1c0341432SJohn Baldwin.\" Copyright (c) 2020, Chelsio Inc 2c0341432SJohn Baldwin.\" 3c0341432SJohn Baldwin.\" Redistribution and use in source and binary forms, with or without 4c0341432SJohn Baldwin.\" modification, are permitted provided that the following conditions are met: 5c0341432SJohn Baldwin.\" 6c0341432SJohn Baldwin.\" 1. Redistributions of source code must retain the above copyright notice, 7c0341432SJohn Baldwin.\" this list of conditions and the following disclaimer. 8c0341432SJohn Baldwin.\" 9c0341432SJohn Baldwin.\" 2. Redistributions in binary form must reproduce the above copyright 10c0341432SJohn Baldwin.\" notice, this list of conditions and the following disclaimer in the 11c0341432SJohn Baldwin.\" documentation and/or other materials provided with the distribution. 12c0341432SJohn Baldwin.\" 13c0341432SJohn Baldwin.\" 3. Neither the name of the Chelsio Inc nor the names of its 14c0341432SJohn Baldwin.\" contributors may be used to endorse or promote products derived from 15c0341432SJohn Baldwin.\" this software without specific prior written permission. 16c0341432SJohn Baldwin.\" 17c0341432SJohn Baldwin.\" THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" 18c0341432SJohn Baldwin.\" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 19c0341432SJohn Baldwin.\" IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 20c0341432SJohn Baldwin.\" ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE 21c0341432SJohn Baldwin.\" LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR 22c0341432SJohn Baldwin.\" CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF 23c0341432SJohn Baldwin.\" SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS 24c0341432SJohn Baldwin.\" INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN 25c0341432SJohn Baldwin.\" CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) 26c0341432SJohn Baldwin.\" ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE 27c0341432SJohn Baldwin.\" POSSIBILITY OF SUCH DAMAGE. 28c0341432SJohn Baldwin.\" 29c0341432SJohn Baldwin.\" * Other names and brands may be claimed as the property of others. 30c0341432SJohn Baldwin.\" 31*76681661SJohn Baldwin.Dd April 12, 2021 32c0341432SJohn Baldwin.Dt CRYPTO_DRIVER 9 33c0341432SJohn Baldwin.Os 34c0341432SJohn Baldwin.Sh NAME 35c0341432SJohn Baldwin.Nm crypto_driver 36c0341432SJohn Baldwin.Nd interface for symmetric cryptographic drivers 37c0341432SJohn Baldwin.Sh SYNOPSIS 38c0341432SJohn Baldwin.In opencrypto/cryptodev.h 39c0341432SJohn Baldwin.Ft void 40c0341432SJohn Baldwin.Fn crypto_copyback "struct cryptop *crp" "int off" "int size" "const void *src" 41c0341432SJohn Baldwin.Ft void 42c0341432SJohn Baldwin.Fn crypto_copydata "struct cryptop *crp" "int off" "int size" "void *dst" 43c0341432SJohn Baldwin.Ft void 44c0341432SJohn Baldwin.Fn crypto_done "struct cryptop *crp" 45c0341432SJohn Baldwin.Ft int32_t 46c0341432SJohn Baldwin.Fn crypto_get_driverid "device_t dev" "size_t session_size" "int flags" 47c0341432SJohn Baldwin.Ft void * 48c0341432SJohn Baldwin.Fn crypto_get_driver_session "crypto_session_t crypto_session" 4929fe41ddSJohn Baldwin.Ft void 5029fe41ddSJohn Baldwin.Fn crypto_read_iv "struct cryptop *crp" "void *iv" 51c0341432SJohn Baldwin.Ft int 52c0341432SJohn Baldwin.Fn crypto_unblock "uint32_t driverid" "int what" 53c0341432SJohn Baldwin.Ft int 54c0341432SJohn Baldwin.Fn crypto_unregister_all "uint32_t driverid" 55c0341432SJohn Baldwin.Ft int 56c0341432SJohn Baldwin.Fn CRYPTODEV_FREESESSION "device_t dev" "crypto_session_t crypto_session" 57c0341432SJohn Baldwin.Ft int 58c0341432SJohn Baldwin.Fo CRYPTODEV_NEWSESSION 59c0341432SJohn Baldwin.Fa "device_t dev" 60c0341432SJohn Baldwin.Fa "crypto_session_t crypto_session" 61c0341432SJohn Baldwin.Fa "const struct crypto_session_params *csp" 62c0341432SJohn Baldwin.Fc 63c0341432SJohn Baldwin.Ft int 64c0341432SJohn Baldwin.Fo CRYPTODEV_PROBESESSION 65c0341432SJohn Baldwin.Fa "device_t dev" 66c0341432SJohn Baldwin.Fa "const struct crypto_session_params *csp" 67c0341432SJohn Baldwin.Fc 68c0341432SJohn Baldwin.Ft int 69c0341432SJohn Baldwin.Fn CRYPTODEV_PROCESS "device_t dev" "struct cryptop *crp" "int flags" 70c0341432SJohn Baldwin.Ft void 71c0341432SJohn Baldwin.Fo hmac_init_ipad 72c0341432SJohn Baldwin.Fa "struct auth_hash *axf" 73c0341432SJohn Baldwin.Fa "const char *key" 74c0341432SJohn Baldwin.Fa "int klen" 75c0341432SJohn Baldwin.Fa "void *auth_ctx" 76c0341432SJohn Baldwin.Fc 77c0341432SJohn Baldwin.Ft void 78c0341432SJohn Baldwin.Fo hmac_init_opad 79c0341432SJohn Baldwin.Fa "struct auth_hash *axf" 80c0341432SJohn Baldwin.Fa "const char *key" 81c0341432SJohn Baldwin.Fa "int klen" 82c0341432SJohn Baldwin.Fa "void *auth_ctx" 83c0341432SJohn Baldwin.Fc 84c0341432SJohn Baldwin.Sh DESCRIPTION 85c0341432SJohn BaldwinSymmetric cryptographic drivers process cryptographic requests 86c0341432SJohn Baldwinsubmitted to sessions associated with the driver. 87c0341432SJohn Baldwin.Pp 88c0341432SJohn BaldwinCryptographic drivers call 89c0341432SJohn Baldwin.Fn crypto_get_driverid 90c0341432SJohn Baldwinto register with the cryptographic framework. 91c0341432SJohn Baldwin.Fa dev 92c0341432SJohn Baldwinis the device used to service requests. 93c0341432SJohn BaldwinThe 94c0341432SJohn Baldwin.Fn CRYPTODEV 95c0341432SJohn Baldwinmethods are defined in the method table for the device driver attached to 96c0341432SJohn Baldwin.Fa dev . 97c0341432SJohn Baldwin.Fa session_size 98c0341432SJohn Baldwinspecifies the size of a driver-specific per-session structure allocated by 99c0341432SJohn Baldwinthe cryptographic framework. 100c0341432SJohn Baldwin.Fa flags 101c0341432SJohn Baldwinis a bitmask of properties about the driver. 102c0341432SJohn BaldwinExactly one of 103c0341432SJohn Baldwin.Dv CRYPTOCAP_F_SOFTWARE 104c0341432SJohn Baldwinor 105c0341432SJohn Baldwin.Dv CRYPTOCAP_F_HARDWARE 106c0341432SJohn Baldwinmust be specified. 107c0341432SJohn Baldwin.Dv CRYPTOCAP_F_SOFTWARE 108c0341432SJohn Baldwinshould be used for drivers which process requests using host CPUs. 109c0341432SJohn Baldwin.Dv CRYPTOCAP_F_HARDWARE 110c0341432SJohn Baldwinshould be used for drivers which process requests on separate co-processors. 111c0341432SJohn Baldwin.Dv CRYPTOCAP_F_SYNC 112c0341432SJohn Baldwinshould be set for drivers which process requests synchronously in 113c0341432SJohn Baldwin.Fn CRYPTODEV_PROCESS . 114a3d565a1SJohn Baldwin.Dv CRYPTOCAP_F_ACCEL_SOFTWARE 115a3d565a1SJohn Baldwinshould be set for software drivers which use accelerated CPU instructions. 116c0341432SJohn Baldwin.Fn crypto_get_driverid 117c0341432SJohn Baldwinreturns an opaque driver id. 118c0341432SJohn Baldwin.Pp 119c0341432SJohn Baldwin.Fn crypto_unregister_all 120c0341432SJohn Baldwinunregisters a driver from the cryptographic framework. 121c0341432SJohn BaldwinIf there are any pending operations or open sessions, 122c0341432SJohn Baldwinthis function will sleep. 123c0341432SJohn Baldwin.Fa driverid 124c0341432SJohn Baldwinis the value returned by an earlier call to 125c0341432SJohn Baldwin.Fn crypto_get_driverid . 126c0341432SJohn Baldwin.Pp 127c0341432SJohn BaldwinWhen a new session is created by 128c0341432SJohn Baldwin.Fn crypto_newsession , 129c0341432SJohn Baldwin.Fn CRYPTODEV_PROBESESSION 130c0341432SJohn Baldwinis invoked by the cryptographic framework on each active driver to 131c0341432SJohn Baldwindetermine the best driver to use for the session. 132c0341432SJohn BaldwinThis method should inspect the session parameters in 133c0341432SJohn Baldwin.Fa csp . 134c0341432SJohn BaldwinIf a driver does not support requests described by 135c0341432SJohn Baldwin.Fa csp , 136c0341432SJohn Baldwinthis method should return an error value. 137c0341432SJohn BaldwinIf the driver does support requests described by 138c0341432SJohn Baldwin.Fa csp , 139c0341432SJohn Baldwinit should return a negative value. 140c0341432SJohn BaldwinThe framework prefers drivers with the largest negative value, 141c0341432SJohn Baldwinsimilar to 142c0341432SJohn Baldwin.Xr DEVICE_PROBE 9 . 143c0341432SJohn BaldwinThe following values are defined for non-error return values from this 144c0341432SJohn Baldwinmethod: 145c0341432SJohn Baldwin.Bl -tag -width "CRYPTODEV_PROBE_ACCEL_SOFTWARE" 146c0341432SJohn Baldwin.It Dv CRYPTODEV_PROBE_HARDWARE 147c0341432SJohn BaldwinThe driver processes requests via a co-processor. 148c0341432SJohn Baldwin.It Dv CRYPTODEV_PROBE_ACCEL_SOFTWARE 149c0341432SJohn BaldwinThe driver processes requests on the host CPU using optimized instructions 150c0341432SJohn Baldwinsuch as AES-NI. 151c0341432SJohn Baldwin.It Dv CRYPTODEV_PROBE_SOFTWARE 152c0341432SJohn BaldwinThe driver processes requests on the host CPU. 153c0341432SJohn Baldwin.El 154c0341432SJohn Baldwin.Pp 155c0341432SJohn BaldwinThis method should not sleep. 156c0341432SJohn Baldwin.Pp 157c0341432SJohn BaldwinOnce the framework has chosen a driver for a session, 158c0341432SJohn Baldwinthe framework invokes the 159c0341432SJohn Baldwin.Fn CRYPTODEV_NEWSESSION 160c0341432SJohn Baldwinmethod to initialize driver-specific session state. 161c0341432SJohn BaldwinPrior to calling this method, 162c0341432SJohn Baldwinthe framework allocates a per-session driver-specific data structure. 163c0341432SJohn BaldwinThis structure is initialized with zeroes, 164c0341432SJohn Baldwinand its size is set by the 165c0341432SJohn Baldwin.Fa session_size 166c0341432SJohn Baldwinpassed to 167c0341432SJohn Baldwin.Fn crypto_get_driverid . 168c0341432SJohn BaldwinThis method can retrieve a pointer to this data structure by passing 169c0341432SJohn Baldwin.Fa crypto_session 170c0341432SJohn Baldwinto 171c0341432SJohn Baldwin.Fn crypto_get_driver_session . 172c0341432SJohn BaldwinSession parameters are described in 173c0341432SJohn Baldwin.Fa csp . 174c0341432SJohn Baldwin.Pp 175c0341432SJohn BaldwinThis method should not sleep. 176c0341432SJohn Baldwin.Pp 177c0341432SJohn Baldwin.Fn CRYPTODEV_FREESESSION 178c0341432SJohn Baldwinis invoked to release any driver-specific state when a session is 179c0341432SJohn Baldwindestroyed. 180c0341432SJohn BaldwinThe per-session driver-specific data structure is explicitly zeroed 181c0341432SJohn Baldwinand freed by the framework after this method returns. 182c0341432SJohn BaldwinIf a driver requires no additional tear-down steps, it can leave 183c0341432SJohn Baldwinthis method undefined. 184c0341432SJohn Baldwin.Pp 185c0341432SJohn BaldwinThis method should not sleep. 186c0341432SJohn Baldwin.Pp 187c0341432SJohn Baldwin.Fn CRYPTODEV_PROCESS 188c0341432SJohn Baldwinis invoked for each request submitted to an active session. 189c0341432SJohn BaldwinThis method can either complete a request synchronously or 190c0341432SJohn Baldwinschedule it to be completed asynchronously, 191c0341432SJohn Baldwinbut it must not sleep. 192c0341432SJohn Baldwin.Pp 193c0341432SJohn BaldwinIf this method is not able to complete a request due to insufficient 194c0341432SJohn Baldwinresources such as a full command queue, 195c0341432SJohn Baldwinit can defer the request by returning 196c0341432SJohn Baldwin.Dv ERESTART . 197c0341432SJohn BaldwinThe request will be queued by the framework and retried once the 198c0341432SJohn Baldwindriver releases pending requests via 199c0341432SJohn Baldwin.Fn crypto_unblock . 200c0341432SJohn BaldwinAny requests submitted to sessions belonging to the driver will also 201c0341432SJohn Baldwinbe queued until 202c0341432SJohn Baldwin.Fn crypto_unblock 203c0341432SJohn Baldwinis called. 204c0341432SJohn Baldwin.Pp 205c0341432SJohn BaldwinIf a driver encounters errors while processing a request, 206c0341432SJohn Baldwinit should report them via the 207c0341432SJohn Baldwin.Fa crp_etype 208c0341432SJohn Baldwinfield of 209c0341432SJohn Baldwin.Fa crp 210c0341432SJohn Baldwinrather than returning an error directly. 211c0341432SJohn Baldwin.Pp 212c0341432SJohn Baldwin.Fa flags 213c0341432SJohn Baldwinmay be set to 214c0341432SJohn Baldwin.Dv CRYPTO_HINT_MORE 215c0341432SJohn Baldwinif there are additional requests queued for this driver. 216c0341432SJohn BaldwinThe driver can use this as a hint to batch completion interrupts. 217c0341432SJohn BaldwinNote that these additional requests may be from different sessions. 218c0341432SJohn Baldwin.Pp 219c0341432SJohn Baldwin.Fn crypto_get_driver_session 220c0341432SJohn Baldwinreturns a pointer to the driver-specific per-session data structure 221c0341432SJohn Baldwinfor the session 222c0341432SJohn Baldwin.Fa crypto_session . 223c0341432SJohn BaldwinThis function can be used in the 224c0341432SJohn Baldwin.Fn CRYPTODEV_NEWSESSION , 225c0341432SJohn Baldwin.Fn CRYPTODEV_PROCESS , 226c0341432SJohn Baldwinand 227c0341432SJohn Baldwin.Fn CRYPTODEV_FREESESSION 228c0341432SJohn Baldwincallbacks. 229c0341432SJohn Baldwin.Pp 230c0341432SJohn Baldwin.Fn crypto_copydata 231c0341432SJohn Baldwincopies 232c0341432SJohn Baldwin.Fa size 2339c0e3d3aSJohn Baldwinbytes out of the input buffer for 234c0341432SJohn Baldwin.Fa crp 235c0341432SJohn Baldwininto a local buffer pointed to by 236c0341432SJohn Baldwin.Fa dst . 237c0341432SJohn BaldwinThe bytes are read starting at an offset of 238c0341432SJohn Baldwin.Fa off 2399c0e3d3aSJohn Baldwinbytes in the request's input buffer. 240c0341432SJohn Baldwin.Pp 241c0341432SJohn Baldwin.Fn crypto_copyback 242c0341432SJohn Baldwincopies 243c0341432SJohn Baldwin.Fa size 244c0341432SJohn Baldwinbytes from the local buffer pointed to by 245c0341432SJohn Baldwin.Fa src 2469c0e3d3aSJohn Baldwininto the output buffer for 247c0341432SJohn Baldwin.Fa crp . 248c0341432SJohn BaldwinThe bytes are written starting at an offset of 249c0341432SJohn Baldwin.Fa off 2509c0e3d3aSJohn Baldwinbytes in the request's output buffer. 251c0341432SJohn Baldwin.Pp 25229fe41ddSJohn Baldwin.Fn crypto_read_iv 25329fe41ddSJohn Baldwincopies the IV or nonce for 25429fe41ddSJohn Baldwin.Fa crp 2559c0e3d3aSJohn Baldwininto the local buffer pointed to by 25629fe41ddSJohn Baldwin.Fa iv . 25729fe41ddSJohn Baldwin.Pp 258c0341432SJohn BaldwinA driver calls 259c0341432SJohn Baldwin.Fn crypto_done 260c0341432SJohn Baldwinto mark the request 261c0341432SJohn Baldwin.Fa crp 262c0341432SJohn Baldwinas completed. 263c0341432SJohn BaldwinAny errors should be set in 264c0341432SJohn Baldwin.Fa crp_etype 265c0341432SJohn Baldwinprior to calling this function. 266c0341432SJohn Baldwin.Pp 267c0341432SJohn BaldwinIf a driver defers a request by returning 268c0341432SJohn Baldwin.Dv ERESTART 269c0341432SJohn Baldwinfrom 270c0341432SJohn Baldwin.Dv CRYPTO_PROCESS , 271c0341432SJohn Baldwinthe framework will queue all requests for the driver until the driver calls 272c0341432SJohn Baldwin.Fn crypto_unblock 273c0341432SJohn Baldwinto indicate that the temporary resource shortage has been relieved. 274c0341432SJohn BaldwinFor example, 275c0341432SJohn Baldwinif a driver returns 276c0341432SJohn Baldwin.Dv ERESTART 277c0341432SJohn Baldwindue to a full command ring, 278c0341432SJohn Baldwinit would invoke 279c0341432SJohn Baldwin.Fn crypto_unblock 280c0341432SJohn Baldwinfrom a command completion interrupt that makes a command ring entry available. 281c0341432SJohn Baldwin.Fa driverid 282c0341432SJohn Baldwinis the value returned by 283c0341432SJohn Baldwin.Fn crypto_get_driverid . 284c0341432SJohn Baldwin.Fa what 285c0341432SJohn Baldwinindicates which types of requests the driver is able to handle again: 286*76681661SJohn Baldwin.Bl -tag -width "CRYPTO_SYMQ" 287c0341432SJohn Baldwin.It Dv CRYPTO_SYMQ 288c0341432SJohn Baldwinindicates that the driver is able to handle symmetric requests passed to 289c0341432SJohn Baldwin.Fn CRYPTODEV_PROCESS . 290c0341432SJohn Baldwin.El 291c0341432SJohn Baldwin.Pp 292c0341432SJohn Baldwin.Fn hmac_init_ipad 293c0341432SJohn Baldwinprepares an authentication context to generate the inner hash of an HMAC. 294c0341432SJohn Baldwin.Fa axf 295c0341432SJohn Baldwinis a software implementation of an authentication algorithm such as the 296c0341432SJohn Baldwinvalue returned by 297c0341432SJohn Baldwin.Fn crypto_auth_hash . 298c0341432SJohn Baldwin.Fa key 299c0341432SJohn Baldwinis a pointer to a HMAC key of 300c0341432SJohn Baldwin.Fa klen 301c0341432SJohn Baldwinbytes. 302c0341432SJohn Baldwin.Fa auth_ctx 303c0341432SJohn Baldwinpoints to a valid authentication context for the desired algorithm. 304c0341432SJohn BaldwinThe function initializes the context with the supplied key. 305c0341432SJohn Baldwin.Pp 306c0341432SJohn Baldwin.Fn hmac_init_opad 307c0341432SJohn Baldwinis similar to 308c0341432SJohn Baldwin.Fn hmac_init_ipad 309c0341432SJohn Baldwinexcept that it prepares an authentication context to generate the 310c0341432SJohn Baldwinouter hash of an HMAC. 311c0341432SJohn Baldwin.Sh RETURN VALUES 312c0341432SJohn Baldwin.Fn crypto_apply 313c0341432SJohn Baldwinreturns the return value from the caller-supplied callback function. 314c0341432SJohn Baldwin.Pp 315c0341432SJohn Baldwin.Fn crypto_contiguous_subsegment 316c0341432SJohn Baldwinreturns a pointer to a contiguous segment or 317c0341432SJohn Baldwin.Dv NULL . 318c0341432SJohn Baldwin.Pp 319c0341432SJohn Baldwin.Fn crypto_get_driverid 320c0341432SJohn Baldwinreturns a driver identifier on success or -1 on error. 321c0341432SJohn Baldwin.Pp 322c0341432SJohn Baldwin.Fn crypto_unblock , 323c0341432SJohn Baldwin.Fn crypto_unregister_all , 324c0341432SJohn Baldwin.Fn CRYPTODEV_FREESESSION , 325c0341432SJohn Baldwin.Fn CRYPTODEV_NEWSESSION , 326c0341432SJohn Baldwinand 327c0341432SJohn Baldwin.Fn CRYPTODEV_PROCESS 328c0341432SJohn Baldwinreturn zero on success or an error on failure. 329c0341432SJohn Baldwin.Pp 330c0341432SJohn Baldwin.Fn CRYPTODEV_PROBESESSION 331c0341432SJohn Baldwinreturns a negative value on success or an error on failure. 332c0341432SJohn Baldwin.Sh SEE ALSO 333c0341432SJohn Baldwin.Xr crypto 7 , 334c0341432SJohn Baldwin.Xr crypto 9 , 3359c0e3d3aSJohn Baldwin.Xr crypto_buffer 9 , 336c0341432SJohn Baldwin.Xr crypto_request 9 , 337c0341432SJohn Baldwin.Xr crypto_session 9 338