mirror of
https://github.com/openwrt/openwrt.git
synced 2025-01-07 06:18:54 +00:00
d540725871
Without this patch, the chacha block counter is not incremented on neon rounds, resulting in incorrect calculations and corrupt packets. This also switches to using `--no-numbered --zero-commit` so that future diffs are smaller. Reported-by: Hans Geiblinger <cybrnook2002@yahoo.com> Reviewed-by: Ilya Lipnitskiy <ilya.lipnitskiy@gmail.com> Cc: David Bauer <mail@david-bauer.net> Cc: Petr Štetiar <ynezz@true.cz> Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
172 lines
5.7 KiB
Diff
172 lines
5.7 KiB
Diff
From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
|
|
From: "Jason A. Donenfeld" <Jason@zx2c4.com>
|
|
Date: Sun, 5 Jan 2020 22:40:49 -0500
|
|
Subject: [PATCH] crypto: {arm,arm64,mips}/poly1305 - remove redundant
|
|
non-reduction from emit
|
|
MIME-Version: 1.0
|
|
Content-Type: text/plain; charset=UTF-8
|
|
Content-Transfer-Encoding: 8bit
|
|
|
|
commit 31899908a0d248b030b4464425b86c717e0007d4 upstream.
|
|
|
|
This appears to be some kind of copy and paste error, and is actually
|
|
dead code.
|
|
|
|
Pre: f = 0 ⇒ (f >> 32) = 0
|
|
f = (f >> 32) + le32_to_cpu(digest[0]);
|
|
Post: 0 ≤ f < 2³²
|
|
put_unaligned_le32(f, dst);
|
|
|
|
Pre: 0 ≤ f < 2³² ⇒ (f >> 32) = 0
|
|
f = (f >> 32) + le32_to_cpu(digest[1]);
|
|
Post: 0 ≤ f < 2³²
|
|
put_unaligned_le32(f, dst + 4);
|
|
|
|
Pre: 0 ≤ f < 2³² ⇒ (f >> 32) = 0
|
|
f = (f >> 32) + le32_to_cpu(digest[2]);
|
|
Post: 0 ≤ f < 2³²
|
|
put_unaligned_le32(f, dst + 8);
|
|
|
|
Pre: 0 ≤ f < 2³² ⇒ (f >> 32) = 0
|
|
f = (f >> 32) + le32_to_cpu(digest[3]);
|
|
Post: 0 ≤ f < 2³²
|
|
put_unaligned_le32(f, dst + 12);
|
|
|
|
Therefore this sequence is redundant. And Andy's code appears to handle
|
|
misalignment acceptably.
|
|
|
|
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
|
|
Tested-by: Ard Biesheuvel <ardb@kernel.org>
|
|
Reviewed-by: Ard Biesheuvel <ardb@kernel.org>
|
|
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
|
|
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
|
|
---
|
|
arch/arm/crypto/poly1305-glue.c | 18 ++----------------
|
|
arch/arm64/crypto/poly1305-glue.c | 18 ++----------------
|
|
arch/mips/crypto/poly1305-glue.c | 18 ++----------------
|
|
3 files changed, 6 insertions(+), 48 deletions(-)
|
|
|
|
--- a/arch/arm/crypto/poly1305-glue.c
|
|
+++ b/arch/arm/crypto/poly1305-glue.c
|
|
@@ -20,7 +20,7 @@
|
|
|
|
void poly1305_init_arm(void *state, const u8 *key);
|
|
void poly1305_blocks_arm(void *state, const u8 *src, u32 len, u32 hibit);
|
|
-void poly1305_emit_arm(void *state, __le32 *digest, const u32 *nonce);
|
|
+void poly1305_emit_arm(void *state, u8 *digest, const u32 *nonce);
|
|
|
|
void __weak poly1305_blocks_neon(void *state, const u8 *src, u32 len, u32 hibit)
|
|
{
|
|
@@ -179,9 +179,6 @@ EXPORT_SYMBOL(poly1305_update_arch);
|
|
|
|
void poly1305_final_arch(struct poly1305_desc_ctx *dctx, u8 *dst)
|
|
{
|
|
- __le32 digest[4];
|
|
- u64 f = 0;
|
|
-
|
|
if (unlikely(dctx->buflen)) {
|
|
dctx->buf[dctx->buflen++] = 1;
|
|
memset(dctx->buf + dctx->buflen, 0,
|
|
@@ -189,18 +186,7 @@ void poly1305_final_arch(struct poly1305
|
|
poly1305_blocks_arm(&dctx->h, dctx->buf, POLY1305_BLOCK_SIZE, 0);
|
|
}
|
|
|
|
- poly1305_emit_arm(&dctx->h, digest, dctx->s);
|
|
-
|
|
- /* mac = (h + s) % (2^128) */
|
|
- f = (f >> 32) + le32_to_cpu(digest[0]);
|
|
- put_unaligned_le32(f, dst);
|
|
- f = (f >> 32) + le32_to_cpu(digest[1]);
|
|
- put_unaligned_le32(f, dst + 4);
|
|
- f = (f >> 32) + le32_to_cpu(digest[2]);
|
|
- put_unaligned_le32(f, dst + 8);
|
|
- f = (f >> 32) + le32_to_cpu(digest[3]);
|
|
- put_unaligned_le32(f, dst + 12);
|
|
-
|
|
+ poly1305_emit_arm(&dctx->h, dst, dctx->s);
|
|
*dctx = (struct poly1305_desc_ctx){};
|
|
}
|
|
EXPORT_SYMBOL(poly1305_final_arch);
|
|
--- a/arch/arm64/crypto/poly1305-glue.c
|
|
+++ b/arch/arm64/crypto/poly1305-glue.c
|
|
@@ -21,7 +21,7 @@
|
|
asmlinkage void poly1305_init_arm64(void *state, const u8 *key);
|
|
asmlinkage void poly1305_blocks(void *state, const u8 *src, u32 len, u32 hibit);
|
|
asmlinkage void poly1305_blocks_neon(void *state, const u8 *src, u32 len, u32 hibit);
|
|
-asmlinkage void poly1305_emit(void *state, __le32 *digest, const u32 *nonce);
|
|
+asmlinkage void poly1305_emit(void *state, u8 *digest, const u32 *nonce);
|
|
|
|
static __ro_after_init DEFINE_STATIC_KEY_FALSE(have_neon);
|
|
|
|
@@ -162,9 +162,6 @@ EXPORT_SYMBOL(poly1305_update_arch);
|
|
|
|
void poly1305_final_arch(struct poly1305_desc_ctx *dctx, u8 *dst)
|
|
{
|
|
- __le32 digest[4];
|
|
- u64 f = 0;
|
|
-
|
|
if (unlikely(dctx->buflen)) {
|
|
dctx->buf[dctx->buflen++] = 1;
|
|
memset(dctx->buf + dctx->buflen, 0,
|
|
@@ -172,18 +169,7 @@ void poly1305_final_arch(struct poly1305
|
|
poly1305_blocks(&dctx->h, dctx->buf, POLY1305_BLOCK_SIZE, 0);
|
|
}
|
|
|
|
- poly1305_emit(&dctx->h, digest, dctx->s);
|
|
-
|
|
- /* mac = (h + s) % (2^128) */
|
|
- f = (f >> 32) + le32_to_cpu(digest[0]);
|
|
- put_unaligned_le32(f, dst);
|
|
- f = (f >> 32) + le32_to_cpu(digest[1]);
|
|
- put_unaligned_le32(f, dst + 4);
|
|
- f = (f >> 32) + le32_to_cpu(digest[2]);
|
|
- put_unaligned_le32(f, dst + 8);
|
|
- f = (f >> 32) + le32_to_cpu(digest[3]);
|
|
- put_unaligned_le32(f, dst + 12);
|
|
-
|
|
+ poly1305_emit(&dctx->h, dst, dctx->s);
|
|
*dctx = (struct poly1305_desc_ctx){};
|
|
}
|
|
EXPORT_SYMBOL(poly1305_final_arch);
|
|
--- a/arch/mips/crypto/poly1305-glue.c
|
|
+++ b/arch/mips/crypto/poly1305-glue.c
|
|
@@ -15,7 +15,7 @@
|
|
|
|
asmlinkage void poly1305_init_mips(void *state, const u8 *key);
|
|
asmlinkage void poly1305_blocks_mips(void *state, const u8 *src, u32 len, u32 hibit);
|
|
-asmlinkage void poly1305_emit_mips(void *state, __le32 *digest, const u32 *nonce);
|
|
+asmlinkage void poly1305_emit_mips(void *state, u8 *digest, const u32 *nonce);
|
|
|
|
void poly1305_init_arch(struct poly1305_desc_ctx *dctx, const u8 *key)
|
|
{
|
|
@@ -134,9 +134,6 @@ EXPORT_SYMBOL(poly1305_update_arch);
|
|
|
|
void poly1305_final_arch(struct poly1305_desc_ctx *dctx, u8 *dst)
|
|
{
|
|
- __le32 digest[4];
|
|
- u64 f = 0;
|
|
-
|
|
if (unlikely(dctx->buflen)) {
|
|
dctx->buf[dctx->buflen++] = 1;
|
|
memset(dctx->buf + dctx->buflen, 0,
|
|
@@ -144,18 +141,7 @@ void poly1305_final_arch(struct poly1305
|
|
poly1305_blocks_mips(&dctx->h, dctx->buf, POLY1305_BLOCK_SIZE, 0);
|
|
}
|
|
|
|
- poly1305_emit_mips(&dctx->h, digest, dctx->s);
|
|
-
|
|
- /* mac = (h + s) % (2^128) */
|
|
- f = (f >> 32) + le32_to_cpu(digest[0]);
|
|
- put_unaligned_le32(f, dst);
|
|
- f = (f >> 32) + le32_to_cpu(digest[1]);
|
|
- put_unaligned_le32(f, dst + 4);
|
|
- f = (f >> 32) + le32_to_cpu(digest[2]);
|
|
- put_unaligned_le32(f, dst + 8);
|
|
- f = (f >> 32) + le32_to_cpu(digest[3]);
|
|
- put_unaligned_le32(f, dst + 12);
|
|
-
|
|
+ poly1305_emit_mips(&dctx->h, dst, dctx->s);
|
|
*dctx = (struct poly1305_desc_ctx){};
|
|
}
|
|
EXPORT_SYMBOL(poly1305_final_arch);
|