2019-11-08 13:22:24 +01:00
|
|
|
// SPDX-License-Identifier: GPL-2.0
|
|
|
|
/*
|
|
|
|
* OpenSSL/Cryptogams accelerated Poly1305 transform for arm64
|
|
|
|
*
|
|
|
|
* Copyright (C) 2019 Linaro Ltd. <ard.biesheuvel@linaro.org>
|
|
|
|
*/
|
|
|
|
|
|
|
|
#include <asm/hwcap.h>
|
|
|
|
#include <asm/neon.h>
|
2025-07-06 16:10:58 -07:00
|
|
|
#include <asm/simd.h>
|
2025-04-28 12:56:11 +08:00
|
|
|
#include <crypto/internal/poly1305.h>
|
2019-11-08 13:22:24 +01:00
|
|
|
#include <linux/cpufeature.h>
|
|
|
|
#include <linux/jump_label.h>
|
2025-04-28 12:56:11 +08:00
|
|
|
#include <linux/kernel.h>
|
2019-11-08 13:22:24 +01:00
|
|
|
#include <linux/module.h>
|
2025-04-12 21:54:16 -07:00
|
|
|
#include <linux/unaligned.h>
|
2019-11-08 13:22:24 +01:00
|
|
|
|
2025-04-28 12:56:11 +08:00
|
|
|
asmlinkage void poly1305_block_init_arch(
|
|
|
|
struct poly1305_block_state *state,
|
|
|
|
const u8 raw_key[POLY1305_BLOCK_SIZE]);
|
|
|
|
EXPORT_SYMBOL_GPL(poly1305_block_init_arch);
|
|
|
|
asmlinkage void poly1305_blocks(struct poly1305_block_state *state,
|
|
|
|
const u8 *src, u32 len, u32 hibit);
|
|
|
|
asmlinkage void poly1305_blocks_neon(struct poly1305_block_state *state,
|
|
|
|
const u8 *src, u32 len, u32 hibit);
|
|
|
|
asmlinkage void poly1305_emit_arch(const struct poly1305_state *state,
|
|
|
|
u8 digest[POLY1305_DIGEST_SIZE],
|
|
|
|
const u32 nonce[4]);
|
|
|
|
EXPORT_SYMBOL_GPL(poly1305_emit_arch);
|
2019-11-08 13:22:24 +01:00
|
|
|
|
|
|
|
static __ro_after_init DEFINE_STATIC_KEY_FALSE(have_neon);
|
|
|
|
|
2025-04-28 12:56:11 +08:00
|
|
|
void poly1305_blocks_arch(struct poly1305_block_state *state, const u8 *src,
|
|
|
|
unsigned int len, u32 padbit)
|
|
|
|
{
|
|
|
|
len = round_down(len, POLY1305_BLOCK_SIZE);
|
2025-07-06 16:10:58 -07:00
|
|
|
if (static_branch_likely(&have_neon) && likely(may_use_simd())) {
|
2025-04-28 12:56:11 +08:00
|
|
|
do {
|
|
|
|
unsigned int todo = min_t(unsigned int, len, SZ_4K);
|
|
|
|
|
|
|
|
kernel_neon_begin();
|
2025-06-15 18:06:54 -07:00
|
|
|
poly1305_blocks_neon(state, src, todo, padbit);
|
2025-04-28 12:56:11 +08:00
|
|
|
kernel_neon_end();
|
|
|
|
|
|
|
|
len -= todo;
|
|
|
|
src += todo;
|
|
|
|
} while (len);
|
|
|
|
} else
|
2025-06-15 18:06:54 -07:00
|
|
|
poly1305_blocks(state, src, len, padbit);
|
2025-04-28 12:56:11 +08:00
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(poly1305_blocks_arch);
|
|
|
|
|
crypto: poly1305 - centralize the shash wrappers for arch code
Following the example of the crc32, crc32c, and chacha code, make the
crypto subsystem register both generic and architecture-optimized
poly1305 shash algorithms, both implemented on top of the appropriate
library functions. This eliminates the need for every architecture to
implement the same shash glue code.
Note that the poly1305 shash requires that the key be prepended to the
data, which differs from the library functions where the key is simply a
parameter to poly1305_init(). Previously this was handled at a fairly
low level, polluting the library code with shash-specific code.
Reorganize things so that the shash code handles this quirk itself.
Also, to register the architecture-optimized shashes only when
architecture-optimized code is actually being used, add a function
poly1305_is_arch_optimized() and make each arch implement it. Change
each architecture's Poly1305 module_init function to arch_initcall so
that the CPU feature detection is guaranteed to run before
poly1305_is_arch_optimized() gets called by crypto/poly1305.c. (In
cases where poly1305_is_arch_optimized() just returns true
unconditionally, using arch_initcall is not strictly needed, but it's
still good to be consistent across architectures.)
Signed-off-by: Eric Biggers <ebiggers@google.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
2025-04-12 21:54:14 -07:00
|
|
|
bool poly1305_is_arch_optimized(void)
|
|
|
|
{
|
|
|
|
/* We always can use at least the ARM64 scalar implementation. */
|
|
|
|
return true;
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL(poly1305_is_arch_optimized);
|
|
|
|
|
2019-11-08 13:22:24 +01:00
|
|
|
static int __init neon_poly1305_mod_init(void)
|
|
|
|
{
|
2025-04-12 21:54:16 -07:00
|
|
|
if (cpu_have_named_feature(ASIMD))
|
|
|
|
static_branch_enable(&have_neon);
|
|
|
|
return 0;
|
2019-11-08 13:22:24 +01:00
|
|
|
}
|
2025-04-30 16:17:02 +08:00
|
|
|
subsys_initcall(neon_poly1305_mod_init);
|
2019-11-08 13:22:24 +01:00
|
|
|
|
2025-04-17 21:00:17 -07:00
|
|
|
static void __exit neon_poly1305_mod_exit(void)
|
|
|
|
{
|
|
|
|
}
|
|
|
|
module_exit(neon_poly1305_mod_exit);
|
|
|
|
|
2025-04-12 21:54:16 -07:00
|
|
|
MODULE_DESCRIPTION("Poly1305 authenticator (ARM64 optimized)");
|
2019-11-08 13:22:24 +01:00
|
|
|
MODULE_LICENSE("GPL v2");
|