162306a36Sopenharmony_ci/*
262306a36Sopenharmony_ci * Intel SHA Extensions optimized implementation of a SHA-1 update function
362306a36Sopenharmony_ci *
462306a36Sopenharmony_ci * This file is provided under a dual BSD/GPLv2 license.  When using or
562306a36Sopenharmony_ci * redistributing this file, you may do so under either license.
662306a36Sopenharmony_ci *
762306a36Sopenharmony_ci * GPL LICENSE SUMMARY
862306a36Sopenharmony_ci *
962306a36Sopenharmony_ci * Copyright(c) 2015 Intel Corporation.
1062306a36Sopenharmony_ci *
1162306a36Sopenharmony_ci * This program is free software; you can redistribute it and/or modify
1262306a36Sopenharmony_ci * it under the terms of version 2 of the GNU General Public License as
1362306a36Sopenharmony_ci * published by the Free Software Foundation.
1462306a36Sopenharmony_ci *
1562306a36Sopenharmony_ci * This program is distributed in the hope that it will be useful, but
1662306a36Sopenharmony_ci * WITHOUT ANY WARRANTY; without even the implied warranty of
1762306a36Sopenharmony_ci * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
1862306a36Sopenharmony_ci * General Public License for more details.
1962306a36Sopenharmony_ci *
2062306a36Sopenharmony_ci * Contact Information:
2162306a36Sopenharmony_ci * 	Sean Gulley <sean.m.gulley@intel.com>
2262306a36Sopenharmony_ci * 	Tim Chen <tim.c.chen@linux.intel.com>
2362306a36Sopenharmony_ci *
2462306a36Sopenharmony_ci * BSD LICENSE
2562306a36Sopenharmony_ci *
2662306a36Sopenharmony_ci * Copyright(c) 2015 Intel Corporation.
2762306a36Sopenharmony_ci *
2862306a36Sopenharmony_ci * Redistribution and use in source and binary forms, with or without
2962306a36Sopenharmony_ci * modification, are permitted provided that the following conditions
3062306a36Sopenharmony_ci * are met:
3162306a36Sopenharmony_ci *
3262306a36Sopenharmony_ci * 	* Redistributions of source code must retain the above copyright
3362306a36Sopenharmony_ci * 	  notice, this list of conditions and the following disclaimer.
3462306a36Sopenharmony_ci * 	* Redistributions in binary form must reproduce the above copyright
3562306a36Sopenharmony_ci * 	  notice, this list of conditions and the following disclaimer in
3662306a36Sopenharmony_ci * 	  the documentation and/or other materials provided with the
3762306a36Sopenharmony_ci * 	  distribution.
3862306a36Sopenharmony_ci * 	* Neither the name of Intel Corporation nor the names of its
3962306a36Sopenharmony_ci * 	  contributors may be used to endorse or promote products derived
4062306a36Sopenharmony_ci * 	  from this software without specific prior written permission.
4162306a36Sopenharmony_ci *
4262306a36Sopenharmony_ci * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
4362306a36Sopenharmony_ci * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
4462306a36Sopenharmony_ci * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
4562306a36Sopenharmony_ci * A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
4662306a36Sopenharmony_ci * OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
4762306a36Sopenharmony_ci * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
4862306a36Sopenharmony_ci * LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
4962306a36Sopenharmony_ci * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
5062306a36Sopenharmony_ci * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
5162306a36Sopenharmony_ci * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
5262306a36Sopenharmony_ci * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
5362306a36Sopenharmony_ci *
5462306a36Sopenharmony_ci */
5562306a36Sopenharmony_ci
5662306a36Sopenharmony_ci#include <linux/linkage.h>
5762306a36Sopenharmony_ci#include <linux/cfi_types.h>
5862306a36Sopenharmony_ci
5962306a36Sopenharmony_ci#define DIGEST_PTR	%rdi	/* 1st arg */
6062306a36Sopenharmony_ci#define DATA_PTR	%rsi	/* 2nd arg */
6162306a36Sopenharmony_ci#define NUM_BLKS	%rdx	/* 3rd arg */
6262306a36Sopenharmony_ci
6362306a36Sopenharmony_ci/* gcc conversion */
6462306a36Sopenharmony_ci#define FRAME_SIZE	32	/* space for 2x16 bytes */
6562306a36Sopenharmony_ci
6662306a36Sopenharmony_ci#define ABCD		%xmm0
6762306a36Sopenharmony_ci#define E0		%xmm1	/* Need two E's b/c they ping pong */
6862306a36Sopenharmony_ci#define E1		%xmm2
6962306a36Sopenharmony_ci#define MSG0		%xmm3
7062306a36Sopenharmony_ci#define MSG1		%xmm4
7162306a36Sopenharmony_ci#define MSG2		%xmm5
7262306a36Sopenharmony_ci#define MSG3		%xmm6
7362306a36Sopenharmony_ci#define SHUF_MASK	%xmm7
7462306a36Sopenharmony_ci
7562306a36Sopenharmony_ci
7662306a36Sopenharmony_ci/*
7762306a36Sopenharmony_ci * Intel SHA Extensions optimized implementation of a SHA-1 update function
7862306a36Sopenharmony_ci *
7962306a36Sopenharmony_ci * The function takes a pointer to the current hash values, a pointer to the
8062306a36Sopenharmony_ci * input data, and a number of 64 byte blocks to process.  Once all blocks have
8162306a36Sopenharmony_ci * been processed, the digest pointer is  updated with the resulting hash value.
8262306a36Sopenharmony_ci * The function only processes complete blocks, there is no functionality to
8362306a36Sopenharmony_ci * store partial blocks. All message padding and hash value initialization must
8462306a36Sopenharmony_ci * be done outside the update function.
8562306a36Sopenharmony_ci *
8662306a36Sopenharmony_ci * The indented lines in the loop are instructions related to rounds processing.
8762306a36Sopenharmony_ci * The non-indented lines are instructions related to the message schedule.
8862306a36Sopenharmony_ci *
8962306a36Sopenharmony_ci * void sha1_ni_transform(uint32_t *digest, const void *data,
9062306a36Sopenharmony_ci		uint32_t numBlocks)
9162306a36Sopenharmony_ci * digest : pointer to digest
9262306a36Sopenharmony_ci * data: pointer to input data
9362306a36Sopenharmony_ci * numBlocks: Number of blocks to process
9462306a36Sopenharmony_ci */
9562306a36Sopenharmony_ci.text
9662306a36Sopenharmony_ciSYM_TYPED_FUNC_START(sha1_ni_transform)
9762306a36Sopenharmony_ci	push		%rbp
9862306a36Sopenharmony_ci	mov		%rsp, %rbp
9962306a36Sopenharmony_ci	sub		$FRAME_SIZE, %rsp
10062306a36Sopenharmony_ci	and		$~0xF, %rsp
10162306a36Sopenharmony_ci
10262306a36Sopenharmony_ci	shl		$6, NUM_BLKS		/* convert to bytes */
10362306a36Sopenharmony_ci	jz		.Ldone_hash
10462306a36Sopenharmony_ci	add		DATA_PTR, NUM_BLKS	/* pointer to end of data */
10562306a36Sopenharmony_ci
10662306a36Sopenharmony_ci	/* load initial hash values */
10762306a36Sopenharmony_ci	pinsrd		$3, 1*16(DIGEST_PTR), E0
10862306a36Sopenharmony_ci	movdqu		0*16(DIGEST_PTR), ABCD
10962306a36Sopenharmony_ci	pand		UPPER_WORD_MASK(%rip), E0
11062306a36Sopenharmony_ci	pshufd		$0x1B, ABCD, ABCD
11162306a36Sopenharmony_ci
11262306a36Sopenharmony_ci	movdqa		PSHUFFLE_BYTE_FLIP_MASK(%rip), SHUF_MASK
11362306a36Sopenharmony_ci
11462306a36Sopenharmony_ci.Lloop0:
11562306a36Sopenharmony_ci	/* Save hash values for addition after rounds */
11662306a36Sopenharmony_ci	movdqa		E0, (0*16)(%rsp)
11762306a36Sopenharmony_ci	movdqa		ABCD, (1*16)(%rsp)
11862306a36Sopenharmony_ci
11962306a36Sopenharmony_ci	/* Rounds 0-3 */
12062306a36Sopenharmony_ci	movdqu		0*16(DATA_PTR), MSG0
12162306a36Sopenharmony_ci	pshufb		SHUF_MASK, MSG0
12262306a36Sopenharmony_ci		paddd		MSG0, E0
12362306a36Sopenharmony_ci		movdqa		ABCD, E1
12462306a36Sopenharmony_ci		sha1rnds4	$0, E0, ABCD
12562306a36Sopenharmony_ci
12662306a36Sopenharmony_ci	/* Rounds 4-7 */
12762306a36Sopenharmony_ci	movdqu		1*16(DATA_PTR), MSG1
12862306a36Sopenharmony_ci	pshufb		SHUF_MASK, MSG1
12962306a36Sopenharmony_ci		sha1nexte	MSG1, E1
13062306a36Sopenharmony_ci		movdqa		ABCD, E0
13162306a36Sopenharmony_ci		sha1rnds4	$0, E1, ABCD
13262306a36Sopenharmony_ci	sha1msg1	MSG1, MSG0
13362306a36Sopenharmony_ci
13462306a36Sopenharmony_ci	/* Rounds 8-11 */
13562306a36Sopenharmony_ci	movdqu		2*16(DATA_PTR), MSG2
13662306a36Sopenharmony_ci	pshufb		SHUF_MASK, MSG2
13762306a36Sopenharmony_ci		sha1nexte	MSG2, E0
13862306a36Sopenharmony_ci		movdqa		ABCD, E1
13962306a36Sopenharmony_ci		sha1rnds4	$0, E0, ABCD
14062306a36Sopenharmony_ci	sha1msg1	MSG2, MSG1
14162306a36Sopenharmony_ci	pxor		MSG2, MSG0
14262306a36Sopenharmony_ci
14362306a36Sopenharmony_ci	/* Rounds 12-15 */
14462306a36Sopenharmony_ci	movdqu		3*16(DATA_PTR), MSG3
14562306a36Sopenharmony_ci	pshufb		SHUF_MASK, MSG3
14662306a36Sopenharmony_ci		sha1nexte	MSG3, E1
14762306a36Sopenharmony_ci		movdqa		ABCD, E0
14862306a36Sopenharmony_ci	sha1msg2	MSG3, MSG0
14962306a36Sopenharmony_ci		sha1rnds4	$0, E1, ABCD
15062306a36Sopenharmony_ci	sha1msg1	MSG3, MSG2
15162306a36Sopenharmony_ci	pxor		MSG3, MSG1
15262306a36Sopenharmony_ci
15362306a36Sopenharmony_ci	/* Rounds 16-19 */
15462306a36Sopenharmony_ci		sha1nexte	MSG0, E0
15562306a36Sopenharmony_ci		movdqa		ABCD, E1
15662306a36Sopenharmony_ci	sha1msg2	MSG0, MSG1
15762306a36Sopenharmony_ci		sha1rnds4	$0, E0, ABCD
15862306a36Sopenharmony_ci	sha1msg1	MSG0, MSG3
15962306a36Sopenharmony_ci	pxor		MSG0, MSG2
16062306a36Sopenharmony_ci
16162306a36Sopenharmony_ci	/* Rounds 20-23 */
16262306a36Sopenharmony_ci		sha1nexte	MSG1, E1
16362306a36Sopenharmony_ci		movdqa		ABCD, E0
16462306a36Sopenharmony_ci	sha1msg2	MSG1, MSG2
16562306a36Sopenharmony_ci		sha1rnds4	$1, E1, ABCD
16662306a36Sopenharmony_ci	sha1msg1	MSG1, MSG0
16762306a36Sopenharmony_ci	pxor		MSG1, MSG3
16862306a36Sopenharmony_ci
16962306a36Sopenharmony_ci	/* Rounds 24-27 */
17062306a36Sopenharmony_ci		sha1nexte	MSG2, E0
17162306a36Sopenharmony_ci		movdqa		ABCD, E1
17262306a36Sopenharmony_ci	sha1msg2	MSG2, MSG3
17362306a36Sopenharmony_ci		sha1rnds4	$1, E0, ABCD
17462306a36Sopenharmony_ci	sha1msg1	MSG2, MSG1
17562306a36Sopenharmony_ci	pxor		MSG2, MSG0
17662306a36Sopenharmony_ci
17762306a36Sopenharmony_ci	/* Rounds 28-31 */
17862306a36Sopenharmony_ci		sha1nexte	MSG3, E1
17962306a36Sopenharmony_ci		movdqa		ABCD, E0
18062306a36Sopenharmony_ci	sha1msg2	MSG3, MSG0
18162306a36Sopenharmony_ci		sha1rnds4	$1, E1, ABCD
18262306a36Sopenharmony_ci	sha1msg1	MSG3, MSG2
18362306a36Sopenharmony_ci	pxor		MSG3, MSG1
18462306a36Sopenharmony_ci
18562306a36Sopenharmony_ci	/* Rounds 32-35 */
18662306a36Sopenharmony_ci		sha1nexte	MSG0, E0
18762306a36Sopenharmony_ci		movdqa		ABCD, E1
18862306a36Sopenharmony_ci	sha1msg2	MSG0, MSG1
18962306a36Sopenharmony_ci		sha1rnds4	$1, E0, ABCD
19062306a36Sopenharmony_ci	sha1msg1	MSG0, MSG3
19162306a36Sopenharmony_ci	pxor		MSG0, MSG2
19262306a36Sopenharmony_ci
19362306a36Sopenharmony_ci	/* Rounds 36-39 */
19462306a36Sopenharmony_ci		sha1nexte	MSG1, E1
19562306a36Sopenharmony_ci		movdqa		ABCD, E0
19662306a36Sopenharmony_ci	sha1msg2	MSG1, MSG2
19762306a36Sopenharmony_ci		sha1rnds4	$1, E1, ABCD
19862306a36Sopenharmony_ci	sha1msg1	MSG1, MSG0
19962306a36Sopenharmony_ci	pxor		MSG1, MSG3
20062306a36Sopenharmony_ci
20162306a36Sopenharmony_ci	/* Rounds 40-43 */
20262306a36Sopenharmony_ci		sha1nexte	MSG2, E0
20362306a36Sopenharmony_ci		movdqa		ABCD, E1
20462306a36Sopenharmony_ci	sha1msg2	MSG2, MSG3
20562306a36Sopenharmony_ci		sha1rnds4	$2, E0, ABCD
20662306a36Sopenharmony_ci	sha1msg1	MSG2, MSG1
20762306a36Sopenharmony_ci	pxor		MSG2, MSG0
20862306a36Sopenharmony_ci
20962306a36Sopenharmony_ci	/* Rounds 44-47 */
21062306a36Sopenharmony_ci		sha1nexte	MSG3, E1
21162306a36Sopenharmony_ci		movdqa		ABCD, E0
21262306a36Sopenharmony_ci	sha1msg2	MSG3, MSG0
21362306a36Sopenharmony_ci		sha1rnds4	$2, E1, ABCD
21462306a36Sopenharmony_ci	sha1msg1	MSG3, MSG2
21562306a36Sopenharmony_ci	pxor		MSG3, MSG1
21662306a36Sopenharmony_ci
21762306a36Sopenharmony_ci	/* Rounds 48-51 */
21862306a36Sopenharmony_ci		sha1nexte	MSG0, E0
21962306a36Sopenharmony_ci		movdqa		ABCD, E1
22062306a36Sopenharmony_ci	sha1msg2	MSG0, MSG1
22162306a36Sopenharmony_ci		sha1rnds4	$2, E0, ABCD
22262306a36Sopenharmony_ci	sha1msg1	MSG0, MSG3
22362306a36Sopenharmony_ci	pxor		MSG0, MSG2
22462306a36Sopenharmony_ci
22562306a36Sopenharmony_ci	/* Rounds 52-55 */
22662306a36Sopenharmony_ci		sha1nexte	MSG1, E1
22762306a36Sopenharmony_ci		movdqa		ABCD, E0
22862306a36Sopenharmony_ci	sha1msg2	MSG1, MSG2
22962306a36Sopenharmony_ci		sha1rnds4	$2, E1, ABCD
23062306a36Sopenharmony_ci	sha1msg1	MSG1, MSG0
23162306a36Sopenharmony_ci	pxor		MSG1, MSG3
23262306a36Sopenharmony_ci
23362306a36Sopenharmony_ci	/* Rounds 56-59 */
23462306a36Sopenharmony_ci		sha1nexte	MSG2, E0
23562306a36Sopenharmony_ci		movdqa		ABCD, E1
23662306a36Sopenharmony_ci	sha1msg2	MSG2, MSG3
23762306a36Sopenharmony_ci		sha1rnds4	$2, E0, ABCD
23862306a36Sopenharmony_ci	sha1msg1	MSG2, MSG1
23962306a36Sopenharmony_ci	pxor		MSG2, MSG0
24062306a36Sopenharmony_ci
24162306a36Sopenharmony_ci	/* Rounds 60-63 */
24262306a36Sopenharmony_ci		sha1nexte	MSG3, E1
24362306a36Sopenharmony_ci		movdqa		ABCD, E0
24462306a36Sopenharmony_ci	sha1msg2	MSG3, MSG0
24562306a36Sopenharmony_ci		sha1rnds4	$3, E1, ABCD
24662306a36Sopenharmony_ci	sha1msg1	MSG3, MSG2
24762306a36Sopenharmony_ci	pxor		MSG3, MSG1
24862306a36Sopenharmony_ci
24962306a36Sopenharmony_ci	/* Rounds 64-67 */
25062306a36Sopenharmony_ci		sha1nexte	MSG0, E0
25162306a36Sopenharmony_ci		movdqa		ABCD, E1
25262306a36Sopenharmony_ci	sha1msg2	MSG0, MSG1
25362306a36Sopenharmony_ci		sha1rnds4	$3, E0, ABCD
25462306a36Sopenharmony_ci	sha1msg1	MSG0, MSG3
25562306a36Sopenharmony_ci	pxor		MSG0, MSG2
25662306a36Sopenharmony_ci
25762306a36Sopenharmony_ci	/* Rounds 68-71 */
25862306a36Sopenharmony_ci		sha1nexte	MSG1, E1
25962306a36Sopenharmony_ci		movdqa		ABCD, E0
26062306a36Sopenharmony_ci	sha1msg2	MSG1, MSG2
26162306a36Sopenharmony_ci		sha1rnds4	$3, E1, ABCD
26262306a36Sopenharmony_ci	pxor		MSG1, MSG3
26362306a36Sopenharmony_ci
26462306a36Sopenharmony_ci	/* Rounds 72-75 */
26562306a36Sopenharmony_ci		sha1nexte	MSG2, E0
26662306a36Sopenharmony_ci		movdqa		ABCD, E1
26762306a36Sopenharmony_ci	sha1msg2	MSG2, MSG3
26862306a36Sopenharmony_ci		sha1rnds4	$3, E0, ABCD
26962306a36Sopenharmony_ci
27062306a36Sopenharmony_ci	/* Rounds 76-79 */
27162306a36Sopenharmony_ci		sha1nexte	MSG3, E1
27262306a36Sopenharmony_ci		movdqa		ABCD, E0
27362306a36Sopenharmony_ci		sha1rnds4	$3, E1, ABCD
27462306a36Sopenharmony_ci
27562306a36Sopenharmony_ci	/* Add current hash values with previously saved */
27662306a36Sopenharmony_ci	sha1nexte	(0*16)(%rsp), E0
27762306a36Sopenharmony_ci	paddd		(1*16)(%rsp), ABCD
27862306a36Sopenharmony_ci
27962306a36Sopenharmony_ci	/* Increment data pointer and loop if more to process */
28062306a36Sopenharmony_ci	add		$64, DATA_PTR
28162306a36Sopenharmony_ci	cmp		NUM_BLKS, DATA_PTR
28262306a36Sopenharmony_ci	jne		.Lloop0
28362306a36Sopenharmony_ci
28462306a36Sopenharmony_ci	/* Write hash values back in the correct order */
28562306a36Sopenharmony_ci	pshufd		$0x1B, ABCD, ABCD
28662306a36Sopenharmony_ci	movdqu		ABCD, 0*16(DIGEST_PTR)
28762306a36Sopenharmony_ci	pextrd		$3, E0, 1*16(DIGEST_PTR)
28862306a36Sopenharmony_ci
28962306a36Sopenharmony_ci.Ldone_hash:
29062306a36Sopenharmony_ci	mov		%rbp, %rsp
29162306a36Sopenharmony_ci	pop		%rbp
29262306a36Sopenharmony_ci
29362306a36Sopenharmony_ci	RET
29462306a36Sopenharmony_ciSYM_FUNC_END(sha1_ni_transform)
29562306a36Sopenharmony_ci
29662306a36Sopenharmony_ci.section	.rodata.cst16.PSHUFFLE_BYTE_FLIP_MASK, "aM", @progbits, 16
29762306a36Sopenharmony_ci.align 16
29862306a36Sopenharmony_ciPSHUFFLE_BYTE_FLIP_MASK:
29962306a36Sopenharmony_ci	.octa 0x000102030405060708090a0b0c0d0e0f
30062306a36Sopenharmony_ci
30162306a36Sopenharmony_ci.section	.rodata.cst16.UPPER_WORD_MASK, "aM", @progbits, 16
30262306a36Sopenharmony_ci.align 16
30362306a36Sopenharmony_ciUPPER_WORD_MASK:
30462306a36Sopenharmony_ci	.octa 0xFFFFFFFF000000000000000000000000
305