update master-with-bazel from master branch
This commit is contained in:
@@ -173,15 +173,13 @@ static size_t hw_gcm_decrypt(const uint8_t *in, uint8_t *out, size_t len,
|
||||
#endif // HW_GCM && AARCH64
|
||||
|
||||
void CRYPTO_ghash_init(gmult_func *out_mult, ghash_func *out_hash,
|
||||
u128 *out_key, u128 out_table[16], int *out_is_avx,
|
||||
u128 out_table[16], int *out_is_avx,
|
||||
const uint8_t gcm_key[16]) {
|
||||
*out_is_avx = 0;
|
||||
|
||||
// H is stored in host byte order.
|
||||
uint64_t H[2] = {CRYPTO_load_u64_be(gcm_key),
|
||||
CRYPTO_load_u64_be(gcm_key + 8)};
|
||||
out_key->hi = H[0];
|
||||
out_key->lo = H[1];
|
||||
|
||||
#if defined(GHASH_ASM_X86_64)
|
||||
if (crypto_gcm_clmul_enabled()) {
|
||||
@@ -247,14 +245,13 @@ void CRYPTO_gcm128_init_key(GCM128_KEY *gcm_key, const AES_KEY *aes_key,
|
||||
(*block)(ghash_key, ghash_key, aes_key);
|
||||
|
||||
int is_avx;
|
||||
CRYPTO_ghash_init(&gcm_key->gmult, &gcm_key->ghash, &gcm_key->H,
|
||||
gcm_key->Htable, &is_avx, ghash_key);
|
||||
CRYPTO_ghash_init(&gcm_key->gmult, &gcm_key->ghash, gcm_key->Htable, &is_avx,
|
||||
ghash_key);
|
||||
|
||||
#if defined(OPENSSL_AARCH64) && !defined(OPENSSL_NO_ASM)
|
||||
gcm_key->use_hw_gcm_crypt = (gcm_pmull_capable() && block_is_hwaes) ? 1 :
|
||||
0;
|
||||
gcm_key->use_hw_gcm_crypt = (gcm_pmull_capable() && block_is_hwaes) ? 1 : 0;
|
||||
#else
|
||||
gcm_key->use_hw_gcm_crypt = (is_avx && block_is_hwaes) ? 1 : 0;
|
||||
gcm_key->use_hw_gcm_crypt = (is_avx && block_is_hwaes) ? 1 : 0;
|
||||
#endif
|
||||
}
|
||||
|
||||
|
||||
@@ -124,12 +124,10 @@ typedef void (*ghash_func)(uint64_t Xi[2], const u128 Htable[16],
|
||||
const uint8_t *inp, size_t len);
|
||||
|
||||
typedef struct gcm128_key_st {
|
||||
// Note the MOVBE-based, x86-64, GHASH assembly requires |H| and |Htable| to
|
||||
// be the first two elements of this struct. Additionally, some assembly
|
||||
// routines require a 16-byte-aligned |Htable| when hashing data, but not
|
||||
// |gcm_*_ssse3| require a 16-byte-aligned |Htable| when hashing data, but not
|
||||
// initialization. |GCM128_KEY| is not itself aligned to simplify embedding in
|
||||
// |EVP_AEAD_CTX|, but |Htable|'s offset must be a multiple of 16.
|
||||
u128 H;
|
||||
// TODO(crbug.com/boringssl/604): Revisit this.
|
||||
u128 Htable[16];
|
||||
gmult_func gmult;
|
||||
ghash_func ghash;
|
||||
@@ -152,10 +150,8 @@ typedef struct {
|
||||
crypto_word_t t[16 / sizeof(crypto_word_t)];
|
||||
} Yi, EKi, EK0, len, Xi;
|
||||
|
||||
// Note that the order of |Xi| and |gcm_key| is fixed by the MOVBE-based,
|
||||
// x86-64, GHASH assembly. Additionally, some assembly routines require
|
||||
// |gcm_key| to be 16-byte aligned. |GCM128_KEY| is not itself aligned to
|
||||
// simplify embedding in |EVP_AEAD_CTX|.
|
||||
// |gcm_*_ssse3| require |Htable| to be 16-byte-aligned.
|
||||
// TODO(crbug.com/boringssl/604): Revisit this.
|
||||
alignas(16) GCM128_KEY gcm_key;
|
||||
|
||||
unsigned mres, ares;
|
||||
@@ -172,7 +168,7 @@ int crypto_gcm_clmul_enabled(void);
|
||||
// accelerated) functions for performing operations in the GHASH field. If the
|
||||
// AVX implementation was used |*out_is_avx| will be true.
|
||||
void CRYPTO_ghash_init(gmult_func *out_mult, ghash_func *out_hash,
|
||||
u128 *out_key, u128 out_table[16], int *out_is_avx,
|
||||
u128 out_table[16], int *out_is_avx,
|
||||
const uint8_t gcm_key[16]);
|
||||
|
||||
// CRYPTO_gcm128_init_key initialises |gcm_key| to use |block| (typically AES)
|
||||
@@ -392,11 +388,9 @@ typedef union {
|
||||
} polyval_block;
|
||||
|
||||
struct polyval_ctx {
|
||||
// Note that the order of |S|, |H| and |Htable| is fixed by the MOVBE-based,
|
||||
// x86-64, GHASH assembly. Additionally, some assembly routines require
|
||||
// |Htable| to be 16-byte aligned.
|
||||
polyval_block S;
|
||||
u128 H;
|
||||
// |gcm_*_ssse3| require |Htable| to be 16-byte-aligned.
|
||||
// TODO(crbug.com/boringssl/604): Revisit this.
|
||||
alignas(16) u128 Htable[16];
|
||||
gmult_func gmult;
|
||||
ghash_func ghash;
|
||||
|
||||
@@ -56,8 +56,7 @@ void CRYPTO_POLYVAL_init(struct polyval_ctx *ctx, const uint8_t key[16]) {
|
||||
reverse_and_mulX_ghash(&H);
|
||||
|
||||
int is_avx;
|
||||
CRYPTO_ghash_init(&ctx->gmult, &ctx->ghash, &ctx->H, ctx->Htable, &is_avx,
|
||||
H.c);
|
||||
CRYPTO_ghash_init(&ctx->gmult, &ctx->ghash, ctx->Htable, &is_avx, H.c);
|
||||
OPENSSL_memset(&ctx->S, 0, sizeof(ctx->S));
|
||||
}
|
||||
|
||||
|
||||
@@ -210,7 +210,7 @@ OPENSSL_EXPORT size_t EVP_AEAD_max_tag_len(const EVP_AEAD *aead);
|
||||
// AEAD operations.
|
||||
|
||||
union evp_aead_ctx_st_state {
|
||||
uint8_t opaque[580];
|
||||
uint8_t opaque[564];
|
||||
uint64_t alignment;
|
||||
};
|
||||
|
||||
|
||||
Reference in New Issue
Block a user