1 /*
2  * CDDL HEADER START
3  *
4  * The contents of this file are subject to the terms of the
5  * Common Development and Distribution License (the "License").
6  * You may not use this file except in compliance with the License.
7  *
8  * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
9  * or http://opensource.org/licenses/CDDL-1.0.
10  * See the License for the specific language governing permissions
11  * and limitations under the License.
12  *
13  * When distributing Covered Code, include this CDDL HEADER in each
14  * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
15  * If applicable, add the following below this CDDL HEADER, with the
16  * fields enclosed by brackets "[]" replaced with your own identifying
17  * information: Portions Copyright [yyyy] [name of copyright owner]
18  *
19  * CDDL HEADER END
20  */
21 /*
22  * Copyright 2013 Saso Kiselkov.  All rights reserved.
23  * Use is subject to license terms.
24  */
25 #include <sys/edonr.h>
26 
27 #define	EDONR_MODE		512
28 #define	EDONR_BLOCK_SIZE	EdonR512_BLOCK_SIZE
29 
30 /*
31  * Native zio_checksum interface for the Edon-R hash function.
32  */
33 /*ARGSUSED*/
34 static void
zio_checksum_edonr_native(const void * buf,uint64_t size,const void * ctx_template,zio_cksum_t * zcp)35 zio_checksum_edonr_native(const void *buf, uint64_t size,
36     const void *ctx_template, zio_cksum_t *zcp)
37 {
38 	uint8_t		digest[EDONR_MODE / 8];
39 	EdonRState	ctx;
40 
41 	ASSERT(ctx_template != NULL);
42 	bcopy(ctx_template, &ctx, sizeof (ctx));
43 	EdonRUpdate(&ctx, buf, size * 8);
44 	EdonRFinal(&ctx, digest);
45 	bcopy(digest, zcp->zc_word, sizeof (zcp->zc_word));
46 }
47 
48 /*
49  * Byteswapped zio_checksum interface for the Edon-R hash function.
50  */
51 static void
zio_checksum_edonr_byteswap(const void * buf,uint64_t size,const void * ctx_template,zio_cksum_t * zcp)52 zio_checksum_edonr_byteswap(const void *buf, uint64_t size,
53     const void *ctx_template, zio_cksum_t *zcp)
54 {
55 	zio_cksum_t	tmp;
56 
57 	zio_checksum_edonr_native(buf, size, ctx_template, &tmp);
58 	zcp->zc_word[0] = BSWAP_64(zcp->zc_word[0]);
59 	zcp->zc_word[1] = BSWAP_64(zcp->zc_word[1]);
60 	zcp->zc_word[2] = BSWAP_64(zcp->zc_word[2]);
61 	zcp->zc_word[3] = BSWAP_64(zcp->zc_word[3]);
62 }
63 
64 static void *
zio_checksum_edonr_tmpl_init(const zio_cksum_salt_t * salt)65 zio_checksum_edonr_tmpl_init(const zio_cksum_salt_t *salt)
66 {
67 	EdonRState	*ctx;
68 	uint8_t		salt_block[EDONR_BLOCK_SIZE];
69 
70 	/*
71 	 * Edon-R needs all but the last hash invocation to be on full-size
72 	 * blocks, but the salt is too small. Rather than simply padding it
73 	 * with zeros, we expand the salt into a new salt block of proper
74 	 * size by double-hashing it (the new salt block will be composed of
75 	 * H(salt) || H(H(salt))).
76 	 */
77 	EdonRHash(EDONR_MODE, salt->zcs_bytes, sizeof (salt->zcs_bytes) * 8,
78 	    salt_block);
79 	EdonRHash(EDONR_MODE, salt_block, EDONR_MODE, salt_block +
80 	    EDONR_MODE / 8);
81 
82 	/*
83 	 * Feed the new salt block into the hash function - this will serve
84 	 * as our MAC key.
85 	 */
86 	ctx = malloc(sizeof (*ctx));
87 	bzero(ctx, sizeof (*ctx));
88 	EdonRInit(ctx, EDONR_MODE);
89 	EdonRUpdate(ctx, salt_block, sizeof (salt_block) * 8);
90 	return (ctx);
91 }
92 
93 static void
zio_checksum_edonr_tmpl_free(void * ctx_template)94 zio_checksum_edonr_tmpl_free(void *ctx_template)
95 {
96 	EdonRState	*ctx = ctx_template;
97 
98 	bzero(ctx, sizeof (*ctx));
99 	free(ctx);
100 }
101