1/*
2 * CDDL HEADER START
3 *
4 * The contents of this file are subject to the terms of the
5 * Common Development and Distribution License (the "License").
6 * You may not use this file except in compliance with the License.
7 *
8 * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
9 * or http://opensource.org/licenses/CDDL-1.0.
10 * See the License for the specific language governing permissions
11 * and limitations under the License.
12 *
13 * When distributing Covered Code, include this CDDL HEADER in each
14 * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
15 * If applicable, add the following below this CDDL HEADER, with the
16 * fields enclosed by brackets "[]" replaced with your own identifying
17 * information: Portions Copyright [yyyy] [name of copyright owner]
18 *
19 * CDDL HEADER END
20 */
21/*
22 * Copyright 2013 Saso Kiselkov.  All rights reserved.
23 * Use is subject to license terms.
24 */
25/*
26 * Copyright (c) 2016 by Delphix. All rights reserved.
27 */
28#include <sys/zfs_context.h>
29#include <sys/zio.h>
30#include <sys/edonr.h>
31#include <sys/abd.h>
32
33#define	EDONR_MODE		512
34#define	EDONR_BLOCK_SIZE	EdonR512_BLOCK_SIZE
35
36static int
37edonr_incremental(void *buf, size_t size, void *arg)
38{
39	EdonRState *ctx = arg;
40	EdonRUpdate(ctx, buf, size * 8);
41	return (0);
42}
43
44/*
45 * Native zio_checksum interface for the Edon-R hash function.
46 */
47/*ARGSUSED*/
48void
49abd_checksum_edonr_native(abd_t *abd, uint64_t size,
50    const void *ctx_template, zio_cksum_t *zcp)
51{
52	uint8_t		digest[EDONR_MODE / 8];
53	EdonRState	ctx;
54
55	ASSERT(ctx_template != NULL);
56	bcopy(ctx_template, &ctx, sizeof (ctx));
57	(void) abd_iterate_func(abd, 0, size, edonr_incremental, &ctx);
58	EdonRFinal(&ctx, digest);
59	bcopy(digest, zcp->zc_word, sizeof (zcp->zc_word));
60}
61
62/*
63 * Byteswapped zio_checksum interface for the Edon-R hash function.
64 */
65void
66abd_checksum_edonr_byteswap(abd_t *abd, uint64_t size,
67    const void *ctx_template, zio_cksum_t *zcp)
68{
69	zio_cksum_t	tmp;
70
71	abd_checksum_edonr_native(abd, size, ctx_template, &tmp);
72	zcp->zc_word[0] = BSWAP_64(zcp->zc_word[0]);
73	zcp->zc_word[1] = BSWAP_64(zcp->zc_word[1]);
74	zcp->zc_word[2] = BSWAP_64(zcp->zc_word[2]);
75	zcp->zc_word[3] = BSWAP_64(zcp->zc_word[3]);
76}
77
78void *
79abd_checksum_edonr_tmpl_init(const zio_cksum_salt_t *salt)
80{
81	EdonRState	*ctx;
82	uint8_t		salt_block[EDONR_BLOCK_SIZE];
83
84	/*
85	 * Edon-R needs all but the last hash invocation to be on full-size
86	 * blocks, but the salt is too small. Rather than simply padding it
87	 * with zeros, we expand the salt into a new salt block of proper
88	 * size by double-hashing it (the new salt block will be composed of
89	 * H(salt) || H(H(salt))).
90	 */
91	CTASSERT(EDONR_BLOCK_SIZE == 2 * (EDONR_MODE / 8));
92	EdonRHash(EDONR_MODE, salt->zcs_bytes, sizeof (salt->zcs_bytes) * 8,
93	    salt_block);
94	EdonRHash(EDONR_MODE, salt_block, EDONR_MODE, salt_block +
95	    EDONR_MODE / 8);
96
97	/*
98	 * Feed the new salt block into the hash function - this will serve
99	 * as our MAC key.
100	 */
101	ctx = kmem_zalloc(sizeof (*ctx), KM_SLEEP);
102	EdonRInit(ctx, EDONR_MODE);
103	EdonRUpdate(ctx, salt_block, sizeof (salt_block) * 8);
104	return (ctx);
105}
106
107void
108abd_checksum_edonr_tmpl_free(void *ctx_template)
109{
110	EdonRState	*ctx = ctx_template;
111
112	bzero(ctx, sizeof (*ctx));
113	kmem_free(ctx, sizeof (*ctx));
114}
115