xref: /netbsd-src/sys/opencrypto/ocryptodev.c (revision b943dbddef07d1ff3c35665f96083297d85658b6)
1*b943dbddSriastradh /*	$NetBSD: ocryptodev.c,v 1.17 2022/03/12 17:15:04 riastradh Exp $ */
236ea3668Sdarran /*	$FreeBSD: src/sys/opencrypto/cryptodev.c,v 1.4.2.4 2003/06/03 00:09:02 sam Exp $	*/
336ea3668Sdarran /*	$OpenBSD: cryptodev.c,v 1.53 2002/07/10 22:21:30 mickey Exp $	*/
436ea3668Sdarran 
536ea3668Sdarran /*-
636ea3668Sdarran  * Copyright (c) 2008 The NetBSD Foundation, Inc.
736ea3668Sdarran  * All rights reserved.
836ea3668Sdarran  *
936ea3668Sdarran  * This code is derived from software contributed to The NetBSD Foundation
1036ea3668Sdarran  * by Coyote Point Systems, Inc.
1136ea3668Sdarran  *
1236ea3668Sdarran  * Redistribution and use in source and binary forms, with or without
1336ea3668Sdarran  * modification, are permitted provided that the following conditions
1436ea3668Sdarran  * are met:
1536ea3668Sdarran  * 1. Redistributions of source code must retain the above copyright
1636ea3668Sdarran  *    notice, this list of conditions and the following disclaimer.
1736ea3668Sdarran  * 2. Redistributions in binary form must reproduce the above copyright
1836ea3668Sdarran  *    notice, this list of conditions and the following disclaimer in the
1936ea3668Sdarran  *    documentation and/or other materials provided with the distribution.
2036ea3668Sdarran  *
2136ea3668Sdarran  * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS
2236ea3668Sdarran  * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
2336ea3668Sdarran  * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
2436ea3668Sdarran  * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS
2536ea3668Sdarran  * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
2636ea3668Sdarran  * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
2736ea3668Sdarran  * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
2836ea3668Sdarran  * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
2936ea3668Sdarran  * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
3036ea3668Sdarran  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
3136ea3668Sdarran  * POSSIBILITY OF SUCH DAMAGE.
3236ea3668Sdarran  */
3336ea3668Sdarran 
3436ea3668Sdarran /*
3536ea3668Sdarran  * Copyright (c) 2001 Theo de Raadt
3636ea3668Sdarran  *
3736ea3668Sdarran  * Redistribution and use in source and binary forms, with or without
3836ea3668Sdarran  * modification, are permitted provided that the following conditions
3936ea3668Sdarran  * are met:
4036ea3668Sdarran  *
4136ea3668Sdarran  * 1. Redistributions of source code must retain the above copyright
4236ea3668Sdarran  *   notice, this list of conditions and the following disclaimer.
4336ea3668Sdarran  * 2. Redistributions in binary form must reproduce the above copyright
4436ea3668Sdarran  *   notice, this list of conditions and the following disclaimer in the
4536ea3668Sdarran  *   documentation and/or other materials provided with the distribution.
4636ea3668Sdarran  * 3. The name of the author may not be used to endorse or promote products
4736ea3668Sdarran  *   derived from this software without specific prior written permission.
4836ea3668Sdarran  *
4936ea3668Sdarran  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
5036ea3668Sdarran  * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
5136ea3668Sdarran  * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
5236ea3668Sdarran  * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
5336ea3668Sdarran  * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
5436ea3668Sdarran  * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
5536ea3668Sdarran  * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
5636ea3668Sdarran  * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
5736ea3668Sdarran  * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
5836ea3668Sdarran  * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
5936ea3668Sdarran  *
6036ea3668Sdarran  * Effort sponsored in part by the Defense Advanced Research Projects
6136ea3668Sdarran  * Agency (DARPA) and Air Force Research Laboratory, Air Force
6236ea3668Sdarran  * Materiel Command, USAF, under agreement number F30602-01-2-0537.
6336ea3668Sdarran  *
6436ea3668Sdarran  */
6536ea3668Sdarran 
6636ea3668Sdarran /*
6736ea3668Sdarran  * Implement backward compatibility IOCTLs in this module.
6836ea3668Sdarran  *
6936ea3668Sdarran  */
7036ea3668Sdarran 
7136ea3668Sdarran #include <sys/cdefs.h>
72*b943dbddSriastradh __KERNEL_RCSID(0, "$NetBSD: ocryptodev.c,v 1.17 2022/03/12 17:15:04 riastradh Exp $");
7336ea3668Sdarran 
7436ea3668Sdarran #include <sys/param.h>
7536ea3668Sdarran #include <sys/systm.h>
7636ea3668Sdarran #include <sys/kmem.h>
7736ea3668Sdarran #include <sys/malloc.h>
7836ea3668Sdarran #include <sys/mbuf.h>
7936ea3668Sdarran #include <sys/pool.h>
8036ea3668Sdarran #include <sys/sysctl.h>
8136ea3668Sdarran #include <sys/file.h>
8236ea3668Sdarran #include <sys/filedesc.h>
8336ea3668Sdarran #include <sys/errno.h>
8436ea3668Sdarran #include <sys/md5.h>
8536ea3668Sdarran #include <sys/sha1.h>
8636ea3668Sdarran #include <sys/conf.h>
8736ea3668Sdarran #include <sys/device.h>
8836ea3668Sdarran #include <sys/kauth.h>
8936ea3668Sdarran #include <sys/select.h>
9036ea3668Sdarran #include <sys/poll.h>
9136ea3668Sdarran #include <sys/atomic.h>
92d91f98a8Spgoyette #include <sys/compat_stub.h>
93d91f98a8Spgoyette #include <sys/module.h>
9436ea3668Sdarran 
952dd4f4d9Spgoyette #ifdef _KERNEL_OPT
9636ea3668Sdarran #include "opt_ocf.h"
972dd4f4d9Spgoyette #endif
982dd4f4d9Spgoyette 
9936ea3668Sdarran #include <opencrypto/cryptodev.h>
100c3a6a9f4Sdrochner #include <opencrypto/cryptodev_internal.h>
10136ea3668Sdarran #include <opencrypto/ocryptodev.h>
10236ea3668Sdarran #include <opencrypto/xform.h>
10336ea3668Sdarran 
10436ea3668Sdarran static int	ocryptodev_op(struct csession *, struct ocrypt_op *,
10536ea3668Sdarran 		    struct lwp *);
10636ea3668Sdarran static int	ocryptodev_mop(struct fcrypt *, struct ocrypt_n_op *, int,
10736ea3668Sdarran 		    struct lwp *);
10836ea3668Sdarran static int	ocryptodev_session(struct fcrypt *, struct osession_op *);
109d91f98a8Spgoyette static int	ocryptodev_msession(struct fcrypt *, struct osession_n_op *,
110d91f98a8Spgoyette 		    int);
11136ea3668Sdarran 
11236ea3668Sdarran int
ocryptof_ioctl(struct file * fp,u_long cmd,void * data)11336ea3668Sdarran ocryptof_ioctl(struct file *fp, u_long cmd, void *data)
11436ea3668Sdarran {
11568a7688eSmatt 	struct fcrypt *fcr = fp->f_fcrypt;
11636ea3668Sdarran 	struct csession *cse;
11736ea3668Sdarran 	struct osession_op *osop;
11836ea3668Sdarran 	struct osession_n_op *osnop;
11936ea3668Sdarran 	struct ocrypt_op *ocop;
12036ea3668Sdarran 	struct ocrypt_mop *omop;
12136ea3668Sdarran 	struct ocrypt_n_op *ocnop;
12236ea3668Sdarran 	struct ocrypt_sgop *osgop;
12336ea3668Sdarran 
12436ea3668Sdarran 	int error = 0;
12536ea3668Sdarran 
12636ea3668Sdarran 	switch (cmd) {
12736ea3668Sdarran 	case OCIOCGSESSION:
12836ea3668Sdarran 		osop = (struct osession_op *)data;
12936ea3668Sdarran 		error = ocryptodev_session(fcr, osop);
13036ea3668Sdarran 		break;
13136ea3668Sdarran 	case CIOCNGSESSION:
13236ea3668Sdarran 		osgop = (struct ocrypt_sgop *)data;
1330090c87fSriastradh 		if ((osgop->count <= 0) ||
1340090c87fSriastradh 		    (SIZE_MAX/sizeof(struct osession_n_op) < osgop->count)) {
1350090c87fSriastradh 			error = EINVAL;
1360090c87fSriastradh 			break;
1370090c87fSriastradh 		}
13836ea3668Sdarran 		osnop = kmem_alloc((osgop->count *
13936ea3668Sdarran 				  sizeof(struct osession_n_op)), KM_SLEEP);
14036ea3668Sdarran 		error = copyin(osgop->sessions, osnop, osgop->count *
14136ea3668Sdarran 			       sizeof(struct osession_n_op));
14236ea3668Sdarran 		if (error) {
14336ea3668Sdarran 			goto mbail;
14436ea3668Sdarran 		}
14536ea3668Sdarran 
14636ea3668Sdarran 		error = ocryptodev_msession(fcr, osnop, osgop->count);
14736ea3668Sdarran 		if (error) {
14836ea3668Sdarran 			goto mbail;
14936ea3668Sdarran 		}
15036ea3668Sdarran 
15136ea3668Sdarran 		error = copyout(osnop, osgop->sessions, osgop->count *
15236ea3668Sdarran 		    sizeof(struct osession_n_op));
15336ea3668Sdarran mbail:
15436ea3668Sdarran 		kmem_free(osnop, osgop->count * sizeof(struct osession_n_op));
15536ea3668Sdarran 		break;
15636ea3668Sdarran 	case OCIOCCRYPT:
1576623cb2cSknakahara 		mutex_enter(&cryptodev_mtx);
15836ea3668Sdarran 		ocop = (struct ocrypt_op *)data;
15936ea3668Sdarran 		cse = cryptodev_csefind(fcr, ocop->ses);
1606623cb2cSknakahara 		mutex_exit(&cryptodev_mtx);
16136ea3668Sdarran 		if (cse == NULL) {
162c4e549c7Sknakahara 			DPRINTF("csefind failed\n");
16336ea3668Sdarran 			return EINVAL;
16436ea3668Sdarran 		}
16536ea3668Sdarran 		error = ocryptodev_op(cse, ocop, curlwp);
166c4e549c7Sknakahara 		DPRINTF("ocryptodev_op error = %d\n", error);
16736ea3668Sdarran 		break;
16836ea3668Sdarran 	case OCIOCNCRYPTM:
16936ea3668Sdarran 		omop = (struct ocrypt_mop *)data;
170*b943dbddSriastradh 		if (omop->count <= 0 || omop->count > 1) {
171027f8447Sriastradh 			error = EINVAL;
172027f8447Sriastradh 			break;
173027f8447Sriastradh 		}
17436ea3668Sdarran 		ocnop = kmem_alloc((omop->count * sizeof(struct ocrypt_n_op)),
17536ea3668Sdarran 		    KM_SLEEP);
17636ea3668Sdarran 		error = copyin(omop->reqs, ocnop,
17736ea3668Sdarran 		    (omop->count * sizeof(struct ocrypt_n_op)));
17836ea3668Sdarran 		if(!error) {
179d91f98a8Spgoyette 			error = ocryptodev_mop(fcr, ocnop, omop->count,
180d91f98a8Spgoyette 			    curlwp);
18136ea3668Sdarran 			if (!error) {
18236ea3668Sdarran 				error = copyout(ocnop, omop->reqs,
18336ea3668Sdarran 				    (omop->count * sizeof(struct ocrypt_n_op)));
18436ea3668Sdarran 			}
18536ea3668Sdarran 		}
18636ea3668Sdarran 		kmem_free(ocnop, (omop->count * sizeof(struct ocrypt_n_op)));
18736ea3668Sdarran 		break;
18836ea3668Sdarran 	default:
189c4e549c7Sknakahara 		DPRINTF("invalid ioctl cmd 0x%lx\n", cmd);
19036ea3668Sdarran 		return EINVAL;
19136ea3668Sdarran 	}
19236ea3668Sdarran 	return error;
19336ea3668Sdarran }
19436ea3668Sdarran 
19536ea3668Sdarran 
19636ea3668Sdarran static int
ocryptodev_op(struct csession * cse,struct ocrypt_op * ocop,struct lwp * l)19736ea3668Sdarran ocryptodev_op(struct csession *cse, struct ocrypt_op *ocop, struct lwp *l)
19836ea3668Sdarran {
19936ea3668Sdarran 	struct crypt_op cop;
20036ea3668Sdarran 
20136ea3668Sdarran 	cop.ses = ocop->ses;
20236ea3668Sdarran 	cop.op = ocop->op;
20336ea3668Sdarran 	cop.flags = ocop->flags;
20436ea3668Sdarran 	cop.len = ocop->len;
20536ea3668Sdarran 	cop.src = ocop->src;
20636ea3668Sdarran 	cop.dst = ocop->dst;
20736ea3668Sdarran 	cop.mac = ocop->mac;
20836ea3668Sdarran 	cop.iv = ocop->iv;
20936ea3668Sdarran 	cop.dst_len = 0;
21036ea3668Sdarran 
21136ea3668Sdarran 	return cryptodev_op(cse, &cop, l);
21236ea3668Sdarran };
21336ea3668Sdarran 
21436ea3668Sdarran static int
ocryptodev_mop(struct fcrypt * fcr,struct ocrypt_n_op * ocnop,int count,struct lwp * l)215d91f98a8Spgoyette ocryptodev_mop(struct fcrypt *fcr, struct ocrypt_n_op *ocnop, int count,
216d91f98a8Spgoyette     struct lwp *l)
21736ea3668Sdarran {
21836ea3668Sdarran 	int res;
21936ea3668Sdarran 
22036ea3668Sdarran 	struct crypt_n_op cnop;
22136ea3668Sdarran 
22236ea3668Sdarran 	cnop.ses = ocnop->ses;
22336ea3668Sdarran 	cnop.op = ocnop->op;
22436ea3668Sdarran 	cnop.flags = ocnop->flags;
22536ea3668Sdarran 	cnop.len = ocnop->len;
22636ea3668Sdarran 	cnop.reqid = ocnop->reqid;
22736ea3668Sdarran 	cnop.status = ocnop->status;
22836ea3668Sdarran 	cnop.opaque = ocnop->opaque;
22936ea3668Sdarran 	cnop.keylen = ocnop->keylen;
23036ea3668Sdarran 	cnop.key = ocnop->key;
23136ea3668Sdarran 	cnop.mackeylen = ocnop->mackeylen;
23236ea3668Sdarran 	cnop.mackey = ocnop->mackey;
23336ea3668Sdarran 	cnop.src = ocnop->src;
23436ea3668Sdarran 	cnop.dst = ocnop->dst;
23536ea3668Sdarran 	cnop.mac = ocnop->mac;
23636ea3668Sdarran 	cnop.iv = ocnop->iv;
23736ea3668Sdarran 	cnop.dst_len = 0;
23836ea3668Sdarran 	res = cryptodev_mop(fcr, &cnop, count, l);
23936ea3668Sdarran 	ocnop->reqid = cnop.reqid;
24036ea3668Sdarran 	ocnop->status = cnop.status;
24136ea3668Sdarran 
24236ea3668Sdarran 	return res;
24336ea3668Sdarran };
24436ea3668Sdarran 
24536ea3668Sdarran 
24636ea3668Sdarran static int
ocryptodev_session(struct fcrypt * fcr,struct osession_op * osop)24736ea3668Sdarran ocryptodev_session(struct fcrypt *fcr, struct osession_op *osop)
24836ea3668Sdarran {
24936ea3668Sdarran 	struct session_op sop;
25036ea3668Sdarran 	int res;
25136ea3668Sdarran 
25236ea3668Sdarran 	sop.cipher = osop->cipher;
25336ea3668Sdarran 	sop.mac = osop->mac;
25436ea3668Sdarran 	sop.comp_alg = 0;
25536ea3668Sdarran 	sop.keylen = osop->keylen;
25636ea3668Sdarran 	sop.key = osop->key;
25736ea3668Sdarran 	sop.mackeylen = osop->mackeylen;
25836ea3668Sdarran 	sop.mackey = osop->mackey;
25936ea3668Sdarran 	res = cryptodev_session(fcr, &sop);
2600633411dSriastradh 	if (res)
26136ea3668Sdarran 		return res;
2620633411dSriastradh 	osop->ses = sop.ses;
2630633411dSriastradh 	return 0;
26436ea3668Sdarran 
26536ea3668Sdarran }
26636ea3668Sdarran 
26736ea3668Sdarran static int
ocryptodev_msession(struct fcrypt * fcr,struct osession_n_op * osn_ops,int count)26836ea3668Sdarran ocryptodev_msession(struct fcrypt *fcr, struct osession_n_op *osn_ops,
26936ea3668Sdarran 		   int count)
27036ea3668Sdarran {
27136ea3668Sdarran 	int i;
27236ea3668Sdarran 
27336ea3668Sdarran 	for (i = 0; i < count; i++, osn_ops++) {
27436ea3668Sdarran 		struct osession_op os_op;
27536ea3668Sdarran 		os_op.cipher =		osn_ops->cipher;
27636ea3668Sdarran 		os_op.mac =		osn_ops->mac;
27736ea3668Sdarran 		os_op.keylen =		osn_ops->keylen;
27836ea3668Sdarran 		os_op.key =		osn_ops->key;
27936ea3668Sdarran 		os_op.mackeylen =	osn_ops->mackeylen;
28036ea3668Sdarran 		os_op.mackey =		osn_ops->mackey;
281d17a5906Schristos 		os_op.ses =		~0;
28236ea3668Sdarran 
28336ea3668Sdarran 		osn_ops->status = ocryptodev_session(fcr, &os_op);
28436ea3668Sdarran 		osn_ops->ses =		os_op.ses;
28536ea3668Sdarran 	}
28636ea3668Sdarran 
28736ea3668Sdarran 	return 0;
28836ea3668Sdarran }
289