2 ;; Copyright (c) 2012-2018, Intel Corporation
4 ;; Redistribution and use in source and binary forms, with or without
5 ;; modification, are permitted provided that the following conditions are met:
7 ;; * Redistributions of source code must retain the above copyright notice,
8 ;; this list of conditions and the following disclaimer.
9 ;; * Redistributions in binary form must reproduce the above copyright
10 ;; notice, this list of conditions and the following disclaimer in the
11 ;; documentation and/or other materials provided with the distribution.
12 ;; * Neither the name of Intel Corporation nor the names of its contributors
13 ;; may be used to endorse or promote products derived from this software
14 ;; without specific prior written permission.
16 ;; THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
17 ;; AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
18 ;; IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
19 ;; DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE
20 ;; FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
21 ;; DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
22 ;; SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER
23 ;; CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
24 ;; OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
25 ;; OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
29 %include "job_aes_hmac.asm"
30 %include "mb_mgr_datastruct.asm"
31 %include "reg_sizes.asm"
34 %include "dbgprint.asm"
41 byteswap: ;ddq 0x0c0d0e0f08090a0b0405060700010203
42 dq 0x0405060700010203, 0x0c0d0e0f08090a0b
64 ; idx needs to be in rbx, rdi, rbp
69 %define start_offset r11
71 %define unused_lanes r12
77 %define size_offset reg3
83 %define extra_blocks r8
92 ; we clobber rsi, rdi, rbp, r12; called routine clobbers also r13-r15
98 ; JOB* submit_job_hmac_avx(MB_MGR_HMAC_SHA_1_OOO *state, JOB_AES_HMAC *job)
101 MKGLOBAL(submit_job_hmac_avx2,function,internal)
102 submit_job_hmac_avx2:
106 and rsp, -32 ; align to 32 byte boundary
107 mov [rsp + _gpr_save + 8*0], rbp
108 mov [rsp + _gpr_save + 8*1], r12
109 mov [rsp + _gpr_save + 8*2], r13
110 mov [rsp + _gpr_save + 8*3], r14
111 mov [rsp + _gpr_save + 8*4], r15
113 mov [rsp + _gpr_save + 8*5], rsi
114 mov [rsp + _gpr_save + 8*6], rdi
116 mov [rsp + _rsp_save], rax
117 DBGPRINTL "---------- enter sha1 submit -----------"
119 mov unused_lanes, [state + _unused_lanes]
120 mov lane, unused_lanes
121 and lane, 0xF ;; just a nibble
123 imul lane_data, lane, _HMAC_SHA1_LANE_DATA_size
124 lea lane_data, [state + _ldata + lane_data]
125 mov [state + _unused_lanes], unused_lanes
127 mov len, [job + _msg_len_to_hash_in_bytes]
129 shr tmp, 6 ; divide by 64, len in terms of blocks
131 mov [lane_data + _job_in_lane], job
132 mov dword [lane_data + _outer_done], 0
133 mov [state + _lens + 2*lane], WORD(tmp)
137 lea extra_blocks, [last_len + 9 + 63]
139 mov [lane_data + _extra_blocks], DWORD(extra_blocks)
142 add p, [job + _hash_start_src_offset_in_bytes]
143 mov [state + _args_data_ptr + PTR_SZ*lane], p
149 vmovdqu ymm0, [p - 64 + 0 * 32]
150 vmovdqu ymm1, [p - 64 + 1 * 32]
151 vmovdqu [lane_data + _extra_block + 0*32], ymm0
152 vmovdqu [lane_data + _extra_block + 1*32], ymm1
155 mov size_offset, extra_blocks
157 sub size_offset, last_len
158 add size_offset, 64-8
159 mov [lane_data + _size_offset], DWORD(size_offset)
161 sub start_offset, last_len
162 mov [lane_data + _start_offset], DWORD(start_offset)
164 lea tmp, [8*64 + 8*len]
166 mov [lane_data + _extra_block + size_offset], tmp
168 mov tmp, [job + _auth_key_xor_ipad]
170 mov DWORD(tmp), [tmp + 4*4]
171 vmovd [state + _args_digest + SHA1_DIGEST_WORD_SIZE*lane + 0*SHA1_DIGEST_ROW_SIZE], xmm0
172 vpextrd [state + _args_digest + SHA1_DIGEST_WORD_SIZE*lane + 1*SHA1_DIGEST_ROW_SIZE], xmm0, 1
173 vpextrd [state + _args_digest + SHA1_DIGEST_WORD_SIZE*lane + 2*SHA1_DIGEST_ROW_SIZE], xmm0, 2
174 vpextrd [state + _args_digest + SHA1_DIGEST_WORD_SIZE*lane + 3*SHA1_DIGEST_ROW_SIZE], xmm0, 3
175 mov [state + _args_digest + SHA1_DIGEST_WORD_SIZE*lane + 4*SHA1_DIGEST_ROW_SIZE], DWORD(tmp)
181 mov [state + _lens + 2*lane], WORD(extra_blocks)
182 lea tmp, [lane_data + _extra_block + start_offset]
183 mov [state + _args_data_ptr + PTR_SZ*lane], tmp
184 mov dword [lane_data + _extra_blocks], 0
187 cmp unused_lanes, 0xf
194 vmovdqa xmm0, [state + _lens]
195 vphminposuw xmm1, xmm0
196 vpextrw DWORD(len2), xmm1, 0 ; min value
197 vpextrw DWORD(idx), xmm1, 1 ; min index (0...3)
198 DBGPRINTL64 "min_length", len2
199 DBGPRINTL64 "min_length index ", idx
203 vpbroadcastw xmm1, xmm1
204 DBGPRINTL_XMM "SUBMIT lens after shuffle", xmm1
206 vpsubw xmm0, xmm0, xmm1
207 vmovdqa [state + _lens], xmm0
208 DBGPRINTL_XMM "lengths after subtraction", xmm0
210 ; "state" and "args" are the same address, arg1
213 ; state and idx are intact
216 ; process completed job "idx"
217 imul lane_data, idx, _HMAC_SHA1_LANE_DATA_size
218 lea lane_data, [state + _ldata + lane_data]
219 mov DWORD(extra_blocks), [lane_data + _extra_blocks]
221 jne proc_extra_blocks
222 cmp dword [lane_data + _outer_done], 0
226 mov dword [lane_data + _outer_done], 1
227 mov DWORD(size_offset), [lane_data + _size_offset]
228 mov qword [lane_data + _extra_block + size_offset], 0
229 mov word [state + _lens + 2*idx], 1
230 lea tmp, [lane_data + _outer_block]
231 mov job, [lane_data + _job_in_lane]
232 mov [state + _args_data_ptr + PTR_SZ*idx], tmp
234 vmovd xmm0, [state + _args_digest + SHA1_DIGEST_WORD_SIZE*idx + 0*SHA1_DIGEST_ROW_SIZE]
235 vpinsrd xmm0, xmm0, [state + _args_digest + SHA1_DIGEST_WORD_SIZE*idx + 1*SHA1_DIGEST_ROW_SIZE], 1
236 vpinsrd xmm0, xmm0, [state + _args_digest + SHA1_DIGEST_WORD_SIZE*idx + 2*SHA1_DIGEST_ROW_SIZE], 2
237 vpinsrd xmm0, xmm0, [state + _args_digest + SHA1_DIGEST_WORD_SIZE*idx + 3*SHA1_DIGEST_ROW_SIZE], 3
238 vpshufb xmm0, xmm0, [rel byteswap]
239 mov DWORD(tmp), [state + _args_digest + SHA1_DIGEST_WORD_SIZE*idx + 4*SHA1_DIGEST_ROW_SIZE]
241 vmovdqa [lane_data + _outer_block], xmm0
242 mov [lane_data + _outer_block + 4*SHA1_DIGEST_WORD_SIZE], DWORD(tmp)
244 mov tmp, [job + _auth_key_xor_opad]
246 mov DWORD(tmp), [tmp + 4*4]
247 vmovd [state + _args_digest + SHA1_DIGEST_WORD_SIZE*idx + 0*SHA1_DIGEST_ROW_SIZE], xmm0
248 vpextrd [state + _args_digest + SHA1_DIGEST_WORD_SIZE*idx + 1*SHA1_DIGEST_ROW_SIZE], xmm0, 1
249 vpextrd [state + _args_digest + SHA1_DIGEST_WORD_SIZE*idx + 2*SHA1_DIGEST_ROW_SIZE], xmm0, 2
250 vpextrd [state + _args_digest + SHA1_DIGEST_WORD_SIZE*idx + 3*SHA1_DIGEST_ROW_SIZE], xmm0, 3
251 mov [state + _args_digest + SHA1_DIGEST_WORD_SIZE*idx + 4*SHA1_DIGEST_ROW_SIZE], DWORD(tmp)
256 mov DWORD(start_offset), [lane_data + _start_offset]
257 mov [state + _lens + 2*idx], WORD(extra_blocks)
258 lea tmp, [lane_data + _extra_block + start_offset]
259 mov [state + _args_data_ptr + PTR_SZ*idx], tmp
260 mov dword [lane_data + _extra_blocks], 0
265 ;; less than one message block of data
266 ;; beginning of source block
267 ;; destination extrablock but backwards by len from where 0x80 pre-populated
268 lea p2, [lane_data + _extra_block + 64]
270 memcpy_avx2_64_1 p2, p, len, tmp4, tmp2, ymm0, ymm1
271 mov unused_lanes, [state + _unused_lanes]
280 mov job_rax, [lane_data + _job_in_lane]
281 mov unused_lanes, [state + _unused_lanes]
282 mov qword [lane_data + _job_in_lane], 0
283 or dword [job_rax + _status], STS_COMPLETED_HMAC
286 mov [state + _unused_lanes], unused_lanes
288 mov p, [job_rax + _auth_tag_output]
291 mov DWORD(tmp), [state + _args_digest + SHA1_DIGEST_WORD_SIZE*idx + 0*SHA1_DIGEST_ROW_SIZE]
292 mov DWORD(tmp2), [state + _args_digest + SHA1_DIGEST_WORD_SIZE*idx + 1*SHA1_DIGEST_ROW_SIZE]
293 mov DWORD(tmp3), [state + _args_digest + SHA1_DIGEST_WORD_SIZE*idx + 2*SHA1_DIGEST_ROW_SIZE]
297 mov [p + 0*SHA1_DIGEST_WORD_SIZE], DWORD(tmp)
298 mov [p + 1*SHA1_DIGEST_WORD_SIZE], DWORD(tmp2)
299 mov [p + 2*SHA1_DIGEST_WORD_SIZE], DWORD(tmp3)
302 DBGPRINTL "---------- exit sha1 submit -----------"
303 mov rbp, [rsp + _gpr_save + 8*0]
304 mov r12, [rsp + _gpr_save + 8*1]
305 mov r13, [rsp + _gpr_save + 8*2]
306 mov r14, [rsp + _gpr_save + 8*3]
307 mov r15, [rsp + _gpr_save + 8*4]
309 mov rsi, [rsp + _gpr_save + 8*5]
310 mov rdi, [rsp + _gpr_save + 8*6]
312 mov rsp, [rsp + _rsp_save]
317 section .note.GNU-stack noalloc noexec nowrite progbits