1 /* 2 * CDDL HEADER START 3 * 4 * The contents of this file are subject to the terms of the 5 * Common Development and Distribution License (the "License"). 6 * You may not use this file except in compliance with the License. 7 * 8 * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE 9 * or http://opensource.org/licenses/CDDL-1.0. 10 * See the License for the specific language governing permissions 11 * and limitations under the License. 12 * 13 * When distributing Covered Code, include this CDDL HEADER in each 14 * file and include the License file at usr/src/OPENSOLARIS.LICENSE. 15 * If applicable, add the following below this CDDL HEADER, with the 16 * fields enclosed by brackets "[]" replaced with your own identifying 17 * information: Portions Copyright [yyyy] [name of copyright owner] 18 * 19 * CDDL HEADER END 20 */ 21 /* 22 * Copyright 2013 Saso Kiselkov. All rights reserved. 23 * Use is subject to license terms. 24 */ 25 #include <sys/edonr.h> 26 27 #define EDONR_MODE 512 28 #define EDONR_BLOCK_SIZE EdonR512_BLOCK_SIZE 29 30 /* 31 * Native zio_checksum interface for the Edon-R hash function. 32 */ 33 /*ARGSUSED*/ 34 static void 35 zio_checksum_edonr_native(const void *buf, uint64_t size, 36 const void *ctx_template, zio_cksum_t *zcp) 37 { 38 uint8_t digest[EDONR_MODE / 8]; 39 EdonRState ctx; 40 41 ASSERT(ctx_template != NULL); 42 bcopy(ctx_template, &ctx, sizeof (ctx)); 43 EdonRUpdate(&ctx, buf, size * 8); 44 EdonRFinal(&ctx, digest); 45 bcopy(digest, zcp->zc_word, sizeof (zcp->zc_word)); 46 } 47 48 /* 49 * Byteswapped zio_checksum interface for the Edon-R hash function. 50 */ 51 static void 52 zio_checksum_edonr_byteswap(const void *buf, uint64_t size, 53 const void *ctx_template, zio_cksum_t *zcp) 54 { 55 zio_cksum_t tmp; 56 57 zio_checksum_edonr_native(buf, size, ctx_template, &tmp); 58 zcp->zc_word[0] = BSWAP_64(zcp->zc_word[0]); 59 zcp->zc_word[1] = BSWAP_64(zcp->zc_word[1]); 60 zcp->zc_word[2] = BSWAP_64(zcp->zc_word[2]); 61 zcp->zc_word[3] = BSWAP_64(zcp->zc_word[3]); 62 } 63 64 static void * 65 zio_checksum_edonr_tmpl_init(const zio_cksum_salt_t *salt) 66 { 67 EdonRState *ctx; 68 uint8_t salt_block[EDONR_BLOCK_SIZE]; 69 70 /* 71 * Edon-R needs all but the last hash invocation to be on full-size 72 * blocks, but the salt is too small. Rather than simply padding it 73 * with zeros, we expand the salt into a new salt block of proper 74 * size by double-hashing it (the new salt block will be composed of 75 * H(salt) || H(H(salt))). 76 */ 77 EdonRHash(EDONR_MODE, salt->zcs_bytes, sizeof (salt->zcs_bytes) * 8, 78 salt_block); 79 EdonRHash(EDONR_MODE, salt_block, EDONR_MODE, salt_block + 80 EDONR_MODE / 8); 81 82 /* 83 * Feed the new salt block into the hash function - this will serve 84 * as our MAC key. 85 */ 86 ctx = malloc(sizeof (*ctx)); 87 bzero(ctx, sizeof (*ctx)); 88 EdonRInit(ctx, EDONR_MODE); 89 EdonRUpdate(ctx, salt_block, sizeof (salt_block) * 8); 90 return (ctx); 91 } 92 93 static void 94 zio_checksum_edonr_tmpl_free(void *ctx_template) 95 { 96 EdonRState *ctx = ctx_template; 97 98 bzero(ctx, sizeof (*ctx)); 99 free(ctx); 100 } 101