162306a36Sopenharmony_ci// SPDX-License-Identifier: GPL-2.0-only 262306a36Sopenharmony_ci/* Glue code for SHA256 hashing optimized for sparc64 crypto opcodes. 362306a36Sopenharmony_ci * 462306a36Sopenharmony_ci * This is based largely upon crypto/sha256_generic.c 562306a36Sopenharmony_ci * 662306a36Sopenharmony_ci * Copyright (c) Jean-Luc Cooke <jlcooke@certainkey.com> 762306a36Sopenharmony_ci * Copyright (c) Andrew McDonald <andrew@mcdonald.org.uk> 862306a36Sopenharmony_ci * Copyright (c) 2002 James Morris <jmorris@intercode.com.au> 962306a36Sopenharmony_ci * SHA224 Support Copyright 2007 Intel Corporation <jonathan.lynch@intel.com> 1062306a36Sopenharmony_ci */ 1162306a36Sopenharmony_ci 1262306a36Sopenharmony_ci#define pr_fmt(fmt) KBUILD_MODNAME ": " fmt 1362306a36Sopenharmony_ci 1462306a36Sopenharmony_ci#include <crypto/internal/hash.h> 1562306a36Sopenharmony_ci#include <linux/init.h> 1662306a36Sopenharmony_ci#include <linux/module.h> 1762306a36Sopenharmony_ci#include <linux/mm.h> 1862306a36Sopenharmony_ci#include <linux/types.h> 1962306a36Sopenharmony_ci#include <crypto/sha2.h> 2062306a36Sopenharmony_ci#include <crypto/sha256_base.h> 2162306a36Sopenharmony_ci 2262306a36Sopenharmony_ci#include <asm/pstate.h> 2362306a36Sopenharmony_ci#include <asm/elf.h> 2462306a36Sopenharmony_ci 2562306a36Sopenharmony_ci#include "opcodes.h" 2662306a36Sopenharmony_ci 2762306a36Sopenharmony_ciasmlinkage void sha256_sparc64_transform(u32 *digest, const char *data, 2862306a36Sopenharmony_ci unsigned int rounds); 2962306a36Sopenharmony_ci 3062306a36Sopenharmony_cistatic void __sha256_sparc64_update(struct sha256_state *sctx, const u8 *data, 3162306a36Sopenharmony_ci unsigned int len, unsigned int partial) 3262306a36Sopenharmony_ci{ 3362306a36Sopenharmony_ci unsigned int done = 0; 3462306a36Sopenharmony_ci 3562306a36Sopenharmony_ci sctx->count += len; 3662306a36Sopenharmony_ci if (partial) { 3762306a36Sopenharmony_ci done = SHA256_BLOCK_SIZE - partial; 3862306a36Sopenharmony_ci memcpy(sctx->buf + partial, data, done); 3962306a36Sopenharmony_ci sha256_sparc64_transform(sctx->state, sctx->buf, 1); 4062306a36Sopenharmony_ci } 4162306a36Sopenharmony_ci if (len - done >= SHA256_BLOCK_SIZE) { 4262306a36Sopenharmony_ci const unsigned int rounds = (len - done) / SHA256_BLOCK_SIZE; 4362306a36Sopenharmony_ci 4462306a36Sopenharmony_ci sha256_sparc64_transform(sctx->state, data + done, rounds); 4562306a36Sopenharmony_ci done += rounds * SHA256_BLOCK_SIZE; 4662306a36Sopenharmony_ci } 4762306a36Sopenharmony_ci 4862306a36Sopenharmony_ci memcpy(sctx->buf, data + done, len - done); 4962306a36Sopenharmony_ci} 5062306a36Sopenharmony_ci 5162306a36Sopenharmony_cistatic int sha256_sparc64_update(struct shash_desc *desc, const u8 *data, 5262306a36Sopenharmony_ci unsigned int len) 5362306a36Sopenharmony_ci{ 5462306a36Sopenharmony_ci struct sha256_state *sctx = shash_desc_ctx(desc); 5562306a36Sopenharmony_ci unsigned int partial = sctx->count % SHA256_BLOCK_SIZE; 5662306a36Sopenharmony_ci 5762306a36Sopenharmony_ci /* Handle the fast case right here */ 5862306a36Sopenharmony_ci if (partial + len < SHA256_BLOCK_SIZE) { 5962306a36Sopenharmony_ci sctx->count += len; 6062306a36Sopenharmony_ci memcpy(sctx->buf + partial, data, len); 6162306a36Sopenharmony_ci } else 6262306a36Sopenharmony_ci __sha256_sparc64_update(sctx, data, len, partial); 6362306a36Sopenharmony_ci 6462306a36Sopenharmony_ci return 0; 6562306a36Sopenharmony_ci} 6662306a36Sopenharmony_ci 6762306a36Sopenharmony_cistatic int sha256_sparc64_final(struct shash_desc *desc, u8 *out) 6862306a36Sopenharmony_ci{ 6962306a36Sopenharmony_ci struct sha256_state *sctx = shash_desc_ctx(desc); 7062306a36Sopenharmony_ci unsigned int i, index, padlen; 7162306a36Sopenharmony_ci __be32 *dst = (__be32 *)out; 7262306a36Sopenharmony_ci __be64 bits; 7362306a36Sopenharmony_ci static const u8 padding[SHA256_BLOCK_SIZE] = { 0x80, }; 7462306a36Sopenharmony_ci 7562306a36Sopenharmony_ci bits = cpu_to_be64(sctx->count << 3); 7662306a36Sopenharmony_ci 7762306a36Sopenharmony_ci /* Pad out to 56 mod 64 and append length */ 7862306a36Sopenharmony_ci index = sctx->count % SHA256_BLOCK_SIZE; 7962306a36Sopenharmony_ci padlen = (index < 56) ? (56 - index) : ((SHA256_BLOCK_SIZE+56) - index); 8062306a36Sopenharmony_ci 8162306a36Sopenharmony_ci /* We need to fill a whole block for __sha256_sparc64_update() */ 8262306a36Sopenharmony_ci if (padlen <= 56) { 8362306a36Sopenharmony_ci sctx->count += padlen; 8462306a36Sopenharmony_ci memcpy(sctx->buf + index, padding, padlen); 8562306a36Sopenharmony_ci } else { 8662306a36Sopenharmony_ci __sha256_sparc64_update(sctx, padding, padlen, index); 8762306a36Sopenharmony_ci } 8862306a36Sopenharmony_ci __sha256_sparc64_update(sctx, (const u8 *)&bits, sizeof(bits), 56); 8962306a36Sopenharmony_ci 9062306a36Sopenharmony_ci /* Store state in digest */ 9162306a36Sopenharmony_ci for (i = 0; i < 8; i++) 9262306a36Sopenharmony_ci dst[i] = cpu_to_be32(sctx->state[i]); 9362306a36Sopenharmony_ci 9462306a36Sopenharmony_ci /* Wipe context */ 9562306a36Sopenharmony_ci memset(sctx, 0, sizeof(*sctx)); 9662306a36Sopenharmony_ci 9762306a36Sopenharmony_ci return 0; 9862306a36Sopenharmony_ci} 9962306a36Sopenharmony_ci 10062306a36Sopenharmony_cistatic int sha224_sparc64_final(struct shash_desc *desc, u8 *hash) 10162306a36Sopenharmony_ci{ 10262306a36Sopenharmony_ci u8 D[SHA256_DIGEST_SIZE]; 10362306a36Sopenharmony_ci 10462306a36Sopenharmony_ci sha256_sparc64_final(desc, D); 10562306a36Sopenharmony_ci 10662306a36Sopenharmony_ci memcpy(hash, D, SHA224_DIGEST_SIZE); 10762306a36Sopenharmony_ci memzero_explicit(D, SHA256_DIGEST_SIZE); 10862306a36Sopenharmony_ci 10962306a36Sopenharmony_ci return 0; 11062306a36Sopenharmony_ci} 11162306a36Sopenharmony_ci 11262306a36Sopenharmony_cistatic int sha256_sparc64_export(struct shash_desc *desc, void *out) 11362306a36Sopenharmony_ci{ 11462306a36Sopenharmony_ci struct sha256_state *sctx = shash_desc_ctx(desc); 11562306a36Sopenharmony_ci 11662306a36Sopenharmony_ci memcpy(out, sctx, sizeof(*sctx)); 11762306a36Sopenharmony_ci return 0; 11862306a36Sopenharmony_ci} 11962306a36Sopenharmony_ci 12062306a36Sopenharmony_cistatic int sha256_sparc64_import(struct shash_desc *desc, const void *in) 12162306a36Sopenharmony_ci{ 12262306a36Sopenharmony_ci struct sha256_state *sctx = shash_desc_ctx(desc); 12362306a36Sopenharmony_ci 12462306a36Sopenharmony_ci memcpy(sctx, in, sizeof(*sctx)); 12562306a36Sopenharmony_ci return 0; 12662306a36Sopenharmony_ci} 12762306a36Sopenharmony_ci 12862306a36Sopenharmony_cistatic struct shash_alg sha256_alg = { 12962306a36Sopenharmony_ci .digestsize = SHA256_DIGEST_SIZE, 13062306a36Sopenharmony_ci .init = sha256_base_init, 13162306a36Sopenharmony_ci .update = sha256_sparc64_update, 13262306a36Sopenharmony_ci .final = sha256_sparc64_final, 13362306a36Sopenharmony_ci .export = sha256_sparc64_export, 13462306a36Sopenharmony_ci .import = sha256_sparc64_import, 13562306a36Sopenharmony_ci .descsize = sizeof(struct sha256_state), 13662306a36Sopenharmony_ci .statesize = sizeof(struct sha256_state), 13762306a36Sopenharmony_ci .base = { 13862306a36Sopenharmony_ci .cra_name = "sha256", 13962306a36Sopenharmony_ci .cra_driver_name= "sha256-sparc64", 14062306a36Sopenharmony_ci .cra_priority = SPARC_CR_OPCODE_PRIORITY, 14162306a36Sopenharmony_ci .cra_blocksize = SHA256_BLOCK_SIZE, 14262306a36Sopenharmony_ci .cra_module = THIS_MODULE, 14362306a36Sopenharmony_ci } 14462306a36Sopenharmony_ci}; 14562306a36Sopenharmony_ci 14662306a36Sopenharmony_cistatic struct shash_alg sha224_alg = { 14762306a36Sopenharmony_ci .digestsize = SHA224_DIGEST_SIZE, 14862306a36Sopenharmony_ci .init = sha224_base_init, 14962306a36Sopenharmony_ci .update = sha256_sparc64_update, 15062306a36Sopenharmony_ci .final = sha224_sparc64_final, 15162306a36Sopenharmony_ci .descsize = sizeof(struct sha256_state), 15262306a36Sopenharmony_ci .base = { 15362306a36Sopenharmony_ci .cra_name = "sha224", 15462306a36Sopenharmony_ci .cra_driver_name= "sha224-sparc64", 15562306a36Sopenharmony_ci .cra_priority = SPARC_CR_OPCODE_PRIORITY, 15662306a36Sopenharmony_ci .cra_blocksize = SHA224_BLOCK_SIZE, 15762306a36Sopenharmony_ci .cra_module = THIS_MODULE, 15862306a36Sopenharmony_ci } 15962306a36Sopenharmony_ci}; 16062306a36Sopenharmony_ci 16162306a36Sopenharmony_cistatic bool __init sparc64_has_sha256_opcode(void) 16262306a36Sopenharmony_ci{ 16362306a36Sopenharmony_ci unsigned long cfr; 16462306a36Sopenharmony_ci 16562306a36Sopenharmony_ci if (!(sparc64_elf_hwcap & HWCAP_SPARC_CRYPTO)) 16662306a36Sopenharmony_ci return false; 16762306a36Sopenharmony_ci 16862306a36Sopenharmony_ci __asm__ __volatile__("rd %%asr26, %0" : "=r" (cfr)); 16962306a36Sopenharmony_ci if (!(cfr & CFR_SHA256)) 17062306a36Sopenharmony_ci return false; 17162306a36Sopenharmony_ci 17262306a36Sopenharmony_ci return true; 17362306a36Sopenharmony_ci} 17462306a36Sopenharmony_ci 17562306a36Sopenharmony_cistatic int __init sha256_sparc64_mod_init(void) 17662306a36Sopenharmony_ci{ 17762306a36Sopenharmony_ci if (sparc64_has_sha256_opcode()) { 17862306a36Sopenharmony_ci int ret = crypto_register_shash(&sha224_alg); 17962306a36Sopenharmony_ci if (ret < 0) 18062306a36Sopenharmony_ci return ret; 18162306a36Sopenharmony_ci 18262306a36Sopenharmony_ci ret = crypto_register_shash(&sha256_alg); 18362306a36Sopenharmony_ci if (ret < 0) { 18462306a36Sopenharmony_ci crypto_unregister_shash(&sha224_alg); 18562306a36Sopenharmony_ci return ret; 18662306a36Sopenharmony_ci } 18762306a36Sopenharmony_ci 18862306a36Sopenharmony_ci pr_info("Using sparc64 sha256 opcode optimized SHA-256/SHA-224 implementation\n"); 18962306a36Sopenharmony_ci return 0; 19062306a36Sopenharmony_ci } 19162306a36Sopenharmony_ci pr_info("sparc64 sha256 opcode not available.\n"); 19262306a36Sopenharmony_ci return -ENODEV; 19362306a36Sopenharmony_ci} 19462306a36Sopenharmony_ci 19562306a36Sopenharmony_cistatic void __exit sha256_sparc64_mod_fini(void) 19662306a36Sopenharmony_ci{ 19762306a36Sopenharmony_ci crypto_unregister_shash(&sha224_alg); 19862306a36Sopenharmony_ci crypto_unregister_shash(&sha256_alg); 19962306a36Sopenharmony_ci} 20062306a36Sopenharmony_ci 20162306a36Sopenharmony_cimodule_init(sha256_sparc64_mod_init); 20262306a36Sopenharmony_cimodule_exit(sha256_sparc64_mod_fini); 20362306a36Sopenharmony_ci 20462306a36Sopenharmony_ciMODULE_LICENSE("GPL"); 20562306a36Sopenharmony_ciMODULE_DESCRIPTION("SHA-224 and SHA-256 Secure Hash Algorithm, sparc64 sha256 opcode accelerated"); 20662306a36Sopenharmony_ci 20762306a36Sopenharmony_ciMODULE_ALIAS_CRYPTO("sha224"); 20862306a36Sopenharmony_ciMODULE_ALIAS_CRYPTO("sha256"); 20962306a36Sopenharmony_ci 21062306a36Sopenharmony_ci#include "crop_devid.c" 211