xref: /OK3568_Linux_fs/kernel/crypto/ahash.c (revision 4882a59341e53eb6f0b4789bf948001014eff981)
1*4882a593Smuzhiyun // SPDX-License-Identifier: GPL-2.0-or-later
2*4882a593Smuzhiyun /*
3*4882a593Smuzhiyun  * Asynchronous Cryptographic Hash operations.
4*4882a593Smuzhiyun  *
5*4882a593Smuzhiyun  * This is the asynchronous version of hash.c with notification of
6*4882a593Smuzhiyun  * completion via a callback.
7*4882a593Smuzhiyun  *
8*4882a593Smuzhiyun  * Copyright (c) 2008 Loc Ho <lho@amcc.com>
9*4882a593Smuzhiyun  */
10*4882a593Smuzhiyun 
11*4882a593Smuzhiyun #include <crypto/internal/hash.h>
12*4882a593Smuzhiyun #include <crypto/scatterwalk.h>
13*4882a593Smuzhiyun #include <linux/err.h>
14*4882a593Smuzhiyun #include <linux/kernel.h>
15*4882a593Smuzhiyun #include <linux/module.h>
16*4882a593Smuzhiyun #include <linux/sched.h>
17*4882a593Smuzhiyun #include <linux/slab.h>
18*4882a593Smuzhiyun #include <linux/seq_file.h>
19*4882a593Smuzhiyun #include <linux/cryptouser.h>
20*4882a593Smuzhiyun #include <linux/compiler.h>
21*4882a593Smuzhiyun #include <net/netlink.h>
22*4882a593Smuzhiyun 
23*4882a593Smuzhiyun #include "internal.h"
24*4882a593Smuzhiyun 
25*4882a593Smuzhiyun static const struct crypto_type crypto_ahash_type;
26*4882a593Smuzhiyun 
27*4882a593Smuzhiyun struct ahash_request_priv {
28*4882a593Smuzhiyun 	crypto_completion_t complete;
29*4882a593Smuzhiyun 	void *data;
30*4882a593Smuzhiyun 	u8 *result;
31*4882a593Smuzhiyun 	u32 flags;
32*4882a593Smuzhiyun 	void *ubuf[] CRYPTO_MINALIGN_ATTR;
33*4882a593Smuzhiyun };
34*4882a593Smuzhiyun 
crypto_ahash_alg(struct crypto_ahash * hash)35*4882a593Smuzhiyun static inline struct ahash_alg *crypto_ahash_alg(struct crypto_ahash *hash)
36*4882a593Smuzhiyun {
37*4882a593Smuzhiyun 	return container_of(crypto_hash_alg_common(hash), struct ahash_alg,
38*4882a593Smuzhiyun 			    halg);
39*4882a593Smuzhiyun }
40*4882a593Smuzhiyun 
hash_walk_next(struct crypto_hash_walk * walk)41*4882a593Smuzhiyun static int hash_walk_next(struct crypto_hash_walk *walk)
42*4882a593Smuzhiyun {
43*4882a593Smuzhiyun 	unsigned int alignmask = walk->alignmask;
44*4882a593Smuzhiyun 	unsigned int offset = walk->offset;
45*4882a593Smuzhiyun 	unsigned int nbytes = min(walk->entrylen,
46*4882a593Smuzhiyun 				  ((unsigned int)(PAGE_SIZE)) - offset);
47*4882a593Smuzhiyun 
48*4882a593Smuzhiyun 	walk->data = kmap_atomic(walk->pg);
49*4882a593Smuzhiyun 	walk->data += offset;
50*4882a593Smuzhiyun 
51*4882a593Smuzhiyun 	if (offset & alignmask) {
52*4882a593Smuzhiyun 		unsigned int unaligned = alignmask + 1 - (offset & alignmask);
53*4882a593Smuzhiyun 
54*4882a593Smuzhiyun 		if (nbytes > unaligned)
55*4882a593Smuzhiyun 			nbytes = unaligned;
56*4882a593Smuzhiyun 	}
57*4882a593Smuzhiyun 
58*4882a593Smuzhiyun 	walk->entrylen -= nbytes;
59*4882a593Smuzhiyun 	return nbytes;
60*4882a593Smuzhiyun }
61*4882a593Smuzhiyun 
hash_walk_new_entry(struct crypto_hash_walk * walk)62*4882a593Smuzhiyun static int hash_walk_new_entry(struct crypto_hash_walk *walk)
63*4882a593Smuzhiyun {
64*4882a593Smuzhiyun 	struct scatterlist *sg;
65*4882a593Smuzhiyun 
66*4882a593Smuzhiyun 	sg = walk->sg;
67*4882a593Smuzhiyun 	walk->offset = sg->offset;
68*4882a593Smuzhiyun 	walk->pg = sg_page(walk->sg) + (walk->offset >> PAGE_SHIFT);
69*4882a593Smuzhiyun 	walk->offset = offset_in_page(walk->offset);
70*4882a593Smuzhiyun 	walk->entrylen = sg->length;
71*4882a593Smuzhiyun 
72*4882a593Smuzhiyun 	if (walk->entrylen > walk->total)
73*4882a593Smuzhiyun 		walk->entrylen = walk->total;
74*4882a593Smuzhiyun 	walk->total -= walk->entrylen;
75*4882a593Smuzhiyun 
76*4882a593Smuzhiyun 	return hash_walk_next(walk);
77*4882a593Smuzhiyun }
78*4882a593Smuzhiyun 
crypto_hash_walk_done(struct crypto_hash_walk * walk,int err)79*4882a593Smuzhiyun int crypto_hash_walk_done(struct crypto_hash_walk *walk, int err)
80*4882a593Smuzhiyun {
81*4882a593Smuzhiyun 	unsigned int alignmask = walk->alignmask;
82*4882a593Smuzhiyun 
83*4882a593Smuzhiyun 	walk->data -= walk->offset;
84*4882a593Smuzhiyun 
85*4882a593Smuzhiyun 	if (walk->entrylen && (walk->offset & alignmask) && !err) {
86*4882a593Smuzhiyun 		unsigned int nbytes;
87*4882a593Smuzhiyun 
88*4882a593Smuzhiyun 		walk->offset = ALIGN(walk->offset, alignmask + 1);
89*4882a593Smuzhiyun 		nbytes = min(walk->entrylen,
90*4882a593Smuzhiyun 			     (unsigned int)(PAGE_SIZE - walk->offset));
91*4882a593Smuzhiyun 		if (nbytes) {
92*4882a593Smuzhiyun 			walk->entrylen -= nbytes;
93*4882a593Smuzhiyun 			walk->data += walk->offset;
94*4882a593Smuzhiyun 			return nbytes;
95*4882a593Smuzhiyun 		}
96*4882a593Smuzhiyun 	}
97*4882a593Smuzhiyun 
98*4882a593Smuzhiyun 	kunmap_atomic(walk->data);
99*4882a593Smuzhiyun 	crypto_yield(walk->flags);
100*4882a593Smuzhiyun 
101*4882a593Smuzhiyun 	if (err)
102*4882a593Smuzhiyun 		return err;
103*4882a593Smuzhiyun 
104*4882a593Smuzhiyun 	if (walk->entrylen) {
105*4882a593Smuzhiyun 		walk->offset = 0;
106*4882a593Smuzhiyun 		walk->pg++;
107*4882a593Smuzhiyun 		return hash_walk_next(walk);
108*4882a593Smuzhiyun 	}
109*4882a593Smuzhiyun 
110*4882a593Smuzhiyun 	if (!walk->total)
111*4882a593Smuzhiyun 		return 0;
112*4882a593Smuzhiyun 
113*4882a593Smuzhiyun 	walk->sg = sg_next(walk->sg);
114*4882a593Smuzhiyun 
115*4882a593Smuzhiyun 	return hash_walk_new_entry(walk);
116*4882a593Smuzhiyun }
117*4882a593Smuzhiyun EXPORT_SYMBOL_GPL(crypto_hash_walk_done);
118*4882a593Smuzhiyun 
crypto_hash_walk_first(struct ahash_request * req,struct crypto_hash_walk * walk)119*4882a593Smuzhiyun int crypto_hash_walk_first(struct ahash_request *req,
120*4882a593Smuzhiyun 			   struct crypto_hash_walk *walk)
121*4882a593Smuzhiyun {
122*4882a593Smuzhiyun 	walk->total = req->nbytes;
123*4882a593Smuzhiyun 
124*4882a593Smuzhiyun 	if (!walk->total) {
125*4882a593Smuzhiyun 		walk->entrylen = 0;
126*4882a593Smuzhiyun 		return 0;
127*4882a593Smuzhiyun 	}
128*4882a593Smuzhiyun 
129*4882a593Smuzhiyun 	walk->alignmask = crypto_ahash_alignmask(crypto_ahash_reqtfm(req));
130*4882a593Smuzhiyun 	walk->sg = req->src;
131*4882a593Smuzhiyun 	walk->flags = req->base.flags;
132*4882a593Smuzhiyun 
133*4882a593Smuzhiyun 	return hash_walk_new_entry(walk);
134*4882a593Smuzhiyun }
135*4882a593Smuzhiyun EXPORT_SYMBOL_GPL(crypto_hash_walk_first);
136*4882a593Smuzhiyun 
ahash_setkey_unaligned(struct crypto_ahash * tfm,const u8 * key,unsigned int keylen)137*4882a593Smuzhiyun static int ahash_setkey_unaligned(struct crypto_ahash *tfm, const u8 *key,
138*4882a593Smuzhiyun 				unsigned int keylen)
139*4882a593Smuzhiyun {
140*4882a593Smuzhiyun 	unsigned long alignmask = crypto_ahash_alignmask(tfm);
141*4882a593Smuzhiyun 	int ret;
142*4882a593Smuzhiyun 	u8 *buffer, *alignbuffer;
143*4882a593Smuzhiyun 	unsigned long absize;
144*4882a593Smuzhiyun 
145*4882a593Smuzhiyun 	absize = keylen + alignmask;
146*4882a593Smuzhiyun 	buffer = kmalloc(absize, GFP_KERNEL);
147*4882a593Smuzhiyun 	if (!buffer)
148*4882a593Smuzhiyun 		return -ENOMEM;
149*4882a593Smuzhiyun 
150*4882a593Smuzhiyun 	alignbuffer = (u8 *)ALIGN((unsigned long)buffer, alignmask + 1);
151*4882a593Smuzhiyun 	memcpy(alignbuffer, key, keylen);
152*4882a593Smuzhiyun 	ret = tfm->setkey(tfm, alignbuffer, keylen);
153*4882a593Smuzhiyun 	kfree_sensitive(buffer);
154*4882a593Smuzhiyun 	return ret;
155*4882a593Smuzhiyun }
156*4882a593Smuzhiyun 
ahash_nosetkey(struct crypto_ahash * tfm,const u8 * key,unsigned int keylen)157*4882a593Smuzhiyun static int ahash_nosetkey(struct crypto_ahash *tfm, const u8 *key,
158*4882a593Smuzhiyun 			  unsigned int keylen)
159*4882a593Smuzhiyun {
160*4882a593Smuzhiyun 	return -ENOSYS;
161*4882a593Smuzhiyun }
162*4882a593Smuzhiyun 
ahash_set_needkey(struct crypto_ahash * tfm)163*4882a593Smuzhiyun static void ahash_set_needkey(struct crypto_ahash *tfm)
164*4882a593Smuzhiyun {
165*4882a593Smuzhiyun 	const struct hash_alg_common *alg = crypto_hash_alg_common(tfm);
166*4882a593Smuzhiyun 
167*4882a593Smuzhiyun 	if (tfm->setkey != ahash_nosetkey &&
168*4882a593Smuzhiyun 	    !(alg->base.cra_flags & CRYPTO_ALG_OPTIONAL_KEY))
169*4882a593Smuzhiyun 		crypto_ahash_set_flags(tfm, CRYPTO_TFM_NEED_KEY);
170*4882a593Smuzhiyun }
171*4882a593Smuzhiyun 
crypto_ahash_setkey(struct crypto_ahash * tfm,const u8 * key,unsigned int keylen)172*4882a593Smuzhiyun int crypto_ahash_setkey(struct crypto_ahash *tfm, const u8 *key,
173*4882a593Smuzhiyun 			unsigned int keylen)
174*4882a593Smuzhiyun {
175*4882a593Smuzhiyun 	unsigned long alignmask = crypto_ahash_alignmask(tfm);
176*4882a593Smuzhiyun 	int err;
177*4882a593Smuzhiyun 
178*4882a593Smuzhiyun 	if ((unsigned long)key & alignmask)
179*4882a593Smuzhiyun 		err = ahash_setkey_unaligned(tfm, key, keylen);
180*4882a593Smuzhiyun 	else
181*4882a593Smuzhiyun 		err = tfm->setkey(tfm, key, keylen);
182*4882a593Smuzhiyun 
183*4882a593Smuzhiyun 	if (unlikely(err)) {
184*4882a593Smuzhiyun 		ahash_set_needkey(tfm);
185*4882a593Smuzhiyun 		return err;
186*4882a593Smuzhiyun 	}
187*4882a593Smuzhiyun 
188*4882a593Smuzhiyun 	crypto_ahash_clear_flags(tfm, CRYPTO_TFM_NEED_KEY);
189*4882a593Smuzhiyun 	return 0;
190*4882a593Smuzhiyun }
191*4882a593Smuzhiyun EXPORT_SYMBOL_GPL(crypto_ahash_setkey);
192*4882a593Smuzhiyun 
ahash_align_buffer_size(unsigned len,unsigned long mask)193*4882a593Smuzhiyun static inline unsigned int ahash_align_buffer_size(unsigned len,
194*4882a593Smuzhiyun 						   unsigned long mask)
195*4882a593Smuzhiyun {
196*4882a593Smuzhiyun 	return len + (mask & ~(crypto_tfm_ctx_alignment() - 1));
197*4882a593Smuzhiyun }
198*4882a593Smuzhiyun 
ahash_save_req(struct ahash_request * req,crypto_completion_t cplt)199*4882a593Smuzhiyun static int ahash_save_req(struct ahash_request *req, crypto_completion_t cplt)
200*4882a593Smuzhiyun {
201*4882a593Smuzhiyun 	struct crypto_ahash *tfm = crypto_ahash_reqtfm(req);
202*4882a593Smuzhiyun 	unsigned long alignmask = crypto_ahash_alignmask(tfm);
203*4882a593Smuzhiyun 	unsigned int ds = crypto_ahash_digestsize(tfm);
204*4882a593Smuzhiyun 	struct ahash_request_priv *priv;
205*4882a593Smuzhiyun 
206*4882a593Smuzhiyun 	priv = kmalloc(sizeof(*priv) + ahash_align_buffer_size(ds, alignmask),
207*4882a593Smuzhiyun 		       (req->base.flags & CRYPTO_TFM_REQ_MAY_SLEEP) ?
208*4882a593Smuzhiyun 		       GFP_KERNEL : GFP_ATOMIC);
209*4882a593Smuzhiyun 	if (!priv)
210*4882a593Smuzhiyun 		return -ENOMEM;
211*4882a593Smuzhiyun 
212*4882a593Smuzhiyun 	/*
213*4882a593Smuzhiyun 	 * WARNING: Voodoo programming below!
214*4882a593Smuzhiyun 	 *
215*4882a593Smuzhiyun 	 * The code below is obscure and hard to understand, thus explanation
216*4882a593Smuzhiyun 	 * is necessary. See include/crypto/hash.h and include/linux/crypto.h
217*4882a593Smuzhiyun 	 * to understand the layout of structures used here!
218*4882a593Smuzhiyun 	 *
219*4882a593Smuzhiyun 	 * The code here will replace portions of the ORIGINAL request with
220*4882a593Smuzhiyun 	 * pointers to new code and buffers so the hashing operation can store
221*4882a593Smuzhiyun 	 * the result in aligned buffer. We will call the modified request
222*4882a593Smuzhiyun 	 * an ADJUSTED request.
223*4882a593Smuzhiyun 	 *
224*4882a593Smuzhiyun 	 * The newly mangled request will look as such:
225*4882a593Smuzhiyun 	 *
226*4882a593Smuzhiyun 	 * req {
227*4882a593Smuzhiyun 	 *   .result        = ADJUSTED[new aligned buffer]
228*4882a593Smuzhiyun 	 *   .base.complete = ADJUSTED[pointer to completion function]
229*4882a593Smuzhiyun 	 *   .base.data     = ADJUSTED[*req (pointer to self)]
230*4882a593Smuzhiyun 	 *   .priv          = ADJUSTED[new priv] {
231*4882a593Smuzhiyun 	 *           .result   = ORIGINAL(result)
232*4882a593Smuzhiyun 	 *           .complete = ORIGINAL(base.complete)
233*4882a593Smuzhiyun 	 *           .data     = ORIGINAL(base.data)
234*4882a593Smuzhiyun 	 *   }
235*4882a593Smuzhiyun 	 */
236*4882a593Smuzhiyun 
237*4882a593Smuzhiyun 	priv->result = req->result;
238*4882a593Smuzhiyun 	priv->complete = req->base.complete;
239*4882a593Smuzhiyun 	priv->data = req->base.data;
240*4882a593Smuzhiyun 	priv->flags = req->base.flags;
241*4882a593Smuzhiyun 
242*4882a593Smuzhiyun 	/*
243*4882a593Smuzhiyun 	 * WARNING: We do not backup req->priv here! The req->priv
244*4882a593Smuzhiyun 	 *          is for internal use of the Crypto API and the
245*4882a593Smuzhiyun 	 *          user must _NOT_ _EVER_ depend on it's content!
246*4882a593Smuzhiyun 	 */
247*4882a593Smuzhiyun 
248*4882a593Smuzhiyun 	req->result = PTR_ALIGN((u8 *)priv->ubuf, alignmask + 1);
249*4882a593Smuzhiyun 	req->base.complete = cplt;
250*4882a593Smuzhiyun 	req->base.data = req;
251*4882a593Smuzhiyun 	req->priv = priv;
252*4882a593Smuzhiyun 
253*4882a593Smuzhiyun 	return 0;
254*4882a593Smuzhiyun }
255*4882a593Smuzhiyun 
ahash_restore_req(struct ahash_request * req,int err)256*4882a593Smuzhiyun static void ahash_restore_req(struct ahash_request *req, int err)
257*4882a593Smuzhiyun {
258*4882a593Smuzhiyun 	struct ahash_request_priv *priv = req->priv;
259*4882a593Smuzhiyun 
260*4882a593Smuzhiyun 	if (!err)
261*4882a593Smuzhiyun 		memcpy(priv->result, req->result,
262*4882a593Smuzhiyun 		       crypto_ahash_digestsize(crypto_ahash_reqtfm(req)));
263*4882a593Smuzhiyun 
264*4882a593Smuzhiyun 	/* Restore the original crypto request. */
265*4882a593Smuzhiyun 	req->result = priv->result;
266*4882a593Smuzhiyun 
267*4882a593Smuzhiyun 	ahash_request_set_callback(req, priv->flags,
268*4882a593Smuzhiyun 				   priv->complete, priv->data);
269*4882a593Smuzhiyun 	req->priv = NULL;
270*4882a593Smuzhiyun 
271*4882a593Smuzhiyun 	/* Free the req->priv.priv from the ADJUSTED request. */
272*4882a593Smuzhiyun 	kfree_sensitive(priv);
273*4882a593Smuzhiyun }
274*4882a593Smuzhiyun 
ahash_notify_einprogress(struct ahash_request * req)275*4882a593Smuzhiyun static void ahash_notify_einprogress(struct ahash_request *req)
276*4882a593Smuzhiyun {
277*4882a593Smuzhiyun 	struct ahash_request_priv *priv = req->priv;
278*4882a593Smuzhiyun 	struct crypto_async_request oreq;
279*4882a593Smuzhiyun 
280*4882a593Smuzhiyun 	oreq.data = priv->data;
281*4882a593Smuzhiyun 
282*4882a593Smuzhiyun 	priv->complete(&oreq, -EINPROGRESS);
283*4882a593Smuzhiyun }
284*4882a593Smuzhiyun 
ahash_op_unaligned_done(struct crypto_async_request * req,int err)285*4882a593Smuzhiyun static void ahash_op_unaligned_done(struct crypto_async_request *req, int err)
286*4882a593Smuzhiyun {
287*4882a593Smuzhiyun 	struct ahash_request *areq = req->data;
288*4882a593Smuzhiyun 
289*4882a593Smuzhiyun 	if (err == -EINPROGRESS) {
290*4882a593Smuzhiyun 		ahash_notify_einprogress(areq);
291*4882a593Smuzhiyun 		return;
292*4882a593Smuzhiyun 	}
293*4882a593Smuzhiyun 
294*4882a593Smuzhiyun 	/*
295*4882a593Smuzhiyun 	 * Restore the original request, see ahash_op_unaligned() for what
296*4882a593Smuzhiyun 	 * goes where.
297*4882a593Smuzhiyun 	 *
298*4882a593Smuzhiyun 	 * The "struct ahash_request *req" here is in fact the "req.base"
299*4882a593Smuzhiyun 	 * from the ADJUSTED request from ahash_op_unaligned(), thus as it
300*4882a593Smuzhiyun 	 * is a pointer to self, it is also the ADJUSTED "req" .
301*4882a593Smuzhiyun 	 */
302*4882a593Smuzhiyun 
303*4882a593Smuzhiyun 	/* First copy req->result into req->priv.result */
304*4882a593Smuzhiyun 	ahash_restore_req(areq, err);
305*4882a593Smuzhiyun 
306*4882a593Smuzhiyun 	/* Complete the ORIGINAL request. */
307*4882a593Smuzhiyun 	areq->base.complete(&areq->base, err);
308*4882a593Smuzhiyun }
309*4882a593Smuzhiyun 
ahash_op_unaligned(struct ahash_request * req,int (* op)(struct ahash_request *))310*4882a593Smuzhiyun static int ahash_op_unaligned(struct ahash_request *req,
311*4882a593Smuzhiyun 			      int (*op)(struct ahash_request *))
312*4882a593Smuzhiyun {
313*4882a593Smuzhiyun 	int err;
314*4882a593Smuzhiyun 
315*4882a593Smuzhiyun 	err = ahash_save_req(req, ahash_op_unaligned_done);
316*4882a593Smuzhiyun 	if (err)
317*4882a593Smuzhiyun 		return err;
318*4882a593Smuzhiyun 
319*4882a593Smuzhiyun 	err = op(req);
320*4882a593Smuzhiyun 	if (err == -EINPROGRESS || err == -EBUSY)
321*4882a593Smuzhiyun 		return err;
322*4882a593Smuzhiyun 
323*4882a593Smuzhiyun 	ahash_restore_req(req, err);
324*4882a593Smuzhiyun 
325*4882a593Smuzhiyun 	return err;
326*4882a593Smuzhiyun }
327*4882a593Smuzhiyun 
crypto_ahash_op(struct ahash_request * req,int (* op)(struct ahash_request *))328*4882a593Smuzhiyun static int crypto_ahash_op(struct ahash_request *req,
329*4882a593Smuzhiyun 			   int (*op)(struct ahash_request *))
330*4882a593Smuzhiyun {
331*4882a593Smuzhiyun 	struct crypto_ahash *tfm = crypto_ahash_reqtfm(req);
332*4882a593Smuzhiyun 	unsigned long alignmask = crypto_ahash_alignmask(tfm);
333*4882a593Smuzhiyun 
334*4882a593Smuzhiyun 	if ((unsigned long)req->result & alignmask)
335*4882a593Smuzhiyun 		return ahash_op_unaligned(req, op);
336*4882a593Smuzhiyun 
337*4882a593Smuzhiyun 	return op(req);
338*4882a593Smuzhiyun }
339*4882a593Smuzhiyun 
crypto_ahash_final(struct ahash_request * req)340*4882a593Smuzhiyun int crypto_ahash_final(struct ahash_request *req)
341*4882a593Smuzhiyun {
342*4882a593Smuzhiyun 	struct crypto_ahash *tfm = crypto_ahash_reqtfm(req);
343*4882a593Smuzhiyun 	struct crypto_alg *alg = tfm->base.__crt_alg;
344*4882a593Smuzhiyun 	unsigned int nbytes = req->nbytes;
345*4882a593Smuzhiyun 	int ret;
346*4882a593Smuzhiyun 
347*4882a593Smuzhiyun 	crypto_stats_get(alg);
348*4882a593Smuzhiyun 	ret = crypto_ahash_op(req, crypto_ahash_reqtfm(req)->final);
349*4882a593Smuzhiyun 	crypto_stats_ahash_final(nbytes, ret, alg);
350*4882a593Smuzhiyun 	return ret;
351*4882a593Smuzhiyun }
352*4882a593Smuzhiyun EXPORT_SYMBOL_GPL(crypto_ahash_final);
353*4882a593Smuzhiyun 
crypto_ahash_finup(struct ahash_request * req)354*4882a593Smuzhiyun int crypto_ahash_finup(struct ahash_request *req)
355*4882a593Smuzhiyun {
356*4882a593Smuzhiyun 	struct crypto_ahash *tfm = crypto_ahash_reqtfm(req);
357*4882a593Smuzhiyun 	struct crypto_alg *alg = tfm->base.__crt_alg;
358*4882a593Smuzhiyun 	unsigned int nbytes = req->nbytes;
359*4882a593Smuzhiyun 	int ret;
360*4882a593Smuzhiyun 
361*4882a593Smuzhiyun 	crypto_stats_get(alg);
362*4882a593Smuzhiyun 	ret = crypto_ahash_op(req, crypto_ahash_reqtfm(req)->finup);
363*4882a593Smuzhiyun 	crypto_stats_ahash_final(nbytes, ret, alg);
364*4882a593Smuzhiyun 	return ret;
365*4882a593Smuzhiyun }
366*4882a593Smuzhiyun EXPORT_SYMBOL_GPL(crypto_ahash_finup);
367*4882a593Smuzhiyun 
crypto_ahash_digest(struct ahash_request * req)368*4882a593Smuzhiyun int crypto_ahash_digest(struct ahash_request *req)
369*4882a593Smuzhiyun {
370*4882a593Smuzhiyun 	struct crypto_ahash *tfm = crypto_ahash_reqtfm(req);
371*4882a593Smuzhiyun 	struct crypto_alg *alg = tfm->base.__crt_alg;
372*4882a593Smuzhiyun 	unsigned int nbytes = req->nbytes;
373*4882a593Smuzhiyun 	int ret;
374*4882a593Smuzhiyun 
375*4882a593Smuzhiyun 	crypto_stats_get(alg);
376*4882a593Smuzhiyun 	if (crypto_ahash_get_flags(tfm) & CRYPTO_TFM_NEED_KEY)
377*4882a593Smuzhiyun 		ret = -ENOKEY;
378*4882a593Smuzhiyun 	else
379*4882a593Smuzhiyun 		ret = crypto_ahash_op(req, tfm->digest);
380*4882a593Smuzhiyun 	crypto_stats_ahash_final(nbytes, ret, alg);
381*4882a593Smuzhiyun 	return ret;
382*4882a593Smuzhiyun }
383*4882a593Smuzhiyun EXPORT_SYMBOL_GPL(crypto_ahash_digest);
384*4882a593Smuzhiyun 
ahash_def_finup_done2(struct crypto_async_request * req,int err)385*4882a593Smuzhiyun static void ahash_def_finup_done2(struct crypto_async_request *req, int err)
386*4882a593Smuzhiyun {
387*4882a593Smuzhiyun 	struct ahash_request *areq = req->data;
388*4882a593Smuzhiyun 
389*4882a593Smuzhiyun 	if (err == -EINPROGRESS)
390*4882a593Smuzhiyun 		return;
391*4882a593Smuzhiyun 
392*4882a593Smuzhiyun 	ahash_restore_req(areq, err);
393*4882a593Smuzhiyun 
394*4882a593Smuzhiyun 	areq->base.complete(&areq->base, err);
395*4882a593Smuzhiyun }
396*4882a593Smuzhiyun 
ahash_def_finup_finish1(struct ahash_request * req,int err)397*4882a593Smuzhiyun static int ahash_def_finup_finish1(struct ahash_request *req, int err)
398*4882a593Smuzhiyun {
399*4882a593Smuzhiyun 	if (err)
400*4882a593Smuzhiyun 		goto out;
401*4882a593Smuzhiyun 
402*4882a593Smuzhiyun 	req->base.complete = ahash_def_finup_done2;
403*4882a593Smuzhiyun 
404*4882a593Smuzhiyun 	err = crypto_ahash_reqtfm(req)->final(req);
405*4882a593Smuzhiyun 	if (err == -EINPROGRESS || err == -EBUSY)
406*4882a593Smuzhiyun 		return err;
407*4882a593Smuzhiyun 
408*4882a593Smuzhiyun out:
409*4882a593Smuzhiyun 	ahash_restore_req(req, err);
410*4882a593Smuzhiyun 	return err;
411*4882a593Smuzhiyun }
412*4882a593Smuzhiyun 
ahash_def_finup_done1(struct crypto_async_request * req,int err)413*4882a593Smuzhiyun static void ahash_def_finup_done1(struct crypto_async_request *req, int err)
414*4882a593Smuzhiyun {
415*4882a593Smuzhiyun 	struct ahash_request *areq = req->data;
416*4882a593Smuzhiyun 
417*4882a593Smuzhiyun 	if (err == -EINPROGRESS) {
418*4882a593Smuzhiyun 		ahash_notify_einprogress(areq);
419*4882a593Smuzhiyun 		return;
420*4882a593Smuzhiyun 	}
421*4882a593Smuzhiyun 
422*4882a593Smuzhiyun 	areq->base.flags &= ~CRYPTO_TFM_REQ_MAY_SLEEP;
423*4882a593Smuzhiyun 
424*4882a593Smuzhiyun 	err = ahash_def_finup_finish1(areq, err);
425*4882a593Smuzhiyun 	if (areq->priv)
426*4882a593Smuzhiyun 		return;
427*4882a593Smuzhiyun 
428*4882a593Smuzhiyun 	areq->base.complete(&areq->base, err);
429*4882a593Smuzhiyun }
430*4882a593Smuzhiyun 
ahash_def_finup(struct ahash_request * req)431*4882a593Smuzhiyun static int ahash_def_finup(struct ahash_request *req)
432*4882a593Smuzhiyun {
433*4882a593Smuzhiyun 	struct crypto_ahash *tfm = crypto_ahash_reqtfm(req);
434*4882a593Smuzhiyun 	int err;
435*4882a593Smuzhiyun 
436*4882a593Smuzhiyun 	err = ahash_save_req(req, ahash_def_finup_done1);
437*4882a593Smuzhiyun 	if (err)
438*4882a593Smuzhiyun 		return err;
439*4882a593Smuzhiyun 
440*4882a593Smuzhiyun 	err = tfm->update(req);
441*4882a593Smuzhiyun 	if (err == -EINPROGRESS || err == -EBUSY)
442*4882a593Smuzhiyun 		return err;
443*4882a593Smuzhiyun 
444*4882a593Smuzhiyun 	return ahash_def_finup_finish1(req, err);
445*4882a593Smuzhiyun }
446*4882a593Smuzhiyun 
crypto_ahash_exit_tfm(struct crypto_tfm * tfm)447*4882a593Smuzhiyun static void crypto_ahash_exit_tfm(struct crypto_tfm *tfm)
448*4882a593Smuzhiyun {
449*4882a593Smuzhiyun 	struct crypto_ahash *hash = __crypto_ahash_cast(tfm);
450*4882a593Smuzhiyun 	struct ahash_alg *alg = crypto_ahash_alg(hash);
451*4882a593Smuzhiyun 
452*4882a593Smuzhiyun 	alg->exit_tfm(hash);
453*4882a593Smuzhiyun }
454*4882a593Smuzhiyun 
crypto_ahash_init_tfm(struct crypto_tfm * tfm)455*4882a593Smuzhiyun static int crypto_ahash_init_tfm(struct crypto_tfm *tfm)
456*4882a593Smuzhiyun {
457*4882a593Smuzhiyun 	struct crypto_ahash *hash = __crypto_ahash_cast(tfm);
458*4882a593Smuzhiyun 	struct ahash_alg *alg = crypto_ahash_alg(hash);
459*4882a593Smuzhiyun 
460*4882a593Smuzhiyun 	hash->setkey = ahash_nosetkey;
461*4882a593Smuzhiyun 
462*4882a593Smuzhiyun 	if (tfm->__crt_alg->cra_type != &crypto_ahash_type)
463*4882a593Smuzhiyun 		return crypto_init_shash_ops_async(tfm);
464*4882a593Smuzhiyun 
465*4882a593Smuzhiyun 	hash->init = alg->init;
466*4882a593Smuzhiyun 	hash->update = alg->update;
467*4882a593Smuzhiyun 	hash->final = alg->final;
468*4882a593Smuzhiyun 	hash->finup = alg->finup ?: ahash_def_finup;
469*4882a593Smuzhiyun 	hash->digest = alg->digest;
470*4882a593Smuzhiyun 	hash->export = alg->export;
471*4882a593Smuzhiyun 	hash->import = alg->import;
472*4882a593Smuzhiyun 
473*4882a593Smuzhiyun 	if (alg->setkey) {
474*4882a593Smuzhiyun 		hash->setkey = alg->setkey;
475*4882a593Smuzhiyun 		ahash_set_needkey(hash);
476*4882a593Smuzhiyun 	}
477*4882a593Smuzhiyun 
478*4882a593Smuzhiyun 	if (alg->exit_tfm)
479*4882a593Smuzhiyun 		tfm->exit = crypto_ahash_exit_tfm;
480*4882a593Smuzhiyun 
481*4882a593Smuzhiyun 	return alg->init_tfm ? alg->init_tfm(hash) : 0;
482*4882a593Smuzhiyun }
483*4882a593Smuzhiyun 
crypto_ahash_extsize(struct crypto_alg * alg)484*4882a593Smuzhiyun static unsigned int crypto_ahash_extsize(struct crypto_alg *alg)
485*4882a593Smuzhiyun {
486*4882a593Smuzhiyun 	if (alg->cra_type != &crypto_ahash_type)
487*4882a593Smuzhiyun 		return sizeof(struct crypto_shash *);
488*4882a593Smuzhiyun 
489*4882a593Smuzhiyun 	return crypto_alg_extsize(alg);
490*4882a593Smuzhiyun }
491*4882a593Smuzhiyun 
crypto_ahash_free_instance(struct crypto_instance * inst)492*4882a593Smuzhiyun static void crypto_ahash_free_instance(struct crypto_instance *inst)
493*4882a593Smuzhiyun {
494*4882a593Smuzhiyun 	struct ahash_instance *ahash = ahash_instance(inst);
495*4882a593Smuzhiyun 
496*4882a593Smuzhiyun 	ahash->free(ahash);
497*4882a593Smuzhiyun }
498*4882a593Smuzhiyun 
499*4882a593Smuzhiyun #ifdef CONFIG_NET
crypto_ahash_report(struct sk_buff * skb,struct crypto_alg * alg)500*4882a593Smuzhiyun static int crypto_ahash_report(struct sk_buff *skb, struct crypto_alg *alg)
501*4882a593Smuzhiyun {
502*4882a593Smuzhiyun 	struct crypto_report_hash rhash;
503*4882a593Smuzhiyun 
504*4882a593Smuzhiyun 	memset(&rhash, 0, sizeof(rhash));
505*4882a593Smuzhiyun 
506*4882a593Smuzhiyun 	strscpy(rhash.type, "ahash", sizeof(rhash.type));
507*4882a593Smuzhiyun 
508*4882a593Smuzhiyun 	rhash.blocksize = alg->cra_blocksize;
509*4882a593Smuzhiyun 	rhash.digestsize = __crypto_hash_alg_common(alg)->digestsize;
510*4882a593Smuzhiyun 
511*4882a593Smuzhiyun 	return nla_put(skb, CRYPTOCFGA_REPORT_HASH, sizeof(rhash), &rhash);
512*4882a593Smuzhiyun }
513*4882a593Smuzhiyun #else
crypto_ahash_report(struct sk_buff * skb,struct crypto_alg * alg)514*4882a593Smuzhiyun static int crypto_ahash_report(struct sk_buff *skb, struct crypto_alg *alg)
515*4882a593Smuzhiyun {
516*4882a593Smuzhiyun 	return -ENOSYS;
517*4882a593Smuzhiyun }
518*4882a593Smuzhiyun #endif
519*4882a593Smuzhiyun 
520*4882a593Smuzhiyun static void crypto_ahash_show(struct seq_file *m, struct crypto_alg *alg)
521*4882a593Smuzhiyun 	__maybe_unused;
crypto_ahash_show(struct seq_file * m,struct crypto_alg * alg)522*4882a593Smuzhiyun static void crypto_ahash_show(struct seq_file *m, struct crypto_alg *alg)
523*4882a593Smuzhiyun {
524*4882a593Smuzhiyun 	seq_printf(m, "type         : ahash\n");
525*4882a593Smuzhiyun 	seq_printf(m, "async        : %s\n", alg->cra_flags & CRYPTO_ALG_ASYNC ?
526*4882a593Smuzhiyun 					     "yes" : "no");
527*4882a593Smuzhiyun 	seq_printf(m, "blocksize    : %u\n", alg->cra_blocksize);
528*4882a593Smuzhiyun 	seq_printf(m, "digestsize   : %u\n",
529*4882a593Smuzhiyun 		   __crypto_hash_alg_common(alg)->digestsize);
530*4882a593Smuzhiyun }
531*4882a593Smuzhiyun 
532*4882a593Smuzhiyun static const struct crypto_type crypto_ahash_type = {
533*4882a593Smuzhiyun 	.extsize = crypto_ahash_extsize,
534*4882a593Smuzhiyun 	.init_tfm = crypto_ahash_init_tfm,
535*4882a593Smuzhiyun 	.free = crypto_ahash_free_instance,
536*4882a593Smuzhiyun #ifdef CONFIG_PROC_FS
537*4882a593Smuzhiyun 	.show = crypto_ahash_show,
538*4882a593Smuzhiyun #endif
539*4882a593Smuzhiyun 	.report = crypto_ahash_report,
540*4882a593Smuzhiyun 	.maskclear = ~CRYPTO_ALG_TYPE_MASK,
541*4882a593Smuzhiyun 	.maskset = CRYPTO_ALG_TYPE_AHASH_MASK,
542*4882a593Smuzhiyun 	.type = CRYPTO_ALG_TYPE_AHASH,
543*4882a593Smuzhiyun 	.tfmsize = offsetof(struct crypto_ahash, base),
544*4882a593Smuzhiyun };
545*4882a593Smuzhiyun 
crypto_grab_ahash(struct crypto_ahash_spawn * spawn,struct crypto_instance * inst,const char * name,u32 type,u32 mask)546*4882a593Smuzhiyun int crypto_grab_ahash(struct crypto_ahash_spawn *spawn,
547*4882a593Smuzhiyun 		      struct crypto_instance *inst,
548*4882a593Smuzhiyun 		      const char *name, u32 type, u32 mask)
549*4882a593Smuzhiyun {
550*4882a593Smuzhiyun 	spawn->base.frontend = &crypto_ahash_type;
551*4882a593Smuzhiyun 	return crypto_grab_spawn(&spawn->base, inst, name, type, mask);
552*4882a593Smuzhiyun }
553*4882a593Smuzhiyun EXPORT_SYMBOL_GPL(crypto_grab_ahash);
554*4882a593Smuzhiyun 
crypto_alloc_ahash(const char * alg_name,u32 type,u32 mask)555*4882a593Smuzhiyun struct crypto_ahash *crypto_alloc_ahash(const char *alg_name, u32 type,
556*4882a593Smuzhiyun 					u32 mask)
557*4882a593Smuzhiyun {
558*4882a593Smuzhiyun 	return crypto_alloc_tfm(alg_name, &crypto_ahash_type, type, mask);
559*4882a593Smuzhiyun }
560*4882a593Smuzhiyun EXPORT_SYMBOL_GPL(crypto_alloc_ahash);
561*4882a593Smuzhiyun 
crypto_has_ahash(const char * alg_name,u32 type,u32 mask)562*4882a593Smuzhiyun int crypto_has_ahash(const char *alg_name, u32 type, u32 mask)
563*4882a593Smuzhiyun {
564*4882a593Smuzhiyun 	return crypto_type_has_alg(alg_name, &crypto_ahash_type, type, mask);
565*4882a593Smuzhiyun }
566*4882a593Smuzhiyun EXPORT_SYMBOL_GPL(crypto_has_ahash);
567*4882a593Smuzhiyun 
ahash_prepare_alg(struct ahash_alg * alg)568*4882a593Smuzhiyun static int ahash_prepare_alg(struct ahash_alg *alg)
569*4882a593Smuzhiyun {
570*4882a593Smuzhiyun 	struct crypto_alg *base = &alg->halg.base;
571*4882a593Smuzhiyun 
572*4882a593Smuzhiyun 	if (alg->halg.digestsize > HASH_MAX_DIGESTSIZE ||
573*4882a593Smuzhiyun 	    alg->halg.statesize > HASH_MAX_STATESIZE ||
574*4882a593Smuzhiyun 	    alg->halg.statesize == 0)
575*4882a593Smuzhiyun 		return -EINVAL;
576*4882a593Smuzhiyun 
577*4882a593Smuzhiyun 	base->cra_type = &crypto_ahash_type;
578*4882a593Smuzhiyun 	base->cra_flags &= ~CRYPTO_ALG_TYPE_MASK;
579*4882a593Smuzhiyun 	base->cra_flags |= CRYPTO_ALG_TYPE_AHASH;
580*4882a593Smuzhiyun 
581*4882a593Smuzhiyun 	return 0;
582*4882a593Smuzhiyun }
583*4882a593Smuzhiyun 
crypto_register_ahash(struct ahash_alg * alg)584*4882a593Smuzhiyun int crypto_register_ahash(struct ahash_alg *alg)
585*4882a593Smuzhiyun {
586*4882a593Smuzhiyun 	struct crypto_alg *base = &alg->halg.base;
587*4882a593Smuzhiyun 	int err;
588*4882a593Smuzhiyun 
589*4882a593Smuzhiyun 	err = ahash_prepare_alg(alg);
590*4882a593Smuzhiyun 	if (err)
591*4882a593Smuzhiyun 		return err;
592*4882a593Smuzhiyun 
593*4882a593Smuzhiyun 	return crypto_register_alg(base);
594*4882a593Smuzhiyun }
595*4882a593Smuzhiyun EXPORT_SYMBOL_GPL(crypto_register_ahash);
596*4882a593Smuzhiyun 
crypto_unregister_ahash(struct ahash_alg * alg)597*4882a593Smuzhiyun void crypto_unregister_ahash(struct ahash_alg *alg)
598*4882a593Smuzhiyun {
599*4882a593Smuzhiyun 	crypto_unregister_alg(&alg->halg.base);
600*4882a593Smuzhiyun }
601*4882a593Smuzhiyun EXPORT_SYMBOL_GPL(crypto_unregister_ahash);
602*4882a593Smuzhiyun 
crypto_register_ahashes(struct ahash_alg * algs,int count)603*4882a593Smuzhiyun int crypto_register_ahashes(struct ahash_alg *algs, int count)
604*4882a593Smuzhiyun {
605*4882a593Smuzhiyun 	int i, ret;
606*4882a593Smuzhiyun 
607*4882a593Smuzhiyun 	for (i = 0; i < count; i++) {
608*4882a593Smuzhiyun 		ret = crypto_register_ahash(&algs[i]);
609*4882a593Smuzhiyun 		if (ret)
610*4882a593Smuzhiyun 			goto err;
611*4882a593Smuzhiyun 	}
612*4882a593Smuzhiyun 
613*4882a593Smuzhiyun 	return 0;
614*4882a593Smuzhiyun 
615*4882a593Smuzhiyun err:
616*4882a593Smuzhiyun 	for (--i; i >= 0; --i)
617*4882a593Smuzhiyun 		crypto_unregister_ahash(&algs[i]);
618*4882a593Smuzhiyun 
619*4882a593Smuzhiyun 	return ret;
620*4882a593Smuzhiyun }
621*4882a593Smuzhiyun EXPORT_SYMBOL_GPL(crypto_register_ahashes);
622*4882a593Smuzhiyun 
crypto_unregister_ahashes(struct ahash_alg * algs,int count)623*4882a593Smuzhiyun void crypto_unregister_ahashes(struct ahash_alg *algs, int count)
624*4882a593Smuzhiyun {
625*4882a593Smuzhiyun 	int i;
626*4882a593Smuzhiyun 
627*4882a593Smuzhiyun 	for (i = count - 1; i >= 0; --i)
628*4882a593Smuzhiyun 		crypto_unregister_ahash(&algs[i]);
629*4882a593Smuzhiyun }
630*4882a593Smuzhiyun EXPORT_SYMBOL_GPL(crypto_unregister_ahashes);
631*4882a593Smuzhiyun 
ahash_register_instance(struct crypto_template * tmpl,struct ahash_instance * inst)632*4882a593Smuzhiyun int ahash_register_instance(struct crypto_template *tmpl,
633*4882a593Smuzhiyun 			    struct ahash_instance *inst)
634*4882a593Smuzhiyun {
635*4882a593Smuzhiyun 	int err;
636*4882a593Smuzhiyun 
637*4882a593Smuzhiyun 	if (WARN_ON(!inst->free))
638*4882a593Smuzhiyun 		return -EINVAL;
639*4882a593Smuzhiyun 
640*4882a593Smuzhiyun 	err = ahash_prepare_alg(&inst->alg);
641*4882a593Smuzhiyun 	if (err)
642*4882a593Smuzhiyun 		return err;
643*4882a593Smuzhiyun 
644*4882a593Smuzhiyun 	return crypto_register_instance(tmpl, ahash_crypto_instance(inst));
645*4882a593Smuzhiyun }
646*4882a593Smuzhiyun EXPORT_SYMBOL_GPL(ahash_register_instance);
647*4882a593Smuzhiyun 
crypto_hash_alg_has_setkey(struct hash_alg_common * halg)648*4882a593Smuzhiyun bool crypto_hash_alg_has_setkey(struct hash_alg_common *halg)
649*4882a593Smuzhiyun {
650*4882a593Smuzhiyun 	struct crypto_alg *alg = &halg->base;
651*4882a593Smuzhiyun 
652*4882a593Smuzhiyun 	if (alg->cra_type != &crypto_ahash_type)
653*4882a593Smuzhiyun 		return crypto_shash_alg_has_setkey(__crypto_shash_alg(alg));
654*4882a593Smuzhiyun 
655*4882a593Smuzhiyun 	return __crypto_ahash_alg(alg)->setkey != NULL;
656*4882a593Smuzhiyun }
657*4882a593Smuzhiyun EXPORT_SYMBOL_GPL(crypto_hash_alg_has_setkey);
658*4882a593Smuzhiyun 
659*4882a593Smuzhiyun MODULE_LICENSE("GPL");
660*4882a593Smuzhiyun MODULE_DESCRIPTION("Asynchronous cryptographic hash type");
661