WIP: update tizen_qemu_defconfig
[platform/kernel/linux-starfive.git] / crypto / algapi.c
1 // SPDX-License-Identifier: GPL-2.0-or-later
2 /*
3  * Cryptographic API for algorithms (i.e., low-level API).
4  *
5  * Copyright (c) 2006 Herbert Xu <herbert@gondor.apana.org.au>
6  */
7
8 #include <crypto/algapi.h>
9 #include <crypto/internal/simd.h>
10 #include <linux/err.h>
11 #include <linux/errno.h>
12 #include <linux/fips.h>
13 #include <linux/init.h>
14 #include <linux/kernel.h>
15 #include <linux/list.h>
16 #include <linux/module.h>
17 #include <linux/rtnetlink.h>
18 #include <linux/slab.h>
19 #include <linux/string.h>
20
21 #include "internal.h"
22
23 static LIST_HEAD(crypto_template_list);
24
25 #ifdef CONFIG_CRYPTO_MANAGER_EXTRA_TESTS
26 DEFINE_PER_CPU(bool, crypto_simd_disabled_for_test);
27 EXPORT_PER_CPU_SYMBOL_GPL(crypto_simd_disabled_for_test);
28 #endif
29
30 static inline void crypto_check_module_sig(struct module *mod)
31 {
32         if (fips_enabled && mod && !module_sig_ok(mod))
33                 panic("Module %s signature verification failed in FIPS mode\n",
34                       module_name(mod));
35 }
36
37 static int crypto_check_alg(struct crypto_alg *alg)
38 {
39         crypto_check_module_sig(alg->cra_module);
40
41         if (!alg->cra_name[0] || !alg->cra_driver_name[0])
42                 return -EINVAL;
43
44         if (alg->cra_alignmask & (alg->cra_alignmask + 1))
45                 return -EINVAL;
46
47         /* General maximums for all algs. */
48         if (alg->cra_alignmask > MAX_ALGAPI_ALIGNMASK)
49                 return -EINVAL;
50
51         if (alg->cra_blocksize > MAX_ALGAPI_BLOCKSIZE)
52                 return -EINVAL;
53
54         /* Lower maximums for specific alg types. */
55         if (!alg->cra_type && (alg->cra_flags & CRYPTO_ALG_TYPE_MASK) ==
56                                CRYPTO_ALG_TYPE_CIPHER) {
57                 if (alg->cra_alignmask > MAX_CIPHER_ALIGNMASK)
58                         return -EINVAL;
59
60                 if (alg->cra_blocksize > MAX_CIPHER_BLOCKSIZE)
61                         return -EINVAL;
62         }
63
64         if (alg->cra_priority < 0)
65                 return -EINVAL;
66
67         refcount_set(&alg->cra_refcnt, 1);
68
69         return 0;
70 }
71
72 static void crypto_free_instance(struct crypto_instance *inst)
73 {
74         inst->alg.cra_type->free(inst);
75 }
76
77 static void crypto_destroy_instance(struct crypto_alg *alg)
78 {
79         struct crypto_instance *inst = (void *)alg;
80         struct crypto_template *tmpl = inst->tmpl;
81
82         crypto_free_instance(inst);
83         crypto_tmpl_put(tmpl);
84 }
85
86 /*
87  * This function adds a spawn to the list secondary_spawns which
88  * will be used at the end of crypto_remove_spawns to unregister
89  * instances, unless the spawn happens to be one that is depended
90  * on by the new algorithm (nalg in crypto_remove_spawns).
91  *
92  * This function is also responsible for resurrecting any algorithms
93  * in the dependency chain of nalg by unsetting n->dead.
94  */
95 static struct list_head *crypto_more_spawns(struct crypto_alg *alg,
96                                             struct list_head *stack,
97                                             struct list_head *top,
98                                             struct list_head *secondary_spawns)
99 {
100         struct crypto_spawn *spawn, *n;
101
102         spawn = list_first_entry_or_null(stack, struct crypto_spawn, list);
103         if (!spawn)
104                 return NULL;
105
106         n = list_prev_entry(spawn, list);
107         list_move(&spawn->list, secondary_spawns);
108
109         if (list_is_last(&n->list, stack))
110                 return top;
111
112         n = list_next_entry(n, list);
113         if (!spawn->dead)
114                 n->dead = false;
115
116         return &n->inst->alg.cra_users;
117 }
118
119 static void crypto_remove_instance(struct crypto_instance *inst,
120                                    struct list_head *list)
121 {
122         struct crypto_template *tmpl = inst->tmpl;
123
124         if (crypto_is_dead(&inst->alg))
125                 return;
126
127         inst->alg.cra_flags |= CRYPTO_ALG_DEAD;
128
129         if (!tmpl || !crypto_tmpl_get(tmpl))
130                 return;
131
132         list_move(&inst->alg.cra_list, list);
133         hlist_del(&inst->list);
134         inst->alg.cra_destroy = crypto_destroy_instance;
135
136         BUG_ON(!list_empty(&inst->alg.cra_users));
137 }
138
139 /*
140  * Given an algorithm alg, remove all algorithms that depend on it
141  * through spawns.  If nalg is not null, then exempt any algorithms
142  * that is depended on by nalg.  This is useful when nalg itself
143  * depends on alg.
144  */
145 void crypto_remove_spawns(struct crypto_alg *alg, struct list_head *list,
146                           struct crypto_alg *nalg)
147 {
148         u32 new_type = (nalg ?: alg)->cra_flags;
149         struct crypto_spawn *spawn, *n;
150         LIST_HEAD(secondary_spawns);
151         struct list_head *spawns;
152         LIST_HEAD(stack);
153         LIST_HEAD(top);
154
155         spawns = &alg->cra_users;
156         list_for_each_entry_safe(spawn, n, spawns, list) {
157                 if ((spawn->alg->cra_flags ^ new_type) & spawn->mask)
158                         continue;
159
160                 list_move(&spawn->list, &top);
161         }
162
163         /*
164          * Perform a depth-first walk starting from alg through
165          * the cra_users tree.  The list stack records the path
166          * from alg to the current spawn.
167          */
168         spawns = &top;
169         do {
170                 while (!list_empty(spawns)) {
171                         struct crypto_instance *inst;
172
173                         spawn = list_first_entry(spawns, struct crypto_spawn,
174                                                  list);
175                         inst = spawn->inst;
176
177                         list_move(&spawn->list, &stack);
178                         spawn->dead = !spawn->registered || &inst->alg != nalg;
179
180                         if (!spawn->registered)
181                                 break;
182
183                         BUG_ON(&inst->alg == alg);
184
185                         if (&inst->alg == nalg)
186                                 break;
187
188                         spawns = &inst->alg.cra_users;
189
190                         /*
191                          * Even if spawn->registered is true, the
192                          * instance itself may still be unregistered.
193                          * This is because it may have failed during
194                          * registration.  Therefore we still need to
195                          * make the following test.
196                          *
197                          * We may encounter an unregistered instance here, since
198                          * an instance's spawns are set up prior to the instance
199                          * being registered.  An unregistered instance will have
200                          * NULL ->cra_users.next, since ->cra_users isn't
201                          * properly initialized until registration.  But an
202                          * unregistered instance cannot have any users, so treat
203                          * it the same as ->cra_users being empty.
204                          */
205                         if (spawns->next == NULL)
206                                 break;
207                 }
208         } while ((spawns = crypto_more_spawns(alg, &stack, &top,
209                                               &secondary_spawns)));
210
211         /*
212          * Remove all instances that are marked as dead.  Also
213          * complete the resurrection of the others by moving them
214          * back to the cra_users list.
215          */
216         list_for_each_entry_safe(spawn, n, &secondary_spawns, list) {
217                 if (!spawn->dead)
218                         list_move(&spawn->list, &spawn->alg->cra_users);
219                 else if (spawn->registered)
220                         crypto_remove_instance(spawn->inst, list);
221         }
222 }
223 EXPORT_SYMBOL_GPL(crypto_remove_spawns);
224
225 static struct crypto_larval *crypto_alloc_test_larval(struct crypto_alg *alg)
226 {
227         struct crypto_larval *larval;
228
229         if (!IS_ENABLED(CONFIG_CRYPTO_MANAGER))
230                 return NULL;
231
232         larval = crypto_larval_alloc(alg->cra_name,
233                                      alg->cra_flags | CRYPTO_ALG_TESTED, 0);
234         if (IS_ERR(larval))
235                 return larval;
236
237         larval->adult = crypto_mod_get(alg);
238         if (!larval->adult) {
239                 kfree(larval);
240                 return ERR_PTR(-ENOENT);
241         }
242
243         refcount_set(&larval->alg.cra_refcnt, 1);
244         memcpy(larval->alg.cra_driver_name, alg->cra_driver_name,
245                CRYPTO_MAX_ALG_NAME);
246         larval->alg.cra_priority = alg->cra_priority;
247
248         return larval;
249 }
250
251 static struct crypto_larval *__crypto_register_alg(struct crypto_alg *alg)
252 {
253         struct crypto_alg *q;
254         struct crypto_larval *larval;
255         int ret = -EAGAIN;
256
257         if (crypto_is_dead(alg))
258                 goto err;
259
260         INIT_LIST_HEAD(&alg->cra_users);
261
262         /* No cheating! */
263         alg->cra_flags &= ~CRYPTO_ALG_TESTED;
264
265         ret = -EEXIST;
266
267         list_for_each_entry(q, &crypto_alg_list, cra_list) {
268                 if (q == alg)
269                         goto err;
270
271                 if (crypto_is_moribund(q))
272                         continue;
273
274                 if (crypto_is_larval(q)) {
275                         if (!strcmp(alg->cra_driver_name, q->cra_driver_name))
276                                 goto err;
277                         continue;
278                 }
279
280                 if (!strcmp(q->cra_driver_name, alg->cra_name) ||
281                     !strcmp(q->cra_name, alg->cra_driver_name))
282                         goto err;
283         }
284
285         larval = crypto_alloc_test_larval(alg);
286         if (IS_ERR(larval))
287                 goto out;
288
289         list_add(&alg->cra_list, &crypto_alg_list);
290
291         if (larval)
292                 list_add(&larval->alg.cra_list, &crypto_alg_list);
293         else
294                 alg->cra_flags |= CRYPTO_ALG_TESTED;
295
296         crypto_stats_init(alg);
297
298 out:
299         return larval;
300
301 err:
302         larval = ERR_PTR(ret);
303         goto out;
304 }
305
306 void crypto_alg_tested(const char *name, int err)
307 {
308         struct crypto_larval *test;
309         struct crypto_alg *alg;
310         struct crypto_alg *q;
311         LIST_HEAD(list);
312         bool best;
313
314         down_write(&crypto_alg_sem);
315         list_for_each_entry(q, &crypto_alg_list, cra_list) {
316                 if (crypto_is_moribund(q) || !crypto_is_larval(q))
317                         continue;
318
319                 test = (struct crypto_larval *)q;
320
321                 if (!strcmp(q->cra_driver_name, name))
322                         goto found;
323         }
324
325         pr_err("alg: Unexpected test result for %s: %d\n", name, err);
326         goto unlock;
327
328 found:
329         q->cra_flags |= CRYPTO_ALG_DEAD;
330         alg = test->adult;
331
332         if (list_empty(&alg->cra_list))
333                 goto complete;
334
335         if (err == -ECANCELED)
336                 alg->cra_flags |= CRYPTO_ALG_FIPS_INTERNAL;
337         else if (err)
338                 goto complete;
339         else
340                 alg->cra_flags &= ~CRYPTO_ALG_FIPS_INTERNAL;
341
342         alg->cra_flags |= CRYPTO_ALG_TESTED;
343
344         /* Only satisfy larval waiters if we are the best. */
345         best = true;
346         list_for_each_entry(q, &crypto_alg_list, cra_list) {
347                 if (crypto_is_moribund(q) || !crypto_is_larval(q))
348                         continue;
349
350                 if (strcmp(alg->cra_name, q->cra_name))
351                         continue;
352
353                 if (q->cra_priority > alg->cra_priority) {
354                         best = false;
355                         break;
356                 }
357         }
358
359         list_for_each_entry(q, &crypto_alg_list, cra_list) {
360                 if (q == alg)
361                         continue;
362
363                 if (crypto_is_moribund(q))
364                         continue;
365
366                 if (crypto_is_larval(q)) {
367                         struct crypto_larval *larval = (void *)q;
368
369                         /*
370                          * Check to see if either our generic name or
371                          * specific name can satisfy the name requested
372                          * by the larval entry q.
373                          */
374                         if (strcmp(alg->cra_name, q->cra_name) &&
375                             strcmp(alg->cra_driver_name, q->cra_name))
376                                 continue;
377
378                         if (larval->adult)
379                                 continue;
380                         if ((q->cra_flags ^ alg->cra_flags) & larval->mask)
381                                 continue;
382
383                         if (best && crypto_mod_get(alg))
384                                 larval->adult = alg;
385                         else
386                                 larval->adult = ERR_PTR(-EAGAIN);
387
388                         continue;
389                 }
390
391                 if (strcmp(alg->cra_name, q->cra_name))
392                         continue;
393
394                 if (strcmp(alg->cra_driver_name, q->cra_driver_name) &&
395                     q->cra_priority > alg->cra_priority)
396                         continue;
397
398                 crypto_remove_spawns(q, &list, alg);
399         }
400
401 complete:
402         complete_all(&test->completion);
403
404 unlock:
405         up_write(&crypto_alg_sem);
406
407         crypto_remove_final(&list);
408 }
409 EXPORT_SYMBOL_GPL(crypto_alg_tested);
410
411 void crypto_remove_final(struct list_head *list)
412 {
413         struct crypto_alg *alg;
414         struct crypto_alg *n;
415
416         list_for_each_entry_safe(alg, n, list, cra_list) {
417                 list_del_init(&alg->cra_list);
418                 crypto_alg_put(alg);
419         }
420 }
421 EXPORT_SYMBOL_GPL(crypto_remove_final);
422
423 int crypto_register_alg(struct crypto_alg *alg)
424 {
425         struct crypto_larval *larval;
426         bool test_started;
427         int err;
428
429         alg->cra_flags &= ~CRYPTO_ALG_DEAD;
430         err = crypto_check_alg(alg);
431         if (err)
432                 return err;
433
434         down_write(&crypto_alg_sem);
435         larval = __crypto_register_alg(alg);
436         test_started = static_key_enabled(&crypto_boot_test_finished);
437         if (!IS_ERR_OR_NULL(larval))
438                 larval->test_started = test_started;
439         up_write(&crypto_alg_sem);
440
441         if (IS_ERR_OR_NULL(larval))
442                 return PTR_ERR(larval);
443
444         if (test_started)
445                 crypto_wait_for_test(larval);
446         return 0;
447 }
448 EXPORT_SYMBOL_GPL(crypto_register_alg);
449
450 static int crypto_remove_alg(struct crypto_alg *alg, struct list_head *list)
451 {
452         if (unlikely(list_empty(&alg->cra_list)))
453                 return -ENOENT;
454
455         alg->cra_flags |= CRYPTO_ALG_DEAD;
456
457         list_del_init(&alg->cra_list);
458         crypto_remove_spawns(alg, list, NULL);
459
460         return 0;
461 }
462
463 void crypto_unregister_alg(struct crypto_alg *alg)
464 {
465         int ret;
466         LIST_HEAD(list);
467
468         down_write(&crypto_alg_sem);
469         ret = crypto_remove_alg(alg, &list);
470         up_write(&crypto_alg_sem);
471
472         if (WARN(ret, "Algorithm %s is not registered", alg->cra_driver_name))
473                 return;
474
475         if (WARN_ON(refcount_read(&alg->cra_refcnt) != 1))
476                 return;
477
478         if (alg->cra_destroy)
479                 alg->cra_destroy(alg);
480
481         crypto_remove_final(&list);
482 }
483 EXPORT_SYMBOL_GPL(crypto_unregister_alg);
484
485 int crypto_register_algs(struct crypto_alg *algs, int count)
486 {
487         int i, ret;
488
489         for (i = 0; i < count; i++) {
490                 ret = crypto_register_alg(&algs[i]);
491                 if (ret)
492                         goto err;
493         }
494
495         return 0;
496
497 err:
498         for (--i; i >= 0; --i)
499                 crypto_unregister_alg(&algs[i]);
500
501         return ret;
502 }
503 EXPORT_SYMBOL_GPL(crypto_register_algs);
504
505 void crypto_unregister_algs(struct crypto_alg *algs, int count)
506 {
507         int i;
508
509         for (i = 0; i < count; i++)
510                 crypto_unregister_alg(&algs[i]);
511 }
512 EXPORT_SYMBOL_GPL(crypto_unregister_algs);
513
514 int crypto_register_template(struct crypto_template *tmpl)
515 {
516         struct crypto_template *q;
517         int err = -EEXIST;
518
519         down_write(&crypto_alg_sem);
520
521         crypto_check_module_sig(tmpl->module);
522
523         list_for_each_entry(q, &crypto_template_list, list) {
524                 if (q == tmpl)
525                         goto out;
526         }
527
528         list_add(&tmpl->list, &crypto_template_list);
529         err = 0;
530 out:
531         up_write(&crypto_alg_sem);
532         return err;
533 }
534 EXPORT_SYMBOL_GPL(crypto_register_template);
535
536 int crypto_register_templates(struct crypto_template *tmpls, int count)
537 {
538         int i, err;
539
540         for (i = 0; i < count; i++) {
541                 err = crypto_register_template(&tmpls[i]);
542                 if (err)
543                         goto out;
544         }
545         return 0;
546
547 out:
548         for (--i; i >= 0; --i)
549                 crypto_unregister_template(&tmpls[i]);
550         return err;
551 }
552 EXPORT_SYMBOL_GPL(crypto_register_templates);
553
554 void crypto_unregister_template(struct crypto_template *tmpl)
555 {
556         struct crypto_instance *inst;
557         struct hlist_node *n;
558         struct hlist_head *list;
559         LIST_HEAD(users);
560
561         down_write(&crypto_alg_sem);
562
563         BUG_ON(list_empty(&tmpl->list));
564         list_del_init(&tmpl->list);
565
566         list = &tmpl->instances;
567         hlist_for_each_entry(inst, list, list) {
568                 int err = crypto_remove_alg(&inst->alg, &users);
569
570                 BUG_ON(err);
571         }
572
573         up_write(&crypto_alg_sem);
574
575         hlist_for_each_entry_safe(inst, n, list, list) {
576                 BUG_ON(refcount_read(&inst->alg.cra_refcnt) != 1);
577                 crypto_free_instance(inst);
578         }
579         crypto_remove_final(&users);
580 }
581 EXPORT_SYMBOL_GPL(crypto_unregister_template);
582
583 void crypto_unregister_templates(struct crypto_template *tmpls, int count)
584 {
585         int i;
586
587         for (i = count - 1; i >= 0; --i)
588                 crypto_unregister_template(&tmpls[i]);
589 }
590 EXPORT_SYMBOL_GPL(crypto_unregister_templates);
591
592 static struct crypto_template *__crypto_lookup_template(const char *name)
593 {
594         struct crypto_template *q, *tmpl = NULL;
595
596         down_read(&crypto_alg_sem);
597         list_for_each_entry(q, &crypto_template_list, list) {
598                 if (strcmp(q->name, name))
599                         continue;
600                 if (unlikely(!crypto_tmpl_get(q)))
601                         continue;
602
603                 tmpl = q;
604                 break;
605         }
606         up_read(&crypto_alg_sem);
607
608         return tmpl;
609 }
610
611 struct crypto_template *crypto_lookup_template(const char *name)
612 {
613         return try_then_request_module(__crypto_lookup_template(name),
614                                        "crypto-%s", name);
615 }
616 EXPORT_SYMBOL_GPL(crypto_lookup_template);
617
618 int crypto_register_instance(struct crypto_template *tmpl,
619                              struct crypto_instance *inst)
620 {
621         struct crypto_larval *larval;
622         struct crypto_spawn *spawn;
623         u32 fips_internal = 0;
624         int err;
625
626         err = crypto_check_alg(&inst->alg);
627         if (err)
628                 return err;
629
630         inst->alg.cra_module = tmpl->module;
631         inst->alg.cra_flags |= CRYPTO_ALG_INSTANCE;
632
633         down_write(&crypto_alg_sem);
634
635         larval = ERR_PTR(-EAGAIN);
636         for (spawn = inst->spawns; spawn;) {
637                 struct crypto_spawn *next;
638
639                 if (spawn->dead)
640                         goto unlock;
641
642                 next = spawn->next;
643                 spawn->inst = inst;
644                 spawn->registered = true;
645
646                 fips_internal |= spawn->alg->cra_flags;
647
648                 crypto_mod_put(spawn->alg);
649
650                 spawn = next;
651         }
652
653         inst->alg.cra_flags |= (fips_internal & CRYPTO_ALG_FIPS_INTERNAL);
654
655         larval = __crypto_register_alg(&inst->alg);
656         if (IS_ERR(larval))
657                 goto unlock;
658         else if (larval)
659                 larval->test_started = true;
660
661         hlist_add_head(&inst->list, &tmpl->instances);
662         inst->tmpl = tmpl;
663
664 unlock:
665         up_write(&crypto_alg_sem);
666
667         err = PTR_ERR(larval);
668         if (IS_ERR_OR_NULL(larval))
669                 goto err;
670
671         crypto_wait_for_test(larval);
672         err = 0;
673
674 err:
675         return err;
676 }
677 EXPORT_SYMBOL_GPL(crypto_register_instance);
678
679 void crypto_unregister_instance(struct crypto_instance *inst)
680 {
681         LIST_HEAD(list);
682
683         down_write(&crypto_alg_sem);
684
685         crypto_remove_spawns(&inst->alg, &list, NULL);
686         crypto_remove_instance(inst, &list);
687
688         up_write(&crypto_alg_sem);
689
690         crypto_remove_final(&list);
691 }
692 EXPORT_SYMBOL_GPL(crypto_unregister_instance);
693
694 int crypto_grab_spawn(struct crypto_spawn *spawn, struct crypto_instance *inst,
695                       const char *name, u32 type, u32 mask)
696 {
697         struct crypto_alg *alg;
698         int err = -EAGAIN;
699
700         if (WARN_ON_ONCE(inst == NULL))
701                 return -EINVAL;
702
703         /* Allow the result of crypto_attr_alg_name() to be passed directly */
704         if (IS_ERR(name))
705                 return PTR_ERR(name);
706
707         alg = crypto_find_alg(name, spawn->frontend,
708                               type | CRYPTO_ALG_FIPS_INTERNAL, mask);
709         if (IS_ERR(alg))
710                 return PTR_ERR(alg);
711
712         down_write(&crypto_alg_sem);
713         if (!crypto_is_moribund(alg)) {
714                 list_add(&spawn->list, &alg->cra_users);
715                 spawn->alg = alg;
716                 spawn->mask = mask;
717                 spawn->next = inst->spawns;
718                 inst->spawns = spawn;
719                 inst->alg.cra_flags |=
720                         (alg->cra_flags & CRYPTO_ALG_INHERITED_FLAGS);
721                 err = 0;
722         }
723         up_write(&crypto_alg_sem);
724         if (err)
725                 crypto_mod_put(alg);
726         return err;
727 }
728 EXPORT_SYMBOL_GPL(crypto_grab_spawn);
729
730 void crypto_drop_spawn(struct crypto_spawn *spawn)
731 {
732         if (!spawn->alg) /* not yet initialized? */
733                 return;
734
735         down_write(&crypto_alg_sem);
736         if (!spawn->dead)
737                 list_del(&spawn->list);
738         up_write(&crypto_alg_sem);
739
740         if (!spawn->registered)
741                 crypto_mod_put(spawn->alg);
742 }
743 EXPORT_SYMBOL_GPL(crypto_drop_spawn);
744
745 static struct crypto_alg *crypto_spawn_alg(struct crypto_spawn *spawn)
746 {
747         struct crypto_alg *alg = ERR_PTR(-EAGAIN);
748         struct crypto_alg *target;
749         bool shoot = false;
750
751         down_read(&crypto_alg_sem);
752         if (!spawn->dead) {
753                 alg = spawn->alg;
754                 if (!crypto_mod_get(alg)) {
755                         target = crypto_alg_get(alg);
756                         shoot = true;
757                         alg = ERR_PTR(-EAGAIN);
758                 }
759         }
760         up_read(&crypto_alg_sem);
761
762         if (shoot) {
763                 crypto_shoot_alg(target);
764                 crypto_alg_put(target);
765         }
766
767         return alg;
768 }
769
770 struct crypto_tfm *crypto_spawn_tfm(struct crypto_spawn *spawn, u32 type,
771                                     u32 mask)
772 {
773         struct crypto_alg *alg;
774         struct crypto_tfm *tfm;
775
776         alg = crypto_spawn_alg(spawn);
777         if (IS_ERR(alg))
778                 return ERR_CAST(alg);
779
780         tfm = ERR_PTR(-EINVAL);
781         if (unlikely((alg->cra_flags ^ type) & mask))
782                 goto out_put_alg;
783
784         tfm = __crypto_alloc_tfm(alg, type, mask);
785         if (IS_ERR(tfm))
786                 goto out_put_alg;
787
788         return tfm;
789
790 out_put_alg:
791         crypto_mod_put(alg);
792         return tfm;
793 }
794 EXPORT_SYMBOL_GPL(crypto_spawn_tfm);
795
796 void *crypto_spawn_tfm2(struct crypto_spawn *spawn)
797 {
798         struct crypto_alg *alg;
799         struct crypto_tfm *tfm;
800
801         alg = crypto_spawn_alg(spawn);
802         if (IS_ERR(alg))
803                 return ERR_CAST(alg);
804
805         tfm = crypto_create_tfm(alg, spawn->frontend);
806         if (IS_ERR(tfm))
807                 goto out_put_alg;
808
809         return tfm;
810
811 out_put_alg:
812         crypto_mod_put(alg);
813         return tfm;
814 }
815 EXPORT_SYMBOL_GPL(crypto_spawn_tfm2);
816
817 int crypto_register_notifier(struct notifier_block *nb)
818 {
819         return blocking_notifier_chain_register(&crypto_chain, nb);
820 }
821 EXPORT_SYMBOL_GPL(crypto_register_notifier);
822
823 int crypto_unregister_notifier(struct notifier_block *nb)
824 {
825         return blocking_notifier_chain_unregister(&crypto_chain, nb);
826 }
827 EXPORT_SYMBOL_GPL(crypto_unregister_notifier);
828
829 struct crypto_attr_type *crypto_get_attr_type(struct rtattr **tb)
830 {
831         struct rtattr *rta = tb[0];
832         struct crypto_attr_type *algt;
833
834         if (!rta)
835                 return ERR_PTR(-ENOENT);
836         if (RTA_PAYLOAD(rta) < sizeof(*algt))
837                 return ERR_PTR(-EINVAL);
838         if (rta->rta_type != CRYPTOA_TYPE)
839                 return ERR_PTR(-EINVAL);
840
841         algt = RTA_DATA(rta);
842
843         return algt;
844 }
845 EXPORT_SYMBOL_GPL(crypto_get_attr_type);
846
847 /**
848  * crypto_check_attr_type() - check algorithm type and compute inherited mask
849  * @tb: the template parameters
850  * @type: the algorithm type the template would be instantiated as
851  * @mask_ret: (output) the mask that should be passed to crypto_grab_*()
852  *            to restrict the flags of any inner algorithms
853  *
854  * Validate that the algorithm type the user requested is compatible with the
855  * one the template would actually be instantiated as.  E.g., if the user is
856  * doing crypto_alloc_shash("cbc(aes)", ...), this would return an error because
857  * the "cbc" template creates an "skcipher" algorithm, not an "shash" algorithm.
858  *
859  * Also compute the mask to use to restrict the flags of any inner algorithms.
860  *
861  * Return: 0 on success; -errno on failure
862  */
863 int crypto_check_attr_type(struct rtattr **tb, u32 type, u32 *mask_ret)
864 {
865         struct crypto_attr_type *algt;
866
867         algt = crypto_get_attr_type(tb);
868         if (IS_ERR(algt))
869                 return PTR_ERR(algt);
870
871         if ((algt->type ^ type) & algt->mask)
872                 return -EINVAL;
873
874         *mask_ret = crypto_algt_inherited_mask(algt);
875         return 0;
876 }
877 EXPORT_SYMBOL_GPL(crypto_check_attr_type);
878
879 const char *crypto_attr_alg_name(struct rtattr *rta)
880 {
881         struct crypto_attr_alg *alga;
882
883         if (!rta)
884                 return ERR_PTR(-ENOENT);
885         if (RTA_PAYLOAD(rta) < sizeof(*alga))
886                 return ERR_PTR(-EINVAL);
887         if (rta->rta_type != CRYPTOA_ALG)
888                 return ERR_PTR(-EINVAL);
889
890         alga = RTA_DATA(rta);
891         alga->name[CRYPTO_MAX_ALG_NAME - 1] = 0;
892
893         return alga->name;
894 }
895 EXPORT_SYMBOL_GPL(crypto_attr_alg_name);
896
897 int crypto_inst_setname(struct crypto_instance *inst, const char *name,
898                         struct crypto_alg *alg)
899 {
900         if (snprintf(inst->alg.cra_name, CRYPTO_MAX_ALG_NAME, "%s(%s)", name,
901                      alg->cra_name) >= CRYPTO_MAX_ALG_NAME)
902                 return -ENAMETOOLONG;
903
904         if (snprintf(inst->alg.cra_driver_name, CRYPTO_MAX_ALG_NAME, "%s(%s)",
905                      name, alg->cra_driver_name) >= CRYPTO_MAX_ALG_NAME)
906                 return -ENAMETOOLONG;
907
908         return 0;
909 }
910 EXPORT_SYMBOL_GPL(crypto_inst_setname);
911
912 void crypto_init_queue(struct crypto_queue *queue, unsigned int max_qlen)
913 {
914         INIT_LIST_HEAD(&queue->list);
915         queue->backlog = &queue->list;
916         queue->qlen = 0;
917         queue->max_qlen = max_qlen;
918 }
919 EXPORT_SYMBOL_GPL(crypto_init_queue);
920
921 int crypto_enqueue_request(struct crypto_queue *queue,
922                            struct crypto_async_request *request)
923 {
924         int err = -EINPROGRESS;
925
926         if (unlikely(queue->qlen >= queue->max_qlen)) {
927                 if (!(request->flags & CRYPTO_TFM_REQ_MAY_BACKLOG)) {
928                         err = -ENOSPC;
929                         goto out;
930                 }
931                 err = -EBUSY;
932                 if (queue->backlog == &queue->list)
933                         queue->backlog = &request->list;
934         }
935
936         queue->qlen++;
937         list_add_tail(&request->list, &queue->list);
938
939 out:
940         return err;
941 }
942 EXPORT_SYMBOL_GPL(crypto_enqueue_request);
943
944 void crypto_enqueue_request_head(struct crypto_queue *queue,
945                                  struct crypto_async_request *request)
946 {
947         if (unlikely(queue->qlen >= queue->max_qlen))
948                 queue->backlog = queue->backlog->prev;
949
950         queue->qlen++;
951         list_add(&request->list, &queue->list);
952 }
953 EXPORT_SYMBOL_GPL(crypto_enqueue_request_head);
954
955 struct crypto_async_request *crypto_dequeue_request(struct crypto_queue *queue)
956 {
957         struct list_head *request;
958
959         if (unlikely(!queue->qlen))
960                 return NULL;
961
962         queue->qlen--;
963
964         if (queue->backlog != &queue->list)
965                 queue->backlog = queue->backlog->next;
966
967         request = queue->list.next;
968         list_del(request);
969
970         return list_entry(request, struct crypto_async_request, list);
971 }
972 EXPORT_SYMBOL_GPL(crypto_dequeue_request);
973
974 static inline void crypto_inc_byte(u8 *a, unsigned int size)
975 {
976         u8 *b = (a + size);
977         u8 c;
978
979         for (; size; size--) {
980                 c = *--b + 1;
981                 *b = c;
982                 if (c)
983                         break;
984         }
985 }
986
987 void crypto_inc(u8 *a, unsigned int size)
988 {
989         __be32 *b = (__be32 *)(a + size);
990         u32 c;
991
992         if (IS_ENABLED(CONFIG_HAVE_EFFICIENT_UNALIGNED_ACCESS) ||
993             IS_ALIGNED((unsigned long)b, __alignof__(*b)))
994                 for (; size >= 4; size -= 4) {
995                         c = be32_to_cpu(*--b) + 1;
996                         *b = cpu_to_be32(c);
997                         if (likely(c))
998                                 return;
999                 }
1000
1001         crypto_inc_byte(a, size);
1002 }
1003 EXPORT_SYMBOL_GPL(crypto_inc);
1004
1005 unsigned int crypto_alg_extsize(struct crypto_alg *alg)
1006 {
1007         return alg->cra_ctxsize +
1008                (alg->cra_alignmask & ~(crypto_tfm_ctx_alignment() - 1));
1009 }
1010 EXPORT_SYMBOL_GPL(crypto_alg_extsize);
1011
1012 int crypto_type_has_alg(const char *name, const struct crypto_type *frontend,
1013                         u32 type, u32 mask)
1014 {
1015         int ret = 0;
1016         struct crypto_alg *alg = crypto_find_alg(name, frontend, type, mask);
1017
1018         if (!IS_ERR(alg)) {
1019                 crypto_mod_put(alg);
1020                 ret = 1;
1021         }
1022
1023         return ret;
1024 }
1025 EXPORT_SYMBOL_GPL(crypto_type_has_alg);
1026
1027 #ifdef CONFIG_CRYPTO_STATS
1028 void crypto_stats_init(struct crypto_alg *alg)
1029 {
1030         memset(&alg->stats, 0, sizeof(alg->stats));
1031 }
1032 EXPORT_SYMBOL_GPL(crypto_stats_init);
1033
1034 void crypto_stats_get(struct crypto_alg *alg)
1035 {
1036         crypto_alg_get(alg);
1037 }
1038 EXPORT_SYMBOL_GPL(crypto_stats_get);
1039
1040 void crypto_stats_aead_encrypt(unsigned int cryptlen, struct crypto_alg *alg,
1041                                int ret)
1042 {
1043         if (ret && ret != -EINPROGRESS && ret != -EBUSY) {
1044                 atomic64_inc(&alg->stats.aead.err_cnt);
1045         } else {
1046                 atomic64_inc(&alg->stats.aead.encrypt_cnt);
1047                 atomic64_add(cryptlen, &alg->stats.aead.encrypt_tlen);
1048         }
1049         crypto_alg_put(alg);
1050 }
1051 EXPORT_SYMBOL_GPL(crypto_stats_aead_encrypt);
1052
1053 void crypto_stats_aead_decrypt(unsigned int cryptlen, struct crypto_alg *alg,
1054                                int ret)
1055 {
1056         if (ret && ret != -EINPROGRESS && ret != -EBUSY) {
1057                 atomic64_inc(&alg->stats.aead.err_cnt);
1058         } else {
1059                 atomic64_inc(&alg->stats.aead.decrypt_cnt);
1060                 atomic64_add(cryptlen, &alg->stats.aead.decrypt_tlen);
1061         }
1062         crypto_alg_put(alg);
1063 }
1064 EXPORT_SYMBOL_GPL(crypto_stats_aead_decrypt);
1065
1066 void crypto_stats_akcipher_encrypt(unsigned int src_len, int ret,
1067                                    struct crypto_alg *alg)
1068 {
1069         if (ret && ret != -EINPROGRESS && ret != -EBUSY) {
1070                 atomic64_inc(&alg->stats.akcipher.err_cnt);
1071         } else {
1072                 atomic64_inc(&alg->stats.akcipher.encrypt_cnt);
1073                 atomic64_add(src_len, &alg->stats.akcipher.encrypt_tlen);
1074         }
1075         crypto_alg_put(alg);
1076 }
1077 EXPORT_SYMBOL_GPL(crypto_stats_akcipher_encrypt);
1078
1079 void crypto_stats_akcipher_decrypt(unsigned int src_len, int ret,
1080                                    struct crypto_alg *alg)
1081 {
1082         if (ret && ret != -EINPROGRESS && ret != -EBUSY) {
1083                 atomic64_inc(&alg->stats.akcipher.err_cnt);
1084         } else {
1085                 atomic64_inc(&alg->stats.akcipher.decrypt_cnt);
1086                 atomic64_add(src_len, &alg->stats.akcipher.decrypt_tlen);
1087         }
1088         crypto_alg_put(alg);
1089 }
1090 EXPORT_SYMBOL_GPL(crypto_stats_akcipher_decrypt);
1091
1092 void crypto_stats_akcipher_sign(int ret, struct crypto_alg *alg)
1093 {
1094         if (ret && ret != -EINPROGRESS && ret != -EBUSY)
1095                 atomic64_inc(&alg->stats.akcipher.err_cnt);
1096         else
1097                 atomic64_inc(&alg->stats.akcipher.sign_cnt);
1098         crypto_alg_put(alg);
1099 }
1100 EXPORT_SYMBOL_GPL(crypto_stats_akcipher_sign);
1101
1102 void crypto_stats_akcipher_verify(int ret, struct crypto_alg *alg)
1103 {
1104         if (ret && ret != -EINPROGRESS && ret != -EBUSY)
1105                 atomic64_inc(&alg->stats.akcipher.err_cnt);
1106         else
1107                 atomic64_inc(&alg->stats.akcipher.verify_cnt);
1108         crypto_alg_put(alg);
1109 }
1110 EXPORT_SYMBOL_GPL(crypto_stats_akcipher_verify);
1111
1112 void crypto_stats_compress(unsigned int slen, int ret, struct crypto_alg *alg)
1113 {
1114         if (ret && ret != -EINPROGRESS && ret != -EBUSY) {
1115                 atomic64_inc(&alg->stats.compress.err_cnt);
1116         } else {
1117                 atomic64_inc(&alg->stats.compress.compress_cnt);
1118                 atomic64_add(slen, &alg->stats.compress.compress_tlen);
1119         }
1120         crypto_alg_put(alg);
1121 }
1122 EXPORT_SYMBOL_GPL(crypto_stats_compress);
1123
1124 void crypto_stats_decompress(unsigned int slen, int ret, struct crypto_alg *alg)
1125 {
1126         if (ret && ret != -EINPROGRESS && ret != -EBUSY) {
1127                 atomic64_inc(&alg->stats.compress.err_cnt);
1128         } else {
1129                 atomic64_inc(&alg->stats.compress.decompress_cnt);
1130                 atomic64_add(slen, &alg->stats.compress.decompress_tlen);
1131         }
1132         crypto_alg_put(alg);
1133 }
1134 EXPORT_SYMBOL_GPL(crypto_stats_decompress);
1135
1136 void crypto_stats_ahash_update(unsigned int nbytes, int ret,
1137                                struct crypto_alg *alg)
1138 {
1139         if (ret && ret != -EINPROGRESS && ret != -EBUSY)
1140                 atomic64_inc(&alg->stats.hash.err_cnt);
1141         else
1142                 atomic64_add(nbytes, &alg->stats.hash.hash_tlen);
1143         crypto_alg_put(alg);
1144 }
1145 EXPORT_SYMBOL_GPL(crypto_stats_ahash_update);
1146
1147 void crypto_stats_ahash_final(unsigned int nbytes, int ret,
1148                               struct crypto_alg *alg)
1149 {
1150         if (ret && ret != -EINPROGRESS && ret != -EBUSY) {
1151                 atomic64_inc(&alg->stats.hash.err_cnt);
1152         } else {
1153                 atomic64_inc(&alg->stats.hash.hash_cnt);
1154                 atomic64_add(nbytes, &alg->stats.hash.hash_tlen);
1155         }
1156         crypto_alg_put(alg);
1157 }
1158 EXPORT_SYMBOL_GPL(crypto_stats_ahash_final);
1159
1160 void crypto_stats_kpp_set_secret(struct crypto_alg *alg, int ret)
1161 {
1162         if (ret)
1163                 atomic64_inc(&alg->stats.kpp.err_cnt);
1164         else
1165                 atomic64_inc(&alg->stats.kpp.setsecret_cnt);
1166         crypto_alg_put(alg);
1167 }
1168 EXPORT_SYMBOL_GPL(crypto_stats_kpp_set_secret);
1169
1170 void crypto_stats_kpp_generate_public_key(struct crypto_alg *alg, int ret)
1171 {
1172         if (ret)
1173                 atomic64_inc(&alg->stats.kpp.err_cnt);
1174         else
1175                 atomic64_inc(&alg->stats.kpp.generate_public_key_cnt);
1176         crypto_alg_put(alg);
1177 }
1178 EXPORT_SYMBOL_GPL(crypto_stats_kpp_generate_public_key);
1179
1180 void crypto_stats_kpp_compute_shared_secret(struct crypto_alg *alg, int ret)
1181 {
1182         if (ret)
1183                 atomic64_inc(&alg->stats.kpp.err_cnt);
1184         else
1185                 atomic64_inc(&alg->stats.kpp.compute_shared_secret_cnt);
1186         crypto_alg_put(alg);
1187 }
1188 EXPORT_SYMBOL_GPL(crypto_stats_kpp_compute_shared_secret);
1189
1190 void crypto_stats_rng_seed(struct crypto_alg *alg, int ret)
1191 {
1192         if (ret && ret != -EINPROGRESS && ret != -EBUSY)
1193                 atomic64_inc(&alg->stats.rng.err_cnt);
1194         else
1195                 atomic64_inc(&alg->stats.rng.seed_cnt);
1196         crypto_alg_put(alg);
1197 }
1198 EXPORT_SYMBOL_GPL(crypto_stats_rng_seed);
1199
1200 void crypto_stats_rng_generate(struct crypto_alg *alg, unsigned int dlen,
1201                                int ret)
1202 {
1203         if (ret && ret != -EINPROGRESS && ret != -EBUSY) {
1204                 atomic64_inc(&alg->stats.rng.err_cnt);
1205         } else {
1206                 atomic64_inc(&alg->stats.rng.generate_cnt);
1207                 atomic64_add(dlen, &alg->stats.rng.generate_tlen);
1208         }
1209         crypto_alg_put(alg);
1210 }
1211 EXPORT_SYMBOL_GPL(crypto_stats_rng_generate);
1212
1213 void crypto_stats_skcipher_encrypt(unsigned int cryptlen, int ret,
1214                                    struct crypto_alg *alg)
1215 {
1216         if (ret && ret != -EINPROGRESS && ret != -EBUSY) {
1217                 atomic64_inc(&alg->stats.cipher.err_cnt);
1218         } else {
1219                 atomic64_inc(&alg->stats.cipher.encrypt_cnt);
1220                 atomic64_add(cryptlen, &alg->stats.cipher.encrypt_tlen);
1221         }
1222         crypto_alg_put(alg);
1223 }
1224 EXPORT_SYMBOL_GPL(crypto_stats_skcipher_encrypt);
1225
1226 void crypto_stats_skcipher_decrypt(unsigned int cryptlen, int ret,
1227                                    struct crypto_alg *alg)
1228 {
1229         if (ret && ret != -EINPROGRESS && ret != -EBUSY) {
1230                 atomic64_inc(&alg->stats.cipher.err_cnt);
1231         } else {
1232                 atomic64_inc(&alg->stats.cipher.decrypt_cnt);
1233                 atomic64_add(cryptlen, &alg->stats.cipher.decrypt_tlen);
1234         }
1235         crypto_alg_put(alg);
1236 }
1237 EXPORT_SYMBOL_GPL(crypto_stats_skcipher_decrypt);
1238 #endif
1239
1240 static void __init crypto_start_tests(void)
1241 {
1242         for (;;) {
1243                 struct crypto_larval *larval = NULL;
1244                 struct crypto_alg *q;
1245
1246                 down_write(&crypto_alg_sem);
1247
1248                 list_for_each_entry(q, &crypto_alg_list, cra_list) {
1249                         struct crypto_larval *l;
1250
1251                         if (!crypto_is_larval(q))
1252                                 continue;
1253
1254                         l = (void *)q;
1255
1256                         if (!crypto_is_test_larval(l))
1257                                 continue;
1258
1259                         if (l->test_started)
1260                                 continue;
1261
1262                         l->test_started = true;
1263                         larval = l;
1264                         break;
1265                 }
1266
1267                 up_write(&crypto_alg_sem);
1268
1269                 if (!larval)
1270                         break;
1271
1272                 crypto_wait_for_test(larval);
1273         }
1274
1275         static_branch_enable(&crypto_boot_test_finished);
1276 }
1277
1278 static int __init crypto_algapi_init(void)
1279 {
1280         crypto_init_proc();
1281         crypto_start_tests();
1282         return 0;
1283 }
1284
1285 static void __exit crypto_algapi_exit(void)
1286 {
1287         crypto_exit_proc();
1288 }
1289
1290 /*
1291  * We run this at late_initcall so that all the built-in algorithms
1292  * have had a chance to register themselves first.
1293  */
1294 late_initcall(crypto_algapi_init);
1295 module_exit(crypto_algapi_exit);
1296
1297 MODULE_LICENSE("GPL");
1298 MODULE_DESCRIPTION("Cryptographic algorithms API");
1299 MODULE_SOFTDEP("pre: cryptomgr");