xref: /dpdk/examples/fips_validation/main.c (revision 9252e81a9fc31fcad44132fde54b2e9cf8cb658f)
13d0fad56SMarko Kovacevic /* SPDX-License-Identifier: BSD-3-Clause
23d0fad56SMarko Kovacevic  * Copyright(c) 2018 Intel Corporation
33d0fad56SMarko Kovacevic  */
43d0fad56SMarko Kovacevic 
53d0fad56SMarko Kovacevic #include <sys/stat.h>
63d0fad56SMarko Kovacevic #include <getopt.h>
73d0fad56SMarko Kovacevic #include <dirent.h>
83d0fad56SMarko Kovacevic 
93d0fad56SMarko Kovacevic #include <rte_cryptodev.h>
103d0fad56SMarko Kovacevic #include <rte_cryptodev_pmd.h>
113d0fad56SMarko Kovacevic #include <rte_mempool.h>
123d0fad56SMarko Kovacevic #include <rte_mbuf.h>
133d0fad56SMarko Kovacevic #include <rte_string_fns.h>
143d0fad56SMarko Kovacevic 
153d0fad56SMarko Kovacevic #include "fips_validation.h"
163d0fad56SMarko Kovacevic 
173d0fad56SMarko Kovacevic #define REQ_FILE_PATH_KEYWORD	"req-file"
183d0fad56SMarko Kovacevic #define RSP_FILE_PATH_KEYWORD	"rsp-file"
193d0fad56SMarko Kovacevic #define FOLDER_KEYWORD		"path-is-folder"
203d0fad56SMarko Kovacevic #define CRYPTODEV_KEYWORD	"cryptodev"
213d0fad56SMarko Kovacevic #define CRYPTODEV_ID_KEYWORD	"cryptodev-id"
223d0fad56SMarko Kovacevic 
233d0fad56SMarko Kovacevic struct fips_test_vector vec;
243d0fad56SMarko Kovacevic struct fips_test_interim_info info;
253d0fad56SMarko Kovacevic 
263d0fad56SMarko Kovacevic struct cryptodev_fips_validate_env {
273d0fad56SMarko Kovacevic 	const char *req_path;
283d0fad56SMarko Kovacevic 	const char *rsp_path;
293d0fad56SMarko Kovacevic 	uint32_t is_path_folder;
303d0fad56SMarko Kovacevic 	uint32_t dev_id;
313d0fad56SMarko Kovacevic 	struct rte_mempool *mpool;
323d0fad56SMarko Kovacevic 	struct rte_mempool *op_pool;
333d0fad56SMarko Kovacevic 	struct rte_mbuf *mbuf;
343d0fad56SMarko Kovacevic 	struct rte_crypto_op *op;
353d0fad56SMarko Kovacevic 	struct rte_cryptodev_sym_session *sess;
363d0fad56SMarko Kovacevic } env;
373d0fad56SMarko Kovacevic 
383d0fad56SMarko Kovacevic static int
393d0fad56SMarko Kovacevic cryptodev_fips_validate_app_int(void)
403d0fad56SMarko Kovacevic {
413d0fad56SMarko Kovacevic 	struct rte_cryptodev_config conf = {rte_socket_id(), 1};
423d0fad56SMarko Kovacevic 	struct rte_cryptodev_qp_conf qp_conf = {128};
433d0fad56SMarko Kovacevic 	int ret;
443d0fad56SMarko Kovacevic 
453d0fad56SMarko Kovacevic 	ret = rte_cryptodev_configure(env.dev_id, &conf);
463d0fad56SMarko Kovacevic 	if (ret < 0)
473d0fad56SMarko Kovacevic 		return ret;
483d0fad56SMarko Kovacevic 
493d0fad56SMarko Kovacevic 	env.mpool = rte_pktmbuf_pool_create("FIPS_MEMPOOL", 128, 0, 0,
503d0fad56SMarko Kovacevic 			UINT16_MAX, rte_socket_id());
513d0fad56SMarko Kovacevic 	if (!env.mpool)
523d0fad56SMarko Kovacevic 		return ret;
533d0fad56SMarko Kovacevic 
543d0fad56SMarko Kovacevic 	ret = rte_cryptodev_queue_pair_setup(env.dev_id, 0, &qp_conf,
553d0fad56SMarko Kovacevic 			rte_socket_id(), env.mpool);
563d0fad56SMarko Kovacevic 	if (ret < 0)
573d0fad56SMarko Kovacevic 		return ret;
583d0fad56SMarko Kovacevic 
593d0fad56SMarko Kovacevic 	ret = -ENOMEM;
603d0fad56SMarko Kovacevic 
613d0fad56SMarko Kovacevic 	env.op_pool = rte_crypto_op_pool_create(
623d0fad56SMarko Kovacevic 			"FIPS_OP_POOL",
633d0fad56SMarko Kovacevic 			RTE_CRYPTO_OP_TYPE_SYMMETRIC,
643d0fad56SMarko Kovacevic 			1, 0,
653d0fad56SMarko Kovacevic 			16,
663d0fad56SMarko Kovacevic 			rte_socket_id());
673d0fad56SMarko Kovacevic 	if (!env.op_pool)
683d0fad56SMarko Kovacevic 		goto error_exit;
693d0fad56SMarko Kovacevic 
703d0fad56SMarko Kovacevic 	env.mbuf = rte_pktmbuf_alloc(env.mpool);
713d0fad56SMarko Kovacevic 	if (!env.mbuf)
723d0fad56SMarko Kovacevic 		goto error_exit;
733d0fad56SMarko Kovacevic 
743d0fad56SMarko Kovacevic 	env.op = rte_crypto_op_alloc(env.op_pool, RTE_CRYPTO_OP_TYPE_SYMMETRIC);
753d0fad56SMarko Kovacevic 	if (!env.op)
763d0fad56SMarko Kovacevic 		goto error_exit;
773d0fad56SMarko Kovacevic 
783d0fad56SMarko Kovacevic 	return 0;
793d0fad56SMarko Kovacevic 
803d0fad56SMarko Kovacevic error_exit:
813d0fad56SMarko Kovacevic 	rte_mempool_free(env.mpool);
823d0fad56SMarko Kovacevic 	if (env.op_pool)
833d0fad56SMarko Kovacevic 		rte_mempool_free(env.op_pool);
843d0fad56SMarko Kovacevic 
853d0fad56SMarko Kovacevic 	return ret;
863d0fad56SMarko Kovacevic }
873d0fad56SMarko Kovacevic 
883d0fad56SMarko Kovacevic static void
893d0fad56SMarko Kovacevic cryptodev_fips_validate_app_uninit(void)
903d0fad56SMarko Kovacevic {
913d0fad56SMarko Kovacevic 	rte_pktmbuf_free(env.mbuf);
923d0fad56SMarko Kovacevic 	rte_crypto_op_free(env.op);
933d0fad56SMarko Kovacevic 	rte_cryptodev_sym_session_clear(env.dev_id, env.sess);
943d0fad56SMarko Kovacevic 	rte_cryptodev_sym_session_free(env.sess);
953d0fad56SMarko Kovacevic 	rte_mempool_free(env.mpool);
963d0fad56SMarko Kovacevic 	rte_mempool_free(env.op_pool);
973d0fad56SMarko Kovacevic }
983d0fad56SMarko Kovacevic 
993d0fad56SMarko Kovacevic static int
1003d0fad56SMarko Kovacevic fips_test_one_file(void);
1013d0fad56SMarko Kovacevic 
1023d0fad56SMarko Kovacevic static int
1033d0fad56SMarko Kovacevic parse_cryptodev_arg(char *arg)
1043d0fad56SMarko Kovacevic {
1053d0fad56SMarko Kovacevic 	int id = rte_cryptodev_get_dev_id(arg);
1063d0fad56SMarko Kovacevic 
1073d0fad56SMarko Kovacevic 	if (id < 0) {
1083d0fad56SMarko Kovacevic 		RTE_LOG(ERR, USER1, "Error %i: invalid cryptodev name %s\n",
1093d0fad56SMarko Kovacevic 				id, arg);
1103d0fad56SMarko Kovacevic 		return id;
1113d0fad56SMarko Kovacevic 	}
1123d0fad56SMarko Kovacevic 
1133d0fad56SMarko Kovacevic 	env.dev_id = (uint32_t)id;
1143d0fad56SMarko Kovacevic 
1153d0fad56SMarko Kovacevic 	return 0;
1163d0fad56SMarko Kovacevic }
1173d0fad56SMarko Kovacevic 
1183d0fad56SMarko Kovacevic static int
1193d0fad56SMarko Kovacevic parse_cryptodev_id_arg(char *arg)
1203d0fad56SMarko Kovacevic {
1213d0fad56SMarko Kovacevic 	uint32_t cryptodev_id;
1223d0fad56SMarko Kovacevic 
1233d0fad56SMarko Kovacevic 	if (parser_read_uint32(&cryptodev_id, arg) < 0) {
1243d0fad56SMarko Kovacevic 		RTE_LOG(ERR, USER1, "Error %i: invalid cryptodev id %s\n",
1253d0fad56SMarko Kovacevic 				-EINVAL, arg);
1263d0fad56SMarko Kovacevic 		return -1;
1273d0fad56SMarko Kovacevic 	}
1283d0fad56SMarko Kovacevic 
1293d0fad56SMarko Kovacevic 
1303d0fad56SMarko Kovacevic 	if (!rte_cryptodev_pmd_is_valid_dev(cryptodev_id)) {
1313d0fad56SMarko Kovacevic 		RTE_LOG(ERR, USER1, "Error %i: invalid cryptodev id %s\n",
1323d0fad56SMarko Kovacevic 				cryptodev_id, arg);
1333d0fad56SMarko Kovacevic 		return -1;
1343d0fad56SMarko Kovacevic 	}
1353d0fad56SMarko Kovacevic 
1363d0fad56SMarko Kovacevic 	env.dev_id = (uint32_t)cryptodev_id;
1373d0fad56SMarko Kovacevic 
1383d0fad56SMarko Kovacevic 	return 0;
1393d0fad56SMarko Kovacevic }
1403d0fad56SMarko Kovacevic 
1413d0fad56SMarko Kovacevic static void
1423d0fad56SMarko Kovacevic cryptodev_fips_validate_usage(const char *prgname)
1433d0fad56SMarko Kovacevic {
1443d0fad56SMarko Kovacevic 	printf("%s [EAL options] --\n"
1453d0fad56SMarko Kovacevic 		"  --%s: REQUEST-FILE-PATH\n"
1463d0fad56SMarko Kovacevic 		"  --%s: RESPONSE-FILE-PATH\n"
1473d0fad56SMarko Kovacevic 		"  --%s: indicating both paths are folders\n"
1483d0fad56SMarko Kovacevic 		"  --%s: CRYPTODEV-NAME\n"
1493d0fad56SMarko Kovacevic 		"  --%s: CRYPTODEV-ID-NAME\n",
1503d0fad56SMarko Kovacevic 		prgname, REQ_FILE_PATH_KEYWORD, RSP_FILE_PATH_KEYWORD,
1513d0fad56SMarko Kovacevic 		FOLDER_KEYWORD, CRYPTODEV_KEYWORD, CRYPTODEV_ID_KEYWORD);
1523d0fad56SMarko Kovacevic }
1533d0fad56SMarko Kovacevic 
1543d0fad56SMarko Kovacevic static int
1553d0fad56SMarko Kovacevic cryptodev_fips_validate_parse_args(int argc, char **argv)
1563d0fad56SMarko Kovacevic {
1573d0fad56SMarko Kovacevic 	int opt, ret;
1583d0fad56SMarko Kovacevic 	char *prgname = argv[0];
1593d0fad56SMarko Kovacevic 	char **argvopt;
1603d0fad56SMarko Kovacevic 	int option_index;
1613d0fad56SMarko Kovacevic 	struct option lgopts[] = {
1623d0fad56SMarko Kovacevic 			{REQ_FILE_PATH_KEYWORD, required_argument, 0, 0},
1633d0fad56SMarko Kovacevic 			{RSP_FILE_PATH_KEYWORD, required_argument, 0, 0},
1643d0fad56SMarko Kovacevic 			{FOLDER_KEYWORD, no_argument, 0, 0},
1653d0fad56SMarko Kovacevic 			{CRYPTODEV_KEYWORD, required_argument, 0, 0},
1663d0fad56SMarko Kovacevic 			{CRYPTODEV_ID_KEYWORD, required_argument, 0, 0},
1673d0fad56SMarko Kovacevic 			{NULL, 0, 0, 0}
1683d0fad56SMarko Kovacevic 	};
1693d0fad56SMarko Kovacevic 
1703d0fad56SMarko Kovacevic 	argvopt = argv;
1713d0fad56SMarko Kovacevic 
1723d0fad56SMarko Kovacevic 	while ((opt = getopt_long(argc, argvopt, "s:",
1733d0fad56SMarko Kovacevic 				  lgopts, &option_index)) != EOF) {
1743d0fad56SMarko Kovacevic 
1753d0fad56SMarko Kovacevic 		switch (opt) {
1763d0fad56SMarko Kovacevic 		case 0:
1773d0fad56SMarko Kovacevic 			if (strcmp(lgopts[option_index].name,
1783d0fad56SMarko Kovacevic 					REQ_FILE_PATH_KEYWORD) == 0)
1793d0fad56SMarko Kovacevic 				env.req_path = optarg;
1803d0fad56SMarko Kovacevic 			else if (strcmp(lgopts[option_index].name,
1813d0fad56SMarko Kovacevic 					RSP_FILE_PATH_KEYWORD) == 0)
1823d0fad56SMarko Kovacevic 				env.rsp_path = optarg;
1833d0fad56SMarko Kovacevic 			else if (strcmp(lgopts[option_index].name,
1843d0fad56SMarko Kovacevic 					FOLDER_KEYWORD) == 0)
1853d0fad56SMarko Kovacevic 				env.is_path_folder = 1;
1863d0fad56SMarko Kovacevic 			else if (strcmp(lgopts[option_index].name,
1873d0fad56SMarko Kovacevic 					CRYPTODEV_KEYWORD) == 0) {
1883d0fad56SMarko Kovacevic 				ret = parse_cryptodev_arg(optarg);
1893d0fad56SMarko Kovacevic 				if (ret < 0) {
1903d0fad56SMarko Kovacevic 					cryptodev_fips_validate_usage(prgname);
1913d0fad56SMarko Kovacevic 					return -EINVAL;
1923d0fad56SMarko Kovacevic 				}
1933d0fad56SMarko Kovacevic 			} else if (strcmp(lgopts[option_index].name,
1943d0fad56SMarko Kovacevic 					CRYPTODEV_ID_KEYWORD) == 0) {
1953d0fad56SMarko Kovacevic 				ret = parse_cryptodev_id_arg(optarg);
1963d0fad56SMarko Kovacevic 				if (ret < 0) {
1973d0fad56SMarko Kovacevic 					cryptodev_fips_validate_usage(prgname);
1983d0fad56SMarko Kovacevic 					return -EINVAL;
1993d0fad56SMarko Kovacevic 				}
2003d0fad56SMarko Kovacevic 			} else {
2013d0fad56SMarko Kovacevic 				cryptodev_fips_validate_usage(prgname);
2023d0fad56SMarko Kovacevic 				return -EINVAL;
2033d0fad56SMarko Kovacevic 			}
2043d0fad56SMarko Kovacevic 			break;
2053d0fad56SMarko Kovacevic 		default:
2063d0fad56SMarko Kovacevic 			return -1;
2073d0fad56SMarko Kovacevic 		}
2083d0fad56SMarko Kovacevic 	}
2093d0fad56SMarko Kovacevic 
2103d0fad56SMarko Kovacevic 	if (env.req_path == NULL || env.rsp_path == NULL ||
2113d0fad56SMarko Kovacevic 			env.dev_id == UINT32_MAX) {
2123d0fad56SMarko Kovacevic 		cryptodev_fips_validate_usage(prgname);
2133d0fad56SMarko Kovacevic 		return -EINVAL;
2143d0fad56SMarko Kovacevic 	}
2153d0fad56SMarko Kovacevic 
2163d0fad56SMarko Kovacevic 	return 0;
2173d0fad56SMarko Kovacevic }
2183d0fad56SMarko Kovacevic 
2193d0fad56SMarko Kovacevic int
2203d0fad56SMarko Kovacevic main(int argc, char *argv[])
2213d0fad56SMarko Kovacevic {
2223d0fad56SMarko Kovacevic 	int ret;
2233d0fad56SMarko Kovacevic 
2243d0fad56SMarko Kovacevic 	ret = rte_eal_init(argc, argv);
2253d0fad56SMarko Kovacevic 	if (ret < 0) {
2263d0fad56SMarko Kovacevic 		RTE_LOG(ERR, USER1, "Error %i: Failed init\n", ret);
2273d0fad56SMarko Kovacevic 		return -1;
2283d0fad56SMarko Kovacevic 	}
2293d0fad56SMarko Kovacevic 
2303d0fad56SMarko Kovacevic 	argc -= ret;
2313d0fad56SMarko Kovacevic 	argv += ret;
2323d0fad56SMarko Kovacevic 
2333d0fad56SMarko Kovacevic 	ret = cryptodev_fips_validate_parse_args(argc, argv);
2343d0fad56SMarko Kovacevic 	if (ret < 0)
2353d0fad56SMarko Kovacevic 		rte_exit(EXIT_FAILURE, "Failed to parse arguments!\n");
2363d0fad56SMarko Kovacevic 
2373d0fad56SMarko Kovacevic 	ret = cryptodev_fips_validate_app_int();
2383d0fad56SMarko Kovacevic 	if (ret < 0) {
2393d0fad56SMarko Kovacevic 		RTE_LOG(ERR, USER1, "Error %i: Failed init\n", ret);
2403d0fad56SMarko Kovacevic 		return -1;
2413d0fad56SMarko Kovacevic 	}
2423d0fad56SMarko Kovacevic 
2433d0fad56SMarko Kovacevic 	if (!env.is_path_folder) {
2443d0fad56SMarko Kovacevic 		printf("Processing file %s... ", env.req_path);
2453d0fad56SMarko Kovacevic 
2463d0fad56SMarko Kovacevic 		ret = fips_test_init(env.req_path, env.rsp_path,
2473d0fad56SMarko Kovacevic 			rte_cryptodev_name_get(env.dev_id));
2483d0fad56SMarko Kovacevic 		if (ret < 0) {
2493d0fad56SMarko Kovacevic 			RTE_LOG(ERR, USER1, "Error %i: Failed test %s\n",
2503d0fad56SMarko Kovacevic 					ret, env.req_path);
2513d0fad56SMarko Kovacevic 			goto exit;
2523d0fad56SMarko Kovacevic 		}
2533d0fad56SMarko Kovacevic 
2543d0fad56SMarko Kovacevic 
2553d0fad56SMarko Kovacevic 		ret = fips_test_one_file();
2563d0fad56SMarko Kovacevic 		if (ret < 0) {
2573d0fad56SMarko Kovacevic 			RTE_LOG(ERR, USER1, "Error %i: Failed test %s\n",
2583d0fad56SMarko Kovacevic 					ret, env.req_path);
2593d0fad56SMarko Kovacevic 			goto exit;
2603d0fad56SMarko Kovacevic 		}
2613d0fad56SMarko Kovacevic 
2623d0fad56SMarko Kovacevic 		printf("Done\n");
2633d0fad56SMarko Kovacevic 
2643d0fad56SMarko Kovacevic 	} else {
2653d0fad56SMarko Kovacevic 		struct dirent *dir;
2663d0fad56SMarko Kovacevic 		DIR *d_req, *d_rsp;
2673d0fad56SMarko Kovacevic 		char req_path[1024];
2683d0fad56SMarko Kovacevic 		char rsp_path[1024];
2693d0fad56SMarko Kovacevic 
2703d0fad56SMarko Kovacevic 		d_req = opendir(env.req_path);
2713d0fad56SMarko Kovacevic 		if (!d_req) {
2723d0fad56SMarko Kovacevic 			RTE_LOG(ERR, USER1, "Error %i: Path %s not exist\n",
2733d0fad56SMarko Kovacevic 					-EINVAL, env.req_path);
2743d0fad56SMarko Kovacevic 			goto exit;
2753d0fad56SMarko Kovacevic 		}
2763d0fad56SMarko Kovacevic 
2773d0fad56SMarko Kovacevic 		d_rsp = opendir(env.rsp_path);
2783d0fad56SMarko Kovacevic 		if (!d_rsp) {
2793d0fad56SMarko Kovacevic 			ret = mkdir(env.rsp_path, 0700);
2803d0fad56SMarko Kovacevic 			if (ret == 0)
2813d0fad56SMarko Kovacevic 				d_rsp = opendir(env.rsp_path);
2823d0fad56SMarko Kovacevic 			else {
2833d0fad56SMarko Kovacevic 				RTE_LOG(ERR, USER1, "Error %i: Invalid %s\n",
2843d0fad56SMarko Kovacevic 						-EINVAL, env.rsp_path);
2853d0fad56SMarko Kovacevic 				goto exit;
2863d0fad56SMarko Kovacevic 			}
2873d0fad56SMarko Kovacevic 		}
2883d0fad56SMarko Kovacevic 		closedir(d_rsp);
2893d0fad56SMarko Kovacevic 
2903d0fad56SMarko Kovacevic 		while ((dir = readdir(d_req)) != NULL) {
2913d0fad56SMarko Kovacevic 			if (strstr(dir->d_name, "req") == NULL)
2923d0fad56SMarko Kovacevic 				continue;
2933d0fad56SMarko Kovacevic 
2943d0fad56SMarko Kovacevic 			snprintf(req_path, 1023, "%s/%s", env.req_path,
2953d0fad56SMarko Kovacevic 					dir->d_name);
2963d0fad56SMarko Kovacevic 			snprintf(rsp_path, 1023, "%s/%s", env.rsp_path,
2973d0fad56SMarko Kovacevic 					dir->d_name);
2983d0fad56SMarko Kovacevic 			strlcpy(strstr(rsp_path, "req"), "rsp", 4);
2993d0fad56SMarko Kovacevic 
3003d0fad56SMarko Kovacevic 			printf("Processing file %s... ", req_path);
3013d0fad56SMarko Kovacevic 
3023d0fad56SMarko Kovacevic 			ret = fips_test_init(req_path, rsp_path,
3033d0fad56SMarko Kovacevic 			rte_cryptodev_name_get(env.dev_id));
3043d0fad56SMarko Kovacevic 			if (ret < 0) {
3053d0fad56SMarko Kovacevic 				RTE_LOG(ERR, USER1, "Error %i: Failed test %s\n",
3063d0fad56SMarko Kovacevic 						ret, req_path);
3073d0fad56SMarko Kovacevic 				break;
3083d0fad56SMarko Kovacevic 			}
3093d0fad56SMarko Kovacevic 
3103d0fad56SMarko Kovacevic 			ret = fips_test_one_file();
3113d0fad56SMarko Kovacevic 			if (ret < 0) {
3123d0fad56SMarko Kovacevic 				RTE_LOG(ERR, USER1, "Error %i: Failed test %s\n",
3133d0fad56SMarko Kovacevic 						ret, req_path);
3143d0fad56SMarko Kovacevic 				break;
3153d0fad56SMarko Kovacevic 			}
3163d0fad56SMarko Kovacevic 
3173d0fad56SMarko Kovacevic 			printf("Done\n");
3183d0fad56SMarko Kovacevic 		}
3193d0fad56SMarko Kovacevic 
3203d0fad56SMarko Kovacevic 		closedir(d_req);
3213d0fad56SMarko Kovacevic 	}
3223d0fad56SMarko Kovacevic 
3233d0fad56SMarko Kovacevic 
3243d0fad56SMarko Kovacevic exit:
3253d0fad56SMarko Kovacevic 	fips_test_clear();
3263d0fad56SMarko Kovacevic 	cryptodev_fips_validate_app_uninit();
3273d0fad56SMarko Kovacevic 
3283d0fad56SMarko Kovacevic 	return ret;
3293d0fad56SMarko Kovacevic 
3303d0fad56SMarko Kovacevic }
3313d0fad56SMarko Kovacevic 
332cd255ccfSMarko Kovacevic #define IV_OFF (sizeof(struct rte_crypto_op) + sizeof(struct rte_crypto_sym_op))
333cd255ccfSMarko Kovacevic #define CRYPTODEV_FIPS_MAX_RETRIES	16
334cd255ccfSMarko Kovacevic 
335cd255ccfSMarko Kovacevic typedef int (*fips_test_one_case_t)(void);
336cd255ccfSMarko Kovacevic typedef int (*fips_prepare_op_t)(void);
337cd255ccfSMarko Kovacevic typedef int (*fips_prepare_xform_t)(struct rte_crypto_sym_xform *);
338cd255ccfSMarko Kovacevic 
339cd255ccfSMarko Kovacevic struct fips_test_ops {
340cd255ccfSMarko Kovacevic 	fips_prepare_xform_t prepare_xform;
341cd255ccfSMarko Kovacevic 	fips_prepare_op_t prepare_op;
342cd255ccfSMarko Kovacevic 	fips_test_one_case_t test;
343cd255ccfSMarko Kovacevic } test_ops;
344cd255ccfSMarko Kovacevic 
345cd255ccfSMarko Kovacevic static int
346cd255ccfSMarko Kovacevic prepare_cipher_op(void)
347cd255ccfSMarko Kovacevic {
348cd255ccfSMarko Kovacevic 	struct rte_crypto_sym_op *sym = env.op->sym;
349cd255ccfSMarko Kovacevic 	uint8_t *iv = rte_crypto_op_ctod_offset(env.op, uint8_t *, IV_OFF);
350cd255ccfSMarko Kovacevic 
351cd255ccfSMarko Kovacevic 	__rte_crypto_op_reset(env.op, RTE_CRYPTO_OP_TYPE_SYMMETRIC);
352cd255ccfSMarko Kovacevic 	rte_pktmbuf_reset(env.mbuf);
353cd255ccfSMarko Kovacevic 
354cd255ccfSMarko Kovacevic 	sym->m_src = env.mbuf;
355cd255ccfSMarko Kovacevic 	sym->cipher.data.offset = 0;
356cd255ccfSMarko Kovacevic 
357cd255ccfSMarko Kovacevic 	memcpy(iv, vec.iv.val, vec.iv.len);
358cd255ccfSMarko Kovacevic 
359cd255ccfSMarko Kovacevic 	if (info.op == FIPS_TEST_ENC_AUTH_GEN) {
360cd255ccfSMarko Kovacevic 		uint8_t *pt;
361cd255ccfSMarko Kovacevic 
362cd255ccfSMarko Kovacevic 		if (vec.pt.len > RTE_MBUF_MAX_NB_SEGS) {
363cd255ccfSMarko Kovacevic 			RTE_LOG(ERR, USER1, "PT len %u\n", vec.pt.len);
364cd255ccfSMarko Kovacevic 			return -EPERM;
365cd255ccfSMarko Kovacevic 		}
366cd255ccfSMarko Kovacevic 
367cd255ccfSMarko Kovacevic 		pt = (uint8_t *)rte_pktmbuf_append(env.mbuf, vec.pt.len);
368cd255ccfSMarko Kovacevic 
369cd255ccfSMarko Kovacevic 		if (!pt) {
370cd255ccfSMarko Kovacevic 			RTE_LOG(ERR, USER1, "Error %i: MBUF too small\n",
371cd255ccfSMarko Kovacevic 					-ENOMEM);
372cd255ccfSMarko Kovacevic 			return -ENOMEM;
373cd255ccfSMarko Kovacevic 		}
374cd255ccfSMarko Kovacevic 
375cd255ccfSMarko Kovacevic 		memcpy(pt, vec.pt.val, vec.pt.len);
376cd255ccfSMarko Kovacevic 		sym->cipher.data.length = vec.pt.len;
377cd255ccfSMarko Kovacevic 
378cd255ccfSMarko Kovacevic 	} else {
379cd255ccfSMarko Kovacevic 		uint8_t *ct;
380cd255ccfSMarko Kovacevic 
381cd255ccfSMarko Kovacevic 		if (vec.ct.len > RTE_MBUF_MAX_NB_SEGS) {
382cd255ccfSMarko Kovacevic 			RTE_LOG(ERR, USER1, "CT len %u\n", vec.ct.len);
383cd255ccfSMarko Kovacevic 			return -EPERM;
384cd255ccfSMarko Kovacevic 		}
385cd255ccfSMarko Kovacevic 
386cd255ccfSMarko Kovacevic 		ct = (uint8_t *)rte_pktmbuf_append(env.mbuf, vec.ct.len);
387cd255ccfSMarko Kovacevic 
388cd255ccfSMarko Kovacevic 		if (!ct) {
389cd255ccfSMarko Kovacevic 			RTE_LOG(ERR, USER1, "Error %i: MBUF too small\n",
390cd255ccfSMarko Kovacevic 					-ENOMEM);
391cd255ccfSMarko Kovacevic 			return -ENOMEM;
392cd255ccfSMarko Kovacevic 		}
393cd255ccfSMarko Kovacevic 
394cd255ccfSMarko Kovacevic 		memcpy(ct, vec.ct.val, vec.ct.len);
395cd255ccfSMarko Kovacevic 		sym->cipher.data.length = vec.ct.len;
396cd255ccfSMarko Kovacevic 	}
397cd255ccfSMarko Kovacevic 
398cd255ccfSMarko Kovacevic 	rte_crypto_op_attach_sym_session(env.op, env.sess);
399cd255ccfSMarko Kovacevic 
400cd255ccfSMarko Kovacevic 	return 0;
401cd255ccfSMarko Kovacevic }
402cd255ccfSMarko Kovacevic 
403cd255ccfSMarko Kovacevic static int
404f64adb67SMarko Kovacevic prepare_auth_op(void)
405f64adb67SMarko Kovacevic {
406f64adb67SMarko Kovacevic 	struct rte_crypto_sym_op *sym = env.op->sym;
407f64adb67SMarko Kovacevic 
408f64adb67SMarko Kovacevic 	__rte_crypto_op_reset(env.op, RTE_CRYPTO_OP_TYPE_SYMMETRIC);
409f64adb67SMarko Kovacevic 	rte_pktmbuf_reset(env.mbuf);
410f64adb67SMarko Kovacevic 
411f64adb67SMarko Kovacevic 	sym->m_src = env.mbuf;
412f64adb67SMarko Kovacevic 	sym->auth.data.offset = 0;
413f64adb67SMarko Kovacevic 
414f64adb67SMarko Kovacevic 	if (info.op == FIPS_TEST_ENC_AUTH_GEN) {
415f64adb67SMarko Kovacevic 		uint8_t *pt;
416f64adb67SMarko Kovacevic 
417f64adb67SMarko Kovacevic 		if (vec.pt.len > RTE_MBUF_MAX_NB_SEGS) {
418f64adb67SMarko Kovacevic 			RTE_LOG(ERR, USER1, "PT len %u\n", vec.pt.len);
419f64adb67SMarko Kovacevic 			return -EPERM;
420f64adb67SMarko Kovacevic 		}
421f64adb67SMarko Kovacevic 
422f64adb67SMarko Kovacevic 		pt = (uint8_t *)rte_pktmbuf_append(env.mbuf, vec.pt.len +
423f64adb67SMarko Kovacevic 				vec.cipher_auth.digest.len);
424f64adb67SMarko Kovacevic 
425f64adb67SMarko Kovacevic 		if (!pt) {
426f64adb67SMarko Kovacevic 			RTE_LOG(ERR, USER1, "Error %i: MBUF too small\n",
427f64adb67SMarko Kovacevic 					-ENOMEM);
428f64adb67SMarko Kovacevic 			return -ENOMEM;
429f64adb67SMarko Kovacevic 		}
430f64adb67SMarko Kovacevic 
431f64adb67SMarko Kovacevic 		memcpy(pt, vec.pt.val, vec.pt.len);
432f64adb67SMarko Kovacevic 		sym->auth.data.length = vec.pt.len;
433f64adb67SMarko Kovacevic 		sym->auth.digest.data = pt + vec.pt.len;
434f64adb67SMarko Kovacevic 		sym->auth.digest.phys_addr = rte_pktmbuf_mtophys_offset(
435f64adb67SMarko Kovacevic 				env.mbuf, vec.pt.len);
436f64adb67SMarko Kovacevic 
437f64adb67SMarko Kovacevic 	} else {
438f64adb67SMarko Kovacevic 		uint8_t *ct;
439f64adb67SMarko Kovacevic 
440f64adb67SMarko Kovacevic 		if (vec.ct.len > RTE_MBUF_MAX_NB_SEGS) {
441f64adb67SMarko Kovacevic 			RTE_LOG(ERR, USER1, "CT len %u\n", vec.ct.len);
442f64adb67SMarko Kovacevic 			return -EPERM;
443f64adb67SMarko Kovacevic 		}
444f64adb67SMarko Kovacevic 
445f64adb67SMarko Kovacevic 		ct = (uint8_t *)rte_pktmbuf_append(env.mbuf,
446f64adb67SMarko Kovacevic 				vec.ct.len + vec.cipher_auth.digest.len);
447f64adb67SMarko Kovacevic 
448f64adb67SMarko Kovacevic 		if (!ct) {
449f64adb67SMarko Kovacevic 			RTE_LOG(ERR, USER1, "Error %i: MBUF too small\n",
450f64adb67SMarko Kovacevic 					-ENOMEM);
451f64adb67SMarko Kovacevic 			return -ENOMEM;
452f64adb67SMarko Kovacevic 		}
453f64adb67SMarko Kovacevic 
454f64adb67SMarko Kovacevic 		memcpy(ct, vec.ct.val, vec.ct.len);
455f64adb67SMarko Kovacevic 		sym->auth.data.length = vec.ct.len;
456f64adb67SMarko Kovacevic 		sym->auth.digest.data = vec.cipher_auth.digest.val;
457f64adb67SMarko Kovacevic 		sym->auth.digest.phys_addr = rte_malloc_virt2iova(
458f64adb67SMarko Kovacevic 				sym->auth.digest.data);
459f64adb67SMarko Kovacevic 	}
460f64adb67SMarko Kovacevic 
461f64adb67SMarko Kovacevic 	rte_crypto_op_attach_sym_session(env.op, env.sess);
462c05e4ab7SThomas Monjalon 
463c05e4ab7SThomas Monjalon 	return 0;
464f64adb67SMarko Kovacevic }
465f64adb67SMarko Kovacevic 
466f64adb67SMarko Kovacevic static int
4674aaad299SMarko Kovacevic prepare_aead_op(void)
4684aaad299SMarko Kovacevic {
4694aaad299SMarko Kovacevic 	struct rte_crypto_sym_op *sym = env.op->sym;
4704aaad299SMarko Kovacevic 	uint8_t *iv = rte_crypto_op_ctod_offset(env.op, uint8_t *, IV_OFF);
4714aaad299SMarko Kovacevic 
4724aaad299SMarko Kovacevic 	__rte_crypto_op_reset(env.op, RTE_CRYPTO_OP_TYPE_SYMMETRIC);
4734aaad299SMarko Kovacevic 	rte_pktmbuf_reset(env.mbuf);
4744aaad299SMarko Kovacevic 
475305921f4SMarko Kovacevic 	if (info.algo == FIPS_TEST_ALGO_AES_CCM)
476305921f4SMarko Kovacevic 		memcpy(iv + 1, vec.iv.val, vec.iv.len);
477305921f4SMarko Kovacevic 	else
4784aaad299SMarko Kovacevic 		memcpy(iv, vec.iv.val, vec.iv.len);
4794aaad299SMarko Kovacevic 
4804aaad299SMarko Kovacevic 	sym->m_src = env.mbuf;
4814aaad299SMarko Kovacevic 	sym->aead.data.offset = 0;
4824aaad299SMarko Kovacevic 	sym->aead.aad.data = vec.aead.aad.val;
4834aaad299SMarko Kovacevic 	sym->aead.aad.phys_addr = rte_malloc_virt2iova(sym->aead.aad.data);
4844aaad299SMarko Kovacevic 
4854aaad299SMarko Kovacevic 	if (info.op == FIPS_TEST_ENC_AUTH_GEN) {
4864aaad299SMarko Kovacevic 		uint8_t *pt;
4874aaad299SMarko Kovacevic 
4884aaad299SMarko Kovacevic 		if (vec.pt.len > RTE_MBUF_MAX_NB_SEGS) {
4894aaad299SMarko Kovacevic 			RTE_LOG(ERR, USER1, "PT len %u\n", vec.pt.len);
4904aaad299SMarko Kovacevic 			return -EPERM;
4914aaad299SMarko Kovacevic 		}
4924aaad299SMarko Kovacevic 
4934aaad299SMarko Kovacevic 		pt = (uint8_t *)rte_pktmbuf_append(env.mbuf,
4944aaad299SMarko Kovacevic 				vec.pt.len + vec.aead.digest.len);
4954aaad299SMarko Kovacevic 
4964aaad299SMarko Kovacevic 		if (!pt) {
4974aaad299SMarko Kovacevic 			RTE_LOG(ERR, USER1, "Error %i: MBUF too small\n",
4984aaad299SMarko Kovacevic 					-ENOMEM);
4994aaad299SMarko Kovacevic 			return -ENOMEM;
5004aaad299SMarko Kovacevic 		}
5014aaad299SMarko Kovacevic 
5024aaad299SMarko Kovacevic 		memcpy(pt, vec.pt.val, vec.pt.len);
5034aaad299SMarko Kovacevic 		sym->aead.data.length = vec.pt.len;
5044aaad299SMarko Kovacevic 		sym->aead.digest.data = pt + vec.pt.len;
5054aaad299SMarko Kovacevic 		sym->aead.digest.phys_addr = rte_pktmbuf_mtophys_offset(
5064aaad299SMarko Kovacevic 				env.mbuf, vec.pt.len);
5074aaad299SMarko Kovacevic 	} else {
5084aaad299SMarko Kovacevic 		uint8_t *ct;
5094aaad299SMarko Kovacevic 
5104aaad299SMarko Kovacevic 		if (vec.ct.len > RTE_MBUF_MAX_NB_SEGS) {
5114aaad299SMarko Kovacevic 			RTE_LOG(ERR, USER1, "CT len %u\n", vec.ct.len);
5124aaad299SMarko Kovacevic 			return -EPERM;
5134aaad299SMarko Kovacevic 		}
5144aaad299SMarko Kovacevic 
5154aaad299SMarko Kovacevic 		ct = (uint8_t *)rte_pktmbuf_append(env.mbuf, vec.ct.len);
5164aaad299SMarko Kovacevic 
5174aaad299SMarko Kovacevic 		if (!ct) {
5184aaad299SMarko Kovacevic 			RTE_LOG(ERR, USER1, "Error %i: MBUF too small\n",
5194aaad299SMarko Kovacevic 					-ENOMEM);
5204aaad299SMarko Kovacevic 			return -ENOMEM;
5214aaad299SMarko Kovacevic 		}
5224aaad299SMarko Kovacevic 
5234aaad299SMarko Kovacevic 		memcpy(ct, vec.ct.val, vec.ct.len);
5244aaad299SMarko Kovacevic 		sym->aead.data.length = vec.ct.len;
5254aaad299SMarko Kovacevic 		sym->aead.digest.data = vec.aead.digest.val;
5264aaad299SMarko Kovacevic 		sym->aead.digest.phys_addr = rte_malloc_virt2iova(
5274aaad299SMarko Kovacevic 				sym->aead.digest.data);
5284aaad299SMarko Kovacevic 	}
5294aaad299SMarko Kovacevic 
5304aaad299SMarko Kovacevic 	rte_crypto_op_attach_sym_session(env.op, env.sess);
531c05e4ab7SThomas Monjalon 
532c05e4ab7SThomas Monjalon 	return 0;
5334aaad299SMarko Kovacevic }
5344aaad299SMarko Kovacevic 
5354aaad299SMarko Kovacevic static int
536cd255ccfSMarko Kovacevic prepare_aes_xform(struct rte_crypto_sym_xform *xform)
537cd255ccfSMarko Kovacevic {
538cd255ccfSMarko Kovacevic 	const struct rte_cryptodev_symmetric_capability *cap;
539cd255ccfSMarko Kovacevic 	struct rte_cryptodev_sym_capability_idx cap_idx;
540cd255ccfSMarko Kovacevic 	struct rte_crypto_cipher_xform *cipher_xform = &xform->cipher;
541cd255ccfSMarko Kovacevic 
542cd255ccfSMarko Kovacevic 	xform->type = RTE_CRYPTO_SYM_XFORM_CIPHER;
543cd255ccfSMarko Kovacevic 
544cd255ccfSMarko Kovacevic 	cipher_xform->algo = RTE_CRYPTO_CIPHER_AES_CBC;
545cd255ccfSMarko Kovacevic 	cipher_xform->op = (info.op == FIPS_TEST_ENC_AUTH_GEN) ?
546cd255ccfSMarko Kovacevic 			RTE_CRYPTO_CIPHER_OP_ENCRYPT :
547cd255ccfSMarko Kovacevic 			RTE_CRYPTO_CIPHER_OP_DECRYPT;
548cd255ccfSMarko Kovacevic 	cipher_xform->key.data = vec.cipher_auth.key.val;
549cd255ccfSMarko Kovacevic 	cipher_xform->key.length = vec.cipher_auth.key.len;
550cd255ccfSMarko Kovacevic 	cipher_xform->iv.length = vec.iv.len;
551cd255ccfSMarko Kovacevic 	cipher_xform->iv.offset = IV_OFF;
552cd255ccfSMarko Kovacevic 
553cd255ccfSMarko Kovacevic 	cap_idx.algo.cipher = RTE_CRYPTO_CIPHER_AES_CBC;
554cd255ccfSMarko Kovacevic 	cap_idx.type = RTE_CRYPTO_SYM_XFORM_CIPHER;
555cd255ccfSMarko Kovacevic 
556cd255ccfSMarko Kovacevic 	cap = rte_cryptodev_sym_capability_get(env.dev_id, &cap_idx);
557cd255ccfSMarko Kovacevic 	if (!cap) {
558cd255ccfSMarko Kovacevic 		RTE_LOG(ERR, USER1, "Failed to get capability for cdev %u\n",
559cd255ccfSMarko Kovacevic 				env.dev_id);
560cd255ccfSMarko Kovacevic 		return -EINVAL;
561cd255ccfSMarko Kovacevic 	}
562cd255ccfSMarko Kovacevic 
563cd255ccfSMarko Kovacevic 	if (rte_cryptodev_sym_capability_check_cipher(cap,
564cd255ccfSMarko Kovacevic 			cipher_xform->key.length,
565cd255ccfSMarko Kovacevic 			cipher_xform->iv.length) != 0) {
566cd255ccfSMarko Kovacevic 		RTE_LOG(ERR, USER1, "PMD %s key length %u IV length %u\n",
567cd255ccfSMarko Kovacevic 				info.device_name, cipher_xform->key.length,
568cd255ccfSMarko Kovacevic 				cipher_xform->iv.length);
569cd255ccfSMarko Kovacevic 		return -EPERM;
570cd255ccfSMarko Kovacevic 	}
571cd255ccfSMarko Kovacevic 
572cd255ccfSMarko Kovacevic 	return 0;
573cd255ccfSMarko Kovacevic }
574cd255ccfSMarko Kovacevic 
575f64adb67SMarko Kovacevic static int
576527cbf3dSMarko Kovacevic prepare_tdes_xform(struct rte_crypto_sym_xform *xform)
577527cbf3dSMarko Kovacevic {
578527cbf3dSMarko Kovacevic 	const struct rte_cryptodev_symmetric_capability *cap;
579527cbf3dSMarko Kovacevic 	struct rte_cryptodev_sym_capability_idx cap_idx;
580527cbf3dSMarko Kovacevic 	struct rte_crypto_cipher_xform *cipher_xform = &xform->cipher;
581527cbf3dSMarko Kovacevic 
582527cbf3dSMarko Kovacevic 	xform->type = RTE_CRYPTO_SYM_XFORM_CIPHER;
583527cbf3dSMarko Kovacevic 
584527cbf3dSMarko Kovacevic 	cipher_xform->algo = RTE_CRYPTO_CIPHER_3DES_CBC;
585527cbf3dSMarko Kovacevic 	cipher_xform->op = (info.op == FIPS_TEST_ENC_AUTH_GEN) ?
586527cbf3dSMarko Kovacevic 			RTE_CRYPTO_CIPHER_OP_ENCRYPT :
587527cbf3dSMarko Kovacevic 			RTE_CRYPTO_CIPHER_OP_DECRYPT;
588527cbf3dSMarko Kovacevic 	cipher_xform->key.data = vec.cipher_auth.key.val;
589527cbf3dSMarko Kovacevic 	cipher_xform->key.length = vec.cipher_auth.key.len;
590527cbf3dSMarko Kovacevic 	cipher_xform->iv.length = vec.iv.len;
591527cbf3dSMarko Kovacevic 	cipher_xform->iv.offset = IV_OFF;
592527cbf3dSMarko Kovacevic 
593527cbf3dSMarko Kovacevic 	cap_idx.algo.cipher = RTE_CRYPTO_CIPHER_3DES_CBC;
594527cbf3dSMarko Kovacevic 	cap_idx.type = RTE_CRYPTO_SYM_XFORM_CIPHER;
595527cbf3dSMarko Kovacevic 
596527cbf3dSMarko Kovacevic 	cap = rte_cryptodev_sym_capability_get(env.dev_id, &cap_idx);
597527cbf3dSMarko Kovacevic 	if (!cap) {
598527cbf3dSMarko Kovacevic 		RTE_LOG(ERR, USER1, "Failed to get capability for cdev %u\n",
599527cbf3dSMarko Kovacevic 				env.dev_id);
600527cbf3dSMarko Kovacevic 		return -EINVAL;
601527cbf3dSMarko Kovacevic 	}
602527cbf3dSMarko Kovacevic 
603527cbf3dSMarko Kovacevic 	if (rte_cryptodev_sym_capability_check_cipher(cap,
604527cbf3dSMarko Kovacevic 			cipher_xform->key.length,
605527cbf3dSMarko Kovacevic 			cipher_xform->iv.length) != 0) {
606527cbf3dSMarko Kovacevic 		RTE_LOG(ERR, USER1, "PMD %s key length %u IV length %u\n",
607527cbf3dSMarko Kovacevic 				info.device_name, cipher_xform->key.length,
608527cbf3dSMarko Kovacevic 				cipher_xform->iv.length);
609527cbf3dSMarko Kovacevic 		return -EPERM;
610527cbf3dSMarko Kovacevic 	}
611527cbf3dSMarko Kovacevic 
612527cbf3dSMarko Kovacevic 	return 0;
613527cbf3dSMarko Kovacevic }
614527cbf3dSMarko Kovacevic 
615527cbf3dSMarko Kovacevic static int
616f64adb67SMarko Kovacevic prepare_hmac_xform(struct rte_crypto_sym_xform *xform)
617f64adb67SMarko Kovacevic {
618f64adb67SMarko Kovacevic 	const struct rte_cryptodev_symmetric_capability *cap;
619f64adb67SMarko Kovacevic 	struct rte_cryptodev_sym_capability_idx cap_idx;
620f64adb67SMarko Kovacevic 	struct rte_crypto_auth_xform *auth_xform = &xform->auth;
621f64adb67SMarko Kovacevic 
622f64adb67SMarko Kovacevic 	xform->type = RTE_CRYPTO_SYM_XFORM_AUTH;
623f64adb67SMarko Kovacevic 
624f64adb67SMarko Kovacevic 	auth_xform->algo = info.interim_info.hmac_data.algo;
625f64adb67SMarko Kovacevic 	auth_xform->op = RTE_CRYPTO_AUTH_OP_GENERATE;
626f64adb67SMarko Kovacevic 	auth_xform->digest_length = vec.cipher_auth.digest.len;
627f64adb67SMarko Kovacevic 	auth_xform->key.data = vec.cipher_auth.key.val;
628f64adb67SMarko Kovacevic 	auth_xform->key.length = vec.cipher_auth.key.len;
629f64adb67SMarko Kovacevic 
630f64adb67SMarko Kovacevic 	cap_idx.algo.auth = auth_xform->algo;
631f64adb67SMarko Kovacevic 	cap_idx.type = RTE_CRYPTO_SYM_XFORM_AUTH;
632f64adb67SMarko Kovacevic 
633f64adb67SMarko Kovacevic 	cap = rte_cryptodev_sym_capability_get(env.dev_id, &cap_idx);
634f64adb67SMarko Kovacevic 	if (!cap) {
635f64adb67SMarko Kovacevic 		RTE_LOG(ERR, USER1, "Failed to get capability for cdev %u\n",
636f64adb67SMarko Kovacevic 				env.dev_id);
637f64adb67SMarko Kovacevic 		return -EINVAL;
638f64adb67SMarko Kovacevic 	}
639f64adb67SMarko Kovacevic 
640f64adb67SMarko Kovacevic 	if (rte_cryptodev_sym_capability_check_auth(cap,
641f64adb67SMarko Kovacevic 			auth_xform->key.length,
642f64adb67SMarko Kovacevic 			auth_xform->digest_length, 0) != 0) {
643f64adb67SMarko Kovacevic 		RTE_LOG(ERR, USER1, "PMD %s key length %u IV length %u\n",
644f64adb67SMarko Kovacevic 				info.device_name, auth_xform->key.length,
645f64adb67SMarko Kovacevic 				auth_xform->digest_length);
646f64adb67SMarko Kovacevic 		return -EPERM;
647f64adb67SMarko Kovacevic 	}
648f64adb67SMarko Kovacevic 
649f64adb67SMarko Kovacevic 	return 0;
650f64adb67SMarko Kovacevic }
651f64adb67SMarko Kovacevic 
6524aaad299SMarko Kovacevic static int
6534aaad299SMarko Kovacevic prepare_gcm_xform(struct rte_crypto_sym_xform *xform)
6544aaad299SMarko Kovacevic {
6554aaad299SMarko Kovacevic 	const struct rte_cryptodev_symmetric_capability *cap;
6564aaad299SMarko Kovacevic 	struct rte_cryptodev_sym_capability_idx cap_idx;
6574aaad299SMarko Kovacevic 	struct rte_crypto_aead_xform *aead_xform = &xform->aead;
6584aaad299SMarko Kovacevic 
6594aaad299SMarko Kovacevic 	xform->type = RTE_CRYPTO_SYM_XFORM_AEAD;
6604aaad299SMarko Kovacevic 
6614aaad299SMarko Kovacevic 	aead_xform->algo = RTE_CRYPTO_AEAD_AES_GCM;
6624aaad299SMarko Kovacevic 	aead_xform->aad_length = vec.aead.aad.len;
6634aaad299SMarko Kovacevic 	aead_xform->digest_length = vec.aead.digest.len;
6644aaad299SMarko Kovacevic 	aead_xform->iv.offset = IV_OFF;
6654aaad299SMarko Kovacevic 	aead_xform->iv.length = vec.iv.len;
6664aaad299SMarko Kovacevic 	aead_xform->key.data = vec.aead.key.val;
6674aaad299SMarko Kovacevic 	aead_xform->key.length = vec.aead.key.len;
6684aaad299SMarko Kovacevic 	aead_xform->op = (info.op == FIPS_TEST_ENC_AUTH_GEN) ?
6694aaad299SMarko Kovacevic 			RTE_CRYPTO_AEAD_OP_ENCRYPT :
6704aaad299SMarko Kovacevic 			RTE_CRYPTO_AEAD_OP_DECRYPT;
6714aaad299SMarko Kovacevic 
6724aaad299SMarko Kovacevic 	cap_idx.algo.aead = aead_xform->algo;
6734aaad299SMarko Kovacevic 	cap_idx.type = RTE_CRYPTO_SYM_XFORM_AEAD;
6744aaad299SMarko Kovacevic 
6754aaad299SMarko Kovacevic 	cap = rte_cryptodev_sym_capability_get(env.dev_id, &cap_idx);
6764aaad299SMarko Kovacevic 	if (!cap) {
6774aaad299SMarko Kovacevic 		RTE_LOG(ERR, USER1, "Failed to get capability for cdev %u\n",
6784aaad299SMarko Kovacevic 				env.dev_id);
6794aaad299SMarko Kovacevic 		return -EINVAL;
6804aaad299SMarko Kovacevic 	}
6814aaad299SMarko Kovacevic 
6824aaad299SMarko Kovacevic 	if (rte_cryptodev_sym_capability_check_aead(cap,
6834aaad299SMarko Kovacevic 			aead_xform->key.length,
6844aaad299SMarko Kovacevic 			aead_xform->digest_length, aead_xform->aad_length,
6854aaad299SMarko Kovacevic 			aead_xform->iv.length) != 0) {
6864aaad299SMarko Kovacevic 		RTE_LOG(ERR, USER1,
6874aaad299SMarko Kovacevic 			"PMD %s key_len %u tag_len %u aad_len %u iv_len %u\n",
6884aaad299SMarko Kovacevic 				info.device_name, aead_xform->key.length,
6894aaad299SMarko Kovacevic 				aead_xform->digest_length,
6904aaad299SMarko Kovacevic 				aead_xform->aad_length,
6914aaad299SMarko Kovacevic 				aead_xform->iv.length);
6924aaad299SMarko Kovacevic 		return -EPERM;
6934aaad299SMarko Kovacevic 	}
6944aaad299SMarko Kovacevic 
6954aaad299SMarko Kovacevic 	return 0;
6964aaad299SMarko Kovacevic }
6974aaad299SMarko Kovacevic 
698ac026f46SMarko Kovacevic static int
699ac026f46SMarko Kovacevic prepare_cmac_xform(struct rte_crypto_sym_xform *xform)
700ac026f46SMarko Kovacevic {
701ac026f46SMarko Kovacevic 	const struct rte_cryptodev_symmetric_capability *cap;
702ac026f46SMarko Kovacevic 	struct rte_cryptodev_sym_capability_idx cap_idx;
703ac026f46SMarko Kovacevic 	struct rte_crypto_auth_xform *auth_xform = &xform->auth;
704ac026f46SMarko Kovacevic 
705ac026f46SMarko Kovacevic 	xform->type = RTE_CRYPTO_SYM_XFORM_AUTH;
706ac026f46SMarko Kovacevic 
707ac026f46SMarko Kovacevic 	auth_xform->algo = RTE_CRYPTO_AUTH_AES_CMAC;
708ac026f46SMarko Kovacevic 	auth_xform->op = (info.op == FIPS_TEST_ENC_AUTH_GEN) ?
709ac026f46SMarko Kovacevic 			RTE_CRYPTO_AUTH_OP_GENERATE : RTE_CRYPTO_AUTH_OP_VERIFY;
710ac026f46SMarko Kovacevic 	auth_xform->digest_length = vec.cipher_auth.digest.len;
711ac026f46SMarko Kovacevic 	auth_xform->key.data = vec.cipher_auth.key.val;
712ac026f46SMarko Kovacevic 	auth_xform->key.length = vec.cipher_auth.key.len;
713ac026f46SMarko Kovacevic 
714ac026f46SMarko Kovacevic 	cap_idx.algo.auth = auth_xform->algo;
715ac026f46SMarko Kovacevic 	cap_idx.type = RTE_CRYPTO_SYM_XFORM_AUTH;
716ac026f46SMarko Kovacevic 
717ac026f46SMarko Kovacevic 	cap = rte_cryptodev_sym_capability_get(env.dev_id, &cap_idx);
718ac026f46SMarko Kovacevic 	if (!cap) {
719ac026f46SMarko Kovacevic 		RTE_LOG(ERR, USER1, "Failed to get capability for cdev %u\n",
720ac026f46SMarko Kovacevic 				env.dev_id);
721ac026f46SMarko Kovacevic 		return -EINVAL;
722ac026f46SMarko Kovacevic 	}
723ac026f46SMarko Kovacevic 
724ac026f46SMarko Kovacevic 	if (rte_cryptodev_sym_capability_check_auth(cap,
725ac026f46SMarko Kovacevic 			auth_xform->key.length,
726ac026f46SMarko Kovacevic 			auth_xform->digest_length, 0) != 0) {
727ac026f46SMarko Kovacevic 		RTE_LOG(ERR, USER1, "PMD %s key length %u IV length %u\n",
728ac026f46SMarko Kovacevic 				info.device_name, auth_xform->key.length,
729ac026f46SMarko Kovacevic 				auth_xform->digest_length);
730ac026f46SMarko Kovacevic 		return -EPERM;
731ac026f46SMarko Kovacevic 	}
732ac026f46SMarko Kovacevic 
733ac026f46SMarko Kovacevic 	return 0;
734ac026f46SMarko Kovacevic }
735ac026f46SMarko Kovacevic 
736305921f4SMarko Kovacevic static int
737305921f4SMarko Kovacevic prepare_ccm_xform(struct rte_crypto_sym_xform *xform)
738305921f4SMarko Kovacevic {
739305921f4SMarko Kovacevic 	const struct rte_cryptodev_symmetric_capability *cap;
740305921f4SMarko Kovacevic 	struct rte_cryptodev_sym_capability_idx cap_idx;
741305921f4SMarko Kovacevic 	struct rte_crypto_aead_xform *aead_xform = &xform->aead;
742305921f4SMarko Kovacevic 
743305921f4SMarko Kovacevic 	xform->type = RTE_CRYPTO_SYM_XFORM_AEAD;
744305921f4SMarko Kovacevic 
745305921f4SMarko Kovacevic 	aead_xform->algo = RTE_CRYPTO_AEAD_AES_CCM;
746305921f4SMarko Kovacevic 	aead_xform->aad_length = vec.aead.aad.len;
747305921f4SMarko Kovacevic 	aead_xform->digest_length = vec.aead.digest.len;
748305921f4SMarko Kovacevic 	aead_xform->iv.offset = IV_OFF;
749305921f4SMarko Kovacevic 	aead_xform->iv.length = vec.iv.len;
750305921f4SMarko Kovacevic 	aead_xform->key.data = vec.aead.key.val;
751305921f4SMarko Kovacevic 	aead_xform->key.length = vec.aead.key.len;
752305921f4SMarko Kovacevic 	aead_xform->op = (info.op == FIPS_TEST_ENC_AUTH_GEN) ?
753305921f4SMarko Kovacevic 			RTE_CRYPTO_AEAD_OP_ENCRYPT :
754305921f4SMarko Kovacevic 			RTE_CRYPTO_AEAD_OP_DECRYPT;
755305921f4SMarko Kovacevic 
756305921f4SMarko Kovacevic 	cap_idx.algo.aead = aead_xform->algo;
757305921f4SMarko Kovacevic 	cap_idx.type = RTE_CRYPTO_SYM_XFORM_AEAD;
758305921f4SMarko Kovacevic 
759305921f4SMarko Kovacevic 	cap = rte_cryptodev_sym_capability_get(env.dev_id, &cap_idx);
760305921f4SMarko Kovacevic 	if (!cap) {
761305921f4SMarko Kovacevic 		RTE_LOG(ERR, USER1, "Failed to get capability for cdev %u\n",
762305921f4SMarko Kovacevic 				env.dev_id);
763305921f4SMarko Kovacevic 		return -EINVAL;
764305921f4SMarko Kovacevic 	}
765305921f4SMarko Kovacevic 
766305921f4SMarko Kovacevic 	if (rte_cryptodev_sym_capability_check_aead(cap,
767305921f4SMarko Kovacevic 			aead_xform->key.length,
768305921f4SMarko Kovacevic 			aead_xform->digest_length, aead_xform->aad_length,
769305921f4SMarko Kovacevic 			aead_xform->iv.length) != 0) {
770305921f4SMarko Kovacevic 		RTE_LOG(ERR, USER1,
771305921f4SMarko Kovacevic 			"PMD %s key_len %u tag_len %u aad_len %u iv_len %u\n",
772305921f4SMarko Kovacevic 				info.device_name, aead_xform->key.length,
773305921f4SMarko Kovacevic 				aead_xform->digest_length,
774305921f4SMarko Kovacevic 				aead_xform->aad_length,
775305921f4SMarko Kovacevic 				aead_xform->iv.length);
776305921f4SMarko Kovacevic 		return -EPERM;
777305921f4SMarko Kovacevic 	}
778305921f4SMarko Kovacevic 
779305921f4SMarko Kovacevic 	return 0;
780305921f4SMarko Kovacevic }
781305921f4SMarko Kovacevic 
782cd255ccfSMarko Kovacevic static void
783cd255ccfSMarko Kovacevic get_writeback_data(struct fips_val *val)
784cd255ccfSMarko Kovacevic {
785cd255ccfSMarko Kovacevic 	val->val = rte_pktmbuf_mtod(env.mbuf, uint8_t *);
786cd255ccfSMarko Kovacevic 	val->len = rte_pktmbuf_pkt_len(env.mbuf);
787cd255ccfSMarko Kovacevic }
788cd255ccfSMarko Kovacevic 
789cd255ccfSMarko Kovacevic static int
790cd255ccfSMarko Kovacevic fips_run_test(void)
791cd255ccfSMarko Kovacevic {
792cd255ccfSMarko Kovacevic 	struct rte_crypto_sym_xform xform = {0};
793cd255ccfSMarko Kovacevic 	uint16_t n_deqd;
794cd255ccfSMarko Kovacevic 	int ret;
795cd255ccfSMarko Kovacevic 
796cd255ccfSMarko Kovacevic 	ret = test_ops.prepare_xform(&xform);
797cd255ccfSMarko Kovacevic 	if (ret < 0)
798cd255ccfSMarko Kovacevic 		return ret;
799cd255ccfSMarko Kovacevic 
800cd255ccfSMarko Kovacevic 	env.sess = rte_cryptodev_sym_session_create(env.mpool);
801cd255ccfSMarko Kovacevic 	if (!env.sess)
802cd255ccfSMarko Kovacevic 		return -ENOMEM;
803cd255ccfSMarko Kovacevic 
804cd255ccfSMarko Kovacevic 	ret = rte_cryptodev_sym_session_init(env.dev_id,
805cd255ccfSMarko Kovacevic 			env.sess, &xform, env.mpool);
806cd255ccfSMarko Kovacevic 	if (ret < 0) {
807cd255ccfSMarko Kovacevic 		RTE_LOG(ERR, USER1, "Error %i: Init session\n",
808cd255ccfSMarko Kovacevic 				ret);
809cd255ccfSMarko Kovacevic 		return ret;
810cd255ccfSMarko Kovacevic 	}
811cd255ccfSMarko Kovacevic 
812cd255ccfSMarko Kovacevic 	ret = test_ops.prepare_op();
813cd255ccfSMarko Kovacevic 	if (ret < 0) {
814cd255ccfSMarko Kovacevic 		RTE_LOG(ERR, USER1, "Error %i: Prepare op\n",
815cd255ccfSMarko Kovacevic 				ret);
816cd255ccfSMarko Kovacevic 		return ret;
817cd255ccfSMarko Kovacevic 	}
818cd255ccfSMarko Kovacevic 
819cd255ccfSMarko Kovacevic 	if (rte_cryptodev_enqueue_burst(env.dev_id, 0, &env.op, 1) < 1) {
820cd255ccfSMarko Kovacevic 		RTE_LOG(ERR, USER1, "Error: Failed enqueue\n");
821cd255ccfSMarko Kovacevic 		return ret;
822cd255ccfSMarko Kovacevic 	}
823cd255ccfSMarko Kovacevic 
824cd255ccfSMarko Kovacevic 	do {
825cd255ccfSMarko Kovacevic 		struct rte_crypto_op *deqd_op;
826cd255ccfSMarko Kovacevic 
827cd255ccfSMarko Kovacevic 		n_deqd = rte_cryptodev_dequeue_burst(env.dev_id, 0, &deqd_op,
828cd255ccfSMarko Kovacevic 				1);
829cd255ccfSMarko Kovacevic 	} while (n_deqd == 0);
830cd255ccfSMarko Kovacevic 
831cd255ccfSMarko Kovacevic 	vec.status = env.op->status;
832cd255ccfSMarko Kovacevic 
833cd255ccfSMarko Kovacevic 	rte_cryptodev_sym_session_clear(env.dev_id, env.sess);
834cd255ccfSMarko Kovacevic 	rte_cryptodev_sym_session_free(env.sess);
835cd255ccfSMarko Kovacevic 	env.sess = NULL;
836cd255ccfSMarko Kovacevic 
837cd255ccfSMarko Kovacevic 	return ret;
838cd255ccfSMarko Kovacevic }
839cd255ccfSMarko Kovacevic 
840cd255ccfSMarko Kovacevic static int
841cd255ccfSMarko Kovacevic fips_generic_test(void)
842cd255ccfSMarko Kovacevic {
843cd255ccfSMarko Kovacevic 	struct fips_val val;
844cd255ccfSMarko Kovacevic 	int ret;
845cd255ccfSMarko Kovacevic 
846cd255ccfSMarko Kovacevic 	fips_test_write_one_case();
847cd255ccfSMarko Kovacevic 
848cd255ccfSMarko Kovacevic 	ret = fips_run_test();
849cd255ccfSMarko Kovacevic 	if (ret < 0) {
850cd255ccfSMarko Kovacevic 		if (ret == -EPERM) {
851cd255ccfSMarko Kovacevic 			fprintf(info.fp_wr, "Bypass\n\n");
852cd255ccfSMarko Kovacevic 			return 0;
853cd255ccfSMarko Kovacevic 		}
854cd255ccfSMarko Kovacevic 
855cd255ccfSMarko Kovacevic 		return ret;
856cd255ccfSMarko Kovacevic 	}
857cd255ccfSMarko Kovacevic 
858cd255ccfSMarko Kovacevic 	get_writeback_data(&val);
859cd255ccfSMarko Kovacevic 
860cd255ccfSMarko Kovacevic 	switch (info.file_type) {
861cd255ccfSMarko Kovacevic 	case FIPS_TYPE_REQ:
862cd255ccfSMarko Kovacevic 	case FIPS_TYPE_RSP:
863cd255ccfSMarko Kovacevic 		if (info.parse_writeback == NULL)
864cd255ccfSMarko Kovacevic 			return -EPERM;
865cd255ccfSMarko Kovacevic 		ret = info.parse_writeback(&val);
866cd255ccfSMarko Kovacevic 		if (ret < 0)
867cd255ccfSMarko Kovacevic 			return ret;
868cd255ccfSMarko Kovacevic 		break;
869cd255ccfSMarko Kovacevic 	case FIPS_TYPE_FAX:
870cd255ccfSMarko Kovacevic 		if (info.kat_check == NULL)
871cd255ccfSMarko Kovacevic 			return -EPERM;
872cd255ccfSMarko Kovacevic 		ret = info.kat_check(&val);
873cd255ccfSMarko Kovacevic 		if (ret < 0)
874cd255ccfSMarko Kovacevic 			return ret;
875cd255ccfSMarko Kovacevic 		break;
876cd255ccfSMarko Kovacevic 	}
877cd255ccfSMarko Kovacevic 
878cd255ccfSMarko Kovacevic 	fprintf(info.fp_wr, "\n");
879cd255ccfSMarko Kovacevic 
880cd255ccfSMarko Kovacevic 	return 0;
881cd255ccfSMarko Kovacevic }
882cd255ccfSMarko Kovacevic 
883cd255ccfSMarko Kovacevic static int
884527cbf3dSMarko Kovacevic fips_mct_tdes_test(void)
885527cbf3dSMarko Kovacevic {
886527cbf3dSMarko Kovacevic #define TDES_BLOCK_SIZE		8
887527cbf3dSMarko Kovacevic #define TDES_EXTERN_ITER	400
888527cbf3dSMarko Kovacevic #define TDES_INTERN_ITER	10000
889527cbf3dSMarko Kovacevic 	struct fips_val val, val_key;
890*9252e81aSMarko Kovacevic 	uint8_t prev_out[TDES_BLOCK_SIZE] = {0};
891*9252e81aSMarko Kovacevic 	uint8_t prev_prev_out[TDES_BLOCK_SIZE] = {0};
892*9252e81aSMarko Kovacevic 	uint8_t prev_in[TDES_BLOCK_SIZE] = {0};
893527cbf3dSMarko Kovacevic 	uint32_t i, j, k;
894527cbf3dSMarko Kovacevic 	int ret;
895527cbf3dSMarko Kovacevic 
896527cbf3dSMarko Kovacevic 	for (i = 0; i < TDES_EXTERN_ITER; i++) {
897527cbf3dSMarko Kovacevic 		if (i != 0)
898527cbf3dSMarko Kovacevic 			update_info_vec(i);
899527cbf3dSMarko Kovacevic 
900527cbf3dSMarko Kovacevic 		fips_test_write_one_case();
901527cbf3dSMarko Kovacevic 
902527cbf3dSMarko Kovacevic 		for (j = 0; j < TDES_INTERN_ITER; j++) {
903527cbf3dSMarko Kovacevic 			ret = fips_run_test();
904527cbf3dSMarko Kovacevic 			if (ret < 0) {
905527cbf3dSMarko Kovacevic 				if (ret == -EPERM) {
906527cbf3dSMarko Kovacevic 					fprintf(info.fp_wr, "Bypass\n");
907527cbf3dSMarko Kovacevic 					return 0;
908527cbf3dSMarko Kovacevic 				}
909527cbf3dSMarko Kovacevic 
910527cbf3dSMarko Kovacevic 				return ret;
911527cbf3dSMarko Kovacevic 			}
912527cbf3dSMarko Kovacevic 
913527cbf3dSMarko Kovacevic 			get_writeback_data(&val);
914527cbf3dSMarko Kovacevic 
915527cbf3dSMarko Kovacevic 			if (info.op == FIPS_TEST_DEC_AUTH_VERIF)
916527cbf3dSMarko Kovacevic 				memcpy(prev_in, vec.ct.val, TDES_BLOCK_SIZE);
917527cbf3dSMarko Kovacevic 
918527cbf3dSMarko Kovacevic 			if (j == 0) {
919527cbf3dSMarko Kovacevic 				memcpy(prev_out, val.val, TDES_BLOCK_SIZE);
920527cbf3dSMarko Kovacevic 
921527cbf3dSMarko Kovacevic 				if (info.op == FIPS_TEST_ENC_AUTH_GEN) {
922527cbf3dSMarko Kovacevic 					memcpy(vec.pt.val, vec.iv.val,
923527cbf3dSMarko Kovacevic 							TDES_BLOCK_SIZE);
924527cbf3dSMarko Kovacevic 					memcpy(vec.iv.val, val.val,
925527cbf3dSMarko Kovacevic 							TDES_BLOCK_SIZE);
926527cbf3dSMarko Kovacevic 				} else {
927527cbf3dSMarko Kovacevic 					memcpy(vec.iv.val, vec.ct.val,
928527cbf3dSMarko Kovacevic 							TDES_BLOCK_SIZE);
929527cbf3dSMarko Kovacevic 					memcpy(vec.ct.val, val.val,
930527cbf3dSMarko Kovacevic 							TDES_BLOCK_SIZE);
931527cbf3dSMarko Kovacevic 				}
932527cbf3dSMarko Kovacevic 				continue;
933527cbf3dSMarko Kovacevic 			}
934527cbf3dSMarko Kovacevic 
935527cbf3dSMarko Kovacevic 			if (info.op == FIPS_TEST_ENC_AUTH_GEN) {
936527cbf3dSMarko Kovacevic 				memcpy(vec.iv.val, val.val, TDES_BLOCK_SIZE);
937527cbf3dSMarko Kovacevic 				memcpy(vec.pt.val, prev_out, TDES_BLOCK_SIZE);
938527cbf3dSMarko Kovacevic 			} else {
939527cbf3dSMarko Kovacevic 				memcpy(vec.iv.val, vec.ct.val, TDES_BLOCK_SIZE);
940527cbf3dSMarko Kovacevic 				memcpy(vec.ct.val, val.val, TDES_BLOCK_SIZE);
941527cbf3dSMarko Kovacevic 			}
942527cbf3dSMarko Kovacevic 
943527cbf3dSMarko Kovacevic 			if (j == TDES_INTERN_ITER - 1)
944527cbf3dSMarko Kovacevic 				continue;
945527cbf3dSMarko Kovacevic 
946527cbf3dSMarko Kovacevic 			memcpy(prev_out, val.val, TDES_BLOCK_SIZE);
947527cbf3dSMarko Kovacevic 
948527cbf3dSMarko Kovacevic 			if (j == TDES_INTERN_ITER - 3)
949527cbf3dSMarko Kovacevic 				memcpy(prev_prev_out, val.val, TDES_BLOCK_SIZE);
950527cbf3dSMarko Kovacevic 		}
951527cbf3dSMarko Kovacevic 
952527cbf3dSMarko Kovacevic 		info.parse_writeback(&val);
953527cbf3dSMarko Kovacevic 		fprintf(info.fp_wr, "\n");
954527cbf3dSMarko Kovacevic 
955527cbf3dSMarko Kovacevic 		if (i == TDES_EXTERN_ITER - 1)
956527cbf3dSMarko Kovacevic 			continue;
957527cbf3dSMarko Kovacevic 
958527cbf3dSMarko Kovacevic 		/** update key */
959527cbf3dSMarko Kovacevic 		memcpy(&val_key, &vec.cipher_auth.key, sizeof(val_key));
960527cbf3dSMarko Kovacevic 
961527cbf3dSMarko Kovacevic 		if (info.interim_info.tdes_data.nb_keys == 0) {
962527cbf3dSMarko Kovacevic 			if (memcmp(val_key.val, val_key.val + 8, 8) == 0)
963527cbf3dSMarko Kovacevic 				info.interim_info.tdes_data.nb_keys = 1;
964527cbf3dSMarko Kovacevic 			else if (memcmp(val_key.val, val_key.val + 16, 8) == 0)
965527cbf3dSMarko Kovacevic 				info.interim_info.tdes_data.nb_keys = 2;
966527cbf3dSMarko Kovacevic 			else
967527cbf3dSMarko Kovacevic 				info.interim_info.tdes_data.nb_keys = 3;
968527cbf3dSMarko Kovacevic 
969527cbf3dSMarko Kovacevic 		}
970527cbf3dSMarko Kovacevic 
971527cbf3dSMarko Kovacevic 		for (k = 0; k < TDES_BLOCK_SIZE; k++) {
972527cbf3dSMarko Kovacevic 
973527cbf3dSMarko Kovacevic 			switch (info.interim_info.tdes_data.nb_keys) {
974527cbf3dSMarko Kovacevic 			case 3:
975527cbf3dSMarko Kovacevic 				val_key.val[k] ^= val.val[k];
976527cbf3dSMarko Kovacevic 				val_key.val[k + 8] ^= prev_out[k];
977527cbf3dSMarko Kovacevic 				val_key.val[k + 16] ^= prev_prev_out[k];
978527cbf3dSMarko Kovacevic 				break;
979527cbf3dSMarko Kovacevic 			case 2:
980527cbf3dSMarko Kovacevic 				val_key.val[k] ^= val.val[k];
981527cbf3dSMarko Kovacevic 				val_key.val[k + 8] ^= prev_out[k];
982527cbf3dSMarko Kovacevic 				val_key.val[k + 16] ^= val.val[k];
983527cbf3dSMarko Kovacevic 				break;
984527cbf3dSMarko Kovacevic 			default: /* case 1 */
985527cbf3dSMarko Kovacevic 				val_key.val[k] ^= val.val[k];
986527cbf3dSMarko Kovacevic 				val_key.val[k + 8] ^= val.val[k];
987527cbf3dSMarko Kovacevic 				val_key.val[k + 16] ^= val.val[k];
988527cbf3dSMarko Kovacevic 				break;
989527cbf3dSMarko Kovacevic 			}
990527cbf3dSMarko Kovacevic 
991527cbf3dSMarko Kovacevic 		}
992527cbf3dSMarko Kovacevic 
993527cbf3dSMarko Kovacevic 		for (k = 0; k < 24; k++)
994527cbf3dSMarko Kovacevic 			val_key.val[k] = (__builtin_popcount(val_key.val[k]) &
995527cbf3dSMarko Kovacevic 					0x1) ?
996527cbf3dSMarko Kovacevic 					val_key.val[k] : (val_key.val[k] ^ 0x1);
997527cbf3dSMarko Kovacevic 
998527cbf3dSMarko Kovacevic 		if (info.op == FIPS_TEST_ENC_AUTH_GEN) {
999527cbf3dSMarko Kovacevic 			memcpy(vec.iv.val, val.val, TDES_BLOCK_SIZE);
1000527cbf3dSMarko Kovacevic 			memcpy(vec.pt.val, prev_out, TDES_BLOCK_SIZE);
1001527cbf3dSMarko Kovacevic 		} else {
1002527cbf3dSMarko Kovacevic 			memcpy(vec.iv.val, prev_out, TDES_BLOCK_SIZE);
1003527cbf3dSMarko Kovacevic 			memcpy(vec.ct.val, val.val, TDES_BLOCK_SIZE);
1004527cbf3dSMarko Kovacevic 		}
1005527cbf3dSMarko Kovacevic 	}
1006527cbf3dSMarko Kovacevic 
1007527cbf3dSMarko Kovacevic 	return 0;
1008527cbf3dSMarko Kovacevic }
1009527cbf3dSMarko Kovacevic 
1010527cbf3dSMarko Kovacevic static int
1011cd255ccfSMarko Kovacevic fips_mct_aes_test(void)
1012cd255ccfSMarko Kovacevic {
1013cd255ccfSMarko Kovacevic #define AES_BLOCK_SIZE	16
1014cd255ccfSMarko Kovacevic #define AES_EXTERN_ITER	100
1015cd255ccfSMarko Kovacevic #define AES_INTERN_ITER	1000
1016cd255ccfSMarko Kovacevic 	struct fips_val val, val_key;
1017cd255ccfSMarko Kovacevic 	uint8_t prev_out[AES_BLOCK_SIZE] = {0};
1018cd255ccfSMarko Kovacevic 	uint8_t prev_in[AES_BLOCK_SIZE] = {0};
1019cd255ccfSMarko Kovacevic 	uint32_t i, j, k;
1020cd255ccfSMarko Kovacevic 	int ret;
1021cd255ccfSMarko Kovacevic 
1022cd255ccfSMarko Kovacevic 	for (i = 0; i < AES_EXTERN_ITER; i++) {
1023cd255ccfSMarko Kovacevic 		if (i != 0)
1024cd255ccfSMarko Kovacevic 			update_info_vec(i);
1025cd255ccfSMarko Kovacevic 
1026cd255ccfSMarko Kovacevic 		fips_test_write_one_case();
1027cd255ccfSMarko Kovacevic 
1028cd255ccfSMarko Kovacevic 		for (j = 0; j < AES_INTERN_ITER; j++) {
1029cd255ccfSMarko Kovacevic 			ret = fips_run_test();
1030cd255ccfSMarko Kovacevic 			if (ret < 0) {
1031cd255ccfSMarko Kovacevic 				if (ret == -EPERM) {
1032cd255ccfSMarko Kovacevic 					fprintf(info.fp_wr, "Bypass\n");
1033cd255ccfSMarko Kovacevic 					return 0;
1034cd255ccfSMarko Kovacevic 				}
1035cd255ccfSMarko Kovacevic 
1036cd255ccfSMarko Kovacevic 				return ret;
1037cd255ccfSMarko Kovacevic 			}
1038cd255ccfSMarko Kovacevic 
1039cd255ccfSMarko Kovacevic 			get_writeback_data(&val);
1040cd255ccfSMarko Kovacevic 
1041cd255ccfSMarko Kovacevic 			if (info.op == FIPS_TEST_DEC_AUTH_VERIF)
1042cd255ccfSMarko Kovacevic 				memcpy(prev_in, vec.ct.val, AES_BLOCK_SIZE);
1043cd255ccfSMarko Kovacevic 
1044cd255ccfSMarko Kovacevic 			if (j == 0) {
1045cd255ccfSMarko Kovacevic 				memcpy(prev_out, val.val, AES_BLOCK_SIZE);
1046cd255ccfSMarko Kovacevic 
1047cd255ccfSMarko Kovacevic 				if (info.op == FIPS_TEST_ENC_AUTH_GEN) {
1048cd255ccfSMarko Kovacevic 					memcpy(vec.pt.val, vec.iv.val,
1049cd255ccfSMarko Kovacevic 							AES_BLOCK_SIZE);
1050cd255ccfSMarko Kovacevic 					memcpy(vec.iv.val, val.val,
1051cd255ccfSMarko Kovacevic 							AES_BLOCK_SIZE);
1052cd255ccfSMarko Kovacevic 				} else {
1053cd255ccfSMarko Kovacevic 					memcpy(vec.ct.val, vec.iv.val,
1054cd255ccfSMarko Kovacevic 							AES_BLOCK_SIZE);
1055cd255ccfSMarko Kovacevic 					memcpy(vec.iv.val, prev_in,
1056cd255ccfSMarko Kovacevic 							AES_BLOCK_SIZE);
1057cd255ccfSMarko Kovacevic 				}
1058cd255ccfSMarko Kovacevic 				continue;
1059cd255ccfSMarko Kovacevic 			}
1060cd255ccfSMarko Kovacevic 
1061cd255ccfSMarko Kovacevic 			if (info.op == FIPS_TEST_ENC_AUTH_GEN) {
1062cd255ccfSMarko Kovacevic 				memcpy(vec.iv.val, val.val, AES_BLOCK_SIZE);
1063cd255ccfSMarko Kovacevic 				memcpy(vec.pt.val, prev_out, AES_BLOCK_SIZE);
1064cd255ccfSMarko Kovacevic 			} else {
1065cd255ccfSMarko Kovacevic 				memcpy(vec.iv.val, prev_in, AES_BLOCK_SIZE);
1066cd255ccfSMarko Kovacevic 				memcpy(vec.ct.val, prev_out, AES_BLOCK_SIZE);
1067cd255ccfSMarko Kovacevic 			}
1068cd255ccfSMarko Kovacevic 
1069cd255ccfSMarko Kovacevic 			if (j == AES_INTERN_ITER - 1)
1070cd255ccfSMarko Kovacevic 				continue;
1071cd255ccfSMarko Kovacevic 
1072cd255ccfSMarko Kovacevic 			memcpy(prev_out, val.val, AES_BLOCK_SIZE);
1073cd255ccfSMarko Kovacevic 		}
1074cd255ccfSMarko Kovacevic 
1075cd255ccfSMarko Kovacevic 		info.parse_writeback(&val);
1076cd255ccfSMarko Kovacevic 		fprintf(info.fp_wr, "\n");
1077cd255ccfSMarko Kovacevic 
1078cd255ccfSMarko Kovacevic 		if (i == AES_EXTERN_ITER - 1)
1079cd255ccfSMarko Kovacevic 			continue;
1080cd255ccfSMarko Kovacevic 
1081cd255ccfSMarko Kovacevic 		/** update key */
1082cd255ccfSMarko Kovacevic 		memcpy(&val_key, &vec.cipher_auth.key, sizeof(val_key));
1083cd255ccfSMarko Kovacevic 		for (k = 0; k < vec.cipher_auth.key.len; k++) {
1084cd255ccfSMarko Kovacevic 			switch (vec.cipher_auth.key.len) {
1085cd255ccfSMarko Kovacevic 			case 16:
1086cd255ccfSMarko Kovacevic 				val_key.val[k] ^= val.val[k];
1087cd255ccfSMarko Kovacevic 				break;
1088cd255ccfSMarko Kovacevic 			case 24:
1089cd255ccfSMarko Kovacevic 				if (k < 8)
1090cd255ccfSMarko Kovacevic 					val_key.val[k] ^= prev_out[k + 8];
1091cd255ccfSMarko Kovacevic 				else
1092cd255ccfSMarko Kovacevic 					val_key.val[k] ^= val.val[k - 8];
1093cd255ccfSMarko Kovacevic 				break;
1094cd255ccfSMarko Kovacevic 			case 32:
1095cd255ccfSMarko Kovacevic 				if (k < 16)
1096cd255ccfSMarko Kovacevic 					val_key.val[k] ^= prev_out[k];
1097cd255ccfSMarko Kovacevic 				else
1098cd255ccfSMarko Kovacevic 					val_key.val[k] ^= val.val[k - 16];
1099cd255ccfSMarko Kovacevic 				break;
1100cd255ccfSMarko Kovacevic 			default:
1101cd255ccfSMarko Kovacevic 				return -1;
1102cd255ccfSMarko Kovacevic 			}
1103cd255ccfSMarko Kovacevic 		}
1104cd255ccfSMarko Kovacevic 
1105cd255ccfSMarko Kovacevic 		if (info.op == FIPS_TEST_DEC_AUTH_VERIF)
1106cd255ccfSMarko Kovacevic 			memcpy(vec.iv.val, val.val, AES_BLOCK_SIZE);
1107cd255ccfSMarko Kovacevic 	}
1108cd255ccfSMarko Kovacevic 
1109cd255ccfSMarko Kovacevic 	return 0;
1110cd255ccfSMarko Kovacevic }
1111cd255ccfSMarko Kovacevic 
1112cd255ccfSMarko Kovacevic static int
1113cd255ccfSMarko Kovacevic init_test_ops(void)
1114cd255ccfSMarko Kovacevic {
1115cd255ccfSMarko Kovacevic 	switch (info.algo) {
1116cd255ccfSMarko Kovacevic 	case FIPS_TEST_ALGO_AES:
1117cd255ccfSMarko Kovacevic 		test_ops.prepare_op = prepare_cipher_op;
1118cd255ccfSMarko Kovacevic 		test_ops.prepare_xform  = prepare_aes_xform;
1119cd255ccfSMarko Kovacevic 		if (info.interim_info.aes_data.test_type == AESAVS_TYPE_MCT)
1120cd255ccfSMarko Kovacevic 			test_ops.test = fips_mct_aes_test;
1121cd255ccfSMarko Kovacevic 		else
1122cd255ccfSMarko Kovacevic 			test_ops.test = fips_generic_test;
1123cd255ccfSMarko Kovacevic 		break;
1124f64adb67SMarko Kovacevic 	case FIPS_TEST_ALGO_HMAC:
1125f64adb67SMarko Kovacevic 		test_ops.prepare_op = prepare_auth_op;
1126f64adb67SMarko Kovacevic 		test_ops.prepare_xform = prepare_hmac_xform;
1127f64adb67SMarko Kovacevic 		test_ops.test = fips_generic_test;
1128f64adb67SMarko Kovacevic 		break;
1129527cbf3dSMarko Kovacevic 	case FIPS_TEST_ALGO_TDES:
1130527cbf3dSMarko Kovacevic 		test_ops.prepare_op = prepare_cipher_op;
1131527cbf3dSMarko Kovacevic 		test_ops.prepare_xform  = prepare_tdes_xform;
1132527cbf3dSMarko Kovacevic 		if (info.interim_info.tdes_data.test_type == TDES_MCT)
1133527cbf3dSMarko Kovacevic 			test_ops.test = fips_mct_tdes_test;
1134527cbf3dSMarko Kovacevic 		else
1135527cbf3dSMarko Kovacevic 			test_ops.test = fips_generic_test;
1136527cbf3dSMarko Kovacevic 		break;
11374aaad299SMarko Kovacevic 	case FIPS_TEST_ALGO_AES_GCM:
11384aaad299SMarko Kovacevic 		test_ops.prepare_op = prepare_aead_op;
11394aaad299SMarko Kovacevic 		test_ops.prepare_xform = prepare_gcm_xform;
11404aaad299SMarko Kovacevic 		test_ops.test = fips_generic_test;
11414aaad299SMarko Kovacevic 		break;
1142ac026f46SMarko Kovacevic 	case FIPS_TEST_ALGO_AES_CMAC:
1143ac026f46SMarko Kovacevic 		test_ops.prepare_op = prepare_auth_op;
1144ac026f46SMarko Kovacevic 		test_ops.prepare_xform = prepare_cmac_xform;
1145ac026f46SMarko Kovacevic 		test_ops.test = fips_generic_test;
1146ac026f46SMarko Kovacevic 		break;
1147305921f4SMarko Kovacevic 	case FIPS_TEST_ALGO_AES_CCM:
1148305921f4SMarko Kovacevic 		test_ops.prepare_op = prepare_aead_op;
1149305921f4SMarko Kovacevic 		test_ops.prepare_xform = prepare_ccm_xform;
1150305921f4SMarko Kovacevic 		test_ops.test = fips_generic_test;
1151305921f4SMarko Kovacevic 		break;
1152cd255ccfSMarko Kovacevic 	default:
1153cd255ccfSMarko Kovacevic 		return -1;
1154cd255ccfSMarko Kovacevic 	}
1155cd255ccfSMarko Kovacevic 
1156cd255ccfSMarko Kovacevic 	return 0;
1157cd255ccfSMarko Kovacevic }
1158cd255ccfSMarko Kovacevic 
11593d0fad56SMarko Kovacevic static void
11603d0fad56SMarko Kovacevic print_test_block(void)
11613d0fad56SMarko Kovacevic {
11623d0fad56SMarko Kovacevic 	uint32_t i;
11633d0fad56SMarko Kovacevic 
11643d0fad56SMarko Kovacevic 	for (i = 0; i < info.nb_vec_lines; i++)
11653d0fad56SMarko Kovacevic 		printf("%s\n", info.vec[i]);
11663d0fad56SMarko Kovacevic 
11673d0fad56SMarko Kovacevic 	printf("\n");
11683d0fad56SMarko Kovacevic }
11693d0fad56SMarko Kovacevic 
11703d0fad56SMarko Kovacevic static int
11713d0fad56SMarko Kovacevic fips_test_one_file(void)
11723d0fad56SMarko Kovacevic {
11733d0fad56SMarko Kovacevic 	int fetch_ret = 0, ret;
11743d0fad56SMarko Kovacevic 
1175cd255ccfSMarko Kovacevic 
1176cd255ccfSMarko Kovacevic 	ret = init_test_ops();
1177cd255ccfSMarko Kovacevic 	if (ret < 0) {
1178cd255ccfSMarko Kovacevic 		RTE_LOG(ERR, USER1, "Error %i: Init test op\n", ret);
1179cd255ccfSMarko Kovacevic 		return ret;
1180cd255ccfSMarko Kovacevic 	}
1181cd255ccfSMarko Kovacevic 
1182cd255ccfSMarko Kovacevic 	while (ret >= 0 && fetch_ret == 0) {
11833d0fad56SMarko Kovacevic 		fetch_ret = fips_test_fetch_one_block();
11843d0fad56SMarko Kovacevic 		if (fetch_ret < 0) {
11853d0fad56SMarko Kovacevic 			RTE_LOG(ERR, USER1, "Error %i: Fetch block\n",
11863d0fad56SMarko Kovacevic 					fetch_ret);
11873d0fad56SMarko Kovacevic 			ret = fetch_ret;
11883d0fad56SMarko Kovacevic 			goto error_one_case;
11893d0fad56SMarko Kovacevic 		}
11903d0fad56SMarko Kovacevic 
11913d0fad56SMarko Kovacevic 		if (info.nb_vec_lines == 0) {
11923d0fad56SMarko Kovacevic 			if (fetch_ret == -EOF)
11933d0fad56SMarko Kovacevic 				break;
11943d0fad56SMarko Kovacevic 
11953d0fad56SMarko Kovacevic 			fprintf(info.fp_wr, "\n");
11963d0fad56SMarko Kovacevic 			continue;
11973d0fad56SMarko Kovacevic 		}
11983d0fad56SMarko Kovacevic 
11993d0fad56SMarko Kovacevic 		ret = fips_test_parse_one_case();
12003d0fad56SMarko Kovacevic 		switch (ret) {
12013d0fad56SMarko Kovacevic 		case 0:
1202cd255ccfSMarko Kovacevic 			ret = test_ops.test();
12033d0fad56SMarko Kovacevic 			if (ret == 0)
12043d0fad56SMarko Kovacevic 				break;
12053d0fad56SMarko Kovacevic 			RTE_LOG(ERR, USER1, "Error %i: test block\n",
12063d0fad56SMarko Kovacevic 					ret);
12073d0fad56SMarko Kovacevic 			goto error_one_case;
12083d0fad56SMarko Kovacevic 		case 1:
12093d0fad56SMarko Kovacevic 			break;
12103d0fad56SMarko Kovacevic 		default:
12113d0fad56SMarko Kovacevic 			RTE_LOG(ERR, USER1, "Error %i: Parse block\n",
12123d0fad56SMarko Kovacevic 					ret);
12133d0fad56SMarko Kovacevic 			goto error_one_case;
12143d0fad56SMarko Kovacevic 		}
12153d0fad56SMarko Kovacevic 
12163d0fad56SMarko Kovacevic 		continue;
12173d0fad56SMarko Kovacevic error_one_case:
12183d0fad56SMarko Kovacevic 		print_test_block();
12193d0fad56SMarko Kovacevic 	}
12203d0fad56SMarko Kovacevic 
12213d0fad56SMarko Kovacevic 	fips_test_clear();
12223d0fad56SMarko Kovacevic 
1223cd255ccfSMarko Kovacevic 	return ret;
1224cd255ccfSMarko Kovacevic 
12253d0fad56SMarko Kovacevic }
1226