162306a36Sopenharmony_ci/* SPDX-License-Identifier: GPL-2.0-only */
262306a36Sopenharmony_ci/*
362306a36Sopenharmony_ci * AMD Cryptographic Coprocessor (CCP) crypto API support
462306a36Sopenharmony_ci *
562306a36Sopenharmony_ci * Copyright (C) 2013,2017 Advanced Micro Devices, Inc.
662306a36Sopenharmony_ci *
762306a36Sopenharmony_ci * Author: Tom Lendacky <thomas.lendacky@amd.com>
862306a36Sopenharmony_ci */
962306a36Sopenharmony_ci
1062306a36Sopenharmony_ci#ifndef __CCP_CRYPTO_H__
1162306a36Sopenharmony_ci#define __CCP_CRYPTO_H__
1262306a36Sopenharmony_ci
1362306a36Sopenharmony_ci#include <linux/list.h>
1462306a36Sopenharmony_ci#include <linux/wait.h>
1562306a36Sopenharmony_ci#include <linux/ccp.h>
1662306a36Sopenharmony_ci#include <crypto/algapi.h>
1762306a36Sopenharmony_ci#include <crypto/aes.h>
1862306a36Sopenharmony_ci#include <crypto/internal/aead.h>
1962306a36Sopenharmony_ci#include <crypto/aead.h>
2062306a36Sopenharmony_ci#include <crypto/ctr.h>
2162306a36Sopenharmony_ci#include <crypto/hash.h>
2262306a36Sopenharmony_ci#include <crypto/sha1.h>
2362306a36Sopenharmony_ci#include <crypto/sha2.h>
2462306a36Sopenharmony_ci#include <crypto/akcipher.h>
2562306a36Sopenharmony_ci#include <crypto/skcipher.h>
2662306a36Sopenharmony_ci#include <crypto/internal/rsa.h>
2762306a36Sopenharmony_ci
2862306a36Sopenharmony_ci/* We want the module name in front of our messages */
2962306a36Sopenharmony_ci#undef pr_fmt
3062306a36Sopenharmony_ci#define	pr_fmt(fmt)	KBUILD_MODNAME ": " fmt
3162306a36Sopenharmony_ci
3262306a36Sopenharmony_ci#define	CCP_LOG_LEVEL	KERN_INFO
3362306a36Sopenharmony_ci
3462306a36Sopenharmony_ci#define CCP_CRA_PRIORITY	300
3562306a36Sopenharmony_ci
3662306a36Sopenharmony_cistruct ccp_crypto_skcipher_alg {
3762306a36Sopenharmony_ci	struct list_head entry;
3862306a36Sopenharmony_ci
3962306a36Sopenharmony_ci	u32 mode;
4062306a36Sopenharmony_ci
4162306a36Sopenharmony_ci	struct skcipher_alg alg;
4262306a36Sopenharmony_ci};
4362306a36Sopenharmony_ci
4462306a36Sopenharmony_cistruct ccp_crypto_aead {
4562306a36Sopenharmony_ci	struct list_head entry;
4662306a36Sopenharmony_ci
4762306a36Sopenharmony_ci	u32 mode;
4862306a36Sopenharmony_ci
4962306a36Sopenharmony_ci	struct aead_alg alg;
5062306a36Sopenharmony_ci};
5162306a36Sopenharmony_ci
5262306a36Sopenharmony_cistruct ccp_crypto_ahash_alg {
5362306a36Sopenharmony_ci	struct list_head entry;
5462306a36Sopenharmony_ci
5562306a36Sopenharmony_ci	const __be32 *init;
5662306a36Sopenharmony_ci	u32 type;
5762306a36Sopenharmony_ci	u32 mode;
5862306a36Sopenharmony_ci
5962306a36Sopenharmony_ci	/* Child algorithm used for HMAC, CMAC, etc */
6062306a36Sopenharmony_ci	char child_alg[CRYPTO_MAX_ALG_NAME];
6162306a36Sopenharmony_ci
6262306a36Sopenharmony_ci	struct ahash_alg alg;
6362306a36Sopenharmony_ci};
6462306a36Sopenharmony_ci
6562306a36Sopenharmony_cistruct ccp_crypto_akcipher_alg {
6662306a36Sopenharmony_ci	struct list_head entry;
6762306a36Sopenharmony_ci
6862306a36Sopenharmony_ci	struct akcipher_alg alg;
6962306a36Sopenharmony_ci};
7062306a36Sopenharmony_ci
7162306a36Sopenharmony_cistatic inline struct ccp_crypto_skcipher_alg *
7262306a36Sopenharmony_ci	ccp_crypto_skcipher_alg(struct crypto_skcipher *tfm)
7362306a36Sopenharmony_ci{
7462306a36Sopenharmony_ci	struct skcipher_alg *alg = crypto_skcipher_alg(tfm);
7562306a36Sopenharmony_ci
7662306a36Sopenharmony_ci	return container_of(alg, struct ccp_crypto_skcipher_alg, alg);
7762306a36Sopenharmony_ci}
7862306a36Sopenharmony_ci
7962306a36Sopenharmony_cistatic inline struct ccp_crypto_ahash_alg *
8062306a36Sopenharmony_ci	ccp_crypto_ahash_alg(struct crypto_tfm *tfm)
8162306a36Sopenharmony_ci{
8262306a36Sopenharmony_ci	struct crypto_alg *alg = tfm->__crt_alg;
8362306a36Sopenharmony_ci	struct ahash_alg *ahash_alg;
8462306a36Sopenharmony_ci
8562306a36Sopenharmony_ci	ahash_alg = container_of(alg, struct ahash_alg, halg.base);
8662306a36Sopenharmony_ci
8762306a36Sopenharmony_ci	return container_of(ahash_alg, struct ccp_crypto_ahash_alg, alg);
8862306a36Sopenharmony_ci}
8962306a36Sopenharmony_ci
9062306a36Sopenharmony_ci/***** AES related defines *****/
9162306a36Sopenharmony_cistruct ccp_aes_ctx {
9262306a36Sopenharmony_ci	/* Fallback cipher for XTS with unsupported unit sizes */
9362306a36Sopenharmony_ci	struct crypto_skcipher *tfm_skcipher;
9462306a36Sopenharmony_ci
9562306a36Sopenharmony_ci	enum ccp_engine engine;
9662306a36Sopenharmony_ci	enum ccp_aes_type type;
9762306a36Sopenharmony_ci	enum ccp_aes_mode mode;
9862306a36Sopenharmony_ci
9962306a36Sopenharmony_ci	struct scatterlist key_sg;
10062306a36Sopenharmony_ci	unsigned int key_len;
10162306a36Sopenharmony_ci	u8 key[AES_MAX_KEY_SIZE * 2];
10262306a36Sopenharmony_ci
10362306a36Sopenharmony_ci	u8 nonce[CTR_RFC3686_NONCE_SIZE];
10462306a36Sopenharmony_ci
10562306a36Sopenharmony_ci	/* CMAC key structures */
10662306a36Sopenharmony_ci	struct scatterlist k1_sg;
10762306a36Sopenharmony_ci	struct scatterlist k2_sg;
10862306a36Sopenharmony_ci	unsigned int kn_len;
10962306a36Sopenharmony_ci	u8 k1[AES_BLOCK_SIZE];
11062306a36Sopenharmony_ci	u8 k2[AES_BLOCK_SIZE];
11162306a36Sopenharmony_ci};
11262306a36Sopenharmony_ci
11362306a36Sopenharmony_cistruct ccp_aes_req_ctx {
11462306a36Sopenharmony_ci	struct scatterlist iv_sg;
11562306a36Sopenharmony_ci	u8 iv[AES_BLOCK_SIZE];
11662306a36Sopenharmony_ci
11762306a36Sopenharmony_ci	struct scatterlist tag_sg;
11862306a36Sopenharmony_ci	u8 tag[AES_BLOCK_SIZE];
11962306a36Sopenharmony_ci
12062306a36Sopenharmony_ci	/* Fields used for RFC3686 requests */
12162306a36Sopenharmony_ci	u8 *rfc3686_info;
12262306a36Sopenharmony_ci	u8 rfc3686_iv[AES_BLOCK_SIZE];
12362306a36Sopenharmony_ci
12462306a36Sopenharmony_ci	struct ccp_cmd cmd;
12562306a36Sopenharmony_ci
12662306a36Sopenharmony_ci	struct skcipher_request fallback_req;	// keep at the end
12762306a36Sopenharmony_ci};
12862306a36Sopenharmony_ci
12962306a36Sopenharmony_cistruct ccp_aes_cmac_req_ctx {
13062306a36Sopenharmony_ci	unsigned int null_msg;
13162306a36Sopenharmony_ci	unsigned int final;
13262306a36Sopenharmony_ci
13362306a36Sopenharmony_ci	struct scatterlist *src;
13462306a36Sopenharmony_ci	unsigned int nbytes;
13562306a36Sopenharmony_ci
13662306a36Sopenharmony_ci	u64 hash_cnt;
13762306a36Sopenharmony_ci	unsigned int hash_rem;
13862306a36Sopenharmony_ci
13962306a36Sopenharmony_ci	struct sg_table data_sg;
14062306a36Sopenharmony_ci
14162306a36Sopenharmony_ci	struct scatterlist iv_sg;
14262306a36Sopenharmony_ci	u8 iv[AES_BLOCK_SIZE];
14362306a36Sopenharmony_ci
14462306a36Sopenharmony_ci	struct scatterlist buf_sg;
14562306a36Sopenharmony_ci	unsigned int buf_count;
14662306a36Sopenharmony_ci	u8 buf[AES_BLOCK_SIZE];
14762306a36Sopenharmony_ci
14862306a36Sopenharmony_ci	struct scatterlist pad_sg;
14962306a36Sopenharmony_ci	unsigned int pad_count;
15062306a36Sopenharmony_ci	u8 pad[AES_BLOCK_SIZE];
15162306a36Sopenharmony_ci
15262306a36Sopenharmony_ci	struct ccp_cmd cmd;
15362306a36Sopenharmony_ci};
15462306a36Sopenharmony_ci
15562306a36Sopenharmony_cistruct ccp_aes_cmac_exp_ctx {
15662306a36Sopenharmony_ci	unsigned int null_msg;
15762306a36Sopenharmony_ci
15862306a36Sopenharmony_ci	u8 iv[AES_BLOCK_SIZE];
15962306a36Sopenharmony_ci
16062306a36Sopenharmony_ci	unsigned int buf_count;
16162306a36Sopenharmony_ci	u8 buf[AES_BLOCK_SIZE];
16262306a36Sopenharmony_ci};
16362306a36Sopenharmony_ci
16462306a36Sopenharmony_ci/***** 3DES related defines *****/
16562306a36Sopenharmony_cistruct ccp_des3_ctx {
16662306a36Sopenharmony_ci	enum ccp_engine engine;
16762306a36Sopenharmony_ci	enum ccp_des3_type type;
16862306a36Sopenharmony_ci	enum ccp_des3_mode mode;
16962306a36Sopenharmony_ci
17062306a36Sopenharmony_ci	struct scatterlist key_sg;
17162306a36Sopenharmony_ci	unsigned int key_len;
17262306a36Sopenharmony_ci	u8 key[AES_MAX_KEY_SIZE];
17362306a36Sopenharmony_ci};
17462306a36Sopenharmony_ci
17562306a36Sopenharmony_cistruct ccp_des3_req_ctx {
17662306a36Sopenharmony_ci	struct scatterlist iv_sg;
17762306a36Sopenharmony_ci	u8 iv[AES_BLOCK_SIZE];
17862306a36Sopenharmony_ci
17962306a36Sopenharmony_ci	struct ccp_cmd cmd;
18062306a36Sopenharmony_ci};
18162306a36Sopenharmony_ci
18262306a36Sopenharmony_ci/* SHA-related defines
18362306a36Sopenharmony_ci * These values must be large enough to accommodate any variant
18462306a36Sopenharmony_ci */
18562306a36Sopenharmony_ci#define MAX_SHA_CONTEXT_SIZE	SHA512_DIGEST_SIZE
18662306a36Sopenharmony_ci#define MAX_SHA_BLOCK_SIZE	SHA512_BLOCK_SIZE
18762306a36Sopenharmony_ci
18862306a36Sopenharmony_cistruct ccp_sha_ctx {
18962306a36Sopenharmony_ci	struct scatterlist opad_sg;
19062306a36Sopenharmony_ci	unsigned int opad_count;
19162306a36Sopenharmony_ci
19262306a36Sopenharmony_ci	unsigned int key_len;
19362306a36Sopenharmony_ci	u8 key[MAX_SHA_BLOCK_SIZE];
19462306a36Sopenharmony_ci	u8 ipad[MAX_SHA_BLOCK_SIZE];
19562306a36Sopenharmony_ci	u8 opad[MAX_SHA_BLOCK_SIZE];
19662306a36Sopenharmony_ci	struct crypto_shash *hmac_tfm;
19762306a36Sopenharmony_ci};
19862306a36Sopenharmony_ci
19962306a36Sopenharmony_cistruct ccp_sha_req_ctx {
20062306a36Sopenharmony_ci	enum ccp_sha_type type;
20162306a36Sopenharmony_ci
20262306a36Sopenharmony_ci	u64 msg_bits;
20362306a36Sopenharmony_ci
20462306a36Sopenharmony_ci	unsigned int first;
20562306a36Sopenharmony_ci	unsigned int final;
20662306a36Sopenharmony_ci
20762306a36Sopenharmony_ci	struct scatterlist *src;
20862306a36Sopenharmony_ci	unsigned int nbytes;
20962306a36Sopenharmony_ci
21062306a36Sopenharmony_ci	u64 hash_cnt;
21162306a36Sopenharmony_ci	unsigned int hash_rem;
21262306a36Sopenharmony_ci
21362306a36Sopenharmony_ci	struct sg_table data_sg;
21462306a36Sopenharmony_ci
21562306a36Sopenharmony_ci	struct scatterlist ctx_sg;
21662306a36Sopenharmony_ci	u8 ctx[MAX_SHA_CONTEXT_SIZE];
21762306a36Sopenharmony_ci
21862306a36Sopenharmony_ci	struct scatterlist buf_sg;
21962306a36Sopenharmony_ci	unsigned int buf_count;
22062306a36Sopenharmony_ci	u8 buf[MAX_SHA_BLOCK_SIZE];
22162306a36Sopenharmony_ci
22262306a36Sopenharmony_ci	/* CCP driver command */
22362306a36Sopenharmony_ci	struct ccp_cmd cmd;
22462306a36Sopenharmony_ci};
22562306a36Sopenharmony_ci
22662306a36Sopenharmony_cistruct ccp_sha_exp_ctx {
22762306a36Sopenharmony_ci	enum ccp_sha_type type;
22862306a36Sopenharmony_ci
22962306a36Sopenharmony_ci	u64 msg_bits;
23062306a36Sopenharmony_ci
23162306a36Sopenharmony_ci	unsigned int first;
23262306a36Sopenharmony_ci
23362306a36Sopenharmony_ci	u8 ctx[MAX_SHA_CONTEXT_SIZE];
23462306a36Sopenharmony_ci
23562306a36Sopenharmony_ci	unsigned int buf_count;
23662306a36Sopenharmony_ci	u8 buf[MAX_SHA_BLOCK_SIZE];
23762306a36Sopenharmony_ci};
23862306a36Sopenharmony_ci
23962306a36Sopenharmony_ci/***** RSA related defines *****/
24062306a36Sopenharmony_ci
24162306a36Sopenharmony_cistruct ccp_rsa_ctx {
24262306a36Sopenharmony_ci	unsigned int key_len; /* in bits */
24362306a36Sopenharmony_ci	struct scatterlist e_sg;
24462306a36Sopenharmony_ci	u8 *e_buf;
24562306a36Sopenharmony_ci	unsigned int e_len;
24662306a36Sopenharmony_ci	struct scatterlist n_sg;
24762306a36Sopenharmony_ci	u8 *n_buf;
24862306a36Sopenharmony_ci	unsigned int n_len;
24962306a36Sopenharmony_ci	struct scatterlist d_sg;
25062306a36Sopenharmony_ci	u8 *d_buf;
25162306a36Sopenharmony_ci	unsigned int d_len;
25262306a36Sopenharmony_ci};
25362306a36Sopenharmony_ci
25462306a36Sopenharmony_cistruct ccp_rsa_req_ctx {
25562306a36Sopenharmony_ci	struct ccp_cmd cmd;
25662306a36Sopenharmony_ci};
25762306a36Sopenharmony_ci
25862306a36Sopenharmony_ci#define	CCP_RSA_MAXMOD	(4 * 1024 / 8)
25962306a36Sopenharmony_ci#define	CCP5_RSA_MAXMOD	(16 * 1024 / 8)
26062306a36Sopenharmony_ci
26162306a36Sopenharmony_ci/***** Common Context Structure *****/
26262306a36Sopenharmony_cistruct ccp_ctx {
26362306a36Sopenharmony_ci	int (*complete)(struct crypto_async_request *req, int ret);
26462306a36Sopenharmony_ci
26562306a36Sopenharmony_ci	union {
26662306a36Sopenharmony_ci		struct ccp_aes_ctx aes;
26762306a36Sopenharmony_ci		struct ccp_rsa_ctx rsa;
26862306a36Sopenharmony_ci		struct ccp_sha_ctx sha;
26962306a36Sopenharmony_ci		struct ccp_des3_ctx des3;
27062306a36Sopenharmony_ci	} u;
27162306a36Sopenharmony_ci};
27262306a36Sopenharmony_ci
27362306a36Sopenharmony_ciint ccp_crypto_enqueue_request(struct crypto_async_request *req,
27462306a36Sopenharmony_ci			       struct ccp_cmd *cmd);
27562306a36Sopenharmony_cistruct scatterlist *ccp_crypto_sg_table_add(struct sg_table *table,
27662306a36Sopenharmony_ci					    struct scatterlist *sg_add);
27762306a36Sopenharmony_ci
27862306a36Sopenharmony_ciint ccp_register_aes_algs(struct list_head *head);
27962306a36Sopenharmony_ciint ccp_register_aes_cmac_algs(struct list_head *head);
28062306a36Sopenharmony_ciint ccp_register_aes_xts_algs(struct list_head *head);
28162306a36Sopenharmony_ciint ccp_register_aes_aeads(struct list_head *head);
28262306a36Sopenharmony_ciint ccp_register_sha_algs(struct list_head *head);
28362306a36Sopenharmony_ciint ccp_register_des3_algs(struct list_head *head);
28462306a36Sopenharmony_ciint ccp_register_rsa_algs(struct list_head *head);
28562306a36Sopenharmony_ci
28662306a36Sopenharmony_ci#endif
287