blob: 81bea1f8c79f1fc3b8b9197ec581aff1ba93367a [file] [log] [blame]
Paul Bakker5121ce52009-01-03 21:22:43 +00001/*
2 * VIA PadLock support functions
3 *
Bence Szépkúti1e148272020-08-07 13:07:28 +02004 * Copyright The Mbed TLS Contributors
Manuel Pégourié-Gonnard37ff1402015-09-04 14:21:07 +02005 * SPDX-License-Identifier: Apache-2.0
6 *
7 * Licensed under the Apache License, Version 2.0 (the "License"); you may
8 * not use this file except in compliance with the License.
9 * You may obtain a copy of the License at
10 *
11 * http://www.apache.org/licenses/LICENSE-2.0
12 *
13 * Unless required by applicable law or agreed to in writing, software
14 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
15 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
16 * See the License for the specific language governing permissions and
17 * limitations under the License.
Paul Bakker5121ce52009-01-03 21:22:43 +000018 */
19/*
20 * This implementation is based on the VIA PadLock Programming Guide:
21 *
22 * http://www.via.com.tw/en/downloads/whitepapers/initiatives/padlock/
23 * programming_guide.pdf
24 */
25
Gilles Peskinedb09ef62020-06-03 01:43:33 +020026#include "common.h"
Paul Bakker5121ce52009-01-03 21:22:43 +000027
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020028#if defined(MBEDTLS_PADLOCK_C)
Paul Bakker5121ce52009-01-03 21:22:43 +000029
Chris Jones16dbaeb2021-03-09 17:47:55 +000030#include "padlock.h"
Paul Bakker5121ce52009-01-03 21:22:43 +000031
Manuel Pégourié-Gonnard45ec8da2015-02-10 13:50:47 +000032#include <string.h>
33
David Horstmanne3d8f312023-01-03 11:07:09 +000034/* *INDENT-OFF* */
Manuel Pégourié-Gonnardba194322015-05-29 09:47:57 +020035#ifndef asm
36#define asm __asm
37#endif
David Horstmanne3d8f312023-01-03 11:07:09 +000038/* *INDENT-ON* */
Manuel Pégourié-Gonnardba194322015-05-29 09:47:57 +020039
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020040#if defined(MBEDTLS_HAVE_X86)
Paul Bakker5121ce52009-01-03 21:22:43 +000041
Paul Bakker5121ce52009-01-03 21:22:43 +000042/*
43 * PadLock detection routine
44 */
Manuel Pégourié-Gonnardc730ed32015-06-02 10:38:50 +010045int mbedtls_padlock_has_support( int feature )
Paul Bakker5121ce52009-01-03 21:22:43 +000046{
47 static int flags = -1;
Paul Bakker53e15132013-12-30 20:43:40 +010048 int ebx = 0, edx = 0;
Paul Bakker5121ce52009-01-03 21:22:43 +000049
50 if( flags == -1 )
51 {
Manuel Pégourié-Gonnard87a8ffe2014-06-23 12:40:01 +020052 asm( "movl %%ebx, %0 \n\t"
53 "movl $0xC0000000, %%eax \n\t"
54 "cpuid \n\t"
55 "cmpl $0xC0000001, %%eax \n\t"
56 "movl $0, %%edx \n\t"
okhowang(王沛文)0c4bbda2020-06-24 16:02:10 +080057 "jb 1f \n\t"
Manuel Pégourié-Gonnard87a8ffe2014-06-23 12:40:01 +020058 "movl $0xC0000001, %%eax \n\t"
59 "cpuid \n\t"
okhowang(王沛文)0c4bbda2020-06-24 16:02:10 +080060 "1: \n\t"
Manuel Pégourié-Gonnard87a8ffe2014-06-23 12:40:01 +020061 "movl %%edx, %1 \n\t"
62 "movl %2, %%ebx \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +000063 : "=m" (ebx), "=m" (edx)
64 : "m" (ebx)
65 : "eax", "ecx", "edx" );
66
67 flags = edx;
68 }
69
70 return( flags & feature );
71}
72
73/*
74 * PadLock AES-ECB block en(de)cryption
75 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020076int mbedtls_padlock_xcryptecb( mbedtls_aes_context *ctx,
Paul Bakker5121ce52009-01-03 21:22:43 +000077 int mode,
Paul Bakkerff60ee62010-03-16 21:09:09 +000078 const unsigned char input[16],
Paul Bakker5121ce52009-01-03 21:22:43 +000079 unsigned char output[16] )
80{
Paul Bakker53e15132013-12-30 20:43:40 +010081 int ebx = 0;
Paul Bakker5c2364c2012-10-01 14:41:15 +000082 uint32_t *rk;
83 uint32_t *blk;
84 uint32_t *ctrl;
Paul Bakker5121ce52009-01-03 21:22:43 +000085 unsigned char buf[256];
86
Werner Lewisc1999d52022-07-05 11:55:15 +010087 rk = ctx->buf + ctx->rk_offset;
88
89 if( ( (long) rk & 15 ) != 0 )
90 return( MBEDTLS_ERR_PADLOCK_DATA_MISALIGNED );
91
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020092 blk = MBEDTLS_PADLOCK_ALIGN16( buf );
Paul Bakker5121ce52009-01-03 21:22:43 +000093 memcpy( blk, input, 16 );
94
95 ctrl = blk + 4;
96 *ctrl = 0x80 | ctx->nr | ( ( ctx->nr + ( mode^1 ) - 10 ) << 9 );
97
Manuel Pégourié-Gonnard87a8ffe2014-06-23 12:40:01 +020098 asm( "pushfl \n\t"
99 "popfl \n\t"
100 "movl %%ebx, %0 \n\t"
101 "movl $1, %%ecx \n\t"
102 "movl %2, %%edx \n\t"
103 "movl %3, %%ebx \n\t"
104 "movl %4, %%esi \n\t"
105 "movl %4, %%edi \n\t"
106 ".byte 0xf3,0x0f,0xa7,0xc8 \n\t"
107 "movl %1, %%ebx \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000108 : "=m" (ebx)
109 : "m" (ebx), "m" (ctrl), "m" (rk), "m" (blk)
Manuel Pégourié-Gonnardcf201202015-04-02 10:46:55 +0100110 : "memory", "ecx", "edx", "esi", "edi" );
Paul Bakker5121ce52009-01-03 21:22:43 +0000111
112 memcpy( output, blk, 16 );
113
114 return( 0 );
115}
116
117/*
118 * PadLock AES-CBC buffer en(de)cryption
119 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200120int mbedtls_padlock_xcryptcbc( mbedtls_aes_context *ctx,
Paul Bakker5121ce52009-01-03 21:22:43 +0000121 int mode,
Paul Bakker23986e52011-04-24 08:57:21 +0000122 size_t length,
Paul Bakker5121ce52009-01-03 21:22:43 +0000123 unsigned char iv[16],
Paul Bakkerff60ee62010-03-16 21:09:09 +0000124 const unsigned char *input,
Paul Bakker5121ce52009-01-03 21:22:43 +0000125 unsigned char *output )
126{
Paul Bakker53e15132013-12-30 20:43:40 +0100127 int ebx = 0;
Paul Bakker23986e52011-04-24 08:57:21 +0000128 size_t count;
Paul Bakker5c2364c2012-10-01 14:41:15 +0000129 uint32_t *rk;
130 uint32_t *iw;
131 uint32_t *ctrl;
Paul Bakker5121ce52009-01-03 21:22:43 +0000132 unsigned char buf[256];
133
Werner Lewisc1999d52022-07-05 11:55:15 +0100134 rk = ctx->buf + ctx->rk_offset;
135
Paul Bakker5121ce52009-01-03 21:22:43 +0000136 if( ( (long) input & 15 ) != 0 ||
Werner Lewisc1999d52022-07-05 11:55:15 +0100137 ( (long) output & 15 ) != 0 ||
138 ( (long) rk & 15 ) != 0 )
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200139 return( MBEDTLS_ERR_PADLOCK_DATA_MISALIGNED );
Paul Bakker5121ce52009-01-03 21:22:43 +0000140
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200141 iw = MBEDTLS_PADLOCK_ALIGN16( buf );
Paul Bakker5121ce52009-01-03 21:22:43 +0000142 memcpy( iw, iv, 16 );
143
144 ctrl = iw + 4;
Paul Bakker66d5d072014-06-17 16:39:18 +0200145 *ctrl = 0x80 | ctx->nr | ( ( ctx->nr + ( mode ^ 1 ) - 10 ) << 9 );
Paul Bakker5121ce52009-01-03 21:22:43 +0000146
Paul Bakker66d5d072014-06-17 16:39:18 +0200147 count = ( length + 15 ) >> 4;
Paul Bakker5121ce52009-01-03 21:22:43 +0000148
Manuel Pégourié-Gonnard87a8ffe2014-06-23 12:40:01 +0200149 asm( "pushfl \n\t"
150 "popfl \n\t"
151 "movl %%ebx, %0 \n\t"
152 "movl %2, %%ecx \n\t"
153 "movl %3, %%edx \n\t"
154 "movl %4, %%ebx \n\t"
155 "movl %5, %%esi \n\t"
156 "movl %6, %%edi \n\t"
157 "movl %7, %%eax \n\t"
158 ".byte 0xf3,0x0f,0xa7,0xd0 \n\t"
159 "movl %1, %%ebx \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000160 : "=m" (ebx)
161 : "m" (ebx), "m" (count), "m" (ctrl),
162 "m" (rk), "m" (input), "m" (output), "m" (iw)
Manuel Pégourié-Gonnardcf201202015-04-02 10:46:55 +0100163 : "memory", "eax", "ecx", "edx", "esi", "edi" );
Paul Bakker5121ce52009-01-03 21:22:43 +0000164
165 memcpy( iv, iw, 16 );
166
167 return( 0 );
168}
169
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200170#endif /* MBEDTLS_HAVE_X86 */
Paul Bakker5121ce52009-01-03 21:22:43 +0000171
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200172#endif /* MBEDTLS_PADLOCK_C */