]>
Commit | Line | Data |
---|---|---|
11fdf7f2 TL |
1 | ;; |
2 | ;; Copyright (c) 2012-2018, Intel Corporation | |
3 | ;; | |
4 | ;; Redistribution and use in source and binary forms, with or without | |
5 | ;; modification, are permitted provided that the following conditions are met: | |
6 | ;; | |
7 | ;; * Redistributions of source code must retain the above copyright notice, | |
8 | ;; this list of conditions and the following disclaimer. | |
9 | ;; * Redistributions in binary form must reproduce the above copyright | |
10 | ;; notice, this list of conditions and the following disclaimer in the | |
11 | ;; documentation and/or other materials provided with the distribution. | |
12 | ;; * Neither the name of Intel Corporation nor the names of its contributors | |
13 | ;; may be used to endorse or promote products derived from this software | |
14 | ;; without specific prior written permission. | |
15 | ;; | |
16 | ;; THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" | |
17 | ;; AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE | |
18 | ;; IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE | |
19 | ;; DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE | |
20 | ;; FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL | |
21 | ;; DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR | |
22 | ;; SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER | |
23 | ;; CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, | |
24 | ;; OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE | |
25 | ;; OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. | |
26 | ;; | |
27 | ||
f67539c2 | 28 | %include "include/os.asm" |
11fdf7f2 TL |
29 | %include "job_aes_hmac.asm" |
30 | %include "mb_mgr_datastruct.asm" | |
f67539c2 TL |
31 | %include "include/reg_sizes.asm" |
32 | %include "include/memcpy.asm" | |
33 | %include "include/const.inc" | |
11fdf7f2 TL |
34 | |
35 | ;%define DO_DBGPRINT | |
f67539c2 | 36 | %include "include/dbgprint.asm" |
11fdf7f2 TL |
37 | |
38 | extern sha1_mult_sse | |
39 | ||
40 | section .data | |
41 | default rel | |
42 | ||
43 | align 16 | |
44 | byteswap: ;ddq 0x0c0d0e0f08090a0b0405060700010203 | |
45 | dq 0x0405060700010203, 0x0c0d0e0f08090a0b | |
46 | ||
47 | section .text | |
48 | ||
49 | %if 1 | |
50 | %ifdef LINUX | |
51 | %define arg1 rdi | |
52 | %define arg2 rsi | |
53 | %define reg3 rcx | |
54 | %define reg4 rdx | |
55 | %else | |
56 | %define arg1 rcx | |
57 | %define arg2 rdx | |
58 | %define reg3 rdi | |
59 | %define reg4 rsi | |
60 | %endif | |
61 | ||
62 | %define state arg1 | |
63 | %define job arg2 | |
64 | %define len2 arg2 | |
65 | ||
66 | ||
67 | ; idx needs to be in rbx, rbp, r12-r15 | |
68 | %define last_len rbp | |
69 | %define idx rbp | |
70 | ||
71 | %define p r11 | |
72 | %define start_offset r11 | |
73 | ||
74 | %define unused_lanes rbx | |
75 | %define tmp4 rbx | |
76 | ||
77 | %define job_rax rax | |
78 | %define len rax | |
79 | ||
80 | %define size_offset reg3 | |
81 | %define tmp2 reg3 | |
82 | ||
83 | %define lane reg4 | |
84 | %define tmp3 reg4 | |
85 | ||
86 | %define extra_blocks r8 | |
87 | ||
88 | %define tmp r9 | |
89 | %define p2 r9 | |
90 | ||
91 | %define lane_data r10 | |
92 | ||
93 | %endif | |
94 | ||
95 | ; This routine clobbers rdi, rsi, rbx, rbp | |
96 | struc STACK | |
97 | _gpr_save: resq 4 | |
98 | _rsp_save: resq 1 | |
99 | endstruc | |
100 | ||
101 | ; JOB* submit_job_hmac_sse(MB_MGR_HMAC_SHA_1_OOO *state, JOB_AES_HMAC *job) | |
102 | ; arg 1 : rcx : state | |
103 | ; arg 2 : rdx : job | |
104 | MKGLOBAL(submit_job_hmac_sse,function, internal) | |
105 | submit_job_hmac_sse: | |
106 | ||
107 | mov rax, rsp | |
108 | sub rsp, STACK_size | |
109 | and rsp, -16 | |
110 | ||
111 | mov [rsp + _gpr_save + 8*0], rbx | |
112 | mov [rsp + _gpr_save + 8*1], rbp | |
113 | %ifndef LINUX | |
114 | mov [rsp + _gpr_save + 8*2], rsi | |
115 | mov [rsp + _gpr_save + 8*3], rdi | |
116 | %endif | |
117 | mov [rsp + _rsp_save], rax ; original SP | |
118 | ||
119 | DBGPRINTL "enter sha1-sse submit" | |
120 | mov unused_lanes, [state + _unused_lanes] | |
121 | movzx lane, BYTE(unused_lanes) | |
122 | shr unused_lanes, 8 | |
123 | imul lane_data, lane, _HMAC_SHA1_LANE_DATA_size | |
124 | lea lane_data, [state + _ldata + lane_data] | |
125 | mov [state + _unused_lanes], unused_lanes | |
126 | mov len, [job + _msg_len_to_hash_in_bytes] | |
127 | mov tmp, len | |
128 | shr tmp, 6 ; divide by 64, len in terms of blocks | |
129 | ||
130 | mov [lane_data + _job_in_lane], job | |
131 | mov dword [lane_data + _outer_done], 0 | |
9f95a23c TL |
132 | |
133 | movdqa xmm0, [state + _lens] | |
134 | XPINSRW xmm0, xmm1, p, lane, tmp, scale_x16 | |
135 | movdqa [state + _lens], xmm0 | |
11fdf7f2 TL |
136 | |
137 | mov last_len, len | |
138 | and last_len, 63 | |
139 | lea extra_blocks, [last_len + 9 + 63] | |
140 | shr extra_blocks, 6 | |
141 | mov [lane_data + _extra_blocks], DWORD(extra_blocks) | |
142 | ||
143 | mov p, [job + _src] | |
144 | add p, [job + _hash_start_src_offset_in_bytes] | |
145 | mov [state + _args_data_ptr + PTR_SZ*lane], p | |
146 | cmp len, 64 | |
147 | jb copy_lt64 | |
148 | ||
149 | fast_copy: | |
150 | add p, len | |
151 | movdqu xmm0, [p - 64 + 0*16] | |
152 | movdqu xmm1, [p - 64 + 1*16] | |
153 | movdqu xmm2, [p - 64 + 2*16] | |
154 | movdqu xmm3, [p - 64 + 3*16] | |
155 | movdqa [lane_data + _extra_block + 0*16], xmm0 | |
156 | movdqa [lane_data + _extra_block + 1*16], xmm1 | |
157 | movdqa [lane_data + _extra_block + 2*16], xmm2 | |
158 | movdqa [lane_data + _extra_block + 3*16], xmm3 | |
159 | end_fast_copy: | |
160 | ||
161 | mov size_offset, extra_blocks | |
162 | shl size_offset, 6 | |
163 | sub size_offset, last_len | |
164 | add size_offset, 64-8 | |
165 | mov [lane_data + _size_offset], DWORD(size_offset) | |
166 | mov start_offset, 64 | |
167 | sub start_offset, last_len | |
168 | mov [lane_data + _start_offset], DWORD(start_offset) | |
169 | ||
170 | lea tmp, [8*64 + 8*len] | |
171 | bswap tmp | |
172 | mov [lane_data + _extra_block + size_offset], tmp | |
173 | ||
174 | mov tmp, [job + _auth_key_xor_ipad] | |
175 | movdqu xmm0, [tmp] | |
176 | mov DWORD(tmp), [tmp + 4*4] | |
177 | movd [state + _args_digest + SHA1_DIGEST_WORD_SIZE*lane + 0*SHA1_DIGEST_ROW_SIZE], xmm0 | |
178 | pextrd [state + _args_digest + SHA1_DIGEST_WORD_SIZE*lane + 1*SHA1_DIGEST_ROW_SIZE], xmm0, 1 | |
179 | pextrd [state + _args_digest + SHA1_DIGEST_WORD_SIZE*lane + 2*SHA1_DIGEST_ROW_SIZE], xmm0, 2 | |
180 | pextrd [state + _args_digest + SHA1_DIGEST_WORD_SIZE*lane + 3*SHA1_DIGEST_ROW_SIZE], xmm0, 3 | |
181 | mov [state + _args_digest + SHA1_DIGEST_WORD_SIZE*lane + 4*SHA1_DIGEST_ROW_SIZE], DWORD(tmp) | |
182 | ||
183 | test len, ~63 | |
184 | jnz ge64_bytes | |
185 | ||
186 | lt64_bytes: | |
9f95a23c TL |
187 | movdqa xmm0, [state + _lens] |
188 | XPINSRW xmm0, xmm1, tmp, lane, extra_blocks, scale_x16 | |
189 | movdqa [state + _lens], xmm0 | |
190 | ||
11fdf7f2 TL |
191 | lea tmp, [lane_data + _extra_block + start_offset] |
192 | mov [state + _args_data_ptr + PTR_SZ*lane], tmp | |
193 | mov dword [lane_data + _extra_blocks], 0 | |
194 | ||
195 | ge64_bytes: | |
196 | cmp unused_lanes, 0xff | |
197 | jne return_null | |
9f95a23c | 198 | movdqa xmm0, [state + _lens] |
11fdf7f2 TL |
199 | jmp start_loop |
200 | ||
201 | align 16 | |
202 | start_loop: | |
203 | ; Find min length | |
11fdf7f2 TL |
204 | phminposuw xmm1, xmm0 |
205 | pextrw len2, xmm1, 0 ; min value | |
206 | pextrw idx, xmm1, 1 ; min index (0...3) | |
207 | cmp len2, 0 | |
208 | je len_is_0 | |
209 | ||
210 | pshuflw xmm1, xmm1, 0 | |
211 | psubw xmm0, xmm1 | |
212 | movdqa [state + _lens], xmm0 | |
213 | ||
214 | ; "state" and "args" are the same address, arg1 | |
215 | ; len is arg2 | |
216 | call sha1_mult_sse | |
217 | ; state is intact | |
218 | ||
219 | len_is_0: | |
220 | ; process completed job "idx" | |
221 | imul lane_data, idx, _HMAC_SHA1_LANE_DATA_size | |
222 | lea lane_data, [state + _ldata + lane_data] | |
223 | mov DWORD(extra_blocks), [lane_data + _extra_blocks] | |
224 | cmp extra_blocks, 0 | |
225 | jne proc_extra_blocks | |
226 | cmp dword [lane_data + _outer_done], 0 | |
227 | jne end_loop | |
228 | ||
229 | proc_outer: | |
230 | mov dword [lane_data + _outer_done], 1 | |
231 | mov DWORD(size_offset), [lane_data + _size_offset] | |
232 | mov qword [lane_data + _extra_block + size_offset], 0 | |
9f95a23c TL |
233 | |
234 | movdqa xmm1, [state + _lens] | |
235 | XPINSRW xmm1, xmm2, tmp, idx, 1, scale_x16 | |
236 | movdqa [state + _lens], xmm1 | |
237 | ||
11fdf7f2 TL |
238 | lea tmp, [lane_data + _outer_block] |
239 | mov job, [lane_data + _job_in_lane] | |
240 | mov [state + _args_data_ptr + PTR_SZ*idx], tmp | |
241 | ||
242 | movd xmm0, [state + _args_digest + SHA1_DIGEST_WORD_SIZE*idx + 0*SHA1_DIGEST_ROW_SIZE] | |
243 | pinsrd xmm0, [state + _args_digest + SHA1_DIGEST_WORD_SIZE*idx + 1*SHA1_DIGEST_ROW_SIZE], 1 | |
244 | pinsrd xmm0, [state + _args_digest + SHA1_DIGEST_WORD_SIZE*idx + 2*SHA1_DIGEST_ROW_SIZE], 2 | |
245 | pinsrd xmm0, [state + _args_digest + SHA1_DIGEST_WORD_SIZE*idx + 3*SHA1_DIGEST_ROW_SIZE], 3 | |
246 | pshufb xmm0, [rel byteswap] | |
247 | mov DWORD(tmp), [state + _args_digest + SHA1_DIGEST_WORD_SIZE*idx + 4*SHA1_DIGEST_ROW_SIZE] | |
248 | bswap DWORD(tmp) | |
249 | movdqa [lane_data + _outer_block], xmm0 | |
250 | mov [lane_data + _outer_block + 4*SHA1_DIGEST_WORD_SIZE], DWORD(tmp) | |
251 | ||
252 | mov tmp, [job + _auth_key_xor_opad] | |
253 | movdqu xmm0, [tmp] | |
254 | mov DWORD(tmp), [tmp + 4*4] | |
255 | movd [state + _args_digest + SHA1_DIGEST_WORD_SIZE*idx + 0*SHA1_DIGEST_ROW_SIZE], xmm0 | |
256 | pextrd [state + _args_digest + SHA1_DIGEST_WORD_SIZE*idx + 1*SHA1_DIGEST_ROW_SIZE], xmm0, 1 | |
257 | pextrd [state + _args_digest + SHA1_DIGEST_WORD_SIZE*idx + 2*SHA1_DIGEST_ROW_SIZE], xmm0, 2 | |
258 | pextrd [state + _args_digest + SHA1_DIGEST_WORD_SIZE*idx + 3*SHA1_DIGEST_ROW_SIZE], xmm0, 3 | |
259 | mov [state + _args_digest + SHA1_DIGEST_WORD_SIZE*idx + 4*SHA1_DIGEST_ROW_SIZE], DWORD(tmp) | |
9f95a23c | 260 | movdqa xmm0, xmm1 |
11fdf7f2 TL |
261 | jmp start_loop |
262 | ||
263 | align 16 | |
264 | proc_extra_blocks: | |
265 | mov DWORD(start_offset), [lane_data + _start_offset] | |
9f95a23c TL |
266 | |
267 | movdqa xmm0, [state + _lens] | |
268 | XPINSRW xmm0, xmm1, tmp, idx, extra_blocks, scale_x16 | |
269 | movdqa [state + _lens], xmm0 | |
270 | ||
11fdf7f2 TL |
271 | lea tmp, [lane_data + _extra_block + start_offset] |
272 | mov [state + _args_data_ptr + PTR_SZ*idx], tmp | |
273 | mov dword [lane_data + _extra_blocks], 0 | |
274 | jmp start_loop | |
275 | ||
276 | align 16 | |
277 | copy_lt64: | |
278 | ;; less than one message block of data | |
279 | ;; beginning of source block | |
280 | ;; destination extrablock but backwards by len from where 0x80 pre-populated | |
281 | lea p2, [lane_data + _extra_block + 64] | |
282 | sub p2, len | |
283 | memcpy_sse_64_1 p2, p, len, tmp4, tmp2, xmm0, xmm1, xmm2, xmm3 | |
284 | mov unused_lanes, [state + _unused_lanes] | |
285 | jmp end_fast_copy | |
286 | ||
287 | return_null: | |
288 | xor job_rax, job_rax | |
289 | jmp return | |
290 | ||
291 | align 16 | |
292 | end_loop: | |
293 | mov job_rax, [lane_data + _job_in_lane] | |
294 | mov unused_lanes, [state + _unused_lanes] | |
295 | mov qword [lane_data + _job_in_lane], 0 | |
296 | or dword [job_rax + _status], STS_COMPLETED_HMAC | |
297 | shl unused_lanes, 8 | |
298 | or unused_lanes, idx | |
299 | mov [state + _unused_lanes], unused_lanes | |
300 | ||
301 | mov p, [job_rax + _auth_tag_output] | |
302 | ||
303 | ; copy 12 bytes | |
304 | mov DWORD(tmp), [state + _args_digest + SHA1_DIGEST_WORD_SIZE*idx + 0*SHA1_DIGEST_ROW_SIZE] | |
305 | mov DWORD(tmp2), [state + _args_digest + SHA1_DIGEST_WORD_SIZE*idx + 1*SHA1_DIGEST_ROW_SIZE] | |
306 | mov DWORD(tmp3), [state + _args_digest + SHA1_DIGEST_WORD_SIZE*idx + 2*SHA1_DIGEST_ROW_SIZE] | |
307 | bswap DWORD(tmp) | |
308 | bswap DWORD(tmp2) | |
309 | bswap DWORD(tmp3) | |
310 | mov [p + 0*SHA1_DIGEST_WORD_SIZE], DWORD(tmp) | |
311 | mov [p + 1*SHA1_DIGEST_WORD_SIZE], DWORD(tmp2) | |
312 | mov [p + 2*SHA1_DIGEST_WORD_SIZE], DWORD(tmp3) | |
313 | ||
9f95a23c | 314 | cmp qword [job_rax + _auth_tag_output_len_in_bytes], 12 |
f67539c2 | 315 | je clear_ret |
9f95a23c TL |
316 | |
317 | ;; copy remaining 8 bytes to return 20 byte digest | |
318 | mov DWORD(tmp), [state + _args_digest + SHA1_DIGEST_WORD_SIZE*idx + 3*SHA1_DIGEST_ROW_SIZE] | |
319 | mov DWORD(tmp2), [state + _args_digest + SHA1_DIGEST_WORD_SIZE*idx + 4*SHA1_DIGEST_ROW_SIZE] | |
320 | bswap DWORD(tmp) | |
321 | bswap DWORD(tmp2) | |
322 | mov [p + 3*SHA1_DIGEST_WORD_SIZE], DWORD(tmp) | |
323 | mov [p + 4*SHA1_DIGEST_WORD_SIZE], DWORD(tmp2) | |
324 | ||
f67539c2 TL |
325 | clear_ret: |
326 | ||
327 | %ifdef SAFE_DATA | |
328 | ;; Clear digest (20B), outer_block (20B) and extra_block (64B) of returned job | |
329 | mov dword [state + _args_digest + SHA1_DIGEST_WORD_SIZE*idx + 0*SHA1_DIGEST_ROW_SIZE], 0 | |
330 | mov dword [state + _args_digest + SHA1_DIGEST_WORD_SIZE*idx + 1*SHA1_DIGEST_ROW_SIZE], 0 | |
331 | mov dword [state + _args_digest + SHA1_DIGEST_WORD_SIZE*idx + 2*SHA1_DIGEST_ROW_SIZE], 0 | |
332 | mov dword [state + _args_digest + SHA1_DIGEST_WORD_SIZE*idx + 3*SHA1_DIGEST_ROW_SIZE], 0 | |
333 | mov dword [state + _args_digest + SHA1_DIGEST_WORD_SIZE*idx + 4*SHA1_DIGEST_ROW_SIZE], 0 | |
334 | ||
335 | pxor xmm0, xmm0 | |
336 | imul lane_data, idx, _HMAC_SHA1_LANE_DATA_size | |
337 | lea lane_data, [state + _ldata + lane_data] | |
338 | ;; Clear first 64 bytes of extra_block | |
339 | %assign offset 0 | |
340 | %rep 4 | |
341 | movdqa [lane_data + _extra_block + offset], xmm0 | |
342 | %assign offset (offset + 16) | |
343 | %endrep | |
344 | ||
345 | ;; Clear first 20 bytes of outer_block | |
346 | movdqa [lane_data + _outer_block], xmm0 | |
347 | mov dword [lane_data + _outer_block + 16], 0 | |
348 | %endif | |
349 | ||
11fdf7f2 TL |
350 | return: |
351 | ||
352 | mov rbx, [rsp + _gpr_save + 8*0] | |
353 | mov rbp, [rsp + _gpr_save + 8*1] | |
354 | %ifndef LINUX | |
355 | mov rsi, [rsp + _gpr_save + 8*2] | |
356 | mov rdi, [rsp + _gpr_save + 8*3] | |
357 | %endif | |
358 | mov rsp, [rsp + _rsp_save] ; original SP | |
359 | ||
360 | ret | |
361 | ||
362 | %ifdef LINUX | |
363 | section .note.GNU-stack noalloc noexec nowrite progbits | |
364 | %endif |