162306a36Sopenharmony_ci// SPDX-License-Identifier: GPL-2.0-or-later
262306a36Sopenharmony_ci/*
362306a36Sopenharmony_ci * CCM: Counter with CBC-MAC
462306a36Sopenharmony_ci *
562306a36Sopenharmony_ci * (C) Copyright IBM Corp. 2007 - Joy Latten <latten@us.ibm.com>
662306a36Sopenharmony_ci */
762306a36Sopenharmony_ci
862306a36Sopenharmony_ci#include <crypto/internal/aead.h>
962306a36Sopenharmony_ci#include <crypto/internal/cipher.h>
1062306a36Sopenharmony_ci#include <crypto/internal/hash.h>
1162306a36Sopenharmony_ci#include <crypto/internal/skcipher.h>
1262306a36Sopenharmony_ci#include <crypto/scatterwalk.h>
1362306a36Sopenharmony_ci#include <linux/err.h>
1462306a36Sopenharmony_ci#include <linux/init.h>
1562306a36Sopenharmony_ci#include <linux/kernel.h>
1662306a36Sopenharmony_ci#include <linux/module.h>
1762306a36Sopenharmony_ci#include <linux/slab.h>
1862306a36Sopenharmony_ci
1962306a36Sopenharmony_cistruct ccm_instance_ctx {
2062306a36Sopenharmony_ci	struct crypto_skcipher_spawn ctr;
2162306a36Sopenharmony_ci	struct crypto_ahash_spawn mac;
2262306a36Sopenharmony_ci};
2362306a36Sopenharmony_ci
2462306a36Sopenharmony_cistruct crypto_ccm_ctx {
2562306a36Sopenharmony_ci	struct crypto_ahash *mac;
2662306a36Sopenharmony_ci	struct crypto_skcipher *ctr;
2762306a36Sopenharmony_ci};
2862306a36Sopenharmony_ci
2962306a36Sopenharmony_cistruct crypto_rfc4309_ctx {
3062306a36Sopenharmony_ci	struct crypto_aead *child;
3162306a36Sopenharmony_ci	u8 nonce[3];
3262306a36Sopenharmony_ci};
3362306a36Sopenharmony_ci
3462306a36Sopenharmony_cistruct crypto_rfc4309_req_ctx {
3562306a36Sopenharmony_ci	struct scatterlist src[3];
3662306a36Sopenharmony_ci	struct scatterlist dst[3];
3762306a36Sopenharmony_ci	struct aead_request subreq;
3862306a36Sopenharmony_ci};
3962306a36Sopenharmony_ci
4062306a36Sopenharmony_cistruct crypto_ccm_req_priv_ctx {
4162306a36Sopenharmony_ci	u8 odata[16];
4262306a36Sopenharmony_ci	u8 idata[16];
4362306a36Sopenharmony_ci	u8 auth_tag[16];
4462306a36Sopenharmony_ci	u32 flags;
4562306a36Sopenharmony_ci	struct scatterlist src[3];
4662306a36Sopenharmony_ci	struct scatterlist dst[3];
4762306a36Sopenharmony_ci	union {
4862306a36Sopenharmony_ci		struct ahash_request ahreq;
4962306a36Sopenharmony_ci		struct skcipher_request skreq;
5062306a36Sopenharmony_ci	};
5162306a36Sopenharmony_ci};
5262306a36Sopenharmony_ci
5362306a36Sopenharmony_cistruct cbcmac_tfm_ctx {
5462306a36Sopenharmony_ci	struct crypto_cipher *child;
5562306a36Sopenharmony_ci};
5662306a36Sopenharmony_ci
5762306a36Sopenharmony_cistruct cbcmac_desc_ctx {
5862306a36Sopenharmony_ci	unsigned int len;
5962306a36Sopenharmony_ci};
6062306a36Sopenharmony_ci
6162306a36Sopenharmony_cistatic inline struct crypto_ccm_req_priv_ctx *crypto_ccm_reqctx(
6262306a36Sopenharmony_ci	struct aead_request *req)
6362306a36Sopenharmony_ci{
6462306a36Sopenharmony_ci	unsigned long align = crypto_aead_alignmask(crypto_aead_reqtfm(req));
6562306a36Sopenharmony_ci
6662306a36Sopenharmony_ci	return (void *)PTR_ALIGN((u8 *)aead_request_ctx(req), align + 1);
6762306a36Sopenharmony_ci}
6862306a36Sopenharmony_ci
6962306a36Sopenharmony_cistatic int set_msg_len(u8 *block, unsigned int msglen, int csize)
7062306a36Sopenharmony_ci{
7162306a36Sopenharmony_ci	__be32 data;
7262306a36Sopenharmony_ci
7362306a36Sopenharmony_ci	memset(block, 0, csize);
7462306a36Sopenharmony_ci	block += csize;
7562306a36Sopenharmony_ci
7662306a36Sopenharmony_ci	if (csize >= 4)
7762306a36Sopenharmony_ci		csize = 4;
7862306a36Sopenharmony_ci	else if (msglen > (1 << (8 * csize)))
7962306a36Sopenharmony_ci		return -EOVERFLOW;
8062306a36Sopenharmony_ci
8162306a36Sopenharmony_ci	data = cpu_to_be32(msglen);
8262306a36Sopenharmony_ci	memcpy(block - csize, (u8 *)&data + 4 - csize, csize);
8362306a36Sopenharmony_ci
8462306a36Sopenharmony_ci	return 0;
8562306a36Sopenharmony_ci}
8662306a36Sopenharmony_ci
8762306a36Sopenharmony_cistatic int crypto_ccm_setkey(struct crypto_aead *aead, const u8 *key,
8862306a36Sopenharmony_ci			     unsigned int keylen)
8962306a36Sopenharmony_ci{
9062306a36Sopenharmony_ci	struct crypto_ccm_ctx *ctx = crypto_aead_ctx(aead);
9162306a36Sopenharmony_ci	struct crypto_skcipher *ctr = ctx->ctr;
9262306a36Sopenharmony_ci	struct crypto_ahash *mac = ctx->mac;
9362306a36Sopenharmony_ci	int err;
9462306a36Sopenharmony_ci
9562306a36Sopenharmony_ci	crypto_skcipher_clear_flags(ctr, CRYPTO_TFM_REQ_MASK);
9662306a36Sopenharmony_ci	crypto_skcipher_set_flags(ctr, crypto_aead_get_flags(aead) &
9762306a36Sopenharmony_ci				       CRYPTO_TFM_REQ_MASK);
9862306a36Sopenharmony_ci	err = crypto_skcipher_setkey(ctr, key, keylen);
9962306a36Sopenharmony_ci	if (err)
10062306a36Sopenharmony_ci		return err;
10162306a36Sopenharmony_ci
10262306a36Sopenharmony_ci	crypto_ahash_clear_flags(mac, CRYPTO_TFM_REQ_MASK);
10362306a36Sopenharmony_ci	crypto_ahash_set_flags(mac, crypto_aead_get_flags(aead) &
10462306a36Sopenharmony_ci				    CRYPTO_TFM_REQ_MASK);
10562306a36Sopenharmony_ci	return crypto_ahash_setkey(mac, key, keylen);
10662306a36Sopenharmony_ci}
10762306a36Sopenharmony_ci
10862306a36Sopenharmony_cistatic int crypto_ccm_setauthsize(struct crypto_aead *tfm,
10962306a36Sopenharmony_ci				  unsigned int authsize)
11062306a36Sopenharmony_ci{
11162306a36Sopenharmony_ci	switch (authsize) {
11262306a36Sopenharmony_ci	case 4:
11362306a36Sopenharmony_ci	case 6:
11462306a36Sopenharmony_ci	case 8:
11562306a36Sopenharmony_ci	case 10:
11662306a36Sopenharmony_ci	case 12:
11762306a36Sopenharmony_ci	case 14:
11862306a36Sopenharmony_ci	case 16:
11962306a36Sopenharmony_ci		break;
12062306a36Sopenharmony_ci	default:
12162306a36Sopenharmony_ci		return -EINVAL;
12262306a36Sopenharmony_ci	}
12362306a36Sopenharmony_ci
12462306a36Sopenharmony_ci	return 0;
12562306a36Sopenharmony_ci}
12662306a36Sopenharmony_ci
12762306a36Sopenharmony_cistatic int format_input(u8 *info, struct aead_request *req,
12862306a36Sopenharmony_ci			unsigned int cryptlen)
12962306a36Sopenharmony_ci{
13062306a36Sopenharmony_ci	struct crypto_aead *aead = crypto_aead_reqtfm(req);
13162306a36Sopenharmony_ci	unsigned int lp = req->iv[0];
13262306a36Sopenharmony_ci	unsigned int l = lp + 1;
13362306a36Sopenharmony_ci	unsigned int m;
13462306a36Sopenharmony_ci
13562306a36Sopenharmony_ci	m = crypto_aead_authsize(aead);
13662306a36Sopenharmony_ci
13762306a36Sopenharmony_ci	memcpy(info, req->iv, 16);
13862306a36Sopenharmony_ci
13962306a36Sopenharmony_ci	/* format control info per RFC 3610 and
14062306a36Sopenharmony_ci	 * NIST Special Publication 800-38C
14162306a36Sopenharmony_ci	 */
14262306a36Sopenharmony_ci	*info |= (8 * ((m - 2) / 2));
14362306a36Sopenharmony_ci	if (req->assoclen)
14462306a36Sopenharmony_ci		*info |= 64;
14562306a36Sopenharmony_ci
14662306a36Sopenharmony_ci	return set_msg_len(info + 16 - l, cryptlen, l);
14762306a36Sopenharmony_ci}
14862306a36Sopenharmony_ci
14962306a36Sopenharmony_cistatic int format_adata(u8 *adata, unsigned int a)
15062306a36Sopenharmony_ci{
15162306a36Sopenharmony_ci	int len = 0;
15262306a36Sopenharmony_ci
15362306a36Sopenharmony_ci	/* add control info for associated data
15462306a36Sopenharmony_ci	 * RFC 3610 and NIST Special Publication 800-38C
15562306a36Sopenharmony_ci	 */
15662306a36Sopenharmony_ci	if (a < 65280) {
15762306a36Sopenharmony_ci		*(__be16 *)adata = cpu_to_be16(a);
15862306a36Sopenharmony_ci		len = 2;
15962306a36Sopenharmony_ci	} else  {
16062306a36Sopenharmony_ci		*(__be16 *)adata = cpu_to_be16(0xfffe);
16162306a36Sopenharmony_ci		*(__be32 *)&adata[2] = cpu_to_be32(a);
16262306a36Sopenharmony_ci		len = 6;
16362306a36Sopenharmony_ci	}
16462306a36Sopenharmony_ci
16562306a36Sopenharmony_ci	return len;
16662306a36Sopenharmony_ci}
16762306a36Sopenharmony_ci
16862306a36Sopenharmony_cistatic int crypto_ccm_auth(struct aead_request *req, struct scatterlist *plain,
16962306a36Sopenharmony_ci			   unsigned int cryptlen)
17062306a36Sopenharmony_ci{
17162306a36Sopenharmony_ci	struct crypto_ccm_req_priv_ctx *pctx = crypto_ccm_reqctx(req);
17262306a36Sopenharmony_ci	struct crypto_aead *aead = crypto_aead_reqtfm(req);
17362306a36Sopenharmony_ci	struct crypto_ccm_ctx *ctx = crypto_aead_ctx(aead);
17462306a36Sopenharmony_ci	struct ahash_request *ahreq = &pctx->ahreq;
17562306a36Sopenharmony_ci	unsigned int assoclen = req->assoclen;
17662306a36Sopenharmony_ci	struct scatterlist sg[3];
17762306a36Sopenharmony_ci	u8 *odata = pctx->odata;
17862306a36Sopenharmony_ci	u8 *idata = pctx->idata;
17962306a36Sopenharmony_ci	int ilen, err;
18062306a36Sopenharmony_ci
18162306a36Sopenharmony_ci	/* format control data for input */
18262306a36Sopenharmony_ci	err = format_input(odata, req, cryptlen);
18362306a36Sopenharmony_ci	if (err)
18462306a36Sopenharmony_ci		goto out;
18562306a36Sopenharmony_ci
18662306a36Sopenharmony_ci	sg_init_table(sg, 3);
18762306a36Sopenharmony_ci	sg_set_buf(&sg[0], odata, 16);
18862306a36Sopenharmony_ci
18962306a36Sopenharmony_ci	/* format associated data and compute into mac */
19062306a36Sopenharmony_ci	if (assoclen) {
19162306a36Sopenharmony_ci		ilen = format_adata(idata, assoclen);
19262306a36Sopenharmony_ci		sg_set_buf(&sg[1], idata, ilen);
19362306a36Sopenharmony_ci		sg_chain(sg, 3, req->src);
19462306a36Sopenharmony_ci	} else {
19562306a36Sopenharmony_ci		ilen = 0;
19662306a36Sopenharmony_ci		sg_chain(sg, 2, req->src);
19762306a36Sopenharmony_ci	}
19862306a36Sopenharmony_ci
19962306a36Sopenharmony_ci	ahash_request_set_tfm(ahreq, ctx->mac);
20062306a36Sopenharmony_ci	ahash_request_set_callback(ahreq, pctx->flags, NULL, NULL);
20162306a36Sopenharmony_ci	ahash_request_set_crypt(ahreq, sg, NULL, assoclen + ilen + 16);
20262306a36Sopenharmony_ci	err = crypto_ahash_init(ahreq);
20362306a36Sopenharmony_ci	if (err)
20462306a36Sopenharmony_ci		goto out;
20562306a36Sopenharmony_ci	err = crypto_ahash_update(ahreq);
20662306a36Sopenharmony_ci	if (err)
20762306a36Sopenharmony_ci		goto out;
20862306a36Sopenharmony_ci
20962306a36Sopenharmony_ci	/* we need to pad the MAC input to a round multiple of the block size */
21062306a36Sopenharmony_ci	ilen = 16 - (assoclen + ilen) % 16;
21162306a36Sopenharmony_ci	if (ilen < 16) {
21262306a36Sopenharmony_ci		memset(idata, 0, ilen);
21362306a36Sopenharmony_ci		sg_init_table(sg, 2);
21462306a36Sopenharmony_ci		sg_set_buf(&sg[0], idata, ilen);
21562306a36Sopenharmony_ci		if (plain)
21662306a36Sopenharmony_ci			sg_chain(sg, 2, plain);
21762306a36Sopenharmony_ci		plain = sg;
21862306a36Sopenharmony_ci		cryptlen += ilen;
21962306a36Sopenharmony_ci	}
22062306a36Sopenharmony_ci
22162306a36Sopenharmony_ci	ahash_request_set_crypt(ahreq, plain, odata, cryptlen);
22262306a36Sopenharmony_ci	err = crypto_ahash_finup(ahreq);
22362306a36Sopenharmony_ciout:
22462306a36Sopenharmony_ci	return err;
22562306a36Sopenharmony_ci}
22662306a36Sopenharmony_ci
22762306a36Sopenharmony_cistatic void crypto_ccm_encrypt_done(void *data, int err)
22862306a36Sopenharmony_ci{
22962306a36Sopenharmony_ci	struct aead_request *req = data;
23062306a36Sopenharmony_ci	struct crypto_aead *aead = crypto_aead_reqtfm(req);
23162306a36Sopenharmony_ci	struct crypto_ccm_req_priv_ctx *pctx = crypto_ccm_reqctx(req);
23262306a36Sopenharmony_ci	u8 *odata = pctx->odata;
23362306a36Sopenharmony_ci
23462306a36Sopenharmony_ci	if (!err)
23562306a36Sopenharmony_ci		scatterwalk_map_and_copy(odata, req->dst,
23662306a36Sopenharmony_ci					 req->assoclen + req->cryptlen,
23762306a36Sopenharmony_ci					 crypto_aead_authsize(aead), 1);
23862306a36Sopenharmony_ci	aead_request_complete(req, err);
23962306a36Sopenharmony_ci}
24062306a36Sopenharmony_ci
24162306a36Sopenharmony_cistatic inline int crypto_ccm_check_iv(const u8 *iv)
24262306a36Sopenharmony_ci{
24362306a36Sopenharmony_ci	/* 2 <= L <= 8, so 1 <= L' <= 7. */
24462306a36Sopenharmony_ci	if (1 > iv[0] || iv[0] > 7)
24562306a36Sopenharmony_ci		return -EINVAL;
24662306a36Sopenharmony_ci
24762306a36Sopenharmony_ci	return 0;
24862306a36Sopenharmony_ci}
24962306a36Sopenharmony_ci
25062306a36Sopenharmony_cistatic int crypto_ccm_init_crypt(struct aead_request *req, u8 *tag)
25162306a36Sopenharmony_ci{
25262306a36Sopenharmony_ci	struct crypto_ccm_req_priv_ctx *pctx = crypto_ccm_reqctx(req);
25362306a36Sopenharmony_ci	struct scatterlist *sg;
25462306a36Sopenharmony_ci	u8 *iv = req->iv;
25562306a36Sopenharmony_ci	int err;
25662306a36Sopenharmony_ci
25762306a36Sopenharmony_ci	err = crypto_ccm_check_iv(iv);
25862306a36Sopenharmony_ci	if (err)
25962306a36Sopenharmony_ci		return err;
26062306a36Sopenharmony_ci
26162306a36Sopenharmony_ci	pctx->flags = aead_request_flags(req);
26262306a36Sopenharmony_ci
26362306a36Sopenharmony_ci	 /* Note: rfc 3610 and NIST 800-38C require counter of
26462306a36Sopenharmony_ci	 * zero to encrypt auth tag.
26562306a36Sopenharmony_ci	 */
26662306a36Sopenharmony_ci	memset(iv + 15 - iv[0], 0, iv[0] + 1);
26762306a36Sopenharmony_ci
26862306a36Sopenharmony_ci	sg_init_table(pctx->src, 3);
26962306a36Sopenharmony_ci	sg_set_buf(pctx->src, tag, 16);
27062306a36Sopenharmony_ci	sg = scatterwalk_ffwd(pctx->src + 1, req->src, req->assoclen);
27162306a36Sopenharmony_ci	if (sg != pctx->src + 1)
27262306a36Sopenharmony_ci		sg_chain(pctx->src, 2, sg);
27362306a36Sopenharmony_ci
27462306a36Sopenharmony_ci	if (req->src != req->dst) {
27562306a36Sopenharmony_ci		sg_init_table(pctx->dst, 3);
27662306a36Sopenharmony_ci		sg_set_buf(pctx->dst, tag, 16);
27762306a36Sopenharmony_ci		sg = scatterwalk_ffwd(pctx->dst + 1, req->dst, req->assoclen);
27862306a36Sopenharmony_ci		if (sg != pctx->dst + 1)
27962306a36Sopenharmony_ci			sg_chain(pctx->dst, 2, sg);
28062306a36Sopenharmony_ci	}
28162306a36Sopenharmony_ci
28262306a36Sopenharmony_ci	return 0;
28362306a36Sopenharmony_ci}
28462306a36Sopenharmony_ci
28562306a36Sopenharmony_cistatic int crypto_ccm_encrypt(struct aead_request *req)
28662306a36Sopenharmony_ci{
28762306a36Sopenharmony_ci	struct crypto_aead *aead = crypto_aead_reqtfm(req);
28862306a36Sopenharmony_ci	struct crypto_ccm_ctx *ctx = crypto_aead_ctx(aead);
28962306a36Sopenharmony_ci	struct crypto_ccm_req_priv_ctx *pctx = crypto_ccm_reqctx(req);
29062306a36Sopenharmony_ci	struct skcipher_request *skreq = &pctx->skreq;
29162306a36Sopenharmony_ci	struct scatterlist *dst;
29262306a36Sopenharmony_ci	unsigned int cryptlen = req->cryptlen;
29362306a36Sopenharmony_ci	u8 *odata = pctx->odata;
29462306a36Sopenharmony_ci	u8 *iv = req->iv;
29562306a36Sopenharmony_ci	int err;
29662306a36Sopenharmony_ci
29762306a36Sopenharmony_ci	err = crypto_ccm_init_crypt(req, odata);
29862306a36Sopenharmony_ci	if (err)
29962306a36Sopenharmony_ci		return err;
30062306a36Sopenharmony_ci
30162306a36Sopenharmony_ci	err = crypto_ccm_auth(req, sg_next(pctx->src), cryptlen);
30262306a36Sopenharmony_ci	if (err)
30362306a36Sopenharmony_ci		return err;
30462306a36Sopenharmony_ci
30562306a36Sopenharmony_ci	dst = pctx->src;
30662306a36Sopenharmony_ci	if (req->src != req->dst)
30762306a36Sopenharmony_ci		dst = pctx->dst;
30862306a36Sopenharmony_ci
30962306a36Sopenharmony_ci	skcipher_request_set_tfm(skreq, ctx->ctr);
31062306a36Sopenharmony_ci	skcipher_request_set_callback(skreq, pctx->flags,
31162306a36Sopenharmony_ci				      crypto_ccm_encrypt_done, req);
31262306a36Sopenharmony_ci	skcipher_request_set_crypt(skreq, pctx->src, dst, cryptlen + 16, iv);
31362306a36Sopenharmony_ci	err = crypto_skcipher_encrypt(skreq);
31462306a36Sopenharmony_ci	if (err)
31562306a36Sopenharmony_ci		return err;
31662306a36Sopenharmony_ci
31762306a36Sopenharmony_ci	/* copy authtag to end of dst */
31862306a36Sopenharmony_ci	scatterwalk_map_and_copy(odata, sg_next(dst), cryptlen,
31962306a36Sopenharmony_ci				 crypto_aead_authsize(aead), 1);
32062306a36Sopenharmony_ci	return err;
32162306a36Sopenharmony_ci}
32262306a36Sopenharmony_ci
32362306a36Sopenharmony_cistatic void crypto_ccm_decrypt_done(void *data, int err)
32462306a36Sopenharmony_ci{
32562306a36Sopenharmony_ci	struct aead_request *req = data;
32662306a36Sopenharmony_ci	struct crypto_ccm_req_priv_ctx *pctx = crypto_ccm_reqctx(req);
32762306a36Sopenharmony_ci	struct crypto_aead *aead = crypto_aead_reqtfm(req);
32862306a36Sopenharmony_ci	unsigned int authsize = crypto_aead_authsize(aead);
32962306a36Sopenharmony_ci	unsigned int cryptlen = req->cryptlen - authsize;
33062306a36Sopenharmony_ci	struct scatterlist *dst;
33162306a36Sopenharmony_ci
33262306a36Sopenharmony_ci	pctx->flags = 0;
33362306a36Sopenharmony_ci
33462306a36Sopenharmony_ci	dst = sg_next(req->src == req->dst ? pctx->src : pctx->dst);
33562306a36Sopenharmony_ci
33662306a36Sopenharmony_ci	if (!err) {
33762306a36Sopenharmony_ci		err = crypto_ccm_auth(req, dst, cryptlen);
33862306a36Sopenharmony_ci		if (!err && crypto_memneq(pctx->auth_tag, pctx->odata, authsize))
33962306a36Sopenharmony_ci			err = -EBADMSG;
34062306a36Sopenharmony_ci	}
34162306a36Sopenharmony_ci	aead_request_complete(req, err);
34262306a36Sopenharmony_ci}
34362306a36Sopenharmony_ci
34462306a36Sopenharmony_cistatic int crypto_ccm_decrypt(struct aead_request *req)
34562306a36Sopenharmony_ci{
34662306a36Sopenharmony_ci	struct crypto_aead *aead = crypto_aead_reqtfm(req);
34762306a36Sopenharmony_ci	struct crypto_ccm_ctx *ctx = crypto_aead_ctx(aead);
34862306a36Sopenharmony_ci	struct crypto_ccm_req_priv_ctx *pctx = crypto_ccm_reqctx(req);
34962306a36Sopenharmony_ci	struct skcipher_request *skreq = &pctx->skreq;
35062306a36Sopenharmony_ci	struct scatterlist *dst;
35162306a36Sopenharmony_ci	unsigned int authsize = crypto_aead_authsize(aead);
35262306a36Sopenharmony_ci	unsigned int cryptlen = req->cryptlen;
35362306a36Sopenharmony_ci	u8 *authtag = pctx->auth_tag;
35462306a36Sopenharmony_ci	u8 *odata = pctx->odata;
35562306a36Sopenharmony_ci	u8 *iv = pctx->idata;
35662306a36Sopenharmony_ci	int err;
35762306a36Sopenharmony_ci
35862306a36Sopenharmony_ci	cryptlen -= authsize;
35962306a36Sopenharmony_ci
36062306a36Sopenharmony_ci	err = crypto_ccm_init_crypt(req, authtag);
36162306a36Sopenharmony_ci	if (err)
36262306a36Sopenharmony_ci		return err;
36362306a36Sopenharmony_ci
36462306a36Sopenharmony_ci	scatterwalk_map_and_copy(authtag, sg_next(pctx->src), cryptlen,
36562306a36Sopenharmony_ci				 authsize, 0);
36662306a36Sopenharmony_ci
36762306a36Sopenharmony_ci	dst = pctx->src;
36862306a36Sopenharmony_ci	if (req->src != req->dst)
36962306a36Sopenharmony_ci		dst = pctx->dst;
37062306a36Sopenharmony_ci
37162306a36Sopenharmony_ci	memcpy(iv, req->iv, 16);
37262306a36Sopenharmony_ci
37362306a36Sopenharmony_ci	skcipher_request_set_tfm(skreq, ctx->ctr);
37462306a36Sopenharmony_ci	skcipher_request_set_callback(skreq, pctx->flags,
37562306a36Sopenharmony_ci				      crypto_ccm_decrypt_done, req);
37662306a36Sopenharmony_ci	skcipher_request_set_crypt(skreq, pctx->src, dst, cryptlen + 16, iv);
37762306a36Sopenharmony_ci	err = crypto_skcipher_decrypt(skreq);
37862306a36Sopenharmony_ci	if (err)
37962306a36Sopenharmony_ci		return err;
38062306a36Sopenharmony_ci
38162306a36Sopenharmony_ci	err = crypto_ccm_auth(req, sg_next(dst), cryptlen);
38262306a36Sopenharmony_ci	if (err)
38362306a36Sopenharmony_ci		return err;
38462306a36Sopenharmony_ci
38562306a36Sopenharmony_ci	/* verify */
38662306a36Sopenharmony_ci	if (crypto_memneq(authtag, odata, authsize))
38762306a36Sopenharmony_ci		return -EBADMSG;
38862306a36Sopenharmony_ci
38962306a36Sopenharmony_ci	return err;
39062306a36Sopenharmony_ci}
39162306a36Sopenharmony_ci
39262306a36Sopenharmony_cistatic int crypto_ccm_init_tfm(struct crypto_aead *tfm)
39362306a36Sopenharmony_ci{
39462306a36Sopenharmony_ci	struct aead_instance *inst = aead_alg_instance(tfm);
39562306a36Sopenharmony_ci	struct ccm_instance_ctx *ictx = aead_instance_ctx(inst);
39662306a36Sopenharmony_ci	struct crypto_ccm_ctx *ctx = crypto_aead_ctx(tfm);
39762306a36Sopenharmony_ci	struct crypto_ahash *mac;
39862306a36Sopenharmony_ci	struct crypto_skcipher *ctr;
39962306a36Sopenharmony_ci	unsigned long align;
40062306a36Sopenharmony_ci	int err;
40162306a36Sopenharmony_ci
40262306a36Sopenharmony_ci	mac = crypto_spawn_ahash(&ictx->mac);
40362306a36Sopenharmony_ci	if (IS_ERR(mac))
40462306a36Sopenharmony_ci		return PTR_ERR(mac);
40562306a36Sopenharmony_ci
40662306a36Sopenharmony_ci	ctr = crypto_spawn_skcipher(&ictx->ctr);
40762306a36Sopenharmony_ci	err = PTR_ERR(ctr);
40862306a36Sopenharmony_ci	if (IS_ERR(ctr))
40962306a36Sopenharmony_ci		goto err_free_mac;
41062306a36Sopenharmony_ci
41162306a36Sopenharmony_ci	ctx->mac = mac;
41262306a36Sopenharmony_ci	ctx->ctr = ctr;
41362306a36Sopenharmony_ci
41462306a36Sopenharmony_ci	align = crypto_aead_alignmask(tfm);
41562306a36Sopenharmony_ci	align &= ~(crypto_tfm_ctx_alignment() - 1);
41662306a36Sopenharmony_ci	crypto_aead_set_reqsize(
41762306a36Sopenharmony_ci		tfm,
41862306a36Sopenharmony_ci		align + sizeof(struct crypto_ccm_req_priv_ctx) +
41962306a36Sopenharmony_ci		max(crypto_ahash_reqsize(mac), crypto_skcipher_reqsize(ctr)));
42062306a36Sopenharmony_ci
42162306a36Sopenharmony_ci	return 0;
42262306a36Sopenharmony_ci
42362306a36Sopenharmony_cierr_free_mac:
42462306a36Sopenharmony_ci	crypto_free_ahash(mac);
42562306a36Sopenharmony_ci	return err;
42662306a36Sopenharmony_ci}
42762306a36Sopenharmony_ci
42862306a36Sopenharmony_cistatic void crypto_ccm_exit_tfm(struct crypto_aead *tfm)
42962306a36Sopenharmony_ci{
43062306a36Sopenharmony_ci	struct crypto_ccm_ctx *ctx = crypto_aead_ctx(tfm);
43162306a36Sopenharmony_ci
43262306a36Sopenharmony_ci	crypto_free_ahash(ctx->mac);
43362306a36Sopenharmony_ci	crypto_free_skcipher(ctx->ctr);
43462306a36Sopenharmony_ci}
43562306a36Sopenharmony_ci
43662306a36Sopenharmony_cistatic void crypto_ccm_free(struct aead_instance *inst)
43762306a36Sopenharmony_ci{
43862306a36Sopenharmony_ci	struct ccm_instance_ctx *ctx = aead_instance_ctx(inst);
43962306a36Sopenharmony_ci
44062306a36Sopenharmony_ci	crypto_drop_ahash(&ctx->mac);
44162306a36Sopenharmony_ci	crypto_drop_skcipher(&ctx->ctr);
44262306a36Sopenharmony_ci	kfree(inst);
44362306a36Sopenharmony_ci}
44462306a36Sopenharmony_ci
44562306a36Sopenharmony_cistatic int crypto_ccm_create_common(struct crypto_template *tmpl,
44662306a36Sopenharmony_ci				    struct rtattr **tb,
44762306a36Sopenharmony_ci				    const char *ctr_name,
44862306a36Sopenharmony_ci				    const char *mac_name)
44962306a36Sopenharmony_ci{
45062306a36Sopenharmony_ci	u32 mask;
45162306a36Sopenharmony_ci	struct aead_instance *inst;
45262306a36Sopenharmony_ci	struct ccm_instance_ctx *ictx;
45362306a36Sopenharmony_ci	struct skcipher_alg *ctr;
45462306a36Sopenharmony_ci	struct hash_alg_common *mac;
45562306a36Sopenharmony_ci	int err;
45662306a36Sopenharmony_ci
45762306a36Sopenharmony_ci	err = crypto_check_attr_type(tb, CRYPTO_ALG_TYPE_AEAD, &mask);
45862306a36Sopenharmony_ci	if (err)
45962306a36Sopenharmony_ci		return err;
46062306a36Sopenharmony_ci
46162306a36Sopenharmony_ci	inst = kzalloc(sizeof(*inst) + sizeof(*ictx), GFP_KERNEL);
46262306a36Sopenharmony_ci	if (!inst)
46362306a36Sopenharmony_ci		return -ENOMEM;
46462306a36Sopenharmony_ci	ictx = aead_instance_ctx(inst);
46562306a36Sopenharmony_ci
46662306a36Sopenharmony_ci	err = crypto_grab_ahash(&ictx->mac, aead_crypto_instance(inst),
46762306a36Sopenharmony_ci				mac_name, 0, mask | CRYPTO_ALG_ASYNC);
46862306a36Sopenharmony_ci	if (err)
46962306a36Sopenharmony_ci		goto err_free_inst;
47062306a36Sopenharmony_ci	mac = crypto_spawn_ahash_alg(&ictx->mac);
47162306a36Sopenharmony_ci
47262306a36Sopenharmony_ci	err = -EINVAL;
47362306a36Sopenharmony_ci	if (strncmp(mac->base.cra_name, "cbcmac(", 7) != 0 ||
47462306a36Sopenharmony_ci	    mac->digestsize != 16)
47562306a36Sopenharmony_ci		goto err_free_inst;
47662306a36Sopenharmony_ci
47762306a36Sopenharmony_ci	err = crypto_grab_skcipher(&ictx->ctr, aead_crypto_instance(inst),
47862306a36Sopenharmony_ci				   ctr_name, 0, mask);
47962306a36Sopenharmony_ci	if (err)
48062306a36Sopenharmony_ci		goto err_free_inst;
48162306a36Sopenharmony_ci	ctr = crypto_spawn_skcipher_alg(&ictx->ctr);
48262306a36Sopenharmony_ci
48362306a36Sopenharmony_ci	/* The skcipher algorithm must be CTR mode, using 16-byte blocks. */
48462306a36Sopenharmony_ci	err = -EINVAL;
48562306a36Sopenharmony_ci	if (strncmp(ctr->base.cra_name, "ctr(", 4) != 0 ||
48662306a36Sopenharmony_ci	    crypto_skcipher_alg_ivsize(ctr) != 16 ||
48762306a36Sopenharmony_ci	    ctr->base.cra_blocksize != 1)
48862306a36Sopenharmony_ci		goto err_free_inst;
48962306a36Sopenharmony_ci
49062306a36Sopenharmony_ci	/* ctr and cbcmac must use the same underlying block cipher. */
49162306a36Sopenharmony_ci	if (strcmp(ctr->base.cra_name + 4, mac->base.cra_name + 7) != 0)
49262306a36Sopenharmony_ci		goto err_free_inst;
49362306a36Sopenharmony_ci
49462306a36Sopenharmony_ci	err = -ENAMETOOLONG;
49562306a36Sopenharmony_ci	if (snprintf(inst->alg.base.cra_name, CRYPTO_MAX_ALG_NAME,
49662306a36Sopenharmony_ci		     "ccm(%s", ctr->base.cra_name + 4) >= CRYPTO_MAX_ALG_NAME)
49762306a36Sopenharmony_ci		goto err_free_inst;
49862306a36Sopenharmony_ci
49962306a36Sopenharmony_ci	if (snprintf(inst->alg.base.cra_driver_name, CRYPTO_MAX_ALG_NAME,
50062306a36Sopenharmony_ci		     "ccm_base(%s,%s)", ctr->base.cra_driver_name,
50162306a36Sopenharmony_ci		     mac->base.cra_driver_name) >= CRYPTO_MAX_ALG_NAME)
50262306a36Sopenharmony_ci		goto err_free_inst;
50362306a36Sopenharmony_ci
50462306a36Sopenharmony_ci	inst->alg.base.cra_priority = (mac->base.cra_priority +
50562306a36Sopenharmony_ci				       ctr->base.cra_priority) / 2;
50662306a36Sopenharmony_ci	inst->alg.base.cra_blocksize = 1;
50762306a36Sopenharmony_ci	inst->alg.base.cra_alignmask = mac->base.cra_alignmask |
50862306a36Sopenharmony_ci				       ctr->base.cra_alignmask;
50962306a36Sopenharmony_ci	inst->alg.ivsize = 16;
51062306a36Sopenharmony_ci	inst->alg.chunksize = crypto_skcipher_alg_chunksize(ctr);
51162306a36Sopenharmony_ci	inst->alg.maxauthsize = 16;
51262306a36Sopenharmony_ci	inst->alg.base.cra_ctxsize = sizeof(struct crypto_ccm_ctx);
51362306a36Sopenharmony_ci	inst->alg.init = crypto_ccm_init_tfm;
51462306a36Sopenharmony_ci	inst->alg.exit = crypto_ccm_exit_tfm;
51562306a36Sopenharmony_ci	inst->alg.setkey = crypto_ccm_setkey;
51662306a36Sopenharmony_ci	inst->alg.setauthsize = crypto_ccm_setauthsize;
51762306a36Sopenharmony_ci	inst->alg.encrypt = crypto_ccm_encrypt;
51862306a36Sopenharmony_ci	inst->alg.decrypt = crypto_ccm_decrypt;
51962306a36Sopenharmony_ci
52062306a36Sopenharmony_ci	inst->free = crypto_ccm_free;
52162306a36Sopenharmony_ci
52262306a36Sopenharmony_ci	err = aead_register_instance(tmpl, inst);
52362306a36Sopenharmony_ci	if (err) {
52462306a36Sopenharmony_cierr_free_inst:
52562306a36Sopenharmony_ci		crypto_ccm_free(inst);
52662306a36Sopenharmony_ci	}
52762306a36Sopenharmony_ci	return err;
52862306a36Sopenharmony_ci}
52962306a36Sopenharmony_ci
53062306a36Sopenharmony_cistatic int crypto_ccm_create(struct crypto_template *tmpl, struct rtattr **tb)
53162306a36Sopenharmony_ci{
53262306a36Sopenharmony_ci	const char *cipher_name;
53362306a36Sopenharmony_ci	char ctr_name[CRYPTO_MAX_ALG_NAME];
53462306a36Sopenharmony_ci	char mac_name[CRYPTO_MAX_ALG_NAME];
53562306a36Sopenharmony_ci
53662306a36Sopenharmony_ci	cipher_name = crypto_attr_alg_name(tb[1]);
53762306a36Sopenharmony_ci	if (IS_ERR(cipher_name))
53862306a36Sopenharmony_ci		return PTR_ERR(cipher_name);
53962306a36Sopenharmony_ci
54062306a36Sopenharmony_ci	if (snprintf(ctr_name, CRYPTO_MAX_ALG_NAME, "ctr(%s)",
54162306a36Sopenharmony_ci		     cipher_name) >= CRYPTO_MAX_ALG_NAME)
54262306a36Sopenharmony_ci		return -ENAMETOOLONG;
54362306a36Sopenharmony_ci
54462306a36Sopenharmony_ci	if (snprintf(mac_name, CRYPTO_MAX_ALG_NAME, "cbcmac(%s)",
54562306a36Sopenharmony_ci		     cipher_name) >= CRYPTO_MAX_ALG_NAME)
54662306a36Sopenharmony_ci		return -ENAMETOOLONG;
54762306a36Sopenharmony_ci
54862306a36Sopenharmony_ci	return crypto_ccm_create_common(tmpl, tb, ctr_name, mac_name);
54962306a36Sopenharmony_ci}
55062306a36Sopenharmony_ci
55162306a36Sopenharmony_cistatic int crypto_ccm_base_create(struct crypto_template *tmpl,
55262306a36Sopenharmony_ci				  struct rtattr **tb)
55362306a36Sopenharmony_ci{
55462306a36Sopenharmony_ci	const char *ctr_name;
55562306a36Sopenharmony_ci	const char *mac_name;
55662306a36Sopenharmony_ci
55762306a36Sopenharmony_ci	ctr_name = crypto_attr_alg_name(tb[1]);
55862306a36Sopenharmony_ci	if (IS_ERR(ctr_name))
55962306a36Sopenharmony_ci		return PTR_ERR(ctr_name);
56062306a36Sopenharmony_ci
56162306a36Sopenharmony_ci	mac_name = crypto_attr_alg_name(tb[2]);
56262306a36Sopenharmony_ci	if (IS_ERR(mac_name))
56362306a36Sopenharmony_ci		return PTR_ERR(mac_name);
56462306a36Sopenharmony_ci
56562306a36Sopenharmony_ci	return crypto_ccm_create_common(tmpl, tb, ctr_name, mac_name);
56662306a36Sopenharmony_ci}
56762306a36Sopenharmony_ci
56862306a36Sopenharmony_cistatic int crypto_rfc4309_setkey(struct crypto_aead *parent, const u8 *key,
56962306a36Sopenharmony_ci				 unsigned int keylen)
57062306a36Sopenharmony_ci{
57162306a36Sopenharmony_ci	struct crypto_rfc4309_ctx *ctx = crypto_aead_ctx(parent);
57262306a36Sopenharmony_ci	struct crypto_aead *child = ctx->child;
57362306a36Sopenharmony_ci
57462306a36Sopenharmony_ci	if (keylen < 3)
57562306a36Sopenharmony_ci		return -EINVAL;
57662306a36Sopenharmony_ci
57762306a36Sopenharmony_ci	keylen -= 3;
57862306a36Sopenharmony_ci	memcpy(ctx->nonce, key + keylen, 3);
57962306a36Sopenharmony_ci
58062306a36Sopenharmony_ci	crypto_aead_clear_flags(child, CRYPTO_TFM_REQ_MASK);
58162306a36Sopenharmony_ci	crypto_aead_set_flags(child, crypto_aead_get_flags(parent) &
58262306a36Sopenharmony_ci				     CRYPTO_TFM_REQ_MASK);
58362306a36Sopenharmony_ci	return crypto_aead_setkey(child, key, keylen);
58462306a36Sopenharmony_ci}
58562306a36Sopenharmony_ci
58662306a36Sopenharmony_cistatic int crypto_rfc4309_setauthsize(struct crypto_aead *parent,
58762306a36Sopenharmony_ci				      unsigned int authsize)
58862306a36Sopenharmony_ci{
58962306a36Sopenharmony_ci	struct crypto_rfc4309_ctx *ctx = crypto_aead_ctx(parent);
59062306a36Sopenharmony_ci
59162306a36Sopenharmony_ci	switch (authsize) {
59262306a36Sopenharmony_ci	case 8:
59362306a36Sopenharmony_ci	case 12:
59462306a36Sopenharmony_ci	case 16:
59562306a36Sopenharmony_ci		break;
59662306a36Sopenharmony_ci	default:
59762306a36Sopenharmony_ci		return -EINVAL;
59862306a36Sopenharmony_ci	}
59962306a36Sopenharmony_ci
60062306a36Sopenharmony_ci	return crypto_aead_setauthsize(ctx->child, authsize);
60162306a36Sopenharmony_ci}
60262306a36Sopenharmony_ci
60362306a36Sopenharmony_cistatic struct aead_request *crypto_rfc4309_crypt(struct aead_request *req)
60462306a36Sopenharmony_ci{
60562306a36Sopenharmony_ci	struct crypto_rfc4309_req_ctx *rctx = aead_request_ctx(req);
60662306a36Sopenharmony_ci	struct aead_request *subreq = &rctx->subreq;
60762306a36Sopenharmony_ci	struct crypto_aead *aead = crypto_aead_reqtfm(req);
60862306a36Sopenharmony_ci	struct crypto_rfc4309_ctx *ctx = crypto_aead_ctx(aead);
60962306a36Sopenharmony_ci	struct crypto_aead *child = ctx->child;
61062306a36Sopenharmony_ci	struct scatterlist *sg;
61162306a36Sopenharmony_ci	u8 *iv = PTR_ALIGN((u8 *)(subreq + 1) + crypto_aead_reqsize(child),
61262306a36Sopenharmony_ci			   crypto_aead_alignmask(child) + 1);
61362306a36Sopenharmony_ci
61462306a36Sopenharmony_ci	/* L' */
61562306a36Sopenharmony_ci	iv[0] = 3;
61662306a36Sopenharmony_ci
61762306a36Sopenharmony_ci	memcpy(iv + 1, ctx->nonce, 3);
61862306a36Sopenharmony_ci	memcpy(iv + 4, req->iv, 8);
61962306a36Sopenharmony_ci
62062306a36Sopenharmony_ci	scatterwalk_map_and_copy(iv + 16, req->src, 0, req->assoclen - 8, 0);
62162306a36Sopenharmony_ci
62262306a36Sopenharmony_ci	sg_init_table(rctx->src, 3);
62362306a36Sopenharmony_ci	sg_set_buf(rctx->src, iv + 16, req->assoclen - 8);
62462306a36Sopenharmony_ci	sg = scatterwalk_ffwd(rctx->src + 1, req->src, req->assoclen);
62562306a36Sopenharmony_ci	if (sg != rctx->src + 1)
62662306a36Sopenharmony_ci		sg_chain(rctx->src, 2, sg);
62762306a36Sopenharmony_ci
62862306a36Sopenharmony_ci	if (req->src != req->dst) {
62962306a36Sopenharmony_ci		sg_init_table(rctx->dst, 3);
63062306a36Sopenharmony_ci		sg_set_buf(rctx->dst, iv + 16, req->assoclen - 8);
63162306a36Sopenharmony_ci		sg = scatterwalk_ffwd(rctx->dst + 1, req->dst, req->assoclen);
63262306a36Sopenharmony_ci		if (sg != rctx->dst + 1)
63362306a36Sopenharmony_ci			sg_chain(rctx->dst, 2, sg);
63462306a36Sopenharmony_ci	}
63562306a36Sopenharmony_ci
63662306a36Sopenharmony_ci	aead_request_set_tfm(subreq, child);
63762306a36Sopenharmony_ci	aead_request_set_callback(subreq, req->base.flags, req->base.complete,
63862306a36Sopenharmony_ci				  req->base.data);
63962306a36Sopenharmony_ci	aead_request_set_crypt(subreq, rctx->src,
64062306a36Sopenharmony_ci			       req->src == req->dst ? rctx->src : rctx->dst,
64162306a36Sopenharmony_ci			       req->cryptlen, iv);
64262306a36Sopenharmony_ci	aead_request_set_ad(subreq, req->assoclen - 8);
64362306a36Sopenharmony_ci
64462306a36Sopenharmony_ci	return subreq;
64562306a36Sopenharmony_ci}
64662306a36Sopenharmony_ci
64762306a36Sopenharmony_cistatic int crypto_rfc4309_encrypt(struct aead_request *req)
64862306a36Sopenharmony_ci{
64962306a36Sopenharmony_ci	if (req->assoclen != 16 && req->assoclen != 20)
65062306a36Sopenharmony_ci		return -EINVAL;
65162306a36Sopenharmony_ci
65262306a36Sopenharmony_ci	req = crypto_rfc4309_crypt(req);
65362306a36Sopenharmony_ci
65462306a36Sopenharmony_ci	return crypto_aead_encrypt(req);
65562306a36Sopenharmony_ci}
65662306a36Sopenharmony_ci
65762306a36Sopenharmony_cistatic int crypto_rfc4309_decrypt(struct aead_request *req)
65862306a36Sopenharmony_ci{
65962306a36Sopenharmony_ci	if (req->assoclen != 16 && req->assoclen != 20)
66062306a36Sopenharmony_ci		return -EINVAL;
66162306a36Sopenharmony_ci
66262306a36Sopenharmony_ci	req = crypto_rfc4309_crypt(req);
66362306a36Sopenharmony_ci
66462306a36Sopenharmony_ci	return crypto_aead_decrypt(req);
66562306a36Sopenharmony_ci}
66662306a36Sopenharmony_ci
66762306a36Sopenharmony_cistatic int crypto_rfc4309_init_tfm(struct crypto_aead *tfm)
66862306a36Sopenharmony_ci{
66962306a36Sopenharmony_ci	struct aead_instance *inst = aead_alg_instance(tfm);
67062306a36Sopenharmony_ci	struct crypto_aead_spawn *spawn = aead_instance_ctx(inst);
67162306a36Sopenharmony_ci	struct crypto_rfc4309_ctx *ctx = crypto_aead_ctx(tfm);
67262306a36Sopenharmony_ci	struct crypto_aead *aead;
67362306a36Sopenharmony_ci	unsigned long align;
67462306a36Sopenharmony_ci
67562306a36Sopenharmony_ci	aead = crypto_spawn_aead(spawn);
67662306a36Sopenharmony_ci	if (IS_ERR(aead))
67762306a36Sopenharmony_ci		return PTR_ERR(aead);
67862306a36Sopenharmony_ci
67962306a36Sopenharmony_ci	ctx->child = aead;
68062306a36Sopenharmony_ci
68162306a36Sopenharmony_ci	align = crypto_aead_alignmask(aead);
68262306a36Sopenharmony_ci	align &= ~(crypto_tfm_ctx_alignment() - 1);
68362306a36Sopenharmony_ci	crypto_aead_set_reqsize(
68462306a36Sopenharmony_ci		tfm,
68562306a36Sopenharmony_ci		sizeof(struct crypto_rfc4309_req_ctx) +
68662306a36Sopenharmony_ci		ALIGN(crypto_aead_reqsize(aead), crypto_tfm_ctx_alignment()) +
68762306a36Sopenharmony_ci		align + 32);
68862306a36Sopenharmony_ci
68962306a36Sopenharmony_ci	return 0;
69062306a36Sopenharmony_ci}
69162306a36Sopenharmony_ci
69262306a36Sopenharmony_cistatic void crypto_rfc4309_exit_tfm(struct crypto_aead *tfm)
69362306a36Sopenharmony_ci{
69462306a36Sopenharmony_ci	struct crypto_rfc4309_ctx *ctx = crypto_aead_ctx(tfm);
69562306a36Sopenharmony_ci
69662306a36Sopenharmony_ci	crypto_free_aead(ctx->child);
69762306a36Sopenharmony_ci}
69862306a36Sopenharmony_ci
69962306a36Sopenharmony_cistatic void crypto_rfc4309_free(struct aead_instance *inst)
70062306a36Sopenharmony_ci{
70162306a36Sopenharmony_ci	crypto_drop_aead(aead_instance_ctx(inst));
70262306a36Sopenharmony_ci	kfree(inst);
70362306a36Sopenharmony_ci}
70462306a36Sopenharmony_ci
70562306a36Sopenharmony_cistatic int crypto_rfc4309_create(struct crypto_template *tmpl,
70662306a36Sopenharmony_ci				 struct rtattr **tb)
70762306a36Sopenharmony_ci{
70862306a36Sopenharmony_ci	u32 mask;
70962306a36Sopenharmony_ci	struct aead_instance *inst;
71062306a36Sopenharmony_ci	struct crypto_aead_spawn *spawn;
71162306a36Sopenharmony_ci	struct aead_alg *alg;
71262306a36Sopenharmony_ci	int err;
71362306a36Sopenharmony_ci
71462306a36Sopenharmony_ci	err = crypto_check_attr_type(tb, CRYPTO_ALG_TYPE_AEAD, &mask);
71562306a36Sopenharmony_ci	if (err)
71662306a36Sopenharmony_ci		return err;
71762306a36Sopenharmony_ci
71862306a36Sopenharmony_ci	inst = kzalloc(sizeof(*inst) + sizeof(*spawn), GFP_KERNEL);
71962306a36Sopenharmony_ci	if (!inst)
72062306a36Sopenharmony_ci		return -ENOMEM;
72162306a36Sopenharmony_ci
72262306a36Sopenharmony_ci	spawn = aead_instance_ctx(inst);
72362306a36Sopenharmony_ci	err = crypto_grab_aead(spawn, aead_crypto_instance(inst),
72462306a36Sopenharmony_ci			       crypto_attr_alg_name(tb[1]), 0, mask);
72562306a36Sopenharmony_ci	if (err)
72662306a36Sopenharmony_ci		goto err_free_inst;
72762306a36Sopenharmony_ci
72862306a36Sopenharmony_ci	alg = crypto_spawn_aead_alg(spawn);
72962306a36Sopenharmony_ci
73062306a36Sopenharmony_ci	err = -EINVAL;
73162306a36Sopenharmony_ci
73262306a36Sopenharmony_ci	/* We only support 16-byte blocks. */
73362306a36Sopenharmony_ci	if (crypto_aead_alg_ivsize(alg) != 16)
73462306a36Sopenharmony_ci		goto err_free_inst;
73562306a36Sopenharmony_ci
73662306a36Sopenharmony_ci	/* Not a stream cipher? */
73762306a36Sopenharmony_ci	if (alg->base.cra_blocksize != 1)
73862306a36Sopenharmony_ci		goto err_free_inst;
73962306a36Sopenharmony_ci
74062306a36Sopenharmony_ci	err = -ENAMETOOLONG;
74162306a36Sopenharmony_ci	if (snprintf(inst->alg.base.cra_name, CRYPTO_MAX_ALG_NAME,
74262306a36Sopenharmony_ci		     "rfc4309(%s)", alg->base.cra_name) >=
74362306a36Sopenharmony_ci	    CRYPTO_MAX_ALG_NAME ||
74462306a36Sopenharmony_ci	    snprintf(inst->alg.base.cra_driver_name, CRYPTO_MAX_ALG_NAME,
74562306a36Sopenharmony_ci		     "rfc4309(%s)", alg->base.cra_driver_name) >=
74662306a36Sopenharmony_ci	    CRYPTO_MAX_ALG_NAME)
74762306a36Sopenharmony_ci		goto err_free_inst;
74862306a36Sopenharmony_ci
74962306a36Sopenharmony_ci	inst->alg.base.cra_priority = alg->base.cra_priority;
75062306a36Sopenharmony_ci	inst->alg.base.cra_blocksize = 1;
75162306a36Sopenharmony_ci	inst->alg.base.cra_alignmask = alg->base.cra_alignmask;
75262306a36Sopenharmony_ci
75362306a36Sopenharmony_ci	inst->alg.ivsize = 8;
75462306a36Sopenharmony_ci	inst->alg.chunksize = crypto_aead_alg_chunksize(alg);
75562306a36Sopenharmony_ci	inst->alg.maxauthsize = 16;
75662306a36Sopenharmony_ci
75762306a36Sopenharmony_ci	inst->alg.base.cra_ctxsize = sizeof(struct crypto_rfc4309_ctx);
75862306a36Sopenharmony_ci
75962306a36Sopenharmony_ci	inst->alg.init = crypto_rfc4309_init_tfm;
76062306a36Sopenharmony_ci	inst->alg.exit = crypto_rfc4309_exit_tfm;
76162306a36Sopenharmony_ci
76262306a36Sopenharmony_ci	inst->alg.setkey = crypto_rfc4309_setkey;
76362306a36Sopenharmony_ci	inst->alg.setauthsize = crypto_rfc4309_setauthsize;
76462306a36Sopenharmony_ci	inst->alg.encrypt = crypto_rfc4309_encrypt;
76562306a36Sopenharmony_ci	inst->alg.decrypt = crypto_rfc4309_decrypt;
76662306a36Sopenharmony_ci
76762306a36Sopenharmony_ci	inst->free = crypto_rfc4309_free;
76862306a36Sopenharmony_ci
76962306a36Sopenharmony_ci	err = aead_register_instance(tmpl, inst);
77062306a36Sopenharmony_ci	if (err) {
77162306a36Sopenharmony_cierr_free_inst:
77262306a36Sopenharmony_ci		crypto_rfc4309_free(inst);
77362306a36Sopenharmony_ci	}
77462306a36Sopenharmony_ci	return err;
77562306a36Sopenharmony_ci}
77662306a36Sopenharmony_ci
77762306a36Sopenharmony_cistatic int crypto_cbcmac_digest_setkey(struct crypto_shash *parent,
77862306a36Sopenharmony_ci				     const u8 *inkey, unsigned int keylen)
77962306a36Sopenharmony_ci{
78062306a36Sopenharmony_ci	struct cbcmac_tfm_ctx *ctx = crypto_shash_ctx(parent);
78162306a36Sopenharmony_ci
78262306a36Sopenharmony_ci	return crypto_cipher_setkey(ctx->child, inkey, keylen);
78362306a36Sopenharmony_ci}
78462306a36Sopenharmony_ci
78562306a36Sopenharmony_cistatic int crypto_cbcmac_digest_init(struct shash_desc *pdesc)
78662306a36Sopenharmony_ci{
78762306a36Sopenharmony_ci	struct cbcmac_desc_ctx *ctx = shash_desc_ctx(pdesc);
78862306a36Sopenharmony_ci	int bs = crypto_shash_digestsize(pdesc->tfm);
78962306a36Sopenharmony_ci	u8 *dg = (u8 *)ctx + crypto_shash_descsize(pdesc->tfm) - bs;
79062306a36Sopenharmony_ci
79162306a36Sopenharmony_ci	ctx->len = 0;
79262306a36Sopenharmony_ci	memset(dg, 0, bs);
79362306a36Sopenharmony_ci
79462306a36Sopenharmony_ci	return 0;
79562306a36Sopenharmony_ci}
79662306a36Sopenharmony_ci
79762306a36Sopenharmony_cistatic int crypto_cbcmac_digest_update(struct shash_desc *pdesc, const u8 *p,
79862306a36Sopenharmony_ci				       unsigned int len)
79962306a36Sopenharmony_ci{
80062306a36Sopenharmony_ci	struct crypto_shash *parent = pdesc->tfm;
80162306a36Sopenharmony_ci	struct cbcmac_tfm_ctx *tctx = crypto_shash_ctx(parent);
80262306a36Sopenharmony_ci	struct cbcmac_desc_ctx *ctx = shash_desc_ctx(pdesc);
80362306a36Sopenharmony_ci	struct crypto_cipher *tfm = tctx->child;
80462306a36Sopenharmony_ci	int bs = crypto_shash_digestsize(parent);
80562306a36Sopenharmony_ci	u8 *dg = (u8 *)ctx + crypto_shash_descsize(parent) - bs;
80662306a36Sopenharmony_ci
80762306a36Sopenharmony_ci	while (len > 0) {
80862306a36Sopenharmony_ci		unsigned int l = min(len, bs - ctx->len);
80962306a36Sopenharmony_ci
81062306a36Sopenharmony_ci		crypto_xor(dg + ctx->len, p, l);
81162306a36Sopenharmony_ci		ctx->len +=l;
81262306a36Sopenharmony_ci		len -= l;
81362306a36Sopenharmony_ci		p += l;
81462306a36Sopenharmony_ci
81562306a36Sopenharmony_ci		if (ctx->len == bs) {
81662306a36Sopenharmony_ci			crypto_cipher_encrypt_one(tfm, dg, dg);
81762306a36Sopenharmony_ci			ctx->len = 0;
81862306a36Sopenharmony_ci		}
81962306a36Sopenharmony_ci	}
82062306a36Sopenharmony_ci
82162306a36Sopenharmony_ci	return 0;
82262306a36Sopenharmony_ci}
82362306a36Sopenharmony_ci
82462306a36Sopenharmony_cistatic int crypto_cbcmac_digest_final(struct shash_desc *pdesc, u8 *out)
82562306a36Sopenharmony_ci{
82662306a36Sopenharmony_ci	struct crypto_shash *parent = pdesc->tfm;
82762306a36Sopenharmony_ci	struct cbcmac_tfm_ctx *tctx = crypto_shash_ctx(parent);
82862306a36Sopenharmony_ci	struct cbcmac_desc_ctx *ctx = shash_desc_ctx(pdesc);
82962306a36Sopenharmony_ci	struct crypto_cipher *tfm = tctx->child;
83062306a36Sopenharmony_ci	int bs = crypto_shash_digestsize(parent);
83162306a36Sopenharmony_ci	u8 *dg = (u8 *)ctx + crypto_shash_descsize(parent) - bs;
83262306a36Sopenharmony_ci
83362306a36Sopenharmony_ci	if (ctx->len)
83462306a36Sopenharmony_ci		crypto_cipher_encrypt_one(tfm, dg, dg);
83562306a36Sopenharmony_ci
83662306a36Sopenharmony_ci	memcpy(out, dg, bs);
83762306a36Sopenharmony_ci	return 0;
83862306a36Sopenharmony_ci}
83962306a36Sopenharmony_ci
84062306a36Sopenharmony_cistatic int cbcmac_init_tfm(struct crypto_tfm *tfm)
84162306a36Sopenharmony_ci{
84262306a36Sopenharmony_ci	struct crypto_cipher *cipher;
84362306a36Sopenharmony_ci	struct crypto_instance *inst = (void *)tfm->__crt_alg;
84462306a36Sopenharmony_ci	struct crypto_cipher_spawn *spawn = crypto_instance_ctx(inst);
84562306a36Sopenharmony_ci	struct cbcmac_tfm_ctx *ctx = crypto_tfm_ctx(tfm);
84662306a36Sopenharmony_ci
84762306a36Sopenharmony_ci	cipher = crypto_spawn_cipher(spawn);
84862306a36Sopenharmony_ci	if (IS_ERR(cipher))
84962306a36Sopenharmony_ci		return PTR_ERR(cipher);
85062306a36Sopenharmony_ci
85162306a36Sopenharmony_ci	ctx->child = cipher;
85262306a36Sopenharmony_ci
85362306a36Sopenharmony_ci	return 0;
85462306a36Sopenharmony_ci};
85562306a36Sopenharmony_ci
85662306a36Sopenharmony_cistatic void cbcmac_exit_tfm(struct crypto_tfm *tfm)
85762306a36Sopenharmony_ci{
85862306a36Sopenharmony_ci	struct cbcmac_tfm_ctx *ctx = crypto_tfm_ctx(tfm);
85962306a36Sopenharmony_ci	crypto_free_cipher(ctx->child);
86062306a36Sopenharmony_ci}
86162306a36Sopenharmony_ci
86262306a36Sopenharmony_cistatic int cbcmac_create(struct crypto_template *tmpl, struct rtattr **tb)
86362306a36Sopenharmony_ci{
86462306a36Sopenharmony_ci	struct shash_instance *inst;
86562306a36Sopenharmony_ci	struct crypto_cipher_spawn *spawn;
86662306a36Sopenharmony_ci	struct crypto_alg *alg;
86762306a36Sopenharmony_ci	u32 mask;
86862306a36Sopenharmony_ci	int err;
86962306a36Sopenharmony_ci
87062306a36Sopenharmony_ci	err = crypto_check_attr_type(tb, CRYPTO_ALG_TYPE_SHASH, &mask);
87162306a36Sopenharmony_ci	if (err)
87262306a36Sopenharmony_ci		return err;
87362306a36Sopenharmony_ci
87462306a36Sopenharmony_ci	inst = kzalloc(sizeof(*inst) + sizeof(*spawn), GFP_KERNEL);
87562306a36Sopenharmony_ci	if (!inst)
87662306a36Sopenharmony_ci		return -ENOMEM;
87762306a36Sopenharmony_ci	spawn = shash_instance_ctx(inst);
87862306a36Sopenharmony_ci
87962306a36Sopenharmony_ci	err = crypto_grab_cipher(spawn, shash_crypto_instance(inst),
88062306a36Sopenharmony_ci				 crypto_attr_alg_name(tb[1]), 0, mask);
88162306a36Sopenharmony_ci	if (err)
88262306a36Sopenharmony_ci		goto err_free_inst;
88362306a36Sopenharmony_ci	alg = crypto_spawn_cipher_alg(spawn);
88462306a36Sopenharmony_ci
88562306a36Sopenharmony_ci	err = crypto_inst_setname(shash_crypto_instance(inst), tmpl->name, alg);
88662306a36Sopenharmony_ci	if (err)
88762306a36Sopenharmony_ci		goto err_free_inst;
88862306a36Sopenharmony_ci
88962306a36Sopenharmony_ci	inst->alg.base.cra_priority = alg->cra_priority;
89062306a36Sopenharmony_ci	inst->alg.base.cra_blocksize = 1;
89162306a36Sopenharmony_ci
89262306a36Sopenharmony_ci	inst->alg.digestsize = alg->cra_blocksize;
89362306a36Sopenharmony_ci	inst->alg.descsize = ALIGN(sizeof(struct cbcmac_desc_ctx),
89462306a36Sopenharmony_ci				   alg->cra_alignmask + 1) +
89562306a36Sopenharmony_ci			     alg->cra_blocksize;
89662306a36Sopenharmony_ci
89762306a36Sopenharmony_ci	inst->alg.base.cra_ctxsize = sizeof(struct cbcmac_tfm_ctx);
89862306a36Sopenharmony_ci	inst->alg.base.cra_init = cbcmac_init_tfm;
89962306a36Sopenharmony_ci	inst->alg.base.cra_exit = cbcmac_exit_tfm;
90062306a36Sopenharmony_ci
90162306a36Sopenharmony_ci	inst->alg.init = crypto_cbcmac_digest_init;
90262306a36Sopenharmony_ci	inst->alg.update = crypto_cbcmac_digest_update;
90362306a36Sopenharmony_ci	inst->alg.final = crypto_cbcmac_digest_final;
90462306a36Sopenharmony_ci	inst->alg.setkey = crypto_cbcmac_digest_setkey;
90562306a36Sopenharmony_ci
90662306a36Sopenharmony_ci	inst->free = shash_free_singlespawn_instance;
90762306a36Sopenharmony_ci
90862306a36Sopenharmony_ci	err = shash_register_instance(tmpl, inst);
90962306a36Sopenharmony_ci	if (err) {
91062306a36Sopenharmony_cierr_free_inst:
91162306a36Sopenharmony_ci		shash_free_singlespawn_instance(inst);
91262306a36Sopenharmony_ci	}
91362306a36Sopenharmony_ci	return err;
91462306a36Sopenharmony_ci}
91562306a36Sopenharmony_ci
91662306a36Sopenharmony_cistatic struct crypto_template crypto_ccm_tmpls[] = {
91762306a36Sopenharmony_ci	{
91862306a36Sopenharmony_ci		.name = "cbcmac",
91962306a36Sopenharmony_ci		.create = cbcmac_create,
92062306a36Sopenharmony_ci		.module = THIS_MODULE,
92162306a36Sopenharmony_ci	}, {
92262306a36Sopenharmony_ci		.name = "ccm_base",
92362306a36Sopenharmony_ci		.create = crypto_ccm_base_create,
92462306a36Sopenharmony_ci		.module = THIS_MODULE,
92562306a36Sopenharmony_ci	}, {
92662306a36Sopenharmony_ci		.name = "ccm",
92762306a36Sopenharmony_ci		.create = crypto_ccm_create,
92862306a36Sopenharmony_ci		.module = THIS_MODULE,
92962306a36Sopenharmony_ci	}, {
93062306a36Sopenharmony_ci		.name = "rfc4309",
93162306a36Sopenharmony_ci		.create = crypto_rfc4309_create,
93262306a36Sopenharmony_ci		.module = THIS_MODULE,
93362306a36Sopenharmony_ci	},
93462306a36Sopenharmony_ci};
93562306a36Sopenharmony_ci
93662306a36Sopenharmony_cistatic int __init crypto_ccm_module_init(void)
93762306a36Sopenharmony_ci{
93862306a36Sopenharmony_ci	return crypto_register_templates(crypto_ccm_tmpls,
93962306a36Sopenharmony_ci					 ARRAY_SIZE(crypto_ccm_tmpls));
94062306a36Sopenharmony_ci}
94162306a36Sopenharmony_ci
94262306a36Sopenharmony_cistatic void __exit crypto_ccm_module_exit(void)
94362306a36Sopenharmony_ci{
94462306a36Sopenharmony_ci	crypto_unregister_templates(crypto_ccm_tmpls,
94562306a36Sopenharmony_ci				    ARRAY_SIZE(crypto_ccm_tmpls));
94662306a36Sopenharmony_ci}
94762306a36Sopenharmony_ci
94862306a36Sopenharmony_cisubsys_initcall(crypto_ccm_module_init);
94962306a36Sopenharmony_cimodule_exit(crypto_ccm_module_exit);
95062306a36Sopenharmony_ci
95162306a36Sopenharmony_ciMODULE_LICENSE("GPL");
95262306a36Sopenharmony_ciMODULE_DESCRIPTION("Counter with CBC MAC");
95362306a36Sopenharmony_ciMODULE_ALIAS_CRYPTO("ccm_base");
95462306a36Sopenharmony_ciMODULE_ALIAS_CRYPTO("rfc4309");
95562306a36Sopenharmony_ciMODULE_ALIAS_CRYPTO("ccm");
95662306a36Sopenharmony_ciMODULE_ALIAS_CRYPTO("cbcmac");
95762306a36Sopenharmony_ciMODULE_IMPORT_NS(CRYPTO_INTERNAL);
958