]> git.proxmox.com Git - mirror_zfs.git/blob - module/zfs/edonr_zfs.c
OpenZFS 4185 - add new cryptographic checksums to ZFS: SHA-512, Skein, Edon-R
[mirror_zfs.git] / module / zfs / edonr_zfs.c
1 /*
2 * CDDL HEADER START
3 *
4 * The contents of this file are subject to the terms of the
5 * Common Development and Distribution License (the "License").
6 * You may not use this file except in compliance with the License.
7 *
8 * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
9 * or http://opensource.org/licenses/CDDL-1.0.
10 * See the License for the specific language governing permissions
11 * and limitations under the License.
12 *
13 * When distributing Covered Code, include this CDDL HEADER in each
14 * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
15 * If applicable, add the following below this CDDL HEADER, with the
16 * fields enclosed by brackets "[]" replaced with your own identifying
17 * information: Portions Copyright [yyyy] [name of copyright owner]
18 *
19 * CDDL HEADER END
20 */
21 /*
22 * Copyright 2013 Saso Kiselkov. All rights reserved.
23 * Use is subject to license terms.
24 */
25 #include <sys/zfs_context.h>
26 #include <sys/zio.h>
27 #include <sys/edonr.h>
28 #include <sys/zfs_context.h> /* For CTASSERT() */
29
30 #define EDONR_MODE 512
31 #define EDONR_BLOCK_SIZE EdonR512_BLOCK_SIZE
32
33 /*
34 * Native zio_checksum interface for the Edon-R hash function.
35 */
36 /*ARGSUSED*/
37 void
38 zio_checksum_edonr_native(const void *buf, uint64_t size,
39 const void *ctx_template, zio_cksum_t *zcp)
40 {
41 uint8_t digest[EDONR_MODE / 8];
42 EdonRState ctx;
43
44 ASSERT(ctx_template != NULL);
45 bcopy(ctx_template, &ctx, sizeof (ctx));
46 EdonRUpdate(&ctx, buf, size * 8);
47 EdonRFinal(&ctx, digest);
48 bcopy(digest, zcp->zc_word, sizeof (zcp->zc_word));
49 }
50
51 /*
52 * Byteswapped zio_checksum interface for the Edon-R hash function.
53 */
54 void
55 zio_checksum_edonr_byteswap(const void *buf, uint64_t size,
56 const void *ctx_template, zio_cksum_t *zcp)
57 {
58 zio_cksum_t tmp;
59
60 zio_checksum_edonr_native(buf, size, ctx_template, &tmp);
61 zcp->zc_word[0] = BSWAP_64(zcp->zc_word[0]);
62 zcp->zc_word[1] = BSWAP_64(zcp->zc_word[1]);
63 zcp->zc_word[2] = BSWAP_64(zcp->zc_word[2]);
64 zcp->zc_word[3] = BSWAP_64(zcp->zc_word[3]);
65 }
66
67 void *
68 zio_checksum_edonr_tmpl_init(const zio_cksum_salt_t *salt)
69 {
70 EdonRState *ctx;
71 uint8_t salt_block[EDONR_BLOCK_SIZE];
72
73 /*
74 * Edon-R needs all but the last hash invocation to be on full-size
75 * blocks, but the salt is too small. Rather than simply padding it
76 * with zeros, we expand the salt into a new salt block of proper
77 * size by double-hashing it (the new salt block will be composed of
78 * H(salt) || H(H(salt))).
79 */
80 CTASSERT(EDONR_BLOCK_SIZE == 2 * (EDONR_MODE / 8));
81 EdonRHash(EDONR_MODE, salt->zcs_bytes, sizeof (salt->zcs_bytes) * 8,
82 salt_block);
83 EdonRHash(EDONR_MODE, salt_block, EDONR_MODE, salt_block +
84 EDONR_MODE / 8);
85
86 /*
87 * Feed the new salt block into the hash function - this will serve
88 * as our MAC key.
89 */
90 ctx = kmem_zalloc(sizeof (*ctx), KM_SLEEP);
91 EdonRInit(ctx, EDONR_MODE);
92 EdonRUpdate(ctx, salt_block, sizeof (salt_block) * 8);
93 return (ctx);
94 }
95
96 void
97 zio_checksum_edonr_tmpl_free(void *ctx_template)
98 {
99 EdonRState *ctx = ctx_template;
100
101 bzero(ctx, sizeof (*ctx));
102 kmem_free(ctx, sizeof (*ctx));
103 }