1 /*
   2  * CDDL HEADER START
   3  *
   4  * The contents of this file are subject to the terms of the
   5  * Common Development and Distribution License (the "License").
   6  * You may not use this file except in compliance with the License.
   7  *
   8  * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
   9  * or http://opensource.org/licenses/CDDL-1.0.
  10  * See the License for the specific language governing permissions
  11  * and limitations under the License.
  12  *
  13  * When distributing Covered Code, include this CDDL HEADER in each
  14  * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
  15  * If applicable, add the following below this CDDL HEADER, with the
  16  * fields enclosed by brackets "[]" replaced with your own identifying
  17  * information: Portions Copyright [yyyy] [name of copyright owner]
  18  *
  19  * CDDL HEADER END
  20  */
  21 /*
  22  * Copyright 2013 Saso Kiselkov.  All rights reserved.
  23  * Use is subject to license terms.
  24  */
  25 #include <sys/zfs_context.h>
  26 #include <sys/zio.h>
  27 #include <sys/edonr.h>
  28 
  29 #define EDONR_MODE              512
  30 #define EDONR_BLOCK_SIZE        EdonR512_BLOCK_SIZE
  31 
  32 /*
  33  * Native zio_checksum interface for the Edon-R hash function.
  34  */
  35 /*ARGSUSED*/
  36 void
  37 zio_checksum_edonr_native(const void *buf, uint64_t size,
  38     const zio_cksum_salt_t *salt, const void *ctx_template, zio_cksum_t *zcp)
  39 {
  40         uint8_t         digest[EDONR_MODE / 8];
  41         EdonRState      ctx;
  42 
  43         ASSERT(ctx_template != NULL);
  44         bcopy(ctx_template, &ctx, sizeof (ctx));
  45         EdonRUpdate(&ctx, buf, size * 8);
  46         EdonRFinal(&ctx, digest);
  47         bcopy(digest, zcp->zc_word, sizeof (zcp->zc_word));
  48 }
  49 
  50 /*
  51  * Byteswapped zio_checksum interface for the Edon-R hash function.
  52  */
  53 void
  54 zio_checksum_edonr_byteswap(const void *buf, uint64_t size,
  55     const zio_cksum_salt_t *salt, const void *ctx_template, zio_cksum_t *zcp)
  56 {
  57         zio_cksum_t     tmp;
  58 
  59         zio_checksum_edonr_native(buf, size, salt, ctx_template, &tmp);
  60         zcp->zc_word[0] = BSWAP_64(zcp->zc_word[0]);
  61         zcp->zc_word[1] = BSWAP_64(zcp->zc_word[1]);
  62         zcp->zc_word[2] = BSWAP_64(zcp->zc_word[2]);
  63         zcp->zc_word[3] = BSWAP_64(zcp->zc_word[3]);
  64 }
  65 
  66 void *
  67 zio_checksum_edonr_tmpl_init(const zio_cksum_salt_t *salt)
  68 {
  69         EdonRState      *ctx;
  70         uint8_t         salt_block[EDONR_BLOCK_SIZE];
  71 
  72         /*
  73          * Edon-R needs all but the last hash invocation to be on full-size
  74          * blocks, but the salt is too small. Rather than simply padding it
  75          * with zeros, we expand the salt into a new salt block of proper
  76          * size by double-hashing it (the new salt block will be composed of
  77          * H(salt) || H(H(salt))).
  78          */
  79         CTASSERT(EDONR_BLOCK_SIZE == 2 * (EDONR_MODE / 8));
  80         EdonRHash(EDONR_MODE, salt->zcs_bytes, sizeof (salt->zcs_bytes) * 8,
  81             salt_block);
  82         EdonRHash(EDONR_MODE, salt_block, EDONR_MODE, salt_block +
  83             EDONR_MODE / 8);
  84 
  85         /*
  86          * Feed the new salt block into the hash function - this will serve
  87          * as our MAC key.
  88          */
  89         ctx = kmem_zalloc(sizeof (*ctx), KM_SLEEP);
  90         EdonRInit(ctx, EDONR_MODE);
  91         EdonRUpdate(ctx, salt_block, sizeof (salt_block) * 8);
  92         return (ctx);
  93 }
  94 
  95 void
  96 zio_checksum_edonr_tmpl_free(void *ctx_template)
  97 {
  98         EdonRState      *ctx = ctx_template;
  99 
 100         bzero(ctx, sizeof (*ctx));
 101         kmem_free(ctx, sizeof (*ctx));
 102 }