diff --git a/distrib/sets/lists/minix-base/mi b/distrib/sets/lists/minix-base/mi index d45151deb..29b062921 100644 --- a/distrib/sets/lists/minix-base/mi +++ b/distrib/sets/lists/minix-base/mi @@ -869,6 +869,18 @@ ./usr/lib/librefuse.so minix-base ./usr/lib/librefuse.so.2 minix-base ./usr/lib/librefuse.so.2.0 minix-base +./usr/lib/librumpkern_crypto.so.0.0 minix-base rump +./usr/lib/librumpkern_crypto.so.0 minix-base rump +./usr/lib/librumpkern_crypto.so minix-base rump +./usr/lib/librumpkern_sysproxy.so.0.0 minix-base rump +./usr/lib/librumpkern_sysproxy.so.0 minix-base rump +./usr/lib/librumpkern_sysproxy.so minix-base rump +./usr/lib/librumpkern_tty.so.0.0 minix-base rump +./usr/lib/librumpkern_tty.so.0 minix-base rump +./usr/lib/librumpkern_tty.so minix-base rump +./usr/lib/librumpkern_z.so.0.0 minix-base rump +./usr/lib/librumpkern_z.so.0 minix-base rump +./usr/lib/librumpkern_z.so minix-base rump ./usr/lib/libsaslc.a minix-base crypto ./usr/lib/libsaslc.so.0.0 minix-base crypto ./usr/lib/libsaslc.so.0 minix-base crypto diff --git a/distrib/sets/lists/minix-comp/mi b/distrib/sets/lists/minix-comp/mi index 54f8a8a26..109fa05fd 100644 --- a/distrib/sets/lists/minix-comp/mi +++ b/distrib/sets/lists/minix-comp/mi @@ -2264,6 +2264,14 @@ ./usr/lib/librefuse.a minix-comp ./usr/lib/librefuse_pic.a minix-comp ./usr/lib/librmt.a minix-comp +./usr/lib/librumpkern_crypto.a minix-comp rump +./usr/lib/librumpkern_crypto_pic.a minix-comp rump +./usr/lib/librumpkern_sysproxy.a minix-comp rump +./usr/lib/librumpkern_sysproxy_pic.a minix-comp rump +./usr/lib/librumpkern_tty.a minix-comp rump +./usr/lib/librumpkern_tty_pic.a minix-comp rump +./usr/lib/librumpkern_z.a minix-comp rump +./usr/lib/librumpkern_z_pic.a minix-comp rump ./usr/lib/libsffs.a minix-comp ./usr/lib/libsffs_pic.a minix-comp ./usr/lib/libsqlite3.a minix-comp diff --git a/lib/Makefile b/lib/Makefile index 585a55a5f..deb47bdbd 100644 --- a/lib/Makefile +++ b/lib/Makefile @@ -325,7 +325,7 @@ SUBDIR+= ../crypto/external/cpl/tpm-tools/lib # depends on trousers .if !defined(BSD_MK_COMPAT_FILE) #SUBDIR+= ../sys/rump/dev/lib #SUBDIR+= ../sys/rump/fs/lib -#SUBDIR+= ../sys/rump/kern/lib +SUBDIR+= ../sys/rump/kern/lib #SUBDIR+= ../sys/rump/net/lib .endif .endif diff --git a/sys/crypto/arc4/arc4.c b/sys/crypto/arc4/arc4.c new file mode 100644 index 000000000..10fb561fc --- /dev/null +++ b/sys/crypto/arc4/arc4.c @@ -0,0 +1,120 @@ +/* $NetBSD: arc4.c,v 1.7 2014/08/10 16:44:35 tls Exp $ */ + +/* + * ARC4 implementation + * A Stream Cipher Encryption Algorithm "Arcfour" + * + */ + +/* This code illustrates a sample implementation + * of the Arcfour algorithm + * Copyright (c) April 29, 1997 Kalle Kaukonen. + * All Rights Reserved. + * + * Redistribution and use in source and binary forms, with or + * without modification, are permitted provided that this copyright + * notice and disclaimer are retained. + * + * THIS SOFTWARE IS PROVIDED BY KALLE KAUKONEN AND CONTRIBUTORS ``AS + * IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT + * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS + * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL KALLE + * KAUKONEN OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, + * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES + * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS + * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS + * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, + * WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING + * NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF + * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + */ + +#include +__KERNEL_RCSID(0, "$NetBSD: arc4.c,v 1.7 2014/08/10 16:44:35 tls Exp $"); + +#include + +#include + +int +arc4_ctxlen(void) +{ + return sizeof(struct arc4_ctx); +} + +void +arc4_setkey(void *ctxp, const u_char *key, u_int keylen) +{ + struct arc4_ctx *ctx = ctxp; + unsigned int i, t, u, ki, si; + unsigned int *state; + + state = ctx->state; + ctx->x = 0; + ctx->y = 0; + for (i = 0; i < 256; i++) + state[i] = i; + ki = si = 0; + for (i = 0; i < 256; i++) { + t = state[i]; + si = (si + key[ki] + t) & 0xff; + u = state[si]; + state[si] = t; + state[i] = u; + if (++ki >= keylen) + ki = 0; + } +} + +void +arc4_encrypt(void *ctxp, u_char *dst, const u_char *src, int len) +{ + struct arc4_ctx *ctx = ctxp; + unsigned int x, y, sx, sy; + unsigned int *state; + const unsigned char *endsrc; + + state = ctx->state; + x = ctx->x; + y = ctx->y; + for (endsrc = src + len; src != endsrc; src++, dst++) { + x = (x + 1) & 0xff; + sx = state[x]; + y = (sx + y) & 0xff; + state[x] = sy = state[y]; + state[y] = sx; + *dst = *src ^ state[(sx + sy) & 0xff]; + } + ctx->x = x; + ctx->y = y; +} + +void +arc4_stream(void *ctxp, u_char *dst, int len) +{ + struct arc4_ctx *ctx = ctxp; + unsigned int x, y, sx, sy; + unsigned int *state; + const unsigned char *enddst; + + state = ctx->state; + x = ctx->x; + y = ctx->y; + + for (enddst = dst + len; dst != enddst; dst++) { + x = (x + 1) & 0xff; + sx = state[x]; + y = (sx + y) & 0xff; + state[x] = sy = state[y]; + state[y]= sx; + *dst = state[(sx + sy) & 0xff]; + } + ctx->x = x; + ctx->y = y; +} + +void +arc4_decrypt(void *ctxp, u_char *dst, const u_char *src, int len) +{ + arc4_encrypt(ctxp, dst, src, len); +} diff --git a/sys/crypto/arc4/arc4.h b/sys/crypto/arc4/arc4.h new file mode 100644 index 000000000..5d95b8f3c --- /dev/null +++ b/sys/crypto/arc4/arc4.h @@ -0,0 +1,49 @@ +/* $NetBSD: arc4.h,v 1.5 2014/08/10 16:44:35 tls Exp $ */ + +/* + * ARC4 implementation + * A Stream Cipher Encryption Algorithm "Arcfour" + * + */ + +/* This code illustrates a sample implementation + * of the Arcfour algorithm + * Copyright (c) April 29, 1997 Kalle Kaukonen. + * All Rights Reserved. + * + * Redistribution and use in source and binary forms, with or + * without modification, are permitted provided that this copyright + * notice and disclaimer are retained. + * + * THIS SOFTWARE IS PROVIDED BY KALLE KAUKONEN AND CONTRIBUTORS ``AS + * IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT + * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS + * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL KALLE + * KAUKONEN OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, + * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES + * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS + * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS + * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, + * WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING + * NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF + * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + */ + +#ifndef _CRYPTO_ARC4_H_ +#define _CRYPTO_ARC4_H_ + +typedef struct arc4_ctx { + unsigned int x; + unsigned int y; + unsigned int state[256]; + /* was unsigned char, changed to int for performance -- onoe */ +} arc4_ctx_t; + +int arc4_ctxlen(void); +void arc4_setkey(void *, const u_char *, unsigned int); +void arc4_encrypt(void *, u_char *, const u_char *, int); +void arc4_decrypt(void *, u_char *, const u_char *, int); + +void arc4_stream(void *, u_char *, int); + +#endif /* _CRYPTO_ARC4_H_ */ diff --git a/sys/crypto/arc4/files.arc4 b/sys/crypto/arc4/files.arc4 new file mode 100644 index 000000000..cde98e1f7 --- /dev/null +++ b/sys/crypto/arc4/files.arc4 @@ -0,0 +1,5 @@ +# $NetBSD: files.arc4,v 1.2 2014/08/10 16:44:35 tls Exp $ + +define arc4 + +file crypto/arc4/arc4.c diff --git a/sys/crypto/blowfish/arch/i386/bf_cbc.S b/sys/crypto/blowfish/arch/i386/bf_cbc.S new file mode 100644 index 000000000..108143e65 --- /dev/null +++ b/sys/crypto/blowfish/arch/i386/bf_cbc.S @@ -0,0 +1,296 @@ +/* $NetBSD: bf_cbc.S,v 1.6 2007/12/11 23:13:57 lukem Exp $ */ + +/* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com) + * All rights reserved. + * + * This package is an SSL implementation written + * by Eric Young (eay@cryptsoft.com). + * The implementation was written so as to conform with Netscapes SSL. + * + * This library is free for commercial and non-commercial use as long as + * the following conditions are aheared to. The following conditions + * apply to all code found in this distribution, be it the RC4, RSA, + * lhash, DES, etc., code; not just the SSL code. The SSL documentation + * included with this distribution is covered by the same copyright terms + * except that the holder is Tim Hudson (tjh@cryptsoft.com). + * + * Copyright remains Eric Young's, and as such any Copyright notices in + * the code are not to be removed. + * If this package is used in a product, Eric Young should be given attribution + * as the author of the parts of the library used. + * This can be in the form of a textual message at program startup or + * in documentation (online or textual) provided with the package. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * 3. All advertising materials mentioning features or use of this software + * must display the following acknowledgement: + * "This product includes cryptographic software written by + * Eric Young (eay@cryptsoft.com)" + * The word 'cryptographic' can be left out if the rouines from the library + * being used are not cryptographic related :-). + * 4. If you include any Windows specific code (or a derivative thereof) from + * the apps directory (application code) you must include an acknowledgement: + * "This product includes software written by Tim Hudson (tjh@cryptsoft.com)" + * + * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND + * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE + * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE + * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE + * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL + * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS + * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) + * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT + * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY + * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF + * SUCH DAMAGE. + * + * The licence and distribution terms for any publically available version or + * derivative of this code cannot be changed. i.e. this code cannot simply be + * copied and put under another distribution licence + * [including the GNU Public Licence.] + */ + +/* + * Modified from the output of `perl bf-686.pl elf' by + * Thor Lancelot Simon + */ + +#include +__KERNEL_RCSID(0, "$NetBSD: bf_cbc.S,v 1.6 2007/12/11 23:13:57 lukem Exp $"); + +ENTRY(BF_cbc_encrypt) + + pushl %ebp + pushl %ebx + pushl %esi + pushl %edi + movl 28(%esp), %ebp + # getting iv ptr from parameter 4 + movl 36(%esp), %ebx + movl (%ebx), %esi + movl 4(%ebx), %edi + pushl %edi + pushl %esi + pushl %edi + pushl %esi + movl %esp, %ebx + movl 36(%esp), %esi + movl 40(%esp), %edi + # getting encrypt flag from parameter 5 + movl 56(%esp), %ecx + # get and push parameter 3 + movl 48(%esp), %eax + pushl %eax + pushl %ebx + cmpl $0, %ecx + jz .L000decrypt + andl $4294967288, %ebp + movl 8(%esp), %eax + movl 12(%esp), %ebx + jz .L001encrypt_finish +.L002encrypt_loop: + movl (%esi), %ecx + movl 4(%esi), %edx + xorl %ecx, %eax + xorl %edx, %ebx +.byte 15 +.byte 200 # bswapl %eax +.byte 15 +.byte 203 # bswapl %ebx + movl %eax, 8(%esp) + movl %ebx, 12(%esp) + call _C_LABEL(BF_encrypt) + movl 8(%esp), %eax + movl 12(%esp), %ebx +.byte 15 +.byte 200 # bswapl %eax +.byte 15 +.byte 203 # bswapl %ebx + movl %eax, (%edi) + movl %ebx, 4(%edi) + addl $8, %esi + addl $8, %edi + subl $8, %ebp + jnz .L002encrypt_loop +.L001encrypt_finish: + movl 52(%esp), %ebp + andl $7, %ebp + jz .L003finish + xorl %ecx, %ecx + xorl %edx, %edx + movl .L004cbc_enc_jmp_table(,%ebp,4),%ebp + jmp *%ebp +.L005ej7: + movb 6(%esi), %dh + sall $8, %edx +.L006ej6: + movb 5(%esi), %dh +.L007ej5: + movb 4(%esi), %dl +.L008ej4: + movl (%esi), %ecx + jmp .L009ejend +.L010ej3: + movb 2(%esi), %ch + sall $8, %ecx +.L011ej2: + movb 1(%esi), %ch +.L012ej1: + movb (%esi), %cl +.L009ejend: + xorl %ecx, %eax + xorl %edx, %ebx +.byte 15 +.byte 200 # bswapl %eax +.byte 15 +.byte 203 # bswapl %ebx + movl %eax, 8(%esp) + movl %ebx, 12(%esp) + call _C_LABEL(BF_encrypt) + movl 8(%esp), %eax + movl 12(%esp), %ebx +.byte 15 +.byte 200 # bswapl %eax +.byte 15 +.byte 203 # bswapl %ebx + movl %eax, (%edi) + movl %ebx, 4(%edi) + jmp .L003finish +#ifdef __ELF__ +.align 16 +#else +.align 4 +#endif +.L000decrypt: + andl $4294967288, %ebp + movl 16(%esp), %eax + movl 20(%esp), %ebx + jz .L013decrypt_finish +.L014decrypt_loop: + movl (%esi), %eax + movl 4(%esi), %ebx +.byte 15 +.byte 200 # bswapl %eax +.byte 15 +.byte 203 # bswapl %ebx + movl %eax, 8(%esp) + movl %ebx, 12(%esp) + call _C_LABEL(BF_decrypt) + movl 8(%esp), %eax + movl 12(%esp), %ebx +.byte 15 +.byte 200 # bswapl %eax +.byte 15 +.byte 203 # bswapl %ebx + movl 16(%esp), %ecx + movl 20(%esp), %edx + xorl %eax, %ecx + xorl %ebx, %edx + movl (%esi), %eax + movl 4(%esi), %ebx + movl %ecx, (%edi) + movl %edx, 4(%edi) + movl %eax, 16(%esp) + movl %ebx, 20(%esp) + addl $8, %esi + addl $8, %edi + subl $8, %ebp + jnz .L014decrypt_loop +.L013decrypt_finish: + movl 52(%esp), %ebp + andl $7, %ebp + jz .L003finish + movl (%esi), %eax + movl 4(%esi), %ebx +.byte 15 +.byte 200 # bswapl %eax +.byte 15 +.byte 203 # bswapl %ebx + movl %eax, 8(%esp) + movl %ebx, 12(%esp) + call _C_LABEL(BF_decrypt) + movl 8(%esp), %eax + movl 12(%esp), %ebx +.byte 15 +.byte 200 # bswapl %eax +.byte 15 +.byte 203 # bswapl %ebx + movl 16(%esp), %ecx + movl 20(%esp), %edx + xorl %eax, %ecx + xorl %ebx, %edx + movl (%esi), %eax + movl 4(%esi), %ebx +.L015dj7: + rorl $16, %edx + movb %dl, 6(%edi) + shrl $16, %edx +.L016dj6: + movb %dh, 5(%edi) +.L017dj5: + movb %dl, 4(%edi) +.L018dj4: + movl %ecx, (%edi) + jmp .L019djend +.L020dj3: + rorl $16, %ecx + movb %cl, 2(%edi) + sall $16, %ecx +.L021dj2: + movb %ch, 1(%esi) +.L022dj1: + movb %cl, (%esi) +.L019djend: + jmp .L003finish +#ifdef __ELF__ +.align 16 +#else +.align 4 +#endif +.L003finish: + movl 60(%esp), %ecx + addl $24, %esp + movl %eax, (%ecx) + movl %ebx, 4(%ecx) + popl %edi + popl %esi + popl %ebx + popl %ebp + ret +#ifdef __ELF__ +.align 16 +#else +.align 4 +#endif +.L004cbc_enc_jmp_table: + .long 0 + .long .L012ej1 + .long .L011ej2 + .long .L010ej3 + .long .L008ej4 + .long .L007ej5 + .long .L006ej6 + .long .L005ej7 +#ifdef __ELF__ +.align 16 +#else +.align 4 +#endif +.L023cbc_dec_jmp_table: + .long 0 + .long .L022dj1 + .long .L021dj2 + .long .L020dj3 + .long .L018dj4 + .long .L017dj5 + .long .L016dj6 + .long .L015dj7 +.L_BF_cbc_encrypt_end: + .size _C_LABEL(BF_cbc_encrypt),.L_BF_cbc_encrypt_end-_C_LABEL(BF_cbc_encrypt) diff --git a/sys/crypto/blowfish/arch/i386/bf_enc.S b/sys/crypto/blowfish/arch/i386/bf_enc.S new file mode 100644 index 000000000..543e6eeca --- /dev/null +++ b/sys/crypto/blowfish/arch/i386/bf_enc.S @@ -0,0 +1,19 @@ +/* $NetBSD: bf_enc.S,v 1.4 2007/12/11 23:15:30 lukem Exp $ */ + +/* + * Written by Jason R. Thorpe and Thor Lancelot Simon + * . Public domain. + */ + +#include +__KERNEL_RCSID(0, "$NetBSD: bf_enc.S,v 1.4 2007/12/11 23:15:30 lukem Exp $"); + +/* + * XXX Should use CPP symbols defined as a result of + * XXX `cc -mcpu=pentiumpro'. + */ +#if defined(I386_CPU) || defined(I486_CPU) || defined(I586_CPU) +#include "bf_enc_586.S" +#else +#include "bf_enc_686.S" +#endif diff --git a/sys/crypto/blowfish/arch/i386/bf_enc_586.S b/sys/crypto/blowfish/arch/i386/bf_enc_586.S new file mode 100644 index 000000000..0bbc3a0f9 --- /dev/null +++ b/sys/crypto/blowfish/arch/i386/bf_enc_586.S @@ -0,0 +1,761 @@ +/* $NetBSD: bf_enc_586.S,v 1.5 2007/12/11 23:13:57 lukem Exp $ */ + +/* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com) + * All rights reserved. + * + * This package is an SSL implementation written + * by Eric Young (eay@cryptsoft.com). + * The implementation was written so as to conform with Netscapes SSL. + * + * This library is free for commercial and non-commercial use as long as + * the following conditions are aheared to. The following conditions + * apply to all code found in this distribution, be it the RC4, RSA, + * lhash, DES, etc., code; not just the SSL code. The SSL documentation + * included with this distribution is covered by the same copyright terms + * except that the holder is Tim Hudson (tjh@cryptsoft.com). + * + * Copyright remains Eric Young's, and as such any Copyright notices in + * the code are not to be removed. + * If this package is used in a product, Eric Young should be given attribution + * as the author of the parts of the library used. + * This can be in the form of a textual message at program startup or + * in documentation (online or textual) provided with the package. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * 3. All advertising materials mentioning features or use of this software + * must display the following acknowledgement: + * "This product includes cryptographic software written by + * Eric Young (eay@cryptsoft.com)" + * The word 'cryptographic' can be left out if the rouines from the library + * being used are not cryptographic related :-). + * 4. If you include any Windows specific code (or a derivative thereof) from + * the apps directory (application code) you must include an acknowledgement: + * "This product includes software written by Tim Hudson (tjh@cryptsoft.com)" + * + * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND + * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE + * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE + * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE + * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL + * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS + * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) + * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT + * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY + * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF + * SUCH DAMAGE. + * + * The licence and distribution terms for any publically available version or + * derivative of this code cannot be changed. i.e. this code cannot simply be + * copied and put under another distribution licence + * [including the GNU Public Licence.] + */ + +/* + * Modified from the output of `perl bf-586.pl elf' by + * Jason R. Thorpe and Thor Lancelot Simon + * + */ + +#include +__KERNEL_RCSID(1, "$NetBSD: bf_enc_586.S,v 1.5 2007/12/11 23:13:57 lukem Exp $"); + +ENTRY(BF_encrypt) + pushl %ebp + pushl %ebx + movl 12(%esp), %ebx + movl 16(%esp), %ebp + pushl %esi + pushl %edi + /* Load the 2 words */ + movl (%ebx), %edi + movl 4(%ebx), %esi + xorl %eax, %eax + movl (%ebp), %ebx + xorl %ecx, %ecx + xorl %ebx, %edi + + /* Round 0 */ + movl 4(%ebp), %edx + movl %edi, %ebx + xorl %edx, %esi + shrl $16, %ebx + movl %edi, %edx + movb %bh, %al + andl $255, %ebx + movb %dh, %cl + andl $255, %edx + movl 72(%ebp,%eax,4),%eax + movl 1096(%ebp,%ebx,4),%ebx + addl %eax, %ebx + movl 2120(%ebp,%ecx,4),%eax + xorl %eax, %ebx + movl 3144(%ebp,%edx,4),%edx + addl %edx, %ebx + xorl %eax, %eax + xorl %ebx, %esi + + /* Round 1 */ + movl 8(%ebp), %edx + movl %esi, %ebx + xorl %edx, %edi + shrl $16, %ebx + movl %esi, %edx + movb %bh, %al + andl $255, %ebx + movb %dh, %cl + andl $255, %edx + movl 72(%ebp,%eax,4),%eax + movl 1096(%ebp,%ebx,4),%ebx + addl %eax, %ebx + movl 2120(%ebp,%ecx,4),%eax + xorl %eax, %ebx + movl 3144(%ebp,%edx,4),%edx + addl %edx, %ebx + xorl %eax, %eax + xorl %ebx, %edi + + /* Round 2 */ + movl 12(%ebp), %edx + movl %edi, %ebx + xorl %edx, %esi + shrl $16, %ebx + movl %edi, %edx + movb %bh, %al + andl $255, %ebx + movb %dh, %cl + andl $255, %edx + movl 72(%ebp,%eax,4),%eax + movl 1096(%ebp,%ebx,4),%ebx + addl %eax, %ebx + movl 2120(%ebp,%ecx,4),%eax + xorl %eax, %ebx + movl 3144(%ebp,%edx,4),%edx + addl %edx, %ebx + xorl %eax, %eax + xorl %ebx, %esi + + /* Round 3 */ + movl 16(%ebp), %edx + movl %esi, %ebx + xorl %edx, %edi + shrl $16, %ebx + movl %esi, %edx + movb %bh, %al + andl $255, %ebx + movb %dh, %cl + andl $255, %edx + movl 72(%ebp,%eax,4),%eax + movl 1096(%ebp,%ebx,4),%ebx + addl %eax, %ebx + movl 2120(%ebp,%ecx,4),%eax + xorl %eax, %ebx + movl 3144(%ebp,%edx,4),%edx + addl %edx, %ebx + xorl %eax, %eax + xorl %ebx, %edi + + /* Round 4 */ + movl 20(%ebp), %edx + movl %edi, %ebx + xorl %edx, %esi + shrl $16, %ebx + movl %edi, %edx + movb %bh, %al + andl $255, %ebx + movb %dh, %cl + andl $255, %edx + movl 72(%ebp,%eax,4),%eax + movl 1096(%ebp,%ebx,4),%ebx + addl %eax, %ebx + movl 2120(%ebp,%ecx,4),%eax + xorl %eax, %ebx + movl 3144(%ebp,%edx,4),%edx + addl %edx, %ebx + xorl %eax, %eax + xorl %ebx, %esi + + /* Round 5 */ + movl 24(%ebp), %edx + movl %esi, %ebx + xorl %edx, %edi + shrl $16, %ebx + movl %esi, %edx + movb %bh, %al + andl $255, %ebx + movb %dh, %cl + andl $255, %edx + movl 72(%ebp,%eax,4),%eax + movl 1096(%ebp,%ebx,4),%ebx + addl %eax, %ebx + movl 2120(%ebp,%ecx,4),%eax + xorl %eax, %ebx + movl 3144(%ebp,%edx,4),%edx + addl %edx, %ebx + xorl %eax, %eax + xorl %ebx, %edi + + /* Round 6 */ + movl 28(%ebp), %edx + movl %edi, %ebx + xorl %edx, %esi + shrl $16, %ebx + movl %edi, %edx + movb %bh, %al + andl $255, %ebx + movb %dh, %cl + andl $255, %edx + movl 72(%ebp,%eax,4),%eax + movl 1096(%ebp,%ebx,4),%ebx + addl %eax, %ebx + movl 2120(%ebp,%ecx,4),%eax + xorl %eax, %ebx + movl 3144(%ebp,%edx,4),%edx + addl %edx, %ebx + xorl %eax, %eax + xorl %ebx, %esi + + /* Round 7 */ + movl 32(%ebp), %edx + movl %esi, %ebx + xorl %edx, %edi + shrl $16, %ebx + movl %esi, %edx + movb %bh, %al + andl $255, %ebx + movb %dh, %cl + andl $255, %edx + movl 72(%ebp,%eax,4),%eax + movl 1096(%ebp,%ebx,4),%ebx + addl %eax, %ebx + movl 2120(%ebp,%ecx,4),%eax + xorl %eax, %ebx + movl 3144(%ebp,%edx,4),%edx + addl %edx, %ebx + xorl %eax, %eax + xorl %ebx, %edi + + /* Round 8 */ + movl 36(%ebp), %edx + movl %edi, %ebx + xorl %edx, %esi + shrl $16, %ebx + movl %edi, %edx + movb %bh, %al + andl $255, %ebx + movb %dh, %cl + andl $255, %edx + movl 72(%ebp,%eax,4),%eax + movl 1096(%ebp,%ebx,4),%ebx + addl %eax, %ebx + movl 2120(%ebp,%ecx,4),%eax + xorl %eax, %ebx + movl 3144(%ebp,%edx,4),%edx + addl %edx, %ebx + xorl %eax, %eax + xorl %ebx, %esi + + /* Round 9 */ + movl 40(%ebp), %edx + movl %esi, %ebx + xorl %edx, %edi + shrl $16, %ebx + movl %esi, %edx + movb %bh, %al + andl $255, %ebx + movb %dh, %cl + andl $255, %edx + movl 72(%ebp,%eax,4),%eax + movl 1096(%ebp,%ebx,4),%ebx + addl %eax, %ebx + movl 2120(%ebp,%ecx,4),%eax + xorl %eax, %ebx + movl 3144(%ebp,%edx,4),%edx + addl %edx, %ebx + xorl %eax, %eax + xorl %ebx, %edi + + /* Round 10 */ + movl 44(%ebp), %edx + movl %edi, %ebx + xorl %edx, %esi + shrl $16, %ebx + movl %edi, %edx + movb %bh, %al + andl $255, %ebx + movb %dh, %cl + andl $255, %edx + movl 72(%ebp,%eax,4),%eax + movl 1096(%ebp,%ebx,4),%ebx + addl %eax, %ebx + movl 2120(%ebp,%ecx,4),%eax + xorl %eax, %ebx + movl 3144(%ebp,%edx,4),%edx + addl %edx, %ebx + xorl %eax, %eax + xorl %ebx, %esi + + /* Round 11 */ + movl 48(%ebp), %edx + movl %esi, %ebx + xorl %edx, %edi + shrl $16, %ebx + movl %esi, %edx + movb %bh, %al + andl $255, %ebx + movb %dh, %cl + andl $255, %edx + movl 72(%ebp,%eax,4),%eax + movl 1096(%ebp,%ebx,4),%ebx + addl %eax, %ebx + movl 2120(%ebp,%ecx,4),%eax + xorl %eax, %ebx + movl 3144(%ebp,%edx,4),%edx + addl %edx, %ebx + xorl %eax, %eax + xorl %ebx, %edi + + /* Round 12 */ + movl 52(%ebp), %edx + movl %edi, %ebx + xorl %edx, %esi + shrl $16, %ebx + movl %edi, %edx + movb %bh, %al + andl $255, %ebx + movb %dh, %cl + andl $255, %edx + movl 72(%ebp,%eax,4),%eax + movl 1096(%ebp,%ebx,4),%ebx + addl %eax, %ebx + movl 2120(%ebp,%ecx,4),%eax + xorl %eax, %ebx + movl 3144(%ebp,%edx,4),%edx + addl %edx, %ebx + xorl %eax, %eax + xorl %ebx, %esi + + /* Round 13 */ + movl 56(%ebp), %edx + movl %esi, %ebx + xorl %edx, %edi + shrl $16, %ebx + movl %esi, %edx + movb %bh, %al + andl $255, %ebx + movb %dh, %cl + andl $255, %edx + movl 72(%ebp,%eax,4),%eax + movl 1096(%ebp,%ebx,4),%ebx + addl %eax, %ebx + movl 2120(%ebp,%ecx,4),%eax + xorl %eax, %ebx + movl 3144(%ebp,%edx,4),%edx + addl %edx, %ebx + xorl %eax, %eax + xorl %ebx, %edi + + /* Round 14 */ + movl 60(%ebp), %edx + movl %edi, %ebx + xorl %edx, %esi + shrl $16, %ebx + movl %edi, %edx + movb %bh, %al + andl $255, %ebx + movb %dh, %cl + andl $255, %edx + movl 72(%ebp,%eax,4),%eax + movl 1096(%ebp,%ebx,4),%ebx + addl %eax, %ebx + movl 2120(%ebp,%ecx,4),%eax + xorl %eax, %ebx + movl 3144(%ebp,%edx,4),%edx + addl %edx, %ebx + xorl %eax, %eax + xorl %ebx, %esi + + /* Round 15 */ + movl 64(%ebp), %edx + movl %esi, %ebx + xorl %edx, %edi + shrl $16, %ebx + movl %esi, %edx + movb %bh, %al + andl $255, %ebx + movb %dh, %cl + andl $255, %edx + movl 72(%ebp,%eax,4),%eax + movl 1096(%ebp,%ebx,4),%ebx + addl %eax, %ebx + movl 2120(%ebp,%ecx,4),%eax + xorl %eax, %ebx + movl 3144(%ebp,%edx,4),%edx + addl %edx, %ebx + # Load parameter 0 (16) enc=1 + movl 20(%esp), %eax + xorl %ebx, %edi + movl 68(%ebp), %edx + xorl %edx, %esi + movl %edi, 4(%eax) + movl %esi, (%eax) + popl %edi + popl %esi + popl %ebx + popl %ebp + ret +.L_BF_encrypt_end: + .size _C_LABEL(BF_encrypt),.L_BF_encrypt_end-_C_LABEL(BF_encrypt) + +ENTRY(BF_decrypt) + pushl %ebp + pushl %ebx + movl 12(%esp), %ebx + movl 16(%esp), %ebp + pushl %esi + pushl %edi + # Load the 2 words + movl (%ebx), %edi + movl 4(%ebx), %esi + xorl %eax, %eax + movl 68(%ebp), %ebx + xorl %ecx, %ecx + xorl %ebx, %edi + + /* Round 16 */ + movl 64(%ebp), %edx + movl %edi, %ebx + xorl %edx, %esi + shrl $16, %ebx + movl %edi, %edx + movb %bh, %al + andl $255, %ebx + movb %dh, %cl + andl $255, %edx + movl 72(%ebp,%eax,4),%eax + movl 1096(%ebp,%ebx,4),%ebx + addl %eax, %ebx + movl 2120(%ebp,%ecx,4),%eax + xorl %eax, %ebx + movl 3144(%ebp,%edx,4),%edx + addl %edx, %ebx + xorl %eax, %eax + xorl %ebx, %esi + + /* Round 15 */ + movl 60(%ebp), %edx + movl %esi, %ebx + xorl %edx, %edi + shrl $16, %ebx + movl %esi, %edx + movb %bh, %al + andl $255, %ebx + movb %dh, %cl + andl $255, %edx + movl 72(%ebp,%eax,4),%eax + movl 1096(%ebp,%ebx,4),%ebx + addl %eax, %ebx + movl 2120(%ebp,%ecx,4),%eax + xorl %eax, %ebx + movl 3144(%ebp,%edx,4),%edx + addl %edx, %ebx + xorl %eax, %eax + xorl %ebx, %edi + + /* Round 14 */ + movl 56(%ebp), %edx + movl %edi, %ebx + xorl %edx, %esi + shrl $16, %ebx + movl %edi, %edx + movb %bh, %al + andl $255, %ebx + movb %dh, %cl + andl $255, %edx + movl 72(%ebp,%eax,4),%eax + movl 1096(%ebp,%ebx,4),%ebx + addl %eax, %ebx + movl 2120(%ebp,%ecx,4),%eax + xorl %eax, %ebx + movl 3144(%ebp,%edx,4),%edx + addl %edx, %ebx + xorl %eax, %eax + xorl %ebx, %esi + + /* Round 13 */ + movl 52(%ebp), %edx + movl %esi, %ebx + xorl %edx, %edi + shrl $16, %ebx + movl %esi, %edx + movb %bh, %al + andl $255, %ebx + movb %dh, %cl + andl $255, %edx + movl 72(%ebp,%eax,4),%eax + movl 1096(%ebp,%ebx,4),%ebx + addl %eax, %ebx + movl 2120(%ebp,%ecx,4),%eax + xorl %eax, %ebx + movl 3144(%ebp,%edx,4),%edx + addl %edx, %ebx + xorl %eax, %eax + xorl %ebx, %edi + + /* Round 12 */ + movl 48(%ebp), %edx + movl %edi, %ebx + xorl %edx, %esi + shrl $16, %ebx + movl %edi, %edx + movb %bh, %al + andl $255, %ebx + movb %dh, %cl + andl $255, %edx + movl 72(%ebp,%eax,4),%eax + movl 1096(%ebp,%ebx,4),%ebx + addl %eax, %ebx + movl 2120(%ebp,%ecx,4),%eax + xorl %eax, %ebx + movl 3144(%ebp,%edx,4),%edx + addl %edx, %ebx + xorl %eax, %eax + xorl %ebx, %esi + + /* Round 11 */ + movl 44(%ebp), %edx + movl %esi, %ebx + xorl %edx, %edi + shrl $16, %ebx + movl %esi, %edx + movb %bh, %al + andl $255, %ebx + movb %dh, %cl + andl $255, %edx + movl 72(%ebp,%eax,4),%eax + movl 1096(%ebp,%ebx,4),%ebx + addl %eax, %ebx + movl 2120(%ebp,%ecx,4),%eax + xorl %eax, %ebx + movl 3144(%ebp,%edx,4),%edx + addl %edx, %ebx + xorl %eax, %eax + xorl %ebx, %edi + + /* Round 10 */ + movl 40(%ebp), %edx + movl %edi, %ebx + xorl %edx, %esi + shrl $16, %ebx + movl %edi, %edx + movb %bh, %al + andl $255, %ebx + movb %dh, %cl + andl $255, %edx + movl 72(%ebp,%eax,4),%eax + movl 1096(%ebp,%ebx,4),%ebx + addl %eax, %ebx + movl 2120(%ebp,%ecx,4),%eax + xorl %eax, %ebx + movl 3144(%ebp,%edx,4),%edx + addl %edx, %ebx + xorl %eax, %eax + xorl %ebx, %esi + + /* Round 9 */ + movl 36(%ebp), %edx + movl %esi, %ebx + xorl %edx, %edi + shrl $16, %ebx + movl %esi, %edx + movb %bh, %al + andl $255, %ebx + movb %dh, %cl + andl $255, %edx + movl 72(%ebp,%eax,4),%eax + movl 1096(%ebp,%ebx,4),%ebx + addl %eax, %ebx + movl 2120(%ebp,%ecx,4),%eax + xorl %eax, %ebx + movl 3144(%ebp,%edx,4),%edx + addl %edx, %ebx + xorl %eax, %eax + xorl %ebx, %edi + + /* Round 8 */ + movl 32(%ebp), %edx + movl %edi, %ebx + xorl %edx, %esi + shrl $16, %ebx + movl %edi, %edx + movb %bh, %al + andl $255, %ebx + movb %dh, %cl + andl $255, %edx + movl 72(%ebp,%eax,4),%eax + movl 1096(%ebp,%ebx,4),%ebx + addl %eax, %ebx + movl 2120(%ebp,%ecx,4),%eax + xorl %eax, %ebx + movl 3144(%ebp,%edx,4),%edx + addl %edx, %ebx + xorl %eax, %eax + xorl %ebx, %esi + + /* Round 7 */ + movl 28(%ebp), %edx + movl %esi, %ebx + xorl %edx, %edi + shrl $16, %ebx + movl %esi, %edx + movb %bh, %al + andl $255, %ebx + movb %dh, %cl + andl $255, %edx + movl 72(%ebp,%eax,4),%eax + movl 1096(%ebp,%ebx,4),%ebx + addl %eax, %ebx + movl 2120(%ebp,%ecx,4),%eax + xorl %eax, %ebx + movl 3144(%ebp,%edx,4),%edx + addl %edx, %ebx + xorl %eax, %eax + xorl %ebx, %edi + + /* Round 6 */ + movl 24(%ebp), %edx + movl %edi, %ebx + xorl %edx, %esi + shrl $16, %ebx + movl %edi, %edx + movb %bh, %al + andl $255, %ebx + movb %dh, %cl + andl $255, %edx + movl 72(%ebp,%eax,4),%eax + movl 1096(%ebp,%ebx,4),%ebx + addl %eax, %ebx + movl 2120(%ebp,%ecx,4),%eax + xorl %eax, %ebx + movl 3144(%ebp,%edx,4),%edx + addl %edx, %ebx + xorl %eax, %eax + xorl %ebx, %esi + + /* Round 5 */ + movl 20(%ebp), %edx + movl %esi, %ebx + xorl %edx, %edi + shrl $16, %ebx + movl %esi, %edx + movb %bh, %al + andl $255, %ebx + movb %dh, %cl + andl $255, %edx + movl 72(%ebp,%eax,4),%eax + movl 1096(%ebp,%ebx,4),%ebx + addl %eax, %ebx + movl 2120(%ebp,%ecx,4),%eax + xorl %eax, %ebx + movl 3144(%ebp,%edx,4),%edx + addl %edx, %ebx + xorl %eax, %eax + xorl %ebx, %edi + + /* Round 4 */ + movl 16(%ebp), %edx + movl %edi, %ebx + xorl %edx, %esi + shrl $16, %ebx + movl %edi, %edx + movb %bh, %al + andl $255, %ebx + movb %dh, %cl + andl $255, %edx + movl 72(%ebp,%eax,4),%eax + movl 1096(%ebp,%ebx,4),%ebx + addl %eax, %ebx + movl 2120(%ebp,%ecx,4),%eax + xorl %eax, %ebx + movl 3144(%ebp,%edx,4),%edx + addl %edx, %ebx + xorl %eax, %eax + xorl %ebx, %esi + + /* Round 3 */ + movl 12(%ebp), %edx + movl %esi, %ebx + xorl %edx, %edi + shrl $16, %ebx + movl %esi, %edx + movb %bh, %al + andl $255, %ebx + movb %dh, %cl + andl $255, %edx + movl 72(%ebp,%eax,4),%eax + movl 1096(%ebp,%ebx,4),%ebx + addl %eax, %ebx + movl 2120(%ebp,%ecx,4),%eax + xorl %eax, %ebx + movl 3144(%ebp,%edx,4),%edx + addl %edx, %ebx + xorl %eax, %eax + xorl %ebx, %edi + + /* Round 2 */ + movl 8(%ebp), %edx + movl %edi, %ebx + xorl %edx, %esi + shrl $16, %ebx + movl %edi, %edx + movb %bh, %al + andl $255, %ebx + movb %dh, %cl + andl $255, %edx + movl 72(%ebp,%eax,4),%eax + movl 1096(%ebp,%ebx,4),%ebx + addl %eax, %ebx + movl 2120(%ebp,%ecx,4),%eax + xorl %eax, %ebx + movl 3144(%ebp,%edx,4),%edx + addl %edx, %ebx + xorl %eax, %eax + xorl %ebx, %esi + + /* Round 1 */ + movl 4(%ebp), %edx + movl %esi, %ebx + xorl %edx, %edi + shrl $16, %ebx + movl %esi, %edx + movb %bh, %al + andl $255, %ebx + movb %dh, %cl + andl $255, %edx + movl 72(%ebp,%eax,4),%eax + movl 1096(%ebp,%ebx,4),%ebx + addl %eax, %ebx + movl 2120(%ebp,%ecx,4),%eax + xorl %eax, %ebx + movl 3144(%ebp,%edx,4),%edx + addl %edx, %ebx + # Load parameter 0 (1) enc=0 + movl 20(%esp), %eax + xorl %ebx, %edi + movl (%ebp), %edx + xorl %edx, %esi + movl %edi, 4(%eax) + movl %esi, (%eax) + popl %edi + popl %esi + popl %ebx + popl %ebp + ret +.L_BF_decrypt_end: + .size _C_LABEL(BF_decrypt),.L_BF_decrypt_end-_C_LABEL(BF_decrypt) diff --git a/sys/crypto/blowfish/arch/i386/bf_enc_686.S b/sys/crypto/blowfish/arch/i386/bf_enc_686.S new file mode 100644 index 000000000..c0e476e8c --- /dev/null +++ b/sys/crypto/blowfish/arch/i386/bf_enc_686.S @@ -0,0 +1,733 @@ +/* $NetBSD: bf_enc_686.S,v 1.5 2007/12/11 23:13:57 lukem Exp $ */ + +/* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com) + * All rights reserved. + * + * This package is an SSL implementation written + * by Eric Young (eay@cryptsoft.com). + * The implementation was written so as to conform with Netscapes SSL. + * + * This library is free for commercial and non-commercial use as long as + * the following conditions are aheared to. The following conditions + * apply to all code found in this distribution, be it the RC4, RSA, + * lhash, DES, etc., code; not just the SSL code. The SSL documentation + * included with this distribution is covered by the same copyright terms + * except that the holder is Tim Hudson (tjh@cryptsoft.com). + * + * Copyright remains Eric Young's, and as such any Copyright notices in + * the code are not to be removed. + * If this package is used in a product, Eric Young should be given attribution + * as the author of the parts of the library used. + * This can be in the form of a textual message at program startup or + * in documentation (online or textual) provided with the package. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * 3. All advertising materials mentioning features or use of this software + * must display the following acknowledgement: + * "This product includes cryptographic software written by + * Eric Young (eay@cryptsoft.com)" + * The word 'cryptographic' can be left out if the rouines from the library + * being used are not cryptographic related :-). + * 4. If you include any Windows specific code (or a derivative thereof) from + * the apps directory (application code) you must include an acknowledgement: + * "This product includes software written by Tim Hudson (tjh@cryptsoft.com)" + * + * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND + * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE + * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE + * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE + * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL + * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS + * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) + * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT + * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY + * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF + * SUCH DAMAGE. + * + * The licence and distribution terms for any publically available version or + * derivative of this code cannot be changed. i.e. this code cannot simply be + * copied and put under another distribution licence + * [including the GNU Public Licence.] + */ + +/* + * Modified from the output of `perl bf-686.pl elf' by + * Jason R. Thorpe and Thor Lancelot Simon + * + */ + +#include +__KERNEL_RCSID(1, "$NetBSD: bf_enc_686.S,v 1.5 2007/12/11 23:13:57 lukem Exp $"); + +ENTRY(BF_encrypt) + pushl %ebp + pushl %ebx + pushl %esi + pushl %edi + + + /* Load the 2 words */ + movl 20(%esp), %eax + movl (%eax), %ecx + movl 4(%eax), %edx + + /* P pointer, s and enc flag */ + movl 24(%esp), %edi + xorl %eax, %eax + xorl %ebx, %ebx + xorl (%edi), %ecx + + /* Round 0 */ + rorl $16, %ecx + movl 4(%edi), %esi + movb %ch, %al + movb %cl, %bl + rorl $16, %ecx + xorl %esi, %edx + movl 72(%edi,%eax,4),%esi + movl 1096(%edi,%ebx,4),%ebp + movb %ch, %al + movb %cl, %bl + addl %ebp, %esi + movl 2120(%edi,%eax,4),%eax + xorl %eax, %esi + movl 3144(%edi,%ebx,4),%ebp + addl %ebp, %esi + xorl %eax, %eax + xorl %esi, %edx + + /* Round 1 */ + rorl $16, %edx + movl 8(%edi), %esi + movb %dh, %al + movb %dl, %bl + rorl $16, %edx + xorl %esi, %ecx + movl 72(%edi,%eax,4),%esi + movl 1096(%edi,%ebx,4),%ebp + movb %dh, %al + movb %dl, %bl + addl %ebp, %esi + movl 2120(%edi,%eax,4),%eax + xorl %eax, %esi + movl 3144(%edi,%ebx,4),%ebp + addl %ebp, %esi + xorl %eax, %eax + xorl %esi, %ecx + + /* Round 2 */ + rorl $16, %ecx + movl 12(%edi), %esi + movb %ch, %al + movb %cl, %bl + rorl $16, %ecx + xorl %esi, %edx + movl 72(%edi,%eax,4),%esi + movl 1096(%edi,%ebx,4),%ebp + movb %ch, %al + movb %cl, %bl + addl %ebp, %esi + movl 2120(%edi,%eax,4),%eax + xorl %eax, %esi + movl 3144(%edi,%ebx,4),%ebp + addl %ebp, %esi + xorl %eax, %eax + xorl %esi, %edx + + /* Round 3 */ + rorl $16, %edx + movl 16(%edi), %esi + movb %dh, %al + movb %dl, %bl + rorl $16, %edx + xorl %esi, %ecx + movl 72(%edi,%eax,4),%esi + movl 1096(%edi,%ebx,4),%ebp + movb %dh, %al + movb %dl, %bl + addl %ebp, %esi + movl 2120(%edi,%eax,4),%eax + xorl %eax, %esi + movl 3144(%edi,%ebx,4),%ebp + addl %ebp, %esi + xorl %eax, %eax + xorl %esi, %ecx + + /* Round 4 */ + rorl $16, %ecx + movl 20(%edi), %esi + movb %ch, %al + movb %cl, %bl + rorl $16, %ecx + xorl %esi, %edx + movl 72(%edi,%eax,4),%esi + movl 1096(%edi,%ebx,4),%ebp + movb %ch, %al + movb %cl, %bl + addl %ebp, %esi + movl 2120(%edi,%eax,4),%eax + xorl %eax, %esi + movl 3144(%edi,%ebx,4),%ebp + addl %ebp, %esi + xorl %eax, %eax + xorl %esi, %edx + + /* Round 5 */ + rorl $16, %edx + movl 24(%edi), %esi + movb %dh, %al + movb %dl, %bl + rorl $16, %edx + xorl %esi, %ecx + movl 72(%edi,%eax,4),%esi + movl 1096(%edi,%ebx,4),%ebp + movb %dh, %al + movb %dl, %bl + addl %ebp, %esi + movl 2120(%edi,%eax,4),%eax + xorl %eax, %esi + movl 3144(%edi,%ebx,4),%ebp + addl %ebp, %esi + xorl %eax, %eax + xorl %esi, %ecx + + /* Round 6 */ + rorl $16, %ecx + movl 28(%edi), %esi + movb %ch, %al + movb %cl, %bl + rorl $16, %ecx + xorl %esi, %edx + movl 72(%edi,%eax,4),%esi + movl 1096(%edi,%ebx,4),%ebp + movb %ch, %al + movb %cl, %bl + addl %ebp, %esi + movl 2120(%edi,%eax,4),%eax + xorl %eax, %esi + movl 3144(%edi,%ebx,4),%ebp + addl %ebp, %esi + xorl %eax, %eax + xorl %esi, %edx + + /* Round 7 */ + rorl $16, %edx + movl 32(%edi), %esi + movb %dh, %al + movb %dl, %bl + rorl $16, %edx + xorl %esi, %ecx + movl 72(%edi,%eax,4),%esi + movl 1096(%edi,%ebx,4),%ebp + movb %dh, %al + movb %dl, %bl + addl %ebp, %esi + movl 2120(%edi,%eax,4),%eax + xorl %eax, %esi + movl 3144(%edi,%ebx,4),%ebp + addl %ebp, %esi + xorl %eax, %eax + xorl %esi, %ecx + + /* Round 8 */ + rorl $16, %ecx + movl 36(%edi), %esi + movb %ch, %al + movb %cl, %bl + rorl $16, %ecx + xorl %esi, %edx + movl 72(%edi,%eax,4),%esi + movl 1096(%edi,%ebx,4),%ebp + movb %ch, %al + movb %cl, %bl + addl %ebp, %esi + movl 2120(%edi,%eax,4),%eax + xorl %eax, %esi + movl 3144(%edi,%ebx,4),%ebp + addl %ebp, %esi + xorl %eax, %eax + xorl %esi, %edx + + /* Round 9 */ + rorl $16, %edx + movl 40(%edi), %esi + movb %dh, %al + movb %dl, %bl + rorl $16, %edx + xorl %esi, %ecx + movl 72(%edi,%eax,4),%esi + movl 1096(%edi,%ebx,4),%ebp + movb %dh, %al + movb %dl, %bl + addl %ebp, %esi + movl 2120(%edi,%eax,4),%eax + xorl %eax, %esi + movl 3144(%edi,%ebx,4),%ebp + addl %ebp, %esi + xorl %eax, %eax + xorl %esi, %ecx + + /* Round 10 */ + rorl $16, %ecx + movl 44(%edi), %esi + movb %ch, %al + movb %cl, %bl + rorl $16, %ecx + xorl %esi, %edx + movl 72(%edi,%eax,4),%esi + movl 1096(%edi,%ebx,4),%ebp + movb %ch, %al + movb %cl, %bl + addl %ebp, %esi + movl 2120(%edi,%eax,4),%eax + xorl %eax, %esi + movl 3144(%edi,%ebx,4),%ebp + addl %ebp, %esi + xorl %eax, %eax + xorl %esi, %edx + + /* Round 11 */ + rorl $16, %edx + movl 48(%edi), %esi + movb %dh, %al + movb %dl, %bl + rorl $16, %edx + xorl %esi, %ecx + movl 72(%edi,%eax,4),%esi + movl 1096(%edi,%ebx,4),%ebp + movb %dh, %al + movb %dl, %bl + addl %ebp, %esi + movl 2120(%edi,%eax,4),%eax + xorl %eax, %esi + movl 3144(%edi,%ebx,4),%ebp + addl %ebp, %esi + xorl %eax, %eax + xorl %esi, %ecx + + /* Round 12 */ + rorl $16, %ecx + movl 52(%edi), %esi + movb %ch, %al + movb %cl, %bl + rorl $16, %ecx + xorl %esi, %edx + movl 72(%edi,%eax,4),%esi + movl 1096(%edi,%ebx,4),%ebp + movb %ch, %al + movb %cl, %bl + addl %ebp, %esi + movl 2120(%edi,%eax,4),%eax + xorl %eax, %esi + movl 3144(%edi,%ebx,4),%ebp + addl %ebp, %esi + xorl %eax, %eax + xorl %esi, %edx + + /* Round 13 */ + rorl $16, %edx + movl 56(%edi), %esi + movb %dh, %al + movb %dl, %bl + rorl $16, %edx + xorl %esi, %ecx + movl 72(%edi,%eax,4),%esi + movl 1096(%edi,%ebx,4),%ebp + movb %dh, %al + movb %dl, %bl + addl %ebp, %esi + movl 2120(%edi,%eax,4),%eax + xorl %eax, %esi + movl 3144(%edi,%ebx,4),%ebp + addl %ebp, %esi + xorl %eax, %eax + xorl %esi, %ecx + + /* Round 14 */ + rorl $16, %ecx + movl 60(%edi), %esi + movb %ch, %al + movb %cl, %bl + rorl $16, %ecx + xorl %esi, %edx + movl 72(%edi,%eax,4),%esi + movl 1096(%edi,%ebx,4),%ebp + movb %ch, %al + movb %cl, %bl + addl %ebp, %esi + movl 2120(%edi,%eax,4),%eax + xorl %eax, %esi + movl 3144(%edi,%ebx,4),%ebp + addl %ebp, %esi + xorl %eax, %eax + xorl %esi, %edx + + /* Round 15 */ + rorl $16, %edx + movl 64(%edi), %esi + movb %dh, %al + movb %dl, %bl + rorl $16, %edx + xorl %esi, %ecx + movl 72(%edi,%eax,4),%esi + movl 1096(%edi,%ebx,4),%ebp + movb %dh, %al + movb %dl, %bl + addl %ebp, %esi + movl 2120(%edi,%eax,4),%eax + xorl %eax, %esi + movl 3144(%edi,%ebx,4),%ebp + addl %ebp, %esi + xorl %eax, %eax + xorl %esi, %ecx + xorl 68(%edi), %edx + movl 20(%esp), %eax + movl %edx, (%eax) + movl %ecx, 4(%eax) + popl %edi + popl %esi + popl %ebx + popl %ebp + ret +.L_BF_encrypt_end: + .size _C_LABEL(BF_encrypt),.L_BF_encrypt_end-_C_LABEL(BF_encrypt) + +ENTRY(BF_decrypt) + pushl %ebp + pushl %ebx + pushl %esi + pushl %edi + + + /* Load the 2 words */ + movl 20(%esp), %eax + movl (%eax), %ecx + movl 4(%eax), %edx + + /* P pointer, s and enc flag */ + movl 24(%esp), %edi + xorl %eax, %eax + xorl %ebx, %ebx + xorl 68(%edi), %ecx + + /* Round 16 */ + rorl $16, %ecx + movl 64(%edi), %esi + movb %ch, %al + movb %cl, %bl + rorl $16, %ecx + xorl %esi, %edx + movl 72(%edi,%eax,4),%esi + movl 1096(%edi,%ebx,4),%ebp + movb %ch, %al + movb %cl, %bl + addl %ebp, %esi + movl 2120(%edi,%eax,4),%eax + xorl %eax, %esi + movl 3144(%edi,%ebx,4),%ebp + addl %ebp, %esi + xorl %eax, %eax + xorl %esi, %edx + + /* Round 15 */ + rorl $16, %edx + movl 60(%edi), %esi + movb %dh, %al + movb %dl, %bl + rorl $16, %edx + xorl %esi, %ecx + movl 72(%edi,%eax,4),%esi + movl 1096(%edi,%ebx,4),%ebp + movb %dh, %al + movb %dl, %bl + addl %ebp, %esi + movl 2120(%edi,%eax,4),%eax + xorl %eax, %esi + movl 3144(%edi,%ebx,4),%ebp + addl %ebp, %esi + xorl %eax, %eax + xorl %esi, %ecx + + /* Round 14 */ + rorl $16, %ecx + movl 56(%edi), %esi + movb %ch, %al + movb %cl, %bl + rorl $16, %ecx + xorl %esi, %edx + movl 72(%edi,%eax,4),%esi + movl 1096(%edi,%ebx,4),%ebp + movb %ch, %al + movb %cl, %bl + addl %ebp, %esi + movl 2120(%edi,%eax,4),%eax + xorl %eax, %esi + movl 3144(%edi,%ebx,4),%ebp + addl %ebp, %esi + xorl %eax, %eax + xorl %esi, %edx + + /* Round 13 */ + rorl $16, %edx + movl 52(%edi), %esi + movb %dh, %al + movb %dl, %bl + rorl $16, %edx + xorl %esi, %ecx + movl 72(%edi,%eax,4),%esi + movl 1096(%edi,%ebx,4),%ebp + movb %dh, %al + movb %dl, %bl + addl %ebp, %esi + movl 2120(%edi,%eax,4),%eax + xorl %eax, %esi + movl 3144(%edi,%ebx,4),%ebp + addl %ebp, %esi + xorl %eax, %eax + xorl %esi, %ecx + + /* Round 12 */ + rorl $16, %ecx + movl 48(%edi), %esi + movb %ch, %al + movb %cl, %bl + rorl $16, %ecx + xorl %esi, %edx + movl 72(%edi,%eax,4),%esi + movl 1096(%edi,%ebx,4),%ebp + movb %ch, %al + movb %cl, %bl + addl %ebp, %esi + movl 2120(%edi,%eax,4),%eax + xorl %eax, %esi + movl 3144(%edi,%ebx,4),%ebp + addl %ebp, %esi + xorl %eax, %eax + xorl %esi, %edx + + /* Round 11 */ + rorl $16, %edx + movl 44(%edi), %esi + movb %dh, %al + movb %dl, %bl + rorl $16, %edx + xorl %esi, %ecx + movl 72(%edi,%eax,4),%esi + movl 1096(%edi,%ebx,4),%ebp + movb %dh, %al + movb %dl, %bl + addl %ebp, %esi + movl 2120(%edi,%eax,4),%eax + xorl %eax, %esi + movl 3144(%edi,%ebx,4),%ebp + addl %ebp, %esi + xorl %eax, %eax + xorl %esi, %ecx + + /* Round 10 */ + rorl $16, %ecx + movl 40(%edi), %esi + movb %ch, %al + movb %cl, %bl + rorl $16, %ecx + xorl %esi, %edx + movl 72(%edi,%eax,4),%esi + movl 1096(%edi,%ebx,4),%ebp + movb %ch, %al + movb %cl, %bl + addl %ebp, %esi + movl 2120(%edi,%eax,4),%eax + xorl %eax, %esi + movl 3144(%edi,%ebx,4),%ebp + addl %ebp, %esi + xorl %eax, %eax + xorl %esi, %edx + + /* Round 9 */ + rorl $16, %edx + movl 36(%edi), %esi + movb %dh, %al + movb %dl, %bl + rorl $16, %edx + xorl %esi, %ecx + movl 72(%edi,%eax,4),%esi + movl 1096(%edi,%ebx,4),%ebp + movb %dh, %al + movb %dl, %bl + addl %ebp, %esi + movl 2120(%edi,%eax,4),%eax + xorl %eax, %esi + movl 3144(%edi,%ebx,4),%ebp + addl %ebp, %esi + xorl %eax, %eax + xorl %esi, %ecx + + /* Round 8 */ + rorl $16, %ecx + movl 32(%edi), %esi + movb %ch, %al + movb %cl, %bl + rorl $16, %ecx + xorl %esi, %edx + movl 72(%edi,%eax,4),%esi + movl 1096(%edi,%ebx,4),%ebp + movb %ch, %al + movb %cl, %bl + addl %ebp, %esi + movl 2120(%edi,%eax,4),%eax + xorl %eax, %esi + movl 3144(%edi,%ebx,4),%ebp + addl %ebp, %esi + xorl %eax, %eax + xorl %esi, %edx + + /* Round 7 */ + rorl $16, %edx + movl 28(%edi), %esi + movb %dh, %al + movb %dl, %bl + rorl $16, %edx + xorl %esi, %ecx + movl 72(%edi,%eax,4),%esi + movl 1096(%edi,%ebx,4),%ebp + movb %dh, %al + movb %dl, %bl + addl %ebp, %esi + movl 2120(%edi,%eax,4),%eax + xorl %eax, %esi + movl 3144(%edi,%ebx,4),%ebp + addl %ebp, %esi + xorl %eax, %eax + xorl %esi, %ecx + + /* Round 6 */ + rorl $16, %ecx + movl 24(%edi), %esi + movb %ch, %al + movb %cl, %bl + rorl $16, %ecx + xorl %esi, %edx + movl 72(%edi,%eax,4),%esi + movl 1096(%edi,%ebx,4),%ebp + movb %ch, %al + movb %cl, %bl + addl %ebp, %esi + movl 2120(%edi,%eax,4),%eax + xorl %eax, %esi + movl 3144(%edi,%ebx,4),%ebp + addl %ebp, %esi + xorl %eax, %eax + xorl %esi, %edx + + /* Round 5 */ + rorl $16, %edx + movl 20(%edi), %esi + movb %dh, %al + movb %dl, %bl + rorl $16, %edx + xorl %esi, %ecx + movl 72(%edi,%eax,4),%esi + movl 1096(%edi,%ebx,4),%ebp + movb %dh, %al + movb %dl, %bl + addl %ebp, %esi + movl 2120(%edi,%eax,4),%eax + xorl %eax, %esi + movl 3144(%edi,%ebx,4),%ebp + addl %ebp, %esi + xorl %eax, %eax + xorl %esi, %ecx + + /* Round 4 */ + rorl $16, %ecx + movl 16(%edi), %esi + movb %ch, %al + movb %cl, %bl + rorl $16, %ecx + xorl %esi, %edx + movl 72(%edi,%eax,4),%esi + movl 1096(%edi,%ebx,4),%ebp + movb %ch, %al + movb %cl, %bl + addl %ebp, %esi + movl 2120(%edi,%eax,4),%eax + xorl %eax, %esi + movl 3144(%edi,%ebx,4),%ebp + addl %ebp, %esi + xorl %eax, %eax + xorl %esi, %edx + + /* Round 3 */ + rorl $16, %edx + movl 12(%edi), %esi + movb %dh, %al + movb %dl, %bl + rorl $16, %edx + xorl %esi, %ecx + movl 72(%edi,%eax,4),%esi + movl 1096(%edi,%ebx,4),%ebp + movb %dh, %al + movb %dl, %bl + addl %ebp, %esi + movl 2120(%edi,%eax,4),%eax + xorl %eax, %esi + movl 3144(%edi,%ebx,4),%ebp + addl %ebp, %esi + xorl %eax, %eax + xorl %esi, %ecx + + /* Round 2 */ + rorl $16, %ecx + movl 8(%edi), %esi + movb %ch, %al + movb %cl, %bl + rorl $16, %ecx + xorl %esi, %edx + movl 72(%edi,%eax,4),%esi + movl 1096(%edi,%ebx,4),%ebp + movb %ch, %al + movb %cl, %bl + addl %ebp, %esi + movl 2120(%edi,%eax,4),%eax + xorl %eax, %esi + movl 3144(%edi,%ebx,4),%ebp + addl %ebp, %esi + xorl %eax, %eax + xorl %esi, %edx + + /* Round 1 */ + rorl $16, %edx + movl 4(%edi), %esi + movb %dh, %al + movb %dl, %bl + rorl $16, %edx + xorl %esi, %ecx + movl 72(%edi,%eax,4),%esi + movl 1096(%edi,%ebx,4),%ebp + movb %dh, %al + movb %dl, %bl + addl %ebp, %esi + movl 2120(%edi,%eax,4),%eax + xorl %eax, %esi + movl 3144(%edi,%ebx,4),%ebp + addl %ebp, %esi + xorl %eax, %eax + xorl %esi, %ecx + xorl (%edi), %edx + movl 20(%esp), %eax + movl %edx, (%eax) + movl %ecx, 4(%eax) + popl %edi + popl %esi + popl %ebx + popl %ebp + ret + .L_BF_decrypt_end: + .size _C_LABEL(BF_decrypt),.L_BF_decrypt_end-_C_LABEL(BF_decrypt) diff --git a/sys/crypto/blowfish/bf_cbc.c b/sys/crypto/blowfish/bf_cbc.c new file mode 100644 index 000000000..056602c3f --- /dev/null +++ b/sys/crypto/blowfish/bf_cbc.c @@ -0,0 +1,150 @@ +/* $NetBSD: bf_cbc.c,v 1.12 2005/12/11 12:20:48 christos Exp $ */ + +/* crypto/bf/bf_cbc.c */ +/* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com) + * All rights reserved. + * + * This package is an SSL implementation written + * by Eric Young (eay@cryptsoft.com). + * The implementation was written so as to conform with Netscapes SSL. + * + * This library is free for commercial and non-commercial use as long as + * the following conditions are aheared to. The following conditions + * apply to all code found in this distribution, be it the RC4, RSA, + * lhash, DES, etc., code; not just the SSL code. The SSL documentation + * included with this distribution is covered by the same copyright terms + * except that the holder is Tim Hudson (tjh@cryptsoft.com). + * + * Copyright remains Eric Young's, and as such any Copyright notices in + * the code are not to be removed. + * If this package is used in a product, Eric Young should be given attribution + * as the author of the parts of the library used. + * This can be in the form of a textual message at program startup or + * in documentation (online or textual) provided with the package. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * 3. All advertising materials mentioning features or use of this software + * must display the following acknowledgement: + * "This product includes cryptographic software written by + * Eric Young (eay@cryptsoft.com)" + * The word 'cryptographic' can be left out if the rouines from the library + * being used are not cryptographic related :-). + * 4. If you include any Windows specific code (or a derivative thereof) from + * the apps directory (application code) you must include an acknowledgement: + * "This product includes software written by Tim Hudson (tjh@cryptsoft.com)" + * + * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND + * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE + * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE + * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE + * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL + * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS + * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) + * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT + * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY + * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF + * SUCH DAMAGE. + * + * The licence and distribution terms for any publically available version or + * derivative of this code cannot be changed. i.e. this code cannot simply be + * copied and put under another distribution licence + * [including the GNU Public Licence.] + */ + +#include +__KERNEL_RCSID(0, "$NetBSD: bf_cbc.c,v 1.12 2005/12/11 12:20:48 christos Exp $"); + +#include + +#include +#include "bf_locl.h" + +void BF_cbc_encrypt(const unsigned char *in, unsigned char *out, long length, + const BF_KEY *schedule, unsigned char *ivec, int encrypt) + { + register BF_LONG tin0,tin1; + register BF_LONG tout0,tout1,xor0,xor1; + register long l=length; + BF_LONG tin[2]; + + if (encrypt) + { + n2l(ivec,tout0); + n2l(ivec,tout1); + ivec-=8; + for (l-=8; l>=0; l-=8) + { + n2l(in,tin0); + n2l(in,tin1); + tin0^=tout0; + tin1^=tout1; + tin[0]=tin0; + tin[1]=tin1; + BF_encrypt(tin,(const BF_KEY *)schedule); + tout0=tin[0]; + tout1=tin[1]; + l2n(tout0,out); + l2n(tout1,out); + } + if (l != -8) + { + n2ln(in,tin0,tin1,l+8); + tin0^=tout0; + tin1^=tout1; + tin[0]=tin0; + tin[1]=tin1; + BF_encrypt(tin,(const BF_KEY *)schedule); + tout0=tin[0]; + tout1=tin[1]; + l2n(tout0,out); + l2n(tout1,out); + } + l2n(tout0,ivec); + l2n(tout1,ivec); + } + else + { + n2l(ivec,xor0); + n2l(ivec,xor1); + ivec-=8; + for (l-=8; l>=0; l-=8) + { + n2l(in,tin0); + n2l(in,tin1); + tin[0]=tin0; + tin[1]=tin1; + BF_decrypt(tin,(const BF_KEY *)schedule); + tout0=tin[0]^xor0; + tout1=tin[1]^xor1; + l2n(tout0,out); + l2n(tout1,out); + xor0=tin0; + xor1=tin1; + } + if (l != -8) + { + n2l(in,tin0); + n2l(in,tin1); + tin[0]=tin0; + tin[1]=tin1; + BF_decrypt(tin,(const BF_KEY *)schedule); + tout0=tin[0]^xor0; + tout1=tin[1]^xor1; + l2nn(tout0,tout1,out,l+8); + xor0=tin0; + xor1=tin1; + } + l2n(xor0,ivec); + l2n(xor1,ivec); + } + tin0=tin1=tout0=tout1=xor0=xor1=0; + tin[0]=tin[1]=0; + } + diff --git a/sys/crypto/blowfish/bf_ecb.c b/sys/crypto/blowfish/bf_ecb.c new file mode 100644 index 000000000..8ab3d0ad0 --- /dev/null +++ b/sys/crypto/blowfish/bf_ecb.c @@ -0,0 +1,89 @@ +/* $NetBSD: bf_ecb.c,v 1.3 2005/12/11 12:20:48 christos Exp $ */ + +/* crypto/bf/bf_ecb.c */ +/* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com) + * All rights reserved. + * + * This package is an SSL implementation written + * by Eric Young (eay@cryptsoft.com). + * The implementation was written so as to conform with Netscapes SSL. + * + * This library is free for commercial and non-commercial use as long as + * the following conditions are aheared to. The following conditions + * apply to all code found in this distribution, be it the RC4, RSA, + * lhash, DES, etc., code; not just the SSL code. The SSL documentation + * included with this distribution is covered by the same copyright terms + * except that the holder is Tim Hudson (tjh@cryptsoft.com). + * + * Copyright remains Eric Young's, and as such any Copyright notices in + * the code are not to be removed. + * If this package is used in a product, Eric Young should be given attribution + * as the author of the parts of the library used. + * This can be in the form of a textual message at program startup or + * in documentation (online or textual) provided with the package. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * 3. All advertising materials mentioning features or use of this software + * must display the following acknowledgement: + * "This product includes cryptographic software written by + * Eric Young (eay@cryptsoft.com)" + * The word 'cryptographic' can be left out if the rouines from the library + * being used are not cryptographic related :-). + * 4. If you include any Windows specific code (or a derivative thereof) from + * the apps directory (application code) you must include an acknowledgement: + * "This product includes software written by Tim Hudson (tjh@cryptsoft.com)" + * + * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND + * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE + * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE + * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE + * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL + * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS + * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) + * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT + * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY + * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF + * SUCH DAMAGE. + * + * The licence and distribution terms for any publically available version or + * derivative of this code cannot be changed. i.e. this code cannot simply be + * copied and put under another distribution licence + * [including the GNU Public Licence.] + */ + +#include +__KERNEL_RCSID(0, "$NetBSD: bf_ecb.c,v 1.3 2005/12/11 12:20:48 christos Exp $"); + +#include + +#include +#include "bf_locl.h" + +/* Blowfish as implemented from 'Blowfish: Springer-Verlag paper' + * (From LECTURE NOTES IN COMPUTER SCIENCE 809, FAST SOFTWARE ENCRYPTION, + * CAMBRIDGE SECURITY WORKSHOP, CAMBRIDGE, U.K., DECEMBER 9-11, 1993) + */ + +void BF_ecb_encrypt(const unsigned char *in, unsigned char *out, + const BF_KEY *key, int encrypt) + { + BF_LONG l,d[2]; + + n2l(in,l); d[0]=l; + n2l(in,l); d[1]=l; + if (encrypt) + BF_encrypt(d,key); + else + BF_decrypt(d,key); + l=d[0]; l2n(l,out); + l=d[1]; l2n(l,out); + l=d[0]=d[1]=0; + } + diff --git a/sys/crypto/blowfish/bf_enc.c b/sys/crypto/blowfish/bf_enc.c new file mode 100644 index 000000000..76a228364 --- /dev/null +++ b/sys/crypto/blowfish/bf_enc.c @@ -0,0 +1,158 @@ +/* $NetBSD: bf_enc.c,v 1.10 2005/12/11 12:20:48 christos Exp $ */ + +/* crypto/bf/bf_enc.c */ +/* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com) + * All rights reserved. + * + * This package is an SSL implementation written + * by Eric Young (eay@cryptsoft.com). + * The implementation was written so as to conform with Netscapes SSL. + * + * This library is free for commercial and non-commercial use as long as + * the following conditions are aheared to. The following conditions + * apply to all code found in this distribution, be it the RC4, RSA, + * lhash, DES, etc., code; not just the SSL code. The SSL documentation + * included with this distribution is covered by the same copyright terms + * except that the holder is Tim Hudson (tjh@cryptsoft.com). + * + * Copyright remains Eric Young's, and as such any Copyright notices in + * the code are not to be removed. + * If this package is used in a product, Eric Young should be given attribution + * as the author of the parts of the library used. + * This can be in the form of a textual message at program startup or + * in documentation (online or textual) provided with the package. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * 3. All advertising materials mentioning features or use of this software + * must display the following acknowledgement: + * "This product includes cryptographic software written by + * Eric Young (eay@cryptsoft.com)" + * The word 'cryptographic' can be left out if the rouines from the library + * being used are not cryptographic related :-). + * 4. If you include any Windows specific code (or a derivative thereof) from + * the apps directory (application code) you must include an acknowledgement: + * "This product includes software written by Tim Hudson (tjh@cryptsoft.com)" + * + * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND + * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE + * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE + * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE + * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL + * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS + * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) + * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT + * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY + * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF + * SUCH DAMAGE. + * + * The licence and distribution terms for any publically available version or + * derivative of this code cannot be changed. i.e. this code cannot simply be + * copied and put under another distribution licence + * [including the GNU Public Licence.] + */ + +#include +__KERNEL_RCSID(0, "$NetBSD: bf_enc.c,v 1.10 2005/12/11 12:20:48 christos Exp $"); + +#include +#include +#include + +/* Blowfish as implemented from 'Blowfish: Springer-Verlag paper' + * (From LECTURE NOTES IN COIMPUTER SCIENCE 809, FAST SOFTWARE ENCRYPTION, + * CAMBRIDGE SECURITY WORKSHOP, CAMBRIDGE, U.K., DECEMBER 9-11, 1993) + */ + +#if (BF_ROUNDS != 16) && (BF_ROUNDS != 20) +If you set BF_ROUNDS to some value other than 16 or 20, you will have +to modify the code. +#endif + +/* XXX "data" is host endian */ +void +BF_encrypt(BF_LONG *data, const BF_KEY *key) +{ + BF_LONG l, r; + const BF_LONG *p, *s; + + p = key->P; + s= &key->S[0]; + l = data[0]; + r = data[1]; + + l^=p[0]; + BF_ENC(r, l, s, p[ 1]); + BF_ENC(l, r, s, p[ 2]); + BF_ENC(r, l, s, p[ 3]); + BF_ENC(l, r, s, p[ 4]); + BF_ENC(r, l, s, p[ 5]); + BF_ENC(l, r, s, p[ 6]); + BF_ENC(r, l, s, p[ 7]); + BF_ENC(l, r, s, p[ 8]); + BF_ENC(r, l, s, p[ 9]); + BF_ENC(l, r, s, p[10]); + BF_ENC(r, l, s, p[11]); + BF_ENC(l, r, s, p[12]); + BF_ENC(r, l, s, p[13]); + BF_ENC(l, r, s, p[14]); + BF_ENC(r, l, s, p[15]); + BF_ENC(l, r, s, p[16]); +#if BF_ROUNDS == 20 + BF_ENC(r, l, s, p[17]); + BF_ENC(l, r, s, p[18]); + BF_ENC(r, l, s, p[19]); + BF_ENC(l, r, s, p[20]); +#endif + r ^= p[BF_ROUNDS + 1]; + + data[1] = l & 0xffffffff; + data[0] = r & 0xffffffff; +} + +/* XXX "data" is host endian */ +void +BF_decrypt(BF_LONG *data, const BF_KEY *key) +{ + BF_LONG l, r; + const BF_LONG *p, *s; + + p = key->P; + s= &key->S[0]; + l = data[0]; + r = data[1]; + + l ^= p[BF_ROUNDS + 1]; +#if BF_ROUNDS == 20 + BF_ENC(r, l, s, p[20]); + BF_ENC(l, r, s, p[19]); + BF_ENC(r, l, s, p[18]); + BF_ENC(l, r, s, p[17]); +#endif + BF_ENC(r, l, s, p[16]); + BF_ENC(l, r, s, p[15]); + BF_ENC(r, l, s, p[14]); + BF_ENC(l, r, s, p[13]); + BF_ENC(r, l, s, p[12]); + BF_ENC(l, r, s, p[11]); + BF_ENC(r, l, s, p[10]); + BF_ENC(l, r, s, p[ 9]); + BF_ENC(r, l, s, p[ 8]); + BF_ENC(l, r, s, p[ 7]); + BF_ENC(r, l, s, p[ 6]); + BF_ENC(l, r, s, p[ 5]); + BF_ENC(r, l, s, p[ 4]); + BF_ENC(l, r, s, p[ 3]); + BF_ENC(r, l, s, p[ 2]); + BF_ENC(l, r, s, p[ 1]); + r ^= p[0]; + + data[1] = l & 0xffffffff; + data[0] = r & 0xffffffff; +} diff --git a/sys/crypto/blowfish/bf_locl.h b/sys/crypto/blowfish/bf_locl.h new file mode 100644 index 000000000..358f29f26 --- /dev/null +++ b/sys/crypto/blowfish/bf_locl.h @@ -0,0 +1,224 @@ +/* $NetBSD: bf_locl.h,v 1.5 2009/06/30 13:14:40 pooka Exp $ */ +/* $KAME: bf_locl.h,v 1.5 2000/08/31 06:03:48 itojun Exp $ */ + +/* crypto/bf/bf_local.h */ +/* Copyright (C) 1995-1997 Eric Young (eay@mincom.oz.au) + * All rights reserved. + * + * This package is an SSL implementation written + * by Eric Young (eay@mincom.oz.au). + * The implementation was written so as to conform with Netscapes SSL. + * + * This library is free for commercial and non-commercial use as long as + * the following conditions are aheared to. The following conditions + * apply to all code found in this distribution, be it the RC4, RSA, + * lhash, DES, etc., code; not just the SSL code. The SSL documentation + * included with this distribution is covered by the same copyright terms + * except that the holder is Tim Hudson (tjh@mincom.oz.au). + * + * Copyright remains Eric Young's, and as such any Copyright notices in + * the code are not to be removed. + * If this package is used in a product, Eric Young should be given attribution + * as the author of the parts of the library used. + * This can be in the form of a textual message at program startup or + * in documentation (online or textual) provided with the package. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * 3. All advertising materials mentioning features or use of this software + * must display the following acknowledgement: + * "This product includes cryptographic software written by + * Eric Young (eay@mincom.oz.au)" + * The word 'cryptographic' can be left out if the rouines from the library + * being used are not cryptographic related :-). + * 4. If you include any Windows specific code (or a derivative thereof) from + * the apps directory (application code) you must include an acknowledgement: + * "This product includes software written by Tim Hudson (tjh@mincom.oz.au)" + * + * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND + * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE + * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE + * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE + * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL + * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS + * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) + * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT + * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY + * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF + * SUCH DAMAGE. + * + * The licence and distribution terms for any publically available version or + * derivative of this code cannot be changed. i.e. this code cannot simply be + * copied and put under another distribution licence + * [including the GNU Public Licence.] + */ +/* WARNING WARNING WARNING WARNING WARNING WARNING WARNING WARNING WARNING + * + * Always modify bf_locl.org since bf_locl.h is automatically generated from + * it during SSLeay configuration. + * + * WARNING WARNING WARNING WARNING WARNING WARNING WARNING WARNING WARNING + */ + +#undef c2l +#define c2l(c,l) (l =((BF_LONG)(*((c)++))) , \ + l|=((BF_LONG)(*((c)++)))<< 8L, \ + l|=((BF_LONG)(*((c)++)))<<16L, \ + l|=((BF_LONG)(*((c)++)))<<24L) + +/* NOTE - c is not incremented as per c2l */ +#undef c2ln +#define c2ln(c,l1,l2,n) { \ + c+=n; \ + l1=l2=0; \ + switch (n) { \ + case 8: l2 =((BF_LONG)(*(--(c))))<<24L; \ + case 7: l2|=((BF_LONG)(*(--(c))))<<16L; \ + case 6: l2|=((BF_LONG)(*(--(c))))<< 8L; \ + case 5: l2|=((BF_LONG)(*(--(c)))); \ + case 4: l1 =((BF_LONG)(*(--(c))))<<24L; \ + case 3: l1|=((BF_LONG)(*(--(c))))<<16L; \ + case 2: l1|=((BF_LONG)(*(--(c))))<< 8L; \ + case 1: l1|=((BF_LONG)(*(--(c)))); \ + } \ + } + +#undef l2c +#define l2c(l,c) (*((c)++)=(unsigned char)(((l) )&0xff), \ + *((c)++)=(unsigned char)(((l)>> 8L)&0xff), \ + *((c)++)=(unsigned char)(((l)>>16L)&0xff), \ + *((c)++)=(unsigned char)(((l)>>24L)&0xff)) + +/* NOTE - c is not incremented as per l2c */ +#undef l2cn +#define l2cn(l1,l2,c,n) { \ + c+=n; \ + switch (n) { \ + case 8: *(--(c))=(unsigned char)(((l2)>>24L)&0xff); \ + case 7: *(--(c))=(unsigned char)(((l2)>>16L)&0xff); \ + case 6: *(--(c))=(unsigned char)(((l2)>> 8L)&0xff); \ + case 5: *(--(c))=(unsigned char)(((l2) )&0xff); \ + case 4: *(--(c))=(unsigned char)(((l1)>>24L)&0xff); \ + case 3: *(--(c))=(unsigned char)(((l1)>>16L)&0xff); \ + case 2: *(--(c))=(unsigned char)(((l1)>> 8L)&0xff); \ + case 1: *(--(c))=(unsigned char)(((l1) )&0xff); \ + } \ + } + +/* NOTE - c is not incremented as per n2l */ +#define n2ln(c,l1,l2,n) { \ + c+=n; \ + l1=l2=0; \ + switch (n) { \ + case 8: l2 =((BF_LONG)(*(--(c)))) ; \ + case 7: l2|=((BF_LONG)(*(--(c))))<< 8; \ + case 6: l2|=((BF_LONG)(*(--(c))))<<16; \ + case 5: l2|=((BF_LONG)(*(--(c))))<<24; \ + case 4: l1 =((BF_LONG)(*(--(c)))) ; \ + case 3: l1|=((BF_LONG)(*(--(c))))<< 8; \ + case 2: l1|=((BF_LONG)(*(--(c))))<<16; \ + case 1: l1|=((BF_LONG)(*(--(c))))<<24; \ + } \ + } + +/* NOTE - c is not incremented as per l2n */ +#define l2nn(l1,l2,c,n) { \ + c+=n; \ + switch (n) { \ + case 8: *(--(c))=(unsigned char)(((l2) )&0xff); \ + case 7: *(--(c))=(unsigned char)(((l2)>> 8)&0xff); \ + case 6: *(--(c))=(unsigned char)(((l2)>>16)&0xff); \ + case 5: *(--(c))=(unsigned char)(((l2)>>24)&0xff); \ + case 4: *(--(c))=(unsigned char)(((l1) )&0xff); \ + case 3: *(--(c))=(unsigned char)(((l1)>> 8)&0xff); \ + case 2: *(--(c))=(unsigned char)(((l1)>>16)&0xff); \ + case 1: *(--(c))=(unsigned char)(((l1)>>24)&0xff); \ + } \ + } + +#undef n2l +#define n2l(c,l) (l =((BF_LONG)(*((c)++)))<<24L, \ + l|=((BF_LONG)(*((c)++)))<<16L, \ + l|=((BF_LONG)(*((c)++)))<< 8L, \ + l|=((BF_LONG)(*((c)++)))) + +#undef l2n +#define l2n(l,c) (*((c)++)=(unsigned char)(((l)>>24L)&0xff), \ + *((c)++)=(unsigned char)(((l)>>16L)&0xff), \ + *((c)++)=(unsigned char)(((l)>> 8L)&0xff), \ + *((c)++)=(unsigned char)(((l) )&0xff)) + +/* This is actually a big endian algorithm, the most significate byte + * is used to lookup array 0 */ + +/* use BF_PTR2 for intel boxes, + * BF_PTR for sparc and MIPS/SGI + * use nothing for Alpha and HP. + */ +#undef BF_PTR +#undef BF_PTR2 +#ifdef __i386__ +#define BF_PTR2 +#else +#ifdef __mips__ +#define BF_PTR +#endif +#endif + +#define BF_M 0x3fc +#define BF_0 22L +#define BF_1 14L +#define BF_2 6L +#define BF_3 2L /* left shift */ + +#if defined(BF_PTR2) + +/* This is basically a special pentium verson */ +#define BF_ENC(LL,R,S,P) \ + { \ + BF_LONG t,u,v; \ + u=R>>BF_0; \ + v=R>>BF_1; \ + u&=BF_M; \ + v&=BF_M; \ + t= *(const BF_LONG *)((const unsigned char *)&(S[ 0])+u); \ + u=R>>BF_2; \ + t+= *(const BF_LONG *)((const unsigned char *)&(S[256])+v); \ + v=R<>BF_0)&BF_M))+ \ + *(const BF_LONG *)((const unsigned char *)&(S[256])+((R>>BF_1)&BF_M)))^ \ + *(const BF_LONG *)((const unsigned char *)&(S[512])+((R>>BF_2)&BF_M)))+ \ + *(const BF_LONG *)((const unsigned char *)&(S[768])+((R<>24L) ] + \ + S[0x0100+((R>>16L)&0xff)])^ \ + S[0x0200+((R>> 8L)&0xff)])+ \ + S[0x0300+((R )&0xff)])&0xffffffff; +#endif diff --git a/sys/crypto/blowfish/bf_module.c b/sys/crypto/blowfish/bf_module.c new file mode 100644 index 000000000..4350fc798 --- /dev/null +++ b/sys/crypto/blowfish/bf_module.c @@ -0,0 +1,51 @@ +/* $NetBSD: bf_module.c,v 1.1 2014/01/01 15:18:57 pgoyette Exp $ */ + +/*- + * Copyright (c) 2014 The NetBSD Foundation, Inc. + * All rights reserved. + * + * This code is derived from software contributed to The NetBSD Foundation + * by Paul Goyette + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the above copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * + * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS + * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED + * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR + * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS + * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR + * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF + * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS + * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN + * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) + * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE + * POSSIBILITY OF SUCH DAMAGE. + */ +#include +__KERNEL_RCSID(0, "$NetBSD: bf_module.c,v 1.1 2014/01/01 15:18:57 pgoyette Exp $"); + +#include +#include + +MODULE(MODULE_CLASS_MISC, blowfish, NULL); + +static int +blowfish_modcmd(modcmd_t cmd, void *opaque) +{ + + switch (cmd) { + case MODULE_CMD_INIT: + return 0; + case MODULE_CMD_FINI: + return 0; + default: + return ENOTTY; + } +} diff --git a/sys/crypto/blowfish/bf_pi.h b/sys/crypto/blowfish/bf_pi.h new file mode 100644 index 000000000..030f1f7ba --- /dev/null +++ b/sys/crypto/blowfish/bf_pi.h @@ -0,0 +1,328 @@ +/* $NetBSD: bf_pi.h,v 1.2 2001/02/21 21:39:53 jdolecek Exp $ */ +/* $KAME: bf_pi.h,v 1.3 2000/03/27 04:36:26 sumikawa Exp $ */ + +/* crypto/bf/bf_pi.h */ +/* Copyright (C) 1995-1997 Eric Young (eay@mincom.oz.au) + * All rights reserved. + * + * This package is an SSL implementation written + * by Eric Young (eay@mincom.oz.au). + * The implementation was written so as to conform with Netscapes SSL. + * + * This library is free for commercial and non-commercial use as long as + * the following conditions are aheared to. The following conditions + * apply to all code found in this distribution, be it the RC4, RSA, + * lhash, DES, etc., code; not just the SSL code. The SSL documentation + * included with this distribution is covered by the same copyright terms + * except that the holder is Tim Hudson (tjh@mincom.oz.au). + * + * Copyright remains Eric Young's, and as such any Copyright notices in + * the code are not to be removed. + * If this package is used in a product, Eric Young should be given attribution + * as the author of the parts of the library used. + * This can be in the form of a textual message at program startup or + * in documentation (online or textual) provided with the package. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * 3. All advertising materials mentioning features or use of this software + * must display the following acknowledgement: + * "This product includes cryptographic software written by + * Eric Young (eay@mincom.oz.au)" + * The word 'cryptographic' can be left out if the rouines from the library + * being used are not cryptographic related :-). + * 4. If you include any Windows specific code (or a derivative thereof) from + * the apps directory (application code) you must include an acknowledgement: + * "This product includes software written by Tim Hudson (tjh@mincom.oz.au)" + * + * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND + * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE + * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE + * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE + * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL + * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS + * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) + * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT + * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY + * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF + * SUCH DAMAGE. + * + * The licence and distribution terms for any publically available version or + * derivative of this code cannot be changed. i.e. this code cannot simply be + * copied and put under another distribution licence + * [including the GNU Public Licence.] + */ + +static const BF_KEY bf_init= { + { + 0x243f6a88L, 0x85a308d3L, 0x13198a2eL, 0x03707344L, + 0xa4093822L, 0x299f31d0L, 0x082efa98L, 0xec4e6c89L, + 0x452821e6L, 0x38d01377L, 0xbe5466cfL, 0x34e90c6cL, + 0xc0ac29b7L, 0xc97c50ddL, 0x3f84d5b5L, 0xb5470917L, + 0x9216d5d9L, 0x8979fb1b + },{ + 0xd1310ba6L, 0x98dfb5acL, 0x2ffd72dbL, 0xd01adfb7L, + 0xb8e1afedL, 0x6a267e96L, 0xba7c9045L, 0xf12c7f99L, + 0x24a19947L, 0xb3916cf7L, 0x0801f2e2L, 0x858efc16L, + 0x636920d8L, 0x71574e69L, 0xa458fea3L, 0xf4933d7eL, + 0x0d95748fL, 0x728eb658L, 0x718bcd58L, 0x82154aeeL, + 0x7b54a41dL, 0xc25a59b5L, 0x9c30d539L, 0x2af26013L, + 0xc5d1b023L, 0x286085f0L, 0xca417918L, 0xb8db38efL, + 0x8e79dcb0L, 0x603a180eL, 0x6c9e0e8bL, 0xb01e8a3eL, + 0xd71577c1L, 0xbd314b27L, 0x78af2fdaL, 0x55605c60L, + 0xe65525f3L, 0xaa55ab94L, 0x57489862L, 0x63e81440L, + 0x55ca396aL, 0x2aab10b6L, 0xb4cc5c34L, 0x1141e8ceL, + 0xa15486afL, 0x7c72e993L, 0xb3ee1411L, 0x636fbc2aL, + 0x2ba9c55dL, 0x741831f6L, 0xce5c3e16L, 0x9b87931eL, + 0xafd6ba33L, 0x6c24cf5cL, 0x7a325381L, 0x28958677L, + 0x3b8f4898L, 0x6b4bb9afL, 0xc4bfe81bL, 0x66282193L, + 0x61d809ccL, 0xfb21a991L, 0x487cac60L, 0x5dec8032L, + 0xef845d5dL, 0xe98575b1L, 0xdc262302L, 0xeb651b88L, + 0x23893e81L, 0xd396acc5L, 0x0f6d6ff3L, 0x83f44239L, + 0x2e0b4482L, 0xa4842004L, 0x69c8f04aL, 0x9e1f9b5eL, + 0x21c66842L, 0xf6e96c9aL, 0x670c9c61L, 0xabd388f0L, + 0x6a51a0d2L, 0xd8542f68L, 0x960fa728L, 0xab5133a3L, + 0x6eef0b6cL, 0x137a3be4L, 0xba3bf050L, 0x7efb2a98L, + 0xa1f1651dL, 0x39af0176L, 0x66ca593eL, 0x82430e88L, + 0x8cee8619L, 0x456f9fb4L, 0x7d84a5c3L, 0x3b8b5ebeL, + 0xe06f75d8L, 0x85c12073L, 0x401a449fL, 0x56c16aa6L, + 0x4ed3aa62L, 0x363f7706L, 0x1bfedf72L, 0x429b023dL, + 0x37d0d724L, 0xd00a1248L, 0xdb0fead3L, 0x49f1c09bL, + 0x075372c9L, 0x80991b7bL, 0x25d479d8L, 0xf6e8def7L, + 0xe3fe501aL, 0xb6794c3bL, 0x976ce0bdL, 0x04c006baL, + 0xc1a94fb6L, 0x409f60c4L, 0x5e5c9ec2L, 0x196a2463L, + 0x68fb6fafL, 0x3e6c53b5L, 0x1339b2ebL, 0x3b52ec6fL, + 0x6dfc511fL, 0x9b30952cL, 0xcc814544L, 0xaf5ebd09L, + 0xbee3d004L, 0xde334afdL, 0x660f2807L, 0x192e4bb3L, + 0xc0cba857L, 0x45c8740fL, 0xd20b5f39L, 0xb9d3fbdbL, + 0x5579c0bdL, 0x1a60320aL, 0xd6a100c6L, 0x402c7279L, + 0x679f25feL, 0xfb1fa3ccL, 0x8ea5e9f8L, 0xdb3222f8L, + 0x3c7516dfL, 0xfd616b15L, 0x2f501ec8L, 0xad0552abL, + 0x323db5faL, 0xfd238760L, 0x53317b48L, 0x3e00df82L, + 0x9e5c57bbL, 0xca6f8ca0L, 0x1a87562eL, 0xdf1769dbL, + 0xd542a8f6L, 0x287effc3L, 0xac6732c6L, 0x8c4f5573L, + 0x695b27b0L, 0xbbca58c8L, 0xe1ffa35dL, 0xb8f011a0L, + 0x10fa3d98L, 0xfd2183b8L, 0x4afcb56cL, 0x2dd1d35bL, + 0x9a53e479L, 0xb6f84565L, 0xd28e49bcL, 0x4bfb9790L, + 0xe1ddf2daL, 0xa4cb7e33L, 0x62fb1341L, 0xcee4c6e8L, + 0xef20cadaL, 0x36774c01L, 0xd07e9efeL, 0x2bf11fb4L, + 0x95dbda4dL, 0xae909198L, 0xeaad8e71L, 0x6b93d5a0L, + 0xd08ed1d0L, 0xafc725e0L, 0x8e3c5b2fL, 0x8e7594b7L, + 0x8ff6e2fbL, 0xf2122b64L, 0x8888b812L, 0x900df01cL, + 0x4fad5ea0L, 0x688fc31cL, 0xd1cff191L, 0xb3a8c1adL, + 0x2f2f2218L, 0xbe0e1777L, 0xea752dfeL, 0x8b021fa1L, + 0xe5a0cc0fL, 0xb56f74e8L, 0x18acf3d6L, 0xce89e299L, + 0xb4a84fe0L, 0xfd13e0b7L, 0x7cc43b81L, 0xd2ada8d9L, + 0x165fa266L, 0x80957705L, 0x93cc7314L, 0x211a1477L, + 0xe6ad2065L, 0x77b5fa86L, 0xc75442f5L, 0xfb9d35cfL, + 0xebcdaf0cL, 0x7b3e89a0L, 0xd6411bd3L, 0xae1e7e49L, + 0x00250e2dL, 0x2071b35eL, 0x226800bbL, 0x57b8e0afL, + 0x2464369bL, 0xf009b91eL, 0x5563911dL, 0x59dfa6aaL, + 0x78c14389L, 0xd95a537fL, 0x207d5ba2L, 0x02e5b9c5L, + 0x83260376L, 0x6295cfa9L, 0x11c81968L, 0x4e734a41L, + 0xb3472dcaL, 0x7b14a94aL, 0x1b510052L, 0x9a532915L, + 0xd60f573fL, 0xbc9bc6e4L, 0x2b60a476L, 0x81e67400L, + 0x08ba6fb5L, 0x571be91fL, 0xf296ec6bL, 0x2a0dd915L, + 0xb6636521L, 0xe7b9f9b6L, 0xff34052eL, 0xc5855664L, + 0x53b02d5dL, 0xa99f8fa1L, 0x08ba4799L, 0x6e85076aL, + 0x4b7a70e9L, 0xb5b32944L, 0xdb75092eL, 0xc4192623L, + 0xad6ea6b0L, 0x49a7df7dL, 0x9cee60b8L, 0x8fedb266L, + 0xecaa8c71L, 0x699a17ffL, 0x5664526cL, 0xc2b19ee1L, + 0x193602a5L, 0x75094c29L, 0xa0591340L, 0xe4183a3eL, + 0x3f54989aL, 0x5b429d65L, 0x6b8fe4d6L, 0x99f73fd6L, + 0xa1d29c07L, 0xefe830f5L, 0x4d2d38e6L, 0xf0255dc1L, + 0x4cdd2086L, 0x8470eb26L, 0x6382e9c6L, 0x021ecc5eL, + 0x09686b3fL, 0x3ebaefc9L, 0x3c971814L, 0x6b6a70a1L, + 0x687f3584L, 0x52a0e286L, 0xb79c5305L, 0xaa500737L, + 0x3e07841cL, 0x7fdeae5cL, 0x8e7d44ecL, 0x5716f2b8L, + 0xb03ada37L, 0xf0500c0dL, 0xf01c1f04L, 0x0200b3ffL, + 0xae0cf51aL, 0x3cb574b2L, 0x25837a58L, 0xdc0921bdL, + 0xd19113f9L, 0x7ca92ff6L, 0x94324773L, 0x22f54701L, + 0x3ae5e581L, 0x37c2dadcL, 0xc8b57634L, 0x9af3dda7L, + 0xa9446146L, 0x0fd0030eL, 0xecc8c73eL, 0xa4751e41L, + 0xe238cd99L, 0x3bea0e2fL, 0x3280bba1L, 0x183eb331L, + 0x4e548b38L, 0x4f6db908L, 0x6f420d03L, 0xf60a04bfL, + 0x2cb81290L, 0x24977c79L, 0x5679b072L, 0xbcaf89afL, + 0xde9a771fL, 0xd9930810L, 0xb38bae12L, 0xdccf3f2eL, + 0x5512721fL, 0x2e6b7124L, 0x501adde6L, 0x9f84cd87L, + 0x7a584718L, 0x7408da17L, 0xbc9f9abcL, 0xe94b7d8cL, + 0xec7aec3aL, 0xdb851dfaL, 0x63094366L, 0xc464c3d2L, + 0xef1c1847L, 0x3215d908L, 0xdd433b37L, 0x24c2ba16L, + 0x12a14d43L, 0x2a65c451L, 0x50940002L, 0x133ae4ddL, + 0x71dff89eL, 0x10314e55L, 0x81ac77d6L, 0x5f11199bL, + 0x043556f1L, 0xd7a3c76bL, 0x3c11183bL, 0x5924a509L, + 0xf28fe6edL, 0x97f1fbfaL, 0x9ebabf2cL, 0x1e153c6eL, + 0x86e34570L, 0xeae96fb1L, 0x860e5e0aL, 0x5a3e2ab3L, + 0x771fe71cL, 0x4e3d06faL, 0x2965dcb9L, 0x99e71d0fL, + 0x803e89d6L, 0x5266c825L, 0x2e4cc978L, 0x9c10b36aL, + 0xc6150ebaL, 0x94e2ea78L, 0xa5fc3c53L, 0x1e0a2df4L, + 0xf2f74ea7L, 0x361d2b3dL, 0x1939260fL, 0x19c27960L, + 0x5223a708L, 0xf71312b6L, 0xebadfe6eL, 0xeac31f66L, + 0xe3bc4595L, 0xa67bc883L, 0xb17f37d1L, 0x018cff28L, + 0xc332ddefL, 0xbe6c5aa5L, 0x65582185L, 0x68ab9802L, + 0xeecea50fL, 0xdb2f953bL, 0x2aef7dadL, 0x5b6e2f84L, + 0x1521b628L, 0x29076170L, 0xecdd4775L, 0x619f1510L, + 0x13cca830L, 0xeb61bd96L, 0x0334fe1eL, 0xaa0363cfL, + 0xb5735c90L, 0x4c70a239L, 0xd59e9e0bL, 0xcbaade14L, + 0xeecc86bcL, 0x60622ca7L, 0x9cab5cabL, 0xb2f3846eL, + 0x648b1eafL, 0x19bdf0caL, 0xa02369b9L, 0x655abb50L, + 0x40685a32L, 0x3c2ab4b3L, 0x319ee9d5L, 0xc021b8f7L, + 0x9b540b19L, 0x875fa099L, 0x95f7997eL, 0x623d7da8L, + 0xf837889aL, 0x97e32d77L, 0x11ed935fL, 0x16681281L, + 0x0e358829L, 0xc7e61fd6L, 0x96dedfa1L, 0x7858ba99L, + 0x57f584a5L, 0x1b227263L, 0x9b83c3ffL, 0x1ac24696L, + 0xcdb30aebL, 0x532e3054L, 0x8fd948e4L, 0x6dbc3128L, + 0x58ebf2efL, 0x34c6ffeaL, 0xfe28ed61L, 0xee7c3c73L, + 0x5d4a14d9L, 0xe864b7e3L, 0x42105d14L, 0x203e13e0L, + 0x45eee2b6L, 0xa3aaabeaL, 0xdb6c4f15L, 0xfacb4fd0L, + 0xc742f442L, 0xef6abbb5L, 0x654f3b1dL, 0x41cd2105L, + 0xd81e799eL, 0x86854dc7L, 0xe44b476aL, 0x3d816250L, + 0xcf62a1f2L, 0x5b8d2646L, 0xfc8883a0L, 0xc1c7b6a3L, + 0x7f1524c3L, 0x69cb7492L, 0x47848a0bL, 0x5692b285L, + 0x095bbf00L, 0xad19489dL, 0x1462b174L, 0x23820e00L, + 0x58428d2aL, 0x0c55f5eaL, 0x1dadf43eL, 0x233f7061L, + 0x3372f092L, 0x8d937e41L, 0xd65fecf1L, 0x6c223bdbL, + 0x7cde3759L, 0xcbee7460L, 0x4085f2a7L, 0xce77326eL, + 0xa6078084L, 0x19f8509eL, 0xe8efd855L, 0x61d99735L, + 0xa969a7aaL, 0xc50c06c2L, 0x5a04abfcL, 0x800bcadcL, + 0x9e447a2eL, 0xc3453484L, 0xfdd56705L, 0x0e1e9ec9L, + 0xdb73dbd3L, 0x105588cdL, 0x675fda79L, 0xe3674340L, + 0xc5c43465L, 0x713e38d8L, 0x3d28f89eL, 0xf16dff20L, + 0x153e21e7L, 0x8fb03d4aL, 0xe6e39f2bL, 0xdb83adf7L, + 0xe93d5a68L, 0x948140f7L, 0xf64c261cL, 0x94692934L, + 0x411520f7L, 0x7602d4f7L, 0xbcf46b2eL, 0xd4a20068L, + 0xd4082471L, 0x3320f46aL, 0x43b7d4b7L, 0x500061afL, + 0x1e39f62eL, 0x97244546L, 0x14214f74L, 0xbf8b8840L, + 0x4d95fc1dL, 0x96b591afL, 0x70f4ddd3L, 0x66a02f45L, + 0xbfbc09ecL, 0x03bd9785L, 0x7fac6dd0L, 0x31cb8504L, + 0x96eb27b3L, 0x55fd3941L, 0xda2547e6L, 0xabca0a9aL, + 0x28507825L, 0x530429f4L, 0x0a2c86daL, 0xe9b66dfbL, + 0x68dc1462L, 0xd7486900L, 0x680ec0a4L, 0x27a18deeL, + 0x4f3ffea2L, 0xe887ad8cL, 0xb58ce006L, 0x7af4d6b6L, + 0xaace1e7cL, 0xd3375fecL, 0xce78a399L, 0x406b2a42L, + 0x20fe9e35L, 0xd9f385b9L, 0xee39d7abL, 0x3b124e8bL, + 0x1dc9faf7L, 0x4b6d1856L, 0x26a36631L, 0xeae397b2L, + 0x3a6efa74L, 0xdd5b4332L, 0x6841e7f7L, 0xca7820fbL, + 0xfb0af54eL, 0xd8feb397L, 0x454056acL, 0xba489527L, + 0x55533a3aL, 0x20838d87L, 0xfe6ba9b7L, 0xd096954bL, + 0x55a867bcL, 0xa1159a58L, 0xcca92963L, 0x99e1db33L, + 0xa62a4a56L, 0x3f3125f9L, 0x5ef47e1cL, 0x9029317cL, + 0xfdf8e802L, 0x04272f70L, 0x80bb155cL, 0x05282ce3L, + 0x95c11548L, 0xe4c66d22L, 0x48c1133fL, 0xc70f86dcL, + 0x07f9c9eeL, 0x41041f0fL, 0x404779a4L, 0x5d886e17L, + 0x325f51ebL, 0xd59bc0d1L, 0xf2bcc18fL, 0x41113564L, + 0x257b7834L, 0x602a9c60L, 0xdff8e8a3L, 0x1f636c1bL, + 0x0e12b4c2L, 0x02e1329eL, 0xaf664fd1L, 0xcad18115L, + 0x6b2395e0L, 0x333e92e1L, 0x3b240b62L, 0xeebeb922L, + 0x85b2a20eL, 0xe6ba0d99L, 0xde720c8cL, 0x2da2f728L, + 0xd0127845L, 0x95b794fdL, 0x647d0862L, 0xe7ccf5f0L, + 0x5449a36fL, 0x877d48faL, 0xc39dfd27L, 0xf33e8d1eL, + 0x0a476341L, 0x992eff74L, 0x3a6f6eabL, 0xf4f8fd37L, + 0xa812dc60L, 0xa1ebddf8L, 0x991be14cL, 0xdb6e6b0dL, + 0xc67b5510L, 0x6d672c37L, 0x2765d43bL, 0xdcd0e804L, + 0xf1290dc7L, 0xcc00ffa3L, 0xb5390f92L, 0x690fed0bL, + 0x667b9ffbL, 0xcedb7d9cL, 0xa091cf0bL, 0xd9155ea3L, + 0xbb132f88L, 0x515bad24L, 0x7b9479bfL, 0x763bd6ebL, + 0x37392eb3L, 0xcc115979L, 0x8026e297L, 0xf42e312dL, + 0x6842ada7L, 0xc66a2b3bL, 0x12754cccL, 0x782ef11cL, + 0x6a124237L, 0xb79251e7L, 0x06a1bbe6L, 0x4bfb6350L, + 0x1a6b1018L, 0x11caedfaL, 0x3d25bdd8L, 0xe2e1c3c9L, + 0x44421659L, 0x0a121386L, 0xd90cec6eL, 0xd5abea2aL, + 0x64af674eL, 0xda86a85fL, 0xbebfe988L, 0x64e4c3feL, + 0x9dbc8057L, 0xf0f7c086L, 0x60787bf8L, 0x6003604dL, + 0xd1fd8346L, 0xf6381fb0L, 0x7745ae04L, 0xd736fcccL, + 0x83426b33L, 0xf01eab71L, 0xb0804187L, 0x3c005e5fL, + 0x77a057beL, 0xbde8ae24L, 0x55464299L, 0xbf582e61L, + 0x4e58f48fL, 0xf2ddfda2L, 0xf474ef38L, 0x8789bdc2L, + 0x5366f9c3L, 0xc8b38e74L, 0xb475f255L, 0x46fcd9b9L, + 0x7aeb2661L, 0x8b1ddf84L, 0x846a0e79L, 0x915f95e2L, + 0x466e598eL, 0x20b45770L, 0x8cd55591L, 0xc902de4cL, + 0xb90bace1L, 0xbb8205d0L, 0x11a86248L, 0x7574a99eL, + 0xb77f19b6L, 0xe0a9dc09L, 0x662d09a1L, 0xc4324633L, + 0xe85a1f02L, 0x09f0be8cL, 0x4a99a025L, 0x1d6efe10L, + 0x1ab93d1dL, 0x0ba5a4dfL, 0xa186f20fL, 0x2868f169L, + 0xdcb7da83L, 0x573906feL, 0xa1e2ce9bL, 0x4fcd7f52L, + 0x50115e01L, 0xa70683faL, 0xa002b5c4L, 0x0de6d027L, + 0x9af88c27L, 0x773f8641L, 0xc3604c06L, 0x61a806b5L, + 0xf0177a28L, 0xc0f586e0L, 0x006058aaL, 0x30dc7d62L, + 0x11e69ed7L, 0x2338ea63L, 0x53c2dd94L, 0xc2c21634L, + 0xbbcbee56L, 0x90bcb6deL, 0xebfc7da1L, 0xce591d76L, + 0x6f05e409L, 0x4b7c0188L, 0x39720a3dL, 0x7c927c24L, + 0x86e3725fL, 0x724d9db9L, 0x1ac15bb4L, 0xd39eb8fcL, + 0xed545578L, 0x08fca5b5L, 0xd83d7cd3L, 0x4dad0fc4L, + 0x1e50ef5eL, 0xb161e6f8L, 0xa28514d9L, 0x6c51133cL, + 0x6fd5c7e7L, 0x56e14ec4L, 0x362abfceL, 0xddc6c837L, + 0xd79a3234L, 0x92638212L, 0x670efa8eL, 0x406000e0L, + 0x3a39ce37L, 0xd3faf5cfL, 0xabc27737L, 0x5ac52d1bL, + 0x5cb0679eL, 0x4fa33742L, 0xd3822740L, 0x99bc9bbeL, + 0xd5118e9dL, 0xbf0f7315L, 0xd62d1c7eL, 0xc700c47bL, + 0xb78c1b6bL, 0x21a19045L, 0xb26eb1beL, 0x6a366eb4L, + 0x5748ab2fL, 0xbc946e79L, 0xc6a376d2L, 0x6549c2c8L, + 0x530ff8eeL, 0x468dde7dL, 0xd5730a1dL, 0x4cd04dc6L, + 0x2939bbdbL, 0xa9ba4650L, 0xac9526e8L, 0xbe5ee304L, + 0xa1fad5f0L, 0x6a2d519aL, 0x63ef8ce2L, 0x9a86ee22L, + 0xc089c2b8L, 0x43242ef6L, 0xa51e03aaL, 0x9cf2d0a4L, + 0x83c061baL, 0x9be96a4dL, 0x8fe51550L, 0xba645bd6L, + 0x2826a2f9L, 0xa73a3ae1L, 0x4ba99586L, 0xef5562e9L, + 0xc72fefd3L, 0xf752f7daL, 0x3f046f69L, 0x77fa0a59L, + 0x80e4a915L, 0x87b08601L, 0x9b09e6adL, 0x3b3ee593L, + 0xe990fd5aL, 0x9e34d797L, 0x2cf0b7d9L, 0x022b8b51L, + 0x96d5ac3aL, 0x017da67dL, 0xd1cf3ed6L, 0x7c7d2d28L, + 0x1f9f25cfL, 0xadf2b89bL, 0x5ad6b472L, 0x5a88f54cL, + 0xe029ac71L, 0xe019a5e6L, 0x47b0acfdL, 0xed93fa9bL, + 0xe8d3c48dL, 0x283b57ccL, 0xf8d56629L, 0x79132e28L, + 0x785f0191L, 0xed756055L, 0xf7960e44L, 0xe3d35e8cL, + 0x15056dd4L, 0x88f46dbaL, 0x03a16125L, 0x0564f0bdL, + 0xc3eb9e15L, 0x3c9057a2L, 0x97271aecL, 0xa93a072aL, + 0x1b3f6d9bL, 0x1e6321f5L, 0xf59c66fbL, 0x26dcf319L, + 0x7533d928L, 0xb155fdf5L, 0x03563482L, 0x8aba3cbbL, + 0x28517711L, 0xc20ad9f8L, 0xabcc5167L, 0xccad925fL, + 0x4de81751L, 0x3830dc8eL, 0x379d5862L, 0x9320f991L, + 0xea7a90c2L, 0xfb3e7bceL, 0x5121ce64L, 0x774fbe32L, + 0xa8b6e37eL, 0xc3293d46L, 0x48de5369L, 0x6413e680L, + 0xa2ae0810L, 0xdd6db224L, 0x69852dfdL, 0x09072166L, + 0xb39a460aL, 0x6445c0ddL, 0x586cdecfL, 0x1c20c8aeL, + 0x5bbef7ddL, 0x1b588d40L, 0xccd2017fL, 0x6bb4e3bbL, + 0xdda26a7eL, 0x3a59ff45L, 0x3e350a44L, 0xbcb4cdd5L, + 0x72eacea8L, 0xfa6484bbL, 0x8d6612aeL, 0xbf3c6f47L, + 0xd29be463L, 0x542f5d9eL, 0xaec2771bL, 0xf64e6370L, + 0x740e0d8dL, 0xe75b1357L, 0xf8721671L, 0xaf537d5dL, + 0x4040cb08L, 0x4eb4e2ccL, 0x34d2466aL, 0x0115af84L, + 0xe1b00428L, 0x95983a1dL, 0x06b89fb4L, 0xce6ea048L, + 0x6f3f3b82L, 0x3520ab82L, 0x011a1d4bL, 0x277227f8L, + 0x611560b1L, 0xe7933fdcL, 0xbb3a792bL, 0x344525bdL, + 0xa08839e1L, 0x51ce794bL, 0x2f32c9b7L, 0xa01fbac9L, + 0xe01cc87eL, 0xbcc7d1f6L, 0xcf0111c3L, 0xa1e8aac7L, + 0x1a908749L, 0xd44fbd9aL, 0xd0dadecbL, 0xd50ada38L, + 0x0339c32aL, 0xc6913667L, 0x8df9317cL, 0xe0b12b4fL, + 0xf79e59b7L, 0x43f5bb3aL, 0xf2d519ffL, 0x27d9459cL, + 0xbf97222cL, 0x15e6fc2aL, 0x0f91fc71L, 0x9b941525L, + 0xfae59361L, 0xceb69cebL, 0xc2a86459L, 0x12baa8d1L, + 0xb6c1075eL, 0xe3056a0cL, 0x10d25065L, 0xcb03a442L, + 0xe0ec6e0eL, 0x1698db3bL, 0x4c98a0beL, 0x3278e964L, + 0x9f1f9532L, 0xe0d392dfL, 0xd3a0342bL, 0x8971f21eL, + 0x1b0a7441L, 0x4ba3348cL, 0xc5be7120L, 0xc37632d8L, + 0xdf359f8dL, 0x9b992f2eL, 0xe60b6f47L, 0x0fe3f11dL, + 0xe54cda54L, 0x1edad891L, 0xce6279cfL, 0xcd3e7e6fL, + 0x1618b166L, 0xfd2c1d05L, 0x848fd2c5L, 0xf6fb2299L, + 0xf523f357L, 0xa6327623L, 0x93a83531L, 0x56cccd02L, + 0xacf08162L, 0x5a75ebb5L, 0x6e163697L, 0x88d273ccL, + 0xde966292L, 0x81b949d0L, 0x4c50901bL, 0x71c65614L, + 0xe6c6c7bdL, 0x327a140aL, 0x45e1d006L, 0xc3f27b9aL, + 0xc9aa53fdL, 0x62a80f00L, 0xbb25bfe2L, 0x35bdd2f6L, + 0x71126905L, 0xb2040222L, 0xb6cbcf7cL, 0xcd769c2bL, + 0x53113ec0L, 0x1640e3d3L, 0x38abbd60L, 0x2547adf0L, + 0xba38209cL, 0xf746ce76L, 0x77afa1c5L, 0x20756060L, + 0x85cbfe4eL, 0x8ae88dd8L, 0x7aaaf9b0L, 0x4cf9aa7eL, + 0x1948c25cL, 0x02fb8a8cL, 0x01c36ae4L, 0xd6ebe1f9L, + 0x90d4f869L, 0xa65cdea0L, 0x3f09252dL, 0xc208e69fL, + 0xb74e6132L, 0xce77e25bL, 0x578fdfe3L, 0x3ac372e6L, + } + }; + diff --git a/sys/crypto/blowfish/bf_skey.c b/sys/crypto/blowfish/bf_skey.c new file mode 100644 index 000000000..45ecc84cc --- /dev/null +++ b/sys/crypto/blowfish/bf_skey.c @@ -0,0 +1,124 @@ +/* $NetBSD: bf_skey.c,v 1.6 2005/12/11 12:20:48 christos Exp $ */ +/* $KAME: bf_skey.c,v 1.5 2000/11/06 13:58:08 itojun Exp $ */ + +/* crypto/bf/bf_skey.c */ +/* Copyright (C) 1995-1997 Eric Young (eay@mincom.oz.au) + * All rights reserved. + * + * This package is an SSL implementation written + * by Eric Young (eay@mincom.oz.au). + * The implementation was written so as to conform with Netscapes SSL. + * + * This library is free for commercial and non-commercial use as long as + * the following conditions are aheared to. The following conditions + * apply to all code found in this distribution, be it the RC4, RSA, + * lhash, DES, etc., code; not just the SSL code. The SSL documentation + * included with this distribution is covered by the same copyright terms + * except that the holder is Tim Hudson (tjh@mincom.oz.au). + * + * Copyright remains Eric Young's, and as such any Copyright notices in + * the code are not to be removed. + * If this package is used in a product, Eric Young should be given attribution + * as the author of the parts of the library used. + * This can be in the form of a textual message at program startup or + * in documentation (online or textual) provided with the package. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * 3. All advertising materials mentioning features or use of this software + * must display the following acknowledgement: + * "This product includes cryptographic software written by + * Eric Young (eay@mincom.oz.au)" + * The word 'cryptographic' can be left out if the rouines from the library + * being used are not cryptographic related :-). + * 4. If you include any Windows specific code (or a derivative thereof) from + * the apps directory (application code) you must include an acknowledgement: + * "This product includes software written by Tim Hudson (tjh@mincom.oz.au)" + * + * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND + * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE + * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE + * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE + * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL + * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS + * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) + * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT + * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY + * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF + * SUCH DAMAGE. + * + * The licence and distribution terms for any publically available version or + * derivative of this code cannot be changed. i.e. this code cannot simply be + * copied and put under another distribution licence + * [including the GNU Public Licence.] + */ + +#include +__KERNEL_RCSID(0, "$NetBSD: bf_skey.c,v 1.6 2005/12/11 12:20:48 christos Exp $"); + +#include +#include +#ifdef _KERNEL +#include +#else +#include +#endif +#include +#include +#include + +void +BF_set_key(BF_KEY *key, int len, const unsigned char *data) +{ + int i; + BF_LONG *p, ri, in[2]; + const unsigned char *d, *end; + + memcpy(key, &bf_init, sizeof(BF_KEY)); + p = key->P; + + if (len > ((BF_ROUNDS + 2) * 4)) + len = (BF_ROUNDS + 2) * 4; + + d = data; + end= &(data[len]); + for (i = 0; i < BF_ROUNDS + 2; i++) { + ri = *(d++); + if (d >= end) d = data; + + ri <<= 8; + ri |= *(d++); + if (d >= end) d = data; + + ri <<= 8; + ri |= *(d++); + if (d >= end) d = data; + + ri <<= 8; + ri |= *(d++); + if (d >= end) d = data; + + p[i] ^= ri; + } + + in[0] = 0L; + in[1] = 0L; + for (i = 0; i < BF_ROUNDS + 2; i += 2) { + BF_encrypt(in, key); + p[i ] = in[0]; + p[i+1] = in[1]; + } + + p = key->S; + for (i = 0; i < 4 * 256; i += 2) { + BF_encrypt(in, key); + p[i ] = in[0]; + p[i+1] = in[1]; + } +} diff --git a/sys/crypto/blowfish/blowfish.h b/sys/crypto/blowfish/blowfish.h new file mode 100644 index 000000000..3cf2f4a11 --- /dev/null +++ b/sys/crypto/blowfish/blowfish.h @@ -0,0 +1,95 @@ +/* $NetBSD: blowfish.h,v 1.8 2009/03/14 14:46:08 dsl Exp $ */ +/* $KAME: blowfish.h,v 1.10 2000/09/18 21:21:20 itojun Exp $ */ + +/* crypto/bf/blowfish.h */ +/* Copyright (C) 1995-1997 Eric Young (eay@mincom.oz.au) + * All rights reserved. + * + * This package is an SSL implementation written + * by Eric Young (eay@mincom.oz.au). + * The implementation was written so as to conform with Netscapes SSL. + * + * This library is free for commercial and non-commercial use as long as + * the following conditions are aheared to. The following conditions + * apply to all code found in this distribution, be it the RC4, RSA, + * lhash, DES, etc., code; not just the SSL code. The SSL documentation + * included with this distribution is covered by the same copyright terms + * except that the holder is Tim Hudson (tjh@mincom.oz.au). + * + * Copyright remains Eric Young's, and as such any Copyright notices in + * the code are not to be removed. + * If this package is used in a product, Eric Young should be given attribution + * as the author of the parts of the library used. + * This can be in the form of a textual message at program startup or + * in documentation (online or textual) provided with the package. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * 3. All advertising materials mentioning features or use of this software + * must display the following acknowledgement: + * "This product includes cryptographic software written by + * Eric Young (eay@mincom.oz.au)" + * The word 'cryptographic' can be left out if the rouines from the library + * being used are not cryptographic related :-). + * 4. If you include any Windows specific code (or a derivative thereof) from + * the apps directory (application code) you must include an acknowledgement: + * "This product includes software written by Tim Hudson (tjh@mincom.oz.au)" + * + * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND + * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE + * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE + * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE + * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL + * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS + * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) + * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT + * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY + * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF + * SUCH DAMAGE. + * + * The licence and distribution terms for any publically available version or + * derivative of this code cannot be changed. i.e. this code cannot simply be + * copied and put under another distribution licence + * [including the GNU Public Licence.] + */ + +#ifndef HEADER_BLOWFISH_H +#define HEADER_BLOWFISH_H + +#ifdef __cplusplus +extern "C" { +#endif + +#define BF_ENCRYPT 1 +#define BF_DECRYPT 0 + +/* must be 32bit quantity */ +#define BF_LONG u_int32_t + +#define BF_ROUNDS 16 +#define BF_BLOCK 8 + +typedef struct bf_key_st { + BF_LONG P[BF_ROUNDS+2]; + BF_LONG S[4*256]; +} BF_KEY; + +void BF_set_key(BF_KEY *, int, const unsigned char *); +void BF_encrypt(BF_LONG *, const BF_KEY *); +void BF_decrypt(BF_LONG *, const BF_KEY *); +void BF_cbc_encrypt(const unsigned char *, unsigned char *, long, + const BF_KEY *, unsigned char *, int); +void BF_ecb_encrypt(const unsigned char *, unsigned char *, + const BF_KEY *, int); + +#ifdef __cplusplus +} +#endif + +#endif diff --git a/sys/crypto/blowfish/files.blowfish b/sys/crypto/blowfish/files.blowfish new file mode 100644 index 000000000..9ba9a35c2 --- /dev/null +++ b/sys/crypto/blowfish/files.blowfish @@ -0,0 +1,9 @@ +# $NetBSD: files.blowfish,v 1.4 2014/01/01 15:18:57 pgoyette Exp $ + +define blowfish + +file crypto/blowfish/bf_module.c blowfish +file crypto/blowfish/bf_ecb.c blowfish +file crypto/blowfish/bf_enc.c blowfish +file crypto/blowfish/bf_cbc.c blowfish +file crypto/blowfish/bf_skey.c blowfish diff --git a/sys/crypto/camellia/camellia-api.c b/sys/crypto/camellia/camellia-api.c new file mode 100644 index 000000000..992c0f062 --- /dev/null +++ b/sys/crypto/camellia/camellia-api.c @@ -0,0 +1,55 @@ +/* $NetBSD: camellia-api.c,v 1.1 2011/05/05 17:38:36 drochner Exp $ */ + +/* + * + * Copyright (c) 2006 + * NTT (Nippon Telegraph and Telephone Corporation) . All rights reserved. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the above copyright + * notice, this list of conditions and the following disclaimer as + * the first lines of this file unmodified. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * + * THIS SOFTWARE IS PROVIDED BY NTT ``AS IS'' AND ANY EXPRESS OR + * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES + * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. + * IN NO EVENT SHALL NTT BE LIABLE FOR ANY DIRECT, INDIRECT, + * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT + * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, + * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY + * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT + * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF + * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + */ + +#include + +#include +#include + +void +camellia_set_key(camellia_ctx *ctx, const u_char *key, int bits) +{ + + Camellia_Ekeygen(bits, key, ctx->subkey); + ctx->bits = bits; +} + +void +camellia_decrypt(const camellia_ctx *ctx, const u_char *src, u_char *dst) +{ + + Camellia_DecryptBlock(ctx->bits, src, ctx->subkey, dst); +} + +void +camellia_encrypt(const camellia_ctx *ctx, const u_char *src, u_char *dst) +{ + + Camellia_EncryptBlock(ctx->bits, src, ctx->subkey, dst); +} diff --git a/sys/crypto/camellia/camellia.c b/sys/crypto/camellia/camellia.c new file mode 100644 index 000000000..d1bf528a5 --- /dev/null +++ b/sys/crypto/camellia/camellia.c @@ -0,0 +1,1342 @@ +/* $NetBSD: camellia.c,v 1.2 2014/01/01 15:18:57 pgoyette Exp $ */ + +/* camellia.h ver 1.1.0 + * + * Copyright (c) 2006 + * NTT (Nippon Telegraph and Telephone Corporation) . All rights reserved. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the above copyright + * notice, this list of conditions and the following disclaimer as + * the first lines of this file unmodified. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * + * THIS SOFTWARE IS PROVIDED BY NTT ``AS IS'' AND ANY EXPRESS OR + * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES + * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. + * IN NO EVENT SHALL NTT BE LIABLE FOR ANY DIRECT, INDIRECT, + * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT + * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, + * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY + * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT + * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF + * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + */ + +/* + * Algorithm Specification + * http://info.isl.ntt.co.jp/crypt/eng/camellia/specifications.html + */ + +#include +#include +#include +#include +#include + +#include + + +/* key constants */ + +#define CAMELLIA_SIGMA1L (0xA09E667FL) +#define CAMELLIA_SIGMA1R (0x3BCC908BL) +#define CAMELLIA_SIGMA2L (0xB67AE858L) +#define CAMELLIA_SIGMA2R (0x4CAA73B2L) +#define CAMELLIA_SIGMA3L (0xC6EF372FL) +#define CAMELLIA_SIGMA3R (0xE94F82BEL) +#define CAMELLIA_SIGMA4L (0x54FF53A5L) +#define CAMELLIA_SIGMA4R (0xF1D36F1CL) +#define CAMELLIA_SIGMA5L (0x10E527FAL) +#define CAMELLIA_SIGMA5R (0xDE682D1DL) +#define CAMELLIA_SIGMA6L (0xB05688C2L) +#define CAMELLIA_SIGMA6R (0xB3E6C1FDL) + +/* + * macros + */ +#define GETU32(pt) (((uint32_t)(pt)[0] << 24) \ + ^ ((uint32_t)(pt)[1] << 16) \ + ^ ((uint32_t)(pt)[2] << 8) \ + ^ ((uint32_t)(pt)[3])) + +#define PUTU32(ct, st) {(ct)[0] = (uint8_t)((st) >> 24); \ + (ct)[1] = (uint8_t)((st) >> 16); \ + (ct)[2] = (uint8_t)((st) >> 8); \ + (ct)[3] = (uint8_t)(st);} + +#define SUBL(INDEX) (subkey[(INDEX)*2+1]) +#define SUBR(INDEX) (subkey[(INDEX)*2]) + +#define CAMELLIA_RR8(x) (((x) >> 8) + ((x) << 24)) +#define CAMELLIA_RL1(x) (((x) << 1) + ((x) >> 31)) +#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24)) + +#define CAMELLIA_ROLDQ(ll, lr, rl, rr, w0, w1, bits) \ + do { \ + w0 = ll; \ + ll = (ll << bits) + (lr >> (32 - bits)); \ + lr = (lr << bits) + (rl >> (32 - bits)); \ + rl = (rl << bits) + (rr >> (32 - bits)); \ + rr = (rr << bits) + (w0 >> (32 - bits)); \ + } while(0) + +#define CAMELLIA_ROLDQo32(ll, lr, rl, rr, w0, w1, bits) \ + do { \ + w0 = ll; \ + w1 = lr; \ + ll = (lr << (bits - 32)) + (rl >> (64 - bits)); \ + lr = (rl << (bits - 32)) + (rr >> (64 - bits)); \ + rl = (rr << (bits - 32)) + (w0 >> (64 - bits)); \ + rr = (w0 << (bits - 32)) + (w1 >> (64 - bits)); \ + } while(0) + +#define CAMELLIA_SP1110(INDEX) (camellia_sp1110[(INDEX)]) +#define CAMELLIA_SP0222(INDEX) (camellia_sp0222[(INDEX)]) +#define CAMELLIA_SP3033(INDEX) (camellia_sp3033[(INDEX)]) +#define CAMELLIA_SP4404(INDEX) (camellia_sp4404[(INDEX)]) + +#define CAMELLIA_F(xl, xr, kl, kr, yl, yr, il, ir, t0, t1) \ + do { \ + il = xl ^ kl; \ + ir = xr ^ kr; \ + t0 = il >> 16; \ + t1 = ir >> 16; \ + yl = CAMELLIA_SP1110(ir & 0xff) \ + ^ CAMELLIA_SP0222((t1 >> 8) & 0xff) \ + ^ CAMELLIA_SP3033(t1 & 0xff) \ + ^ CAMELLIA_SP4404((ir >> 8) & 0xff); \ + yr = CAMELLIA_SP1110((t0 >> 8) & 0xff) \ + ^ CAMELLIA_SP0222(t0 & 0xff) \ + ^ CAMELLIA_SP3033((il >> 8) & 0xff) \ + ^ CAMELLIA_SP4404(il & 0xff); \ + yl ^= yr; \ + yr = CAMELLIA_RR8(yr); \ + yr ^= yl; \ + } while(0) + + +#define CAMELLIA_FLS(ll, lr, rl, rr, kll, klr, krl, krr, t0, t1, t2, t3) \ + do { \ + t0 = kll; \ + t2 = krr; \ + t0 &= ll; \ + t2 |= rr; \ + rl ^= t2; \ + lr ^= CAMELLIA_RL1(t0); \ + t3 = krl; \ + t1 = klr; \ + t3 &= rl; \ + t1 |= lr; \ + ll ^= t1; \ + rr ^= CAMELLIA_RL1(t3); \ + } while(0) + +#define CAMELLIA_ROUNDSM(xl, xr, kl, kr, yl, yr, il, ir, t0, t1) \ + do { \ + ir = CAMELLIA_SP1110(xr & 0xff); \ + il = CAMELLIA_SP1110((xl>>24) & 0xff); \ + ir ^= CAMELLIA_SP0222((xr>>24) & 0xff); \ + il ^= CAMELLIA_SP0222((xl>>16) & 0xff); \ + ir ^= CAMELLIA_SP3033((xr>>16) & 0xff); \ + il ^= CAMELLIA_SP3033((xl>>8) & 0xff); \ + ir ^= CAMELLIA_SP4404((xr>>8) & 0xff); \ + il ^= CAMELLIA_SP4404(xl & 0xff); \ + il ^= kl; \ + ir ^= kr; \ + ir ^= il; \ + il = CAMELLIA_RR8(il); \ + il ^= ir; \ + yl ^= ir; \ + yr ^= il; \ + } while(0) + + +static const uint32_t camellia_sp1110[256] = { + 0x70707000,0x82828200,0x2c2c2c00,0xececec00, + 0xb3b3b300,0x27272700,0xc0c0c000,0xe5e5e500, + 0xe4e4e400,0x85858500,0x57575700,0x35353500, + 0xeaeaea00,0x0c0c0c00,0xaeaeae00,0x41414100, + 0x23232300,0xefefef00,0x6b6b6b00,0x93939300, + 0x45454500,0x19191900,0xa5a5a500,0x21212100, + 0xededed00,0x0e0e0e00,0x4f4f4f00,0x4e4e4e00, + 0x1d1d1d00,0x65656500,0x92929200,0xbdbdbd00, + 0x86868600,0xb8b8b800,0xafafaf00,0x8f8f8f00, + 0x7c7c7c00,0xebebeb00,0x1f1f1f00,0xcecece00, + 0x3e3e3e00,0x30303000,0xdcdcdc00,0x5f5f5f00, + 0x5e5e5e00,0xc5c5c500,0x0b0b0b00,0x1a1a1a00, + 0xa6a6a600,0xe1e1e100,0x39393900,0xcacaca00, + 0xd5d5d500,0x47474700,0x5d5d5d00,0x3d3d3d00, + 0xd9d9d900,0x01010100,0x5a5a5a00,0xd6d6d600, + 0x51515100,0x56565600,0x6c6c6c00,0x4d4d4d00, + 0x8b8b8b00,0x0d0d0d00,0x9a9a9a00,0x66666600, + 0xfbfbfb00,0xcccccc00,0xb0b0b000,0x2d2d2d00, + 0x74747400,0x12121200,0x2b2b2b00,0x20202000, + 0xf0f0f000,0xb1b1b100,0x84848400,0x99999900, + 0xdfdfdf00,0x4c4c4c00,0xcbcbcb00,0xc2c2c200, + 0x34343400,0x7e7e7e00,0x76767600,0x05050500, + 0x6d6d6d00,0xb7b7b700,0xa9a9a900,0x31313100, + 0xd1d1d100,0x17171700,0x04040400,0xd7d7d700, + 0x14141400,0x58585800,0x3a3a3a00,0x61616100, + 0xdedede00,0x1b1b1b00,0x11111100,0x1c1c1c00, + 0x32323200,0x0f0f0f00,0x9c9c9c00,0x16161600, + 0x53535300,0x18181800,0xf2f2f200,0x22222200, + 0xfefefe00,0x44444400,0xcfcfcf00,0xb2b2b200, + 0xc3c3c300,0xb5b5b500,0x7a7a7a00,0x91919100, + 0x24242400,0x08080800,0xe8e8e800,0xa8a8a800, + 0x60606000,0xfcfcfc00,0x69696900,0x50505000, + 0xaaaaaa00,0xd0d0d000,0xa0a0a000,0x7d7d7d00, + 0xa1a1a100,0x89898900,0x62626200,0x97979700, + 0x54545400,0x5b5b5b00,0x1e1e1e00,0x95959500, + 0xe0e0e000,0xffffff00,0x64646400,0xd2d2d200, + 0x10101000,0xc4c4c400,0x00000000,0x48484800, + 0xa3a3a300,0xf7f7f700,0x75757500,0xdbdbdb00, + 0x8a8a8a00,0x03030300,0xe6e6e600,0xdadada00, + 0x09090900,0x3f3f3f00,0xdddddd00,0x94949400, + 0x87878700,0x5c5c5c00,0x83838300,0x02020200, + 0xcdcdcd00,0x4a4a4a00,0x90909000,0x33333300, + 0x73737300,0x67676700,0xf6f6f600,0xf3f3f300, + 0x9d9d9d00,0x7f7f7f00,0xbfbfbf00,0xe2e2e200, + 0x52525200,0x9b9b9b00,0xd8d8d800,0x26262600, + 0xc8c8c800,0x37373700,0xc6c6c600,0x3b3b3b00, + 0x81818100,0x96969600,0x6f6f6f00,0x4b4b4b00, + 0x13131300,0xbebebe00,0x63636300,0x2e2e2e00, + 0xe9e9e900,0x79797900,0xa7a7a700,0x8c8c8c00, + 0x9f9f9f00,0x6e6e6e00,0xbcbcbc00,0x8e8e8e00, + 0x29292900,0xf5f5f500,0xf9f9f900,0xb6b6b600, + 0x2f2f2f00,0xfdfdfd00,0xb4b4b400,0x59595900, + 0x78787800,0x98989800,0x06060600,0x6a6a6a00, + 0xe7e7e700,0x46464600,0x71717100,0xbababa00, + 0xd4d4d400,0x25252500,0xababab00,0x42424200, + 0x88888800,0xa2a2a200,0x8d8d8d00,0xfafafa00, + 0x72727200,0x07070700,0xb9b9b900,0x55555500, + 0xf8f8f800,0xeeeeee00,0xacacac00,0x0a0a0a00, + 0x36363600,0x49494900,0x2a2a2a00,0x68686800, + 0x3c3c3c00,0x38383800,0xf1f1f100,0xa4a4a400, + 0x40404000,0x28282800,0xd3d3d300,0x7b7b7b00, + 0xbbbbbb00,0xc9c9c900,0x43434300,0xc1c1c100, + 0x15151500,0xe3e3e300,0xadadad00,0xf4f4f400, + 0x77777700,0xc7c7c700,0x80808000,0x9e9e9e00, +}; + +static const uint32_t camellia_sp0222[256] = { + 0x00e0e0e0,0x00050505,0x00585858,0x00d9d9d9, + 0x00676767,0x004e4e4e,0x00818181,0x00cbcbcb, + 0x00c9c9c9,0x000b0b0b,0x00aeaeae,0x006a6a6a, + 0x00d5d5d5,0x00181818,0x005d5d5d,0x00828282, + 0x00464646,0x00dfdfdf,0x00d6d6d6,0x00272727, + 0x008a8a8a,0x00323232,0x004b4b4b,0x00424242, + 0x00dbdbdb,0x001c1c1c,0x009e9e9e,0x009c9c9c, + 0x003a3a3a,0x00cacaca,0x00252525,0x007b7b7b, + 0x000d0d0d,0x00717171,0x005f5f5f,0x001f1f1f, + 0x00f8f8f8,0x00d7d7d7,0x003e3e3e,0x009d9d9d, + 0x007c7c7c,0x00606060,0x00b9b9b9,0x00bebebe, + 0x00bcbcbc,0x008b8b8b,0x00161616,0x00343434, + 0x004d4d4d,0x00c3c3c3,0x00727272,0x00959595, + 0x00ababab,0x008e8e8e,0x00bababa,0x007a7a7a, + 0x00b3b3b3,0x00020202,0x00b4b4b4,0x00adadad, + 0x00a2a2a2,0x00acacac,0x00d8d8d8,0x009a9a9a, + 0x00171717,0x001a1a1a,0x00353535,0x00cccccc, + 0x00f7f7f7,0x00999999,0x00616161,0x005a5a5a, + 0x00e8e8e8,0x00242424,0x00565656,0x00404040, + 0x00e1e1e1,0x00636363,0x00090909,0x00333333, + 0x00bfbfbf,0x00989898,0x00979797,0x00858585, + 0x00686868,0x00fcfcfc,0x00ececec,0x000a0a0a, + 0x00dadada,0x006f6f6f,0x00535353,0x00626262, + 0x00a3a3a3,0x002e2e2e,0x00080808,0x00afafaf, + 0x00282828,0x00b0b0b0,0x00747474,0x00c2c2c2, + 0x00bdbdbd,0x00363636,0x00222222,0x00383838, + 0x00646464,0x001e1e1e,0x00393939,0x002c2c2c, + 0x00a6a6a6,0x00303030,0x00e5e5e5,0x00444444, + 0x00fdfdfd,0x00888888,0x009f9f9f,0x00656565, + 0x00878787,0x006b6b6b,0x00f4f4f4,0x00232323, + 0x00484848,0x00101010,0x00d1d1d1,0x00515151, + 0x00c0c0c0,0x00f9f9f9,0x00d2d2d2,0x00a0a0a0, + 0x00555555,0x00a1a1a1,0x00414141,0x00fafafa, + 0x00434343,0x00131313,0x00c4c4c4,0x002f2f2f, + 0x00a8a8a8,0x00b6b6b6,0x003c3c3c,0x002b2b2b, + 0x00c1c1c1,0x00ffffff,0x00c8c8c8,0x00a5a5a5, + 0x00202020,0x00898989,0x00000000,0x00909090, + 0x00474747,0x00efefef,0x00eaeaea,0x00b7b7b7, + 0x00151515,0x00060606,0x00cdcdcd,0x00b5b5b5, + 0x00121212,0x007e7e7e,0x00bbbbbb,0x00292929, + 0x000f0f0f,0x00b8b8b8,0x00070707,0x00040404, + 0x009b9b9b,0x00949494,0x00212121,0x00666666, + 0x00e6e6e6,0x00cecece,0x00ededed,0x00e7e7e7, + 0x003b3b3b,0x00fefefe,0x007f7f7f,0x00c5c5c5, + 0x00a4a4a4,0x00373737,0x00b1b1b1,0x004c4c4c, + 0x00919191,0x006e6e6e,0x008d8d8d,0x00767676, + 0x00030303,0x002d2d2d,0x00dedede,0x00969696, + 0x00262626,0x007d7d7d,0x00c6c6c6,0x005c5c5c, + 0x00d3d3d3,0x00f2f2f2,0x004f4f4f,0x00191919, + 0x003f3f3f,0x00dcdcdc,0x00797979,0x001d1d1d, + 0x00525252,0x00ebebeb,0x00f3f3f3,0x006d6d6d, + 0x005e5e5e,0x00fbfbfb,0x00696969,0x00b2b2b2, + 0x00f0f0f0,0x00313131,0x000c0c0c,0x00d4d4d4, + 0x00cfcfcf,0x008c8c8c,0x00e2e2e2,0x00757575, + 0x00a9a9a9,0x004a4a4a,0x00575757,0x00848484, + 0x00111111,0x00454545,0x001b1b1b,0x00f5f5f5, + 0x00e4e4e4,0x000e0e0e,0x00737373,0x00aaaaaa, + 0x00f1f1f1,0x00dddddd,0x00595959,0x00141414, + 0x006c6c6c,0x00929292,0x00545454,0x00d0d0d0, + 0x00787878,0x00707070,0x00e3e3e3,0x00494949, + 0x00808080,0x00505050,0x00a7a7a7,0x00f6f6f6, + 0x00777777,0x00939393,0x00868686,0x00838383, + 0x002a2a2a,0x00c7c7c7,0x005b5b5b,0x00e9e9e9, + 0x00eeeeee,0x008f8f8f,0x00010101,0x003d3d3d, +}; + +static const uint32_t camellia_sp3033[256] = { + 0x38003838,0x41004141,0x16001616,0x76007676, + 0xd900d9d9,0x93009393,0x60006060,0xf200f2f2, + 0x72007272,0xc200c2c2,0xab00abab,0x9a009a9a, + 0x75007575,0x06000606,0x57005757,0xa000a0a0, + 0x91009191,0xf700f7f7,0xb500b5b5,0xc900c9c9, + 0xa200a2a2,0x8c008c8c,0xd200d2d2,0x90009090, + 0xf600f6f6,0x07000707,0xa700a7a7,0x27002727, + 0x8e008e8e,0xb200b2b2,0x49004949,0xde00dede, + 0x43004343,0x5c005c5c,0xd700d7d7,0xc700c7c7, + 0x3e003e3e,0xf500f5f5,0x8f008f8f,0x67006767, + 0x1f001f1f,0x18001818,0x6e006e6e,0xaf00afaf, + 0x2f002f2f,0xe200e2e2,0x85008585,0x0d000d0d, + 0x53005353,0xf000f0f0,0x9c009c9c,0x65006565, + 0xea00eaea,0xa300a3a3,0xae00aeae,0x9e009e9e, + 0xec00ecec,0x80008080,0x2d002d2d,0x6b006b6b, + 0xa800a8a8,0x2b002b2b,0x36003636,0xa600a6a6, + 0xc500c5c5,0x86008686,0x4d004d4d,0x33003333, + 0xfd00fdfd,0x66006666,0x58005858,0x96009696, + 0x3a003a3a,0x09000909,0x95009595,0x10001010, + 0x78007878,0xd800d8d8,0x42004242,0xcc00cccc, + 0xef00efef,0x26002626,0xe500e5e5,0x61006161, + 0x1a001a1a,0x3f003f3f,0x3b003b3b,0x82008282, + 0xb600b6b6,0xdb00dbdb,0xd400d4d4,0x98009898, + 0xe800e8e8,0x8b008b8b,0x02000202,0xeb00ebeb, + 0x0a000a0a,0x2c002c2c,0x1d001d1d,0xb000b0b0, + 0x6f006f6f,0x8d008d8d,0x88008888,0x0e000e0e, + 0x19001919,0x87008787,0x4e004e4e,0x0b000b0b, + 0xa900a9a9,0x0c000c0c,0x79007979,0x11001111, + 0x7f007f7f,0x22002222,0xe700e7e7,0x59005959, + 0xe100e1e1,0xda00dada,0x3d003d3d,0xc800c8c8, + 0x12001212,0x04000404,0x74007474,0x54005454, + 0x30003030,0x7e007e7e,0xb400b4b4,0x28002828, + 0x55005555,0x68006868,0x50005050,0xbe00bebe, + 0xd000d0d0,0xc400c4c4,0x31003131,0xcb00cbcb, + 0x2a002a2a,0xad00adad,0x0f000f0f,0xca00caca, + 0x70007070,0xff00ffff,0x32003232,0x69006969, + 0x08000808,0x62006262,0x00000000,0x24002424, + 0xd100d1d1,0xfb00fbfb,0xba00baba,0xed00eded, + 0x45004545,0x81008181,0x73007373,0x6d006d6d, + 0x84008484,0x9f009f9f,0xee00eeee,0x4a004a4a, + 0xc300c3c3,0x2e002e2e,0xc100c1c1,0x01000101, + 0xe600e6e6,0x25002525,0x48004848,0x99009999, + 0xb900b9b9,0xb300b3b3,0x7b007b7b,0xf900f9f9, + 0xce00cece,0xbf00bfbf,0xdf00dfdf,0x71007171, + 0x29002929,0xcd00cdcd,0x6c006c6c,0x13001313, + 0x64006464,0x9b009b9b,0x63006363,0x9d009d9d, + 0xc000c0c0,0x4b004b4b,0xb700b7b7,0xa500a5a5, + 0x89008989,0x5f005f5f,0xb100b1b1,0x17001717, + 0xf400f4f4,0xbc00bcbc,0xd300d3d3,0x46004646, + 0xcf00cfcf,0x37003737,0x5e005e5e,0x47004747, + 0x94009494,0xfa00fafa,0xfc00fcfc,0x5b005b5b, + 0x97009797,0xfe00fefe,0x5a005a5a,0xac00acac, + 0x3c003c3c,0x4c004c4c,0x03000303,0x35003535, + 0xf300f3f3,0x23002323,0xb800b8b8,0x5d005d5d, + 0x6a006a6a,0x92009292,0xd500d5d5,0x21002121, + 0x44004444,0x51005151,0xc600c6c6,0x7d007d7d, + 0x39003939,0x83008383,0xdc00dcdc,0xaa00aaaa, + 0x7c007c7c,0x77007777,0x56005656,0x05000505, + 0x1b001b1b,0xa400a4a4,0x15001515,0x34003434, + 0x1e001e1e,0x1c001c1c,0xf800f8f8,0x52005252, + 0x20002020,0x14001414,0xe900e9e9,0xbd00bdbd, + 0xdd00dddd,0xe400e4e4,0xa100a1a1,0xe000e0e0, + 0x8a008a8a,0xf100f1f1,0xd600d6d6,0x7a007a7a, + 0xbb00bbbb,0xe300e3e3,0x40004040,0x4f004f4f, +}; + +static const uint32_t camellia_sp4404[256] = { + 0x70700070,0x2c2c002c,0xb3b300b3,0xc0c000c0, + 0xe4e400e4,0x57570057,0xeaea00ea,0xaeae00ae, + 0x23230023,0x6b6b006b,0x45450045,0xa5a500a5, + 0xeded00ed,0x4f4f004f,0x1d1d001d,0x92920092, + 0x86860086,0xafaf00af,0x7c7c007c,0x1f1f001f, + 0x3e3e003e,0xdcdc00dc,0x5e5e005e,0x0b0b000b, + 0xa6a600a6,0x39390039,0xd5d500d5,0x5d5d005d, + 0xd9d900d9,0x5a5a005a,0x51510051,0x6c6c006c, + 0x8b8b008b,0x9a9a009a,0xfbfb00fb,0xb0b000b0, + 0x74740074,0x2b2b002b,0xf0f000f0,0x84840084, + 0xdfdf00df,0xcbcb00cb,0x34340034,0x76760076, + 0x6d6d006d,0xa9a900a9,0xd1d100d1,0x04040004, + 0x14140014,0x3a3a003a,0xdede00de,0x11110011, + 0x32320032,0x9c9c009c,0x53530053,0xf2f200f2, + 0xfefe00fe,0xcfcf00cf,0xc3c300c3,0x7a7a007a, + 0x24240024,0xe8e800e8,0x60600060,0x69690069, + 0xaaaa00aa,0xa0a000a0,0xa1a100a1,0x62620062, + 0x54540054,0x1e1e001e,0xe0e000e0,0x64640064, + 0x10100010,0x00000000,0xa3a300a3,0x75750075, + 0x8a8a008a,0xe6e600e6,0x09090009,0xdddd00dd, + 0x87870087,0x83830083,0xcdcd00cd,0x90900090, + 0x73730073,0xf6f600f6,0x9d9d009d,0xbfbf00bf, + 0x52520052,0xd8d800d8,0xc8c800c8,0xc6c600c6, + 0x81810081,0x6f6f006f,0x13130013,0x63630063, + 0xe9e900e9,0xa7a700a7,0x9f9f009f,0xbcbc00bc, + 0x29290029,0xf9f900f9,0x2f2f002f,0xb4b400b4, + 0x78780078,0x06060006,0xe7e700e7,0x71710071, + 0xd4d400d4,0xabab00ab,0x88880088,0x8d8d008d, + 0x72720072,0xb9b900b9,0xf8f800f8,0xacac00ac, + 0x36360036,0x2a2a002a,0x3c3c003c,0xf1f100f1, + 0x40400040,0xd3d300d3,0xbbbb00bb,0x43430043, + 0x15150015,0xadad00ad,0x77770077,0x80800080, + 0x82820082,0xecec00ec,0x27270027,0xe5e500e5, + 0x85850085,0x35350035,0x0c0c000c,0x41410041, + 0xefef00ef,0x93930093,0x19190019,0x21210021, + 0x0e0e000e,0x4e4e004e,0x65650065,0xbdbd00bd, + 0xb8b800b8,0x8f8f008f,0xebeb00eb,0xcece00ce, + 0x30300030,0x5f5f005f,0xc5c500c5,0x1a1a001a, + 0xe1e100e1,0xcaca00ca,0x47470047,0x3d3d003d, + 0x01010001,0xd6d600d6,0x56560056,0x4d4d004d, + 0x0d0d000d,0x66660066,0xcccc00cc,0x2d2d002d, + 0x12120012,0x20200020,0xb1b100b1,0x99990099, + 0x4c4c004c,0xc2c200c2,0x7e7e007e,0x05050005, + 0xb7b700b7,0x31310031,0x17170017,0xd7d700d7, + 0x58580058,0x61610061,0x1b1b001b,0x1c1c001c, + 0x0f0f000f,0x16160016,0x18180018,0x22220022, + 0x44440044,0xb2b200b2,0xb5b500b5,0x91910091, + 0x08080008,0xa8a800a8,0xfcfc00fc,0x50500050, + 0xd0d000d0,0x7d7d007d,0x89890089,0x97970097, + 0x5b5b005b,0x95950095,0xffff00ff,0xd2d200d2, + 0xc4c400c4,0x48480048,0xf7f700f7,0xdbdb00db, + 0x03030003,0xdada00da,0x3f3f003f,0x94940094, + 0x5c5c005c,0x02020002,0x4a4a004a,0x33330033, + 0x67670067,0xf3f300f3,0x7f7f007f,0xe2e200e2, + 0x9b9b009b,0x26260026,0x37370037,0x3b3b003b, + 0x96960096,0x4b4b004b,0xbebe00be,0x2e2e002e, + 0x79790079,0x8c8c008c,0x6e6e006e,0x8e8e008e, + 0xf5f500f5,0xb6b600b6,0xfdfd00fd,0x59590059, + 0x98980098,0x6a6a006a,0x46460046,0xbaba00ba, + 0x25250025,0x42420042,0xa2a200a2,0xfafa00fa, + 0x07070007,0x55550055,0xeeee00ee,0x0a0a000a, + 0x49490049,0x68680068,0x38380038,0xa4a400a4, + 0x28280028,0x7b7b007b,0xc9c900c9,0xc1c100c1, + 0xe3e300e3,0xf4f400f4,0xc7c700c7,0x9e9e009e, +}; + + +/* + * Stuff related to the Camellia key schedule + */ +#define subl(x) subL[(x)] +#define subr(x) subR[(x)] + +void +camellia_setup128(const unsigned char *key, uint32_t *subkey) +{ + uint32_t kll, klr, krl, krr; + uint32_t il, ir, t0, t1, w0, w1; + uint32_t kw4l, kw4r, dw, tl, tr; + uint32_t subL[26]; + uint32_t subR[26]; + + /* + * k == kll || klr || krl || krr (|| is concatination) + */ + kll = GETU32(key ); + klr = GETU32(key + 4); + krl = GETU32(key + 8); + krr = GETU32(key + 12); + /* + * generate KL dependent subkeys + */ + subl(0) = kll; subr(0) = klr; + subl(1) = krl; subr(1) = krr; + CAMELLIA_ROLDQ(kll, klr, krl, krr, w0, w1, 15); + subl(4) = kll; subr(4) = klr; + subl(5) = krl; subr(5) = krr; + CAMELLIA_ROLDQ(kll, klr, krl, krr, w0, w1, 30); + subl(10) = kll; subr(10) = klr; + subl(11) = krl; subr(11) = krr; + CAMELLIA_ROLDQ(kll, klr, krl, krr, w0, w1, 15); + subl(13) = krl; subr(13) = krr; + CAMELLIA_ROLDQ(kll, klr, krl, krr, w0, w1, 17); + subl(16) = kll; subr(16) = klr; + subl(17) = krl; subr(17) = krr; + CAMELLIA_ROLDQ(kll, klr, krl, krr, w0, w1, 17); + subl(18) = kll; subr(18) = klr; + subl(19) = krl; subr(19) = krr; + CAMELLIA_ROLDQ(kll, klr, krl, krr, w0, w1, 17); + subl(22) = kll; subr(22) = klr; + subl(23) = krl; subr(23) = krr; + + /* generate KA */ + kll = subl(0); klr = subr(0); + krl = subl(1); krr = subr(1); + CAMELLIA_F(kll, klr, CAMELLIA_SIGMA1L, CAMELLIA_SIGMA1R, + w0, w1, il, ir, t0, t1); + krl ^= w0; krr ^= w1; + CAMELLIA_F(krl, krr, CAMELLIA_SIGMA2L, CAMELLIA_SIGMA2R, + kll, klr, il, ir, t0, t1); + CAMELLIA_F(kll, klr, CAMELLIA_SIGMA3L, CAMELLIA_SIGMA3R, + krl, krr, il, ir, t0, t1); + krl ^= w0; krr ^= w1; + CAMELLIA_F(krl, krr, CAMELLIA_SIGMA4L, CAMELLIA_SIGMA4R, + w0, w1, il, ir, t0, t1); + kll ^= w0; klr ^= w1; + + /* generate KA dependent subkeys */ + subl(2) = kll; subr(2) = klr; + subl(3) = krl; subr(3) = krr; + CAMELLIA_ROLDQ(kll, klr, krl, krr, w0, w1, 15); + subl(6) = kll; subr(6) = klr; + subl(7) = krl; subr(7) = krr; + CAMELLIA_ROLDQ(kll, klr, krl, krr, w0, w1, 15); + subl(8) = kll; subr(8) = klr; + subl(9) = krl; subr(9) = krr; + CAMELLIA_ROLDQ(kll, klr, krl, krr, w0, w1, 15); + subl(12) = kll; subr(12) = klr; + CAMELLIA_ROLDQ(kll, klr, krl, krr, w0, w1, 15); + subl(14) = kll; subr(14) = klr; + subl(15) = krl; subr(15) = krr; + CAMELLIA_ROLDQo32(kll, klr, krl, krr, w0, w1, 34); + subl(20) = kll; subr(20) = klr; + subl(21) = krl; subr(21) = krr; + CAMELLIA_ROLDQ(kll, klr, krl, krr, w0, w1, 17); + subl(24) = kll; subr(24) = klr; + subl(25) = krl; subr(25) = krr; + + + /* absorb kw2 to other subkeys */ + subl(3) ^= subl(1); subr(3) ^= subr(1); + subl(5) ^= subl(1); subr(5) ^= subr(1); + subl(7) ^= subl(1); subr(7) ^= subr(1); + subl(1) ^= subr(1) & ~subr(9); + dw = subl(1) & subl(9), subr(1) ^= CAMELLIA_RL1(dw); + subl(11) ^= subl(1); subr(11) ^= subr(1); + subl(13) ^= subl(1); subr(13) ^= subr(1); + subl(15) ^= subl(1); subr(15) ^= subr(1); + subl(1) ^= subr(1) & ~subr(17); + dw = subl(1) & subl(17), subr(1) ^= CAMELLIA_RL1(dw); + subl(19) ^= subl(1); subr(19) ^= subr(1); + subl(21) ^= subl(1); subr(21) ^= subr(1); + subl(23) ^= subl(1); subr(23) ^= subr(1); + subl(24) ^= subl(1); subr(24) ^= subr(1); + + /* absorb kw4 to other subkeys */ + kw4l = subl(25); kw4r = subr(25); + subl(22) ^= kw4l; subr(22) ^= kw4r; + subl(20) ^= kw4l; subr(20) ^= kw4r; + subl(18) ^= kw4l; subr(18) ^= kw4r; + kw4l ^= kw4r & ~subr(16); + dw = kw4l & subl(16), kw4r ^= CAMELLIA_RL1(dw); + subl(14) ^= kw4l; subr(14) ^= kw4r; + subl(12) ^= kw4l; subr(12) ^= kw4r; + subl(10) ^= kw4l; subr(10) ^= kw4r; + kw4l ^= kw4r & ~subr(8); + dw = kw4l & subl(8), kw4r ^= CAMELLIA_RL1(dw); + subl(6) ^= kw4l; subr(6) ^= kw4r; + subl(4) ^= kw4l; subr(4) ^= kw4r; + subl(2) ^= kw4l; subr(2) ^= kw4r; + subl(0) ^= kw4l; subr(0) ^= kw4r; + + /* key XOR is end of F-function */ + SUBL(0) = subl(0) ^ subl(2); + SUBR(0) = subr(0) ^ subr(2); + SUBL(2) = subl(3); + SUBR(2) = subr(3); + SUBL(3) = subl(2) ^ subl(4); + SUBR(3) = subr(2) ^ subr(4); + SUBL(4) = subl(3) ^ subl(5); + SUBR(4) = subr(3) ^ subr(5); + SUBL(5) = subl(4) ^ subl(6); + SUBR(5) = subr(4) ^ subr(6); + SUBL(6) = subl(5) ^ subl(7); + SUBR(6) = subr(5) ^ subr(7); + tl = subl(10) ^ (subr(10) & ~subr(8)); + dw = tl & subl(8), tr = subr(10) ^ CAMELLIA_RL1(dw); + SUBL(7) = subl(6) ^ tl; + SUBR(7) = subr(6) ^ tr; + SUBL(8) = subl(8); + SUBR(8) = subr(8); + SUBL(9) = subl(9); + SUBR(9) = subr(9); + tl = subl(7) ^ (subr(7) & ~subr(9)); + dw = tl & subl(9), tr = subr(7) ^ CAMELLIA_RL1(dw); + SUBL(10) = tl ^ subl(11); + SUBR(10) = tr ^ subr(11); + SUBL(11) = subl(10) ^ subl(12); + SUBR(11) = subr(10) ^ subr(12); + SUBL(12) = subl(11) ^ subl(13); + SUBR(12) = subr(11) ^ subr(13); + SUBL(13) = subl(12) ^ subl(14); + SUBR(13) = subr(12) ^ subr(14); + SUBL(14) = subl(13) ^ subl(15); + SUBR(14) = subr(13) ^ subr(15); + tl = subl(18) ^ (subr(18) & ~subr(16)); + dw = tl & subl(16), tr = subr(18) ^ CAMELLIA_RL1(dw); + SUBL(15) = subl(14) ^ tl; + SUBR(15) = subr(14) ^ tr; + SUBL(16) = subl(16); + SUBR(16) = subr(16); + SUBL(17) = subl(17); + SUBR(17) = subr(17); + tl = subl(15) ^ (subr(15) & ~subr(17)); + dw = tl & subl(17), tr = subr(15) ^ CAMELLIA_RL1(dw); + SUBL(18) = tl ^ subl(19); + SUBR(18) = tr ^ subr(19); + SUBL(19) = subl(18) ^ subl(20); + SUBR(19) = subr(18) ^ subr(20); + SUBL(20) = subl(19) ^ subl(21); + SUBR(20) = subr(19) ^ subr(21); + SUBL(21) = subl(20) ^ subl(22); + SUBR(21) = subr(20) ^ subr(22); + SUBL(22) = subl(21) ^ subl(23); + SUBR(22) = subr(21) ^ subr(23); + SUBL(23) = subl(22); + SUBR(23) = subr(22); + SUBL(24) = subl(24) ^ subl(23); + SUBR(24) = subr(24) ^ subr(23); + + /* apply the inverse of the last half of P-function */ + dw = SUBL(2) ^ SUBR(2), dw = CAMELLIA_RL8(dw); + SUBR(2) = SUBL(2) ^ dw, SUBL(2) = dw; + dw = SUBL(3) ^ SUBR(3), dw = CAMELLIA_RL8(dw); + SUBR(3) = SUBL(3) ^ dw, SUBL(3) = dw; + dw = SUBL(4) ^ SUBR(4), dw = CAMELLIA_RL8(dw); + SUBR(4) = SUBL(4) ^ dw, SUBL(4) = dw; + dw = SUBL(5) ^ SUBR(5), dw = CAMELLIA_RL8(dw); + SUBR(5) = SUBL(5) ^ dw, SUBL(5) = dw; + dw = SUBL(6) ^ SUBR(6), dw = CAMELLIA_RL8(dw); + SUBR(6) = SUBL(6) ^ dw, SUBL(6) = dw; + dw = SUBL(7) ^ SUBR(7), dw = CAMELLIA_RL8(dw); + SUBR(7) = SUBL(7) ^ dw, SUBL(7) = dw; + dw = SUBL(10) ^ SUBR(10), dw = CAMELLIA_RL8(dw); + SUBR(10) = SUBL(10) ^ dw, SUBL(10) = dw; + dw = SUBL(11) ^ SUBR(11), dw = CAMELLIA_RL8(dw); + SUBR(11) = SUBL(11) ^ dw, SUBL(11) = dw; + dw = SUBL(12) ^ SUBR(12), dw = CAMELLIA_RL8(dw); + SUBR(12) = SUBL(12) ^ dw, SUBL(12) = dw; + dw = SUBL(13) ^ SUBR(13), dw = CAMELLIA_RL8(dw); + SUBR(13) = SUBL(13) ^ dw, SUBL(13) = dw; + dw = SUBL(14) ^ SUBR(14), dw = CAMELLIA_RL8(dw); + SUBR(14) = SUBL(14) ^ dw, SUBL(14) = dw; + dw = SUBL(15) ^ SUBR(15), dw = CAMELLIA_RL8(dw); + SUBR(15) = SUBL(15) ^ dw, SUBL(15) = dw; + dw = SUBL(18) ^ SUBR(18), dw = CAMELLIA_RL8(dw); + SUBR(18) = SUBL(18) ^ dw, SUBL(18) = dw; + dw = SUBL(19) ^ SUBR(19), dw = CAMELLIA_RL8(dw); + SUBR(19) = SUBL(19) ^ dw, SUBL(19) = dw; + dw = SUBL(20) ^ SUBR(20), dw = CAMELLIA_RL8(dw); + SUBR(20) = SUBL(20) ^ dw, SUBL(20) = dw; + dw = SUBL(21) ^ SUBR(21), dw = CAMELLIA_RL8(dw); + SUBR(21) = SUBL(21) ^ dw, SUBL(21) = dw; + dw = SUBL(22) ^ SUBR(22), dw = CAMELLIA_RL8(dw); + SUBR(22) = SUBL(22) ^ dw, SUBL(22) = dw; + dw = SUBL(23) ^ SUBR(23), dw = CAMELLIA_RL8(dw); + SUBR(23) = SUBL(23) ^ dw, SUBL(23) = dw; +} + +void +camellia_setup256(const unsigned char *key, uint32_t *subkey) +{ + uint32_t kll,klr,krl,krr; /* left half of key */ + uint32_t krll,krlr,krrl,krrr; /* right half of key */ + uint32_t il, ir, t0, t1, w0, w1; /* temporary variables */ + uint32_t kw4l, kw4r, dw, tl, tr; + uint32_t subL[34]; + uint32_t subR[34]; + + /* + * key = (kll || klr || krl || krr || krll || krlr || krrl || krrr) + * (|| is concatination) + */ + + kll = GETU32(key ); + klr = GETU32(key + 4); + krl = GETU32(key + 8); + krr = GETU32(key + 12); + krll = GETU32(key + 16); + krlr = GETU32(key + 20); + krrl = GETU32(key + 24); + krrr = GETU32(key + 28); + + /* generate KL dependent subkeys */ + subl(0) = kll; subr(0) = klr; + subl(1) = krl; subr(1) = krr; + CAMELLIA_ROLDQo32(kll, klr, krl, krr, w0, w1, 45); + subl(12) = kll; subr(12) = klr; + subl(13) = krl; subr(13) = krr; + CAMELLIA_ROLDQ(kll, klr, krl, krr, w0, w1, 15); + subl(16) = kll; subr(16) = klr; + subl(17) = krl; subr(17) = krr; + CAMELLIA_ROLDQ(kll, klr, krl, krr, w0, w1, 17); + subl(22) = kll; subr(22) = klr; + subl(23) = krl; subr(23) = krr; + CAMELLIA_ROLDQo32(kll, klr, krl, krr, w0, w1, 34); + subl(30) = kll; subr(30) = klr; + subl(31) = krl; subr(31) = krr; + + /* generate KR dependent subkeys */ + CAMELLIA_ROLDQ(krll, krlr, krrl, krrr, w0, w1, 15); + subl(4) = krll; subr(4) = krlr; + subl(5) = krrl; subr(5) = krrr; + CAMELLIA_ROLDQ(krll, krlr, krrl, krrr, w0, w1, 15); + subl(8) = krll; subr(8) = krlr; + subl(9) = krrl; subr(9) = krrr; + CAMELLIA_ROLDQ(krll, krlr, krrl, krrr, w0, w1, 30); + subl(18) = krll; subr(18) = krlr; + subl(19) = krrl; subr(19) = krrr; + CAMELLIA_ROLDQo32(krll, krlr, krrl, krrr, w0, w1, 34); + subl(26) = krll; subr(26) = krlr; + subl(27) = krrl; subr(27) = krrr; + CAMELLIA_ROLDQo32(krll, krlr, krrl, krrr, w0, w1, 34); + + /* generate KA */ + kll = subl(0) ^ krll; klr = subr(0) ^ krlr; + krl = subl(1) ^ krrl; krr = subr(1) ^ krrr; + CAMELLIA_F(kll, klr, CAMELLIA_SIGMA1L, CAMELLIA_SIGMA1R, + w0, w1, il, ir, t0, t1); + krl ^= w0; krr ^= w1; + CAMELLIA_F(krl, krr, CAMELLIA_SIGMA2L, CAMELLIA_SIGMA2R, + kll, klr, il, ir, t0, t1); + kll ^= krll; klr ^= krlr; + CAMELLIA_F(kll, klr, CAMELLIA_SIGMA3L, CAMELLIA_SIGMA3R, + krl, krr, il, ir, t0, t1); + krl ^= w0 ^ krrl; krr ^= w1 ^ krrr; + CAMELLIA_F(krl, krr, CAMELLIA_SIGMA4L, CAMELLIA_SIGMA4R, + w0, w1, il, ir, t0, t1); + kll ^= w0; klr ^= w1; + + /* generate KB */ + krll ^= kll; krlr ^= klr; + krrl ^= krl; krrr ^= krr; + CAMELLIA_F(krll, krlr, CAMELLIA_SIGMA5L, CAMELLIA_SIGMA5R, + w0, w1, il, ir, t0, t1); + krrl ^= w0; krrr ^= w1; + CAMELLIA_F(krrl, krrr, CAMELLIA_SIGMA6L, CAMELLIA_SIGMA6R, + w0, w1, il, ir, t0, t1); + krll ^= w0; krlr ^= w1; + + /* generate KA dependent subkeys */ + CAMELLIA_ROLDQ(kll, klr, krl, krr, w0, w1, 15); + subl(6) = kll; subr(6) = klr; + subl(7) = krl; subr(7) = krr; + CAMELLIA_ROLDQ(kll, klr, krl, krr, w0, w1, 30); + subl(14) = kll; subr(14) = klr; + subl(15) = krl; subr(15) = krr; + subl(24) = klr; subr(24) = krl; + subl(25) = krr; subr(25) = kll; + CAMELLIA_ROLDQo32(kll, klr, krl, krr, w0, w1, 49); + subl(28) = kll; subr(28) = klr; + subl(29) = krl; subr(29) = krr; + + /* generate KB dependent subkeys */ + subl(2) = krll; subr(2) = krlr; + subl(3) = krrl; subr(3) = krrr; + CAMELLIA_ROLDQ(krll, krlr, krrl, krrr, w0, w1, 30); + subl(10) = krll; subr(10) = krlr; + subl(11) = krrl; subr(11) = krrr; + CAMELLIA_ROLDQ(krll, krlr, krrl, krrr, w0, w1, 30); + subl(20) = krll; subr(20) = krlr; + subl(21) = krrl; subr(21) = krrr; + CAMELLIA_ROLDQo32(krll, krlr, krrl, krrr, w0, w1, 51); + subl(32) = krll; subr(32) = krlr; + subl(33) = krrl; subr(33) = krrr; + + /* absorb kw2 to other subkeys */ + subl(3) ^= subl(1); subr(3) ^= subr(1); + subl(5) ^= subl(1); subr(5) ^= subr(1); + subl(7) ^= subl(1); subr(7) ^= subr(1); + subl(1) ^= subr(1) & ~subr(9); + dw = subl(1) & subl(9), subr(1) ^= CAMELLIA_RL1(dw); + subl(11) ^= subl(1); subr(11) ^= subr(1); + subl(13) ^= subl(1); subr(13) ^= subr(1); + subl(15) ^= subl(1); subr(15) ^= subr(1); + subl(1) ^= subr(1) & ~subr(17); + dw = subl(1) & subl(17), subr(1) ^= CAMELLIA_RL1(dw); + subl(19) ^= subl(1); subr(19) ^= subr(1); + subl(21) ^= subl(1); subr(21) ^= subr(1); + subl(23) ^= subl(1); subr(23) ^= subr(1); + subl(1) ^= subr(1) & ~subr(25); + dw = subl(1) & subl(25), subr(1) ^= CAMELLIA_RL1(dw); + subl(27) ^= subl(1); subr(27) ^= subr(1); + subl(29) ^= subl(1); subr(29) ^= subr(1); + subl(31) ^= subl(1); subr(31) ^= subr(1); + subl(32) ^= subl(1); subr(32) ^= subr(1); + + + /* absorb kw4 to other subkeys */ + kw4l = subl(33); kw4r = subr(33); + subl(30) ^= kw4l; subr(30) ^= kw4r; + subl(28) ^= kw4l; subr(28) ^= kw4r; + subl(26) ^= kw4l; subr(26) ^= kw4r; + kw4l ^= kw4r & ~subr(24); + dw = kw4l & subl(24), kw4r ^= CAMELLIA_RL1(dw); + subl(22) ^= kw4l; subr(22) ^= kw4r; + subl(20) ^= kw4l; subr(20) ^= kw4r; + subl(18) ^= kw4l; subr(18) ^= kw4r; + kw4l ^= kw4r & ~subr(16); + dw = kw4l & subl(16), kw4r ^= CAMELLIA_RL1(dw); + subl(14) ^= kw4l; subr(14) ^= kw4r; + subl(12) ^= kw4l; subr(12) ^= kw4r; + subl(10) ^= kw4l; subr(10) ^= kw4r; + kw4l ^= kw4r & ~subr(8); + dw = kw4l & subl(8), kw4r ^= CAMELLIA_RL1(dw); + subl(6) ^= kw4l; subr(6) ^= kw4r; + subl(4) ^= kw4l; subr(4) ^= kw4r; + subl(2) ^= kw4l; subr(2) ^= kw4r; + subl(0) ^= kw4l; subr(0) ^= kw4r; + + /* key XOR is end of F-function */ + SUBL(0) = subl(0) ^ subl(2); + SUBR(0) = subr(0) ^ subr(2); + SUBL(2) = subl(3); + SUBR(2) = subr(3); + SUBL(3) = subl(2) ^ subl(4); + SUBR(3) = subr(2) ^ subr(4); + SUBL(4) = subl(3) ^ subl(5); + SUBR(4) = subr(3) ^ subr(5); + SUBL(5) = subl(4) ^ subl(6); + SUBR(5) = subr(4) ^ subr(6); + SUBL(6) = subl(5) ^ subl(7); + SUBR(6) = subr(5) ^ subr(7); + tl = subl(10) ^ (subr(10) & ~subr(8)); + dw = tl & subl(8), tr = subr(10) ^ CAMELLIA_RL1(dw); + SUBL(7) = subl(6) ^ tl; + SUBR(7) = subr(6) ^ tr; + SUBL(8) = subl(8); + SUBR(8) = subr(8); + SUBL(9) = subl(9); + SUBR(9) = subr(9); + tl = subl(7) ^ (subr(7) & ~subr(9)); + dw = tl & subl(9), tr = subr(7) ^ CAMELLIA_RL1(dw); + SUBL(10) = tl ^ subl(11); + SUBR(10) = tr ^ subr(11); + SUBL(11) = subl(10) ^ subl(12); + SUBR(11) = subr(10) ^ subr(12); + SUBL(12) = subl(11) ^ subl(13); + SUBR(12) = subr(11) ^ subr(13); + SUBL(13) = subl(12) ^ subl(14); + SUBR(13) = subr(12) ^ subr(14); + SUBL(14) = subl(13) ^ subl(15); + SUBR(14) = subr(13) ^ subr(15); + tl = subl(18) ^ (subr(18) & ~subr(16)); + dw = tl & subl(16), tr = subr(18) ^ CAMELLIA_RL1(dw); + SUBL(15) = subl(14) ^ tl; + SUBR(15) = subr(14) ^ tr; + SUBL(16) = subl(16); + SUBR(16) = subr(16); + SUBL(17) = subl(17); + SUBR(17) = subr(17); + tl = subl(15) ^ (subr(15) & ~subr(17)); + dw = tl & subl(17), tr = subr(15) ^ CAMELLIA_RL1(dw); + SUBL(18) = tl ^ subl(19); + SUBR(18) = tr ^ subr(19); + SUBL(19) = subl(18) ^ subl(20); + SUBR(19) = subr(18) ^ subr(20); + SUBL(20) = subl(19) ^ subl(21); + SUBR(20) = subr(19) ^ subr(21); + SUBL(21) = subl(20) ^ subl(22); + SUBR(21) = subr(20) ^ subr(22); + SUBL(22) = subl(21) ^ subl(23); + SUBR(22) = subr(21) ^ subr(23); + tl = subl(26) ^ (subr(26) & ~subr(24)); + dw = tl & subl(24), tr = subr(26) ^ CAMELLIA_RL1(dw); + SUBL(23) = subl(22) ^ tl; + SUBR(23) = subr(22) ^ tr; + SUBL(24) = subl(24); + SUBR(24) = subr(24); + SUBL(25) = subl(25); + SUBR(25) = subr(25); + tl = subl(23) ^ (subr(23) & ~subr(25)); + dw = tl & subl(25), tr = subr(23) ^ CAMELLIA_RL1(dw); + SUBL(26) = tl ^ subl(27); + SUBR(26) = tr ^ subr(27); + SUBL(27) = subl(26) ^ subl(28); + SUBR(27) = subr(26) ^ subr(28); + SUBL(28) = subl(27) ^ subl(29); + SUBR(28) = subr(27) ^ subr(29); + SUBL(29) = subl(28) ^ subl(30); + SUBR(29) = subr(28) ^ subr(30); + SUBL(30) = subl(29) ^ subl(31); + SUBR(30) = subr(29) ^ subr(31); + SUBL(31) = subl(30); + SUBR(31) = subr(30); + SUBL(32) = subl(32) ^ subl(31); + SUBR(32) = subr(32) ^ subr(31); + + /* apply the inverse of the last half of P-function */ + dw = SUBL(2) ^ SUBR(2), dw = CAMELLIA_RL8(dw); + SUBR(2) = SUBL(2) ^ dw, SUBL(2) = dw; + dw = SUBL(3) ^ SUBR(3), dw = CAMELLIA_RL8(dw); + SUBR(3) = SUBL(3) ^ dw, SUBL(3) = dw; + dw = SUBL(4) ^ SUBR(4), dw = CAMELLIA_RL8(dw); + SUBR(4) = SUBL(4) ^ dw, SUBL(4) = dw; + dw = SUBL(5) ^ SUBR(5), dw = CAMELLIA_RL8(dw); + SUBR(5) = SUBL(5) ^ dw, SUBL(5) = dw; + dw = SUBL(6) ^ SUBR(6), dw = CAMELLIA_RL8(dw); + SUBR(6) = SUBL(6) ^ dw, SUBL(6) = dw; + dw = SUBL(7) ^ SUBR(7), dw = CAMELLIA_RL8(dw); + SUBR(7) = SUBL(7) ^ dw, SUBL(7) = dw; + dw = SUBL(10) ^ SUBR(10), dw = CAMELLIA_RL8(dw); + SUBR(10) = SUBL(10) ^ dw, SUBL(10) = dw; + dw = SUBL(11) ^ SUBR(11), dw = CAMELLIA_RL8(dw); + SUBR(11) = SUBL(11) ^ dw, SUBL(11) = dw; + dw = SUBL(12) ^ SUBR(12), dw = CAMELLIA_RL8(dw); + SUBR(12) = SUBL(12) ^ dw, SUBL(12) = dw; + dw = SUBL(13) ^ SUBR(13), dw = CAMELLIA_RL8(dw); + SUBR(13) = SUBL(13) ^ dw, SUBL(13) = dw; + dw = SUBL(14) ^ SUBR(14), dw = CAMELLIA_RL8(dw); + SUBR(14) = SUBL(14) ^ dw, SUBL(14) = dw; + dw = SUBL(15) ^ SUBR(15), dw = CAMELLIA_RL8(dw); + SUBR(15) = SUBL(15) ^ dw, SUBL(15) = dw; + dw = SUBL(18) ^ SUBR(18), dw = CAMELLIA_RL8(dw); + SUBR(18) = SUBL(18) ^ dw, SUBL(18) = dw; + dw = SUBL(19) ^ SUBR(19), dw = CAMELLIA_RL8(dw); + SUBR(19) = SUBL(19) ^ dw, SUBL(19) = dw; + dw = SUBL(20) ^ SUBR(20), dw = CAMELLIA_RL8(dw); + SUBR(20) = SUBL(20) ^ dw, SUBL(20) = dw; + dw = SUBL(21) ^ SUBR(21), dw = CAMELLIA_RL8(dw); + SUBR(21) = SUBL(21) ^ dw, SUBL(21) = dw; + dw = SUBL(22) ^ SUBR(22), dw = CAMELLIA_RL8(dw); + SUBR(22) = SUBL(22) ^ dw, SUBL(22) = dw; + dw = SUBL(23) ^ SUBR(23), dw = CAMELLIA_RL8(dw); + SUBR(23) = SUBL(23) ^ dw, SUBL(23) = dw; + dw = SUBL(26) ^ SUBR(26), dw = CAMELLIA_RL8(dw); + SUBR(26) = SUBL(26) ^ dw, SUBL(26) = dw; + dw = SUBL(27) ^ SUBR(27), dw = CAMELLIA_RL8(dw); + SUBR(27) = SUBL(27) ^ dw, SUBL(27) = dw; + dw = SUBL(28) ^ SUBR(28), dw = CAMELLIA_RL8(dw); + SUBR(28) = SUBL(28) ^ dw, SUBL(28) = dw; + dw = SUBL(29) ^ SUBR(29), dw = CAMELLIA_RL8(dw); + SUBR(29) = SUBL(29) ^ dw, SUBL(29) = dw; + dw = SUBL(30) ^ SUBR(30), dw = CAMELLIA_RL8(dw); + SUBR(30) = SUBL(30) ^ dw, SUBL(30) = dw; + dw = SUBL(31) ^ SUBR(31), dw = CAMELLIA_RL8(dw); + SUBR(31) = SUBL(31) ^ dw, SUBL(31) = dw; +} + +void +camellia_setup192(const unsigned char *key, uint32_t *subkey) +{ + unsigned char kk[32]; + uint32_t krll, krlr, krrl,krrr; + + memcpy(kk, key, 24); + memcpy((unsigned char *)&krll, key+16,4); + memcpy((unsigned char *)&krlr, key+20,4); + krrl = ~krll; + krrr = ~krlr; + memcpy(kk+24, (unsigned char *)&krrl, 4); + memcpy(kk+28, (unsigned char *)&krrr, 4); + camellia_setup256(kk, subkey); +} + + +/** + * Stuff related to camellia encryption/decryption + */ +void +camellia_encrypt128(const uint32_t *subkey, uint32_t *io) +{ + uint32_t il, ir, t0, t1; + + /* pre whitening but absorb kw2*/ + io[0] ^= SUBL(0); + io[1] ^= SUBR(0); + /* main iteration */ + + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(2),SUBR(2), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(3),SUBR(3), + io[0],io[1],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(4),SUBR(4), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(5),SUBR(5), + io[0],io[1],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(6),SUBR(6), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(7),SUBR(7), + io[0],io[1],il,ir,t0,t1); + + CAMELLIA_FLS(io[0],io[1],io[2],io[3], SUBL(8),SUBR(8), SUBL(9),SUBR(9), + t0,t1,il,ir); + + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(10),SUBR(10), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(11),SUBR(11), + io[0],io[1],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(12),SUBR(12), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(13),SUBR(13), + io[0],io[1],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(14),SUBR(14), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(15),SUBR(15), + io[0],io[1],il,ir,t0,t1); + + CAMELLIA_FLS(io[0],io[1],io[2],io[3], SUBL(16), SUBR(16), SUBL(17),SUBR(17), + t0,t1,il,ir); + + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(18),SUBR(18), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(19),SUBR(19), + io[0],io[1],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(20),SUBR(20), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(21),SUBR(21), + io[0],io[1],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(22),SUBR(22), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(23),SUBR(23), + io[0],io[1],il,ir,t0,t1); + + /* post whitening but kw4 */ + io[2] ^= SUBL(24); + io[3] ^= SUBR(24); + + t0 = io[0]; + t1 = io[1]; + io[0] = io[2]; + io[1] = io[3]; + io[2] = t0; + io[3] = t1; +} + +void +camellia_decrypt128(const uint32_t *subkey, uint32_t *io) +{ + uint32_t il,ir,t0,t1; /* temporary valiables */ + + /* pre whitening but absorb kw2*/ + io[0] ^= SUBL(24); + io[1] ^= SUBR(24); + + /* main iteration */ + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(23),SUBR(23), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(22),SUBR(22), + io[0],io[1],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(21),SUBR(21), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(20),SUBR(20), + io[0],io[1],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(19),SUBR(19), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(18),SUBR(18), + io[0],io[1],il,ir,t0,t1); + + CAMELLIA_FLS(io[0],io[1],io[2],io[3],SUBL(17),SUBR(17),SUBL(16),SUBR(16), + t0,t1,il,ir); + + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(15),SUBR(15), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(14),SUBR(14), + io[0],io[1],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(13),SUBR(13), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(12),SUBR(12), + io[0],io[1],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(11),SUBR(11), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(10),SUBR(10), + io[0],io[1],il,ir,t0,t1); + + CAMELLIA_FLS(io[0],io[1],io[2],io[3], SUBL(9),SUBR(9), SUBL(8),SUBR(8), + t0,t1,il,ir); + + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(7),SUBR(7), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(6),SUBR(6), + io[0],io[1],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(5),SUBR(5), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(4),SUBR(4), + io[0],io[1],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(3),SUBR(3), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(2),SUBR(2), + io[0],io[1],il,ir,t0,t1); + + /* post whitening but kw4 */ + io[2] ^= SUBL(0); + io[3] ^= SUBR(0); + + t0 = io[0]; + t1 = io[1]; + io[0] = io[2]; + io[1] = io[3]; + io[2] = t0; + io[3] = t1; +} + +/** + * stuff for 192 and 256bit encryption/decryption + */ +void +camellia_encrypt256(const uint32_t *subkey, uint32_t *io) +{ + uint32_t il,ir,t0,t1; /* temporary valiables */ + + /* pre whitening but absorb kw2*/ + io[0] ^= SUBL(0); + io[1] ^= SUBR(0); + + /* main iteration */ + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(2),SUBR(2), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(3),SUBR(3), + io[0],io[1],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(4),SUBR(4), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(5),SUBR(5), + io[0],io[1],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(6),SUBR(6), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(7),SUBR(7), + io[0],io[1],il,ir,t0,t1); + + CAMELLIA_FLS(io[0],io[1],io[2],io[3], SUBL(8),SUBR(8), SUBL(9),SUBR(9), + t0,t1,il,ir); + + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(10),SUBR(10), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(11),SUBR(11), + io[0],io[1],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(12),SUBR(12), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(13),SUBR(13), + io[0],io[1],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(14),SUBR(14), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(15),SUBR(15), + io[0],io[1],il,ir,t0,t1); + + CAMELLIA_FLS(io[0],io[1],io[2],io[3], SUBL(16),SUBR(16), SUBL(17),SUBR(17), + t0,t1,il,ir); + + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(18),SUBR(18), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(19),SUBR(19), + io[0],io[1],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(20),SUBR(20), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(21),SUBR(21), + io[0],io[1],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(22),SUBR(22), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(23),SUBR(23), + io[0],io[1],il,ir,t0,t1); + + CAMELLIA_FLS(io[0],io[1],io[2],io[3], SUBL(24),SUBR(24), SUBL(25),SUBR(25), + t0,t1,il,ir); + + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(26),SUBR(26), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(27),SUBR(27), + io[0],io[1],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(28),SUBR(28), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(29),SUBR(29), + io[0],io[1],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(30),SUBR(30), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(31),SUBR(31), + io[0],io[1],il,ir,t0,t1); + + /* post whitening but kw4 */ + io[2] ^= SUBL(32); + io[3] ^= SUBR(32); + + t0 = io[0]; + t1 = io[1]; + io[0] = io[2]; + io[1] = io[3]; + io[2] = t0; + io[3] = t1; +} + +void +camellia_decrypt256(const uint32_t *subkey, uint32_t *io) +{ + uint32_t il,ir,t0,t1; /* temporary valiables */ + + /* pre whitening but absorb kw2*/ + io[0] ^= SUBL(32); + io[1] ^= SUBR(32); + + /* main iteration */ + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(31),SUBR(31), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(30),SUBR(30), + io[0],io[1],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(29),SUBR(29), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(28),SUBR(28), + io[0],io[1],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(27),SUBR(27), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(26),SUBR(26), + io[0],io[1],il,ir,t0,t1); + + CAMELLIA_FLS(io[0],io[1],io[2],io[3], SUBL(25),SUBR(25), SUBL(24),SUBR(24), + t0,t1,il,ir); + + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(23),SUBR(23), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(22),SUBR(22), + io[0],io[1],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(21),SUBR(21), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(20),SUBR(20), + io[0],io[1],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(19),SUBR(19), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(18),SUBR(18), + io[0],io[1],il,ir,t0,t1); + + CAMELLIA_FLS(io[0],io[1],io[2],io[3], SUBL(17),SUBR(17), SUBL(16),SUBR(16), + t0,t1,il,ir); + + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(15),SUBR(15), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(14),SUBR(14), + io[0],io[1],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(13),SUBR(13), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(12),SUBR(12), + io[0],io[1],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(11),SUBR(11), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(10),SUBR(10), + io[0],io[1],il,ir,t0,t1); + + CAMELLIA_FLS(io[0],io[1],io[2],io[3], SUBL(9),SUBR(9), SUBL(8),SUBR(8), + t0,t1,il,ir); + + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(7),SUBR(7), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(6),SUBR(6), + io[0],io[1],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(5),SUBR(5), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(4),SUBR(4), + io[0],io[1],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[0],io[1], SUBL(3),SUBR(3), + io[2],io[3],il,ir,t0,t1); + CAMELLIA_ROUNDSM(io[2],io[3], SUBL(2),SUBR(2), + io[0],io[1],il,ir,t0,t1); + + /* post whitening but kw4 */ + io[2] ^= SUBL(0); + io[3] ^= SUBR(0); + + t0 = io[0]; + t1 = io[1]; + io[0] = io[2]; + io[1] = io[3]; + io[2] = t0; + io[3] = t1; +} + +void +Camellia_Ekeygen(const int keyBitLength, + const unsigned char *rawKey, + uint32_t *subkey) +{ + KASSERT(keyBitLength == 128 || keyBitLength == 192 || keyBitLength == 256); + + switch(keyBitLength) { + case 128: + camellia_setup128(rawKey, subkey); + break; + case 192: + camellia_setup192(rawKey, subkey); + break; + case 256: + camellia_setup256(rawKey, subkey); + break; + default: + break; + } +} +void +Camellia_EncryptBlock(const int keyBitLength, + const unsigned char *plaintext, + const uint32_t *subkey, + unsigned char *ciphertext) +{ + uint32_t tmp[4]; + + tmp[0] = GETU32(plaintext); + tmp[1] = GETU32(plaintext + 4); + tmp[2] = GETU32(plaintext + 8); + tmp[3] = GETU32(plaintext + 12); + + switch (keyBitLength) { + case 128: + camellia_encrypt128(subkey, tmp); + break; + case 192: + /* fall through */ + case 256: + camellia_encrypt256(subkey, tmp); + break; + default: + break; + } + + PUTU32(ciphertext, tmp[0]); + PUTU32(ciphertext+4, tmp[1]); + PUTU32(ciphertext+8, tmp[2]); + PUTU32(ciphertext+12, tmp[3]); +} + +void +Camellia_DecryptBlock(const int keyBitLength, + const unsigned char *ciphertext, + const uint32_t *subkey, + unsigned char *plaintext) +{ + uint32_t tmp[4]; + + tmp[0] = GETU32(ciphertext); + tmp[1] = GETU32(ciphertext + 4); + tmp[2] = GETU32(ciphertext + 8); + tmp[3] = GETU32(ciphertext + 12); + + switch (keyBitLength) { + case 128: + camellia_decrypt128(subkey, tmp); + break; + case 192: + /* fall through */ + case 256: + camellia_decrypt256(subkey, tmp); + break; + default: + break; + } + + PUTU32(plaintext, tmp[0]); + PUTU32(plaintext+4, tmp[1]); + PUTU32(plaintext+8, tmp[2]); + PUTU32(plaintext+12, tmp[3]); +} + +MODULE(MODULE_CLASS_MISC, camellia, NULL); + +static int +camellia_modcmd(modcmd_t cmd, void *opaque) +{ + + switch (cmd) { + case MODULE_CMD_INIT: + return 0; + case MODULE_CMD_FINI: + return 0; + default: + return ENOTTY; + } +} diff --git a/sys/crypto/camellia/camellia.h b/sys/crypto/camellia/camellia.h new file mode 100644 index 000000000..d5f7eafe2 --- /dev/null +++ b/sys/crypto/camellia/camellia.h @@ -0,0 +1,69 @@ +/* $NetBSD: camellia.h,v 1.1 2011/05/05 17:38:36 drochner Exp $ */ + +/* camellia.h ver 1.1.0 + * + * Copyright (c) 2006 + * NTT (Nippon Telegraph and Telephone Corporation) . All rights reserved. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the above copyright + * notice, this list of conditions and the following disclaimer as + * the first lines of this file unmodified. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * + * THIS SOFTWARE IS PROVIDED BY NTT ``AS IS'' AND ANY EXPRESS OR + * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES + * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. + * IN NO EVENT SHALL NTT BE LIABLE FOR ANY DIRECT, INDIRECT, + * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT + * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, + * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY + * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT + * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF + * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + */ + +#ifndef _CAMELLIA_H +#define _CAMELLIA_H + +#define CAMELLIA_BLOCK_SIZE 16 +#define CAMELLIA_SUBKEYWORD 68 /* (34*8/4) */ + +typedef struct { + int bits; /* key-length */ + uint32_t subkey[CAMELLIA_SUBKEYWORD]; /* encrypt/decrypt key schedule */ +} camellia_ctx; + +void camellia_set_key(camellia_ctx *, const u_char *, int); +void camellia_decrypt(const camellia_ctx *, const u_char *, u_char *); +void camellia_encrypt(const camellia_ctx *, const u_char *, u_char *); + + +void Camellia_Ekeygen(const int keyBitLength, + const unsigned char *rawKey, + uint32_t *subkey); + +void Camellia_EncryptBlock(const int keyBitLength, + const unsigned char *plaintext, + const uint32_t *subkey, + unsigned char *cipherText); + +void Camellia_DecryptBlock(const int keyBitLength, + const unsigned char *cipherText, + const uint32_t *subkey, + unsigned char *plaintext); + +void camellia_setup128(const unsigned char *key, uint32_t *subkey); +void camellia_setup192(const unsigned char *key, uint32_t *subkey); +void camellia_setup256(const unsigned char *key, uint32_t *subkey); +void camellia_encrypt128(const uint32_t *subkey, uint32_t *io); +void camellia_encrypt256(const uint32_t *subkey, uint32_t *io); +void camellia_decrypt128(const uint32_t *subkey, uint32_t *io); +void camellia_decrypt256(const uint32_t *subkey, uint32_t *io); + + +#endif /* _CAMELLIA_H */ diff --git a/sys/crypto/camellia/files.camellia b/sys/crypto/camellia/files.camellia new file mode 100644 index 000000000..832733958 --- /dev/null +++ b/sys/crypto/camellia/files.camellia @@ -0,0 +1,6 @@ +# $NetBSD: files.camellia,v 1.1 2011/05/05 17:38:36 drochner Exp $ + +define camellia + +file crypto/camellia/camellia.c camellia +file crypto/camellia/camellia-api.c camellia diff --git a/sys/crypto/cast128/cast128.c b/sys/crypto/cast128/cast128.c new file mode 100644 index 000000000..34f2cb7ef --- /dev/null +++ b/sys/crypto/cast128/cast128.c @@ -0,0 +1,271 @@ +/* $NetBSD: cast128.c,v 1.10 2014/01/01 15:18:57 pgoyette Exp $ */ +/* $OpenBSD: cast.c,v 1.2 2000/06/06 06:49:47 deraadt Exp $ */ + +/* + * CAST-128 in C + * Written by Steve Reid + * 100% Public Domain - no warranty + * Released 1997.10.11 + */ + +#include +__KERNEL_RCSID(0, "$NetBSD: cast128.c,v 1.10 2014/01/01 15:18:57 pgoyette Exp $"); + +#include +#include +#include + +#include +#include + +/* Macros to access 8-bit bytes out of a 32-bit word */ +#define U_INT8_Ta(x) ( (u_int8_t) (x>>24) ) +#define U_INT8_Tb(x) ( (u_int8_t) ((x>>16)&255) ) +#define U_INT8_Tc(x) ( (u_int8_t) ((x>>8)&255) ) +#define U_INT8_Td(x) ( (u_int8_t) ((x)&255) ) + +/* Circular left shift */ +#define ROL(x, n) ( ((x)<<(n)) | ((x)>>(32-(n))) ) + +/* CAST-128 uses three different round functions */ +#define F1(l, r, i) \ + t = ROL(key->xkey[i] + r, key->xkey[i+16]); \ + l ^= ((cast_sbox1[U_INT8_Ta(t)] ^ cast_sbox2[U_INT8_Tb(t)]) - \ + cast_sbox3[U_INT8_Tc(t)]) + cast_sbox4[U_INT8_Td(t)]; +#define F2(l, r, i) \ + t = ROL(key->xkey[i] ^ r, key->xkey[i+16]); \ + l ^= ((cast_sbox1[U_INT8_Ta(t)] - cast_sbox2[U_INT8_Tb(t)]) + \ + cast_sbox3[U_INT8_Tc(t)]) ^ cast_sbox4[U_INT8_Td(t)]; +#define F3(l, r, i) \ + t = ROL(key->xkey[i] - r, key->xkey[i+16]); \ + l ^= ((cast_sbox1[U_INT8_Ta(t)] + cast_sbox2[U_INT8_Tb(t)]) ^ \ + cast_sbox3[U_INT8_Tc(t)]) - cast_sbox4[U_INT8_Td(t)]; + + +/***** Encryption Function *****/ + +void cast128_encrypt(const cast128_key* key, const u_int8_t* inblock, + u_int8_t* outblock) +{ +u_int32_t t, l, r; + + /* Get inblock into l,r */ + l = ((u_int32_t)inblock[0] << 24) | ((u_int32_t)inblock[1] << 16) | + ((u_int32_t)inblock[2] << 8) | (u_int32_t)inblock[3]; + r = ((u_int32_t)inblock[4] << 24) | ((u_int32_t)inblock[5] << 16) | + ((u_int32_t)inblock[6] << 8) | (u_int32_t)inblock[7]; + /* Do the work */ + F1(l, r, 0); + F2(r, l, 1); + F3(l, r, 2); + F1(r, l, 3); + F2(l, r, 4); + F3(r, l, 5); + F1(l, r, 6); + F2(r, l, 7); + F3(l, r, 8); + F1(r, l, 9); + F2(l, r, 10); + F3(r, l, 11); + /* Only do full 16 rounds if key length > 80 bits */ + if (key->rounds > 12) { + F1(l, r, 12); + F2(r, l, 13); + F3(l, r, 14); + F1(r, l, 15); + } + /* Put l,r into outblock */ + outblock[0] = U_INT8_Ta(r); + outblock[1] = U_INT8_Tb(r); + outblock[2] = U_INT8_Tc(r); + outblock[3] = U_INT8_Td(r); + outblock[4] = U_INT8_Ta(l); + outblock[5] = U_INT8_Tb(l); + outblock[6] = U_INT8_Tc(l); + outblock[7] = U_INT8_Td(l); + /* Wipe clean */ + t = l = r = 0; +} + + +/***** Decryption Function *****/ + +void cast128_decrypt(const cast128_key* key, const u_int8_t* inblock, + u_int8_t* outblock) +{ +u_int32_t t, l, r; + + /* Get inblock into l,r */ + r = ((u_int32_t)inblock[0] << 24) | ((u_int32_t)inblock[1] << 16) | + ((u_int32_t)inblock[2] << 8) | (u_int32_t)inblock[3]; + l = ((u_int32_t)inblock[4] << 24) | ((u_int32_t)inblock[5] << 16) | + ((u_int32_t)inblock[6] << 8) | (u_int32_t)inblock[7]; + /* Do the work */ + /* Only do full 16 rounds if key length > 80 bits */ + if (key->rounds > 12) { + F1(r, l, 15); + F3(l, r, 14); + F2(r, l, 13); + F1(l, r, 12); + } + F3(r, l, 11); + F2(l, r, 10); + F1(r, l, 9); + F3(l, r, 8); + F2(r, l, 7); + F1(l, r, 6); + F3(r, l, 5); + F2(l, r, 4); + F1(r, l, 3); + F3(l, r, 2); + F2(r, l, 1); + F1(l, r, 0); + /* Put l,r into outblock */ + outblock[0] = U_INT8_Ta(l); + outblock[1] = U_INT8_Tb(l); + outblock[2] = U_INT8_Tc(l); + outblock[3] = U_INT8_Td(l); + outblock[4] = U_INT8_Ta(r); + outblock[5] = U_INT8_Tb(r); + outblock[6] = U_INT8_Tc(r); + outblock[7] = U_INT8_Td(r); + /* Wipe clean */ + t = l = r = 0; +} + + +/***** Key Schedual *****/ + +void cast128_setkey(cast128_key* key, const u_int8_t* rawkey, int keybytes) +{ + u_int32_t t[4], z[4], x[4]; + int i; + + /* Set number of rounds to 12 or 16, depending on key length */ + key->rounds = (keybytes <= 10 ? 12 : 16); + + /* Copy key to workspace x */ + for (i = 0; i < 4; i++) { + x[i] = 0; + t[i] = z[i] = 0; /* XXX gcc */ + if ((i*4+0) < keybytes) x[i] = (u_int32_t)rawkey[i*4+0] << 24; + if ((i*4+1) < keybytes) x[i] |= (u_int32_t)rawkey[i*4+1] << 16; + if ((i*4+2) < keybytes) x[i] |= (u_int32_t)rawkey[i*4+2] << 8; + if ((i*4+3) < keybytes) x[i] |= (u_int32_t)rawkey[i*4+3]; + } + /* Generate 32 subkeys, four at a time */ + for (i = 0; i < 32; i+=4) { + switch (i & 4) { + case 0: + t[0] = z[0] = x[0] ^ cast_sbox5[U_INT8_Tb(x[3])] ^ + cast_sbox6[U_INT8_Td(x[3])] ^ cast_sbox7[U_INT8_Ta(x[3])] ^ + cast_sbox8[U_INT8_Tc(x[3])] ^ cast_sbox7[U_INT8_Ta(x[2])]; + t[1] = z[1] = x[2] ^ cast_sbox5[U_INT8_Ta(z[0])] ^ + cast_sbox6[U_INT8_Tc(z[0])] ^ cast_sbox7[U_INT8_Tb(z[0])] ^ + cast_sbox8[U_INT8_Td(z[0])] ^ cast_sbox8[U_INT8_Tc(x[2])]; + t[2] = z[2] = x[3] ^ cast_sbox5[U_INT8_Td(z[1])] ^ + cast_sbox6[U_INT8_Tc(z[1])] ^ cast_sbox7[U_INT8_Tb(z[1])] ^ + cast_sbox8[U_INT8_Ta(z[1])] ^ cast_sbox5[U_INT8_Tb(x[2])]; + t[3] = z[3] = x[1] ^ cast_sbox5[U_INT8_Tc(z[2])] ^ + cast_sbox6[U_INT8_Tb(z[2])] ^ cast_sbox7[U_INT8_Td(z[2])] ^ + cast_sbox8[U_INT8_Ta(z[2])] ^ cast_sbox6[U_INT8_Td(x[2])]; + break; + case 4: + t[0] = x[0] = z[2] ^ cast_sbox5[U_INT8_Tb(z[1])] ^ + cast_sbox6[U_INT8_Td(z[1])] ^ cast_sbox7[U_INT8_Ta(z[1])] ^ + cast_sbox8[U_INT8_Tc(z[1])] ^ cast_sbox7[U_INT8_Ta(z[0])]; + t[1] = x[1] = z[0] ^ cast_sbox5[U_INT8_Ta(x[0])] ^ + cast_sbox6[U_INT8_Tc(x[0])] ^ cast_sbox7[U_INT8_Tb(x[0])] ^ + cast_sbox8[U_INT8_Td(x[0])] ^ cast_sbox8[U_INT8_Tc(z[0])]; + t[2] = x[2] = z[1] ^ cast_sbox5[U_INT8_Td(x[1])] ^ + cast_sbox6[U_INT8_Tc(x[1])] ^ cast_sbox7[U_INT8_Tb(x[1])] ^ + cast_sbox8[U_INT8_Ta(x[1])] ^ cast_sbox5[U_INT8_Tb(z[0])]; + t[3] = x[3] = z[3] ^ cast_sbox5[U_INT8_Tc(x[2])] ^ + cast_sbox6[U_INT8_Tb(x[2])] ^ cast_sbox7[U_INT8_Td(x[2])] ^ + cast_sbox8[U_INT8_Ta(x[2])] ^ cast_sbox6[U_INT8_Td(z[0])]; + break; + } + switch (i & 12) { + case 0: + case 12: + key->xkey[i+0] = cast_sbox5[U_INT8_Ta(t[2])] ^ cast_sbox6[U_INT8_Tb(t[2])] ^ + cast_sbox7[U_INT8_Td(t[1])] ^ cast_sbox8[U_INT8_Tc(t[1])]; + key->xkey[i+1] = cast_sbox5[U_INT8_Tc(t[2])] ^ cast_sbox6[U_INT8_Td(t[2])] ^ + cast_sbox7[U_INT8_Tb(t[1])] ^ cast_sbox8[U_INT8_Ta(t[1])]; + key->xkey[i+2] = cast_sbox5[U_INT8_Ta(t[3])] ^ cast_sbox6[U_INT8_Tb(t[3])] ^ + cast_sbox7[U_INT8_Td(t[0])] ^ cast_sbox8[U_INT8_Tc(t[0])]; + key->xkey[i+3] = cast_sbox5[U_INT8_Tc(t[3])] ^ cast_sbox6[U_INT8_Td(t[3])] ^ + cast_sbox7[U_INT8_Tb(t[0])] ^ cast_sbox8[U_INT8_Ta(t[0])]; + break; + case 4: + case 8: + key->xkey[i+0] = cast_sbox5[U_INT8_Td(t[0])] ^ cast_sbox6[U_INT8_Tc(t[0])] ^ + cast_sbox7[U_INT8_Ta(t[3])] ^ cast_sbox8[U_INT8_Tb(t[3])]; + key->xkey[i+1] = cast_sbox5[U_INT8_Tb(t[0])] ^ cast_sbox6[U_INT8_Ta(t[0])] ^ + cast_sbox7[U_INT8_Tc(t[3])] ^ cast_sbox8[U_INT8_Td(t[3])]; + key->xkey[i+2] = cast_sbox5[U_INT8_Td(t[1])] ^ cast_sbox6[U_INT8_Tc(t[1])] ^ + cast_sbox7[U_INT8_Ta(t[2])] ^ cast_sbox8[U_INT8_Tb(t[2])]; + key->xkey[i+3] = cast_sbox5[U_INT8_Tb(t[1])] ^ cast_sbox6[U_INT8_Ta(t[1])] ^ + cast_sbox7[U_INT8_Tc(t[2])] ^ cast_sbox8[U_INT8_Td(t[2])]; + break; + } + switch (i & 12) { + case 0: + key->xkey[i+0] ^= cast_sbox5[U_INT8_Tc(z[0])]; + key->xkey[i+1] ^= cast_sbox6[U_INT8_Tc(z[1])]; + key->xkey[i+2] ^= cast_sbox7[U_INT8_Tb(z[2])]; + key->xkey[i+3] ^= cast_sbox8[U_INT8_Ta(z[3])]; + break; + case 4: + key->xkey[i+0] ^= cast_sbox5[U_INT8_Ta(x[2])]; + key->xkey[i+1] ^= cast_sbox6[U_INT8_Tb(x[3])]; + key->xkey[i+2] ^= cast_sbox7[U_INT8_Td(x[0])]; + key->xkey[i+3] ^= cast_sbox8[U_INT8_Td(x[1])]; + break; + case 8: + key->xkey[i+0] ^= cast_sbox5[U_INT8_Tb(z[2])]; + key->xkey[i+1] ^= cast_sbox6[U_INT8_Ta(z[3])]; + key->xkey[i+2] ^= cast_sbox7[U_INT8_Tc(z[0])]; + key->xkey[i+3] ^= cast_sbox8[U_INT8_Tc(z[1])]; + break; + case 12: + key->xkey[i+0] ^= cast_sbox5[U_INT8_Td(x[0])]; + key->xkey[i+1] ^= cast_sbox6[U_INT8_Td(x[1])]; + key->xkey[i+2] ^= cast_sbox7[U_INT8_Ta(x[2])]; + key->xkey[i+3] ^= cast_sbox8[U_INT8_Tb(x[3])]; + break; + } + if (i >= 16) { + key->xkey[i+0] &= 31; + key->xkey[i+1] &= 31; + key->xkey[i+2] &= 31; + key->xkey[i+3] &= 31; + } + } + /* Wipe clean */ + for (i = 0; i < 4; i++) { + t[i] = x[i] = z[i] = 0; + } +} + +/* Made in Canada */ + +#if defined(_KERNEL) + +MODULE(MODULE_CLASS_MISC, cast128, NULL); + +static int +cast128_modcmd(modcmd_t cmd, void *opaque) +{ + + switch (cmd) { + case MODULE_CMD_INIT: + return 0; + case MODULE_CMD_FINI: + return 0; + default: + return ENOTTY; + } +} + +#endif /* defined(KERNEL) */ diff --git a/sys/crypto/cast128/cast128.h b/sys/crypto/cast128/cast128.h new file mode 100644 index 000000000..9abb15302 --- /dev/null +++ b/sys/crypto/cast128/cast128.h @@ -0,0 +1,25 @@ +/* $NetBSD: cast128.h,v 1.7 2005/12/11 12:20:52 christos Exp $ */ +/* $OpenBSD: cast.h,v 1.2 2002/03/14 01:26:51 millert Exp $ */ + +/* + * CAST-128 in C + * Written by Steve Reid + * 100% Public Domain - no warranty + * Released 1997.10.11 + */ + +#ifndef _CAST128_H_ +#define _CAST128_H_ + +typedef struct { + u_int32_t xkey[32]; /* Key, after expansion */ + int rounds; /* Number of rounds to use, 12 or 16 */ +} cast128_key; + +void cast128_setkey(cast128_key *key, const u_int8_t *rawkey, int keybytes); +void cast128_encrypt(const cast128_key *key, const u_int8_t *inblock, + u_int8_t *outblock); +void cast128_decrypt(const cast128_key *key, const u_int8_t *inblock, + u_int8_t *outblock); + +#endif /* _CAST128_H_ */ diff --git a/sys/crypto/cast128/cast128sb.h b/sys/crypto/cast128/cast128sb.h new file mode 100644 index 000000000..a7b938406 --- /dev/null +++ b/sys/crypto/cast128/cast128sb.h @@ -0,0 +1,545 @@ +/* $NetBSD: cast128sb.h,v 1.2 2005/12/11 12:20:52 christos Exp $ */ +/* $OpenBSD: castsb.h,v 1.1 2000/02/28 23:13:04 deraadt Exp $ */ + +/* + * CAST-128 in C + * Written by Steve Reid + * 100% Public Domain - no warranty + * Released 1997.10.11 + */ + +static const u_int32_t cast_sbox1[256] = { + 0x30FB40D4, 0x9FA0FF0B, 0x6BECCD2F, 0x3F258C7A, + 0x1E213F2F, 0x9C004DD3, 0x6003E540, 0xCF9FC949, + 0xBFD4AF27, 0x88BBBDB5, 0xE2034090, 0x98D09675, + 0x6E63A0E0, 0x15C361D2, 0xC2E7661D, 0x22D4FF8E, + 0x28683B6F, 0xC07FD059, 0xFF2379C8, 0x775F50E2, + 0x43C340D3, 0xDF2F8656, 0x887CA41A, 0xA2D2BD2D, + 0xA1C9E0D6, 0x346C4819, 0x61B76D87, 0x22540F2F, + 0x2ABE32E1, 0xAA54166B, 0x22568E3A, 0xA2D341D0, + 0x66DB40C8, 0xA784392F, 0x004DFF2F, 0x2DB9D2DE, + 0x97943FAC, 0x4A97C1D8, 0x527644B7, 0xB5F437A7, + 0xB82CBAEF, 0xD751D159, 0x6FF7F0ED, 0x5A097A1F, + 0x827B68D0, 0x90ECF52E, 0x22B0C054, 0xBC8E5935, + 0x4B6D2F7F, 0x50BB64A2, 0xD2664910, 0xBEE5812D, + 0xB7332290, 0xE93B159F, 0xB48EE411, 0x4BFF345D, + 0xFD45C240, 0xAD31973F, 0xC4F6D02E, 0x55FC8165, + 0xD5B1CAAD, 0xA1AC2DAE, 0xA2D4B76D, 0xC19B0C50, + 0x882240F2, 0x0C6E4F38, 0xA4E4BFD7, 0x4F5BA272, + 0x564C1D2F, 0xC59C5319, 0xB949E354, 0xB04669FE, + 0xB1B6AB8A, 0xC71358DD, 0x6385C545, 0x110F935D, + 0x57538AD5, 0x6A390493, 0xE63D37E0, 0x2A54F6B3, + 0x3A787D5F, 0x6276A0B5, 0x19A6FCDF, 0x7A42206A, + 0x29F9D4D5, 0xF61B1891, 0xBB72275E, 0xAA508167, + 0x38901091, 0xC6B505EB, 0x84C7CB8C, 0x2AD75A0F, + 0x874A1427, 0xA2D1936B, 0x2AD286AF, 0xAA56D291, + 0xD7894360, 0x425C750D, 0x93B39E26, 0x187184C9, + 0x6C00B32D, 0x73E2BB14, 0xA0BEBC3C, 0x54623779, + 0x64459EAB, 0x3F328B82, 0x7718CF82, 0x59A2CEA6, + 0x04EE002E, 0x89FE78E6, 0x3FAB0950, 0x325FF6C2, + 0x81383F05, 0x6963C5C8, 0x76CB5AD6, 0xD49974C9, + 0xCA180DCF, 0x380782D5, 0xC7FA5CF6, 0x8AC31511, + 0x35E79E13, 0x47DA91D0, 0xF40F9086, 0xA7E2419E, + 0x31366241, 0x051EF495, 0xAA573B04, 0x4A805D8D, + 0x548300D0, 0x00322A3C, 0xBF64CDDF, 0xBA57A68E, + 0x75C6372B, 0x50AFD341, 0xA7C13275, 0x915A0BF5, + 0x6B54BFAB, 0x2B0B1426, 0xAB4CC9D7, 0x449CCD82, + 0xF7FBF265, 0xAB85C5F3, 0x1B55DB94, 0xAAD4E324, + 0xCFA4BD3F, 0x2DEAA3E2, 0x9E204D02, 0xC8BD25AC, + 0xEADF55B3, 0xD5BD9E98, 0xE31231B2, 0x2AD5AD6C, + 0x954329DE, 0xADBE4528, 0xD8710F69, 0xAA51C90F, + 0xAA786BF6, 0x22513F1E, 0xAA51A79B, 0x2AD344CC, + 0x7B5A41F0, 0xD37CFBAD, 0x1B069505, 0x41ECE491, + 0xB4C332E6, 0x032268D4, 0xC9600ACC, 0xCE387E6D, + 0xBF6BB16C, 0x6A70FB78, 0x0D03D9C9, 0xD4DF39DE, + 0xE01063DA, 0x4736F464, 0x5AD328D8, 0xB347CC96, + 0x75BB0FC3, 0x98511BFB, 0x4FFBCC35, 0xB58BCF6A, + 0xE11F0ABC, 0xBFC5FE4A, 0xA70AEC10, 0xAC39570A, + 0x3F04442F, 0x6188B153, 0xE0397A2E, 0x5727CB79, + 0x9CEB418F, 0x1CACD68D, 0x2AD37C96, 0x0175CB9D, + 0xC69DFF09, 0xC75B65F0, 0xD9DB40D8, 0xEC0E7779, + 0x4744EAD4, 0xB11C3274, 0xDD24CB9E, 0x7E1C54BD, + 0xF01144F9, 0xD2240EB1, 0x9675B3FD, 0xA3AC3755, + 0xD47C27AF, 0x51C85F4D, 0x56907596, 0xA5BB15E6, + 0x580304F0, 0xCA042CF1, 0x011A37EA, 0x8DBFAADB, + 0x35BA3E4A, 0x3526FFA0, 0xC37B4D09, 0xBC306ED9, + 0x98A52666, 0x5648F725, 0xFF5E569D, 0x0CED63D0, + 0x7C63B2CF, 0x700B45E1, 0xD5EA50F1, 0x85A92872, + 0xAF1FBDA7, 0xD4234870, 0xA7870BF3, 0x2D3B4D79, + 0x42E04198, 0x0CD0EDE7, 0x26470DB8, 0xF881814C, + 0x474D6AD7, 0x7C0C5E5C, 0xD1231959, 0x381B7298, + 0xF5D2F4DB, 0xAB838653, 0x6E2F1E23, 0x83719C9E, + 0xBD91E046, 0x9A56456E, 0xDC39200C, 0x20C8C571, + 0x962BDA1C, 0xE1E696FF, 0xB141AB08, 0x7CCA89B9, + 0x1A69E783, 0x02CC4843, 0xA2F7C579, 0x429EF47D, + 0x427B169C, 0x5AC9F049, 0xDD8F0F00, 0x5C8165BF +}; + +static const u_int32_t cast_sbox2[256] = { + 0x1F201094, 0xEF0BA75B, 0x69E3CF7E, 0x393F4380, + 0xFE61CF7A, 0xEEC5207A, 0x55889C94, 0x72FC0651, + 0xADA7EF79, 0x4E1D7235, 0xD55A63CE, 0xDE0436BA, + 0x99C430EF, 0x5F0C0794, 0x18DCDB7D, 0xA1D6EFF3, + 0xA0B52F7B, 0x59E83605, 0xEE15B094, 0xE9FFD909, + 0xDC440086, 0xEF944459, 0xBA83CCB3, 0xE0C3CDFB, + 0xD1DA4181, 0x3B092AB1, 0xF997F1C1, 0xA5E6CF7B, + 0x01420DDB, 0xE4E7EF5B, 0x25A1FF41, 0xE180F806, + 0x1FC41080, 0x179BEE7A, 0xD37AC6A9, 0xFE5830A4, + 0x98DE8B7F, 0x77E83F4E, 0x79929269, 0x24FA9F7B, + 0xE113C85B, 0xACC40083, 0xD7503525, 0xF7EA615F, + 0x62143154, 0x0D554B63, 0x5D681121, 0xC866C359, + 0x3D63CF73, 0xCEE234C0, 0xD4D87E87, 0x5C672B21, + 0x071F6181, 0x39F7627F, 0x361E3084, 0xE4EB573B, + 0x602F64A4, 0xD63ACD9C, 0x1BBC4635, 0x9E81032D, + 0x2701F50C, 0x99847AB4, 0xA0E3DF79, 0xBA6CF38C, + 0x10843094, 0x2537A95E, 0xF46F6FFE, 0xA1FF3B1F, + 0x208CFB6A, 0x8F458C74, 0xD9E0A227, 0x4EC73A34, + 0xFC884F69, 0x3E4DE8DF, 0xEF0E0088, 0x3559648D, + 0x8A45388C, 0x1D804366, 0x721D9BFD, 0xA58684BB, + 0xE8256333, 0x844E8212, 0x128D8098, 0xFED33FB4, + 0xCE280AE1, 0x27E19BA5, 0xD5A6C252, 0xE49754BD, + 0xC5D655DD, 0xEB667064, 0x77840B4D, 0xA1B6A801, + 0x84DB26A9, 0xE0B56714, 0x21F043B7, 0xE5D05860, + 0x54F03084, 0x066FF472, 0xA31AA153, 0xDADC4755, + 0xB5625DBF, 0x68561BE6, 0x83CA6B94, 0x2D6ED23B, + 0xECCF01DB, 0xA6D3D0BA, 0xB6803D5C, 0xAF77A709, + 0x33B4A34C, 0x397BC8D6, 0x5EE22B95, 0x5F0E5304, + 0x81ED6F61, 0x20E74364, 0xB45E1378, 0xDE18639B, + 0x881CA122, 0xB96726D1, 0x8049A7E8, 0x22B7DA7B, + 0x5E552D25, 0x5272D237, 0x79D2951C, 0xC60D894C, + 0x488CB402, 0x1BA4FE5B, 0xA4B09F6B, 0x1CA815CF, + 0xA20C3005, 0x8871DF63, 0xB9DE2FCB, 0x0CC6C9E9, + 0x0BEEFF53, 0xE3214517, 0xB4542835, 0x9F63293C, + 0xEE41E729, 0x6E1D2D7C, 0x50045286, 0x1E6685F3, + 0xF33401C6, 0x30A22C95, 0x31A70850, 0x60930F13, + 0x73F98417, 0xA1269859, 0xEC645C44, 0x52C877A9, + 0xCDFF33A6, 0xA02B1741, 0x7CBAD9A2, 0x2180036F, + 0x50D99C08, 0xCB3F4861, 0xC26BD765, 0x64A3F6AB, + 0x80342676, 0x25A75E7B, 0xE4E6D1FC, 0x20C710E6, + 0xCDF0B680, 0x17844D3B, 0x31EEF84D, 0x7E0824E4, + 0x2CCB49EB, 0x846A3BAE, 0x8FF77888, 0xEE5D60F6, + 0x7AF75673, 0x2FDD5CDB, 0xA11631C1, 0x30F66F43, + 0xB3FAEC54, 0x157FD7FA, 0xEF8579CC, 0xD152DE58, + 0xDB2FFD5E, 0x8F32CE19, 0x306AF97A, 0x02F03EF8, + 0x99319AD5, 0xC242FA0F, 0xA7E3EBB0, 0xC68E4906, + 0xB8DA230C, 0x80823028, 0xDCDEF3C8, 0xD35FB171, + 0x088A1BC8, 0xBEC0C560, 0x61A3C9E8, 0xBCA8F54D, + 0xC72FEFFA, 0x22822E99, 0x82C570B4, 0xD8D94E89, + 0x8B1C34BC, 0x301E16E6, 0x273BE979, 0xB0FFEAA6, + 0x61D9B8C6, 0x00B24869, 0xB7FFCE3F, 0x08DC283B, + 0x43DAF65A, 0xF7E19798, 0x7619B72F, 0x8F1C9BA4, + 0xDC8637A0, 0x16A7D3B1, 0x9FC393B7, 0xA7136EEB, + 0xC6BCC63E, 0x1A513742, 0xEF6828BC, 0x520365D6, + 0x2D6A77AB, 0x3527ED4B, 0x821FD216, 0x095C6E2E, + 0xDB92F2FB, 0x5EEA29CB, 0x145892F5, 0x91584F7F, + 0x5483697B, 0x2667A8CC, 0x85196048, 0x8C4BACEA, + 0x833860D4, 0x0D23E0F9, 0x6C387E8A, 0x0AE6D249, + 0xB284600C, 0xD835731D, 0xDCB1C647, 0xAC4C56EA, + 0x3EBD81B3, 0x230EABB0, 0x6438BC87, 0xF0B5B1FA, + 0x8F5EA2B3, 0xFC184642, 0x0A036B7A, 0x4FB089BD, + 0x649DA589, 0xA345415E, 0x5C038323, 0x3E5D3BB9, + 0x43D79572, 0x7E6DD07C, 0x06DFDF1E, 0x6C6CC4EF, + 0x7160A539, 0x73BFBE70, 0x83877605, 0x4523ECF1 +}; + +static const u_int32_t cast_sbox3[256] = { + 0x8DEFC240, 0x25FA5D9F, 0xEB903DBF, 0xE810C907, + 0x47607FFF, 0x369FE44B, 0x8C1FC644, 0xAECECA90, + 0xBEB1F9BF, 0xEEFBCAEA, 0xE8CF1950, 0x51DF07AE, + 0x920E8806, 0xF0AD0548, 0xE13C8D83, 0x927010D5, + 0x11107D9F, 0x07647DB9, 0xB2E3E4D4, 0x3D4F285E, + 0xB9AFA820, 0xFADE82E0, 0xA067268B, 0x8272792E, + 0x553FB2C0, 0x489AE22B, 0xD4EF9794, 0x125E3FBC, + 0x21FFFCEE, 0x825B1BFD, 0x9255C5ED, 0x1257A240, + 0x4E1A8302, 0xBAE07FFF, 0x528246E7, 0x8E57140E, + 0x3373F7BF, 0x8C9F8188, 0xA6FC4EE8, 0xC982B5A5, + 0xA8C01DB7, 0x579FC264, 0x67094F31, 0xF2BD3F5F, + 0x40FFF7C1, 0x1FB78DFC, 0x8E6BD2C1, 0x437BE59B, + 0x99B03DBF, 0xB5DBC64B, 0x638DC0E6, 0x55819D99, + 0xA197C81C, 0x4A012D6E, 0xC5884A28, 0xCCC36F71, + 0xB843C213, 0x6C0743F1, 0x8309893C, 0x0FEDDD5F, + 0x2F7FE850, 0xD7C07F7E, 0x02507FBF, 0x5AFB9A04, + 0xA747D2D0, 0x1651192E, 0xAF70BF3E, 0x58C31380, + 0x5F98302E, 0x727CC3C4, 0x0A0FB402, 0x0F7FEF82, + 0x8C96FDAD, 0x5D2C2AAE, 0x8EE99A49, 0x50DA88B8, + 0x8427F4A0, 0x1EAC5790, 0x796FB449, 0x8252DC15, + 0xEFBD7D9B, 0xA672597D, 0xADA840D8, 0x45F54504, + 0xFA5D7403, 0xE83EC305, 0x4F91751A, 0x925669C2, + 0x23EFE941, 0xA903F12E, 0x60270DF2, 0x0276E4B6, + 0x94FD6574, 0x927985B2, 0x8276DBCB, 0x02778176, + 0xF8AF918D, 0x4E48F79E, 0x8F616DDF, 0xE29D840E, + 0x842F7D83, 0x340CE5C8, 0x96BBB682, 0x93B4B148, + 0xEF303CAB, 0x984FAF28, 0x779FAF9B, 0x92DC560D, + 0x224D1E20, 0x8437AA88, 0x7D29DC96, 0x2756D3DC, + 0x8B907CEE, 0xB51FD240, 0xE7C07CE3, 0xE566B4A1, + 0xC3E9615E, 0x3CF8209D, 0x6094D1E3, 0xCD9CA341, + 0x5C76460E, 0x00EA983B, 0xD4D67881, 0xFD47572C, + 0xF76CEDD9, 0xBDA8229C, 0x127DADAA, 0x438A074E, + 0x1F97C090, 0x081BDB8A, 0x93A07EBE, 0xB938CA15, + 0x97B03CFF, 0x3DC2C0F8, 0x8D1AB2EC, 0x64380E51, + 0x68CC7BFB, 0xD90F2788, 0x12490181, 0x5DE5FFD4, + 0xDD7EF86A, 0x76A2E214, 0xB9A40368, 0x925D958F, + 0x4B39FFFA, 0xBA39AEE9, 0xA4FFD30B, 0xFAF7933B, + 0x6D498623, 0x193CBCFA, 0x27627545, 0x825CF47A, + 0x61BD8BA0, 0xD11E42D1, 0xCEAD04F4, 0x127EA392, + 0x10428DB7, 0x8272A972, 0x9270C4A8, 0x127DE50B, + 0x285BA1C8, 0x3C62F44F, 0x35C0EAA5, 0xE805D231, + 0x428929FB, 0xB4FCDF82, 0x4FB66A53, 0x0E7DC15B, + 0x1F081FAB, 0x108618AE, 0xFCFD086D, 0xF9FF2889, + 0x694BCC11, 0x236A5CAE, 0x12DECA4D, 0x2C3F8CC5, + 0xD2D02DFE, 0xF8EF5896, 0xE4CF52DA, 0x95155B67, + 0x494A488C, 0xB9B6A80C, 0x5C8F82BC, 0x89D36B45, + 0x3A609437, 0xEC00C9A9, 0x44715253, 0x0A874B49, + 0xD773BC40, 0x7C34671C, 0x02717EF6, 0x4FEB5536, + 0xA2D02FFF, 0xD2BF60C4, 0xD43F03C0, 0x50B4EF6D, + 0x07478CD1, 0x006E1888, 0xA2E53F55, 0xB9E6D4BC, + 0xA2048016, 0x97573833, 0xD7207D67, 0xDE0F8F3D, + 0x72F87B33, 0xABCC4F33, 0x7688C55D, 0x7B00A6B0, + 0x947B0001, 0x570075D2, 0xF9BB88F8, 0x8942019E, + 0x4264A5FF, 0x856302E0, 0x72DBD92B, 0xEE971B69, + 0x6EA22FDE, 0x5F08AE2B, 0xAF7A616D, 0xE5C98767, + 0xCF1FEBD2, 0x61EFC8C2, 0xF1AC2571, 0xCC8239C2, + 0x67214CB8, 0xB1E583D1, 0xB7DC3E62, 0x7F10BDCE, + 0xF90A5C38, 0x0FF0443D, 0x606E6DC6, 0x60543A49, + 0x5727C148, 0x2BE98A1D, 0x8AB41738, 0x20E1BE24, + 0xAF96DA0F, 0x68458425, 0x99833BE5, 0x600D457D, + 0x282F9350, 0x8334B362, 0xD91D1120, 0x2B6D8DA0, + 0x642B1E31, 0x9C305A00, 0x52BCE688, 0x1B03588A, + 0xF7BAEFD5, 0x4142ED9C, 0xA4315C11, 0x83323EC5, + 0xDFEF4636, 0xA133C501, 0xE9D3531C, 0xEE353783 +}; + +static const u_int32_t cast_sbox4[256] = { + 0x9DB30420, 0x1FB6E9DE, 0xA7BE7BEF, 0xD273A298, + 0x4A4F7BDB, 0x64AD8C57, 0x85510443, 0xFA020ED1, + 0x7E287AFF, 0xE60FB663, 0x095F35A1, 0x79EBF120, + 0xFD059D43, 0x6497B7B1, 0xF3641F63, 0x241E4ADF, + 0x28147F5F, 0x4FA2B8CD, 0xC9430040, 0x0CC32220, + 0xFDD30B30, 0xC0A5374F, 0x1D2D00D9, 0x24147B15, + 0xEE4D111A, 0x0FCA5167, 0x71FF904C, 0x2D195FFE, + 0x1A05645F, 0x0C13FEFE, 0x081B08CA, 0x05170121, + 0x80530100, 0xE83E5EFE, 0xAC9AF4F8, 0x7FE72701, + 0xD2B8EE5F, 0x06DF4261, 0xBB9E9B8A, 0x7293EA25, + 0xCE84FFDF, 0xF5718801, 0x3DD64B04, 0xA26F263B, + 0x7ED48400, 0x547EEBE6, 0x446D4CA0, 0x6CF3D6F5, + 0x2649ABDF, 0xAEA0C7F5, 0x36338CC1, 0x503F7E93, + 0xD3772061, 0x11B638E1, 0x72500E03, 0xF80EB2BB, + 0xABE0502E, 0xEC8D77DE, 0x57971E81, 0xE14F6746, + 0xC9335400, 0x6920318F, 0x081DBB99, 0xFFC304A5, + 0x4D351805, 0x7F3D5CE3, 0xA6C866C6, 0x5D5BCCA9, + 0xDAEC6FEA, 0x9F926F91, 0x9F46222F, 0x3991467D, + 0xA5BF6D8E, 0x1143C44F, 0x43958302, 0xD0214EEB, + 0x022083B8, 0x3FB6180C, 0x18F8931E, 0x281658E6, + 0x26486E3E, 0x8BD78A70, 0x7477E4C1, 0xB506E07C, + 0xF32D0A25, 0x79098B02, 0xE4EABB81, 0x28123B23, + 0x69DEAD38, 0x1574CA16, 0xDF871B62, 0x211C40B7, + 0xA51A9EF9, 0x0014377B, 0x041E8AC8, 0x09114003, + 0xBD59E4D2, 0xE3D156D5, 0x4FE876D5, 0x2F91A340, + 0x557BE8DE, 0x00EAE4A7, 0x0CE5C2EC, 0x4DB4BBA6, + 0xE756BDFF, 0xDD3369AC, 0xEC17B035, 0x06572327, + 0x99AFC8B0, 0x56C8C391, 0x6B65811C, 0x5E146119, + 0x6E85CB75, 0xBE07C002, 0xC2325577, 0x893FF4EC, + 0x5BBFC92D, 0xD0EC3B25, 0xB7801AB7, 0x8D6D3B24, + 0x20C763EF, 0xC366A5FC, 0x9C382880, 0x0ACE3205, + 0xAAC9548A, 0xECA1D7C7, 0x041AFA32, 0x1D16625A, + 0x6701902C, 0x9B757A54, 0x31D477F7, 0x9126B031, + 0x36CC6FDB, 0xC70B8B46, 0xD9E66A48, 0x56E55A79, + 0x026A4CEB, 0x52437EFF, 0x2F8F76B4, 0x0DF980A5, + 0x8674CDE3, 0xEDDA04EB, 0x17A9BE04, 0x2C18F4DF, + 0xB7747F9D, 0xAB2AF7B4, 0xEFC34D20, 0x2E096B7C, + 0x1741A254, 0xE5B6A035, 0x213D42F6, 0x2C1C7C26, + 0x61C2F50F, 0x6552DAF9, 0xD2C231F8, 0x25130F69, + 0xD8167FA2, 0x0418F2C8, 0x001A96A6, 0x0D1526AB, + 0x63315C21, 0x5E0A72EC, 0x49BAFEFD, 0x187908D9, + 0x8D0DBD86, 0x311170A7, 0x3E9B640C, 0xCC3E10D7, + 0xD5CAD3B6, 0x0CAEC388, 0xF73001E1, 0x6C728AFF, + 0x71EAE2A1, 0x1F9AF36E, 0xCFCBD12F, 0xC1DE8417, + 0xAC07BE6B, 0xCB44A1D8, 0x8B9B0F56, 0x013988C3, + 0xB1C52FCA, 0xB4BE31CD, 0xD8782806, 0x12A3A4E2, + 0x6F7DE532, 0x58FD7EB6, 0xD01EE900, 0x24ADFFC2, + 0xF4990FC5, 0x9711AAC5, 0x001D7B95, 0x82E5E7D2, + 0x109873F6, 0x00613096, 0xC32D9521, 0xADA121FF, + 0x29908415, 0x7FBB977F, 0xAF9EB3DB, 0x29C9ED2A, + 0x5CE2A465, 0xA730F32C, 0xD0AA3FE8, 0x8A5CC091, + 0xD49E2CE7, 0x0CE454A9, 0xD60ACD86, 0x015F1919, + 0x77079103, 0xDEA03AF6, 0x78A8565E, 0xDEE356DF, + 0x21F05CBE, 0x8B75E387, 0xB3C50651, 0xB8A5C3EF, + 0xD8EEB6D2, 0xE523BE77, 0xC2154529, 0x2F69EFDF, + 0xAFE67AFB, 0xF470C4B2, 0xF3E0EB5B, 0xD6CC9876, + 0x39E4460C, 0x1FDA8538, 0x1987832F, 0xCA007367, + 0xA99144F8, 0x296B299E, 0x492FC295, 0x9266BEAB, + 0xB5676E69, 0x9BD3DDDA, 0xDF7E052F, 0xDB25701C, + 0x1B5E51EE, 0xF65324E6, 0x6AFCE36C, 0x0316CC04, + 0x8644213E, 0xB7DC59D0, 0x7965291F, 0xCCD6FD43, + 0x41823979, 0x932BCDF6, 0xB657C34D, 0x4EDFD282, + 0x7AE5290C, 0x3CB9536B, 0x851E20FE, 0x9833557E, + 0x13ECF0B0, 0xD3FFB372, 0x3F85C5C1, 0x0AEF7ED2 +}; + +static const u_int32_t cast_sbox5[256] = { + 0x7EC90C04, 0x2C6E74B9, 0x9B0E66DF, 0xA6337911, + 0xB86A7FFF, 0x1DD358F5, 0x44DD9D44, 0x1731167F, + 0x08FBF1FA, 0xE7F511CC, 0xD2051B00, 0x735ABA00, + 0x2AB722D8, 0x386381CB, 0xACF6243A, 0x69BEFD7A, + 0xE6A2E77F, 0xF0C720CD, 0xC4494816, 0xCCF5C180, + 0x38851640, 0x15B0A848, 0xE68B18CB, 0x4CAADEFF, + 0x5F480A01, 0x0412B2AA, 0x259814FC, 0x41D0EFE2, + 0x4E40B48D, 0x248EB6FB, 0x8DBA1CFE, 0x41A99B02, + 0x1A550A04, 0xBA8F65CB, 0x7251F4E7, 0x95A51725, + 0xC106ECD7, 0x97A5980A, 0xC539B9AA, 0x4D79FE6A, + 0xF2F3F763, 0x68AF8040, 0xED0C9E56, 0x11B4958B, + 0xE1EB5A88, 0x8709E6B0, 0xD7E07156, 0x4E29FEA7, + 0x6366E52D, 0x02D1C000, 0xC4AC8E05, 0x9377F571, + 0x0C05372A, 0x578535F2, 0x2261BE02, 0xD642A0C9, + 0xDF13A280, 0x74B55BD2, 0x682199C0, 0xD421E5EC, + 0x53FB3CE8, 0xC8ADEDB3, 0x28A87FC9, 0x3D959981, + 0x5C1FF900, 0xFE38D399, 0x0C4EFF0B, 0x062407EA, + 0xAA2F4FB1, 0x4FB96976, 0x90C79505, 0xB0A8A774, + 0xEF55A1FF, 0xE59CA2C2, 0xA6B62D27, 0xE66A4263, + 0xDF65001F, 0x0EC50966, 0xDFDD55BC, 0x29DE0655, + 0x911E739A, 0x17AF8975, 0x32C7911C, 0x89F89468, + 0x0D01E980, 0x524755F4, 0x03B63CC9, 0x0CC844B2, + 0xBCF3F0AA, 0x87AC36E9, 0xE53A7426, 0x01B3D82B, + 0x1A9E7449, 0x64EE2D7E, 0xCDDBB1DA, 0x01C94910, + 0xB868BF80, 0x0D26F3FD, 0x9342EDE7, 0x04A5C284, + 0x636737B6, 0x50F5B616, 0xF24766E3, 0x8ECA36C1, + 0x136E05DB, 0xFEF18391, 0xFB887A37, 0xD6E7F7D4, + 0xC7FB7DC9, 0x3063FCDF, 0xB6F589DE, 0xEC2941DA, + 0x26E46695, 0xB7566419, 0xF654EFC5, 0xD08D58B7, + 0x48925401, 0xC1BACB7F, 0xE5FF550F, 0xB6083049, + 0x5BB5D0E8, 0x87D72E5A, 0xAB6A6EE1, 0x223A66CE, + 0xC62BF3CD, 0x9E0885F9, 0x68CB3E47, 0x086C010F, + 0xA21DE820, 0xD18B69DE, 0xF3F65777, 0xFA02C3F6, + 0x407EDAC3, 0xCBB3D550, 0x1793084D, 0xB0D70EBA, + 0x0AB378D5, 0xD951FB0C, 0xDED7DA56, 0x4124BBE4, + 0x94CA0B56, 0x0F5755D1, 0xE0E1E56E, 0x6184B5BE, + 0x580A249F, 0x94F74BC0, 0xE327888E, 0x9F7B5561, + 0xC3DC0280, 0x05687715, 0x646C6BD7, 0x44904DB3, + 0x66B4F0A3, 0xC0F1648A, 0x697ED5AF, 0x49E92FF6, + 0x309E374F, 0x2CB6356A, 0x85808573, 0x4991F840, + 0x76F0AE02, 0x083BE84D, 0x28421C9A, 0x44489406, + 0x736E4CB8, 0xC1092910, 0x8BC95FC6, 0x7D869CF4, + 0x134F616F, 0x2E77118D, 0xB31B2BE1, 0xAA90B472, + 0x3CA5D717, 0x7D161BBA, 0x9CAD9010, 0xAF462BA2, + 0x9FE459D2, 0x45D34559, 0xD9F2DA13, 0xDBC65487, + 0xF3E4F94E, 0x176D486F, 0x097C13EA, 0x631DA5C7, + 0x445F7382, 0x175683F4, 0xCDC66A97, 0x70BE0288, + 0xB3CDCF72, 0x6E5DD2F3, 0x20936079, 0x459B80A5, + 0xBE60E2DB, 0xA9C23101, 0xEBA5315C, 0x224E42F2, + 0x1C5C1572, 0xF6721B2C, 0x1AD2FFF3, 0x8C25404E, + 0x324ED72F, 0x4067B7FD, 0x0523138E, 0x5CA3BC78, + 0xDC0FD66E, 0x75922283, 0x784D6B17, 0x58EBB16E, + 0x44094F85, 0x3F481D87, 0xFCFEAE7B, 0x77B5FF76, + 0x8C2302BF, 0xAAF47556, 0x5F46B02A, 0x2B092801, + 0x3D38F5F7, 0x0CA81F36, 0x52AF4A8A, 0x66D5E7C0, + 0xDF3B0874, 0x95055110, 0x1B5AD7A8, 0xF61ED5AD, + 0x6CF6E479, 0x20758184, 0xD0CEFA65, 0x88F7BE58, + 0x4A046826, 0x0FF6F8F3, 0xA09C7F70, 0x5346ABA0, + 0x5CE96C28, 0xE176EDA3, 0x6BAC307F, 0x376829D2, + 0x85360FA9, 0x17E3FE2A, 0x24B79767, 0xF5A96B20, + 0xD6CD2595, 0x68FF1EBF, 0x7555442C, 0xF19F06BE, + 0xF9E0659A, 0xEEB9491D, 0x34010718, 0xBB30CAB8, + 0xE822FE15, 0x88570983, 0x750E6249, 0xDA627E55, + 0x5E76FFA8, 0xB1534546, 0x6D47DE08, 0xEFE9E7D4 +}; + +static const u_int32_t cast_sbox6[256] = { + 0xF6FA8F9D, 0x2CAC6CE1, 0x4CA34867, 0xE2337F7C, + 0x95DB08E7, 0x016843B4, 0xECED5CBC, 0x325553AC, + 0xBF9F0960, 0xDFA1E2ED, 0x83F0579D, 0x63ED86B9, + 0x1AB6A6B8, 0xDE5EBE39, 0xF38FF732, 0x8989B138, + 0x33F14961, 0xC01937BD, 0xF506C6DA, 0xE4625E7E, + 0xA308EA99, 0x4E23E33C, 0x79CBD7CC, 0x48A14367, + 0xA3149619, 0xFEC94BD5, 0xA114174A, 0xEAA01866, + 0xA084DB2D, 0x09A8486F, 0xA888614A, 0x2900AF98, + 0x01665991, 0xE1992863, 0xC8F30C60, 0x2E78EF3C, + 0xD0D51932, 0xCF0FEC14, 0xF7CA07D2, 0xD0A82072, + 0xFD41197E, 0x9305A6B0, 0xE86BE3DA, 0x74BED3CD, + 0x372DA53C, 0x4C7F4448, 0xDAB5D440, 0x6DBA0EC3, + 0x083919A7, 0x9FBAEED9, 0x49DBCFB0, 0x4E670C53, + 0x5C3D9C01, 0x64BDB941, 0x2C0E636A, 0xBA7DD9CD, + 0xEA6F7388, 0xE70BC762, 0x35F29ADB, 0x5C4CDD8D, + 0xF0D48D8C, 0xB88153E2, 0x08A19866, 0x1AE2EAC8, + 0x284CAF89, 0xAA928223, 0x9334BE53, 0x3B3A21BF, + 0x16434BE3, 0x9AEA3906, 0xEFE8C36E, 0xF890CDD9, + 0x80226DAE, 0xC340A4A3, 0xDF7E9C09, 0xA694A807, + 0x5B7C5ECC, 0x221DB3A6, 0x9A69A02F, 0x68818A54, + 0xCEB2296F, 0x53C0843A, 0xFE893655, 0x25BFE68A, + 0xB4628ABC, 0xCF222EBF, 0x25AC6F48, 0xA9A99387, + 0x53BDDB65, 0xE76FFBE7, 0xE967FD78, 0x0BA93563, + 0x8E342BC1, 0xE8A11BE9, 0x4980740D, 0xC8087DFC, + 0x8DE4BF99, 0xA11101A0, 0x7FD37975, 0xDA5A26C0, + 0xE81F994F, 0x9528CD89, 0xFD339FED, 0xB87834BF, + 0x5F04456D, 0x22258698, 0xC9C4C83B, 0x2DC156BE, + 0x4F628DAA, 0x57F55EC5, 0xE2220ABE, 0xD2916EBF, + 0x4EC75B95, 0x24F2C3C0, 0x42D15D99, 0xCD0D7FA0, + 0x7B6E27FF, 0xA8DC8AF0, 0x7345C106, 0xF41E232F, + 0x35162386, 0xE6EA8926, 0x3333B094, 0x157EC6F2, + 0x372B74AF, 0x692573E4, 0xE9A9D848, 0xF3160289, + 0x3A62EF1D, 0xA787E238, 0xF3A5F676, 0x74364853, + 0x20951063, 0x4576698D, 0xB6FAD407, 0x592AF950, + 0x36F73523, 0x4CFB6E87, 0x7DA4CEC0, 0x6C152DAA, + 0xCB0396A8, 0xC50DFE5D, 0xFCD707AB, 0x0921C42F, + 0x89DFF0BB, 0x5FE2BE78, 0x448F4F33, 0x754613C9, + 0x2B05D08D, 0x48B9D585, 0xDC049441, 0xC8098F9B, + 0x7DEDE786, 0xC39A3373, 0x42410005, 0x6A091751, + 0x0EF3C8A6, 0x890072D6, 0x28207682, 0xA9A9F7BE, + 0xBF32679D, 0xD45B5B75, 0xB353FD00, 0xCBB0E358, + 0x830F220A, 0x1F8FB214, 0xD372CF08, 0xCC3C4A13, + 0x8CF63166, 0x061C87BE, 0x88C98F88, 0x6062E397, + 0x47CF8E7A, 0xB6C85283, 0x3CC2ACFB, 0x3FC06976, + 0x4E8F0252, 0x64D8314D, 0xDA3870E3, 0x1E665459, + 0xC10908F0, 0x513021A5, 0x6C5B68B7, 0x822F8AA0, + 0x3007CD3E, 0x74719EEF, 0xDC872681, 0x073340D4, + 0x7E432FD9, 0x0C5EC241, 0x8809286C, 0xF592D891, + 0x08A930F6, 0x957EF305, 0xB7FBFFBD, 0xC266E96F, + 0x6FE4AC98, 0xB173ECC0, 0xBC60B42A, 0x953498DA, + 0xFBA1AE12, 0x2D4BD736, 0x0F25FAAB, 0xA4F3FCEB, + 0xE2969123, 0x257F0C3D, 0x9348AF49, 0x361400BC, + 0xE8816F4A, 0x3814F200, 0xA3F94043, 0x9C7A54C2, + 0xBC704F57, 0xDA41E7F9, 0xC25AD33A, 0x54F4A084, + 0xB17F5505, 0x59357CBE, 0xEDBD15C8, 0x7F97C5AB, + 0xBA5AC7B5, 0xB6F6DEAF, 0x3A479C3A, 0x5302DA25, + 0x653D7E6A, 0x54268D49, 0x51A477EA, 0x5017D55B, + 0xD7D25D88, 0x44136C76, 0x0404A8C8, 0xB8E5A121, + 0xB81A928A, 0x60ED5869, 0x97C55B96, 0xEAEC991B, + 0x29935913, 0x01FDB7F1, 0x088E8DFA, 0x9AB6F6F5, + 0x3B4CBF9F, 0x4A5DE3AB, 0xE6051D35, 0xA0E1D855, + 0xD36B4CF1, 0xF544EDEB, 0xB0E93524, 0xBEBB8FBD, + 0xA2D762CF, 0x49C92F54, 0x38B5F331, 0x7128A454, + 0x48392905, 0xA65B1DB8, 0x851C97BD, 0xD675CF2F +}; + +static const u_int32_t cast_sbox7[256] = { + 0x85E04019, 0x332BF567, 0x662DBFFF, 0xCFC65693, + 0x2A8D7F6F, 0xAB9BC912, 0xDE6008A1, 0x2028DA1F, + 0x0227BCE7, 0x4D642916, 0x18FAC300, 0x50F18B82, + 0x2CB2CB11, 0xB232E75C, 0x4B3695F2, 0xB28707DE, + 0xA05FBCF6, 0xCD4181E9, 0xE150210C, 0xE24EF1BD, + 0xB168C381, 0xFDE4E789, 0x5C79B0D8, 0x1E8BFD43, + 0x4D495001, 0x38BE4341, 0x913CEE1D, 0x92A79C3F, + 0x089766BE, 0xBAEEADF4, 0x1286BECF, 0xB6EACB19, + 0x2660C200, 0x7565BDE4, 0x64241F7A, 0x8248DCA9, + 0xC3B3AD66, 0x28136086, 0x0BD8DFA8, 0x356D1CF2, + 0x107789BE, 0xB3B2E9CE, 0x0502AA8F, 0x0BC0351E, + 0x166BF52A, 0xEB12FF82, 0xE3486911, 0xD34D7516, + 0x4E7B3AFF, 0x5F43671B, 0x9CF6E037, 0x4981AC83, + 0x334266CE, 0x8C9341B7, 0xD0D854C0, 0xCB3A6C88, + 0x47BC2829, 0x4725BA37, 0xA66AD22B, 0x7AD61F1E, + 0x0C5CBAFA, 0x4437F107, 0xB6E79962, 0x42D2D816, + 0x0A961288, 0xE1A5C06E, 0x13749E67, 0x72FC081A, + 0xB1D139F7, 0xF9583745, 0xCF19DF58, 0xBEC3F756, + 0xC06EBA30, 0x07211B24, 0x45C28829, 0xC95E317F, + 0xBC8EC511, 0x38BC46E9, 0xC6E6FA14, 0xBAE8584A, + 0xAD4EBC46, 0x468F508B, 0x7829435F, 0xF124183B, + 0x821DBA9F, 0xAFF60FF4, 0xEA2C4E6D, 0x16E39264, + 0x92544A8B, 0x009B4FC3, 0xABA68CED, 0x9AC96F78, + 0x06A5B79A, 0xB2856E6E, 0x1AEC3CA9, 0xBE838688, + 0x0E0804E9, 0x55F1BE56, 0xE7E5363B, 0xB3A1F25D, + 0xF7DEBB85, 0x61FE033C, 0x16746233, 0x3C034C28, + 0xDA6D0C74, 0x79AAC56C, 0x3CE4E1AD, 0x51F0C802, + 0x98F8F35A, 0x1626A49F, 0xEED82B29, 0x1D382FE3, + 0x0C4FB99A, 0xBB325778, 0x3EC6D97B, 0x6E77A6A9, + 0xCB658B5C, 0xD45230C7, 0x2BD1408B, 0x60C03EB7, + 0xB9068D78, 0xA33754F4, 0xF430C87D, 0xC8A71302, + 0xB96D8C32, 0xEBD4E7BE, 0xBE8B9D2D, 0x7979FB06, + 0xE7225308, 0x8B75CF77, 0x11EF8DA4, 0xE083C858, + 0x8D6B786F, 0x5A6317A6, 0xFA5CF7A0, 0x5DDA0033, + 0xF28EBFB0, 0xF5B9C310, 0xA0EAC280, 0x08B9767A, + 0xA3D9D2B0, 0x79D34217, 0x021A718D, 0x9AC6336A, + 0x2711FD60, 0x438050E3, 0x069908A8, 0x3D7FEDC4, + 0x826D2BEF, 0x4EEB8476, 0x488DCF25, 0x36C9D566, + 0x28E74E41, 0xC2610ACA, 0x3D49A9CF, 0xBAE3B9DF, + 0xB65F8DE6, 0x92AEAF64, 0x3AC7D5E6, 0x9EA80509, + 0xF22B017D, 0xA4173F70, 0xDD1E16C3, 0x15E0D7F9, + 0x50B1B887, 0x2B9F4FD5, 0x625ABA82, 0x6A017962, + 0x2EC01B9C, 0x15488AA9, 0xD716E740, 0x40055A2C, + 0x93D29A22, 0xE32DBF9A, 0x058745B9, 0x3453DC1E, + 0xD699296E, 0x496CFF6F, 0x1C9F4986, 0xDFE2ED07, + 0xB87242D1, 0x19DE7EAE, 0x053E561A, 0x15AD6F8C, + 0x66626C1C, 0x7154C24C, 0xEA082B2A, 0x93EB2939, + 0x17DCB0F0, 0x58D4F2AE, 0x9EA294FB, 0x52CF564C, + 0x9883FE66, 0x2EC40581, 0x763953C3, 0x01D6692E, + 0xD3A0C108, 0xA1E7160E, 0xE4F2DFA6, 0x693ED285, + 0x74904698, 0x4C2B0EDD, 0x4F757656, 0x5D393378, + 0xA132234F, 0x3D321C5D, 0xC3F5E194, 0x4B269301, + 0xC79F022F, 0x3C997E7E, 0x5E4F9504, 0x3FFAFBBD, + 0x76F7AD0E, 0x296693F4, 0x3D1FCE6F, 0xC61E45BE, + 0xD3B5AB34, 0xF72BF9B7, 0x1B0434C0, 0x4E72B567, + 0x5592A33D, 0xB5229301, 0xCFD2A87F, 0x60AEB767, + 0x1814386B, 0x30BCC33D, 0x38A0C07D, 0xFD1606F2, + 0xC363519B, 0x589DD390, 0x5479F8E6, 0x1CB8D647, + 0x97FD61A9, 0xEA7759F4, 0x2D57539D, 0x569A58CF, + 0xE84E63AD, 0x462E1B78, 0x6580F87E, 0xF3817914, + 0x91DA55F4, 0x40A230F3, 0xD1988F35, 0xB6E318D2, + 0x3FFA50BC, 0x3D40F021, 0xC3C0BDAE, 0x4958C24C, + 0x518F36B2, 0x84B1D370, 0x0FEDCE83, 0x878DDADA, + 0xF2A279C7, 0x94E01BE8, 0x90716F4B, 0x954B8AA3 +}; + +static const u_int32_t cast_sbox8[256] = { + 0xE216300D, 0xBBDDFFFC, 0xA7EBDABD, 0x35648095, + 0x7789F8B7, 0xE6C1121B, 0x0E241600, 0x052CE8B5, + 0x11A9CFB0, 0xE5952F11, 0xECE7990A, 0x9386D174, + 0x2A42931C, 0x76E38111, 0xB12DEF3A, 0x37DDDDFC, + 0xDE9ADEB1, 0x0A0CC32C, 0xBE197029, 0x84A00940, + 0xBB243A0F, 0xB4D137CF, 0xB44E79F0, 0x049EEDFD, + 0x0B15A15D, 0x480D3168, 0x8BBBDE5A, 0x669DED42, + 0xC7ECE831, 0x3F8F95E7, 0x72DF191B, 0x7580330D, + 0x94074251, 0x5C7DCDFA, 0xABBE6D63, 0xAA402164, + 0xB301D40A, 0x02E7D1CA, 0x53571DAE, 0x7A3182A2, + 0x12A8DDEC, 0xFDAA335D, 0x176F43E8, 0x71FB46D4, + 0x38129022, 0xCE949AD4, 0xB84769AD, 0x965BD862, + 0x82F3D055, 0x66FB9767, 0x15B80B4E, 0x1D5B47A0, + 0x4CFDE06F, 0xC28EC4B8, 0x57E8726E, 0x647A78FC, + 0x99865D44, 0x608BD593, 0x6C200E03, 0x39DC5FF6, + 0x5D0B00A3, 0xAE63AFF2, 0x7E8BD632, 0x70108C0C, + 0xBBD35049, 0x2998DF04, 0x980CF42A, 0x9B6DF491, + 0x9E7EDD53, 0x06918548, 0x58CB7E07, 0x3B74EF2E, + 0x522FFFB1, 0xD24708CC, 0x1C7E27CD, 0xA4EB215B, + 0x3CF1D2E2, 0x19B47A38, 0x424F7618, 0x35856039, + 0x9D17DEE7, 0x27EB35E6, 0xC9AFF67B, 0x36BAF5B8, + 0x09C467CD, 0xC18910B1, 0xE11DBF7B, 0x06CD1AF8, + 0x7170C608, 0x2D5E3354, 0xD4DE495A, 0x64C6D006, + 0xBCC0C62C, 0x3DD00DB3, 0x708F8F34, 0x77D51B42, + 0x264F620F, 0x24B8D2BF, 0x15C1B79E, 0x46A52564, + 0xF8D7E54E, 0x3E378160, 0x7895CDA5, 0x859C15A5, + 0xE6459788, 0xC37BC75F, 0xDB07BA0C, 0x0676A3AB, + 0x7F229B1E, 0x31842E7B, 0x24259FD7, 0xF8BEF472, + 0x835FFCB8, 0x6DF4C1F2, 0x96F5B195, 0xFD0AF0FC, + 0xB0FE134C, 0xE2506D3D, 0x4F9B12EA, 0xF215F225, + 0xA223736F, 0x9FB4C428, 0x25D04979, 0x34C713F8, + 0xC4618187, 0xEA7A6E98, 0x7CD16EFC, 0x1436876C, + 0xF1544107, 0xBEDEEE14, 0x56E9AF27, 0xA04AA441, + 0x3CF7C899, 0x92ECBAE6, 0xDD67016D, 0x151682EB, + 0xA842EEDF, 0xFDBA60B4, 0xF1907B75, 0x20E3030F, + 0x24D8C29E, 0xE139673B, 0xEFA63FB8, 0x71873054, + 0xB6F2CF3B, 0x9F326442, 0xCB15A4CC, 0xB01A4504, + 0xF1E47D8D, 0x844A1BE5, 0xBAE7DFDC, 0x42CBDA70, + 0xCD7DAE0A, 0x57E85B7A, 0xD53F5AF6, 0x20CF4D8C, + 0xCEA4D428, 0x79D130A4, 0x3486EBFB, 0x33D3CDDC, + 0x77853B53, 0x37EFFCB5, 0xC5068778, 0xE580B3E6, + 0x4E68B8F4, 0xC5C8B37E, 0x0D809EA2, 0x398FEB7C, + 0x132A4F94, 0x43B7950E, 0x2FEE7D1C, 0x223613BD, + 0xDD06CAA2, 0x37DF932B, 0xC4248289, 0xACF3EBC3, + 0x5715F6B7, 0xEF3478DD, 0xF267616F, 0xC148CBE4, + 0x9052815E, 0x5E410FAB, 0xB48A2465, 0x2EDA7FA4, + 0xE87B40E4, 0xE98EA084, 0x5889E9E1, 0xEFD390FC, + 0xDD07D35B, 0xDB485694, 0x38D7E5B2, 0x57720101, + 0x730EDEBC, 0x5B643113, 0x94917E4F, 0x503C2FBA, + 0x646F1282, 0x7523D24A, 0xE0779695, 0xF9C17A8F, + 0x7A5B2121, 0xD187B896, 0x29263A4D, 0xBA510CDF, + 0x81F47C9F, 0xAD1163ED, 0xEA7B5965, 0x1A00726E, + 0x11403092, 0x00DA6D77, 0x4A0CDD61, 0xAD1F4603, + 0x605BDFB0, 0x9EEDC364, 0x22EBE6A8, 0xCEE7D28A, + 0xA0E736A0, 0x5564A6B9, 0x10853209, 0xC7EB8F37, + 0x2DE705CA, 0x8951570F, 0xDF09822B, 0xBD691A6C, + 0xAA12E4F2, 0x87451C0F, 0xE0F6A27A, 0x3ADA4819, + 0x4CF1764F, 0x0D771C2B, 0x67CDB156, 0x350D8384, + 0x5938FA0F, 0x42399EF3, 0x36997B07, 0x0E84093D, + 0x4AA93E61, 0x8360D87B, 0x1FA98B0C, 0x1149382C, + 0xE97625A5, 0x0614D1B7, 0x0E25244B, 0x0C768347, + 0x589E8D82, 0x0D2059D1, 0xA466BB1E, 0xF8DA0A82, + 0x04F19130, 0xBA6E4EC0, 0x99265164, 0x1EE7230D, + 0x50B2AD80, 0xEAEE6801, 0x8DB2A283, 0xEA8BF59E +}; diff --git a/sys/crypto/cast128/files.cast128 b/sys/crypto/cast128/files.cast128 new file mode 100644 index 000000000..d96c2d6fd --- /dev/null +++ b/sys/crypto/cast128/files.cast128 @@ -0,0 +1,5 @@ +# $NetBSD: files.cast128,v 1.1 2002/10/11 01:52:09 thorpej Exp $ + +define cast128 + +file crypto/cast128/cast128.c cast128 diff --git a/sys/crypto/des/arch/i386/des_cbc.S b/sys/crypto/des/arch/i386/des_cbc.S new file mode 100644 index 000000000..2007030d6 --- /dev/null +++ b/sys/crypto/des/arch/i386/des_cbc.S @@ -0,0 +1,470 @@ +/* $NetBSD: des_cbc.S,v 1.6 2007/12/11 23:31:07 lukem Exp $ */ + +/* Copyright (C) 1995-1997 Eric Young (eay@cryptsoft.com) + * All rights reserved. + * + * This package is an SSL implementation written + * by Eric Young (eay@cryptsoft.com). + * The implementation was written so as to conform with Netscapes SSL. + * + * This library is free for commercial and non-commercial use as long as + * the following conditions are aheared to. The following conditions + * apply to all code found in this distribution, be it the RC4, RSA, + * lhash, DES, etc., code; not just the SSL code. The SSL documentation + * included with this distribution is covered by the same copyright terms + * except that the holder is Tim Hudson (tjh@cryptsoft.com). + * + * Copyright remains Eric Young's, and as such any Copyright notices in + * the code are not to be removed. + * If this package is used in a product, Eric Young should be given attribution + * as the author of the parts of the library used. + * This can be in the form of a textual message at program startup or + * in documentation (online or textual) provided with the package. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * 3. All advertising materials mentioning features or use of this software + * must display the following acknowledgement: + * "This product includes cryptographic software written by + * Eric Young (eay@cryptsoft.com)" + * The word 'cryptographic' can be left out if the rouines from the library + * being used are not cryptographic related :-). + * 4. If you include any Windows specific code (or a derivative thereof) from + * the apps directory (application code) you must include an acknowledgement: + * "This product includes software written by Tim Hudson (tjh@cryptsoft.com)" + * + * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND + * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE + * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE + * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE + * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL + * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS + * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) + * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT + * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY + * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF + * SUCH DAMAGE. + * + * The licence and distribution terms for any publically available version or + * derivative of this code cannot be changed. i.e. this code cannot simply be + * copied and put under another distribution licence + * [including the GNU Public Licence.] + */ + +/* + * Modified from the output of `perl des686.pl elf' by + * Thor Lancelot Simon + */ + +#include +__KERNEL_RCSID(0, "$NetBSD: des_cbc.S,v 1.6 2007/12/11 23:31:07 lukem Exp $"); + +ENTRY(des_ncbc_encrypt) + + pushl %ebp + pushl %ebx + pushl %esi + pushl %edi + movl 28(%esp), %ebp + # getting iv ptr from parameter 4 + movl 36(%esp), %ebx + movl (%ebx), %esi + movl 4(%ebx), %edi + pushl %edi + pushl %esi + pushl %edi + pushl %esi + movl %esp, %ebx + movl 36(%esp), %esi + movl 40(%esp), %edi + # getting encrypt flag from parameter 5 + movl 56(%esp), %ecx + # get and push parameter 5 + pushl %ecx + # get and push parameter 3 + movl 52(%esp), %eax + pushl %eax + pushl %ebx + cmpl $0, %ecx + jz .L004decrypt + andl $4294967288, %ebp + movl 12(%esp), %eax + movl 16(%esp), %ebx + jz .L005encrypt_finish +.L006encrypt_loop: + movl (%esi), %ecx + movl 4(%esi), %edx + xorl %ecx, %eax + xorl %edx, %ebx + movl %eax, 12(%esp) + movl %ebx, 16(%esp) + call _C_LABEL(des_encrypt1) + movl 12(%esp), %eax + movl 16(%esp), %ebx + movl %eax, (%edi) + movl %ebx, 4(%edi) + addl $8, %esi + addl $8, %edi + subl $8, %ebp + jnz .L006encrypt_loop +.L005encrypt_finish: + movl 56(%esp), %ebp + andl $7, %ebp + jz .L007finish + xorl %ecx, %ecx + xorl %edx, %edx + movl .L008cbc_enc_jmp_table(,%ebp,4),%ebp + jmp *%ebp +.L009ej7: + movb 6(%esi), %dh + sall $8, %edx +.L010ej6: + movb 5(%esi), %dh +.L011ej5: + movb 4(%esi), %dl +.L012ej4: + movl (%esi), %ecx + jmp .L013ejend +.L014ej3: + movb 2(%esi), %ch + sall $8, %ecx +.L015ej2: + movb 1(%esi), %ch +.L016ej1: + movb (%esi), %cl +.L013ejend: + xorl %ecx, %eax + xorl %edx, %ebx + movl %eax, 12(%esp) + movl %ebx, 16(%esp) + call _C_LABEL(des_encrypt1) + movl 12(%esp), %eax + movl 16(%esp), %ebx + movl %eax, (%edi) + movl %ebx, 4(%edi) + jmp .L007finish +#ifdef __ELF__ +.align 16 +#else +.align 4 +#endif +.L004decrypt: + andl $4294967288, %ebp + movl 20(%esp), %eax + movl 24(%esp), %ebx + jz .L017decrypt_finish +.L018decrypt_loop: + movl (%esi), %eax + movl 4(%esi), %ebx + movl %eax, 12(%esp) + movl %ebx, 16(%esp) + call _C_LABEL(des_encrypt1) + movl 12(%esp), %eax + movl 16(%esp), %ebx + movl 20(%esp), %ecx + movl 24(%esp), %edx + xorl %eax, %ecx + xorl %ebx, %edx + movl (%esi), %eax + movl 4(%esi), %ebx + movl %ecx, (%edi) + movl %edx, 4(%edi) + movl %eax, 20(%esp) + movl %ebx, 24(%esp) + addl $8, %esi + addl $8, %edi + subl $8, %ebp + jnz .L018decrypt_loop +.L017decrypt_finish: + movl 56(%esp), %ebp + andl $7, %ebp + jz .L007finish + movl (%esi), %eax + movl 4(%esi), %ebx + movl %eax, 12(%esp) + movl %ebx, 16(%esp) + call _C_LABEL(des_encrypt1) + movl 12(%esp), %eax + movl 16(%esp), %ebx + movl 20(%esp), %ecx + movl 24(%esp), %edx + xorl %eax, %ecx + xorl %ebx, %edx + movl (%esi), %eax + movl 4(%esi), %ebx +.L019dj7: + rorl $16, %edx + movb %dl, 6(%edi) + shrl $16, %edx +.L020dj6: + movb %dh, 5(%edi) +.L021dj5: + movb %dl, 4(%edi) +.L022dj4: + movl %ecx, (%edi) + jmp .L023djend +.L024dj3: + rorl $16, %ecx + movb %cl, 2(%edi) + sall $16, %ecx +.L025dj2: + movb %ch, 1(%esi) +.L026dj1: + movb %cl, (%esi) +.L023djend: + jmp .L007finish +#ifdef __ELF__ +.align 16 +#else +.align 4 +#endif +.L007finish: + movl 64(%esp), %ecx + addl $28, %esp + movl %eax, (%ecx) + movl %ebx, 4(%ecx) + popl %edi + popl %esi + popl %ebx + popl %ebp + ret +#ifdef __ELF__ +.align 16 +#else +.align 4 +#endif +.L008cbc_enc_jmp_table: + .long 0 + .long .L016ej1 + .long .L015ej2 + .long .L014ej3 + .long .L012ej4 + .long .L011ej5 + .long .L010ej6 + .long .L009ej7 +#ifdef __ELF__ +.align 16 +#else +.align 4 +#endif +.L027cbc_dec_jmp_table: + .long 0 + .long .L026dj1 + .long .L025dj2 + .long .L024dj3 + .long .L022dj4 + .long .L021dj5 + .long .L020dj6 + .long .L019dj7 +.L_des_ncbc_encrypt_end: + .size _C_LABEL(des_ncbc_encrypt),.L_des_ncbc_encrypt_end-_C_LABEL(des_ncbc_encrypt) + +ENTRY(des_ede3_cbc_encrypt) + + pushl %ebp + pushl %ebx + pushl %esi + pushl %edi + movl 28(%esp), %ebp + # getting iv ptr from parameter 6 + movl 44(%esp), %ebx + movl (%ebx), %esi + movl 4(%ebx), %edi + pushl %edi + pushl %esi + pushl %edi + pushl %esi + movl %esp, %ebx + movl 36(%esp), %esi + movl 40(%esp), %edi + # getting encrypt flag from parameter 7 + movl 64(%esp), %ecx + # get and push parameter 5 + movl 56(%esp), %eax + pushl %eax + # get and push parameter 4 + movl 56(%esp), %eax + pushl %eax + # get and push parameter 3 + movl 56(%esp), %eax + pushl %eax + pushl %ebx + cmpl $0, %ecx + jz .L028decrypt + andl $4294967288, %ebp + movl 16(%esp), %eax + movl 20(%esp), %ebx + jz .L029encrypt_finish +.L030encrypt_loop: + movl (%esi), %ecx + movl 4(%esi), %edx + xorl %ecx, %eax + xorl %edx, %ebx + movl %eax, 16(%esp) + movl %ebx, 20(%esp) + call _C_LABEL(des_encrypt3) + movl 16(%esp), %eax + movl 20(%esp), %ebx + movl %eax, (%edi) + movl %ebx, 4(%edi) + addl $8, %esi + addl $8, %edi + subl $8, %ebp + jnz .L030encrypt_loop +.L029encrypt_finish: + movl 60(%esp), %ebp + andl $7, %ebp + jz .L031finish + xorl %ecx, %ecx + xorl %edx, %edx + movl .L032cbc_enc_jmp_table(,%ebp,4),%ebp + jmp *%ebp +.L033ej7: + movb 6(%esi), %dh + sall $8, %edx +.L034ej6: + movb 5(%esi), %dh +.L035ej5: + movb 4(%esi), %dl +.L036ej4: + movl (%esi), %ecx + jmp .L037ejend +.L038ej3: + movb 2(%esi), %ch + sall $8, %ecx +.L039ej2: + movb 1(%esi), %ch +.L040ej1: + movb (%esi), %cl +.L037ejend: + xorl %ecx, %eax + xorl %edx, %ebx + movl %eax, 16(%esp) + movl %ebx, 20(%esp) + call _C_LABEL(des_encrypt3) + movl 16(%esp), %eax + movl 20(%esp), %ebx + movl %eax, (%edi) + movl %ebx, 4(%edi) + jmp .L031finish +#ifdef __ELF__ +.align 16 +#else +.align 4 +#endif +.L028decrypt: + andl $4294967288, %ebp + movl 24(%esp), %eax + movl 28(%esp), %ebx + jz .L041decrypt_finish +.L042decrypt_loop: + movl (%esi), %eax + movl 4(%esi), %ebx + movl %eax, 16(%esp) + movl %ebx, 20(%esp) + call _C_LABEL(des_decrypt3) + movl 16(%esp), %eax + movl 20(%esp), %ebx + movl 24(%esp), %ecx + movl 28(%esp), %edx + xorl %eax, %ecx + xorl %ebx, %edx + movl (%esi), %eax + movl 4(%esi), %ebx + movl %ecx, (%edi) + movl %edx, 4(%edi) + movl %eax, 24(%esp) + movl %ebx, 28(%esp) + addl $8, %esi + addl $8, %edi + subl $8, %ebp + jnz .L042decrypt_loop +.L041decrypt_finish: + movl 60(%esp), %ebp + andl $7, %ebp + jz .L031finish + movl (%esi), %eax + movl 4(%esi), %ebx + movl %eax, 16(%esp) + movl %ebx, 20(%esp) + call _C_LABEL(des_decrypt3) + movl 16(%esp), %eax + movl 20(%esp), %ebx + movl 24(%esp), %ecx + movl 28(%esp), %edx + xorl %eax, %ecx + xorl %ebx, %edx + movl (%esi), %eax + movl 4(%esi), %ebx +.L043dj7: + rorl $16, %edx + movb %dl, 6(%edi) + shrl $16, %edx +.L044dj6: + movb %dh, 5(%edi) +.L045dj5: + movb %dl, 4(%edi) +.L046dj4: + movl %ecx, (%edi) + jmp .L047djend +.L048dj3: + rorl $16, %ecx + movb %cl, 2(%edi) + sall $16, %ecx +.L049dj2: + movb %ch, 1(%esi) +.L050dj1: + movb %cl, (%esi) +.L047djend: + jmp .L031finish +#ifdef __ELF__ +.align 16 +#else +.align 4 +#endif +.L031finish: + movl 76(%esp), %ecx + addl $32, %esp + movl %eax, (%ecx) + movl %ebx, 4(%ecx) + popl %edi + popl %esi + popl %ebx + popl %ebp + ret +#ifdef __ELF__ +.align 16 +#else +.align 4 +#endif +.L032cbc_enc_jmp_table: + .long 0 + .long .L040ej1 + .long .L039ej2 + .long .L038ej3 + .long .L036ej4 + .long .L035ej5 + .long .L034ej6 + .long .L033ej7 +#ifdef __ELF__ +.align 16 +#else +.align 4 +#endif +.L051cbc_dec_jmp_table: + .long 0 + .long .L050dj1 + .long .L049dj2 + .long .L048dj3 + .long .L046dj4 + .long .L045dj5 + .long .L044dj6 + .long .L043dj7 +.L_des_ede3_cbc_encrypt_end: + .size _C_LABEL(des_ede3_cbc_encrypt),.L_des_ede3_cbc_encrypt_end-_C_LABEL(des_ede3_cbc_encrypt) diff --git a/sys/crypto/des/arch/i386/des_enc.S b/sys/crypto/des/arch/i386/des_enc.S new file mode 100644 index 000000000..0d5bc77e7 --- /dev/null +++ b/sys/crypto/des/arch/i386/des_enc.S @@ -0,0 +1,2814 @@ +/* $NetBSD: des_enc.S,v 1.5 2007/12/11 23:31:08 lukem Exp $ */ + +/* Copyright (C) 1995-1997 Eric Young (eay@cryptsoft.com) + * All rights reserved. + * + * This package is an SSL implementation written + * by Eric Young (eay@cryptsoft.com). + * The implementation was written so as to conform with Netscapes SSL. + * + * This library is free for commercial and non-commercial use as long as + * the following conditions are aheared to. The following conditions + * apply to all code found in this distribution, be it the RC4, RSA, + * lhash, DES, etc., code; not just the SSL code. The SSL documentation + * included with this distribution is covered by the same copyright terms + * except that the holder is Tim Hudson (tjh@cryptsoft.com). + * + * Copyright remains Eric Young's, and as such any Copyright notices in + * the code are not to be removed. + * If this package is used in a product, Eric Young should be given attribution + * as the author of the parts of the library used. + * This can be in the form of a textual message at program startup or + * in documentation (online or textual) provided with the package. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * 3. All advertising materials mentioning features or use of this software + * must display the following acknowledgement: + * "This product includes cryptographic software written by + * Eric Young (eay@cryptsoft.com)" + * The word 'cryptographic' can be left out if the rouines from the library + * being used are not cryptographic related :-). + * 4. If you include any Windows specific code (or a derivative thereof) from + * the apps directory (application code) you must include an acknowledgement: + * "This product includes software written by Tim Hudson (tjh@cryptsoft.com)" + * + * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND + * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE + * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE + * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE + * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL + * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS + * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) + * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT + * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY + * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF + * SUCH DAMAGE. + * + * The licence and distribution terms for any publically available version or + * derivative of this code cannot be changed. i.e. this code cannot simply be + * copied and put under another distribution licence + * [including the GNU Public Licence.] + */ + +/* + * Modified from the output of `perl des686.pl elf' by + * Thor Lancelot Simon + */ + +#include +__KERNEL_RCSID(0, "$NetBSD: des_enc.S,v 1.5 2007/12/11 23:31:08 lukem Exp $"); + +ENTRY(des_encrypt1) + pushl %esi + pushl %edi + + # Load the 2 words + movl 12(%esp), %esi + xorl %ecx, %ecx + pushl %ebx + pushl %ebp + movl (%esi), %eax + movl 28(%esp), %ebx + movl 4(%esi), %edi + + # IP + roll $4, %eax + movl %eax, %esi + xorl %edi, %eax + andl $0xf0f0f0f0, %eax + xorl %eax, %esi + xorl %eax, %edi + + roll $20, %edi + movl %edi, %eax + xorl %esi, %edi + andl $0xfff0000f, %edi + xorl %edi, %eax + xorl %edi, %esi + + roll $14, %eax + movl %eax, %edi + xorl %esi, %eax + andl $0x33333333, %eax + xorl %eax, %edi + xorl %eax, %esi + + roll $22, %esi + movl %esi, %eax + xorl %edi, %esi + andl $0x03fc03fc, %esi + xorl %esi, %eax + xorl %esi, %edi + + roll $9, %eax + movl %eax, %esi + xorl %edi, %eax + andl $0xaaaaaaaa, %eax + xorl %eax, %esi + xorl %eax, %edi + +.byte 209 +.byte 199 # roll $1 %edi + movl 24(%esp), %ebp + cmpl $0, %ebx + je .L000start_decrypt + + # Round 0 + movl (%ebp), %eax + xorl %ebx, %ebx + movl 4(%ebp), %edx + xorl %esi, %eax + xorl %esi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %edi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %edi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %edi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %edi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %edi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %edi + + # Round 1 + movl 8(%ebp), %eax + xorl %ebx, %ebx + movl 12(%ebp), %edx + xorl %edi, %eax + xorl %edi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %esi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %esi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %esi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %esi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %esi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %esi + + # Round 2 + movl 16(%ebp), %eax + xorl %ebx, %ebx + movl 20(%ebp), %edx + xorl %esi, %eax + xorl %esi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %edi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %edi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %edi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %edi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %edi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %edi + + # Round 3 + movl 24(%ebp), %eax + xorl %ebx, %ebx + movl 28(%ebp), %edx + xorl %edi, %eax + xorl %edi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %esi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %esi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %esi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %esi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %esi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %esi + + # Round 4 + movl 32(%ebp), %eax + xorl %ebx, %ebx + movl 36(%ebp), %edx + xorl %esi, %eax + xorl %esi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %edi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %edi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %edi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %edi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %edi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %edi + + # Round 5 + movl 40(%ebp), %eax + xorl %ebx, %ebx + movl 44(%ebp), %edx + xorl %edi, %eax + xorl %edi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %esi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %esi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %esi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %esi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %esi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %esi + + # Round 6 + movl 48(%ebp), %eax + xorl %ebx, %ebx + movl 52(%ebp), %edx + xorl %esi, %eax + xorl %esi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %edi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %edi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %edi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %edi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %edi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %edi + + # Round 7 + movl 56(%ebp), %eax + xorl %ebx, %ebx + movl 60(%ebp), %edx + xorl %edi, %eax + xorl %edi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %esi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %esi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %esi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %esi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %esi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %esi + + # Round 8 + movl 64(%ebp), %eax + xorl %ebx, %ebx + movl 68(%ebp), %edx + xorl %esi, %eax + xorl %esi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %edi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %edi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %edi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %edi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %edi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %edi + + # Round 9 + movl 72(%ebp), %eax + xorl %ebx, %ebx + movl 76(%ebp), %edx + xorl %edi, %eax + xorl %edi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %esi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %esi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %esi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %esi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %esi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %esi + + # Round 10 + movl 80(%ebp), %eax + xorl %ebx, %ebx + movl 84(%ebp), %edx + xorl %esi, %eax + xorl %esi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %edi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %edi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %edi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %edi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %edi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %edi + + # Round 11 + movl 88(%ebp), %eax + xorl %ebx, %ebx + movl 92(%ebp), %edx + xorl %edi, %eax + xorl %edi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %esi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %esi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %esi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %esi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %esi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %esi + + # Round 12 + movl 96(%ebp), %eax + xorl %ebx, %ebx + movl 100(%ebp), %edx + xorl %esi, %eax + xorl %esi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %edi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %edi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %edi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %edi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %edi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %edi + + # Round 13 + movl 104(%ebp), %eax + xorl %ebx, %ebx + movl 108(%ebp), %edx + xorl %edi, %eax + xorl %edi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %esi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %esi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %esi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %esi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %esi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %esi + + # Round 14 + movl 112(%ebp), %eax + xorl %ebx, %ebx + movl 116(%ebp), %edx + xorl %esi, %eax + xorl %esi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %edi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %edi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %edi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %edi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %edi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %edi + + # Round 15 + movl 120(%ebp), %eax + xorl %ebx, %ebx + movl 124(%ebp), %edx + xorl %edi, %eax + xorl %edi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %esi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %esi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %esi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %esi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %esi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %esi + jmp .L001end +.L000start_decrypt: + + # Round 15 + movl 120(%ebp), %eax + xorl %ebx, %ebx + movl 124(%ebp), %edx + xorl %esi, %eax + xorl %esi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %edi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %edi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %edi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %edi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %edi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %edi + + # Round 14 + movl 112(%ebp), %eax + xorl %ebx, %ebx + movl 116(%ebp), %edx + xorl %edi, %eax + xorl %edi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %esi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %esi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %esi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %esi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %esi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %esi + + # Round 13 + movl 104(%ebp), %eax + xorl %ebx, %ebx + movl 108(%ebp), %edx + xorl %esi, %eax + xorl %esi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %edi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %edi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %edi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %edi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %edi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %edi + + # Round 12 + movl 96(%ebp), %eax + xorl %ebx, %ebx + movl 100(%ebp), %edx + xorl %edi, %eax + xorl %edi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %esi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %esi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %esi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %esi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %esi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %esi + + # Round 11 + movl 88(%ebp), %eax + xorl %ebx, %ebx + movl 92(%ebp), %edx + xorl %esi, %eax + xorl %esi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %edi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %edi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %edi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %edi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %edi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %edi + + # Round 10 + movl 80(%ebp), %eax + xorl %ebx, %ebx + movl 84(%ebp), %edx + xorl %edi, %eax + xorl %edi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %esi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %esi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %esi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %esi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %esi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %esi + + # Round 9 + movl 72(%ebp), %eax + xorl %ebx, %ebx + movl 76(%ebp), %edx + xorl %esi, %eax + xorl %esi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %edi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %edi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %edi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %edi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %edi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %edi + + # Round 8 + movl 64(%ebp), %eax + xorl %ebx, %ebx + movl 68(%ebp), %edx + xorl %edi, %eax + xorl %edi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %esi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %esi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %esi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %esi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %esi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %esi + + # Round 7 + movl 56(%ebp), %eax + xorl %ebx, %ebx + movl 60(%ebp), %edx + xorl %esi, %eax + xorl %esi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %edi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %edi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %edi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %edi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %edi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %edi + + # Round 6 + movl 48(%ebp), %eax + xorl %ebx, %ebx + movl 52(%ebp), %edx + xorl %edi, %eax + xorl %edi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %esi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %esi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %esi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %esi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %esi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %esi + + # Round 5 + movl 40(%ebp), %eax + xorl %ebx, %ebx + movl 44(%ebp), %edx + xorl %esi, %eax + xorl %esi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %edi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %edi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %edi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %edi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %edi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %edi + + # Round 4 + movl 32(%ebp), %eax + xorl %ebx, %ebx + movl 36(%ebp), %edx + xorl %edi, %eax + xorl %edi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %esi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %esi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %esi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %esi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %esi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %esi + + # Round 3 + movl 24(%ebp), %eax + xorl %ebx, %ebx + movl 28(%ebp), %edx + xorl %esi, %eax + xorl %esi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %edi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %edi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %edi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %edi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %edi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %edi + + # Round 2 + movl 16(%ebp), %eax + xorl %ebx, %ebx + movl 20(%ebp), %edx + xorl %edi, %eax + xorl %edi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %esi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %esi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %esi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %esi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %esi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %esi + + # Round 1 + movl 8(%ebp), %eax + xorl %ebx, %ebx + movl 12(%ebp), %edx + xorl %esi, %eax + xorl %esi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %edi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %edi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %edi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %edi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %edi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %edi + + # Round 0 + movl (%ebp), %eax + xorl %ebx, %ebx + movl 4(%ebp), %edx + xorl %edi, %eax + xorl %edi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %esi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %esi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %esi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %esi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %esi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %esi +.L001end: + + # FP + movl 20(%esp), %edx +.byte 209 +.byte 206 # rorl $1 %esi + movl %edi, %eax + xorl %esi, %edi + andl $0xaaaaaaaa, %edi + xorl %edi, %eax + xorl %edi, %esi + + roll $23, %eax + movl %eax, %edi + xorl %esi, %eax + andl $0x03fc03fc, %eax + xorl %eax, %edi + xorl %eax, %esi + + roll $10, %edi + movl %edi, %eax + xorl %esi, %edi + andl $0x33333333, %edi + xorl %edi, %eax + xorl %edi, %esi + + roll $18, %esi + movl %esi, %edi + xorl %eax, %esi + andl $0xfff0000f, %esi + xorl %esi, %edi + xorl %esi, %eax + + roll $12, %edi + movl %edi, %esi + xorl %eax, %edi + andl $0xf0f0f0f0, %edi + xorl %edi, %esi + xorl %edi, %eax + + rorl $4, %eax + movl %eax, (%edx) + movl %esi, 4(%edx) + popl %ebp + popl %ebx + popl %edi + popl %esi + ret +.L_des_encrypt1_end: + .size _C_LABEL(des_encrypt1),.L_des_encrypt1_end-_C_LABEL(des_encrypt1) + +ENTRY(des_encrypt2) + pushl %esi + pushl %edi + + # Load the 2 words + movl 12(%esp), %eax + xorl %ecx, %ecx + pushl %ebx + pushl %ebp + movl (%eax), %esi + movl 28(%esp), %ebx + roll $3, %esi + movl 4(%eax), %edi + roll $3, %edi + movl 24(%esp), %ebp + cmpl $0, %ebx + je .L002start_decrypt + + # Round 0 + movl (%ebp), %eax + xorl %ebx, %ebx + movl 4(%ebp), %edx + xorl %esi, %eax + xorl %esi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %edi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %edi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %edi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %edi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %edi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %edi + + # Round 1 + movl 8(%ebp), %eax + xorl %ebx, %ebx + movl 12(%ebp), %edx + xorl %edi, %eax + xorl %edi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %esi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %esi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %esi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %esi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %esi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %esi + + # Round 2 + movl 16(%ebp), %eax + xorl %ebx, %ebx + movl 20(%ebp), %edx + xorl %esi, %eax + xorl %esi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %edi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %edi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %edi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %edi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %edi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %edi + + # Round 3 + movl 24(%ebp), %eax + xorl %ebx, %ebx + movl 28(%ebp), %edx + xorl %edi, %eax + xorl %edi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %esi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %esi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %esi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %esi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %esi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %esi + + # Round 4 + movl 32(%ebp), %eax + xorl %ebx, %ebx + movl 36(%ebp), %edx + xorl %esi, %eax + xorl %esi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %edi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %edi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %edi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %edi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %edi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %edi + + # Round 5 + movl 40(%ebp), %eax + xorl %ebx, %ebx + movl 44(%ebp), %edx + xorl %edi, %eax + xorl %edi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %esi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %esi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %esi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %esi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %esi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %esi + + # Round 6 + movl 48(%ebp), %eax + xorl %ebx, %ebx + movl 52(%ebp), %edx + xorl %esi, %eax + xorl %esi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %edi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %edi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %edi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %edi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %edi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %edi + + # Round 7 + movl 56(%ebp), %eax + xorl %ebx, %ebx + movl 60(%ebp), %edx + xorl %edi, %eax + xorl %edi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %esi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %esi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %esi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %esi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %esi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %esi + + # Round 8 + movl 64(%ebp), %eax + xorl %ebx, %ebx + movl 68(%ebp), %edx + xorl %esi, %eax + xorl %esi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %edi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %edi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %edi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %edi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %edi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %edi + + # Round 9 + movl 72(%ebp), %eax + xorl %ebx, %ebx + movl 76(%ebp), %edx + xorl %edi, %eax + xorl %edi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %esi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %esi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %esi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %esi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %esi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %esi + + # Round 10 + movl 80(%ebp), %eax + xorl %ebx, %ebx + movl 84(%ebp), %edx + xorl %esi, %eax + xorl %esi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %edi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %edi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %edi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %edi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %edi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %edi + + # Round 11 + movl 88(%ebp), %eax + xorl %ebx, %ebx + movl 92(%ebp), %edx + xorl %edi, %eax + xorl %edi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %esi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %esi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %esi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %esi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %esi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %esi + + # Round 12 + movl 96(%ebp), %eax + xorl %ebx, %ebx + movl 100(%ebp), %edx + xorl %esi, %eax + xorl %esi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %edi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %edi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %edi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %edi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %edi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %edi + + # Round 13 + movl 104(%ebp), %eax + xorl %ebx, %ebx + movl 108(%ebp), %edx + xorl %edi, %eax + xorl %edi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %esi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %esi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %esi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %esi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %esi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %esi + + # Round 14 + movl 112(%ebp), %eax + xorl %ebx, %ebx + movl 116(%ebp), %edx + xorl %esi, %eax + xorl %esi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %edi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %edi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %edi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %edi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %edi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %edi + + # Round 15 + movl 120(%ebp), %eax + xorl %ebx, %ebx + movl 124(%ebp), %edx + xorl %edi, %eax + xorl %edi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %esi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %esi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %esi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %esi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %esi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %esi + jmp .L003end +.L002start_decrypt: + + # Round 15 + movl 120(%ebp), %eax + xorl %ebx, %ebx + movl 124(%ebp), %edx + xorl %esi, %eax + xorl %esi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %edi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %edi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %edi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %edi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %edi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %edi + + # Round 14 + movl 112(%ebp), %eax + xorl %ebx, %ebx + movl 116(%ebp), %edx + xorl %edi, %eax + xorl %edi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %esi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %esi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %esi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %esi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %esi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %esi + + # Round 13 + movl 104(%ebp), %eax + xorl %ebx, %ebx + movl 108(%ebp), %edx + xorl %esi, %eax + xorl %esi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %edi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %edi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %edi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %edi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %edi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %edi + + # Round 12 + movl 96(%ebp), %eax + xorl %ebx, %ebx + movl 100(%ebp), %edx + xorl %edi, %eax + xorl %edi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %esi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %esi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %esi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %esi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %esi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %esi + + # Round 11 + movl 88(%ebp), %eax + xorl %ebx, %ebx + movl 92(%ebp), %edx + xorl %esi, %eax + xorl %esi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %edi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %edi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %edi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %edi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %edi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %edi + + # Round 10 + movl 80(%ebp), %eax + xorl %ebx, %ebx + movl 84(%ebp), %edx + xorl %edi, %eax + xorl %edi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %esi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %esi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %esi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %esi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %esi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %esi + + # Round 9 + movl 72(%ebp), %eax + xorl %ebx, %ebx + movl 76(%ebp), %edx + xorl %esi, %eax + xorl %esi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %edi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %edi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %edi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %edi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %edi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %edi + + # Round 8 + movl 64(%ebp), %eax + xorl %ebx, %ebx + movl 68(%ebp), %edx + xorl %edi, %eax + xorl %edi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %esi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %esi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %esi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %esi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %esi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %esi + + # Round 7 + movl 56(%ebp), %eax + xorl %ebx, %ebx + movl 60(%ebp), %edx + xorl %esi, %eax + xorl %esi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %edi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %edi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %edi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %edi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %edi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %edi + + # Round 6 + movl 48(%ebp), %eax + xorl %ebx, %ebx + movl 52(%ebp), %edx + xorl %edi, %eax + xorl %edi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %esi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %esi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %esi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %esi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %esi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %esi + + # Round 5 + movl 40(%ebp), %eax + xorl %ebx, %ebx + movl 44(%ebp), %edx + xorl %esi, %eax + xorl %esi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %edi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %edi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %edi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %edi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %edi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %edi + + # Round 4 + movl 32(%ebp), %eax + xorl %ebx, %ebx + movl 36(%ebp), %edx + xorl %edi, %eax + xorl %edi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %esi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %esi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %esi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %esi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %esi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %esi + + # Round 3 + movl 24(%ebp), %eax + xorl %ebx, %ebx + movl 28(%ebp), %edx + xorl %esi, %eax + xorl %esi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %edi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %edi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %edi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %edi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %edi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %edi + + # Round 2 + movl 16(%ebp), %eax + xorl %ebx, %ebx + movl 20(%ebp), %edx + xorl %edi, %eax + xorl %edi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %esi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %esi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %esi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %esi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %esi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %esi + + # Round 1 + movl 8(%ebp), %eax + xorl %ebx, %ebx + movl 12(%ebp), %edx + xorl %esi, %eax + xorl %esi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %edi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %edi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %edi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %edi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %edi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %edi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %edi + + # Round 0 + movl (%ebp), %eax + xorl %ebx, %ebx + movl 4(%ebp), %edx + xorl %edi, %eax + xorl %edi, %edx + andl $0xfcfcfcfc, %eax + andl $0xcfcfcfcf, %edx + movb %al, %bl + movb %ah, %cl + rorl $4, %edx + movl _C_LABEL(des_SPtrans)(%ebx),%ebp + movb %dl, %bl + xorl %ebp, %esi + movl 0x200+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movb %dh, %cl + shrl $16, %eax + movl 0x100+_C_LABEL(des_SPtrans)(%ebx),%ebp + xorl %ebp, %esi + movb %ah, %bl + shrl $16, %edx + movl 0x300+_C_LABEL(des_SPtrans)(%ecx),%ebp + xorl %ebp, %esi + movl 24(%esp), %ebp + movb %dh, %cl + andl $0xff, %eax + andl $0xff, %edx + movl 0x600+_C_LABEL(des_SPtrans)(%ebx),%ebx + xorl %ebx, %esi + movl 0x700+_C_LABEL(des_SPtrans)(%ecx),%ebx + xorl %ebx, %esi + movl 0x400+_C_LABEL(des_SPtrans)(%eax),%ebx + xorl %ebx, %esi + movl 0x500+_C_LABEL(des_SPtrans)(%edx),%ebx + xorl %ebx, %esi +.L003end: + + # Fixup + rorl $3, %edi + movl 20(%esp), %eax + rorl $3, %esi + movl %edi, (%eax) + movl %esi, 4(%eax) + popl %ebp + popl %ebx + popl %edi + popl %esi + ret +.L_des_encrypt2_end: + .size _C_LABEL(des_encrypt2),.L_des_encrypt2_end-_C_LABEL(des_encrypt2) + +ENTRY(des_encrypt3) + pushl %ebx + movl 8(%esp), %ebx + pushl %ebp + pushl %esi + pushl %edi + + # Load the data words + movl (%ebx), %edi + movl 4(%ebx), %esi + subl $12, %esp + + # IP + roll $4, %edi + movl %edi, %edx + xorl %esi, %edi + andl $0xf0f0f0f0, %edi + xorl %edi, %edx + xorl %edi, %esi + + roll $20, %esi + movl %esi, %edi + xorl %edx, %esi + andl $0xfff0000f, %esi + xorl %esi, %edi + xorl %esi, %edx + + roll $14, %edi + movl %edi, %esi + xorl %edx, %edi + andl $0x33333333, %edi + xorl %edi, %esi + xorl %edi, %edx + + roll $22, %edx + movl %edx, %edi + xorl %esi, %edx + andl $0x03fc03fc, %edx + xorl %edx, %edi + xorl %edx, %esi + + roll $9, %edi + movl %edi, %edx + xorl %esi, %edi + andl $0xaaaaaaaa, %edi + xorl %edi, %edx + xorl %edi, %esi + + rorl $3, %edx + rorl $2, %esi + movl %esi, 4(%ebx) + movl 36(%esp), %eax + movl %edx, (%ebx) + movl 40(%esp), %edi + movl 44(%esp), %esi + movl $1, 8(%esp) + movl %eax, 4(%esp) + movl %ebx, (%esp) + call _C_LABEL(des_encrypt2) + movl $0, 8(%esp) + movl %edi, 4(%esp) + movl %ebx, (%esp) + call _C_LABEL(des_encrypt2) + movl $1, 8(%esp) + movl %esi, 4(%esp) + movl %ebx, (%esp) + call _C_LABEL(des_encrypt2) + addl $12, %esp + movl (%ebx), %edi + movl 4(%ebx), %esi + + # FP + roll $2, %esi + roll $3, %edi + movl %edi, %eax + xorl %esi, %edi + andl $0xaaaaaaaa, %edi + xorl %edi, %eax + xorl %edi, %esi + + roll $23, %eax + movl %eax, %edi + xorl %esi, %eax + andl $0x03fc03fc, %eax + xorl %eax, %edi + xorl %eax, %esi + + roll $10, %edi + movl %edi, %eax + xorl %esi, %edi + andl $0x33333333, %edi + xorl %edi, %eax + xorl %edi, %esi + + roll $18, %esi + movl %esi, %edi + xorl %eax, %esi + andl $0xfff0000f, %esi + xorl %esi, %edi + xorl %esi, %eax + + roll $12, %edi + movl %edi, %esi + xorl %eax, %edi + andl $0xf0f0f0f0, %edi + xorl %edi, %esi + xorl %edi, %eax + + rorl $4, %eax + movl %eax, (%ebx) + movl %esi, 4(%ebx) + popl %edi + popl %esi + popl %ebp + popl %ebx + ret +.L_des_encrypt3_end: + .size _C_LABEL(des_encrypt3),.L_des_encrypt3_end-_C_LABEL(des_encrypt3) + +ENTRY(des_decrypt3) + pushl %ebx + movl 8(%esp), %ebx + pushl %ebp + pushl %esi + pushl %edi + + # Load the data words + movl (%ebx), %edi + movl 4(%ebx), %esi + subl $12, %esp + + # IP + roll $4, %edi + movl %edi, %edx + xorl %esi, %edi + andl $0xf0f0f0f0, %edi + xorl %edi, %edx + xorl %edi, %esi + + roll $20, %esi + movl %esi, %edi + xorl %edx, %esi + andl $0xfff0000f, %esi + xorl %esi, %edi + xorl %esi, %edx + + roll $14, %edi + movl %edi, %esi + xorl %edx, %edi + andl $0x33333333, %edi + xorl %edi, %esi + xorl %edi, %edx + + roll $22, %edx + movl %edx, %edi + xorl %esi, %edx + andl $0x03fc03fc, %edx + xorl %edx, %edi + xorl %edx, %esi + + roll $9, %edi + movl %edi, %edx + xorl %esi, %edi + andl $0xaaaaaaaa, %edi + xorl %edi, %edx + xorl %edi, %esi + + rorl $3, %edx + rorl $2, %esi + movl %esi, 4(%ebx) + movl 36(%esp), %esi + movl %edx, (%ebx) + movl 40(%esp), %edi + movl 44(%esp), %eax + movl $0, 8(%esp) + movl %eax, 4(%esp) + movl %ebx, (%esp) + call _C_LABEL(des_encrypt2) + movl $1, 8(%esp) + movl %edi, 4(%esp) + movl %ebx, (%esp) + call _C_LABEL(des_encrypt2) + movl $0, 8(%esp) + movl %esi, 4(%esp) + movl %ebx, (%esp) + call _C_LABEL(des_encrypt2) + addl $12, %esp + movl (%ebx), %edi + movl 4(%ebx), %esi + + # FP + roll $2, %esi + roll $3, %edi + movl %edi, %eax + xorl %esi, %edi + andl $0xaaaaaaaa, %edi + xorl %edi, %eax + xorl %edi, %esi + + roll $23, %eax + movl %eax, %edi + xorl %esi, %eax + andl $0x03fc03fc, %eax + xorl %eax, %edi + xorl %eax, %esi + + roll $10, %edi + movl %edi, %eax + xorl %esi, %edi + andl $0x33333333, %edi + xorl %edi, %eax + xorl %edi, %esi + + roll $18, %esi + movl %esi, %edi + xorl %eax, %esi + andl $0xfff0000f, %esi + xorl %esi, %edi + xorl %esi, %eax + + roll $12, %edi + movl %edi, %esi + xorl %eax, %edi + andl $0xf0f0f0f0, %edi + xorl %edi, %esi + xorl %edi, %eax + + rorl $4, %eax + movl %eax, (%ebx) + movl %esi, 4(%ebx) + popl %edi + popl %esi + popl %ebp + popl %ebx + ret +.L_des_decrypt3_end: + .size _C_LABEL(des_decrypt3),.L_des_decrypt3_end-_C_LABEL(des_decrypt3) diff --git a/sys/crypto/des/des.h b/sys/crypto/des/des.h new file mode 100644 index 000000000..0810db1f1 --- /dev/null +++ b/sys/crypto/des/des.h @@ -0,0 +1,118 @@ +/* $NetBSD: des.h,v 1.8 2009/03/14 14:46:08 dsl Exp $ */ +/* $KAME: des.h,v 1.7 2000/09/18 20:59:21 itojun Exp $ */ + +/* lib/des/des.h */ +/* Copyright (C) 1995-1996 Eric Young (eay@mincom.oz.au) + * All rights reserved. + * + * This file is part of an SSL implementation written + * by Eric Young (eay@mincom.oz.au). + * The implementation was written so as to conform with Netscapes SSL + * specification. This library and applications are + * FREE FOR COMMERCIAL AND NON-COMMERCIAL USE + * as long as the following conditions are aheared to. + * + * Copyright remains Eric Young's, and as such any Copyright notices in + * the code are not to be removed. If this code is used in a product, + * Eric Young should be given attribution as the author of the parts used. + * This can be in the form of a textual message at program startup or + * in documentation (online or textual) provided with the package. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * 3. All advertising materials mentioning features or use of this software + * must display the following acknowledgement: + * This product includes software developed by Eric Young (eay@mincom.oz.au) + * + * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND + * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE + * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE + * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE + * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL + * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS + * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) + * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT + * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY + * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF + * SUCH DAMAGE. + * + * The licence and distribution terms for any publically available version or + * derivative of this code cannot be changed. i.e. this code cannot simply be + * copied and put under another distribution licence + * [including the GNU Public Licence.] + */ + +#ifndef HEADER_DES_H +#define HEADER_DES_H + +#ifdef __cplusplus +extern "C" { +#endif + +/* must be 32bit quantity */ +#define DES_LONG u_int32_t + +typedef unsigned char des_cblock[8]; +typedef struct des_ks_struct + { + union { + des_cblock cblock; + /* make sure things are correct size on machines with + * 8 byte longs */ + DES_LONG deslong[2]; + } ks; + int weak_key; +} des_key_schedule[16]; + +#define DES_KEY_SZ (sizeof(des_cblock)) +#define DES_SCHEDULE_SZ (sizeof(des_key_schedule)) + +#define DES_ENCRYPT 1 +#define DES_DECRYPT 0 + +#define DES_CBC_MODE 0 +#define DES_PCBC_MODE 1 + +extern int des_check_key; /* defaults to false */ + +char *des_options(void); +void des_ecb_encrypt(des_cblock *, des_cblock *, + des_key_schedule, int); + +void des_encrypt1(DES_LONG *, des_key_schedule, int); +void des_encrypt2(DES_LONG *, des_key_schedule, int); +void des_encrypt3(DES_LONG *, des_key_schedule, des_key_schedule, + des_key_schedule); +void des_decrypt3(DES_LONG *, des_key_schedule, des_key_schedule, + des_key_schedule); + +void des_ecb3_encrypt(des_cblock *, des_cblock *, des_key_schedule, + des_key_schedule, des_key_schedule, int); + +void des_ncbc_encrypt(const unsigned char *, unsigned char *, long, + des_key_schedule, des_cblock *, int); + +void des_ede3_cbc_encrypt(const unsigned char *, unsigned char *, long, + des_key_schedule, des_key_schedule, + des_key_schedule, des_cblock *, int); + +void des_set_odd_parity(des_cblock *); +void des_fixup_key_parity(des_cblock *); +int des_is_weak_key(des_cblock *); +int des_set_key(des_cblock *, des_key_schedule); +int des_key_sched(des_cblock *, des_key_schedule); +int des_set_key_checked(des_cblock *, des_key_schedule); +void des_set_key_unchecked(des_cblock *, des_key_schedule); +int des_check_key_parity(des_cblock *); + +#ifdef __cplusplus +} +#endif + +#endif diff --git a/sys/crypto/des/des_cbc.c b/sys/crypto/des/des_cbc.c new file mode 100644 index 000000000..711eee65c --- /dev/null +++ b/sys/crypto/des/des_cbc.c @@ -0,0 +1,247 @@ +/* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com) + * All rights reserved. + * + * This package is an SSL implementation written + * by Eric Young (eay@cryptsoft.com). + * The implementation was written so as to conform with Netscapes SSL. + * + * This library is free for commercial and non-commercial use as long as + * the following conditions are aheared to. The following conditions + * apply to all code found in this distribution, be it the RC4, RSA, + * lhash, DES, etc., code; not just the SSL code. The SSL documentation + * included with this distribution is covered by the same copyright terms + * except that the holder is Tim Hudson (tjh@cryptsoft.com). + * + * Copyright remains Eric Young's, and as such any Copyright notices in + * the code are not to be removed. + * If this package is used in a product, Eric Young should be given attribution + * as the author of the parts of the library used. + * This can be in the form of a textual message at program startup or + * in documentation (online or textual) provided with the package. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * 3. All advertising materials mentioning features or use of this software + * must display the following acknowledgement: + * "This product includes cryptographic software written by + * Eric Young (eay@cryptsoft.com)" + * The word 'cryptographic' can be left out if the rouines from the library + * being used are not cryptographic related :-). + * 4. If you include any Windows specific code (or a derivative thereof) from + * the apps directory (application code) you must include an acknowledgement: + * "This product includes software written by Tim Hudson (tjh@cryptsoft.com)" + * + * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND + * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE + * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE + * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE + * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL + * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS + * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) + * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT + * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY + * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF + * SUCH DAMAGE. + * + * The licence and distribution terms for any publically available version or + * derivative of this code cannot be changed. i.e. this code cannot simply be + * copied and put under another distribution licence + * [including the GNU Public Licence.] + */ + +#include +__KERNEL_RCSID(0, "$NetBSD: des_cbc.c,v 1.8 2005/12/11 12:20:52 christos Exp $"); + +#include + +#include + +void des_ncbc_encrypt(const unsigned char *in, unsigned char *out, long length, + des_key_schedule schedule, des_cblock *ivec, int enc) +{ + register DES_LONG tin0,tin1; + register DES_LONG tout0,tout1,xor0,xor1; + register long l=length; + DES_LONG tin[2]; + unsigned char *iv; + + iv = &(*ivec)[0]; + + if (enc) + { + c2l(iv,tout0); + c2l(iv,tout1); + for (l-=8; l>=0; l-=8) + { + c2l(in,tin0); + c2l(in,tin1); + tin0^=tout0; tin[0]=tin0; + tin1^=tout1; tin[1]=tin1; + des_encrypt1((DES_LONG *)tin,schedule,DES_ENCRYPT); + tout0=tin[0]; l2c(tout0,out); + tout1=tin[1]; l2c(tout1,out); + } + if (l != -8) + { + c2ln(in,tin0,tin1,l+8); + tin0^=tout0; tin[0]=tin0; + tin1^=tout1; tin[1]=tin1; + des_encrypt1((DES_LONG *)tin,schedule,DES_ENCRYPT); + tout0=tin[0]; l2c(tout0,out); + tout1=tin[1]; l2c(tout1,out); + } + iv = &(*ivec)[0]; + l2c(tout0,iv); + l2c(tout1,iv); + } + else + { + c2l(iv,xor0); + c2l(iv,xor1); + for (l-=8; l>=0; l-=8) + { + c2l(in,tin0); tin[0]=tin0; + c2l(in,tin1); tin[1]=tin1; + des_encrypt1((DES_LONG *)tin,schedule,DES_DECRYPT); + tout0=tin[0]^xor0; + tout1=tin[1]^xor1; + l2c(tout0,out); + l2c(tout1,out); + xor0=tin0; + xor1=tin1; + } + if (l != -8) + { + c2l(in,tin0); tin[0]=tin0; + c2l(in,tin1); tin[1]=tin1; + des_encrypt1((DES_LONG *)tin,schedule,DES_DECRYPT); + tout0=tin[0]^xor0; + tout1=tin[1]^xor1; + l2cn(tout0,tout1,out,l+8); + xor0=tin0; + xor1=tin1; + } + iv = &(*ivec)[0]; + l2c(xor0,iv); + l2c(xor1,iv); + } + tin0=tin1=tout0=tout1=xor0=xor1=0; + tin[0]=tin[1]=0; +} + +void des_ede3_cbc_encrypt(const unsigned char *input, unsigned char *output, + long length, des_key_schedule ks1, des_key_schedule ks2, + des_key_schedule ks3, des_cblock *ivec, int enc) +{ + register DES_LONG tin0,tin1; + register DES_LONG tout0,tout1,xor0,xor1; + register const unsigned char *in; + unsigned char *out; + register long l=length; + DES_LONG tin[2]; + unsigned char *iv; + + in=input; + out=output; + iv = &(*ivec)[0]; + + if (enc) + { + c2l(iv,tout0); + c2l(iv,tout1); + for (l-=8; l>=0; l-=8) + { + c2l(in,tin0); + c2l(in,tin1); + tin0^=tout0; + tin1^=tout1; + + tin[0]=tin0; + tin[1]=tin1; + des_encrypt3((DES_LONG *)tin,ks1,ks2,ks3); + tout0=tin[0]; + tout1=tin[1]; + + l2c(tout0,out); + l2c(tout1,out); + } + if (l != -8) + { + c2ln(in,tin0,tin1,l+8); + tin0^=tout0; + tin1^=tout1; + + tin[0]=tin0; + tin[1]=tin1; + des_encrypt3((DES_LONG *)tin,ks1,ks2,ks3); + tout0=tin[0]; + tout1=tin[1]; + + l2c(tout0,out); + l2c(tout1,out); + } + iv = &(*ivec)[0]; + l2c(tout0,iv); + l2c(tout1,iv); + } + else + { + register DES_LONG t0,t1; + + c2l(iv,xor0); + c2l(iv,xor1); + for (l-=8; l>=0; l-=8) + { + c2l(in,tin0); + c2l(in,tin1); + + t0=tin0; + t1=tin1; + + tin[0]=tin0; + tin[1]=tin1; + des_decrypt3((DES_LONG *)tin,ks1,ks2,ks3); + tout0=tin[0]; + tout1=tin[1]; + + tout0^=xor0; + tout1^=xor1; + l2c(tout0,out); + l2c(tout1,out); + xor0=t0; + xor1=t1; + } + if (l != -8) + { + c2l(in,tin0); + c2l(in,tin1); + + t0=tin0; + t1=tin1; + + tin[0]=tin0; + tin[1]=tin1; + des_decrypt3((DES_LONG *)tin,ks1,ks2,ks3); + tout0=tin[0]; + tout1=tin[1]; + + tout0^=xor0; + tout1^=xor1; + l2cn(tout0,tout1,out,l+8); + xor0=t0; + xor1=t1; + } + + iv = &(*ivec)[0]; + l2c(xor0,iv); + l2c(xor1,iv); + } + tin0=tin1=tout0=tout1=xor0=xor1=0; + tin[0]=tin[1]=0; +} diff --git a/sys/crypto/des/des_ecb.c b/sys/crypto/des/des_ecb.c new file mode 100644 index 000000000..67b29923d --- /dev/null +++ b/sys/crypto/des/des_ecb.c @@ -0,0 +1,146 @@ +/* $NetBSD: des_ecb.c,v 1.10 2014/03/25 16:28:15 christos Exp $ */ +/* $KAME: des_ecb.c,v 1.5 2000/11/06 13:58:08 itojun Exp $ */ + +/* crypto/des/ecb_enc.c */ +/* Copyright (C) 1995-1998 Eric Young (eay@mincom.oz.au) + * All rights reserved. + * + * This file is part of an SSL implementation written + * by Eric Young (eay@mincom.oz.au). + * The implementation was written so as to conform with Netscapes SSL + * specification. This library and applications are + * FREE FOR COMMERCIAL AND NON-COMMERCIAL USE + * as long as the following conditions are aheared to. + * + * Copyright remains Eric Young's, and as such any Copyright notices in + * the code are not to be removed. If this code is used in a product, + * Eric Young should be given attribution as the author of the parts used. + * This can be in the form of a textual message at program startup or + * in documentation (online or textual) provided with the package. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * 3. All advertising materials mentioning features or use of this software + * must display the following acknowledgement: + * This product includes software developed by Eric Young (eay@mincom.oz.au) + * + * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND + * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE + * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE + * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE + * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL + * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS + * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) + * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT + * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY + * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF + * SUCH DAMAGE. + * + * The licence and distribution terms for any publically available version or + * derivative of this code cannot be changed. i.e. this code cannot simply be + * copied and put under another distribution licence + * [including the GNU Public Licence.] + */ + +#include +__KERNEL_RCSID(0, "$NetBSD: des_ecb.c,v 1.10 2014/03/25 16:28:15 christos Exp $"); + +#include +#ifdef _KERNEL +#include +#else +#include +#include +#endif +#include +#include + +/* char *libdes_version="libdes v 3.24 - 20-Apr-1996 - eay"; */ /* wrong */ +/* char *DES_version="DES part of SSLeay 0.6.4 30-Aug-1996"; */ + +char *des_options(void) + { + static int init=1; + static char buf[32]; + + if (init) + { + const char *ptr,*unroll,*risc,*size; + +#ifdef DES_PTR + ptr="ptr"; +#else + ptr="idx"; +#endif +#if defined(DES_RISC1) || defined(DES_RISC2) +#ifdef DES_RISC1 + risc="risc1"; +#endif +#ifdef DES_RISC2 + risc="risc2"; +#endif +#else + risc="cisc"; +#endif +#ifdef DES_UNROLL + unroll="16"; +#else + unroll="4"; +#endif + /*CONSTCOND*/ + if (sizeof(DES_LONG) != sizeof(long)) + size="int"; + else + size="long"; + snprintf(buf, sizeof(buf), "des(%s,%s,%s,%s)", + ptr, risc, unroll, size); + init=0; + } + return(buf); +} +void des_ecb_encrypt(des_cblock *input, des_cblock *output, + des_key_schedule ks, int enc) +{ + register DES_LONG l; + DES_LONG ll[2]; + const unsigned char *in=&(*input)[0]; + unsigned char *out = &(*output)[0]; + + c2l(in,l); ll[0]=l; + c2l(in,l); ll[1]=l; + des_encrypt1(ll,ks,enc); + l=ll[0]; l2c(l,out); + l=ll[1]; l2c(l,out); + l=ll[0]=ll[1]=0; +} + +void des_ecb3_encrypt(des_cblock *input, des_cblock *output, + des_key_schedule ks1, des_key_schedule ks2, des_key_schedule ks3, + int enc) +{ + register DES_LONG l0,l1; + DES_LONG ll[2]; + const unsigned char *in = &(*input)[0]; + unsigned char *out = &(*output)[0]; + + c2l(in,l0); + c2l(in,l1); + ll[0]=l0; + ll[1]=l1; + + if (enc) + des_encrypt3(ll,ks1,ks2,ks3); + else + des_decrypt3(ll,ks1,ks2,ks3); + + l0=ll[0]; + l1=ll[1]; + l2c(l0,out); + l2c(l1,out); +} diff --git a/sys/crypto/des/des_enc.c b/sys/crypto/des/des_enc.c new file mode 100644 index 000000000..8683be8c0 --- /dev/null +++ b/sys/crypto/des/des_enc.c @@ -0,0 +1,294 @@ +/* crypto/des/des_enc.c */ +/* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com) + * All rights reserved. + * + * This package is an SSL implementation written + * by Eric Young (eay@cryptsoft.com). + * The implementation was written so as to conform with Netscapes SSL. + * + * This library is free for commercial and non-commercial use as long as + * the following conditions are aheared to. The following conditions + * apply to all code found in this distribution, be it the RC4, RSA, + * lhash, DES, etc., code; not just the SSL code. The SSL documentation + * included with this distribution is covered by the same copyright terms + * except that the holder is Tim Hudson (tjh@cryptsoft.com). + * + * Copyright remains Eric Young's, and as such any Copyright notices in + * the code are not to be removed. + * If this package is used in a product, Eric Young should be given attribution + * as the author of the parts of the library used. + * This can be in the form of a textual message at program startup or + * in documentation (online or textual) provided with the package. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * 3. All advertising materials mentioning features or use of this software + * must display the following acknowledgement: + * "This product includes cryptographic software written by + * Eric Young (eay@cryptsoft.com)" + * The word 'cryptographic' can be left out if the rouines from the library + * being used are not cryptographic related :-). + * 4. If you include any Windows specific code (or a derivative thereof) from + * the apps directory (application code) you must include an acknowledgement: + * "This product includes software written by Tim Hudson (tjh@cryptsoft.com)" + * + * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND + * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE + * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE + * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE + * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL + * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS + * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) + * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT + * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY + * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF + * SUCH DAMAGE. + * + * The licence and distribution terms for any publically available version or + * derivative of this code cannot be changed. i.e. this code cannot simply be + * copied and put under another distribution licence + * [including the GNU Public Licence.] + */ + +#include +__KERNEL_RCSID(0, "$NetBSD: des_enc.c,v 1.4 2005/12/11 12:20:52 christos Exp $"); + +#include +#include + +extern const DES_LONG des_SPtrans[8][64]; + +void des_encrypt1(DES_LONG *data, des_key_schedule ks, int enc) +{ + register DES_LONG l,r,t,u; +#ifdef DES_PTR + register const unsigned char *des_SP=(const unsigned char *)des_SPtrans; +#endif +#ifndef DES_UNROLL + register int i; +#endif + register DES_LONG *s; + + r=data[0]; + l=data[1]; + + IP(r,l); + /* Things have been modified so that the initial rotate is + * done outside the loop. This required the + * des_SPtrans values in sp.h to be rotated 1 bit to the right. + * One perl script later and things have a 5% speed up on a sparc2. + * Thanks to Richard Outerbridge <71755.204@CompuServe.COM> + * for pointing this out. */ + /* clear the top bits on machines with 8byte longs */ + /* shift left by 2 */ + r=ROTATE(r,29)&0xffffffffL; + l=ROTATE(l,29)&0xffffffffL; + + s=ks->ks.deslong; + /* I don't know if it is worth the effort of loop unrolling the + * inner loop */ + if (enc) + { +#ifdef DES_UNROLL + D_ENCRYPT(l,r, 0); /* 1 */ + D_ENCRYPT(r,l, 2); /* 2 */ + D_ENCRYPT(l,r, 4); /* 3 */ + D_ENCRYPT(r,l, 6); /* 4 */ + D_ENCRYPT(l,r, 8); /* 5 */ + D_ENCRYPT(r,l,10); /* 6 */ + D_ENCRYPT(l,r,12); /* 7 */ + D_ENCRYPT(r,l,14); /* 8 */ + D_ENCRYPT(l,r,16); /* 9 */ + D_ENCRYPT(r,l,18); /* 10 */ + D_ENCRYPT(l,r,20); /* 11 */ + D_ENCRYPT(r,l,22); /* 12 */ + D_ENCRYPT(l,r,24); /* 13 */ + D_ENCRYPT(r,l,26); /* 14 */ + D_ENCRYPT(l,r,28); /* 15 */ + D_ENCRYPT(r,l,30); /* 16 */ +#else + for (i=0; i<32; i+=8) + { + D_ENCRYPT(l,r,i+0); /* 1 */ + D_ENCRYPT(r,l,i+2); /* 2 */ + D_ENCRYPT(l,r,i+4); /* 3 */ + D_ENCRYPT(r,l,i+6); /* 4 */ + } +#endif + } + else + { +#ifdef DES_UNROLL + D_ENCRYPT(l,r,30); /* 16 */ + D_ENCRYPT(r,l,28); /* 15 */ + D_ENCRYPT(l,r,26); /* 14 */ + D_ENCRYPT(r,l,24); /* 13 */ + D_ENCRYPT(l,r,22); /* 12 */ + D_ENCRYPT(r,l,20); /* 11 */ + D_ENCRYPT(l,r,18); /* 10 */ + D_ENCRYPT(r,l,16); /* 9 */ + D_ENCRYPT(l,r,14); /* 8 */ + D_ENCRYPT(r,l,12); /* 7 */ + D_ENCRYPT(l,r,10); /* 6 */ + D_ENCRYPT(r,l, 8); /* 5 */ + D_ENCRYPT(l,r, 6); /* 4 */ + D_ENCRYPT(r,l, 4); /* 3 */ + D_ENCRYPT(l,r, 2); /* 2 */ + D_ENCRYPT(r,l, 0); /* 1 */ +#else + for (i=30; i>0; i-=8) + { + D_ENCRYPT(l,r,i-0); /* 16 */ + D_ENCRYPT(r,l,i-2); /* 15 */ + D_ENCRYPT(l,r,i-4); /* 14 */ + D_ENCRYPT(r,l,i-6); /* 13 */ + } +#endif + } + + /* rotate and clear the top bits on machines with 8byte longs */ + l=ROTATE(l,3)&0xffffffffL; + r=ROTATE(r,3)&0xffffffffL; + + FP(r,l); + data[0]=l; + data[1]=r; + l=r=t=u=0; +} + +void des_encrypt2(DES_LONG *data, des_key_schedule ks, int enc) +{ + register DES_LONG l,r,t,u; +#ifdef DES_PTR + register const unsigned char *des_SP=(const unsigned char *)des_SPtrans; +#endif +#ifndef DES_UNROLL + register int i; +#endif + register DES_LONG *s; + + r=data[0]; + l=data[1]; + + /* Things have been modified so that the initial rotate is + * done outside the loop. This required the + * des_SPtrans values in sp.h to be rotated 1 bit to the right. + * One perl script later and things have a 5% speed up on a sparc2. + * Thanks to Richard Outerbridge <71755.204@CompuServe.COM> + * for pointing this out. */ + /* clear the top bits on machines with 8byte longs */ + r=ROTATE(r,29)&0xffffffffL; + l=ROTATE(l,29)&0xffffffffL; + + s=ks->ks.deslong; + /* I don't know if it is worth the effort of loop unrolling the + * inner loop */ + if (enc) + { +#ifdef DES_UNROLL + D_ENCRYPT(l,r, 0); /* 1 */ + D_ENCRYPT(r,l, 2); /* 2 */ + D_ENCRYPT(l,r, 4); /* 3 */ + D_ENCRYPT(r,l, 6); /* 4 */ + D_ENCRYPT(l,r, 8); /* 5 */ + D_ENCRYPT(r,l,10); /* 6 */ + D_ENCRYPT(l,r,12); /* 7 */ + D_ENCRYPT(r,l,14); /* 8 */ + D_ENCRYPT(l,r,16); /* 9 */ + D_ENCRYPT(r,l,18); /* 10 */ + D_ENCRYPT(l,r,20); /* 11 */ + D_ENCRYPT(r,l,22); /* 12 */ + D_ENCRYPT(l,r,24); /* 13 */ + D_ENCRYPT(r,l,26); /* 14 */ + D_ENCRYPT(l,r,28); /* 15 */ + D_ENCRYPT(r,l,30); /* 16 */ +#else + for (i=0; i<32; i+=8) + { + D_ENCRYPT(l,r,i+0); /* 1 */ + D_ENCRYPT(r,l,i+2); /* 2 */ + D_ENCRYPT(l,r,i+4); /* 3 */ + D_ENCRYPT(r,l,i+6); /* 4 */ + } +#endif + } + else + { +#ifdef DES_UNROLL + D_ENCRYPT(l,r,30); /* 16 */ + D_ENCRYPT(r,l,28); /* 15 */ + D_ENCRYPT(l,r,26); /* 14 */ + D_ENCRYPT(r,l,24); /* 13 */ + D_ENCRYPT(l,r,22); /* 12 */ + D_ENCRYPT(r,l,20); /* 11 */ + D_ENCRYPT(l,r,18); /* 10 */ + D_ENCRYPT(r,l,16); /* 9 */ + D_ENCRYPT(l,r,14); /* 8 */ + D_ENCRYPT(r,l,12); /* 7 */ + D_ENCRYPT(l,r,10); /* 6 */ + D_ENCRYPT(r,l, 8); /* 5 */ + D_ENCRYPT(l,r, 6); /* 4 */ + D_ENCRYPT(r,l, 4); /* 3 */ + D_ENCRYPT(l,r, 2); /* 2 */ + D_ENCRYPT(r,l, 0); /* 1 */ +#else + for (i=30; i>0; i-=8) + { + D_ENCRYPT(l,r,i-0); /* 16 */ + D_ENCRYPT(r,l,i-2); /* 15 */ + D_ENCRYPT(l,r,i-4); /* 14 */ + D_ENCRYPT(r,l,i-6); /* 13 */ + } +#endif + } + /* rotate and clear the top bits on machines with 8byte longs */ + data[0]=ROTATE(l,3)&0xffffffffL; + data[1]=ROTATE(r,3)&0xffffffffL; + l=r=t=u=0; +} + +void des_encrypt3(DES_LONG *data, des_key_schedule ks1, des_key_schedule ks2, + des_key_schedule ks3) +{ + register DES_LONG l,r; + + l=data[0]; + r=data[1]; + IP(l,r); + data[0]=l; + data[1]=r; + des_encrypt2((DES_LONG *)data,ks1,DES_ENCRYPT); + des_encrypt2((DES_LONG *)data,ks2,DES_DECRYPT); + des_encrypt2((DES_LONG *)data,ks3,DES_ENCRYPT); + l=data[0]; + r=data[1]; + FP(r,l); + data[0]=l; + data[1]=r; +} + +void des_decrypt3(DES_LONG *data, des_key_schedule ks1, des_key_schedule ks2, + des_key_schedule ks3) +{ + register DES_LONG l,r; + + l=data[0]; + r=data[1]; + IP(l,r); + data[0]=l; + data[1]=r; + des_encrypt2((DES_LONG *)data,ks3,DES_DECRYPT); + des_encrypt2((DES_LONG *)data,ks2,DES_ENCRYPT); + des_encrypt2((DES_LONG *)data,ks1,DES_DECRYPT); + l=data[0]; + r=data[1]; + FP(r,l); + data[0]=l; + data[1]=r; +} diff --git a/sys/crypto/des/des_locl.h b/sys/crypto/des/des_locl.h new file mode 100644 index 000000000..25474dd77 --- /dev/null +++ b/sys/crypto/des/des_locl.h @@ -0,0 +1,364 @@ +/* $NetBSD: des_locl.h,v 1.4 2001/09/09 11:01:02 tls Exp $ */ +/* $KAME: des_locl.h,v 1.6 2000/11/06 13:58:09 itojun Exp $ */ + +/* crypto/des/des_locl.h */ +/* Copyright (C) 1995-1997 Eric Young (eay@mincom.oz.au) + * All rights reserved. + * + * This file is part of an SSL implementation written + * by Eric Young (eay@mincom.oz.au). + * The implementation was written so as to conform with Netscapes SSL + * specification. This library and applications are + * FREE FOR COMMERCIAL AND NON-COMMERCIAL USE + * as long as the following conditions are aheared to. + * + * Copyright remains Eric Young's, and as such any Copyright notices in + * the code are not to be removed. If this code is used in a product, + * Eric Young should be given attribution as the author of the parts used. + * This can be in the form of a textual message at program startup or + * in documentation (online or textual) provided with the package. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * 3. All advertising materials mentioning features or use of this software + * must display the following acknowledgement: + * This product includes software developed by Eric Young (eay@mincom.oz.au) + * + * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND + * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE + * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE + * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE + * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL + * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS + * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) + * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT + * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY + * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF + * SUCH DAMAGE. + * + * The licence and distribution terms for any publically available version or + * derivative of this code cannot be changed. i.e. this code cannot simply be + * copied and put under another distribution licence + * [including the GNU Public Licence.] + */ + +#ifndef HEADER_DES_LOCL_H +#define HEADER_DES_LOCL_H + +#include + +#undef DES_PTR + +#ifdef __STDC__ +#undef NOPROTO +#endif + +#define ITERATIONS 16 +#define HALF_ITERATIONS 8 + +/* used in des_read and des_write */ +#define MAXWRITE (1024*16) +#define BSIZE (MAXWRITE+4) + +#define c2l(c,l) (l =((DES_LONG)(*((c)++))) , \ + l|=((DES_LONG)(*((c)++)))<< 8L, \ + l|=((DES_LONG)(*((c)++)))<<16L, \ + l|=((DES_LONG)(*((c)++)))<<24L) + +/* NOTE - c is not incremented as per c2l */ +#define c2ln(c,l1,l2,n) { \ + c+=n; \ + l1=l2=0; \ + switch (n) { \ + case 8: l2 =((DES_LONG)(*(--(c))))<<24L; \ + case 7: l2|=((DES_LONG)(*(--(c))))<<16L; \ + case 6: l2|=((DES_LONG)(*(--(c))))<< 8L; \ + case 5: l2|=((DES_LONG)(*(--(c)))); \ + case 4: l1 =((DES_LONG)(*(--(c))))<<24L; \ + case 3: l1|=((DES_LONG)(*(--(c))))<<16L; \ + case 2: l1|=((DES_LONG)(*(--(c))))<< 8L; \ + case 1: l1|=((DES_LONG)(*(--(c)))); \ + } \ + } + +#define l2c(l,c) (*((c)++)=(unsigned char)(((l) )&0xff), \ + *((c)++)=(unsigned char)(((l)>> 8L)&0xff), \ + *((c)++)=(unsigned char)(((l)>>16L)&0xff), \ + *((c)++)=(unsigned char)(((l)>>24L)&0xff)) + +/* replacements for htonl and ntohl since I have no idea what to do + * when faced with machines with 8 byte longs. */ +#define HDRSIZE 4 + +#define n2l(c,l) (l =((DES_LONG)(*((c)++)))<<24L, \ + l|=((DES_LONG)(*((c)++)))<<16L, \ + l|=((DES_LONG)(*((c)++)))<< 8L, \ + l|=((DES_LONG)(*((c)++)))) + +#define l2n(l,c) (*((c)++)=(unsigned char)(((l)>>24L)&0xff), \ + *((c)++)=(unsigned char)(((l)>>16L)&0xff), \ + *((c)++)=(unsigned char)(((l)>> 8L)&0xff), \ + *((c)++)=(unsigned char)(((l) )&0xff)) + +/* NOTE - c is not incremented as per l2c */ +#define l2cn(l1,l2,c,n) { \ + c+=n; \ + switch (n) { \ + case 8: *(--(c))=(unsigned char)(((l2)>>24L)&0xff); \ + case 7: *(--(c))=(unsigned char)(((l2)>>16L)&0xff); \ + case 6: *(--(c))=(unsigned char)(((l2)>> 8L)&0xff); \ + case 5: *(--(c))=(unsigned char)(((l2) )&0xff); \ + case 4: *(--(c))=(unsigned char)(((l1)>>24L)&0xff); \ + case 3: *(--(c))=(unsigned char)(((l1)>>16L)&0xff); \ + case 2: *(--(c))=(unsigned char)(((l1)>> 8L)&0xff); \ + case 1: *(--(c))=(unsigned char)(((l1) )&0xff); \ + } \ + } + +#define ROTATE(a,n) (((a)>>(n))+((a)<<(32-(n)))) + +#define LOAD_DATA_tmp(a,b,c,d,e,f) LOAD_DATA(a,b,c,d,e,f,g) +#define LOAD_DATA(R,S,u,t,E0,E1,tmp) \ + u=R^s[S ]; \ + t=R^s[S+1] + +/* The changes to this macro may help or hinder, depending on the + * compiler and the achitecture. gcc2 always seems to do well :-). + * Inspired by Dana How + * DO NOT use the alternative version on machines with 8 byte longs. + * It does not seem to work on the Alpha, even when DES_LONG is 4 + * bytes, probably an issue of accessing non-word aligned objects :-( */ +#ifdef DES_PTR + +/* It recently occurred to me that 0^0^0^0^0^0^0 == 0, so there + * is no reason to not xor all the sub items together. This potentially + * saves a register since things can be xored directly into L */ + +#if defined(DES_RISC1) || defined(DES_RISC2) +#ifdef DES_RISC1 +#define D_ENCRYPT(LL,R,S) { \ + unsigned int u1,u2,u3; \ + LOAD_DATA(R,S,u,t,E0,E1,u1); \ + u2=(int)u>>8L; \ + u1=(int)u&0xfc; \ + u2&=0xfc; \ + t=ROTATE(t,4); \ + u>>=16L; \ + LL^= *(const DES_LONG *)(des_SP +u1); \ + LL^= *(const DES_LONG *)(des_SP+0x200+u2); \ + u3=(int)(u>>8L); \ + u1=(int)u&0xfc; \ + u3&=0xfc; \ + LL^= *(const DES_LONG *)(des_SP+0x400+u1); \ + LL^= *(const DES_LONG *)(des_SP+0x600+u3); \ + u2=(int)t>>8L; \ + u1=(int)t&0xfc; \ + u2&=0xfc; \ + t>>=16L; \ + LL^= *(const DES_LONG *)(des_SP+0x100+u1); \ + LL^= *(const DES_LONG *)(des_SP+0x300+u2); \ + u3=(int)t>>8L; \ + u1=(int)t&0xfc; \ + u3&=0xfc; \ + LL^= *(const DES_LONG *)(des_SP+0x500+u1); \ + LL^= *(const DES_LONG *)(des_SP+0x700+u3); } +#endif /* DES_RISC1 */ +#ifdef DES_RISC2 +#define D_ENCRYPT(LL,R,S) { \ + unsigned int u1,u2,s1,s2; \ + LOAD_DATA(R,S,u,t,E0,E1,u1); \ + u2=(int)u>>8L; \ + u1=(int)u&0xfc; \ + u2&=0xfc; \ + t=ROTATE(t,4); \ + LL^= *(const DES_LONG *)(des_SP +u1); \ + LL^= *(const DES_LONG *)(des_SP+0x200+u2); \ + s1=(int)(u>>16L); \ + s2=(int)(u>>24L); \ + s1&=0xfc; \ + s2&=0xfc; \ + LL^= *(const DES_LONG *)(des_SP+0x400+s1); \ + LL^= *(const DES_LONG *)(des_SP+0x600+s2); \ + u2=(int)t>>8L; \ + u1=(int)t&0xfc; \ + u2&=0xfc; \ + LL^= *(const DES_LONG *)(des_SP+0x100+u1); \ + LL^= *(const DES_LONG *)(des_SP+0x300+u2); \ + s1=(int)(t>>16L); \ + s2=(int)(t>>24L); \ + s1&=0xfc; \ + s2&=0xfc; \ + LL^= *(const DES_LONG *)(des_SP+0x400+s1); \ + LL^= *(const DES_LONG *)(des_SP+0x600+s2); \ + u2=(int)t>>8L; \ + u1=(int)t&0xfc; \ + u2&=0xfc; \ + LL^= *(const DES_LONG *)(des_SP+0x100+u1); \ + LL^= *(const DES_LONG *)(des_SP+0x300+u2); \ + s1=(int)(t>>16L); \ + s2=(int)(t>>24L); \ + s1&=0xfc; \ + s2&=0xfc; \ + LL^= *(const DES_LONG *)(des_SP+0x500+s1); \ + LL^= *(const DES_LONG *)(des_SP+0x700+s2); } +#endif /* DES_RISC2 */ +#else /* DES_RISC1 || DES_RISC2 */ +#define D_ENCRYPT(LL,R,S) { \ + LOAD_DATA_tmp(R,S,u,t,E0,E1); \ + t=ROTATE(t,4); \ + LL^= \ + *(const DES_LONG *)(des_SP +((u )&0xfc))^ \ + *(const DES_LONG *)(des_SP+0x200+((u>> 8L)&0xfc))^ \ + *(const DES_LONG *)(des_SP+0x400+((u>>16L)&0xfc))^ \ + *(const DES_LONG *)(des_SP+0x600+((u>>24L)&0xfc))^ \ + *(const DES_LONG *)(des_SP+0x100+((t )&0xfc))^ \ + *(const DES_LONG *)(des_SP+0x300+((t>> 8L)&0xfc))^ \ + *(const DES_LONG *)(des_SP+0x500+((t>>16L)&0xfc))^ \ + *(const DES_LONG *)(des_SP+0x700+((t>>24L)&0xfc)); } +#endif /* DES_RISC1 || DES_RISC2 */ +#else /* original version */ + +#if defined(DES_RISC1) || defined(DES_RISC2) +#ifdef DES_RISC1 +#define D_ENCRYPT(LL,R,S) {\ + unsigned int u1,u2,u3; \ + LOAD_DATA(R,S,u,t,E0,E1,u1); \ + u>>=2L; \ + t=ROTATE(t,6); \ + u2=(int)u>>8L; \ + u1=(int)u&0x3f; \ + u2&=0x3f; \ + u>>=16L; \ + LL^=des_SPtrans[0][u1]; \ + LL^=des_SPtrans[2][u2]; \ + u3=(int)u>>8L; \ + u1=(int)u&0x3f; \ + u3&=0x3f; \ + LL^=des_SPtrans[4][u1]; \ + LL^=des_SPtrans[6][u3]; \ + u2=(int)t>>8L; \ + u1=(int)t&0x3f; \ + u2&=0x3f; \ + t>>=16L; \ + LL^=des_SPtrans[1][u1]; \ + LL^=des_SPtrans[3][u2]; \ + u3=(int)t>>8L; \ + u1=(int)t&0x3f; \ + u3&=0x3f; \ + LL^=des_SPtrans[5][u1]; \ + LL^=des_SPtrans[7][u3]; } +#endif /* DES_RISC1 */ +#ifdef DES_RISC2 +#define D_ENCRYPT(LL,R,S) {\ + unsigned int u1,u2,s1,s2; \ + LOAD_DATA(R,S,u,t,E0,E1,u1); \ + u>>=2L; \ + t=ROTATE(t,6); \ + u2=(int)u>>8L; \ + u1=(int)u&0x3f; \ + u2&=0x3f; \ + LL^=des_SPtrans[0][u1]; \ + LL^=des_SPtrans[2][u2]; \ + s1=(int)u>>16L; \ + s2=(int)u>>24L; \ + s1&=0x3f; \ + s2&=0x3f; \ + LL^=des_SPtrans[4][s1]; \ + LL^=des_SPtrans[6][s2]; \ + u2=(int)t>>8L; \ + u1=(int)t&0x3f; \ + u2&=0x3f; \ + LL^=des_SPtrans[1][u1]; \ + LL^=des_SPtrans[3][u2]; \ + s1=(int)t>>16; \ + s2=(int)t>>24L; \ + s1&=0x3f; \ + s2&=0x3f; \ + LL^=des_SPtrans[5][s1]; \ + LL^=des_SPtrans[7][s2]; } +#endif /* DES_RISC2 */ + +#else /* DES_RISC1 || DES_RISC2 */ + +#define D_ENCRYPT(LL,R,S) {\ + LOAD_DATA_tmp(R,S,u,t,E0,E1); \ + t=ROTATE(t,4); \ + LL^=\ + des_SPtrans[0][(u>> 2L)&0x3f]^ \ + des_SPtrans[2][(u>>10L)&0x3f]^ \ + des_SPtrans[4][(u>>18L)&0x3f]^ \ + des_SPtrans[6][(u>>26L)&0x3f]^ \ + des_SPtrans[1][(t>> 2L)&0x3f]^ \ + des_SPtrans[3][(t>>10L)&0x3f]^ \ + des_SPtrans[5][(t>>18L)&0x3f]^ \ + des_SPtrans[7][(t>>26L)&0x3f]; } +#endif /* DES_RISC1 || DES_RISC2 */ +#endif /* DES_PTR */ + + /* IP and FP + * The problem is more of a geometric problem that random bit fiddling. + 0 1 2 3 4 5 6 7 62 54 46 38 30 22 14 6 + 8 9 10 11 12 13 14 15 60 52 44 36 28 20 12 4 + 16 17 18 19 20 21 22 23 58 50 42 34 26 18 10 2 + 24 25 26 27 28 29 30 31 to 56 48 40 32 24 16 8 0 + + 32 33 34 35 36 37 38 39 63 55 47 39 31 23 15 7 + 40 41 42 43 44 45 46 47 61 53 45 37 29 21 13 5 + 48 49 50 51 52 53 54 55 59 51 43 35 27 19 11 3 + 56 57 58 59 60 61 62 63 57 49 41 33 25 17 9 1 + + The output has been subject to swaps of the form + 0 1 -> 3 1 but the odd and even bits have been put into + 2 3 2 0 + different words. The main trick is to remember that + t=((l>>size)^r)&(mask); + r^=t; + l^=(t<>(n))^(b))&(m)),\ + (b)^=(t),\ + (a)^=((t)<<(n))) + +#define IP(l,r) \ + { \ + register DES_LONG tt; \ + PERM_OP(r,l,tt, 4,0x0f0f0f0fL); \ + PERM_OP(l,r,tt,16,0x0000ffffL); \ + PERM_OP(r,l,tt, 2,0x33333333L); \ + PERM_OP(l,r,tt, 8,0x00ff00ffL); \ + PERM_OP(r,l,tt, 1,0x55555555L); \ + } + +#define FP(l,r) \ + { \ + register DES_LONG tt; \ + PERM_OP(l,r,tt, 1,0x55555555L); \ + PERM_OP(r,l,tt, 8,0x00ff00ffL); \ + PERM_OP(l,r,tt, 2,0x33333333L); \ + PERM_OP(r,l,tt,16,0x0000ffffL); \ + PERM_OP(l,r,tt, 4,0x0f0f0f0fL); \ + } +#endif diff --git a/sys/crypto/des/des_module.c b/sys/crypto/des/des_module.c new file mode 100644 index 000000000..7906f0e9c --- /dev/null +++ b/sys/crypto/des/des_module.c @@ -0,0 +1,51 @@ +/* $NetBSD: des_module.c,v 1.1 2014/01/01 15:18:57 pgoyette Exp $ */ + +/*- + * Copyright (c) 2014 The NetBSD Foundation, Inc. + * All rights reserved. + * + * This code is derived from software contributed to The NetBSD Foundation + * by Paul Goyette + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the above copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * + * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS + * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED + * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR + * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS + * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR + * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF + * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS + * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN + * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) + * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE + * POSSIBILITY OF SUCH DAMAGE. + */ +#include +__KERNEL_RCSID(0, "$NetBSD: des_module.c,v 1.1 2014/01/01 15:18:57 pgoyette Exp $"); + +#include +#include + +MODULE(MODULE_CLASS_MISC, des, NULL); + +static int +des_modcmd(modcmd_t cmd, void *opaque) +{ + + switch (cmd) { + case MODULE_CMD_INIT: + return 0; + case MODULE_CMD_FINI: + return 0; + default: + return ENOTTY; + } +} diff --git a/sys/crypto/des/des_setkey.c b/sys/crypto/des/des_setkey.c new file mode 100644 index 000000000..f578d2231 --- /dev/null +++ b/sys/crypto/des/des_setkey.c @@ -0,0 +1,240 @@ +/* $NetBSD: des_setkey.c,v 1.10 2005/12/11 12:20:52 christos Exp $ */ +/* $KAME: des_setkey.c,v 1.6 2001/07/03 14:27:53 itojun Exp $ */ + +/* crypto/des/set_key.c */ +/* Copyright (C) 1995-1996 Eric Young (eay@mincom.oz.au) + * All rights reserved. + * + * This file is part of an SSL implementation written + * by Eric Young (eay@mincom.oz.au). + * The implementation was written so as to conform with Netscapes SSL + * specification. This library and applications are + * FREE FOR COMMERCIAL AND NON-COMMERCIAL USE + * as long as the following conditions are aheared to. + * + * Copyright remains Eric Young's, and as such any Copyright notices in + * the code are not to be removed. If this code is used in a product, + * Eric Young should be given attribution as the author of the parts used. + * This can be in the form of a textual message at program startup or + * in documentation (online or textual) provided with the package. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * 3. All advertising materials mentioning features or use of this software + * must display the following acknowledgement: + * This product includes software developed by Eric Young (eay@mincom.oz.au) + * + * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND + * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE + * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE + * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE + * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL + * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS + * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) + * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT + * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY + * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF + * SUCH DAMAGE. + * + * The licence and distribution terms for any publically available version or + * derivative of this code cannot be changed. i.e. this code cannot simply be + * copied and put under another distribution licence + * [including the GNU Public Licence.] + */ + +/* set_key.c v 1.4 eay 24/9/91 + * 1.4 Speed up by 400% :-) + * 1.3 added register declarations. + * 1.2 unrolled make_key_sched a bit more + * 1.1 added norm_expand_bits + * 1.0 First working version + */ + +#include +__KERNEL_RCSID(0, "$NetBSD: des_setkey.c,v 1.10 2005/12/11 12:20:52 christos Exp $"); + +#include +#ifdef _KERNEL +#include +#else +#include +#endif +#include +#include +#include + +int des_check_key=0; + +void des_set_odd_parity(des_cblock *key) +{ + unsigned int i; + + for (i=0; i>(n))^(b))&(m)),\ + * (b)^=(t),\ + * (a)=((a)^((t)<<(n)))) + */ + +#define HPERM_OP(a,t,n,m) ((t)=((((a)<<(16-(n)))^(a))&(m)),\ + (a)=(a)^(t)^(t>>(16-(n)))) + +int des_set_key(des_cblock *key, des_key_schedule schedule) +{ + if (des_check_key) + { + return des_set_key_checked(key, schedule); + } + else + { + des_set_key_unchecked(key, schedule); + return 0; + } +} + +/* return 0 if key parity is odd (correct), + * return -1 if key parity error, + * return -2 if illegal weak key. + */ +int des_set_key_checked(des_cblock *key, des_key_schedule schedule) +{ + if (!des_check_key_parity(key)) + return(-1); + if (des_is_weak_key(key)) + return(-2); + des_set_key_unchecked(key, schedule); + return 0; +} + +void des_set_key_unchecked(des_cblock *key, des_key_schedule schedule) +{ + static int shifts2[16]={0,0,1,1,1,1,1,1,0,1,1,1,1,1,1,0}; + register DES_LONG c,d,t,s,t2; + register const unsigned char *in; + register DES_LONG *k; + register int i; + + k = &schedule->ks.deslong[0]; + in = &(*key)[0]; + + c2l(in,c); + c2l(in,d); + + /* do PC1 in 47 simple operations :-) + * Thanks to John Fletcher (john_fletcher@lccmail.ocf.llnl.gov) + * for the inspiration. :-) */ + PERM_OP (d,c,t,4,0x0f0f0f0fL); + HPERM_OP(c,t,-2,0xcccc0000L); + HPERM_OP(d,t,-2,0xcccc0000L); + PERM_OP (d,c,t,1,0x55555555L); + PERM_OP (c,d,t,8,0x00ff00ffL); + PERM_OP (d,c,t,1,0x55555555L); + d= (((d&0x000000ffL)<<16L)| (d&0x0000ff00L) | + ((d&0x00ff0000L)>>16L)|((c&0xf0000000L)>>4L)); + c&=0x0fffffffL; + + for (i=0; i>2L)|(c<<26L)); d=((d>>2L)|(d<<26L)); } + else + { c=((c>>1L)|(c<<27L)); d=((d>>1L)|(d<<27L)); } + c&=0x0fffffffL; + d&=0x0fffffffL; + /* could be a few less shifts but I am to lazy at this + * point in time to investigate */ + s= des_skb[0][ (c )&0x3f ]| + des_skb[1][((c>> 6L)&0x03)|((c>> 7L)&0x3c)]| + des_skb[2][((c>>13L)&0x0f)|((c>>14L)&0x30)]| + des_skb[3][((c>>20L)&0x01)|((c>>21L)&0x06) | + ((c>>22L)&0x38)]; + t= des_skb[4][ (d )&0x3f ]| + des_skb[5][((d>> 7L)&0x03)|((d>> 8L)&0x3c)]| + des_skb[6][ (d>>15L)&0x3f ]| + des_skb[7][((d>>21L)&0x0f)|((d>>22L)&0x30)]; + + /* table contained 0213 4657 */ + t2=((t<<16L)|(s&0x0000ffffL))&0xffffffffL; + *(k++)=ROTATE(t2,30)&0xffffffffL; + + t2=((s>>16L)|(t&0xffff0000L)); + *(k++)=ROTATE(t2,26)&0xffffffffL; + } +} + +int des_key_sched(des_cblock *key, des_key_schedule schedule) +{ + return(des_set_key(key,schedule)); +} + +void des_fixup_key_parity(des_cblock *key) +{ + des_set_odd_parity(key); +} diff --git a/sys/crypto/des/files.des b/sys/crypto/des/files.des new file mode 100644 index 000000000..2c494406e --- /dev/null +++ b/sys/crypto/des/files.des @@ -0,0 +1,9 @@ +# $NetBSD: files.des,v 1.2 2014/01/01 15:18:57 pgoyette Exp $ + +define des + +file crypto/des/des_module.c des +file crypto/des/des_ecb.c des +file crypto/des/des_setkey.c des +file crypto/des/des_enc.c des +file crypto/des/des_cbc.c des diff --git a/sys/crypto/des/podd.h b/sys/crypto/des/podd.h new file mode 100644 index 000000000..9fe36a128 --- /dev/null +++ b/sys/crypto/des/podd.h @@ -0,0 +1,67 @@ +/* $NetBSD: podd.h,v 1.1.1.1 2000/06/14 19:45:36 thorpej Exp $ */ +/* $KAME: podd.h,v 1.3 2000/03/27 04:36:34 sumikawa Exp $ */ + +/* crypto/des/podd.h */ +/* Copyright (C) 1995-1996 Eric Young (eay@mincom.oz.au) + * All rights reserved. + * + * This file is part of an SSL implementation written + * by Eric Young (eay@mincom.oz.au). + * The implementation was written so as to conform with Netscapes SSL + * specification. This library and applications are + * FREE FOR COMMERCIAL AND NON-COMMERCIAL USE + * as long as the following conditions are aheared to. + * + * Copyright remains Eric Young's, and as such any Copyright notices in + * the code are not to be removed. If this code is used in a product, + * Eric Young should be given attribution as the author of the parts used. + * This can be in the form of a textual message at program startup or + * in documentation (online or textual) provided with the package. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * 3. All advertising materials mentioning features or use of this software + * must display the following acknowledgement: + * This product includes software developed by Eric Young (eay@mincom.oz.au) + * + * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND + * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE + * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE + * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE + * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL + * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS + * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) + * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT + * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY + * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF + * SUCH DAMAGE. + * + * The licence and distribution terms for any publically available version or + * derivative of this code cannot be changed. i.e. this code cannot simply be + * copied and put under another distribution licence + * [including the GNU Public Licence.] + */ + +static const unsigned char odd_parity[256]={ + 1, 1, 2, 2, 4, 4, 7, 7, 8, 8, 11, 11, 13, 13, 14, 14, + 16, 16, 19, 19, 21, 21, 22, 22, 25, 25, 26, 26, 28, 28, 31, 31, + 32, 32, 35, 35, 37, 37, 38, 38, 41, 41, 42, 42, 44, 44, 47, 47, + 49, 49, 50, 50, 52, 52, 55, 55, 56, 56, 59, 59, 61, 61, 62, 62, + 64, 64, 67, 67, 69, 69, 70, 70, 73, 73, 74, 74, 76, 76, 79, 79, + 81, 81, 82, 82, 84, 84, 87, 87, 88, 88, 91, 91, 93, 93, 94, 94, + 97, 97, 98, 98,100,100,103,103,104,104,107,107,109,109,110,110, +112,112,115,115,117,117,118,118,121,121,122,122,124,124,127,127, +128,128,131,131,133,133,134,134,137,137,138,138,140,140,143,143, +145,145,146,146,148,148,151,151,152,152,155,155,157,157,158,158, +161,161,162,162,164,164,167,167,168,168,171,171,173,173,174,174, +176,176,179,179,181,181,182,182,185,185,186,186,188,188,191,191, +193,193,194,194,196,196,199,199,200,200,203,203,205,205,206,206, +208,208,211,211,213,213,214,214,217,217,218,218,220,220,223,223, +224,224,227,227,229,229,230,230,233,233,234,234,236,236,239,239, +241,241,242,242,244,244,247,247,248,248,251,251,253,253,254,254}; diff --git a/sys/crypto/des/sk.h b/sys/crypto/des/sk.h new file mode 100644 index 000000000..a9739e8a4 --- /dev/null +++ b/sys/crypto/des/sk.h @@ -0,0 +1,196 @@ +/* $NetBSD: sk.h,v 1.1.1.1 2000/06/14 19:45:36 thorpej Exp $ */ +/* $KAME: sk.h,v 1.3 2000/03/27 04:36:34 sumikawa Exp $ */ + +/* crypto/des/sk.h */ +/* Copyright (C) 1995-1996 Eric Young (eay@mincom.oz.au) + * All rights reserved. + * + * This file is part of an SSL implementation written + * by Eric Young (eay@mincom.oz.au). + * The implementation was written so as to conform with Netscapes SSL + * specification. This library and applications are + * FREE FOR COMMERCIAL AND NON-COMMERCIAL USE + * as long as the following conditions are aheared to. + * + * Copyright remains Eric Young's, and as such any Copyright notices in + * the code are not to be removed. If this code is used in a product, + * Eric Young should be given attribution as the author of the parts used. + * This can be in the form of a textual message at program startup or + * in documentation (online or textual) provided with the package. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * 3. All advertising materials mentioning features or use of this software + * must display the following acknowledgement: + * This product includes software developed by Eric Young (eay@mincom.oz.au) + * + * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND + * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE + * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE + * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE + * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL + * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS + * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) + * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT + * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY + * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF + * SUCH DAMAGE. + * + * The licence and distribution terms for any publically available version or + * derivative of this code cannot be changed. i.e. this code cannot simply be + * copied and put under another distribution licence + * [including the GNU Public Licence.] + */ + +static const DES_LONG des_skb[8][64]={ +{ +/* for C bits (numbered as per FIPS 46) 1 2 3 4 5 6 */ +0x00000000L,0x00000010L,0x20000000L,0x20000010L, +0x00010000L,0x00010010L,0x20010000L,0x20010010L, +0x00000800L,0x00000810L,0x20000800L,0x20000810L, +0x00010800L,0x00010810L,0x20010800L,0x20010810L, +0x00000020L,0x00000030L,0x20000020L,0x20000030L, +0x00010020L,0x00010030L,0x20010020L,0x20010030L, +0x00000820L,0x00000830L,0x20000820L,0x20000830L, +0x00010820L,0x00010830L,0x20010820L,0x20010830L, +0x00080000L,0x00080010L,0x20080000L,0x20080010L, +0x00090000L,0x00090010L,0x20090000L,0x20090010L, +0x00080800L,0x00080810L,0x20080800L,0x20080810L, +0x00090800L,0x00090810L,0x20090800L,0x20090810L, +0x00080020L,0x00080030L,0x20080020L,0x20080030L, +0x00090020L,0x00090030L,0x20090020L,0x20090030L, +0x00080820L,0x00080830L,0x20080820L,0x20080830L, +0x00090820L,0x00090830L,0x20090820L,0x20090830L, +},{ +/* for C bits (numbered as per FIPS 46) 7 8 10 11 12 13 */ +0x00000000L,0x02000000L,0x00002000L,0x02002000L, +0x00200000L,0x02200000L,0x00202000L,0x02202000L, +0x00000004L,0x02000004L,0x00002004L,0x02002004L, +0x00200004L,0x02200004L,0x00202004L,0x02202004L, +0x00000400L,0x02000400L,0x00002400L,0x02002400L, +0x00200400L,0x02200400L,0x00202400L,0x02202400L, +0x00000404L,0x02000404L,0x00002404L,0x02002404L, +0x00200404L,0x02200404L,0x00202404L,0x02202404L, +0x10000000L,0x12000000L,0x10002000L,0x12002000L, +0x10200000L,0x12200000L,0x10202000L,0x12202000L, +0x10000004L,0x12000004L,0x10002004L,0x12002004L, +0x10200004L,0x12200004L,0x10202004L,0x12202004L, +0x10000400L,0x12000400L,0x10002400L,0x12002400L, +0x10200400L,0x12200400L,0x10202400L,0x12202400L, +0x10000404L,0x12000404L,0x10002404L,0x12002404L, +0x10200404L,0x12200404L,0x10202404L,0x12202404L, +},{ +/* for C bits (numbered as per FIPS 46) 14 15 16 17 19 20 */ +0x00000000L,0x00000001L,0x00040000L,0x00040001L, +0x01000000L,0x01000001L,0x01040000L,0x01040001L, +0x00000002L,0x00000003L,0x00040002L,0x00040003L, +0x01000002L,0x01000003L,0x01040002L,0x01040003L, +0x00000200L,0x00000201L,0x00040200L,0x00040201L, +0x01000200L,0x01000201L,0x01040200L,0x01040201L, +0x00000202L,0x00000203L,0x00040202L,0x00040203L, +0x01000202L,0x01000203L,0x01040202L,0x01040203L, +0x08000000L,0x08000001L,0x08040000L,0x08040001L, +0x09000000L,0x09000001L,0x09040000L,0x09040001L, +0x08000002L,0x08000003L,0x08040002L,0x08040003L, +0x09000002L,0x09000003L,0x09040002L,0x09040003L, +0x08000200L,0x08000201L,0x08040200L,0x08040201L, +0x09000200L,0x09000201L,0x09040200L,0x09040201L, +0x08000202L,0x08000203L,0x08040202L,0x08040203L, +0x09000202L,0x09000203L,0x09040202L,0x09040203L, +},{ +/* for C bits (numbered as per FIPS 46) 21 23 24 26 27 28 */ +0x00000000L,0x00100000L,0x00000100L,0x00100100L, +0x00000008L,0x00100008L,0x00000108L,0x00100108L, +0x00001000L,0x00101000L,0x00001100L,0x00101100L, +0x00001008L,0x00101008L,0x00001108L,0x00101108L, +0x04000000L,0x04100000L,0x04000100L,0x04100100L, +0x04000008L,0x04100008L,0x04000108L,0x04100108L, +0x04001000L,0x04101000L,0x04001100L,0x04101100L, +0x04001008L,0x04101008L,0x04001108L,0x04101108L, +0x00020000L,0x00120000L,0x00020100L,0x00120100L, +0x00020008L,0x00120008L,0x00020108L,0x00120108L, +0x00021000L,0x00121000L,0x00021100L,0x00121100L, +0x00021008L,0x00121008L,0x00021108L,0x00121108L, +0x04020000L,0x04120000L,0x04020100L,0x04120100L, +0x04020008L,0x04120008L,0x04020108L,0x04120108L, +0x04021000L,0x04121000L,0x04021100L,0x04121100L, +0x04021008L,0x04121008L,0x04021108L,0x04121108L, +},{ +/* for D bits (numbered as per FIPS 46) 1 2 3 4 5 6 */ +0x00000000L,0x10000000L,0x00010000L,0x10010000L, +0x00000004L,0x10000004L,0x00010004L,0x10010004L, +0x20000000L,0x30000000L,0x20010000L,0x30010000L, +0x20000004L,0x30000004L,0x20010004L,0x30010004L, +0x00100000L,0x10100000L,0x00110000L,0x10110000L, +0x00100004L,0x10100004L,0x00110004L,0x10110004L, +0x20100000L,0x30100000L,0x20110000L,0x30110000L, +0x20100004L,0x30100004L,0x20110004L,0x30110004L, +0x00001000L,0x10001000L,0x00011000L,0x10011000L, +0x00001004L,0x10001004L,0x00011004L,0x10011004L, +0x20001000L,0x30001000L,0x20011000L,0x30011000L, +0x20001004L,0x30001004L,0x20011004L,0x30011004L, +0x00101000L,0x10101000L,0x00111000L,0x10111000L, +0x00101004L,0x10101004L,0x00111004L,0x10111004L, +0x20101000L,0x30101000L,0x20111000L,0x30111000L, +0x20101004L,0x30101004L,0x20111004L,0x30111004L, +},{ +/* for D bits (numbered as per FIPS 46) 8 9 11 12 13 14 */ +0x00000000L,0x08000000L,0x00000008L,0x08000008L, +0x00000400L,0x08000400L,0x00000408L,0x08000408L, +0x00020000L,0x08020000L,0x00020008L,0x08020008L, +0x00020400L,0x08020400L,0x00020408L,0x08020408L, +0x00000001L,0x08000001L,0x00000009L,0x08000009L, +0x00000401L,0x08000401L,0x00000409L,0x08000409L, +0x00020001L,0x08020001L,0x00020009L,0x08020009L, +0x00020401L,0x08020401L,0x00020409L,0x08020409L, +0x02000000L,0x0A000000L,0x02000008L,0x0A000008L, +0x02000400L,0x0A000400L,0x02000408L,0x0A000408L, +0x02020000L,0x0A020000L,0x02020008L,0x0A020008L, +0x02020400L,0x0A020400L,0x02020408L,0x0A020408L, +0x02000001L,0x0A000001L,0x02000009L,0x0A000009L, +0x02000401L,0x0A000401L,0x02000409L,0x0A000409L, +0x02020001L,0x0A020001L,0x02020009L,0x0A020009L, +0x02020401L,0x0A020401L,0x02020409L,0x0A020409L, +},{ +/* for D bits (numbered as per FIPS 46) 16 17 18 19 20 21 */ +0x00000000L,0x00000100L,0x00080000L,0x00080100L, +0x01000000L,0x01000100L,0x01080000L,0x01080100L, +0x00000010L,0x00000110L,0x00080010L,0x00080110L, +0x01000010L,0x01000110L,0x01080010L,0x01080110L, +0x00200000L,0x00200100L,0x00280000L,0x00280100L, +0x01200000L,0x01200100L,0x01280000L,0x01280100L, +0x00200010L,0x00200110L,0x00280010L,0x00280110L, +0x01200010L,0x01200110L,0x01280010L,0x01280110L, +0x00000200L,0x00000300L,0x00080200L,0x00080300L, +0x01000200L,0x01000300L,0x01080200L,0x01080300L, +0x00000210L,0x00000310L,0x00080210L,0x00080310L, +0x01000210L,0x01000310L,0x01080210L,0x01080310L, +0x00200200L,0x00200300L,0x00280200L,0x00280300L, +0x01200200L,0x01200300L,0x01280200L,0x01280300L, +0x00200210L,0x00200310L,0x00280210L,0x00280310L, +0x01200210L,0x01200310L,0x01280210L,0x01280310L, +},{ +/* for D bits (numbered as per FIPS 46) 22 23 24 25 27 28 */ +0x00000000L,0x04000000L,0x00040000L,0x04040000L, +0x00000002L,0x04000002L,0x00040002L,0x04040002L, +0x00002000L,0x04002000L,0x00042000L,0x04042000L, +0x00002002L,0x04002002L,0x00042002L,0x04042002L, +0x00000020L,0x04000020L,0x00040020L,0x04040020L, +0x00000022L,0x04000022L,0x00040022L,0x04040022L, +0x00002020L,0x04002020L,0x00042020L,0x04042020L, +0x00002022L,0x04002022L,0x00042022L,0x04042022L, +0x00000800L,0x04000800L,0x00040800L,0x04040800L, +0x00000802L,0x04000802L,0x00040802L,0x04040802L, +0x00002800L,0x04002800L,0x00042800L,0x04042800L, +0x00002802L,0x04002802L,0x00042802L,0x04042802L, +0x00000820L,0x04000820L,0x00040820L,0x04040820L, +0x00000822L,0x04000822L,0x00040822L,0x04040822L, +0x00002820L,0x04002820L,0x00042820L,0x04042820L, +0x00002822L,0x04002822L,0x00042822L,0x04042822L, +}}; diff --git a/sys/crypto/des/spr.h b/sys/crypto/des/spr.h new file mode 100644 index 000000000..e0dcca3b0 --- /dev/null +++ b/sys/crypto/des/spr.h @@ -0,0 +1,204 @@ +/* crypto/des/spr.h */ +/* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com) + * All rights reserved. + * + * This package is an SSL implementation written + * by Eric Young (eay@cryptsoft.com). + * The implementation was written so as to conform with Netscapes SSL. + * + * This library is free for commercial and non-commercial use as long as + * the following conditions are aheared to. The following conditions + * apply to all code found in this distribution, be it the RC4, RSA, + * lhash, DES, etc., code; not just the SSL code. The SSL documentation + * included with this distribution is covered by the same copyright terms + * except that the holder is Tim Hudson (tjh@cryptsoft.com). + * + * Copyright remains Eric Young's, and as such any Copyright notices in + * the code are not to be removed. + * If this package is used in a product, Eric Young should be given attribution + * as the author of the parts of the library used. + * This can be in the form of a textual message at program startup or + * in documentation (online or textual) provided with the package. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * 3. All advertising materials mentioning features or use of this software + * must display the following acknowledgement: + * "This product includes cryptographic software written by + * Eric Young (eay@cryptsoft.com)" + * The word 'cryptographic' can be left out if the rouines from the library + * being used are not cryptographic related :-). + * 4. If you include any Windows specific code (or a derivative thereof) from + * the apps directory (application code) you must include an acknowledgement: + * "This product includes software written by Tim Hudson (tjh@cryptsoft.com)" + * + * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND + * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE + * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE + * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE + * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL + * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS + * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) + * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT + * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY + * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF + * SUCH DAMAGE. + * + * The licence and distribution terms for any publically available version or + * derivative of this code cannot be changed. i.e. this code cannot simply be + * copied and put under another distribution licence + * [including the GNU Public Licence.] + */ + +const DES_LONG des_SPtrans[8][64]={ +{ +/* nibble 0 */ +0x02080800L, 0x00080000L, 0x02000002L, 0x02080802L, +0x02000000L, 0x00080802L, 0x00080002L, 0x02000002L, +0x00080802L, 0x02080800L, 0x02080000L, 0x00000802L, +0x02000802L, 0x02000000L, 0x00000000L, 0x00080002L, +0x00080000L, 0x00000002L, 0x02000800L, 0x00080800L, +0x02080802L, 0x02080000L, 0x00000802L, 0x02000800L, +0x00000002L, 0x00000800L, 0x00080800L, 0x02080002L, +0x00000800L, 0x02000802L, 0x02080002L, 0x00000000L, +0x00000000L, 0x02080802L, 0x02000800L, 0x00080002L, +0x02080800L, 0x00080000L, 0x00000802L, 0x02000800L, +0x02080002L, 0x00000800L, 0x00080800L, 0x02000002L, +0x00080802L, 0x00000002L, 0x02000002L, 0x02080000L, +0x02080802L, 0x00080800L, 0x02080000L, 0x02000802L, +0x02000000L, 0x00000802L, 0x00080002L, 0x00000000L, +0x00080000L, 0x02000000L, 0x02000802L, 0x02080800L, +0x00000002L, 0x02080002L, 0x00000800L, 0x00080802L, +},{ +/* nibble 1 */ +0x40108010L, 0x00000000L, 0x00108000L, 0x40100000L, +0x40000010L, 0x00008010L, 0x40008000L, 0x00108000L, +0x00008000L, 0x40100010L, 0x00000010L, 0x40008000L, +0x00100010L, 0x40108000L, 0x40100000L, 0x00000010L, +0x00100000L, 0x40008010L, 0x40100010L, 0x00008000L, +0x00108010L, 0x40000000L, 0x00000000L, 0x00100010L, +0x40008010L, 0x00108010L, 0x40108000L, 0x40000010L, +0x40000000L, 0x00100000L, 0x00008010L, 0x40108010L, +0x00100010L, 0x40108000L, 0x40008000L, 0x00108010L, +0x40108010L, 0x00100010L, 0x40000010L, 0x00000000L, +0x40000000L, 0x00008010L, 0x00100000L, 0x40100010L, +0x00008000L, 0x40000000L, 0x00108010L, 0x40008010L, +0x40108000L, 0x00008000L, 0x00000000L, 0x40000010L, +0x00000010L, 0x40108010L, 0x00108000L, 0x40100000L, +0x40100010L, 0x00100000L, 0x00008010L, 0x40008000L, +0x40008010L, 0x00000010L, 0x40100000L, 0x00108000L, +},{ +/* nibble 2 */ +0x04000001L, 0x04040100L, 0x00000100L, 0x04000101L, +0x00040001L, 0x04000000L, 0x04000101L, 0x00040100L, +0x04000100L, 0x00040000L, 0x04040000L, 0x00000001L, +0x04040101L, 0x00000101L, 0x00000001L, 0x04040001L, +0x00000000L, 0x00040001L, 0x04040100L, 0x00000100L, +0x00000101L, 0x04040101L, 0x00040000L, 0x04000001L, +0x04040001L, 0x04000100L, 0x00040101L, 0x04040000L, +0x00040100L, 0x00000000L, 0x04000000L, 0x00040101L, +0x04040100L, 0x00000100L, 0x00000001L, 0x00040000L, +0x00000101L, 0x00040001L, 0x04040000L, 0x04000101L, +0x00000000L, 0x04040100L, 0x00040100L, 0x04040001L, +0x00040001L, 0x04000000L, 0x04040101L, 0x00000001L, +0x00040101L, 0x04000001L, 0x04000000L, 0x04040101L, +0x00040000L, 0x04000100L, 0x04000101L, 0x00040100L, +0x04000100L, 0x00000000L, 0x04040001L, 0x00000101L, +0x04000001L, 0x00040101L, 0x00000100L, 0x04040000L, +},{ +/* nibble 3 */ +0x00401008L, 0x10001000L, 0x00000008L, 0x10401008L, +0x00000000L, 0x10400000L, 0x10001008L, 0x00400008L, +0x10401000L, 0x10000008L, 0x10000000L, 0x00001008L, +0x10000008L, 0x00401008L, 0x00400000L, 0x10000000L, +0x10400008L, 0x00401000L, 0x00001000L, 0x00000008L, +0x00401000L, 0x10001008L, 0x10400000L, 0x00001000L, +0x00001008L, 0x00000000L, 0x00400008L, 0x10401000L, +0x10001000L, 0x10400008L, 0x10401008L, 0x00400000L, +0x10400008L, 0x00001008L, 0x00400000L, 0x10000008L, +0x00401000L, 0x10001000L, 0x00000008L, 0x10400000L, +0x10001008L, 0x00000000L, 0x00001000L, 0x00400008L, +0x00000000L, 0x10400008L, 0x10401000L, 0x00001000L, +0x10000000L, 0x10401008L, 0x00401008L, 0x00400000L, +0x10401008L, 0x00000008L, 0x10001000L, 0x00401008L, +0x00400008L, 0x00401000L, 0x10400000L, 0x10001008L, +0x00001008L, 0x10000000L, 0x10000008L, 0x10401000L, +},{ +/* nibble 4 */ +0x08000000L, 0x00010000L, 0x00000400L, 0x08010420L, +0x08010020L, 0x08000400L, 0x00010420L, 0x08010000L, +0x00010000L, 0x00000020L, 0x08000020L, 0x00010400L, +0x08000420L, 0x08010020L, 0x08010400L, 0x00000000L, +0x00010400L, 0x08000000L, 0x00010020L, 0x00000420L, +0x08000400L, 0x00010420L, 0x00000000L, 0x08000020L, +0x00000020L, 0x08000420L, 0x08010420L, 0x00010020L, +0x08010000L, 0x00000400L, 0x00000420L, 0x08010400L, +0x08010400L, 0x08000420L, 0x00010020L, 0x08010000L, +0x00010000L, 0x00000020L, 0x08000020L, 0x08000400L, +0x08000000L, 0x00010400L, 0x08010420L, 0x00000000L, +0x00010420L, 0x08000000L, 0x00000400L, 0x00010020L, +0x08000420L, 0x00000400L, 0x00000000L, 0x08010420L, +0x08010020L, 0x08010400L, 0x00000420L, 0x00010000L, +0x00010400L, 0x08010020L, 0x08000400L, 0x00000420L, +0x00000020L, 0x00010420L, 0x08010000L, 0x08000020L, +},{ +/* nibble 5 */ +0x80000040L, 0x00200040L, 0x00000000L, 0x80202000L, +0x00200040L, 0x00002000L, 0x80002040L, 0x00200000L, +0x00002040L, 0x80202040L, 0x00202000L, 0x80000000L, +0x80002000L, 0x80000040L, 0x80200000L, 0x00202040L, +0x00200000L, 0x80002040L, 0x80200040L, 0x00000000L, +0x00002000L, 0x00000040L, 0x80202000L, 0x80200040L, +0x80202040L, 0x80200000L, 0x80000000L, 0x00002040L, +0x00000040L, 0x00202000L, 0x00202040L, 0x80002000L, +0x00002040L, 0x80000000L, 0x80002000L, 0x00202040L, +0x80202000L, 0x00200040L, 0x00000000L, 0x80002000L, +0x80000000L, 0x00002000L, 0x80200040L, 0x00200000L, +0x00200040L, 0x80202040L, 0x00202000L, 0x00000040L, +0x80202040L, 0x00202000L, 0x00200000L, 0x80002040L, +0x80000040L, 0x80200000L, 0x00202040L, 0x00000000L, +0x00002000L, 0x80000040L, 0x80002040L, 0x80202000L, +0x80200000L, 0x00002040L, 0x00000040L, 0x80200040L, +},{ +/* nibble 6 */ +0x00004000L, 0x00000200L, 0x01000200L, 0x01000004L, +0x01004204L, 0x00004004L, 0x00004200L, 0x00000000L, +0x01000000L, 0x01000204L, 0x00000204L, 0x01004000L, +0x00000004L, 0x01004200L, 0x01004000L, 0x00000204L, +0x01000204L, 0x00004000L, 0x00004004L, 0x01004204L, +0x00000000L, 0x01000200L, 0x01000004L, 0x00004200L, +0x01004004L, 0x00004204L, 0x01004200L, 0x00000004L, +0x00004204L, 0x01004004L, 0x00000200L, 0x01000000L, +0x00004204L, 0x01004000L, 0x01004004L, 0x00000204L, +0x00004000L, 0x00000200L, 0x01000000L, 0x01004004L, +0x01000204L, 0x00004204L, 0x00004200L, 0x00000000L, +0x00000200L, 0x01000004L, 0x00000004L, 0x01000200L, +0x00000000L, 0x01000204L, 0x01000200L, 0x00004200L, +0x00000204L, 0x00004000L, 0x01004204L, 0x01000000L, +0x01004200L, 0x00000004L, 0x00004004L, 0x01004204L, +0x01000004L, 0x01004200L, 0x01004000L, 0x00004004L, +},{ +/* nibble 7 */ +0x20800080L, 0x20820000L, 0x00020080L, 0x00000000L, +0x20020000L, 0x00800080L, 0x20800000L, 0x20820080L, +0x00000080L, 0x20000000L, 0x00820000L, 0x00020080L, +0x00820080L, 0x20020080L, 0x20000080L, 0x20800000L, +0x00020000L, 0x00820080L, 0x00800080L, 0x20020000L, +0x20820080L, 0x20000080L, 0x00000000L, 0x00820000L, +0x20000000L, 0x00800000L, 0x20020080L, 0x20800080L, +0x00800000L, 0x00020000L, 0x20820000L, 0x00000080L, +0x00800000L, 0x00020000L, 0x20000080L, 0x20820080L, +0x00020080L, 0x20000000L, 0x00000000L, 0x00820000L, +0x20800080L, 0x20020080L, 0x20020000L, 0x00800080L, +0x20820000L, 0x00000080L, 0x00800080L, 0x20020000L, +0x20820080L, 0x00800000L, 0x20800000L, 0x20000080L, +0x00820000L, 0x00020080L, 0x20020080L, 0x20800000L, +0x00000080L, 0x20820000L, 0x00820080L, 0x00000000L, +0x20000000L, 0x20800080L, 0x00020000L, 0x00820080L, +}}; diff --git a/sys/crypto/skipjack/files.skipjack b/sys/crypto/skipjack/files.skipjack new file mode 100644 index 000000000..d12b8c544 --- /dev/null +++ b/sys/crypto/skipjack/files.skipjack @@ -0,0 +1,5 @@ +# $NetBSD: files.skipjack,v 1.2 2005/12/11 12:20:53 christos Exp $ + +define skipjack + +file crypto/skipjack/skipjack.c skipjack diff --git a/sys/crypto/skipjack/skipjack.c b/sys/crypto/skipjack/skipjack.c new file mode 100644 index 000000000..c1de28c9b --- /dev/null +++ b/sys/crypto/skipjack/skipjack.c @@ -0,0 +1,281 @@ +/* $NetBSD: skipjack.c,v 1.4 2014/01/01 15:18:57 pgoyette Exp $ */ +/* $OpenBSD: skipjack.c,v 1.3 2001/05/05 00:31:34 angelos Exp $ */ + +/* + * Further optimized test implementation of SKIPJACK algorithm + * Mark Tillotson , 25 June 98 + * Optimizations suit RISC (lots of registers) machine best. + * + * based on unoptimized implementation of + * Panu Rissanen 960624 + * + * SKIPJACK and KEA Algorithm Specifications + * Version 2.0 + * 29 May 1998 +*/ + +#include +__KERNEL_RCSID(0, "$NetBSD: skipjack.c,v 1.4 2014/01/01 15:18:57 pgoyette Exp $"); + +#include +#include +#include +#include + +#include +#include + +static const u_int8_t ftable[0x100] = +{ + 0xa3, 0xd7, 0x09, 0x83, 0xf8, 0x48, 0xf6, 0xf4, + 0xb3, 0x21, 0x15, 0x78, 0x99, 0xb1, 0xaf, 0xf9, + 0xe7, 0x2d, 0x4d, 0x8a, 0xce, 0x4c, 0xca, 0x2e, + 0x52, 0x95, 0xd9, 0x1e, 0x4e, 0x38, 0x44, 0x28, + 0x0a, 0xdf, 0x02, 0xa0, 0x17, 0xf1, 0x60, 0x68, + 0x12, 0xb7, 0x7a, 0xc3, 0xe9, 0xfa, 0x3d, 0x53, + 0x96, 0x84, 0x6b, 0xba, 0xf2, 0x63, 0x9a, 0x19, + 0x7c, 0xae, 0xe5, 0xf5, 0xf7, 0x16, 0x6a, 0xa2, + 0x39, 0xb6, 0x7b, 0x0f, 0xc1, 0x93, 0x81, 0x1b, + 0xee, 0xb4, 0x1a, 0xea, 0xd0, 0x91, 0x2f, 0xb8, + 0x55, 0xb9, 0xda, 0x85, 0x3f, 0x41, 0xbf, 0xe0, + 0x5a, 0x58, 0x80, 0x5f, 0x66, 0x0b, 0xd8, 0x90, + 0x35, 0xd5, 0xc0, 0xa7, 0x33, 0x06, 0x65, 0x69, + 0x45, 0x00, 0x94, 0x56, 0x6d, 0x98, 0x9b, 0x76, + 0x97, 0xfc, 0xb2, 0xc2, 0xb0, 0xfe, 0xdb, 0x20, + 0xe1, 0xeb, 0xd6, 0xe4, 0xdd, 0x47, 0x4a, 0x1d, + 0x42, 0xed, 0x9e, 0x6e, 0x49, 0x3c, 0xcd, 0x43, + 0x27, 0xd2, 0x07, 0xd4, 0xde, 0xc7, 0x67, 0x18, + 0x89, 0xcb, 0x30, 0x1f, 0x8d, 0xc6, 0x8f, 0xaa, + 0xc8, 0x74, 0xdc, 0xc9, 0x5d, 0x5c, 0x31, 0xa4, + 0x70, 0x88, 0x61, 0x2c, 0x9f, 0x0d, 0x2b, 0x87, + 0x50, 0x82, 0x54, 0x64, 0x26, 0x7d, 0x03, 0x40, + 0x34, 0x4b, 0x1c, 0x73, 0xd1, 0xc4, 0xfd, 0x3b, + 0xcc, 0xfb, 0x7f, 0xab, 0xe6, 0x3e, 0x5b, 0xa5, + 0xad, 0x04, 0x23, 0x9c, 0x14, 0x51, 0x22, 0xf0, + 0x29, 0x79, 0x71, 0x7e, 0xff, 0x8c, 0x0e, 0xe2, + 0x0c, 0xef, 0xbc, 0x72, 0x75, 0x6f, 0x37, 0xa1, + 0xec, 0xd3, 0x8e, 0x62, 0x8b, 0x86, 0x10, 0xe8, + 0x08, 0x77, 0x11, 0xbe, 0x92, 0x4f, 0x24, 0xc5, + 0x32, 0x36, 0x9d, 0xcf, 0xf3, 0xa6, 0xbb, 0xac, + 0x5e, 0x6c, 0xa9, 0x13, 0x57, 0x25, 0xb5, 0xe3, + 0xbd, 0xa8, 0x3a, 0x01, 0x05, 0x59, 0x2a, 0x46 +}; + +/* + * For each key byte generate a table to represent the function + * ftable [in ^ keybyte] + * + * These tables used to save an XOR in each stage of the G-function + * the tables are hopefully pointed to by register allocated variables + * k0, k1..k9 + */ +void +subkey_table_gen (const u_int8_t *key, u_int8_t **key_tables) +{ + int i, k; + + for (k = 0; k < 10; k++) { + u_int8_t key_byte = key [k]; + u_int8_t * table = key_tables[k]; + for (i = 0; i < 0x100; i++) + table [i] = ftable [i ^ key_byte]; + } +} + + +#define g(k0, k1, k2, k3, ih, il, oh, ol) \ +{ \ + oh = k##k0 [il] ^ ih; \ + ol = k##k1 [oh] ^ il; \ + oh = k##k2 [ol] ^ oh; \ + ol = k##k3 [oh] ^ ol; \ +} + +#define g0(ih, il, oh, ol) g(0, 1, 2, 3, ih, il, oh, ol) +#define g4(ih, il, oh, ol) g(4, 5, 6, 7, ih, il, oh, ol) +#define g8(ih, il, oh, ol) g(8, 9, 0, 1, ih, il, oh, ol) +#define g2(ih, il, oh, ol) g(2, 3, 4, 5, ih, il, oh, ol) +#define g6(ih, il, oh, ol) g(6, 7, 8, 9, ih, il, oh, ol) + + +#define g_inv(k0, k1, k2, k3, ih, il, oh, ol) \ +{ \ + ol = k##k3 [ih] ^ il; \ + oh = k##k2 [ol] ^ ih; \ + ol = k##k1 [oh] ^ ol; \ + oh = k##k0 [ol] ^ oh; \ +} + + +#define g0_inv(ih, il, oh, ol) g_inv(0, 1, 2, 3, ih, il, oh, ol) +#define g4_inv(ih, il, oh, ol) g_inv(4, 5, 6, 7, ih, il, oh, ol) +#define g8_inv(ih, il, oh, ol) g_inv(8, 9, 0, 1, ih, il, oh, ol) +#define g2_inv(ih, il, oh, ol) g_inv(2, 3, 4, 5, ih, il, oh, ol) +#define g6_inv(ih, il, oh, ol) g_inv(6, 7, 8, 9, ih, il, oh, ol) + +/* optimized version of Skipjack algorithm + * + * the appropriate g-function is inlined for each round + * + * the data movement is minimized by rotating the names of the + * variables w1..w4, not their contents (saves 3 moves per round) + * + * the loops are completely unrolled (needed to staticize choice of g) + * + * compiles to about 470 instructions on a Sparc (gcc -O) + * which is about 58 instructions per byte, 14 per round. + * gcc seems to leave in some unnecessary and with 0xFF operations + * but only in the latter part of the functions. Perhaps it + * runs out of resources to properly optimize long inlined function? + * in theory should get about 11 instructions per round, not 14 + */ + +void +skipjack_forwards(u_int8_t *plain, u_int8_t *cipher, u_int8_t **key_tables) +{ + u_int8_t wh1 = plain[0]; u_int8_t wl1 = plain[1]; + u_int8_t wh2 = plain[2]; u_int8_t wl2 = plain[3]; + u_int8_t wh3 = plain[4]; u_int8_t wl3 = plain[5]; + u_int8_t wh4 = plain[6]; u_int8_t wl4 = plain[7]; + + u_int8_t * k0 = key_tables [0]; + u_int8_t * k1 = key_tables [1]; + u_int8_t * k2 = key_tables [2]; + u_int8_t * k3 = key_tables [3]; + u_int8_t * k4 = key_tables [4]; + u_int8_t * k5 = key_tables [5]; + u_int8_t * k6 = key_tables [6]; + u_int8_t * k7 = key_tables [7]; + u_int8_t * k8 = key_tables [8]; + u_int8_t * k9 = key_tables [9]; + + /* first 8 rounds */ + g0 (wh1,wl1, wh1,wl1); wl4 ^= wl1 ^ 1; wh4 ^= wh1; + g4 (wh4,wl4, wh4,wl4); wl3 ^= wl4 ^ 2; wh3 ^= wh4; + g8 (wh3,wl3, wh3,wl3); wl2 ^= wl3 ^ 3; wh2 ^= wh3; + g2 (wh2,wl2, wh2,wl2); wl1 ^= wl2 ^ 4; wh1 ^= wh2; + g6 (wh1,wl1, wh1,wl1); wl4 ^= wl1 ^ 5; wh4 ^= wh1; + g0 (wh4,wl4, wh4,wl4); wl3 ^= wl4 ^ 6; wh3 ^= wh4; + g4 (wh3,wl3, wh3,wl3); wl2 ^= wl3 ^ 7; wh2 ^= wh3; + g8 (wh2,wl2, wh2,wl2); wl1 ^= wl2 ^ 8; wh1 ^= wh2; + + /* second 8 rounds */ + wh2 ^= wh1; wl2 ^= wl1 ^ 9 ; g2 (wh1,wl1, wh1,wl1); + wh1 ^= wh4; wl1 ^= wl4 ^ 10; g6 (wh4,wl4, wh4,wl4); + wh4 ^= wh3; wl4 ^= wl3 ^ 11; g0 (wh3,wl3, wh3,wl3); + wh3 ^= wh2; wl3 ^= wl2 ^ 12; g4 (wh2,wl2, wh2,wl2); + wh2 ^= wh1; wl2 ^= wl1 ^ 13; g8 (wh1,wl1, wh1,wl1); + wh1 ^= wh4; wl1 ^= wl4 ^ 14; g2 (wh4,wl4, wh4,wl4); + wh4 ^= wh3; wl4 ^= wl3 ^ 15; g6 (wh3,wl3, wh3,wl3); + wh3 ^= wh2; wl3 ^= wl2 ^ 16; g0 (wh2,wl2, wh2,wl2); + + /* third 8 rounds */ + g4 (wh1,wl1, wh1,wl1); wl4 ^= wl1 ^ 17; wh4 ^= wh1; + g8 (wh4,wl4, wh4,wl4); wl3 ^= wl4 ^ 18; wh3 ^= wh4; + g2 (wh3,wl3, wh3,wl3); wl2 ^= wl3 ^ 19; wh2 ^= wh3; + g6 (wh2,wl2, wh2,wl2); wl1 ^= wl2 ^ 20; wh1 ^= wh2; + g0 (wh1,wl1, wh1,wl1); wl4 ^= wl1 ^ 21; wh4 ^= wh1; + g4 (wh4,wl4, wh4,wl4); wl3 ^= wl4 ^ 22; wh3 ^= wh4; + g8 (wh3,wl3, wh3,wl3); wl2 ^= wl3 ^ 23; wh2 ^= wh3; + g2 (wh2,wl2, wh2,wl2); wl1 ^= wl2 ^ 24; wh1 ^= wh2; + + /* last 8 rounds */ + wh2 ^= wh1; wl2 ^= wl1 ^ 25; g6 (wh1,wl1, wh1,wl1); + wh1 ^= wh4; wl1 ^= wl4 ^ 26; g0 (wh4,wl4, wh4,wl4); + wh4 ^= wh3; wl4 ^= wl3 ^ 27; g4 (wh3,wl3, wh3,wl3); + wh3 ^= wh2; wl3 ^= wl2 ^ 28; g8 (wh2,wl2, wh2,wl2); + wh2 ^= wh1; wl2 ^= wl1 ^ 29; g2 (wh1,wl1, wh1,wl1); + wh1 ^= wh4; wl1 ^= wl4 ^ 30; g6 (wh4,wl4, wh4,wl4); + wh4 ^= wh3; wl4 ^= wl3 ^ 31; g0 (wh3,wl3, wh3,wl3); + wh3 ^= wh2; wl3 ^= wl2 ^ 32; g4 (wh2,wl2, wh2,wl2); + + /* pack into byte vector */ + cipher [0] = wh1; cipher [1] = wl1; + cipher [2] = wh2; cipher [3] = wl2; + cipher [4] = wh3; cipher [5] = wl3; + cipher [6] = wh4; cipher [7] = wl4; +} + + +void +skipjack_backwards (u_int8_t *cipher, u_int8_t *plain, u_int8_t **key_tables) +{ + /* setup 4 16-bit portions */ + u_int8_t wh1 = cipher[0]; u_int8_t wl1 = cipher[1]; + u_int8_t wh2 = cipher[2]; u_int8_t wl2 = cipher[3]; + u_int8_t wh3 = cipher[4]; u_int8_t wl3 = cipher[5]; + u_int8_t wh4 = cipher[6]; u_int8_t wl4 = cipher[7]; + + u_int8_t * k0 = key_tables [0]; + u_int8_t * k1 = key_tables [1]; + u_int8_t * k2 = key_tables [2]; + u_int8_t * k3 = key_tables [3]; + u_int8_t * k4 = key_tables [4]; + u_int8_t * k5 = key_tables [5]; + u_int8_t * k6 = key_tables [6]; + u_int8_t * k7 = key_tables [7]; + u_int8_t * k8 = key_tables [8]; + u_int8_t * k9 = key_tables [9]; + + /* first 8 rounds */ + g4_inv (wh2,wl2, wh2,wl2); wl3 ^= wl2 ^ 32; wh3 ^= wh2; + g0_inv (wh3,wl3, wh3,wl3); wl4 ^= wl3 ^ 31; wh4 ^= wh3; + g6_inv (wh4,wl4, wh4,wl4); wl1 ^= wl4 ^ 30; wh1 ^= wh4; + g2_inv (wh1,wl1, wh1,wl1); wl2 ^= wl1 ^ 29; wh2 ^= wh1; + g8_inv (wh2,wl2, wh2,wl2); wl3 ^= wl2 ^ 28; wh3 ^= wh2; + g4_inv (wh3,wl3, wh3,wl3); wl4 ^= wl3 ^ 27; wh4 ^= wh3; + g0_inv (wh4,wl4, wh4,wl4); wl1 ^= wl4 ^ 26; wh1 ^= wh4; + g6_inv (wh1,wl1, wh1,wl1); wl2 ^= wl1 ^ 25; wh2 ^= wh1; + + /* second 8 rounds */ + wh1 ^= wh2; wl1 ^= wl2 ^ 24; g2_inv (wh2,wl2, wh2,wl2); + wh2 ^= wh3; wl2 ^= wl3 ^ 23; g8_inv (wh3,wl3, wh3,wl3); + wh3 ^= wh4; wl3 ^= wl4 ^ 22; g4_inv (wh4,wl4, wh4,wl4); + wh4 ^= wh1; wl4 ^= wl1 ^ 21; g0_inv (wh1,wl1, wh1,wl1); + wh1 ^= wh2; wl1 ^= wl2 ^ 20; g6_inv (wh2,wl2, wh2,wl2); + wh2 ^= wh3; wl2 ^= wl3 ^ 19; g2_inv (wh3,wl3, wh3,wl3); + wh3 ^= wh4; wl3 ^= wl4 ^ 18; g8_inv (wh4,wl4, wh4,wl4); + wh4 ^= wh1; wl4 ^= wl1 ^ 17; g4_inv (wh1,wl1, wh1,wl1); + + /* third 8 rounds */ + g0_inv (wh2,wl2, wh2,wl2); wl3 ^= wl2 ^ 16; wh3 ^= wh2; + g6_inv (wh3,wl3, wh3,wl3); wl4 ^= wl3 ^ 15; wh4 ^= wh3; + g2_inv (wh4,wl4, wh4,wl4); wl1 ^= wl4 ^ 14; wh1 ^= wh4; + g8_inv (wh1,wl1, wh1,wl1); wl2 ^= wl1 ^ 13; wh2 ^= wh1; + g4_inv (wh2,wl2, wh2,wl2); wl3 ^= wl2 ^ 12; wh3 ^= wh2; + g0_inv (wh3,wl3, wh3,wl3); wl4 ^= wl3 ^ 11; wh4 ^= wh3; + g6_inv (wh4,wl4, wh4,wl4); wl1 ^= wl4 ^ 10; wh1 ^= wh4; + g2_inv (wh1,wl1, wh1,wl1); wl2 ^= wl1 ^ 9; wh2 ^= wh1; + + /* last 8 rounds */ + wh1 ^= wh2; wl1 ^= wl2 ^ 8; g8_inv (wh2,wl2, wh2,wl2); + wh2 ^= wh3; wl2 ^= wl3 ^ 7; g4_inv (wh3,wl3, wh3,wl3); + wh3 ^= wh4; wl3 ^= wl4 ^ 6; g0_inv (wh4,wl4, wh4,wl4); + wh4 ^= wh1; wl4 ^= wl1 ^ 5; g6_inv (wh1,wl1, wh1,wl1); + wh1 ^= wh2; wl1 ^= wl2 ^ 4; g2_inv (wh2,wl2, wh2,wl2); + wh2 ^= wh3; wl2 ^= wl3 ^ 3; g8_inv (wh3,wl3, wh3,wl3); + wh3 ^= wh4; wl3 ^= wl4 ^ 2; g4_inv (wh4,wl4, wh4,wl4); + wh4 ^= wh1; wl4 ^= wl1 ^ 1; g0_inv (wh1,wl1, wh1,wl1); + + /* pack into byte vector */ + plain [0] = wh1; plain [1] = wl1; + plain [2] = wh2; plain [3] = wl2; + plain [4] = wh3; plain [5] = wl3; + plain [6] = wh4; plain [7] = wl4; +} + +MODULE(MODULE_CLASS_MISC, skipjack, NULL); + +static int +skipjack_modcmd(modcmd_t cmd, void *opaque) +{ + + switch (cmd) { + case MODULE_CMD_INIT: + return 0; + case MODULE_CMD_FINI: + return 0; + default: + return ENOTTY; + } +} diff --git a/sys/crypto/skipjack/skipjack.h b/sys/crypto/skipjack/skipjack.h new file mode 100644 index 000000000..a25cfc5ee --- /dev/null +++ b/sys/crypto/skipjack/skipjack.h @@ -0,0 +1,19 @@ +/* $NetBSD: skipjack.h,v 1.3 2005/12/11 12:20:53 christos Exp $ */ +/* $OpenBSD: skipjack.h,v 1.3 2002/03/14 01:26:51 millert Exp $ */ + +/* + * Further optimized test implementation of SKIPJACK algorithm + * Mark Tillotson , 25 June 98 + * Optimizations suit RISC (lots of registers) machine best. + * + * based on unoptimized implementation of + * Panu Rissanen 960624 + * + * SKIPJACK and KEA Algorithm Specifications + * Version 2.0 + * 29 May 1998 +*/ + +extern void skipjack_forwards(u_int8_t *plain, u_int8_t *cipher, u_int8_t **key); +extern void skipjack_backwards(u_int8_t *cipher, u_int8_t *plain, u_int8_t **key); +extern void subkey_table_gen(const u_int8_t *key, u_int8_t **key_tables); diff --git a/sys/opencrypto/Makefile b/sys/opencrypto/Makefile new file mode 100644 index 000000000..1abb439d8 --- /dev/null +++ b/sys/opencrypto/Makefile @@ -0,0 +1,11 @@ +# $NetBSD: Makefile,v 1.3 2005/12/11 12:25:20 christos Exp $ + +# Install userland OpenCrypto Framework (OCF) headers in /usr/include/crypto, +# to keep our userland API (openssl, apache, ...) compatible with the +# original OpenBSD API. + +INCSDIR=/usr/include/crypto + +INCS= cryptodev.h + +.include diff --git a/sys/opencrypto/aesxcbcmac.c b/sys/opencrypto/aesxcbcmac.c new file mode 100644 index 000000000..9ed0a3397 --- /dev/null +++ b/sys/opencrypto/aesxcbcmac.c @@ -0,0 +1,141 @@ +/* $NetBSD: aesxcbcmac.c,v 1.1 2011/05/24 19:10:08 drochner Exp $ */ + +/* + * Copyright (C) 1995, 1996, 1997, 1998 and 2003 WIDE Project. + * All rights reserved. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the above copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * 3. Neither the name of the project nor the names of its contributors + * may be used to endorse or promote products derived from this software + * without specific prior written permission. + * + * THIS SOFTWARE IS PROVIDED BY THE PROJECT AND CONTRIBUTORS ``AS IS'' AND + * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE + * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE + * ARE DISCLAIMED. IN NO EVENT SHALL THE PROJECT OR CONTRIBUTORS BE LIABLE + * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL + * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS + * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) + * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT + * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY + * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF + * SUCH DAMAGE. + */ + +#include +__KERNEL_RCSID(0, "$NetBSD: aesxcbcmac.c,v 1.1 2011/05/24 19:10:08 drochner Exp $"); + +#include +#include +#include + +#include + +int +aes_xcbc_mac_init(void *vctx, const u_int8_t *key, u_int16_t keylen) +{ + u_int8_t k1seed[AES_BLOCKSIZE] = { 1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1 }; + u_int8_t k2seed[AES_BLOCKSIZE] = { 2,2,2,2,2,2,2,2,2,2,2,2,2,2,2,2 }; + u_int8_t k3seed[AES_BLOCKSIZE] = { 3,3,3,3,3,3,3,3,3,3,3,3,3,3,3,3 }; + u_int32_t r_ks[(RIJNDAEL_MAXNR+1)*4]; + aesxcbc_ctx *ctx; + u_int8_t k1[AES_BLOCKSIZE]; + + ctx = (aesxcbc_ctx *)vctx; + memset(ctx, 0, sizeof(aesxcbc_ctx)); + + if ((ctx->r_nr = rijndaelKeySetupEnc(r_ks, key, keylen * 8)) == 0) + return -1; + rijndaelEncrypt(r_ks, ctx->r_nr, k1seed, k1); + rijndaelEncrypt(r_ks, ctx->r_nr, k2seed, ctx->k2); + rijndaelEncrypt(r_ks, ctx->r_nr, k3seed, ctx->k3); + if (rijndaelKeySetupEnc(ctx->r_k1s, k1, AES_BLOCKSIZE * 8) == 0) + return -1; + if (rijndaelKeySetupEnc(ctx->r_k2s, ctx->k2, AES_BLOCKSIZE * 8) == 0) + return -1; + if (rijndaelKeySetupEnc(ctx->r_k3s, ctx->k3, AES_BLOCKSIZE * 8) == 0) + return -1; + + return 0; +} + +int +aes_xcbc_mac_loop(void *vctx, const u_int8_t *addr, u_int16_t len) +{ + u_int8_t buf[AES_BLOCKSIZE]; + aesxcbc_ctx *ctx; + const u_int8_t *ep; + int i; + + ctx = (aesxcbc_ctx *)vctx; + ep = addr + len; + + if (ctx->buflen == sizeof(ctx->buf)) { + for (i = 0; i < sizeof(ctx->e); i++) + ctx->buf[i] ^= ctx->e[i]; + rijndaelEncrypt(ctx->r_k1s, ctx->r_nr, ctx->buf, ctx->e); + ctx->buflen = 0; + } + if (ctx->buflen + len < sizeof(ctx->buf)) { + memcpy(ctx->buf + ctx->buflen, addr, len); + ctx->buflen += len; + return 0; + } + if (ctx->buflen && ctx->buflen + len > sizeof(ctx->buf)) { + memcpy(ctx->buf + ctx->buflen, addr, + sizeof(ctx->buf) - ctx->buflen); + for (i = 0; i < sizeof(ctx->e); i++) + ctx->buf[i] ^= ctx->e[i]; + rijndaelEncrypt(ctx->r_k1s, ctx->r_nr, ctx->buf, ctx->e); + addr += sizeof(ctx->buf) - ctx->buflen; + ctx->buflen = 0; + } + /* due to the special processing for M[n], "=" case is not included */ + while (addr + AES_BLOCKSIZE < ep) { + memcpy(buf, addr, AES_BLOCKSIZE); + for (i = 0; i < sizeof(buf); i++) + buf[i] ^= ctx->e[i]; + rijndaelEncrypt(ctx->r_k1s, ctx->r_nr, buf, ctx->e); + addr += AES_BLOCKSIZE; + } + if (addr < ep) { + memcpy(ctx->buf + ctx->buflen, addr, ep - addr); + ctx->buflen += ep - addr; + } + return 0; +} + +void +aes_xcbc_mac_result(u_int8_t *addr, void *vctx) +{ + u_char digest[AES_BLOCKSIZE]; + aesxcbc_ctx *ctx; + int i; + + ctx = (aesxcbc_ctx *)vctx; + + if (ctx->buflen == sizeof(ctx->buf)) { + for (i = 0; i < sizeof(ctx->buf); i++) { + ctx->buf[i] ^= ctx->e[i]; + ctx->buf[i] ^= ctx->k2[i]; + } + rijndaelEncrypt(ctx->r_k1s, ctx->r_nr, ctx->buf, digest); + } else { + for (i = ctx->buflen; i < sizeof(ctx->buf); i++) + ctx->buf[i] = (i == ctx->buflen) ? 0x80 : 0x00; + for (i = 0; i < sizeof(ctx->buf); i++) { + ctx->buf[i] ^= ctx->e[i]; + ctx->buf[i] ^= ctx->k3[i]; + } + rijndaelEncrypt(ctx->r_k1s, ctx->r_nr, ctx->buf, digest); + } + + memcpy(addr, digest, sizeof(digest)); +} diff --git a/sys/opencrypto/aesxcbcmac.h b/sys/opencrypto/aesxcbcmac.h new file mode 100644 index 000000000..a06fe142a --- /dev/null +++ b/sys/opencrypto/aesxcbcmac.h @@ -0,0 +1,21 @@ +/* $NetBSD: aesxcbcmac.h,v 1.1 2011/05/24 19:10:09 drochner Exp $ */ + +#include + +#define AES_BLOCKSIZE 16 + +typedef struct { + u_int8_t e[AES_BLOCKSIZE]; + u_int8_t buf[AES_BLOCKSIZE]; + size_t buflen; + u_int32_t r_k1s[(RIJNDAEL_MAXNR+1)*4]; + u_int32_t r_k2s[(RIJNDAEL_MAXNR+1)*4]; + u_int32_t r_k3s[(RIJNDAEL_MAXNR+1)*4]; + int r_nr; /* key-length-dependent number of rounds */ + u_int8_t k2[AES_BLOCKSIZE]; + u_int8_t k3[AES_BLOCKSIZE]; +} aesxcbc_ctx; + +int aes_xcbc_mac_init(void *, const u_int8_t *, u_int16_t); +int aes_xcbc_mac_loop(void *, const u_int8_t *, u_int16_t); +void aes_xcbc_mac_result(u_int8_t *, void *); diff --git a/sys/opencrypto/criov.c b/sys/opencrypto/criov.c new file mode 100644 index 000000000..cf82448fa --- /dev/null +++ b/sys/opencrypto/criov.c @@ -0,0 +1,189 @@ +/* $NetBSD: criov.c,v 1.8 2011/02/24 19:28:03 drochner Exp $ */ +/* $OpenBSD: criov.c,v 1.11 2002/06/10 19:36:43 espie Exp $ */ + +/* + * Copyright (c) 1999 Theo de Raadt + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * + * 1. Redistributions of source code must retain the above copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * 3. The name of the author may not be used to endorse or promote products + * derived from this software without specific prior written permission. + * + * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR + * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES + * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. + * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, + * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT + * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, + * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY + * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT + * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF + * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + */ + +#include +__KERNEL_RCSID(0, "$NetBSD: criov.c,v 1.8 2011/02/24 19:28:03 drochner Exp $"); + +#include +#include +#include +#include +#include +#include +#include + +#include + +#include +int cuio_getindx(struct uio *uio, int loc, int *off); + + +void +cuio_copydata(struct uio *uio, int off, int len, void *cp) +{ + struct iovec *iov = uio->uio_iov; + int iol = uio->uio_iovcnt; + unsigned count; + + if (off < 0) + panic("cuio_copydata: off %d < 0", off); + if (len < 0) + panic("cuio_copydata: len %d < 0", len); + while (off > 0) { + if (iol == 0) + panic("iov_copydata: empty in skip"); + if (off < iov->iov_len) + break; + off -= iov->iov_len; + iol--; + iov++; + } + while (len > 0) { + if (iol == 0) + panic("cuio_copydata: empty"); + count = min(iov->iov_len - off, len); + memcpy(cp, (char *)iov->iov_base + off, count); + len -= count; + cp = (char *)cp + count; + off = 0; + iol--; + iov++; + } +} + +void +cuio_copyback(struct uio *uio, int off, int len, void *cp) +{ + struct iovec *iov = uio->uio_iov; + int iol = uio->uio_iovcnt; + unsigned count; + + if (off < 0) + panic("cuio_copyback: off %d < 0", off); + if (len < 0) + panic("cuio_copyback: len %d < 0", len); + while (off > 0) { + if (iol == 0) { +#ifdef DEBUG + printf("cuio_copyback: empty in skip\n"); +#endif + return; + } + if (off < iov->iov_len) + break; + off -= iov->iov_len; + iol--; + iov++; + } + while (len > 0) { + if (iol == 0) { +#ifdef DEBUG + printf("uio_copyback: empty\n"); +#endif + return; + } + count = min(iov->iov_len - off, len); + memcpy((char *)iov->iov_base + off, cp, count); + len -= count; + cp = (char *)cp + count; + off = 0; + iol--; + iov++; + } +} + +/* + * Return a pointer to iov/offset of location in iovec list. + */ + +int +cuio_getptr(struct uio *uio, int loc, int *off) +{ + int ind, len; + + ind = 0; + while (loc >= 0 && ind < uio->uio_iovcnt) { + len = uio->uio_iov[ind].iov_len; + if (len > loc) { + *off = loc; + return (ind); + } + loc -= len; + ind++; + } + + if (ind > 0 && loc == 0) { + ind--; + *off = uio->uio_iov[ind].iov_len; + return (ind); + } + + return (-1); +} + +int +cuio_apply(struct uio *uio, int off, int len, + int (*f)(void *, void *, unsigned int), void *fstate) +{ + int rval, ind, uiolen; + unsigned int count; + + if (len < 0) + panic("%s: len %d < 0", __func__, len); + if (off < 0) + panic("%s: off %d < 0", __func__, off); + + ind = 0; + while (off > 0) { + if (ind >= uio->uio_iovcnt) + panic("cuio_apply: out of ivecs before data in uio"); + uiolen = uio->uio_iov[ind].iov_len; + if (off < uiolen) + break; + off -= uiolen; + ind++; + } + while (len > 0) { + if (ind >= uio->uio_iovcnt) + panic("cuio_apply: out of ivecs when processing uio"); + count = min(uio->uio_iov[ind].iov_len - off, len); + + rval = f(fstate, + ((char *)uio->uio_iov[ind].iov_base + off), count); + if (rval) + return (rval); + + len -= count; + off = 0; + ind++; + } + + return (0); +} diff --git a/sys/opencrypto/crypto.c b/sys/opencrypto/crypto.c new file mode 100644 index 000000000..d056726de --- /dev/null +++ b/sys/opencrypto/crypto.c @@ -0,0 +1,1363 @@ +/* $NetBSD: crypto.c,v 1.45 2014/02/25 18:30:12 pooka Exp $ */ +/* $FreeBSD: src/sys/opencrypto/crypto.c,v 1.4.2.5 2003/02/26 00:14:05 sam Exp $ */ +/* $OpenBSD: crypto.c,v 1.41 2002/07/17 23:52:38 art Exp $ */ + +/*- + * Copyright (c) 2008 The NetBSD Foundation, Inc. + * All rights reserved. + * + * This code is derived from software contributed to The NetBSD Foundation + * by Coyote Point Systems, Inc. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the above copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * + * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS + * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED + * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR + * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS + * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR + * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF + * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS + * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN + * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) + * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE + * POSSIBILITY OF SUCH DAMAGE. + */ + +/* + * The author of this code is Angelos D. Keromytis (angelos@cis.upenn.edu) + * + * This code was written by Angelos D. Keromytis in Athens, Greece, in + * February 2000. Network Security Technologies Inc. (NSTI) kindly + * supported the development of this code. + * + * Copyright (c) 2000, 2001 Angelos D. Keromytis + * + * Permission to use, copy, and modify this software with or without fee + * is hereby granted, provided that this entire notice is included in + * all source code copies of any software which is or includes a copy or + * modification of this software. + * + * THIS SOFTWARE IS BEING PROVIDED "AS IS", WITHOUT ANY EXPRESS OR + * IMPLIED WARRANTY. IN PARTICULAR, NONE OF THE AUTHORS MAKES ANY + * REPRESENTATION OR WARRANTY OF ANY KIND CONCERNING THE + * MERCHANTABILITY OF THIS SOFTWARE OR ITS FITNESS FOR ANY PARTICULAR + * PURPOSE. + */ + +#include +__KERNEL_RCSID(0, "$NetBSD: crypto.c,v 1.45 2014/02/25 18:30:12 pooka Exp $"); + +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include + +#if defined(_KERNEL_OPT) +#include "opt_ocf.h" +#endif + +#include +#include /* XXX for M_XDATA */ + +kmutex_t crypto_q_mtx; +kmutex_t crypto_ret_q_mtx; +kcondvar_t cryptoret_cv; +kmutex_t crypto_mtx; + +/* below are kludges for residual code wrtitten to FreeBSD interfaces */ + #define SWI_CRYPTO 17 + #define register_swi(lvl, fn) \ + softint_establish(SOFTINT_NET|SOFTINT_MPSAFE, (void (*)(void *))fn, NULL) + #define unregister_swi(lvl, fn) softint_disestablish(softintr_cookie) + #define setsoftcrypto(x) softint_schedule(x) + +int crypto_ret_q_check(struct cryptop *); + +/* + * Crypto drivers register themselves by allocating a slot in the + * crypto_drivers table with crypto_get_driverid() and then registering + * each algorithm they support with crypto_register() and crypto_kregister(). + */ +static struct cryptocap *crypto_drivers; +static int crypto_drivers_num; +static void *softintr_cookie; + +/* + * There are two queues for crypto requests; one for symmetric (e.g. + * cipher) operations and one for asymmetric (e.g. MOD) operations. + * See below for how synchronization is handled. + */ +static TAILQ_HEAD(,cryptop) crp_q = /* request queues */ + TAILQ_HEAD_INITIALIZER(crp_q); +static TAILQ_HEAD(,cryptkop) crp_kq = + TAILQ_HEAD_INITIALIZER(crp_kq); + +/* + * There are two queues for processing completed crypto requests; one + * for the symmetric and one for the asymmetric ops. We only need one + * but have two to avoid type futzing (cryptop vs. cryptkop). See below + * for how synchronization is handled. + */ +static TAILQ_HEAD(crprethead, cryptop) crp_ret_q = /* callback queues */ + TAILQ_HEAD_INITIALIZER(crp_ret_q); +static TAILQ_HEAD(krprethead, cryptkop) crp_ret_kq = + TAILQ_HEAD_INITIALIZER(crp_ret_kq); + +/* + * XXX these functions are ghastly hacks for when the submission + * XXX routines discover a request that was not CBIMM is already + * XXX done, and must be yanked from the retq (where _done) put it + * XXX as cryptoret won't get the chance. The queue is walked backwards + * XXX as the request is generally the last one queued. + * + * call with the lock held, or else. + */ +int +crypto_ret_q_remove(struct cryptop *crp) +{ + struct cryptop * acrp, *next; + + TAILQ_FOREACH_REVERSE_SAFE(acrp, &crp_ret_q, crprethead, crp_next, next) { + if (acrp == crp) { + TAILQ_REMOVE(&crp_ret_q, crp, crp_next); + crp->crp_flags &= (~CRYPTO_F_ONRETQ); + return 1; + } + } + return 0; +} + +int +crypto_ret_kq_remove(struct cryptkop *krp) +{ + struct cryptkop * akrp, *next; + + TAILQ_FOREACH_REVERSE_SAFE(akrp, &crp_ret_kq, krprethead, krp_next, next) { + if (akrp == krp) { + TAILQ_REMOVE(&crp_ret_kq, krp, krp_next); + krp->krp_flags &= (~CRYPTO_F_ONRETQ); + return 1; + } + } + return 0; +} + +/* + * Crypto op and desciptor data structures are allocated + * from separate private zones(FreeBSD)/pools(netBSD/OpenBSD) . + */ +struct pool cryptop_pool; +struct pool cryptodesc_pool; +struct pool cryptkop_pool; + +int crypto_usercrypto = 1; /* userland may open /dev/crypto */ +int crypto_userasymcrypto = 1; /* userland may do asym crypto reqs */ +/* + * cryptodevallowsoft is (intended to be) sysctl'able, controlling + * access to hardware versus software transforms as below: + * + * crypto_devallowsoft < 0: Force userlevel requests to use software + * transforms, always + * crypto_devallowsoft = 0: Use hardware if present, grant userlevel + * requests for non-accelerated transforms + * (handling the latter in software) + * crypto_devallowsoft > 0: Allow user requests only for transforms which + * are hardware-accelerated. + */ +int crypto_devallowsoft = 1; /* only use hardware crypto */ + +SYSCTL_SETUP(sysctl_opencrypto_setup, "sysctl opencrypto subtree setup") +{ + + sysctl_createv(clog, 0, NULL, NULL, + CTLFLAG_PERMANENT|CTLFLAG_READWRITE, + CTLTYPE_INT, "usercrypto", + SYSCTL_DESCR("Enable/disable user-mode access to " + "crypto support"), + NULL, 0, &crypto_usercrypto, 0, + CTL_KERN, CTL_CREATE, CTL_EOL); + sysctl_createv(clog, 0, NULL, NULL, + CTLFLAG_PERMANENT|CTLFLAG_READWRITE, + CTLTYPE_INT, "userasymcrypto", + SYSCTL_DESCR("Enable/disable user-mode access to " + "asymmetric crypto support"), + NULL, 0, &crypto_userasymcrypto, 0, + CTL_KERN, CTL_CREATE, CTL_EOL); + sysctl_createv(clog, 0, NULL, NULL, + CTLFLAG_PERMANENT|CTLFLAG_READWRITE, + CTLTYPE_INT, "cryptodevallowsoft", + SYSCTL_DESCR("Enable/disable use of software " + "asymmetric crypto support"), + NULL, 0, &crypto_devallowsoft, 0, + CTL_KERN, CTL_CREATE, CTL_EOL); +} + +MALLOC_DEFINE(M_CRYPTO_DATA, "crypto", "crypto session records"); + +/* + * Synchronization: read carefully, this is non-trivial. + * + * Crypto requests are submitted via crypto_dispatch. Typically + * these come in from network protocols at spl0 (output path) or + * spl[,soft]net (input path). + * + * Requests are typically passed on the driver directly, but they + * may also be queued for processing by a software interrupt thread, + * cryptointr, that runs at splsoftcrypto. This thread dispatches + * the requests to crypto drivers (h/w or s/w) who call crypto_done + * when a request is complete. Hardware crypto drivers are assumed + * to register their IRQ's as network devices so their interrupt handlers + * and subsequent "done callbacks" happen at spl[imp,net]. + * + * Completed crypto ops are queued for a separate kernel thread that + * handles the callbacks at spl0. This decoupling insures the crypto + * driver interrupt service routine is not delayed while the callback + * takes place and that callbacks are delivered after a context switch + * (as opposed to a software interrupt that clients must block). + * + * This scheme is not intended for SMP machines. + */ +static void cryptointr(void); /* swi thread to dispatch ops */ +static void cryptoret(void); /* kernel thread for callbacks*/ +static struct lwp *cryptothread; +static void crypto_destroy(void); +static int crypto_invoke(struct cryptop *crp, int hint); +static int crypto_kinvoke(struct cryptkop *krp, int hint); + +static struct cryptostats cryptostats; +#ifdef CRYPTO_TIMING +static int crypto_timing = 0; +#endif + +#ifdef _MODULE + static struct sysctllog *sysctl_opencrypto_clog; +#endif + +static int +crypto_init0(void) +{ + int error; + + mutex_init(&crypto_mtx, MUTEX_DEFAULT, IPL_NONE); + mutex_init(&crypto_q_mtx, MUTEX_DEFAULT, IPL_NET); + mutex_init(&crypto_ret_q_mtx, MUTEX_DEFAULT, IPL_NET); + cv_init(&cryptoret_cv, "crypto_w"); + pool_init(&cryptop_pool, sizeof(struct cryptop), 0, 0, + 0, "cryptop", NULL, IPL_NET); + pool_init(&cryptodesc_pool, sizeof(struct cryptodesc), 0, 0, + 0, "cryptodesc", NULL, IPL_NET); + pool_init(&cryptkop_pool, sizeof(struct cryptkop), 0, 0, + 0, "cryptkop", NULL, IPL_NET); + + crypto_drivers = malloc(CRYPTO_DRIVERS_INITIAL * + sizeof(struct cryptocap), M_CRYPTO_DATA, M_NOWAIT | M_ZERO); + if (crypto_drivers == NULL) { + printf("crypto_init: cannot malloc driver table\n"); + return 0; + } + crypto_drivers_num = CRYPTO_DRIVERS_INITIAL; + + softintr_cookie = register_swi(SWI_CRYPTO, cryptointr); + error = kthread_create(PRI_NONE, KTHREAD_MPSAFE, NULL, + (void (*)(void *))cryptoret, NULL, &cryptothread, "cryptoret"); + if (error) { + printf("crypto_init: cannot start cryptoret thread; error %d", + error); + crypto_destroy(); + } + +#ifdef _MODULE + sysctl_opencrypto_setup(&sysctl_opencrypto_clog); +#endif + return 0; +} + +void +crypto_init(void) +{ + static ONCE_DECL(crypto_init_once); + + RUN_ONCE(&crypto_init_once, crypto_init0); +} + +static void +crypto_destroy(void) +{ + /* XXX no wait to reclaim zones */ + if (crypto_drivers != NULL) + free(crypto_drivers, M_CRYPTO_DATA); + unregister_swi(SWI_CRYPTO, cryptointr); +} + +/* + * Create a new session. Must be called with crypto_mtx held. + */ +int +crypto_newsession(u_int64_t *sid, struct cryptoini *cri, int hard) +{ + struct cryptoini *cr; + u_int32_t hid, lid; + int err = EINVAL; + + mutex_enter(&crypto_mtx); + + if (crypto_drivers == NULL) + goto done; + + /* + * The algorithm we use here is pretty stupid; just use the + * first driver that supports all the algorithms we need. + * + * XXX We need more smarts here (in real life too, but that's + * XXX another story altogether). + */ + + for (hid = 0; hid < crypto_drivers_num; hid++) { + /* + * If it's not initialized or has remaining sessions + * referencing it, skip. + */ + if (crypto_drivers[hid].cc_newsession == NULL || + (crypto_drivers[hid].cc_flags & CRYPTOCAP_F_CLEANUP)) + continue; + + /* Hardware required -- ignore software drivers. */ + if (hard > 0 && + (crypto_drivers[hid].cc_flags & CRYPTOCAP_F_SOFTWARE)) + continue; + /* Software required -- ignore hardware drivers. */ + if (hard < 0 && + (crypto_drivers[hid].cc_flags & CRYPTOCAP_F_SOFTWARE) == 0) + continue; + + /* See if all the algorithms are supported. */ + for (cr = cri; cr; cr = cr->cri_next) + if (crypto_drivers[hid].cc_alg[cr->cri_alg] == 0) { + DPRINTF(("crypto_newsession: alg %d not supported\n", cr->cri_alg)); + break; + } + + if (cr == NULL) { + /* Ok, all algorithms are supported. */ + + /* + * Can't do everything in one session. + * + * XXX Fix this. We need to inject a "virtual" session layer right + * XXX about here. + */ + + /* Call the driver initialization routine. */ + lid = hid; /* Pass the driver ID. */ + err = crypto_drivers[hid].cc_newsession( + crypto_drivers[hid].cc_arg, &lid, cri); + if (err == 0) { + (*sid) = hid; + (*sid) <<= 32; + (*sid) |= (lid & 0xffffffff); + crypto_drivers[hid].cc_sessions++; + } + goto done; + /*break;*/ + } + } +done: + mutex_exit(&crypto_mtx); + return err; +} + +/* + * Delete an existing session (or a reserved session on an unregistered + * driver). Must be called with crypto_mtx mutex held. + */ +int +crypto_freesession(u_int64_t sid) +{ + u_int32_t hid; + int err = 0; + + mutex_enter(&crypto_mtx); + + if (crypto_drivers == NULL) { + err = EINVAL; + goto done; + } + + /* Determine two IDs. */ + hid = CRYPTO_SESID2HID(sid); + + if (hid >= crypto_drivers_num) { + err = ENOENT; + goto done; + } + + if (crypto_drivers[hid].cc_sessions) + crypto_drivers[hid].cc_sessions--; + + /* Call the driver cleanup routine, if available. */ + if (crypto_drivers[hid].cc_freesession) { + err = crypto_drivers[hid].cc_freesession( + crypto_drivers[hid].cc_arg, sid); + } + else + err = 0; + + /* + * If this was the last session of a driver marked as invalid, + * make the entry available for reuse. + */ + if ((crypto_drivers[hid].cc_flags & CRYPTOCAP_F_CLEANUP) && + crypto_drivers[hid].cc_sessions == 0) + memset(&crypto_drivers[hid], 0, sizeof(struct cryptocap)); + +done: + mutex_exit(&crypto_mtx); + return err; +} + +/* + * Return an unused driver id. Used by drivers prior to registering + * support for the algorithms they handle. + */ +int32_t +crypto_get_driverid(u_int32_t flags) +{ + struct cryptocap *newdrv; + int i; + + crypto_init(); /* XXX oh, this is foul! */ + + mutex_enter(&crypto_mtx); + for (i = 0; i < crypto_drivers_num; i++) + if (crypto_drivers[i].cc_process == NULL && + (crypto_drivers[i].cc_flags & CRYPTOCAP_F_CLEANUP) == 0 && + crypto_drivers[i].cc_sessions == 0) + break; + + /* Out of entries, allocate some more. */ + if (i == crypto_drivers_num) { + /* Be careful about wrap-around. */ + if (2 * crypto_drivers_num <= crypto_drivers_num) { + mutex_exit(&crypto_mtx); + printf("crypto: driver count wraparound!\n"); + return -1; + } + + newdrv = malloc(2 * crypto_drivers_num * + sizeof(struct cryptocap), M_CRYPTO_DATA, M_NOWAIT|M_ZERO); + if (newdrv == NULL) { + mutex_exit(&crypto_mtx); + printf("crypto: no space to expand driver table!\n"); + return -1; + } + + memcpy(newdrv, crypto_drivers, + crypto_drivers_num * sizeof(struct cryptocap)); + + crypto_drivers_num *= 2; + + free(crypto_drivers, M_CRYPTO_DATA); + crypto_drivers = newdrv; + } + + /* NB: state is zero'd on free */ + crypto_drivers[i].cc_sessions = 1; /* Mark */ + crypto_drivers[i].cc_flags = flags; + + if (bootverbose) + printf("crypto: assign driver %u, flags %u\n", i, flags); + + mutex_exit(&crypto_mtx); + + return i; +} + +static struct cryptocap * +crypto_checkdriver(u_int32_t hid) +{ + if (crypto_drivers == NULL) + return NULL; + return (hid >= crypto_drivers_num ? NULL : &crypto_drivers[hid]); +} + +/* + * Register support for a key-related algorithm. This routine + * is called once for each algorithm supported a driver. + */ +int +crypto_kregister(u_int32_t driverid, int kalg, u_int32_t flags, + int (*kprocess)(void *, struct cryptkop *, int), + void *karg) +{ + struct cryptocap *cap; + int err; + + mutex_enter(&crypto_mtx); + + cap = crypto_checkdriver(driverid); + if (cap != NULL && + (CRK_ALGORITM_MIN <= kalg && kalg <= CRK_ALGORITHM_MAX)) { + /* + * XXX Do some performance testing to determine placing. + * XXX We probably need an auxiliary data structure that + * XXX describes relative performances. + */ + + cap->cc_kalg[kalg] = flags | CRYPTO_ALG_FLAG_SUPPORTED; + if (bootverbose) { + printf("crypto: driver %u registers key alg %u " + " flags %u\n", + driverid, + kalg, + flags + ); + } + + if (cap->cc_kprocess == NULL) { + cap->cc_karg = karg; + cap->cc_kprocess = kprocess; + } + err = 0; + } else + err = EINVAL; + + mutex_exit(&crypto_mtx); + return err; +} + +/* + * Register support for a non-key-related algorithm. This routine + * is called once for each such algorithm supported by a driver. + */ +int +crypto_register(u_int32_t driverid, int alg, u_int16_t maxoplen, + u_int32_t flags, + int (*newses)(void *, u_int32_t*, struct cryptoini*), + int (*freeses)(void *, u_int64_t), + int (*process)(void *, struct cryptop *, int), + void *arg) +{ + struct cryptocap *cap; + int err; + + mutex_enter(&crypto_mtx); + + cap = crypto_checkdriver(driverid); + /* NB: algorithms are in the range [1..max] */ + if (cap != NULL && + (CRYPTO_ALGORITHM_MIN <= alg && alg <= CRYPTO_ALGORITHM_MAX)) { + /* + * XXX Do some performance testing to determine placing. + * XXX We probably need an auxiliary data structure that + * XXX describes relative performances. + */ + + cap->cc_alg[alg] = flags | CRYPTO_ALG_FLAG_SUPPORTED; + cap->cc_max_op_len[alg] = maxoplen; + if (bootverbose) { + printf("crypto: driver %u registers alg %u " + "flags %u maxoplen %u\n", + driverid, + alg, + flags, + maxoplen + ); + } + + if (cap->cc_process == NULL) { + cap->cc_arg = arg; + cap->cc_newsession = newses; + cap->cc_process = process; + cap->cc_freesession = freeses; + cap->cc_sessions = 0; /* Unmark */ + } + err = 0; + } else + err = EINVAL; + + mutex_exit(&crypto_mtx); + return err; +} + +/* + * Unregister a crypto driver. If there are pending sessions using it, + * leave enough information around so that subsequent calls using those + * sessions will correctly detect the driver has been unregistered and + * reroute requests. + */ +int +crypto_unregister(u_int32_t driverid, int alg) +{ + int i, err; + u_int32_t ses; + struct cryptocap *cap; + + mutex_enter(&crypto_mtx); + + cap = crypto_checkdriver(driverid); + if (cap != NULL && + (CRYPTO_ALGORITHM_MIN <= alg && alg <= CRYPTO_ALGORITHM_MAX) && + cap->cc_alg[alg] != 0) { + cap->cc_alg[alg] = 0; + cap->cc_max_op_len[alg] = 0; + + /* Was this the last algorithm ? */ + for (i = 1; i <= CRYPTO_ALGORITHM_MAX; i++) + if (cap->cc_alg[i] != 0) + break; + + if (i == CRYPTO_ALGORITHM_MAX + 1) { + ses = cap->cc_sessions; + memset(cap, 0, sizeof(struct cryptocap)); + if (ses != 0) { + /* + * If there are pending sessions, just mark as invalid. + */ + cap->cc_flags |= CRYPTOCAP_F_CLEANUP; + cap->cc_sessions = ses; + } + } + err = 0; + } else + err = EINVAL; + + mutex_exit(&crypto_mtx); + return err; +} + +/* + * Unregister all algorithms associated with a crypto driver. + * If there are pending sessions using it, leave enough information + * around so that subsequent calls using those sessions will + * correctly detect the driver has been unregistered and reroute + * requests. + * + * XXX careful. Don't change this to call crypto_unregister() for each + * XXX registered algorithm unless you drop the mutex across the calls; + * XXX you can't take it recursively. + */ +int +crypto_unregister_all(u_int32_t driverid) +{ + int i, err; + u_int32_t ses; + struct cryptocap *cap; + + mutex_enter(&crypto_mtx); + cap = crypto_checkdriver(driverid); + if (cap != NULL) { + for (i = CRYPTO_ALGORITHM_MIN; i <= CRYPTO_ALGORITHM_MAX; i++) { + cap->cc_alg[i] = 0; + cap->cc_max_op_len[i] = 0; + } + ses = cap->cc_sessions; + memset(cap, 0, sizeof(struct cryptocap)); + if (ses != 0) { + /* + * If there are pending sessions, just mark as invalid. + */ + cap->cc_flags |= CRYPTOCAP_F_CLEANUP; + cap->cc_sessions = ses; + } + err = 0; + } else + err = EINVAL; + + mutex_exit(&crypto_mtx); + return err; +} + +/* + * Clear blockage on a driver. The what parameter indicates whether + * the driver is now ready for cryptop's and/or cryptokop's. + */ +int +crypto_unblock(u_int32_t driverid, int what) +{ + struct cryptocap *cap; + int needwakeup, err; + + mutex_spin_enter(&crypto_q_mtx); + cap = crypto_checkdriver(driverid); + if (cap != NULL) { + needwakeup = 0; + if (what & CRYPTO_SYMQ) { + needwakeup |= cap->cc_qblocked; + cap->cc_qblocked = 0; + } + if (what & CRYPTO_ASYMQ) { + needwakeup |= cap->cc_kqblocked; + cap->cc_kqblocked = 0; + } + err = 0; + if (needwakeup) + setsoftcrypto(softintr_cookie); + mutex_spin_exit(&crypto_q_mtx); + } else { + err = EINVAL; + mutex_spin_exit(&crypto_q_mtx); + } + + return err; +} + +/* + * Dispatch a crypto request to a driver or queue + * it, to be processed by the kernel thread. + */ +int +crypto_dispatch(struct cryptop *crp) +{ + u_int32_t hid = CRYPTO_SESID2HID(crp->crp_sid); + int result; + + mutex_spin_enter(&crypto_q_mtx); + DPRINTF(("crypto_dispatch: crp %p, alg %d\n", + crp, crp->crp_desc->crd_alg)); + + cryptostats.cs_ops++; + +#ifdef CRYPTO_TIMING + if (crypto_timing) + nanouptime(&crp->crp_tstamp); +#endif + if ((crp->crp_flags & CRYPTO_F_BATCH) == 0) { + struct cryptocap *cap; + /* + * Caller marked the request to be processed + * immediately; dispatch it directly to the + * driver unless the driver is currently blocked. + */ + cap = crypto_checkdriver(hid); + if (cap && !cap->cc_qblocked) { + mutex_spin_exit(&crypto_q_mtx); + result = crypto_invoke(crp, 0); + if (result == ERESTART) { + /* + * The driver ran out of resources, mark the + * driver ``blocked'' for cryptop's and put + * the op on the queue. + */ + mutex_spin_enter(&crypto_q_mtx); + crypto_drivers[hid].cc_qblocked = 1; + TAILQ_INSERT_HEAD(&crp_q, crp, crp_next); + cryptostats.cs_blocks++; + mutex_spin_exit(&crypto_q_mtx); + } + goto out_released; + } else { + /* + * The driver is blocked, just queue the op until + * it unblocks and the swi thread gets kicked. + */ + TAILQ_INSERT_TAIL(&crp_q, crp, crp_next); + result = 0; + } + } else { + int wasempty = TAILQ_EMPTY(&crp_q); + /* + * Caller marked the request as ``ok to delay''; + * queue it for the swi thread. This is desirable + * when the operation is low priority and/or suitable + * for batching. + */ + TAILQ_INSERT_TAIL(&crp_q, crp, crp_next); + if (wasempty) { + setsoftcrypto(softintr_cookie); + mutex_spin_exit(&crypto_q_mtx); + result = 0; + goto out_released; + } + + result = 0; + } + + mutex_spin_exit(&crypto_q_mtx); +out_released: + return result; +} + +/* + * Add an asymetric crypto request to a queue, + * to be processed by the kernel thread. + */ +int +crypto_kdispatch(struct cryptkop *krp) +{ + struct cryptocap *cap; + int result; + + mutex_spin_enter(&crypto_q_mtx); + cryptostats.cs_kops++; + + cap = crypto_checkdriver(krp->krp_hid); + if (cap && !cap->cc_kqblocked) { + mutex_spin_exit(&crypto_q_mtx); + result = crypto_kinvoke(krp, 0); + if (result == ERESTART) { + /* + * The driver ran out of resources, mark the + * driver ``blocked'' for cryptop's and put + * the op on the queue. + */ + mutex_spin_enter(&crypto_q_mtx); + crypto_drivers[krp->krp_hid].cc_kqblocked = 1; + TAILQ_INSERT_HEAD(&crp_kq, krp, krp_next); + cryptostats.cs_kblocks++; + mutex_spin_exit(&crypto_q_mtx); + } + } else { + /* + * The driver is blocked, just queue the op until + * it unblocks and the swi thread gets kicked. + */ + TAILQ_INSERT_TAIL(&crp_kq, krp, krp_next); + result = 0; + mutex_spin_exit(&crypto_q_mtx); + } + + return result; +} + +/* + * Dispatch an assymetric crypto request to the appropriate crypto devices. + */ +static int +crypto_kinvoke(struct cryptkop *krp, int hint) +{ + u_int32_t hid; + int error; + + /* Sanity checks. */ + if (krp == NULL) + return EINVAL; + if (krp->krp_callback == NULL) { + cv_destroy(&krp->krp_cv); + pool_put(&cryptkop_pool, krp); + return EINVAL; + } + + mutex_enter(&crypto_mtx); + for (hid = 0; hid < crypto_drivers_num; hid++) { + if ((crypto_drivers[hid].cc_flags & CRYPTOCAP_F_SOFTWARE) && + crypto_devallowsoft == 0) + continue; + if (crypto_drivers[hid].cc_kprocess == NULL) + continue; + if ((crypto_drivers[hid].cc_kalg[krp->krp_op] & + CRYPTO_ALG_FLAG_SUPPORTED) == 0) + continue; + break; + } + if (hid < crypto_drivers_num) { + int (*process)(void *, struct cryptkop *, int); + void *arg; + + process = crypto_drivers[hid].cc_kprocess; + arg = crypto_drivers[hid].cc_karg; + mutex_exit(&crypto_mtx); + krp->krp_hid = hid; + error = (*process)(arg, krp, hint); + } else { + mutex_exit(&crypto_mtx); + error = ENODEV; + } + + if (error) { + krp->krp_status = error; + crypto_kdone(krp); + } + return 0; +} + +#ifdef CRYPTO_TIMING +static void +crypto_tstat(struct cryptotstat *ts, struct timespec *tv) +{ + struct timespec now, t; + + nanouptime(&now); + t.tv_sec = now.tv_sec - tv->tv_sec; + t.tv_nsec = now.tv_nsec - tv->tv_nsec; + if (t.tv_nsec < 0) { + t.tv_sec--; + t.tv_nsec += 1000000000; + } + timespecadd(&ts->acc, &t, &t); + if (timespeccmp(&t, &ts->min, <)) + ts->min = t; + if (timespeccmp(&t, &ts->max, >)) + ts->max = t; + ts->count++; + + *tv = now; +} +#endif + +/* + * Dispatch a crypto request to the appropriate crypto devices. + */ +static int +crypto_invoke(struct cryptop *crp, int hint) +{ + u_int32_t hid; + +#ifdef CRYPTO_TIMING + if (crypto_timing) + crypto_tstat(&cryptostats.cs_invoke, &crp->crp_tstamp); +#endif + /* Sanity checks. */ + if (crp == NULL) + return EINVAL; + if (crp->crp_callback == NULL) { + return EINVAL; + } + if (crp->crp_desc == NULL) { + crp->crp_etype = EINVAL; + crypto_done(crp); + return 0; + } + + hid = CRYPTO_SESID2HID(crp->crp_sid); + + if (hid < crypto_drivers_num) { + int (*process)(void *, struct cryptop *, int); + void *arg; + + if (crypto_drivers[hid].cc_flags & CRYPTOCAP_F_CLEANUP) { + mutex_exit(&crypto_mtx); + crypto_freesession(crp->crp_sid); + mutex_enter(&crypto_mtx); + } + process = crypto_drivers[hid].cc_process; + arg = crypto_drivers[hid].cc_arg; + + /* + * Invoke the driver to process the request. + */ + DPRINTF(("calling process for %p\n", crp)); + return (*process)(arg, crp, hint); + } else { + struct cryptodesc *crd; + u_int64_t nid = 0; + + /* + * Driver has unregistered; migrate the session and return + * an error to the caller so they'll resubmit the op. + */ + for (crd = crp->crp_desc; crd->crd_next; crd = crd->crd_next) + crd->CRD_INI.cri_next = &(crd->crd_next->CRD_INI); + + if (crypto_newsession(&nid, &(crp->crp_desc->CRD_INI), 0) == 0) + crp->crp_sid = nid; + + crp->crp_etype = EAGAIN; + + crypto_done(crp); + return 0; + } +} + +/* + * Release a set of crypto descriptors. + */ +void +crypto_freereq(struct cryptop *crp) +{ + struct cryptodesc *crd; + + if (crp == NULL) + return; + DPRINTF(("crypto_freereq[%u]: crp %p\n", + CRYPTO_SESID2LID(crp->crp_sid), crp)); + + /* sanity check */ + if (crp->crp_flags & CRYPTO_F_ONRETQ) { + panic("crypto_freereq() freeing crp on RETQ\n"); + } + + while ((crd = crp->crp_desc) != NULL) { + crp->crp_desc = crd->crd_next; + pool_put(&cryptodesc_pool, crd); + } + pool_put(&cryptop_pool, crp); +} + +/* + * Acquire a set of crypto descriptors. + */ +struct cryptop * +crypto_getreq(int num) +{ + struct cryptodesc *crd; + struct cryptop *crp; + + crp = pool_get(&cryptop_pool, 0); + if (crp == NULL) { + return NULL; + } + memset(crp, 0, sizeof(struct cryptop)); + + while (num--) { + crd = pool_get(&cryptodesc_pool, 0); + if (crd == NULL) { + crypto_freereq(crp); + return NULL; + } + + memset(crd, 0, sizeof(struct cryptodesc)); + crd->crd_next = crp->crp_desc; + crp->crp_desc = crd; + } + + return crp; +} + +/* + * Invoke the callback on behalf of the driver. + */ +void +crypto_done(struct cryptop *crp) +{ + int wasempty; + + if (crp->crp_etype != 0) + cryptostats.cs_errs++; +#ifdef CRYPTO_TIMING + if (crypto_timing) + crypto_tstat(&cryptostats.cs_done, &crp->crp_tstamp); +#endif + DPRINTF(("crypto_done[%u]: crp %p\n", + CRYPTO_SESID2LID(crp->crp_sid), crp)); + + /* + * Normal case; queue the callback for the thread. + * + * The return queue is manipulated by the swi thread + * and, potentially, by crypto device drivers calling + * back to mark operations completed. Thus we need + * to mask both while manipulating the return queue. + */ + if (crp->crp_flags & CRYPTO_F_CBIMM) { + /* + * Do the callback directly. This is ok when the + * callback routine does very little (e.g. the + * /dev/crypto callback method just does a wakeup). + */ + mutex_spin_enter(&crypto_ret_q_mtx); + crp->crp_flags |= CRYPTO_F_DONE; + mutex_spin_exit(&crypto_ret_q_mtx); + +#ifdef CRYPTO_TIMING + if (crypto_timing) { + /* + * NB: We must copy the timestamp before + * doing the callback as the cryptop is + * likely to be reclaimed. + */ + struct timespec t = crp->crp_tstamp; + crypto_tstat(&cryptostats.cs_cb, &t); + crp->crp_callback(crp); + crypto_tstat(&cryptostats.cs_finis, &t); + } else +#endif + crp->crp_callback(crp); + } else { + mutex_spin_enter(&crypto_ret_q_mtx); + crp->crp_flags |= CRYPTO_F_DONE; + + if (crp->crp_flags & CRYPTO_F_USER) { + /* the request has completed while + * running in the user context + * so don't queue it - the user + * thread won't sleep when it sees + * the CRYPTO_F_DONE flag. + * This is an optimization to avoid + * unecessary context switches. + */ + DPRINTF(("crypto_done[%u]: crp %p CRYPTO_F_USER\n", + CRYPTO_SESID2LID(crp->crp_sid), crp)); + } else { + wasempty = TAILQ_EMPTY(&crp_ret_q); + DPRINTF(("crypto_done[%u]: queueing %p\n", + CRYPTO_SESID2LID(crp->crp_sid), crp)); + crp->crp_flags |= CRYPTO_F_ONRETQ; + TAILQ_INSERT_TAIL(&crp_ret_q, crp, crp_next); + if (wasempty) { + DPRINTF(("crypto_done[%u]: waking cryptoret, " + "crp %p hit empty queue\n.", + CRYPTO_SESID2LID(crp->crp_sid), crp)); + cv_signal(&cryptoret_cv); + } + } + mutex_spin_exit(&crypto_ret_q_mtx); + } +} + +/* + * Invoke the callback on behalf of the driver. + */ +void +crypto_kdone(struct cryptkop *krp) +{ + int wasempty; + + if (krp->krp_status != 0) + cryptostats.cs_kerrs++; + + krp->krp_flags |= CRYPTO_F_DONE; + + /* + * The return queue is manipulated by the swi thread + * and, potentially, by crypto device drivers calling + * back to mark operations completed. Thus we need + * to mask both while manipulating the return queue. + */ + if (krp->krp_flags & CRYPTO_F_CBIMM) { + krp->krp_callback(krp); + } else { + mutex_spin_enter(&crypto_ret_q_mtx); + wasempty = TAILQ_EMPTY(&crp_ret_kq); + krp->krp_flags |= CRYPTO_F_ONRETQ; + TAILQ_INSERT_TAIL(&crp_ret_kq, krp, krp_next); + if (wasempty) + cv_signal(&cryptoret_cv); + mutex_spin_exit(&crypto_ret_q_mtx); + } +} + +int +crypto_getfeat(int *featp) +{ + int hid, kalg, feat = 0; + + mutex_enter(&crypto_mtx); + + if (crypto_userasymcrypto == 0) + goto out; + + for (hid = 0; hid < crypto_drivers_num; hid++) { + if ((crypto_drivers[hid].cc_flags & CRYPTOCAP_F_SOFTWARE) && + crypto_devallowsoft == 0) { + continue; + } + if (crypto_drivers[hid].cc_kprocess == NULL) + continue; + for (kalg = 0; kalg < CRK_ALGORITHM_MAX; kalg++) + if ((crypto_drivers[hid].cc_kalg[kalg] & + CRYPTO_ALG_FLAG_SUPPORTED) != 0) + feat |= 1 << kalg; + } +out: + mutex_exit(&crypto_mtx); + *featp = feat; + return (0); +} + +/* + * Software interrupt thread to dispatch crypto requests. + */ +static void +cryptointr(void) +{ + struct cryptop *crp, *submit, *cnext; + struct cryptkop *krp, *knext; + struct cryptocap *cap; + int result, hint; + + cryptostats.cs_intrs++; + mutex_spin_enter(&crypto_q_mtx); + do { + /* + * Find the first element in the queue that can be + * processed and look-ahead to see if multiple ops + * are ready for the same driver. + */ + submit = NULL; + hint = 0; + TAILQ_FOREACH_SAFE(crp, &crp_q, crp_next, cnext) { + u_int32_t hid = CRYPTO_SESID2HID(crp->crp_sid); + cap = crypto_checkdriver(hid); + if (cap == NULL || cap->cc_process == NULL) { + /* Op needs to be migrated, process it. */ + if (submit == NULL) + submit = crp; + break; + } + if (!cap->cc_qblocked) { + if (submit != NULL) { + /* + * We stop on finding another op, + * regardless whether its for the same + * driver or not. We could keep + * searching the queue but it might be + * better to just use a per-driver + * queue instead. + */ + if (CRYPTO_SESID2HID(submit->crp_sid) + == hid) + hint = CRYPTO_HINT_MORE; + break; + } else { + submit = crp; + if ((submit->crp_flags & CRYPTO_F_BATCH) == 0) + break; + /* keep scanning for more are q'd */ + } + } + } + if (submit != NULL) { + TAILQ_REMOVE(&crp_q, submit, crp_next); + mutex_spin_exit(&crypto_q_mtx); + result = crypto_invoke(submit, hint); + /* we must take here as the TAILQ op or kinvoke + may need this mutex below. sigh. */ + mutex_spin_enter(&crypto_q_mtx); + if (result == ERESTART) { + /* + * The driver ran out of resources, mark the + * driver ``blocked'' for cryptop's and put + * the request back in the queue. It would + * best to put the request back where we got + * it but that's hard so for now we put it + * at the front. This should be ok; putting + * it at the end does not work. + */ + /* XXX validate sid again? */ + crypto_drivers[CRYPTO_SESID2HID(submit->crp_sid)].cc_qblocked = 1; + TAILQ_INSERT_HEAD(&crp_q, submit, crp_next); + cryptostats.cs_blocks++; + } + } + + /* As above, but for key ops */ + TAILQ_FOREACH_SAFE(krp, &crp_kq, krp_next, knext) { + cap = crypto_checkdriver(krp->krp_hid); + if (cap == NULL || cap->cc_kprocess == NULL) { + /* Op needs to be migrated, process it. */ + break; + } + if (!cap->cc_kqblocked) + break; + } + if (krp != NULL) { + TAILQ_REMOVE(&crp_kq, krp, krp_next); + mutex_spin_exit(&crypto_q_mtx); + result = crypto_kinvoke(krp, 0); + /* the next iteration will want the mutex. :-/ */ + mutex_spin_enter(&crypto_q_mtx); + if (result == ERESTART) { + /* + * The driver ran out of resources, mark the + * driver ``blocked'' for cryptkop's and put + * the request back in the queue. It would + * best to put the request back where we got + * it but that's hard so for now we put it + * at the front. This should be ok; putting + * it at the end does not work. + */ + /* XXX validate sid again? */ + crypto_drivers[krp->krp_hid].cc_kqblocked = 1; + TAILQ_INSERT_HEAD(&crp_kq, krp, krp_next); + cryptostats.cs_kblocks++; + } + } + } while (submit != NULL || krp != NULL); + mutex_spin_exit(&crypto_q_mtx); +} + +/* + * Kernel thread to do callbacks. + */ +static void +cryptoret(void) +{ + struct cryptop *crp; + struct cryptkop *krp; + + mutex_spin_enter(&crypto_ret_q_mtx); + for (;;) { + crp = TAILQ_FIRST(&crp_ret_q); + if (crp != NULL) { + TAILQ_REMOVE(&crp_ret_q, crp, crp_next); + crp->crp_flags &= ~CRYPTO_F_ONRETQ; + } + krp = TAILQ_FIRST(&crp_ret_kq); + if (krp != NULL) { + TAILQ_REMOVE(&crp_ret_kq, krp, krp_next); + krp->krp_flags &= ~CRYPTO_F_ONRETQ; + } + + /* drop before calling any callbacks. */ + if (crp == NULL && krp == NULL) { + cryptostats.cs_rets++; + cv_wait(&cryptoret_cv, &crypto_ret_q_mtx); + continue; + } + + mutex_spin_exit(&crypto_ret_q_mtx); + + if (crp != NULL) { +#ifdef CRYPTO_TIMING + if (crypto_timing) { + /* + * NB: We must copy the timestamp before + * doing the callback as the cryptop is + * likely to be reclaimed. + */ + struct timespec t = crp->crp_tstamp; + crypto_tstat(&cryptostats.cs_cb, &t); + crp->crp_callback(crp); + crypto_tstat(&cryptostats.cs_finis, &t); + } else +#endif + { + crp->crp_callback(crp); + } + } + if (krp != NULL) + krp->krp_callback(krp); + + mutex_spin_enter(&crypto_ret_q_mtx); + } +} + +/* NetBSD module interface */ + +MODULE(MODULE_CLASS_MISC, opencrypto, NULL); + +static int +opencrypto_modcmd(modcmd_t cmd, void *opaque) +{ + + switch (cmd) { + case MODULE_CMD_INIT: +#ifdef _MODULE + crypto_init(); +#endif + return 0; + case MODULE_CMD_FINI: +#ifdef _MODULE + sysctl_teardown(&sysctl_opencrypto_clog); +#endif + return 0; + default: + return ENOTTY; + } +} diff --git a/sys/opencrypto/cryptodev.c b/sys/opencrypto/cryptodev.c new file mode 100644 index 000000000..006b125ff --- /dev/null +++ b/sys/opencrypto/cryptodev.c @@ -0,0 +1,2242 @@ +/* $NetBSD: cryptodev.c,v 1.84 2015/08/20 14:40:19 christos Exp $ */ +/* $FreeBSD: src/sys/opencrypto/cryptodev.c,v 1.4.2.4 2003/06/03 00:09:02 sam Exp $ */ +/* $OpenBSD: cryptodev.c,v 1.53 2002/07/10 22:21:30 mickey Exp $ */ + +/*- + * Copyright (c) 2008 The NetBSD Foundation, Inc. + * All rights reserved. + * + * This code is derived from software contributed to The NetBSD Foundation + * by Coyote Point Systems, Inc. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the above copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * + * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS + * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED + * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR + * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS + * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR + * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF + * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS + * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN + * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) + * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE + * POSSIBILITY OF SUCH DAMAGE. + */ + +/* + * Copyright (c) 2001 Theo de Raadt + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * + * 1. Redistributions of source code must retain the above copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * 3. The name of the author may not be used to endorse or promote products + * derived from this software without specific prior written permission. + * + * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR + * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES + * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. + * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, + * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT + * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, + * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY + * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT + * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF + * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + * + * Effort sponsored in part by the Defense Advanced Research Projects + * Agency (DARPA) and Air Force Research Laboratory, Air Force + * Materiel Command, USAF, under agreement number F30602-01-2-0537. + * + */ + +#include +__KERNEL_RCSID(0, "$NetBSD: cryptodev.c,v 1.84 2015/08/20 14:40:19 christos Exp $"); + +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include + +#ifdef _KERNEL_OPT +#include "opt_ocf.h" +#include "opt_compat_netbsd.h" +#endif + +#include +#include +#include + +#include "ioconf.h" + +struct csession { + TAILQ_ENTRY(csession) next; + u_int64_t sid; + u_int32_t ses; + + u_int32_t cipher; /* note: shares name space in crd_alg */ + const struct enc_xform *txform; + u_int32_t mac; /* note: shares name space in crd_alg */ + const struct auth_hash *thash; + u_int32_t comp_alg; /* note: shares name space in crd_alg */ + const struct comp_algo *tcomp; + + void * key; + int keylen; + u_char tmp_iv[EALG_MAX_BLOCK_LEN]; + + void * mackey; + int mackeylen; + u_char tmp_mac[CRYPTO_MAX_MAC_LEN]; + + struct iovec iovec[1]; /* user requests never have more */ + struct uio uio; + int error; +}; + +struct fcrypt { + TAILQ_HEAD(csessionlist, csession) csessions; + TAILQ_HEAD(crprethead, cryptop) crp_ret_mq; + TAILQ_HEAD(krprethead, cryptkop) crp_ret_mkq; + int sesn; + struct selinfo sinfo; + u_int32_t requestid; + struct timespec atime; + struct timespec mtime; + struct timespec btime; +}; + +/* For our fixed-size allocations */ +static struct pool fcrpl; +static struct pool csepl; + +/* Declaration of master device (fd-cloning/ctxt-allocating) entrypoints */ +static int cryptoopen(dev_t dev, int flag, int mode, struct lwp *l); +static int cryptoread(dev_t dev, struct uio *uio, int ioflag); +static int cryptowrite(dev_t dev, struct uio *uio, int ioflag); +static int cryptoselect(dev_t dev, int rw, struct lwp *l); + +static int crypto_refcount = 0; /* Prevent detaching while in use */ + +/* Declaration of cloned-device (per-ctxt) entrypoints */ +static int cryptof_read(struct file *, off_t *, struct uio *, + kauth_cred_t, int); +static int cryptof_write(struct file *, off_t *, struct uio *, + kauth_cred_t, int); +static int cryptof_ioctl(struct file *, u_long, void *); +static int cryptof_close(struct file *); +static int cryptof_poll(struct file *, int); +static int cryptof_stat(struct file *, struct stat *); + +static const struct fileops cryptofops = { + .fo_read = cryptof_read, + .fo_write = cryptof_write, + .fo_ioctl = cryptof_ioctl, + .fo_fcntl = fnullop_fcntl, + .fo_poll = cryptof_poll, + .fo_stat = cryptof_stat, + .fo_close = cryptof_close, + .fo_kqfilter = fnullop_kqfilter, + .fo_restart = fnullop_restart, +}; + +struct csession *cryptodev_csefind(struct fcrypt *, u_int); +static struct csession *csefind(struct fcrypt *, u_int); +static int csedelete(struct fcrypt *, struct csession *); +static struct csession *cseadd(struct fcrypt *, struct csession *); +static struct csession *csecreate(struct fcrypt *, u_int64_t, void *, + u_int64_t, void *, u_int64_t, u_int32_t, u_int32_t, u_int32_t, + const struct enc_xform *, const struct auth_hash *, + const struct comp_algo *); +static int csefree(struct csession *); + +static int cryptodev_key(struct crypt_kop *); +static int cryptodev_mkey(struct fcrypt *, struct crypt_n_kop *, int); +static int cryptodev_msessionfin(struct fcrypt *, int, u_int32_t *); + +static int cryptodev_cb(void *); +static int cryptodevkey_cb(void *); + +static int cryptodev_mcb(void *); +static int cryptodevkey_mcb(void *); + +static int cryptodev_getmstatus(struct fcrypt *, struct crypt_result *, + int); +static int cryptodev_getstatus(struct fcrypt *, struct crypt_result *); + +#ifdef COMPAT_50 +extern int ocryptof_ioctl(struct file *, u_long, void *); +#endif + +/* + * sysctl-able control variables for /dev/crypto now defined in crypto.c: + * crypto_usercrypto, crypto_userasmcrypto, crypto_devallowsoft. + */ + +/* ARGSUSED */ +int +cryptof_read(file_t *fp, off_t *poff, + struct uio *uio, kauth_cred_t cred, int flags) +{ + return EIO; +} + +/* ARGSUSED */ +int +cryptof_write(file_t *fp, off_t *poff, + struct uio *uio, kauth_cred_t cred, int flags) +{ + return EIO; +} + +/* ARGSUSED */ +int +cryptof_ioctl(struct file *fp, u_long cmd, void *data) +{ + struct fcrypt *fcr = fp->f_fcrypt; + struct csession *cse; + struct session_op *sop; + struct session_n_op *snop; + struct crypt_op *cop; + struct crypt_mop *mop; + struct crypt_mkop *mkop; + struct crypt_n_op *cnop; + struct crypt_n_kop *knop; + struct crypt_sgop *sgop; + struct crypt_sfop *sfop; + struct cryptret *crypt_ret; + struct crypt_result *crypt_res; + u_int32_t ses; + u_int32_t *sesid; + int error = 0; + size_t count; + + /* backwards compatibility */ + file_t *criofp; + struct fcrypt *criofcr; + int criofd; + + mutex_enter(&crypto_mtx); + getnanotime(&fcr->atime); + mutex_exit(&crypto_mtx); + + switch (cmd) { + case CRIOGET: /* XXX deprecated, remove after 5.0 */ + if ((error = fd_allocfile(&criofp, &criofd)) != 0) + return error; + criofcr = pool_get(&fcrpl, PR_WAITOK); + mutex_enter(&crypto_mtx); + TAILQ_INIT(&criofcr->csessions); + TAILQ_INIT(&criofcr->crp_ret_mq); + TAILQ_INIT(&criofcr->crp_ret_mkq); + selinit(&criofcr->sinfo); + + /* + * Don't ever return session 0, to allow detection of + * failed creation attempts with multi-create ioctl. + */ + criofcr->sesn = 1; + criofcr->requestid = 1; + crypto_refcount++; + mutex_exit(&crypto_mtx); + (void)fd_clone(criofp, criofd, (FREAD|FWRITE), + &cryptofops, criofcr); + *(u_int32_t *)data = criofd; + return error; + break; + case CIOCGSESSION: + sop = (struct session_op *)data; + error = cryptodev_session(fcr, sop); + break; + case CIOCNGSESSION: + sgop = (struct crypt_sgop *)data; + snop = kmem_alloc((sgop->count * + sizeof(struct session_n_op)), KM_SLEEP); + error = copyin(sgop->sessions, snop, sgop->count * + sizeof(struct session_n_op)); + if (error) { + goto mbail; + } + + mutex_enter(&crypto_mtx); + fcr->mtime = fcr->atime; + mutex_exit(&crypto_mtx); + error = cryptodev_msession(fcr, snop, sgop->count); + if (error) { + goto mbail; + } + + error = copyout(snop, sgop->sessions, sgop->count * + sizeof(struct session_n_op)); +mbail: + kmem_free(snop, sgop->count * sizeof(struct session_n_op)); + break; + case CIOCFSESSION: + mutex_enter(&crypto_mtx); + fcr->mtime = fcr->atime; + ses = *(u_int32_t *)data; + cse = csefind(fcr, ses); + if (cse == NULL) { + mutex_exit(&crypto_mtx); + return EINVAL; + } + csedelete(fcr, cse); + mutex_exit(&crypto_mtx); + error = csefree(cse); + break; + case CIOCNFSESSION: + mutex_enter(&crypto_mtx); + fcr->mtime = fcr->atime; + mutex_exit(&crypto_mtx); + sfop = (struct crypt_sfop *)data; + sesid = kmem_alloc((sfop->count * sizeof(u_int32_t)), + KM_SLEEP); + error = copyin(sfop->sesid, sesid, + (sfop->count * sizeof(u_int32_t))); + if (!error) { + error = cryptodev_msessionfin(fcr, sfop->count, sesid); + } + kmem_free(sesid, (sfop->count * sizeof(u_int32_t))); + break; + case CIOCCRYPT: + mutex_enter(&crypto_mtx); + fcr->mtime = fcr->atime; + cop = (struct crypt_op *)data; + cse = csefind(fcr, cop->ses); + mutex_exit(&crypto_mtx); + if (cse == NULL) { + DPRINTF(("csefind failed\n")); + return EINVAL; + } + error = cryptodev_op(cse, cop, curlwp); + DPRINTF(("cryptodev_op error = %d\n", error)); + break; + case CIOCNCRYPTM: + mutex_enter(&crypto_mtx); + fcr->mtime = fcr->atime; + mutex_exit(&crypto_mtx); + mop = (struct crypt_mop *)data; + cnop = kmem_alloc((mop->count * sizeof(struct crypt_n_op)), + KM_SLEEP); + error = copyin(mop->reqs, cnop, + (mop->count * sizeof(struct crypt_n_op))); + if(!error) { + error = cryptodev_mop(fcr, cnop, mop->count, curlwp); + if (!error) { + error = copyout(cnop, mop->reqs, + (mop->count * sizeof(struct crypt_n_op))); + } + } + kmem_free(cnop, (mop->count * sizeof(struct crypt_n_op))); + break; + case CIOCKEY: + error = cryptodev_key((struct crypt_kop *)data); + DPRINTF(("cryptodev_key error = %d\n", error)); + break; + case CIOCNFKEYM: + mutex_enter(&crypto_mtx); + fcr->mtime = fcr->atime; + mutex_exit(&crypto_mtx); + mkop = (struct crypt_mkop *)data; + knop = kmem_alloc((mkop->count * sizeof(struct crypt_n_kop)), + KM_SLEEP); + error = copyin(mkop->reqs, knop, + (mkop->count * sizeof(struct crypt_n_kop))); + if (!error) { + error = cryptodev_mkey(fcr, knop, mkop->count); + if (!error) + error = copyout(knop, mkop->reqs, + (mkop->count * sizeof(struct crypt_n_kop))); + } + kmem_free(knop, (mkop->count * sizeof(struct crypt_n_kop))); + break; + case CIOCASYMFEAT: + error = crypto_getfeat((int *)data); + break; + case CIOCNCRYPTRETM: + mutex_enter(&crypto_mtx); + fcr->mtime = fcr->atime; + mutex_exit(&crypto_mtx); + crypt_ret = (struct cryptret *)data; + count = crypt_ret->count; + crypt_res = kmem_alloc((count * sizeof(struct crypt_result)), + KM_SLEEP); + error = copyin(crypt_ret->results, crypt_res, + (count * sizeof(struct crypt_result))); + if (error) + goto reterr; + crypt_ret->count = cryptodev_getmstatus(fcr, crypt_res, + crypt_ret->count); + /* sanity check count */ + if (crypt_ret->count > count) { + printf("%s.%d: error returned count %zd > original " + " count %zd\n", + __FILE__, __LINE__, crypt_ret->count, count); + crypt_ret->count = count; + + } + error = copyout(crypt_res, crypt_ret->results, + (crypt_ret->count * sizeof(struct crypt_result))); +reterr: + kmem_free(crypt_res, (count * sizeof(struct crypt_result))); + break; + case CIOCNCRYPTRET: + error = cryptodev_getstatus(fcr, (struct crypt_result *)data); + break; + default: +#ifdef COMPAT_50 + /* Check for backward compatible commands */ + error = ocryptof_ioctl(fp, cmd, data); +#else + return EINVAL; +#endif + } + return error; +} + +int +cryptodev_op(struct csession *cse, struct crypt_op *cop, struct lwp *l) +{ + struct cryptop *crp = NULL; + struct cryptodesc *crde = NULL, *crda = NULL, *crdc = NULL; + int error; + int iov_len = cop->len; + int flags=0; + int dst_len; /* copyout size */ + + if (cop->len > 256*1024-4) + return E2BIG; + + if (cse->txform) { + if (cop->len < cse->txform->blocksize + + (cop->iv ? 0 : cse->txform->ivsize) || + (cop->len - (cop->iv ? 0 : cse->txform->ivsize)) + % cse->txform->blocksize != 0) + return EINVAL; + } + + DPRINTF(("cryptodev_op[%u]: iov_len %d\n", + CRYPTO_SESID2LID(cse->sid), iov_len)); + if ((cse->tcomp) && cop->dst_len) { + if (iov_len < cop->dst_len) { + /* Need larger iov to deal with decompress */ + iov_len = cop->dst_len; + } + DPRINTF(("cryptodev_op: iov_len -> %d for decompress\n", iov_len)); + } + + (void)memset(&cse->uio, 0, sizeof(cse->uio)); + cse->uio.uio_iovcnt = 1; + cse->uio.uio_resid = 0; + cse->uio.uio_rw = UIO_WRITE; + cse->uio.uio_iov = cse->iovec; + UIO_SETUP_SYSSPACE(&cse->uio); + memset(&cse->iovec, 0, sizeof(cse->iovec)); + + /* the iov needs to be big enough to handle the uncompressed + * data.... */ + cse->uio.uio_iov[0].iov_len = iov_len; + if (iov_len > 0) + cse->uio.uio_iov[0].iov_base = kmem_alloc(iov_len, KM_SLEEP); + cse->uio.uio_resid = cse->uio.uio_iov[0].iov_len; + DPRINTF(("cryptodev_op[%u]: uio.iov_base %p malloced %d bytes\n", + CRYPTO_SESID2LID(cse->sid), + cse->uio.uio_iov[0].iov_base, iov_len)); + + crp = crypto_getreq((cse->tcomp != NULL) + (cse->txform != NULL) + (cse->thash != NULL)); + if (crp == NULL) { + error = ENOMEM; + goto bail; + } + DPRINTF(("cryptodev_op[%u]: crp %p\n", + CRYPTO_SESID2LID(cse->sid), crp)); + + /* crds are always ordered tcomp, thash, then txform */ + /* with optional missing links */ + + /* XXX: If we're going to compress then hash or encrypt, we need + * to be able to pass on the new size of the data. + */ + + if (cse->tcomp) { + crdc = crp->crp_desc; + } + + if (cse->thash) { + crda = crdc ? crdc->crd_next : crp->crp_desc; + if (cse->txform && crda) + crde = crda->crd_next; + } else { + if (cse->txform) { + crde = crdc ? crdc->crd_next : crp->crp_desc; + } else if (!cse->tcomp) { + error = EINVAL; + goto bail; + } + } + + DPRINTF(("ocf[%u]: iov_len %zu, cop->len %u\n", + CRYPTO_SESID2LID(cse->sid), + cse->uio.uio_iov[0].iov_len, + cop->len)); + + if ((error = copyin(cop->src, cse->uio.uio_iov[0].iov_base, cop->len))) + { + printf("copyin failed %s %d \n", (char *)cop->src, error); + goto bail; + } + + if (crdc) { + switch (cop->op) { + case COP_COMP: + crdc->crd_flags |= CRD_F_COMP; + break; + case COP_DECOMP: + crdc->crd_flags &= ~CRD_F_COMP; + break; + default: + break; + } + /* more data to follow? */ + if (cop->flags & COP_F_MORE) { + flags |= CRYPTO_F_MORE; + } + crdc->crd_len = cop->len; + crdc->crd_inject = 0; + + crdc->crd_alg = cse->comp_alg; + crdc->crd_key = NULL; + crdc->crd_klen = 0; + DPRINTF(("cryptodev_op[%u]: crdc setup for comp_alg %d.\n", + CRYPTO_SESID2LID(cse->sid), crdc->crd_alg)); + } + + if (crda) { + crda->crd_skip = 0; + crda->crd_len = cop->len; + crda->crd_inject = 0; /* ??? */ + + crda->crd_alg = cse->mac; + crda->crd_key = cse->mackey; + crda->crd_klen = cse->mackeylen * 8; + DPRINTF(("cryptodev_op: crda setup for mac %d.\n", crda->crd_alg)); + } + + if (crde) { + switch (cop->op) { + case COP_ENCRYPT: + crde->crd_flags |= CRD_F_ENCRYPT; + break; + case COP_DECRYPT: + crde->crd_flags &= ~CRD_F_ENCRYPT; + break; + default: + break; + } + crde->crd_len = cop->len; + crde->crd_inject = 0; + + if (cse->cipher == CRYPTO_AES_GCM_16 && crda) + crda->crd_len = 0; + else if (cse->cipher == CRYPTO_AES_GMAC) + crde->crd_len = 0; + + crde->crd_alg = cse->cipher; + crde->crd_key = cse->key; + crde->crd_klen = cse->keylen * 8; + DPRINTF(("cryptodev_op: crde setup for cipher %d.\n", crde->crd_alg)); + } + + + crp->crp_ilen = cop->len; + /* The reqest is flagged as CRYPTO_F_USER as long as it is running + * in the user IOCTL thread. This flag lets us skip using the retq for + * the request if it completes immediately. If the request ends up being + * delayed or is not completed immediately the flag is removed. + */ + crp->crp_flags = CRYPTO_F_IOV | (cop->flags & COP_F_BATCH) | CRYPTO_F_USER | + flags; + crp->crp_buf = (void *)&cse->uio; + crp->crp_callback = (int (*) (struct cryptop *)) cryptodev_cb; + crp->crp_sid = cse->sid; + crp->crp_opaque = (void *)cse; + + if (cop->iv) { + if (crde == NULL) { + error = EINVAL; + goto bail; + } + if (cse->txform->ivsize == 0) { + error = EINVAL; + goto bail; + } + if ((error = copyin(cop->iv, cse->tmp_iv, + cse->txform->ivsize))) + goto bail; + (void)memcpy(crde->crd_iv, cse->tmp_iv, cse->txform->ivsize); + crde->crd_flags |= CRD_F_IV_EXPLICIT | CRD_F_IV_PRESENT; + crde->crd_skip = 0; + } else if (crde) { + if (cse->txform->ivsize == 0) { + crde->crd_skip = 0; + } else { + if (!(crde->crd_flags & CRD_F_ENCRYPT)) + crde->crd_flags |= CRD_F_IV_PRESENT; + crde->crd_skip = cse->txform->ivsize; + crde->crd_len -= cse->txform->ivsize; + } + } + + if (cop->mac) { + if (crda == NULL) { + error = EINVAL; + goto bail; + } + crp->crp_mac=cse->tmp_mac; + } + + cv_init(&crp->crp_cv, "crydev"); + + /* + * XXX there was a comment here which said that we went to + * XXX splcrypto() but needed to only if CRYPTO_F_CBIMM, + * XXX disabled on NetBSD since 1.6O due to a race condition. + * XXX But crypto_dispatch went to splcrypto() itself! (And + * XXX now takes the crypto_mtx mutex itself). We do, however, + * XXX need to hold the mutex across the call to cv_wait(). + * XXX (should we arrange for crypto_dispatch to return to + * XXX us with it held? it seems quite ugly to do so.) + */ +#ifdef notyet +eagain: +#endif + error = crypto_dispatch(crp); + mutex_enter(&crypto_mtx); + + /* + * If the request was going to be completed by the + * ioctl thread then it would have been done by now. + * Remove the F_USER flag so crypto_done() is not confused + * if the crypto device calls it after this point. + */ + crp->crp_flags &= ~(CRYPTO_F_USER); + + switch (error) { +#ifdef notyet /* don't loop forever -- but EAGAIN not possible here yet */ + case EAGAIN: + mutex_exit(&crypto_mtx); + goto eagain; + break; +#endif + case 0: + break; + default: + DPRINTF(("cryptodev_op: not waiting, error.\n")); + mutex_exit(&crypto_mtx); + cv_destroy(&crp->crp_cv); + goto bail; + } + + while (!(crp->crp_flags & CRYPTO_F_DONE)) { + DPRINTF(("cryptodev_op[%d]: sleeping on cv %p for crp %p\n", + (uint32_t)cse->sid, &crp->crp_cv, crp)); + cv_wait(&crp->crp_cv, &crypto_mtx); /* XXX cv_wait_sig? */ + } + if (crp->crp_flags & CRYPTO_F_ONRETQ) { + /* XXX this should never happen now with the CRYPTO_F_USER flag + * changes. + */ + DPRINTF(("cryptodev_op: DONE, not woken by cryptoret.\n")); + (void)crypto_ret_q_remove(crp); + } + mutex_exit(&crypto_mtx); + cv_destroy(&crp->crp_cv); + + if (crp->crp_etype != 0) { + DPRINTF(("cryptodev_op: crp_etype %d\n", crp->crp_etype)); + error = crp->crp_etype; + goto bail; + } + + if (cse->error) { + DPRINTF(("cryptodev_op: cse->error %d\n", cse->error)); + error = cse->error; + goto bail; + } + + dst_len = crp->crp_ilen; + /* let the user know how much data was returned */ + if (crp->crp_olen) { + if (crp->crp_olen > (cop->dst_len ? cop->dst_len : cop->len)) { + error = ENOSPC; + goto bail; + } + dst_len = cop->dst_len = crp->crp_olen; + } + + if (cop->dst) { + DPRINTF(("cryptodev_op: copyout %d bytes to %p\n", dst_len, cop->dst)); + } + if (cop->dst && + (error = copyout(cse->uio.uio_iov[0].iov_base, cop->dst, dst_len))) + { + DPRINTF(("cryptodev_op: copyout error %d\n", error)); + goto bail; + } + + if (cop->mac && + (error = copyout(crp->crp_mac, cop->mac, cse->thash->authsize))) { + DPRINTF(("cryptodev_op: mac copyout error %d\n", error)); + goto bail; + } + + +bail: + if (crp) { + crypto_freereq(crp); + } + if (cse->uio.uio_iov[0].iov_base) { + kmem_free(cse->uio.uio_iov[0].iov_base,iov_len); + } + + return error; +} + +static int +cryptodev_cb(void *op) +{ + struct cryptop *crp = (struct cryptop *) op; + struct csession *cse = (struct csession *)crp->crp_opaque; + int error = 0; + + mutex_enter(&crypto_mtx); + cse->error = crp->crp_etype; + if (crp->crp_etype == EAGAIN) { + /* always drop mutex to call dispatch routine */ + mutex_exit(&crypto_mtx); + error = crypto_dispatch(crp); + mutex_enter(&crypto_mtx); + } + if (error != 0 || (crp->crp_flags & CRYPTO_F_DONE)) { + cv_signal(&crp->crp_cv); + } + mutex_exit(&crypto_mtx); + return 0; +} + +static int +cryptodev_mcb(void *op) +{ + struct cryptop *crp = (struct cryptop *) op; + struct csession *cse = (struct csession *)crp->crp_opaque; + int error=0; + + mutex_enter(&crypto_mtx); + cse->error = crp->crp_etype; + if (crp->crp_etype == EAGAIN) { + mutex_exit(&crypto_mtx); + error = crypto_dispatch(crp); + mutex_enter(&crypto_mtx); + } + if (error != 0 || (crp->crp_flags & CRYPTO_F_DONE)) { + cv_signal(&crp->crp_cv); + } + + TAILQ_INSERT_TAIL(&crp->fcrp->crp_ret_mq, crp, crp_next); + selnotify(&crp->fcrp->sinfo, 0, 0); + mutex_exit(&crypto_mtx); + return 0; +} + +static int +cryptodevkey_cb(void *op) +{ + struct cryptkop *krp = op; + + mutex_enter(&crypto_mtx); + cv_signal(&krp->krp_cv); + mutex_exit(&crypto_mtx); + return 0; +} + +static int +cryptodevkey_mcb(void *op) +{ + struct cryptkop *krp = op; + + mutex_enter(&crypto_mtx); + cv_signal(&krp->krp_cv); + TAILQ_INSERT_TAIL(&krp->fcrp->crp_ret_mkq, krp, krp_next); + selnotify(&krp->fcrp->sinfo, 0, 0); + mutex_exit(&crypto_mtx); + return 0; +} + +static int +cryptodev_key(struct crypt_kop *kop) +{ + struct cryptkop *krp = NULL; + int error = EINVAL; + int in, out, size, i; + + if (kop->crk_iparams + kop->crk_oparams > CRK_MAXPARAM) + return EFBIG; + + in = kop->crk_iparams; + out = kop->crk_oparams; + switch (kop->crk_op) { + case CRK_MOD_EXP: + if (in == 3 && out == 1) + break; + return EINVAL; + case CRK_MOD_EXP_CRT: + if (in == 6 && out == 1) + break; + return EINVAL; + case CRK_DSA_SIGN: + if (in == 5 && out == 2) + break; + return EINVAL; + case CRK_DSA_VERIFY: + if (in == 7 && out == 0) + break; + return EINVAL; + case CRK_DH_COMPUTE_KEY: + if (in == 3 && out == 1) + break; + return EINVAL; + case CRK_MOD_ADD: + if (in == 3 && out == 1) + break; + return EINVAL; + case CRK_MOD_ADDINV: + if (in == 2 && out == 1) + break; + return EINVAL; + case CRK_MOD_SUB: + if (in == 3 && out == 1) + break; + return EINVAL; + case CRK_MOD_MULT: + if (in == 3 && out == 1) + break; + return EINVAL; + case CRK_MOD_MULTINV: + if (in == 2 && out == 1) + break; + return EINVAL; + case CRK_MOD: + if (in == 2 && out == 1) + break; + return EINVAL; + default: + return EINVAL; + } + + krp = pool_get(&cryptkop_pool, PR_WAITOK); + (void)memset(krp, 0, sizeof *krp); + cv_init(&krp->krp_cv, "crykdev"); + krp->krp_op = kop->crk_op; + krp->krp_status = kop->crk_status; + krp->krp_iparams = kop->crk_iparams; + krp->krp_oparams = kop->crk_oparams; + krp->krp_status = 0; + krp->krp_callback = (int (*) (struct cryptkop *)) cryptodevkey_cb; + + for (i = 0; i < CRK_MAXPARAM; i++) + krp->krp_param[i].crp_nbits = kop->crk_param[i].crp_nbits; + for (i = 0; i < krp->krp_iparams + krp->krp_oparams; i++) { + size = (krp->krp_param[i].crp_nbits + 7) / 8; + if (size == 0) + continue; + krp->krp_param[i].crp_p = kmem_alloc(size, KM_SLEEP); + if (i >= krp->krp_iparams) + continue; + error = copyin(kop->crk_param[i].crp_p, + krp->krp_param[i].crp_p, size); + if (error) + goto fail; + } + + error = crypto_kdispatch(krp); + if (error != 0) { + goto fail; + } + + mutex_enter(&crypto_mtx); + while (!(krp->krp_flags & CRYPTO_F_DONE)) { + cv_wait(&krp->krp_cv, &crypto_mtx); /* XXX cv_wait_sig? */ + } + if (krp->krp_flags & CRYPTO_F_ONRETQ) { + DPRINTF(("cryptodev_key: DONE early, not via cryptoret.\n")); + (void)crypto_ret_kq_remove(krp); + } + mutex_exit(&crypto_mtx); + + if (krp->krp_status != 0) { + DPRINTF(("cryptodev_key: krp->krp_status 0x%08x\n", + krp->krp_status)); + error = krp->krp_status; + goto fail; + } + + for (i = krp->krp_iparams; i < krp->krp_iparams + krp->krp_oparams; + i++) { + size = (krp->krp_param[i].crp_nbits + 7) / 8; + if (size == 0) + continue; + error = copyout(krp->krp_param[i].crp_p, + kop->crk_param[i].crp_p, size); + if (error) { + DPRINTF(("cryptodev_key: copyout oparam %d failed, " + "error=%d\n", i-krp->krp_iparams, error)); + goto fail; + } + } + +fail: + kop->crk_status = krp->krp_status; + for (i = 0; i < CRK_MAXPARAM; i++) { + struct crparam *kp = &(krp->krp_param[i]); + if (krp->krp_param[i].crp_p) { + size = (kp->crp_nbits + 7) / 8; + KASSERT(size > 0); + (void)memset(kp->crp_p, 0, size); + kmem_free(kp->crp_p, size); + } + } + cv_destroy(&krp->krp_cv); + pool_put(&cryptkop_pool, krp); + DPRINTF(("cryptodev_key: error=0x%08x\n", error)); + return error; +} + +/* ARGSUSED */ +static int +cryptof_close(struct file *fp) +{ + struct fcrypt *fcr = fp->f_fcrypt; + struct csession *cse; + + mutex_enter(&crypto_mtx); + while ((cse = TAILQ_FIRST(&fcr->csessions))) { + TAILQ_REMOVE(&fcr->csessions, cse, next); + mutex_exit(&crypto_mtx); + (void)csefree(cse); + mutex_enter(&crypto_mtx); + } + seldestroy(&fcr->sinfo); + fp->f_fcrypt = NULL; + crypto_refcount--; + mutex_exit(&crypto_mtx); + + pool_put(&fcrpl, fcr); + return 0; +} + +/* needed for compatibility module */ +struct csession *cryptodev_csefind(struct fcrypt *fcr, u_int ses) +{ + return csefind(fcr, ses); +} + +/* csefind: call with crypto_mtx held. */ +static struct csession * +csefind(struct fcrypt *fcr, u_int ses) +{ + struct csession *cse, *cnext, *ret = NULL; + + KASSERT(mutex_owned(&crypto_mtx)); + TAILQ_FOREACH_SAFE(cse, &fcr->csessions, next, cnext) + if (cse->ses == ses) + ret = cse; + + return ret; +} + +/* csedelete: call with crypto_mtx held. */ +static int +csedelete(struct fcrypt *fcr, struct csession *cse_del) +{ + struct csession *cse, *cnext; + int ret = 0; + + KASSERT(mutex_owned(&crypto_mtx)); + TAILQ_FOREACH_SAFE(cse, &fcr->csessions, next, cnext) { + if (cse == cse_del) { + TAILQ_REMOVE(&fcr->csessions, cse, next); + ret = 1; + } + } + return ret; +} + +static struct csession * +cseadd(struct fcrypt *fcr, struct csession *cse) +{ + mutex_enter(&crypto_mtx); + /* don't let session ID wrap! */ + if (fcr->sesn + 1 == 0) return NULL; + TAILQ_INSERT_TAIL(&fcr->csessions, cse, next); + cse->ses = fcr->sesn++; + mutex_exit(&crypto_mtx); + return cse; +} + +static struct csession * +csecreate(struct fcrypt *fcr, u_int64_t sid, void *key, u_int64_t keylen, + void *mackey, u_int64_t mackeylen, u_int32_t cipher, u_int32_t mac, + u_int32_t comp_alg, const struct enc_xform *txform, + const struct auth_hash *thash, const struct comp_algo *tcomp) +{ + struct csession *cse; + + cse = pool_get(&csepl, PR_NOWAIT); + if (cse == NULL) + return NULL; + cse->key = key; + cse->keylen = keylen/8; + cse->mackey = mackey; + cse->mackeylen = mackeylen/8; + cse->sid = sid; + cse->cipher = cipher; + cse->mac = mac; + cse->comp_alg = comp_alg; + cse->txform = txform; + cse->thash = thash; + cse->tcomp = tcomp; + cse->error = 0; + if (cseadd(fcr, cse)) + return cse; + else { + pool_put(&csepl, cse); + return NULL; + } +} + +/* csefree: call with crypto_mtx held. */ +static int +csefree(struct csession *cse) +{ + int error; + + error = crypto_freesession(cse->sid); + if (cse->key) + free(cse->key, M_XDATA); + if (cse->mackey) + free(cse->mackey, M_XDATA); + pool_put(&csepl, cse); + return error; +} + +static int +cryptoopen(dev_t dev, int flag, int mode, + struct lwp *l) +{ + file_t *fp; + struct fcrypt *fcr; + int fd, error; + + if (crypto_usercrypto == 0) + return ENXIO; + + if ((error = fd_allocfile(&fp, &fd)) != 0) + return error; + + fcr = pool_get(&fcrpl, PR_WAITOK); + getnanotime(&fcr->btime); + fcr->atime = fcr->mtime = fcr->btime; + mutex_enter(&crypto_mtx); + TAILQ_INIT(&fcr->csessions); + TAILQ_INIT(&fcr->crp_ret_mq); + TAILQ_INIT(&fcr->crp_ret_mkq); + selinit(&fcr->sinfo); + /* + * Don't ever return session 0, to allow detection of + * failed creation attempts with multi-create ioctl. + */ + fcr->sesn = 1; + fcr->requestid = 1; + crypto_refcount++; + mutex_exit(&crypto_mtx); + return fd_clone(fp, fd, flag, &cryptofops, fcr); +} + +static int +cryptoread(dev_t dev, struct uio *uio, int ioflag) +{ + return EIO; +} + +static int +cryptowrite(dev_t dev, struct uio *uio, int ioflag) +{ + return EIO; +} + +int +cryptoselect(dev_t dev, int rw, struct lwp *l) +{ + return 0; +} + +/*static*/ +struct cdevsw crypto_cdevsw = { + .d_open = cryptoopen, + .d_close = noclose, + .d_read = cryptoread, + .d_write = cryptowrite, + .d_ioctl = noioctl, + .d_stop = nostop, + .d_tty = notty, + .d_poll = cryptoselect /*nopoll*/, + .d_mmap = nommap, + .d_kqfilter = nokqfilter, + .d_discard = nodiscard, + .d_flag = D_OTHER +}; + +int +cryptodev_mop(struct fcrypt *fcr, + struct crypt_n_op * cnop, + int count, struct lwp *l) +{ + struct cryptop *crp = NULL; + struct cryptodesc *crde = NULL, *crda = NULL, *crdc = NULL; + int req, error=0; + struct csession *cse; + int flags=0; + int iov_len; + + for (req = 0; req < count; req++) { + mutex_enter(&crypto_mtx); + cse = csefind(fcr, cnop[req].ses); + if (cse == NULL) { + DPRINTF(("csefind failed\n")); + cnop[req].status = EINVAL; + mutex_exit(&crypto_mtx); + continue; + } + mutex_exit(&crypto_mtx); + + if (cnop[req].len > 256*1024-4) { + DPRINTF(("length failed\n")); + cnop[req].status = EINVAL; + continue; + } + if (cse->txform) { + if (cnop[req].len < cse->txform->blocksize - + (cnop[req].iv ? 0 : cse->txform->ivsize) || + (cnop[req].len - + (cnop[req].iv ? 0 : cse->txform->ivsize)) + % cse->txform->blocksize) { + cnop[req].status = EINVAL; + continue; + } + } + + crp = crypto_getreq((cse->txform != NULL) + + (cse->thash != NULL) + + (cse->tcomp != NULL)); + if (crp == NULL) { + cnop[req].status = ENOMEM; + goto bail; + } + + iov_len = cnop[req].len; + /* got a compression/decompression max size? */ + if ((cse->tcomp) && cnop[req].dst_len) { + if (iov_len < cnop[req].dst_len) { + /* Need larger iov to deal with decompress */ + iov_len = cnop[req].dst_len; + } + DPRINTF(("cryptodev_mop: iov_len -> %d for decompress\n", iov_len)); + } + + (void)memset(&crp->uio, 0, sizeof(crp->uio)); + crp->uio.uio_iovcnt = 1; + crp->uio.uio_resid = 0; + crp->uio.uio_rw = UIO_WRITE; + crp->uio.uio_iov = crp->iovec; + UIO_SETUP_SYSSPACE(&crp->uio); + memset(&crp->iovec, 0, sizeof(crp->iovec)); + crp->uio.uio_iov[0].iov_len = iov_len; + DPRINTF(("cryptodev_mop: kmem_alloc(%d) for iov \n", iov_len)); + crp->uio.uio_iov[0].iov_base = kmem_alloc(iov_len, KM_SLEEP); + crp->uio.uio_resid = crp->uio.uio_iov[0].iov_len; + + if (cse->tcomp) { + crdc = crp->crp_desc; + } + + if (cse->thash) { + crda = crdc ? crdc->crd_next : crp->crp_desc; + if (cse->txform && crda) + crde = crda->crd_next; + } else { + if (cse->txform) { + crde = crdc ? crdc->crd_next : crp->crp_desc; + } else if (!cse->tcomp) { + error = EINVAL; + goto bail; + } + } + + if ((copyin(cnop[req].src, + crp->uio.uio_iov[0].iov_base, cnop[req].len))) { + cnop[req].status = EINVAL; + goto bail; + } + + if (crdc) { + switch (cnop[req].op) { + case COP_COMP: + crdc->crd_flags |= CRD_F_COMP; + break; + case COP_DECOMP: + crdc->crd_flags &= ~CRD_F_COMP; + break; + default: + break; + } + /* more data to follow? */ + if (cnop[req].flags & COP_F_MORE) { + flags |= CRYPTO_F_MORE; + } + crdc->crd_len = cnop[req].len; + crdc->crd_inject = 0; + + crdc->crd_alg = cse->comp_alg; + crdc->crd_key = NULL; + crdc->crd_klen = 0; + DPRINTF(("cryptodev_mop[%d]: crdc setup for comp_alg %d" + " len %d.\n", + (uint32_t)cse->sid, crdc->crd_alg, + crdc->crd_len)); + } + + if (crda) { + crda->crd_skip = 0; + crda->crd_len = cnop[req].len; + crda->crd_inject = 0; /* ??? */ + + crda->crd_alg = cse->mac; + crda->crd_key = cse->mackey; + crda->crd_klen = cse->mackeylen * 8; + } + + if (crde) { + if (cnop[req].op == COP_ENCRYPT) + crde->crd_flags |= CRD_F_ENCRYPT; + else + crde->crd_flags &= ~CRD_F_ENCRYPT; + crde->crd_len = cnop[req].len; + crde->crd_inject = 0; + + crde->crd_alg = cse->cipher; +#ifdef notyet /* XXX must notify h/w driver new key, drain */ + if(cnop[req].key && cnop[req].keylen) { + crde->crd_key = malloc(cnop[req].keylen, + M_XDATA, M_WAITOK); + if((error = copyin(cnop[req].key, + crde->crd_key, cnop[req].keylen))) { + cnop[req].status = EINVAL; + goto bail; + } + crde->crd_klen = cnop[req].keylen * 8; + } else { ... } +#endif + crde->crd_key = cse->key; + crde->crd_klen = cse->keylen * 8; + } + + crp->crp_ilen = cnop[req].len; + crp->crp_flags = CRYPTO_F_IOV | CRYPTO_F_CBIMM | + (cnop[req].flags & COP_F_BATCH) | flags; + crp->crp_buf = (void *)&crp->uio; + crp->crp_callback = (int (*) (struct cryptop *)) cryptodev_mcb; + crp->crp_sid = cse->sid; + crp->crp_opaque = (void *)cse; + crp->fcrp = fcr; + crp->dst = cnop[req].dst; + crp->len = cnop[req].len; /* input len, iov may be larger */ + crp->mac = cnop[req].mac; + DPRINTF(("cryptodev_mop: iov_base %p dst %p len %d mac %p\n", + crp->uio.uio_iov[0].iov_base, crp->dst, crp->len, + crp->mac)); + + if (cnop[req].iv) { + if (crde == NULL) { + cnop[req].status = EINVAL; + goto bail; + } + if (cse->cipher == CRYPTO_ARC4) { /* XXX use flag? */ + cnop[req].status = EINVAL; + goto bail; + } + if ((error = copyin(cnop[req].iv, crp->tmp_iv, + cse->txform->ivsize))) { + cnop[req].status = EINVAL; + goto bail; + } + (void)memcpy(crde->crd_iv, crp->tmp_iv, + cse->txform->ivsize); + crde->crd_flags |= CRD_F_IV_EXPLICIT | CRD_F_IV_PRESENT; + crde->crd_skip = 0; + } else if (crde) { + if (cse->cipher == CRYPTO_ARC4) { /* XXX use flag? */ + crde->crd_skip = 0; + } else { + if (!(crde->crd_flags & CRD_F_ENCRYPT)) + crde->crd_flags |= CRD_F_IV_PRESENT; + crde->crd_skip = cse->txform->ivsize; + crde->crd_len -= cse->txform->ivsize; + } + } + + if (cnop[req].mac) { + if (crda == NULL) { + cnop[req].status = EINVAL; + goto bail; + } + crp->crp_mac=cse->tmp_mac; + } + cnop[req].reqid = atomic_inc_32_nv(&(fcr->requestid)); + crp->crp_reqid = cnop[req].reqid; + crp->crp_usropaque = cnop[req].opaque; + cv_init(&crp->crp_cv, "crydev"); +#ifdef notyet +eagain: +#endif + cnop[req].status = crypto_dispatch(crp); + mutex_enter(&crypto_mtx); /* XXX why mutex? */ + + switch (cnop[req].status) { +#ifdef notyet /* don't loop forever -- but EAGAIN not possible here yet */ + case EAGAIN: + mutex_exit(&crypto_mtx); + goto eagain; + break; +#endif + case 0: + break; + default: + DPRINTF(("cryptodev_op: not waiting, error.\n")); + mutex_exit(&crypto_mtx); + cv_destroy(&crp->crp_cv); + goto bail; + } + + mutex_exit(&crypto_mtx); + cv_destroy(&crp->crp_cv); +bail: + if (cnop[req].status) { + if (crp) { + if (crp->uio.uio_iov[0].iov_base) { + kmem_free(crp->uio.uio_iov[0].iov_base, + crp->uio.uio_iov[0].iov_len); + } + crypto_freereq(crp); + } + error = 0; + } + } + return error; +} + +static int +cryptodev_mkey(struct fcrypt *fcr, struct crypt_n_kop *kop, int count) +{ + struct cryptkop *krp = NULL; + int error = EINVAL; + int in, out, size, i, req; + + for (req = 0; req < count; req++) { + if (kop[req].crk_iparams + kop[req].crk_oparams > CRK_MAXPARAM) + return EFBIG; + + in = kop[req].crk_iparams; + out = kop[req].crk_oparams; + switch (kop[req].crk_op) { + case CRK_MOD_EXP: + if (in == 3 && out == 1) + break; + kop[req].crk_status = EINVAL; + continue; + case CRK_MOD_EXP_CRT: + if (in == 6 && out == 1) + break; + kop[req].crk_status = EINVAL; + continue; + case CRK_DSA_SIGN: + if (in == 5 && out == 2) + break; + kop[req].crk_status = EINVAL; + continue; + case CRK_DSA_VERIFY: + if (in == 7 && out == 0) + break; + kop[req].crk_status = EINVAL; + continue; + case CRK_DH_COMPUTE_KEY: + if (in == 3 && out == 1) + break; + kop[req].crk_status = EINVAL; + continue; + case CRK_MOD_ADD: + if (in == 3 && out == 1) + break; + kop[req].crk_status = EINVAL; + continue; + case CRK_MOD_ADDINV: + if (in == 2 && out == 1) + break; + kop[req].crk_status = EINVAL; + continue; + case CRK_MOD_SUB: + if (in == 3 && out == 1) + break; + kop[req].crk_status = EINVAL; + continue; + case CRK_MOD_MULT: + if (in == 3 && out == 1) + break; + kop[req].crk_status = EINVAL; + continue; + case CRK_MOD_MULTINV: + if (in == 2 && out == 1) + break; + kop[req].crk_status = EINVAL; + continue; + case CRK_MOD: + if (in == 2 && out == 1) + break; + kop[req].crk_status = EINVAL; + continue; + default: + kop[req].crk_status = EINVAL; + continue; + } + + krp = pool_get(&cryptkop_pool, PR_WAITOK); + (void)memset(krp, 0, sizeof *krp); + cv_init(&krp->krp_cv, "crykdev"); + krp->krp_op = kop[req].crk_op; + krp->krp_status = kop[req].crk_status; + krp->krp_iparams = kop[req].crk_iparams; + krp->krp_oparams = kop[req].crk_oparams; + krp->krp_status = 0; + krp->krp_callback = + (int (*) (struct cryptkop *)) cryptodevkey_mcb; + (void)memcpy(krp->crk_param, kop[req].crk_param, + sizeof(kop[req].crk_param)); + + krp->krp_flags = CRYPTO_F_CBIMM; + + for (i = 0; i < CRK_MAXPARAM; i++) + krp->krp_param[i].crp_nbits = + kop[req].crk_param[i].crp_nbits; + for (i = 0; i < krp->krp_iparams + krp->krp_oparams; i++) { + size = (krp->krp_param[i].crp_nbits + 7) / 8; + if (size == 0) + continue; + krp->krp_param[i].crp_p = + kmem_alloc(size, KM_SLEEP); + if (i >= krp->krp_iparams) + continue; + kop[req].crk_status = + copyin(kop[req].crk_param[i].crp_p, + krp->krp_param[i].crp_p, size); + if (kop[req].crk_status) + goto fail; + } + krp->fcrp = fcr; + + kop[req].crk_reqid = atomic_inc_32_nv(&(fcr->requestid)); + krp->krp_reqid = kop[req].crk_reqid; + krp->krp_usropaque = kop[req].crk_opaque; + + kop[req].crk_status = crypto_kdispatch(krp); + if (kop[req].crk_status != 0) { + goto fail; + } + +fail: + if(kop[req].crk_status) { + if (krp) { + kop[req].crk_status = krp->krp_status; + for (i = 0; i < CRK_MAXPARAM; i++) { + struct crparam *kp = + &(krp->krp_param[i]); + if (kp->crp_p) { + size = (kp->crp_nbits + 7) / 8; + KASSERT(size > 0); + memset(kp->crp_p, 0, size); + kmem_free(kp->crp_p, size); + } + } + cv_destroy(&krp->krp_cv); + pool_put(&cryptkop_pool, krp); + } + } + error = 0; + } + DPRINTF(("cryptodev_key: error=0x%08x\n", error)); + return error; +} + +int +cryptodev_session(struct fcrypt *fcr, struct session_op *sop) +{ + struct cryptoini cria, crie; + struct cryptoini cric; /* compressor */ + struct cryptoini *crihead = NULL; + const struct enc_xform *txform = NULL; + const struct auth_hash *thash = NULL; + const struct comp_algo *tcomp = NULL; + struct csession *cse; + u_int64_t sid; + int error = 0; + + DPRINTF(("cryptodev_session() cipher=%d, mac=%d\n", sop->cipher, sop->mac)); + + /* XXX there must be a way to not embed the list of xforms here */ + switch (sop->cipher) { + case 0: + break; + case CRYPTO_DES_CBC: + txform = &enc_xform_des; + break; + case CRYPTO_3DES_CBC: + txform = &enc_xform_3des; + break; + case CRYPTO_BLF_CBC: + txform = &enc_xform_blf; + break; + case CRYPTO_CAST_CBC: + txform = &enc_xform_cast5; + break; + case CRYPTO_SKIPJACK_CBC: + txform = &enc_xform_skipjack; + break; + case CRYPTO_AES_CBC: + txform = &enc_xform_rijndael128; + break; + case CRYPTO_CAMELLIA_CBC: + txform = &enc_xform_camellia; + break; + case CRYPTO_AES_CTR: + txform = &enc_xform_aes_ctr; + break; + case CRYPTO_AES_GCM_16: + txform = &enc_xform_aes_gcm; + break; + case CRYPTO_AES_GMAC: + txform = &enc_xform_aes_gmac; + break; + case CRYPTO_NULL_CBC: + txform = &enc_xform_null; + break; + case CRYPTO_ARC4: + txform = &enc_xform_arc4; + break; + default: + DPRINTF(("Invalid cipher %d\n", sop->cipher)); + return EINVAL; + } + + switch (sop->comp_alg) { + case 0: + break; + case CRYPTO_DEFLATE_COMP: + tcomp = &comp_algo_deflate; + break; + case CRYPTO_GZIP_COMP: + tcomp = &comp_algo_gzip; + DPRINTF(("cryptodev_session() tcomp for GZIP\n")); + break; + default: + DPRINTF(("Invalid compression alg %d\n", sop->comp_alg)); + return EINVAL; + } + + switch (sop->mac) { + case 0: + break; + case CRYPTO_MD5_HMAC: + thash = &auth_hash_hmac_md5; + break; + case CRYPTO_SHA1_HMAC: + thash = &auth_hash_hmac_sha1; + break; + case CRYPTO_MD5_HMAC_96: + thash = &auth_hash_hmac_md5_96; + break; + case CRYPTO_SHA1_HMAC_96: + thash = &auth_hash_hmac_sha1_96; + break; + case CRYPTO_SHA2_HMAC: + /* XXX switching on key length seems questionable */ + if (sop->mackeylen == auth_hash_hmac_sha2_256.keysize) { + thash = &auth_hash_hmac_sha2_256; + } else if (sop->mackeylen == auth_hash_hmac_sha2_384.keysize) { + thash = &auth_hash_hmac_sha2_384; + } else if (sop->mackeylen == auth_hash_hmac_sha2_512.keysize) { + thash = &auth_hash_hmac_sha2_512; + } else { + DPRINTF(("Invalid mackeylen %d\n", sop->mackeylen)); + return EINVAL; + } + break; + case CRYPTO_RIPEMD160_HMAC: + thash = &auth_hash_hmac_ripemd_160; + break; + case CRYPTO_RIPEMD160_HMAC_96: + thash = &auth_hash_hmac_ripemd_160_96; + break; + case CRYPTO_MD5: + thash = &auth_hash_md5; + break; + case CRYPTO_SHA1: + thash = &auth_hash_sha1; + break; + case CRYPTO_AES_XCBC_MAC_96: + thash = &auth_hash_aes_xcbc_mac_96; + break; + case CRYPTO_AES_128_GMAC: + thash = &auth_hash_gmac_aes_128; + break; + case CRYPTO_AES_192_GMAC: + thash = &auth_hash_gmac_aes_192; + break; + case CRYPTO_AES_256_GMAC: + thash = &auth_hash_gmac_aes_256; + break; + case CRYPTO_NULL_HMAC: + thash = &auth_hash_null; + break; + default: + DPRINTF(("Invalid mac %d\n", sop->mac)); + return EINVAL; + } + + memset(&crie, 0, sizeof(crie)); + memset(&cria, 0, sizeof(cria)); + memset(&cric, 0, sizeof(cric)); + + if (tcomp) { + cric.cri_alg = tcomp->type; + cric.cri_klen = 0; + DPRINTF(("tcomp->type = %d\n", tcomp->type)); + + crihead = &cric; + if (txform) { + cric.cri_next = &crie; + } else if (thash) { + cric.cri_next = &cria; + } + } + + if (txform) { + crie.cri_alg = txform->type; + crie.cri_klen = sop->keylen * 8; + if (sop->keylen > txform->maxkey || + sop->keylen < txform->minkey) { + DPRINTF(("keylen %d not in [%d,%d]\n", + sop->keylen, txform->minkey, txform->maxkey)); + error = EINVAL; + goto bail; + } + + crie.cri_key = malloc(crie.cri_klen / 8, M_XDATA, M_WAITOK); + if ((error = copyin(sop->key, crie.cri_key, crie.cri_klen / 8))) + goto bail; + if (!crihead) { + crihead = &crie; + } + if (thash) + crie.cri_next = &cria; + } + + if (thash) { + cria.cri_alg = thash->type; + cria.cri_klen = sop->mackeylen * 8; + if (sop->mackeylen != thash->keysize) { + DPRINTF(("mackeylen %d != keysize %d\n", + sop->mackeylen, thash->keysize)); + error = EINVAL; + goto bail; + } + if (cria.cri_klen) { + cria.cri_key = malloc(cria.cri_klen / 8, M_XDATA, + M_WAITOK); + if ((error = copyin(sop->mackey, cria.cri_key, + cria.cri_klen / 8))) { + goto bail; + } + } + if (!crihead) { + crihead = &cria; + } + } + + error = crypto_newsession(&sid, crihead, crypto_devallowsoft); + if (!error) { + DPRINTF(("cryptodev_session: got session %d\n", (uint32_t)sid)); + cse = csecreate(fcr, sid, crie.cri_key, crie.cri_klen, + cria.cri_key, cria.cri_klen, (txform ? sop->cipher : 0), sop->mac, + (tcomp ? sop->comp_alg : 0), txform, thash, tcomp); + if (cse != NULL) { + sop->ses = cse->ses; + } else { + DPRINTF(("csecreate failed\n")); + crypto_freesession(sid); + error = EINVAL; + } + } else { + DPRINTF(("SIOCSESSION violates kernel parameters %d\n", + error)); + } +bail: + if (error) { + if (crie.cri_key) { + memset(crie.cri_key, 0, crie.cri_klen / 8); + free(crie.cri_key, M_XDATA); + } + if (cria.cri_key) { + memset(cria.cri_key, 0, cria.cri_klen / 8); + free(cria.cri_key, M_XDATA); + } + } + return error; +} + +int +cryptodev_msession(struct fcrypt *fcr, struct session_n_op *sn_ops, + int count) +{ + int i; + + for (i = 0; i < count; i++, sn_ops++) { + struct session_op s_op; + s_op.cipher = sn_ops->cipher; + s_op.mac = sn_ops->mac; + s_op.keylen = sn_ops->keylen; + s_op.key = sn_ops->key; + s_op.mackeylen = sn_ops->mackeylen; + s_op.mackey = sn_ops->mackey; + + sn_ops->status = cryptodev_session(fcr, &s_op); + sn_ops->ses = s_op.ses; + } + + return 0; +} + +static int +cryptodev_msessionfin(struct fcrypt *fcr, int count, u_int32_t *sesid) +{ + struct csession *cse; + int req, error = 0; + + mutex_enter(&crypto_mtx); + for(req = 0; req < count; req++) { + cse = csefind(fcr, sesid[req]); + if (cse == NULL) + continue; + csedelete(fcr, cse); + mutex_exit(&crypto_mtx); + error = csefree(cse); + mutex_enter(&crypto_mtx); + } + mutex_exit(&crypto_mtx); + return error; +} + +/* + * collect as many completed requests as are availble, or count completed + * requests whichever is less. + * return the number of requests. + */ +static int +cryptodev_getmstatus(struct fcrypt *fcr, struct crypt_result *crypt_res, + int count) +{ + struct cryptop *crp = NULL; + struct cryptkop *krp = NULL; + struct csession *cse; + int i, size, req = 0; + int completed=0; + + /* On queue so nobody else can grab them + * and copyout can be delayed-- no locking */ + TAILQ_HEAD(, cryptop) crp_delfree_q = + TAILQ_HEAD_INITIALIZER(crp_delfree_q); + TAILQ_HEAD(, cryptkop) krp_delfree_q = + TAILQ_HEAD_INITIALIZER(krp_delfree_q); + + /* at this point we do not know which response user is requesting for + * (symmetric or asymmetric) so we copyout one from each i.e if the + * count is 2 then 1 from symmetric and 1 from asymmetric queue and + * if 3 then 2 symmetric and 1 asymmetric and so on */ + + /* pull off a list of requests while protected from changes */ + mutex_enter(&crypto_mtx); + while (req < count) { + crp = TAILQ_FIRST(&fcr->crp_ret_mq); + if (crp) { + TAILQ_REMOVE(&fcr->crp_ret_mq, crp, crp_next); + TAILQ_INSERT_TAIL(&crp_delfree_q, crp, crp_next); + cse = (struct csession *)crp->crp_opaque; + + /* see if the session is still valid */ + cse = csefind(fcr, cse->ses); + if (cse != NULL) { + crypt_res[req].status = 0; + } else { + DPRINTF(("csefind failed\n")); + crypt_res[req].status = EINVAL; + } + req++; + } + if(req < count) { + crypt_res[req].status = 0; + krp = TAILQ_FIRST(&fcr->crp_ret_mkq); + if (krp) { + TAILQ_REMOVE(&fcr->crp_ret_mkq, krp, krp_next); + TAILQ_INSERT_TAIL(&krp_delfree_q, krp, krp_next); + req++; + } + } + } + mutex_exit(&crypto_mtx); + + /* now do all the work outside the mutex */ + for(req=0; req < count ;) { + crp = TAILQ_FIRST(&crp_delfree_q); + if (crp) { + if (crypt_res[req].status != 0) { + /* csefind failed during collection */ + goto bail; + } + cse = (struct csession *)crp->crp_opaque; + crypt_res[req].reqid = crp->crp_reqid; + crypt_res[req].opaque = crp->crp_usropaque; + completed++; + + if (crp->crp_etype != 0) { + crypt_res[req].status = crp->crp_etype; + goto bail; + } + + if (cse->error) { + crypt_res[req].status = cse->error; + goto bail; + } + + if (crp->dst && (crypt_res[req].status = + copyout(crp->uio.uio_iov[0].iov_base, crp->dst, + crp->len))) + goto bail; + + if (crp->mac && (crypt_res[req].status = + copyout(crp->crp_mac, crp->mac, + cse->thash->authsize))) + goto bail; + +bail: + TAILQ_REMOVE(&crp_delfree_q, crp, crp_next); + kmem_free(crp->uio.uio_iov[0].iov_base, + crp->uio.uio_iov[0].iov_len); + crypto_freereq(crp); + req++; + } + + if (req < count) { + krp = TAILQ_FIRST(&krp_delfree_q); + if (krp) { + crypt_res[req].reqid = krp->krp_reqid; + crypt_res[req].opaque = krp->krp_usropaque; + completed++; + if (krp->krp_status != 0) { + DPRINTF(("cryptodev_key: " + "krp->krp_status 0x%08x\n", + krp->krp_status)); + crypt_res[req].status = krp->krp_status; + goto fail; + } + + for (i = krp->krp_iparams; i < krp->krp_iparams + + krp->krp_oparams; i++) { + size = (krp->krp_param[i].crp_nbits + + 7) / 8; + if (size == 0) + continue; + crypt_res[req].status = copyout + (krp->krp_param[i].crp_p, + krp->crk_param[i].crp_p, size); + if (crypt_res[req].status) { + DPRINTF(("cryptodev_key: " + "copyout oparam %d failed, " + "error=%d\n", + i - krp->krp_iparams, + crypt_res[req].status)); + goto fail; + } + } +fail: + TAILQ_REMOVE(&krp_delfree_q, krp, krp_next); + /* not sure what to do for this */ + /* kop[req].crk_status = krp->krp_status; */ + for (i = 0; i < CRK_MAXPARAM; i++) { + struct crparam *kp = &(krp->krp_param[i]); + if (kp->crp_p) { + size = (kp->crp_nbits + 7) / 8; + KASSERT(size > 0); + (void)memset(kp->crp_p, 0, size); + kmem_free(kp->crp_p, size); + } + } + cv_destroy(&krp->krp_cv); + pool_put(&cryptkop_pool, krp); + req++; + } + } + } + + return completed; +} + +static int +cryptodev_getstatus (struct fcrypt *fcr, struct crypt_result *crypt_res) +{ + struct cryptop *crp = NULL, *cnext; + struct cryptkop *krp = NULL, *knext; + struct csession *cse; + int i, size, req = 0; + + mutex_enter(&crypto_mtx); + /* Here we dont know for which request the user is requesting the + * response so checking in both the queues */ + TAILQ_FOREACH_SAFE(crp, &fcr->crp_ret_mq, crp_next, cnext) { + if(crp && (crp->crp_reqid == crypt_res->reqid)) { + cse = (struct csession *)crp->crp_opaque; + crypt_res->opaque = crp->crp_usropaque; + cse = csefind(fcr, cse->ses); + if (cse == NULL) { + DPRINTF(("csefind failed\n")); + crypt_res->status = EINVAL; + goto bail; + } + + if (crp->crp_etype != 0) { + crypt_res->status = crp->crp_etype; + goto bail; + } + + if (cse->error) { + crypt_res->status = cse->error; + goto bail; + } + + if (crp->dst && (crypt_res->status = + copyout(crp->uio.uio_iov[0].iov_base, + crp->dst, crp->len))) + goto bail; + + if (crp->mac && (crypt_res->status = + copyout(crp->crp_mac, crp->mac, + cse->thash->authsize))) + goto bail; +bail: + TAILQ_REMOVE(&fcr->crp_ret_mq, crp, crp_next); + + mutex_exit(&crypto_mtx); + crypto_freereq(crp); + return 0; + } + } + + TAILQ_FOREACH_SAFE(krp, &fcr->crp_ret_mkq, krp_next, knext) { + if(krp && (krp->krp_reqid == crypt_res->reqid)) { + crypt_res[req].opaque = krp->krp_usropaque; + if (krp->krp_status != 0) { + DPRINTF(("cryptodev_key: " + "krp->krp_status 0x%08x\n", + krp->krp_status)); + crypt_res[req].status = krp->krp_status; + goto fail; + } + + for (i = krp->krp_iparams; i < krp->krp_iparams + + krp->krp_oparams; i++) { + size = (krp->krp_param[i].crp_nbits + 7) / 8; + if (size == 0) + continue; + crypt_res[req].status = copyout( + krp->krp_param[i].crp_p, + krp->crk_param[i].crp_p, size); + if (crypt_res[req].status) { + DPRINTF(("cryptodev_key: copyout oparam" + "%d failed, error=%d\n", + i - krp->krp_iparams, + crypt_res[req].status)); + goto fail; + } + } +fail: + TAILQ_REMOVE(&fcr->crp_ret_mkq, krp, krp_next); + mutex_exit(&crypto_mtx); + /* not sure what to do for this */ + /* kop[req].crk_status = krp->krp_status; */ + for (i = 0; i < CRK_MAXPARAM; i++) { + struct crparam *kp = &(krp->krp_param[i]); + if (kp->crp_p) { + size = (kp->crp_nbits + 7) / 8; + KASSERT(size > 0); + memset(kp->crp_p, 0, size); + kmem_free(kp->crp_p, size); + } + } + cv_destroy(&krp->krp_cv); + pool_put(&cryptkop_pool, krp); + return 0; + } + } + mutex_exit(&crypto_mtx); + return EINPROGRESS; +} + +static int +cryptof_stat(struct file *fp, struct stat *st) +{ + struct fcrypt *fcr = fp->f_fcrypt; + + (void)memset(st, 0, sizeof(*st)); + + mutex_enter(&crypto_mtx); + st->st_dev = makedev(cdevsw_lookup_major(&crypto_cdevsw), fcr->sesn); + st->st_atimespec = fcr->atime; + st->st_mtimespec = fcr->mtime; + st->st_ctimespec = st->st_birthtimespec = fcr->btime; + st->st_uid = kauth_cred_geteuid(fp->f_cred); + st->st_gid = kauth_cred_getegid(fp->f_cred); + mutex_exit(&crypto_mtx); + + return 0; +} + +static int +cryptof_poll(struct file *fp, int events) +{ + struct fcrypt *fcr = fp->f_fcrypt; + int revents = 0; + + if (!(events & (POLLIN | POLLRDNORM))) { + /* only support read and POLLIN */ + return 0; + } + + mutex_enter(&crypto_mtx); + if (TAILQ_EMPTY(&fcr->crp_ret_mq) && TAILQ_EMPTY(&fcr->crp_ret_mkq)) { + /* no completed requests pending, save the poll for later */ + selrecord(curlwp, &fcr->sinfo); + } else { + /* let the app(s) know that there are completed requests */ + revents = events & (POLLIN | POLLRDNORM); + } + mutex_exit(&crypto_mtx); + + return revents; +} + +/* + * Pseudo-device initialization routine for /dev/crypto + */ +void +cryptoattach(int num) +{ + crypto_init(); + + pool_init(&fcrpl, sizeof(struct fcrypt), 0, 0, 0, "fcrpl", + NULL, IPL_NET); /* XXX IPL_NET ("splcrypto") */ + pool_init(&csepl, sizeof(struct csession), 0, 0, 0, "csepl", + NULL, IPL_NET); /* XXX IPL_NET ("splcrypto") */ + + /* + * Preallocate space for 64 users, with 5 sessions each. + * (consider that a TLS protocol session requires at least + * 3DES, MD5, and SHA1 (both hashes are used in the PRF) for + * the negotiation, plus HMAC_SHA1 for the actual SSL records, + * consuming one session here for each algorithm. + */ + pool_prime(&fcrpl, 64); + pool_prime(&csepl, 64 * 5); +} + +void crypto_attach(device_t, device_t, void *); + +void +crypto_attach(device_t parent, device_t self, void * opaque) +{ + + cryptoattach(0); +} + +int crypto_detach(device_t, int); + +int +crypto_detach(device_t self, int num) +{ + + pool_destroy(&fcrpl); + pool_destroy(&csepl); + + return 0; +} + +int crypto_match(device_t, cfdata_t, void *); + +int +crypto_match(device_t parent, cfdata_t data, void *opaque) +{ + + return 1; +} + +MODULE(MODULE_CLASS_DRIVER, crypto, "opencrypto"); + +CFDRIVER_DECL(crypto, DV_DULL, NULL); + +CFATTACH_DECL2_NEW(crypto, 0, crypto_match, crypto_attach, crypto_detach, + NULL, NULL, NULL); + +#ifdef _MODULE +static int cryptoloc[] = { -1, -1 }; + +static struct cfdata crypto_cfdata[] = { + { + .cf_name = "crypto", + .cf_atname = "crypto", + .cf_unit = 0, + .cf_fstate = 0, + .cf_loc = cryptoloc, + .cf_flags = 0, + .cf_pspec = NULL, + }, + { NULL, NULL, 0, 0, NULL, 0, NULL } +}; +#endif + +static int +crypto_modcmd(modcmd_t cmd, void *arg) +{ + int error = 0; +#ifdef _MODULE + devmajor_t cmajor = NODEVMAJOR, bmajor = NODEVMAJOR; +#endif + + switch (cmd) { + case MODULE_CMD_INIT: +#ifdef _MODULE + + error = config_cfdriver_attach(&crypto_cd); + if (error) { + return error; + } + + error = config_cfattach_attach(crypto_cd.cd_name, &crypto_ca); + if (error) { + config_cfdriver_detach(&crypto_cd); + aprint_error("%s: unable to register cfattach\n", + crypto_cd.cd_name); + + return error; + } + + error = config_cfdata_attach(crypto_cfdata, 1); + if (error) { + config_cfattach_detach(crypto_cd.cd_name, &crypto_ca); + config_cfdriver_detach(&crypto_cd); + aprint_error("%s: unable to register cfdata\n", + crypto_cd.cd_name); + + return error; + } + + error = devsw_attach(crypto_cd.cd_name, NULL, &bmajor, + &crypto_cdevsw, &cmajor); + if (error) { + error = config_cfdata_detach(crypto_cfdata); + if (error) { + return error; + } + config_cfattach_detach(crypto_cd.cd_name, &crypto_ca); + config_cfdriver_detach(&crypto_cd); + aprint_error("%s: unable to register devsw\n", + crypto_cd.cd_name); + + return error; + } + + (void)config_attach_pseudo(crypto_cfdata); +#endif + + return error; + case MODULE_CMD_FINI: +#ifdef _MODULE + error = config_cfdata_detach(crypto_cfdata); + if (error) { + return error; + } + + config_cfattach_detach(crypto_cd.cd_name, &crypto_ca); + config_cfdriver_detach(&crypto_cd); + devsw_detach(NULL, &crypto_cdevsw); +#endif + + return error; +#ifdef _MODULE + case MODULE_CMD_AUTOUNLOAD: +#if 0 /* + * XXX Completely disable auto-unload for now, since there is still + * XXX a (small) window where in-module ref-counting doesn't help + */ + if (crypto_refcount != 0) +#endif + return EBUSY; + /* FALLTHROUGH */ +#endif + default: + return ENOTTY; + } +} diff --git a/sys/opencrypto/cryptodev.h b/sys/opencrypto/cryptodev.h new file mode 100644 index 000000000..1a017506c --- /dev/null +++ b/sys/opencrypto/cryptodev.h @@ -0,0 +1,658 @@ +/* $NetBSD: cryptodev.h,v 1.25 2011/06/09 14:41:24 drochner Exp $ */ +/* $FreeBSD: src/sys/opencrypto/cryptodev.h,v 1.2.2.6 2003/07/02 17:04:50 sam Exp $ */ +/* $OpenBSD: cryptodev.h,v 1.33 2002/07/17 23:52:39 art Exp $ */ + +/*- + * Copyright (c) 2008 The NetBSD Foundation, Inc. + * All rights reserved. + * + * This code is derived from software contributed to The NetBSD Foundation + * by Coyote Point Systems, Inc. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the above copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * + * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS + * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED + * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR + * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS + * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR + * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF + * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS + * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN + * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) + * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE + * POSSIBILITY OF SUCH DAMAGE. + */ + +/* + * The author of this code is Angelos D. Keromytis (angelos@cis.upenn.edu) + * + * This code was written by Angelos D. Keromytis in Athens, Greece, in + * February 2000. Network Security Technologies Inc. (NSTI) kindly + * supported the development of this code. + * + * Copyright (c) 2000 Angelos D. Keromytis + * + * Permission to use, copy, and modify this software with or without fee + * is hereby granted, provided that this entire notice is included in + * all source code copies of any software which is or includes a copy or + * modification of this software. + * + * THIS SOFTWARE IS BEING PROVIDED "AS IS", WITHOUT ANY EXPRESS OR + * IMPLIED WARRANTY. IN PARTICULAR, NONE OF THE AUTHORS MAKES ANY + * REPRESENTATION OR WARRANTY OF ANY KIND CONCERNING THE + * MERCHANTABILITY OF THIS SOFTWARE OR ITS FITNESS FOR ANY PARTICULAR + * PURPOSE. + * + * Copyright (c) 2001 Theo de Raadt + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * + * 1. Redistributions of source code must retain the above copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * 3. The name of the author may not be used to endorse or promote products + * derived from this software without specific prior written permission. + * + * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR + * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES + * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. + * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, + * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT + * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, + * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY + * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT + * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF + * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + * + * Effort sponsored in part by the Defense Advanced Research Projects + * Agency (DARPA) and Air Force Research Laboratory, Air Force + * Materiel Command, USAF, under agreement number F30602-01-2-0537. + * + */ + +#ifndef _CRYPTO_CRYPTO_H_ +#define _CRYPTO_CRYPTO_H_ + +#include +#include + +/* Some initial values */ +#define CRYPTO_DRIVERS_INITIAL 4 +#define CRYPTO_SW_SESSIONS 32 + +/* HMAC values */ +#define HMAC_BLOCK_LEN 64 /* for compatibility */ +#define HMAC_IPAD_VAL 0x36 +#define HMAC_OPAD_VAL 0x5C + +/* Encryption algorithm block sizes */ +#define DES_BLOCK_LEN 8 +#define DES3_BLOCK_LEN 8 +#define BLOWFISH_BLOCK_LEN 8 +#define SKIPJACK_BLOCK_LEN 8 +#define CAST128_BLOCK_LEN 8 +#define RIJNDAEL128_BLOCK_LEN 16 +#define EALG_MAX_BLOCK_LEN 16 /* Keep this updated */ + +/* Maximum hash algorithm result length */ +#define AALG_MAX_RESULT_LEN 64 /* Keep this updated */ + +#define CRYPTO_ALGORITHM_MIN 1 +#define CRYPTO_DES_CBC 1 +#define CRYPTO_3DES_CBC 2 +#define CRYPTO_BLF_CBC 3 +#define CRYPTO_CAST_CBC 4 +#define CRYPTO_SKIPJACK_CBC 5 +#define CRYPTO_MD5_HMAC 6 +#define CRYPTO_SHA1_HMAC 7 +#define CRYPTO_RIPEMD160_HMAC 8 +#define CRYPTO_MD5_KPDK 9 +#define CRYPTO_SHA1_KPDK 10 +#define CRYPTO_RIJNDAEL128_CBC 11 /* 128 bit blocksize */ +#define CRYPTO_AES_CBC 11 /* 128 bit blocksize -- the same as above */ +#define CRYPTO_ARC4 12 +#define CRYPTO_MD5 13 +#define CRYPTO_SHA1 14 +#define CRYPTO_SHA2_256_HMAC 15 +#define CRYPTO_SHA2_HMAC CRYPTO_SHA2_256_HMAC /* for compatibility */ +#define CRYPTO_NULL_HMAC 16 +#define CRYPTO_NULL_CBC 17 +#define CRYPTO_DEFLATE_COMP 18 /* Deflate compression algorithm */ +#define CRYPTO_MD5_HMAC_96 19 +#define CRYPTO_SHA1_HMAC_96 20 +#define CRYPTO_RIPEMD160_HMAC_96 21 +#define CRYPTO_GZIP_COMP 22 /* gzip compression algorithm */ +#define CRYPTO_DEFLATE_COMP_NOGROW 23 /* Deflate, fail if not compressible */ +#define CRYPTO_SHA2_384_HMAC 24 +#define CRYPTO_SHA2_512_HMAC 25 +#define CRYPTO_CAMELLIA_CBC 26 +#define CRYPTO_AES_CTR 27 +#define CRYPTO_AES_XCBC_MAC_96 28 +#define CRYPTO_AES_GCM_16 29 +#define CRYPTO_AES_128_GMAC 30 +#define CRYPTO_AES_192_GMAC 31 +#define CRYPTO_AES_256_GMAC 32 +#define CRYPTO_AES_GMAC 33 +#define CRYPTO_ALGORITHM_MAX 33 /* Keep updated - see below */ + +/* Algorithm flags */ +#define CRYPTO_ALG_FLAG_SUPPORTED 0x01 /* Algorithm is supported */ +#define CRYPTO_ALG_FLAG_RNG_ENABLE 0x02 /* Has HW RNG for DH/DSA */ +#define CRYPTO_ALG_FLAG_DSA_SHA 0x04 /* Can do SHA on msg */ + +struct session_op { + u_int32_t cipher; /* ie. CRYPTO_DES_CBC */ + u_int32_t mac; /* ie. CRYPTO_MD5_HMAC */ + u_int32_t comp_alg; /* ie. CRYPTO_GZIP_COMP */ + + u_int32_t keylen; /* cipher key */ + void * key; + int mackeylen; /* mac key */ + void * mackey; + + u_int32_t ses; /* returns: session # */ +}; + +/* to support multiple session creation */ + +struct session_n_op { + u_int32_t cipher; /* ie. CRYPTO_DES_CBC */ + u_int32_t mac; /* ie. CRYPTO_MD5_HMAC */ + u_int32_t comp_alg; /* ie. CRYPTO_GZIP_COMP */ + + u_int32_t keylen; /* cipher key */ + void * key; + int mackeylen; /* mac key */ + void * mackey; + + u_int32_t ses; /* returns: session # */ + int status; +}; + +struct crypt_op { + u_int32_t ses; + u_int16_t op; /* i.e. COP_ENCRYPT */ +#define COP_ENCRYPT 1 +#define COP_DECRYPT 2 +#define COP_COMP 3 +#define COP_DECOMP 4 + u_int16_t flags; +#define COP_F_BATCH 0x0008 /* Dispatch as quickly as possible */ + u_int len; /* src len */ + void * src, *dst; /* become iov[] inside kernel */ + void * mac; /* must be big enough for chosen MAC */ + void * iv; + u_int dst_len; /* dst len if not 0 */ +}; + +/* to support multiple session creation */ +/* + * + * The reqid field is filled when the operation has + * been accepted and started, and can be used to later retrieve + * the operation results via CIOCNCRYPTRET or identify the + * request in the completion list returned by CIOCNCRYPTRETM. + * + * The opaque pointer can be set arbitrarily by the user + * and it is passed back in the crypt_result structure + * when the request completes. This field can be used for example + * to track context for the request and avoid lookups in the + * user application. + */ + +struct crypt_n_op { + u_int32_t ses; + u_int16_t op; /* i.e. COP_ENCRYPT */ +#define COP_ENCRYPT 1 +#define COP_DECRYPT 2 + u_int16_t flags; +#define COP_F_BATCH 0x0008 /* Dispatch as quickly as possible */ +#define COP_F_MORE 0x0010 /* more data to follow */ + u_int len; /* src len */ + + u_int32_t reqid; /* request id */ + int status; /* status of request -accepted or not */ + void *opaque; /* opaque pointer returned to user */ + u_int32_t keylen; /* cipher key - optional */ + void * key; + u_int32_t mackeylen; /* also optional */ + void * mackey; + + void * src, *dst; /* become iov[] inside kernel */ + void * mac; /* must be big enough for chosen MAC */ + void * iv; + u_int dst_len; /* dst len if not 0 */ +}; + +/* CIOCNCRYPTM ioctl argument, supporting one or more asynchronous + * crypt_n_op operations. + * Each crypt_n_op will receive a request id which can be used to check its + * status via CIOCNCRYPTRET, or to watch for its completion in the list + * obtained via CIOCNCRYPTRETM. + */ +struct crypt_mop { + size_t count; /* how many */ + struct crypt_n_op * reqs; /* where to get them */ +}; + +struct crypt_sfop { + size_t count; + u_int32_t *sesid; +}; + +struct crypt_sgop { + size_t count; + struct session_n_op * sessions; +}; + +#define CRYPTO_MAX_MAC_LEN 20 + +/* bignum parameter, in packed bytes, ... */ +struct crparam { + void * crp_p; + u_int crp_nbits; +}; + +#define CRK_MAXPARAM 8 + +struct crypt_kop { + u_int crk_op; /* ie. CRK_MOD_EXP or other */ + u_int crk_status; /* return status */ + u_short crk_iparams; /* # of input parameters */ + u_short crk_oparams; /* # of output parameters */ + u_int crk_pad1; + struct crparam crk_param[CRK_MAXPARAM]; +}; + +/* + * Used with the CIOCNFKEYM ioctl. + * + * This structure allows the OCF to return a request id + * for each of the kop operations specified in the CIOCNFKEYM call. + * + * The crk_opaque pointer can be arbitrarily set by the user + * and it is passed back in the crypt_result structure + * when the request completes. This field can be used for example + * to track context for the request and avoid lookups in the + * user application. + */ +struct crypt_n_kop { + u_int crk_op; /* ie. CRK_MOD_EXP or other */ + u_int crk_status; /* return status */ + u_short crk_iparams; /* # of input parameters */ + u_short crk_oparams; /* # of output parameters */ + u_int32_t crk_reqid; /* request id */ + struct crparam crk_param[CRK_MAXPARAM]; + void *crk_opaque; /* opaque pointer returned to user */ +}; + +struct crypt_mkop { + size_t count; /* how many */ + struct crypt_n_kop * reqs; /* where to get them */ +}; + +/* Asynchronous key or crypto result. + * Note that the status will be set in the crypt_result structure, + * not in the original crypt_kop structure (crk_status). + */ +struct crypt_result { + u_int32_t reqid; /* request id */ + u_int32_t status; /* status of request: 0 if successful */ + void * opaque; /* Opaque pointer from the user, passed along */ +}; + +struct cryptret { + size_t count; /* space for how many */ + struct crypt_result * results; /* where to put them */ +}; + + +/* Assymetric key operations */ +#define CRK_ALGORITM_MIN 0 +#define CRK_MOD_EXP 0 +#define CRK_MOD_EXP_CRT 1 +#define CRK_DSA_SIGN 2 +#define CRK_DSA_VERIFY 3 +#define CRK_DH_COMPUTE_KEY 4 +#define CRK_MOD_ADD 5 +#define CRK_MOD_ADDINV 6 +#define CRK_MOD_SUB 7 +#define CRK_MOD_MULT 8 +#define CRK_MOD_MULTINV 9 +#define CRK_MOD 10 +#define CRK_ALGORITHM_MAX 10 /* Keep updated - see below */ + +#define CRF_MOD_EXP (1 << CRK_MOD_EXP) +#define CRF_MOD_EXP_CRT (1 << CRK_MOD_EXP_CRT) +#define CRF_DSA_SIGN (1 << CRK_DSA_SIGN) +#define CRF_DSA_VERIFY (1 << CRK_DSA_VERIFY) +#define CRF_DH_COMPUTE_KEY (1 << CRK_DH_COMPUTE_KEY) +#define CRF_MOD_ADD (1 << CRK_MOD_ADD) +#define CRF_MOD_ADDINV (1 << CRK_MOD_ADDINV) +#define CRF_MOD_SUB (1 << CRK_MOD_SUB) +#define CRF_MOD_MULT (1 << CRK_MOD_MULT) +#define CRF_MOD_MULTINV (1 << CRK_MOD_MULTINV) +#define CRF_MOD (1 << CRK_MOD) + +/* + * A large comment here once held descriptions of the ioctl + * requests implemented by the device. This text has been moved + * to the crypto(4) manual page and, later, removed from this file + * as it was always a step behind the times. + */ + +/* + * done against open of /dev/crypto, to get a cloned descriptor. + * Please use F_SETFD against the cloned descriptor. But this ioctl + * is obsolete (the device now clones): please, just don't use it. + */ +#define CRIOGET _IOWR('c', 100, u_int32_t) + +/* the following are done against the cloned descriptor */ +#define CIOCFSESSION _IOW('c', 102, u_int32_t) +#define CIOCKEY _IOWR('c', 104, struct crypt_kop) +#define CIOCNFKEYM _IOWR('c', 108, struct crypt_mkop) +#define CIOCNFSESSION _IOW('c', 109, struct crypt_sfop) +#define CIOCNCRYPTRETM _IOWR('c', 110, struct cryptret) +#define CIOCNCRYPTRET _IOWR('c', 111, struct crypt_result) + +#define CIOCGSESSION _IOWR('c', 112, struct session_op) +#define CIOCNGSESSION _IOWR('c', 113, struct crypt_sgop) +#define CIOCCRYPT _IOWR('c', 114, struct crypt_op) +#define CIOCNCRYPTM _IOWR('c', 115, struct crypt_mop) + +#define CIOCASYMFEAT _IOR('c', 105, u_int32_t) + +struct cryptotstat { + struct timespec acc; /* total accumulated time */ + struct timespec min; /* max time */ + struct timespec max; /* max time */ + u_int32_t count; /* number of observations */ +}; + +struct cryptostats { + u_int32_t cs_ops; /* symmetric crypto ops submitted */ + u_int32_t cs_errs; /* symmetric crypto ops that failed */ + u_int32_t cs_kops; /* asymetric/key ops submitted */ + u_int32_t cs_kerrs; /* asymetric/key ops that failed */ + u_int32_t cs_intrs; /* crypto swi thread activations */ + u_int32_t cs_rets; /* crypto return thread activations */ + u_int32_t cs_blocks; /* symmetric op driver block */ + u_int32_t cs_kblocks; /* symmetric op driver block */ + /* + * When CRYPTO_TIMING is defined at compile time and the + * sysctl debug.crypto is set to 1, the crypto system will + * accumulate statistics about how long it takes to process + * crypto requests at various points during processing. + */ + struct cryptotstat cs_invoke; /* crypto_dipsatch -> crypto_invoke */ + struct cryptotstat cs_done; /* crypto_invoke -> crypto_done */ + struct cryptotstat cs_cb; /* crypto_done -> callback */ + struct cryptotstat cs_finis; /* callback -> callback return */ +}; + +#ifdef _KERNEL +/* Standard initialization structure beginning */ +struct cryptoini { + int cri_alg; /* Algorithm to use */ + int cri_klen; /* Key length, in bits */ + int cri_rnd; /* Algorithm rounds, where relevant */ + char *cri_key; /* key to use */ + u_int8_t cri_iv[EALG_MAX_BLOCK_LEN]; /* IV to use */ + struct cryptoini *cri_next; +}; + +/* Describe boundaries of a single crypto operation */ +struct cryptodesc { + int crd_skip; /* How many bytes to ignore from start */ + int crd_len; /* How many bytes to process */ + int crd_inject; /* Where to inject results, if applicable */ + int crd_flags; + +#define CRD_F_ENCRYPT 0x01 /* Set when doing encryption */ +#define CRD_F_IV_PRESENT 0x02 /* When encrypting, IV is already in + place, so don't copy. */ +#define CRD_F_IV_EXPLICIT 0x04 /* IV explicitly provided */ +#define CRD_F_DSA_SHA_NEEDED 0x08 /* Compute SHA-1 of buffer for DSA */ +#define CRD_F_COMP 0x10 /* Set when doing compression */ + + struct cryptoini CRD_INI; /* Initialization/context data */ +#define crd_iv CRD_INI.cri_iv +#define crd_key CRD_INI.cri_key +#define crd_rnd CRD_INI.cri_rnd +#define crd_alg CRD_INI.cri_alg +#define crd_klen CRD_INI.cri_klen + + struct cryptodesc *crd_next; +}; + +/* Structure describing complete operation */ +struct cryptop { + TAILQ_ENTRY(cryptop) crp_next; + u_int64_t crp_sid; /* Session ID */ + + int crp_ilen; /* Input data total length */ + int crp_olen; /* Result total length */ + + int crp_etype; /* + * Error type (zero means no error). + * All error codes except EAGAIN + * indicate possible data corruption (as in, + * the data have been touched). On all + * errors, the crp_sid may have changed + * (reset to a new one), so the caller + * should always check and use the new + * value on future requests. + */ + int crp_flags; /* Note: must hold mutext to modify */ + +#define CRYPTO_F_IMBUF 0x0001 /* Input/output are mbuf chains */ +#define CRYPTO_F_IOV 0x0002 /* Input/output are uio */ +#define CRYPTO_F_REL 0x0004 /* Must return data in same place */ +#define CRYPTO_F_BATCH 0x0008 /* Batch op if possible possible */ +#define CRYPTO_F_CBIMM 0x0010 /* Do callback immediately */ +#define CRYPTO_F_DONE 0x0020 /* Operation completed */ +#define CRYPTO_F_CBIFSYNC 0x0040 /* Do CBIMM if op is synchronous */ +#define CRYPTO_F_ONRETQ 0x0080 /* Request is on return queue */ +#define CRYPTO_F_USER 0x0100 /* Request is in user context */ +#define CRYPTO_F_MORE 0x0200 /* more data to follow */ + + void * crp_buf; /* Data to be processed */ + void * crp_opaque; /* Opaque pointer, passed along */ + struct cryptodesc *crp_desc; /* Linked list of processing descriptors */ + + int (*crp_callback)(struct cryptop *); /* Callback function */ + + void * crp_mac; + + /* + * everything below is private to crypto(4) + */ + u_int32_t crp_reqid; /* request id */ + void * crp_usropaque; /* Opaque pointer from user, passed along */ + struct timespec crp_tstamp; /* performance time stamp */ + kcondvar_t crp_cv; + struct fcrypt *fcrp; + void * dst; + void * mac; + u_int len; + u_char tmp_iv[EALG_MAX_BLOCK_LEN]; + u_char tmp_mac[CRYPTO_MAX_MAC_LEN]; + + struct iovec iovec[1]; + struct uio uio; + uint32_t magic; +}; + +#define CRYPTO_BUF_CONTIG 0x0 +#define CRYPTO_BUF_IOV 0x1 +#define CRYPTO_BUF_MBUF 0x2 + +#define CRYPTO_OP_DECRYPT 0x0 +#define CRYPTO_OP_ENCRYPT 0x1 + +/* + * Hints passed to process methods. + */ +#define CRYPTO_HINT_MORE 0x1 /* more ops coming shortly */ + +struct cryptkop { + TAILQ_ENTRY(cryptkop) krp_next; + + u_int32_t krp_reqid; /* request id */ + void * krp_usropaque; /* Opaque pointer from user, passed along */ + + u_int krp_op; /* ie. CRK_MOD_EXP or other */ + u_int krp_status; /* return status */ + u_short krp_iparams; /* # of input parameters */ + u_short krp_oparams; /* # of output parameters */ + u_int32_t krp_hid; + struct crparam krp_param[CRK_MAXPARAM]; /* kvm */ + int (*krp_callback)(struct cryptkop *); + int krp_flags; /* same values as crp_flags */ + kcondvar_t krp_cv; + struct fcrypt *fcrp; + struct crparam crk_param[CRK_MAXPARAM]; +}; + +/* Crypto capabilities structure */ +struct cryptocap { + u_int32_t cc_sessions; + + /* + * Largest possible operator length (in bits) for each type of + * encryption algorithm. + */ + u_int16_t cc_max_op_len[CRYPTO_ALGORITHM_MAX + 1]; + + u_int8_t cc_alg[CRYPTO_ALGORITHM_MAX + 1]; + + u_int8_t cc_kalg[CRK_ALGORITHM_MAX + 1]; + + u_int8_t cc_flags; + u_int8_t cc_qblocked; /* symmetric q blocked */ + u_int8_t cc_kqblocked; /* asymmetric q blocked */ +#define CRYPTOCAP_F_CLEANUP 0x01 /* needs resource cleanup */ +#define CRYPTOCAP_F_SOFTWARE 0x02 /* software implementation */ +#define CRYPTOCAP_F_SYNC 0x04 /* operates synchronously */ + + void *cc_arg; /* callback argument */ + int (*cc_newsession)(void*, u_int32_t*, struct cryptoini*); + int (*cc_process) (void*, struct cryptop *, int); + int (*cc_freesession) (void*, u_int64_t); + void *cc_karg; /* callback argument */ + int (*cc_kprocess) (void*, struct cryptkop *, int); +}; + +/* + * Session ids are 64 bits. The lower 32 bits contain a "local id" which + * is a driver-private session identifier. The upper 32 bits contain a + * "hardware id" used by the core crypto code to identify the driver and + * a copy of the driver's capabilities that can be used by client code to + * optimize operation. + */ +#define CRYPTO_SESID2HID(_sid) (((_sid) >> 32) & 0xffffff) +#define CRYPTO_SESID2CAPS(_sid) (((_sid) >> 56) & 0xff) +#define CRYPTO_SESID2LID(_sid) (((u_int32_t) (_sid)) & 0xffffffff) + +MALLOC_DECLARE(M_CRYPTO_DATA); + +extern int crypto_newsession(u_int64_t *sid, struct cryptoini *cri, int hard); +extern int crypto_freesession(u_int64_t sid); +extern int32_t crypto_get_driverid(u_int32_t flags); +extern int crypto_register(u_int32_t driverid, int alg, u_int16_t maxoplen, + u_int32_t flags, + int (*newses)(void*, u_int32_t*, struct cryptoini*), + int (*freeses)(void*, u_int64_t), + int (*process)(void*, struct cryptop *, int), + void *arg); +extern int crypto_kregister(u_int32_t, int, u_int32_t, + int (*)(void*, struct cryptkop *, int), + void *arg); +extern int crypto_unregister(u_int32_t driverid, int alg); +extern int crypto_unregister_all(u_int32_t driverid); +extern int crypto_dispatch(struct cryptop *crp); +extern int crypto_kdispatch(struct cryptkop *); +#define CRYPTO_SYMQ 0x1 +#define CRYPTO_ASYMQ 0x2 +extern int crypto_unblock(u_int32_t, int); +extern void crypto_done(struct cryptop *crp); +extern void crypto_kdone(struct cryptkop *); +extern int crypto_getfeat(int *); + +void cuio_copydata(struct uio *, int, int, void *); +void cuio_copyback(struct uio *, int, int, void *); +int cuio_apply(struct uio *, int, int, + int (*f)(void *, void *, unsigned int), void *); + +extern int crypto_ret_q_remove(struct cryptop *); +extern int crypto_ret_kq_remove(struct cryptkop *); +extern void crypto_freereq(struct cryptop *crp); +extern struct cryptop *crypto_getreq(int num); + +extern int crypto_usercrypto; /* userland may do crypto requests */ +extern int crypto_userasymcrypto; /* userland may do asym crypto reqs */ +extern int crypto_devallowsoft; /* only use hardware crypto */ + +/* + * Asymmetric operations are allocated in cryptodev.c but can be + * freed in crypto.c. + */ +extern struct pool cryptkop_pool; + +/* + * Mutual exclusion and its unwelcome friends. + */ + +extern kmutex_t crypto_mtx; + +/* + * initialize the crypto framework subsystem (not the pseudo-device). + * This must be called very early in boot, so the framework is ready + * to handle registration requests when crpto hardware is autoconfigured. + * (This declaration doesnt really belong here but there's no header + * for the raw framework.) + */ +void crypto_init(void); + +/* + * Crypto-related utility routines used mainly by drivers. + * + * XXX these don't really belong here; but for now they're + * kept apart from the rest of the system. + */ +struct uio; +extern void cuio_copydata(struct uio* uio, int off, int len, void *cp); +extern void cuio_copyback(struct uio* uio, int off, int len, void *cp); +extern int cuio_getptr(struct uio *, int loc, int *off); + +#ifdef CRYPTO_DEBUG /* yuck, netipsec defines these differently */ +#ifndef DPRINTF +#define DPRINTF(a) uprintf a +#endif +#ifndef DCPRINTF +#define DCPRINTF(a) printf a +#endif +#else +#ifndef DPRINTF +#define DPRINTF(a) +#endif +#ifndef DCPRINTF +#define DCPRINTF(a) +#endif +#endif + +#endif /* _KERNEL */ +#endif /* _CRYPTO_CRYPTO_H_ */ diff --git a/sys/opencrypto/cryptodev_internal.h b/sys/opencrypto/cryptodev_internal.h new file mode 100644 index 000000000..a4c438a9e --- /dev/null +++ b/sys/opencrypto/cryptodev_internal.h @@ -0,0 +1,10 @@ +/* $NetBSD: cryptodev_internal.h,v 1.1 2011/02/19 16:26:34 drochner Exp $ */ + +/* exported to compat code, not for consumers */ + +struct csession; +int cryptodev_op(struct csession *, struct crypt_op *, struct lwp *); +int cryptodev_mop(struct fcrypt *, struct crypt_n_op *, int, struct lwp *); +int cryptodev_session(struct fcrypt *, struct session_op *); +int cryptodev_msession(struct fcrypt *, struct session_n_op *, int); +struct csession *cryptodev_csefind(struct fcrypt *fcr, u_int ses); diff --git a/sys/opencrypto/cryptosoft.c b/sys/opencrypto/cryptosoft.c new file mode 100644 index 000000000..06ccc30c1 --- /dev/null +++ b/sys/opencrypto/cryptosoft.c @@ -0,0 +1,1434 @@ +/* $NetBSD: cryptosoft.c,v 1.47 2015/08/20 14:40:19 christos Exp $ */ +/* $FreeBSD: src/sys/opencrypto/cryptosoft.c,v 1.2.2.1 2002/11/21 23:34:23 sam Exp $ */ +/* $OpenBSD: cryptosoft.c,v 1.35 2002/04/26 08:43:50 deraadt Exp $ */ + +/* + * The author of this code is Angelos D. Keromytis (angelos@cis.upenn.edu) + * + * This code was written by Angelos D. Keromytis in Athens, Greece, in + * February 2000. Network Security Technologies Inc. (NSTI) kindly + * supported the development of this code. + * + * Copyright (c) 2000, 2001 Angelos D. Keromytis + * + * Permission to use, copy, and modify this software with or without fee + * is hereby granted, provided that this entire notice is included in + * all source code copies of any software which is or includes a copy or + * modification of this software. + * + * THIS SOFTWARE IS BEING PROVIDED "AS IS", WITHOUT ANY EXPRESS OR + * IMPLIED WARRANTY. IN PARTICULAR, NONE OF THE AUTHORS MAKES ANY + * REPRESENTATION OR WARRANTY OF ANY KIND CONCERNING THE + * MERCHANTABILITY OF THIS SOFTWARE OR ITS FITNESS FOR ANY PARTICULAR + * PURPOSE. + */ + +#include +__KERNEL_RCSID(0, "$NetBSD: cryptosoft.c,v 1.47 2015/08/20 14:40:19 christos Exp $"); + +#include +#include +#include +#include +#include +#include +#include +#include +#include + +#ifdef _KERNEL_OPT +#include "opt_ocf.h" +#endif + +#include +#include +#include + +#include + +#include "ioconf.h" + +union authctx { + MD5_CTX md5ctx; + SHA1_CTX sha1ctx; + RMD160_CTX rmd160ctx; + SHA256_CTX sha256ctx; + SHA384_CTX sha384ctx; + SHA512_CTX sha512ctx; + aesxcbc_ctx aesxcbcctx; + AES_GMAC_CTX aesgmacctx; +}; + +struct swcr_data **swcr_sessions = NULL; +u_int32_t swcr_sesnum = 0; +int32_t swcr_id = -1; + +#define COPYBACK(x, a, b, c, d) \ + (x) == CRYPTO_BUF_MBUF ? m_copyback((struct mbuf *)a,b,c,d) \ + : cuio_copyback((struct uio *)a,b,c,d) +#define COPYDATA(x, a, b, c, d) \ + (x) == CRYPTO_BUF_MBUF ? m_copydata((struct mbuf *)a,b,c,d) \ + : cuio_copydata((struct uio *)a,b,c,d) + +static int swcr_encdec(struct cryptodesc *, const struct swcr_data *, void *, int); +static int swcr_compdec(struct cryptodesc *, const struct swcr_data *, void *, int, int *); +static int swcr_combined(struct cryptop *, int); +static int swcr_process(void *, struct cryptop *, int); +static int swcr_newsession(void *, u_int32_t *, struct cryptoini *); +static int swcr_freesession(void *, u_int64_t); + +/* + * Apply a symmetric encryption/decryption algorithm. + */ +static int +swcr_encdec(struct cryptodesc *crd, const struct swcr_data *sw, void *bufv, + int outtype) +{ + char *buf = bufv; + unsigned char iv[EALG_MAX_BLOCK_LEN], blk[EALG_MAX_BLOCK_LEN], *idat; + unsigned char *ivp, piv[EALG_MAX_BLOCK_LEN]; + const struct swcr_enc_xform *exf; + int i, k, j, blks, ivlen; + int count, ind; + + exf = sw->sw_exf; + blks = exf->enc_xform->blocksize; + ivlen = exf->enc_xform->ivsize; + KASSERT(exf->reinit ? ivlen <= blks : ivlen == blks); + + /* Check for non-padded data */ + if (crd->crd_len % blks) + return EINVAL; + + /* Initialize the IV */ + if (crd->crd_flags & CRD_F_ENCRYPT) { + /* IV explicitly provided ? */ + if (crd->crd_flags & CRD_F_IV_EXPLICIT) { + memcpy(iv, crd->crd_iv, ivlen); + if (exf->reinit) + exf->reinit(sw->sw_kschedule, iv, 0); + } else if (exf->reinit) { + exf->reinit(sw->sw_kschedule, 0, iv); + } else { + /* Get random IV */ + for (i = 0; + i + sizeof (u_int32_t) <= EALG_MAX_BLOCK_LEN; + i += sizeof (u_int32_t)) { + u_int32_t temp = cprng_fast32(); + + memcpy(iv + i, &temp, sizeof(u_int32_t)); + } + /* + * What if the block size is not a multiple + * of sizeof (u_int32_t), which is the size of + * what arc4random() returns ? + */ + if (EALG_MAX_BLOCK_LEN % sizeof (u_int32_t) != 0) { + u_int32_t temp = cprng_fast32(); + + bcopy (&temp, iv + i, + EALG_MAX_BLOCK_LEN - i); + } + } + + /* Do we need to write the IV */ + if (!(crd->crd_flags & CRD_F_IV_PRESENT)) { + COPYBACK(outtype, buf, crd->crd_inject, ivlen, iv); + } + + } else { /* Decryption */ + /* IV explicitly provided ? */ + if (crd->crd_flags & CRD_F_IV_EXPLICIT) + memcpy(iv, crd->crd_iv, ivlen); + else { + /* Get IV off buf */ + COPYDATA(outtype, buf, crd->crd_inject, ivlen, iv); + } + if (exf->reinit) + exf->reinit(sw->sw_kschedule, iv, 0); + } + + ivp = iv; + + if (outtype == CRYPTO_BUF_CONTIG) { + if (exf->reinit) { + for (i = crd->crd_skip; + i < crd->crd_skip + crd->crd_len; i += blks) { + if (crd->crd_flags & CRD_F_ENCRYPT) { + exf->encrypt(sw->sw_kschedule, buf + i); + } else { + exf->decrypt(sw->sw_kschedule, buf + i); + } + } + } else if (crd->crd_flags & CRD_F_ENCRYPT) { + for (i = crd->crd_skip; + i < crd->crd_skip + crd->crd_len; i += blks) { + /* XOR with the IV/previous block, as appropriate. */ + if (i == crd->crd_skip) + for (k = 0; k < blks; k++) + buf[i + k] ^= ivp[k]; + else + for (k = 0; k < blks; k++) + buf[i + k] ^= buf[i + k - blks]; + exf->encrypt(sw->sw_kschedule, buf + i); + } + } else { /* Decrypt */ + /* + * Start at the end, so we don't need to keep the encrypted + * block as the IV for the next block. + */ + for (i = crd->crd_skip + crd->crd_len - blks; + i >= crd->crd_skip; i -= blks) { + exf->decrypt(sw->sw_kschedule, buf + i); + + /* XOR with the IV/previous block, as appropriate */ + if (i == crd->crd_skip) + for (k = 0; k < blks; k++) + buf[i + k] ^= ivp[k]; + else + for (k = 0; k < blks; k++) + buf[i + k] ^= buf[i + k - blks]; + } + } + + return 0; + } else if (outtype == CRYPTO_BUF_MBUF) { + struct mbuf *m = (struct mbuf *) buf; + + /* Find beginning of data */ + m = m_getptr(m, crd->crd_skip, &k); + if (m == NULL) + return EINVAL; + + i = crd->crd_len; + + while (i > 0) { + /* + * If there's insufficient data at the end of + * an mbuf, we have to do some copying. + */ + if (m->m_len < k + blks && m->m_len != k) { + m_copydata(m, k, blks, blk); + + /* Actual encryption/decryption */ + if (exf->reinit) { + if (crd->crd_flags & CRD_F_ENCRYPT) { + exf->encrypt(sw->sw_kschedule, + blk); + } else { + exf->decrypt(sw->sw_kschedule, + blk); + } + } else if (crd->crd_flags & CRD_F_ENCRYPT) { + /* XOR with previous block */ + for (j = 0; j < blks; j++) + blk[j] ^= ivp[j]; + + exf->encrypt(sw->sw_kschedule, blk); + + /* + * Keep encrypted block for XOR'ing + * with next block + */ + memcpy(iv, blk, blks); + ivp = iv; + } else { /* decrypt */ + /* + * Keep encrypted block for XOR'ing + * with next block + */ + if (ivp == iv) + memcpy(piv, blk, blks); + else + memcpy(iv, blk, blks); + + exf->decrypt(sw->sw_kschedule, blk); + + /* XOR with previous block */ + for (j = 0; j < blks; j++) + blk[j] ^= ivp[j]; + + if (ivp == iv) + memcpy(iv, piv, blks); + else + ivp = iv; + } + + /* Copy back decrypted block */ + m_copyback(m, k, blks, blk); + + /* Advance pointer */ + m = m_getptr(m, k + blks, &k); + if (m == NULL) + return EINVAL; + + i -= blks; + + /* Could be done... */ + if (i == 0) + break; + } + + /* Skip possibly empty mbufs */ + if (k == m->m_len) { + for (m = m->m_next; m && m->m_len == 0; + m = m->m_next) + ; + k = 0; + } + + /* Sanity check */ + if (m == NULL) + return EINVAL; + + /* + * Warning: idat may point to garbage here, but + * we only use it in the while() loop, only if + * there are indeed enough data. + */ + idat = mtod(m, unsigned char *) + k; + + while (m->m_len >= k + blks && i > 0) { + if (exf->reinit) { + if (crd->crd_flags & CRD_F_ENCRYPT) { + exf->encrypt(sw->sw_kschedule, + idat); + } else { + exf->decrypt(sw->sw_kschedule, + idat); + } + } else if (crd->crd_flags & CRD_F_ENCRYPT) { + /* XOR with previous block/IV */ + for (j = 0; j < blks; j++) + idat[j] ^= ivp[j]; + + exf->encrypt(sw->sw_kschedule, idat); + ivp = idat; + } else { /* decrypt */ + /* + * Keep encrypted block to be used + * in next block's processing. + */ + if (ivp == iv) + memcpy(piv, idat, blks); + else + memcpy(iv, idat, blks); + + exf->decrypt(sw->sw_kschedule, idat); + + /* XOR with previous block/IV */ + for (j = 0; j < blks; j++) + idat[j] ^= ivp[j]; + + if (ivp == iv) + memcpy(iv, piv, blks); + else + ivp = iv; + } + + idat += blks; + k += blks; + i -= blks; + } + } + + return 0; /* Done with mbuf encryption/decryption */ + } else if (outtype == CRYPTO_BUF_IOV) { + struct uio *uio = (struct uio *) buf; + + /* Find beginning of data */ + count = crd->crd_skip; + ind = cuio_getptr(uio, count, &k); + if (ind == -1) + return EINVAL; + + i = crd->crd_len; + + while (i > 0) { + /* + * If there's insufficient data at the end, + * we have to do some copying. + */ + if (uio->uio_iov[ind].iov_len < k + blks && + uio->uio_iov[ind].iov_len != k) { + cuio_copydata(uio, k, blks, blk); + + /* Actual encryption/decryption */ + if (exf->reinit) { + if (crd->crd_flags & CRD_F_ENCRYPT) { + exf->encrypt(sw->sw_kschedule, + blk); + } else { + exf->decrypt(sw->sw_kschedule, + blk); + } + } else if (crd->crd_flags & CRD_F_ENCRYPT) { + /* XOR with previous block */ + for (j = 0; j < blks; j++) + blk[j] ^= ivp[j]; + + exf->encrypt(sw->sw_kschedule, blk); + + /* + * Keep encrypted block for XOR'ing + * with next block + */ + memcpy(iv, blk, blks); + ivp = iv; + } else { /* decrypt */ + /* + * Keep encrypted block for XOR'ing + * with next block + */ + if (ivp == iv) + memcpy(piv, blk, blks); + else + memcpy(iv, blk, blks); + + exf->decrypt(sw->sw_kschedule, blk); + + /* XOR with previous block */ + for (j = 0; j < blks; j++) + blk[j] ^= ivp[j]; + + if (ivp == iv) + memcpy(iv, piv, blks); + else + ivp = iv; + } + + /* Copy back decrypted block */ + cuio_copyback(uio, k, blks, blk); + + count += blks; + + /* Advance pointer */ + ind = cuio_getptr(uio, count, &k); + if (ind == -1) + return (EINVAL); + + i -= blks; + + /* Could be done... */ + if (i == 0) + break; + } + + /* + * Warning: idat may point to garbage here, but + * we only use it in the while() loop, only if + * there are indeed enough data. + */ + idat = ((char *)uio->uio_iov[ind].iov_base) + k; + + while (uio->uio_iov[ind].iov_len >= k + blks && + i > 0) { + if (exf->reinit) { + if (crd->crd_flags & CRD_F_ENCRYPT) { + exf->encrypt(sw->sw_kschedule, + idat); + } else { + exf->decrypt(sw->sw_kschedule, + idat); + } + } else if (crd->crd_flags & CRD_F_ENCRYPT) { + /* XOR with previous block/IV */ + for (j = 0; j < blks; j++) + idat[j] ^= ivp[j]; + + exf->encrypt(sw->sw_kschedule, idat); + ivp = idat; + } else { /* decrypt */ + /* + * Keep encrypted block to be used + * in next block's processing. + */ + if (ivp == iv) + memcpy(piv, idat, blks); + else + memcpy(iv, idat, blks); + + exf->decrypt(sw->sw_kschedule, idat); + + /* XOR with previous block/IV */ + for (j = 0; j < blks; j++) + idat[j] ^= ivp[j]; + + if (ivp == iv) + memcpy(iv, piv, blks); + else + ivp = iv; + } + + idat += blks; + count += blks; + k += blks; + i -= blks; + } + } + return 0; /* Done with mbuf encryption/decryption */ + } + + /* Unreachable */ + return EINVAL; +} + +/* + * Compute keyed-hash authenticator. + */ +int +swcr_authcompute(struct cryptop *crp, struct cryptodesc *crd, + const struct swcr_data *sw, void *buf, int outtype) +{ + unsigned char aalg[AALG_MAX_RESULT_LEN]; + const struct swcr_auth_hash *axf; + union authctx ctx; + int err; + + if (sw->sw_ictx == 0) + return EINVAL; + + axf = sw->sw_axf; + + memcpy(&ctx, sw->sw_ictx, axf->ctxsize); + + switch (outtype) { + case CRYPTO_BUF_CONTIG: + axf->Update(&ctx, (char *)buf + crd->crd_skip, crd->crd_len); + break; + case CRYPTO_BUF_MBUF: + err = m_apply((struct mbuf *) buf, crd->crd_skip, crd->crd_len, + (int (*)(void*, void *, unsigned int)) axf->Update, + (void *) &ctx); + if (err) + return err; + break; + case CRYPTO_BUF_IOV: + err = cuio_apply((struct uio *) buf, crd->crd_skip, + crd->crd_len, + (int (*)(void *, void *, unsigned int)) axf->Update, + (void *) &ctx); + if (err) { + return err; + } + break; + default: + return EINVAL; + } + + switch (sw->sw_alg) { + case CRYPTO_MD5_HMAC: + case CRYPTO_MD5_HMAC_96: + case CRYPTO_SHA1_HMAC: + case CRYPTO_SHA1_HMAC_96: + case CRYPTO_SHA2_256_HMAC: + case CRYPTO_SHA2_384_HMAC: + case CRYPTO_SHA2_512_HMAC: + case CRYPTO_RIPEMD160_HMAC: + case CRYPTO_RIPEMD160_HMAC_96: + if (sw->sw_octx == NULL) + return EINVAL; + + axf->Final(aalg, &ctx); + memcpy(&ctx, sw->sw_octx, axf->ctxsize); + axf->Update(&ctx, aalg, axf->auth_hash->hashsize); + axf->Final(aalg, &ctx); + break; + + case CRYPTO_MD5_KPDK: + case CRYPTO_SHA1_KPDK: + if (sw->sw_octx == NULL) + return EINVAL; + + axf->Update(&ctx, sw->sw_octx, sw->sw_klen); + axf->Final(aalg, &ctx); + break; + + case CRYPTO_NULL_HMAC: + case CRYPTO_MD5: + case CRYPTO_SHA1: + case CRYPTO_AES_XCBC_MAC_96: + axf->Final(aalg, &ctx); + break; + } + + /* Inject the authentication data */ + switch (outtype) { + case CRYPTO_BUF_CONTIG: + (void)memcpy((char *)buf + crd->crd_inject, aalg, + axf->auth_hash->authsize); + break; + case CRYPTO_BUF_MBUF: + m_copyback((struct mbuf *) buf, crd->crd_inject, + axf->auth_hash->authsize, aalg); + break; + case CRYPTO_BUF_IOV: + memcpy(crp->crp_mac, aalg, axf->auth_hash->authsize); + break; + default: + return EINVAL; + } + return 0; +} + +/* + * Apply a combined encryption-authentication transformation + */ +static int +swcr_combined(struct cryptop *crp, int outtype) +{ + uint32_t blkbuf[howmany(EALG_MAX_BLOCK_LEN, sizeof(uint32_t))]; + u_char *blk = (u_char *)blkbuf; + u_char aalg[AALG_MAX_RESULT_LEN]; + u_char iv[EALG_MAX_BLOCK_LEN]; + union authctx ctx; + struct cryptodesc *crd, *crda = NULL, *crde = NULL; + struct swcr_data *sw, *swa, *swe = NULL; + const struct swcr_auth_hash *axf = NULL; + const struct swcr_enc_xform *exf = NULL; + void *buf = (void *)crp->crp_buf; + uint32_t *blkp; + int i, blksz = 0, ivlen = 0, len; + + for (crd = crp->crp_desc; crd; crd = crd->crd_next) { + for (sw = swcr_sessions[crp->crp_sid & 0xffffffff]; + sw && sw->sw_alg != crd->crd_alg; + sw = sw->sw_next) + ; + if (sw == NULL) + return (EINVAL); + + switch (sw->sw_alg) { + case CRYPTO_AES_GCM_16: + case CRYPTO_AES_GMAC: + swe = sw; + crde = crd; + exf = swe->sw_exf; + ivlen = exf->enc_xform->ivsize; + break; + case CRYPTO_AES_128_GMAC: + case CRYPTO_AES_192_GMAC: + case CRYPTO_AES_256_GMAC: + swa = sw; + crda = crd; + axf = swa->sw_axf; + if (swa->sw_ictx == 0) + return (EINVAL); + memcpy(&ctx, swa->sw_ictx, axf->ctxsize); + blksz = axf->auth_hash->blocksize; + break; + default: + return (EINVAL); + } + } + if (crde == NULL || crda == NULL) + return (EINVAL); + if (outtype == CRYPTO_BUF_CONTIG) + return (EINVAL); + + /* Initialize the IV */ + if (crde->crd_flags & CRD_F_ENCRYPT) { + /* IV explicitly provided ? */ + if (crde->crd_flags & CRD_F_IV_EXPLICIT) { + memcpy(iv, crde->crd_iv, ivlen); + if (exf->reinit) + exf->reinit(swe->sw_kschedule, iv, 0); + } else if (exf->reinit) + exf->reinit(swe->sw_kschedule, 0, iv); + else + cprng_fast(iv, ivlen); + + /* Do we need to write the IV */ + if (!(crde->crd_flags & CRD_F_IV_PRESENT)) + COPYBACK(outtype, buf, crde->crd_inject, ivlen, iv); + + } else { /* Decryption */ + /* IV explicitly provided ? */ + if (crde->crd_flags & CRD_F_IV_EXPLICIT) + memcpy(iv, crde->crd_iv, ivlen); + else { + /* Get IV off buf */ + COPYDATA(outtype, buf, crde->crd_inject, ivlen, iv); + } + if (exf->reinit) + exf->reinit(swe->sw_kschedule, iv, 0); + } + + /* Supply MAC with IV */ + if (axf->Reinit) + axf->Reinit(&ctx, iv, ivlen); + + /* Supply MAC with AAD */ + for (i = 0; i < crda->crd_len; i += blksz) { + len = MIN(crda->crd_len - i, blksz); + COPYDATA(outtype, buf, crda->crd_skip + i, len, blk); + axf->Update(&ctx, blk, len); + } + + /* Do encryption/decryption with MAC */ + for (i = 0; i < crde->crd_len; i += blksz) { + len = MIN(crde->crd_len - i, blksz); + if (len < blksz) + memset(blk, 0, blksz); + COPYDATA(outtype, buf, crde->crd_skip + i, len, blk); + if (crde->crd_flags & CRD_F_ENCRYPT) { + exf->encrypt(swe->sw_kschedule, blk); + axf->Update(&ctx, blk, len); + } else { + axf->Update(&ctx, blk, len); + exf->decrypt(swe->sw_kschedule, blk); + } + COPYBACK(outtype, buf, crde->crd_skip + i, len, blk); + } + + /* Do any required special finalization */ + switch (crda->crd_alg) { + case CRYPTO_AES_128_GMAC: + case CRYPTO_AES_192_GMAC: + case CRYPTO_AES_256_GMAC: + /* length block */ + memset(blk, 0, blksz); + blkp = (uint32_t *)blk + 1; + *blkp = htobe32(crda->crd_len * 8); + blkp = (uint32_t *)blk + 3; + *blkp = htobe32(crde->crd_len * 8); + axf->Update(&ctx, blk, blksz); + break; + } + + /* Finalize MAC */ + axf->Final(aalg, &ctx); + + /* Inject the authentication data */ + if (outtype == CRYPTO_BUF_MBUF) + COPYBACK(outtype, buf, crda->crd_inject, axf->auth_hash->authsize, aalg); + else + memcpy(crp->crp_mac, aalg, axf->auth_hash->authsize); + + return (0); +} + +/* + * Apply a compression/decompression algorithm + */ +static int +swcr_compdec(struct cryptodesc *crd, const struct swcr_data *sw, + void *buf, int outtype, int *res_size) +{ + u_int8_t *data, *out; + const struct swcr_comp_algo *cxf; + int adj; + u_int32_t result; + + cxf = sw->sw_cxf; + + /* We must handle the whole buffer of data in one time + * then if there is not all the data in the mbuf, we must + * copy in a buffer. + */ + + data = malloc(crd->crd_len, M_CRYPTO_DATA, M_NOWAIT); + if (data == NULL) + return (EINVAL); + COPYDATA(outtype, buf, crd->crd_skip, crd->crd_len, data); + + if (crd->crd_flags & CRD_F_COMP) + result = cxf->compress(data, crd->crd_len, &out); + else + result = cxf->decompress(data, crd->crd_len, &out, + *res_size); + + free(data, M_CRYPTO_DATA); + if (result == 0) + return EINVAL; + + /* Copy back the (de)compressed data. m_copyback is + * extending the mbuf as necessary. + */ + *res_size = (int)result; + /* Check the compressed size when doing compression */ + if (crd->crd_flags & CRD_F_COMP && + sw->sw_alg == CRYPTO_DEFLATE_COMP_NOGROW && + result >= crd->crd_len) { + /* Compression was useless, we lost time */ + free(out, M_CRYPTO_DATA); + return 0; + } + + COPYBACK(outtype, buf, crd->crd_skip, result, out); + if (result < crd->crd_len) { + adj = result - crd->crd_len; + if (outtype == CRYPTO_BUF_MBUF) { + adj = result - crd->crd_len; + m_adj((struct mbuf *)buf, adj); + } + /* Don't adjust the iov_len, it breaks the kmem_free */ + } + free(out, M_CRYPTO_DATA); + return 0; +} + +/* + * Generate a new software session. + */ +static int +swcr_newsession(void *arg, u_int32_t *sid, struct cryptoini *cri) +{ + struct swcr_data **swd; + const struct swcr_auth_hash *axf; + const struct swcr_enc_xform *txf; + const struct swcr_comp_algo *cxf; + u_int32_t i; + int k, error; + + if (sid == NULL || cri == NULL) + return EINVAL; + + if (swcr_sessions) { + for (i = 1; i < swcr_sesnum; i++) + if (swcr_sessions[i] == NULL) + break; + } else + i = 1; /* NB: to silence compiler warning */ + + if (swcr_sessions == NULL || i == swcr_sesnum) { + if (swcr_sessions == NULL) { + i = 1; /* We leave swcr_sessions[0] empty */ + swcr_sesnum = CRYPTO_SW_SESSIONS; + } else + swcr_sesnum *= 2; + + swd = malloc(swcr_sesnum * sizeof(struct swcr_data *), + M_CRYPTO_DATA, M_NOWAIT); + if (swd == NULL) { + /* Reset session number */ + if (swcr_sesnum == CRYPTO_SW_SESSIONS) + swcr_sesnum = 0; + else + swcr_sesnum /= 2; + return ENOBUFS; + } + + memset(swd, 0, swcr_sesnum * sizeof(struct swcr_data *)); + + /* Copy existing sessions */ + if (swcr_sessions) { + memcpy(swd, swcr_sessions, + (swcr_sesnum / 2) * sizeof(struct swcr_data *)); + free(swcr_sessions, M_CRYPTO_DATA); + } + + swcr_sessions = swd; + } + + swd = &swcr_sessions[i]; + *sid = i; + + while (cri) { + *swd = malloc(sizeof **swd, M_CRYPTO_DATA, M_NOWAIT); + if (*swd == NULL) { + swcr_freesession(NULL, i); + return ENOBUFS; + } + memset(*swd, 0, sizeof(struct swcr_data)); + + switch (cri->cri_alg) { + case CRYPTO_DES_CBC: + txf = &swcr_enc_xform_des; + goto enccommon; + case CRYPTO_3DES_CBC: + txf = &swcr_enc_xform_3des; + goto enccommon; + case CRYPTO_BLF_CBC: + txf = &swcr_enc_xform_blf; + goto enccommon; + case CRYPTO_CAST_CBC: + txf = &swcr_enc_xform_cast5; + goto enccommon; + case CRYPTO_SKIPJACK_CBC: + txf = &swcr_enc_xform_skipjack; + goto enccommon; + case CRYPTO_RIJNDAEL128_CBC: + txf = &swcr_enc_xform_rijndael128; + goto enccommon; + case CRYPTO_CAMELLIA_CBC: + txf = &swcr_enc_xform_camellia; + goto enccommon; + case CRYPTO_AES_CTR: + txf = &swcr_enc_xform_aes_ctr; + goto enccommon; + case CRYPTO_AES_GCM_16: + txf = &swcr_enc_xform_aes_gcm; + goto enccommon; + case CRYPTO_AES_GMAC: + txf = &swcr_enc_xform_aes_gmac; + goto enccommon; + case CRYPTO_NULL_CBC: + txf = &swcr_enc_xform_null; + goto enccommon; + enccommon: + error = txf->setkey(&((*swd)->sw_kschedule), + cri->cri_key, cri->cri_klen / 8); + if (error) { + swcr_freesession(NULL, i); + return error; + } + (*swd)->sw_exf = txf; + break; + + case CRYPTO_MD5_HMAC: + axf = &swcr_auth_hash_hmac_md5; + goto authcommon; + case CRYPTO_MD5_HMAC_96: + axf = &swcr_auth_hash_hmac_md5_96; + goto authcommon; + case CRYPTO_SHA1_HMAC: + axf = &swcr_auth_hash_hmac_sha1; + goto authcommon; + case CRYPTO_SHA1_HMAC_96: + axf = &swcr_auth_hash_hmac_sha1_96; + goto authcommon; + case CRYPTO_SHA2_256_HMAC: + axf = &swcr_auth_hash_hmac_sha2_256; + goto authcommon; + case CRYPTO_SHA2_384_HMAC: + axf = &swcr_auth_hash_hmac_sha2_384; + goto authcommon; + case CRYPTO_SHA2_512_HMAC: + axf = &swcr_auth_hash_hmac_sha2_512; + goto authcommon; + case CRYPTO_NULL_HMAC: + axf = &swcr_auth_hash_null; + goto authcommon; + case CRYPTO_RIPEMD160_HMAC: + axf = &swcr_auth_hash_hmac_ripemd_160; + goto authcommon; + case CRYPTO_RIPEMD160_HMAC_96: + axf = &swcr_auth_hash_hmac_ripemd_160_96; + goto authcommon; /* leave this for safety */ + authcommon: + (*swd)->sw_ictx = malloc(axf->ctxsize, + M_CRYPTO_DATA, M_NOWAIT); + if ((*swd)->sw_ictx == NULL) { + swcr_freesession(NULL, i); + return ENOBUFS; + } + + (*swd)->sw_octx = malloc(axf->ctxsize, + M_CRYPTO_DATA, M_NOWAIT); + if ((*swd)->sw_octx == NULL) { + swcr_freesession(NULL, i); + return ENOBUFS; + } + + for (k = 0; k < cri->cri_klen / 8; k++) + cri->cri_key[k] ^= HMAC_IPAD_VAL; + + axf->Init((*swd)->sw_ictx); + axf->Update((*swd)->sw_ictx, cri->cri_key, + cri->cri_klen / 8); + axf->Update((*swd)->sw_ictx, hmac_ipad_buffer, + axf->auth_hash->blocksize - (cri->cri_klen / 8)); + + for (k = 0; k < cri->cri_klen / 8; k++) + cri->cri_key[k] ^= (HMAC_IPAD_VAL ^ HMAC_OPAD_VAL); + + axf->Init((*swd)->sw_octx); + axf->Update((*swd)->sw_octx, cri->cri_key, + cri->cri_klen / 8); + axf->Update((*swd)->sw_octx, hmac_opad_buffer, + axf->auth_hash->blocksize - (cri->cri_klen / 8)); + + for (k = 0; k < cri->cri_klen / 8; k++) + cri->cri_key[k] ^= HMAC_OPAD_VAL; + (*swd)->sw_axf = axf; + break; + + case CRYPTO_MD5_KPDK: + axf = &swcr_auth_hash_key_md5; + goto auth2common; + + case CRYPTO_SHA1_KPDK: + axf = &swcr_auth_hash_key_sha1; + auth2common: + (*swd)->sw_ictx = malloc(axf->ctxsize, + M_CRYPTO_DATA, M_NOWAIT); + if ((*swd)->sw_ictx == NULL) { + swcr_freesession(NULL, i); + return ENOBUFS; + } + + /* Store the key so we can "append" it to the payload */ + (*swd)->sw_octx = malloc(cri->cri_klen / 8, M_CRYPTO_DATA, + M_NOWAIT); + if ((*swd)->sw_octx == NULL) { + swcr_freesession(NULL, i); + return ENOBUFS; + } + + (*swd)->sw_klen = cri->cri_klen / 8; + memcpy((*swd)->sw_octx, cri->cri_key, cri->cri_klen / 8); + axf->Init((*swd)->sw_ictx); + axf->Update((*swd)->sw_ictx, cri->cri_key, + cri->cri_klen / 8); + axf->Final(NULL, (*swd)->sw_ictx); + (*swd)->sw_axf = axf; + break; + + case CRYPTO_MD5: + axf = &swcr_auth_hash_md5; + goto auth3common; + + case CRYPTO_SHA1: + axf = &swcr_auth_hash_sha1; + auth3common: + (*swd)->sw_ictx = malloc(axf->ctxsize, + M_CRYPTO_DATA, M_NOWAIT); + if ((*swd)->sw_ictx == NULL) { + swcr_freesession(NULL, i); + return ENOBUFS; + } + + axf->Init((*swd)->sw_ictx); + (*swd)->sw_axf = axf; + break; + + case CRYPTO_AES_XCBC_MAC_96: + axf = &swcr_auth_hash_aes_xcbc_mac; + goto auth4common; + case CRYPTO_AES_128_GMAC: + axf = &swcr_auth_hash_gmac_aes_128; + goto auth4common; + case CRYPTO_AES_192_GMAC: + axf = &swcr_auth_hash_gmac_aes_192; + goto auth4common; + case CRYPTO_AES_256_GMAC: + axf = &swcr_auth_hash_gmac_aes_256; + auth4common: + (*swd)->sw_ictx = malloc(axf->ctxsize, + M_CRYPTO_DATA, M_NOWAIT); + if ((*swd)->sw_ictx == NULL) { + swcr_freesession(NULL, i); + return ENOBUFS; + } + axf->Init((*swd)->sw_ictx); + axf->Setkey((*swd)->sw_ictx, + cri->cri_key, cri->cri_klen / 8); + (*swd)->sw_axf = axf; + break; + + case CRYPTO_DEFLATE_COMP: + cxf = &swcr_comp_algo_deflate; + (*swd)->sw_cxf = cxf; + break; + + case CRYPTO_DEFLATE_COMP_NOGROW: + cxf = &swcr_comp_algo_deflate_nogrow; + (*swd)->sw_cxf = cxf; + break; + + case CRYPTO_GZIP_COMP: + cxf = &swcr_comp_algo_gzip; + (*swd)->sw_cxf = cxf; + break; + default: + swcr_freesession(NULL, i); + return EINVAL; + } + + (*swd)->sw_alg = cri->cri_alg; + cri = cri->cri_next; + swd = &((*swd)->sw_next); + } + return 0; +} + +/* + * Free a session. + */ +static int +swcr_freesession(void *arg, u_int64_t tid) +{ + struct swcr_data *swd; + const struct swcr_enc_xform *txf; + const struct swcr_auth_hash *axf; + u_int32_t sid = ((u_int32_t) tid) & 0xffffffff; + + if (sid > swcr_sesnum || swcr_sessions == NULL || + swcr_sessions[sid] == NULL) + return EINVAL; + + /* Silently accept and return */ + if (sid == 0) + return 0; + + while ((swd = swcr_sessions[sid]) != NULL) { + swcr_sessions[sid] = swd->sw_next; + + switch (swd->sw_alg) { + case CRYPTO_DES_CBC: + case CRYPTO_3DES_CBC: + case CRYPTO_BLF_CBC: + case CRYPTO_CAST_CBC: + case CRYPTO_SKIPJACK_CBC: + case CRYPTO_RIJNDAEL128_CBC: + case CRYPTO_CAMELLIA_CBC: + case CRYPTO_AES_CTR: + case CRYPTO_AES_GCM_16: + case CRYPTO_AES_GMAC: + case CRYPTO_NULL_CBC: + txf = swd->sw_exf; + + if (swd->sw_kschedule) + txf->zerokey(&(swd->sw_kschedule)); + break; + + case CRYPTO_MD5_HMAC: + case CRYPTO_MD5_HMAC_96: + case CRYPTO_SHA1_HMAC: + case CRYPTO_SHA1_HMAC_96: + case CRYPTO_SHA2_256_HMAC: + case CRYPTO_SHA2_384_HMAC: + case CRYPTO_SHA2_512_HMAC: + case CRYPTO_RIPEMD160_HMAC: + case CRYPTO_RIPEMD160_HMAC_96: + case CRYPTO_NULL_HMAC: + axf = swd->sw_axf; + + if (swd->sw_ictx) { + explicit_memset(swd->sw_ictx, 0, axf->ctxsize); + free(swd->sw_ictx, M_CRYPTO_DATA); + } + if (swd->sw_octx) { + explicit_memset(swd->sw_octx, 0, axf->ctxsize); + free(swd->sw_octx, M_CRYPTO_DATA); + } + break; + + case CRYPTO_MD5_KPDK: + case CRYPTO_SHA1_KPDK: + axf = swd->sw_axf; + + if (swd->sw_ictx) { + explicit_memset(swd->sw_ictx, 0, axf->ctxsize); + free(swd->sw_ictx, M_CRYPTO_DATA); + } + if (swd->sw_octx) { + explicit_memset(swd->sw_octx, 0, swd->sw_klen); + free(swd->sw_octx, M_CRYPTO_DATA); + } + break; + + case CRYPTO_MD5: + case CRYPTO_SHA1: + case CRYPTO_AES_XCBC_MAC_96: + case CRYPTO_AES_128_GMAC: + case CRYPTO_AES_192_GMAC: + case CRYPTO_AES_256_GMAC: + axf = swd->sw_axf; + + if (swd->sw_ictx) { + explicit_memset(swd->sw_ictx, 0, axf->ctxsize); + free(swd->sw_ictx, M_CRYPTO_DATA); + } + break; + + case CRYPTO_DEFLATE_COMP: + case CRYPTO_DEFLATE_COMP_NOGROW: + case CRYPTO_GZIP_COMP: + break; + } + + free(swd, M_CRYPTO_DATA); + } + return 0; +} + +/* + * Process a software request. + */ +static int +swcr_process(void *arg, struct cryptop *crp, int hint) +{ + struct cryptodesc *crd; + struct swcr_data *sw; + u_int32_t lid; + int type; + + /* Sanity check */ + if (crp == NULL) + return EINVAL; + + if (crp->crp_desc == NULL || crp->crp_buf == NULL) { + crp->crp_etype = EINVAL; + goto done; + } + + lid = crp->crp_sid & 0xffffffff; + if (lid >= swcr_sesnum || lid == 0 || swcr_sessions[lid] == NULL) { + crp->crp_etype = ENOENT; + goto done; + } + + if (crp->crp_flags & CRYPTO_F_IMBUF) { + type = CRYPTO_BUF_MBUF; + } else if (crp->crp_flags & CRYPTO_F_IOV) { + type = CRYPTO_BUF_IOV; + } else { + type = CRYPTO_BUF_CONTIG; + } + + /* Go through crypto descriptors, processing as we go */ + for (crd = crp->crp_desc; crd; crd = crd->crd_next) { + /* + * Find the crypto context. + * + * XXX Note that the logic here prevents us from having + * XXX the same algorithm multiple times in a session + * XXX (or rather, we can but it won't give us the right + * XXX results). To do that, we'd need some way of differentiating + * XXX between the various instances of an algorithm (so we can + * XXX locate the correct crypto context). + */ + for (sw = swcr_sessions[lid]; + sw && sw->sw_alg != crd->crd_alg; + sw = sw->sw_next) + ; + + /* No such context ? */ + if (sw == NULL) { + crp->crp_etype = EINVAL; + goto done; + } + + switch (sw->sw_alg) { + case CRYPTO_DES_CBC: + case CRYPTO_3DES_CBC: + case CRYPTO_BLF_CBC: + case CRYPTO_CAST_CBC: + case CRYPTO_SKIPJACK_CBC: + case CRYPTO_RIJNDAEL128_CBC: + case CRYPTO_CAMELLIA_CBC: + case CRYPTO_AES_CTR: + if ((crp->crp_etype = swcr_encdec(crd, sw, + crp->crp_buf, type)) != 0) + goto done; + break; + case CRYPTO_NULL_CBC: + crp->crp_etype = 0; + break; + case CRYPTO_MD5_HMAC: + case CRYPTO_MD5_HMAC_96: + case CRYPTO_SHA1_HMAC: + case CRYPTO_SHA1_HMAC_96: + case CRYPTO_SHA2_256_HMAC: + case CRYPTO_SHA2_384_HMAC: + case CRYPTO_SHA2_512_HMAC: + case CRYPTO_RIPEMD160_HMAC: + case CRYPTO_RIPEMD160_HMAC_96: + case CRYPTO_NULL_HMAC: + case CRYPTO_MD5_KPDK: + case CRYPTO_SHA1_KPDK: + case CRYPTO_MD5: + case CRYPTO_SHA1: + case CRYPTO_AES_XCBC_MAC_96: + if ((crp->crp_etype = swcr_authcompute(crp, crd, sw, + crp->crp_buf, type)) != 0) + goto done; + break; + + case CRYPTO_AES_GCM_16: + case CRYPTO_AES_GMAC: + case CRYPTO_AES_128_GMAC: + case CRYPTO_AES_192_GMAC: + case CRYPTO_AES_256_GMAC: + crp->crp_etype = swcr_combined(crp, type); + goto done; + + case CRYPTO_DEFLATE_COMP: + case CRYPTO_DEFLATE_COMP_NOGROW: + case CRYPTO_GZIP_COMP: + DPRINTF(("swcr_process: compdec for %d\n", sw->sw_alg)); + if ((crp->crp_etype = swcr_compdec(crd, sw, + crp->crp_buf, type, &crp->crp_olen)) != 0) + goto done; + break; + + default: + /* Unknown/unsupported algorithm */ + crp->crp_etype = EINVAL; + goto done; + } + } + +done: + DPRINTF(("request %p done\n", crp)); + crypto_done(crp); + return 0; +} + +static void +swcr_init(void) +{ + swcr_id = crypto_get_driverid(CRYPTOCAP_F_SOFTWARE); + if (swcr_id < 0) { + /* This should never happen */ + panic("Software crypto device cannot initialize!"); + } + + crypto_register(swcr_id, CRYPTO_DES_CBC, + 0, 0, swcr_newsession, swcr_freesession, swcr_process, NULL); +#define REGISTER(alg) \ + crypto_register(swcr_id, alg, 0, 0, NULL, NULL, NULL, NULL) + + REGISTER(CRYPTO_3DES_CBC); + REGISTER(CRYPTO_BLF_CBC); + REGISTER(CRYPTO_CAST_CBC); + REGISTER(CRYPTO_SKIPJACK_CBC); + REGISTER(CRYPTO_CAMELLIA_CBC); + REGISTER(CRYPTO_AES_CTR); + REGISTER(CRYPTO_AES_GCM_16); + REGISTER(CRYPTO_AES_GMAC); + REGISTER(CRYPTO_NULL_CBC); + REGISTER(CRYPTO_MD5_HMAC); + REGISTER(CRYPTO_MD5_HMAC_96); + REGISTER(CRYPTO_SHA1_HMAC); + REGISTER(CRYPTO_SHA1_HMAC_96); + REGISTER(CRYPTO_SHA2_256_HMAC); + REGISTER(CRYPTO_SHA2_384_HMAC); + REGISTER(CRYPTO_SHA2_512_HMAC); + REGISTER(CRYPTO_RIPEMD160_HMAC); + REGISTER(CRYPTO_RIPEMD160_HMAC_96); + REGISTER(CRYPTO_NULL_HMAC); + REGISTER(CRYPTO_MD5_KPDK); + REGISTER(CRYPTO_SHA1_KPDK); + REGISTER(CRYPTO_MD5); + REGISTER(CRYPTO_SHA1); + REGISTER(CRYPTO_AES_XCBC_MAC_96); + REGISTER(CRYPTO_AES_128_GMAC); + REGISTER(CRYPTO_AES_192_GMAC); + REGISTER(CRYPTO_AES_256_GMAC); + REGISTER(CRYPTO_RIJNDAEL128_CBC); + REGISTER(CRYPTO_DEFLATE_COMP); + REGISTER(CRYPTO_DEFLATE_COMP_NOGROW); + REGISTER(CRYPTO_GZIP_COMP); +#undef REGISTER +} + + +/* + * Pseudo-device init routine for software crypto. + */ + +void +swcryptoattach(int num) +{ + + swcr_init(); +} + +void swcrypto_attach(device_t, device_t, void *); + +void +swcrypto_attach(device_t parent, device_t self, void *opaque) +{ + + swcr_init(); + + if (!pmf_device_register(self, NULL, NULL)) + aprint_error_dev(self, "couldn't establish power handler\n"); +} + +int swcrypto_detach(device_t, int); + +int +swcrypto_detach(device_t self, int flag) +{ + pmf_device_deregister(self); + if (swcr_id >= 0) + crypto_unregister_all(swcr_id); + return 0; +} + +int swcrypto_match(device_t, cfdata_t, void *); + +int +swcrypto_match(device_t parent, cfdata_t data, void *opaque) +{ + + return 1; +} + +MODULE(MODULE_CLASS_DRIVER, swcrypto, + "opencrypto,zlib,blowfish,des,cast128,camellia,skipjack"); + +CFDRIVER_DECL(swcrypto, DV_DULL, NULL); + +CFATTACH_DECL2_NEW(swcrypto, 0, swcrypto_match, swcrypto_attach, + swcrypto_detach, NULL, NULL, NULL); + +static int swcryptoloc[] = { -1, -1 }; + +static struct cfdata swcrypto_cfdata[] = { + { + .cf_name = "swcrypto", + .cf_atname = "swcrypto", + .cf_unit = 0, + .cf_fstate = 0, + .cf_loc = swcryptoloc, + .cf_flags = 0, + .cf_pspec = NULL, + }, + { NULL, NULL, 0, 0, NULL, 0, NULL } +}; + +static int +swcrypto_modcmd(modcmd_t cmd, void *arg) +{ + int error; + + switch (cmd) { + case MODULE_CMD_INIT: + error = config_cfdriver_attach(&swcrypto_cd); + if (error) { + return error; + } + + error = config_cfattach_attach(swcrypto_cd.cd_name, + &swcrypto_ca); + if (error) { + config_cfdriver_detach(&swcrypto_cd); + aprint_error("%s: unable to register cfattach\n", + swcrypto_cd.cd_name); + + return error; + } + + error = config_cfdata_attach(swcrypto_cfdata, 1); + if (error) { + config_cfattach_detach(swcrypto_cd.cd_name, + &swcrypto_ca); + config_cfdriver_detach(&swcrypto_cd); + aprint_error("%s: unable to register cfdata\n", + swcrypto_cd.cd_name); + + return error; + } + + (void)config_attach_pseudo(swcrypto_cfdata); + + return 0; + case MODULE_CMD_FINI: + error = config_cfdata_detach(swcrypto_cfdata); + if (error) { + return error; + } + + config_cfattach_detach(swcrypto_cd.cd_name, &swcrypto_ca); + config_cfdriver_detach(&swcrypto_cd); + + return 0; + default: + return ENOTTY; + } +} diff --git a/sys/opencrypto/cryptosoft.h b/sys/opencrypto/cryptosoft.h new file mode 100644 index 000000000..54243c8c7 --- /dev/null +++ b/sys/opencrypto/cryptosoft.h @@ -0,0 +1,63 @@ +/* $NetBSD: cryptosoft.h,v 1.7 2011/02/10 21:00:42 drochner Exp $ */ +/* $OpenBSD: cryptosoft.h,v 1.10 2002/04/22 23:10:09 deraadt Exp $ */ + +/* + * The author of this code is Angelos D. Keromytis (angelos@cis.upenn.edu) + * + * This code was written by Angelos D. Keromytis in Athens, Greece, in + * February 2000. Network Security Technologies Inc. (NSTI) kindly + * supported the development of this code. + * + * Copyright (c) 2000 Angelos D. Keromytis + * + * Permission to use, copy, and modify this software with or without fee + * is hereby granted, provided that this entire notice is included in + * all source code copies of any software which is or includes a copy or + * modification of this software. + * + * THIS SOFTWARE IS BEING PROVIDED "AS IS", WITHOUT ANY EXPRESS OR + * IMPLIED WARRANTY. IN PARTICULAR, NONE OF THE AUTHORS MAKES ANY + * REPRESENTATION OR WARRANTY OF ANY KIND CONCERNING THE + * MERCHANTABILITY OF THIS SOFTWARE OR ITS FITNESS FOR ANY PARTICULAR + * PURPOSE. + */ + +#ifndef _CRYPTO_CRYPTOSOFT_H_ +#define _CRYPTO_CRYPTOSOFT_H_ + +/* Software session entry */ +struct swcr_data { + int sw_alg; /* Algorithm */ + union { + struct { + u_int8_t *SW_ictx; + u_int8_t *SW_octx; + u_int32_t SW_klen; + const struct swcr_auth_hash *SW_axf; + } SWCR_AUTH; + struct { + u_int8_t *SW_kschedule; + const struct swcr_enc_xform *SW_exf; + } SWCR_ENC; + struct { + const struct swcr_comp_algo *SW_cxf; + } SWCR_COMP; + } SWCR_UN; + +#define sw_ictx SWCR_UN.SWCR_AUTH.SW_ictx +#define sw_octx SWCR_UN.SWCR_AUTH.SW_octx +#define sw_klen SWCR_UN.SWCR_AUTH.SW_klen +#define sw_axf SWCR_UN.SWCR_AUTH.SW_axf +#define sw_kschedule SWCR_UN.SWCR_ENC.SW_kschedule +#define sw_exf SWCR_UN.SWCR_ENC.SW_exf +#define sw_cxf SWCR_UN.SWCR_COMP.SW_cxf + + struct swcr_data *sw_next; +}; + +#ifdef _KERNEL +int swcr_authcompute(struct cryptop *crp, struct cryptodesc *crd, + const struct swcr_data *sw, void *buf, int outtype); +#endif /* _KERNEL */ + +#endif /* _CRYPTO_CRYPTO_H_ */ diff --git a/sys/opencrypto/cryptosoft_xform.c b/sys/opencrypto/cryptosoft_xform.c new file mode 100644 index 000000000..707337ecc --- /dev/null +++ b/sys/opencrypto/cryptosoft_xform.c @@ -0,0 +1,923 @@ +/* $NetBSD: cryptosoft_xform.c,v 1.27 2014/11/27 20:30:21 christos Exp $ */ +/* $FreeBSD: src/sys/opencrypto/xform.c,v 1.1.2.1 2002/11/21 23:34:23 sam Exp $ */ +/* $OpenBSD: xform.c,v 1.19 2002/08/16 22:47:25 dhartmei Exp $ */ + +/* + * The authors of this code are John Ioannidis (ji@tla.org), + * Angelos D. Keromytis (kermit@csd.uch.gr) and + * Niels Provos (provos@physnet.uni-hamburg.de). + * + * This code was written by John Ioannidis for BSD/OS in Athens, Greece, + * in November 1995. + * + * Ported to OpenBSD and NetBSD, with additional transforms, in December 1996, + * by Angelos D. Keromytis. + * + * Additional transforms and features in 1997 and 1998 by Angelos D. Keromytis + * and Niels Provos. + * + * Additional features in 1999 by Angelos D. Keromytis. + * + * Copyright (C) 1995, 1996, 1997, 1998, 1999 by John Ioannidis, + * Angelos D. Keromytis and Niels Provos. + * + * Copyright (C) 2001, Angelos D. Keromytis. + * + * Permission to use, copy, and modify this software with or without fee + * is hereby granted, provided that this entire notice is included in + * all copies of any software which is or includes a copy or + * modification of this software. + * You may use this code under the GNU public license if you so wish. Please + * contribute changes back to the authors under this freer than GPL license + * so that we may further the use of strong encryption without limitations to + * all. + * + * THIS SOFTWARE IS BEING PROVIDED "AS IS", WITHOUT ANY EXPRESS OR + * IMPLIED WARRANTY. IN PARTICULAR, NONE OF THE AUTHORS MAKES ANY + * REPRESENTATION OR WARRANTY OF ANY KIND CONCERNING THE + * MERCHANTABILITY OF THIS SOFTWARE OR ITS FITNESS FOR ANY PARTICULAR + * PURPOSE. + */ + +#include +__KERNEL_RCSID(1, "$NetBSD: cryptosoft_xform.c,v 1.27 2014/11/27 20:30:21 christos Exp $"); + +#include +#include +#include +#include +#include +#include + +#include + +#include +#include +#include +#include +#include +#include +#include + +struct swcr_auth_hash { + const struct auth_hash *auth_hash; + int ctxsize; + void (*Init)(void *); + void (*Setkey)(void *, const uint8_t *, uint16_t); + void (*Reinit)(void *, const uint8_t *, uint16_t); + int (*Update)(void *, const uint8_t *, uint16_t); + void (*Final)(uint8_t *, void *); +}; + +struct swcr_enc_xform { + const struct enc_xform *enc_xform; + void (*encrypt)(void *, uint8_t *); + void (*decrypt)(void *, uint8_t *); + int (*setkey)(uint8_t **, const uint8_t *, int); + void (*zerokey)(uint8_t **); + void (*reinit)(void *, const uint8_t *, uint8_t *); +}; + +struct swcr_comp_algo { + const struct comp_algo *unused_comp_algo; + uint32_t (*compress)(uint8_t *, uint32_t, uint8_t **); + uint32_t (*decompress)(uint8_t *, uint32_t, uint8_t **, int); +}; + +static void null_encrypt(void *, u_int8_t *); +static void null_decrypt(void *, u_int8_t *); +static int null_setkey(u_int8_t **, const u_int8_t *, int); +static void null_zerokey(u_int8_t **); + +static int des1_setkey(u_int8_t **, const u_int8_t *, int); +static int des3_setkey(u_int8_t **, const u_int8_t *, int); +static int blf_setkey(u_int8_t **, const u_int8_t *, int); +static int cast5_setkey(u_int8_t **, const u_int8_t *, int); +static int skipjack_setkey(u_int8_t **, const u_int8_t *, int); +static int rijndael128_setkey(u_int8_t **, const u_int8_t *, int); +static int cml_setkey(u_int8_t **, const u_int8_t *, int); +static int aes_ctr_setkey(u_int8_t **, const u_int8_t *, int); +static int aes_gmac_setkey(u_int8_t **, const u_int8_t *, int); +static void des1_encrypt(void *, u_int8_t *); +static void des3_encrypt(void *, u_int8_t *); +static void blf_encrypt(void *, u_int8_t *); +static void cast5_encrypt(void *, u_int8_t *); +static void skipjack_encrypt(void *, u_int8_t *); +static void rijndael128_encrypt(void *, u_int8_t *); +static void cml_encrypt(void *, u_int8_t *); +static void des1_decrypt(void *, u_int8_t *); +static void des3_decrypt(void *, u_int8_t *); +static void blf_decrypt(void *, u_int8_t *); +static void cast5_decrypt(void *, u_int8_t *); +static void skipjack_decrypt(void *, u_int8_t *); +static void rijndael128_decrypt(void *, u_int8_t *); +static void cml_decrypt(void *, u_int8_t *); +static void aes_ctr_crypt(void *, u_int8_t *); +static void des1_zerokey(u_int8_t **); +static void des3_zerokey(u_int8_t **); +static void blf_zerokey(u_int8_t **); +static void cast5_zerokey(u_int8_t **); +static void skipjack_zerokey(u_int8_t **); +static void rijndael128_zerokey(u_int8_t **); +static void cml_zerokey(u_int8_t **); +static void aes_ctr_zerokey(u_int8_t **); +static void aes_gmac_zerokey(u_int8_t **); +static void aes_ctr_reinit(void *, const u_int8_t *, u_int8_t *); +static void aes_gcm_reinit(void *, const u_int8_t *, u_int8_t *); +static void aes_gmac_reinit(void *, const u_int8_t *, u_int8_t *); + +static void null_init(void *); +static int null_update(void *, const u_int8_t *, u_int16_t); +static void null_final(u_int8_t *, void *); + +static int MD5Update_int(void *, const u_int8_t *, u_int16_t); +static void SHA1Init_int(void *); +static int SHA1Update_int(void *, const u_int8_t *, u_int16_t); +static void SHA1Final_int(u_int8_t *, void *); + + +static int RMD160Update_int(void *, const u_int8_t *, u_int16_t); +static int SHA1Update_int(void *, const u_int8_t *, u_int16_t); +static void SHA1Final_int(u_int8_t *, void *); +static int RMD160Update_int(void *, const u_int8_t *, u_int16_t); +static int SHA256Update_int(void *, const u_int8_t *, u_int16_t); +static int SHA384Update_int(void *, const u_int8_t *, u_int16_t); +static int SHA512Update_int(void *, const u_int8_t *, u_int16_t); + +static u_int32_t deflate_compress(u_int8_t *, u_int32_t, u_int8_t **); +static u_int32_t deflate_decompress(u_int8_t *, u_int32_t, u_int8_t **, int); +static u_int32_t gzip_compress(u_int8_t *, u_int32_t, u_int8_t **); +static u_int32_t gzip_decompress(u_int8_t *, u_int32_t, u_int8_t **, int); + +/* Encryption instances */ +static const struct swcr_enc_xform swcr_enc_xform_null = { + &enc_xform_null, + null_encrypt, + null_decrypt, + null_setkey, + null_zerokey, + NULL +}; + +static const struct swcr_enc_xform swcr_enc_xform_des = { + &enc_xform_des, + des1_encrypt, + des1_decrypt, + des1_setkey, + des1_zerokey, + NULL +}; + +static const struct swcr_enc_xform swcr_enc_xform_3des = { + &enc_xform_3des, + des3_encrypt, + des3_decrypt, + des3_setkey, + des3_zerokey, + NULL +}; + +static const struct swcr_enc_xform swcr_enc_xform_blf = { + &enc_xform_blf, + blf_encrypt, + blf_decrypt, + blf_setkey, + blf_zerokey, + NULL +}; + +static const struct swcr_enc_xform swcr_enc_xform_cast5 = { + &enc_xform_cast5, + cast5_encrypt, + cast5_decrypt, + cast5_setkey, + cast5_zerokey, + NULL +}; + +static const struct swcr_enc_xform swcr_enc_xform_skipjack = { + &enc_xform_skipjack, + skipjack_encrypt, + skipjack_decrypt, + skipjack_setkey, + skipjack_zerokey, + NULL +}; + +static const struct swcr_enc_xform swcr_enc_xform_rijndael128 = { + &enc_xform_rijndael128, + rijndael128_encrypt, + rijndael128_decrypt, + rijndael128_setkey, + rijndael128_zerokey, + NULL +}; + +static const struct swcr_enc_xform swcr_enc_xform_aes_ctr = { + &enc_xform_aes_ctr, + aes_ctr_crypt, + aes_ctr_crypt, + aes_ctr_setkey, + aes_ctr_zerokey, + aes_ctr_reinit +}; + +static const struct swcr_enc_xform swcr_enc_xform_aes_gcm = { + &enc_xform_aes_gcm, + aes_ctr_crypt, + aes_ctr_crypt, + aes_ctr_setkey, + aes_ctr_zerokey, + aes_gcm_reinit +}; + +static const struct swcr_enc_xform swcr_enc_xform_aes_gmac = { + &enc_xform_aes_gmac, + NULL, + NULL, + aes_gmac_setkey, + aes_gmac_zerokey, + aes_gmac_reinit +}; + +static const struct swcr_enc_xform swcr_enc_xform_camellia = { + &enc_xform_camellia, + cml_encrypt, + cml_decrypt, + cml_setkey, + cml_zerokey, + NULL +}; + +/* Authentication instances */ +static const struct swcr_auth_hash swcr_auth_hash_null = { + &auth_hash_null, sizeof(int), /* NB: context isn't used */ + null_init, NULL, NULL, null_update, null_final +}; + +static const struct swcr_auth_hash swcr_auth_hash_hmac_md5 = { + &auth_hash_hmac_md5, sizeof(MD5_CTX), + (void (*) (void *)) MD5Init, NULL, NULL, MD5Update_int, + (void (*) (u_int8_t *, void *)) MD5Final +}; + +static const struct swcr_auth_hash swcr_auth_hash_hmac_sha1 = { + &auth_hash_hmac_sha1, sizeof(SHA1_CTX), + SHA1Init_int, NULL, NULL, SHA1Update_int, SHA1Final_int +}; + +static const struct swcr_auth_hash swcr_auth_hash_hmac_ripemd_160 = { + &auth_hash_hmac_ripemd_160, sizeof(RMD160_CTX), + (void (*)(void *)) RMD160Init, NULL, NULL, RMD160Update_int, + (void (*)(u_int8_t *, void *)) RMD160Final +}; +static const struct swcr_auth_hash swcr_auth_hash_hmac_md5_96 = { + &auth_hash_hmac_md5_96, sizeof(MD5_CTX), + (void (*) (void *)) MD5Init, NULL, NULL, MD5Update_int, + (void (*) (u_int8_t *, void *)) MD5Final +}; + +static const struct swcr_auth_hash swcr_auth_hash_hmac_sha1_96 = { + &auth_hash_hmac_sha1_96, sizeof(SHA1_CTX), + SHA1Init_int, NULL, NULL, SHA1Update_int, SHA1Final_int +}; + +static const struct swcr_auth_hash swcr_auth_hash_hmac_ripemd_160_96 = { + &auth_hash_hmac_ripemd_160_96, sizeof(RMD160_CTX), + (void (*)(void *)) RMD160Init, NULL, NULL, RMD160Update_int, + (void (*)(u_int8_t *, void *)) RMD160Final +}; + +static const struct swcr_auth_hash swcr_auth_hash_key_md5 = { + &auth_hash_key_md5, sizeof(MD5_CTX), + (void (*)(void *)) MD5Init, NULL, NULL, MD5Update_int, + (void (*)(u_int8_t *, void *)) MD5Final +}; + +static const struct swcr_auth_hash swcr_auth_hash_key_sha1 = { + &auth_hash_key_sha1, sizeof(SHA1_CTX), + SHA1Init_int, NULL, NULL, SHA1Update_int, SHA1Final_int +}; + +static const struct swcr_auth_hash swcr_auth_hash_md5 = { + &auth_hash_md5, sizeof(MD5_CTX), + (void (*) (void *)) MD5Init, NULL, NULL, MD5Update_int, + (void (*) (u_int8_t *, void *)) MD5Final +}; + +static const struct swcr_auth_hash swcr_auth_hash_sha1 = { + &auth_hash_sha1, sizeof(SHA1_CTX), + (void (*)(void *)) SHA1Init, NULL, NULL, SHA1Update_int, + (void (*)(u_int8_t *, void *)) SHA1Final +}; + +static const struct swcr_auth_hash swcr_auth_hash_hmac_sha2_256 = { + &auth_hash_hmac_sha2_256, sizeof(SHA256_CTX), + (void (*)(void *)) SHA256_Init, NULL, NULL, SHA256Update_int, + (void (*)(u_int8_t *, void *)) SHA256_Final +}; + +static const struct swcr_auth_hash swcr_auth_hash_hmac_sha2_384 = { + &auth_hash_hmac_sha2_384, sizeof(SHA384_CTX), + (void (*)(void *)) SHA384_Init, NULL, NULL, SHA384Update_int, + (void (*)(u_int8_t *, void *)) SHA384_Final +}; + +static const struct swcr_auth_hash swcr_auth_hash_hmac_sha2_512 = { + &auth_hash_hmac_sha2_512, sizeof(SHA512_CTX), + (void (*)(void *)) SHA512_Init, NULL, NULL, SHA512Update_int, + (void (*)(u_int8_t *, void *)) SHA512_Final +}; + +static const struct swcr_auth_hash swcr_auth_hash_aes_xcbc_mac = { + &auth_hash_aes_xcbc_mac_96, sizeof(aesxcbc_ctx), + null_init, + (void (*)(void *, const u_int8_t *, u_int16_t))aes_xcbc_mac_init, + NULL, aes_xcbc_mac_loop, aes_xcbc_mac_result +}; + +static const struct swcr_auth_hash swcr_auth_hash_gmac_aes_128 = { + &auth_hash_gmac_aes_128, sizeof(AES_GMAC_CTX), + (void (*)(void *))AES_GMAC_Init, + (void (*)(void *, const u_int8_t *, u_int16_t))AES_GMAC_Setkey, + (void (*)(void *, const u_int8_t *, u_int16_t))AES_GMAC_Reinit, + (int (*)(void *, const u_int8_t *, u_int16_t))AES_GMAC_Update, + (void (*)(u_int8_t *, void *))AES_GMAC_Final +}; + +static const struct swcr_auth_hash swcr_auth_hash_gmac_aes_192 = { + &auth_hash_gmac_aes_192, sizeof(AES_GMAC_CTX), + (void (*)(void *))AES_GMAC_Init, + (void (*)(void *, const u_int8_t *, u_int16_t))AES_GMAC_Setkey, + (void (*)(void *, const u_int8_t *, u_int16_t))AES_GMAC_Reinit, + (int (*)(void *, const u_int8_t *, u_int16_t))AES_GMAC_Update, + (void (*)(u_int8_t *, void *))AES_GMAC_Final +}; + +static const struct swcr_auth_hash swcr_auth_hash_gmac_aes_256 = { + &auth_hash_gmac_aes_256, sizeof(AES_GMAC_CTX), + (void (*)(void *))AES_GMAC_Init, + (void (*)(void *, const u_int8_t *, u_int16_t))AES_GMAC_Setkey, + (void (*)(void *, const u_int8_t *, u_int16_t))AES_GMAC_Reinit, + (int (*)(void *, const u_int8_t *, u_int16_t))AES_GMAC_Update, + (void (*)(u_int8_t *, void *))AES_GMAC_Final +}; + +/* Compression instance */ +static const struct swcr_comp_algo swcr_comp_algo_deflate = { + &comp_algo_deflate, + deflate_compress, + deflate_decompress +}; + +static const struct swcr_comp_algo swcr_comp_algo_deflate_nogrow = { + &comp_algo_deflate_nogrow, + deflate_compress, + deflate_decompress +}; + +static const struct swcr_comp_algo swcr_comp_algo_gzip = { + &comp_algo_deflate, + gzip_compress, + gzip_decompress +}; + +/* + * Encryption wrapper routines. + */ +static void +null_encrypt(void *key, u_int8_t *blk) +{ +} +static void +null_decrypt(void *key, u_int8_t *blk) +{ +} +static int +null_setkey(u_int8_t **sched, const u_int8_t *key, int len) +{ + *sched = NULL; + return 0; +} +static void +null_zerokey(u_int8_t **sched) +{ + *sched = NULL; +} + +static void +des1_encrypt(void *key, u_int8_t *blk) +{ + des_cblock *cb = (des_cblock *) blk; + des_key_schedule *p = (des_key_schedule *) key; + + des_ecb_encrypt(cb, cb, p[0], DES_ENCRYPT); +} + +static void +des1_decrypt(void *key, u_int8_t *blk) +{ + des_cblock *cb = (des_cblock *) blk; + des_key_schedule *p = (des_key_schedule *) key; + + des_ecb_encrypt(cb, cb, p[0], DES_DECRYPT); +} + +static int +des1_setkey(u_int8_t **sched, const u_int8_t *key, int len) +{ + des_key_schedule *p; + + p = malloc(sizeof (des_key_schedule), + M_CRYPTO_DATA, M_NOWAIT|M_ZERO); + *sched = (u_int8_t *) p; + if (p == NULL) + return ENOMEM; + des_set_key((des_cblock *)__UNCONST(key), p[0]); + return 0; +} + +static void +des1_zerokey(u_int8_t **sched) +{ + memset(*sched, 0, sizeof (des_key_schedule)); + free(*sched, M_CRYPTO_DATA); + *sched = NULL; +} + +static void +des3_encrypt(void *key, u_int8_t *blk) +{ + des_cblock *cb = (des_cblock *) blk; + des_key_schedule *p = (des_key_schedule *) key; + + des_ecb3_encrypt(cb, cb, p[0], p[1], p[2], DES_ENCRYPT); +} + +static void +des3_decrypt(void *key, u_int8_t *blk) +{ + des_cblock *cb = (des_cblock *) blk; + des_key_schedule *p = (des_key_schedule *) key; + + des_ecb3_encrypt(cb, cb, p[0], p[1], p[2], DES_DECRYPT); +} + +static int +des3_setkey(u_int8_t **sched, const u_int8_t *key, int len) +{ + des_key_schedule *p; + + p = malloc(3*sizeof (des_key_schedule), + M_CRYPTO_DATA, M_NOWAIT|M_ZERO); + *sched = (u_int8_t *) p; + if (p == NULL) + return ENOMEM; + des_set_key((des_cblock *)__UNCONST(key + 0), p[0]); + des_set_key((des_cblock *)__UNCONST(key + 8), p[1]); + des_set_key((des_cblock *)__UNCONST(key + 16), p[2]); + return 0; +} + +static void +des3_zerokey(u_int8_t **sched) +{ + memset(*sched, 0, 3*sizeof (des_key_schedule)); + free(*sched, M_CRYPTO_DATA); + *sched = NULL; +} + +static void +blf_encrypt(void *key, u_int8_t *blk) +{ + + BF_ecb_encrypt(blk, blk, (BF_KEY *)key, 1); +} + +static void +blf_decrypt(void *key, u_int8_t *blk) +{ + + BF_ecb_encrypt(blk, blk, (BF_KEY *)key, 0); +} + +static int +blf_setkey(u_int8_t **sched, const u_int8_t *key, int len) +{ + + *sched = malloc(sizeof(BF_KEY), + M_CRYPTO_DATA, M_NOWAIT|M_ZERO); + if (*sched == NULL) + return ENOMEM; + BF_set_key((BF_KEY *) *sched, len, key); + return 0; +} + +static void +blf_zerokey(u_int8_t **sched) +{ + memset(*sched, 0, sizeof(BF_KEY)); + free(*sched, M_CRYPTO_DATA); + *sched = NULL; +} + +static void +cast5_encrypt(void *key, u_int8_t *blk) +{ + cast128_encrypt((cast128_key *) key, blk, blk); +} + +static void +cast5_decrypt(void *key, u_int8_t *blk) +{ + cast128_decrypt((cast128_key *) key, blk, blk); +} + +static int +cast5_setkey(u_int8_t **sched, const u_int8_t *key, int len) +{ + + *sched = malloc(sizeof(cast128_key), M_CRYPTO_DATA, + M_NOWAIT|M_ZERO); + if (*sched == NULL) + return ENOMEM; + cast128_setkey((cast128_key *)*sched, key, len); + return 0; +} + +static void +cast5_zerokey(u_int8_t **sched) +{ + memset(*sched, 0, sizeof(cast128_key)); + free(*sched, M_CRYPTO_DATA); + *sched = NULL; +} + +static void +skipjack_encrypt(void *key, u_int8_t *blk) +{ + skipjack_forwards(blk, blk, (u_int8_t **) key); +} + +static void +skipjack_decrypt(void *key, u_int8_t *blk) +{ + skipjack_backwards(blk, blk, (u_int8_t **) key); +} + +static int +skipjack_setkey(u_int8_t **sched, const u_int8_t *key, int len) +{ + + /* NB: allocate all the memory that's needed at once */ + /* XXX assumes bytes are aligned on sizeof(u_char) == 1 boundaries. + * Will this break a pdp-10, Cray-1, or GE-645 port? + */ + *sched = malloc(10 * (sizeof(u_int8_t *) + 0x100), + M_CRYPTO_DATA, M_NOWAIT|M_ZERO); + + if (*sched == NULL) + return ENOMEM; + + u_int8_t** key_tables = (u_int8_t**) *sched; + u_int8_t* table = (u_int8_t*) &key_tables[10]; + int k; + + for (k = 0; k < 10; k++) { + key_tables[k] = table; + table += 0x100; + } + subkey_table_gen(key, (u_int8_t **) *sched); + return 0; +} + +static void +skipjack_zerokey(u_int8_t **sched) +{ + memset(*sched, 0, 10 * (sizeof(u_int8_t *) + 0x100)); + free(*sched, M_CRYPTO_DATA); + *sched = NULL; +} + +static void +rijndael128_encrypt(void *key, u_int8_t *blk) +{ + rijndael_encrypt((rijndael_ctx *) key, (u_char *) blk, (u_char *) blk); +} + +static void +rijndael128_decrypt(void *key, u_int8_t *blk) +{ + rijndael_decrypt((rijndael_ctx *) key, (u_char *) blk, + (u_char *) blk); +} + +static int +rijndael128_setkey(u_int8_t **sched, const u_int8_t *key, int len) +{ + + if (len != 16 && len != 24 && len != 32) + return EINVAL; + *sched = malloc(sizeof(rijndael_ctx), M_CRYPTO_DATA, + M_NOWAIT|M_ZERO); + if (*sched == NULL) + return ENOMEM; + rijndael_set_key((rijndael_ctx *) *sched, key, len * 8); + return 0; +} + +static void +rijndael128_zerokey(u_int8_t **sched) +{ + memset(*sched, 0, sizeof(rijndael_ctx)); + free(*sched, M_CRYPTO_DATA); + *sched = NULL; +} + +static void +cml_encrypt(void *key, u_int8_t *blk) +{ + + camellia_encrypt(key, blk, blk); +} + +static void +cml_decrypt(void *key, u_int8_t *blk) +{ + + camellia_decrypt(key, blk, blk); +} + +static int +cml_setkey(u_int8_t **sched, const u_int8_t *key, int len) +{ + + if (len != 16 && len != 24 && len != 32) + return (EINVAL); + *sched = malloc(sizeof(camellia_ctx), M_CRYPTO_DATA, + M_NOWAIT|M_ZERO); + if (*sched == NULL) + return ENOMEM; + + camellia_set_key((camellia_ctx *) *sched, key, len * 8); + return 0; +} + +static void +cml_zerokey(u_int8_t **sched) +{ + + memset(*sched, 0, sizeof(camellia_ctx)); + free(*sched, M_CRYPTO_DATA); + *sched = NULL; +} + +#define AESCTR_NONCESIZE 4 +#define AESCTR_IVSIZE 8 +#define AESCTR_BLOCKSIZE 16 + +struct aes_ctr_ctx { + /* need only encryption half */ + u_int32_t ac_ek[4*(RIJNDAEL_MAXNR + 1)]; + u_int8_t ac_block[AESCTR_BLOCKSIZE]; + int ac_nr; + struct { + u_int64_t lastiv; + } ivgenctx; +}; + +static void +aes_ctr_crypt(void *key, u_int8_t *blk) +{ + struct aes_ctr_ctx *ctx; + u_int8_t keystream[AESCTR_BLOCKSIZE]; + int i; + + ctx = key; + /* increment counter */ + for (i = AESCTR_BLOCKSIZE - 1; + i >= AESCTR_NONCESIZE + AESCTR_IVSIZE; i--) + if (++ctx->ac_block[i]) /* continue on overflow */ + break; + rijndaelEncrypt(ctx->ac_ek, ctx->ac_nr, ctx->ac_block, keystream); + for (i = 0; i < AESCTR_BLOCKSIZE; i++) + blk[i] ^= keystream[i]; + memset(keystream, 0, sizeof(keystream)); +} + +int +aes_ctr_setkey(u_int8_t **sched, const u_int8_t *key, int len) +{ + struct aes_ctr_ctx *ctx; + + if (len < AESCTR_NONCESIZE) + return EINVAL; + + ctx = malloc(sizeof(struct aes_ctr_ctx), M_CRYPTO_DATA, + M_NOWAIT|M_ZERO); + if (!ctx) + return ENOMEM; + ctx->ac_nr = rijndaelKeySetupEnc(ctx->ac_ek, (const u_char *)key, + (len - AESCTR_NONCESIZE) * 8); + if (!ctx->ac_nr) { /* wrong key len */ + aes_ctr_zerokey((u_int8_t **)&ctx); + return EINVAL; + } + memcpy(ctx->ac_block, key + len - AESCTR_NONCESIZE, AESCTR_NONCESIZE); + /* random start value for simple counter */ + cprng_fast(&ctx->ivgenctx.lastiv, sizeof(ctx->ivgenctx.lastiv)); + *sched = (void *)ctx; + return 0; +} + +void +aes_ctr_zerokey(u_int8_t **sched) +{ + + memset(*sched, 0, sizeof(struct aes_ctr_ctx)); + free(*sched, M_CRYPTO_DATA); + *sched = NULL; +} + +void +aes_ctr_reinit(void *key, const u_int8_t *iv, u_int8_t *ivout) +{ + struct aes_ctr_ctx *ctx = key; + + if (!iv) { + ctx->ivgenctx.lastiv++; + iv = (const u_int8_t *)&ctx->ivgenctx.lastiv; + } + if (ivout) + memcpy(ivout, iv, AESCTR_IVSIZE); + memcpy(ctx->ac_block + AESCTR_NONCESIZE, iv, AESCTR_IVSIZE); + /* reset counter */ + memset(ctx->ac_block + AESCTR_NONCESIZE + AESCTR_IVSIZE, 0, 4); +} + +void +aes_gcm_reinit(void *key, const u_int8_t *iv, u_int8_t *ivout) +{ + struct aes_ctr_ctx *ctx = key; + + if (!iv) { + ctx->ivgenctx.lastiv++; + iv = (const u_int8_t *)&ctx->ivgenctx.lastiv; + } + if (ivout) + memcpy(ivout, iv, AESCTR_IVSIZE); + memcpy(ctx->ac_block + AESCTR_NONCESIZE, iv, AESCTR_IVSIZE); + /* reset counter */ + memset(ctx->ac_block + AESCTR_NONCESIZE + AESCTR_IVSIZE, 0, 4); + ctx->ac_block[AESCTR_BLOCKSIZE - 1] = 1; /* GCM starts with 1 */ +} + +struct aes_gmac_ctx { + struct { + u_int64_t lastiv; + } ivgenctx; +}; + +int +aes_gmac_setkey(u_int8_t **sched, const u_int8_t *key, int len) +{ + struct aes_gmac_ctx *ctx; + + ctx = malloc(sizeof(struct aes_gmac_ctx), M_CRYPTO_DATA, + M_NOWAIT|M_ZERO); + if (!ctx) + return ENOMEM; + + /* random start value for simple counter */ + cprng_fast(&ctx->ivgenctx.lastiv, sizeof(ctx->ivgenctx.lastiv)); + *sched = (void *)ctx; + return 0; +} + +void +aes_gmac_zerokey(u_int8_t **sched) +{ + + free(*sched, M_CRYPTO_DATA); + *sched = NULL; +} + +void +aes_gmac_reinit(void *key, const u_int8_t *iv, u_int8_t *ivout) +{ + struct aes_gmac_ctx *ctx = key; + + if (!iv) { + ctx->ivgenctx.lastiv++; + iv = (const u_int8_t *)&ctx->ivgenctx.lastiv; + } + if (ivout) + memcpy(ivout, iv, AESCTR_IVSIZE); +} + +/* + * And now for auth. + */ + +static void +null_init(void *ctx) +{ +} + +static int +null_update(void *ctx, const u_int8_t *buf, + u_int16_t len) +{ + return 0; +} + +static void +null_final(u_int8_t *buf, void *ctx) +{ + if (buf != (u_int8_t *) 0) + memset(buf, 0, 12); +} + +static int +RMD160Update_int(void *ctx, const u_int8_t *buf, u_int16_t len) +{ + RMD160Update(ctx, buf, len); + return 0; +} + +static int +MD5Update_int(void *ctx, const u_int8_t *buf, u_int16_t len) +{ + MD5Update(ctx, buf, len); + return 0; +} + +static void +SHA1Init_int(void *ctx) +{ + SHA1Init(ctx); +} + +static int +SHA1Update_int(void *ctx, const u_int8_t *buf, u_int16_t len) +{ + SHA1Update(ctx, buf, len); + return 0; +} + +static void +SHA1Final_int(u_int8_t *blk, void *ctx) +{ + SHA1Final(blk, ctx); +} + +static int +SHA256Update_int(void *ctx, const u_int8_t *buf, u_int16_t len) +{ + SHA256_Update(ctx, buf, len); + return 0; +} + +static int +SHA384Update_int(void *ctx, const u_int8_t *buf, u_int16_t len) +{ + SHA384_Update(ctx, buf, len); + return 0; +} + +static int +SHA512Update_int(void *ctx, const u_int8_t *buf, u_int16_t len) +{ + SHA512_Update(ctx, buf, len); + return 0; +} + +/* + * And compression + */ + +static u_int32_t +deflate_compress(u_int8_t *data, u_int32_t size, u_int8_t **out) +{ + return deflate_global(data, size, 0, out, 0); +} + +static u_int32_t +deflate_decompress(u_int8_t *data, u_int32_t size, u_int8_t **out, + int size_hint) +{ + return deflate_global(data, size, 1, out, size_hint); +} + +static u_int32_t +gzip_compress(u_int8_t *data, u_int32_t size, u_int8_t **out) +{ + return gzip_global(data, size, 0, out, 0); +} + +static u_int32_t +gzip_decompress(u_int8_t *data, u_int32_t size, u_int8_t **out, + int size_hint) +{ + return gzip_global(data, size, 1, out, size_hint); +} diff --git a/sys/opencrypto/deflate.c b/sys/opencrypto/deflate.c new file mode 100644 index 000000000..9c1493203 --- /dev/null +++ b/sys/opencrypto/deflate.c @@ -0,0 +1,430 @@ +/* $NetBSD: deflate.c,v 1.22 2015/03/26 17:40:16 prlw1 Exp $ */ +/* $FreeBSD: src/sys/opencrypto/deflate.c,v 1.1.2.1 2002/11/21 23:34:23 sam Exp $ */ +/* $OpenBSD: deflate.c,v 1.3 2001/08/20 02:45:22 hugh Exp $ */ + +/* + * Copyright (c) 2001 Jean-Jacques Bernard-Gundol (jj@wabbitt.org) + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * + * 1. Redistributions of source code must retain the above copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * 3. The name of the author may not be used to endorse or promote products + * derived from this software without specific prior written permission. + * + * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR + * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES + * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. + * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, + * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT + * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, + * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY + * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT + * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF + * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + */ + +/* + * This file contains a wrapper around the deflate algo compression + * functions using the zlib library (see net/zlib.{c,h}) + */ + +#include +__KERNEL_RCSID(0, "$NetBSD: deflate.c,v 1.22 2015/03/26 17:40:16 prlw1 Exp $"); + +#include +#include +#include +#include +#include + +#include +#include + +#define ZBUF 10 + +struct deflate_buf { + u_int8_t *out; + u_int32_t size; +}; + +int window_inflate = -1 * MAX_WBITS; +int window_deflate = -12; + +/* + * This function takes a block of data and (de)compress it using the deflate + * algorithm + */ + +static void * +ocf_zalloc(void *nil, u_int type, u_int size) +{ + void *ptr; + + ptr = malloc(type *size, M_CRYPTO_DATA, M_NOWAIT); + return ptr; +} + +static void +ocf_zfree(void *nil, void *ptr) +{ + free(ptr, M_CRYPTO_DATA); +} + +u_int32_t +deflate_global(u_int8_t *data, u_int32_t size, int decomp, u_int8_t **out, + int size_hint) +{ + /* decomp indicates whether we compress (0) or decompress (1) */ + + z_stream zbuf; + u_int8_t *output; + u_int32_t count, result, tocopy; + int error, i, j; + struct deflate_buf buf[ZBUF]; + + DPRINTF(("deflate_global: size %u\n", size)); + + memset(&zbuf, 0, sizeof(z_stream)); + zbuf.next_in = data; /* data that is going to be processed */ + zbuf.zalloc = ocf_zalloc; + zbuf.zfree = ocf_zfree; + zbuf.opaque = Z_NULL; + zbuf.avail_in = size; /* Total length of data to be processed */ + + if (!decomp) { + buf[0].size = size; + } else { + /* + * Choose a buffer with 4x the size of the input buffer + * for the size of the output buffer in the case of + * decompression. If it's not sufficient, it will need to be + * updated while the decompression is going on + */ + + buf[0].size = MAX(size * 4, size_hint); + } + buf[0].out = malloc(buf[0].size, M_CRYPTO_DATA, M_NOWAIT); + if (buf[0].out == NULL) + return 0; + i = 1; + + zbuf.next_out = buf[0].out; + zbuf.avail_out = buf[0].size; + + error = decomp ? inflateInit2(&zbuf, window_inflate) : + deflateInit2(&zbuf, Z_DEFAULT_COMPRESSION, Z_METHOD, + window_deflate, Z_MEMLEVEL, Z_DEFAULT_STRATEGY); + + if (error != Z_OK) + goto bad2; + for (;;) { + error = decomp ? inflate(&zbuf, Z_SYNC_FLUSH) : + deflate(&zbuf, Z_FINISH); + if (error == Z_STREAM_END) /* success */ + break; + /* + * XXX compensate for two problems: + * -Former versions of this code didn't set Z_FINISH + * on compression, so the compressed data are not correctly + * terminated and the decompressor doesn't get Z_STREAM_END. + * Accept such packets for interoperability. + * -sys/net/zlib.c has a bug which makes that Z_BUF_ERROR is + * set after successful decompression under rare conditions. + */ + else if (decomp && (error == Z_OK || error == Z_BUF_ERROR) + && zbuf.avail_in == 0 && zbuf.avail_out != 0) + break; + else if (error != Z_OK) + goto bad; + else if (zbuf.avail_out == 0) { + /* we need more output space, allocate size */ + int nextsize = buf[i-1].size * 2; + if (i == ZBUF || nextsize > 1000000) + goto bad; + buf[i].out = malloc(nextsize, M_CRYPTO_DATA, M_NOWAIT); + if (buf[i].out == NULL) + goto bad; + zbuf.next_out = buf[i].out; + zbuf.avail_out = buf[i].size = nextsize; + i++; + } + } + + result = count = zbuf.total_out; + + if (i != 1) { /* copy everything into one buffer */ + output = malloc(result, M_CRYPTO_DATA, M_NOWAIT); + if (output == NULL) + goto bad; + *out = output; + for (j = 0; j < i; j++) { + tocopy = MIN(count, buf[j].size); + /* XXX the last buf can be empty */ + KASSERT(tocopy || j == (i - 1)); + memcpy(output, buf[j].out, tocopy); + output += tocopy; + free(buf[j].out, M_CRYPTO_DATA); + count -= tocopy; + } + KASSERT(count == 0); + } else { + *out = buf[0].out; + } + if (decomp) + inflateEnd(&zbuf); + else + deflateEnd(&zbuf); + return result; + +bad: + if (decomp) + inflateEnd(&zbuf); + else + deflateEnd(&zbuf); +bad2: + for (j = 0; j < i; j++) + free(buf[j].out, M_CRYPTO_DATA); + return 0; +} + +/* + * Initial version will perform a single gzip encapsulation, + * filling in the header, + * and appending the crc and uncompressed length. + * + * Later version will support multiple buffers with + * a flag indication final buffer. The crc is maintained + * over all buffers and appended to the output along with + * the uncompressed length after the final data buffer + * has been compressed and output. + * + * Ditto for uncompress - CRC is extracted from the final packed + * and compared against CRC of uncompressed data. + * + */ + +/* constant header for the gzip */ +static const char gzip_header[10] = { + 0x1f, 0x8b, /* ID1 ID2 */ + Z_DEFLATED, /* CM */ + 0, /* FLG */ + 0, 0, 0, 0, /* MTIME */ + 0, /* XFL */ + 0x03 /* OS (Unix) */ +}; + +/* Followed by compressed payload */ +/* Followed by uint32_t CRC32 and uint32_t ISIZE */ +#define GZIP_TAIL_SIZE 8 + +u_int32_t +gzip_global(u_int8_t *data, u_int32_t size, + int decomp, u_int8_t **out, int size_hint) +{ + /* decomp indicates whether we compress (0) or decompress (1) */ + z_stream zbuf; + u_int8_t *output; + u_int32_t count, result; + int error, i, j; + struct deflate_buf buf[ZBUF]; + u_int32_t crc; + u_int32_t isize = 0, icrc = 0; + + DPRINTF(("gzip_global: decomp %d, size %u\n", decomp, size)); + + memset(&zbuf, 0, sizeof(z_stream)); + zbuf.zalloc = ocf_zalloc; + zbuf.zfree = ocf_zfree; + zbuf.opaque = Z_NULL; + + if (!decomp) { + /* compress */ + DPRINTF(("gzip_global: compress malloc %u + %zu + %u = %zu\n", + size, sizeof(gzip_header), GZIP_TAIL_SIZE, + size + sizeof(gzip_header) + GZIP_TAIL_SIZE)); + + buf[0].size = size; + crc = crc32(0, data, size); + DPRINTF(("gzip_compress: size %u, crc 0x%x\n", size, crc)); + zbuf.avail_in = size; /* Total length of data to be processed */ + zbuf.next_in = data; /* data that is going to be processed */ + } else { + /* decompress */ + /* check the gzip header */ + if (size <= sizeof(gzip_header) + GZIP_TAIL_SIZE) { + /* Not enough data for the header & tail */ + DPRINTF(("gzip_global: not enough data (%u)\n", + size)); + return 0; + } + + /* XXX this is pretty basic, + * needs to be expanded to ignore MTIME, OS, + * but still ensure flags are 0. + * Q. Do we need to support the flags and + * optional header fields? Likely. + * XXX add flag and field support too. + */ + if (memcmp(data, gzip_header, sizeof(gzip_header)) != 0) { + DPRINTF(("gzip_global: unsupported gzip header (%02x%02x)\n", + data[0], data[1])); + return 0; + } else { + DPRINTF(("gzip_global.%d: gzip header ok\n",__LINE__)); + } + + memcpy(&isize, &data[size-sizeof(uint32_t)], sizeof(uint32_t)); + LE32TOH(isize); + memcpy(&icrc, &data[size-2*sizeof(uint32_t)], sizeof(uint32_t)); + LE32TOH(icrc); + + DPRINTF(("gzip_global: isize = %u (%02x %02x %02x %02x)\n", + isize, + data[size-4], + data[size-3], + data[size-2], + data[size-1])); + + buf[0].size = isize; + crc = crc32(0, NULL, 0); /* get initial crc value */ + + /* skip over the gzip header */ + zbuf.next_in = data + sizeof(gzip_header); + + /* actual payload size stripped of gzip header and tail */ + zbuf.avail_in = size - sizeof(gzip_header) - GZIP_TAIL_SIZE; + } + + buf[0].out = malloc(buf[0].size, M_CRYPTO_DATA, M_NOWAIT); + if (buf[0].out == NULL) + return 0; + zbuf.next_out = buf[0].out; + zbuf.avail_out = buf[0].size; + DPRINTF(("zbuf avail_in %u, avail_out %u\n", + zbuf.avail_in, zbuf.avail_out)); + i = 1; + + error = decomp ? inflateInit2(&zbuf, window_inflate) : + deflateInit2(&zbuf, Z_DEFAULT_COMPRESSION, Z_METHOD, + window_deflate, Z_MEMLEVEL, Z_DEFAULT_STRATEGY); + + if (error != Z_OK) { + printf("deflateInit2() failed\n"); + goto bad2; + } + for (;;) { + DPRINTF(("pre: %s in:%u out:%u\n", decomp ? "deflate()" : "inflate()", + zbuf.avail_in, zbuf.avail_out)); + error = decomp ? inflate(&zbuf, Z_SYNC_FLUSH) : + deflate(&zbuf, Z_FINISH); + DPRINTF(("post: %s in:%u out:%u\n", decomp ? "deflate()" : "inflate()", + zbuf.avail_in, zbuf.avail_out)); + if (error == Z_STREAM_END) /* success */ + break; + /* + * XXX compensate for a zlib problem: + * -sys/net/zlib.c has a bug which makes that Z_BUF_ERROR is + * set after successful decompression under rare conditions. + */ + else if (decomp && error == Z_BUF_ERROR + && zbuf.avail_in == 0 && zbuf.avail_out != 0) + break; + else if (error != Z_OK) + goto bad; + else if (zbuf.avail_out == 0) { + /* we need more output space, allocate size */ + int nextsize = buf[i-1].size * 2; + if (i == ZBUF || nextsize > 1000000) + goto bad; + buf[i].out = malloc(nextsize, M_CRYPTO_DATA, M_NOWAIT); + if (buf[i].out == NULL) + goto bad; + zbuf.next_out = buf[i].out; + zbuf.avail_out = buf[i].size = nextsize; + i++; + } + } + + if (decomp) { + count = result = zbuf.total_out; + } else { + /* need room for header, CRC, and ISIZE */ + result = zbuf.total_out + sizeof(gzip_header) + GZIP_TAIL_SIZE; + count = zbuf.total_out; + } + + DPRINTF(("gzip_global: in %u -> out %u\n", size, result)); + + *out = malloc(result, M_CRYPTO_DATA, M_NOWAIT); + if (*out == NULL) + goto bad; + output = *out; + if (decomp) + inflateEnd(&zbuf); + else { + deflateEnd(&zbuf); + + /* fill in gzip header */ + memcpy(output, gzip_header, sizeof(gzip_header)); + output += sizeof(gzip_header); + } + for (j = 0; j < i; j++) { + if (decomp) { + /* update crc for decompressed data */ + crc = crc32(crc, buf[j].out, MIN(count, buf[j].size)); + } + if (count > buf[j].size) { + memcpy(output, buf[j].out, buf[j].size); + output += buf[j].size; + free(buf[j].out, M_CRYPTO_DATA); + count -= buf[j].size; + } else { + /* it should be the last buffer */ + memcpy(output, buf[j].out, count); + output += count; + free(buf[j].out, M_CRYPTO_DATA); + count = 0; + } + } + + if (!decomp) { + /* fill in CRC and ISIZE */ + HTOLE32(crc); + memcpy(output, &crc, sizeof(uint32_t)); + HTOLE32(size); + memcpy(output + sizeof(uint32_t), &size, sizeof(uint32_t)); + + DPRINTF(("gzip_global: size = 0x%x (%02x %02x %02x %02x)\n", + size, + output[7], + output[3], + output[5], + output[4])); + } else { + if (crc != icrc || result != isize) { + DPRINTF(("gzip_global: crc/size mismatch\n")); + free(*out, M_CRYPTO_DATA); + *out = NULL; + return 0; + } + } + + return result; + +bad: + if (decomp) + inflateEnd(&zbuf); + else + deflateEnd(&zbuf); +bad2: + *out = NULL; + for (j = 0; j < i; j++) + free(buf[j].out, M_CRYPTO_DATA); + return 0; +} diff --git a/sys/opencrypto/deflate.h b/sys/opencrypto/deflate.h new file mode 100644 index 000000000..9fef6545d --- /dev/null +++ b/sys/opencrypto/deflate.h @@ -0,0 +1,49 @@ +/* $NetBSD: deflate.h,v 1.9 2011/03/09 11:36:43 drochner Exp $ */ +/* $FreeBSD: src/sys/opencrypto/deflate.h,v 1.1.2.1 2002/11/21 23:34:23 sam Exp $ */ +/* $OpenBSD: deflate.h,v 1.3 2002/03/14 01:26:51 millert Exp $ */ + +/* + * Copyright (c) 2001 Jean-Jacques Bernard-Gundol (jj@wabbitt.org) + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * + * 1. Redistributions of source code must retain the above copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * 3. The name of the author may not be used to endorse or promote products + * derived from this software without specific prior written permission. + * + * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR + * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES + * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. + * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, + * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT + * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, + * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY + * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT + * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF + * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + */ + +/* + * Definition for the wrapper around the deflate compression + * algorithm used in /sys/crypto + */ + +#ifndef _CRYPTO_DEFLATE_H_ +#define _CRYPTO_DEFLATE_H_ + +#include + +#define Z_METHOD 8 +#define Z_MEMLEVEL 8 +#define MINCOMP 2 /* won't be used, but must be defined */ + +u_int32_t deflate_global(u_int8_t *, u_int32_t, int, u_int8_t **, int); +u_int32_t gzip_global(u_int8_t *, u_int32_t, int, u_int8_t **, int); + +#endif /* _CRYPTO_DEFLATE_H_ */ diff --git a/sys/opencrypto/files.opencrypto b/sys/opencrypto/files.opencrypto new file mode 100644 index 000000000..010285cc1 --- /dev/null +++ b/sys/opencrypto/files.opencrypto @@ -0,0 +1,30 @@ +# $NetBSD: files.opencrypto,v 1.25 2011/11/19 22:51:30 tls Exp $ +# +# + +# Opencrypto framework. +# Devices that provide crypto transforms via opencrypto, or subsystems +# that use the opencrypto framework, should list opencrypto as a dependency +# to pull in the framework. + +define opencrypto +file opencrypto/criov.c opencrypto +file opencrypto/xform.c opencrypto +file opencrypto/crypto.c opencrypto + +# Pseudo-device that provides software implementations of various cryptographic +# algorithms. +defpseudo swcrypto: opencrypto, + blowfish, des, cast128, skipjack, camellia +file opencrypto/cryptosoft.c swcrypto +file opencrypto/deflate.c swcrypto # wrapper around zlib +file opencrypto/aesxcbcmac.c swcrypto +file opencrypto/gmac.c swcrypto + +# Pseudo-device for userspace access to opencrypto +# (and thus crypto hardware accelerators). +defpseudo crypto: opencrypto +file opencrypto/cryptodev.c crypto +file opencrypto/ocryptodev.c crypto & compat_50 + +defflag opt_ocf.h CRYPTO_DEBUG CRYPTO_TIMING diff --git a/sys/opencrypto/gmac.c b/sys/opencrypto/gmac.c new file mode 100644 index 000000000..6665c8ddf --- /dev/null +++ b/sys/opencrypto/gmac.c @@ -0,0 +1,193 @@ +/* $NetBSD: gmac.c,v 1.3 2011/06/09 14:47:42 drochner Exp $ */ +/* OpenBSD: gmac.c,v 1.3 2011/01/11 15:44:23 deraadt Exp */ + +/* + * Copyright (c) 2010 Mike Belopuhov + * + * Permission to use, copy, modify, and distribute this software for any + * purpose with or without fee is hereby granted, provided that the above + * copyright notice and this permission notice appear in all copies. + * + * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES + * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF + * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR + * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES + * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN + * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF + * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. + */ + +/* + * This code implements the Message Authentication part of the + * Galois/Counter Mode (as being described in the RFC 4543) using + * the AES cipher. FIPS SP 800-38D describes the algorithm details. + */ + +#include +#include + +#include +#include + +void ghash_gfmul(const GMAC_INT *, const GMAC_INT *, GMAC_INT *); +void ghash_update(GHASH_CTX *, const uint8_t *, size_t); + +/* Computes a block multiplication in the GF(2^128) */ +void +ghash_gfmul(const GMAC_INT *X, const GMAC_INT *Y, GMAC_INT *product) +{ + GMAC_INT v[GMAC_BLOCK_LEN/GMAC_INTLEN]; + uint32_t mul; + int i; + + memcpy(v, Y, GMAC_BLOCK_LEN); + memset(product, 0, GMAC_BLOCK_LEN); + + for (i = 0; i < GMAC_BLOCK_LEN * 8; i++) { + /* update Z */ +#if GMAC_INTLEN == 8 + if (X[i >> 6] & (1ULL << (~i & 63))) { + product[0] ^= v[0]; + product[1] ^= v[1]; + } /* else: we preserve old values */ +#else + if (X[i >> 5] & (1 << (~i & 31))) { + product[0] ^= v[0]; + product[1] ^= v[1]; + product[2] ^= v[2]; + product[3] ^= v[3]; + } /* else: we preserve old values */ +#endif + /* update V */ +#if GMAC_INTLEN == 8 + mul = v[1] & 1; + v[1] = (v[0] << 63) | (v[1] >> 1); + v[0] = (v[0] >> 1) ^ (0xe100000000000000ULL * mul); +#else + mul = v[3] & 1; + v[3] = (v[2] << 31) | (v[3] >> 1); + v[2] = (v[1] << 31) | (v[2] >> 1); + v[1] = (v[0] << 31) | (v[1] >> 1); + v[0] = (v[0] >> 1) ^ (0xe1000000 * mul); +#endif + } +} + +void +ghash_update(GHASH_CTX *ctx, const uint8_t *X, size_t len) +{ + GMAC_INT x; + GMAC_INT *s = ctx->S; + GMAC_INT *y = ctx->Z; + int i, j, k; + + for (i = 0; i < len / GMAC_BLOCK_LEN; i++) { + for (j = 0; j < GMAC_BLOCK_LEN/GMAC_INTLEN; j++) { + x = 0; + for (k = 0; k < GMAC_INTLEN; k++) { + x <<= 8; + x |= X[k]; + } + s[j] = y[j] ^ x; + X += GMAC_INTLEN; + } + + ghash_gfmul(ctx->H, ctx->S, ctx->S); + + y = s; + } + + memcpy(ctx->Z, ctx->S, GMAC_BLOCK_LEN); +} + +#define AESCTR_NONCESIZE 4 + +void +AES_GMAC_Init(AES_GMAC_CTX *ctx) +{ + + memset(ctx, 0, sizeof(AES_GMAC_CTX)); +} + +void +AES_GMAC_Setkey(AES_GMAC_CTX *ctx, const uint8_t *key, uint16_t klen) +{ + int i; + + ctx->rounds = rijndaelKeySetupEnc(ctx->K, (const u_char *)key, + (klen - AESCTR_NONCESIZE) * 8); + /* copy out salt to the counter block */ + memcpy(ctx->J, key + klen - AESCTR_NONCESIZE, AESCTR_NONCESIZE); + /* prepare a hash subkey */ + rijndaelEncrypt(ctx->K, ctx->rounds, (void *)ctx->ghash.H, + (void *)ctx->ghash.H); +#if GMAC_INTLEN == 8 + for (i = 0; i < 2; i++) + ctx->ghash.H[i] = be64toh(ctx->ghash.H[i]); +#else + for (i = 0; i < 4; i++) + ctx->ghash.H[i] = be32toh(ctx->ghash.H[i]); +#endif +} + +void +AES_GMAC_Reinit(AES_GMAC_CTX *ctx, const uint8_t *iv, uint16_t ivlen) +{ + /* copy out IV to the counter block */ + memcpy(ctx->J + AESCTR_NONCESIZE, iv, ivlen); +} + +int +AES_GMAC_Update(AES_GMAC_CTX *ctx, const uint8_t *data, uint16_t len) +{ + uint8_t blk[16] = { 0 }; + int plen; + + if (len > 0) { + plen = len % GMAC_BLOCK_LEN; + if (len >= GMAC_BLOCK_LEN) + ghash_update(&ctx->ghash, data, len - plen); + if (plen) { + memcpy(blk, data + (len - plen), plen); + ghash_update(&ctx->ghash, blk, GMAC_BLOCK_LEN); + } + } + return (0); +} + +void +AES_GMAC_Final(uint8_t digest[GMAC_DIGEST_LEN], AES_GMAC_CTX *ctx) +{ + uint8_t keystream[GMAC_BLOCK_LEN], *k, *d; + int i; + + /* do one round of GCTR */ + ctx->J[GMAC_BLOCK_LEN - 1] = 1; + rijndaelEncrypt(ctx->K, ctx->rounds, ctx->J, keystream); + k = keystream; + d = digest; +#if GMAC_INTLEN == 8 + for (i = 0; i < GMAC_DIGEST_LEN/8; i++) { + d[0] = (uint8_t)(ctx->ghash.S[i] >> 56) ^ k[0]; + d[1] = (uint8_t)(ctx->ghash.S[i] >> 48) ^ k[1]; + d[2] = (uint8_t)(ctx->ghash.S[i] >> 40) ^ k[2]; + d[3] = (uint8_t)(ctx->ghash.S[i] >> 32) ^ k[3]; + d[4] = (uint8_t)(ctx->ghash.S[i] >> 24) ^ k[4]; + d[5] = (uint8_t)(ctx->ghash.S[i] >> 16) ^ k[5]; + d[6] = (uint8_t)(ctx->ghash.S[i] >> 8) ^ k[6]; + d[7] = (uint8_t)ctx->ghash.S[i] ^ k[7]; + d += 8; + k += 8; + } +#else + for (i = 0; i < GMAC_DIGEST_LEN/4; i++) { + d[0] = (uint8_t)(ctx->ghash.S[i] >> 24) ^ k[0]; + d[1] = (uint8_t)(ctx->ghash.S[i] >> 16) ^ k[1]; + d[2] = (uint8_t)(ctx->ghash.S[i] >> 8) ^ k[2]; + d[3] = (uint8_t)ctx->ghash.S[i] ^ k[3]; + d += 4; + k += 4; + } +#endif + memset(keystream, 0, sizeof(keystream)); +} diff --git a/sys/opencrypto/gmac.h b/sys/opencrypto/gmac.h new file mode 100644 index 000000000..614a1f005 --- /dev/null +++ b/sys/opencrypto/gmac.h @@ -0,0 +1,59 @@ +/* $NetBSD: gmac.h,v 1.2 2011/06/09 14:47:42 drochner Exp $ */ +/* OpenBSD: gmac.h,v 1.1 2010/09/22 11:54:23 mikeb Exp */ + +/* + * Copyright (c) 2010 Mike Belopuhov + * + * Permission to use, copy, modify, and distribute this software for any + * purpose with or without fee is hereby granted, provided that the above + * copyright notice and this permission notice appear in all copies. + * + * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES + * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF + * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR + * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES + * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN + * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF + * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. + */ + +#ifndef _GMAC_H_ +#define _GMAC_H_ + +#include + +#define GMAC_BLOCK_LEN 16 +#define GMAC_DIGEST_LEN 16 + +#ifdef _LP64 +#define GMAC_INT uint64_t +#define GMAC_INTLEN 8 +#else +#define GMAC_INT uint32_t +#define GMAC_INTLEN 4 +#endif + +typedef struct _GHASH_CTX { + GMAC_INT H[GMAC_BLOCK_LEN/GMAC_INTLEN]; /* hash subkey */ + GMAC_INT S[GMAC_BLOCK_LEN/GMAC_INTLEN]; /* state */ + GMAC_INT Z[GMAC_BLOCK_LEN/GMAC_INTLEN]; /* initial state */ +} GHASH_CTX; + +typedef struct _AES_GMAC_CTX { + GHASH_CTX ghash; + uint32_t K[4*(RIJNDAEL_MAXNR + 1)]; + uint8_t J[GMAC_BLOCK_LEN]; /* counter block */ + int rounds; +} AES_GMAC_CTX; + +#include + +__BEGIN_DECLS +void AES_GMAC_Init(AES_GMAC_CTX *); +void AES_GMAC_Setkey(AES_GMAC_CTX *, const uint8_t *, uint16_t); +void AES_GMAC_Reinit(AES_GMAC_CTX *, const uint8_t *, uint16_t); +int AES_GMAC_Update(AES_GMAC_CTX *, const uint8_t *, uint16_t); +void AES_GMAC_Final(uint8_t [GMAC_DIGEST_LEN], AES_GMAC_CTX *); +__END_DECLS + +#endif /* _GMAC_H_ */ diff --git a/sys/opencrypto/ocryptodev.c b/sys/opencrypto/ocryptodev.c new file mode 100644 index 000000000..d69aafb40 --- /dev/null +++ b/sys/opencrypto/ocryptodev.c @@ -0,0 +1,273 @@ +/* $NetBSD: ocryptodev.c,v 1.6 2014/09/05 09:23:40 matt Exp $ */ +/* $FreeBSD: src/sys/opencrypto/cryptodev.c,v 1.4.2.4 2003/06/03 00:09:02 sam Exp $ */ +/* $OpenBSD: cryptodev.c,v 1.53 2002/07/10 22:21:30 mickey Exp $ */ + +/*- + * Copyright (c) 2008 The NetBSD Foundation, Inc. + * All rights reserved. + * + * This code is derived from software contributed to The NetBSD Foundation + * by Coyote Point Systems, Inc. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the above copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * + * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS + * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED + * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR + * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS + * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR + * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF + * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS + * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN + * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) + * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE + * POSSIBILITY OF SUCH DAMAGE. + */ + +/* + * Copyright (c) 2001 Theo de Raadt + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * + * 1. Redistributions of source code must retain the above copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * 3. The name of the author may not be used to endorse or promote products + * derived from this software without specific prior written permission. + * + * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR + * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES + * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. + * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, + * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT + * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, + * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY + * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT + * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF + * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + * + * Effort sponsored in part by the Defense Advanced Research Projects + * Agency (DARPA) and Air Force Research Laboratory, Air Force + * Materiel Command, USAF, under agreement number F30602-01-2-0537. + * + */ + +/* + * Implement backward compatibility IOCTLs in this module. + * + */ + +#include +__KERNEL_RCSID(0, "$NetBSD: ocryptodev.c,v 1.6 2014/09/05 09:23:40 matt Exp $"); + +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include + +#ifdef _KERNEL_OPT +#include "opt_ocf.h" +#endif + +#include +#include +#include +#include + +static int ocryptodev_op(struct csession *, struct ocrypt_op *, + struct lwp *); +static int ocryptodev_mop(struct fcrypt *, struct ocrypt_n_op *, int, + struct lwp *); +static int ocryptodev_session(struct fcrypt *, struct osession_op *); +static int ocryptodev_msession(struct fcrypt *, struct osession_n_op *, int); + +int +ocryptof_ioctl(struct file *fp, u_long cmd, void *data) +{ + struct fcrypt *fcr = fp->f_fcrypt; + struct csession *cse; + struct osession_op *osop; + struct osession_n_op *osnop; + struct ocrypt_op *ocop; + struct ocrypt_mop *omop; + struct ocrypt_n_op *ocnop; + struct ocrypt_sgop *osgop; + + int error = 0; + + switch (cmd) { + case OCIOCGSESSION: + osop = (struct osession_op *)data; + error = ocryptodev_session(fcr, osop); + break; + case CIOCNGSESSION: + osgop = (struct ocrypt_sgop *)data; + osnop = kmem_alloc((osgop->count * + sizeof(struct osession_n_op)), KM_SLEEP); + error = copyin(osgop->sessions, osnop, osgop->count * + sizeof(struct osession_n_op)); + if (error) { + goto mbail; + } + + error = ocryptodev_msession(fcr, osnop, osgop->count); + if (error) { + goto mbail; + } + + error = copyout(osnop, osgop->sessions, osgop->count * + sizeof(struct osession_n_op)); +mbail: + kmem_free(osnop, osgop->count * sizeof(struct osession_n_op)); + break; + case OCIOCCRYPT: + mutex_enter(&crypto_mtx); + ocop = (struct ocrypt_op *)data; + cse = cryptodev_csefind(fcr, ocop->ses); + mutex_exit(&crypto_mtx); + if (cse == NULL) { + DPRINTF(("csefind failed\n")); + return EINVAL; + } + error = ocryptodev_op(cse, ocop, curlwp); + DPRINTF(("ocryptodev_op error = %d\n", error)); + break; + case OCIOCNCRYPTM: + omop = (struct ocrypt_mop *)data; + ocnop = kmem_alloc((omop->count * sizeof(struct ocrypt_n_op)), + KM_SLEEP); + error = copyin(omop->reqs, ocnop, + (omop->count * sizeof(struct ocrypt_n_op))); + if(!error) { + error = ocryptodev_mop(fcr, ocnop, omop->count, curlwp); + if (!error) { + error = copyout(ocnop, omop->reqs, + (omop->count * sizeof(struct ocrypt_n_op))); + } + } + kmem_free(ocnop, (omop->count * sizeof(struct ocrypt_n_op))); + break; + default: + DPRINTF(("invalid ioctl cmd 0x%lx\n", cmd)); + return EINVAL; + } + return error; +} + + +static int +ocryptodev_op(struct csession *cse, struct ocrypt_op *ocop, struct lwp *l) +{ + struct crypt_op cop; + + cop.ses = ocop->ses; + cop.op = ocop->op; + cop.flags = ocop->flags; + cop.len = ocop->len; + cop.src = ocop->src; + cop.dst = ocop->dst; + cop.mac = ocop->mac; + cop.iv = ocop->iv; + cop.dst_len = 0; + + return cryptodev_op(cse, &cop, l); +}; + +static int +ocryptodev_mop(struct fcrypt *fcr, + struct ocrypt_n_op *ocnop, + int count, struct lwp *l) +{ + int res; + + struct crypt_n_op cnop; + + cnop.ses = ocnop->ses; + cnop.op = ocnop->op; + cnop.flags = ocnop->flags; + cnop.len = ocnop->len; + cnop.reqid = ocnop->reqid; + cnop.status = ocnop->status; + cnop.opaque = ocnop->opaque; + cnop.keylen = ocnop->keylen; + cnop.key = ocnop->key; + cnop.mackeylen = ocnop->mackeylen; + cnop.mackey = ocnop->mackey; + cnop.src = ocnop->src; + cnop.dst = ocnop->dst; + cnop.mac = ocnop->mac; + cnop.iv = ocnop->iv; + cnop.dst_len = 0; + res = cryptodev_mop(fcr, &cnop, count, l); + ocnop->reqid = cnop.reqid; + ocnop->status = cnop.status; + + return res; +}; + + +static int +ocryptodev_session(struct fcrypt *fcr, struct osession_op *osop) +{ + struct session_op sop; + int res; + + sop.cipher = osop->cipher; + sop.mac = osop->mac; + sop.comp_alg = 0; + sop.keylen = osop->keylen; + sop.key = osop->key; + sop.mackeylen = osop->mackeylen; + sop.mackey = osop->mackey; + res = cryptodev_session(fcr, &sop); + osop->ses = sop.ses; + return res; + +} + +static int +ocryptodev_msession(struct fcrypt *fcr, struct osession_n_op *osn_ops, + int count) +{ + int i; + + for (i = 0; i < count; i++, osn_ops++) { + struct osession_op os_op; + os_op.cipher = osn_ops->cipher; + os_op.mac = osn_ops->mac; + os_op.keylen = osn_ops->keylen; + os_op.key = osn_ops->key; + os_op.mackeylen = osn_ops->mackeylen; + os_op.mackey = osn_ops->mackey; + + osn_ops->status = ocryptodev_session(fcr, &os_op); + osn_ops->ses = os_op.ses; + } + + return 0; +} diff --git a/sys/opencrypto/ocryptodev.h b/sys/opencrypto/ocryptodev.h new file mode 100644 index 000000000..9ed3cae5a --- /dev/null +++ b/sys/opencrypto/ocryptodev.h @@ -0,0 +1,175 @@ +/* $NetBSD: ocryptodev.h,v 1.3 2015/09/06 06:01:02 dholland Exp $ */ +/* $FreeBSD: src/sys/opencrypto/cryptodev.h,v 1.2.2.6 2003/07/02 17:04:50 sam Exp $ */ +/* $OpenBSD: cryptodev.h,v 1.33 2002/07/17 23:52:39 art Exp $ */ + +/*- + * Copyright (c) 2008 The NetBSD Foundation, Inc. + * All rights reserved. + * + * This code is derived from software contributed to The NetBSD Foundation + * by Coyote Point Systems, Inc. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the above copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * + * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS + * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED + * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR + * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS + * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR + * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF + * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS + * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN + * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) + * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE + * POSSIBILITY OF SUCH DAMAGE. + */ + +/* + * The author of this code is Angelos D. Keromytis (angelos@cis.upenn.edu) + * + * This code was written by Angelos D. Keromytis in Athens, Greece, in + * February 2000. Network Security Technologies Inc. (NSTI) kindly + * supported the development of this code. + * + * Copyright (c) 2000 Angelos D. Keromytis + * + * Permission to use, copy, and modify this software with or without fee + * is hereby granted, provided that this entire notice is included in + * all source code copies of any software which is or includes a copy or + * modification of this software. + * + * THIS SOFTWARE IS BEING PROVIDED "AS IS", WITHOUT ANY EXPRESS OR + * IMPLIED WARRANTY. IN PARTICULAR, NONE OF THE AUTHORS MAKES ANY + * REPRESENTATION OR WARRANTY OF ANY KIND CONCERNING THE + * MERCHANTABILITY OF THIS SOFTWARE OR ITS FITNESS FOR ANY PARTICULAR + * PURPOSE. + * + * Copyright (c) 2001 Theo de Raadt + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * + * 1. Redistributions of source code must retain the above copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * 3. The name of the author may not be used to endorse or promote products + * derived from this software without specific prior written permission. + * + * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR + * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES + * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. + * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, + * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT + * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, + * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY + * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT + * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF + * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + * + * Effort sponsored in part by the Defense Advanced Research Projects + * Agency (DARPA) and Air Force Research Laboratory, Air Force + * Materiel Command, USAF, under agreement number F30602-01-2-0537. + * + */ + +#ifndef _CRYPTO_OCRYPTODEV_H_ +#define _CRYPTO_OCRYPTODEV_H_ + +#include + +struct osession_op { /* backwards compatible */ + u_int32_t cipher; /* ie. CRYPTO_DES_CBC */ + u_int32_t mac; /* ie. CRYPTO_MD5_HMAC */ + u_int32_t keylen; /* cipher key */ + void * key; + int mackeylen; /* mac key */ + void * mackey; + + u_int32_t ses; /* returns: session # */ +}; + +struct osession_n_op { + u_int32_t cipher; /* ie. CRYPTO_DES_CBC */ + u_int32_t mac; /* ie. CRYPTO_MD5_HMAC */ + + u_int32_t keylen; /* cipher key */ + void * key; + int mackeylen; /* mac key */ + void * mackey; + + u_int32_t ses; /* returns: session # */ + int status; +}; + +struct ocrypt_op { + u_int32_t ses; + u_int16_t op; /* i.e. COP_ENCRYPT */ + u_int16_t flags; + u_int len; + void * src, *dst; /* become iov[] inside kernel */ + void * mac; /* must be big enough for chosen MAC */ + void * iv; +}; + +/* to support multiple session creation */ +/* + * + * The reqid field is filled when the operation has + * been accepted and started, and can be used to later retrieve + * the operation results via CIOCNCRYPTRET or identify the + * request in the completion list returned by CIOCNCRYPTRETM. + * + * The opaque pointer can be set arbitrarily by the user + * and it is passed back in the crypt_result structure + * when the request completes. This field can be used for example + * to track context for the request and avoid lookups in the + * user application. + */ + +struct ocrypt_n_op { + u_int32_t ses; + u_int16_t op; /* i.e. COP_ENCRYPT */ + u_int16_t flags; + u_int len; /* src & dst len */ + + u_int32_t reqid; /* request id */ + int status; /* status of request -accepted or not */ + void *opaque; /* opaque pointer returned to user */ + u_int32_t keylen; /* cipher key - optional */ + void * key; + u_int32_t mackeylen; /* also optional */ + void * mackey; + + void * src, *dst; /* become iov[] inside kernel */ + void * mac; /* must be big enough for chosen MAC */ + void * iv; +}; + +struct ocrypt_sgop { + size_t count; + struct osession_n_op * sessions; +}; + +struct ocrypt_mop { + size_t count; /* how many */ + struct ocrypt_n_op * reqs; /* where to get them */ +}; + +#define OCIOCGSESSION _IOWR('c', 101, struct osession_op) +#define OCIOCNGSESSION _IOWR('c', 106, struct ocrypt_sgop) +#define OCIOCCRYPT _IOWR('c', 103, struct ocrypt_op) +#define OCIOCNCRYPTM _IOWR('c', 107, struct ocrypt_mop) + +int ocryptof_ioctl(struct file *, u_long, void *); + +#endif /* _CRYPTO_OCRYPTODEV_H_ */ diff --git a/sys/opencrypto/xform.c b/sys/opencrypto/xform.c new file mode 100644 index 000000000..62e7b2612 --- /dev/null +++ b/sys/opencrypto/xform.c @@ -0,0 +1,258 @@ +/* $NetBSD: xform.c,v 1.28 2011/05/26 21:50:03 drochner Exp $ */ +/* $FreeBSD: src/sys/opencrypto/xform.c,v 1.1.2.1 2002/11/21 23:34:23 sam Exp $ */ +/* $OpenBSD: xform.c,v 1.19 2002/08/16 22:47:25 dhartmei Exp $ */ + +/* + * The authors of this code are John Ioannidis (ji@tla.org), + * Angelos D. Keromytis (kermit@csd.uch.gr) and + * Niels Provos (provos@physnet.uni-hamburg.de). + * + * This code was written by John Ioannidis for BSD/OS in Athens, Greece, + * in November 1995. + * + * Ported to OpenBSD and NetBSD, with additional transforms, in December 1996, + * by Angelos D. Keromytis. + * + * Additional transforms and features in 1997 and 1998 by Angelos D. Keromytis + * and Niels Provos. + * + * Additional features in 1999 by Angelos D. Keromytis. + * + * Copyright (C) 1995, 1996, 1997, 1998, 1999 by John Ioannidis, + * Angelos D. Keromytis and Niels Provos. + * + * Copyright (C) 2001, Angelos D. Keromytis. + * + * Permission to use, copy, and modify this software with or without fee + * is hereby granted, provided that this entire notice is included in + * all copies of any software which is or includes a copy or + * modification of this software. + * You may use this code under the GNU public license if you so wish. Please + * contribute changes back to the authors under this freer than GPL license + * so that we may further the use of strong encryption without limitations to + * all. + * + * THIS SOFTWARE IS BEING PROVIDED "AS IS", WITHOUT ANY EXPRESS OR + * IMPLIED WARRANTY. IN PARTICULAR, NONE OF THE AUTHORS MAKES ANY + * REPRESENTATION OR WARRANTY OF ANY KIND CONCERNING THE + * MERCHANTABILITY OF THIS SOFTWARE OR ITS FITNESS FOR ANY PARTICULAR + * PURPOSE. + */ + +#include +__KERNEL_RCSID(0, "$NetBSD: xform.c,v 1.28 2011/05/26 21:50:03 drochner Exp $"); + +#include +#include + +#include +#include + +MALLOC_DEFINE(M_XDATA, "xform", "xform data buffers"); + +const u_int8_t hmac_ipad_buffer[128] = { + 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, + 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, + 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, + 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, + 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, + 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, + 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, + 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, + 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, + 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, + 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, + 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, + 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, + 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, + 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, + 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36 +}; + +const u_int8_t hmac_opad_buffer[128] = { + 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, + 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, + 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, + 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, + 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, + 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, + 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, + 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, + 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, + 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, + 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, + 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, + 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, + 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, + 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, + 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C, 0x5C +}; + +/* Encryption instances */ +const struct enc_xform enc_xform_null = { + CRYPTO_NULL_CBC, "NULL", + /* NB: blocksize of 4 is to generate a properly aligned ESP header */ + 4, 0, 0, 256 /* 2048 bits, max key */ +}; + +const struct enc_xform enc_xform_des = { + CRYPTO_DES_CBC, "DES", + 8, 8, 8, 8 +}; + +const struct enc_xform enc_xform_3des = { + CRYPTO_3DES_CBC, "3DES", + 8, 8, 24, 24 +}; + +const struct enc_xform enc_xform_blf = { + CRYPTO_BLF_CBC, "Blowfish", + 8, 8, 5, 56 /* 448 bits, max key */ +}; + +const struct enc_xform enc_xform_cast5 = { + CRYPTO_CAST_CBC, "CAST-128", + 8, 8, 5, 16 +}; + +const struct enc_xform enc_xform_skipjack = { + CRYPTO_SKIPJACK_CBC, "Skipjack", + 8, 8, 10, 10 +}; + +const struct enc_xform enc_xform_rijndael128 = { + CRYPTO_RIJNDAEL128_CBC, "Rijndael-128/AES", + 16, 16, 16, 32 +}; + +const struct enc_xform enc_xform_arc4 = { + CRYPTO_ARC4, "ARC4", + 1, 0, 1, 32 +}; + +const struct enc_xform enc_xform_camellia = { + CRYPTO_CAMELLIA_CBC, "Camellia", + 16, 16, 8, 32 +}; + +const struct enc_xform enc_xform_aes_ctr = { + CRYPTO_AES_CTR, "AES-CTR", + 16, 8, 16+4, 32+4 +}; + +const struct enc_xform enc_xform_aes_gcm = { + CRYPTO_AES_GCM_16, "AES-GCM", + 4 /* ??? */, 8, 16+4, 32+4 +}; + +const struct enc_xform enc_xform_aes_gmac = { + CRYPTO_AES_GMAC, "AES-GMAC", + 4 /* ??? */, 8, 16+4, 32+4 +}; + +/* Authentication instances */ +const struct auth_hash auth_hash_null = { + CRYPTO_NULL_HMAC, "NULL-HMAC", + 0, 0, 12, 64 +}; + +const struct auth_hash auth_hash_hmac_md5 = { + CRYPTO_MD5_HMAC, "HMAC-MD5", + 16, 16, 16, 64 +}; + +const struct auth_hash auth_hash_hmac_sha1 = { + CRYPTO_SHA1_HMAC, "HMAC-SHA1", + 20, 20, 20, 64 +}; + +const struct auth_hash auth_hash_hmac_ripemd_160 = { + CRYPTO_RIPEMD160_HMAC, "HMAC-RIPEMD-160", + 20, 20, 20, 64 +}; + +const struct auth_hash auth_hash_hmac_md5_96 = { + CRYPTO_MD5_HMAC_96, "HMAC-MD5-96", + 16, 16, 12, 64 +}; + +const struct auth_hash auth_hash_hmac_sha1_96 = { + CRYPTO_SHA1_HMAC_96, "HMAC-SHA1-96", + 20, 20, 12, 64 +}; + +const struct auth_hash auth_hash_hmac_ripemd_160_96 = { + CRYPTO_RIPEMD160_HMAC_96, "HMAC-RIPEMD-160", + 20, 20, 12, 64 +}; + +const struct auth_hash auth_hash_key_md5 = { + CRYPTO_MD5_KPDK, "Keyed MD5", + 0, 16, 16, 0 +}; + +const struct auth_hash auth_hash_key_sha1 = { + CRYPTO_SHA1_KPDK, "Keyed SHA1", + 0, 20, 20, 0 +}; + +const struct auth_hash auth_hash_md5 = { + CRYPTO_MD5, "MD5", + 0, 16, 16, 0 +}; + +const struct auth_hash auth_hash_sha1 = { + CRYPTO_SHA1, "SHA1", + 0, 20, 20, 0 +}; + +const struct auth_hash auth_hash_hmac_sha2_256 = { + CRYPTO_SHA2_256_HMAC, "HMAC-SHA2", + 32, 32, 16, 64 +}; + +const struct auth_hash auth_hash_hmac_sha2_384 = { + CRYPTO_SHA2_384_HMAC, "HMAC-SHA2-384", + 48, 48, 24, 128 +}; + +const struct auth_hash auth_hash_hmac_sha2_512 = { + CRYPTO_SHA2_512_HMAC, "HMAC-SHA2-512", + 64, 64, 32, 128 +}; + +const struct auth_hash auth_hash_aes_xcbc_mac_96 = { + CRYPTO_AES_XCBC_MAC_96, "AES-XCBC-MAC-96", + 16, 16, 12, 0 +}; + +const struct auth_hash auth_hash_gmac_aes_128 = { + CRYPTO_AES_128_GMAC, "GMAC-AES-128", + 16+4, 16, 16, 16 /* ??? */ +}; + +const struct auth_hash auth_hash_gmac_aes_192 = { + CRYPTO_AES_192_GMAC, "GMAC-AES-192", + 24+4, 16, 16, 16 /* ??? */ +}; + +const struct auth_hash auth_hash_gmac_aes_256 = { + CRYPTO_AES_256_GMAC, "GMAC-AES-256", + 32+4, 16, 16, 16 /* ??? */ +}; + +/* Compression instance */ +const struct comp_algo comp_algo_deflate = { + CRYPTO_DEFLATE_COMP, "Deflate", + 90 +}; + +const struct comp_algo comp_algo_deflate_nogrow = { + CRYPTO_DEFLATE_COMP_NOGROW, "Deflate", + 90 +}; + +const struct comp_algo comp_algo_gzip = { + CRYPTO_GZIP_COMP, "GZIP", + 90 +}; diff --git a/sys/opencrypto/xform.h b/sys/opencrypto/xform.h new file mode 100644 index 000000000..97caaa521 --- /dev/null +++ b/sys/opencrypto/xform.h @@ -0,0 +1,98 @@ +/* $NetBSD: xform.h,v 1.19 2011/05/26 21:50:03 drochner Exp $ */ +/* $FreeBSD: src/sys/opencrypto/xform.h,v 1.1.2.1 2002/11/21 23:34:23 sam Exp $ */ +/* $OpenBSD: xform.h,v 1.10 2002/04/22 23:10:09 deraadt Exp $ */ + +/* + * The author of this code is Angelos D. Keromytis (angelos@cis.upenn.edu) + * + * This code was written by Angelos D. Keromytis in Athens, Greece, in + * February 2000. Network Security Technologies Inc. (NSTI) kindly + * supported the development of this code. + * + * Copyright (c) 2000 Angelos D. Keromytis + * + * Permission to use, copy, and modify this software with or without fee + * is hereby granted, provided that this entire notice is included in + * all source code copies of any software which is or includes a copy or + * modification of this software. + * + * THIS SOFTWARE IS BEING PROVIDED "AS IS", WITHOUT ANY EXPRESS OR + * IMPLIED WARRANTY. IN PARTICULAR, NONE OF THE AUTHORS MAKES ANY + * REPRESENTATION OR WARRANTY OF ANY KIND CONCERNING THE + * MERCHANTABILITY OF THIS SOFTWARE OR ITS FITNESS FOR ANY PARTICULAR + * PURPOSE. + */ + +#ifndef _CRYPTO_XFORM_H_ +#define _CRYPTO_XFORM_H_ + +/* Declarations */ +struct auth_hash { + int type; + const char *name; + u_int16_t keysize; + u_int16_t hashsize; + u_int16_t authsize; + u_int16_t blocksize; +}; + +/* Provide array-limit for clients (e.g., netipsec) */ +#define AH_ALEN_MAX 32 /* max authenticator hash length */ + +struct enc_xform { + int type; + const char *name; + u_int16_t blocksize, ivsize; + u_int16_t minkey, maxkey; +}; + +struct comp_algo { + int type; + const char *name; + size_t minlen; +}; + +extern const u_int8_t hmac_ipad_buffer[128]; +extern const u_int8_t hmac_opad_buffer[128]; + +extern const struct enc_xform enc_xform_null; +extern const struct enc_xform enc_xform_des; +extern const struct enc_xform enc_xform_3des; +extern const struct enc_xform enc_xform_blf; +extern const struct enc_xform enc_xform_cast5; +extern const struct enc_xform enc_xform_skipjack; +extern const struct enc_xform enc_xform_rijndael128; +extern const struct enc_xform enc_xform_arc4; +extern const struct enc_xform enc_xform_camellia; +extern const struct enc_xform enc_xform_aes_ctr; +extern const struct enc_xform enc_xform_aes_gcm; +extern const struct enc_xform enc_xform_aes_gmac; + +extern const struct auth_hash auth_hash_null; +extern const struct auth_hash auth_hash_md5; +extern const struct auth_hash auth_hash_sha1; +extern const struct auth_hash auth_hash_key_md5; +extern const struct auth_hash auth_hash_key_sha1; +extern const struct auth_hash auth_hash_hmac_md5; +extern const struct auth_hash auth_hash_hmac_sha1; +extern const struct auth_hash auth_hash_hmac_ripemd_160; +extern const struct auth_hash auth_hash_hmac_md5_96; +extern const struct auth_hash auth_hash_hmac_sha1_96; +extern const struct auth_hash auth_hash_hmac_ripemd_160_96; +extern const struct auth_hash auth_hash_hmac_sha2_256; +extern const struct auth_hash auth_hash_hmac_sha2_384; +extern const struct auth_hash auth_hash_hmac_sha2_512; +extern const struct auth_hash auth_hash_aes_xcbc_mac_96; +extern const struct auth_hash auth_hash_gmac_aes_128; +extern const struct auth_hash auth_hash_gmac_aes_192; +extern const struct auth_hash auth_hash_gmac_aes_256; + +extern const struct comp_algo comp_algo_deflate; +extern const struct comp_algo comp_algo_deflate_nogrow; +extern const struct comp_algo comp_algo_gzip; + +#ifdef _KERNEL +#include +MALLOC_DECLARE(M_XDATA); +#endif +#endif /* _CRYPTO_XFORM_H_ */ diff --git a/sys/rump/kern/Makefile b/sys/rump/kern/Makefile new file mode 100644 index 000000000..0a5dbfb7d --- /dev/null +++ b/sys/rump/kern/Makefile @@ -0,0 +1,6 @@ +# $NetBSD: Makefile,v 1.1 2010/06/10 21:56:42 pooka Exp $ +# + +SUBDIR= lib + +.include diff --git a/sys/rump/kern/Makefile.rumpkerncomp b/sys/rump/kern/Makefile.rumpkerncomp new file mode 100644 index 000000000..c6d84ee9f --- /dev/null +++ b/sys/rump/kern/Makefile.rumpkerncomp @@ -0,0 +1,19 @@ +# $NetBSD: Makefile.rumpkerncomp,v 1.11 2015/01/07 22:24:03 pooka Exp $ +# + +.include + +RUMPKERNCOMPS= crypto sysproxy tty z + +.if ${MKSLJIT} != "no" +RUMPKERNCOMPS+= sljit +.endif + +.if ${MKZFS} != "no" +RUMPKERNCOMPS+= solaris +.endif + +.for var in ${RUMPKERNCOMPS} +RUMPKERNLIBS+=lib${var} +RUMPKERNLDADD+=-lrumpkern_${var} +.endfor diff --git a/sys/rump/kern/lib/Makefile b/sys/rump/kern/lib/Makefile new file mode 100644 index 000000000..0930cd42f --- /dev/null +++ b/sys/rump/kern/lib/Makefile @@ -0,0 +1,8 @@ +# $NetBSD: Makefile,v 1.6 2014/08/25 18:44:02 pooka Exp $ +# + +.include "${.CURDIR}/../Makefile.rumpkerncomp" + +SUBDIR+= ${RUMPKERNLIBS} + +.include diff --git a/sys/rump/kern/lib/Makefile.inc b/sys/rump/kern/lib/Makefile.inc new file mode 100644 index 000000000..e249c327e --- /dev/null +++ b/sys/rump/kern/lib/Makefile.inc @@ -0,0 +1,6 @@ +# $NetBSD: Makefile.inc,v 1.1 2010/06/10 21:56:42 pooka Exp $ +# + +RUMPTOP= ${.CURDIR}/../../.. + +.include "${RUMPTOP}/Makefile.rump" diff --git a/sys/rump/kern/lib/Makefile.sys b/sys/rump/kern/lib/Makefile.sys new file mode 100644 index 000000000..18afc02df --- /dev/null +++ b/sys/rump/kern/lib/Makefile.sys @@ -0,0 +1,18 @@ +# $NetBSD: Makefile.sys,v 1.3 2015/05/18 17:49:16 pooka Exp $ + +SYS_MKSYSCALLS=${.CURDIR}/../../../../kern/makesyscalls.sh + +SYS_DST= ${SYS_P}calls.c ${SYS_P}ent.c ${SYS_P}callargs.h ${SYS_P}call.h +SYS_SRC=${SYS_MKSYSCALLS} ${.CURDIR}/syscalls.conf ${.CURDIR}/syscalls.master + +${SYS_P}callargs.h: ${SYS_SRC} + cd ${.OBJDIR} && ${HOST_SH} ${.ALLSRC} + +${SYS_P}ent.c: ${SYS_P}callargs.h + +CPPFLAGS+= -I${.OBJDIR} + +DPSRCS+= ${SYS_P}callargs.h +SRCS+= ${SYS_P}ent.c + +CLEANFILES+= ${SYS_DST} diff --git a/sys/rump/kern/lib/libcrypto/Makefile b/sys/rump/kern/lib/libcrypto/Makefile new file mode 100644 index 000000000..84094a313 --- /dev/null +++ b/sys/rump/kern/lib/libcrypto/Makefile @@ -0,0 +1,37 @@ +# $NetBSD: Makefile,v 1.3 2014/01/17 01:32:53 pooka Exp $ +# + +.PATH: ${.CURDIR}/../../../../crypto/arc4 \ + ${.CURDIR}/../../../../crypto/blowfish \ + ${.CURDIR}/../../../../crypto/camellia \ + ${.CURDIR}/../../../../crypto/cast128 \ + ${.CURDIR}/../../../../crypto/des \ + ${.CURDIR}/../../../../crypto/rijndael \ + ${.CURDIR}/../../../../crypto/skipjack + +LIB= rumpkern_crypto + +# arc4 +SRCS+= arc4.c + +# blowfish +SRCS+= bf_ecb.c bf_enc.c bf_cbc.c bf_skey.c bf_module.c + +# camellia +SRCS+= camellia.c camellia-api.c + +# cast128 +SRCS+= cast128.c + +# DES +SRCS+= des_ecb.c des_setkey.c des_enc.c des_cbc.c des_module.c + +# rijndael +# rijndael is in rumpkern due to it being used by cprng +#SRCS+= rijndael-alg-fst.c rijndael-api-fst.c rijndael.c + +# skipjack +SRCS+= skipjack.c + +.include +.include diff --git a/sys/rump/kern/lib/libcrypto/i386 b/sys/rump/kern/lib/libcrypto/i386 new file mode 120000 index 000000000..1c75cf687 --- /dev/null +++ b/sys/rump/kern/lib/libcrypto/i386 @@ -0,0 +1 @@ +/home/boricj/Documents/Projets/minix/src/sys/arch/i386/include \ No newline at end of file diff --git a/sys/rump/kern/lib/libcrypto/machine b/sys/rump/kern/lib/libcrypto/machine new file mode 120000 index 000000000..1c75cf687 --- /dev/null +++ b/sys/rump/kern/lib/libcrypto/machine @@ -0,0 +1 @@ +/home/boricj/Documents/Projets/minix/src/sys/arch/i386/include \ No newline at end of file diff --git a/sys/rump/kern/lib/libcrypto/x86 b/sys/rump/kern/lib/libcrypto/x86 new file mode 120000 index 000000000..a11afa2e4 --- /dev/null +++ b/sys/rump/kern/lib/libcrypto/x86 @@ -0,0 +1 @@ +/home/boricj/Documents/Projets/minix/src/sys/arch/x86/include \ No newline at end of file diff --git a/sys/rump/kern/lib/libsljit/Makefile b/sys/rump/kern/lib/libsljit/Makefile new file mode 100644 index 000000000..3ff356fb1 --- /dev/null +++ b/sys/rump/kern/lib/libsljit/Makefile @@ -0,0 +1,39 @@ +# $NetBSD: Makefile,v 1.3 2014/07/23 07:16:14 alnsn Exp $ +# +# Public Domain. +# + +.PATH: ${.CURDIR}/../../../../external/bsd/sljit/sljit \ + ${.CURDIR}/../../../../external/bsd/sljit/dist/sljit_src + +LIB= rumpkern_sljit + +SRCS= sljitLir.c sljit_mod.c + +# NOTE This is not the best place for icache sync routine but only +# sljit uses it at the moment. +# XXX Think about a good hypercall interface (hi, pooka!) and move +# this stuff to rumpuser. +.if !empty(MACHINE_ARCH:Mmips*) +SRCS+= cache.c +RUMPCOMP_USER_SRCS= sljit_rump.c +.PATH: ${.CURDIR}/arch/mips + +RUMPCOMP_INCS_DIR:= ${.PARSEDIR} +RUMPCOMP_USER_CPPFLAGS=-I${RUMPCOMP_INCS_DIR} +.endif + +.if !empty(MACHINE_ARCH:Marm*) || !empty(MACHINE_ARCH:Mearm*) +SRCS+= cpufunc.c +RUMPCOMP_USER_SRCS= sljit_rump.c +.PATH: ${.CURDIR}/arch/arm + +RUMPCOMP_INCS_DIR:= ${.PARSEDIR} +RUMPCOMP_USER_CPPFLAGS=-I${RUMPCOMP_INCS_DIR} + +# Link to libarm to get arm_sync_icache(2) +LDADD+= -larm +.endif + +.include +.include diff --git a/sys/rump/kern/lib/libsljit/arch/arm/cpufunc.c b/sys/rump/kern/lib/libsljit/arch/arm/cpufunc.c new file mode 100644 index 000000000..df4b43e50 --- /dev/null +++ b/sys/rump/kern/lib/libsljit/arch/arm/cpufunc.c @@ -0,0 +1,52 @@ +/* $NetBSD: cpufunc.c,v 1.1 2014/07/23 07:16:14 alnsn Exp $ */ + +/*- + * Copyright (c) 2014 Alexander Nasonov. + * All rights reserved. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the above copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * + * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS + * OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED + * WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE + * DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE + * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL + * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR + * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) + * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT + * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY + * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF + * SUCH DAMAGE. + */ + +#include +__KERNEL_RCSID(0, "$NetBSD: cpufunc.c,v 1.1 2014/07/23 07:16:14 alnsn Exp $"); + +/* + * Barebone implementation of arm cpufunc routines for rump. + */ + +#include +#include + +#include "sljit_rump.h" + +static void icache_sync_range(vaddr_t, vsize_t); + +struct cpu_functions cpufuncs = { + .cf_icache_sync_range = &icache_sync_range +}; + +static void +icache_sync_range(vaddr_t va, vsize_t sz) +{ + + (void)rumpcomp_sync_icache((void *)va, (uint64_t)sz); +} diff --git a/sys/rump/kern/lib/libsljit/arch/arm/sljit_rump.c b/sys/rump/kern/lib/libsljit/arch/arm/sljit_rump.c new file mode 100644 index 000000000..0c3bc8a72 --- /dev/null +++ b/sys/rump/kern/lib/libsljit/arch/arm/sljit_rump.c @@ -0,0 +1,47 @@ +/* $NetBSD: sljit_rump.c,v 1.1 2014/07/23 07:16:14 alnsn Exp $ */ + +/*- + * Copyright (c) 2014 Alexander Nasonov. + * All rights reserved. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the above copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * + * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS + * OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED + * WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE + * DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE + * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL + * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR + * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) + * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT + * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY + * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF + * SUCH DAMAGE. + */ + +#include +__KERNEL_RCSID(0, "$NetBSD: sljit_rump.c,v 1.1 2014/07/23 07:16:14 alnsn Exp $"); + +#ifndef _KERNEL + +#include + +#include +#include + +#include "sljit_rump.h" + +int +rumpcomp_sync_icache(void *addr, uint64_t len) +{ + + return arm_sync_icache((uintptr_t)addr, (size_t)len); +} +#endif diff --git a/sys/rump/kern/lib/libsljit/arch/mips/cache.c b/sys/rump/kern/lib/libsljit/arch/mips/cache.c new file mode 100644 index 000000000..574171e4c --- /dev/null +++ b/sys/rump/kern/lib/libsljit/arch/mips/cache.c @@ -0,0 +1,52 @@ +/* $NetBSD: cache.c,v 1.1 2014/07/22 20:25:13 alnsn Exp $ */ + +/*- + * Copyright (c) 2014 Alexander Nasonov. + * All rights reserved. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the above copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * + * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS + * OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED + * WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE + * DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE + * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL + * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR + * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) + * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT + * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY + * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF + * SUCH DAMAGE. + */ + +#include +__KERNEL_RCSID(0, "$NetBSD: cache.c,v 1.1 2014/07/22 20:25:13 alnsn Exp $"); + +/* + * Barebone implementation of mips cache routines for rump. + */ + +#include +#include + +#include "sljit_rump.h" + +static void icache_sync_range(vaddr_t, vsize_t); + +struct mips_cache_ops mips_cache_ops = { + .mco_icache_sync_range = &icache_sync_range +}; + +static void +icache_sync_range(vaddr_t va, vsize_t sz) +{ + + (void)rumpcomp_sync_icache((void *)va, (uint64_t)sz); +} diff --git a/sys/rump/kern/lib/libsljit/arch/mips/sljit_rump.c b/sys/rump/kern/lib/libsljit/arch/mips/sljit_rump.c new file mode 100644 index 000000000..a7099d4f2 --- /dev/null +++ b/sys/rump/kern/lib/libsljit/arch/mips/sljit_rump.c @@ -0,0 +1,45 @@ +/* $NetBSD: sljit_rump.c,v 1.1 2014/07/22 20:25:13 alnsn Exp $ */ + +/*- + * Copyright (c) 2014 Alexander Nasonov. + * All rights reserved. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the above copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * + * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS + * OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED + * WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE + * DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE + * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL + * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR + * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) + * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT + * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY + * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF + * SUCH DAMAGE. + */ + +#include +__KERNEL_RCSID(0, "$NetBSD: sljit_rump.c,v 1.1 2014/07/22 20:25:13 alnsn Exp $"); + +#ifndef _KERNEL + +#include +#include + +#include "sljit_rump.h" + +int +rumpcomp_sync_icache(void *addr, uint64_t len) +{ + + return _cacheflush(addr, (size_t)len, ICACHE); +} +#endif diff --git a/sys/rump/kern/lib/libsljit/sljit_rump.h b/sys/rump/kern/lib/libsljit/sljit_rump.h new file mode 100644 index 000000000..547e1eae1 --- /dev/null +++ b/sys/rump/kern/lib/libsljit/sljit_rump.h @@ -0,0 +1,29 @@ +/* $NetBSD: sljit_rump.h,v 1.1 2014/07/22 20:25:13 alnsn Exp $ */ + +/*- + * Copyright (c) 2014 Alexander Nasonov. + * All rights reserved. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the above copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * + * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS + * OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED + * WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE + * DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE + * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL + * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR + * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) + * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT + * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY + * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF + * SUCH DAMAGE. + */ + +int rumpcomp_sync_icache(void *, uint64_t); diff --git a/sys/rump/kern/lib/libsolaris/Makefile b/sys/rump/kern/lib/libsolaris/Makefile new file mode 100644 index 000000000..02b504a0f --- /dev/null +++ b/sys/rump/kern/lib/libsolaris/Makefile @@ -0,0 +1,13 @@ +# $NetBSD: Makefile,v 1.2 2011/12/06 18:12:25 njoly Exp $ +# + +S!= cd ${.PARSEDIR}/../../../../;pwd + +.include "${.CURDIR}/../../../../modules/solaris/Makefile.solmod" + +LIB= rumpkern_solaris + +CPPFLAGS+= -DASSERT=KASSERT + +.include +.include diff --git a/sys/rump/kern/lib/libsys_cygwin/Makefile b/sys/rump/kern/lib/libsys_cygwin/Makefile new file mode 100644 index 000000000..00cd56800 --- /dev/null +++ b/sys/rump/kern/lib/libsys_cygwin/Makefile @@ -0,0 +1,16 @@ +# $NetBSD: Makefile,v 1.4 2015/05/09 12:03:10 pooka Exp $ +# + +LIB= rumpkern_sys_cygwin + +SRCS= rump_cygwin_compat.c +SRCS+= sys_cygwin_component.c + +# XXX +CPPFLAGS+= -I${RUMPTOP}/librump/rumpkern + +SYS_P=rump_cygwin_sys +.include "../Makefile.sys" + +.include +.include diff --git a/sys/rump/kern/lib/libsys_cygwin/rump_cygwin_compat.c b/sys/rump/kern/lib/libsys_cygwin/rump_cygwin_compat.c new file mode 100644 index 000000000..a3644fc03 --- /dev/null +++ b/sys/rump/kern/lib/libsys_cygwin/rump_cygwin_compat.c @@ -0,0 +1,251 @@ +/* $NetBSD: rump_cygwin_compat.c,v 1.1 2013/04/10 16:44:54 pooka Exp $ */ + +/* + * Copyright (c) 2013 Antti Kantee. All Rights Reserved. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the above copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * + * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS + * OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED + * WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE + * DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE + * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL + * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR + * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) + * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT + * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY + * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF + * SUCH DAMAGE. + */ + +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include + +#include + +#include "rump_cygwin_syscallargs.h" + +struct cygwin_stat { + int st_dev; + int64_t st_ino; + int st_mode; + unsigned short st_nlink; + int st_uid; + int st_gid; + int st_rdev; + off_t st_size; + + struct timespec50 st_atim; + struct timespec50 st_mtim; + struct timespec50 st_ctim; + + long st_blksize; + uint64_t st_blocks; + + struct timespec50 st_btim; +}; + +#define PARCOPY(a) ssb->a = sb->a +static void +bsd_to_cygwin_stat(const struct stat *sb, struct cygwin_stat *ssb) +{ + + memset(ssb, 0, sizeof(*ssb)); + PARCOPY(st_dev); + PARCOPY(st_ino); + PARCOPY(st_mode); + PARCOPY(st_nlink); + PARCOPY(st_uid); + PARCOPY(st_gid); + PARCOPY(st_rdev); + PARCOPY(st_size); + PARCOPY(st_blksize); + PARCOPY(st_blocks); + + timespec_to_timespec50(&sb->st_atimespec, &ssb->st_atim); + timespec_to_timespec50(&sb->st_mtimespec, &ssb->st_mtim); + timespec_to_timespec50(&sb->st_ctimespec, &ssb->st_ctim); + timespec_to_timespec50(&sb->st_birthtimespec, &ssb->st_btim); +} + +int +rump_cygwin_sys_stat(struct lwp *l, const struct rump_cygwin_sys_stat_args *uap, + register_t *retval) +{ + struct cygwin_stat ssb; + struct stat sb; + int error; + + error = do_sys_stat(SCARG(uap, path), FOLLOW, &sb); + if (error) + return error; + + bsd_to_cygwin_stat(&sb, &ssb); + + return copyout(&ssb, SCARG(uap, sp), sizeof(ssb)); +} + +int +rump_cygwin_sys_fstat(struct lwp *l, const struct rump_cygwin_sys_fstat_args *uap, + register_t *retval) +{ + struct cygwin_stat ssb; + struct stat sb; + int error; + + error = do_sys_fstat(SCARG(uap, fd), &sb); + if (error) + return error; + + bsd_to_cygwin_stat(&sb, &ssb); + + return copyout(&ssb, SCARG(uap, sp), sizeof(ssb)); +} + +int +rump_cygwin_sys_lstat(struct lwp *l, const struct rump_cygwin_sys_lstat_args *uap, + register_t *retval) +{ + struct cygwin_stat ssb; + struct stat sb; + int error; + + error = do_sys_stat(SCARG(uap, path), NOFOLLOW, &sb); + if (error) + return error; + + bsd_to_cygwin_stat(&sb, &ssb); + + return copyout(&ssb, SCARG(uap, sp), sizeof(ssb)); +} + +int +rump_cygwin_sys_open(struct lwp *l, const struct rump_cygwin_sys_open_args *uap, + register_t *retval) +{ + /* { + syscallarg(const char *) path; + syscallarg(int) flags; + syscallarg(int) mode; + } */ + struct sys_open_args ua; + int sflags, flags; + + sflags = SCARG(uap, flags); + flags = sflags & (3 | O_APPEND | O_ASYNC | O_CREAT | O_TRUNC | O_EXCL); + + SCARG(&ua, path) = SCARG(uap, path); + SCARG(&ua, flags) = flags; + SCARG(&ua, mode) = SCARG(uap, mode); + + return sys_open(l, &ua, retval); +} + +#define CYGWIN_NAME_MAX 255 +struct cygwin_dirent { + long d_version; + int64_t d_ino; + unsigned char d_type; + unsigned char d_unused[3]; + uint32_t d_internal; + char d_name[CYGWIN_NAME_MAX + 1]; +} __packed; + +#define CYGWIN_NAMEOFF(dp) offsetof(struct cygwin_dirent,d_name) +#define CYGWIN_RECLEN(dp, namlen) ((CYGWIN_NAMEOFF(dp) + (namlen) + 1)) + +int +rump_cygwin_sys_getdents(struct lwp *l, + const struct rump_cygwin_sys_getdents_args *uap, register_t *retval) +{ + struct file *fp; + struct dirent *bdp; + struct cygwin_dirent idb; + char *buf, *inp, *outp; + size_t resid, buflen, nbytes; + size_t reclen, cygwin_reclen; + int error, done; + + if ((error = fd_getvnode(SCARG(uap, fd), &fp)) != 0) + return (error); + + /* + * Sneaky, but avoids having "rewind" f_offset due to the + * conversions not fitting from our intermediate kernel buffer + * into the user buffer + */ + nbytes = SCARG(uap, nbytes); + buflen = min(MAXBSIZE, (nbytes*8)/10); + buf = kmem_alloc(buflen, KM_SLEEP); + + if ((fp->f_flag & FREAD) == 0) { + error = EBADF; + goto out; + } + + resid = nbytes; + outp = SCARG(uap, buf); + + again: + if ((error = vn_readdir(fp, buf, UIO_SYSSPACE, buflen, &done, + l, NULL, NULL)) != 0) + goto out; + if (done == 0) + goto eof; + + for (inp = buf; done > 0; done -= reclen) { + bdp = (struct dirent *)inp; + reclen = bdp->d_reclen; + + /* skip empty entries */ + if (bdp->d_fileno == 0) { + inp += reclen; + continue; + } + + cygwin_reclen = CYGWIN_RECLEN(&idb, bdp->d_namlen); + if (resid < cygwin_reclen) { + panic("impossible shortage of resid"); + } + + memset(&idb, 0, sizeof(idb)); + idb.d_ino = bdp->d_fileno; + idb.d_type = bdp->d_type; + strlcpy(idb.d_name, bdp->d_name, sizeof(idb.d_name)); + if ((error = copyout(&idb, outp, cygwin_reclen)) != 0) + goto out; + + inp += reclen; + outp += cygwin_reclen; + resid -= cygwin_reclen; + } + + /* if we squished out the whole block, try again */ + if (outp == SCARG(uap, buf)) { + goto again; + } + + eof: + *retval = nbytes - resid; + out: + kmem_free(buf, buflen); + fd_putfile(SCARG(uap, fd)); + + return (error); +} diff --git a/sys/rump/kern/lib/libsys_cygwin/sys_cygwin_component.c b/sys/rump/kern/lib/libsys_cygwin/sys_cygwin_component.c new file mode 100644 index 000000000..85c26b41f --- /dev/null +++ b/sys/rump/kern/lib/libsys_cygwin/sys_cygwin_component.c @@ -0,0 +1,31 @@ +/* $NetBSD: sys_cygwin_component.c,v 1.1 2014/03/13 02:03:16 pooka Exp $ */ + +#include +#include + +#include + +#include "rump_private.h" + +#include "rump_cygwin_syscall.h" + +extern struct sysent rump_cygwin_sysent[]; + +struct emul emul_rump_sys_cygwin = { + .e_name = "cygwin-rump", + .e_sysent = rump_cygwin_sysent, +#ifndef __HAVE_MINIMAL_EMUL + .e_nsysent = RUMP_CYGWIN_SYS_NSYSENT, +#endif + .e_vm_default_addr = uvm_default_mapaddr, +#ifdef __HAVE_SYSCALL_INTERN + .e_syscall_intern = syscall_intern, +#endif +}; + +RUMP_COMPONENT(RUMP_COMPONENT_KERN) +{ + extern struct emul *emul_default; + + emul_default = &emul_rump_sys_cygwin; +} diff --git a/sys/rump/kern/lib/libsys_cygwin/syscalls.conf b/sys/rump/kern/lib/libsys_cygwin/syscalls.conf new file mode 100644 index 000000000..3a0913caf --- /dev/null +++ b/sys/rump/kern/lib/libsys_cygwin/syscalls.conf @@ -0,0 +1,14 @@ +# $NetBSD: syscalls.conf,v 1.1 2013/04/10 16:44:54 pooka Exp $ +# + +sysnames="rump_cygwin_syscalls.c" +sysnumhdr="rump_cygwin_syscall.h" +syssw="rump_cygwin_sysent.c" +sysarghdr="rump_cygwin_syscallargs.h" +compatopts="" +libcompatopts="" + +switchname="rump_cygwin_sysent" +namesname="rump_cygwin_syscallnames" +constprefix="RUMP_CYGWIN_SYS_" +nsysent=512 diff --git a/sys/rump/kern/lib/libsys_cygwin/syscalls.master b/sys/rump/kern/lib/libsys_cygwin/syscalls.master new file mode 100644 index 000000000..c1e0c18a9 --- /dev/null +++ b/sys/rump/kern/lib/libsys_cygwin/syscalls.master @@ -0,0 +1,575 @@ + $NetBSD: syscalls.master,v 1.2 2013/05/15 21:39:30 pooka Exp $ + +; @(#)syscalls.master 8.2 (Berkeley) 1/13/94 + +; NetBSD system call name/number "master" file. +; (See syscalls.conf to see what it is processed into.) +; +; Fields: number type [type-dependent ...] +; number system call number, must be in order +; type one of NODEF, UNIMPL, or NOARGS +; +; types: +; NODEF always included +; UNIMPL unimplemented, not included in system +; NODEF included, but don't define the syscall number +; NOARGS included, but don't define the syscall args structure +; +; arguments: +; PAD argument not part of the C interface, used only for padding +; +; +; Support just enough syscalls to make fs-utils run (plus a few other +; low-hanging fruit) +; + +#include +#include +#include +#include +#include +#include +#include + +#include "rump_cygwin_syscallargs.h" + +%% + +0 NOARGS { int|sys||nosys(void); } +1 UNIMPL exit +2 UNIMPL fork +3 NOARGS { ssize_t|sys||read(int fd, void *buf, size_t nbyte); } +4 NOARGS { ssize_t|sys||write(int fd, const void *buf, \ + size_t nbyte); } +5 NODEF { int|rump_cygwin_sys||open(const char *path, \ + int flags, int mode); } +6 NOARGS { int|sys||close(int fd); } +7 UNIMPL wait4 +8 UNIMPL creat +9 NOARGS { int|sys||link(const char *path, const char *link); } +10 NOARGS { int|sys||unlink(const char *path); } +11 UNIMPL execv +12 NOARGS { int|sys||chdir(const char *path); } +13 NOARGS { int|sys||fchdir(int fd); } +14 UNIMPL mknod +15 NOARGS { int|sys||chmod(const char *path, int mode); } +16 NOARGS { int|sys||chown(const char *path, int uid, int gid); } +17 UNIMPL obreak +18 UNIMPL getfsstat +19 UNIMPL lseek +20 NOARGS { pid_t|sys||getpid_with_ppid(void); } getpid +21 UNIMPL mount +22 UNIMPL unmount +23 NOARGS { int|sys||setuid(int uid); } +24 NOARGS { int|sys||getuid_with_euid(void); } getuid +25 NOARGS { int|sys||geteuid(void); } +26 UNIMPL ptrace +27 UNIMPL recvmsg +28 UNIMPL sendmsg +29 UNIMPL recvfrom +30 UNIMPL accept +31 UNIMPL getpeername +32 UNIMPL getsockname +33 NOARGS { int|sys||access(const char *path, int flags); } +34 UNIMPL chflags +35 UNIMPL fchflags +36 NOARGS { void|sys||sync(void); } +37 UNIMPL kill +38 UNIMPL stat +39 UNIMPL getppid +40 UNIMPL lstat +41 NOARGS { int|sys||dup(int fd); } +42 NOARGS { int|sys||pipe(void); } +43 UNIMPL getegid +44 UNIMPL profil +45 UNIMPL ktrace +46 UNIMPL sigaction +47 NOARGS { int|sys||getgid_with_egid(void); } getgid +48 UNIMPL sigprocmask +49 UNIMPL __getlogin +50 UNIMPL __setlogin +51 UNIMPL acct +52 UNIMPL sigpending +53 UNIMPL sigaltstack +54 UNIMPL ioctl +55 UNIMPL reboot +56 UNIMPL revoke +57 NOARGS { int|sys||symlink(const char *path, \ + const char *link); } +58 NOARGS { ssize_t|sys||readlink(const char *path, char *buf, \ + int count); } +59 UNIMPL execve +60 NOARGS { mode_t|sys||umask(mode_t newmask); } +61 NOARGS { int|sys||chroot(const char *path); } +62 UNIMPL fstat43 +63 UNIMPL getkerninfo +64 UNIMPL getpagesize +65 UNIMPL msync +66 UNIMPL vfork +67 UNIMPL vread +68 UNIMPL vwrite +69 UNIMPL sbrk +70 UNIMPL sstk +71 UNIMPL mmap +72 UNIMPL ovadvise +73 UNIMPL munmap +74 UNIMPL mprotect +75 UNIMPL madvise +76 UNIMPL vhangup +77 UNIMPL vlimit +78 UNIMPL mincore +79 NOARGS { int|sys||getgroups(int gidsetsize, \ + int *gidset); } +80 NOARGS { int|sys||setgroups(int gidsetsize, \ + const int *gidset); } +81 NOARGS { int|sys||getpgrp(void); } +82 NOARGS { int|sys||setpgid(int pid, int pgid); } +83 UNIMPL setitimer +84 UNIMPL wait +85 UNIMPL swapon +86 UNIMPL getitimer +87 UNIMPL gethostname +88 UNIMPL sethostname +89 UNIMPL getdtablesize +90 NOARGS { int|sys||dup2(int from, int to); } +91 UNIMPL getdopt +92 UNIMPL fcntl +93 UNIMPL select +94 UNIMPL setdopt +95 NOARGS { int|sys||fsync(int fd); } +96 UNIMPL setpriority +97 UNIMPL socket +98 UNIMPL connect +99 UNIMPL accept +100 UNIMPL getpriority + +101 UNIMPL send +102 UNIMPL recv + +103 UNIMPL sigreturn +104 UNIMPL bind +105 UNIMPL setsockopt +106 UNIMPL listen +107 UNIMPL vtimes +108 UNIMPL sigvec +109 UNIMPL sigblock +110 UNIMPL sigsetmask +111 UNIMPL sigsuspend +112 UNIMPL sigstack +113 UNIMPL orecvmsg +114 UNIMPL osendmsg +115 UNIMPL vtrace +116 UNIMPL gettimeofday +117 UNIMPL getrusage +118 UNIMPL getsockopt +119 UNIMPL resuba +120 NOARGS { ssize_t|sys||readv(int fd, \ + struct iovec *iovp, int iovcnt); } +121 NOARGS { ssize_t|sys||writev(int fd, \ + struct iovec *iovp, int iovcnt); } +122 UNIMPL settimeofday +123 NOARGS { int|sys||fchown(int fd, int uid, int gid); } +124 NOARGS { int|sys||fchmod(int fd, int mode); } +125 UNIMPL orecvfrom +126 NOARGS { int|sys||setreuid(int ruid, int euid); } +127 NOARGS { int|sys||setregid(int rgid, int egid); } +128 NOARGS { int|sys||rename(char *from, char *to); } +129 UNIMPL otruncate +130 UNIMPL oftruncate +131 NOARGS { int|sys||flock(int fd, int how); } +132 UNIMPL mkfifo +133 UNIMPL sendto +134 UNIMPL shutdown +135 UNIMPL socketpair +136 NOARGS { int|sys||mkdir(const char *path, int mode); } +137 NOARGS { int|sys||rmdir(const char *path); } +138 UNIMPL utimes + +139 UNIMPL 4.2 sigreturn +140 UNIMPL adjtime +141 UNIMPL ogetpeername +142 UNIMPL ogethostid +143 UNIMPL osethostid +144 UNIMPL ogetrlimit +145 UNIMPL osetrlimit +146 UNIMPL okillpg +147 NOARGS { int|sys||setsid(void); } +148 UNIMPL quotactl +149 UNIMPL oquota +150 UNIMPL ogetsockname + +; Syscalls 151-180 inclusive are reserved for vendor-specific +; system calls. (This includes various calls added for compatibity +; with other Unix variants.) +; Some of these calls are now supported by BSD... +151 UNIMPL +152 UNIMPL +153 UNIMPL +154 UNIMPL +155 UNIMPL nfssvc +156 UNIMPL ogetdirentries +157 UNIMPL statfs12 +158 UNIMPL fstatfs12 +159 UNIMPL +160 UNIMPL +161 UNIMPL getfh30 +162 UNIMPL ogetdomainname +163 UNIMPL osetdomainname +164 UNIMPL ouname +165 UNIMPL sysarch +166 UNIMPL +167 UNIMPL +168 UNIMPL +169 UNIMPL 1.0 semsys +170 UNIMPL 1.0 msgsys +171 UNIMPL 1.0 shmsys +172 UNIMPL +173 NOARGS { ssize_t|sys||pread(int fd, char *buf, \ + size_t nbyte, int PAD, off_t offset); } +174 NOARGS { ssize_t|sys||pwrite(int fd, char *buf, \ + size_t nbyte, int PAD, off_t offset); } +175 UNIMPL ntp_gettime +176 UNIMPL ntp_adjtime +177 UNIMPL +178 UNIMPL +179 UNIMPL +180 UNIMPL + +; Syscalls 180-199 are used by/reserved for BSD +181 NOARGS { int|sys||setgid(gid_t gid); } +182 NOARGS { int|sys||setegid(gid_t egid); } +183 NOARGS { int|sys||seteuid(uid_t euid); } +184 UNIMPL lfs_bmapv +185 UNIMPL lfs_markv +186 UNIMPL lfs_segclean +187 UNIMPL lfs_segwait +188 UNIMPL stat12 +189 UNIMPL fstat12 +190 UNIMPL lstat12 +191 UNIMPL pathconf +192 UNIMPL fpathconf +193 UNIMPL +194 UNIMPL getrlimit +195 UNIMPL setrlimit +196 UNIMPL getdirentries +197 UNIMPL mmap +198 UNIMPL __syscall +199 NOARGS { long|sys||lseek(int fd, int PAD, off_t offset, \ + int whence); } +200 NOARGS { int|sys||truncate(const char *path, int PAD, \ + off_t length); } +201 NOARGS { int|sys||ftruncate(int fd, int PAD, off_t length); } +202 UNIMPL __sysctl +203 UNIMPL mlock +204 UNIMPL munlock +205 UNIMPL undelete +206 UNIMPL futimes +207 NOARGS { pid_t|sys||getpgid(pid_t pid); } +208 UNIMPL reboot +209 NOARGS { int|sys||poll(struct pollfd *fds, u_int nfds, \ + int timeout); } +; +; Syscalls 210-219 are reserved for dynamically loaded syscalls +; +210 UNIMPL afssys +211 UNIMPL +212 UNIMPL +213 UNIMPL +214 UNIMPL +215 UNIMPL +216 UNIMPL +217 UNIMPL +218 UNIMPL +219 UNIMPL +220 UNIMPL compat_14_semctl +221 UNIMPL semget +222 UNIMPL semop +223 UNIMPL semconfig +224 UNIMPL compat_14_msgctl +225 UNIMPL msgget +226 UNIMPL msgsnd +227 UNIMPL msgrcv +228 UNIMPL shmat +229 UNIMPL compat_14_shmctl +230 UNIMPL shmdt +231 UNIMPL shmget + +232 UNIMPL clock_gettime +233 UNIMPL clock_settime +234 UNIMPL clock_getres +235 UNIMPL timer_create +236 UNIMPL timer_delete +237 UNIMPL timer_settime +238 UNIMPL timer_gettime +239 UNIMPL timer_getoverrun +; +; Syscalls 240-269 are reserved for other IEEE Std1003.1b syscalls +; +240 UNIMPL nanosleep +241 UNIMPL fdatasync +242 UNIMPL mlockall +243 UNIMPL munlockall +244 UNIMPL __sigtimedwait +245 UNIMPL sigqueueinfo +246 UNIMPL modctl +247 UNIMPL _ksem_init +248 UNIMPL _ksem_open +249 UNIMPL _ksem_unlink +250 UNIMPL _ksem_close +251 UNIMPL _ksem_post +252 UNIMPL _ksem_wait +253 UNIMPL _ksem_trywait +254 UNIMPL _ksem_getvalue +255 UNIMPL _ksem_destroy +256 UNIMPL _ksem_timedwait + +257 UNIMPL mq_open +258 UNIMPL mq_close +259 UNIMPL mq_unlink +260 UNIMPL mq_getattr +261 UNIMPL mq_setattr +262 UNIMPL mq_notify +263 UNIMPL mq_send +264 UNIMPL mq_receive +265 UNIMPL mq_timedsend +266 UNIMPL mq_timedreceive +267 UNIMPL +268 UNIMPL +269 UNIMPL +270 UNIMPL __posix_rename +271 UNIMPL swapctl +272 UNIMPL getdents +273 UNIMPL minherit +274 UNIMPL lchmod +275 UNIMPL lchown +276 UNIMPL lutimes +277 UNIMPL msync +278 UNIMPL stat +279 UNIMPL fstat +280 UNIMPL lstat +281 UNIMPL sigaltstack +282 UNIMPL vfork +283 UNIMPL __posix_chown +284 UNIMPL __posix_fchown +285 UNIMPL __posix_lchown +286 NOARGS { pid_t|sys||getsid(pid_t pid); } + +287 UNIMPL __clone +288 UNIMPL fktrace +289 UNIMPL { ssize_t|sys||preadv(int fd, \ + const struct iovec *iovp, int iovcnt, \ + int PAD, off_t offset); } +290 UNIMPL { ssize_t|sys||pwritev(int fd, \ + const struct iovec *iovp, int iovcnt, \ + int PAD, off_t offset); } +291 UNIMPL sigaction +292 UNIMPL sigpending +293 UNIMPL sigprocmask +294 UNIMPL sigsuspend +295 UNIMPL sigreturn +296 NOARGS { int|sys||__getcwd(char *bufp, size_t length); } +297 NOARGS { int|sys||fchroot(int fd); } +298 UNIMPL fhopen +299 UNIMPL fhstat +300 UNIMPL fhstatfs +301 UNIMPL ____semctl13 +302 UNIMPL __msgctl13 +303 UNIMPL __shmctl13 +304 UNIMPL lchflags +305 UNIMPL issetugid +306 UNIMPL utrace +307 UNIMPL getcontext +308 UNIMPL setcontext +309 UNIMPL _lwp_create +310 UNIMPL _lwp_exit +311 UNIMPL _lwp_self +312 UNIMPL _lwp_wait +313 UNIMPL _lwp_suspend +314 UNIMPL _lwp_continue +315 UNIMPL _lwp_wakeup +316 UNIMPL _lwp_getprivate +317 UNIMPL _lwp_setprivate +318 UNIMPL _lwp_kill +319 UNIMPL _lwp_detach +320 UNIMPL _lwp_park +321 UNIMPL _lwp_unpark +322 UNIMPL _lwp_unpark_all +323 UNIMPL _lwp_setname +324 UNIMPL _lwp_getname +325 UNIMPL _lwp_ctl + +; Syscalls 326-339 reserved for LWP syscalls. +326 UNIMPL +327 UNIMPL +328 UNIMPL +329 UNIMPL +; SA system calls. +330 UNIMPL sa_register +331 UNIMPL sa_stacks +332 UNIMPL sa_enable +333 UNIMPL sa_setconcurrency +334 UNIMPL sa_yield +335 UNIMPL sa_preempt +336 UNIMPL sys_sa_unblockyield +; +; Syscalls 337-339 are reserved for other scheduler activation syscalls. +; +337 UNIMPL +338 UNIMPL +339 UNIMPL + +340 UNIMPL __sigaction_sigtramp +341 UNIMPL pmc_get_info +342 UNIMPL pmc_control +343 UNIMPL rasctl +344 UNIMPL kqueue +345 UNIMPL kevent + +; Scheduling system calls. +346 UNIMPL _sched_setparam +347 UNIMPL _sched_getparam +348 UNIMPL _sched_setaffinity +349 UNIMPL _sched_getaffinity +350 UNIMPL sched_yield +351 UNIMPL +352 UNIMPL +353 UNIMPL + +354 UNIMPL fsync_range +355 UNIMPL uuidgen +356 UNIMPL getvfsstat +357 UNIMPL statvfs1 +358 UNIMPL fstatvfs1 +359 UNIMPL fhstatvfs1 +360 UNIMPL extattrctl +361 UNIMPL extattr_set_file +362 UNIMPL extattr_get_file +363 UNIMPL extattr_delete_file +364 UNIMPL extattr_set_fd +365 UNIMPL extattr_get_fd +366 UNIMPL extattr_delete_fd +367 UNIMPL extattr_set_link +368 UNIMPL extattr_get_link +369 UNIMPL extattr_delete_link +370 UNIMPL extattr_list_fd +371 UNIMPL extattr_list_file +372 UNIMPL extattr_list_link +373 UNIMPL pselect +374 UNIMPL pollts +375 UNIMPL setxattr +376 UNIMPL lsetxattr +377 UNIMPL fsetxattr +378 UNIMPL getxattr +379 UNIMPL lgetxattr +380 UNIMPL fgetxattr +381 UNIMPL listxattr +382 UNIMPL llistxattr +383 UNIMPL flistxattr +384 UNIMPL removexattr +385 UNIMPL lremovexattr +386 UNIMPL fremovexattr +387 UNIMPL stat30 +388 UNIMPL fstat30 +389 UNIMPL lstat30 +390 NODEF { int|rump_cygwin_sys||getdents(int fd, \ + char *buf, size_t nbytes); } +391 UNIMPL old posix_fadvise +392 UNIMPL fhstat +393 UNIMPL ntp_gettime +394 UNIMPL socket +395 UNIMPL getfh +396 UNIMPL fhopen +397 UNIMPL fhstatvfs1 +398 UNIMPL fhstat + +; Asynchronous I/O system calls +399 UNIMPL aio_cancel +400 UNIMPL aio_error +401 UNIMPL aio_fsync +402 UNIMPL aio_read +403 UNIMPL aio_return +404 UNIMPL aio_suspend +405 UNIMPL aio_write +406 UNIMPL lio_listio + +407 UNIMPL +408 UNIMPL +409 UNIMPL + +410 UNIMPL mount +411 UNIMPL mremap + +; Processor-sets system calls +412 UNIMPL pset_create +413 UNIMPL pset_destroy +414 UNIMPL pset_assign +415 UNIMPL _pset_bind +416 UNIMPL fadvise +417 UNIMPL select +418 UNIMPL gettimeofday +419 UNIMPL settimeofday +420 NOARGS { int|compat_50_sys||utimes(char *path, \ + struct timeval50 *tptr); } +421 UNIMPL adjtime +422 UNIMPL lfs_segwait +423 NOARGS { int|compat_50_sys||futimes(int fd, \ + struct timeval50 *tptr); } +424 UNIMPL lutimes +425 UNIMPL setitimer +426 UNIMPL getitimer +427 UNIMPL clock_gettime +428 UNIMPL clock_settime +429 UNIMPL clock_getres +430 UNIMPL nanosleep +431 UNIMPL __sigtimedwait +432 UNIMPL mq_timedsend +433 UNIMPL mq_timedreceive +434 UNIMPL _lwp_park +435 UNIMPL kevent +436 UNIMPL pselect +437 UNIMPL ppoll +438 UNIMPL aio_suspend +439 NODEF { int|rump_cygwin_sys||stat(const char *path, \ + struct cygwin_stat *sp); } +440 NODEF { int|rump_cygwin_sys||fstat(int fd, \ + struct cygwin_stat *sp); } +441 NODEF { int|rump_cygwin_sys||lstat(const char *path, \ + struct cygwin_stat *sp); } +442 UNIMPL __semctl +443 UNIMPL shmctl +444 UNIMPL msgctl +445 UNIMPL getrusage +446 UNIMPL timer_settime +447 UNIMPL timer_gettime +448 UNIMPL ntp_gettime +449 UNIMPL wait4 +450 NOARGS { int|sys|50|mknod(const char *path, mode_t mode, \ + int dev); } +451 UNIMPL fhstat + +; 452 only ever appeared in 5.99.x and can be reused after netbsd-7 +452 UNIMPL 5.99 quotactl +453 UNIMPL pipe2 +454 UNIMPL dup3 +455 UNIMPL kqueue1 +456 UNIMPL paccept +457 UNIMPL linkat +458 UNIMPL renameat +459 UNIMPL mkfifoat +460 UNIMPL mknodat +461 UNIMPL mkdirat +462 UNIMPL faccessat +463 UNIMPL fchmodat +464 UNIMPL fchownat +465 UNIMPL fexecve +466 UNIMPL fstatat +467 UNIMPL utimensat +468 UNIMPL openat +469 UNIMPL readlinkat +470 UNIMPL symlinkat +471 UNIMPL unlinkat +472 UNIMPL futimens +473 UNIMPL __quotactl +474 UNIMPL posix_spawn +475 UNIMPL recvmmsg +476 UNIMPL sendmmsg diff --git a/sys/rump/kern/lib/libsys_linux/Makefile b/sys/rump/kern/lib/libsys_linux/Makefile new file mode 100644 index 000000000..769ba2d3c --- /dev/null +++ b/sys/rump/kern/lib/libsys_linux/Makefile @@ -0,0 +1,25 @@ +# $NetBSD: Makefile,v 1.9 2015/05/09 12:03:10 pooka Exp $ +# + +.PATH: ${.CURDIR}/../../../../compat/linux/common + +LIB= rumpkern_sys_linux + +SRCS= linux_blkio.c linux_cdrom.c linux_errno.c linux_fdio.c \ + linux_file.c linux_hdio.c linux_ioctl.c linux_ipc.c linux_misc.c\ + linux_mtio.c linux_signal.c linux_signo.c linux_socket.c \ + linux_sysctl.c linux_termios.c linux_time.c linux_file64.c \ + linux_pipe.c + +SRCS+= linux_rump.c +SRCS+= sys_linux_component.c + +# XXX +CPPFLAGS+= -I${RUMPTOP}/librump/rumpkern +CPPFLAGS+= -DINET6 + +SYS_P=rump_linux_sys +.include "../Makefile.sys" + +.include +.include diff --git a/sys/rump/kern/lib/libsys_linux/linux_rump.c b/sys/rump/kern/lib/libsys_linux/linux_rump.c new file mode 100644 index 000000000..1ea3db50f --- /dev/null +++ b/sys/rump/kern/lib/libsys_linux/linux_rump.c @@ -0,0 +1,30 @@ +/* $NetBSD: linux_rump.c,v 1.2 2014/01/10 19:44:47 njoly Exp $ */ + +#include + +#include +#include +#include + +#include "rump_linux_syscallargs.h" + +int +rump_linux_sys_mknodat(struct lwp *l, + const struct rump_linux_sys_mknodat_args *uap, register_t *retval) +{ + /* { + syscallarg(int) fd; + syscallarg(const char *) path; + syscallarg(mode_t) mode; + syscallarg(int) PAD; + syscallarg(dev_t) dev; + } */ + struct linux_sys_mknodat_args ua; + + SCARG(&ua, fd) = SCARG(uap, fd); + SCARG(&ua, path) = SCARG(uap, path); + SCARG(&ua, mode) = SCARG(uap, mode); + SCARG(&ua, dev) = SCARG(uap, dev); + + return linux_sys_mknodat(l, &ua, retval); +} diff --git a/sys/rump/kern/lib/libsys_linux/sys_linux_component.c b/sys/rump/kern/lib/libsys_linux/sys_linux_component.c new file mode 100644 index 000000000..a272ad5d0 --- /dev/null +++ b/sys/rump/kern/lib/libsys_linux/sys_linux_component.c @@ -0,0 +1,97 @@ +/* $NetBSD: sys_linux_component.c,v 1.2 2014/04/04 18:24:12 njoly Exp $ */ + +#include +#include + +#include + +#include + +#include "rump_private.h" + +#include "rump_linux_syscall.h" + +extern struct sysent rump_linux_sysent[]; + +#ifdef __HAVE_SYSCALL_INTERN +static void +rumplinux_syscall_intern(struct proc *p) +{ + + p->p_emuldata = __UNCONST(native_to_linux_errno); +} +#endif + +struct emul emul_rump_sys_linux = { + .e_name = "linux-rump", + .e_sysent = rump_linux_sysent, +#ifndef __HAVE_MINIMAL_EMUL + .e_nsysent = RUMP_LINUX_SYS_NSYSENT, + .e_errno = native_to_linux_errno, +#endif + .e_vm_default_addr = uvm_default_mapaddr, +#ifdef __HAVE_SYSCALL_INTERN + .e_syscall_intern = rumplinux_syscall_intern, +#endif +}; + +RUMP_COMPONENT(RUMP_COMPONENT_KERN) +{ + extern struct emul *emul_default; + + emul_default = &emul_rump_sys_linux; +} + +#include + +dev_t +linux_fakedev(dev_t in, int raw) +{ + + /* I don't really think it matters what we return here */ + return in; +} + +/* + * XXX: the linux emulation code is not split into factions + */ +void rumplinux__stub(void); +void rumplinux__stub(void) {panic("unavailable");} + +/* vm-related */ +__weak_alias(sys_mmap,rumplinux__stub); +__weak_alias(vm_map_unlock,rumplinux__stub); +__weak_alias(uvm_map_lookup_entry,rumplinux__stub); +__weak_alias(sys_obreak,rumplinux__stub); +__weak_alias(vm_map_lock,rumplinux__stub); +__weak_alias(uvm_mremap,rumplinux__stub); + +/* signal.c */ +__weak_alias(sigaction1,rumplinux__stub); +__weak_alias(kpsignal2,rumplinux__stub); +__weak_alias(sys_kill,rumplinux__stub); +__weak_alias(sigsuspend1,rumplinux__stub); +__weak_alias(sigtimedwait1,rumplinux__stub); +__weak_alias(lwp_find,rumplinux__stub); + +/* misc */ +__weak_alias(linux_machdepioctl,rumplinux__stub); +__weak_alias(linux_ioctl_sg,rumplinux__stub); +__weak_alias(oss_ioctl_mixer,rumplinux__stub); +__weak_alias(oss_ioctl_sequencer,rumplinux__stub); +__weak_alias(oss_ioctl_audio,rumplinux__stub); +__weak_alias(rusage_to_rusage50,rumplinux__stub); +__weak_alias(do_sys_wait,rumplinux__stub); + +/* arch-specific */ +__weak_alias(compat_offseterr,rumplinux__stub); +__weak_alias(linux_sys_ptrace_arch,rumplinux__stub); + +#ifdef __i386__ +const char * +linux_get_uname_arch(void) +{ + + return MACHINE_ARCH; +} +#endif /* __i386__ */ diff --git a/sys/rump/kern/lib/libsys_linux/syscalls.conf b/sys/rump/kern/lib/libsys_linux/syscalls.conf new file mode 100644 index 000000000..7ecb8ac1a --- /dev/null +++ b/sys/rump/kern/lib/libsys_linux/syscalls.conf @@ -0,0 +1,16 @@ +# $NetBSD: syscalls.conf,v 1.2 2013/03/07 19:08:54 pooka Exp $ +# + +sysnames="rump_linux_syscalls.c" +sysnumhdr="rump_linux_syscall.h" +syssw="rump_linux_sysent.c" +sysarghdr="rump_linux_syscallargs.h" +compatopts="" +libcompatopts="" + +switchname="rump_linux_sysent" +namesname="rump_linux_syscallnames" +constprefix="RUMP_LINUX_SYS_" +nsysent=512 + +sys_nosys="linux_sys_nosys" diff --git a/sys/rump/kern/lib/libsys_linux/syscalls.master b/sys/rump/kern/lib/libsys_linux/syscalls.master new file mode 100644 index 000000000..4ffc99109 --- /dev/null +++ b/sys/rump/kern/lib/libsys_linux/syscalls.master @@ -0,0 +1,638 @@ + $NetBSD: syscalls.master,v 1.16 2014/05/29 10:41:48 njoly Exp $ + +; @(#)syscalls.master 8.2 (Berkeley) 1/13/94 + +; NetBSD system call name/number "master" file. +; (See syscalls.conf to see what it is processed into.) +; +; Fields: number type [type-dependent ...] +; number system call number, must be in order +; type one of NODEF, UNIMPL, or NOARGS +; +; types: +; NODEF always included +; UNIMPL unimplemented, not included in system +; NODEF included, but don't define the syscall number +; NOARGS included, but don't define the syscall args structure +; +; arguments: +; PAD argument not part of the C interface, used only for padding +; +; +; The purpose of this syscalls.master is to map to the Linux types which +; are marshalled into the arg structure by the clientside rump_syscalls.c +; code in librumpclient. +; + +#include +#include +#include +#include +#include +#include +#include + +#include +#include +#include +#include + +#ifdef LINUX_SYS_socketcall +#include +#endif + +#include "rump_linux_syscallargs.h" + +%% + +0 NOARGS { int|linux_sys||nosys(void); } +1 UNIMPL exit +2 UNIMPL fork +3 NOARGS { ssize_t|sys||read(int fd, void *buf, size_t nbyte); } +4 NOARGS { ssize_t|sys||write(int fd, const void *buf, \ + size_t nbyte); } +5 NOARGS { int|linux_sys||open(const char *path, \ + int flags, int mode); } +6 NOARGS { int|sys||close(int fd); } +7 UNIMPL wait4 +8 UNIMPL creat +9 NOARGS { int|sys||link(const char *path, const char *link); } +10 NOARGS { int|linux_sys||unlink(const char *path); } +11 UNIMPL execv +12 NOARGS { int|sys||chdir(const char *path); } +13 NOARGS { int|sys||fchdir(int fd); } +14 UNIMPL mknod +15 NOARGS { int|sys||chmod(const char *path, mode_t mode); } +16 NOARGS { int|sys||__posix_chown(const char *path, uid_t uid, \ + gid_t gid); } +17 UNIMPL obreak +18 UNIMPL getfsstat +19 UNIMPL lseek +20 NOARGS { pid_t|sys||getpid_with_ppid(void); } getpid +21 UNIMPL mount +22 UNIMPL unmount +23 NOARGS { int|sys||setuid(uid_t uid); } +24 NOARGS { uid_t|sys||getuid_with_euid(void); } getuid +25 NOARGS { uid_t|sys||geteuid(void); } +26 UNIMPL ptrace +27 NOARGS { ssize_t|linux_sys||recvmsg(int s, \ + struct linux_msghdr *msg, int flags); } +28 NOARGS { ssize_t|linux_sys||sendmsg(int s, \ + const struct linux_msghdr *msg, int flags); } +29 NOARGS { ssize_t|linux_sys||recvfrom(int s, void *buf, \ + int len, int flags, struct osockaddr *from, \ + int *fromlenaddr); } +30 NOARGS { int|linux_sys||accept(int s, struct osockaddr *name, \ + int *anamelen); } +31 NOARGS { int|linux_sys||getpeername(int fdes, \ + struct osockaddr *asa, int *alen); } +32 NOARGS { int|linux_sys||getsockname(int fdes, \ + struct osockaddr *asa, int *alen); } +33 NOARGS { int|sys||access(const char *path, int flags); } +34 UNIMPL chflags +35 UNIMPL fchflags +36 NOARGS { void|sys||sync(void); } +37 UNIMPL kill +38 UNIMPL stat +39 UNIMPL getppid +40 UNIMPL lstat +41 NOARGS { int|sys||dup(int fd); } + +; we mimic the librumpclient calling convention, therefore no linux_sys_pipe +42 NOARGS { int|sys||pipe(void); } + +43 UNIMPL getegid +44 UNIMPL profil +45 UNIMPL ktrace +46 UNIMPL sigaction +47 NOARGS { gid_t|sys||getgid_with_egid(void); } getgid +48 UNIMPL sigprocmask +49 UNIMPL __getlogin +50 UNIMPL __setlogin +51 UNIMPL acct +52 UNIMPL sigpending +53 UNIMPL sigaltstack +54 NOARGS { int|linux_sys||ioctl(int fd, \ + u_long com, void *data); } +55 UNIMPL reboot +56 UNIMPL revoke +57 NOARGS { int|sys||symlink(const char *path, \ + const char *link); } +58 NOARGS { ssize_t|sys||readlink(const char *path, char *buf, \ + int count); } +59 UNIMPL execve +60 NOARGS { mode_t|sys||umask(mode_t newmask); } +61 NOARGS { int|sys||chroot(const char *path); } +62 UNIMPL fstat43 +63 UNIMPL getkerninfo +64 UNIMPL getpagesize +65 UNIMPL msync +66 UNIMPL vfork +67 UNIMPL vread +68 UNIMPL vwrite +69 UNIMPL sbrk +70 UNIMPL sstk +71 UNIMPL mmap +72 UNIMPL ovadvise +73 UNIMPL munmap +74 UNIMPL mprotect +75 UNIMPL madvise +76 UNIMPL vhangup +77 UNIMPL vlimit +78 UNIMPL mincore +79 NOARGS { int|sys||getgroups(int gidsetsize, \ + int *gidset); } +80 NOARGS { int|sys||setgroups(int gidsetsize, \ + const int *gidset); } +81 NOARGS { int|sys||getpgrp(void); } +82 NOARGS { int|sys||setpgid(int pid, int pgid); } +83 UNIMPL setitimer +84 UNIMPL wait +85 UNIMPL swapon +86 UNIMPL getitimer +87 UNIMPL gethostname +88 UNIMPL sethostname +89 UNIMPL getdtablesize +90 NOARGS { int|sys||dup2(int from, int to); } +91 UNIMPL getdopt +92 NOARGS { int|linux_sys||fcntl(int fd, int cmd, void *arg); } +93 UNIMPL select +94 UNIMPL setdopt +95 NOARGS { int|sys||fsync(int fd); } +96 UNIMPL setpriority +97 UNIMPL socket +98 NOARGS { int|linux_sys||connect(int s, \ + const struct osockaddr *name, \ + unsigned int namelen); } +99 UNIMPL accept +100 UNIMPL getpriority + +101 UNIMPL send +102 UNIMPL recv + +103 UNIMPL sigreturn +104 NOARGS { int|linux_sys||bind(int s, \ + const struct osockaddr *name, unsigned namelen); } +105 NOARGS { int|linux_sys||setsockopt(int s, int level, \ + int name, const void *val, int optlen); } +106 NOARGS { int|sys||listen(int s, int backlog); } +107 UNIMPL vtimes +108 UNIMPL sigvec +109 UNIMPL sigblock +110 UNIMPL sigsetmask +111 UNIMPL sigsuspend +112 UNIMPL sigstack +113 UNIMPL orecvmsg +114 UNIMPL osendmsg +115 UNIMPL vtrace +116 UNIMPL gettimeofday +117 UNIMPL getrusage +118 NOARGS { int|linux_sys||getsockopt(int s, int level, \ + int name, void *val, int *avalsize); } +119 UNIMPL resuba +120 NOARGS { ssize_t|sys||readv(int fd, \ + const struct iovec *iovp, int iovcnt); } +121 NOARGS { ssize_t|sys||writev(int fd, \ + const struct iovec *iovp, int iovcnt); } +122 UNIMPL settimeofday +123 NOARGS { int|sys||__posix_fchown(int fd, int uid, int gid); } +124 NOARGS { int|sys||fchmod(int fd, mode_t mode); } +125 UNIMPL orecvfrom +126 NOARGS { int|sys||setreuid(uid_t ruid, uid_t euid); } +127 NOARGS { int|sys||setregid(gid_t rgid, gid_t egid); } +128 NOARGS { int|sys||__posix_rename(const char *from, \ + const char *to); } +129 UNIMPL otruncate +130 UNIMPL oftruncate +131 NOARGS { int|sys||flock(int fd, int how); } +132 UNIMPL mkfifo +133 NOARGS { int|linux_sys||sendto(int s, void *buf, \ + int len, int flags, const struct osockaddr *to, \ + int tolen); } +134 NOARGS { int|sys||shutdown(int s, int how); } +135 NOARGS { int|linux_sys||socketpair(int domain, int type, \ + int protocol, int *rsv); } +136 NOARGS { int|sys||mkdir(const char *path, mode_t mode); } +137 NOARGS { int|sys||rmdir(const char *path); } +138 UNIMPL utimes + +139 UNIMPL 4.2 sigreturn +140 UNIMPL adjtime +141 UNIMPL ogetpeername +142 UNIMPL ogethostid +143 UNIMPL osethostid +144 UNIMPL ogetrlimit +145 UNIMPL osetrlimit +146 UNIMPL okillpg +147 NOARGS { int|sys||setsid(void); } +148 UNIMPL quotactl +149 UNIMPL oquota +150 UNIMPL ogetsockname + +; Syscalls 151-180 inclusive are reserved for vendor-specific +; system calls. (This includes various calls added for compatibity +; with other Unix variants.) +; Some of these calls are now supported by BSD... +151 UNIMPL +152 UNIMPL +153 UNIMPL +154 UNIMPL +155 UNIMPL nfssvc +156 UNIMPL ogetdirentries +157 UNIMPL statfs12 +158 UNIMPL fstatfs12 +159 UNIMPL +160 UNIMPL +161 UNIMPL getfh30 +162 UNIMPL ogetdomainname +163 UNIMPL osetdomainname +164 UNIMPL ouname +165 UNIMPL sysarch +166 UNIMPL +167 UNIMPL +168 UNIMPL +169 UNIMPL 1.0 semsys +170 UNIMPL 1.0 msgsys +171 UNIMPL 1.0 shmsys +172 UNIMPL +173 NOARGS { ssize_t|sys||pread(int fd, char *buf, \ + size_t nbyte, int PAD, off_t offset); } +174 NOARGS { ssize_t|sys||pwrite(int fd, char *buf, \ + size_t nbyte, int PAD, off_t offset); } +175 UNIMPL ntp_gettime +176 UNIMPL ntp_adjtime +177 UNIMPL +178 UNIMPL +179 UNIMPL +180 UNIMPL + +; Syscalls 180-199 are used by/reserved for BSD +181 NOARGS { int|sys||setgid(gid_t gid); } +182 NOARGS { int|sys||setegid(gid_t egid); } +183 NOARGS { int|sys||seteuid(uid_t euid); } +184 UNIMPL lfs_bmapv +185 UNIMPL lfs_markv +186 UNIMPL lfs_segclean +187 UNIMPL lfs_segwait +188 UNIMPL stat12 +189 UNIMPL fstat12 +190 UNIMPL lstat12 +191 UNIMPL pathconf +192 UNIMPL fpathconf +193 UNIMPL +194 NOARGS { int|linux_sys||getrlimit(int which, \ + struct orlimit *rlp); } +195 NOARGS { int|linux_sys||setrlimit(int which, \ + const struct orlimit *rlp); } +196 UNIMPL getdirentries +197 UNIMPL mmap +198 UNIMPL __syscall +199 NOARGS { off_t|sys||lseek(int fd, int PAD, off_t offset, \ + int whence); } +200 NOARGS { int|sys||truncate(const char *path, int PAD, \ + off_t length); } +201 NOARGS { int|sys||ftruncate(int fd, int PAD, off_t length); } +202 UNIMPL __sysctl +203 UNIMPL mlock +204 UNIMPL munlock +205 UNIMPL undelete +206 UNIMPL futimes +207 NOARGS { pid_t|sys||getpgid(pid_t pid); } +208 UNIMPL reboot +209 NOARGS { int|sys||poll(struct pollfd *fds, u_int nfds, \ + int timeout); } +; +; Syscalls 210-219 are reserved for dynamically loaded syscalls +; +210 UNIMPL afssys +211 UNIMPL +212 UNIMPL +213 UNIMPL +214 UNIMPL +215 UNIMPL +216 UNIMPL +217 UNIMPL +218 UNIMPL +219 UNIMPL +220 UNIMPL compat_14_semctl +221 UNIMPL semget +222 UNIMPL semop +223 UNIMPL semconfig +224 UNIMPL compat_14_msgctl +225 UNIMPL msgget +226 UNIMPL msgsnd +227 UNIMPL msgrcv +228 UNIMPL shmat +229 UNIMPL compat_14_shmctl +230 UNIMPL shmdt +231 UNIMPL shmget + +232 UNIMPL clock_gettime +233 UNIMPL clock_settime +234 UNIMPL clock_getres +235 UNIMPL timer_create +236 UNIMPL timer_delete +237 UNIMPL timer_settime +238 UNIMPL timer_gettime +239 UNIMPL timer_getoverrun +; +; Syscalls 240-269 are reserved for other IEEE Std1003.1b syscalls +; +240 UNIMPL nanosleep +241 NOARGS { int|linux_sys||fdatasync(int fd); } +242 UNIMPL mlockall +243 UNIMPL munlockall +244 UNIMPL __sigtimedwait +245 UNIMPL sigqueueinfo +246 UNIMPL modctl +247 UNIMPL _ksem_init +248 UNIMPL _ksem_open +249 UNIMPL _ksem_unlink +250 UNIMPL _ksem_close +251 UNIMPL _ksem_post +252 UNIMPL _ksem_wait +253 UNIMPL _ksem_trywait +254 UNIMPL _ksem_getvalue +255 UNIMPL _ksem_destroy +256 UNIMPL _ksem_timedwait + +257 UNIMPL mq_open +258 UNIMPL mq_close +259 UNIMPL mq_unlink +260 UNIMPL mq_getattr +261 UNIMPL mq_setattr +262 UNIMPL mq_notify +263 UNIMPL mq_send +264 UNIMPL mq_receive +265 UNIMPL mq_timedsend +266 UNIMPL mq_timedreceive +267 UNIMPL +268 UNIMPL +269 UNIMPL +270 UNIMPL __posix_rename +271 UNIMPL swapctl +272 UNIMPL getdents +273 UNIMPL minherit +274 UNIMPL lchmod +275 NOARGS { int|sys||__posix_lchown(const char *path, uid_t uid, \ + gid_t gid); } +276 UNIMPL lutimes +277 UNIMPL msync +278 UNIMPL stat +279 UNIMPL fstat +280 UNIMPL lstat +281 UNIMPL sigaltstack +282 UNIMPL vfork +283 UNIMPL __posix_chown +284 UNIMPL __posix_fchown +285 UNIMPL __posix_lchown +286 NOARGS { pid_t|sys||getsid(pid_t pid); } + +287 UNIMPL __clone +288 UNIMPL fktrace +289 UNIMPL { ssize_t|sys||preadv(int fd, \ + const struct iovec *iovp, int iovcnt, \ + int PAD, off_t offset); } +290 UNIMPL { ssize_t|sys||pwritev(int fd, \ + const struct iovec *iovp, int iovcnt, \ + int PAD, off_t offset); } +291 UNIMPL sigaction +292 UNIMPL sigpending +293 UNIMPL sigprocmask +294 UNIMPL sigsuspend +295 UNIMPL sigreturn +296 NOARGS { int|sys||__getcwd(char *bufp, size_t length); } +297 NOARGS { int|sys||fchroot(int fd); } +298 UNIMPL fhopen +299 UNIMPL fhstat +300 UNIMPL fhstatfs +301 UNIMPL ____semctl13 +302 UNIMPL __msgctl13 +303 UNIMPL __shmctl13 +304 UNIMPL lchflags +305 UNIMPL issetugid +306 UNIMPL utrace +307 UNIMPL getcontext +308 UNIMPL setcontext +309 UNIMPL _lwp_create +310 UNIMPL _lwp_exit +311 UNIMPL _lwp_self +312 UNIMPL _lwp_wait +313 UNIMPL _lwp_suspend +314 UNIMPL _lwp_continue +315 UNIMPL _lwp_wakeup +316 UNIMPL _lwp_getprivate +317 UNIMPL _lwp_setprivate +318 UNIMPL _lwp_kill +319 UNIMPL _lwp_detach +320 UNIMPL _lwp_park +321 UNIMPL _lwp_unpark +322 UNIMPL _lwp_unpark_all +323 UNIMPL _lwp_setname +324 UNIMPL _lwp_getname +325 UNIMPL _lwp_ctl + +; Syscalls 326-339 reserved for LWP syscalls. +326 UNIMPL +327 UNIMPL +328 UNIMPL +329 UNIMPL +; SA system calls. +330 UNIMPL sa_register +331 UNIMPL sa_stacks +332 UNIMPL sa_enable +333 UNIMPL sa_setconcurrency +334 UNIMPL sa_yield +335 UNIMPL sa_preempt +336 UNIMPL sys_sa_unblockyield +; +; Syscalls 337-339 are reserved for other scheduler activation syscalls. +; +337 UNIMPL +338 UNIMPL +339 UNIMPL + +340 UNIMPL __sigaction_sigtramp +341 UNIMPL pmc_get_info +342 UNIMPL pmc_control +343 UNIMPL rasctl +344 UNIMPL kqueue +345 UNIMPL kevent + +; Scheduling system calls. +346 UNIMPL _sched_setparam +347 UNIMPL _sched_getparam +348 UNIMPL _sched_setaffinity +349 UNIMPL _sched_getaffinity +350 UNIMPL sched_yield +351 UNIMPL +352 UNIMPL +353 UNIMPL + +354 UNIMPL fsync_range +355 UNIMPL uuidgen +356 UNIMPL getvfsstat +357 UNIMPL statvfs1 +358 UNIMPL fstatvfs1 +359 UNIMPL fhstatvfs1 +360 UNIMPL extattrctl +361 UNIMPL extattr_set_file +362 UNIMPL extattr_get_file +363 UNIMPL extattr_delete_file +364 UNIMPL extattr_set_fd +365 UNIMPL extattr_get_fd +366 UNIMPL extattr_delete_fd +367 UNIMPL extattr_set_link +368 UNIMPL extattr_get_link +369 UNIMPL extattr_delete_link +370 UNIMPL extattr_list_fd +371 UNIMPL extattr_list_file +372 UNIMPL extattr_list_link +373 UNIMPL pselect +374 UNIMPL pollts +375 UNIMPL setxattr +376 UNIMPL lsetxattr +377 UNIMPL fsetxattr +378 UNIMPL getxattr +379 UNIMPL lgetxattr +380 UNIMPL fgetxattr +381 UNIMPL listxattr +382 UNIMPL llistxattr +383 UNIMPL flistxattr +384 UNIMPL removexattr +385 UNIMPL lremovexattr +386 UNIMPL fremovexattr +387 UNIMPL stat30 +388 UNIMPL fstat30 +389 UNIMPL lstat30 +390 NOARGS { int|linux_sys||getdents64(int fd, \ + struct linux_dirent64 *dent, unsigned int count); } +391 UNIMPL old posix_fadvise +392 UNIMPL fhstat +393 UNIMPL ntp_gettime +394 NOARGS { int|linux_sys||socket(int domain, \ + int type, int protocol); } +395 UNIMPL getfh +396 UNIMPL fhopen +397 UNIMPL fhstatvfs1 +398 UNIMPL fhstat + +; Asynchronous I/O system calls +399 UNIMPL aio_cancel +400 UNIMPL aio_error +401 UNIMPL aio_fsync +402 UNIMPL aio_read +403 UNIMPL aio_return +404 UNIMPL aio_suspend +405 UNIMPL aio_write +406 UNIMPL lio_listio + +407 UNIMPL +408 UNIMPL +409 UNIMPL + +410 UNIMPL mount +411 UNIMPL mremap + +; Processor-sets system calls +412 UNIMPL pset_create +413 UNIMPL pset_destroy +414 UNIMPL pset_assign +415 UNIMPL _pset_bind +416 UNIMPL fadvise +417 NOARGS { int|linux_sys||select(int nd, \ + fd_set *in, fd_set *ou, fd_set *ex, \ + struct timeval50 *tv); } +418 NOARGS { int|linux_sys||gettimeofday(struct timeval50 *tp, \ + struct timezone *tzp); } +419 NOARGS { int|linux_sys||settimeofday(struct timeval50 *tp, \ + struct timezone *tzp); } +420 NOARGS { int|compat_50_sys||utimes(const char *path, \ + const struct timveval50 *tptr); } +421 UNIMPL adjtime +422 UNIMPL lfs_segwait +423 NOARGS { int|sys|50|futimes(int fd, \ + const struct timeval *tptr); } +424 NOARGS { int|sys|50|lutimes(const char *path, \ + const struct timeval *tptr); } +425 UNIMPL setitimer +426 UNIMPL getitimer +427 NOARGS { int|linux_sys||clock_gettime(clockid_t which, \ + struct linux_timespec *tp); } +428 NOARGS { int|linux_sys||clock_settime(clockid_t which, \ + struct linux_timespec *tp); } +429 NOARGS { int|linux_sys||clock_getres(clockid_t which, \ + struct linux_timespec *tp); } +430 NOARGS { int|linux_sys||nanosleep( \ + const struct linux_timespec *rqtp, \ + struct linux_timespec *rmtp); } +431 UNIMPL __sigtimedwait +432 UNIMPL mq_timedsend +433 UNIMPL mq_timedreceive +434 UNIMPL _lwp_park +435 UNIMPL kevent +436 UNIMPL pselect +437 NOARGS { int|linux_sys||ppoll(struct pollfd *fds, \ + u_int nfds, const struct linux_timespec *timeout, \ + const linux_sigset_t *mask);} +438 UNIMPL aio_suspend +439 NOARGS { int|linux_sys||stat64(const char *path, \ + struct linux_stat64 *sp); } +440 NOARGS { int|linux_sys||fstat64(int fd, \ + struct linux_stat64 *sp); } +441 NOARGS { int|linux_sys||lstat64(const char *path, \ + struct linux_stat64 *sp); } +442 UNIMPL __semctl +443 UNIMPL shmctl +444 UNIMPL msgctl +445 UNIMPL getrusage +446 UNIMPL timer_settime +447 UNIMPL timer_gettime +448 UNIMPL ntp_gettime +449 UNIMPL wait4 +450 NOARGS { int|linux_sys||mknod(const char *path, mode_t mode, \ + int dev); } +451 UNIMPL fhstat + +; 452 only ever appeared in 5.99.x and can be reused after netbsd-7 +452 UNIMPL 5.99 quotactl +453 NOARGS { int|linux_sys||pipe2(int *pfds, int flags); } +454 NOARGS { int|linux_sys||dup3(int from, int to, int flags); } +455 UNIMPL kqueue1 +456 UNIMPL paccept +457 NOARGS { int|linux_sys||linkat(int fd1, const char *name1, \ + int fd2, const char *name2, int flags); } +458 NOARGS { int|sys||renameat(int fromfd, const char *from, \ + int tofd, const char *to); } +459 UNIMPL mkfifoat +460 STD { int|rump_linux_sys||mknodat(int fd, const char *path, \ + mode_t mode, int PAD, unsigned dev); } +461 NOARGS { int|sys||mkdirat(int fd, const char *path, \ + mode_t mode); } +462 NOARGS { int|linux_sys||faccessat(int fd, const char *path, \ + int amode); } +463 NOARGS { int|linux_sys||fchmodat(int fd, const char *path, \ + mode_t mode); } +464 NOARGS { int|linux_sys||fchownat(int fd, const char *path, \ + uid_t owner, gid_t group, int flag); } +465 UNIMPL fexecve +466 NOARGS { int|linux_sys||fstatat64(int fd, const char *path, \ + struct linux_stat *sp, int flag); } +467 NOARGS { int|linux_sys||utimensat(int fd, const char *path, \ + struct linux_timespec *times, int flag); } +468 NOARGS { int|linux_sys||openat(int fd, const char *path, \ + int flags, ... mode_t mode); } +469 NOARGS { int|sys||readlinkat(int fd, const char *path, \ + char *buf, size_t bufsize); } +470 NOARGS { int|sys||symlinkat(const char *path1, int fd, \ + const char *path2); } +471 NOARGS { int|linux_sys||unlinkat(int fd, const char *path, \ + int flag); } +472 UNIMPL futimens +473 UNIMPL __quotactl +474 UNIMPL posix_spawn +475 UNIMPL recvmmsg +476 UNIMPL sendmmsg +477 NOARGS { int|linux_sys||clock_nanosleep(clockid_t which, \ + int flags, struct linux_timespec *rqtp, \ + struct linux_timespec *rmtp); } diff --git a/sys/rump/kern/lib/libsys_sunos/Makefile b/sys/rump/kern/lib/libsys_sunos/Makefile new file mode 100644 index 000000000..faee943f7 --- /dev/null +++ b/sys/rump/kern/lib/libsys_sunos/Makefile @@ -0,0 +1,16 @@ +# $NetBSD: Makefile,v 1.5 2015/05/09 12:03:11 pooka Exp $ +# + +LIB= rumpkern_sys_sunos + +SRCS= rump_sunos_compat.c +SRCS+= sys_sunos_component.c + +# XXX +CPPFLAGS+= -I${RUMPTOP}/librump/rumpkern + +SYS_P=rump_sunos_sys +.include "../Makefile.sys" + +.include +.include diff --git a/sys/rump/kern/lib/libsys_sunos/rump_sunos_compat.c b/sys/rump/kern/lib/libsys_sunos/rump_sunos_compat.c new file mode 100644 index 000000000..c7d7b99c0 --- /dev/null +++ b/sys/rump/kern/lib/libsys_sunos/rump_sunos_compat.c @@ -0,0 +1,377 @@ +/* $NetBSD: rump_sunos_compat.c,v 1.1 2013/04/09 13:08:33 pooka Exp $ */ + +/* + * Copyright (c) 2013 Antti Kantee. All Rights Reserved. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the above copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * + * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS + * OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED + * WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE + * DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE + * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL + * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR + * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) + * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT + * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY + * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF + * SUCH DAMAGE. + */ + +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include + +#include + +#include "rump_sunos_syscallargs.h" + +#define SUNOS_MAXNAMLEN 255 + +struct sunos_dirent { + uint64_t d_fileno; + int64_t d_off; + unsigned short d_reclen; + char d_name[SUNOS_MAXNAMLEN + 1]; +}; + +#define SUNOS_NAMEOFF(dp) ((char *)&(dp)->d_name - (char *)dp) +#define SUNOS_RECLEN(de,namlen) ALIGN((SUNOS_NAMEOFF(de) + (namlen) + 1)) + +/* + * Rump kernels always use the _FILE_OFFSET_BITS=64 API. + */ +#ifdef __LP64__ +struct sunos_stat { + unsigned long st_dev; + uint64_t st_ino; + unsigned int st_mode; + unsigned int st_nlink; + unsigned int st_uid; + unsigned int st_gid; + unsigned long st_rdev; + off_t st_size; + + struct timespec st_atim; + struct timespec st_mtim; + struct timespec st_ctim; + int st_blksize; + uint64_t st_blocks; + char st_fstype[16]; +}; +#else +struct sunos_stat { + unsigned long st_dev; + long st_pad1[3]; + uint64_t st_ino; + unsigned int st_mode; + unsigned int st_nlink; + unsigned int st_uid; + unsigned int st_gid; + unsigned long st_rdev; + long st_pad2[2]; + off_t st_size; + + struct timespec50 st_atim; + struct timespec50 st_mtim; + struct timespec50 st_ctim; + + int st_blksize; + uint64_t st_blocks; + char st_fstype[16]; + long st_pad4[8]; +}; +#endif + +#define PARCOPY(a) ssb->a = sb->a +static void +bsd_to_sunos_stat(const struct stat *sb, struct sunos_stat *ssb) +{ + + memset(ssb, 0, sizeof(*ssb)); + PARCOPY(st_dev); + PARCOPY(st_ino); + PARCOPY(st_mode); + PARCOPY(st_nlink); + PARCOPY(st_uid); + PARCOPY(st_gid); + PARCOPY(st_rdev); + PARCOPY(st_size); + PARCOPY(st_blksize); + PARCOPY(st_blocks); + +#ifdef __LP64__ + ssb->st_atim = sb->st_atimespec; + ssb->st_mtim = sb->st_mtimespec; + ssb->st_ctim = sb->st_ctimespec; +#else + timespec_to_timespec50(&sb->st_atimespec, &ssb->st_atim); + timespec_to_timespec50(&sb->st_mtimespec, &ssb->st_mtim); + timespec_to_timespec50(&sb->st_ctimespec, &ssb->st_ctim); +#endif +} + +int +rump_sunos_sys_stat(struct lwp *l, const struct rump_sunos_sys_stat_args *uap, + register_t *retval) +{ + struct sunos_stat ssb; + struct stat sb; + int error; + + error = do_sys_stat(SCARG(uap, path), FOLLOW, &sb); + if (error) + return error; + + bsd_to_sunos_stat(&sb, &ssb); + + return copyout(&ssb, SCARG(uap, sp), sizeof(ssb)); +} + +int +rump_sunos_sys_fstat(struct lwp *l, const struct rump_sunos_sys_fstat_args *uap, + register_t *retval) +{ + struct sunos_stat ssb; + struct stat sb; + int error; + + error = do_sys_fstat(SCARG(uap, fd), &sb); + if (error) + return error; + + bsd_to_sunos_stat(&sb, &ssb); + + return copyout(&ssb, SCARG(uap, sp), sizeof(ssb)); +} + +int +rump_sunos_sys_lstat(struct lwp *l, const struct rump_sunos_sys_lstat_args *uap, + register_t *retval) +{ + struct sunos_stat ssb; + struct stat sb; + int error; + + error = do_sys_stat(SCARG(uap, path), NOFOLLOW, &sb); + if (error) + return error; + + bsd_to_sunos_stat(&sb, &ssb); + + return copyout(&ssb, SCARG(uap, sp), sizeof(ssb)); +} + +int +rump_sunos_sys_open(struct lwp *l, const struct rump_sunos_sys_open_args *uap, + register_t *retval) +{ + /* { + syscallarg(const char *) path; + syscallarg(int) flags; + syscallarg(int) mode; + } */ + struct sys_open_args ua; + int sflags, flags; + + sflags = SCARG(uap, flags); + flags = (sflags & (0x8 | 0x4 | 0x3)); /* nonblock/append/rw */ + flags |= (sflags & 0x10) ? O_SYNC : 0; + flags |= (sflags & 0x40) ? O_DSYNC : 0; + flags |= (sflags & 0x8000) ? O_RSYNC : 0; + flags |= (sflags & 0x80) ? O_NONBLOCK : 0; + flags |= (sflags & 0x100) ? O_CREAT : 0; + flags |= (sflags & 0x200) ? O_TRUNC : 0; + flags |= (sflags & 0x400) ? O_EXCL : 0; + flags |= (sflags & 0x20000) ? O_NOFOLLOW : 0; + + SCARG(&ua, path) = SCARG(uap, path); + SCARG(&ua, flags) = flags; + SCARG(&ua, mode) = SCARG(uap, mode); + + return sys_open(l, &ua, retval); +} + +/*- + * Copyright (c) 1992, 1993 + * The Regents of the University of California. All rights reserved. + * + * This software was developed by the Computer Systems Engineering group + * at Lawrence Berkeley Laboratory under DARPA contract BG 91-66 and + * contributed to Berkeley. + * + * All advertising materials mentioning features or use of this software + * must display the following acknowledgement: + * This product includes software developed by the University of + * California, Lawrence Berkeley Laboratory. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the above copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * 3. Neither the name of the University nor the names of its contributors + * may be used to endorse or promote products derived from this software + * without specific prior written permission. + * + * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND + * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE + * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE + * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE + * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL + * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS + * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) + * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT + * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY + * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF + * SUCH DAMAGE. + * + * @(#)sunos_misc.c 8.1 (Berkeley) 6/18/93 + * + * Header: sunos_misc.c,v 1.16 93/04/07 02:46:27 torek Exp + */ + +int +rump_sunos_sys_getdents(struct lwp *l, + const struct rump_sunos_sys_getdents_args *uap, register_t *retval) +{ + struct dirent *bdp; + struct vnode *vp; + char *inp, *buf; /* BSD-format */ + int len, reclen; /* BSD-format */ + char *outp; /* Sun-format */ + int resid, sunos_reclen;/* Sun-format */ + struct file *fp; + struct uio auio; + struct iovec aiov; + struct sunos_dirent idb; + off_t off; /* true file offset */ + int buflen, error, eofflag; + off_t *cookiebuf, *cookie; + int ncookies; + + if ((error = fd_getvnode(SCARG(uap, fd), &fp)) != 0) + return (error); + + if ((fp->f_flag & FREAD) == 0) { + error = EBADF; + goto out1; + } + + vp = fp->f_data; + if (vp->v_type != VDIR) { + error = EINVAL; + goto out1; + } + + buflen = min(MAXBSIZE, SCARG(uap, nbytes)); + buf = malloc(buflen, M_TEMP, M_WAITOK); + vn_lock(vp, LK_EXCLUSIVE | LK_RETRY); + off = fp->f_offset; +again: + aiov.iov_base = buf; + aiov.iov_len = buflen; + auio.uio_iov = &aiov; + auio.uio_iovcnt = 1; + auio.uio_rw = UIO_READ; + auio.uio_resid = buflen; + auio.uio_offset = off; + UIO_SETUP_SYSSPACE(&auio); + /* + * First we read into the malloc'ed buffer, then + * we massage it into user space, one record at a time. + */ + error = VOP_READDIR(vp, &auio, fp->f_cred, &eofflag, &cookiebuf, + &ncookies); + if (error) + goto out; + + inp = buf; + outp = SCARG(uap, buf); + resid = SCARG(uap, nbytes); + if ((len = buflen - auio.uio_resid) == 0) + goto eof; + + for (cookie = cookiebuf; len > 0; len -= reclen) { + bdp = (struct dirent *)inp; + reclen = bdp->d_reclen; + if (reclen & 3) + panic("sunos_getdents"); + if ((*cookie >> 32) != 0) { + printf("rump_sunos_sys_getdents: offset too large\n"); + error = EINVAL; + goto out; + } + if (bdp->d_fileno == 0) { + inp += reclen; /* it is a hole; squish it out */ + if (cookie) + off = *cookie++; + else + off += reclen; + continue; + } + sunos_reclen = SUNOS_RECLEN(&idb, bdp->d_namlen); + if (reclen > len || resid < sunos_reclen) { + /* entry too big for buffer, so just stop */ + outp++; + break; + } + if (cookie) + off = *cookie++; /* each entry points to next */ + else + off += reclen; + /* + * Massage in place to make a Sun-shaped dirent (otherwise + * we have to worry about touching user memory outside of + * the copyout() call). + */ + idb.d_fileno = bdp->d_fileno; + idb.d_off = off; + idb.d_reclen = sunos_reclen; + strlcpy(idb.d_name, bdp->d_name, sizeof(idb.d_name)); + if ((error = copyout((void *)&idb, outp, sunos_reclen)) != 0) + goto out; + /* advance past this real entry */ + inp += reclen; + /* advance output past Sun-shaped entry */ + outp += sunos_reclen; + resid -= sunos_reclen; + } + + /* if we squished out the whole block, try again */ + if (outp == SCARG(uap, buf)) { + if (cookiebuf) + free(cookiebuf, M_TEMP); + cookiebuf = NULL; + goto again; + } + fp->f_offset = off; /* update the vnode offset */ + +eof: + *retval = SCARG(uap, nbytes) - resid; +out: + VOP_UNLOCK(vp); + free(cookiebuf, M_TEMP); + free(buf, M_TEMP); + out1: + fd_putfile(SCARG(uap, fd)); + return (error); +} diff --git a/sys/rump/kern/lib/libsys_sunos/sys_sunos_component.c b/sys/rump/kern/lib/libsys_sunos/sys_sunos_component.c new file mode 100644 index 000000000..b89f8bf42 --- /dev/null +++ b/sys/rump/kern/lib/libsys_sunos/sys_sunos_component.c @@ -0,0 +1,31 @@ +/* $NetBSD: sys_sunos_component.c,v 1.1 2014/03/13 02:04:14 pooka Exp $ */ + +#include +#include + +#include + +#include "rump_private.h" + +#include "rump_sunos_syscall.h" + +extern struct sysent rump_sunos_sysent[]; + +struct emul emul_rump_sys_sunos = { + .e_name = "sunos-rump", + .e_sysent = rump_sunos_sysent, +#ifndef __HAVE_MINIMAL_EMUL + .e_nsysent = RUMP_SUNOS_SYS_NSYSENT, +#endif + .e_vm_default_addr = uvm_default_mapaddr, +#ifdef __HAVE_SYSCALL_INTERN + .e_syscall_intern = syscall_intern, +#endif +}; + +RUMP_COMPONENT(RUMP_COMPONENT_KERN) +{ + extern struct emul *emul_default; + + emul_default = &emul_rump_sys_sunos; +} diff --git a/sys/rump/kern/lib/libsys_sunos/syscalls.conf b/sys/rump/kern/lib/libsys_sunos/syscalls.conf new file mode 100644 index 000000000..26bcf54a3 --- /dev/null +++ b/sys/rump/kern/lib/libsys_sunos/syscalls.conf @@ -0,0 +1,14 @@ +# $NetBSD: syscalls.conf,v 1.1 2013/04/09 13:08:33 pooka Exp $ +# + +sysnames="rump_sunos_syscalls.c" +sysnumhdr="rump_sunos_syscall.h" +syssw="rump_sunos_sysent.c" +sysarghdr="rump_sunos_syscallargs.h" +compatopts="" +libcompatopts="" + +switchname="rump_sunos_sysent" +namesname="rump_sunos_syscallnames" +constprefix="RUMP_SUNOS_SYS_" +nsysent=512 diff --git a/sys/rump/kern/lib/libsys_sunos/syscalls.master b/sys/rump/kern/lib/libsys_sunos/syscalls.master new file mode 100644 index 000000000..9f273eadb --- /dev/null +++ b/sys/rump/kern/lib/libsys_sunos/syscalls.master @@ -0,0 +1,578 @@ + $NetBSD: syscalls.master,v 1.2 2013/05/15 21:39:30 pooka Exp $ + +; @(#)syscalls.master 8.2 (Berkeley) 1/13/94 + +; NetBSD system call name/number "master" file. +; (See syscalls.conf to see what it is processed into.) +; +; Fields: number type [type-dependent ...] +; number system call number, must be in order +; type one of NODEF, UNIMPL, or NOARGS +; +; types: +; NODEF always included +; UNIMPL unimplemented, not included in system +; NODEF included, but don't define the syscall number +; NOARGS included, but don't define the syscall args structure +; +; arguments: +; PAD argument not part of the C interface, used only for padding +; +; +; Support just enough syscalls to make fs-utils run (plus a few other +; low-hanging fruit) +; + +#include +#include +#include +#include +#include +#include +#include + +#include + +#include "rump_sunos_syscallargs.h" + +%% + +0 NOARGS { int|sys||nosys(void); } +1 UNIMPL exit +2 UNIMPL fork +3 NOARGS { ssize_t|sys||read(int fd, void *buf, size_t nbyte); } +4 NOARGS { ssize_t|sys||write(int fd, const void *buf, \ + size_t nbyte); } +5 NODEF { int|rump_sunos_sys||open(const char *path, \ + int flags, int mode); } +6 NOARGS { int|sys||close(int fd); } +7 UNIMPL wait4 +8 UNIMPL creat +9 NOARGS { int|sys||link(const char *path, const char *link); } +10 NOARGS { int|sys||unlink(const char *path); } +11 UNIMPL execv +12 NOARGS { int|sys||chdir(const char *path); } +13 NOARGS { int|sys||fchdir(int fd); } +14 UNIMPL mknod +15 NOARGS { int|sys||chmod(const char *path, int mode); } +16 NOARGS { int|sys||chown(const char *path, int uid, int gid); } +17 UNIMPL obreak +18 UNIMPL getfsstat +19 UNIMPL lseek +20 NOARGS { pid_t|sys||getpid_with_ppid(void); } getpid +21 UNIMPL mount +22 UNIMPL unmount +23 NOARGS { int|sys||setuid(int uid); } +24 NOARGS { int|sys||getuid_with_euid(void); } getuid +25 NOARGS { int|sys||geteuid(void); } +26 UNIMPL ptrace +27 UNIMPL recvmsg +28 UNIMPL sendmsg +29 UNIMPL recvfrom +30 UNIMPL accept +31 UNIMPL getpeername +32 UNIMPL getsockname +33 NOARGS { int|sys||access(const char *path, int flags); } +34 UNIMPL chflags +35 UNIMPL fchflags +36 NOARGS { void|sys||sync(void); } +37 UNIMPL kill +38 UNIMPL stat +39 UNIMPL getppid +40 UNIMPL lstat +41 NOARGS { int|sys||dup(int fd); } +42 NOARGS { int|sys||pipe(void); } +43 UNIMPL getegid +44 UNIMPL profil +45 UNIMPL ktrace +46 UNIMPL sigaction +47 NOARGS { int|sys||getgid_with_egid(void); } getgid +48 UNIMPL sigprocmask +49 UNIMPL __getlogin +50 UNIMPL __setlogin +51 UNIMPL acct +52 UNIMPL sigpending +53 UNIMPL sigaltstack +54 UNIMPL ioctl +55 UNIMPL reboot +56 UNIMPL revoke +57 NOARGS { int|sys||symlink(const char *path, \ + const char *link); } +58 NOARGS { ssize_t|sys||readlink(const char *path, char *buf, \ + int count); } +59 UNIMPL execve +60 NOARGS { mode_t|sys||umask(mode_t newmask); } +61 NOARGS { int|sys||chroot(const char *path); } +62 UNIMPL fstat43 +63 UNIMPL getkerninfo +64 UNIMPL getpagesize +65 UNIMPL msync +66 UNIMPL vfork +67 UNIMPL vread +68 UNIMPL vwrite +69 UNIMPL sbrk +70 UNIMPL sstk +71 UNIMPL mmap +72 UNIMPL ovadvise +73 UNIMPL munmap +74 UNIMPL mprotect +75 UNIMPL madvise +76 UNIMPL vhangup +77 UNIMPL vlimit +78 UNIMPL mincore +79 NOARGS { int|sys||getgroups(int gidsetsize, \ + int *gidset); } +80 NOARGS { int|sys||setgroups(int gidsetsize, \ + const int *gidset); } +81 NOARGS { int|sys||getpgrp(void); } +82 NOARGS { int|sys||setpgid(int pid, int pgid); } +83 UNIMPL setitimer +84 UNIMPL wait +85 UNIMPL swapon +86 UNIMPL getitimer +87 UNIMPL gethostname +88 UNIMPL sethostname +89 UNIMPL getdtablesize +90 NOARGS { int|sys||dup2(int from, int to); } +91 UNIMPL getdopt +92 UNIMPL fcntl +93 UNIMPL select +94 UNIMPL setdopt +95 NOARGS { int|sys||fsync(int fd); } +96 UNIMPL setpriority +97 UNIMPL socket +98 UNIMPL connect +99 UNIMPL accept +100 UNIMPL getpriority + +101 UNIMPL send +102 UNIMPL recv + +103 UNIMPL sigreturn +104 UNIMPL bind +105 UNIMPL setsockopt +106 UNIMPL listen +107 UNIMPL vtimes +108 UNIMPL sigvec +109 UNIMPL sigblock +110 UNIMPL sigsetmask +111 UNIMPL sigsuspend +112 UNIMPL sigstack +113 UNIMPL orecvmsg +114 UNIMPL osendmsg +115 UNIMPL vtrace +116 UNIMPL gettimeofday +117 UNIMPL getrusage +118 UNIMPL getsockopt +119 UNIMPL resuba +120 NOARGS { ssize_t|sys||readv(int fd, \ + struct iovec *iovp, int iovcnt); } +121 NOARGS { ssize_t|sys||writev(int fd, \ + struct iovec *iovp, int iovcnt); } +122 UNIMPL settimeofday +123 NOARGS { int|sys||fchown(int fd, int uid, int gid); } +124 NOARGS { int|sys||fchmod(int fd, int mode); } +125 UNIMPL orecvfrom +126 NOARGS { int|sys||setreuid(int ruid, int euid); } +127 NOARGS { int|sys||setregid(int rgid, int egid); } +128 NOARGS { int|sys||rename(char *from, char *to); } +129 UNIMPL otruncate +130 UNIMPL oftruncate +131 NOARGS { int|sys||flock(int fd, int how); } +132 UNIMPL mkfifo +133 NOARGS { int|sys||sendto(int s, void *buf, \ + int len, int flags, void *to, int tolen); } +134 NOARGS { int|sys||shutdown(int s, int how); } +135 UNIMPL socketpair +136 NOARGS { int|sys||mkdir(const char *path, int mode); } +137 NOARGS { int|sys||rmdir(const char *path); } +138 UNIMPL utimes + +139 UNIMPL 4.2 sigreturn +140 UNIMPL adjtime +141 UNIMPL ogetpeername +142 UNIMPL ogethostid +143 UNIMPL osethostid +144 UNIMPL ogetrlimit +145 UNIMPL osetrlimit +146 UNIMPL okillpg +147 NOARGS { int|sys||setsid(void); } +148 UNIMPL quotactl +149 UNIMPL oquota +150 UNIMPL ogetsockname + +; Syscalls 151-180 inclusive are reserved for vendor-specific +; system calls. (This includes various calls added for compatibity +; with other Unix variants.) +; Some of these calls are now supported by BSD... +151 UNIMPL +152 UNIMPL +153 UNIMPL +154 UNIMPL +155 UNIMPL nfssvc +156 UNIMPL ogetdirentries +157 UNIMPL statfs12 +158 UNIMPL fstatfs12 +159 UNIMPL +160 UNIMPL +161 UNIMPL getfh30 +162 UNIMPL ogetdomainname +163 UNIMPL osetdomainname +164 UNIMPL ouname +165 UNIMPL sysarch +166 UNIMPL +167 UNIMPL +168 UNIMPL +169 UNIMPL 1.0 semsys +170 UNIMPL 1.0 msgsys +171 UNIMPL 1.0 shmsys +172 UNIMPL +173 NOARGS { ssize_t|sys||pread(int fd, char *buf, \ + size_t nbyte, int PAD, off_t offset); } +174 NOARGS { ssize_t|sys||pwrite(int fd, char *buf, \ + size_t nbyte, int PAD, off_t offset); } +175 UNIMPL ntp_gettime +176 UNIMPL ntp_adjtime +177 UNIMPL +178 UNIMPL +179 UNIMPL +180 UNIMPL + +; Syscalls 180-199 are used by/reserved for BSD +181 NOARGS { int|sys||setgid(gid_t gid); } +182 NOARGS { int|sys||setegid(gid_t egid); } +183 NOARGS { int|sys||seteuid(uid_t euid); } +184 UNIMPL lfs_bmapv +185 UNIMPL lfs_markv +186 UNIMPL lfs_segclean +187 UNIMPL lfs_segwait +188 UNIMPL stat12 +189 UNIMPL fstat12 +190 UNIMPL lstat12 +191 UNIMPL pathconf +192 UNIMPL fpathconf +193 UNIMPL +194 UNIMPL getrlimit +195 UNIMPL setrlimit +196 UNIMPL getdirentries +197 UNIMPL mmap +198 UNIMPL __syscall +199 NOARGS { long|sys||lseek(int fd, int PAD, off_t offset, \ + int whence); } +200 NOARGS { int|sys||truncate(const char *path, int PAD, \ + off_t length); } +201 NOARGS { int|sys||ftruncate(int fd, int PAD, off_t length); } +202 UNIMPL __sysctl +203 UNIMPL mlock +204 UNIMPL munlock +205 UNIMPL undelete +206 UNIMPL futimes +207 NOARGS { pid_t|sys||getpgid(pid_t pid); } +208 UNIMPL reboot +209 NOARGS { int|sys||poll(struct pollfd *fds, u_int nfds, \ + int timeout); } +; +; Syscalls 210-219 are reserved for dynamically loaded syscalls +; +210 UNIMPL afssys +211 UNIMPL +212 UNIMPL +213 UNIMPL +214 UNIMPL +215 UNIMPL +216 UNIMPL +217 UNIMPL +218 UNIMPL +219 UNIMPL +220 UNIMPL compat_14_semctl +221 UNIMPL semget +222 UNIMPL semop +223 UNIMPL semconfig +224 UNIMPL compat_14_msgctl +225 UNIMPL msgget +226 UNIMPL msgsnd +227 UNIMPL msgrcv +228 UNIMPL shmat +229 UNIMPL compat_14_shmctl +230 UNIMPL shmdt +231 UNIMPL shmget + +232 UNIMPL clock_gettime +233 UNIMPL clock_settime +234 UNIMPL clock_getres +235 UNIMPL timer_create +236 UNIMPL timer_delete +237 UNIMPL timer_settime +238 UNIMPL timer_gettime +239 UNIMPL timer_getoverrun +; +; Syscalls 240-269 are reserved for other IEEE Std1003.1b syscalls +; +240 UNIMPL nanosleep +241 UNIMPL fdatasync +242 UNIMPL mlockall +243 UNIMPL munlockall +244 UNIMPL __sigtimedwait +245 UNIMPL sigqueueinfo +246 UNIMPL modctl +247 UNIMPL _ksem_init +248 UNIMPL _ksem_open +249 UNIMPL _ksem_unlink +250 UNIMPL _ksem_close +251 UNIMPL _ksem_post +252 UNIMPL _ksem_wait +253 UNIMPL _ksem_trywait +254 UNIMPL _ksem_getvalue +255 UNIMPL _ksem_destroy +256 UNIMPL _ksem_timedwait + +257 UNIMPL mq_open +258 UNIMPL mq_close +259 UNIMPL mq_unlink +260 UNIMPL mq_getattr +261 UNIMPL mq_setattr +262 UNIMPL mq_notify +263 UNIMPL mq_send +264 UNIMPL mq_receive +265 UNIMPL mq_timedsend +266 UNIMPL mq_timedreceive +267 UNIMPL +268 UNIMPL +269 UNIMPL +270 UNIMPL __posix_rename +271 UNIMPL swapctl +272 UNIMPL getdents +273 UNIMPL minherit +274 UNIMPL lchmod +275 UNIMPL lchown +276 UNIMPL lutimes +277 UNIMPL msync +278 UNIMPL stat +279 UNIMPL fstat +280 UNIMPL lstat +281 UNIMPL sigaltstack +282 UNIMPL vfork +283 UNIMPL __posix_chown +284 UNIMPL __posix_fchown +285 UNIMPL __posix_lchown +286 NOARGS { pid_t|sys||getsid(pid_t pid); } + +287 UNIMPL __clone +288 UNIMPL fktrace +289 UNIMPL { ssize_t|sys||preadv(int fd, \ + const struct iovec *iovp, int iovcnt, \ + int PAD, off_t offset); } +290 UNIMPL { ssize_t|sys||pwritev(int fd, \ + const struct iovec *iovp, int iovcnt, \ + int PAD, off_t offset); } +291 UNIMPL sigaction +292 UNIMPL sigpending +293 UNIMPL sigprocmask +294 UNIMPL sigsuspend +295 UNIMPL sigreturn +296 NOARGS { int|sys||__getcwd(char *bufp, size_t length); } +297 NOARGS { int|sys||fchroot(int fd); } +298 UNIMPL fhopen +299 UNIMPL fhstat +300 UNIMPL fhstatfs +301 UNIMPL ____semctl13 +302 UNIMPL __msgctl13 +303 UNIMPL __shmctl13 +304 UNIMPL lchflags +305 UNIMPL issetugid +306 UNIMPL utrace +307 UNIMPL getcontext +308 UNIMPL setcontext +309 UNIMPL _lwp_create +310 UNIMPL _lwp_exit +311 UNIMPL _lwp_self +312 UNIMPL _lwp_wait +313 UNIMPL _lwp_suspend +314 UNIMPL _lwp_continue +315 UNIMPL _lwp_wakeup +316 UNIMPL _lwp_getprivate +317 UNIMPL _lwp_setprivate +318 UNIMPL _lwp_kill +319 UNIMPL _lwp_detach +320 UNIMPL _lwp_park +321 UNIMPL _lwp_unpark +322 UNIMPL _lwp_unpark_all +323 UNIMPL _lwp_setname +324 UNIMPL _lwp_getname +325 UNIMPL _lwp_ctl + +; Syscalls 326-339 reserved for LWP syscalls. +326 UNIMPL +327 UNIMPL +328 UNIMPL +329 UNIMPL +; SA system calls. +330 UNIMPL sa_register +331 UNIMPL sa_stacks +332 UNIMPL sa_enable +333 UNIMPL sa_setconcurrency +334 UNIMPL sa_yield +335 UNIMPL sa_preempt +336 UNIMPL sys_sa_unblockyield +; +; Syscalls 337-339 are reserved for other scheduler activation syscalls. +; +337 UNIMPL +338 UNIMPL +339 UNIMPL + +340 UNIMPL __sigaction_sigtramp +341 UNIMPL pmc_get_info +342 UNIMPL pmc_control +343 UNIMPL rasctl +344 UNIMPL kqueue +345 UNIMPL kevent + +; Scheduling system calls. +346 UNIMPL _sched_setparam +347 UNIMPL _sched_getparam +348 UNIMPL _sched_setaffinity +349 UNIMPL _sched_getaffinity +350 UNIMPL sched_yield +351 UNIMPL +352 UNIMPL +353 UNIMPL + +354 UNIMPL fsync_range +355 UNIMPL uuidgen +356 UNIMPL getvfsstat +357 UNIMPL statvfs1 +358 UNIMPL fstatvfs1 +359 UNIMPL fhstatvfs1 +360 UNIMPL extattrctl +361 UNIMPL extattr_set_file +362 UNIMPL extattr_get_file +363 UNIMPL extattr_delete_file +364 UNIMPL extattr_set_fd +365 UNIMPL extattr_get_fd +366 UNIMPL extattr_delete_fd +367 UNIMPL extattr_set_link +368 UNIMPL extattr_get_link +369 UNIMPL extattr_delete_link +370 UNIMPL extattr_list_fd +371 UNIMPL extattr_list_file +372 UNIMPL extattr_list_link +373 UNIMPL pselect +374 UNIMPL pollts +375 UNIMPL setxattr +376 UNIMPL lsetxattr +377 UNIMPL fsetxattr +378 UNIMPL getxattr +379 UNIMPL lgetxattr +380 UNIMPL fgetxattr +381 UNIMPL listxattr +382 UNIMPL llistxattr +383 UNIMPL flistxattr +384 UNIMPL removexattr +385 UNIMPL lremovexattr +386 UNIMPL fremovexattr +387 UNIMPL stat30 +388 UNIMPL fstat30 +389 UNIMPL lstat30 +390 NODEF { int|rump_sunos_sys||getdents(int fd, \ + char *buf, size_t nbytes); } +391 UNIMPL old posix_fadvise +392 UNIMPL fhstat +393 UNIMPL ntp_gettime +394 UNIMPL socket +395 UNIMPL getfh +396 UNIMPL fhopen +397 UNIMPL fhstatvfs1 +398 UNIMPL fhstat + +; Asynchronous I/O system calls +399 UNIMPL aio_cancel +400 UNIMPL aio_error +401 UNIMPL aio_fsync +402 UNIMPL aio_read +403 UNIMPL aio_return +404 UNIMPL aio_suspend +405 UNIMPL aio_write +406 UNIMPL lio_listio + +407 UNIMPL +408 UNIMPL +409 UNIMPL + +410 UNIMPL mount +411 UNIMPL mremap + +; Processor-sets system calls +412 UNIMPL pset_create +413 UNIMPL pset_destroy +414 UNIMPL pset_assign +415 UNIMPL _pset_bind +416 UNIMPL fadvise +417 UNIMPL select +418 UNIMPL gettimeofday +419 UNIMPL settimeofday +420 NOARGS { int|compat_50_sys||utimes(char *path, \ + struct timeval50 *tptr); } +421 UNIMPL adjtime +422 UNIMPL lfs_segwait +423 NOARGS { int|compat_50_sys||futimes(int fd, \ + struct timeval50 *tptr); } +424 UNIMPL lutimes +425 UNIMPL setitimer +426 UNIMPL getitimer +427 UNIMPL clock_gettime +428 UNIMPL clock_settime +429 UNIMPL clock_getres +430 UNIMPL nanosleep +431 UNIMPL __sigtimedwait +432 UNIMPL mq_timedsend +433 UNIMPL mq_timedreceive +434 UNIMPL _lwp_park +435 UNIMPL kevent +436 UNIMPL pselect +437 UNIMPL ppoll +438 UNIMPL aio_suspend +439 NODEF { int|rump_sunos_sys||stat(const char *path, \ + struct sunos_stat *sp); } +440 NODEF { int|rump_sunos_sys||fstat(int fd, \ + struct sunos_stat *sp); } +441 NODEF { int|rump_sunos_sys||lstat(const char *path, \ + struct sunos_stat *sp); } +442 UNIMPL __semctl +443 UNIMPL shmctl +444 UNIMPL msgctl +445 UNIMPL getrusage +446 UNIMPL timer_settime +447 UNIMPL timer_gettime +448 UNIMPL ntp_gettime +449 UNIMPL wait4 +450 NOARGS { int|sys|50|mknod(const char *path, mode_t mode, \ + int dev); } +451 UNIMPL fhstat + +; 452 only ever appeared in 5.99.x and can be reused after netbsd-7 +452 UNIMPL 5.99 quotactl +453 UNIMPL pipe2 +454 UNIMPL dup3 +455 UNIMPL kqueue1 +456 UNIMPL paccept +457 UNIMPL linkat +458 UNIMPL renameat +459 UNIMPL mkfifoat +460 UNIMPL mknodat +461 UNIMPL mkdirat +462 UNIMPL faccessat +463 UNIMPL fchmodat +464 UNIMPL fchownat +465 UNIMPL fexecve +466 UNIMPL fstatat +467 UNIMPL utimensat +468 UNIMPL openat +469 UNIMPL readlinkat +470 UNIMPL symlinkat +471 UNIMPL unlinkat +472 UNIMPL futimens +473 UNIMPL __quotactl +474 UNIMPL posix_spawn +475 UNIMPL recvmmsg +476 UNIMPL sendmmsg diff --git a/sys/rump/kern/lib/libsysproxy/Makefile b/sys/rump/kern/lib/libsysproxy/Makefile new file mode 100644 index 000000000..acb0c28be --- /dev/null +++ b/sys/rump/kern/lib/libsysproxy/Makefile @@ -0,0 +1,11 @@ +# $NetBSD: Makefile,v 1.1 2015/01/07 22:24:04 pooka Exp $ +# + +LIB= rumpkern_sysproxy + +SRCS= sysproxy.c + +CPPFLAGS+= -I${RUMPTOP}/librump/rumpkern + +.include +.include diff --git a/sys/rump/kern/lib/libsysproxy/i386 b/sys/rump/kern/lib/libsysproxy/i386 new file mode 120000 index 000000000..1c75cf687 --- /dev/null +++ b/sys/rump/kern/lib/libsysproxy/i386 @@ -0,0 +1 @@ +/home/boricj/Documents/Projets/minix/src/sys/arch/i386/include \ No newline at end of file diff --git a/sys/rump/kern/lib/libsysproxy/machine b/sys/rump/kern/lib/libsysproxy/machine new file mode 120000 index 000000000..1c75cf687 --- /dev/null +++ b/sys/rump/kern/lib/libsysproxy/machine @@ -0,0 +1 @@ +/home/boricj/Documents/Projets/minix/src/sys/arch/i386/include \ No newline at end of file diff --git a/sys/rump/kern/lib/libsysproxy/sysproxy.c b/sys/rump/kern/lib/libsysproxy/sysproxy.c new file mode 100644 index 000000000..51c51c8ad --- /dev/null +++ b/sys/rump/kern/lib/libsysproxy/sysproxy.c @@ -0,0 +1,216 @@ +/* $NetBSD: sysproxy.c,v 1.3 2015/04/18 15:49:18 pooka Exp $ */ + +/* + * Copyright (c) 2010, 2011 Antti Kantee. All Rights Reserved. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the above copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * + * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS + * OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED + * WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE + * DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE + * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL + * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR + * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) + * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT + * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY + * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF + * SUCH DAMAGE. + */ + +#include +__KERNEL_RCSID(0, "$NetBSD: sysproxy.c,v 1.3 2015/04/18 15:49:18 pooka Exp $"); + +#include +#include +#include +#include +#include +#include +#include + +#define _RUMP_SYSPROXY +#include + +#include "rump_private.h" + +int +rump_init_server(const char *url) +{ + + return rumpuser_sp_init(url, ostype, osrelease, MACHINE); +} + +static pid_t +hyp_getpid(void) +{ + + return curproc->p_pid; +} + +static int +hyp_syscall(int num, void *arg, long *retval) +{ + register_t regrv[2] = {0, 0}; + struct lwp *l; + struct sysent *callp; + int rv; + + if (__predict_false(num >= SYS_NSYSENT)) + return ENOSYS; + + /* XXX: always uses native syscall vector */ + callp = rump_sysent + num; + l = curlwp; + rv = sy_invoke(callp, l, (void *)arg, regrv, num); + retval[0] = regrv[0]; + retval[1] = regrv[1]; + + return rv; +} + +static struct pmap remotepmap; + +static int +hyp_rfork(void *priv, int flags, const char *comm) +{ + struct rump_spctl *spctl; + struct vmspace *vm; + struct proc *p; + struct lwp *l; + int error; + bool initfds; + + /* + * If we are forking off of pid 1, initialize file descriptors. + */ + l = curlwp; + if (l->l_proc->p_pid == 1) { + KASSERT(flags == RUMP_RFFD_CLEAR); + initfds = true; + } else { + initfds = false; + } + + /* + * Since it's a proxy proc, we create a vmspace for it. + */ + spctl = kmem_zalloc(sizeof(*spctl), KM_SLEEP); + vm = &spctl->spctl_vm; + uvmspace_init(vm, &remotepmap, 0, 0, false); + spctl->spctl = priv; + + if ((error = rump_lwproc_rfork_vmspace(vm, flags)) != 0) { + kmem_free(vm, sizeof(*vm)); + return error; + } + + /* + * We forked in this routine, so cannot use curlwp (const) + */ + l = rump_lwproc_curlwp(); + p = l->l_proc; + + if (comm) + strlcpy(p->p_comm, comm, sizeof(p->p_comm)); + if (initfds) + rump_consdev_init(); + + return 0; +} + +/* + * Order all lwps in a process to exit. does *not* wait for them to drain. + */ +static void +hyp_lwpexit(void) +{ + struct proc *p = curproc; + uint64_t where; + struct lwp *l; + + mutex_enter(p->p_lock); + /* + * First pass: mark all lwps in the process with LW_RUMP_QEXIT + * so that they know they should exit. + */ + LIST_FOREACH(l, &p->p_lwps, l_sibling) { + if (l == curlwp) + continue; + l->l_flag |= LW_RUMP_QEXIT; + } + mutex_exit(p->p_lock); + + /* + * Next, make sure everyone on all CPUs sees our status + * update. This keeps threads inside cv_wait() and makes + * sure we don't access a stale cv pointer later when + * we wake up the threads. + */ + + where = xc_broadcast(0, (xcfunc_t)nullop, NULL, NULL); + xc_wait(where); + + /* + * Ok, all lwps are either: + * 1) not in the cv code + * 2) sleeping on l->l_private + * 3) sleeping on p->p_waitcv + * + * Either way, l_private is stable until we set PS_RUMP_LWPEXIT + * in p->p_sflag. + */ + + mutex_enter(p->p_lock); + LIST_FOREACH(l, &p->p_lwps, l_sibling) { + if (l->l_private) + cv_broadcast(l->l_private); + } + p->p_sflag |= PS_RUMP_LWPEXIT; + cv_broadcast(&p->p_waitcv); + mutex_exit(p->p_lock); +} + +/* + * Notify process that all threads have been drained and exec is complete. + */ +static void +hyp_execnotify(const char *comm) +{ + struct proc *p = curproc; + + fd_closeexec(); + mutex_enter(p->p_lock); + KASSERT(p->p_nlwps == 1 && p->p_sflag & PS_RUMP_LWPEXIT); + p->p_sflag &= ~PS_RUMP_LWPEXIT; + mutex_exit(p->p_lock); + strlcpy(p->p_comm, comm, sizeof(p->p_comm)); +} + +/* + * Initialize interface pointers since component is present. + */ +RUMP_COMPONENT(RUMP_COMPONENT_KERN) +{ + + rump_sysproxy_ops.rspo_copyin = rumpuser_sp_copyin; + rump_sysproxy_ops.rspo_copyinstr = rumpuser_sp_copyinstr; + rump_sysproxy_ops.rspo_copyout = rumpuser_sp_copyout; + rump_sysproxy_ops.rspo_copyoutstr = rumpuser_sp_copyoutstr; + rump_sysproxy_ops.rspo_anonmmap = rumpuser_sp_anonmmap; + rump_sysproxy_ops.rspo_raise = rumpuser_sp_raise; + rump_sysproxy_ops.rspo_fini = rumpuser_sp_fini; + + rump_sysproxy_ops.rspo_hyp_getpid = hyp_getpid; + rump_sysproxy_ops.rspo_hyp_syscall = hyp_syscall; + rump_sysproxy_ops.rspo_hyp_rfork = hyp_rfork; + rump_sysproxy_ops.rspo_hyp_lwpexit = hyp_lwpexit; + rump_sysproxy_ops.rspo_hyp_execnotify = hyp_execnotify; +} diff --git a/sys/rump/kern/lib/libsysproxy/x86 b/sys/rump/kern/lib/libsysproxy/x86 new file mode 120000 index 000000000..a11afa2e4 --- /dev/null +++ b/sys/rump/kern/lib/libsysproxy/x86 @@ -0,0 +1 @@ +/home/boricj/Documents/Projets/minix/src/sys/arch/x86/include \ No newline at end of file diff --git a/sys/rump/kern/lib/libtty/Makefile b/sys/rump/kern/lib/libtty/Makefile new file mode 100644 index 000000000..6b58d1e9a --- /dev/null +++ b/sys/rump/kern/lib/libtty/Makefile @@ -0,0 +1,22 @@ +# $NetBSD: Makefile,v 1.6 2015/08/20 11:59:16 christos Exp $ +# + +.PATH: ${.CURDIR}/../../../../kern \ + ${.CURDIR}/../../../../compat/common + +LIB= rumpkern_tty +IOCONF= TTY.ioconf +SRCS= tty.c tty_bsdpty.c tty_conf.c tty_ptm.c tty_pty.c tty_tty.c tty_subr.c + +.include + +.if !empty(RUMP_NBCOMPAT:M60) +SRCS+= tty_60.c +.endif + +SRCS+= tty_component.c + +CPPFLAGS+= -I${RUMPTOP}/librump/rumpkern -I${RUMPTOP}/librump/rumpvfs + +.include +.include diff --git a/sys/rump/kern/lib/libtty/TTY.ioconf b/sys/rump/kern/lib/libtty/TTY.ioconf new file mode 100644 index 000000000..44fb535d3 --- /dev/null +++ b/sys/rump/kern/lib/libtty/TTY.ioconf @@ -0,0 +1,7 @@ +# $NetBSD: TTY.ioconf,v 1.1 2015/08/20 11:59:16 christos Exp $ + +ioconf tty + +include "conf/files" + +pseudo-device pty diff --git a/sys/rump/kern/lib/libtty/i386 b/sys/rump/kern/lib/libtty/i386 new file mode 120000 index 000000000..1c75cf687 --- /dev/null +++ b/sys/rump/kern/lib/libtty/i386 @@ -0,0 +1 @@ +/home/boricj/Documents/Projets/minix/src/sys/arch/i386/include \ No newline at end of file diff --git a/sys/rump/kern/lib/libtty/ioconf.c b/sys/rump/kern/lib/libtty/ioconf.c new file mode 100644 index 000000000..3067e9a40 --- /dev/null +++ b/sys/rump/kern/lib/libtty/ioconf.c @@ -0,0 +1,32 @@ +#include "ioconf.h" +/* + * MACHINE GENERATED: DO NOT EDIT + * + * ioconf.c, from "/home/boricj/Documents/Projets/minix/src/sys/rump/kern/lib/libtty/TTY.ioconf" + */ + +#include +#include +#include +#include + + + +static struct cfdriver * const cfdriver_ioconf_tty[] = { + NULL +}; + + + +#define NORM FSTATE_NOTFOUND +#define STAR FSTATE_STAR + +static struct cfdata cfdata_ioconf_tty[] = { + /* driver attachment unit state loc flags pspec */ + { NULL, NULL, 0, 0, NULL, 0, NULL } +}; + + +static const struct cfattachinit cfattach_ioconf_tty[] = { + { NULL, NULL } +}; diff --git a/sys/rump/kern/lib/libtty/ioconf.h b/sys/rump/kern/lib/libtty/ioconf.h new file mode 100644 index 000000000..861041417 --- /dev/null +++ b/sys/rump/kern/lib/libtty/ioconf.h @@ -0,0 +1,4 @@ + +/* pseudo-devices */ + +/* driver structs */ diff --git a/sys/rump/kern/lib/libtty/locators.h b/sys/rump/kern/lib/libtty/locators.h new file mode 100644 index 000000000..e69de29bb diff --git a/sys/rump/kern/lib/libtty/machine b/sys/rump/kern/lib/libtty/machine new file mode 120000 index 000000000..1c75cf687 --- /dev/null +++ b/sys/rump/kern/lib/libtty/machine @@ -0,0 +1 @@ +/home/boricj/Documents/Projets/minix/src/sys/arch/i386/include \ No newline at end of file diff --git a/sys/rump/kern/lib/libtty/opt_ptm.h b/sys/rump/kern/lib/libtty/opt_ptm.h new file mode 100644 index 000000000..1a78e7d1f --- /dev/null +++ b/sys/rump/kern/lib/libtty/opt_ptm.h @@ -0,0 +1,3 @@ +/* $NetBSD: opt_ptm.h,v 1.1 2010/06/14 14:45:47 pooka Exp $ */ + +#define COMPAT_BSDPTY diff --git a/sys/rump/kern/lib/libtty/tty_component.c b/sys/rump/kern/lib/libtty/tty_component.c new file mode 100644 index 000000000..7830bc7c3 --- /dev/null +++ b/sys/rump/kern/lib/libtty/tty_component.c @@ -0,0 +1,73 @@ +/* $NetBSD: tty_component.c,v 1.2 2015/08/20 11:59:16 christos Exp $ */ + +/* + * Copyright (c) 2010 Antti Kantee. All Rights Reserved. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the above copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * + * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS + * OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED + * WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE + * DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE + * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL + * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR + * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) + * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT + * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY + * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF + * SUCH DAMAGE. + */ + +#include +__KERNEL_RCSID(0, "$NetBSD: tty_component.c,v 1.2 2015/08/20 11:59:16 christos Exp $"); + +#include +#include +#include +#include + +#include "rump_private.h" +#include "rump_vfs_private.h" + +#include "ioconf.h" + +RUMP_COMPONENT(RUMP_COMPONENT_KERN_VFS) +{ + extern const struct cdevsw ctty_cdevsw, ptc_cdevsw, pts_cdevsw; + extern const struct cdevsw ptm_cdevsw; + devmajor_t cmaj, bmaj; + + cmaj = bmaj = -1; + FLAWLESSCALL(devsw_attach("ctty", NULL, &bmaj, &ctty_cdevsw, &cmaj)); + FLAWLESSCALL(rump_vfs_makeonedevnode(S_IFCHR, "/dev/tty", cmaj, 0)); + + /* create only 10 nodes. should be enough for everyone ... */ + cmaj = bmaj = -1; + FLAWLESSCALL(devsw_attach("ptc", NULL, &bmaj, &ptc_cdevsw, &cmaj)); + FLAWLESSCALL(rump_vfs_makedevnodes(S_IFCHR, "/dev/ptyp", '0', + cmaj, 0, 9)); + + cmaj = bmaj = -1; + FLAWLESSCALL(devsw_attach("pts", NULL, &bmaj, &pts_cdevsw, &cmaj)); + FLAWLESSCALL(rump_vfs_makedevnodes(S_IFCHR, "/dev/ttyp", '0', + cmaj, 0, 9)); + + cmaj = bmaj = -1; + FLAWLESSCALL(devsw_attach("ptm", NULL, &bmaj, &ptm_cdevsw, &cmaj)); + FLAWLESSCALL(rump_vfs_makeonedevnode(S_IFCHR, "/dev/ptmx", cmaj, 0)); + FLAWLESSCALL(rump_vfs_makeonedevnode(S_IFCHR, "/dev/ptm", cmaj, 1)); + + tty_init(); + ttyldisc_init(); + + ptyattach(1); + + rump_ttycomponent = true; +} diff --git a/sys/rump/kern/lib/libtty/x86 b/sys/rump/kern/lib/libtty/x86 new file mode 120000 index 000000000..a11afa2e4 --- /dev/null +++ b/sys/rump/kern/lib/libtty/x86 @@ -0,0 +1 @@ +/home/boricj/Documents/Projets/minix/src/sys/arch/x86/include \ No newline at end of file diff --git a/sys/rump/kern/lib/libz/Makefile b/sys/rump/kern/lib/libz/Makefile new file mode 100644 index 000000000..06aedcfad --- /dev/null +++ b/sys/rump/kern/lib/libz/Makefile @@ -0,0 +1,12 @@ +# $NetBSD: Makefile,v 1.1 2010/06/21 21:43:28 pooka Exp $ +# + +# zlib.c is logically in sys/net +.PATH: ${.CURDIR}/../../../../net + +LIB= rumpkern_z + +SRCS= zlib.c + +.include +.include diff --git a/sys/rump/kern/lib/libz/i386 b/sys/rump/kern/lib/libz/i386 new file mode 120000 index 000000000..1c75cf687 --- /dev/null +++ b/sys/rump/kern/lib/libz/i386 @@ -0,0 +1 @@ +/home/boricj/Documents/Projets/minix/src/sys/arch/i386/include \ No newline at end of file diff --git a/sys/rump/kern/lib/libz/machine b/sys/rump/kern/lib/libz/machine new file mode 120000 index 000000000..1c75cf687 --- /dev/null +++ b/sys/rump/kern/lib/libz/machine @@ -0,0 +1 @@ +/home/boricj/Documents/Projets/minix/src/sys/arch/i386/include \ No newline at end of file diff --git a/sys/rump/kern/lib/libz/x86 b/sys/rump/kern/lib/libz/x86 new file mode 120000 index 000000000..a11afa2e4 --- /dev/null +++ b/sys/rump/kern/lib/libz/x86 @@ -0,0 +1 @@ +/home/boricj/Documents/Projets/minix/src/sys/arch/x86/include \ No newline at end of file diff --git a/sys/sys/ioctl_compat.h b/sys/sys/ioctl_compat.h index 4d32f14c1..2fb677210 100644 --- a/sys/sys/ioctl_compat.h +++ b/sys/sys/ioctl_compat.h @@ -36,7 +36,7 @@ * @(#)ioctl_compat.h 8.4 (Berkeley) 1/21/94 */ -#if !defined(__minix) +#if !defined(__minix) || defined(_KERNEL) #ifndef _SYS_IOCTL_COMPAT_H_ #define _SYS_IOCTL_COMPAT_H_ diff --git a/sys/sys/tty.h b/sys/sys/tty.h index fcb94d5f6..b5f06f391 100644 --- a/sys/sys/tty.h +++ b/sys/sys/tty.h @@ -317,4 +317,8 @@ int tty_try_xonxoff(struct tty *, unsigned char /*c*/); #endif /* _KERNEL */ +#if defined(__minix) +extern void ptyattach(int); +#endif + #endif /* !_SYS_TTY_H_ */