Module Name:    src
Committed By:   riastradh
Date:           Mon Jun 29 23:38:02 UTC 2020

Modified Files:
        src/sys/arch/x86/conf: files.x86
        src/sys/arch/x86/include: via_padlock.h
        src/sys/arch/x86/x86: via_padlock.c

Log Message:
padlock(4): Remove legacy rijndael API use.

This doesn't actually need to compute AES -- it just needs the
standard AES key schedule, so use the BearSSL constant-time key
schedule implementation.

XXX Compile-tested only.
XXX The byte-order business here seems highly questionable.


To generate a diff of this commit:
cvs rdiff -u -r1.112 -r1.113 src/sys/arch/x86/conf/files.x86
cvs rdiff -u -r1.9 -r1.10 src/sys/arch/x86/include/via_padlock.h
cvs rdiff -u -r1.29 -r1.30 src/sys/arch/x86/x86/via_padlock.c

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.

Modified files:

Index: src/sys/arch/x86/conf/files.x86
diff -u src/sys/arch/x86/conf/files.x86:1.112 src/sys/arch/x86/conf/files.x86:1.113
--- src/sys/arch/x86/conf/files.x86:1.112	Mon Jun 29 23:29:39 2020
+++ src/sys/arch/x86/conf/files.x86	Mon Jun 29 23:38:02 2020
@@ -1,4 +1,4 @@
-#	$NetBSD: files.x86,v 1.112 2020/06/29 23:29:39 riastradh Exp $
+#	$NetBSD: files.x86,v 1.113 2020/06/29 23:38:02 riastradh Exp $
 
 # options for MP configuration through the MP spec
 defflag opt_mpbios.h MPBIOS MPDEBUG MPBIOS_SCANPCI
@@ -59,7 +59,7 @@ device	odcm
 attach	odcm at cpufeaturebus
 file	arch/x86/x86/odcm.c		odcm
 
-device	padlock: opencrypto, rijndael
+device	padlock: opencrypto, aes
 attach	padlock at cpufeaturebus
 file	arch/x86/x86/via_padlock.c	padlock
 

Index: src/sys/arch/x86/include/via_padlock.h
diff -u src/sys/arch/x86/include/via_padlock.h:1.9 src/sys/arch/x86/include/via_padlock.h:1.10
--- src/sys/arch/x86/include/via_padlock.h:1.9	Sat Feb 27 00:54:59 2016
+++ src/sys/arch/x86/include/via_padlock.h	Mon Jun 29 23:38:02 2020
@@ -1,4 +1,4 @@
-/*	$NetBSD: via_padlock.h,v 1.9 2016/02/27 00:54:59 tls Exp $	*/
+/*	$NetBSD: via_padlock.h,v 1.10 2020/06/29 23:38:02 riastradh Exp $	*/
 
 /*-
  * Copyright (c) 2003 Jason Wright
@@ -25,7 +25,8 @@
 
 #include <sys/rndsource.h>
 #include <sys/callout.h>
-#include <crypto/rijndael/rijndael.h>
+
+#include <crypto/aes/aes.h>
 
 /* VIA C3 xcrypt-* instruction context control options */
 #define C3_CRYPT_CWLO_ROUND_M		0x0000000f
@@ -43,9 +44,8 @@
 #define C3_CRYPT_CWLO_KEY256		0x0000080e      /* 256bit, 15 rds */
 
 struct via_padlock_session {
-        uint32_t	ses_ekey[4 * (RIJNDAEL_MAXNR + 1) + 4];	/* 128 bit aligned */
-        uint32_t	ses_dkey[4 * (RIJNDAEL_MAXNR + 1) + 4];	/* 128 bit aligned */
-        uint8_t	ses_iv[16];				/* 128 bit aligned */
+        uint32_t	ses_ekey[4*(AES_256_NROUNDS + 1)];
+        uint32_t	ses_dkey[4*(AES_256_NROUNDS + 1)];
         uint32_t	ses_cw0;
         struct swcr_data	*swd;
         int	ses_klen;

Index: src/sys/arch/x86/x86/via_padlock.c
diff -u src/sys/arch/x86/x86/via_padlock.c:1.29 src/sys/arch/x86/x86/via_padlock.c:1.30
--- src/sys/arch/x86/x86/via_padlock.c:1.29	Sun Jun 14 23:20:15 2020
+++ src/sys/arch/x86/x86/via_padlock.c	Mon Jun 29 23:38:02 2020
@@ -1,5 +1,5 @@
 /*	$OpenBSD: via.c,v 1.8 2006/11/17 07:47:56 tom Exp $	*/
-/*	$NetBSD: via_padlock.c,v 1.29 2020/06/14 23:20:15 riastradh Exp $ */
+/*	$NetBSD: via_padlock.c,v 1.30 2020/06/29 23:38:02 riastradh Exp $ */
 
 /*-
  * Copyright (c) 2003 Jason Wright
@@ -20,7 +20,7 @@
  */
 
 #include <sys/cdefs.h>
-__KERNEL_RCSID(0, "$NetBSD: via_padlock.c,v 1.29 2020/06/14 23:20:15 riastradh Exp $");
+__KERNEL_RCSID(0, "$NetBSD: via_padlock.c,v 1.30 2020/06/29 23:38:02 riastradh Exp $");
 
 #include <sys/param.h>
 #include <sys/systm.h>
@@ -37,10 +37,11 @@ __KERNEL_RCSID(0, "$NetBSD: via_padlock.
 #include <machine/cpufunc.h>
 #include <machine/cpuvar.h>
 
+#include <crypto/aes/aes_bear.h>
+
 #include <opencrypto/cryptodev.h>
 #include <opencrypto/cryptosoft.h>
 #include <opencrypto/xform.h>
-#include <crypto/rijndael/rijndael.h>
 
 #include <opencrypto/cryptosoft_xform.c>
 
@@ -174,14 +175,29 @@ via_padlock_crypto_newsession(void *arg,
 	for (c = cri; c != NULL; c = c->cri_next) {
 		switch (c->cri_alg) {
 		case CRYPTO_AES_CBC:
+			memset(ses->ses_ekey, 0, sizeof(ses->ses_ekey));
+			memset(ses->ses_dkey, 0, sizeof(ses->ses_dkey));
+
 			switch (c->cri_klen) {
 			case 128:
+				br_aes_ct_keysched_stdenc(ses->ses_ekey,
+				    c->cri_key, 16);
+				br_aes_ct_keysched_stddec(ses->ses_dkey,
+				    c->cri_key, 16);
 				cw0 = C3_CRYPT_CWLO_KEY128;
 				break;
 			case 192:
+				br_aes_ct_keysched_stdenc(ses->ses_ekey,
+				    c->cri_key, 24);
+				br_aes_ct_keysched_stddec(ses->ses_dkey,
+				    c->cri_key, 24);
 				cw0 = C3_CRYPT_CWLO_KEY192;
 				break;
 			case 256:
+				br_aes_ct_keysched_stdenc(ses->ses_ekey,
+				    c->cri_key, 32);
+				br_aes_ct_keysched_stddec(ses->ses_dkey,
+				    c->cri_key, 32);
 				cw0 = C3_CRYPT_CWLO_KEY256;
 				break;
 			default:
@@ -194,16 +210,11 @@ via_padlock_crypto_newsession(void *arg,
 			ses->ses_klen = c->cri_klen;
 			ses->ses_cw0 = cw0;
 
-			/* Build expanded keys for both directions */
-			rijndaelKeySetupEnc(ses->ses_ekey, c->cri_key,
-			    c->cri_klen);
-			rijndaelKeySetupDec(ses->ses_dkey, c->cri_key,
-			    c->cri_klen);
-			for (i = 0; i < 4 * (RIJNDAEL_MAXNR + 1); i++) {
+			/* Convert words to host byte order (???) */
+			for (i = 0; i < 4*(AES_256_NROUNDS + 1); i++) {
 				ses->ses_ekey[i] = ntohl(ses->ses_ekey[i]);
 				ses->ses_dkey[i] = ntohl(ses->ses_dkey[i]);
 			}
-
 			break;
 
 		/* Use hashing implementations from the cryptosoft code. */

Reply via email to