1 // SPDX-License-Identifier: GPL-2.0+
3 * Copyright (c) 2013, Google Inc.
8 #include <fdt_support.h>
10 #include <linux/libfdt.h>
15 #include <asm/global_data.h>
16 DECLARE_GLOBAL_DATA_PTR;
17 #endif /* !USE_HOSTCC*/
19 #include <u-boot/ecdsa.h>
20 #include <u-boot/rsa.h>
21 #include <u-boot/hash-checksum.h>
23 #define IMAGE_MAX_HASHED_NODES 100
25 struct checksum_algo checksum_algos[] = {
28 .checksum_len = SHA1_SUM_LEN,
29 .der_len = SHA1_DER_LEN,
30 .der_prefix = sha1_der_prefix,
32 .calculate_sign = EVP_sha1,
34 .calculate = hash_calculate,
38 .checksum_len = SHA256_SUM_LEN,
39 .der_len = SHA256_DER_LEN,
40 .der_prefix = sha256_der_prefix,
42 .calculate_sign = EVP_sha256,
44 .calculate = hash_calculate,
49 .checksum_len = SHA384_SUM_LEN,
50 .der_len = SHA384_DER_LEN,
51 .der_prefix = sha384_der_prefix,
53 .calculate_sign = EVP_sha384,
55 .calculate = hash_calculate,
61 .checksum_len = SHA512_SUM_LEN,
62 .der_len = SHA512_DER_LEN,
63 .der_prefix = sha512_der_prefix,
65 .calculate_sign = EVP_sha512,
67 .calculate = hash_calculate,
73 struct crypto_algo crypto_algos[] = {
76 .key_len = RSA2048_BYTES,
78 .add_verify_data = rsa_add_verify_data,
83 .key_len = RSA4096_BYTES,
85 .add_verify_data = rsa_add_verify_data,
90 .key_len = ECDSA256_BYTES,
92 .add_verify_data = ecdsa_add_verify_data,
93 .verify = ecdsa_verify,
97 struct padding_algo padding_algos[] = {
100 .verify = padding_pkcs_15_verify,
102 #ifdef CONFIG_FIT_ENABLE_RSASSA_PSS_SUPPORT
105 .verify = padding_pss_verify,
107 #endif /* CONFIG_FIT_ENABLE_RSASSA_PSS_SUPPORT */
110 struct checksum_algo *image_get_checksum_algo(const char *full_name)
115 #if !defined(USE_HOSTCC) && defined(CONFIG_NEEDS_MANUAL_RELOC)
120 for (i = 0; i < ARRAY_SIZE(checksum_algos); i++) {
121 checksum_algos[i].name += gd->reloc_off;
122 #if IMAGE_ENABLE_SIGN
123 checksum_algos[i].calculate_sign += gd->reloc_off;
125 checksum_algos[i].calculate += gd->reloc_off;
130 for (i = 0; i < ARRAY_SIZE(checksum_algos); i++) {
131 name = checksum_algos[i].name;
132 /* Make sure names match and next char is a comma */
133 if (!strncmp(name, full_name, strlen(name)) &&
134 full_name[strlen(name)] == ',')
135 return &checksum_algos[i];
141 struct crypto_algo *image_get_crypto_algo(const char *full_name)
146 #if !defined(USE_HOSTCC) && defined(CONFIG_NEEDS_MANUAL_RELOC)
151 for (i = 0; i < ARRAY_SIZE(crypto_algos); i++) {
152 crypto_algos[i].name += gd->reloc_off;
153 crypto_algos[i].sign += gd->reloc_off;
154 crypto_algos[i].add_verify_data += gd->reloc_off;
155 crypto_algos[i].verify += gd->reloc_off;
160 /* Move name to after the comma */
161 name = strchr(full_name, ',');
166 for (i = 0; i < ARRAY_SIZE(crypto_algos); i++) {
167 if (!strcmp(crypto_algos[i].name, name))
168 return &crypto_algos[i];
174 struct padding_algo *image_get_padding_algo(const char *name)
181 for (i = 0; i < ARRAY_SIZE(padding_algos); i++) {
182 if (!strcmp(padding_algos[i].name, name))
183 return &padding_algos[i];