1 /* SPDX-License-Identifier: GPL-2.0-only */
3 * Copyright (c) 2018 Chelsio Communications, Inc.
9 #include <crypto/aes.h>
10 #include <crypto/algapi.h>
11 #include <crypto/hash.h>
12 #include <crypto/sha1.h>
13 #include <crypto/sha2.h>
14 #include <crypto/authenc.h>
15 #include <crypto/ctr.h>
16 #include <crypto/gf128mul.h>
17 #include <crypto/internal/aead.h>
18 #include <crypto/null.h>
19 #include <crypto/internal/skcipher.h>
20 #include <crypto/aead.h>
21 #include <crypto/scatterwalk.h>
22 #include <crypto/internal/hash.h>
23 #include <linux/tls.h>
25 #include <net/tls_toe.h>
30 #include "cxgb4_uld.h"
32 #include "chcr_algo.h"
33 #include "chcr_core.h"
34 #include "chcr_crypto.h"
36 #define CHTLS_DRV_VERSION "1.0.0.0-ko"
38 #define TLS_KEYCTX_RXFLIT_CNT_S 24
39 #define TLS_KEYCTX_RXFLIT_CNT_V(x) ((x) << TLS_KEYCTX_RXFLIT_CNT_S)
41 #define TLS_KEYCTX_RXPROT_VER_S 20
42 #define TLS_KEYCTX_RXPROT_VER_M 0xf
43 #define TLS_KEYCTX_RXPROT_VER_V(x) ((x) << TLS_KEYCTX_RXPROT_VER_S)
45 #define TLS_KEYCTX_RXCIPH_MODE_S 16
46 #define TLS_KEYCTX_RXCIPH_MODE_M 0xf
47 #define TLS_KEYCTX_RXCIPH_MODE_V(x) ((x) << TLS_KEYCTX_RXCIPH_MODE_S)
49 #define TLS_KEYCTX_RXAUTH_MODE_S 12
50 #define TLS_KEYCTX_RXAUTH_MODE_M 0xf
51 #define TLS_KEYCTX_RXAUTH_MODE_V(x) ((x) << TLS_KEYCTX_RXAUTH_MODE_S)
53 #define TLS_KEYCTX_RXCIAU_CTRL_S 11
54 #define TLS_KEYCTX_RXCIAU_CTRL_V(x) ((x) << TLS_KEYCTX_RXCIAU_CTRL_S)
56 #define TLS_KEYCTX_RX_SEQCTR_S 9
57 #define TLS_KEYCTX_RX_SEQCTR_M 0x3
58 #define TLS_KEYCTX_RX_SEQCTR_V(x) ((x) << TLS_KEYCTX_RX_SEQCTR_S)
60 #define TLS_KEYCTX_RX_VALID_S 8
61 #define TLS_KEYCTX_RX_VALID_V(x) ((x) << TLS_KEYCTX_RX_VALID_S)
63 #define TLS_KEYCTX_RXCK_SIZE_S 3
64 #define TLS_KEYCTX_RXCK_SIZE_M 0x7
65 #define TLS_KEYCTX_RXCK_SIZE_V(x) ((x) << TLS_KEYCTX_RXCK_SIZE_S)
67 #define TLS_KEYCTX_RXMK_SIZE_S 0
68 #define TLS_KEYCTX_RXMK_SIZE_M 0x7
69 #define TLS_KEYCTX_RXMK_SIZE_V(x) ((x) << TLS_KEYCTX_RXMK_SIZE_S)
71 #define KEYCTX_TX_WR_IV_S 55
72 #define KEYCTX_TX_WR_IV_M 0x1ffULL
73 #define KEYCTX_TX_WR_IV_V(x) ((x) << KEYCTX_TX_WR_IV_S)
74 #define KEYCTX_TX_WR_IV_G(x) \
75 (((x) >> KEYCTX_TX_WR_IV_S) & KEYCTX_TX_WR_IV_M)
77 #define KEYCTX_TX_WR_AAD_S 47
78 #define KEYCTX_TX_WR_AAD_M 0xffULL
79 #define KEYCTX_TX_WR_AAD_V(x) ((x) << KEYCTX_TX_WR_AAD_S)
80 #define KEYCTX_TX_WR_AAD_G(x) (((x) >> KEYCTX_TX_WR_AAD_S) & \
83 #define KEYCTX_TX_WR_AADST_S 39
84 #define KEYCTX_TX_WR_AADST_M 0xffULL
85 #define KEYCTX_TX_WR_AADST_V(x) ((x) << KEYCTX_TX_WR_AADST_S)
86 #define KEYCTX_TX_WR_AADST_G(x) \
87 (((x) >> KEYCTX_TX_WR_AADST_S) & KEYCTX_TX_WR_AADST_M)
89 #define KEYCTX_TX_WR_CIPHER_S 30
90 #define KEYCTX_TX_WR_CIPHER_M 0x1ffULL
91 #define KEYCTX_TX_WR_CIPHER_V(x) ((x) << KEYCTX_TX_WR_CIPHER_S)
92 #define KEYCTX_TX_WR_CIPHER_G(x) \
93 (((x) >> KEYCTX_TX_WR_CIPHER_S) & KEYCTX_TX_WR_CIPHER_M)
95 #define KEYCTX_TX_WR_CIPHERST_S 23
96 #define KEYCTX_TX_WR_CIPHERST_M 0x7f
97 #define KEYCTX_TX_WR_CIPHERST_V(x) ((x) << KEYCTX_TX_WR_CIPHERST_S)
98 #define KEYCTX_TX_WR_CIPHERST_G(x) \
99 (((x) >> KEYCTX_TX_WR_CIPHERST_S) & KEYCTX_TX_WR_CIPHERST_M)
101 #define KEYCTX_TX_WR_AUTH_S 14
102 #define KEYCTX_TX_WR_AUTH_M 0x1ff
103 #define KEYCTX_TX_WR_AUTH_V(x) ((x) << KEYCTX_TX_WR_AUTH_S)
104 #define KEYCTX_TX_WR_AUTH_G(x) \
105 (((x) >> KEYCTX_TX_WR_AUTH_S) & KEYCTX_TX_WR_AUTH_M)
107 #define KEYCTX_TX_WR_AUTHST_S 7
108 #define KEYCTX_TX_WR_AUTHST_M 0x7f
109 #define KEYCTX_TX_WR_AUTHST_V(x) ((x) << KEYCTX_TX_WR_AUTHST_S)
110 #define KEYCTX_TX_WR_AUTHST_G(x) \
111 (((x) >> KEYCTX_TX_WR_AUTHST_S) & KEYCTX_TX_WR_AUTHST_M)
113 #define KEYCTX_TX_WR_AUTHIN_S 0
114 #define KEYCTX_TX_WR_AUTHIN_M 0x7f
115 #define KEYCTX_TX_WR_AUTHIN_V(x) ((x) << KEYCTX_TX_WR_AUTHIN_S)
116 #define KEYCTX_TX_WR_AUTHIN_G(x) \
117 (((x) >> KEYCTX_TX_WR_AUTHIN_S) & KEYCTX_TX_WR_AUTHIN_M)
119 struct sge_opaque_hdr {
121 dma_addr_t addr[MAX_SKB_FRAGS + 1];
124 #define MAX_IVS_PAGE 256
125 #define TLS_KEY_CONTEXT_SZ 64
126 #define CIPHER_BLOCK_SIZE 16
127 #define GCM_TAG_SIZE 16
128 #define KEY_ON_MEM_SZ 16
129 #define AEAD_EXPLICIT_DATA_SIZE 8
130 #define TLS_HEADER_LENGTH 5
131 #define SCMD_CIPH_MODE_AES_GCM 2
132 /* Any MFS size should work and come from openssl */
133 #define TLS_MFS 16384
135 #define RSS_HDR sizeof(struct rss_header)
136 #define TLS_WR_CPL_LEN \
137 (sizeof(struct fw_tlstx_data_wr) + sizeof(struct cpl_tx_tls_sfo))
140 CHTLS_KEY_CONTEXT_DSGL,
141 CHTLS_KEY_CONTEXT_IMM,
142 CHTLS_KEY_CONTEXT_DDR,
150 /* Flags for return value of CPL message handlers */
152 CPL_RET_BUF_DONE = 1, /* buffer processing done */
153 CPL_RET_BAD_MSG = 2, /* bad CPL message */
154 CPL_RET_UNKNOWN_TID = 4 /* unexpected unknown TID */
157 #define LISTEN_INFO_HASH_SIZE 32
158 #define RSPQ_HASH_BITS 5
160 struct listen_info *next; /* Link to next entry */
161 struct sock *sk; /* The listening socket */
162 unsigned int stid; /* The server TID */
166 T4_LISTEN_START_PENDING,
171 CSK_CALLBACKS_CHKD, /* socket callbacks have been sanitized */
172 CSK_ABORT_REQ_RCVD, /* received one ABORT_REQ_RSS message */
173 CSK_TX_MORE_DATA, /* sending ULP data; don't set SHOVE bit */
174 CSK_TX_WAIT_IDLE, /* suspend Tx until in-flight data is ACKed */
175 CSK_ABORT_SHUTDOWN, /* shouldn't send more abort requests */
176 CSK_ABORT_RPL_PENDING, /* expecting an abort reply */
177 CSK_CLOSE_CON_REQUESTED,/* we've sent a close_conn_req */
178 CSK_TX_DATA_SENT, /* sent a TX_DATA WR on this connection */
179 CSK_TX_FAILOVER, /* Tx traffic failing over */
180 CSK_UPDATE_RCV_WND, /* Need to update rcv window */
181 CSK_RST_ABORTED, /* outgoing RST was aborted */
182 CSK_TLS_HANDSHK, /* TLS Handshake */
183 CSK_CONN_INLINE, /* Connection on HW */
186 enum chtls_cdev_state {
187 CHTLS_CDEV_STATE_UP = 1
192 struct chtls_dev *cdev;
193 struct sk_buff_head synq;
200 unsigned int available;
202 spinlock_t lock; /* lock for key id request from map */
211 struct tls_toe_device tlsdev;
212 struct list_head list;
213 struct cxgb4_lld_info *lldi;
214 struct pci_dev *pdev;
215 struct listen_info *listen_hash_tab[LISTEN_INFO_HASH_SIZE];
216 spinlock_t listen_lock; /* lock for listen list */
217 struct net_device **ports;
218 struct tid_info *tids;
220 const unsigned short *mtus;
222 struct idr hwtid_idr;
225 spinlock_t idr_lock ____cacheline_aligned_in_smp;
227 struct net_device *egr_dev[NCHAN * 2];
228 struct sk_buff *rspq_skb_cache[1 << RSPQ_HASH_BITS];
229 struct sk_buff *askb;
231 struct sk_buff_head deferq;
232 struct work_struct deferq_task;
234 struct list_head list_node;
235 struct list_head rcu_node;
236 struct list_head na_node;
237 unsigned int send_page_order;
241 unsigned int cdev_state;
244 struct chtls_listen {
245 struct chtls_dev *cdev;
250 struct sk_buff_head sk_recv_queue;
271 struct tls_scmd scmd;
273 struct tls12_crypto_info_aes_gcm_128 aes_gcm_128;
274 struct tls12_crypto_info_aes_gcm_256 aes_gcm_256;
280 struct chtls_dev *cdev;
281 struct l2t_entry *l2t_entry; /* pointer to the L2T entry */
282 struct net_device *egress_dev; /* TX_CHAN for act open retry */
284 struct sk_buff_head txq;
285 struct sk_buff *wr_skb_head;
286 struct sk_buff *wr_skb_tail;
287 struct sk_buff *ctrl_skb_cache;
288 struct sk_buff *txdata_skb_cache; /* abort path messages */
296 u32 hwtid; /* TCP Control Block ID */
307 u32 mtu_idx; /* MTU table index */
317 void *passive_reap_next; /* placeholder for passive */
318 struct chtls_hws tlshws;
320 struct sk_buff *next;
321 struct sk_buff *prev;
323 struct listen_ctx *listen_ctx;
332 struct tlsrx_cmp_hdr {
342 /* res_to_mac_error fields */
343 #define TLSRX_HDR_PKT_INT_ERROR_S 4
344 #define TLSRX_HDR_PKT_INT_ERROR_M 0x1
345 #define TLSRX_HDR_PKT_INT_ERROR_V(x) \
346 ((x) << TLSRX_HDR_PKT_INT_ERROR_S)
347 #define TLSRX_HDR_PKT_INT_ERROR_G(x) \
348 (((x) >> TLSRX_HDR_PKT_INT_ERROR_S) & TLSRX_HDR_PKT_INT_ERROR_M)
349 #define TLSRX_HDR_PKT_INT_ERROR_F TLSRX_HDR_PKT_INT_ERROR_V(1U)
351 #define TLSRX_HDR_PKT_SPP_ERROR_S 3
352 #define TLSRX_HDR_PKT_SPP_ERROR_M 0x1
353 #define TLSRX_HDR_PKT_SPP_ERROR_V(x) ((x) << TLSRX_HDR_PKT_SPP_ERROR)
354 #define TLSRX_HDR_PKT_SPP_ERROR_G(x) \
355 (((x) >> TLSRX_HDR_PKT_SPP_ERROR_S) & TLSRX_HDR_PKT_SPP_ERROR_M)
356 #define TLSRX_HDR_PKT_SPP_ERROR_F TLSRX_HDR_PKT_SPP_ERROR_V(1U)
358 #define TLSRX_HDR_PKT_CCDX_ERROR_S 2
359 #define TLSRX_HDR_PKT_CCDX_ERROR_M 0x1
360 #define TLSRX_HDR_PKT_CCDX_ERROR_V(x) ((x) << TLSRX_HDR_PKT_CCDX_ERROR_S)
361 #define TLSRX_HDR_PKT_CCDX_ERROR_G(x) \
362 (((x) >> TLSRX_HDR_PKT_CCDX_ERROR_S) & TLSRX_HDR_PKT_CCDX_ERROR_M)
363 #define TLSRX_HDR_PKT_CCDX_ERROR_F TLSRX_HDR_PKT_CCDX_ERROR_V(1U)
365 #define TLSRX_HDR_PKT_PAD_ERROR_S 1
366 #define TLSRX_HDR_PKT_PAD_ERROR_M 0x1
367 #define TLSRX_HDR_PKT_PAD_ERROR_V(x) ((x) << TLSRX_HDR_PKT_PAD_ERROR_S)
368 #define TLSRX_HDR_PKT_PAD_ERROR_G(x) \
369 (((x) >> TLSRX_HDR_PKT_PAD_ERROR_S) & TLSRX_HDR_PKT_PAD_ERROR_M)
370 #define TLSRX_HDR_PKT_PAD_ERROR_F TLSRX_HDR_PKT_PAD_ERROR_V(1U)
372 #define TLSRX_HDR_PKT_MAC_ERROR_S 0
373 #define TLSRX_HDR_PKT_MAC_ERROR_M 0x1
374 #define TLSRX_HDR_PKT_MAC_ERROR_V(x) ((x) << TLSRX_HDR_PKT_MAC_ERROR)
375 #define TLSRX_HDR_PKT_MAC_ERROR_G(x) \
376 (((x) >> S_TLSRX_HDR_PKT_MAC_ERROR_S) & TLSRX_HDR_PKT_MAC_ERROR_M)
377 #define TLSRX_HDR_PKT_MAC_ERROR_F TLSRX_HDR_PKT_MAC_ERROR_V(1U)
379 #define TLSRX_HDR_PKT_ERROR_M 0x1F
380 #define CONTENT_TYPE_ERROR 0x7F
384 __be32 len16; /* command length */
385 __be32 dlen; /* data length in 32-byte units */
393 u8 reneg_to_write_rx;
399 struct tls_key_wr wr;
400 struct ulp_mem_rw req;
401 struct ulptx_idata sc_imm;
405 * This lives in skb->cb and is used to chain WRs in a linked list.
408 struct l2t_skb_cb l2t; /* reserve space for l2t CB */
409 struct sk_buff *next_wr; /* next write request */
412 /* Per-skb backlog handler. Run when a socket's backlog is processed. */
414 void (*backlog_rcv)(struct sock *sk, struct sk_buff *skb);
415 struct chtls_dev *cdev;
419 * Similar to tcp_skb_cb but with ULP elements added to support TLS,
423 struct wr_skb_cb wr; /* reserve space for write request */
424 u16 flags; /* TCP-like flags */
426 u8 ulp_mode; /* ULP mode/submode of sk_buff */
427 u32 seq; /* TCP sequence number */
428 union { /* ULP-specific fields */
437 #define ULP_SKB_CB(skb) ((struct ulp_skb_cb *)&((skb)->cb[0]))
438 #define BLOG_SKB_CB(skb) ((struct blog_skb_cb *)(skb)->cb)
441 * Flags for ulp_skb_cb.flags.
444 ULPCB_FLAG_NEED_HDR = 1 << 0, /* packet needs a TX_DATA_WR header */
445 ULPCB_FLAG_NO_APPEND = 1 << 1, /* don't grow this skb */
446 ULPCB_FLAG_BARRIER = 1 << 2, /* set TX_WAIT_IDLE after sending */
447 ULPCB_FLAG_HOLD = 1 << 3, /* skb not ready for Tx yet */
448 ULPCB_FLAG_COMPL = 1 << 4, /* request WR completion */
449 ULPCB_FLAG_URG = 1 << 5, /* urgent data */
450 ULPCB_FLAG_TLS_HDR = 1 << 6, /* payload with tls hdr */
451 ULPCB_FLAG_NO_HDR = 1 << 7, /* not a ofld wr */
454 /* The ULP mode/submode of an skbuff */
455 #define skb_ulp_mode(skb) (ULP_SKB_CB(skb)->ulp_mode)
456 #define TCP_PAGE(sk) (sk->sk_frag.page)
457 #define TCP_OFF(sk) (sk->sk_frag.offset)
459 static inline struct chtls_dev *to_chtls_dev(struct tls_toe_device *tlsdev)
461 return container_of(tlsdev, struct chtls_dev, tlsdev);
464 static inline void csk_set_flag(struct chtls_sock *csk,
467 __set_bit(flag, &csk->flags);
470 static inline void csk_reset_flag(struct chtls_sock *csk,
473 __clear_bit(flag, &csk->flags);
476 static inline bool csk_conn_inline(const struct chtls_sock *csk)
478 return test_bit(CSK_CONN_INLINE, &csk->flags);
481 static inline int csk_flag(const struct sock *sk, enum csk_flags flag)
483 struct chtls_sock *csk = rcu_dereference_sk_user_data(sk);
485 if (!csk_conn_inline(csk))
487 return test_bit(flag, &csk->flags);
490 static inline int csk_flag_nochk(const struct chtls_sock *csk,
493 return test_bit(flag, &csk->flags);
496 static inline void *cplhdr(struct sk_buff *skb)
501 static inline int is_neg_adv(unsigned int status)
503 return status == CPL_ERR_RTX_NEG_ADVICE ||
504 status == CPL_ERR_KEEPALV_NEG_ADVICE ||
505 status == CPL_ERR_PERSIST_NEG_ADVICE;
508 static inline void process_cpl_msg(void (*fn)(struct sock *, struct sk_buff *),
512 skb_reset_mac_header(skb);
513 skb_reset_network_header(skb);
514 skb_reset_transport_header(skb);
517 if (unlikely(sock_owned_by_user(sk))) {
518 BLOG_SKB_CB(skb)->backlog_rcv = fn;
519 __sk_add_backlog(sk, skb);
526 static inline void chtls_sock_free(struct kref *ref)
528 struct chtls_sock *csk = container_of(ref, struct chtls_sock,
533 static inline void __chtls_sock_put(const char *fn, struct chtls_sock *csk)
535 kref_put(&csk->kref, chtls_sock_free);
538 static inline void __chtls_sock_get(const char *fn,
539 struct chtls_sock *csk)
541 kref_get(&csk->kref);
544 static inline void send_or_defer(struct sock *sk, struct tcp_sock *tp,
545 struct sk_buff *skb, int through_l2t)
547 struct chtls_sock *csk = rcu_dereference_sk_user_data(sk);
550 /* send through L2T */
551 cxgb4_l2t_send(csk->egress_dev, skb, csk->l2t_entry);
554 cxgb4_ofld_send(csk->egress_dev, skb);
558 typedef int (*chtls_handler_func)(struct chtls_dev *, struct sk_buff *);
559 extern chtls_handler_func chtls_handlers[NUM_CPL_CMDS];
560 void chtls_install_cpl_ops(struct sock *sk);
561 int chtls_init_kmap(struct chtls_dev *cdev, struct cxgb4_lld_info *lldi);
562 void chtls_listen_stop(struct chtls_dev *cdev, struct sock *sk);
563 int chtls_listen_start(struct chtls_dev *cdev, struct sock *sk);
564 void chtls_close(struct sock *sk, long timeout);
565 int chtls_disconnect(struct sock *sk, int flags);
566 void chtls_shutdown(struct sock *sk, int how);
567 void chtls_destroy_sock(struct sock *sk);
568 int chtls_sendmsg(struct sock *sk, struct msghdr *msg, size_t size);
569 int chtls_recvmsg(struct sock *sk, struct msghdr *msg,
570 size_t len, int flags, int *addr_len);
571 void chtls_splice_eof(struct socket *sock);
572 int chtls_sendpage(struct sock *sk, struct page *page,
573 int offset, size_t size, int flags);
574 int send_tx_flowc_wr(struct sock *sk, int compl,
575 u32 snd_nxt, u32 rcv_nxt);
576 void chtls_tcp_push(struct sock *sk, int flags);
577 int chtls_push_frames(struct chtls_sock *csk, int comp);
578 int chtls_set_tcb_tflag(struct sock *sk, unsigned int bit_pos, int val);
579 void chtls_set_tcb_field_rpl_skb(struct sock *sk, u16 word,
580 u64 mask, u64 val, u8 cookie,
582 int chtls_setkey(struct chtls_sock *csk, u32 keylen, u32 mode, int cipher_type);
583 void chtls_set_quiesce_ctrl(struct sock *sk, int val);
584 void skb_entail(struct sock *sk, struct sk_buff *skb, int flags);
585 unsigned int keyid_to_addr(int start_addr, int keyid);
586 void free_tls_keyid(struct sock *sk);