xref: /openbmc/linux/arch/arm/crypto/aes-ce-glue.c (revision 49abc0d2e19b28e90f443334fb6cd66f275713e6)
186464859SArd Biesheuvel /*
286464859SArd Biesheuvel  * aes-ce-glue.c - wrapper code for ARMv8 AES
386464859SArd Biesheuvel  *
486464859SArd Biesheuvel  * Copyright (C) 2015 Linaro Ltd <ard.biesheuvel@linaro.org>
586464859SArd Biesheuvel  *
686464859SArd Biesheuvel  * This program is free software; you can redistribute it and/or modify
786464859SArd Biesheuvel  * it under the terms of the GNU General Public License version 2 as
886464859SArd Biesheuvel  * published by the Free Software Foundation.
986464859SArd Biesheuvel  */
1086464859SArd Biesheuvel 
1186464859SArd Biesheuvel #include <asm/hwcap.h>
1286464859SArd Biesheuvel #include <asm/neon.h>
1386464859SArd Biesheuvel #include <asm/hwcap.h>
1486464859SArd Biesheuvel #include <crypto/aes.h>
1586464859SArd Biesheuvel #include <crypto/ablk_helper.h>
1686464859SArd Biesheuvel #include <crypto/algapi.h>
1786464859SArd Biesheuvel #include <linux/module.h>
18*49abc0d2SStephan Mueller #include <crypto/xts.h>
1986464859SArd Biesheuvel 
2086464859SArd Biesheuvel MODULE_DESCRIPTION("AES-ECB/CBC/CTR/XTS using ARMv8 Crypto Extensions");
2186464859SArd Biesheuvel MODULE_AUTHOR("Ard Biesheuvel <ard.biesheuvel@linaro.org>");
2286464859SArd Biesheuvel MODULE_LICENSE("GPL v2");
2386464859SArd Biesheuvel 
2486464859SArd Biesheuvel /* defined in aes-ce-core.S */
2586464859SArd Biesheuvel asmlinkage u32 ce_aes_sub(u32 input);
2686464859SArd Biesheuvel asmlinkage void ce_aes_invert(void *dst, void *src);
2786464859SArd Biesheuvel 
2886464859SArd Biesheuvel asmlinkage void ce_aes_ecb_encrypt(u8 out[], u8 const in[], u8 const rk[],
2986464859SArd Biesheuvel 				   int rounds, int blocks);
3086464859SArd Biesheuvel asmlinkage void ce_aes_ecb_decrypt(u8 out[], u8 const in[], u8 const rk[],
3186464859SArd Biesheuvel 				   int rounds, int blocks);
3286464859SArd Biesheuvel 
3386464859SArd Biesheuvel asmlinkage void ce_aes_cbc_encrypt(u8 out[], u8 const in[], u8 const rk[],
3486464859SArd Biesheuvel 				   int rounds, int blocks, u8 iv[]);
3586464859SArd Biesheuvel asmlinkage void ce_aes_cbc_decrypt(u8 out[], u8 const in[], u8 const rk[],
3686464859SArd Biesheuvel 				   int rounds, int blocks, u8 iv[]);
3786464859SArd Biesheuvel 
3886464859SArd Biesheuvel asmlinkage void ce_aes_ctr_encrypt(u8 out[], u8 const in[], u8 const rk[],
3986464859SArd Biesheuvel 				   int rounds, int blocks, u8 ctr[]);
4086464859SArd Biesheuvel 
4186464859SArd Biesheuvel asmlinkage void ce_aes_xts_encrypt(u8 out[], u8 const in[], u8 const rk1[],
4286464859SArd Biesheuvel 				   int rounds, int blocks, u8 iv[],
4386464859SArd Biesheuvel 				   u8 const rk2[], int first);
4486464859SArd Biesheuvel asmlinkage void ce_aes_xts_decrypt(u8 out[], u8 const in[], u8 const rk1[],
4586464859SArd Biesheuvel 				   int rounds, int blocks, u8 iv[],
4686464859SArd Biesheuvel 				   u8 const rk2[], int first);
4786464859SArd Biesheuvel 
4886464859SArd Biesheuvel struct aes_block {
4986464859SArd Biesheuvel 	u8 b[AES_BLOCK_SIZE];
5086464859SArd Biesheuvel };
5186464859SArd Biesheuvel 
5286464859SArd Biesheuvel static int num_rounds(struct crypto_aes_ctx *ctx)
5386464859SArd Biesheuvel {
5486464859SArd Biesheuvel 	/*
5586464859SArd Biesheuvel 	 * # of rounds specified by AES:
5686464859SArd Biesheuvel 	 * 128 bit key		10 rounds
5786464859SArd Biesheuvel 	 * 192 bit key		12 rounds
5886464859SArd Biesheuvel 	 * 256 bit key		14 rounds
5986464859SArd Biesheuvel 	 * => n byte key	=> 6 + (n/4) rounds
6086464859SArd Biesheuvel 	 */
6186464859SArd Biesheuvel 	return 6 + ctx->key_length / 4;
6286464859SArd Biesheuvel }
6386464859SArd Biesheuvel 
6486464859SArd Biesheuvel static int ce_aes_expandkey(struct crypto_aes_ctx *ctx, const u8 *in_key,
6586464859SArd Biesheuvel 			    unsigned int key_len)
6686464859SArd Biesheuvel {
6786464859SArd Biesheuvel 	/*
6886464859SArd Biesheuvel 	 * The AES key schedule round constants
6986464859SArd Biesheuvel 	 */
7086464859SArd Biesheuvel 	static u8 const rcon[] = {
7186464859SArd Biesheuvel 		0x01, 0x02, 0x04, 0x08, 0x10, 0x20, 0x40, 0x80, 0x1b, 0x36,
7286464859SArd Biesheuvel 	};
7386464859SArd Biesheuvel 
7486464859SArd Biesheuvel 	u32 kwords = key_len / sizeof(u32);
7586464859SArd Biesheuvel 	struct aes_block *key_enc, *key_dec;
7686464859SArd Biesheuvel 	int i, j;
7786464859SArd Biesheuvel 
7886464859SArd Biesheuvel 	if (key_len != AES_KEYSIZE_128 &&
7986464859SArd Biesheuvel 	    key_len != AES_KEYSIZE_192 &&
8086464859SArd Biesheuvel 	    key_len != AES_KEYSIZE_256)
8186464859SArd Biesheuvel 		return -EINVAL;
8286464859SArd Biesheuvel 
8386464859SArd Biesheuvel 	memcpy(ctx->key_enc, in_key, key_len);
8486464859SArd Biesheuvel 	ctx->key_length = key_len;
8586464859SArd Biesheuvel 
8686464859SArd Biesheuvel 	kernel_neon_begin();
8786464859SArd Biesheuvel 	for (i = 0; i < sizeof(rcon); i++) {
8886464859SArd Biesheuvel 		u32 *rki = ctx->key_enc + (i * kwords);
8986464859SArd Biesheuvel 		u32 *rko = rki + kwords;
9086464859SArd Biesheuvel 
9186464859SArd Biesheuvel 		rko[0] = ror32(ce_aes_sub(rki[kwords - 1]), 8);
9286464859SArd Biesheuvel 		rko[0] = rko[0] ^ rki[0] ^ rcon[i];
9386464859SArd Biesheuvel 		rko[1] = rko[0] ^ rki[1];
9486464859SArd Biesheuvel 		rko[2] = rko[1] ^ rki[2];
9586464859SArd Biesheuvel 		rko[3] = rko[2] ^ rki[3];
9686464859SArd Biesheuvel 
9786464859SArd Biesheuvel 		if (key_len == AES_KEYSIZE_192) {
9886464859SArd Biesheuvel 			if (i >= 7)
9986464859SArd Biesheuvel 				break;
10086464859SArd Biesheuvel 			rko[4] = rko[3] ^ rki[4];
10186464859SArd Biesheuvel 			rko[5] = rko[4] ^ rki[5];
10286464859SArd Biesheuvel 		} else if (key_len == AES_KEYSIZE_256) {
10386464859SArd Biesheuvel 			if (i >= 6)
10486464859SArd Biesheuvel 				break;
10586464859SArd Biesheuvel 			rko[4] = ce_aes_sub(rko[3]) ^ rki[4];
10686464859SArd Biesheuvel 			rko[5] = rko[4] ^ rki[5];
10786464859SArd Biesheuvel 			rko[6] = rko[5] ^ rki[6];
10886464859SArd Biesheuvel 			rko[7] = rko[6] ^ rki[7];
10986464859SArd Biesheuvel 		}
11086464859SArd Biesheuvel 	}
11186464859SArd Biesheuvel 
11286464859SArd Biesheuvel 	/*
11386464859SArd Biesheuvel 	 * Generate the decryption keys for the Equivalent Inverse Cipher.
11486464859SArd Biesheuvel 	 * This involves reversing the order of the round keys, and applying
11586464859SArd Biesheuvel 	 * the Inverse Mix Columns transformation on all but the first and
11686464859SArd Biesheuvel 	 * the last one.
11786464859SArd Biesheuvel 	 */
11886464859SArd Biesheuvel 	key_enc = (struct aes_block *)ctx->key_enc;
11986464859SArd Biesheuvel 	key_dec = (struct aes_block *)ctx->key_dec;
12086464859SArd Biesheuvel 	j = num_rounds(ctx);
12186464859SArd Biesheuvel 
12286464859SArd Biesheuvel 	key_dec[0] = key_enc[j];
12386464859SArd Biesheuvel 	for (i = 1, j--; j > 0; i++, j--)
12486464859SArd Biesheuvel 		ce_aes_invert(key_dec + i, key_enc + j);
12586464859SArd Biesheuvel 	key_dec[i] = key_enc[0];
12686464859SArd Biesheuvel 
12786464859SArd Biesheuvel 	kernel_neon_end();
12886464859SArd Biesheuvel 	return 0;
12986464859SArd Biesheuvel }
13086464859SArd Biesheuvel 
13186464859SArd Biesheuvel static int ce_aes_setkey(struct crypto_tfm *tfm, const u8 *in_key,
13286464859SArd Biesheuvel 			 unsigned int key_len)
13386464859SArd Biesheuvel {
13486464859SArd Biesheuvel 	struct crypto_aes_ctx *ctx = crypto_tfm_ctx(tfm);
13586464859SArd Biesheuvel 	int ret;
13686464859SArd Biesheuvel 
13786464859SArd Biesheuvel 	ret = ce_aes_expandkey(ctx, in_key, key_len);
13886464859SArd Biesheuvel 	if (!ret)
13986464859SArd Biesheuvel 		return 0;
14086464859SArd Biesheuvel 
14186464859SArd Biesheuvel 	tfm->crt_flags |= CRYPTO_TFM_RES_BAD_KEY_LEN;
14286464859SArd Biesheuvel 	return -EINVAL;
14386464859SArd Biesheuvel }
14486464859SArd Biesheuvel 
14586464859SArd Biesheuvel struct crypto_aes_xts_ctx {
14686464859SArd Biesheuvel 	struct crypto_aes_ctx key1;
14786464859SArd Biesheuvel 	struct crypto_aes_ctx __aligned(8) key2;
14886464859SArd Biesheuvel };
14986464859SArd Biesheuvel 
15086464859SArd Biesheuvel static int xts_set_key(struct crypto_tfm *tfm, const u8 *in_key,
15186464859SArd Biesheuvel 		       unsigned int key_len)
15286464859SArd Biesheuvel {
15386464859SArd Biesheuvel 	struct crypto_aes_xts_ctx *ctx = crypto_tfm_ctx(tfm);
15486464859SArd Biesheuvel 	int ret;
15586464859SArd Biesheuvel 
15628856a9eSStephan Mueller 	ret = xts_check_key(tfm, in_key, key_len);
15728856a9eSStephan Mueller 	if (ret)
15828856a9eSStephan Mueller 		return ret;
15928856a9eSStephan Mueller 
16086464859SArd Biesheuvel 	ret = ce_aes_expandkey(&ctx->key1, in_key, key_len / 2);
16186464859SArd Biesheuvel 	if (!ret)
16286464859SArd Biesheuvel 		ret = ce_aes_expandkey(&ctx->key2, &in_key[key_len / 2],
16386464859SArd Biesheuvel 				       key_len / 2);
16486464859SArd Biesheuvel 	if (!ret)
16586464859SArd Biesheuvel 		return 0;
16686464859SArd Biesheuvel 
16786464859SArd Biesheuvel 	tfm->crt_flags |= CRYPTO_TFM_RES_BAD_KEY_LEN;
16886464859SArd Biesheuvel 	return -EINVAL;
16986464859SArd Biesheuvel }
17086464859SArd Biesheuvel 
17186464859SArd Biesheuvel static int ecb_encrypt(struct blkcipher_desc *desc, struct scatterlist *dst,
17286464859SArd Biesheuvel 		       struct scatterlist *src, unsigned int nbytes)
17386464859SArd Biesheuvel {
17486464859SArd Biesheuvel 	struct crypto_aes_ctx *ctx = crypto_blkcipher_ctx(desc->tfm);
17586464859SArd Biesheuvel 	struct blkcipher_walk walk;
17686464859SArd Biesheuvel 	unsigned int blocks;
17786464859SArd Biesheuvel 	int err;
17886464859SArd Biesheuvel 
17986464859SArd Biesheuvel 	desc->flags &= ~CRYPTO_TFM_REQ_MAY_SLEEP;
18086464859SArd Biesheuvel 	blkcipher_walk_init(&walk, dst, src, nbytes);
18186464859SArd Biesheuvel 	err = blkcipher_walk_virt(desc, &walk);
18286464859SArd Biesheuvel 
18386464859SArd Biesheuvel 	kernel_neon_begin();
18486464859SArd Biesheuvel 	while ((blocks = (walk.nbytes / AES_BLOCK_SIZE))) {
18586464859SArd Biesheuvel 		ce_aes_ecb_encrypt(walk.dst.virt.addr, walk.src.virt.addr,
18686464859SArd Biesheuvel 				   (u8 *)ctx->key_enc, num_rounds(ctx), blocks);
18786464859SArd Biesheuvel 		err = blkcipher_walk_done(desc, &walk,
18886464859SArd Biesheuvel 					  walk.nbytes % AES_BLOCK_SIZE);
18986464859SArd Biesheuvel 	}
19086464859SArd Biesheuvel 	kernel_neon_end();
19186464859SArd Biesheuvel 	return err;
19286464859SArd Biesheuvel }
19386464859SArd Biesheuvel 
19486464859SArd Biesheuvel static int ecb_decrypt(struct blkcipher_desc *desc, struct scatterlist *dst,
19586464859SArd Biesheuvel 		       struct scatterlist *src, unsigned int nbytes)
19686464859SArd Biesheuvel {
19786464859SArd Biesheuvel 	struct crypto_aes_ctx *ctx = crypto_blkcipher_ctx(desc->tfm);
19886464859SArd Biesheuvel 	struct blkcipher_walk walk;
19986464859SArd Biesheuvel 	unsigned int blocks;
20086464859SArd Biesheuvel 	int err;
20186464859SArd Biesheuvel 
20286464859SArd Biesheuvel 	desc->flags &= ~CRYPTO_TFM_REQ_MAY_SLEEP;
20386464859SArd Biesheuvel 	blkcipher_walk_init(&walk, dst, src, nbytes);
20486464859SArd Biesheuvel 	err = blkcipher_walk_virt(desc, &walk);
20586464859SArd Biesheuvel 
20686464859SArd Biesheuvel 	kernel_neon_begin();
20786464859SArd Biesheuvel 	while ((blocks = (walk.nbytes / AES_BLOCK_SIZE))) {
20886464859SArd Biesheuvel 		ce_aes_ecb_decrypt(walk.dst.virt.addr, walk.src.virt.addr,
20986464859SArd Biesheuvel 				   (u8 *)ctx->key_dec, num_rounds(ctx), blocks);
21086464859SArd Biesheuvel 		err = blkcipher_walk_done(desc, &walk,
21186464859SArd Biesheuvel 					  walk.nbytes % AES_BLOCK_SIZE);
21286464859SArd Biesheuvel 	}
21386464859SArd Biesheuvel 	kernel_neon_end();
21486464859SArd Biesheuvel 	return err;
21586464859SArd Biesheuvel }
21686464859SArd Biesheuvel 
21786464859SArd Biesheuvel static int cbc_encrypt(struct blkcipher_desc *desc, struct scatterlist *dst,
21886464859SArd Biesheuvel 		       struct scatterlist *src, unsigned int nbytes)
21986464859SArd Biesheuvel {
22086464859SArd Biesheuvel 	struct crypto_aes_ctx *ctx = crypto_blkcipher_ctx(desc->tfm);
22186464859SArd Biesheuvel 	struct blkcipher_walk walk;
22286464859SArd Biesheuvel 	unsigned int blocks;
22386464859SArd Biesheuvel 	int err;
22486464859SArd Biesheuvel 
22586464859SArd Biesheuvel 	desc->flags &= ~CRYPTO_TFM_REQ_MAY_SLEEP;
22686464859SArd Biesheuvel 	blkcipher_walk_init(&walk, dst, src, nbytes);
22786464859SArd Biesheuvel 	err = blkcipher_walk_virt(desc, &walk);
22886464859SArd Biesheuvel 
22986464859SArd Biesheuvel 	kernel_neon_begin();
23086464859SArd Biesheuvel 	while ((blocks = (walk.nbytes / AES_BLOCK_SIZE))) {
23186464859SArd Biesheuvel 		ce_aes_cbc_encrypt(walk.dst.virt.addr, walk.src.virt.addr,
23286464859SArd Biesheuvel 				   (u8 *)ctx->key_enc, num_rounds(ctx), blocks,
23386464859SArd Biesheuvel 				   walk.iv);
23486464859SArd Biesheuvel 		err = blkcipher_walk_done(desc, &walk,
23586464859SArd Biesheuvel 					  walk.nbytes % AES_BLOCK_SIZE);
23686464859SArd Biesheuvel 	}
23786464859SArd Biesheuvel 	kernel_neon_end();
23886464859SArd Biesheuvel 	return err;
23986464859SArd Biesheuvel }
24086464859SArd Biesheuvel 
24186464859SArd Biesheuvel static int cbc_decrypt(struct blkcipher_desc *desc, struct scatterlist *dst,
24286464859SArd Biesheuvel 		       struct scatterlist *src, unsigned int nbytes)
24386464859SArd Biesheuvel {
24486464859SArd Biesheuvel 	struct crypto_aes_ctx *ctx = crypto_blkcipher_ctx(desc->tfm);
24586464859SArd Biesheuvel 	struct blkcipher_walk walk;
24686464859SArd Biesheuvel 	unsigned int blocks;
24786464859SArd Biesheuvel 	int err;
24886464859SArd Biesheuvel 
24986464859SArd Biesheuvel 	desc->flags &= ~CRYPTO_TFM_REQ_MAY_SLEEP;
25086464859SArd Biesheuvel 	blkcipher_walk_init(&walk, dst, src, nbytes);
25186464859SArd Biesheuvel 	err = blkcipher_walk_virt(desc, &walk);
25286464859SArd Biesheuvel 
25386464859SArd Biesheuvel 	kernel_neon_begin();
25486464859SArd Biesheuvel 	while ((blocks = (walk.nbytes / AES_BLOCK_SIZE))) {
25586464859SArd Biesheuvel 		ce_aes_cbc_decrypt(walk.dst.virt.addr, walk.src.virt.addr,
25686464859SArd Biesheuvel 				   (u8 *)ctx->key_dec, num_rounds(ctx), blocks,
25786464859SArd Biesheuvel 				   walk.iv);
25886464859SArd Biesheuvel 		err = blkcipher_walk_done(desc, &walk,
25986464859SArd Biesheuvel 					  walk.nbytes % AES_BLOCK_SIZE);
26086464859SArd Biesheuvel 	}
26186464859SArd Biesheuvel 	kernel_neon_end();
26286464859SArd Biesheuvel 	return err;
26386464859SArd Biesheuvel }
26486464859SArd Biesheuvel 
26586464859SArd Biesheuvel static int ctr_encrypt(struct blkcipher_desc *desc, struct scatterlist *dst,
26686464859SArd Biesheuvel 		       struct scatterlist *src, unsigned int nbytes)
26786464859SArd Biesheuvel {
26886464859SArd Biesheuvel 	struct crypto_aes_ctx *ctx = crypto_blkcipher_ctx(desc->tfm);
26986464859SArd Biesheuvel 	struct blkcipher_walk walk;
27086464859SArd Biesheuvel 	int err, blocks;
27186464859SArd Biesheuvel 
27286464859SArd Biesheuvel 	desc->flags &= ~CRYPTO_TFM_REQ_MAY_SLEEP;
27386464859SArd Biesheuvel 	blkcipher_walk_init(&walk, dst, src, nbytes);
27486464859SArd Biesheuvel 	err = blkcipher_walk_virt_block(desc, &walk, AES_BLOCK_SIZE);
27586464859SArd Biesheuvel 
27686464859SArd Biesheuvel 	kernel_neon_begin();
27786464859SArd Biesheuvel 	while ((blocks = (walk.nbytes / AES_BLOCK_SIZE))) {
27886464859SArd Biesheuvel 		ce_aes_ctr_encrypt(walk.dst.virt.addr, walk.src.virt.addr,
27986464859SArd Biesheuvel 				   (u8 *)ctx->key_enc, num_rounds(ctx), blocks,
28086464859SArd Biesheuvel 				   walk.iv);
28186464859SArd Biesheuvel 		nbytes -= blocks * AES_BLOCK_SIZE;
28286464859SArd Biesheuvel 		if (nbytes && nbytes == walk.nbytes % AES_BLOCK_SIZE)
28386464859SArd Biesheuvel 			break;
28486464859SArd Biesheuvel 		err = blkcipher_walk_done(desc, &walk,
28586464859SArd Biesheuvel 					  walk.nbytes % AES_BLOCK_SIZE);
28686464859SArd Biesheuvel 	}
28786464859SArd Biesheuvel 	if (nbytes) {
28886464859SArd Biesheuvel 		u8 *tdst = walk.dst.virt.addr + blocks * AES_BLOCK_SIZE;
28986464859SArd Biesheuvel 		u8 *tsrc = walk.src.virt.addr + blocks * AES_BLOCK_SIZE;
29086464859SArd Biesheuvel 		u8 __aligned(8) tail[AES_BLOCK_SIZE];
29186464859SArd Biesheuvel 
29286464859SArd Biesheuvel 		/*
29386464859SArd Biesheuvel 		 * Minimum alignment is 8 bytes, so if nbytes is <= 8, we need
29486464859SArd Biesheuvel 		 * to tell aes_ctr_encrypt() to only read half a block.
29586464859SArd Biesheuvel 		 */
29686464859SArd Biesheuvel 		blocks = (nbytes <= 8) ? -1 : 1;
29786464859SArd Biesheuvel 
29886464859SArd Biesheuvel 		ce_aes_ctr_encrypt(tail, tsrc, (u8 *)ctx->key_enc,
29986464859SArd Biesheuvel 				   num_rounds(ctx), blocks, walk.iv);
30086464859SArd Biesheuvel 		memcpy(tdst, tail, nbytes);
30186464859SArd Biesheuvel 		err = blkcipher_walk_done(desc, &walk, 0);
30286464859SArd Biesheuvel 	}
30386464859SArd Biesheuvel 	kernel_neon_end();
30486464859SArd Biesheuvel 
30586464859SArd Biesheuvel 	return err;
30686464859SArd Biesheuvel }
30786464859SArd Biesheuvel 
30886464859SArd Biesheuvel static int xts_encrypt(struct blkcipher_desc *desc, struct scatterlist *dst,
30986464859SArd Biesheuvel 		       struct scatterlist *src, unsigned int nbytes)
31086464859SArd Biesheuvel {
31186464859SArd Biesheuvel 	struct crypto_aes_xts_ctx *ctx = crypto_blkcipher_ctx(desc->tfm);
31286464859SArd Biesheuvel 	int err, first, rounds = num_rounds(&ctx->key1);
31386464859SArd Biesheuvel 	struct blkcipher_walk walk;
31486464859SArd Biesheuvel 	unsigned int blocks;
31586464859SArd Biesheuvel 
31686464859SArd Biesheuvel 	desc->flags &= ~CRYPTO_TFM_REQ_MAY_SLEEP;
31786464859SArd Biesheuvel 	blkcipher_walk_init(&walk, dst, src, nbytes);
31886464859SArd Biesheuvel 	err = blkcipher_walk_virt(desc, &walk);
31986464859SArd Biesheuvel 
32086464859SArd Biesheuvel 	kernel_neon_begin();
32186464859SArd Biesheuvel 	for (first = 1; (blocks = (walk.nbytes / AES_BLOCK_SIZE)); first = 0) {
32286464859SArd Biesheuvel 		ce_aes_xts_encrypt(walk.dst.virt.addr, walk.src.virt.addr,
32386464859SArd Biesheuvel 				   (u8 *)ctx->key1.key_enc, rounds, blocks,
32486464859SArd Biesheuvel 				   walk.iv, (u8 *)ctx->key2.key_enc, first);
32586464859SArd Biesheuvel 		err = blkcipher_walk_done(desc, &walk,
32686464859SArd Biesheuvel 					  walk.nbytes % AES_BLOCK_SIZE);
32786464859SArd Biesheuvel 	}
32886464859SArd Biesheuvel 	kernel_neon_end();
32986464859SArd Biesheuvel 
33086464859SArd Biesheuvel 	return err;
33186464859SArd Biesheuvel }
33286464859SArd Biesheuvel 
33386464859SArd Biesheuvel static int xts_decrypt(struct blkcipher_desc *desc, struct scatterlist *dst,
33486464859SArd Biesheuvel 		       struct scatterlist *src, unsigned int nbytes)
33586464859SArd Biesheuvel {
33686464859SArd Biesheuvel 	struct crypto_aes_xts_ctx *ctx = crypto_blkcipher_ctx(desc->tfm);
33786464859SArd Biesheuvel 	int err, first, rounds = num_rounds(&ctx->key1);
33886464859SArd Biesheuvel 	struct blkcipher_walk walk;
33986464859SArd Biesheuvel 	unsigned int blocks;
34086464859SArd Biesheuvel 
34186464859SArd Biesheuvel 	desc->flags &= ~CRYPTO_TFM_REQ_MAY_SLEEP;
34286464859SArd Biesheuvel 	blkcipher_walk_init(&walk, dst, src, nbytes);
34386464859SArd Biesheuvel 	err = blkcipher_walk_virt(desc, &walk);
34486464859SArd Biesheuvel 
34586464859SArd Biesheuvel 	kernel_neon_begin();
34686464859SArd Biesheuvel 	for (first = 1; (blocks = (walk.nbytes / AES_BLOCK_SIZE)); first = 0) {
34786464859SArd Biesheuvel 		ce_aes_xts_decrypt(walk.dst.virt.addr, walk.src.virt.addr,
34886464859SArd Biesheuvel 				   (u8 *)ctx->key1.key_dec, rounds, blocks,
34986464859SArd Biesheuvel 				   walk.iv, (u8 *)ctx->key2.key_enc, first);
35086464859SArd Biesheuvel 		err = blkcipher_walk_done(desc, &walk,
35186464859SArd Biesheuvel 					  walk.nbytes % AES_BLOCK_SIZE);
35286464859SArd Biesheuvel 	}
35386464859SArd Biesheuvel 	kernel_neon_end();
35486464859SArd Biesheuvel 
35586464859SArd Biesheuvel 	return err;
35686464859SArd Biesheuvel }
35786464859SArd Biesheuvel 
35886464859SArd Biesheuvel static struct crypto_alg aes_algs[] = { {
35986464859SArd Biesheuvel 	.cra_name		= "__ecb-aes-ce",
36086464859SArd Biesheuvel 	.cra_driver_name	= "__driver-ecb-aes-ce",
36186464859SArd Biesheuvel 	.cra_priority		= 0,
36294a7e5e8SStephan Mueller 	.cra_flags		= CRYPTO_ALG_TYPE_BLKCIPHER |
36394a7e5e8SStephan Mueller 				  CRYPTO_ALG_INTERNAL,
36486464859SArd Biesheuvel 	.cra_blocksize		= AES_BLOCK_SIZE,
36586464859SArd Biesheuvel 	.cra_ctxsize		= sizeof(struct crypto_aes_ctx),
36686464859SArd Biesheuvel 	.cra_alignmask		= 7,
36786464859SArd Biesheuvel 	.cra_type		= &crypto_blkcipher_type,
36886464859SArd Biesheuvel 	.cra_module		= THIS_MODULE,
36986464859SArd Biesheuvel 	.cra_blkcipher = {
37086464859SArd Biesheuvel 		.min_keysize	= AES_MIN_KEY_SIZE,
37186464859SArd Biesheuvel 		.max_keysize	= AES_MAX_KEY_SIZE,
37286464859SArd Biesheuvel 		.ivsize		= AES_BLOCK_SIZE,
37386464859SArd Biesheuvel 		.setkey		= ce_aes_setkey,
37486464859SArd Biesheuvel 		.encrypt	= ecb_encrypt,
37586464859SArd Biesheuvel 		.decrypt	= ecb_decrypt,
37686464859SArd Biesheuvel 	},
37786464859SArd Biesheuvel }, {
37886464859SArd Biesheuvel 	.cra_name		= "__cbc-aes-ce",
37986464859SArd Biesheuvel 	.cra_driver_name	= "__driver-cbc-aes-ce",
38086464859SArd Biesheuvel 	.cra_priority		= 0,
38194a7e5e8SStephan Mueller 	.cra_flags		= CRYPTO_ALG_TYPE_BLKCIPHER |
38294a7e5e8SStephan Mueller 				  CRYPTO_ALG_INTERNAL,
38386464859SArd Biesheuvel 	.cra_blocksize		= AES_BLOCK_SIZE,
38486464859SArd Biesheuvel 	.cra_ctxsize		= sizeof(struct crypto_aes_ctx),
38586464859SArd Biesheuvel 	.cra_alignmask		= 7,
38686464859SArd Biesheuvel 	.cra_type		= &crypto_blkcipher_type,
38786464859SArd Biesheuvel 	.cra_module		= THIS_MODULE,
38886464859SArd Biesheuvel 	.cra_blkcipher = {
38986464859SArd Biesheuvel 		.min_keysize	= AES_MIN_KEY_SIZE,
39086464859SArd Biesheuvel 		.max_keysize	= AES_MAX_KEY_SIZE,
39186464859SArd Biesheuvel 		.ivsize		= AES_BLOCK_SIZE,
39286464859SArd Biesheuvel 		.setkey		= ce_aes_setkey,
39386464859SArd Biesheuvel 		.encrypt	= cbc_encrypt,
39486464859SArd Biesheuvel 		.decrypt	= cbc_decrypt,
39586464859SArd Biesheuvel 	},
39686464859SArd Biesheuvel }, {
39786464859SArd Biesheuvel 	.cra_name		= "__ctr-aes-ce",
39886464859SArd Biesheuvel 	.cra_driver_name	= "__driver-ctr-aes-ce",
39986464859SArd Biesheuvel 	.cra_priority		= 0,
40094a7e5e8SStephan Mueller 	.cra_flags		= CRYPTO_ALG_TYPE_BLKCIPHER |
40194a7e5e8SStephan Mueller 				  CRYPTO_ALG_INTERNAL,
40286464859SArd Biesheuvel 	.cra_blocksize		= 1,
40386464859SArd Biesheuvel 	.cra_ctxsize		= sizeof(struct crypto_aes_ctx),
40486464859SArd Biesheuvel 	.cra_alignmask		= 7,
40586464859SArd Biesheuvel 	.cra_type		= &crypto_blkcipher_type,
40686464859SArd Biesheuvel 	.cra_module		= THIS_MODULE,
40786464859SArd Biesheuvel 	.cra_blkcipher = {
40886464859SArd Biesheuvel 		.min_keysize	= AES_MIN_KEY_SIZE,
40986464859SArd Biesheuvel 		.max_keysize	= AES_MAX_KEY_SIZE,
41086464859SArd Biesheuvel 		.ivsize		= AES_BLOCK_SIZE,
41186464859SArd Biesheuvel 		.setkey		= ce_aes_setkey,
41286464859SArd Biesheuvel 		.encrypt	= ctr_encrypt,
41386464859SArd Biesheuvel 		.decrypt	= ctr_encrypt,
41486464859SArd Biesheuvel 	},
41586464859SArd Biesheuvel }, {
41686464859SArd Biesheuvel 	.cra_name		= "__xts-aes-ce",
41786464859SArd Biesheuvel 	.cra_driver_name	= "__driver-xts-aes-ce",
41886464859SArd Biesheuvel 	.cra_priority		= 0,
41994a7e5e8SStephan Mueller 	.cra_flags		= CRYPTO_ALG_TYPE_BLKCIPHER |
42094a7e5e8SStephan Mueller 				  CRYPTO_ALG_INTERNAL,
42186464859SArd Biesheuvel 	.cra_blocksize		= AES_BLOCK_SIZE,
42286464859SArd Biesheuvel 	.cra_ctxsize		= sizeof(struct crypto_aes_xts_ctx),
42386464859SArd Biesheuvel 	.cra_alignmask		= 7,
42486464859SArd Biesheuvel 	.cra_type		= &crypto_blkcipher_type,
42586464859SArd Biesheuvel 	.cra_module		= THIS_MODULE,
42686464859SArd Biesheuvel 	.cra_blkcipher = {
42786464859SArd Biesheuvel 		.min_keysize	= 2 * AES_MIN_KEY_SIZE,
42886464859SArd Biesheuvel 		.max_keysize	= 2 * AES_MAX_KEY_SIZE,
42986464859SArd Biesheuvel 		.ivsize		= AES_BLOCK_SIZE,
43086464859SArd Biesheuvel 		.setkey		= xts_set_key,
43186464859SArd Biesheuvel 		.encrypt	= xts_encrypt,
43286464859SArd Biesheuvel 		.decrypt	= xts_decrypt,
43386464859SArd Biesheuvel 	},
43486464859SArd Biesheuvel }, {
43586464859SArd Biesheuvel 	.cra_name		= "ecb(aes)",
43686464859SArd Biesheuvel 	.cra_driver_name	= "ecb-aes-ce",
43786464859SArd Biesheuvel 	.cra_priority		= 300,
43886464859SArd Biesheuvel 	.cra_flags		= CRYPTO_ALG_TYPE_ABLKCIPHER|CRYPTO_ALG_ASYNC,
43986464859SArd Biesheuvel 	.cra_blocksize		= AES_BLOCK_SIZE,
44086464859SArd Biesheuvel 	.cra_ctxsize		= sizeof(struct async_helper_ctx),
44186464859SArd Biesheuvel 	.cra_alignmask		= 7,
44286464859SArd Biesheuvel 	.cra_type		= &crypto_ablkcipher_type,
44386464859SArd Biesheuvel 	.cra_module		= THIS_MODULE,
44486464859SArd Biesheuvel 	.cra_init		= ablk_init,
44586464859SArd Biesheuvel 	.cra_exit		= ablk_exit,
44686464859SArd Biesheuvel 	.cra_ablkcipher = {
44786464859SArd Biesheuvel 		.min_keysize	= AES_MIN_KEY_SIZE,
44886464859SArd Biesheuvel 		.max_keysize	= AES_MAX_KEY_SIZE,
44986464859SArd Biesheuvel 		.ivsize		= AES_BLOCK_SIZE,
45086464859SArd Biesheuvel 		.setkey		= ablk_set_key,
45186464859SArd Biesheuvel 		.encrypt	= ablk_encrypt,
45286464859SArd Biesheuvel 		.decrypt	= ablk_decrypt,
45386464859SArd Biesheuvel 	}
45486464859SArd Biesheuvel }, {
45586464859SArd Biesheuvel 	.cra_name		= "cbc(aes)",
45686464859SArd Biesheuvel 	.cra_driver_name	= "cbc-aes-ce",
45786464859SArd Biesheuvel 	.cra_priority		= 300,
45886464859SArd Biesheuvel 	.cra_flags		= CRYPTO_ALG_TYPE_ABLKCIPHER|CRYPTO_ALG_ASYNC,
45986464859SArd Biesheuvel 	.cra_blocksize		= AES_BLOCK_SIZE,
46086464859SArd Biesheuvel 	.cra_ctxsize		= sizeof(struct async_helper_ctx),
46186464859SArd Biesheuvel 	.cra_alignmask		= 7,
46286464859SArd Biesheuvel 	.cra_type		= &crypto_ablkcipher_type,
46386464859SArd Biesheuvel 	.cra_module		= THIS_MODULE,
46486464859SArd Biesheuvel 	.cra_init		= ablk_init,
46586464859SArd Biesheuvel 	.cra_exit		= ablk_exit,
46686464859SArd Biesheuvel 	.cra_ablkcipher = {
46786464859SArd Biesheuvel 		.min_keysize	= AES_MIN_KEY_SIZE,
46886464859SArd Biesheuvel 		.max_keysize	= AES_MAX_KEY_SIZE,
46986464859SArd Biesheuvel 		.ivsize		= AES_BLOCK_SIZE,
47086464859SArd Biesheuvel 		.setkey		= ablk_set_key,
47186464859SArd Biesheuvel 		.encrypt	= ablk_encrypt,
47286464859SArd Biesheuvel 		.decrypt	= ablk_decrypt,
47386464859SArd Biesheuvel 	}
47486464859SArd Biesheuvel }, {
47586464859SArd Biesheuvel 	.cra_name		= "ctr(aes)",
47686464859SArd Biesheuvel 	.cra_driver_name	= "ctr-aes-ce",
47786464859SArd Biesheuvel 	.cra_priority		= 300,
47886464859SArd Biesheuvel 	.cra_flags		= CRYPTO_ALG_TYPE_ABLKCIPHER|CRYPTO_ALG_ASYNC,
47986464859SArd Biesheuvel 	.cra_blocksize		= 1,
48086464859SArd Biesheuvel 	.cra_ctxsize		= sizeof(struct async_helper_ctx),
48186464859SArd Biesheuvel 	.cra_alignmask		= 7,
48286464859SArd Biesheuvel 	.cra_type		= &crypto_ablkcipher_type,
48386464859SArd Biesheuvel 	.cra_module		= THIS_MODULE,
48486464859SArd Biesheuvel 	.cra_init		= ablk_init,
48586464859SArd Biesheuvel 	.cra_exit		= ablk_exit,
48686464859SArd Biesheuvel 	.cra_ablkcipher = {
48786464859SArd Biesheuvel 		.min_keysize	= AES_MIN_KEY_SIZE,
48886464859SArd Biesheuvel 		.max_keysize	= AES_MAX_KEY_SIZE,
48986464859SArd Biesheuvel 		.ivsize		= AES_BLOCK_SIZE,
49086464859SArd Biesheuvel 		.setkey		= ablk_set_key,
49186464859SArd Biesheuvel 		.encrypt	= ablk_encrypt,
49286464859SArd Biesheuvel 		.decrypt	= ablk_decrypt,
49386464859SArd Biesheuvel 	}
49486464859SArd Biesheuvel }, {
49586464859SArd Biesheuvel 	.cra_name		= "xts(aes)",
49686464859SArd Biesheuvel 	.cra_driver_name	= "xts-aes-ce",
49786464859SArd Biesheuvel 	.cra_priority		= 300,
49886464859SArd Biesheuvel 	.cra_flags		= CRYPTO_ALG_TYPE_ABLKCIPHER|CRYPTO_ALG_ASYNC,
49986464859SArd Biesheuvel 	.cra_blocksize		= AES_BLOCK_SIZE,
50086464859SArd Biesheuvel 	.cra_ctxsize		= sizeof(struct async_helper_ctx),
50186464859SArd Biesheuvel 	.cra_alignmask		= 7,
50286464859SArd Biesheuvel 	.cra_type		= &crypto_ablkcipher_type,
50386464859SArd Biesheuvel 	.cra_module		= THIS_MODULE,
50486464859SArd Biesheuvel 	.cra_init		= ablk_init,
50586464859SArd Biesheuvel 	.cra_exit		= ablk_exit,
50686464859SArd Biesheuvel 	.cra_ablkcipher = {
50786464859SArd Biesheuvel 		.min_keysize	= 2 * AES_MIN_KEY_SIZE,
50886464859SArd Biesheuvel 		.max_keysize	= 2 * AES_MAX_KEY_SIZE,
50986464859SArd Biesheuvel 		.ivsize		= AES_BLOCK_SIZE,
51086464859SArd Biesheuvel 		.setkey		= ablk_set_key,
51186464859SArd Biesheuvel 		.encrypt	= ablk_encrypt,
51286464859SArd Biesheuvel 		.decrypt	= ablk_decrypt,
51386464859SArd Biesheuvel 	}
51486464859SArd Biesheuvel } };
51586464859SArd Biesheuvel 
51686464859SArd Biesheuvel static int __init aes_init(void)
51786464859SArd Biesheuvel {
51886464859SArd Biesheuvel 	if (!(elf_hwcap2 & HWCAP2_AES))
51986464859SArd Biesheuvel 		return -ENODEV;
52086464859SArd Biesheuvel 	return crypto_register_algs(aes_algs, ARRAY_SIZE(aes_algs));
52186464859SArd Biesheuvel }
52286464859SArd Biesheuvel 
52386464859SArd Biesheuvel static void __exit aes_exit(void)
52486464859SArd Biesheuvel {
52586464859SArd Biesheuvel 	crypto_unregister_algs(aes_algs, ARRAY_SIZE(aes_algs));
52686464859SArd Biesheuvel }
52786464859SArd Biesheuvel 
52886464859SArd Biesheuvel module_init(aes_init);
52986464859SArd Biesheuvel module_exit(aes_exit);
530