162306a36Sopenharmony_ci// SPDX-License-Identifier: GPL-2.0-or-later
262306a36Sopenharmony_ci/*
362306a36Sopenharmony_ci * geniv: Shared IV generator code
462306a36Sopenharmony_ci *
562306a36Sopenharmony_ci * This file provides common code to IV generators such as seqiv.
662306a36Sopenharmony_ci *
762306a36Sopenharmony_ci * Copyright (c) 2007-2019 Herbert Xu <herbert@gondor.apana.org.au>
862306a36Sopenharmony_ci */
962306a36Sopenharmony_ci
1062306a36Sopenharmony_ci#include <crypto/internal/geniv.h>
1162306a36Sopenharmony_ci#include <crypto/internal/rng.h>
1262306a36Sopenharmony_ci#include <crypto/null.h>
1362306a36Sopenharmony_ci#include <linux/err.h>
1462306a36Sopenharmony_ci#include <linux/kernel.h>
1562306a36Sopenharmony_ci#include <linux/module.h>
1662306a36Sopenharmony_ci#include <linux/rtnetlink.h>
1762306a36Sopenharmony_ci#include <linux/slab.h>
1862306a36Sopenharmony_ci
1962306a36Sopenharmony_cistatic int aead_geniv_setkey(struct crypto_aead *tfm,
2062306a36Sopenharmony_ci			     const u8 *key, unsigned int keylen)
2162306a36Sopenharmony_ci{
2262306a36Sopenharmony_ci	struct aead_geniv_ctx *ctx = crypto_aead_ctx(tfm);
2362306a36Sopenharmony_ci
2462306a36Sopenharmony_ci	return crypto_aead_setkey(ctx->child, key, keylen);
2562306a36Sopenharmony_ci}
2662306a36Sopenharmony_ci
2762306a36Sopenharmony_cistatic int aead_geniv_setauthsize(struct crypto_aead *tfm,
2862306a36Sopenharmony_ci				  unsigned int authsize)
2962306a36Sopenharmony_ci{
3062306a36Sopenharmony_ci	struct aead_geniv_ctx *ctx = crypto_aead_ctx(tfm);
3162306a36Sopenharmony_ci
3262306a36Sopenharmony_ci	return crypto_aead_setauthsize(ctx->child, authsize);
3362306a36Sopenharmony_ci}
3462306a36Sopenharmony_ci
3562306a36Sopenharmony_cistatic void aead_geniv_free(struct aead_instance *inst)
3662306a36Sopenharmony_ci{
3762306a36Sopenharmony_ci	crypto_drop_aead(aead_instance_ctx(inst));
3862306a36Sopenharmony_ci	kfree(inst);
3962306a36Sopenharmony_ci}
4062306a36Sopenharmony_ci
4162306a36Sopenharmony_cistruct aead_instance *aead_geniv_alloc(struct crypto_template *tmpl,
4262306a36Sopenharmony_ci				       struct rtattr **tb)
4362306a36Sopenharmony_ci{
4462306a36Sopenharmony_ci	struct crypto_aead_spawn *spawn;
4562306a36Sopenharmony_ci	struct aead_instance *inst;
4662306a36Sopenharmony_ci	struct aead_alg *alg;
4762306a36Sopenharmony_ci	unsigned int ivsize;
4862306a36Sopenharmony_ci	unsigned int maxauthsize;
4962306a36Sopenharmony_ci	u32 mask;
5062306a36Sopenharmony_ci	int err;
5162306a36Sopenharmony_ci
5262306a36Sopenharmony_ci	err = crypto_check_attr_type(tb, CRYPTO_ALG_TYPE_AEAD, &mask);
5362306a36Sopenharmony_ci	if (err)
5462306a36Sopenharmony_ci		return ERR_PTR(err);
5562306a36Sopenharmony_ci
5662306a36Sopenharmony_ci	inst = kzalloc(sizeof(*inst) + sizeof(*spawn), GFP_KERNEL);
5762306a36Sopenharmony_ci	if (!inst)
5862306a36Sopenharmony_ci		return ERR_PTR(-ENOMEM);
5962306a36Sopenharmony_ci
6062306a36Sopenharmony_ci	spawn = aead_instance_ctx(inst);
6162306a36Sopenharmony_ci
6262306a36Sopenharmony_ci	err = crypto_grab_aead(spawn, aead_crypto_instance(inst),
6362306a36Sopenharmony_ci			       crypto_attr_alg_name(tb[1]), 0, mask);
6462306a36Sopenharmony_ci	if (err)
6562306a36Sopenharmony_ci		goto err_free_inst;
6662306a36Sopenharmony_ci
6762306a36Sopenharmony_ci	alg = crypto_spawn_aead_alg(spawn);
6862306a36Sopenharmony_ci
6962306a36Sopenharmony_ci	ivsize = crypto_aead_alg_ivsize(alg);
7062306a36Sopenharmony_ci	maxauthsize = crypto_aead_alg_maxauthsize(alg);
7162306a36Sopenharmony_ci
7262306a36Sopenharmony_ci	err = -EINVAL;
7362306a36Sopenharmony_ci	if (ivsize < sizeof(u64))
7462306a36Sopenharmony_ci		goto err_free_inst;
7562306a36Sopenharmony_ci
7662306a36Sopenharmony_ci	err = -ENAMETOOLONG;
7762306a36Sopenharmony_ci	if (snprintf(inst->alg.base.cra_name, CRYPTO_MAX_ALG_NAME,
7862306a36Sopenharmony_ci		     "%s(%s)", tmpl->name, alg->base.cra_name) >=
7962306a36Sopenharmony_ci	    CRYPTO_MAX_ALG_NAME)
8062306a36Sopenharmony_ci		goto err_free_inst;
8162306a36Sopenharmony_ci	if (snprintf(inst->alg.base.cra_driver_name, CRYPTO_MAX_ALG_NAME,
8262306a36Sopenharmony_ci		     "%s(%s)", tmpl->name, alg->base.cra_driver_name) >=
8362306a36Sopenharmony_ci	    CRYPTO_MAX_ALG_NAME)
8462306a36Sopenharmony_ci		goto err_free_inst;
8562306a36Sopenharmony_ci
8662306a36Sopenharmony_ci	inst->alg.base.cra_priority = alg->base.cra_priority;
8762306a36Sopenharmony_ci	inst->alg.base.cra_blocksize = alg->base.cra_blocksize;
8862306a36Sopenharmony_ci	inst->alg.base.cra_alignmask = alg->base.cra_alignmask;
8962306a36Sopenharmony_ci	inst->alg.base.cra_ctxsize = sizeof(struct aead_geniv_ctx);
9062306a36Sopenharmony_ci
9162306a36Sopenharmony_ci	inst->alg.setkey = aead_geniv_setkey;
9262306a36Sopenharmony_ci	inst->alg.setauthsize = aead_geniv_setauthsize;
9362306a36Sopenharmony_ci
9462306a36Sopenharmony_ci	inst->alg.ivsize = ivsize;
9562306a36Sopenharmony_ci	inst->alg.maxauthsize = maxauthsize;
9662306a36Sopenharmony_ci
9762306a36Sopenharmony_ci	inst->free = aead_geniv_free;
9862306a36Sopenharmony_ci
9962306a36Sopenharmony_ciout:
10062306a36Sopenharmony_ci	return inst;
10162306a36Sopenharmony_ci
10262306a36Sopenharmony_cierr_free_inst:
10362306a36Sopenharmony_ci	aead_geniv_free(inst);
10462306a36Sopenharmony_ci	inst = ERR_PTR(err);
10562306a36Sopenharmony_ci	goto out;
10662306a36Sopenharmony_ci}
10762306a36Sopenharmony_ciEXPORT_SYMBOL_GPL(aead_geniv_alloc);
10862306a36Sopenharmony_ci
10962306a36Sopenharmony_ciint aead_init_geniv(struct crypto_aead *aead)
11062306a36Sopenharmony_ci{
11162306a36Sopenharmony_ci	struct aead_geniv_ctx *ctx = crypto_aead_ctx(aead);
11262306a36Sopenharmony_ci	struct aead_instance *inst = aead_alg_instance(aead);
11362306a36Sopenharmony_ci	struct crypto_aead *child;
11462306a36Sopenharmony_ci	int err;
11562306a36Sopenharmony_ci
11662306a36Sopenharmony_ci	spin_lock_init(&ctx->lock);
11762306a36Sopenharmony_ci
11862306a36Sopenharmony_ci	err = crypto_get_default_rng();
11962306a36Sopenharmony_ci	if (err)
12062306a36Sopenharmony_ci		goto out;
12162306a36Sopenharmony_ci
12262306a36Sopenharmony_ci	err = crypto_rng_get_bytes(crypto_default_rng, ctx->salt,
12362306a36Sopenharmony_ci				   crypto_aead_ivsize(aead));
12462306a36Sopenharmony_ci	crypto_put_default_rng();
12562306a36Sopenharmony_ci	if (err)
12662306a36Sopenharmony_ci		goto out;
12762306a36Sopenharmony_ci
12862306a36Sopenharmony_ci	ctx->sknull = crypto_get_default_null_skcipher();
12962306a36Sopenharmony_ci	err = PTR_ERR(ctx->sknull);
13062306a36Sopenharmony_ci	if (IS_ERR(ctx->sknull))
13162306a36Sopenharmony_ci		goto out;
13262306a36Sopenharmony_ci
13362306a36Sopenharmony_ci	child = crypto_spawn_aead(aead_instance_ctx(inst));
13462306a36Sopenharmony_ci	err = PTR_ERR(child);
13562306a36Sopenharmony_ci	if (IS_ERR(child))
13662306a36Sopenharmony_ci		goto drop_null;
13762306a36Sopenharmony_ci
13862306a36Sopenharmony_ci	ctx->child = child;
13962306a36Sopenharmony_ci	crypto_aead_set_reqsize(aead, crypto_aead_reqsize(child) +
14062306a36Sopenharmony_ci				      sizeof(struct aead_request));
14162306a36Sopenharmony_ci
14262306a36Sopenharmony_ci	err = 0;
14362306a36Sopenharmony_ci
14462306a36Sopenharmony_ciout:
14562306a36Sopenharmony_ci	return err;
14662306a36Sopenharmony_ci
14762306a36Sopenharmony_cidrop_null:
14862306a36Sopenharmony_ci	crypto_put_default_null_skcipher();
14962306a36Sopenharmony_ci	goto out;
15062306a36Sopenharmony_ci}
15162306a36Sopenharmony_ciEXPORT_SYMBOL_GPL(aead_init_geniv);
15262306a36Sopenharmony_ci
15362306a36Sopenharmony_civoid aead_exit_geniv(struct crypto_aead *tfm)
15462306a36Sopenharmony_ci{
15562306a36Sopenharmony_ci	struct aead_geniv_ctx *ctx = crypto_aead_ctx(tfm);
15662306a36Sopenharmony_ci
15762306a36Sopenharmony_ci	crypto_free_aead(ctx->child);
15862306a36Sopenharmony_ci	crypto_put_default_null_skcipher();
15962306a36Sopenharmony_ci}
16062306a36Sopenharmony_ciEXPORT_SYMBOL_GPL(aead_exit_geniv);
16162306a36Sopenharmony_ci
16262306a36Sopenharmony_ciMODULE_LICENSE("GPL");
16362306a36Sopenharmony_ciMODULE_DESCRIPTION("Shared IV generator code");
164