xref: /openbmc/linux/crypto/algif_hash.c (revision 5f2cf757f9c56255470c23a2a4a5574a34edad4b)
1 // SPDX-License-Identifier: GPL-2.0-or-later
2 /*
3  * algif_hash: User-space interface for hash algorithms
4  *
5  * This file provides the user-space API for hash algorithms.
6  *
7  * Copyright (c) 2010 Herbert Xu <herbert@gondor.apana.org.au>
8  */
9 
10 #include <crypto/hash.h>
11 #include <crypto/if_alg.h>
12 #include <linux/init.h>
13 #include <linux/kernel.h>
14 #include <linux/mm.h>
15 #include <linux/module.h>
16 #include <linux/net.h>
17 #include <net/sock.h>
18 
19 struct hash_ctx {
20 	struct af_alg_sgl sgl;
21 
22 	u8 *result;
23 
24 	struct crypto_wait wait;
25 
26 	unsigned int len;
27 	bool more;
28 
29 	struct ahash_request req;
30 };
31 
32 static int hash_alloc_result(struct sock *sk, struct hash_ctx *ctx)
33 {
34 	unsigned ds;
35 
36 	if (ctx->result)
37 		return 0;
38 
39 	ds = crypto_ahash_digestsize(crypto_ahash_reqtfm(&ctx->req));
40 
41 	ctx->result = sock_kmalloc(sk, ds, GFP_KERNEL);
42 	if (!ctx->result)
43 		return -ENOMEM;
44 
45 	memset(ctx->result, 0, ds);
46 
47 	return 0;
48 }
49 
50 static void hash_free_result(struct sock *sk, struct hash_ctx *ctx)
51 {
52 	unsigned ds;
53 
54 	if (!ctx->result)
55 		return;
56 
57 	ds = crypto_ahash_digestsize(crypto_ahash_reqtfm(&ctx->req));
58 
59 	sock_kzfree_s(sk, ctx->result, ds);
60 	ctx->result = NULL;
61 }
62 
63 static int hash_sendmsg(struct socket *sock, struct msghdr *msg,
64 			size_t ignored)
65 {
66 	struct sock *sk = sock->sk;
67 	struct alg_sock *ask = alg_sk(sk);
68 	struct hash_ctx *ctx = ask->private;
69 	ssize_t copied = 0;
70 	size_t len, max_pages, npages;
71 	bool continuing = ctx->more, need_init = false;
72 	int err;
73 
74 	max_pages = min_t(size_t, ALG_MAX_PAGES,
75 			  DIV_ROUND_UP(sk->sk_sndbuf, PAGE_SIZE));
76 
77 	lock_sock(sk);
78 	if (!continuing) {
79 		if ((msg->msg_flags & MSG_MORE))
80 			hash_free_result(sk, ctx);
81 		need_init = true;
82 	}
83 
84 	ctx->more = false;
85 
86 	while (msg_data_left(msg)) {
87 		ctx->sgl.sgt.sgl = ctx->sgl.sgl;
88 		ctx->sgl.sgt.nents = 0;
89 		ctx->sgl.sgt.orig_nents = 0;
90 
91 		err = -EIO;
92 		npages = iov_iter_npages(&msg->msg_iter, max_pages);
93 		if (npages == 0)
94 			goto unlock_free;
95 
96 		if (npages > ARRAY_SIZE(ctx->sgl.sgl)) {
97 			err = -ENOMEM;
98 			ctx->sgl.sgt.sgl =
99 				kvmalloc(array_size(npages,
100 						    sizeof(*ctx->sgl.sgt.sgl)),
101 					 GFP_KERNEL);
102 			if (!ctx->sgl.sgt.sgl)
103 				goto unlock_free;
104 		}
105 		sg_init_table(ctx->sgl.sgl, npages);
106 
107 		ctx->sgl.need_unpin = iov_iter_extract_will_pin(&msg->msg_iter);
108 
109 		err = extract_iter_to_sg(&msg->msg_iter, LONG_MAX,
110 					 &ctx->sgl.sgt, npages, 0);
111 		if (err < 0)
112 			goto unlock_free;
113 		len = err;
114 		sg_mark_end(ctx->sgl.sgt.sgl + ctx->sgl.sgt.nents - 1);
115 
116 		if (!msg_data_left(msg)) {
117 			err = hash_alloc_result(sk, ctx);
118 			if (err)
119 				goto unlock_free;
120 		}
121 
122 		ahash_request_set_crypt(&ctx->req, ctx->sgl.sgt.sgl,
123 					ctx->result, len);
124 
125 		if (!msg_data_left(msg) && !continuing &&
126 		    !(msg->msg_flags & MSG_MORE)) {
127 			err = crypto_ahash_digest(&ctx->req);
128 		} else {
129 			if (need_init) {
130 				err = crypto_wait_req(
131 					crypto_ahash_init(&ctx->req),
132 					&ctx->wait);
133 				if (err)
134 					goto unlock_free;
135 				need_init = false;
136 			}
137 
138 			if (msg_data_left(msg) || (msg->msg_flags & MSG_MORE))
139 				err = crypto_ahash_update(&ctx->req);
140 			else
141 				err = crypto_ahash_finup(&ctx->req);
142 			continuing = true;
143 		}
144 
145 		err = crypto_wait_req(err, &ctx->wait);
146 		if (err)
147 			goto unlock_free;
148 
149 		copied += len;
150 		af_alg_free_sg(&ctx->sgl);
151 	}
152 
153 	ctx->more = msg->msg_flags & MSG_MORE;
154 	err = 0;
155 unlock:
156 	release_sock(sk);
157 	return copied ?: err;
158 
159 unlock_free:
160 	af_alg_free_sg(&ctx->sgl);
161 	goto unlock;
162 }
163 
164 static int hash_recvmsg(struct socket *sock, struct msghdr *msg, size_t len,
165 			int flags)
166 {
167 	struct sock *sk = sock->sk;
168 	struct alg_sock *ask = alg_sk(sk);
169 	struct hash_ctx *ctx = ask->private;
170 	unsigned ds = crypto_ahash_digestsize(crypto_ahash_reqtfm(&ctx->req));
171 	bool result;
172 	int err;
173 
174 	if (len > ds)
175 		len = ds;
176 	else if (len < ds)
177 		msg->msg_flags |= MSG_TRUNC;
178 
179 	lock_sock(sk);
180 	result = ctx->result;
181 	err = hash_alloc_result(sk, ctx);
182 	if (err)
183 		goto unlock;
184 
185 	ahash_request_set_crypt(&ctx->req, NULL, ctx->result, 0);
186 
187 	if (!result && !ctx->more) {
188 		err = crypto_wait_req(crypto_ahash_init(&ctx->req),
189 				      &ctx->wait);
190 		if (err)
191 			goto unlock;
192 	}
193 
194 	if (!result || ctx->more) {
195 		ctx->more = false;
196 		err = crypto_wait_req(crypto_ahash_final(&ctx->req),
197 				      &ctx->wait);
198 		if (err)
199 			goto unlock;
200 	}
201 
202 	err = memcpy_to_msg(msg, ctx->result, len);
203 
204 unlock:
205 	hash_free_result(sk, ctx);
206 	release_sock(sk);
207 
208 	return err ?: len;
209 }
210 
211 static int hash_accept(struct socket *sock, struct socket *newsock, int flags,
212 		       bool kern)
213 {
214 	struct sock *sk = sock->sk;
215 	struct alg_sock *ask = alg_sk(sk);
216 	struct hash_ctx *ctx = ask->private;
217 	struct ahash_request *req = &ctx->req;
218 	struct crypto_ahash *tfm;
219 	struct sock *sk2;
220 	struct alg_sock *ask2;
221 	struct hash_ctx *ctx2;
222 	char *state;
223 	bool more;
224 	int err;
225 
226 	tfm = crypto_ahash_reqtfm(req);
227 	state = kmalloc(crypto_ahash_statesize(tfm), GFP_KERNEL);
228 	err = -ENOMEM;
229 	if (!state)
230 		goto out;
231 
232 	lock_sock(sk);
233 	more = ctx->more;
234 	err = more ? crypto_ahash_export(req, state) : 0;
235 	release_sock(sk);
236 
237 	if (err)
238 		goto out_free_state;
239 
240 	err = af_alg_accept(ask->parent, newsock, kern);
241 	if (err)
242 		goto out_free_state;
243 
244 	sk2 = newsock->sk;
245 	ask2 = alg_sk(sk2);
246 	ctx2 = ask2->private;
247 	ctx2->more = more;
248 
249 	if (!more)
250 		goto out_free_state;
251 
252 	err = crypto_ahash_import(&ctx2->req, state);
253 	if (err) {
254 		sock_orphan(sk2);
255 		sock_put(sk2);
256 	}
257 
258 out_free_state:
259 	kfree_sensitive(state);
260 
261 out:
262 	return err;
263 }
264 
265 static struct proto_ops algif_hash_ops = {
266 	.family		=	PF_ALG,
267 
268 	.connect	=	sock_no_connect,
269 	.socketpair	=	sock_no_socketpair,
270 	.getname	=	sock_no_getname,
271 	.ioctl		=	sock_no_ioctl,
272 	.listen		=	sock_no_listen,
273 	.shutdown	=	sock_no_shutdown,
274 	.mmap		=	sock_no_mmap,
275 	.bind		=	sock_no_bind,
276 
277 	.release	=	af_alg_release,
278 	.sendmsg	=	hash_sendmsg,
279 	.recvmsg	=	hash_recvmsg,
280 	.accept		=	hash_accept,
281 };
282 
283 static int hash_check_key(struct socket *sock)
284 {
285 	int err = 0;
286 	struct sock *psk;
287 	struct alg_sock *pask;
288 	struct crypto_ahash *tfm;
289 	struct sock *sk = sock->sk;
290 	struct alg_sock *ask = alg_sk(sk);
291 
292 	lock_sock(sk);
293 	if (!atomic_read(&ask->nokey_refcnt))
294 		goto unlock_child;
295 
296 	psk = ask->parent;
297 	pask = alg_sk(ask->parent);
298 	tfm = pask->private;
299 
300 	err = -ENOKEY;
301 	lock_sock_nested(psk, SINGLE_DEPTH_NESTING);
302 	if (crypto_ahash_get_flags(tfm) & CRYPTO_TFM_NEED_KEY)
303 		goto unlock;
304 
305 	atomic_dec(&pask->nokey_refcnt);
306 	atomic_set(&ask->nokey_refcnt, 0);
307 
308 	err = 0;
309 
310 unlock:
311 	release_sock(psk);
312 unlock_child:
313 	release_sock(sk);
314 
315 	return err;
316 }
317 
318 static int hash_sendmsg_nokey(struct socket *sock, struct msghdr *msg,
319 			      size_t size)
320 {
321 	int err;
322 
323 	err = hash_check_key(sock);
324 	if (err)
325 		return err;
326 
327 	return hash_sendmsg(sock, msg, size);
328 }
329 
330 static int hash_recvmsg_nokey(struct socket *sock, struct msghdr *msg,
331 			      size_t ignored, int flags)
332 {
333 	int err;
334 
335 	err = hash_check_key(sock);
336 	if (err)
337 		return err;
338 
339 	return hash_recvmsg(sock, msg, ignored, flags);
340 }
341 
342 static int hash_accept_nokey(struct socket *sock, struct socket *newsock,
343 			     int flags, bool kern)
344 {
345 	int err;
346 
347 	err = hash_check_key(sock);
348 	if (err)
349 		return err;
350 
351 	return hash_accept(sock, newsock, flags, kern);
352 }
353 
354 static struct proto_ops algif_hash_ops_nokey = {
355 	.family		=	PF_ALG,
356 
357 	.connect	=	sock_no_connect,
358 	.socketpair	=	sock_no_socketpair,
359 	.getname	=	sock_no_getname,
360 	.ioctl		=	sock_no_ioctl,
361 	.listen		=	sock_no_listen,
362 	.shutdown	=	sock_no_shutdown,
363 	.mmap		=	sock_no_mmap,
364 	.bind		=	sock_no_bind,
365 
366 	.release	=	af_alg_release,
367 	.sendmsg	=	hash_sendmsg_nokey,
368 	.recvmsg	=	hash_recvmsg_nokey,
369 	.accept		=	hash_accept_nokey,
370 };
371 
372 static void *hash_bind(const char *name, u32 type, u32 mask)
373 {
374 	return crypto_alloc_ahash(name, type, mask);
375 }
376 
377 static void hash_release(void *private)
378 {
379 	crypto_free_ahash(private);
380 }
381 
382 static int hash_setkey(void *private, const u8 *key, unsigned int keylen)
383 {
384 	return crypto_ahash_setkey(private, key, keylen);
385 }
386 
387 static void hash_sock_destruct(struct sock *sk)
388 {
389 	struct alg_sock *ask = alg_sk(sk);
390 	struct hash_ctx *ctx = ask->private;
391 
392 	hash_free_result(sk, ctx);
393 	sock_kfree_s(sk, ctx, ctx->len);
394 	af_alg_release_parent(sk);
395 }
396 
397 static int hash_accept_parent_nokey(void *private, struct sock *sk)
398 {
399 	struct crypto_ahash *tfm = private;
400 	struct alg_sock *ask = alg_sk(sk);
401 	struct hash_ctx *ctx;
402 	unsigned int len = sizeof(*ctx) + crypto_ahash_reqsize(tfm);
403 
404 	ctx = sock_kmalloc(sk, len, GFP_KERNEL);
405 	if (!ctx)
406 		return -ENOMEM;
407 
408 	ctx->result = NULL;
409 	ctx->len = len;
410 	ctx->more = false;
411 	crypto_init_wait(&ctx->wait);
412 
413 	ask->private = ctx;
414 
415 	ahash_request_set_tfm(&ctx->req, tfm);
416 	ahash_request_set_callback(&ctx->req, CRYPTO_TFM_REQ_MAY_BACKLOG,
417 				   crypto_req_done, &ctx->wait);
418 
419 	sk->sk_destruct = hash_sock_destruct;
420 
421 	return 0;
422 }
423 
424 static int hash_accept_parent(void *private, struct sock *sk)
425 {
426 	struct crypto_ahash *tfm = private;
427 
428 	if (crypto_ahash_get_flags(tfm) & CRYPTO_TFM_NEED_KEY)
429 		return -ENOKEY;
430 
431 	return hash_accept_parent_nokey(private, sk);
432 }
433 
434 static const struct af_alg_type algif_type_hash = {
435 	.bind		=	hash_bind,
436 	.release	=	hash_release,
437 	.setkey		=	hash_setkey,
438 	.accept		=	hash_accept_parent,
439 	.accept_nokey	=	hash_accept_parent_nokey,
440 	.ops		=	&algif_hash_ops,
441 	.ops_nokey	=	&algif_hash_ops_nokey,
442 	.name		=	"hash",
443 	.owner		=	THIS_MODULE
444 };
445 
446 static int __init algif_hash_init(void)
447 {
448 	return af_alg_register_type(&algif_type_hash);
449 }
450 
451 static void __exit algif_hash_exit(void)
452 {
453 	int err = af_alg_unregister_type(&algif_type_hash);
454 	BUG_ON(err);
455 }
456 
457 module_init(algif_hash_init);
458 module_exit(algif_hash_exit);
459 MODULE_LICENSE("GPL");
460