Damjan Marion | 91f17dc | 2019-03-18 18:59:25 +0100 | [diff] [blame] | 1 | /* |
| 2 | * Copyright (c) 2018 Cisco and/or its affiliates. |
| 3 | * Licensed under the Apache License, Version 2.0 (the "License"); |
| 4 | * you may not use this file except in compliance with the License. |
| 5 | * You may obtain a copy of the License at: |
| 6 | * |
| 7 | * http://www.apache.org/licenses/LICENSE-2.0 |
| 8 | * |
| 9 | * Unless required by applicable law or agreed to in writing, software |
| 10 | * distributed under the License is distributed on an "AS IS" BASIS, |
| 11 | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| 12 | * See the License for the specific language governing permissions and |
| 13 | * limitations under the License. |
| 14 | */ |
| 15 | |
| 16 | #include <stdbool.h> |
| 17 | #include <vlib/vlib.h> |
| 18 | #include <vnet/crypto/crypto.h> |
| 19 | |
| 20 | vnet_crypto_main_t crypto_main; |
| 21 | |
Damjan Marion | 085637f | 2019-04-03 18:39:27 +0200 | [diff] [blame] | 22 | static_always_inline u32 |
| 23 | vnet_crypto_process_ops_call_handler (vlib_main_t * vm, |
| 24 | vnet_crypto_main_t * cm, |
Damjan Marion | 060bfb9 | 2019-03-29 13:47:54 +0100 | [diff] [blame] | 25 | vnet_crypto_op_id_t opt, |
Damjan Marion | 085637f | 2019-04-03 18:39:27 +0200 | [diff] [blame] | 26 | vnet_crypto_op_t * ops[], u32 n_ops) |
| 27 | { |
| 28 | if (n_ops == 0) |
| 29 | return 0; |
| 30 | |
| 31 | if (cm->ops_handlers[opt] == 0) |
| 32 | { |
Damjan Marion | ba01f07 | 2019-04-05 11:11:04 +0200 | [diff] [blame] | 33 | while (n_ops--) |
Damjan Marion | 085637f | 2019-04-03 18:39:27 +0200 | [diff] [blame] | 34 | { |
| 35 | ops[0]->status = VNET_CRYPTO_OP_STATUS_FAIL_NO_HANDLER; |
| 36 | ops++; |
| 37 | } |
| 38 | return 0; |
| 39 | } |
| 40 | |
| 41 | return (cm->ops_handlers[opt]) (vm, ops, n_ops); |
| 42 | } |
| 43 | |
| 44 | |
Damjan Marion | 91f17dc | 2019-03-18 18:59:25 +0100 | [diff] [blame] | 45 | u32 |
| 46 | vnet_crypto_process_ops (vlib_main_t * vm, vnet_crypto_op_t ops[], u32 n_ops) |
| 47 | { |
| 48 | vnet_crypto_main_t *cm = &crypto_main; |
Damjan Marion | 085637f | 2019-04-03 18:39:27 +0200 | [diff] [blame] | 49 | const int op_q_size = VLIB_FRAME_SIZE; |
| 50 | vnet_crypto_op_t *op_queue[op_q_size]; |
Damjan Marion | 060bfb9 | 2019-03-29 13:47:54 +0100 | [diff] [blame] | 51 | vnet_crypto_op_id_t opt, current_op_type = ~0; |
Damjan Marion | 085637f | 2019-04-03 18:39:27 +0200 | [diff] [blame] | 52 | u32 n_op_queue = 0; |
Damjan Marion | 91f17dc | 2019-03-18 18:59:25 +0100 | [diff] [blame] | 53 | u32 rv = 0, i; |
| 54 | |
Damjan Marion | 085637f | 2019-04-03 18:39:27 +0200 | [diff] [blame] | 55 | ASSERT (n_ops >= 1); |
| 56 | |
Damjan Marion | 91f17dc | 2019-03-18 18:59:25 +0100 | [diff] [blame] | 57 | for (i = 0; i < n_ops; i++) |
| 58 | { |
Damjan Marion | 085637f | 2019-04-03 18:39:27 +0200 | [diff] [blame] | 59 | opt = ops[i].op; |
Damjan Marion | 91f17dc | 2019-03-18 18:59:25 +0100 | [diff] [blame] | 60 | |
Damjan Marion | 085637f | 2019-04-03 18:39:27 +0200 | [diff] [blame] | 61 | if (current_op_type != opt || n_op_queue >= op_q_size) |
| 62 | { |
| 63 | rv += vnet_crypto_process_ops_call_handler (vm, cm, current_op_type, |
| 64 | op_queue, n_op_queue); |
| 65 | n_op_queue = 0; |
| 66 | current_op_type = opt; |
| 67 | } |
| 68 | |
| 69 | op_queue[n_op_queue++] = &ops[i]; |
Damjan Marion | 91f17dc | 2019-03-18 18:59:25 +0100 | [diff] [blame] | 70 | } |
| 71 | |
Damjan Marion | 085637f | 2019-04-03 18:39:27 +0200 | [diff] [blame] | 72 | rv += vnet_crypto_process_ops_call_handler (vm, cm, current_op_type, |
| 73 | op_queue, n_op_queue); |
Damjan Marion | 91f17dc | 2019-03-18 18:59:25 +0100 | [diff] [blame] | 74 | return rv; |
| 75 | } |
| 76 | |
| 77 | u32 |
| 78 | vnet_crypto_register_engine (vlib_main_t * vm, char *name, int prio, |
| 79 | char *desc) |
| 80 | { |
| 81 | vnet_crypto_main_t *cm = &crypto_main; |
| 82 | vnet_crypto_engine_t *p; |
| 83 | |
| 84 | vec_add2 (cm->engines, p, 1); |
| 85 | p->name = name; |
| 86 | p->desc = desc; |
| 87 | p->priority = prio; |
| 88 | |
Filip Tehlar | 1469d54 | 2019-03-25 09:04:41 -0700 | [diff] [blame] | 89 | hash_set_mem (cm->engine_index_by_name, p->name, p - cm->engines); |
| 90 | |
Damjan Marion | 91f17dc | 2019-03-18 18:59:25 +0100 | [diff] [blame] | 91 | return p - cm->engines; |
| 92 | } |
| 93 | |
Filip Tehlar | 1469d54 | 2019-03-25 09:04:41 -0700 | [diff] [blame] | 94 | int |
Damjan Marion | 060bfb9 | 2019-03-29 13:47:54 +0100 | [diff] [blame] | 95 | vnet_crypto_set_handler (char *alg_name, char *engine) |
Filip Tehlar | 1469d54 | 2019-03-25 09:04:41 -0700 | [diff] [blame] | 96 | { |
| 97 | uword *p; |
| 98 | vnet_crypto_main_t *cm = &crypto_main; |
Damjan Marion | 060bfb9 | 2019-03-29 13:47:54 +0100 | [diff] [blame] | 99 | vnet_crypto_alg_data_t *ad; |
Filip Tehlar | 1469d54 | 2019-03-25 09:04:41 -0700 | [diff] [blame] | 100 | vnet_crypto_engine_t *ce; |
Damjan Marion | 060bfb9 | 2019-03-29 13:47:54 +0100 | [diff] [blame] | 101 | int i; |
Filip Tehlar | 1469d54 | 2019-03-25 09:04:41 -0700 | [diff] [blame] | 102 | |
Damjan Marion | 060bfb9 | 2019-03-29 13:47:54 +0100 | [diff] [blame] | 103 | p = hash_get_mem (cm->alg_index_by_name, alg_name); |
Filip Tehlar | 1469d54 | 2019-03-25 09:04:41 -0700 | [diff] [blame] | 104 | if (!p) |
| 105 | return -1; |
| 106 | |
Damjan Marion | 060bfb9 | 2019-03-29 13:47:54 +0100 | [diff] [blame] | 107 | ad = vec_elt_at_index (cm->algs, p[0]); |
Filip Tehlar | 1469d54 | 2019-03-25 09:04:41 -0700 | [diff] [blame] | 108 | |
| 109 | p = hash_get_mem (cm->engine_index_by_name, engine); |
| 110 | if (!p) |
| 111 | return -1; |
| 112 | |
Damjan Marion | 060bfb9 | 2019-03-29 13:47:54 +0100 | [diff] [blame] | 113 | ce = vec_elt_at_index (cm->engines, p[0]); |
| 114 | |
| 115 | for (i = 0; i < VNET_CRYPTO_OP_N_TYPES; i++) |
| 116 | { |
| 117 | vnet_crypto_op_data_t *od; |
| 118 | vnet_crypto_op_id_t id = ad->op_by_type[i]; |
| 119 | if (id == 0) |
| 120 | continue; |
| 121 | od = vec_elt_at_index (cm->opt_data, id); |
Neale Ranns | 21ada3b | 2019-04-11 08:18:34 +0000 | [diff] [blame] | 122 | if (ce->ops_handlers[id]) |
| 123 | { |
| 124 | od->active_engine_index = p[0]; |
| 125 | cm->ops_handlers[id] = ce->ops_handlers[id]; |
| 126 | } |
Damjan Marion | 060bfb9 | 2019-03-29 13:47:54 +0100 | [diff] [blame] | 127 | } |
Filip Tehlar | 1469d54 | 2019-03-25 09:04:41 -0700 | [diff] [blame] | 128 | |
| 129 | return 0; |
| 130 | } |
| 131 | |
Damjan Marion | d1bed68 | 2019-04-24 15:20:35 +0200 | [diff] [blame] | 132 | void |
Damjan Marion | 91f17dc | 2019-03-18 18:59:25 +0100 | [diff] [blame] | 133 | vnet_crypto_register_ops_handler (vlib_main_t * vm, u32 engine_index, |
Damjan Marion | 060bfb9 | 2019-03-29 13:47:54 +0100 | [diff] [blame] | 134 | vnet_crypto_op_id_t opt, |
Damjan Marion | 91f17dc | 2019-03-18 18:59:25 +0100 | [diff] [blame] | 135 | vnet_crypto_ops_handler_t * fn) |
| 136 | { |
| 137 | vnet_crypto_main_t *cm = &crypto_main; |
| 138 | vnet_crypto_engine_t *ae, *e = vec_elt_at_index (cm->engines, engine_index); |
Damjan Marion | 060bfb9 | 2019-03-29 13:47:54 +0100 | [diff] [blame] | 139 | vnet_crypto_op_data_t *otd = cm->opt_data + opt; |
| 140 | vec_validate_aligned (cm->ops_handlers, VNET_CRYPTO_N_OP_IDS - 1, |
Damjan Marion | 91f17dc | 2019-03-18 18:59:25 +0100 | [diff] [blame] | 141 | CLIB_CACHE_LINE_BYTES); |
| 142 | e->ops_handlers[opt] = fn; |
| 143 | |
| 144 | if (otd->active_engine_index == ~0) |
| 145 | { |
| 146 | otd->active_engine_index = engine_index; |
| 147 | cm->ops_handlers[opt] = fn; |
Damjan Marion | d1bed68 | 2019-04-24 15:20:35 +0200 | [diff] [blame] | 148 | return; |
Damjan Marion | 91f17dc | 2019-03-18 18:59:25 +0100 | [diff] [blame] | 149 | } |
| 150 | ae = vec_elt_at_index (cm->engines, otd->active_engine_index); |
| 151 | if (ae->priority < e->priority) |
| 152 | { |
| 153 | otd->active_engine_index = engine_index; |
| 154 | cm->ops_handlers[opt] = fn; |
| 155 | } |
| 156 | |
Damjan Marion | d1bed68 | 2019-04-24 15:20:35 +0200 | [diff] [blame] | 157 | return; |
| 158 | } |
| 159 | |
| 160 | void |
| 161 | vnet_crypto_register_key_handler (vlib_main_t * vm, u32 engine_index, |
| 162 | vnet_crypto_key_handler_t * key_handler) |
| 163 | { |
| 164 | vnet_crypto_main_t *cm = &crypto_main; |
| 165 | vnet_crypto_engine_t *e = vec_elt_at_index (cm->engines, engine_index); |
| 166 | e->key_op_handler = key_handler; |
| 167 | return; |
| 168 | } |
| 169 | |
Benoît Ganne | be95444 | 2019-04-29 16:05:46 +0200 | [diff] [blame] | 170 | static int |
| 171 | vnet_crypto_key_len_check (vnet_crypto_alg_t alg, u16 length) |
| 172 | { |
| 173 | switch (alg) |
| 174 | { |
| 175 | case VNET_CRYPTO_N_ALGS: |
| 176 | return 0; |
| 177 | case VNET_CRYPTO_ALG_NONE: |
| 178 | return 1; |
| 179 | |
| 180 | #define _(n, s, l) \ |
| 181 | case VNET_CRYPTO_ALG_##n: \ |
| 182 | if ((l) == length) \ |
Neale Ranns | e6be702 | 2019-06-04 15:37:34 +0000 | [diff] [blame] | 183 | return 1; \ |
| 184 | break; |
Benoît Ganne | be95444 | 2019-04-29 16:05:46 +0200 | [diff] [blame] | 185 | foreach_crypto_cipher_alg foreach_crypto_aead_alg |
| 186 | #undef _ |
| 187 | /* HMAC allows any key length */ |
| 188 | #define _(n, s) \ |
| 189 | case VNET_CRYPTO_ALG_HMAC_##n: \ |
| 190 | return 1; |
| 191 | foreach_crypto_hmac_alg |
| 192 | #undef _ |
| 193 | } |
| 194 | |
| 195 | return 0; |
| 196 | } |
| 197 | |
Damjan Marion | d1bed68 | 2019-04-24 15:20:35 +0200 | [diff] [blame] | 198 | u32 |
| 199 | vnet_crypto_key_add (vlib_main_t * vm, vnet_crypto_alg_t alg, u8 * data, |
| 200 | u16 length) |
| 201 | { |
| 202 | u32 index; |
| 203 | vnet_crypto_main_t *cm = &crypto_main; |
| 204 | vnet_crypto_engine_t *engine; |
| 205 | vnet_crypto_key_t *key; |
Benoît Ganne | be95444 | 2019-04-29 16:05:46 +0200 | [diff] [blame] | 206 | |
Benoît Ganne | be95444 | 2019-04-29 16:05:46 +0200 | [diff] [blame] | 207 | if (!vnet_crypto_key_len_check (alg, length)) |
| 208 | return ~0; |
| 209 | |
Damjan Marion | d1bed68 | 2019-04-24 15:20:35 +0200 | [diff] [blame] | 210 | pool_get_zero (cm->keys, key); |
| 211 | index = key - cm->keys; |
| 212 | key->alg = alg; |
| 213 | vec_validate_aligned (key->data, length - 1, CLIB_CACHE_LINE_BYTES); |
| 214 | clib_memcpy (key->data, data, length); |
| 215 | |
| 216 | /* *INDENT-OFF* */ |
| 217 | vec_foreach (engine, cm->engines) |
| 218 | if (engine->key_op_handler) |
| 219 | engine->key_op_handler (vm, VNET_CRYPTO_KEY_OP_ADD, index); |
| 220 | /* *INDENT-ON* */ |
| 221 | return index; |
| 222 | } |
| 223 | |
| 224 | void |
| 225 | vnet_crypto_key_del (vlib_main_t * vm, vnet_crypto_key_index_t index) |
| 226 | { |
| 227 | vnet_crypto_main_t *cm = &crypto_main; |
| 228 | vnet_crypto_engine_t *engine; |
| 229 | vnet_crypto_key_t *key = pool_elt_at_index (cm->keys, index); |
| 230 | |
| 231 | /* *INDENT-OFF* */ |
| 232 | vec_foreach (engine, cm->engines) |
| 233 | if (engine->key_op_handler) |
| 234 | engine->key_op_handler (vm, VNET_CRYPTO_KEY_OP_DEL, index); |
| 235 | /* *INDENT-ON* */ |
| 236 | |
| 237 | clib_memset (key->data, 0, vec_len (key->data)); |
| 238 | vec_free (key->data); |
| 239 | pool_put (cm->keys, key); |
| 240 | } |
| 241 | |
Damjan Marion | 060bfb9 | 2019-03-29 13:47:54 +0100 | [diff] [blame] | 242 | static void |
| 243 | vnet_crypto_init_cipher_data (vnet_crypto_alg_t alg, vnet_crypto_op_id_t eid, |
| 244 | vnet_crypto_op_id_t did, char *name, u8 is_aead) |
| 245 | { |
| 246 | vnet_crypto_op_type_t eopt, dopt; |
| 247 | vnet_crypto_main_t *cm = &crypto_main; |
| 248 | cm->algs[alg].name = name; |
| 249 | cm->opt_data[eid].alg = cm->opt_data[did].alg = alg; |
| 250 | cm->opt_data[eid].active_engine_index = ~0; |
| 251 | cm->opt_data[did].active_engine_index = ~0; |
| 252 | if (is_aead) |
| 253 | { |
| 254 | eopt = VNET_CRYPTO_OP_TYPE_AEAD_ENCRYPT; |
| 255 | dopt = VNET_CRYPTO_OP_TYPE_AEAD_DECRYPT; |
| 256 | } |
| 257 | else |
| 258 | { |
| 259 | eopt = VNET_CRYPTO_OP_TYPE_ENCRYPT; |
| 260 | dopt = VNET_CRYPTO_OP_TYPE_DECRYPT; |
| 261 | } |
| 262 | cm->opt_data[eid].type = eopt; |
| 263 | cm->opt_data[did].type = dopt; |
| 264 | cm->algs[alg].op_by_type[eopt] = eid; |
| 265 | cm->algs[alg].op_by_type[dopt] = did; |
| 266 | hash_set_mem (cm->alg_index_by_name, name, alg); |
| 267 | } |
| 268 | |
| 269 | static void |
| 270 | vnet_crypto_init_hmac_data (vnet_crypto_alg_t alg, |
| 271 | vnet_crypto_op_id_t id, char *name) |
| 272 | { |
| 273 | vnet_crypto_main_t *cm = &crypto_main; |
| 274 | cm->algs[alg].name = name; |
| 275 | cm->algs[alg].op_by_type[VNET_CRYPTO_OP_TYPE_HMAC] = id; |
| 276 | cm->opt_data[id].alg = alg; |
| 277 | cm->opt_data[id].active_engine_index = ~0; |
| 278 | cm->opt_data[id].type = VNET_CRYPTO_OP_TYPE_HMAC; |
| 279 | hash_set_mem (cm->alg_index_by_name, name, alg); |
| 280 | } |
| 281 | |
Damjan Marion | 91f17dc | 2019-03-18 18:59:25 +0100 | [diff] [blame] | 282 | clib_error_t * |
| 283 | vnet_crypto_init (vlib_main_t * vm) |
| 284 | { |
| 285 | vnet_crypto_main_t *cm = &crypto_main; |
| 286 | vlib_thread_main_t *tm = vlib_get_thread_main (); |
Filip Tehlar | 1469d54 | 2019-03-25 09:04:41 -0700 | [diff] [blame] | 287 | cm->engine_index_by_name = hash_create_string ( /* size */ 0, |
| 288 | sizeof (uword)); |
Damjan Marion | 060bfb9 | 2019-03-29 13:47:54 +0100 | [diff] [blame] | 289 | cm->alg_index_by_name = hash_create_string (0, sizeof (uword)); |
Damjan Marion | 91f17dc | 2019-03-18 18:59:25 +0100 | [diff] [blame] | 290 | vec_validate_aligned (cm->threads, tm->n_vlib_mains, CLIB_CACHE_LINE_BYTES); |
| 291 | vec_validate (cm->algs, VNET_CRYPTO_N_ALGS); |
Benoît Ganne | be95444 | 2019-04-29 16:05:46 +0200 | [diff] [blame] | 292 | #define _(n, s, l) \ |
Damjan Marion | 060bfb9 | 2019-03-29 13:47:54 +0100 | [diff] [blame] | 293 | vnet_crypto_init_cipher_data (VNET_CRYPTO_ALG_##n, \ |
| 294 | VNET_CRYPTO_OP_##n##_ENC, \ |
| 295 | VNET_CRYPTO_OP_##n##_DEC, s, 0); |
| 296 | foreach_crypto_cipher_alg; |
Damjan Marion | 91f17dc | 2019-03-18 18:59:25 +0100 | [diff] [blame] | 297 | #undef _ |
Benoît Ganne | be95444 | 2019-04-29 16:05:46 +0200 | [diff] [blame] | 298 | #define _(n, s, l) \ |
Damjan Marion | 060bfb9 | 2019-03-29 13:47:54 +0100 | [diff] [blame] | 299 | vnet_crypto_init_cipher_data (VNET_CRYPTO_ALG_##n, \ |
| 300 | VNET_CRYPTO_OP_##n##_ENC, \ |
| 301 | VNET_CRYPTO_OP_##n##_DEC, s, 1); |
| 302 | foreach_crypto_aead_alg; |
Damjan Marion | 91f17dc | 2019-03-18 18:59:25 +0100 | [diff] [blame] | 303 | #undef _ |
Damjan Marion | 060bfb9 | 2019-03-29 13:47:54 +0100 | [diff] [blame] | 304 | #define _(n, s) \ |
| 305 | vnet_crypto_init_hmac_data (VNET_CRYPTO_ALG_HMAC_##n, \ |
| 306 | VNET_CRYPTO_OP_##n##_HMAC, "hmac-" s); |
| 307 | foreach_crypto_hmac_alg; |
| 308 | #undef _ |
Damjan Marion | 91f17dc | 2019-03-18 18:59:25 +0100 | [diff] [blame] | 309 | return 0; |
| 310 | } |
| 311 | |
| 312 | VLIB_INIT_FUNCTION (vnet_crypto_init); |
| 313 | |
| 314 | /* |
| 315 | * fd.io coding-style-patch-verification: ON |
| 316 | * |
| 317 | * Local Variables: |
| 318 | * eval: (c-set-style "gnu") |
| 319 | * End: |
| 320 | */ |