^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 1) // SPDX-License-Identifier: GPL-2.0-or-later
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 2) /*
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 3) * Cryptographic API.
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 4) *
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 5) * RIPEMD-128 - RACE Integrity Primitives Evaluation Message Digest.
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 6) *
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 7) * Based on the reference implementation by Antoon Bosselaers, ESAT-COSIC
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 8) *
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 9) * Copyright (c) 2008 Adrian-Ken Rueegsegger <ken@codelabs.ch>
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 10) */
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 11) #include <crypto/internal/hash.h>
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 12) #include <linux/init.h>
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 13) #include <linux/module.h>
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 14) #include <linux/mm.h>
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 15) #include <linux/types.h>
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 16) #include <asm/byteorder.h>
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 17)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 18) #include "ripemd.h"
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 19)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 20) struct rmd128_ctx {
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 21) u64 byte_count;
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 22) u32 state[4];
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 23) __le32 buffer[16];
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 24) };
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 25)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 26) #define K1 RMD_K1
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 27) #define K2 RMD_K2
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 28) #define K3 RMD_K3
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 29) #define K4 RMD_K4
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 30) #define KK1 RMD_K6
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 31) #define KK2 RMD_K7
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 32) #define KK3 RMD_K8
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 33) #define KK4 RMD_K1
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 34)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 35) #define F1(x, y, z) (x ^ y ^ z) /* XOR */
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 36) #define F2(x, y, z) (z ^ (x & (y ^ z))) /* x ? y : z */
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 37) #define F3(x, y, z) ((x | ~y) ^ z)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 38) #define F4(x, y, z) (y ^ (z & (x ^ y))) /* z ? x : y */
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 39)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 40) #define ROUND(a, b, c, d, f, k, x, s) { \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 41) (a) += f((b), (c), (d)) + le32_to_cpup(&(x)) + (k); \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 42) (a) = rol32((a), (s)); \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 43) }
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 44)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 45) static void rmd128_transform(u32 *state, const __le32 *in)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 46) {
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 47) u32 aa, bb, cc, dd, aaa, bbb, ccc, ddd;
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 48)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 49) /* Initialize left lane */
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 50) aa = state[0];
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 51) bb = state[1];
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 52) cc = state[2];
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 53) dd = state[3];
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 54)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 55) /* Initialize right lane */
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 56) aaa = state[0];
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 57) bbb = state[1];
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 58) ccc = state[2];
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 59) ddd = state[3];
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 60)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 61) /* round 1: left lane */
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 62) ROUND(aa, bb, cc, dd, F1, K1, in[0], 11);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 63) ROUND(dd, aa, bb, cc, F1, K1, in[1], 14);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 64) ROUND(cc, dd, aa, bb, F1, K1, in[2], 15);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 65) ROUND(bb, cc, dd, aa, F1, K1, in[3], 12);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 66) ROUND(aa, bb, cc, dd, F1, K1, in[4], 5);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 67) ROUND(dd, aa, bb, cc, F1, K1, in[5], 8);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 68) ROUND(cc, dd, aa, bb, F1, K1, in[6], 7);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 69) ROUND(bb, cc, dd, aa, F1, K1, in[7], 9);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 70) ROUND(aa, bb, cc, dd, F1, K1, in[8], 11);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 71) ROUND(dd, aa, bb, cc, F1, K1, in[9], 13);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 72) ROUND(cc, dd, aa, bb, F1, K1, in[10], 14);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 73) ROUND(bb, cc, dd, aa, F1, K1, in[11], 15);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 74) ROUND(aa, bb, cc, dd, F1, K1, in[12], 6);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 75) ROUND(dd, aa, bb, cc, F1, K1, in[13], 7);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 76) ROUND(cc, dd, aa, bb, F1, K1, in[14], 9);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 77) ROUND(bb, cc, dd, aa, F1, K1, in[15], 8);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 78)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 79) /* round 2: left lane */
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 80) ROUND(aa, bb, cc, dd, F2, K2, in[7], 7);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 81) ROUND(dd, aa, bb, cc, F2, K2, in[4], 6);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 82) ROUND(cc, dd, aa, bb, F2, K2, in[13], 8);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 83) ROUND(bb, cc, dd, aa, F2, K2, in[1], 13);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 84) ROUND(aa, bb, cc, dd, F2, K2, in[10], 11);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 85) ROUND(dd, aa, bb, cc, F2, K2, in[6], 9);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 86) ROUND(cc, dd, aa, bb, F2, K2, in[15], 7);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 87) ROUND(bb, cc, dd, aa, F2, K2, in[3], 15);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 88) ROUND(aa, bb, cc, dd, F2, K2, in[12], 7);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 89) ROUND(dd, aa, bb, cc, F2, K2, in[0], 12);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 90) ROUND(cc, dd, aa, bb, F2, K2, in[9], 15);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 91) ROUND(bb, cc, dd, aa, F2, K2, in[5], 9);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 92) ROUND(aa, bb, cc, dd, F2, K2, in[2], 11);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 93) ROUND(dd, aa, bb, cc, F2, K2, in[14], 7);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 94) ROUND(cc, dd, aa, bb, F2, K2, in[11], 13);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 95) ROUND(bb, cc, dd, aa, F2, K2, in[8], 12);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 96)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 97) /* round 3: left lane */
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 98) ROUND(aa, bb, cc, dd, F3, K3, in[3], 11);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 99) ROUND(dd, aa, bb, cc, F3, K3, in[10], 13);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 100) ROUND(cc, dd, aa, bb, F3, K3, in[14], 6);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 101) ROUND(bb, cc, dd, aa, F3, K3, in[4], 7);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 102) ROUND(aa, bb, cc, dd, F3, K3, in[9], 14);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 103) ROUND(dd, aa, bb, cc, F3, K3, in[15], 9);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 104) ROUND(cc, dd, aa, bb, F3, K3, in[8], 13);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 105) ROUND(bb, cc, dd, aa, F3, K3, in[1], 15);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 106) ROUND(aa, bb, cc, dd, F3, K3, in[2], 14);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 107) ROUND(dd, aa, bb, cc, F3, K3, in[7], 8);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 108) ROUND(cc, dd, aa, bb, F3, K3, in[0], 13);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 109) ROUND(bb, cc, dd, aa, F3, K3, in[6], 6);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 110) ROUND(aa, bb, cc, dd, F3, K3, in[13], 5);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 111) ROUND(dd, aa, bb, cc, F3, K3, in[11], 12);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 112) ROUND(cc, dd, aa, bb, F3, K3, in[5], 7);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 113) ROUND(bb, cc, dd, aa, F3, K3, in[12], 5);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 114)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 115) /* round 4: left lane */
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 116) ROUND(aa, bb, cc, dd, F4, K4, in[1], 11);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 117) ROUND(dd, aa, bb, cc, F4, K4, in[9], 12);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 118) ROUND(cc, dd, aa, bb, F4, K4, in[11], 14);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 119) ROUND(bb, cc, dd, aa, F4, K4, in[10], 15);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 120) ROUND(aa, bb, cc, dd, F4, K4, in[0], 14);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 121) ROUND(dd, aa, bb, cc, F4, K4, in[8], 15);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 122) ROUND(cc, dd, aa, bb, F4, K4, in[12], 9);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 123) ROUND(bb, cc, dd, aa, F4, K4, in[4], 8);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 124) ROUND(aa, bb, cc, dd, F4, K4, in[13], 9);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 125) ROUND(dd, aa, bb, cc, F4, K4, in[3], 14);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 126) ROUND(cc, dd, aa, bb, F4, K4, in[7], 5);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 127) ROUND(bb, cc, dd, aa, F4, K4, in[15], 6);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 128) ROUND(aa, bb, cc, dd, F4, K4, in[14], 8);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 129) ROUND(dd, aa, bb, cc, F4, K4, in[5], 6);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 130) ROUND(cc, dd, aa, bb, F4, K4, in[6], 5);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 131) ROUND(bb, cc, dd, aa, F4, K4, in[2], 12);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 132)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 133) /* round 1: right lane */
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 134) ROUND(aaa, bbb, ccc, ddd, F4, KK1, in[5], 8);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 135) ROUND(ddd, aaa, bbb, ccc, F4, KK1, in[14], 9);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 136) ROUND(ccc, ddd, aaa, bbb, F4, KK1, in[7], 9);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 137) ROUND(bbb, ccc, ddd, aaa, F4, KK1, in[0], 11);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 138) ROUND(aaa, bbb, ccc, ddd, F4, KK1, in[9], 13);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 139) ROUND(ddd, aaa, bbb, ccc, F4, KK1, in[2], 15);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 140) ROUND(ccc, ddd, aaa, bbb, F4, KK1, in[11], 15);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 141) ROUND(bbb, ccc, ddd, aaa, F4, KK1, in[4], 5);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 142) ROUND(aaa, bbb, ccc, ddd, F4, KK1, in[13], 7);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 143) ROUND(ddd, aaa, bbb, ccc, F4, KK1, in[6], 7);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 144) ROUND(ccc, ddd, aaa, bbb, F4, KK1, in[15], 8);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 145) ROUND(bbb, ccc, ddd, aaa, F4, KK1, in[8], 11);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 146) ROUND(aaa, bbb, ccc, ddd, F4, KK1, in[1], 14);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 147) ROUND(ddd, aaa, bbb, ccc, F4, KK1, in[10], 14);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 148) ROUND(ccc, ddd, aaa, bbb, F4, KK1, in[3], 12);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 149) ROUND(bbb, ccc, ddd, aaa, F4, KK1, in[12], 6);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 150)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 151) /* round 2: right lane */
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 152) ROUND(aaa, bbb, ccc, ddd, F3, KK2, in[6], 9);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 153) ROUND(ddd, aaa, bbb, ccc, F3, KK2, in[11], 13);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 154) ROUND(ccc, ddd, aaa, bbb, F3, KK2, in[3], 15);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 155) ROUND(bbb, ccc, ddd, aaa, F3, KK2, in[7], 7);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 156) ROUND(aaa, bbb, ccc, ddd, F3, KK2, in[0], 12);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 157) ROUND(ddd, aaa, bbb, ccc, F3, KK2, in[13], 8);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 158) ROUND(ccc, ddd, aaa, bbb, F3, KK2, in[5], 9);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 159) ROUND(bbb, ccc, ddd, aaa, F3, KK2, in[10], 11);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 160) ROUND(aaa, bbb, ccc, ddd, F3, KK2, in[14], 7);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 161) ROUND(ddd, aaa, bbb, ccc, F3, KK2, in[15], 7);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 162) ROUND(ccc, ddd, aaa, bbb, F3, KK2, in[8], 12);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 163) ROUND(bbb, ccc, ddd, aaa, F3, KK2, in[12], 7);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 164) ROUND(aaa, bbb, ccc, ddd, F3, KK2, in[4], 6);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 165) ROUND(ddd, aaa, bbb, ccc, F3, KK2, in[9], 15);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 166) ROUND(ccc, ddd, aaa, bbb, F3, KK2, in[1], 13);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 167) ROUND(bbb, ccc, ddd, aaa, F3, KK2, in[2], 11);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 168)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 169) /* round 3: right lane */
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 170) ROUND(aaa, bbb, ccc, ddd, F2, KK3, in[15], 9);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 171) ROUND(ddd, aaa, bbb, ccc, F2, KK3, in[5], 7);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 172) ROUND(ccc, ddd, aaa, bbb, F2, KK3, in[1], 15);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 173) ROUND(bbb, ccc, ddd, aaa, F2, KK3, in[3], 11);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 174) ROUND(aaa, bbb, ccc, ddd, F2, KK3, in[7], 8);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 175) ROUND(ddd, aaa, bbb, ccc, F2, KK3, in[14], 6);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 176) ROUND(ccc, ddd, aaa, bbb, F2, KK3, in[6], 6);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 177) ROUND(bbb, ccc, ddd, aaa, F2, KK3, in[9], 14);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 178) ROUND(aaa, bbb, ccc, ddd, F2, KK3, in[11], 12);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 179) ROUND(ddd, aaa, bbb, ccc, F2, KK3, in[8], 13);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 180) ROUND(ccc, ddd, aaa, bbb, F2, KK3, in[12], 5);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 181) ROUND(bbb, ccc, ddd, aaa, F2, KK3, in[2], 14);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 182) ROUND(aaa, bbb, ccc, ddd, F2, KK3, in[10], 13);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 183) ROUND(ddd, aaa, bbb, ccc, F2, KK3, in[0], 13);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 184) ROUND(ccc, ddd, aaa, bbb, F2, KK3, in[4], 7);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 185) ROUND(bbb, ccc, ddd, aaa, F2, KK3, in[13], 5);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 186)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 187) /* round 4: right lane */
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 188) ROUND(aaa, bbb, ccc, ddd, F1, KK4, in[8], 15);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 189) ROUND(ddd, aaa, bbb, ccc, F1, KK4, in[6], 5);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 190) ROUND(ccc, ddd, aaa, bbb, F1, KK4, in[4], 8);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 191) ROUND(bbb, ccc, ddd, aaa, F1, KK4, in[1], 11);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 192) ROUND(aaa, bbb, ccc, ddd, F1, KK4, in[3], 14);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 193) ROUND(ddd, aaa, bbb, ccc, F1, KK4, in[11], 14);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 194) ROUND(ccc, ddd, aaa, bbb, F1, KK4, in[15], 6);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 195) ROUND(bbb, ccc, ddd, aaa, F1, KK4, in[0], 14);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 196) ROUND(aaa, bbb, ccc, ddd, F1, KK4, in[5], 6);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 197) ROUND(ddd, aaa, bbb, ccc, F1, KK4, in[12], 9);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 198) ROUND(ccc, ddd, aaa, bbb, F1, KK4, in[2], 12);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 199) ROUND(bbb, ccc, ddd, aaa, F1, KK4, in[13], 9);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 200) ROUND(aaa, bbb, ccc, ddd, F1, KK4, in[9], 12);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 201) ROUND(ddd, aaa, bbb, ccc, F1, KK4, in[7], 5);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 202) ROUND(ccc, ddd, aaa, bbb, F1, KK4, in[10], 15);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 203) ROUND(bbb, ccc, ddd, aaa, F1, KK4, in[14], 8);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 204)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 205) /* combine results */
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 206) ddd += cc + state[1]; /* final result for state[0] */
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 207) state[1] = state[2] + dd + aaa;
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 208) state[2] = state[3] + aa + bbb;
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 209) state[3] = state[0] + bb + ccc;
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 210) state[0] = ddd;
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 211) }
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 212)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 213) static int rmd128_init(struct shash_desc *desc)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 214) {
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 215) struct rmd128_ctx *rctx = shash_desc_ctx(desc);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 216)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 217) rctx->byte_count = 0;
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 218)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 219) rctx->state[0] = RMD_H0;
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 220) rctx->state[1] = RMD_H1;
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 221) rctx->state[2] = RMD_H2;
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 222) rctx->state[3] = RMD_H3;
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 223)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 224) memset(rctx->buffer, 0, sizeof(rctx->buffer));
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 225)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 226) return 0;
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 227) }
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 228)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 229) static int rmd128_update(struct shash_desc *desc, const u8 *data,
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 230) unsigned int len)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 231) {
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 232) struct rmd128_ctx *rctx = shash_desc_ctx(desc);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 233) const u32 avail = sizeof(rctx->buffer) - (rctx->byte_count & 0x3f);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 234)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 235) rctx->byte_count += len;
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 236)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 237) /* Enough space in buffer? If so copy and we're done */
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 238) if (avail > len) {
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 239) memcpy((char *)rctx->buffer + (sizeof(rctx->buffer) - avail),
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 240) data, len);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 241) goto out;
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 242) }
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 243)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 244) memcpy((char *)rctx->buffer + (sizeof(rctx->buffer) - avail),
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 245) data, avail);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 246)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 247) rmd128_transform(rctx->state, rctx->buffer);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 248) data += avail;
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 249) len -= avail;
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 250)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 251) while (len >= sizeof(rctx->buffer)) {
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 252) memcpy(rctx->buffer, data, sizeof(rctx->buffer));
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 253) rmd128_transform(rctx->state, rctx->buffer);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 254) data += sizeof(rctx->buffer);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 255) len -= sizeof(rctx->buffer);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 256) }
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 257)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 258) memcpy(rctx->buffer, data, len);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 259)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 260) out:
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 261) return 0;
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 262) }
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 263)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 264) /* Add padding and return the message digest. */
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 265) static int rmd128_final(struct shash_desc *desc, u8 *out)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 266) {
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 267) struct rmd128_ctx *rctx = shash_desc_ctx(desc);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 268) u32 i, index, padlen;
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 269) __le64 bits;
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 270) __le32 *dst = (__le32 *)out;
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 271) static const u8 padding[64] = { 0x80, };
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 272)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 273) bits = cpu_to_le64(rctx->byte_count << 3);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 274)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 275) /* Pad out to 56 mod 64 */
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 276) index = rctx->byte_count & 0x3f;
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 277) padlen = (index < 56) ? (56 - index) : ((64+56) - index);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 278) rmd128_update(desc, padding, padlen);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 279)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 280) /* Append length */
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 281) rmd128_update(desc, (const u8 *)&bits, sizeof(bits));
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 282)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 283) /* Store state in digest */
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 284) for (i = 0; i < 4; i++)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 285) dst[i] = cpu_to_le32p(&rctx->state[i]);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 286)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 287) /* Wipe context */
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 288) memset(rctx, 0, sizeof(*rctx));
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 289)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 290) return 0;
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 291) }
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 292)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 293) static struct shash_alg alg = {
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 294) .digestsize = RMD128_DIGEST_SIZE,
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 295) .init = rmd128_init,
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 296) .update = rmd128_update,
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 297) .final = rmd128_final,
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 298) .descsize = sizeof(struct rmd128_ctx),
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 299) .base = {
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 300) .cra_name = "rmd128",
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 301) .cra_driver_name = "rmd128-generic",
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 302) .cra_blocksize = RMD128_BLOCK_SIZE,
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 303) .cra_module = THIS_MODULE,
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 304) }
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 305) };
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 306)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 307) static int __init rmd128_mod_init(void)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 308) {
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 309) return crypto_register_shash(&alg);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 310) }
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 311)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 312) static void __exit rmd128_mod_fini(void)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 313) {
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 314) crypto_unregister_shash(&alg);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 315) }
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 316)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 317) subsys_initcall(rmd128_mod_init);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 318) module_exit(rmd128_mod_fini);
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 319)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 320) MODULE_LICENSE("GPL");
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 321) MODULE_AUTHOR("Adrian-Ken Rueegsegger <ken@codelabs.ch>");
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 322) MODULE_DESCRIPTION("RIPEMD-128 Message Digest");
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 323) MODULE_ALIAS_CRYPTO("rmd128");