1 // SPDX-License-Identifier: GPL-2.0-or-later 2 /* 3 * Cryptographic API for algorithms (i.e., low-level API). 4 * 5 * Copyright (c) 2006 Herbert Xu <herbert@gondor.apana.org.au> 6 */ 7 8 #include <crypto/algapi.h> 9 #include <crypto/internal/simd.h> 10 #include <linux/err.h> 11 #include <linux/errno.h> 12 #include <linux/fips.h> 13 #include <linux/init.h> 14 #include <linux/kernel.h> 15 #include <linux/list.h> 16 #include <linux/module.h> 17 #include <linux/rtnetlink.h> 18 #include <linux/slab.h> 19 #include <linux/string.h> 20 21 #include "internal.h" 22 23 static LIST_HEAD(crypto_template_list); 24 25 #ifdef CONFIG_CRYPTO_MANAGER_EXTRA_TESTS 26 DEFINE_PER_CPU(bool, crypto_simd_disabled_for_test); 27 EXPORT_PER_CPU_SYMBOL_GPL(crypto_simd_disabled_for_test); 28 #endif 29 30 static inline void crypto_check_module_sig(struct module *mod) 31 { 32 if (fips_enabled && mod && !module_sig_ok(mod)) 33 panic("Module %s signature verification failed in FIPS mode\n", 34 module_name(mod)); 35 } 36 37 static int crypto_check_alg(struct crypto_alg *alg) 38 { 39 crypto_check_module_sig(alg->cra_module); 40 41 if (!alg->cra_name[0] || !alg->cra_driver_name[0]) 42 return -EINVAL; 43 44 if (alg->cra_alignmask & (alg->cra_alignmask + 1)) 45 return -EINVAL; 46 47 /* General maximums for all algs. */ 48 if (alg->cra_alignmask > MAX_ALGAPI_ALIGNMASK) 49 return -EINVAL; 50 51 if (alg->cra_blocksize > MAX_ALGAPI_BLOCKSIZE) 52 return -EINVAL; 53 54 /* Lower maximums for specific alg types. */ 55 if (!alg->cra_type && (alg->cra_flags & CRYPTO_ALG_TYPE_MASK) == 56 CRYPTO_ALG_TYPE_CIPHER) { 57 if (alg->cra_alignmask > MAX_CIPHER_ALIGNMASK) 58 return -EINVAL; 59 60 if (alg->cra_blocksize > MAX_CIPHER_BLOCKSIZE) 61 return -EINVAL; 62 } 63 64 if (alg->cra_priority < 0) 65 return -EINVAL; 66 67 refcount_set(&alg->cra_refcnt, 1); 68 69 return 0; 70 } 71 72 static void crypto_free_instance(struct crypto_instance *inst) 73 { 74 inst->alg.cra_type->free(inst); 75 } 76 77 static void crypto_destroy_instance(struct crypto_alg *alg) 78 { 79 struct crypto_instance *inst = (void *)alg; 80 struct crypto_template *tmpl = inst->tmpl; 81 82 crypto_free_instance(inst); 83 crypto_tmpl_put(tmpl); 84 } 85 86 /* 87 * This function adds a spawn to the list secondary_spawns which 88 * will be used at the end of crypto_remove_spawns to unregister 89 * instances, unless the spawn happens to be one that is depended 90 * on by the new algorithm (nalg in crypto_remove_spawns). 91 * 92 * This function is also responsible for resurrecting any algorithms 93 * in the dependency chain of nalg by unsetting n->dead. 94 */ 95 static struct list_head *crypto_more_spawns(struct crypto_alg *alg, 96 struct list_head *stack, 97 struct list_head *top, 98 struct list_head *secondary_spawns) 99 { 100 struct crypto_spawn *spawn, *n; 101 102 spawn = list_first_entry_or_null(stack, struct crypto_spawn, list); 103 if (!spawn) 104 return NULL; 105 106 n = list_prev_entry(spawn, list); 107 list_move(&spawn->list, secondary_spawns); 108 109 if (list_is_last(&n->list, stack)) 110 return top; 111 112 n = list_next_entry(n, list); 113 if (!spawn->dead) 114 n->dead = false; 115 116 return &n->inst->alg.cra_users; 117 } 118 119 static void crypto_remove_instance(struct crypto_instance *inst, 120 struct list_head *list) 121 { 122 struct crypto_template *tmpl = inst->tmpl; 123 124 if (crypto_is_dead(&inst->alg)) 125 return; 126 127 inst->alg.cra_flags |= CRYPTO_ALG_DEAD; 128 129 if (!tmpl || !crypto_tmpl_get(tmpl)) 130 return; 131 132 list_move(&inst->alg.cra_list, list); 133 hlist_del(&inst->list); 134 inst->alg.cra_destroy = crypto_destroy_instance; 135 136 BUG_ON(!list_empty(&inst->alg.cra_users)); 137 } 138 139 /* 140 * Given an algorithm alg, remove all algorithms that depend on it 141 * through spawns. If nalg is not null, then exempt any algorithms 142 * that is depended on by nalg. This is useful when nalg itself 143 * depends on alg. 144 */ 145 void crypto_remove_spawns(struct crypto_alg *alg, struct list_head *list, 146 struct crypto_alg *nalg) 147 { 148 u32 new_type = (nalg ?: alg)->cra_flags; 149 struct crypto_spawn *spawn, *n; 150 LIST_HEAD(secondary_spawns); 151 struct list_head *spawns; 152 LIST_HEAD(stack); 153 LIST_HEAD(top); 154 155 spawns = &alg->cra_users; 156 list_for_each_entry_safe(spawn, n, spawns, list) { 157 if ((spawn->alg->cra_flags ^ new_type) & spawn->mask) 158 continue; 159 160 list_move(&spawn->list, &top); 161 } 162 163 /* 164 * Perform a depth-first walk starting from alg through 165 * the cra_users tree. The list stack records the path 166 * from alg to the current spawn. 167 */ 168 spawns = ⊤ 169 do { 170 while (!list_empty(spawns)) { 171 struct crypto_instance *inst; 172 173 spawn = list_first_entry(spawns, struct crypto_spawn, 174 list); 175 inst = spawn->inst; 176 177 list_move(&spawn->list, &stack); 178 spawn->dead = !spawn->registered || &inst->alg != nalg; 179 180 if (!spawn->registered) 181 break; 182 183 BUG_ON(&inst->alg == alg); 184 185 if (&inst->alg == nalg) 186 break; 187 188 spawns = &inst->alg.cra_users; 189 190 /* 191 * Even if spawn->registered is true, the 192 * instance itself may still be unregistered. 193 * This is because it may have failed during 194 * registration. Therefore we still need to 195 * make the following test. 196 * 197 * We may encounter an unregistered instance here, since 198 * an instance's spawns are set up prior to the instance 199 * being registered. An unregistered instance will have 200 * NULL ->cra_users.next, since ->cra_users isn't 201 * properly initialized until registration. But an 202 * unregistered instance cannot have any users, so treat 203 * it the same as ->cra_users being empty. 204 */ 205 if (spawns->next == NULL) 206 break; 207 } 208 } while ((spawns = crypto_more_spawns(alg, &stack, &top, 209 &secondary_spawns))); 210 211 /* 212 * Remove all instances that are marked as dead. Also 213 * complete the resurrection of the others by moving them 214 * back to the cra_users list. 215 */ 216 list_for_each_entry_safe(spawn, n, &secondary_spawns, list) { 217 if (!spawn->dead) 218 list_move(&spawn->list, &spawn->alg->cra_users); 219 else if (spawn->registered) 220 crypto_remove_instance(spawn->inst, list); 221 } 222 } 223 EXPORT_SYMBOL_GPL(crypto_remove_spawns); 224 225 static struct crypto_larval *crypto_alloc_test_larval(struct crypto_alg *alg) 226 { 227 struct crypto_larval *larval; 228 229 if (!IS_ENABLED(CONFIG_CRYPTO_MANAGER)) 230 return NULL; 231 232 larval = crypto_larval_alloc(alg->cra_name, 233 alg->cra_flags | CRYPTO_ALG_TESTED, 0); 234 if (IS_ERR(larval)) 235 return larval; 236 237 larval->adult = crypto_mod_get(alg); 238 if (!larval->adult) { 239 kfree(larval); 240 return ERR_PTR(-ENOENT); 241 } 242 243 refcount_set(&larval->alg.cra_refcnt, 1); 244 memcpy(larval->alg.cra_driver_name, alg->cra_driver_name, 245 CRYPTO_MAX_ALG_NAME); 246 larval->alg.cra_priority = alg->cra_priority; 247 248 return larval; 249 } 250 251 static struct crypto_larval *__crypto_register_alg(struct crypto_alg *alg) 252 { 253 struct crypto_alg *q; 254 struct crypto_larval *larval; 255 int ret = -EAGAIN; 256 257 if (crypto_is_dead(alg)) 258 goto err; 259 260 INIT_LIST_HEAD(&alg->cra_users); 261 262 /* No cheating! */ 263 alg->cra_flags &= ~CRYPTO_ALG_TESTED; 264 265 ret = -EEXIST; 266 267 list_for_each_entry(q, &crypto_alg_list, cra_list) { 268 if (q == alg) 269 goto err; 270 271 if (crypto_is_moribund(q)) 272 continue; 273 274 if (crypto_is_larval(q)) { 275 if (!strcmp(alg->cra_driver_name, q->cra_driver_name)) 276 goto err; 277 continue; 278 } 279 280 if (!strcmp(q->cra_driver_name, alg->cra_name) || 281 !strcmp(q->cra_name, alg->cra_driver_name)) 282 goto err; 283 } 284 285 larval = crypto_alloc_test_larval(alg); 286 if (IS_ERR(larval)) 287 goto out; 288 289 list_add(&alg->cra_list, &crypto_alg_list); 290 291 if (larval) 292 list_add(&larval->alg.cra_list, &crypto_alg_list); 293 else 294 alg->cra_flags |= CRYPTO_ALG_TESTED; 295 296 crypto_stats_init(alg); 297 298 out: 299 return larval; 300 301 err: 302 larval = ERR_PTR(ret); 303 goto out; 304 } 305 306 void crypto_alg_tested(const char *name, int err) 307 { 308 struct crypto_larval *test; 309 struct crypto_alg *alg; 310 struct crypto_alg *q; 311 LIST_HEAD(list); 312 bool best; 313 314 down_write(&crypto_alg_sem); 315 list_for_each_entry(q, &crypto_alg_list, cra_list) { 316 if (crypto_is_moribund(q) || !crypto_is_larval(q)) 317 continue; 318 319 test = (struct crypto_larval *)q; 320 321 if (!strcmp(q->cra_driver_name, name)) 322 goto found; 323 } 324 325 pr_err("alg: Unexpected test result for %s: %d\n", name, err); 326 goto unlock; 327 328 found: 329 q->cra_flags |= CRYPTO_ALG_DEAD; 330 alg = test->adult; 331 if (err || list_empty(&alg->cra_list)) 332 goto complete; 333 334 alg->cra_flags |= CRYPTO_ALG_TESTED; 335 336 /* Only satisfy larval waiters if we are the best. */ 337 best = true; 338 list_for_each_entry(q, &crypto_alg_list, cra_list) { 339 if (crypto_is_moribund(q) || !crypto_is_larval(q)) 340 continue; 341 342 if (strcmp(alg->cra_name, q->cra_name)) 343 continue; 344 345 if (q->cra_priority > alg->cra_priority) { 346 best = false; 347 break; 348 } 349 } 350 351 list_for_each_entry(q, &crypto_alg_list, cra_list) { 352 if (q == alg) 353 continue; 354 355 if (crypto_is_moribund(q)) 356 continue; 357 358 if (crypto_is_larval(q)) { 359 struct crypto_larval *larval = (void *)q; 360 361 /* 362 * Check to see if either our generic name or 363 * specific name can satisfy the name requested 364 * by the larval entry q. 365 */ 366 if (strcmp(alg->cra_name, q->cra_name) && 367 strcmp(alg->cra_driver_name, q->cra_name)) 368 continue; 369 370 if (larval->adult) 371 continue; 372 if ((q->cra_flags ^ alg->cra_flags) & larval->mask) 373 continue; 374 375 if (best && crypto_mod_get(alg)) 376 larval->adult = alg; 377 else 378 larval->adult = ERR_PTR(-EAGAIN); 379 380 continue; 381 } 382 383 if (strcmp(alg->cra_name, q->cra_name)) 384 continue; 385 386 if (strcmp(alg->cra_driver_name, q->cra_driver_name) && 387 q->cra_priority > alg->cra_priority) 388 continue; 389 390 crypto_remove_spawns(q, &list, alg); 391 } 392 393 complete: 394 complete_all(&test->completion); 395 396 unlock: 397 up_write(&crypto_alg_sem); 398 399 crypto_remove_final(&list); 400 } 401 EXPORT_SYMBOL_GPL(crypto_alg_tested); 402 403 void crypto_remove_final(struct list_head *list) 404 { 405 struct crypto_alg *alg; 406 struct crypto_alg *n; 407 408 list_for_each_entry_safe(alg, n, list, cra_list) { 409 list_del_init(&alg->cra_list); 410 crypto_alg_put(alg); 411 } 412 } 413 EXPORT_SYMBOL_GPL(crypto_remove_final); 414 415 int crypto_register_alg(struct crypto_alg *alg) 416 { 417 struct crypto_larval *larval; 418 bool test_started; 419 int err; 420 421 alg->cra_flags &= ~CRYPTO_ALG_DEAD; 422 err = crypto_check_alg(alg); 423 if (err) 424 return err; 425 426 down_write(&crypto_alg_sem); 427 larval = __crypto_register_alg(alg); 428 test_started = static_key_enabled(&crypto_boot_test_finished); 429 if (!IS_ERR_OR_NULL(larval)) 430 larval->test_started = test_started; 431 up_write(&crypto_alg_sem); 432 433 if (IS_ERR_OR_NULL(larval)) 434 return PTR_ERR(larval); 435 436 if (test_started) 437 crypto_wait_for_test(larval); 438 return 0; 439 } 440 EXPORT_SYMBOL_GPL(crypto_register_alg); 441 442 static int crypto_remove_alg(struct crypto_alg *alg, struct list_head *list) 443 { 444 if (unlikely(list_empty(&alg->cra_list))) 445 return -ENOENT; 446 447 alg->cra_flags |= CRYPTO_ALG_DEAD; 448 449 list_del_init(&alg->cra_list); 450 crypto_remove_spawns(alg, list, NULL); 451 452 return 0; 453 } 454 455 void crypto_unregister_alg(struct crypto_alg *alg) 456 { 457 int ret; 458 LIST_HEAD(list); 459 460 down_write(&crypto_alg_sem); 461 ret = crypto_remove_alg(alg, &list); 462 up_write(&crypto_alg_sem); 463 464 if (WARN(ret, "Algorithm %s is not registered", alg->cra_driver_name)) 465 return; 466 467 BUG_ON(refcount_read(&alg->cra_refcnt) != 1); 468 if (alg->cra_destroy) 469 alg->cra_destroy(alg); 470 471 crypto_remove_final(&list); 472 } 473 EXPORT_SYMBOL_GPL(crypto_unregister_alg); 474 475 int crypto_register_algs(struct crypto_alg *algs, int count) 476 { 477 int i, ret; 478 479 for (i = 0; i < count; i++) { 480 ret = crypto_register_alg(&algs[i]); 481 if (ret) 482 goto err; 483 } 484 485 return 0; 486 487 err: 488 for (--i; i >= 0; --i) 489 crypto_unregister_alg(&algs[i]); 490 491 return ret; 492 } 493 EXPORT_SYMBOL_GPL(crypto_register_algs); 494 495 void crypto_unregister_algs(struct crypto_alg *algs, int count) 496 { 497 int i; 498 499 for (i = 0; i < count; i++) 500 crypto_unregister_alg(&algs[i]); 501 } 502 EXPORT_SYMBOL_GPL(crypto_unregister_algs); 503 504 int crypto_register_template(struct crypto_template *tmpl) 505 { 506 struct crypto_template *q; 507 int err = -EEXIST; 508 509 down_write(&crypto_alg_sem); 510 511 crypto_check_module_sig(tmpl->module); 512 513 list_for_each_entry(q, &crypto_template_list, list) { 514 if (q == tmpl) 515 goto out; 516 } 517 518 list_add(&tmpl->list, &crypto_template_list); 519 err = 0; 520 out: 521 up_write(&crypto_alg_sem); 522 return err; 523 } 524 EXPORT_SYMBOL_GPL(crypto_register_template); 525 526 int crypto_register_templates(struct crypto_template *tmpls, int count) 527 { 528 int i, err; 529 530 for (i = 0; i < count; i++) { 531 err = crypto_register_template(&tmpls[i]); 532 if (err) 533 goto out; 534 } 535 return 0; 536 537 out: 538 for (--i; i >= 0; --i) 539 crypto_unregister_template(&tmpls[i]); 540 return err; 541 } 542 EXPORT_SYMBOL_GPL(crypto_register_templates); 543 544 void crypto_unregister_template(struct crypto_template *tmpl) 545 { 546 struct crypto_instance *inst; 547 struct hlist_node *n; 548 struct hlist_head *list; 549 LIST_HEAD(users); 550 551 down_write(&crypto_alg_sem); 552 553 BUG_ON(list_empty(&tmpl->list)); 554 list_del_init(&tmpl->list); 555 556 list = &tmpl->instances; 557 hlist_for_each_entry(inst, list, list) { 558 int err = crypto_remove_alg(&inst->alg, &users); 559 560 BUG_ON(err); 561 } 562 563 up_write(&crypto_alg_sem); 564 565 hlist_for_each_entry_safe(inst, n, list, list) { 566 BUG_ON(refcount_read(&inst->alg.cra_refcnt) != 1); 567 crypto_free_instance(inst); 568 } 569 crypto_remove_final(&users); 570 } 571 EXPORT_SYMBOL_GPL(crypto_unregister_template); 572 573 void crypto_unregister_templates(struct crypto_template *tmpls, int count) 574 { 575 int i; 576 577 for (i = count - 1; i >= 0; --i) 578 crypto_unregister_template(&tmpls[i]); 579 } 580 EXPORT_SYMBOL_GPL(crypto_unregister_templates); 581 582 static struct crypto_template *__crypto_lookup_template(const char *name) 583 { 584 struct crypto_template *q, *tmpl = NULL; 585 586 down_read(&crypto_alg_sem); 587 list_for_each_entry(q, &crypto_template_list, list) { 588 if (strcmp(q->name, name)) 589 continue; 590 if (unlikely(!crypto_tmpl_get(q))) 591 continue; 592 593 tmpl = q; 594 break; 595 } 596 up_read(&crypto_alg_sem); 597 598 return tmpl; 599 } 600 601 struct crypto_template *crypto_lookup_template(const char *name) 602 { 603 return try_then_request_module(__crypto_lookup_template(name), 604 "crypto-%s", name); 605 } 606 EXPORT_SYMBOL_GPL(crypto_lookup_template); 607 608 int crypto_register_instance(struct crypto_template *tmpl, 609 struct crypto_instance *inst) 610 { 611 struct crypto_larval *larval; 612 struct crypto_spawn *spawn; 613 int err; 614 615 err = crypto_check_alg(&inst->alg); 616 if (err) 617 return err; 618 619 inst->alg.cra_module = tmpl->module; 620 inst->alg.cra_flags |= CRYPTO_ALG_INSTANCE; 621 622 down_write(&crypto_alg_sem); 623 624 larval = ERR_PTR(-EAGAIN); 625 for (spawn = inst->spawns; spawn;) { 626 struct crypto_spawn *next; 627 628 if (spawn->dead) 629 goto unlock; 630 631 next = spawn->next; 632 spawn->inst = inst; 633 spawn->registered = true; 634 635 crypto_mod_put(spawn->alg); 636 637 spawn = next; 638 } 639 640 larval = __crypto_register_alg(&inst->alg); 641 if (IS_ERR(larval)) 642 goto unlock; 643 else if (larval) 644 larval->test_started = true; 645 646 hlist_add_head(&inst->list, &tmpl->instances); 647 inst->tmpl = tmpl; 648 649 unlock: 650 up_write(&crypto_alg_sem); 651 652 err = PTR_ERR(larval); 653 if (IS_ERR_OR_NULL(larval)) 654 goto err; 655 656 crypto_wait_for_test(larval); 657 err = 0; 658 659 err: 660 return err; 661 } 662 EXPORT_SYMBOL_GPL(crypto_register_instance); 663 664 void crypto_unregister_instance(struct crypto_instance *inst) 665 { 666 LIST_HEAD(list); 667 668 down_write(&crypto_alg_sem); 669 670 crypto_remove_spawns(&inst->alg, &list, NULL); 671 crypto_remove_instance(inst, &list); 672 673 up_write(&crypto_alg_sem); 674 675 crypto_remove_final(&list); 676 } 677 EXPORT_SYMBOL_GPL(crypto_unregister_instance); 678 679 int crypto_grab_spawn(struct crypto_spawn *spawn, struct crypto_instance *inst, 680 const char *name, u32 type, u32 mask) 681 { 682 struct crypto_alg *alg; 683 int err = -EAGAIN; 684 685 if (WARN_ON_ONCE(inst == NULL)) 686 return -EINVAL; 687 688 /* Allow the result of crypto_attr_alg_name() to be passed directly */ 689 if (IS_ERR(name)) 690 return PTR_ERR(name); 691 692 alg = crypto_find_alg(name, spawn->frontend, type, mask); 693 if (IS_ERR(alg)) 694 return PTR_ERR(alg); 695 696 down_write(&crypto_alg_sem); 697 if (!crypto_is_moribund(alg)) { 698 list_add(&spawn->list, &alg->cra_users); 699 spawn->alg = alg; 700 spawn->mask = mask; 701 spawn->next = inst->spawns; 702 inst->spawns = spawn; 703 inst->alg.cra_flags |= 704 (alg->cra_flags & CRYPTO_ALG_INHERITED_FLAGS); 705 err = 0; 706 } 707 up_write(&crypto_alg_sem); 708 if (err) 709 crypto_mod_put(alg); 710 return err; 711 } 712 EXPORT_SYMBOL_GPL(crypto_grab_spawn); 713 714 void crypto_drop_spawn(struct crypto_spawn *spawn) 715 { 716 if (!spawn->alg) /* not yet initialized? */ 717 return; 718 719 down_write(&crypto_alg_sem); 720 if (!spawn->dead) 721 list_del(&spawn->list); 722 up_write(&crypto_alg_sem); 723 724 if (!spawn->registered) 725 crypto_mod_put(spawn->alg); 726 } 727 EXPORT_SYMBOL_GPL(crypto_drop_spawn); 728 729 static struct crypto_alg *crypto_spawn_alg(struct crypto_spawn *spawn) 730 { 731 struct crypto_alg *alg = ERR_PTR(-EAGAIN); 732 struct crypto_alg *target; 733 bool shoot = false; 734 735 down_read(&crypto_alg_sem); 736 if (!spawn->dead) { 737 alg = spawn->alg; 738 if (!crypto_mod_get(alg)) { 739 target = crypto_alg_get(alg); 740 shoot = true; 741 alg = ERR_PTR(-EAGAIN); 742 } 743 } 744 up_read(&crypto_alg_sem); 745 746 if (shoot) { 747 crypto_shoot_alg(target); 748 crypto_alg_put(target); 749 } 750 751 return alg; 752 } 753 754 struct crypto_tfm *crypto_spawn_tfm(struct crypto_spawn *spawn, u32 type, 755 u32 mask) 756 { 757 struct crypto_alg *alg; 758 struct crypto_tfm *tfm; 759 760 alg = crypto_spawn_alg(spawn); 761 if (IS_ERR(alg)) 762 return ERR_CAST(alg); 763 764 tfm = ERR_PTR(-EINVAL); 765 if (unlikely((alg->cra_flags ^ type) & mask)) 766 goto out_put_alg; 767 768 tfm = __crypto_alloc_tfm(alg, type, mask); 769 if (IS_ERR(tfm)) 770 goto out_put_alg; 771 772 return tfm; 773 774 out_put_alg: 775 crypto_mod_put(alg); 776 return tfm; 777 } 778 EXPORT_SYMBOL_GPL(crypto_spawn_tfm); 779 780 void *crypto_spawn_tfm2(struct crypto_spawn *spawn) 781 { 782 struct crypto_alg *alg; 783 struct crypto_tfm *tfm; 784 785 alg = crypto_spawn_alg(spawn); 786 if (IS_ERR(alg)) 787 return ERR_CAST(alg); 788 789 tfm = crypto_create_tfm(alg, spawn->frontend); 790 if (IS_ERR(tfm)) 791 goto out_put_alg; 792 793 return tfm; 794 795 out_put_alg: 796 crypto_mod_put(alg); 797 return tfm; 798 } 799 EXPORT_SYMBOL_GPL(crypto_spawn_tfm2); 800 801 int crypto_register_notifier(struct notifier_block *nb) 802 { 803 return blocking_notifier_chain_register(&crypto_chain, nb); 804 } 805 EXPORT_SYMBOL_GPL(crypto_register_notifier); 806 807 int crypto_unregister_notifier(struct notifier_block *nb) 808 { 809 return blocking_notifier_chain_unregister(&crypto_chain, nb); 810 } 811 EXPORT_SYMBOL_GPL(crypto_unregister_notifier); 812 813 struct crypto_attr_type *crypto_get_attr_type(struct rtattr **tb) 814 { 815 struct rtattr *rta = tb[0]; 816 struct crypto_attr_type *algt; 817 818 if (!rta) 819 return ERR_PTR(-ENOENT); 820 if (RTA_PAYLOAD(rta) < sizeof(*algt)) 821 return ERR_PTR(-EINVAL); 822 if (rta->rta_type != CRYPTOA_TYPE) 823 return ERR_PTR(-EINVAL); 824 825 algt = RTA_DATA(rta); 826 827 return algt; 828 } 829 EXPORT_SYMBOL_GPL(crypto_get_attr_type); 830 831 /** 832 * crypto_check_attr_type() - check algorithm type and compute inherited mask 833 * @tb: the template parameters 834 * @type: the algorithm type the template would be instantiated as 835 * @mask_ret: (output) the mask that should be passed to crypto_grab_*() 836 * to restrict the flags of any inner algorithms 837 * 838 * Validate that the algorithm type the user requested is compatible with the 839 * one the template would actually be instantiated as. E.g., if the user is 840 * doing crypto_alloc_shash("cbc(aes)", ...), this would return an error because 841 * the "cbc" template creates an "skcipher" algorithm, not an "shash" algorithm. 842 * 843 * Also compute the mask to use to restrict the flags of any inner algorithms. 844 * 845 * Return: 0 on success; -errno on failure 846 */ 847 int crypto_check_attr_type(struct rtattr **tb, u32 type, u32 *mask_ret) 848 { 849 struct crypto_attr_type *algt; 850 851 algt = crypto_get_attr_type(tb); 852 if (IS_ERR(algt)) 853 return PTR_ERR(algt); 854 855 if ((algt->type ^ type) & algt->mask) 856 return -EINVAL; 857 858 *mask_ret = crypto_algt_inherited_mask(algt); 859 return 0; 860 } 861 EXPORT_SYMBOL_GPL(crypto_check_attr_type); 862 863 const char *crypto_attr_alg_name(struct rtattr *rta) 864 { 865 struct crypto_attr_alg *alga; 866 867 if (!rta) 868 return ERR_PTR(-ENOENT); 869 if (RTA_PAYLOAD(rta) < sizeof(*alga)) 870 return ERR_PTR(-EINVAL); 871 if (rta->rta_type != CRYPTOA_ALG) 872 return ERR_PTR(-EINVAL); 873 874 alga = RTA_DATA(rta); 875 alga->name[CRYPTO_MAX_ALG_NAME - 1] = 0; 876 877 return alga->name; 878 } 879 EXPORT_SYMBOL_GPL(crypto_attr_alg_name); 880 881 int crypto_inst_setname(struct crypto_instance *inst, const char *name, 882 struct crypto_alg *alg) 883 { 884 if (snprintf(inst->alg.cra_name, CRYPTO_MAX_ALG_NAME, "%s(%s)", name, 885 alg->cra_name) >= CRYPTO_MAX_ALG_NAME) 886 return -ENAMETOOLONG; 887 888 if (snprintf(inst->alg.cra_driver_name, CRYPTO_MAX_ALG_NAME, "%s(%s)", 889 name, alg->cra_driver_name) >= CRYPTO_MAX_ALG_NAME) 890 return -ENAMETOOLONG; 891 892 return 0; 893 } 894 EXPORT_SYMBOL_GPL(crypto_inst_setname); 895 896 void crypto_init_queue(struct crypto_queue *queue, unsigned int max_qlen) 897 { 898 INIT_LIST_HEAD(&queue->list); 899 queue->backlog = &queue->list; 900 queue->qlen = 0; 901 queue->max_qlen = max_qlen; 902 } 903 EXPORT_SYMBOL_GPL(crypto_init_queue); 904 905 int crypto_enqueue_request(struct crypto_queue *queue, 906 struct crypto_async_request *request) 907 { 908 int err = -EINPROGRESS; 909 910 if (unlikely(queue->qlen >= queue->max_qlen)) { 911 if (!(request->flags & CRYPTO_TFM_REQ_MAY_BACKLOG)) { 912 err = -ENOSPC; 913 goto out; 914 } 915 err = -EBUSY; 916 if (queue->backlog == &queue->list) 917 queue->backlog = &request->list; 918 } 919 920 queue->qlen++; 921 list_add_tail(&request->list, &queue->list); 922 923 out: 924 return err; 925 } 926 EXPORT_SYMBOL_GPL(crypto_enqueue_request); 927 928 void crypto_enqueue_request_head(struct crypto_queue *queue, 929 struct crypto_async_request *request) 930 { 931 queue->qlen++; 932 list_add(&request->list, &queue->list); 933 } 934 EXPORT_SYMBOL_GPL(crypto_enqueue_request_head); 935 936 struct crypto_async_request *crypto_dequeue_request(struct crypto_queue *queue) 937 { 938 struct list_head *request; 939 940 if (unlikely(!queue->qlen)) 941 return NULL; 942 943 queue->qlen--; 944 945 if (queue->backlog != &queue->list) 946 queue->backlog = queue->backlog->next; 947 948 request = queue->list.next; 949 list_del(request); 950 951 return list_entry(request, struct crypto_async_request, list); 952 } 953 EXPORT_SYMBOL_GPL(crypto_dequeue_request); 954 955 static inline void crypto_inc_byte(u8 *a, unsigned int size) 956 { 957 u8 *b = (a + size); 958 u8 c; 959 960 for (; size; size--) { 961 c = *--b + 1; 962 *b = c; 963 if (c) 964 break; 965 } 966 } 967 968 void crypto_inc(u8 *a, unsigned int size) 969 { 970 __be32 *b = (__be32 *)(a + size); 971 u32 c; 972 973 if (IS_ENABLED(CONFIG_HAVE_EFFICIENT_UNALIGNED_ACCESS) || 974 IS_ALIGNED((unsigned long)b, __alignof__(*b))) 975 for (; size >= 4; size -= 4) { 976 c = be32_to_cpu(*--b) + 1; 977 *b = cpu_to_be32(c); 978 if (likely(c)) 979 return; 980 } 981 982 crypto_inc_byte(a, size); 983 } 984 EXPORT_SYMBOL_GPL(crypto_inc); 985 986 void __crypto_xor(u8 *dst, const u8 *src1, const u8 *src2, unsigned int len) 987 { 988 int relalign = 0; 989 990 if (!IS_ENABLED(CONFIG_HAVE_EFFICIENT_UNALIGNED_ACCESS)) { 991 int size = sizeof(unsigned long); 992 int d = (((unsigned long)dst ^ (unsigned long)src1) | 993 ((unsigned long)dst ^ (unsigned long)src2)) & 994 (size - 1); 995 996 relalign = d ? 1 << __ffs(d) : size; 997 998 /* 999 * If we care about alignment, process as many bytes as 1000 * needed to advance dst and src to values whose alignments 1001 * equal their relative alignment. This will allow us to 1002 * process the remainder of the input using optimal strides. 1003 */ 1004 while (((unsigned long)dst & (relalign - 1)) && len > 0) { 1005 *dst++ = *src1++ ^ *src2++; 1006 len--; 1007 } 1008 } 1009 1010 while (IS_ENABLED(CONFIG_64BIT) && len >= 8 && !(relalign & 7)) { 1011 *(u64 *)dst = *(u64 *)src1 ^ *(u64 *)src2; 1012 dst += 8; 1013 src1 += 8; 1014 src2 += 8; 1015 len -= 8; 1016 } 1017 1018 while (len >= 4 && !(relalign & 3)) { 1019 *(u32 *)dst = *(u32 *)src1 ^ *(u32 *)src2; 1020 dst += 4; 1021 src1 += 4; 1022 src2 += 4; 1023 len -= 4; 1024 } 1025 1026 while (len >= 2 && !(relalign & 1)) { 1027 *(u16 *)dst = *(u16 *)src1 ^ *(u16 *)src2; 1028 dst += 2; 1029 src1 += 2; 1030 src2 += 2; 1031 len -= 2; 1032 } 1033 1034 while (len--) 1035 *dst++ = *src1++ ^ *src2++; 1036 } 1037 EXPORT_SYMBOL_GPL(__crypto_xor); 1038 1039 unsigned int crypto_alg_extsize(struct crypto_alg *alg) 1040 { 1041 return alg->cra_ctxsize + 1042 (alg->cra_alignmask & ~(crypto_tfm_ctx_alignment() - 1)); 1043 } 1044 EXPORT_SYMBOL_GPL(crypto_alg_extsize); 1045 1046 int crypto_type_has_alg(const char *name, const struct crypto_type *frontend, 1047 u32 type, u32 mask) 1048 { 1049 int ret = 0; 1050 struct crypto_alg *alg = crypto_find_alg(name, frontend, type, mask); 1051 1052 if (!IS_ERR(alg)) { 1053 crypto_mod_put(alg); 1054 ret = 1; 1055 } 1056 1057 return ret; 1058 } 1059 EXPORT_SYMBOL_GPL(crypto_type_has_alg); 1060 1061 #ifdef CONFIG_CRYPTO_STATS 1062 void crypto_stats_init(struct crypto_alg *alg) 1063 { 1064 memset(&alg->stats, 0, sizeof(alg->stats)); 1065 } 1066 EXPORT_SYMBOL_GPL(crypto_stats_init); 1067 1068 void crypto_stats_get(struct crypto_alg *alg) 1069 { 1070 crypto_alg_get(alg); 1071 } 1072 EXPORT_SYMBOL_GPL(crypto_stats_get); 1073 1074 void crypto_stats_aead_encrypt(unsigned int cryptlen, struct crypto_alg *alg, 1075 int ret) 1076 { 1077 if (ret && ret != -EINPROGRESS && ret != -EBUSY) { 1078 atomic64_inc(&alg->stats.aead.err_cnt); 1079 } else { 1080 atomic64_inc(&alg->stats.aead.encrypt_cnt); 1081 atomic64_add(cryptlen, &alg->stats.aead.encrypt_tlen); 1082 } 1083 crypto_alg_put(alg); 1084 } 1085 EXPORT_SYMBOL_GPL(crypto_stats_aead_encrypt); 1086 1087 void crypto_stats_aead_decrypt(unsigned int cryptlen, struct crypto_alg *alg, 1088 int ret) 1089 { 1090 if (ret && ret != -EINPROGRESS && ret != -EBUSY) { 1091 atomic64_inc(&alg->stats.aead.err_cnt); 1092 } else { 1093 atomic64_inc(&alg->stats.aead.decrypt_cnt); 1094 atomic64_add(cryptlen, &alg->stats.aead.decrypt_tlen); 1095 } 1096 crypto_alg_put(alg); 1097 } 1098 EXPORT_SYMBOL_GPL(crypto_stats_aead_decrypt); 1099 1100 void crypto_stats_akcipher_encrypt(unsigned int src_len, int ret, 1101 struct crypto_alg *alg) 1102 { 1103 if (ret && ret != -EINPROGRESS && ret != -EBUSY) { 1104 atomic64_inc(&alg->stats.akcipher.err_cnt); 1105 } else { 1106 atomic64_inc(&alg->stats.akcipher.encrypt_cnt); 1107 atomic64_add(src_len, &alg->stats.akcipher.encrypt_tlen); 1108 } 1109 crypto_alg_put(alg); 1110 } 1111 EXPORT_SYMBOL_GPL(crypto_stats_akcipher_encrypt); 1112 1113 void crypto_stats_akcipher_decrypt(unsigned int src_len, int ret, 1114 struct crypto_alg *alg) 1115 { 1116 if (ret && ret != -EINPROGRESS && ret != -EBUSY) { 1117 atomic64_inc(&alg->stats.akcipher.err_cnt); 1118 } else { 1119 atomic64_inc(&alg->stats.akcipher.decrypt_cnt); 1120 atomic64_add(src_len, &alg->stats.akcipher.decrypt_tlen); 1121 } 1122 crypto_alg_put(alg); 1123 } 1124 EXPORT_SYMBOL_GPL(crypto_stats_akcipher_decrypt); 1125 1126 void crypto_stats_akcipher_sign(int ret, struct crypto_alg *alg) 1127 { 1128 if (ret && ret != -EINPROGRESS && ret != -EBUSY) 1129 atomic64_inc(&alg->stats.akcipher.err_cnt); 1130 else 1131 atomic64_inc(&alg->stats.akcipher.sign_cnt); 1132 crypto_alg_put(alg); 1133 } 1134 EXPORT_SYMBOL_GPL(crypto_stats_akcipher_sign); 1135 1136 void crypto_stats_akcipher_verify(int ret, struct crypto_alg *alg) 1137 { 1138 if (ret && ret != -EINPROGRESS && ret != -EBUSY) 1139 atomic64_inc(&alg->stats.akcipher.err_cnt); 1140 else 1141 atomic64_inc(&alg->stats.akcipher.verify_cnt); 1142 crypto_alg_put(alg); 1143 } 1144 EXPORT_SYMBOL_GPL(crypto_stats_akcipher_verify); 1145 1146 void crypto_stats_compress(unsigned int slen, int ret, struct crypto_alg *alg) 1147 { 1148 if (ret && ret != -EINPROGRESS && ret != -EBUSY) { 1149 atomic64_inc(&alg->stats.compress.err_cnt); 1150 } else { 1151 atomic64_inc(&alg->stats.compress.compress_cnt); 1152 atomic64_add(slen, &alg->stats.compress.compress_tlen); 1153 } 1154 crypto_alg_put(alg); 1155 } 1156 EXPORT_SYMBOL_GPL(crypto_stats_compress); 1157 1158 void crypto_stats_decompress(unsigned int slen, int ret, struct crypto_alg *alg) 1159 { 1160 if (ret && ret != -EINPROGRESS && ret != -EBUSY) { 1161 atomic64_inc(&alg->stats.compress.err_cnt); 1162 } else { 1163 atomic64_inc(&alg->stats.compress.decompress_cnt); 1164 atomic64_add(slen, &alg->stats.compress.decompress_tlen); 1165 } 1166 crypto_alg_put(alg); 1167 } 1168 EXPORT_SYMBOL_GPL(crypto_stats_decompress); 1169 1170 void crypto_stats_ahash_update(unsigned int nbytes, int ret, 1171 struct crypto_alg *alg) 1172 { 1173 if (ret && ret != -EINPROGRESS && ret != -EBUSY) 1174 atomic64_inc(&alg->stats.hash.err_cnt); 1175 else 1176 atomic64_add(nbytes, &alg->stats.hash.hash_tlen); 1177 crypto_alg_put(alg); 1178 } 1179 EXPORT_SYMBOL_GPL(crypto_stats_ahash_update); 1180 1181 void crypto_stats_ahash_final(unsigned int nbytes, int ret, 1182 struct crypto_alg *alg) 1183 { 1184 if (ret && ret != -EINPROGRESS && ret != -EBUSY) { 1185 atomic64_inc(&alg->stats.hash.err_cnt); 1186 } else { 1187 atomic64_inc(&alg->stats.hash.hash_cnt); 1188 atomic64_add(nbytes, &alg->stats.hash.hash_tlen); 1189 } 1190 crypto_alg_put(alg); 1191 } 1192 EXPORT_SYMBOL_GPL(crypto_stats_ahash_final); 1193 1194 void crypto_stats_kpp_set_secret(struct crypto_alg *alg, int ret) 1195 { 1196 if (ret) 1197 atomic64_inc(&alg->stats.kpp.err_cnt); 1198 else 1199 atomic64_inc(&alg->stats.kpp.setsecret_cnt); 1200 crypto_alg_put(alg); 1201 } 1202 EXPORT_SYMBOL_GPL(crypto_stats_kpp_set_secret); 1203 1204 void crypto_stats_kpp_generate_public_key(struct crypto_alg *alg, int ret) 1205 { 1206 if (ret) 1207 atomic64_inc(&alg->stats.kpp.err_cnt); 1208 else 1209 atomic64_inc(&alg->stats.kpp.generate_public_key_cnt); 1210 crypto_alg_put(alg); 1211 } 1212 EXPORT_SYMBOL_GPL(crypto_stats_kpp_generate_public_key); 1213 1214 void crypto_stats_kpp_compute_shared_secret(struct crypto_alg *alg, int ret) 1215 { 1216 if (ret) 1217 atomic64_inc(&alg->stats.kpp.err_cnt); 1218 else 1219 atomic64_inc(&alg->stats.kpp.compute_shared_secret_cnt); 1220 crypto_alg_put(alg); 1221 } 1222 EXPORT_SYMBOL_GPL(crypto_stats_kpp_compute_shared_secret); 1223 1224 void crypto_stats_rng_seed(struct crypto_alg *alg, int ret) 1225 { 1226 if (ret && ret != -EINPROGRESS && ret != -EBUSY) 1227 atomic64_inc(&alg->stats.rng.err_cnt); 1228 else 1229 atomic64_inc(&alg->stats.rng.seed_cnt); 1230 crypto_alg_put(alg); 1231 } 1232 EXPORT_SYMBOL_GPL(crypto_stats_rng_seed); 1233 1234 void crypto_stats_rng_generate(struct crypto_alg *alg, unsigned int dlen, 1235 int ret) 1236 { 1237 if (ret && ret != -EINPROGRESS && ret != -EBUSY) { 1238 atomic64_inc(&alg->stats.rng.err_cnt); 1239 } else { 1240 atomic64_inc(&alg->stats.rng.generate_cnt); 1241 atomic64_add(dlen, &alg->stats.rng.generate_tlen); 1242 } 1243 crypto_alg_put(alg); 1244 } 1245 EXPORT_SYMBOL_GPL(crypto_stats_rng_generate); 1246 1247 void crypto_stats_skcipher_encrypt(unsigned int cryptlen, int ret, 1248 struct crypto_alg *alg) 1249 { 1250 if (ret && ret != -EINPROGRESS && ret != -EBUSY) { 1251 atomic64_inc(&alg->stats.cipher.err_cnt); 1252 } else { 1253 atomic64_inc(&alg->stats.cipher.encrypt_cnt); 1254 atomic64_add(cryptlen, &alg->stats.cipher.encrypt_tlen); 1255 } 1256 crypto_alg_put(alg); 1257 } 1258 EXPORT_SYMBOL_GPL(crypto_stats_skcipher_encrypt); 1259 1260 void crypto_stats_skcipher_decrypt(unsigned int cryptlen, int ret, 1261 struct crypto_alg *alg) 1262 { 1263 if (ret && ret != -EINPROGRESS && ret != -EBUSY) { 1264 atomic64_inc(&alg->stats.cipher.err_cnt); 1265 } else { 1266 atomic64_inc(&alg->stats.cipher.decrypt_cnt); 1267 atomic64_add(cryptlen, &alg->stats.cipher.decrypt_tlen); 1268 } 1269 crypto_alg_put(alg); 1270 } 1271 EXPORT_SYMBOL_GPL(crypto_stats_skcipher_decrypt); 1272 #endif 1273 1274 static void __init crypto_start_tests(void) 1275 { 1276 for (;;) { 1277 struct crypto_larval *larval = NULL; 1278 struct crypto_alg *q; 1279 1280 down_write(&crypto_alg_sem); 1281 1282 list_for_each_entry(q, &crypto_alg_list, cra_list) { 1283 struct crypto_larval *l; 1284 1285 if (!crypto_is_larval(q)) 1286 continue; 1287 1288 l = (void *)q; 1289 1290 if (!crypto_is_test_larval(l)) 1291 continue; 1292 1293 if (l->test_started) 1294 continue; 1295 1296 l->test_started = true; 1297 larval = l; 1298 break; 1299 } 1300 1301 up_write(&crypto_alg_sem); 1302 1303 if (!larval) 1304 break; 1305 1306 crypto_wait_for_test(larval); 1307 } 1308 1309 static_branch_enable(&crypto_boot_test_finished); 1310 } 1311 1312 static int __init crypto_algapi_init(void) 1313 { 1314 crypto_init_proc(); 1315 crypto_start_tests(); 1316 return 0; 1317 } 1318 1319 static void __exit crypto_algapi_exit(void) 1320 { 1321 crypto_exit_proc(); 1322 } 1323 1324 /* 1325 * We run this at late_initcall so that all the built-in algorithms 1326 * have had a chance to register themselves first. 1327 */ 1328 late_initcall(crypto_algapi_init); 1329 module_exit(crypto_algapi_exit); 1330 1331 MODULE_LICENSE("GPL"); 1332 MODULE_DESCRIPTION("Cryptographic algorithms API"); 1333