xref: /freebsd/sys/contrib/openzfs/module/os/linux/zfs/qat_crypt.c (revision 61145dc2b94f12f6a47344fb9aac702321880e43)
1*61145dc2SMartin Matuska // SPDX-License-Identifier: CDDL-1.0
2eda14cbcSMatt Macy /*
3eda14cbcSMatt Macy  * CDDL HEADER START
4eda14cbcSMatt Macy  *
5eda14cbcSMatt Macy  * The contents of this file are subject to the terms of the
6eda14cbcSMatt Macy  * Common Development and Distribution License (the "License").
7eda14cbcSMatt Macy  * You may not use this file except in compliance with the License.
8eda14cbcSMatt Macy  *
9eda14cbcSMatt Macy  * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
10271171e0SMartin Matuska  * or https://opensource.org/licenses/CDDL-1.0.
11eda14cbcSMatt Macy  * See the License for the specific language governing permissions
12eda14cbcSMatt Macy  * and limitations under the License.
13eda14cbcSMatt Macy  *
14eda14cbcSMatt Macy  * When distributing Covered Code, include this CDDL HEADER in each
15eda14cbcSMatt Macy  * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
16eda14cbcSMatt Macy  * If applicable, add the following below this CDDL HEADER, with the
17eda14cbcSMatt Macy  * fields enclosed by brackets "[]" replaced with your own identifying
18eda14cbcSMatt Macy  * information: Portions Copyright [yyyy] [name of copyright owner]
19eda14cbcSMatt Macy  *
20eda14cbcSMatt Macy  * CDDL HEADER END
21eda14cbcSMatt Macy  */
22eda14cbcSMatt Macy 
23eda14cbcSMatt Macy /*
24eda14cbcSMatt Macy  * This file represents the QAT implementation of checksums and encryption.
25eda14cbcSMatt Macy  * Internally, QAT shares the same cryptographic instances for both of these
26eda14cbcSMatt Macy  * operations, so the code has been combined here. QAT data compression uses
27eda14cbcSMatt Macy  * compression instances, so that code is separated into qat_compress.c
28eda14cbcSMatt Macy  */
29eda14cbcSMatt Macy 
30eda14cbcSMatt Macy #if defined(_KERNEL) && defined(HAVE_QAT)
31eda14cbcSMatt Macy #include <linux/slab.h>
32eda14cbcSMatt Macy #include <linux/vmalloc.h>
33eda14cbcSMatt Macy #include <linux/pagemap.h>
34eda14cbcSMatt Macy #include <linux/completion.h>
35eda14cbcSMatt Macy #include <sys/zfs_context.h>
36eda14cbcSMatt Macy #include <sys/zio_crypt.h>
37eda14cbcSMatt Macy #include "lac/cpa_cy_im.h"
38eda14cbcSMatt Macy #include "lac/cpa_cy_common.h"
39eda14cbcSMatt Macy #include <sys/qat.h>
40eda14cbcSMatt Macy 
41eda14cbcSMatt Macy /*
42eda14cbcSMatt Macy  * Max instances in a QAT device, each instance is a channel to submit
43eda14cbcSMatt Macy  * jobs to QAT hardware, this is only for pre-allocating instances
44eda14cbcSMatt Macy  * and session arrays; the actual number of instances are defined in
45eda14cbcSMatt Macy  * the QAT driver's configure file.
46eda14cbcSMatt Macy  */
47eda14cbcSMatt Macy #define	QAT_CRYPT_MAX_INSTANCES		48
48eda14cbcSMatt Macy 
49eda14cbcSMatt Macy #define	MAX_PAGE_NUM			1024
50eda14cbcSMatt Macy 
51eda14cbcSMatt Macy static Cpa32U inst_num = 0;
52eda14cbcSMatt Macy static Cpa16U num_inst = 0;
53eda14cbcSMatt Macy static CpaInstanceHandle cy_inst_handles[QAT_CRYPT_MAX_INSTANCES];
54eda14cbcSMatt Macy static boolean_t qat_cy_init_done = B_FALSE;
55eda14cbcSMatt Macy int zfs_qat_encrypt_disable = 0;
56eda14cbcSMatt Macy int zfs_qat_checksum_disable = 0;
57eda14cbcSMatt Macy 
58eda14cbcSMatt Macy typedef struct cy_callback {
59eda14cbcSMatt Macy 	CpaBoolean verify_result;
60eda14cbcSMatt Macy 	struct completion complete;
61eda14cbcSMatt Macy } cy_callback_t;
62eda14cbcSMatt Macy 
63eda14cbcSMatt Macy static void
symcallback(void * p_callback,CpaStatus status,const CpaCySymOp operation,void * op_data,CpaBufferList * buf_list_dst,CpaBoolean verify)64eda14cbcSMatt Macy symcallback(void *p_callback, CpaStatus status, const CpaCySymOp operation,
65eda14cbcSMatt Macy     void *op_data, CpaBufferList *buf_list_dst, CpaBoolean verify)
66eda14cbcSMatt Macy {
67eda14cbcSMatt Macy 	cy_callback_t *cb = p_callback;
68eda14cbcSMatt Macy 
69eda14cbcSMatt Macy 	if (cb != NULL) {
70eda14cbcSMatt Macy 		/* indicate that the function has been called */
71eda14cbcSMatt Macy 		cb->verify_result = verify;
72eda14cbcSMatt Macy 		complete(&cb->complete);
73eda14cbcSMatt Macy 	}
74eda14cbcSMatt Macy }
75eda14cbcSMatt Macy 
76eda14cbcSMatt Macy boolean_t
qat_crypt_use_accel(size_t s_len)77eda14cbcSMatt Macy qat_crypt_use_accel(size_t s_len)
78eda14cbcSMatt Macy {
79eda14cbcSMatt Macy 	return (!zfs_qat_encrypt_disable &&
80eda14cbcSMatt Macy 	    qat_cy_init_done &&
81eda14cbcSMatt Macy 	    s_len >= QAT_MIN_BUF_SIZE &&
82eda14cbcSMatt Macy 	    s_len <= QAT_MAX_BUF_SIZE);
83eda14cbcSMatt Macy }
84eda14cbcSMatt Macy 
85eda14cbcSMatt Macy boolean_t
qat_checksum_use_accel(size_t s_len)86eda14cbcSMatt Macy qat_checksum_use_accel(size_t s_len)
87eda14cbcSMatt Macy {
88eda14cbcSMatt Macy 	return (!zfs_qat_checksum_disable &&
89eda14cbcSMatt Macy 	    qat_cy_init_done &&
90eda14cbcSMatt Macy 	    s_len >= QAT_MIN_BUF_SIZE &&
91eda14cbcSMatt Macy 	    s_len <= QAT_MAX_BUF_SIZE);
92eda14cbcSMatt Macy }
93eda14cbcSMatt Macy 
94eda14cbcSMatt Macy void
qat_cy_clean(void)95eda14cbcSMatt Macy qat_cy_clean(void)
96eda14cbcSMatt Macy {
97eda14cbcSMatt Macy 	for (Cpa16U i = 0; i < num_inst; i++)
98eda14cbcSMatt Macy 		cpaCyStopInstance(cy_inst_handles[i]);
99eda14cbcSMatt Macy 
100eda14cbcSMatt Macy 	num_inst = 0;
101eda14cbcSMatt Macy 	qat_cy_init_done = B_FALSE;
102eda14cbcSMatt Macy }
103eda14cbcSMatt Macy 
104eda14cbcSMatt Macy int
qat_cy_init(void)105eda14cbcSMatt Macy qat_cy_init(void)
106eda14cbcSMatt Macy {
107eda14cbcSMatt Macy 	CpaStatus status = CPA_STATUS_FAIL;
108eda14cbcSMatt Macy 
109eda14cbcSMatt Macy 	if (qat_cy_init_done)
110eda14cbcSMatt Macy 		return (0);
111eda14cbcSMatt Macy 
112eda14cbcSMatt Macy 	status = cpaCyGetNumInstances(&num_inst);
113eda14cbcSMatt Macy 	if (status != CPA_STATUS_SUCCESS)
114eda14cbcSMatt Macy 		return (-1);
115eda14cbcSMatt Macy 
116eda14cbcSMatt Macy 	/* if the user has configured no QAT encryption units just return */
117eda14cbcSMatt Macy 	if (num_inst == 0)
118eda14cbcSMatt Macy 		return (0);
119eda14cbcSMatt Macy 
120eda14cbcSMatt Macy 	if (num_inst > QAT_CRYPT_MAX_INSTANCES)
121eda14cbcSMatt Macy 		num_inst = QAT_CRYPT_MAX_INSTANCES;
122eda14cbcSMatt Macy 
123eda14cbcSMatt Macy 	status = cpaCyGetInstances(num_inst, &cy_inst_handles[0]);
124eda14cbcSMatt Macy 	if (status != CPA_STATUS_SUCCESS)
125eda14cbcSMatt Macy 		return (-1);
126eda14cbcSMatt Macy 
127eda14cbcSMatt Macy 	for (Cpa16U i = 0; i < num_inst; i++) {
128eda14cbcSMatt Macy 		status = cpaCySetAddressTranslation(cy_inst_handles[i],
129eda14cbcSMatt Macy 		    (void *)virt_to_phys);
130eda14cbcSMatt Macy 		if (status != CPA_STATUS_SUCCESS)
131eda14cbcSMatt Macy 			goto error;
132eda14cbcSMatt Macy 
133eda14cbcSMatt Macy 		status = cpaCyStartInstance(cy_inst_handles[i]);
134eda14cbcSMatt Macy 		if (status != CPA_STATUS_SUCCESS)
135eda14cbcSMatt Macy 			goto error;
136eda14cbcSMatt Macy 	}
137eda14cbcSMatt Macy 
138eda14cbcSMatt Macy 	qat_cy_init_done = B_TRUE;
139eda14cbcSMatt Macy 	return (0);
140eda14cbcSMatt Macy 
141eda14cbcSMatt Macy error:
142eda14cbcSMatt Macy 	qat_cy_clean();
143eda14cbcSMatt Macy 	return (-1);
144eda14cbcSMatt Macy }
145eda14cbcSMatt Macy 
146eda14cbcSMatt Macy void
qat_cy_fini(void)147eda14cbcSMatt Macy qat_cy_fini(void)
148eda14cbcSMatt Macy {
149eda14cbcSMatt Macy 	if (!qat_cy_init_done)
150eda14cbcSMatt Macy 		return;
151eda14cbcSMatt Macy 
152eda14cbcSMatt Macy 	qat_cy_clean();
153eda14cbcSMatt Macy }
154eda14cbcSMatt Macy 
155eda14cbcSMatt Macy static CpaStatus
qat_init_crypt_session_ctx(qat_encrypt_dir_t dir,CpaInstanceHandle inst_handle,CpaCySymSessionCtx ** cy_session_ctx,crypto_key_t * key,Cpa64U crypt,Cpa32U aad_len)156eda14cbcSMatt Macy qat_init_crypt_session_ctx(qat_encrypt_dir_t dir, CpaInstanceHandle inst_handle,
157eda14cbcSMatt Macy     CpaCySymSessionCtx **cy_session_ctx, crypto_key_t *key,
158eda14cbcSMatt Macy     Cpa64U crypt, Cpa32U aad_len)
159eda14cbcSMatt Macy {
160eda14cbcSMatt Macy 	CpaStatus status = CPA_STATUS_SUCCESS;
161eda14cbcSMatt Macy 	Cpa32U ctx_size;
162eda14cbcSMatt Macy 	Cpa32U ciper_algorithm;
163eda14cbcSMatt Macy 	Cpa32U hash_algorithm;
164eda14cbcSMatt Macy 	CpaCySymSessionSetupData sd = { 0 };
165eda14cbcSMatt Macy 
166eda14cbcSMatt Macy 	if (zio_crypt_table[crypt].ci_crypt_type == ZC_TYPE_CCM) {
167eda14cbcSMatt Macy 		return (CPA_STATUS_FAIL);
168eda14cbcSMatt Macy 	} else {
169eda14cbcSMatt Macy 		ciper_algorithm = CPA_CY_SYM_CIPHER_AES_GCM;
170eda14cbcSMatt Macy 		hash_algorithm = CPA_CY_SYM_HASH_AES_GCM;
171eda14cbcSMatt Macy 	}
172eda14cbcSMatt Macy 
173eda14cbcSMatt Macy 	sd.cipherSetupData.cipherAlgorithm = ciper_algorithm;
174eda14cbcSMatt Macy 	sd.cipherSetupData.pCipherKey = key->ck_data;
175eda14cbcSMatt Macy 	sd.cipherSetupData.cipherKeyLenInBytes = key->ck_length / 8;
176eda14cbcSMatt Macy 	sd.hashSetupData.hashAlgorithm = hash_algorithm;
177eda14cbcSMatt Macy 	sd.hashSetupData.hashMode = CPA_CY_SYM_HASH_MODE_AUTH;
178eda14cbcSMatt Macy 	sd.hashSetupData.digestResultLenInBytes = ZIO_DATA_MAC_LEN;
179eda14cbcSMatt Macy 	sd.hashSetupData.authModeSetupData.aadLenInBytes = aad_len;
180eda14cbcSMatt Macy 	sd.sessionPriority = CPA_CY_PRIORITY_NORMAL;
181eda14cbcSMatt Macy 	sd.symOperation = CPA_CY_SYM_OP_ALGORITHM_CHAINING;
182eda14cbcSMatt Macy 	sd.digestIsAppended = CPA_FALSE;
183eda14cbcSMatt Macy 	sd.verifyDigest = CPA_FALSE;
184eda14cbcSMatt Macy 
185eda14cbcSMatt Macy 	if (dir == QAT_ENCRYPT) {
186eda14cbcSMatt Macy 		sd.cipherSetupData.cipherDirection =
187eda14cbcSMatt Macy 		    CPA_CY_SYM_CIPHER_DIRECTION_ENCRYPT;
188eda14cbcSMatt Macy 		sd.algChainOrder =
189eda14cbcSMatt Macy 		    CPA_CY_SYM_ALG_CHAIN_ORDER_HASH_THEN_CIPHER;
190eda14cbcSMatt Macy 	} else {
191eda14cbcSMatt Macy 		ASSERT3U(dir, ==, QAT_DECRYPT);
192eda14cbcSMatt Macy 		sd.cipherSetupData.cipherDirection =
193eda14cbcSMatt Macy 		    CPA_CY_SYM_CIPHER_DIRECTION_DECRYPT;
194eda14cbcSMatt Macy 		sd.algChainOrder =
195eda14cbcSMatt Macy 		    CPA_CY_SYM_ALG_CHAIN_ORDER_CIPHER_THEN_HASH;
196eda14cbcSMatt Macy 	}
197eda14cbcSMatt Macy 
198eda14cbcSMatt Macy 	status = cpaCySymSessionCtxGetSize(inst_handle, &sd, &ctx_size);
199eda14cbcSMatt Macy 	if (status != CPA_STATUS_SUCCESS)
200eda14cbcSMatt Macy 		return (status);
201eda14cbcSMatt Macy 
202eda14cbcSMatt Macy 	status = QAT_PHYS_CONTIG_ALLOC(cy_session_ctx, ctx_size);
203eda14cbcSMatt Macy 	if (status != CPA_STATUS_SUCCESS)
204eda14cbcSMatt Macy 		return (status);
205eda14cbcSMatt Macy 
206eda14cbcSMatt Macy 	status = cpaCySymInitSession(inst_handle, symcallback, &sd,
207eda14cbcSMatt Macy 	    *cy_session_ctx);
208eda14cbcSMatt Macy 	if (status != CPA_STATUS_SUCCESS) {
209eda14cbcSMatt Macy 		QAT_PHYS_CONTIG_FREE(*cy_session_ctx);
210eda14cbcSMatt Macy 		return (status);
211eda14cbcSMatt Macy 	}
212eda14cbcSMatt Macy 
213eda14cbcSMatt Macy 	return (CPA_STATUS_SUCCESS);
214eda14cbcSMatt Macy }
215eda14cbcSMatt Macy 
216eda14cbcSMatt Macy static CpaStatus
qat_init_checksum_session_ctx(CpaInstanceHandle inst_handle,CpaCySymSessionCtx ** cy_session_ctx,Cpa64U cksum)217eda14cbcSMatt Macy qat_init_checksum_session_ctx(CpaInstanceHandle inst_handle,
218eda14cbcSMatt Macy     CpaCySymSessionCtx **cy_session_ctx, Cpa64U cksum)
219eda14cbcSMatt Macy {
220eda14cbcSMatt Macy 	CpaStatus status = CPA_STATUS_SUCCESS;
221eda14cbcSMatt Macy 	Cpa32U ctx_size;
222eda14cbcSMatt Macy 	Cpa32U hash_algorithm;
223eda14cbcSMatt Macy 	CpaCySymSessionSetupData sd = { 0 };
224eda14cbcSMatt Macy 
225eda14cbcSMatt Macy 	/*
226eda14cbcSMatt Macy 	 * ZFS's SHA512 checksum is actually SHA512/256, which uses
227eda14cbcSMatt Macy 	 * a different IV from standard SHA512. QAT does not support
228eda14cbcSMatt Macy 	 * SHA512/256, so we can only support SHA256.
229eda14cbcSMatt Macy 	 */
230eda14cbcSMatt Macy 	if (cksum == ZIO_CHECKSUM_SHA256)
231eda14cbcSMatt Macy 		hash_algorithm = CPA_CY_SYM_HASH_SHA256;
232eda14cbcSMatt Macy 	else
233eda14cbcSMatt Macy 		return (CPA_STATUS_FAIL);
234eda14cbcSMatt Macy 
235eda14cbcSMatt Macy 	sd.sessionPriority = CPA_CY_PRIORITY_NORMAL;
236eda14cbcSMatt Macy 	sd.symOperation = CPA_CY_SYM_OP_HASH;
237eda14cbcSMatt Macy 	sd.hashSetupData.hashAlgorithm = hash_algorithm;
238eda14cbcSMatt Macy 	sd.hashSetupData.hashMode = CPA_CY_SYM_HASH_MODE_PLAIN;
239eda14cbcSMatt Macy 	sd.hashSetupData.digestResultLenInBytes = sizeof (zio_cksum_t);
240eda14cbcSMatt Macy 	sd.digestIsAppended = CPA_FALSE;
241eda14cbcSMatt Macy 	sd.verifyDigest = CPA_FALSE;
242eda14cbcSMatt Macy 
243eda14cbcSMatt Macy 	status = cpaCySymSessionCtxGetSize(inst_handle, &sd, &ctx_size);
244eda14cbcSMatt Macy 	if (status != CPA_STATUS_SUCCESS)
245eda14cbcSMatt Macy 		return (status);
246eda14cbcSMatt Macy 
247eda14cbcSMatt Macy 	status = QAT_PHYS_CONTIG_ALLOC(cy_session_ctx, ctx_size);
248eda14cbcSMatt Macy 	if (status != CPA_STATUS_SUCCESS)
249eda14cbcSMatt Macy 		return (status);
250eda14cbcSMatt Macy 
251eda14cbcSMatt Macy 	status = cpaCySymInitSession(inst_handle, symcallback, &sd,
252eda14cbcSMatt Macy 	    *cy_session_ctx);
253eda14cbcSMatt Macy 	if (status != CPA_STATUS_SUCCESS) {
254eda14cbcSMatt Macy 		QAT_PHYS_CONTIG_FREE(*cy_session_ctx);
255eda14cbcSMatt Macy 		return (status);
256eda14cbcSMatt Macy 	}
257eda14cbcSMatt Macy 
258eda14cbcSMatt Macy 	return (CPA_STATUS_SUCCESS);
259eda14cbcSMatt Macy }
260eda14cbcSMatt Macy 
261eda14cbcSMatt Macy static CpaStatus
qat_init_cy_buffer_lists(CpaInstanceHandle inst_handle,uint32_t nr_bufs,CpaBufferList * src,CpaBufferList * dst)262eda14cbcSMatt Macy qat_init_cy_buffer_lists(CpaInstanceHandle inst_handle, uint32_t nr_bufs,
263eda14cbcSMatt Macy     CpaBufferList *src, CpaBufferList *dst)
264eda14cbcSMatt Macy {
265eda14cbcSMatt Macy 	CpaStatus status = CPA_STATUS_SUCCESS;
266eda14cbcSMatt Macy 	Cpa32U meta_size = 0;
267eda14cbcSMatt Macy 
268eda14cbcSMatt Macy 	status = cpaCyBufferListGetMetaSize(inst_handle, nr_bufs, &meta_size);
269eda14cbcSMatt Macy 	if (status != CPA_STATUS_SUCCESS)
270eda14cbcSMatt Macy 		return (status);
271eda14cbcSMatt Macy 
272eda14cbcSMatt Macy 	status = QAT_PHYS_CONTIG_ALLOC(&src->pPrivateMetaData, meta_size);
273eda14cbcSMatt Macy 	if (status != CPA_STATUS_SUCCESS)
274eda14cbcSMatt Macy 		goto error;
275eda14cbcSMatt Macy 
276eda14cbcSMatt Macy 	if (src != dst) {
277eda14cbcSMatt Macy 		status = QAT_PHYS_CONTIG_ALLOC(&dst->pPrivateMetaData,
278eda14cbcSMatt Macy 		    meta_size);
279eda14cbcSMatt Macy 		if (status != CPA_STATUS_SUCCESS)
280eda14cbcSMatt Macy 			goto error;
281eda14cbcSMatt Macy 	}
282eda14cbcSMatt Macy 
283eda14cbcSMatt Macy 	return (CPA_STATUS_SUCCESS);
284eda14cbcSMatt Macy 
285eda14cbcSMatt Macy error:
286eda14cbcSMatt Macy 	QAT_PHYS_CONTIG_FREE(src->pPrivateMetaData);
287eda14cbcSMatt Macy 	if (src != dst)
288eda14cbcSMatt Macy 		QAT_PHYS_CONTIG_FREE(dst->pPrivateMetaData);
289eda14cbcSMatt Macy 
290eda14cbcSMatt Macy 	return (status);
291eda14cbcSMatt Macy }
292eda14cbcSMatt Macy 
293eda14cbcSMatt Macy int
qat_crypt(qat_encrypt_dir_t dir,uint8_t * src_buf,uint8_t * dst_buf,uint8_t * aad_buf,uint32_t aad_len,uint8_t * iv_buf,uint8_t * digest_buf,crypto_key_t * key,uint64_t crypt,uint32_t enc_len)294eda14cbcSMatt Macy qat_crypt(qat_encrypt_dir_t dir, uint8_t *src_buf, uint8_t *dst_buf,
295eda14cbcSMatt Macy     uint8_t *aad_buf, uint32_t aad_len, uint8_t *iv_buf, uint8_t *digest_buf,
296eda14cbcSMatt Macy     crypto_key_t *key, uint64_t crypt, uint32_t enc_len)
297eda14cbcSMatt Macy {
298eda14cbcSMatt Macy 	CpaStatus status = CPA_STATUS_SUCCESS;
299eda14cbcSMatt Macy 	Cpa16U i;
300eda14cbcSMatt Macy 	CpaInstanceHandle cy_inst_handle;
301eda14cbcSMatt Macy 	Cpa16U nr_bufs = (enc_len >> PAGE_SHIFT) + 2;
302eda14cbcSMatt Macy 	Cpa32U bytes_left = 0;
303eda14cbcSMatt Macy 	Cpa8S *data = NULL;
304eda14cbcSMatt Macy 	CpaCySymSessionCtx *cy_session_ctx = NULL;
305eda14cbcSMatt Macy 	cy_callback_t cb;
306eda14cbcSMatt Macy 	CpaCySymOpData op_data = { 0 };
307eda14cbcSMatt Macy 	CpaBufferList src_buffer_list = { 0 };
308eda14cbcSMatt Macy 	CpaBufferList dst_buffer_list = { 0 };
309eda14cbcSMatt Macy 	CpaFlatBuffer *flat_src_buf_array = NULL;
310eda14cbcSMatt Macy 	CpaFlatBuffer *flat_src_buf = NULL;
311eda14cbcSMatt Macy 	CpaFlatBuffer *flat_dst_buf_array = NULL;
312eda14cbcSMatt Macy 	CpaFlatBuffer *flat_dst_buf = NULL;
313eda14cbcSMatt Macy 	struct page *in_pages[MAX_PAGE_NUM];
314eda14cbcSMatt Macy 	struct page *out_pages[MAX_PAGE_NUM];
315eda14cbcSMatt Macy 	Cpa32U in_page_num = 0;
316eda14cbcSMatt Macy 	Cpa32U out_page_num = 0;
317eda14cbcSMatt Macy 	Cpa32U in_page_off = 0;
318eda14cbcSMatt Macy 	Cpa32U out_page_off = 0;
319eda14cbcSMatt Macy 
320eda14cbcSMatt Macy 	if (dir == QAT_ENCRYPT) {
321eda14cbcSMatt Macy 		QAT_STAT_BUMP(encrypt_requests);
322eda14cbcSMatt Macy 		QAT_STAT_INCR(encrypt_total_in_bytes, enc_len);
323eda14cbcSMatt Macy 	} else {
324eda14cbcSMatt Macy 		QAT_STAT_BUMP(decrypt_requests);
325eda14cbcSMatt Macy 		QAT_STAT_INCR(decrypt_total_in_bytes, enc_len);
326eda14cbcSMatt Macy 	}
327eda14cbcSMatt Macy 
328eda14cbcSMatt Macy 	i = (Cpa32U)atomic_inc_32_nv(&inst_num) % num_inst;
329eda14cbcSMatt Macy 	cy_inst_handle = cy_inst_handles[i];
330eda14cbcSMatt Macy 
331eda14cbcSMatt Macy 	status = qat_init_crypt_session_ctx(dir, cy_inst_handle,
332eda14cbcSMatt Macy 	    &cy_session_ctx, key, crypt, aad_len);
333eda14cbcSMatt Macy 	if (status != CPA_STATUS_SUCCESS) {
334eda14cbcSMatt Macy 		/* don't count CCM as a failure since it's not supported */
335eda14cbcSMatt Macy 		if (zio_crypt_table[crypt].ci_crypt_type == ZC_TYPE_GCM)
336eda14cbcSMatt Macy 			QAT_STAT_BUMP(crypt_fails);
337eda14cbcSMatt Macy 		return (status);
338eda14cbcSMatt Macy 	}
339eda14cbcSMatt Macy 
340eda14cbcSMatt Macy 	/*
341eda14cbcSMatt Macy 	 * We increment nr_bufs by 2 to allow us to handle non
342eda14cbcSMatt Macy 	 * page-aligned buffer addresses and buffers whose sizes
343eda14cbcSMatt Macy 	 * are not divisible by PAGE_SIZE.
344eda14cbcSMatt Macy 	 */
345eda14cbcSMatt Macy 	status = qat_init_cy_buffer_lists(cy_inst_handle, nr_bufs,
346eda14cbcSMatt Macy 	    &src_buffer_list, &dst_buffer_list);
347eda14cbcSMatt Macy 	if (status != CPA_STATUS_SUCCESS)
348eda14cbcSMatt Macy 		goto fail;
349eda14cbcSMatt Macy 
350eda14cbcSMatt Macy 	status = QAT_PHYS_CONTIG_ALLOC(&flat_src_buf_array,
351eda14cbcSMatt Macy 	    nr_bufs * sizeof (CpaFlatBuffer));
352eda14cbcSMatt Macy 	if (status != CPA_STATUS_SUCCESS)
353eda14cbcSMatt Macy 		goto fail;
354eda14cbcSMatt Macy 	status = QAT_PHYS_CONTIG_ALLOC(&flat_dst_buf_array,
355eda14cbcSMatt Macy 	    nr_bufs * sizeof (CpaFlatBuffer));
356eda14cbcSMatt Macy 	if (status != CPA_STATUS_SUCCESS)
357eda14cbcSMatt Macy 		goto fail;
358eda14cbcSMatt Macy 	status = QAT_PHYS_CONTIG_ALLOC(&op_data.pDigestResult,
359eda14cbcSMatt Macy 	    ZIO_DATA_MAC_LEN);
360eda14cbcSMatt Macy 	if (status != CPA_STATUS_SUCCESS)
361eda14cbcSMatt Macy 		goto fail;
362eda14cbcSMatt Macy 	status = QAT_PHYS_CONTIG_ALLOC(&op_data.pIv,
363eda14cbcSMatt Macy 	    ZIO_DATA_IV_LEN);
364eda14cbcSMatt Macy 	if (status != CPA_STATUS_SUCCESS)
365eda14cbcSMatt Macy 		goto fail;
366eda14cbcSMatt Macy 	if (aad_len > 0) {
367eda14cbcSMatt Macy 		status = QAT_PHYS_CONTIG_ALLOC(&op_data.pAdditionalAuthData,
368eda14cbcSMatt Macy 		    aad_len);
369eda14cbcSMatt Macy 		if (status != CPA_STATUS_SUCCESS)
370eda14cbcSMatt Macy 			goto fail;
371da5137abSMartin Matuska 		memcpy(op_data.pAdditionalAuthData, aad_buf, aad_len);
372eda14cbcSMatt Macy 	}
373eda14cbcSMatt Macy 
374eda14cbcSMatt Macy 	bytes_left = enc_len;
375eda14cbcSMatt Macy 	data = src_buf;
376eda14cbcSMatt Macy 	flat_src_buf = flat_src_buf_array;
377eda14cbcSMatt Macy 	while (bytes_left > 0) {
378eda14cbcSMatt Macy 		in_page_off = ((long)data & ~PAGE_MASK);
379eda14cbcSMatt Macy 		in_pages[in_page_num] = qat_mem_to_page(data);
380eda14cbcSMatt Macy 		flat_src_buf->pData = kmap(in_pages[in_page_num]) + in_page_off;
381eda14cbcSMatt Macy 		flat_src_buf->dataLenInBytes =
382eda14cbcSMatt Macy 		    min((long)PAGE_SIZE - in_page_off, (long)bytes_left);
383eda14cbcSMatt Macy 		data += flat_src_buf->dataLenInBytes;
384eda14cbcSMatt Macy 		bytes_left -= flat_src_buf->dataLenInBytes;
385eda14cbcSMatt Macy 		flat_src_buf++;
386eda14cbcSMatt Macy 		in_page_num++;
387eda14cbcSMatt Macy 	}
388eda14cbcSMatt Macy 	src_buffer_list.pBuffers = flat_src_buf_array;
389eda14cbcSMatt Macy 	src_buffer_list.numBuffers = in_page_num;
390eda14cbcSMatt Macy 
391eda14cbcSMatt Macy 	bytes_left = enc_len;
392eda14cbcSMatt Macy 	data = dst_buf;
393eda14cbcSMatt Macy 	flat_dst_buf = flat_dst_buf_array;
394eda14cbcSMatt Macy 	while (bytes_left > 0) {
395eda14cbcSMatt Macy 		out_page_off = ((long)data & ~PAGE_MASK);
396eda14cbcSMatt Macy 		out_pages[out_page_num] = qat_mem_to_page(data);
397eda14cbcSMatt Macy 		flat_dst_buf->pData = kmap(out_pages[out_page_num]) +
398eda14cbcSMatt Macy 		    out_page_off;
399eda14cbcSMatt Macy 		flat_dst_buf->dataLenInBytes =
400eda14cbcSMatt Macy 		    min((long)PAGE_SIZE - out_page_off, (long)bytes_left);
401eda14cbcSMatt Macy 		data += flat_dst_buf->dataLenInBytes;
402eda14cbcSMatt Macy 		bytes_left -= flat_dst_buf->dataLenInBytes;
403eda14cbcSMatt Macy 		flat_dst_buf++;
404eda14cbcSMatt Macy 		out_page_num++;
405eda14cbcSMatt Macy 	}
406eda14cbcSMatt Macy 	dst_buffer_list.pBuffers = flat_dst_buf_array;
407eda14cbcSMatt Macy 	dst_buffer_list.numBuffers = out_page_num;
408eda14cbcSMatt Macy 
409eda14cbcSMatt Macy 	op_data.sessionCtx = cy_session_ctx;
410eda14cbcSMatt Macy 	op_data.packetType = CPA_CY_SYM_PACKET_TYPE_FULL;
411eda14cbcSMatt Macy 	op_data.cryptoStartSrcOffsetInBytes = 0;
412eda14cbcSMatt Macy 	op_data.messageLenToCipherInBytes = 0;
413eda14cbcSMatt Macy 	op_data.hashStartSrcOffsetInBytes = 0;
414eda14cbcSMatt Macy 	op_data.messageLenToHashInBytes = 0;
415eda14cbcSMatt Macy 	op_data.messageLenToCipherInBytes = enc_len;
416eda14cbcSMatt Macy 	op_data.ivLenInBytes = ZIO_DATA_IV_LEN;
417da5137abSMartin Matuska 	memcpy(op_data.pIv, iv_buf, ZIO_DATA_IV_LEN);
418eda14cbcSMatt Macy 	/* if dir is QAT_DECRYPT, copy digest_buf to pDigestResult */
419eda14cbcSMatt Macy 	if (dir == QAT_DECRYPT)
420da5137abSMartin Matuska 		memcpy(op_data.pDigestResult, digest_buf, ZIO_DATA_MAC_LEN);
421eda14cbcSMatt Macy 
422eda14cbcSMatt Macy 	cb.verify_result = CPA_FALSE;
423eda14cbcSMatt Macy 	init_completion(&cb.complete);
424eda14cbcSMatt Macy 	status = cpaCySymPerformOp(cy_inst_handle, &cb, &op_data,
425eda14cbcSMatt Macy 	    &src_buffer_list, &dst_buffer_list, NULL);
426eda14cbcSMatt Macy 	if (status != CPA_STATUS_SUCCESS)
427eda14cbcSMatt Macy 		goto fail;
428eda14cbcSMatt Macy 
429eda14cbcSMatt Macy 	/* we now wait until the completion of the operation. */
430eda14cbcSMatt Macy 	wait_for_completion(&cb.complete);
431eda14cbcSMatt Macy 
432eda14cbcSMatt Macy 	if (cb.verify_result == CPA_FALSE) {
433eda14cbcSMatt Macy 		status = CPA_STATUS_FAIL;
434eda14cbcSMatt Macy 		goto fail;
435eda14cbcSMatt Macy 	}
436eda14cbcSMatt Macy 
437eda14cbcSMatt Macy 	if (dir == QAT_ENCRYPT) {
438eda14cbcSMatt Macy 		/* if dir is QAT_ENCRYPT, save pDigestResult to digest_buf */
439da5137abSMartin Matuska 		memcpy(digest_buf, op_data.pDigestResult, ZIO_DATA_MAC_LEN);
440eda14cbcSMatt Macy 		QAT_STAT_INCR(encrypt_total_out_bytes, enc_len);
441eda14cbcSMatt Macy 	} else {
442eda14cbcSMatt Macy 		QAT_STAT_INCR(decrypt_total_out_bytes, enc_len);
443eda14cbcSMatt Macy 	}
444eda14cbcSMatt Macy 
445eda14cbcSMatt Macy fail:
446eda14cbcSMatt Macy 	if (status != CPA_STATUS_SUCCESS)
447eda14cbcSMatt Macy 		QAT_STAT_BUMP(crypt_fails);
448eda14cbcSMatt Macy 
449eda14cbcSMatt Macy 	for (i = 0; i < in_page_num; i++)
450eda14cbcSMatt Macy 		kunmap(in_pages[i]);
451eda14cbcSMatt Macy 	for (i = 0; i < out_page_num; i++)
452eda14cbcSMatt Macy 		kunmap(out_pages[i]);
453eda14cbcSMatt Macy 
454eda14cbcSMatt Macy 	cpaCySymRemoveSession(cy_inst_handle, cy_session_ctx);
455eda14cbcSMatt Macy 	if (aad_len > 0)
456eda14cbcSMatt Macy 		QAT_PHYS_CONTIG_FREE(op_data.pAdditionalAuthData);
457eda14cbcSMatt Macy 	QAT_PHYS_CONTIG_FREE(op_data.pIv);
458eda14cbcSMatt Macy 	QAT_PHYS_CONTIG_FREE(op_data.pDigestResult);
459eda14cbcSMatt Macy 	QAT_PHYS_CONTIG_FREE(src_buffer_list.pPrivateMetaData);
460eda14cbcSMatt Macy 	QAT_PHYS_CONTIG_FREE(dst_buffer_list.pPrivateMetaData);
461eda14cbcSMatt Macy 	QAT_PHYS_CONTIG_FREE(cy_session_ctx);
462eda14cbcSMatt Macy 	QAT_PHYS_CONTIG_FREE(flat_src_buf_array);
463eda14cbcSMatt Macy 	QAT_PHYS_CONTIG_FREE(flat_dst_buf_array);
464eda14cbcSMatt Macy 
465eda14cbcSMatt Macy 	return (status);
466eda14cbcSMatt Macy }
467eda14cbcSMatt Macy 
468eda14cbcSMatt Macy int
qat_checksum(uint64_t cksum,uint8_t * buf,uint64_t size,zio_cksum_t * zcp)469eda14cbcSMatt Macy qat_checksum(uint64_t cksum, uint8_t *buf, uint64_t size, zio_cksum_t *zcp)
470eda14cbcSMatt Macy {
471eda14cbcSMatt Macy 	CpaStatus status;
472eda14cbcSMatt Macy 	Cpa16U i;
473eda14cbcSMatt Macy 	CpaInstanceHandle cy_inst_handle;
474eda14cbcSMatt Macy 	Cpa16U nr_bufs = (size >> PAGE_SHIFT) + 2;
475eda14cbcSMatt Macy 	Cpa32U bytes_left = 0;
476eda14cbcSMatt Macy 	Cpa8S *data = NULL;
477eda14cbcSMatt Macy 	CpaCySymSessionCtx *cy_session_ctx = NULL;
478eda14cbcSMatt Macy 	cy_callback_t cb;
479eda14cbcSMatt Macy 	Cpa8U *digest_buffer = NULL;
480eda14cbcSMatt Macy 	CpaCySymOpData op_data = { 0 };
481eda14cbcSMatt Macy 	CpaBufferList src_buffer_list = { 0 };
482eda14cbcSMatt Macy 	CpaFlatBuffer *flat_src_buf_array = NULL;
483eda14cbcSMatt Macy 	CpaFlatBuffer *flat_src_buf = NULL;
484eda14cbcSMatt Macy 	struct page *in_pages[MAX_PAGE_NUM];
485eda14cbcSMatt Macy 	Cpa32U page_num = 0;
486eda14cbcSMatt Macy 	Cpa32U page_off = 0;
487eda14cbcSMatt Macy 
488eda14cbcSMatt Macy 	QAT_STAT_BUMP(cksum_requests);
489eda14cbcSMatt Macy 	QAT_STAT_INCR(cksum_total_in_bytes, size);
490eda14cbcSMatt Macy 
491eda14cbcSMatt Macy 	i = (Cpa32U)atomic_inc_32_nv(&inst_num) % num_inst;
492eda14cbcSMatt Macy 	cy_inst_handle = cy_inst_handles[i];
493eda14cbcSMatt Macy 
494eda14cbcSMatt Macy 	status = qat_init_checksum_session_ctx(cy_inst_handle,
495eda14cbcSMatt Macy 	    &cy_session_ctx, cksum);
496eda14cbcSMatt Macy 	if (status != CPA_STATUS_SUCCESS) {
497eda14cbcSMatt Macy 		/* don't count unsupported checksums as a failure */
498eda14cbcSMatt Macy 		if (cksum == ZIO_CHECKSUM_SHA256 ||
499eda14cbcSMatt Macy 		    cksum == ZIO_CHECKSUM_SHA512)
500eda14cbcSMatt Macy 			QAT_STAT_BUMP(cksum_fails);
501eda14cbcSMatt Macy 		return (status);
502eda14cbcSMatt Macy 	}
503eda14cbcSMatt Macy 
504eda14cbcSMatt Macy 	/*
505eda14cbcSMatt Macy 	 * We increment nr_bufs by 2 to allow us to handle non
506eda14cbcSMatt Macy 	 * page-aligned buffer addresses and buffers whose sizes
507eda14cbcSMatt Macy 	 * are not divisible by PAGE_SIZE.
508eda14cbcSMatt Macy 	 */
509eda14cbcSMatt Macy 	status = qat_init_cy_buffer_lists(cy_inst_handle, nr_bufs,
510eda14cbcSMatt Macy 	    &src_buffer_list, &src_buffer_list);
511eda14cbcSMatt Macy 	if (status != CPA_STATUS_SUCCESS)
512eda14cbcSMatt Macy 		goto fail;
513eda14cbcSMatt Macy 
514eda14cbcSMatt Macy 	status = QAT_PHYS_CONTIG_ALLOC(&flat_src_buf_array,
515eda14cbcSMatt Macy 	    nr_bufs * sizeof (CpaFlatBuffer));
516eda14cbcSMatt Macy 	if (status != CPA_STATUS_SUCCESS)
517eda14cbcSMatt Macy 		goto fail;
518eda14cbcSMatt Macy 	status = QAT_PHYS_CONTIG_ALLOC(&digest_buffer,
519eda14cbcSMatt Macy 	    sizeof (zio_cksum_t));
520eda14cbcSMatt Macy 	if (status != CPA_STATUS_SUCCESS)
521eda14cbcSMatt Macy 		goto fail;
522eda14cbcSMatt Macy 
523eda14cbcSMatt Macy 	bytes_left = size;
524eda14cbcSMatt Macy 	data = buf;
525eda14cbcSMatt Macy 	flat_src_buf = flat_src_buf_array;
526eda14cbcSMatt Macy 	while (bytes_left > 0) {
527eda14cbcSMatt Macy 		page_off = ((long)data & ~PAGE_MASK);
528eda14cbcSMatt Macy 		in_pages[page_num] = qat_mem_to_page(data);
529eda14cbcSMatt Macy 		flat_src_buf->pData = kmap(in_pages[page_num]) + page_off;
530eda14cbcSMatt Macy 		flat_src_buf->dataLenInBytes =
531eda14cbcSMatt Macy 		    min((long)PAGE_SIZE - page_off, (long)bytes_left);
532eda14cbcSMatt Macy 		data += flat_src_buf->dataLenInBytes;
533eda14cbcSMatt Macy 		bytes_left -= flat_src_buf->dataLenInBytes;
534eda14cbcSMatt Macy 		flat_src_buf++;
535eda14cbcSMatt Macy 		page_num++;
536eda14cbcSMatt Macy 	}
537eda14cbcSMatt Macy 	src_buffer_list.pBuffers = flat_src_buf_array;
538eda14cbcSMatt Macy 	src_buffer_list.numBuffers = page_num;
539eda14cbcSMatt Macy 
540eda14cbcSMatt Macy 	op_data.sessionCtx = cy_session_ctx;
541eda14cbcSMatt Macy 	op_data.packetType = CPA_CY_SYM_PACKET_TYPE_FULL;
542eda14cbcSMatt Macy 	op_data.hashStartSrcOffsetInBytes = 0;
543eda14cbcSMatt Macy 	op_data.messageLenToHashInBytes = size;
544eda14cbcSMatt Macy 	op_data.pDigestResult = digest_buffer;
545eda14cbcSMatt Macy 
546eda14cbcSMatt Macy 	cb.verify_result = CPA_FALSE;
547eda14cbcSMatt Macy 	init_completion(&cb.complete);
548eda14cbcSMatt Macy 	status = cpaCySymPerformOp(cy_inst_handle, &cb, &op_data,
549eda14cbcSMatt Macy 	    &src_buffer_list, &src_buffer_list, NULL);
550eda14cbcSMatt Macy 	if (status != CPA_STATUS_SUCCESS)
551eda14cbcSMatt Macy 		goto fail;
552eda14cbcSMatt Macy 
553eda14cbcSMatt Macy 	/* we now wait until the completion of the operation. */
554eda14cbcSMatt Macy 	wait_for_completion(&cb.complete);
555eda14cbcSMatt Macy 
556eda14cbcSMatt Macy 	if (cb.verify_result == CPA_FALSE) {
557eda14cbcSMatt Macy 		status = CPA_STATUS_FAIL;
558eda14cbcSMatt Macy 		goto fail;
559eda14cbcSMatt Macy 	}
560eda14cbcSMatt Macy 
561da5137abSMartin Matuska 	memcpy(zcp, digest_buffer, sizeof (zio_cksum_t));
562eda14cbcSMatt Macy 
563eda14cbcSMatt Macy fail:
564eda14cbcSMatt Macy 	if (status != CPA_STATUS_SUCCESS)
565eda14cbcSMatt Macy 		QAT_STAT_BUMP(cksum_fails);
566eda14cbcSMatt Macy 
567eda14cbcSMatt Macy 	for (i = 0; i < page_num; i++)
568eda14cbcSMatt Macy 		kunmap(in_pages[i]);
569eda14cbcSMatt Macy 
570eda14cbcSMatt Macy 	cpaCySymRemoveSession(cy_inst_handle, cy_session_ctx);
571eda14cbcSMatt Macy 	QAT_PHYS_CONTIG_FREE(digest_buffer);
572eda14cbcSMatt Macy 	QAT_PHYS_CONTIG_FREE(src_buffer_list.pPrivateMetaData);
573eda14cbcSMatt Macy 	QAT_PHYS_CONTIG_FREE(cy_session_ctx);
574eda14cbcSMatt Macy 	QAT_PHYS_CONTIG_FREE(flat_src_buf_array);
575eda14cbcSMatt Macy 
576eda14cbcSMatt Macy 	return (status);
577eda14cbcSMatt Macy }
578eda14cbcSMatt Macy 
579eda14cbcSMatt Macy static int
param_set_qat_encrypt(const char * val,zfs_kernel_param_t * kp)580eda14cbcSMatt Macy param_set_qat_encrypt(const char *val, zfs_kernel_param_t *kp)
581eda14cbcSMatt Macy {
582eda14cbcSMatt Macy 	int ret;
583eda14cbcSMatt Macy 	int *pvalue = kp->arg;
584eda14cbcSMatt Macy 	ret = param_set_int(val, kp);
585eda14cbcSMatt Macy 	if (ret)
586eda14cbcSMatt Macy 		return (ret);
587eda14cbcSMatt Macy 	/*
588eda14cbcSMatt Macy 	 * zfs_qat_encrypt_disable = 0: enable qat encrypt
589eda14cbcSMatt Macy 	 * try to initialize qat instance if it has not been done
590eda14cbcSMatt Macy 	 */
591eda14cbcSMatt Macy 	if (*pvalue == 0 && !qat_cy_init_done) {
592eda14cbcSMatt Macy 		ret = qat_cy_init();
593eda14cbcSMatt Macy 		if (ret != 0) {
594eda14cbcSMatt Macy 			zfs_qat_encrypt_disable = 1;
595eda14cbcSMatt Macy 			return (ret);
596eda14cbcSMatt Macy 		}
597eda14cbcSMatt Macy 	}
598eda14cbcSMatt Macy 	return (ret);
599eda14cbcSMatt Macy }
600eda14cbcSMatt Macy 
601eda14cbcSMatt Macy static int
param_set_qat_checksum(const char * val,zfs_kernel_param_t * kp)602eda14cbcSMatt Macy param_set_qat_checksum(const char *val, zfs_kernel_param_t *kp)
603eda14cbcSMatt Macy {
604eda14cbcSMatt Macy 	int ret;
605eda14cbcSMatt Macy 	int *pvalue = kp->arg;
606eda14cbcSMatt Macy 	ret = param_set_int(val, kp);
607eda14cbcSMatt Macy 	if (ret)
608eda14cbcSMatt Macy 		return (ret);
609eda14cbcSMatt Macy 	/*
610eda14cbcSMatt Macy 	 * set_checksum_param_ops = 0: enable qat checksum
611eda14cbcSMatt Macy 	 * try to initialize qat instance if it has not been done
612eda14cbcSMatt Macy 	 */
613eda14cbcSMatt Macy 	if (*pvalue == 0 && !qat_cy_init_done) {
614eda14cbcSMatt Macy 		ret = qat_cy_init();
615eda14cbcSMatt Macy 		if (ret != 0) {
616eda14cbcSMatt Macy 			zfs_qat_checksum_disable = 1;
617eda14cbcSMatt Macy 			return (ret);
618eda14cbcSMatt Macy 		}
619eda14cbcSMatt Macy 	}
620eda14cbcSMatt Macy 	return (ret);
621eda14cbcSMatt Macy }
622eda14cbcSMatt Macy 
623eda14cbcSMatt Macy module_param_call(zfs_qat_encrypt_disable, param_set_qat_encrypt,
624eda14cbcSMatt Macy     param_get_int, &zfs_qat_encrypt_disable, 0644);
625eda14cbcSMatt Macy MODULE_PARM_DESC(zfs_qat_encrypt_disable, "Enable/Disable QAT encryption");
626eda14cbcSMatt Macy 
627eda14cbcSMatt Macy module_param_call(zfs_qat_checksum_disable, param_set_qat_checksum,
628eda14cbcSMatt Macy     param_get_int, &zfs_qat_checksum_disable, 0644);
629eda14cbcSMatt Macy MODULE_PARM_DESC(zfs_qat_checksum_disable, "Enable/Disable QAT checksumming");
630eda14cbcSMatt Macy 
631eda14cbcSMatt Macy #endif
632