1eda14cbcSMatt Macy /*
2eda14cbcSMatt Macy * CDDL HEADER START
3eda14cbcSMatt Macy *
4eda14cbcSMatt Macy * The contents of this file are subject to the terms of the
5eda14cbcSMatt Macy * Common Development and Distribution License (the "License").
6eda14cbcSMatt Macy * You may not use this file except in compliance with the License.
7eda14cbcSMatt Macy *
8eda14cbcSMatt Macy * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
9*271171e0SMartin Matuska * or https://opensource.org/licenses/CDDL-1.0.
10eda14cbcSMatt Macy * See the License for the specific language governing permissions
11eda14cbcSMatt Macy * and limitations under the License.
12eda14cbcSMatt Macy *
13eda14cbcSMatt Macy * When distributing Covered Code, include this CDDL HEADER in each
14eda14cbcSMatt Macy * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
15eda14cbcSMatt Macy * If applicable, add the following below this CDDL HEADER, with the
16eda14cbcSMatt Macy * fields enclosed by brackets "[]" replaced with your own identifying
17eda14cbcSMatt Macy * information: Portions Copyright [yyyy] [name of copyright owner]
18eda14cbcSMatt Macy *
19eda14cbcSMatt Macy * CDDL HEADER END
20eda14cbcSMatt Macy */
21eda14cbcSMatt Macy
22eda14cbcSMatt Macy /*
23eda14cbcSMatt Macy * This file represents the QAT implementation of checksums and encryption.
24eda14cbcSMatt Macy * Internally, QAT shares the same cryptographic instances for both of these
25eda14cbcSMatt Macy * operations, so the code has been combined here. QAT data compression uses
26eda14cbcSMatt Macy * compression instances, so that code is separated into qat_compress.c
27eda14cbcSMatt Macy */
28eda14cbcSMatt Macy
29eda14cbcSMatt Macy #if defined(_KERNEL) && defined(HAVE_QAT)
30eda14cbcSMatt Macy #include <linux/slab.h>
31eda14cbcSMatt Macy #include <linux/vmalloc.h>
32eda14cbcSMatt Macy #include <linux/pagemap.h>
33eda14cbcSMatt Macy #include <linux/completion.h>
34eda14cbcSMatt Macy #include <sys/zfs_context.h>
35eda14cbcSMatt Macy #include <sys/zio_crypt.h>
36eda14cbcSMatt Macy #include "lac/cpa_cy_im.h"
37eda14cbcSMatt Macy #include "lac/cpa_cy_common.h"
38eda14cbcSMatt Macy #include <sys/qat.h>
39eda14cbcSMatt Macy
40eda14cbcSMatt Macy /*
41eda14cbcSMatt Macy * Max instances in a QAT device, each instance is a channel to submit
42eda14cbcSMatt Macy * jobs to QAT hardware, this is only for pre-allocating instances
43eda14cbcSMatt Macy * and session arrays; the actual number of instances are defined in
44eda14cbcSMatt Macy * the QAT driver's configure file.
45eda14cbcSMatt Macy */
46eda14cbcSMatt Macy #define QAT_CRYPT_MAX_INSTANCES 48
47eda14cbcSMatt Macy
48eda14cbcSMatt Macy #define MAX_PAGE_NUM 1024
49eda14cbcSMatt Macy
50eda14cbcSMatt Macy static Cpa32U inst_num = 0;
51eda14cbcSMatt Macy static Cpa16U num_inst = 0;
52eda14cbcSMatt Macy static CpaInstanceHandle cy_inst_handles[QAT_CRYPT_MAX_INSTANCES];
53eda14cbcSMatt Macy static boolean_t qat_cy_init_done = B_FALSE;
54eda14cbcSMatt Macy int zfs_qat_encrypt_disable = 0;
55eda14cbcSMatt Macy int zfs_qat_checksum_disable = 0;
56eda14cbcSMatt Macy
57eda14cbcSMatt Macy typedef struct cy_callback {
58eda14cbcSMatt Macy CpaBoolean verify_result;
59eda14cbcSMatt Macy struct completion complete;
60eda14cbcSMatt Macy } cy_callback_t;
61eda14cbcSMatt Macy
62eda14cbcSMatt Macy static void
symcallback(void * p_callback,CpaStatus status,const CpaCySymOp operation,void * op_data,CpaBufferList * buf_list_dst,CpaBoolean verify)63eda14cbcSMatt Macy symcallback(void *p_callback, CpaStatus status, const CpaCySymOp operation,
64eda14cbcSMatt Macy void *op_data, CpaBufferList *buf_list_dst, CpaBoolean verify)
65eda14cbcSMatt Macy {
66eda14cbcSMatt Macy cy_callback_t *cb = p_callback;
67eda14cbcSMatt Macy
68eda14cbcSMatt Macy if (cb != NULL) {
69eda14cbcSMatt Macy /* indicate that the function has been called */
70eda14cbcSMatt Macy cb->verify_result = verify;
71eda14cbcSMatt Macy complete(&cb->complete);
72eda14cbcSMatt Macy }
73eda14cbcSMatt Macy }
74eda14cbcSMatt Macy
75eda14cbcSMatt Macy boolean_t
qat_crypt_use_accel(size_t s_len)76eda14cbcSMatt Macy qat_crypt_use_accel(size_t s_len)
77eda14cbcSMatt Macy {
78eda14cbcSMatt Macy return (!zfs_qat_encrypt_disable &&
79eda14cbcSMatt Macy qat_cy_init_done &&
80eda14cbcSMatt Macy s_len >= QAT_MIN_BUF_SIZE &&
81eda14cbcSMatt Macy s_len <= QAT_MAX_BUF_SIZE);
82eda14cbcSMatt Macy }
83eda14cbcSMatt Macy
84eda14cbcSMatt Macy boolean_t
qat_checksum_use_accel(size_t s_len)85eda14cbcSMatt Macy qat_checksum_use_accel(size_t s_len)
86eda14cbcSMatt Macy {
87eda14cbcSMatt Macy return (!zfs_qat_checksum_disable &&
88eda14cbcSMatt Macy qat_cy_init_done &&
89eda14cbcSMatt Macy s_len >= QAT_MIN_BUF_SIZE &&
90eda14cbcSMatt Macy s_len <= QAT_MAX_BUF_SIZE);
91eda14cbcSMatt Macy }
92eda14cbcSMatt Macy
93eda14cbcSMatt Macy void
qat_cy_clean(void)94eda14cbcSMatt Macy qat_cy_clean(void)
95eda14cbcSMatt Macy {
96eda14cbcSMatt Macy for (Cpa16U i = 0; i < num_inst; i++)
97eda14cbcSMatt Macy cpaCyStopInstance(cy_inst_handles[i]);
98eda14cbcSMatt Macy
99eda14cbcSMatt Macy num_inst = 0;
100eda14cbcSMatt Macy qat_cy_init_done = B_FALSE;
101eda14cbcSMatt Macy }
102eda14cbcSMatt Macy
103eda14cbcSMatt Macy int
qat_cy_init(void)104eda14cbcSMatt Macy qat_cy_init(void)
105eda14cbcSMatt Macy {
106eda14cbcSMatt Macy CpaStatus status = CPA_STATUS_FAIL;
107eda14cbcSMatt Macy
108eda14cbcSMatt Macy if (qat_cy_init_done)
109eda14cbcSMatt Macy return (0);
110eda14cbcSMatt Macy
111eda14cbcSMatt Macy status = cpaCyGetNumInstances(&num_inst);
112eda14cbcSMatt Macy if (status != CPA_STATUS_SUCCESS)
113eda14cbcSMatt Macy return (-1);
114eda14cbcSMatt Macy
115eda14cbcSMatt Macy /* if the user has configured no QAT encryption units just return */
116eda14cbcSMatt Macy if (num_inst == 0)
117eda14cbcSMatt Macy return (0);
118eda14cbcSMatt Macy
119eda14cbcSMatt Macy if (num_inst > QAT_CRYPT_MAX_INSTANCES)
120eda14cbcSMatt Macy num_inst = QAT_CRYPT_MAX_INSTANCES;
121eda14cbcSMatt Macy
122eda14cbcSMatt Macy status = cpaCyGetInstances(num_inst, &cy_inst_handles[0]);
123eda14cbcSMatt Macy if (status != CPA_STATUS_SUCCESS)
124eda14cbcSMatt Macy return (-1);
125eda14cbcSMatt Macy
126eda14cbcSMatt Macy for (Cpa16U i = 0; i < num_inst; i++) {
127eda14cbcSMatt Macy status = cpaCySetAddressTranslation(cy_inst_handles[i],
128eda14cbcSMatt Macy (void *)virt_to_phys);
129eda14cbcSMatt Macy if (status != CPA_STATUS_SUCCESS)
130eda14cbcSMatt Macy goto error;
131eda14cbcSMatt Macy
132eda14cbcSMatt Macy status = cpaCyStartInstance(cy_inst_handles[i]);
133eda14cbcSMatt Macy if (status != CPA_STATUS_SUCCESS)
134eda14cbcSMatt Macy goto error;
135eda14cbcSMatt Macy }
136eda14cbcSMatt Macy
137eda14cbcSMatt Macy qat_cy_init_done = B_TRUE;
138eda14cbcSMatt Macy return (0);
139eda14cbcSMatt Macy
140eda14cbcSMatt Macy error:
141eda14cbcSMatt Macy qat_cy_clean();
142eda14cbcSMatt Macy return (-1);
143eda14cbcSMatt Macy }
144eda14cbcSMatt Macy
145eda14cbcSMatt Macy void
qat_cy_fini(void)146eda14cbcSMatt Macy qat_cy_fini(void)
147eda14cbcSMatt Macy {
148eda14cbcSMatt Macy if (!qat_cy_init_done)
149eda14cbcSMatt Macy return;
150eda14cbcSMatt Macy
151eda14cbcSMatt Macy qat_cy_clean();
152eda14cbcSMatt Macy }
153eda14cbcSMatt Macy
154eda14cbcSMatt Macy static CpaStatus
qat_init_crypt_session_ctx(qat_encrypt_dir_t dir,CpaInstanceHandle inst_handle,CpaCySymSessionCtx ** cy_session_ctx,crypto_key_t * key,Cpa64U crypt,Cpa32U aad_len)155eda14cbcSMatt Macy qat_init_crypt_session_ctx(qat_encrypt_dir_t dir, CpaInstanceHandle inst_handle,
156eda14cbcSMatt Macy CpaCySymSessionCtx **cy_session_ctx, crypto_key_t *key,
157eda14cbcSMatt Macy Cpa64U crypt, Cpa32U aad_len)
158eda14cbcSMatt Macy {
159eda14cbcSMatt Macy CpaStatus status = CPA_STATUS_SUCCESS;
160eda14cbcSMatt Macy Cpa32U ctx_size;
161eda14cbcSMatt Macy Cpa32U ciper_algorithm;
162eda14cbcSMatt Macy Cpa32U hash_algorithm;
163eda14cbcSMatt Macy CpaCySymSessionSetupData sd = { 0 };
164eda14cbcSMatt Macy
165eda14cbcSMatt Macy if (zio_crypt_table[crypt].ci_crypt_type == ZC_TYPE_CCM) {
166eda14cbcSMatt Macy return (CPA_STATUS_FAIL);
167eda14cbcSMatt Macy } else {
168eda14cbcSMatt Macy ciper_algorithm = CPA_CY_SYM_CIPHER_AES_GCM;
169eda14cbcSMatt Macy hash_algorithm = CPA_CY_SYM_HASH_AES_GCM;
170eda14cbcSMatt Macy }
171eda14cbcSMatt Macy
172eda14cbcSMatt Macy sd.cipherSetupData.cipherAlgorithm = ciper_algorithm;
173eda14cbcSMatt Macy sd.cipherSetupData.pCipherKey = key->ck_data;
174eda14cbcSMatt Macy sd.cipherSetupData.cipherKeyLenInBytes = key->ck_length / 8;
175eda14cbcSMatt Macy sd.hashSetupData.hashAlgorithm = hash_algorithm;
176eda14cbcSMatt Macy sd.hashSetupData.hashMode = CPA_CY_SYM_HASH_MODE_AUTH;
177eda14cbcSMatt Macy sd.hashSetupData.digestResultLenInBytes = ZIO_DATA_MAC_LEN;
178eda14cbcSMatt Macy sd.hashSetupData.authModeSetupData.aadLenInBytes = aad_len;
179eda14cbcSMatt Macy sd.sessionPriority = CPA_CY_PRIORITY_NORMAL;
180eda14cbcSMatt Macy sd.symOperation = CPA_CY_SYM_OP_ALGORITHM_CHAINING;
181eda14cbcSMatt Macy sd.digestIsAppended = CPA_FALSE;
182eda14cbcSMatt Macy sd.verifyDigest = CPA_FALSE;
183eda14cbcSMatt Macy
184eda14cbcSMatt Macy if (dir == QAT_ENCRYPT) {
185eda14cbcSMatt Macy sd.cipherSetupData.cipherDirection =
186eda14cbcSMatt Macy CPA_CY_SYM_CIPHER_DIRECTION_ENCRYPT;
187eda14cbcSMatt Macy sd.algChainOrder =
188eda14cbcSMatt Macy CPA_CY_SYM_ALG_CHAIN_ORDER_HASH_THEN_CIPHER;
189eda14cbcSMatt Macy } else {
190eda14cbcSMatt Macy ASSERT3U(dir, ==, QAT_DECRYPT);
191eda14cbcSMatt Macy sd.cipherSetupData.cipherDirection =
192eda14cbcSMatt Macy CPA_CY_SYM_CIPHER_DIRECTION_DECRYPT;
193eda14cbcSMatt Macy sd.algChainOrder =
194eda14cbcSMatt Macy CPA_CY_SYM_ALG_CHAIN_ORDER_CIPHER_THEN_HASH;
195eda14cbcSMatt Macy }
196eda14cbcSMatt Macy
197eda14cbcSMatt Macy status = cpaCySymSessionCtxGetSize(inst_handle, &sd, &ctx_size);
198eda14cbcSMatt Macy if (status != CPA_STATUS_SUCCESS)
199eda14cbcSMatt Macy return (status);
200eda14cbcSMatt Macy
201eda14cbcSMatt Macy status = QAT_PHYS_CONTIG_ALLOC(cy_session_ctx, ctx_size);
202eda14cbcSMatt Macy if (status != CPA_STATUS_SUCCESS)
203eda14cbcSMatt Macy return (status);
204eda14cbcSMatt Macy
205eda14cbcSMatt Macy status = cpaCySymInitSession(inst_handle, symcallback, &sd,
206eda14cbcSMatt Macy *cy_session_ctx);
207eda14cbcSMatt Macy if (status != CPA_STATUS_SUCCESS) {
208eda14cbcSMatt Macy QAT_PHYS_CONTIG_FREE(*cy_session_ctx);
209eda14cbcSMatt Macy return (status);
210eda14cbcSMatt Macy }
211eda14cbcSMatt Macy
212eda14cbcSMatt Macy return (CPA_STATUS_SUCCESS);
213eda14cbcSMatt Macy }
214eda14cbcSMatt Macy
215eda14cbcSMatt Macy static CpaStatus
qat_init_checksum_session_ctx(CpaInstanceHandle inst_handle,CpaCySymSessionCtx ** cy_session_ctx,Cpa64U cksum)216eda14cbcSMatt Macy qat_init_checksum_session_ctx(CpaInstanceHandle inst_handle,
217eda14cbcSMatt Macy CpaCySymSessionCtx **cy_session_ctx, Cpa64U cksum)
218eda14cbcSMatt Macy {
219eda14cbcSMatt Macy CpaStatus status = CPA_STATUS_SUCCESS;
220eda14cbcSMatt Macy Cpa32U ctx_size;
221eda14cbcSMatt Macy Cpa32U hash_algorithm;
222eda14cbcSMatt Macy CpaCySymSessionSetupData sd = { 0 };
223eda14cbcSMatt Macy
224eda14cbcSMatt Macy /*
225eda14cbcSMatt Macy * ZFS's SHA512 checksum is actually SHA512/256, which uses
226eda14cbcSMatt Macy * a different IV from standard SHA512. QAT does not support
227eda14cbcSMatt Macy * SHA512/256, so we can only support SHA256.
228eda14cbcSMatt Macy */
229eda14cbcSMatt Macy if (cksum == ZIO_CHECKSUM_SHA256)
230eda14cbcSMatt Macy hash_algorithm = CPA_CY_SYM_HASH_SHA256;
231eda14cbcSMatt Macy else
232eda14cbcSMatt Macy return (CPA_STATUS_FAIL);
233eda14cbcSMatt Macy
234eda14cbcSMatt Macy sd.sessionPriority = CPA_CY_PRIORITY_NORMAL;
235eda14cbcSMatt Macy sd.symOperation = CPA_CY_SYM_OP_HASH;
236eda14cbcSMatt Macy sd.hashSetupData.hashAlgorithm = hash_algorithm;
237eda14cbcSMatt Macy sd.hashSetupData.hashMode = CPA_CY_SYM_HASH_MODE_PLAIN;
238eda14cbcSMatt Macy sd.hashSetupData.digestResultLenInBytes = sizeof (zio_cksum_t);
239eda14cbcSMatt Macy sd.digestIsAppended = CPA_FALSE;
240eda14cbcSMatt Macy sd.verifyDigest = CPA_FALSE;
241eda14cbcSMatt Macy
242eda14cbcSMatt Macy status = cpaCySymSessionCtxGetSize(inst_handle, &sd, &ctx_size);
243eda14cbcSMatt Macy if (status != CPA_STATUS_SUCCESS)
244eda14cbcSMatt Macy return (status);
245eda14cbcSMatt Macy
246eda14cbcSMatt Macy status = QAT_PHYS_CONTIG_ALLOC(cy_session_ctx, ctx_size);
247eda14cbcSMatt Macy if (status != CPA_STATUS_SUCCESS)
248eda14cbcSMatt Macy return (status);
249eda14cbcSMatt Macy
250eda14cbcSMatt Macy status = cpaCySymInitSession(inst_handle, symcallback, &sd,
251eda14cbcSMatt Macy *cy_session_ctx);
252eda14cbcSMatt Macy if (status != CPA_STATUS_SUCCESS) {
253eda14cbcSMatt Macy QAT_PHYS_CONTIG_FREE(*cy_session_ctx);
254eda14cbcSMatt Macy return (status);
255eda14cbcSMatt Macy }
256eda14cbcSMatt Macy
257eda14cbcSMatt Macy return (CPA_STATUS_SUCCESS);
258eda14cbcSMatt Macy }
259eda14cbcSMatt Macy
260eda14cbcSMatt Macy static CpaStatus
qat_init_cy_buffer_lists(CpaInstanceHandle inst_handle,uint32_t nr_bufs,CpaBufferList * src,CpaBufferList * dst)261eda14cbcSMatt Macy qat_init_cy_buffer_lists(CpaInstanceHandle inst_handle, uint32_t nr_bufs,
262eda14cbcSMatt Macy CpaBufferList *src, CpaBufferList *dst)
263eda14cbcSMatt Macy {
264eda14cbcSMatt Macy CpaStatus status = CPA_STATUS_SUCCESS;
265eda14cbcSMatt Macy Cpa32U meta_size = 0;
266eda14cbcSMatt Macy
267eda14cbcSMatt Macy status = cpaCyBufferListGetMetaSize(inst_handle, nr_bufs, &meta_size);
268eda14cbcSMatt Macy if (status != CPA_STATUS_SUCCESS)
269eda14cbcSMatt Macy return (status);
270eda14cbcSMatt Macy
271eda14cbcSMatt Macy status = QAT_PHYS_CONTIG_ALLOC(&src->pPrivateMetaData, meta_size);
272eda14cbcSMatt Macy if (status != CPA_STATUS_SUCCESS)
273eda14cbcSMatt Macy goto error;
274eda14cbcSMatt Macy
275eda14cbcSMatt Macy if (src != dst) {
276eda14cbcSMatt Macy status = QAT_PHYS_CONTIG_ALLOC(&dst->pPrivateMetaData,
277eda14cbcSMatt Macy meta_size);
278eda14cbcSMatt Macy if (status != CPA_STATUS_SUCCESS)
279eda14cbcSMatt Macy goto error;
280eda14cbcSMatt Macy }
281eda14cbcSMatt Macy
282eda14cbcSMatt Macy return (CPA_STATUS_SUCCESS);
283eda14cbcSMatt Macy
284eda14cbcSMatt Macy error:
285eda14cbcSMatt Macy QAT_PHYS_CONTIG_FREE(src->pPrivateMetaData);
286eda14cbcSMatt Macy if (src != dst)
287eda14cbcSMatt Macy QAT_PHYS_CONTIG_FREE(dst->pPrivateMetaData);
288eda14cbcSMatt Macy
289eda14cbcSMatt Macy return (status);
290eda14cbcSMatt Macy }
291eda14cbcSMatt Macy
292eda14cbcSMatt Macy int
qat_crypt(qat_encrypt_dir_t dir,uint8_t * src_buf,uint8_t * dst_buf,uint8_t * aad_buf,uint32_t aad_len,uint8_t * iv_buf,uint8_t * digest_buf,crypto_key_t * key,uint64_t crypt,uint32_t enc_len)293eda14cbcSMatt Macy qat_crypt(qat_encrypt_dir_t dir, uint8_t *src_buf, uint8_t *dst_buf,
294eda14cbcSMatt Macy uint8_t *aad_buf, uint32_t aad_len, uint8_t *iv_buf, uint8_t *digest_buf,
295eda14cbcSMatt Macy crypto_key_t *key, uint64_t crypt, uint32_t enc_len)
296eda14cbcSMatt Macy {
297eda14cbcSMatt Macy CpaStatus status = CPA_STATUS_SUCCESS;
298eda14cbcSMatt Macy Cpa16U i;
299eda14cbcSMatt Macy CpaInstanceHandle cy_inst_handle;
300eda14cbcSMatt Macy Cpa16U nr_bufs = (enc_len >> PAGE_SHIFT) + 2;
301eda14cbcSMatt Macy Cpa32U bytes_left = 0;
302eda14cbcSMatt Macy Cpa8S *data = NULL;
303eda14cbcSMatt Macy CpaCySymSessionCtx *cy_session_ctx = NULL;
304eda14cbcSMatt Macy cy_callback_t cb;
305eda14cbcSMatt Macy CpaCySymOpData op_data = { 0 };
306eda14cbcSMatt Macy CpaBufferList src_buffer_list = { 0 };
307eda14cbcSMatt Macy CpaBufferList dst_buffer_list = { 0 };
308eda14cbcSMatt Macy CpaFlatBuffer *flat_src_buf_array = NULL;
309eda14cbcSMatt Macy CpaFlatBuffer *flat_src_buf = NULL;
310eda14cbcSMatt Macy CpaFlatBuffer *flat_dst_buf_array = NULL;
311eda14cbcSMatt Macy CpaFlatBuffer *flat_dst_buf = NULL;
312eda14cbcSMatt Macy struct page *in_pages[MAX_PAGE_NUM];
313eda14cbcSMatt Macy struct page *out_pages[MAX_PAGE_NUM];
314eda14cbcSMatt Macy Cpa32U in_page_num = 0;
315eda14cbcSMatt Macy Cpa32U out_page_num = 0;
316eda14cbcSMatt Macy Cpa32U in_page_off = 0;
317eda14cbcSMatt Macy Cpa32U out_page_off = 0;
318eda14cbcSMatt Macy
319eda14cbcSMatt Macy if (dir == QAT_ENCRYPT) {
320eda14cbcSMatt Macy QAT_STAT_BUMP(encrypt_requests);
321eda14cbcSMatt Macy QAT_STAT_INCR(encrypt_total_in_bytes, enc_len);
322eda14cbcSMatt Macy } else {
323eda14cbcSMatt Macy QAT_STAT_BUMP(decrypt_requests);
324eda14cbcSMatt Macy QAT_STAT_INCR(decrypt_total_in_bytes, enc_len);
325eda14cbcSMatt Macy }
326eda14cbcSMatt Macy
327eda14cbcSMatt Macy i = (Cpa32U)atomic_inc_32_nv(&inst_num) % num_inst;
328eda14cbcSMatt Macy cy_inst_handle = cy_inst_handles[i];
329eda14cbcSMatt Macy
330eda14cbcSMatt Macy status = qat_init_crypt_session_ctx(dir, cy_inst_handle,
331eda14cbcSMatt Macy &cy_session_ctx, key, crypt, aad_len);
332eda14cbcSMatt Macy if (status != CPA_STATUS_SUCCESS) {
333eda14cbcSMatt Macy /* don't count CCM as a failure since it's not supported */
334eda14cbcSMatt Macy if (zio_crypt_table[crypt].ci_crypt_type == ZC_TYPE_GCM)
335eda14cbcSMatt Macy QAT_STAT_BUMP(crypt_fails);
336eda14cbcSMatt Macy return (status);
337eda14cbcSMatt Macy }
338eda14cbcSMatt Macy
339eda14cbcSMatt Macy /*
340eda14cbcSMatt Macy * We increment nr_bufs by 2 to allow us to handle non
341eda14cbcSMatt Macy * page-aligned buffer addresses and buffers whose sizes
342eda14cbcSMatt Macy * are not divisible by PAGE_SIZE.
343eda14cbcSMatt Macy */
344eda14cbcSMatt Macy status = qat_init_cy_buffer_lists(cy_inst_handle, nr_bufs,
345eda14cbcSMatt Macy &src_buffer_list, &dst_buffer_list);
346eda14cbcSMatt Macy if (status != CPA_STATUS_SUCCESS)
347eda14cbcSMatt Macy goto fail;
348eda14cbcSMatt Macy
349eda14cbcSMatt Macy status = QAT_PHYS_CONTIG_ALLOC(&flat_src_buf_array,
350eda14cbcSMatt Macy nr_bufs * sizeof (CpaFlatBuffer));
351eda14cbcSMatt Macy if (status != CPA_STATUS_SUCCESS)
352eda14cbcSMatt Macy goto fail;
353eda14cbcSMatt Macy status = QAT_PHYS_CONTIG_ALLOC(&flat_dst_buf_array,
354eda14cbcSMatt Macy nr_bufs * sizeof (CpaFlatBuffer));
355eda14cbcSMatt Macy if (status != CPA_STATUS_SUCCESS)
356eda14cbcSMatt Macy goto fail;
357eda14cbcSMatt Macy status = QAT_PHYS_CONTIG_ALLOC(&op_data.pDigestResult,
358eda14cbcSMatt Macy ZIO_DATA_MAC_LEN);
359eda14cbcSMatt Macy if (status != CPA_STATUS_SUCCESS)
360eda14cbcSMatt Macy goto fail;
361eda14cbcSMatt Macy status = QAT_PHYS_CONTIG_ALLOC(&op_data.pIv,
362eda14cbcSMatt Macy ZIO_DATA_IV_LEN);
363eda14cbcSMatt Macy if (status != CPA_STATUS_SUCCESS)
364eda14cbcSMatt Macy goto fail;
365eda14cbcSMatt Macy if (aad_len > 0) {
366eda14cbcSMatt Macy status = QAT_PHYS_CONTIG_ALLOC(&op_data.pAdditionalAuthData,
367eda14cbcSMatt Macy aad_len);
368eda14cbcSMatt Macy if (status != CPA_STATUS_SUCCESS)
369eda14cbcSMatt Macy goto fail;
370da5137abSMartin Matuska memcpy(op_data.pAdditionalAuthData, aad_buf, aad_len);
371eda14cbcSMatt Macy }
372eda14cbcSMatt Macy
373eda14cbcSMatt Macy bytes_left = enc_len;
374eda14cbcSMatt Macy data = src_buf;
375eda14cbcSMatt Macy flat_src_buf = flat_src_buf_array;
376eda14cbcSMatt Macy while (bytes_left > 0) {
377eda14cbcSMatt Macy in_page_off = ((long)data & ~PAGE_MASK);
378eda14cbcSMatt Macy in_pages[in_page_num] = qat_mem_to_page(data);
379eda14cbcSMatt Macy flat_src_buf->pData = kmap(in_pages[in_page_num]) + in_page_off;
380eda14cbcSMatt Macy flat_src_buf->dataLenInBytes =
381eda14cbcSMatt Macy min((long)PAGE_SIZE - in_page_off, (long)bytes_left);
382eda14cbcSMatt Macy data += flat_src_buf->dataLenInBytes;
383eda14cbcSMatt Macy bytes_left -= flat_src_buf->dataLenInBytes;
384eda14cbcSMatt Macy flat_src_buf++;
385eda14cbcSMatt Macy in_page_num++;
386eda14cbcSMatt Macy }
387eda14cbcSMatt Macy src_buffer_list.pBuffers = flat_src_buf_array;
388eda14cbcSMatt Macy src_buffer_list.numBuffers = in_page_num;
389eda14cbcSMatt Macy
390eda14cbcSMatt Macy bytes_left = enc_len;
391eda14cbcSMatt Macy data = dst_buf;
392eda14cbcSMatt Macy flat_dst_buf = flat_dst_buf_array;
393eda14cbcSMatt Macy while (bytes_left > 0) {
394eda14cbcSMatt Macy out_page_off = ((long)data & ~PAGE_MASK);
395eda14cbcSMatt Macy out_pages[out_page_num] = qat_mem_to_page(data);
396eda14cbcSMatt Macy flat_dst_buf->pData = kmap(out_pages[out_page_num]) +
397eda14cbcSMatt Macy out_page_off;
398eda14cbcSMatt Macy flat_dst_buf->dataLenInBytes =
399eda14cbcSMatt Macy min((long)PAGE_SIZE - out_page_off, (long)bytes_left);
400eda14cbcSMatt Macy data += flat_dst_buf->dataLenInBytes;
401eda14cbcSMatt Macy bytes_left -= flat_dst_buf->dataLenInBytes;
402eda14cbcSMatt Macy flat_dst_buf++;
403eda14cbcSMatt Macy out_page_num++;
404eda14cbcSMatt Macy }
405eda14cbcSMatt Macy dst_buffer_list.pBuffers = flat_dst_buf_array;
406eda14cbcSMatt Macy dst_buffer_list.numBuffers = out_page_num;
407eda14cbcSMatt Macy
408eda14cbcSMatt Macy op_data.sessionCtx = cy_session_ctx;
409eda14cbcSMatt Macy op_data.packetType = CPA_CY_SYM_PACKET_TYPE_FULL;
410eda14cbcSMatt Macy op_data.cryptoStartSrcOffsetInBytes = 0;
411eda14cbcSMatt Macy op_data.messageLenToCipherInBytes = 0;
412eda14cbcSMatt Macy op_data.hashStartSrcOffsetInBytes = 0;
413eda14cbcSMatt Macy op_data.messageLenToHashInBytes = 0;
414eda14cbcSMatt Macy op_data.messageLenToCipherInBytes = enc_len;
415eda14cbcSMatt Macy op_data.ivLenInBytes = ZIO_DATA_IV_LEN;
416da5137abSMartin Matuska memcpy(op_data.pIv, iv_buf, ZIO_DATA_IV_LEN);
417eda14cbcSMatt Macy /* if dir is QAT_DECRYPT, copy digest_buf to pDigestResult */
418eda14cbcSMatt Macy if (dir == QAT_DECRYPT)
419da5137abSMartin Matuska memcpy(op_data.pDigestResult, digest_buf, ZIO_DATA_MAC_LEN);
420eda14cbcSMatt Macy
421eda14cbcSMatt Macy cb.verify_result = CPA_FALSE;
422eda14cbcSMatt Macy init_completion(&cb.complete);
423eda14cbcSMatt Macy status = cpaCySymPerformOp(cy_inst_handle, &cb, &op_data,
424eda14cbcSMatt Macy &src_buffer_list, &dst_buffer_list, NULL);
425eda14cbcSMatt Macy if (status != CPA_STATUS_SUCCESS)
426eda14cbcSMatt Macy goto fail;
427eda14cbcSMatt Macy
428eda14cbcSMatt Macy /* we now wait until the completion of the operation. */
429eda14cbcSMatt Macy wait_for_completion(&cb.complete);
430eda14cbcSMatt Macy
431eda14cbcSMatt Macy if (cb.verify_result == CPA_FALSE) {
432eda14cbcSMatt Macy status = CPA_STATUS_FAIL;
433eda14cbcSMatt Macy goto fail;
434eda14cbcSMatt Macy }
435eda14cbcSMatt Macy
436eda14cbcSMatt Macy if (dir == QAT_ENCRYPT) {
437eda14cbcSMatt Macy /* if dir is QAT_ENCRYPT, save pDigestResult to digest_buf */
438da5137abSMartin Matuska memcpy(digest_buf, op_data.pDigestResult, ZIO_DATA_MAC_LEN);
439eda14cbcSMatt Macy QAT_STAT_INCR(encrypt_total_out_bytes, enc_len);
440eda14cbcSMatt Macy } else {
441eda14cbcSMatt Macy QAT_STAT_INCR(decrypt_total_out_bytes, enc_len);
442eda14cbcSMatt Macy }
443eda14cbcSMatt Macy
444eda14cbcSMatt Macy fail:
445eda14cbcSMatt Macy if (status != CPA_STATUS_SUCCESS)
446eda14cbcSMatt Macy QAT_STAT_BUMP(crypt_fails);
447eda14cbcSMatt Macy
448eda14cbcSMatt Macy for (i = 0; i < in_page_num; i++)
449eda14cbcSMatt Macy kunmap(in_pages[i]);
450eda14cbcSMatt Macy for (i = 0; i < out_page_num; i++)
451eda14cbcSMatt Macy kunmap(out_pages[i]);
452eda14cbcSMatt Macy
453eda14cbcSMatt Macy cpaCySymRemoveSession(cy_inst_handle, cy_session_ctx);
454eda14cbcSMatt Macy if (aad_len > 0)
455eda14cbcSMatt Macy QAT_PHYS_CONTIG_FREE(op_data.pAdditionalAuthData);
456eda14cbcSMatt Macy QAT_PHYS_CONTIG_FREE(op_data.pIv);
457eda14cbcSMatt Macy QAT_PHYS_CONTIG_FREE(op_data.pDigestResult);
458eda14cbcSMatt Macy QAT_PHYS_CONTIG_FREE(src_buffer_list.pPrivateMetaData);
459eda14cbcSMatt Macy QAT_PHYS_CONTIG_FREE(dst_buffer_list.pPrivateMetaData);
460eda14cbcSMatt Macy QAT_PHYS_CONTIG_FREE(cy_session_ctx);
461eda14cbcSMatt Macy QAT_PHYS_CONTIG_FREE(flat_src_buf_array);
462eda14cbcSMatt Macy QAT_PHYS_CONTIG_FREE(flat_dst_buf_array);
463eda14cbcSMatt Macy
464eda14cbcSMatt Macy return (status);
465eda14cbcSMatt Macy }
466eda14cbcSMatt Macy
467eda14cbcSMatt Macy int
qat_checksum(uint64_t cksum,uint8_t * buf,uint64_t size,zio_cksum_t * zcp)468eda14cbcSMatt Macy qat_checksum(uint64_t cksum, uint8_t *buf, uint64_t size, zio_cksum_t *zcp)
469eda14cbcSMatt Macy {
470eda14cbcSMatt Macy CpaStatus status;
471eda14cbcSMatt Macy Cpa16U i;
472eda14cbcSMatt Macy CpaInstanceHandle cy_inst_handle;
473eda14cbcSMatt Macy Cpa16U nr_bufs = (size >> PAGE_SHIFT) + 2;
474eda14cbcSMatt Macy Cpa32U bytes_left = 0;
475eda14cbcSMatt Macy Cpa8S *data = NULL;
476eda14cbcSMatt Macy CpaCySymSessionCtx *cy_session_ctx = NULL;
477eda14cbcSMatt Macy cy_callback_t cb;
478eda14cbcSMatt Macy Cpa8U *digest_buffer = NULL;
479eda14cbcSMatt Macy CpaCySymOpData op_data = { 0 };
480eda14cbcSMatt Macy CpaBufferList src_buffer_list = { 0 };
481eda14cbcSMatt Macy CpaFlatBuffer *flat_src_buf_array = NULL;
482eda14cbcSMatt Macy CpaFlatBuffer *flat_src_buf = NULL;
483eda14cbcSMatt Macy struct page *in_pages[MAX_PAGE_NUM];
484eda14cbcSMatt Macy Cpa32U page_num = 0;
485eda14cbcSMatt Macy Cpa32U page_off = 0;
486eda14cbcSMatt Macy
487eda14cbcSMatt Macy QAT_STAT_BUMP(cksum_requests);
488eda14cbcSMatt Macy QAT_STAT_INCR(cksum_total_in_bytes, size);
489eda14cbcSMatt Macy
490eda14cbcSMatt Macy i = (Cpa32U)atomic_inc_32_nv(&inst_num) % num_inst;
491eda14cbcSMatt Macy cy_inst_handle = cy_inst_handles[i];
492eda14cbcSMatt Macy
493eda14cbcSMatt Macy status = qat_init_checksum_session_ctx(cy_inst_handle,
494eda14cbcSMatt Macy &cy_session_ctx, cksum);
495eda14cbcSMatt Macy if (status != CPA_STATUS_SUCCESS) {
496eda14cbcSMatt Macy /* don't count unsupported checksums as a failure */
497eda14cbcSMatt Macy if (cksum == ZIO_CHECKSUM_SHA256 ||
498eda14cbcSMatt Macy cksum == ZIO_CHECKSUM_SHA512)
499eda14cbcSMatt Macy QAT_STAT_BUMP(cksum_fails);
500eda14cbcSMatt Macy return (status);
501eda14cbcSMatt Macy }
502eda14cbcSMatt Macy
503eda14cbcSMatt Macy /*
504eda14cbcSMatt Macy * We increment nr_bufs by 2 to allow us to handle non
505eda14cbcSMatt Macy * page-aligned buffer addresses and buffers whose sizes
506eda14cbcSMatt Macy * are not divisible by PAGE_SIZE.
507eda14cbcSMatt Macy */
508eda14cbcSMatt Macy status = qat_init_cy_buffer_lists(cy_inst_handle, nr_bufs,
509eda14cbcSMatt Macy &src_buffer_list, &src_buffer_list);
510eda14cbcSMatt Macy if (status != CPA_STATUS_SUCCESS)
511eda14cbcSMatt Macy goto fail;
512eda14cbcSMatt Macy
513eda14cbcSMatt Macy status = QAT_PHYS_CONTIG_ALLOC(&flat_src_buf_array,
514eda14cbcSMatt Macy nr_bufs * sizeof (CpaFlatBuffer));
515eda14cbcSMatt Macy if (status != CPA_STATUS_SUCCESS)
516eda14cbcSMatt Macy goto fail;
517eda14cbcSMatt Macy status = QAT_PHYS_CONTIG_ALLOC(&digest_buffer,
518eda14cbcSMatt Macy sizeof (zio_cksum_t));
519eda14cbcSMatt Macy if (status != CPA_STATUS_SUCCESS)
520eda14cbcSMatt Macy goto fail;
521eda14cbcSMatt Macy
522eda14cbcSMatt Macy bytes_left = size;
523eda14cbcSMatt Macy data = buf;
524eda14cbcSMatt Macy flat_src_buf = flat_src_buf_array;
525eda14cbcSMatt Macy while (bytes_left > 0) {
526eda14cbcSMatt Macy page_off = ((long)data & ~PAGE_MASK);
527eda14cbcSMatt Macy in_pages[page_num] = qat_mem_to_page(data);
528eda14cbcSMatt Macy flat_src_buf->pData = kmap(in_pages[page_num]) + page_off;
529eda14cbcSMatt Macy flat_src_buf->dataLenInBytes =
530eda14cbcSMatt Macy min((long)PAGE_SIZE - page_off, (long)bytes_left);
531eda14cbcSMatt Macy data += flat_src_buf->dataLenInBytes;
532eda14cbcSMatt Macy bytes_left -= flat_src_buf->dataLenInBytes;
533eda14cbcSMatt Macy flat_src_buf++;
534eda14cbcSMatt Macy page_num++;
535eda14cbcSMatt Macy }
536eda14cbcSMatt Macy src_buffer_list.pBuffers = flat_src_buf_array;
537eda14cbcSMatt Macy src_buffer_list.numBuffers = page_num;
538eda14cbcSMatt Macy
539eda14cbcSMatt Macy op_data.sessionCtx = cy_session_ctx;
540eda14cbcSMatt Macy op_data.packetType = CPA_CY_SYM_PACKET_TYPE_FULL;
541eda14cbcSMatt Macy op_data.hashStartSrcOffsetInBytes = 0;
542eda14cbcSMatt Macy op_data.messageLenToHashInBytes = size;
543eda14cbcSMatt Macy op_data.pDigestResult = digest_buffer;
544eda14cbcSMatt Macy
545eda14cbcSMatt Macy cb.verify_result = CPA_FALSE;
546eda14cbcSMatt Macy init_completion(&cb.complete);
547eda14cbcSMatt Macy status = cpaCySymPerformOp(cy_inst_handle, &cb, &op_data,
548eda14cbcSMatt Macy &src_buffer_list, &src_buffer_list, NULL);
549eda14cbcSMatt Macy if (status != CPA_STATUS_SUCCESS)
550eda14cbcSMatt Macy goto fail;
551eda14cbcSMatt Macy
552eda14cbcSMatt Macy /* we now wait until the completion of the operation. */
553eda14cbcSMatt Macy wait_for_completion(&cb.complete);
554eda14cbcSMatt Macy
555eda14cbcSMatt Macy if (cb.verify_result == CPA_FALSE) {
556eda14cbcSMatt Macy status = CPA_STATUS_FAIL;
557eda14cbcSMatt Macy goto fail;
558eda14cbcSMatt Macy }
559eda14cbcSMatt Macy
560da5137abSMartin Matuska memcpy(zcp, digest_buffer, sizeof (zio_cksum_t));
561eda14cbcSMatt Macy
562eda14cbcSMatt Macy fail:
563eda14cbcSMatt Macy if (status != CPA_STATUS_SUCCESS)
564eda14cbcSMatt Macy QAT_STAT_BUMP(cksum_fails);
565eda14cbcSMatt Macy
566eda14cbcSMatt Macy for (i = 0; i < page_num; i++)
567eda14cbcSMatt Macy kunmap(in_pages[i]);
568eda14cbcSMatt Macy
569eda14cbcSMatt Macy cpaCySymRemoveSession(cy_inst_handle, cy_session_ctx);
570eda14cbcSMatt Macy QAT_PHYS_CONTIG_FREE(digest_buffer);
571eda14cbcSMatt Macy QAT_PHYS_CONTIG_FREE(src_buffer_list.pPrivateMetaData);
572eda14cbcSMatt Macy QAT_PHYS_CONTIG_FREE(cy_session_ctx);
573eda14cbcSMatt Macy QAT_PHYS_CONTIG_FREE(flat_src_buf_array);
574eda14cbcSMatt Macy
575eda14cbcSMatt Macy return (status);
576eda14cbcSMatt Macy }
577eda14cbcSMatt Macy
578eda14cbcSMatt Macy static int
param_set_qat_encrypt(const char * val,zfs_kernel_param_t * kp)579eda14cbcSMatt Macy param_set_qat_encrypt(const char *val, zfs_kernel_param_t *kp)
580eda14cbcSMatt Macy {
581eda14cbcSMatt Macy int ret;
582eda14cbcSMatt Macy int *pvalue = kp->arg;
583eda14cbcSMatt Macy ret = param_set_int(val, kp);
584eda14cbcSMatt Macy if (ret)
585eda14cbcSMatt Macy return (ret);
586eda14cbcSMatt Macy /*
587eda14cbcSMatt Macy * zfs_qat_encrypt_disable = 0: enable qat encrypt
588eda14cbcSMatt Macy * try to initialize qat instance if it has not been done
589eda14cbcSMatt Macy */
590eda14cbcSMatt Macy if (*pvalue == 0 && !qat_cy_init_done) {
591eda14cbcSMatt Macy ret = qat_cy_init();
592eda14cbcSMatt Macy if (ret != 0) {
593eda14cbcSMatt Macy zfs_qat_encrypt_disable = 1;
594eda14cbcSMatt Macy return (ret);
595eda14cbcSMatt Macy }
596eda14cbcSMatt Macy }
597eda14cbcSMatt Macy return (ret);
598eda14cbcSMatt Macy }
599eda14cbcSMatt Macy
600eda14cbcSMatt Macy static int
param_set_qat_checksum(const char * val,zfs_kernel_param_t * kp)601eda14cbcSMatt Macy param_set_qat_checksum(const char *val, zfs_kernel_param_t *kp)
602eda14cbcSMatt Macy {
603eda14cbcSMatt Macy int ret;
604eda14cbcSMatt Macy int *pvalue = kp->arg;
605eda14cbcSMatt Macy ret = param_set_int(val, kp);
606eda14cbcSMatt Macy if (ret)
607eda14cbcSMatt Macy return (ret);
608eda14cbcSMatt Macy /*
609eda14cbcSMatt Macy * set_checksum_param_ops = 0: enable qat checksum
610eda14cbcSMatt Macy * try to initialize qat instance if it has not been done
611eda14cbcSMatt Macy */
612eda14cbcSMatt Macy if (*pvalue == 0 && !qat_cy_init_done) {
613eda14cbcSMatt Macy ret = qat_cy_init();
614eda14cbcSMatt Macy if (ret != 0) {
615eda14cbcSMatt Macy zfs_qat_checksum_disable = 1;
616eda14cbcSMatt Macy return (ret);
617eda14cbcSMatt Macy }
618eda14cbcSMatt Macy }
619eda14cbcSMatt Macy return (ret);
620eda14cbcSMatt Macy }
621eda14cbcSMatt Macy
622eda14cbcSMatt Macy module_param_call(zfs_qat_encrypt_disable, param_set_qat_encrypt,
623eda14cbcSMatt Macy param_get_int, &zfs_qat_encrypt_disable, 0644);
624eda14cbcSMatt Macy MODULE_PARM_DESC(zfs_qat_encrypt_disable, "Enable/Disable QAT encryption");
625eda14cbcSMatt Macy
626eda14cbcSMatt Macy module_param_call(zfs_qat_checksum_disable, param_set_qat_checksum,
627eda14cbcSMatt Macy param_get_int, &zfs_qat_checksum_disable, 0644);
628eda14cbcSMatt Macy MODULE_PARM_DESC(zfs_qat_checksum_disable, "Enable/Disable QAT checksumming");
629eda14cbcSMatt Macy
630eda14cbcSMatt Macy #endif
631