytes,
5162306a36Sopenharmony_ci			       const u32 *rkey2_enc);
5262306a36Sopenharmony_ciasmlinkage void sm4_ce_mac_update(const u32 *rkey_enc, u8 *digest,
5362306a36Sopenharmony_ci				  const u8 *src, unsigned int nblocks,
5462306a36Sopenharmony_ci				  bool enc_before, bool enc_after);
5562306a36Sopenharmony_ci
5662306a36Sopenharmony_ciEXPORT_SYMBOL(sm4_ce_expand_key);
5762306a36Sopenharmony_ciEXPORT_SYMBOL(sm4_ce_crypt_block);
5862306a36Sopenharmony_ciEXPORT_SYMBOL(sm4_ce_cbc_enc);
5962306a36Sopenharmony_ciEXPORT_SYMBOL(sm4_ce_cfb_enc);
6062306a36Sopenharmony_ci
6162306a36Sopenharmony_cistruct sm4_xts_ctx {
6262306a36Sopenharmony_ci	struct sm4_ctx key1;
6362306a36Sopenharmony_ci	struct sm4_ctx key2;
6462306a36Sopenharmony_ci};
6562306a36Sopenharmony_ci
6662306a36Sopenharmony_cistruct sm4_mac_tfm_ctx {
6762306a36Sopenharmony_ci	struct sm4_ctx key;
6862306a36Sopenharmony_ci	u8 __aligned(8) consts[];
6962306a36Sopenharmony_ci};
7062306a36Sopenharmony_ci
7162306a36Sopenharmony_cistruct sm4_mac_desc_ctx {
7262306a36Sopenharmony_ci	unsigned int len;
7362306a36Sopenharmony_ci	u8 digest[SM4_BLOCK_SIZE];
7462306a36Sopenharmony_ci};
7562306a36Sopenharmony_ci
7662306a36Sopenharmony_cistatic int sm4_setkey(struct crypto_skcipher *tfm, const u8 *key,
7762306a36Sopenharmony_ci		      unsigned int key_len)
7862306a36Sopenharmony_ci{
7962306a36Sopenharmony_ci	struct sm4_ctx *ctx = crypto_skcipher_ctx(tfm);
8062306a36Sopenharmony_ci
8162306a36Sopenharmony_ci	if (key_len != SM4_KEY_SIZE)
8262306a36Sopenharmony_ci		return -EINVAL;
8362306a36Sopenharmony_ci
8462306a36Sopenharmony_ci	kernel_neon_begin();
8562306a36Sopenharmony_ci	sm4_ce_expand_key(key, ctx->rkey_enc, ctx->rkey_dec,
8662306a36Sopenharmony_ci			  crypto_sm4_fk, crypto_sm4_ck);
8762306a36Sopenharmony_ci	kernel_neon_end();
8862306a36Sopenharmony_ci	return 0;
8962306a36Sopenharmony_ci}
9062306a36Sopenharmony_ci
9162306a36Sopenharmony_cistatic int sm4_xts_setkey(struct crypto_skcipher *tfm, const u8 *key,
9262306a36Sopenharmony_ci			  unsigned int key_len)
9362306a36Sopenharmony_ci{
9462306a36Sopenharmony_ci	struct sm4_xts_ctx *ctx = crypto_skcipher_ctx(tfm);
9562306a36Sopenharmony_ci	int ret;
9662306a36Sopenharmony_ci
9762306a36Sopenharmony_ci	if (key_len != SM4_KEY_SIZE * 2)
9862306a36Sopenharmony_ci		return -EINVAL;
9962306a36Sopenharmony_ci
10062306a36Sopenharmony_ci	ret = xts_verify_key(tfm, key, key_len);
10162306a36Sopenharmony_ci	if (ret)
10262306a36Sopenharmony_ci		return ret;
10362306a36Sopenharmony_ci
10462306a36Sopenharmony_ci	kernel_neon_begin();
10562306a36Sopenharmony_ci	sm4_ce_expand_key(key, ctx->key1.rkey_enc,
10662306a36Sopenharmony_ci			  ctx->key1.rkey_dec, crypto_sm4_fk, crypto_sm4_ck);
10762306a36Sopenharmony_ci	sm4_ce_expand_key(&key[SM4_KEY_SIZE], ctx->key2.rkey_enc,
10862306a36Sopenharmony_ci			  ctx->key2.rkey_dec, crypto_sm4_fk, crypto_sm4_ck);
10962306a36Sopenharmony_ci	kernel_neon_end();
11062306a36Sopenharmony_ci
11162306a36Sopenharmony_ci	return 0;
11262306a36Sopenharmony_ci}
11362306a36Sopenharmony_ci
11462306a36Sopenharmony_cistatic int sm4_ecb_do_crypt(struct skcipher_request *req, const u32 *rkey)
11562306a36Sopenharmony_ci{
11662306a36Sopenharmony_ci	struct skcipher_walk walk;
11762306a36Sopenharmony_ci	unsigned int nbytes;
11862306a36Sopenharmony_ci	int err;
11962306a36Sopenharmony_ci
12062306a36Sopenharmony_ci	err = skcipher_walk_virt(&walk, req, false);
12162306a36Sopenharmony_ci
12262306a36Sopenharmony_ci	while ((nbytes = walk.nbytes) > 0) {
12362306a36Sopenharmony_ci		const u8 *src = walk.src.virt.addr;
12462306a36Sopenharmony_ci		u8 *dst = walk.dst.virt.addr;
12562306a36Sopenharmony_ci		unsigned int nblks;
12662306a36Sopenharmony_ci
12762306a36Sopenharmony_ci		kernel_neon_begin();
12862306a36Sopenharmony_ci
12962306a36Sopenharmony_ci		nblks = BYTES2BLKS(nbytes);
13062306a36Sopenharmony_ci		if (nblks) {
13162306a36Sopenharmony_ci			sm4_ce_crypt(rkey, dst, src, nblks);
13262306a36Sopenharmony_ci			nbytes -= nblks * SM4_BLOCK_SIZE;
13362306a36Sopenharmony_ci		}
13462306a36Sopenharmony_ci
13562306a36Sopenharmony_ci		kernel_neon_end();
13662306a36Sopenharmony_ci
13762306a36Sopenharmony_ci		err = skcipher_walk_done(&walk, nbytes);
13862306a36Sopenharmony_ci	}
13962306a36Sopenharmony_ci
14062306a36Sopenharmony_ci	return err;
14162306a36Sopenharmony_ci}
14262306a36Sopenharmony_ci
14362306a36Sopenharmony_cistatic int sm4_ecb_encrypt(struct skcipher_request *req)
14462306a36Sopenharmony_ci{
14562306a36Sopenharmony_ci	struct crypto_skcipher *tfm = crypto_skcipher_reqtfm(req);
14662306a36Sopenharmony_ci	struct sm4_ctx *ctx = crypto_skcipher_ctx(tfm);
14762306a36Sopenharmony_ci
14862306a36Sopenharmony_ci	return sm4_ecb_do_crypt(req, ctx->rkey_enc);
14962306a36Sopenharmony_ci}
15062306a36Sopenharmony_ci
15162306a36Sopenharmony_cistatic int sm4_ecb_decrypt(struct skcipher_request *req)
15262306a36Sopenharmony_ci{
15362306a36Sopenharmony_ci	struct crypto_skcipher *tfm = crypto_skcipher_reqtfm(req);
15462306a36Sopenharmony_ci	struct sm4_ctx *ctx = crypto_skcipher_ctx(tfm);
15562306a36Sopenharmony_ci
15662306a36Sopenharmony_ci	return sm4_ecb_do_crypt(req, ctx->rkey_dec);
15762306a36Sopenharmony_ci}
15862306a36Sopenharmony_ci
15962306a36Sopenharmony_cistatic int sm4_cbc_crypt(struct skcipher_request *req,
16062306a36Sopenharmony_ci			 struct sm4_ctx *ctx, bool encrypt)
16162306a36Sopenharmony_ci{
16262306a36Sopenharmony_ci	struct skcipher_walk walk;
16362306a36Sopenharmony_ci	unsigned int nbytes;
16462306a36Sopenharmony_ci	int err;
16562306a36Sopenharmony_ci
16662306a36Sopenharmony_ci	err = skcipher_walk_virt(&walk, req, false);
16762306a36Sopenharmony_ci	if (err)
16862306a36Sopenharmony_ci		return err;
16962306a36Sopenharmony_ci
17062306a36Sopenharmony_ci	while ((nbytes = walk.nbytes) > 0) {
17162306a36Sopenharmony_ci		const u8 *src = walk.src.virt.addr;
17262306a36Sopenharmony_ci		u8 *dst = walk.dst.virt.addr;
17362306a36Sopenharmony_ci		unsigned int nblocks;
17462306a36Sopenharmony_ci
17562306a36Sopenharmony_ci		nblocks = nbytes / SM4_BLOCK_SIZE;
17662306a36Sopenharmony_ci		if (nblocks) {
17762306a36Sopenharmony_ci			kernel_neon_begin();
17862306a36Sopenharmony_ci
17962306a36Sopenharmony_ci			if (encrypt)
18062306a36Sopenharmony_ci				sm4_ce_cbc_enc(ctx->rkey_enc, dst, src,
18162306a36Sopenharmony_ci					       walk.iv, nblocks);
18262306a36Sopenharmony_ci			else
18362306a36Sopenharmony_ci				sm4_ce_cbc_dec(ctx->rkey_dec, dst, src,
18462306a36Sopenharmony_ci					       walk.iv, nblocks);
18562306a36Sopenharmony_ci
18662306a36Sopenharmony_ci			kernel_neon_end();
18762306a36Sopenharmony_ci		}
18862306a36Sopenharmony_ci
18962306a36Sopenharmony_ci		err = skcipher_walk_done(&walk, nbytes % SM4_BLOCK_SIZE);
19062306a36Sopenharmony_ci	}
19162306a36Sopenharmony_ci
19262306a36Sopenharmony_ci	return err;
19362306a36Sopenharmony_ci}
19462306a36Sopenharmony_ci
19562306a36Sopenharmony_cistatic int sm4_cbc_encrypt(struct skcipher_request *req)
19662306a36Sopenharmony_ci{
19762306a36Sopenharmony_ci	struct crypto_skcipher *tfm = crypto_skcipher_reqtfm(req);
19862306a36Sopenharmony_ci	struct sm4_ctx *ctx = crypto_skcipher_ctx(tfm);
19962306a36Sopenharmony_ci
20062306a36Sopenharmony_ci	return sm4_cbc_crypt(req, ctx, true);
20162306a36Sopenharmony_ci}
20262306a36Sopenharmony_ci
20362306a36Sopenharmony_cistatic int sm4_cbc_decrypt(struct skcipher_request *req)
20462306a36Sopenharmony_ci{
20562306a36Sopenharmony_ci	struct crypto_skcipher *tfm = crypto_skcipher_reqtfm(req);
20662306a36Sopenharmony_ci	struct sm4_ctx *ctx = crypto_skcipher_ctx(tfm);
20762306a36Sopenharmony_ci
20862306a36Sopenharmony_ci	return sm4_cbc_crypt(req, ctx, false);
20962306a36Sopenharmony_ci}
21062306a36Sopenharmony_ci
21162306a36Sopenharmony_cistatic int sm4_cbc_cts_crypt(struct skcipher_request *req, bool encrypt)
21262306a36Sopenharmony_ci{
21362306a36Sopenharmony_ci	struct crypto_skcipher *tfm = crypto_skcipher_reqtfm(req);
21462306a36Sopenharmony_ci	struct sm4_ctx *ctx = crypto_skcipher_ctx(tfm);
21562306a36Sopenharmony_ci	struct scatterlist *src = req->src;
21662306a36Sopenharmony_ci	struct scatterlist *dst = req->dst;
21762306a36Sopenharmony_ci	struct scatterlist sg_src[2], sg_dst[2];
21862306a36Sopenharmony_ci	struct skcipher_request subreq;
21962306a36Sopenharmony_ci	struct skcipher_walk walk;
22062306a36Sopenharmony_ci	int cbc_blocks;
22162306a36Sopenharmony_ci	int err;
22262306a36Sopenharmony_ci
22362306a36Sopenharmony_ci	if (req->cryptlen < SM4_BLOCK_SIZE)
22462306a36Sopenharmony_ci		return -EINVAL;
22562306a36Sopenharmony_ci
22662306a36Sopenharmony_ci	if (req->cryptlen == SM4_BLOCK_SIZE)
22762306a36Sopenharmony_ci		return sm4_cbc_crypt(req, ctx, encrypt);
22862306a36Sopenharmony_ci
22962306a36Sopenharmony_ci	skcipher_request_set_tfm(&subreq, tfm);
23062306a36Sopenharmony_ci	skcipher_request_set_callback(&subreq, skcipher_request_flags(req),
23162306a36Sopenharmony_ci				      NULL, NULL);
23262306a36Sopenharmony_ci
23362306a36Sopenharmony_ci	/* handle the CBC cryption part */
23462306a36Sopenharmony_ci	cbc_blocks = DIV_ROUND_UP(req->cryptlen, SM4_BLOCK_SIZE) - 2;
23562306a36Sopenharmony_ci	if (cbc_blocks) {
23662306a36Sopenharmony_ci		skcipher_request_set_crypt(&subreq, src, dst,
23762306a36Sopenharmony_ci					   cbc_blocks * SM4_BLOCK_SIZE,
23862306a36Sopenharmony_ci					   req->iv);
23962306a36Sopenharmony_ci
24062306a36Sopenharmony_ci		err = sm4_cbc_crypt(&subreq, ctx, encrypt);
24162306a36Sopenharmony_ci		if (err)
24262306a36Sopenharmony_ci			return err;
24362306a36Sopenharmony_ci
24462306a36Sopenharmony_ci		dst = src = scatterwalk_ffwd(sg_src, src, subreq.cryptlen);
24562306a36Sopenharmony_ci		if (req->dst != req->src)
24662306a36Sopenharmony_ci			dst = scatterwalk_ffwd(sg_dst, req->dst,
24762306a36Sopenharmony_ci					       subreq.cryptlen);
24862306a36Sopenharmony_ci	}
24962306a36Sopenharmony_ci
25062306a36Sopenharmony_ci	/* handle ciphertext stealing */
25162306a36Sopenharmony_ci	skcipher_request_set_crypt(&subreq, src, dst,
25262306a36Sopenharmony_ci				   req->cryptlen - cbc_blocks * SM4_BLOCK_SIZE,
25362306a36Sopenharmony_ci				   req->iv);
25462306a36Sopenharmony_ci
25562306a36Sopenharmony_ci	err = skcipher_walk_virt(&walk, &subreq, false);
25662306a36Sopenharmony_ci	if (err)
25762306a36Sopenharmony_ci		return err;
25862306a36Sopenharmony_ci
25962306a36Sopenharmony_ci	kernel_neon_begin();
26062306a36Sopenharmony_ci
26162306a36Sopenharmony_ci	if (encrypt)
26262306a36Sopenharmony_ci		sm4_ce_cbc_cts_enc(ctx->rkey_enc, walk.dst.virt.addr,
26362306a36Sopenharmony_ci				   walk.src.virt.addr, walk.iv, walk.nbytes);
26462306a36Sopenharmony_ci	else
26562306a36Sopenharmony_ci		sm4_ce_cbc_cts_dec(ctx->rkey_dec, walk.dst.virt.addr,
26662306a36Sopenharmony_ci				   walk.src.virt.addr, walk.iv, walk.nbytes);
26762306a36Sopenharmony_ci
26862306a36Sopenharmony_ci	kernel_neon_end();
26962306a36Sopenharmony_ci
27062306a36Sopenharmony_ci	return skcipher_walk_done(&walk, 0);
27162306a36Sopenharmony_ci}
27262306a36Sopenharmony_ci
27362306a36Sopenharmony_cistatic int sm4_cbc_cts_encrypt(struct skcipher_request *req)
27462306a36Sopenharmony_ci{
27562306a36Sopenharmony_ci	return sm4_cbc_cts_crypt(req, true);
27662306a36Sopenharmony_ci}
27762306a36Sopenharmony_ci
27862306a36Sopenharmony_cistatic int sm4_cbc_cts_decrypt(struct skcipher_request *req)
27962306a36Sopenharmony_ci{
28062306a36Sopenharmony_ci	return sm4_cbc_cts_crypt(req, false);
28162306a36Sopenharmony_ci}
28262306a36Sopenharmony_ci
28362306a36Sopenharmony_cistatic int sm4_cfb_encrypt(struct skcipher_request *req)
28462306a36Sopenharmony_ci{
28562306a36Sopenharmony_ci	struct crypto_skcipher *tfm = crypto_skcipher_reqtfm(req);
28662306a36Sopenharmony_ci	struct sm4_ctx *ctx = crypto_skcipher_ctx(tfm);
28762306a36Sopenharmony_ci	struct skcipher_walk walk;
28862306a36Sopenharmony_ci	unsigned int nbytes;
28962306a36Sopenharmony_ci	int err;
29062306a36Sopenharmony_ci
29162306a36Sopenharmony_ci	err = skcipher_walk_virt(&walk, req, false);
29262306a36Sopenharmony_ci
29362306a36Sopenharmony_ci	while ((nbytes = walk.nbytes) > 0) {
29462306a36Sopenharmony_ci		const u8 *src = walk.src.virt.addr;
29562306a36Sopenharmony_ci		u8 *dst = walk.dst.virt.addr;
29662306a36Sopenharmony_ci		unsigned int nblks;
29762306a36Sopenharmony_ci
29862306a36Sopenharmony_ci		kernel_neon_begin();
29962306a36Sopenharmony_ci
30062306a36Sopenharmony_ci		nblks = BYTES2BLKS(nbytes);
30162306a36Sopenharmony_ci		if (nblks) {
30262306a36Sopenharmony_ci			sm4_ce_cfb_enc(ctx->rkey_enc, dst, src, walk.iv, nblks);
30362306a36Sopenharmony_ci			dst += nblks * SM4_BLOCK_SIZE;
30462306a36Sopenharmony_ci			src += nblks * SM4_BLOCK_SIZE;
30562306a36Sopenharmony_ci			nbytes -= nblks * SM4_BLOCK_SIZE;
30662306a36Sopenharmony_ci		}
30762306a36Sopenharmony_ci
30862306a36Sopenharmony_ci		/* tail */
30962306a36Sopenharmony_ci		if (walk.nbytes == walk.total && nbytes > 0) {
31062306a36Sopenharmony_ci			u8 keystream[SM4_BLOCK_SIZE];
31162306a36Sopenharmony_ci
31262306a36Sopenharmony_ci			sm4_ce_crypt_block(ctx->rkey_enc, keystream, walk.iv);
31362306a36Sopenharmony_ci			crypto_xor_cpy(dst, src, keystream, nbytes);
31462306a36Sopenharmony_ci			nbytes = 0;
31562306a36Sopenharmony_ci		}
31662306a36Sopenharmony_ci
31762306a36Sopenharmony_ci		kernel_neon_end();
31862306a36Sopenharmony_ci
31962306a36Sopenharmony_ci		err = skcipher_walk_done(&walk, nbytes);
32062306a36Sopenharmony_ci	}
32162306a36Sopenharmony_ci
32262306a36Sopenharmony_ci	return err;
32362306a36Sopenharmony_ci}
32462306a36Sopenharmony_ci
32562306a36Sopenharmony_cistatic int sm4_cfb_decrypt(struct skcipher_request *req)
32662306a36Sopenharmony_ci{
32762306a36Sopenharmony_ci	struct crypto_skcipher *tfm = crypto_skcipher_reqtfm(req);
32862306a36Sopenharmony_ci	struct sm4_ctx *ctx = crypto_skcipher_ctx(tfm);
32962306a36Sopenharmony_ci	struct skcipher_walk walk;
33062306a36Sopenharmony_ci	unsigned int nbytes;
33162306a36Sopenharmony_ci	int err;
33262306a36Sopenharmony_ci
33362306a36Sopenharmony_ci	err = skcipher_walk_virt(&walk, req, false);
33462306a36Sopenharmony_ci
33562306a36Sopenharmony_ci	while ((nbytes = walk.nbytes) > 0) {
33662306a36Sopenharmony_ci		const u8 *src = walk.src.virt.addr;
33762306a36Sopenharmony_ci		u8 *dst = walk.dst.virt.addr;
33862306a36Sopenharmony_ci		unsigned int nblks;
33962306a36Sopenharmony_ci
34062306a36Sopenharmony_ci		kernel_neon_begin();
34162306a36Sopenharmony_ci
34262306a36Sopenharmony_ci		nblks = BYTES2BLKS(nbytes);
34362306a36Sopenharmony_ci		if (nblks) {
34462306a36Sopenharmony_ci			sm4_ce_cfb_dec(ctx->rkey_enc, dst, src, walk.iv, nblks);
34562306a36Sopenharmony_ci			dst += nblks * SM4_BLOCK_SIZE;
34662306a36Sopenharmony_ci			src += nblks * SM4_BLOCK_SIZE;
34762306a36Sopenharmony_ci			nbytes -= nblks * SM4_BLOCK_SIZE;
34862306a36Sopenharmony_ci		}
34962306a36Sopenharmony_ci
35062306a36Sopenharmony_ci		/* tail */
35162306a36Sopenharmony_ci		if (walk.nbytes == walk.total && nbytes > 0) {
35262306a36Sopenharmony_ci			u8 keystream[SM4_BLOCK_SIZE];
35362306a36Sopenharmony_ci
35462306a36Sopenharmony_ci			sm4_ce_crypt_block(ctx->rkey_enc, keystream, walk.iv);
35562306a36Sopenharmony_ci			crypto_xor_cpy(dst, src, keystream, nbytes);
35662306a36Sopenharmony_ci			nbytes = 0;
35762306a36Sopenharmony_ci		}
35862306a36Sopenharmony_ci
35962306a36Sopenharmony_ci		kernel_neon_end();
36062306a36Sopenharmony_ci
36162306a36Sopenharmony_ci		err = skcipher_walk_done(&walk, nbytes);
36262306a36Sopenharmony_ci	}
36362306a36Sopenharmony_ci
36462306a36Sopenharmony_ci	return err;
36562306a36Sopenharmony_ci}
36662306a36Sopenharmony_ci
36762306a36Sopenharmony_cistatic int sm4_ctr_crypt(struct skcipher_request *req)
36862306a36Sopenharmony_ci{
36962306a36Sopenharmony_ci	struct crypto_skcipher *tfm = crypto_skcipher_reqtfm(req);
37062306a36Sopenharmony_ci	struct sm4_ctx *ctx = crypto_skcipher_ctx(tfm);
37162306a36Sopenharmony_ci	struct skcipher_walk walk;
37262306a36Sopenharmony_ci	unsigned int nbytes;
37362306a36Sopenharmony_ci	int err;
37462306a36Sopenharmony_ci
37562306a36Sopenharmony_ci	err = skcipher_walk_virt(&walk, req, false);
37662306a36Sopenharmony_ci
37762306a36Sopenharmony_ci	while ((nbytes = walk.nbytes) > 0) {
37862306a36Sopenharmony_ci		const u8 *src = walk.src.virt.addr;
37962306a36Sopenharmony_ci		u8 *dst = walk.dst.virt.addr;
38062306a36Sopenharmony_ci		unsigned int nblks;
38162306a36Sopenharmony_ci
38262306a36Sopenharmony_ci		kernel_neon_begin();
38362306a36Sopenharmony_ci
38462306a36Sopenharmony_ci		nblks = BYTES2BLKS(nbytes);
38562306a36Sopenharmony_ci		if (nblks) {
38662306a36Sopenharmony_ci			sm4_ce_ctr_enc(ctx->rkey_enc, dst, src, walk.iv, nblks);
38762306a36Sopenharmony_ci			dst += nblks * SM4_BLOCK_SIZE;
38862306a36Sopenharmony_ci			src += nblks * SM4_BLOCK_SIZE;
38962306a36Sopenharmony_ci			nbytes -= nblks * SM4_BLOCK_SIZE;
39062306a36Sopenharmony_ci		}
39162306a36Sopenharmony_ci
39262306a36Sopenharmony_ci		/* tail */
39362306a36Sopenharmony_ci		if (walk.nbytes == walk.total && nbytes > 0) {
39462306a36Sopenharmony_ci			u8 keystream[SM4_BLOCK_SIZE];
39562306a36Sopenharmony_ci
39662306a36Sopenharmony_ci			sm4_ce_crypt_block(ctx->rkey_enc, keystream, walk.iv);
39762306a36Sopenharmony_ci			crypto_inc(walk.iv, SM4_BLOCK_SIZE);
39862306a36Sopenharmony_ci			crypto_xor_cpy(dst, src, keystream, nbytes);
39962306a36Sopenharmony_ci			nbytes = 0;
40062306a36Sopenharmony_ci		}
40162306a36Sopenharmony_ci
40262306a36Sopenharmony_ci		kernel_neon_end();
40362306a36Sopenharmony_ci
40462306a36Sopenharmony_ci		err = skcipher_walk_done(&walk, nbytes);
40562306a36Sopenharmony_ci	}
40662306a36Sopenharmony_ci
40762306a36Sopenharmony_ci	return err;
40862306a36Sopenharmony_ci}
40962306a36Sopenharmony_ci
41062306a36Sopenharmony_cistatic int sm4_xts_crypt(struct skcipher_request *req, bool encrypt)
41162306a36Sopenharmony_ci{
41262306a36Sopenharmony_ci	struct crypto_skcipher *tfm = crypto_skcipher_reqtfm(req);
41362306a36Sopenharmony_ci	struct sm4_xts_ctx *ctx = crypto_skcipher_ctx(tfm);
41462306a36Sopenharmony_ci	int tail = req->cryptlen % SM4_BLOCK_SIZE;
41562306a36Sopenharmony_ci	const u32 *rkey2_enc = ctx->key2.rkey_enc;
41662306a36Sopenharmony_ci	struct scatterlist sg_src[2], sg_dst[2];
41762306a36Sopenharmony_ci	struct skcipher_request subreq;
41862306a36Sopenharmony_ci	struct scatterlist *src, *dst;
41962306a36Sopenharmony_ci	struct skcipher_walk walk;
42062306a36Sopenharmony_ci	unsigned int nbytes;
42162306a36Sopenharmony_ci	int err;
42262306a36Sopenharmony_ci
42362306a36Sopenharmony_ci	if (req->cryptlen < SM4_BLOCK_SIZE)
42462306a36Sopenharmony_ci		return -EINVAL;
42562306a36Sopenharmony_ci
42662306a36Sopenharmony_ci	err = skcipher_walk_virt(&walk, req, false);
42762306a36Sopenharmony_ci	if (err)
42862306a36Sopenharmony_ci		return err;
42962306a36Sopenharmony_ci
43062306a36Sopenharmony_ci	if (unlikely(tail > 0 && walk.nbytes < walk.total)) {
43162306a36Sopenharmony_ci		int nblocks = DIV_ROUND_UP(req->cryptlen, SM4_BLOCK_SIZE) - 2;
43262306a36Sopenharmony_ci
43362306a36Sopenharmony_ci		skcipher_walk_abort(&walk);
43462306a36Sopenharmony_ci
43562306a36Sopenharmony_ci		skcipher_request_set_tfm(&subreq, tfm);
43662306a36Sopenharmony_ci		skcipher_request_set_callback(&subreq,
43762306a36Sopenharmony_ci					      skcipher_request_flags(req),
43862306a36Sopenharmony_ci					      NULL, NULL);
43962306a36Sopenharmony_ci		skcipher_request_set_crypt(&subreq, req->src, req->dst,
44062306a36Sopenharmony_ci					   nblocks * SM4_BLOCK_SIZE, req->iv);
44162306a36Sopenharmony_ci
44262306a36Sopenharmony_ci		err = skcipher_walk_virt(&walk, &subreq, false);
44362306a36Sopenharmony_ci		if (err)
44462306a36Sopenharmony_ci			return err;
44562306a36Sopenharmony_ci	} else {
44662306a36Sopenharmony_ci		tail = 0;
44762306a36Sopenharmony_ci	}
44862306a36Sopenharmony_ci
44962306a36Sopenharmony_ci	while ((nbytes = walk.nbytes) >= SM4_BLOCK_SIZE) {
45062306a36Sopenharmony_ci		if (nbytes < walk.total)
45162306a36Sopenharmony_ci			nbytes &= ~(SM4_BLOCK_SIZE - 1);
45262306a36Sopenharmony_ci
45362306a36Sopenharmony_ci		kernel_neon_begin();
45462306a36Sopenharmony_ci
45562306a36Sopenharmony_ci		if (encrypt)
45662306a36Sopenharmony_ci			sm4_ce_xts_enc(ctx->key1.rkey_enc, walk.dst.virt.addr,
45762306a36Sopenharmony_ci				       walk.src.virt.addr, walk.iv, nbytes,
45862306a36Sopenharmony_ci				       rkey2_enc);
45962306a36Sopenharmony_ci		else
46062306a36Sopenharmony_ci			sm4_ce_xts_dec(ctx->key1.rkey_dec, walk.dst.virt.addr,
46162306a36Sopenharmony_ci				       walk.src.virt.addr, walk.iv, nbytes,
46262306a36Sopenharmony_ci				       rkey2_enc);
46362306a36Sopenharmony_ci
46462306a36Sopenharmony_ci		kernel_neon_end();
46562306a36Sopenharmony_ci
46662306a36Sopenharmony_ci		rkey2_enc = NULL;
46762306a36Sopenharmony_ci
46862306a36Sopenharmony_ci		err = skcipher_walk_done(&walk, walk.nbytes - nbytes);
46962306a36Sopenharmony_ci		if (err)
47062306a36Sopenharmony_ci			return err;
47162306a36Sopenharmony_ci	}
47262306a36Sopenharmony_ci
47362306a36Sopenharmony_ci	if (likely(tail == 0))
47462306a36Sopenharmony_ci		return 0;
47562306a36Sopenharmony_ci
47662306a36Sopenharmony_ci	/* handle ciphertext stealing */
47762306a36Sopenharmony_ci
47862306a36Sopenharmony_ci	dst = src = scatterwalk_ffwd(sg_src, req->src, subreq.cryptlen);
47962306a36Sopenharmony_ci	if (req->dst != req->src)
48062306a36Sopenharmony_ci		dst = scatterwalk_ffwd(sg_dst, req->dst, subreq.cryptlen);
48162306a36Sopenharmony_ci
48262306a36Sopenharmony_ci	skcipher_request_set_crypt(&subreq, src, dst, SM4_BLOCK_SIZE + tail,
48362306a36Sopenharmony_ci				   req->iv);
48462306a36Sopenharmony_ci
48562306a36Sopenharmony_ci	err = skcipher_walk_virt(&walk, &subreq, false);
48662306a36Sopenharmony_ci	if (err)
48762306a36Sopenharmony_ci		return err;
48862306a36Sopenharmony_ci
48962306a36Sopenharmony_ci	kernel_neon_begin();
49062306a36Sopenharmony_ci
49162306a36Sopenharmony_ci	if (encrypt)
49262306a36Sopenharmony_ci		sm4_ce_xts_enc(ctx->key1.rkey_enc, walk.dst.virt.addr,
49362306a36Sopenharmony_ci			       walk.src.virt.addr, walk.iv, walk.nbytes,
49462306a36Sopenharmony_ci			       rkey2_enc);
49562306a36Sopenharmony_ci	else
49662306a36Sopenharmony_ci		sm4_ce_xts_dec(ctx->key1.rkey_dec, walk.dst.virt.addr,
49762306a36Sopenharmony_ci			       walk.src.virt.addr, walk.iv, walk.nbytes,
49862306a36Sopenharmony_ci			       rkey2_enc);
49962306a36Sopenharmony_ci
50062306a36Sopenharmony_ci	kernel_neon_end();
50162306a36Sopenharmony_ci
50262306a36Sopenharmony_ci	return skcipher_walk_done(&walk, 0);
50362306a36Sopenharmony_ci}
50462306a36Sopenharmony_ci
50562306a36Sopenharmony_cistatic int sm4_xts_encrypt(struct skcipher_request *req)
50662306a36Sopenharmony_ci{
50762306a36Sopenharmony_ci	return sm4_xts_crypt(req, true);
50862306a36Sopenharmony_ci}
50962306a36Sopenharmony_ci
51062306a36Sopenharmony_cistatic int sm4_xts_decrypt(struct skcipher_request *req)
51162306a36Sopenharmony_ci{
51262306a36Sopenharmony_ci	return sm4_xts_crypt(req, false);
51362306a36Sopenharmony_ci}
51462306a36Sopenharmony_ci
51562306a36Sopenharmony_cistatic struct skcipher_alg sm4_algs[] = {
51662306a36Sopenharmony_ci	{
51762306a36Sopenharmony_ci		.base = {
51862306a36Sopenharmony_ci			.cra_name		= "ecb(sm4)",
51962306a36Sopenharmony_ci			.cra_driver_name	= "ecb-sm4-ce",
52062306a36Sopenharmony_ci			.cra_priority		= 400,
52162306a36Sopenharmony_ci			.cra_blocksize		= SM4_BLOCK_SIZE,
52262306a36Sopenharmony_ci			.cra_ctxsize		= sizeof(struct sm4_ctx),
52362306a36Sopenharmony_ci			.cra_module		= THIS_MODULE,
52462306a36Sopenharmony_ci		},
52562306a36Sopenharmony_ci		.min_keysize	= SM4_KEY_SIZE,
52662306a36Sopenharmony_ci		.max_keysize	= SM4_KEY_SIZE,
52762306a36Sopenharmony_ci		.setkey		= sm4_setkey,
52862306a36Sopenharmony_ci		.encrypt	= sm4_ecb_encrypt,
52962306a36Sopenharmony_ci		.decrypt	= sm4_ecb_decrypt,
53062306a36Sopenharmony_ci	}, {
53162306a36Sopenharmony_ci		.base = {
53262306a36Sopenharmony_ci			.cra_name		= "cbc(sm4)",
53362306a36Sopenharmony_ci			.cra_driver_name	= "cbc-sm4-ce",
53462306a36Sopenharmony_ci			.cra_priority		= 400,
53562306a36Sopenharmony_ci			.cra_blocksize		= SM4_BLOCK_SIZE,
53662306a36Sopenharmony_ci			.cra_ctxsize		= sizeof(struct sm4_ctx),
53762306a36Sopenharmony_ci			.cra_module		= THIS_MODULE,
53862306a36Sopenharmony_ci		},
53962306a36Sopenharmony_ci		.min_keysize	= SM4_KEY_SIZE,
54062306a36Sopenharmony_ci		.max_keysize	= SM4_KEY_SIZE,
54162306a36Sopenharmony_ci		.ivsize		= SM4_BLOCK_SIZE,
54262306a36Sopenharmony_ci		.setkey		= sm4_setkey,
54362306a36Sopenharmony_ci		.encrypt	= sm4_cbc_encrypt,
54462306a36Sopenharmony_ci		.decrypt	= sm4_cbc_decrypt,
54562306a36Sopenharmony_ci	}, {
54662306a36Sopenharmony_ci		.base = {
54762306a36Sopenharmony_ci			.cra_name		= "cfb(sm4)",
54862306a36Sopenharmony_ci			.cra_driver_name	= "cfb-sm4-ce",
54962306a36Sopenharmony_ci			.cra_priority		= 400,
55062306a36Sopenharmony_ci			.cra_blocksize		= 1,
55162306a36Sopenharmony_ci			.cra_ctxsize		= sizeof(struct sm4_ctx),
55262306a36Sopenharmony_ci			.cra_module		= THIS_MODULE,
55362306a36Sopenharmony_ci		},
55462306a36Sopenharmony_ci		.min_keysize	= SM4_KEY_SIZE,
55562306a36Sopenharmony_ci		.max_keysize	= SM4_KEY_SIZE,
55662306a36Sopenharmony_ci		.ivsize		= SM4_BLOCK_SIZE,
55762306a36Sopenharmony_ci		.chunksize	= SM4_BLOCK_SIZE,
55862306a36Sopenharmony_ci		.setkey		= sm4_setkey,
55962306a36Sopenharmony_ci		.encrypt	= sm4_cfb_encrypt,
56062306a36Sopenharmony_ci		.decrypt	= sm4_cfb_decrypt,
56162306a36Sopenharmony_ci	}, {
56262306a36Sopenharmony_ci		.base = {
56362306a36Sopenharmony_ci			.cra_name		= "ctr(sm4)",
56462306a36Sopenharmony_ci			.cra_driver_name	= "ctr-sm4-ce",
56562306a36Sopenharmony_ci			.cra_priority		= 400,
56662306a36Sopenharmony_ci			.cra_blocksize		= 1,
56762306a36Sopenharmony_ci			.cra_ctxsize		= sizeof(struct sm4_ctx),
56862306a36Sopenharmony_ci			.cra_module		= THIS_MODULE,
56962306a36Sopenharmony_ci		},
57062306a36Sopenharmony_ci		.min_keysize	= SM4_KEY_SIZE,
57162306a36Sopenharmony_ci		.max_keysize	= SM4_KEY_SIZE,
57262306a36Sopenharmony_ci		.ivsize		= SM4_BLOCK_SIZE,
57362306a36Sopenharmony_ci		.chunksize	= SM4_BLOCK_SIZE,
57462306a36Sopenharmony_ci		.setkey		= sm4_setkey,
57562306a36Sopenharmony_ci		.encrypt	= sm4_ctr_crypt,
57662306a36Sopenharmony_ci		.decrypt	= sm4_ctr_crypt,
57762306a36Sopenharmony_ci	}, {
57862306a36Sopenharmony_ci		.base = {
57962306a36Sopenharmony_ci			.cra_name		= "cts(cbc(sm4))",
58062306a36Sopenharmony_ci			.cra_driver_name	= "cts-cbc-sm4-ce",
58162306a36Sopenharmony_ci			.cra_priority		= 400,
58262306a36Sopenharmony_ci			.cra_blocksize		= SM4_BLOCK_SIZE,
58362306a36Sopenharmony_ci			.cra_ctxsize		= sizeof(struct sm4_ctx),
58462306a36Sopenharmony_ci			.cra_module		= THIS_MODULE,
58562306a36Sopenharmony_ci		},
58662306a36Sopenharmony_ci		.min_keysize	= SM4_KEY_SIZE,
58762306a36Sopenharmony_ci		.max_keysize	= SM4_KEY_SIZE,
58862306a36Sopenharmony_ci		.ivsize		= SM4_BLOCK_SIZE,
58962306a36Sopenharmony_ci		.walksize	= SM4_BLOCK_SIZE * 2,
59062306a36Sopenharmony_ci		.setkey		= sm4_setkey,
59162306a36Sopenharmony_ci		.encrypt	= sm4_cbc_cts_encrypt,
59262306a36Sopenharmony_ci		.decrypt	= sm4_cbc_cts_decrypt,
59362306a36Sopenharmony_ci	}, {
59462306a36Sopenharmony_ci		.base = {
59562306a36Sopenharmony_ci			.cra_name		= "xts(sm4)",
59662306a36Sopenharmony_ci			.cra_driver_name	= "xts-sm4-ce",
59762306a36Sopenharmony_ci			.cra_priority		= 400,
59862306a36Sopenharmony_ci			.cra_blocksize		= SM4_BLOCK_SIZE,
59962306a36Sopenharmony_ci			.cra_ctxsize		= sizeof(struct sm4_xts_ctx),
60062306a36Sopenharmony_ci			.cra_module		= THIS_MODULE,
60162306a36Sopenharmony_ci		},
60262306a36Sopenharmony_ci		.min_keysize	= SM4_KEY_SIZE * 2,
60362306a36Sopenharmony_ci		.max_keysize	= SM4_KEY_SIZE * 2,
60462306a36Sopenharmony_ci		.ivsize		= SM4_BLOCK_SIZE,
60562306a36Sopenharmony_ci		.walksize	= SM4_BLOCK_SIZE * 2,
60662306a36Sopenharmony_ci		.setkey		= sm4_xts_setkey,
60762306a36Sopenharmony_ci		.encrypt	= sm4_xts_encrypt,
60862306a36Sopenharmony_ci		.decrypt	= sm4_xts_decrypt,
60962306a36Sopenharmony_ci	}
61062306a36Sopenharmony_ci};
61162306a36Sopenharmony_ci
61262306a36Sopenharmony_cistatic int sm4_cbcmac_setkey(struct crypto_shash *tfm, const u8 *key,
61362306a36Sopenharmony_ci			     unsigned int key_len)
61462306a36Sopenharmony_ci{
61562306a36Sopenharmony_ci	struct sm4_mac_tfm_ctx *ctx = crypto_shash_ctx(tfm);
61662306a36Sopenharmony_ci
61762306a36Sopenharmony_ci	if (key_len != SM4_KEY_SIZE)
61862306a36Sopenharmony_ci		return -EINVAL;
61962306a36Sopenharmony_ci
62062306a36Sopenharmony_ci	kernel_neon_begin();
62162306a36Sopenharmony_ci	sm4_ce_expand_key(key, ctx->key.rkey_enc, ctx->key.rkey_dec,
62262306a36Sopenharmony_ci			  crypto_sm4_fk, crypto_sm4_ck);
62362306a36Sopenharmony_ci	kernel_neon_end();
62462306a36Sopenharmony_ci
62562306a36Sopenharmony_ci	return 0;
62662306a36Sopenharmony_ci}
62762306a36Sopenharmony_ci
62862306a36Sopenharmony_cistatic int sm4_cmac_setkey(struct crypto_shash *tfm, const u8 *key,
62962306a36Sopenharmony_ci			   unsigned int key_len)
63062306a36Sopenharmony_ci{
63162306a36Sopenharmony_ci	struct sm4_mac_tfm_ctx *ctx = crypto_shash_ctx(tfm);
63262306a36Sopenharmony_ci	be128 *consts = (be128 *)ctx->consts;
63362306a36Sopenharmony_ci	u64 a, b;
63462306a36Sopenharmony_ci
63562306a36Sopenharmony_ci	if (key_len != SM4_KEY_SIZE)
63662306a36Sopenharmony_ci		return -EINVAL;
63762306a36Sopenharmony_ci
63862306a36Sopenharmony_ci	memset(consts, 0, SM4_BLOCK_SIZE);
63962306a36Sopenharmony_ci
64062306a36Sopenharmony_ci	kernel_neon_begin();
64162306a36Sopenharmony_ci
64262306a36Sopenharmony_ci	sm4_ce_expand_key(key, ctx->key.rkey_enc, ctx->key.rkey_dec,
64362306a36Sopenharmony_ci			  crypto_sm4_fk, crypto_sm4_ck);
64462306a36Sopenharmony_ci
64562306a36Sopenharmony_ci	/* encrypt the zero block */
64662306a36Sopenharmony_ci	sm4_ce_crypt_block(ctx->key.rkey_enc, (u8 *)consts, (const u8 *)consts);
64762306a36Sopenharmony_ci
64862306a36Sopenharmony_ci	kernel_neon_end();
64962306a36Sopenharmony_ci
65062306a36Sopenharmony_ci	/* gf(2^128) multiply zero-ciphertext with u and u^2 */
65162306a36Sopenharmony_ci	a = be64_to_cpu(consts[0].a);
65262306a36Sopenharmony_ci	b = be64_to_cpu(consts[0].b);
65362306a36Sopenharmony_ci	consts[0].a = cpu_to_be64((a << 1) | (b >> 63));
65462306a36Sopenharmony_ci	consts[0].b = cpu_to_be64((b << 1) ^ ((a >> 63) ? 0x87 : 0));
65562306a36Sopenharmony_ci
65662306a36Sopenharmony_ci	a = be64_to_cpu(consts[0].a);
65762306a36Sopenharmony_ci	b = be64_to_cpu(consts[0].b);
65862306a36Sopenharmony_ci	consts[1].a = cpu_to_be64((a << 1) | (b >> 63));
65962306a36Sopenharmony_ci	consts[1].b = cpu_to_be64((b << 1) ^ ((a >> 63) ? 0x87 : 0));
66062306a36Sopenharmony_ci
66162306a36Sopenharmony_ci	return 0;
66262306a36Sopenharmony_ci}
66362306a36Sopenharmony_ci
66462306a36Sopenharmony_cistatic int sm4_xcbc_setkey(struct crypto_shash *tfm, const u8 *key,
66562306a36Sopenharmony_ci			   unsigned int key_len)
66662306a36Sopenharmony_ci{
66762306a36Sopenharmony_ci	struct sm4_mac_tfm_ctx *ctx = crypto_shash_ctx(tfm);
66862306a36Sopenharmony_ci	u8 __aligned(8) key2[SM4_BLOCK_SIZE];
66962306a36Sopenharmony_ci	static u8 const ks[3][SM4_BLOCK_SIZE] = {
67062306a36Sopenharmony_ci		{ [0 ... SM4_BLOCK_SIZE - 1] = 0x1},
67162306a36Sopenharmony_ci		{ [0 ... SM4_BLOCK_SIZE - 1] = 0x2},
67262306a36Sopenharmony_ci		{ [0 ... SM4_BLOCK_SIZE - 1] = 0x3},
67362306a36Sopenharmony_ci	};
67462306a36Sopenharmony_ci
67562306a36Sopenharmony_ci	if (key_len != SM4_KEY_SIZE)
67662306a36Sopenharmony_ci		return -EINVAL;
67762306a36Sopenharmony_ci
67862306a36Sopenharmony_ci	kernel_neon_begin();
67962306a36Sopenharmony_ci
68062306a36Sopenharmony_ci	sm4_ce_expand_key(key, ctx->key.rkey_enc, ctx->key.rkey_dec,
68162306a36Sopenharmony_ci			  crypto_sm4_fk, crypto_sm4_ck);
68262306a36Sopenharmony_ci
68362306a36Sopenharmony_ci	sm4_ce_crypt_block(ctx->key.rkey_enc, key2, ks[0]);
68462306a36Sopenharmony_ci	sm4_ce_crypt(ctx->key.rkey_enc, ctx->consts, ks[1], 2);
68562306a36Sopenharmony_ci
68662306a36Sopenharmony_ci	sm4_ce_expand_key(key2, ctx->key.rkey_enc, ctx->key.rkey_dec,
68762306a36Sopenharmony_ci			  crypto_sm4_fk, crypto_sm4_ck);
68862306a36Sopenharmony_ci
68962306a36Sopenharmony_ci	kernel_neon_end();
69062306a36Sopenharmony_ci
69162306a36Sopenharmony_ci	return 0;
69262306a36Sopenharmony_ci}
69362306a36Sopenharmony_ci
69462306a36Sopenharmony_cistatic int sm4_mac_init(struct shash_desc *desc)
69562306a36Sopenharmony_ci{
69662306a36Sopenharmony_ci	struct sm4_mac_desc_ctx *ctx = shash_desc_ctx(desc);
69762306a36Sopenharmony_ci
69862306a36Sopenharmony_ci	memset(ctx->digest, 0, SM4_BLOCK_SIZE);
69962306a36Sopenharmony_ci	ctx->len = 0;
70062306a36Sopenharmony_ci
70162306a36Sopenharmony_ci	return 0;
70262306a36Sopenharmony_ci}
70362306a36Sopenharmony_ci
70462306a36Sopenharmony_cistatic int sm4_mac_update(struct shash_desc *desc, const u8 *p,
70562306a36Sopenharmony_ci			  unsigned int len)
70662306a36Sopenharmony_ci{
70762306a36Sopenharmony_ci	struct sm4_mac_tfm_ctx *tctx = crypto_shash_ctx(desc->tfm);
70862306a36Sopenharmony_ci	struct sm4_mac_desc_ctx *ctx = shash_desc_ctx(desc);
70962306a36Sopenharmony_ci	unsigned int l, nblocks;
71062306a36Sopenharmony_ci
71162306a36Sopenharmony_ci	if (len == 0)
71262306a36Sopenharmony_ci		return 0;
71362306a36Sopenharmony_ci
71462306a36Sopenharmony_ci	if (ctx->len || ctx->len + len < SM4_BLOCK_SIZE) {
71562306a36Sopenharmony_ci		l = min(len, SM4_BLOCK_SIZE - ctx->len);
71662306a36Sopenharmony_ci
71762306a36Sopenharmony_ci		crypto_xor(ctx->digest + ctx->len, p, l);
71862306a36Sopenharmony_ci		ctx->len += l;
71962306a36Sopenharmony_ci		len -= l;
72062306a36Sopenharmony_ci		p += l;
72162306a36Sopenharmony_ci	}
72262306a36Sopenharmony_ci
72362306a36Sopenharmony_ci	if (len && (ctx->len % SM4_BLOCK_SIZE) == 0) {
72462306a36Sopenharmony_ci		kernel_neon_begin();
72562306a36Sopenharmony_ci
72662306a36Sopenharmony_ci		if (len < SM4_BLOCK_SIZE && ctx->len == SM4_BLOCK_SIZE) {
72762306a36Sopenharmony_ci			sm4_ce_crypt_block(tctx->key.rkey_enc,
72862306a36Sopenharmony_ci					   ctx->digest, ctx->digest);
72962306a36Sopenharmony_ci			ctx->len = 0;
73062306a36Sopenharmony_ci		} else {
73162306a36Sopenharmony_ci			nblocks = len / SM4_BLOCK_SIZE;
73262306a36Sopenharmony_ci			len %= SM4_BLOCK_SIZE;
73362306a36Sopenharmony_ci
73462306a36Sopenharmony_ci			sm4_ce_mac_update(tctx->key.rkey_enc, ctx->digest, p,
73562306a36Sopenharmony_ci					  nblocks, (ctx->len == SM4_BLOCK_SIZE),
73662306a36Sopenharmony_ci					  (len != 0));
73762306a36Sopenharmony_ci
73862306a36Sopenharmony_ci			p += nblocks * SM4_BLOCK_SIZE;
73962306a36Sopenharmony_ci
74062306a36Sopenharmony_ci			if (len == 0)
74162306a36Sopenharmony_ci				ctx->len = SM4_BLOCK_SIZE;
74262306a36Sopenharmony_ci		}
74362306a36Sopenharmony_ci
74462306a36Sopenharmony_ci		kernel_neon_end();
74562306a36Sopenharmony_ci
74662306a36Sopenharmony_ci		if (len) {
74762306a36Sopenharmony_ci			crypto_xor(ctx->digest, p, len);
74862306a36Sopenharmony_ci			ctx->len = len;
74962306a36Sopenharmony_ci		}
75062306a36Sopenharmony_ci	}
75162306a36Sopenharmony_ci
75262306a36Sopenharmony_ci	return 0;
75362306a36Sopenharmony_ci}
75462306a36Sopenharmony_ci
75562306a36Sopenharmony_cistatic int sm4_cmac_final(struct shash_desc *desc, u8 *out)
75662306a36Sopenharmony_ci{
75762306a36Sopenharmony_ci	struct sm4_mac_tfm_ctx *tctx = crypto_shash_ctx(desc->tfm);
75862306a36Sopenharmony_ci	struct sm4_mac_desc_ctx *ctx = shash_desc_ctx(desc);
75962306a36Sopenharmony_ci	const u8 *consts = tctx->consts;
76062306a36Sopenharmony_ci
76162306a36Sopenharmony_ci	if (ctx->len != SM4_BLOCK_SIZE) {
76262306a36Sopenharmony_ci		ctx->digest[ctx->len] ^= 0x80;
76362306a36Sopenharmony_ci		consts += SM4_BLOCK_SIZE;
76462306a36Sopenharmony_ci	}
76562306a36Sopenharmony_ci
76662306a36Sopenharmony_ci	kernel_neon_begin();
76762306a36Sopenharmony_ci	sm4_ce_mac_update(tctx->key.rkey_enc, ctx->digest, consts, 1,
76862306a36Sopenharmony_ci			  false, true);
76962306a36Sopenharmony_ci	kernel_neon_end();
77062306a36Sopenharmony_ci
77162306a36Sopenharmony_ci	memcpy(out, ctx->digest, SM4_BLOCK_SIZE);
77262306a36Sopenharmony_ci
77362306a36Sopenharmony_ci	return 0;
77462306a36Sopenharmony_ci}
77562306a36Sopenharmony_ci
77662306a36Sopenharmony_cistatic int sm4_cbcmac_final(struct shash_desc *desc, u8 *out)
77762306a36Sopenharmony_ci{
77862306a36Sopenharmony_ci	struct sm4_mac_tfm_ctx *tctx = crypto_shash_ctx(desc->tfm);
77962306a36Sopenharmony_ci	struct sm4_mac_desc_ctx *ctx = shash_desc_ctx(desc);
78062306a36Sopenharmony_ci
78162306a36Sopenharmony_ci	if (ctx->len) {
78262306a36Sopenharmony_ci		kernel_neon_begin();
78362306a36Sopenharmony_ci		sm4_ce_crypt_block(tctx->key.rkey_enc, ctx->digest,
78462306a36Sopenharmony_ci				   ctx->digest);
78562306a36Sopenharmony_ci		kernel_neon_end();
78662306a36Sopenharmony_ci	}
78762306a36Sopenharmony_ci
78862306a36Sopenharmony_ci	memcpy(out, ctx->digest, SM4_BLOCK_SIZE);
78962306a36Sopenharmony_ci
79062306a36Sopenharmony_ci	return 0;
79162306a36Sopenharmony_ci}
79262306a36Sopenharmony_ci
79362306a36Sopenharmony_cistatic struct shash_alg sm4_mac_algs[] = {
79462306a36Sopenharmony_ci	{
79562306a36Sopenharmony_ci		.base = {
79662306a36Sopenharmony_ci			.cra_name		= "cmac(sm4)",
79762306a36Sopenharmony_ci			.cra_driver_name	= "cmac-sm4-ce",
79862306a36Sopenharmony_ci			.cra_priority		= 400,
79962306a36Sopenharmony_ci			.cra_blocksize		= SM4_BLOCK_SIZE,
80062306a36Sopenharmony_ci			.cra_ctxsize		= sizeof(struct sm4_mac_tfm_ctx)
80162306a36Sopenharmony_ci							+ SM4_BLOCK_SIZE * 2,
80262306a36Sopenharmony_ci			.cra_module		= THIS_MODULE,
80362306a36Sopenharmony_ci		},
80462306a36Sopenharmony_ci		.digestsize	= SM4_BLOCK_SIZE,
80562306a36Sopenharmony_ci		.init		= sm4_mac_init,
80662306a36Sopenharmony_ci		.update		= sm4_mac_update,
80762306a36Sopenharmony_ci		.final		= sm4_cmac_final,
80862306a36Sopenharmony_ci		.setkey		= sm4_cmac_setkey,
80962306a36Sopenharmony_ci		.descsize	= sizeof(struct sm4_mac_desc_ctx),
81062306a36Sopenharmony_ci	}, {
81162306a36Sopenharmony_ci		.base = {
81262306a36Sopenharmony_ci			.cra_name		= "xcbc(sm4)",
81362306a36Sopenharmony_ci			.cra_driver_name	= "xcbc-sm4-ce",
81462306a36Sopenharmony_ci			.cra_priority		= 400,
81562306a36Sopenharmony_ci			.cra_blocksize		= SM4_BLOCK_SIZE,
81662306a36Sopenharmony_ci			.cra_ctxsize		= sizeof(struct sm4_mac_tfm_ctx)
81762306a36Sopenharmony_ci							+ SM4_BLOCK_SIZE * 2,
81862306a36Sopenharmony_ci			.cra_module		= THIS_MODULE,
81962306a36Sopenharmony_ci		},
82062306a36Sopenharmony_ci		.digestsize	= SM4_BLOCK_SIZE,
82162306a36Sopenharmony_ci		.init		= sm4_mac_init,
82262306a36Sopenharmony_ci		.update		= sm4_mac_update,
82362306a36Sopenharmony_ci		.final		= sm4_cmac_final,
82462306a36Sopenharmony_ci		.setkey		= sm4_xcbc_setkey,
82562306a36Sopenharmony_ci		.descsize	= sizeof(struct sm4_mac_desc_ctx),
82662306a36Sopenharmony_ci	}, {
82762306a36Sopenharmony_ci		.base = {
82862306a36Sopenharmony_ci			.cra_name		= "cbcmac(sm4)",
82962306a36Sopenharmony_ci			.cra_driver_name	= "cbcmac-sm4-ce",
83062306a36Sopenharmony_ci			.cra_priority		= 400,
83162306a36Sopenharmony_ci			.cra_blocksize		= 1,
83262306a36Sopenharmony_ci			.cra_ctxsize		= sizeof(struct sm4_mac_tfm_ctx),
83362306a36Sopenharmony_ci			.cra_module		= THIS_MODULE,
83462306a36Sopenharmony_ci		},
83562306a36Sopenharmony_ci		.digestsize	= SM4_BLOCK_SIZE,
83662306a36Sopenharmony_ci		.init		= sm4_mac_init,
83762306a36Sopenharmony_ci		.update		= sm4_mac_update,
83862306a36Sopenharmony_ci		.final		= sm4_cbcmac_final,
83962306a36Sopenharmony_ci		.setkey		= sm4_cbcmac_setkey,
84062306a36Sopenharmony_ci		.descsize	= sizeof(struct sm4_mac_desc_ctx),
84162306a36Sopenharmony_ci	}
84262306a36Sopenharmony_ci};
84362306a36Sopenharmony_ci
84462306a36Sopenharmony_cistatic int __init sm4_init(void)
84562306a36Sopenharmony_ci{
84662306a36Sopenharmony_ci	int err;
84762306a36Sopenharmony_ci
84862306a36Sopenharmony_ci	err = crypto_register_skciphers(sm4_algs, ARRAY_SIZE(sm4_algs));
84962306a36Sopenharmony_ci	if (err)
85062306a36Sopenharmony_ci		return err;
85162306a36Sopenharmony_ci
85262306a36Sopenharmony_ci	err = crypto_register_shashes(sm4_mac_algs, ARRAY_SIZE(sm4_mac_algs));
85362306a36Sopenharmony_ci	if (err)
85462306a36Sopenharmony_ci		goto out_err;
85562306a36Sopenharmony_ci
85662306a36Sopenharmony_ci	return 0;
85762306a36Sopenharmony_ci
85862306a36Sopenharmony_ciout_err:
85962306a36Sopenharmony_ci	crypto_unregister_skciphers(sm4_algs, ARRAY_SIZE(sm4_algs));
86062306a36Sopenharmony_ci	return err;
86162306a36Sopenharmony_ci}
86262306a36Sopenharmony_ci
86362306a36Sopenharmony_cistatic void __exit sm4_exit(void)
86462306a36Sopenharmony_ci{
86562306a36Sopenharmony_ci	crypto_unregister_shashes(sm4_mac_algs, ARRAY_SIZE(sm4_mac_algs));
86662306a36Sopenharmony_ci	crypto_unregister_skciphers(sm4_algs, ARRAY_SIZE(sm4_algs));
86762306a36Sopenharmony_ci}
86862306a36Sopenharmony_ci
86962306a36Sopenharmony_cimodule_cpu_feature_match(SM4, sm4_init);
87062306a36Sopenharmony_cimodule_exit(sm4_exit);
87162306a36Sopenharmony_ci
87262306a36Sopenharmony_ciMODULE_DESCRIPTION("SM4 ECB/CBC/CFB/CTR/XTS using ARMv8 Crypto Extensions");
87362306a36Sopenharmony_ciMODULE_ALIAS_CRYPTO("sm4-ce");
87462306a36Sopenharmony_ciMODULE_ALIAS_CRYPTO("sm4");
87562306a36Sopenharmony_ciMODULE_ALIAS_CRYPTO("ecb(sm4)");
87662306a36Sopenharmony_ciMODULE_ALIAS_CRYPTO("cbc(sm4)");
87762306a36Sopenharmony_ciMODULE_ALIAS_CRYPTO("cfb(sm4)");
87862306a36Sopenharmony_ciMODULE_ALIAS_CRYPTO("ctr(sm4)");
87962306a36Sopenharmony_ciMODULE_ALIAS_CRYPTO("cts(cbc(sm4))");
88062306a36Sopenharmony_ciMODULE_ALIAS_CRYPTO("xts(sm4)");
88162306a36Sopenharmony_ciMODULE_ALIAS_CRYPTO("cmac(sm4)");
88262306a36Sopenharmony_ciMODULE_ALIAS_CRYPTO("xcbc(sm4)");
88362306a36Sopenharmony_ciMODULE_ALIAS_CRYPTO("cbcmac(sm4)");
88462306a36Sopenharmony_ciMODULE_AUTHOR("Tianjia Zhang <tianjia.zhang@linux.alibaba.com>");
88562306a36Sopenharmony_ciMODULE_LICENSE("GPL v2");
886