xref: /dpdk/examples/fips_validation/main.c (revision f64adb6714e07daf2a1d4fe3ee3172f3f4a80c07)
13d0fad56SMarko Kovacevic /* SPDX-License-Identifier: BSD-3-Clause
23d0fad56SMarko Kovacevic  * Copyright(c) 2018 Intel Corporation
33d0fad56SMarko Kovacevic  */
43d0fad56SMarko Kovacevic 
53d0fad56SMarko Kovacevic #include <sys/stat.h>
63d0fad56SMarko Kovacevic #include <getopt.h>
73d0fad56SMarko Kovacevic #include <dirent.h>
83d0fad56SMarko Kovacevic 
93d0fad56SMarko Kovacevic #include <rte_cryptodev.h>
103d0fad56SMarko Kovacevic #include <rte_cryptodev_pmd.h>
113d0fad56SMarko Kovacevic #include <rte_mempool.h>
123d0fad56SMarko Kovacevic #include <rte_mbuf.h>
133d0fad56SMarko Kovacevic #include <rte_string_fns.h>
143d0fad56SMarko Kovacevic 
153d0fad56SMarko Kovacevic #include "fips_validation.h"
163d0fad56SMarko Kovacevic 
173d0fad56SMarko Kovacevic #define REQ_FILE_PATH_KEYWORD	"req-file"
183d0fad56SMarko Kovacevic #define RSP_FILE_PATH_KEYWORD	"rsp-file"
193d0fad56SMarko Kovacevic #define FOLDER_KEYWORD		"path-is-folder"
203d0fad56SMarko Kovacevic #define CRYPTODEV_KEYWORD	"cryptodev"
213d0fad56SMarko Kovacevic #define CRYPTODEV_ID_KEYWORD	"cryptodev-id"
223d0fad56SMarko Kovacevic 
233d0fad56SMarko Kovacevic struct fips_test_vector vec;
243d0fad56SMarko Kovacevic struct fips_test_interim_info info;
253d0fad56SMarko Kovacevic 
263d0fad56SMarko Kovacevic struct cryptodev_fips_validate_env {
273d0fad56SMarko Kovacevic 	const char *req_path;
283d0fad56SMarko Kovacevic 	const char *rsp_path;
293d0fad56SMarko Kovacevic 	uint32_t is_path_folder;
303d0fad56SMarko Kovacevic 	uint32_t dev_id;
313d0fad56SMarko Kovacevic 	struct rte_mempool *mpool;
323d0fad56SMarko Kovacevic 	struct rte_mempool *op_pool;
333d0fad56SMarko Kovacevic 	struct rte_mbuf *mbuf;
343d0fad56SMarko Kovacevic 	struct rte_crypto_op *op;
353d0fad56SMarko Kovacevic 	struct rte_cryptodev_sym_session *sess;
363d0fad56SMarko Kovacevic } env;
373d0fad56SMarko Kovacevic 
383d0fad56SMarko Kovacevic static int
393d0fad56SMarko Kovacevic cryptodev_fips_validate_app_int(void)
403d0fad56SMarko Kovacevic {
413d0fad56SMarko Kovacevic 	struct rte_cryptodev_config conf = {rte_socket_id(), 1};
423d0fad56SMarko Kovacevic 	struct rte_cryptodev_qp_conf qp_conf = {128};
433d0fad56SMarko Kovacevic 	int ret;
443d0fad56SMarko Kovacevic 
453d0fad56SMarko Kovacevic 	ret = rte_cryptodev_configure(env.dev_id, &conf);
463d0fad56SMarko Kovacevic 	if (ret < 0)
473d0fad56SMarko Kovacevic 		return ret;
483d0fad56SMarko Kovacevic 
493d0fad56SMarko Kovacevic 	env.mpool = rte_pktmbuf_pool_create("FIPS_MEMPOOL", 128, 0, 0,
503d0fad56SMarko Kovacevic 			UINT16_MAX, rte_socket_id());
513d0fad56SMarko Kovacevic 	if (!env.mpool)
523d0fad56SMarko Kovacevic 		return ret;
533d0fad56SMarko Kovacevic 
543d0fad56SMarko Kovacevic 	ret = rte_cryptodev_queue_pair_setup(env.dev_id, 0, &qp_conf,
553d0fad56SMarko Kovacevic 			rte_socket_id(), env.mpool);
563d0fad56SMarko Kovacevic 	if (ret < 0)
573d0fad56SMarko Kovacevic 		return ret;
583d0fad56SMarko Kovacevic 
593d0fad56SMarko Kovacevic 	ret = -ENOMEM;
603d0fad56SMarko Kovacevic 
613d0fad56SMarko Kovacevic 	env.op_pool = rte_crypto_op_pool_create(
623d0fad56SMarko Kovacevic 			"FIPS_OP_POOL",
633d0fad56SMarko Kovacevic 			RTE_CRYPTO_OP_TYPE_SYMMETRIC,
643d0fad56SMarko Kovacevic 			1, 0,
653d0fad56SMarko Kovacevic 			16,
663d0fad56SMarko Kovacevic 			rte_socket_id());
673d0fad56SMarko Kovacevic 	if (!env.op_pool)
683d0fad56SMarko Kovacevic 		goto error_exit;
693d0fad56SMarko Kovacevic 
703d0fad56SMarko Kovacevic 	env.mbuf = rte_pktmbuf_alloc(env.mpool);
713d0fad56SMarko Kovacevic 	if (!env.mbuf)
723d0fad56SMarko Kovacevic 		goto error_exit;
733d0fad56SMarko Kovacevic 
743d0fad56SMarko Kovacevic 	env.op = rte_crypto_op_alloc(env.op_pool, RTE_CRYPTO_OP_TYPE_SYMMETRIC);
753d0fad56SMarko Kovacevic 	if (!env.op)
763d0fad56SMarko Kovacevic 		goto error_exit;
773d0fad56SMarko Kovacevic 
783d0fad56SMarko Kovacevic 	return 0;
793d0fad56SMarko Kovacevic 
803d0fad56SMarko Kovacevic error_exit:
813d0fad56SMarko Kovacevic 	rte_mempool_free(env.mpool);
823d0fad56SMarko Kovacevic 	if (env.op_pool)
833d0fad56SMarko Kovacevic 		rte_mempool_free(env.op_pool);
843d0fad56SMarko Kovacevic 
853d0fad56SMarko Kovacevic 	return ret;
863d0fad56SMarko Kovacevic }
873d0fad56SMarko Kovacevic 
883d0fad56SMarko Kovacevic static void
893d0fad56SMarko Kovacevic cryptodev_fips_validate_app_uninit(void)
903d0fad56SMarko Kovacevic {
913d0fad56SMarko Kovacevic 	rte_pktmbuf_free(env.mbuf);
923d0fad56SMarko Kovacevic 	rte_crypto_op_free(env.op);
933d0fad56SMarko Kovacevic 	rte_cryptodev_sym_session_clear(env.dev_id, env.sess);
943d0fad56SMarko Kovacevic 	rte_cryptodev_sym_session_free(env.sess);
953d0fad56SMarko Kovacevic 	rte_mempool_free(env.mpool);
963d0fad56SMarko Kovacevic 	rte_mempool_free(env.op_pool);
973d0fad56SMarko Kovacevic }
983d0fad56SMarko Kovacevic 
993d0fad56SMarko Kovacevic static int
1003d0fad56SMarko Kovacevic fips_test_one_file(void);
1013d0fad56SMarko Kovacevic 
1023d0fad56SMarko Kovacevic static int
1033d0fad56SMarko Kovacevic parse_cryptodev_arg(char *arg)
1043d0fad56SMarko Kovacevic {
1053d0fad56SMarko Kovacevic 	int id = rte_cryptodev_get_dev_id(arg);
1063d0fad56SMarko Kovacevic 
1073d0fad56SMarko Kovacevic 	if (id < 0) {
1083d0fad56SMarko Kovacevic 		RTE_LOG(ERR, USER1, "Error %i: invalid cryptodev name %s\n",
1093d0fad56SMarko Kovacevic 				id, arg);
1103d0fad56SMarko Kovacevic 		return id;
1113d0fad56SMarko Kovacevic 	}
1123d0fad56SMarko Kovacevic 
1133d0fad56SMarko Kovacevic 	env.dev_id = (uint32_t)id;
1143d0fad56SMarko Kovacevic 
1153d0fad56SMarko Kovacevic 	return 0;
1163d0fad56SMarko Kovacevic }
1173d0fad56SMarko Kovacevic 
1183d0fad56SMarko Kovacevic static int
1193d0fad56SMarko Kovacevic parse_cryptodev_id_arg(char *arg)
1203d0fad56SMarko Kovacevic {
1213d0fad56SMarko Kovacevic 	uint32_t cryptodev_id;
1223d0fad56SMarko Kovacevic 
1233d0fad56SMarko Kovacevic 	if (parser_read_uint32(&cryptodev_id, arg) < 0) {
1243d0fad56SMarko Kovacevic 		RTE_LOG(ERR, USER1, "Error %i: invalid cryptodev id %s\n",
1253d0fad56SMarko Kovacevic 				-EINVAL, arg);
1263d0fad56SMarko Kovacevic 		return -1;
1273d0fad56SMarko Kovacevic 	}
1283d0fad56SMarko Kovacevic 
1293d0fad56SMarko Kovacevic 
1303d0fad56SMarko Kovacevic 	if (!rte_cryptodev_pmd_is_valid_dev(cryptodev_id)) {
1313d0fad56SMarko Kovacevic 		RTE_LOG(ERR, USER1, "Error %i: invalid cryptodev id %s\n",
1323d0fad56SMarko Kovacevic 				cryptodev_id, arg);
1333d0fad56SMarko Kovacevic 		return -1;
1343d0fad56SMarko Kovacevic 	}
1353d0fad56SMarko Kovacevic 
1363d0fad56SMarko Kovacevic 	env.dev_id = (uint32_t)cryptodev_id;
1373d0fad56SMarko Kovacevic 
1383d0fad56SMarko Kovacevic 	return 0;
1393d0fad56SMarko Kovacevic }
1403d0fad56SMarko Kovacevic 
1413d0fad56SMarko Kovacevic static void
1423d0fad56SMarko Kovacevic cryptodev_fips_validate_usage(const char *prgname)
1433d0fad56SMarko Kovacevic {
1443d0fad56SMarko Kovacevic 	printf("%s [EAL options] --\n"
1453d0fad56SMarko Kovacevic 		"  --%s: REQUEST-FILE-PATH\n"
1463d0fad56SMarko Kovacevic 		"  --%s: RESPONSE-FILE-PATH\n"
1473d0fad56SMarko Kovacevic 		"  --%s: indicating both paths are folders\n"
1483d0fad56SMarko Kovacevic 		"  --%s: CRYPTODEV-NAME\n"
1493d0fad56SMarko Kovacevic 		"  --%s: CRYPTODEV-ID-NAME\n",
1503d0fad56SMarko Kovacevic 		prgname, REQ_FILE_PATH_KEYWORD, RSP_FILE_PATH_KEYWORD,
1513d0fad56SMarko Kovacevic 		FOLDER_KEYWORD, CRYPTODEV_KEYWORD, CRYPTODEV_ID_KEYWORD);
1523d0fad56SMarko Kovacevic }
1533d0fad56SMarko Kovacevic 
1543d0fad56SMarko Kovacevic static int
1553d0fad56SMarko Kovacevic cryptodev_fips_validate_parse_args(int argc, char **argv)
1563d0fad56SMarko Kovacevic {
1573d0fad56SMarko Kovacevic 	int opt, ret;
1583d0fad56SMarko Kovacevic 	char *prgname = argv[0];
1593d0fad56SMarko Kovacevic 	char **argvopt;
1603d0fad56SMarko Kovacevic 	int option_index;
1613d0fad56SMarko Kovacevic 	struct option lgopts[] = {
1623d0fad56SMarko Kovacevic 			{REQ_FILE_PATH_KEYWORD, required_argument, 0, 0},
1633d0fad56SMarko Kovacevic 			{RSP_FILE_PATH_KEYWORD, required_argument, 0, 0},
1643d0fad56SMarko Kovacevic 			{FOLDER_KEYWORD, no_argument, 0, 0},
1653d0fad56SMarko Kovacevic 			{CRYPTODEV_KEYWORD, required_argument, 0, 0},
1663d0fad56SMarko Kovacevic 			{CRYPTODEV_ID_KEYWORD, required_argument, 0, 0},
1673d0fad56SMarko Kovacevic 			{NULL, 0, 0, 0}
1683d0fad56SMarko Kovacevic 	};
1693d0fad56SMarko Kovacevic 
1703d0fad56SMarko Kovacevic 	argvopt = argv;
1713d0fad56SMarko Kovacevic 
1723d0fad56SMarko Kovacevic 	while ((opt = getopt_long(argc, argvopt, "s:",
1733d0fad56SMarko Kovacevic 				  lgopts, &option_index)) != EOF) {
1743d0fad56SMarko Kovacevic 
1753d0fad56SMarko Kovacevic 		switch (opt) {
1763d0fad56SMarko Kovacevic 		case 0:
1773d0fad56SMarko Kovacevic 			if (strcmp(lgopts[option_index].name,
1783d0fad56SMarko Kovacevic 					REQ_FILE_PATH_KEYWORD) == 0)
1793d0fad56SMarko Kovacevic 				env.req_path = optarg;
1803d0fad56SMarko Kovacevic 			else if (strcmp(lgopts[option_index].name,
1813d0fad56SMarko Kovacevic 					RSP_FILE_PATH_KEYWORD) == 0)
1823d0fad56SMarko Kovacevic 				env.rsp_path = optarg;
1833d0fad56SMarko Kovacevic 			else if (strcmp(lgopts[option_index].name,
1843d0fad56SMarko Kovacevic 					FOLDER_KEYWORD) == 0)
1853d0fad56SMarko Kovacevic 				env.is_path_folder = 1;
1863d0fad56SMarko Kovacevic 			else if (strcmp(lgopts[option_index].name,
1873d0fad56SMarko Kovacevic 					CRYPTODEV_KEYWORD) == 0) {
1883d0fad56SMarko Kovacevic 				ret = parse_cryptodev_arg(optarg);
1893d0fad56SMarko Kovacevic 				if (ret < 0) {
1903d0fad56SMarko Kovacevic 					cryptodev_fips_validate_usage(prgname);
1913d0fad56SMarko Kovacevic 					return -EINVAL;
1923d0fad56SMarko Kovacevic 				}
1933d0fad56SMarko Kovacevic 			} else if (strcmp(lgopts[option_index].name,
1943d0fad56SMarko Kovacevic 					CRYPTODEV_ID_KEYWORD) == 0) {
1953d0fad56SMarko Kovacevic 				ret = parse_cryptodev_id_arg(optarg);
1963d0fad56SMarko Kovacevic 				if (ret < 0) {
1973d0fad56SMarko Kovacevic 					cryptodev_fips_validate_usage(prgname);
1983d0fad56SMarko Kovacevic 					return -EINVAL;
1993d0fad56SMarko Kovacevic 				}
2003d0fad56SMarko Kovacevic 			} else {
2013d0fad56SMarko Kovacevic 				cryptodev_fips_validate_usage(prgname);
2023d0fad56SMarko Kovacevic 				return -EINVAL;
2033d0fad56SMarko Kovacevic 			}
2043d0fad56SMarko Kovacevic 			break;
2053d0fad56SMarko Kovacevic 		default:
2063d0fad56SMarko Kovacevic 			return -1;
2073d0fad56SMarko Kovacevic 		}
2083d0fad56SMarko Kovacevic 	}
2093d0fad56SMarko Kovacevic 
2103d0fad56SMarko Kovacevic 	if (env.req_path == NULL || env.rsp_path == NULL ||
2113d0fad56SMarko Kovacevic 			env.dev_id == UINT32_MAX) {
2123d0fad56SMarko Kovacevic 		cryptodev_fips_validate_usage(prgname);
2133d0fad56SMarko Kovacevic 		return -EINVAL;
2143d0fad56SMarko Kovacevic 	}
2153d0fad56SMarko Kovacevic 
2163d0fad56SMarko Kovacevic 	return 0;
2173d0fad56SMarko Kovacevic }
2183d0fad56SMarko Kovacevic 
2193d0fad56SMarko Kovacevic int
2203d0fad56SMarko Kovacevic main(int argc, char *argv[])
2213d0fad56SMarko Kovacevic {
2223d0fad56SMarko Kovacevic 	int ret;
2233d0fad56SMarko Kovacevic 
2243d0fad56SMarko Kovacevic 	ret = rte_eal_init(argc, argv);
2253d0fad56SMarko Kovacevic 	if (ret < 0) {
2263d0fad56SMarko Kovacevic 		RTE_LOG(ERR, USER1, "Error %i: Failed init\n", ret);
2273d0fad56SMarko Kovacevic 		return -1;
2283d0fad56SMarko Kovacevic 	}
2293d0fad56SMarko Kovacevic 
2303d0fad56SMarko Kovacevic 	argc -= ret;
2313d0fad56SMarko Kovacevic 	argv += ret;
2323d0fad56SMarko Kovacevic 
2333d0fad56SMarko Kovacevic 	ret = cryptodev_fips_validate_parse_args(argc, argv);
2343d0fad56SMarko Kovacevic 	if (ret < 0)
2353d0fad56SMarko Kovacevic 		rte_exit(EXIT_FAILURE, "Failed to parse arguments!\n");
2363d0fad56SMarko Kovacevic 
2373d0fad56SMarko Kovacevic 	ret = cryptodev_fips_validate_app_int();
2383d0fad56SMarko Kovacevic 	if (ret < 0) {
2393d0fad56SMarko Kovacevic 		RTE_LOG(ERR, USER1, "Error %i: Failed init\n", ret);
2403d0fad56SMarko Kovacevic 		return -1;
2413d0fad56SMarko Kovacevic 	}
2423d0fad56SMarko Kovacevic 
2433d0fad56SMarko Kovacevic 	if (!env.is_path_folder) {
2443d0fad56SMarko Kovacevic 		printf("Processing file %s... ", env.req_path);
2453d0fad56SMarko Kovacevic 
2463d0fad56SMarko Kovacevic 		ret = fips_test_init(env.req_path, env.rsp_path,
2473d0fad56SMarko Kovacevic 			rte_cryptodev_name_get(env.dev_id));
2483d0fad56SMarko Kovacevic 		if (ret < 0) {
2493d0fad56SMarko Kovacevic 			RTE_LOG(ERR, USER1, "Error %i: Failed test %s\n",
2503d0fad56SMarko Kovacevic 					ret, env.req_path);
2513d0fad56SMarko Kovacevic 			goto exit;
2523d0fad56SMarko Kovacevic 		}
2533d0fad56SMarko Kovacevic 
2543d0fad56SMarko Kovacevic 
2553d0fad56SMarko Kovacevic 		ret = fips_test_one_file();
2563d0fad56SMarko Kovacevic 		if (ret < 0) {
2573d0fad56SMarko Kovacevic 			RTE_LOG(ERR, USER1, "Error %i: Failed test %s\n",
2583d0fad56SMarko Kovacevic 					ret, env.req_path);
2593d0fad56SMarko Kovacevic 			goto exit;
2603d0fad56SMarko Kovacevic 		}
2613d0fad56SMarko Kovacevic 
2623d0fad56SMarko Kovacevic 		printf("Done\n");
2633d0fad56SMarko Kovacevic 
2643d0fad56SMarko Kovacevic 	} else {
2653d0fad56SMarko Kovacevic 		struct dirent *dir;
2663d0fad56SMarko Kovacevic 		DIR *d_req, *d_rsp;
2673d0fad56SMarko Kovacevic 		char req_path[1024];
2683d0fad56SMarko Kovacevic 		char rsp_path[1024];
2693d0fad56SMarko Kovacevic 
2703d0fad56SMarko Kovacevic 		d_req = opendir(env.req_path);
2713d0fad56SMarko Kovacevic 		if (!d_req) {
2723d0fad56SMarko Kovacevic 			RTE_LOG(ERR, USER1, "Error %i: Path %s not exist\n",
2733d0fad56SMarko Kovacevic 					-EINVAL, env.req_path);
2743d0fad56SMarko Kovacevic 			goto exit;
2753d0fad56SMarko Kovacevic 		}
2763d0fad56SMarko Kovacevic 
2773d0fad56SMarko Kovacevic 		d_rsp = opendir(env.rsp_path);
2783d0fad56SMarko Kovacevic 		if (!d_rsp) {
2793d0fad56SMarko Kovacevic 			ret = mkdir(env.rsp_path, 0700);
2803d0fad56SMarko Kovacevic 			if (ret == 0)
2813d0fad56SMarko Kovacevic 				d_rsp = opendir(env.rsp_path);
2823d0fad56SMarko Kovacevic 			else {
2833d0fad56SMarko Kovacevic 				RTE_LOG(ERR, USER1, "Error %i: Invalid %s\n",
2843d0fad56SMarko Kovacevic 						-EINVAL, env.rsp_path);
2853d0fad56SMarko Kovacevic 				goto exit;
2863d0fad56SMarko Kovacevic 			}
2873d0fad56SMarko Kovacevic 		}
2883d0fad56SMarko Kovacevic 		closedir(d_rsp);
2893d0fad56SMarko Kovacevic 
2903d0fad56SMarko Kovacevic 		while ((dir = readdir(d_req)) != NULL) {
2913d0fad56SMarko Kovacevic 			if (strstr(dir->d_name, "req") == NULL)
2923d0fad56SMarko Kovacevic 				continue;
2933d0fad56SMarko Kovacevic 
2943d0fad56SMarko Kovacevic 			snprintf(req_path, 1023, "%s/%s", env.req_path,
2953d0fad56SMarko Kovacevic 					dir->d_name);
2963d0fad56SMarko Kovacevic 			snprintf(rsp_path, 1023, "%s/%s", env.rsp_path,
2973d0fad56SMarko Kovacevic 					dir->d_name);
2983d0fad56SMarko Kovacevic 			strlcpy(strstr(rsp_path, "req"), "rsp", 4);
2993d0fad56SMarko Kovacevic 
3003d0fad56SMarko Kovacevic 			printf("Processing file %s... ", req_path);
3013d0fad56SMarko Kovacevic 
3023d0fad56SMarko Kovacevic 			ret = fips_test_init(req_path, rsp_path,
3033d0fad56SMarko Kovacevic 			rte_cryptodev_name_get(env.dev_id));
3043d0fad56SMarko Kovacevic 			if (ret < 0) {
3053d0fad56SMarko Kovacevic 				RTE_LOG(ERR, USER1, "Error %i: Failed test %s\n",
3063d0fad56SMarko Kovacevic 						ret, req_path);
3073d0fad56SMarko Kovacevic 				break;
3083d0fad56SMarko Kovacevic 			}
3093d0fad56SMarko Kovacevic 
3103d0fad56SMarko Kovacevic 			ret = fips_test_one_file();
3113d0fad56SMarko Kovacevic 			if (ret < 0) {
3123d0fad56SMarko Kovacevic 				RTE_LOG(ERR, USER1, "Error %i: Failed test %s\n",
3133d0fad56SMarko Kovacevic 						ret, req_path);
3143d0fad56SMarko Kovacevic 				break;
3153d0fad56SMarko Kovacevic 			}
3163d0fad56SMarko Kovacevic 
3173d0fad56SMarko Kovacevic 			printf("Done\n");
3183d0fad56SMarko Kovacevic 		}
3193d0fad56SMarko Kovacevic 
3203d0fad56SMarko Kovacevic 		closedir(d_req);
3213d0fad56SMarko Kovacevic 	}
3223d0fad56SMarko Kovacevic 
3233d0fad56SMarko Kovacevic 
3243d0fad56SMarko Kovacevic exit:
3253d0fad56SMarko Kovacevic 	fips_test_clear();
3263d0fad56SMarko Kovacevic 	cryptodev_fips_validate_app_uninit();
3273d0fad56SMarko Kovacevic 
3283d0fad56SMarko Kovacevic 	return ret;
3293d0fad56SMarko Kovacevic 
3303d0fad56SMarko Kovacevic }
3313d0fad56SMarko Kovacevic 
332cd255ccfSMarko Kovacevic #define IV_OFF (sizeof(struct rte_crypto_op) + sizeof(struct rte_crypto_sym_op))
333cd255ccfSMarko Kovacevic #define CRYPTODEV_FIPS_MAX_RETRIES	16
334cd255ccfSMarko Kovacevic 
335cd255ccfSMarko Kovacevic typedef int (*fips_test_one_case_t)(void);
336cd255ccfSMarko Kovacevic typedef int (*fips_prepare_op_t)(void);
337cd255ccfSMarko Kovacevic typedef int (*fips_prepare_xform_t)(struct rte_crypto_sym_xform *);
338cd255ccfSMarko Kovacevic 
339cd255ccfSMarko Kovacevic struct fips_test_ops {
340cd255ccfSMarko Kovacevic 	fips_prepare_xform_t prepare_xform;
341cd255ccfSMarko Kovacevic 	fips_prepare_op_t prepare_op;
342cd255ccfSMarko Kovacevic 	fips_test_one_case_t test;
343cd255ccfSMarko Kovacevic } test_ops;
344cd255ccfSMarko Kovacevic 
345cd255ccfSMarko Kovacevic static int
346cd255ccfSMarko Kovacevic prepare_cipher_op(void)
347cd255ccfSMarko Kovacevic {
348cd255ccfSMarko Kovacevic 	struct rte_crypto_sym_op *sym = env.op->sym;
349cd255ccfSMarko Kovacevic 	uint8_t *iv = rte_crypto_op_ctod_offset(env.op, uint8_t *, IV_OFF);
350cd255ccfSMarko Kovacevic 
351cd255ccfSMarko Kovacevic 	__rte_crypto_op_reset(env.op, RTE_CRYPTO_OP_TYPE_SYMMETRIC);
352cd255ccfSMarko Kovacevic 	rte_pktmbuf_reset(env.mbuf);
353cd255ccfSMarko Kovacevic 
354cd255ccfSMarko Kovacevic 	sym->m_src = env.mbuf;
355cd255ccfSMarko Kovacevic 	sym->cipher.data.offset = 0;
356cd255ccfSMarko Kovacevic 
357cd255ccfSMarko Kovacevic 	memcpy(iv, vec.iv.val, vec.iv.len);
358cd255ccfSMarko Kovacevic 
359cd255ccfSMarko Kovacevic 	if (info.op == FIPS_TEST_ENC_AUTH_GEN) {
360cd255ccfSMarko Kovacevic 		uint8_t *pt;
361cd255ccfSMarko Kovacevic 
362cd255ccfSMarko Kovacevic 		if (vec.pt.len > RTE_MBUF_MAX_NB_SEGS) {
363cd255ccfSMarko Kovacevic 			RTE_LOG(ERR, USER1, "PT len %u\n", vec.pt.len);
364cd255ccfSMarko Kovacevic 			return -EPERM;
365cd255ccfSMarko Kovacevic 		}
366cd255ccfSMarko Kovacevic 
367cd255ccfSMarko Kovacevic 		pt = (uint8_t *)rte_pktmbuf_append(env.mbuf, vec.pt.len);
368cd255ccfSMarko Kovacevic 
369cd255ccfSMarko Kovacevic 		if (!pt) {
370cd255ccfSMarko Kovacevic 			RTE_LOG(ERR, USER1, "Error %i: MBUF too small\n",
371cd255ccfSMarko Kovacevic 					-ENOMEM);
372cd255ccfSMarko Kovacevic 			return -ENOMEM;
373cd255ccfSMarko Kovacevic 		}
374cd255ccfSMarko Kovacevic 
375cd255ccfSMarko Kovacevic 		memcpy(pt, vec.pt.val, vec.pt.len);
376cd255ccfSMarko Kovacevic 		sym->cipher.data.length = vec.pt.len;
377cd255ccfSMarko Kovacevic 
378cd255ccfSMarko Kovacevic 	} else {
379cd255ccfSMarko Kovacevic 		uint8_t *ct;
380cd255ccfSMarko Kovacevic 
381cd255ccfSMarko Kovacevic 		if (vec.ct.len > RTE_MBUF_MAX_NB_SEGS) {
382cd255ccfSMarko Kovacevic 			RTE_LOG(ERR, USER1, "CT len %u\n", vec.ct.len);
383cd255ccfSMarko Kovacevic 			return -EPERM;
384cd255ccfSMarko Kovacevic 		}
385cd255ccfSMarko Kovacevic 
386cd255ccfSMarko Kovacevic 		ct = (uint8_t *)rte_pktmbuf_append(env.mbuf, vec.ct.len);
387cd255ccfSMarko Kovacevic 
388cd255ccfSMarko Kovacevic 		if (!ct) {
389cd255ccfSMarko Kovacevic 			RTE_LOG(ERR, USER1, "Error %i: MBUF too small\n",
390cd255ccfSMarko Kovacevic 					-ENOMEM);
391cd255ccfSMarko Kovacevic 			return -ENOMEM;
392cd255ccfSMarko Kovacevic 		}
393cd255ccfSMarko Kovacevic 
394cd255ccfSMarko Kovacevic 		memcpy(ct, vec.ct.val, vec.ct.len);
395cd255ccfSMarko Kovacevic 		sym->cipher.data.length = vec.ct.len;
396cd255ccfSMarko Kovacevic 	}
397cd255ccfSMarko Kovacevic 
398cd255ccfSMarko Kovacevic 	rte_crypto_op_attach_sym_session(env.op, env.sess);
399cd255ccfSMarko Kovacevic 
400cd255ccfSMarko Kovacevic 	return 0;
401cd255ccfSMarko Kovacevic }
402cd255ccfSMarko Kovacevic 
403cd255ccfSMarko Kovacevic static int
404*f64adb67SMarko Kovacevic prepare_auth_op(void)
405*f64adb67SMarko Kovacevic {
406*f64adb67SMarko Kovacevic 	struct rte_crypto_sym_op *sym = env.op->sym;
407*f64adb67SMarko Kovacevic 
408*f64adb67SMarko Kovacevic 	__rte_crypto_op_reset(env.op, RTE_CRYPTO_OP_TYPE_SYMMETRIC);
409*f64adb67SMarko Kovacevic 	rte_pktmbuf_reset(env.mbuf);
410*f64adb67SMarko Kovacevic 
411*f64adb67SMarko Kovacevic 	sym->m_src = env.mbuf;
412*f64adb67SMarko Kovacevic 	sym->auth.data.offset = 0;
413*f64adb67SMarko Kovacevic 
414*f64adb67SMarko Kovacevic 	if (info.op == FIPS_TEST_ENC_AUTH_GEN) {
415*f64adb67SMarko Kovacevic 		uint8_t *pt;
416*f64adb67SMarko Kovacevic 
417*f64adb67SMarko Kovacevic 		if (vec.pt.len > RTE_MBUF_MAX_NB_SEGS) {
418*f64adb67SMarko Kovacevic 			RTE_LOG(ERR, USER1, "PT len %u\n", vec.pt.len);
419*f64adb67SMarko Kovacevic 			return -EPERM;
420*f64adb67SMarko Kovacevic 		}
421*f64adb67SMarko Kovacevic 
422*f64adb67SMarko Kovacevic 		pt = (uint8_t *)rte_pktmbuf_append(env.mbuf, vec.pt.len +
423*f64adb67SMarko Kovacevic 				vec.cipher_auth.digest.len);
424*f64adb67SMarko Kovacevic 
425*f64adb67SMarko Kovacevic 		if (!pt) {
426*f64adb67SMarko Kovacevic 			RTE_LOG(ERR, USER1, "Error %i: MBUF too small\n",
427*f64adb67SMarko Kovacevic 					-ENOMEM);
428*f64adb67SMarko Kovacevic 			return -ENOMEM;
429*f64adb67SMarko Kovacevic 		}
430*f64adb67SMarko Kovacevic 
431*f64adb67SMarko Kovacevic 		memcpy(pt, vec.pt.val, vec.pt.len);
432*f64adb67SMarko Kovacevic 		sym->auth.data.length = vec.pt.len;
433*f64adb67SMarko Kovacevic 		sym->auth.digest.data = pt + vec.pt.len;
434*f64adb67SMarko Kovacevic 		sym->auth.digest.phys_addr = rte_pktmbuf_mtophys_offset(
435*f64adb67SMarko Kovacevic 				env.mbuf, vec.pt.len);
436*f64adb67SMarko Kovacevic 
437*f64adb67SMarko Kovacevic 	} else {
438*f64adb67SMarko Kovacevic 		uint8_t *ct;
439*f64adb67SMarko Kovacevic 
440*f64adb67SMarko Kovacevic 		if (vec.ct.len > RTE_MBUF_MAX_NB_SEGS) {
441*f64adb67SMarko Kovacevic 			RTE_LOG(ERR, USER1, "CT len %u\n", vec.ct.len);
442*f64adb67SMarko Kovacevic 			return -EPERM;
443*f64adb67SMarko Kovacevic 		}
444*f64adb67SMarko Kovacevic 
445*f64adb67SMarko Kovacevic 		ct = (uint8_t *)rte_pktmbuf_append(env.mbuf,
446*f64adb67SMarko Kovacevic 				vec.ct.len + vec.cipher_auth.digest.len);
447*f64adb67SMarko Kovacevic 
448*f64adb67SMarko Kovacevic 		if (!ct) {
449*f64adb67SMarko Kovacevic 			RTE_LOG(ERR, USER1, "Error %i: MBUF too small\n",
450*f64adb67SMarko Kovacevic 					-ENOMEM);
451*f64adb67SMarko Kovacevic 			return -ENOMEM;
452*f64adb67SMarko Kovacevic 		}
453*f64adb67SMarko Kovacevic 
454*f64adb67SMarko Kovacevic 		memcpy(ct, vec.ct.val, vec.ct.len);
455*f64adb67SMarko Kovacevic 		sym->auth.data.length = vec.ct.len;
456*f64adb67SMarko Kovacevic 		sym->auth.digest.data = vec.cipher_auth.digest.val;
457*f64adb67SMarko Kovacevic 		sym->auth.digest.phys_addr = rte_malloc_virt2iova(
458*f64adb67SMarko Kovacevic 				sym->auth.digest.data);
459*f64adb67SMarko Kovacevic 	}
460*f64adb67SMarko Kovacevic 
461*f64adb67SMarko Kovacevic 	rte_crypto_op_attach_sym_session(env.op, env.sess);
462*f64adb67SMarko Kovacevic }
463*f64adb67SMarko Kovacevic 
464*f64adb67SMarko Kovacevic static int
465cd255ccfSMarko Kovacevic prepare_aes_xform(struct rte_crypto_sym_xform *xform)
466cd255ccfSMarko Kovacevic {
467cd255ccfSMarko Kovacevic 	const struct rte_cryptodev_symmetric_capability *cap;
468cd255ccfSMarko Kovacevic 	struct rte_cryptodev_sym_capability_idx cap_idx;
469cd255ccfSMarko Kovacevic 	struct rte_crypto_cipher_xform *cipher_xform = &xform->cipher;
470cd255ccfSMarko Kovacevic 
471cd255ccfSMarko Kovacevic 	xform->type = RTE_CRYPTO_SYM_XFORM_CIPHER;
472cd255ccfSMarko Kovacevic 
473cd255ccfSMarko Kovacevic 	cipher_xform->algo = RTE_CRYPTO_CIPHER_AES_CBC;
474cd255ccfSMarko Kovacevic 	cipher_xform->op = (info.op == FIPS_TEST_ENC_AUTH_GEN) ?
475cd255ccfSMarko Kovacevic 			RTE_CRYPTO_CIPHER_OP_ENCRYPT :
476cd255ccfSMarko Kovacevic 			RTE_CRYPTO_CIPHER_OP_DECRYPT;
477cd255ccfSMarko Kovacevic 	cipher_xform->key.data = vec.cipher_auth.key.val;
478cd255ccfSMarko Kovacevic 	cipher_xform->key.length = vec.cipher_auth.key.len;
479cd255ccfSMarko Kovacevic 	cipher_xform->iv.length = vec.iv.len;
480cd255ccfSMarko Kovacevic 	cipher_xform->iv.offset = IV_OFF;
481cd255ccfSMarko Kovacevic 
482cd255ccfSMarko Kovacevic 	cap_idx.algo.cipher = RTE_CRYPTO_CIPHER_AES_CBC;
483cd255ccfSMarko Kovacevic 	cap_idx.type = RTE_CRYPTO_SYM_XFORM_CIPHER;
484cd255ccfSMarko Kovacevic 
485cd255ccfSMarko Kovacevic 	cap = rte_cryptodev_sym_capability_get(env.dev_id, &cap_idx);
486cd255ccfSMarko Kovacevic 	if (!cap) {
487cd255ccfSMarko Kovacevic 		RTE_LOG(ERR, USER1, "Failed to get capability for cdev %u\n",
488cd255ccfSMarko Kovacevic 				env.dev_id);
489cd255ccfSMarko Kovacevic 		return -EINVAL;
490cd255ccfSMarko Kovacevic 	}
491cd255ccfSMarko Kovacevic 
492cd255ccfSMarko Kovacevic 	if (rte_cryptodev_sym_capability_check_cipher(cap,
493cd255ccfSMarko Kovacevic 			cipher_xform->key.length,
494cd255ccfSMarko Kovacevic 			cipher_xform->iv.length) != 0) {
495cd255ccfSMarko Kovacevic 		RTE_LOG(ERR, USER1, "PMD %s key length %u IV length %u\n",
496cd255ccfSMarko Kovacevic 				info.device_name, cipher_xform->key.length,
497cd255ccfSMarko Kovacevic 				cipher_xform->iv.length);
498cd255ccfSMarko Kovacevic 		return -EPERM;
499cd255ccfSMarko Kovacevic 	}
500cd255ccfSMarko Kovacevic 
501cd255ccfSMarko Kovacevic 	return 0;
502cd255ccfSMarko Kovacevic }
503cd255ccfSMarko Kovacevic 
504*f64adb67SMarko Kovacevic static int
505*f64adb67SMarko Kovacevic prepare_hmac_xform(struct rte_crypto_sym_xform *xform)
506*f64adb67SMarko Kovacevic {
507*f64adb67SMarko Kovacevic 	const struct rte_cryptodev_symmetric_capability *cap;
508*f64adb67SMarko Kovacevic 	struct rte_cryptodev_sym_capability_idx cap_idx;
509*f64adb67SMarko Kovacevic 	struct rte_crypto_auth_xform *auth_xform = &xform->auth;
510*f64adb67SMarko Kovacevic 
511*f64adb67SMarko Kovacevic 	xform->type = RTE_CRYPTO_SYM_XFORM_AUTH;
512*f64adb67SMarko Kovacevic 
513*f64adb67SMarko Kovacevic 	auth_xform->algo = info.interim_info.hmac_data.algo;
514*f64adb67SMarko Kovacevic 	auth_xform->op = RTE_CRYPTO_AUTH_OP_GENERATE;
515*f64adb67SMarko Kovacevic 	auth_xform->digest_length = vec.cipher_auth.digest.len;
516*f64adb67SMarko Kovacevic 	auth_xform->key.data = vec.cipher_auth.key.val;
517*f64adb67SMarko Kovacevic 	auth_xform->key.length = vec.cipher_auth.key.len;
518*f64adb67SMarko Kovacevic 
519*f64adb67SMarko Kovacevic 	cap_idx.algo.auth = auth_xform->algo;
520*f64adb67SMarko Kovacevic 	cap_idx.type = RTE_CRYPTO_SYM_XFORM_AUTH;
521*f64adb67SMarko Kovacevic 
522*f64adb67SMarko Kovacevic 	cap = rte_cryptodev_sym_capability_get(env.dev_id, &cap_idx);
523*f64adb67SMarko Kovacevic 	if (!cap) {
524*f64adb67SMarko Kovacevic 		RTE_LOG(ERR, USER1, "Failed to get capability for cdev %u\n",
525*f64adb67SMarko Kovacevic 				env.dev_id);
526*f64adb67SMarko Kovacevic 		return -EINVAL;
527*f64adb67SMarko Kovacevic 	}
528*f64adb67SMarko Kovacevic 
529*f64adb67SMarko Kovacevic 	if (rte_cryptodev_sym_capability_check_auth(cap,
530*f64adb67SMarko Kovacevic 			auth_xform->key.length,
531*f64adb67SMarko Kovacevic 			auth_xform->digest_length, 0) != 0) {
532*f64adb67SMarko Kovacevic 		RTE_LOG(ERR, USER1, "PMD %s key length %u IV length %u\n",
533*f64adb67SMarko Kovacevic 				info.device_name, auth_xform->key.length,
534*f64adb67SMarko Kovacevic 				auth_xform->digest_length);
535*f64adb67SMarko Kovacevic 		return -EPERM;
536*f64adb67SMarko Kovacevic 	}
537*f64adb67SMarko Kovacevic 
538*f64adb67SMarko Kovacevic 	return 0;
539*f64adb67SMarko Kovacevic }
540*f64adb67SMarko Kovacevic 
541cd255ccfSMarko Kovacevic static void
542cd255ccfSMarko Kovacevic get_writeback_data(struct fips_val *val)
543cd255ccfSMarko Kovacevic {
544cd255ccfSMarko Kovacevic 	val->val = rte_pktmbuf_mtod(env.mbuf, uint8_t *);
545cd255ccfSMarko Kovacevic 	val->len = rte_pktmbuf_pkt_len(env.mbuf);
546cd255ccfSMarko Kovacevic }
547cd255ccfSMarko Kovacevic 
548cd255ccfSMarko Kovacevic static int
549cd255ccfSMarko Kovacevic fips_run_test(void)
550cd255ccfSMarko Kovacevic {
551cd255ccfSMarko Kovacevic 	struct rte_crypto_sym_xform xform = {0};
552cd255ccfSMarko Kovacevic 	uint16_t n_deqd;
553cd255ccfSMarko Kovacevic 	int ret;
554cd255ccfSMarko Kovacevic 
555cd255ccfSMarko Kovacevic 	ret = test_ops.prepare_xform(&xform);
556cd255ccfSMarko Kovacevic 	if (ret < 0)
557cd255ccfSMarko Kovacevic 		return ret;
558cd255ccfSMarko Kovacevic 
559cd255ccfSMarko Kovacevic 	env.sess = rte_cryptodev_sym_session_create(env.mpool);
560cd255ccfSMarko Kovacevic 	if (!env.sess)
561cd255ccfSMarko Kovacevic 		return -ENOMEM;
562cd255ccfSMarko Kovacevic 
563cd255ccfSMarko Kovacevic 	ret = rte_cryptodev_sym_session_init(env.dev_id,
564cd255ccfSMarko Kovacevic 			env.sess, &xform, env.mpool);
565cd255ccfSMarko Kovacevic 	if (ret < 0) {
566cd255ccfSMarko Kovacevic 		RTE_LOG(ERR, USER1, "Error %i: Init session\n",
567cd255ccfSMarko Kovacevic 				ret);
568cd255ccfSMarko Kovacevic 		return ret;
569cd255ccfSMarko Kovacevic 	}
570cd255ccfSMarko Kovacevic 
571cd255ccfSMarko Kovacevic 	ret = test_ops.prepare_op();
572cd255ccfSMarko Kovacevic 	if (ret < 0) {
573cd255ccfSMarko Kovacevic 		RTE_LOG(ERR, USER1, "Error %i: Prepare op\n",
574cd255ccfSMarko Kovacevic 				ret);
575cd255ccfSMarko Kovacevic 		return ret;
576cd255ccfSMarko Kovacevic 	}
577cd255ccfSMarko Kovacevic 
578cd255ccfSMarko Kovacevic 	if (rte_cryptodev_enqueue_burst(env.dev_id, 0, &env.op, 1) < 1) {
579cd255ccfSMarko Kovacevic 		RTE_LOG(ERR, USER1, "Error: Failed enqueue\n");
580cd255ccfSMarko Kovacevic 		return ret;
581cd255ccfSMarko Kovacevic 	}
582cd255ccfSMarko Kovacevic 
583cd255ccfSMarko Kovacevic 	do {
584cd255ccfSMarko Kovacevic 		struct rte_crypto_op *deqd_op;
585cd255ccfSMarko Kovacevic 
586cd255ccfSMarko Kovacevic 		n_deqd = rte_cryptodev_dequeue_burst(env.dev_id, 0, &deqd_op,
587cd255ccfSMarko Kovacevic 				1);
588cd255ccfSMarko Kovacevic 	} while (n_deqd == 0);
589cd255ccfSMarko Kovacevic 
590cd255ccfSMarko Kovacevic 	vec.status = env.op->status;
591cd255ccfSMarko Kovacevic 
592cd255ccfSMarko Kovacevic 	rte_cryptodev_sym_session_clear(env.dev_id, env.sess);
593cd255ccfSMarko Kovacevic 	rte_cryptodev_sym_session_free(env.sess);
594cd255ccfSMarko Kovacevic 	env.sess = NULL;
595cd255ccfSMarko Kovacevic 
596cd255ccfSMarko Kovacevic 	return ret;
597cd255ccfSMarko Kovacevic }
598cd255ccfSMarko Kovacevic 
599cd255ccfSMarko Kovacevic static int
600cd255ccfSMarko Kovacevic fips_generic_test(void)
601cd255ccfSMarko Kovacevic {
602cd255ccfSMarko Kovacevic 	struct fips_val val;
603cd255ccfSMarko Kovacevic 	int ret;
604cd255ccfSMarko Kovacevic 
605cd255ccfSMarko Kovacevic 	fips_test_write_one_case();
606cd255ccfSMarko Kovacevic 
607cd255ccfSMarko Kovacevic 	ret = fips_run_test();
608cd255ccfSMarko Kovacevic 	if (ret < 0) {
609cd255ccfSMarko Kovacevic 		if (ret == -EPERM) {
610cd255ccfSMarko Kovacevic 			fprintf(info.fp_wr, "Bypass\n\n");
611cd255ccfSMarko Kovacevic 			return 0;
612cd255ccfSMarko Kovacevic 		}
613cd255ccfSMarko Kovacevic 
614cd255ccfSMarko Kovacevic 		return ret;
615cd255ccfSMarko Kovacevic 	}
616cd255ccfSMarko Kovacevic 
617cd255ccfSMarko Kovacevic 	get_writeback_data(&val);
618cd255ccfSMarko Kovacevic 
619cd255ccfSMarko Kovacevic 	switch (info.file_type) {
620cd255ccfSMarko Kovacevic 	case FIPS_TYPE_REQ:
621cd255ccfSMarko Kovacevic 	case FIPS_TYPE_RSP:
622cd255ccfSMarko Kovacevic 		if (info.parse_writeback == NULL)
623cd255ccfSMarko Kovacevic 			return -EPERM;
624cd255ccfSMarko Kovacevic 		ret = info.parse_writeback(&val);
625cd255ccfSMarko Kovacevic 		if (ret < 0)
626cd255ccfSMarko Kovacevic 			return ret;
627cd255ccfSMarko Kovacevic 		break;
628cd255ccfSMarko Kovacevic 	case FIPS_TYPE_FAX:
629cd255ccfSMarko Kovacevic 		if (info.kat_check == NULL)
630cd255ccfSMarko Kovacevic 			return -EPERM;
631cd255ccfSMarko Kovacevic 		ret = info.kat_check(&val);
632cd255ccfSMarko Kovacevic 		if (ret < 0)
633cd255ccfSMarko Kovacevic 			return ret;
634cd255ccfSMarko Kovacevic 		break;
635cd255ccfSMarko Kovacevic 	}
636cd255ccfSMarko Kovacevic 
637cd255ccfSMarko Kovacevic 	fprintf(info.fp_wr, "\n");
638cd255ccfSMarko Kovacevic 
639cd255ccfSMarko Kovacevic 	return 0;
640cd255ccfSMarko Kovacevic }
641cd255ccfSMarko Kovacevic 
642cd255ccfSMarko Kovacevic static int
643cd255ccfSMarko Kovacevic fips_mct_aes_test(void)
644cd255ccfSMarko Kovacevic {
645cd255ccfSMarko Kovacevic #define AES_BLOCK_SIZE	16
646cd255ccfSMarko Kovacevic #define AES_EXTERN_ITER	100
647cd255ccfSMarko Kovacevic #define AES_INTERN_ITER	1000
648cd255ccfSMarko Kovacevic 	struct fips_val val, val_key;
649cd255ccfSMarko Kovacevic 	uint8_t prev_out[AES_BLOCK_SIZE] = {0};
650cd255ccfSMarko Kovacevic 	uint8_t prev_in[AES_BLOCK_SIZE] = {0};
651cd255ccfSMarko Kovacevic 	uint32_t i, j, k;
652cd255ccfSMarko Kovacevic 	int ret;
653cd255ccfSMarko Kovacevic 
654cd255ccfSMarko Kovacevic 	for (i = 0; i < AES_EXTERN_ITER; i++) {
655cd255ccfSMarko Kovacevic 		if (i != 0)
656cd255ccfSMarko Kovacevic 			update_info_vec(i);
657cd255ccfSMarko Kovacevic 
658cd255ccfSMarko Kovacevic 		fips_test_write_one_case();
659cd255ccfSMarko Kovacevic 
660cd255ccfSMarko Kovacevic 		for (j = 0; j < AES_INTERN_ITER; j++) {
661cd255ccfSMarko Kovacevic 			ret = fips_run_test();
662cd255ccfSMarko Kovacevic 			if (ret < 0) {
663cd255ccfSMarko Kovacevic 				if (ret == -EPERM) {
664cd255ccfSMarko Kovacevic 					fprintf(info.fp_wr, "Bypass\n");
665cd255ccfSMarko Kovacevic 					return 0;
666cd255ccfSMarko Kovacevic 				}
667cd255ccfSMarko Kovacevic 
668cd255ccfSMarko Kovacevic 				return ret;
669cd255ccfSMarko Kovacevic 			}
670cd255ccfSMarko Kovacevic 
671cd255ccfSMarko Kovacevic 			get_writeback_data(&val);
672cd255ccfSMarko Kovacevic 
673cd255ccfSMarko Kovacevic 			if (info.op == FIPS_TEST_DEC_AUTH_VERIF)
674cd255ccfSMarko Kovacevic 				memcpy(prev_in, vec.ct.val, AES_BLOCK_SIZE);
675cd255ccfSMarko Kovacevic 
676cd255ccfSMarko Kovacevic 			if (j == 0) {
677cd255ccfSMarko Kovacevic 				memcpy(prev_out, val.val, AES_BLOCK_SIZE);
678cd255ccfSMarko Kovacevic 
679cd255ccfSMarko Kovacevic 				if (info.op == FIPS_TEST_ENC_AUTH_GEN) {
680cd255ccfSMarko Kovacevic 					memcpy(vec.pt.val, vec.iv.val,
681cd255ccfSMarko Kovacevic 							AES_BLOCK_SIZE);
682cd255ccfSMarko Kovacevic 					memcpy(vec.iv.val, val.val,
683cd255ccfSMarko Kovacevic 							AES_BLOCK_SIZE);
684cd255ccfSMarko Kovacevic 				} else {
685cd255ccfSMarko Kovacevic 					memcpy(vec.ct.val, vec.iv.val,
686cd255ccfSMarko Kovacevic 							AES_BLOCK_SIZE);
687cd255ccfSMarko Kovacevic 					memcpy(vec.iv.val, prev_in,
688cd255ccfSMarko Kovacevic 							AES_BLOCK_SIZE);
689cd255ccfSMarko Kovacevic 				}
690cd255ccfSMarko Kovacevic 				continue;
691cd255ccfSMarko Kovacevic 			}
692cd255ccfSMarko Kovacevic 
693cd255ccfSMarko Kovacevic 			if (info.op == FIPS_TEST_ENC_AUTH_GEN) {
694cd255ccfSMarko Kovacevic 				memcpy(vec.iv.val, val.val, AES_BLOCK_SIZE);
695cd255ccfSMarko Kovacevic 				memcpy(vec.pt.val, prev_out, AES_BLOCK_SIZE);
696cd255ccfSMarko Kovacevic 			} else {
697cd255ccfSMarko Kovacevic 				memcpy(vec.iv.val, prev_in, AES_BLOCK_SIZE);
698cd255ccfSMarko Kovacevic 				memcpy(vec.ct.val, prev_out, AES_BLOCK_SIZE);
699cd255ccfSMarko Kovacevic 			}
700cd255ccfSMarko Kovacevic 
701cd255ccfSMarko Kovacevic 			if (j == AES_INTERN_ITER - 1)
702cd255ccfSMarko Kovacevic 				continue;
703cd255ccfSMarko Kovacevic 
704cd255ccfSMarko Kovacevic 			memcpy(prev_out, val.val, AES_BLOCK_SIZE);
705cd255ccfSMarko Kovacevic 		}
706cd255ccfSMarko Kovacevic 
707cd255ccfSMarko Kovacevic 		info.parse_writeback(&val);
708cd255ccfSMarko Kovacevic 		fprintf(info.fp_wr, "\n");
709cd255ccfSMarko Kovacevic 
710cd255ccfSMarko Kovacevic 		if (i == AES_EXTERN_ITER - 1)
711cd255ccfSMarko Kovacevic 			continue;
712cd255ccfSMarko Kovacevic 
713cd255ccfSMarko Kovacevic 		/** update key */
714cd255ccfSMarko Kovacevic 		memcpy(&val_key, &vec.cipher_auth.key, sizeof(val_key));
715cd255ccfSMarko Kovacevic 		for (k = 0; k < vec.cipher_auth.key.len; k++) {
716cd255ccfSMarko Kovacevic 			switch (vec.cipher_auth.key.len) {
717cd255ccfSMarko Kovacevic 			case 16:
718cd255ccfSMarko Kovacevic 				val_key.val[k] ^= val.val[k];
719cd255ccfSMarko Kovacevic 				break;
720cd255ccfSMarko Kovacevic 			case 24:
721cd255ccfSMarko Kovacevic 				if (k < 8)
722cd255ccfSMarko Kovacevic 					val_key.val[k] ^= prev_out[k + 8];
723cd255ccfSMarko Kovacevic 				else
724cd255ccfSMarko Kovacevic 					val_key.val[k] ^= val.val[k - 8];
725cd255ccfSMarko Kovacevic 				break;
726cd255ccfSMarko Kovacevic 			case 32:
727cd255ccfSMarko Kovacevic 				if (k < 16)
728cd255ccfSMarko Kovacevic 					val_key.val[k] ^= prev_out[k];
729cd255ccfSMarko Kovacevic 				else
730cd255ccfSMarko Kovacevic 					val_key.val[k] ^= val.val[k - 16];
731cd255ccfSMarko Kovacevic 				break;
732cd255ccfSMarko Kovacevic 			default:
733cd255ccfSMarko Kovacevic 				return -1;
734cd255ccfSMarko Kovacevic 			}
735cd255ccfSMarko Kovacevic 		}
736cd255ccfSMarko Kovacevic 
737cd255ccfSMarko Kovacevic 		if (info.op == FIPS_TEST_DEC_AUTH_VERIF)
738cd255ccfSMarko Kovacevic 			memcpy(vec.iv.val, val.val, AES_BLOCK_SIZE);
739cd255ccfSMarko Kovacevic 	}
740cd255ccfSMarko Kovacevic 
741cd255ccfSMarko Kovacevic 	return 0;
742cd255ccfSMarko Kovacevic }
743cd255ccfSMarko Kovacevic 
744cd255ccfSMarko Kovacevic static int
745cd255ccfSMarko Kovacevic init_test_ops(void)
746cd255ccfSMarko Kovacevic {
747cd255ccfSMarko Kovacevic 	switch (info.algo) {
748cd255ccfSMarko Kovacevic 	case FIPS_TEST_ALGO_AES:
749cd255ccfSMarko Kovacevic 		test_ops.prepare_op = prepare_cipher_op;
750cd255ccfSMarko Kovacevic 		test_ops.prepare_xform  = prepare_aes_xform;
751cd255ccfSMarko Kovacevic 		if (info.interim_info.aes_data.test_type == AESAVS_TYPE_MCT)
752cd255ccfSMarko Kovacevic 			test_ops.test = fips_mct_aes_test;
753cd255ccfSMarko Kovacevic 		else
754cd255ccfSMarko Kovacevic 			test_ops.test = fips_generic_test;
755cd255ccfSMarko Kovacevic 		break;
756*f64adb67SMarko Kovacevic 	case FIPS_TEST_ALGO_HMAC:
757*f64adb67SMarko Kovacevic 		test_ops.prepare_op = prepare_auth_op;
758*f64adb67SMarko Kovacevic 		test_ops.prepare_xform = prepare_hmac_xform;
759*f64adb67SMarko Kovacevic 		test_ops.test = fips_generic_test;
760*f64adb67SMarko Kovacevic 		break;
761cd255ccfSMarko Kovacevic 
762cd255ccfSMarko Kovacevic 	default:
763cd255ccfSMarko Kovacevic 		return -1;
764cd255ccfSMarko Kovacevic 	}
765cd255ccfSMarko Kovacevic 
766cd255ccfSMarko Kovacevic 	return 0;
767cd255ccfSMarko Kovacevic }
768cd255ccfSMarko Kovacevic 
7693d0fad56SMarko Kovacevic static void
7703d0fad56SMarko Kovacevic print_test_block(void)
7713d0fad56SMarko Kovacevic {
7723d0fad56SMarko Kovacevic 	uint32_t i;
7733d0fad56SMarko Kovacevic 
7743d0fad56SMarko Kovacevic 	for (i = 0; i < info.nb_vec_lines; i++)
7753d0fad56SMarko Kovacevic 		printf("%s\n", info.vec[i]);
7763d0fad56SMarko Kovacevic 
7773d0fad56SMarko Kovacevic 	printf("\n");
7783d0fad56SMarko Kovacevic }
7793d0fad56SMarko Kovacevic 
7803d0fad56SMarko Kovacevic static int
7813d0fad56SMarko Kovacevic fips_test_one_file(void)
7823d0fad56SMarko Kovacevic {
7833d0fad56SMarko Kovacevic 	int fetch_ret = 0, ret;
7843d0fad56SMarko Kovacevic 
785cd255ccfSMarko Kovacevic 
786cd255ccfSMarko Kovacevic 	ret = init_test_ops();
787cd255ccfSMarko Kovacevic 	if (ret < 0) {
788cd255ccfSMarko Kovacevic 		RTE_LOG(ERR, USER1, "Error %i: Init test op\n", ret);
789cd255ccfSMarko Kovacevic 		return ret;
790cd255ccfSMarko Kovacevic 	}
791cd255ccfSMarko Kovacevic 
792cd255ccfSMarko Kovacevic 	while (ret >= 0 && fetch_ret == 0) {
7933d0fad56SMarko Kovacevic 		fetch_ret = fips_test_fetch_one_block();
7943d0fad56SMarko Kovacevic 		if (fetch_ret < 0) {
7953d0fad56SMarko Kovacevic 			RTE_LOG(ERR, USER1, "Error %i: Fetch block\n",
7963d0fad56SMarko Kovacevic 					fetch_ret);
7973d0fad56SMarko Kovacevic 			ret = fetch_ret;
7983d0fad56SMarko Kovacevic 			goto error_one_case;
7993d0fad56SMarko Kovacevic 		}
8003d0fad56SMarko Kovacevic 
8013d0fad56SMarko Kovacevic 		if (info.nb_vec_lines == 0) {
8023d0fad56SMarko Kovacevic 			if (fetch_ret == -EOF)
8033d0fad56SMarko Kovacevic 				break;
8043d0fad56SMarko Kovacevic 
8053d0fad56SMarko Kovacevic 			fprintf(info.fp_wr, "\n");
8063d0fad56SMarko Kovacevic 			continue;
8073d0fad56SMarko Kovacevic 		}
8083d0fad56SMarko Kovacevic 
8093d0fad56SMarko Kovacevic 		ret = fips_test_parse_one_case();
8103d0fad56SMarko Kovacevic 		switch (ret) {
8113d0fad56SMarko Kovacevic 		case 0:
812cd255ccfSMarko Kovacevic 			ret = test_ops.test();
8133d0fad56SMarko Kovacevic 			if (ret == 0)
8143d0fad56SMarko Kovacevic 				break;
8153d0fad56SMarko Kovacevic 			RTE_LOG(ERR, USER1, "Error %i: test block\n",
8163d0fad56SMarko Kovacevic 					ret);
8173d0fad56SMarko Kovacevic 			goto error_one_case;
8183d0fad56SMarko Kovacevic 		case 1:
8193d0fad56SMarko Kovacevic 			break;
8203d0fad56SMarko Kovacevic 		default:
8213d0fad56SMarko Kovacevic 			RTE_LOG(ERR, USER1, "Error %i: Parse block\n",
8223d0fad56SMarko Kovacevic 					ret);
8233d0fad56SMarko Kovacevic 			goto error_one_case;
8243d0fad56SMarko Kovacevic 		}
8253d0fad56SMarko Kovacevic 
8263d0fad56SMarko Kovacevic 		continue;
8273d0fad56SMarko Kovacevic error_one_case:
8283d0fad56SMarko Kovacevic 		print_test_block();
8293d0fad56SMarko Kovacevic 	}
8303d0fad56SMarko Kovacevic 
8313d0fad56SMarko Kovacevic 	fips_test_clear();
8323d0fad56SMarko Kovacevic 
833cd255ccfSMarko Kovacevic 	return ret;
834cd255ccfSMarko Kovacevic 
8353d0fad56SMarko Kovacevic }
836