crypto/mvsam: support AES ECB
[dpdk.git] / drivers / crypto / mvsam / rte_mrvl_pmd.c
1 /* SPDX-License-Identifier: BSD-3-Clause
2  * Copyright(c) 2017 Marvell International Ltd.
3  * Copyright(c) 2017 Semihalf.
4  * All rights reserved.
5  */
6
7 #include <rte_common.h>
8 #include <rte_hexdump.h>
9 #include <rte_cryptodev.h>
10 #include <rte_cryptodev_pmd.h>
11 #include <rte_bus_vdev.h>
12 #include <rte_malloc.h>
13 #include <rte_cpuflags.h>
14 #include <rte_kvargs.h>
15
16 #include "rte_mrvl_pmd_private.h"
17
18 #define MRVL_MUSDK_DMA_MEMSIZE 41943040
19
20 #define MRVL_PMD_MAX_NB_SESS_ARG                ("max_nb_sessions")
21 #define MRVL_PMD_DEFAULT_MAX_NB_SESSIONS        2048
22
23 static uint8_t cryptodev_driver_id;
24
25 struct mrvl_pmd_init_params {
26         struct rte_cryptodev_pmd_init_params common;
27         uint32_t max_nb_sessions;
28 };
29
30 const char *mrvl_pmd_valid_params[] = {
31         RTE_CRYPTODEV_PMD_NAME_ARG,
32         RTE_CRYPTODEV_PMD_MAX_NB_QP_ARG,
33         RTE_CRYPTODEV_PMD_SOCKET_ID_ARG,
34         MRVL_PMD_MAX_NB_SESS_ARG
35 };
36
37 /**
38  * Flag if particular crypto algorithm is supported by PMD/MUSDK.
39  *
40  * The idea is to have Not Supported value as default (0).
41  * This way we need only to define proper map sizes,
42  * non-initialized entries will be by default not supported.
43  */
44 enum algo_supported {
45         ALGO_NOT_SUPPORTED = 0,
46         ALGO_SUPPORTED = 1,
47 };
48
49 /** Map elements for cipher mapping.*/
50 struct cipher_params_mapping {
51         enum algo_supported  supported;   /**< On/Off switch */
52         enum sam_cipher_alg  cipher_alg;  /**< Cipher algorithm */
53         enum sam_cipher_mode cipher_mode; /**< Cipher mode */
54         unsigned int max_key_len;         /**< Maximum key length (in bytes)*/
55 }
56 /* We want to squeeze in multiple maps into the cache line. */
57 __rte_aligned(32);
58
59 /** Map elements for auth mapping.*/
60 struct auth_params_mapping {
61         enum algo_supported supported;  /**< On/off switch */
62         enum sam_auth_alg   auth_alg;   /**< Auth algorithm */
63 }
64 /* We want to squeeze in multiple maps into the cache line. */
65 __rte_aligned(32);
66
67 /**
68  * Map of supported cipher algorithms.
69  */
70 static const
71 struct cipher_params_mapping cipher_map[RTE_CRYPTO_CIPHER_LIST_END] = {
72         [RTE_CRYPTO_CIPHER_3DES_CBC] = {
73                 .supported = ALGO_SUPPORTED,
74                 .cipher_alg = SAM_CIPHER_3DES,
75                 .cipher_mode = SAM_CIPHER_CBC,
76                 .max_key_len = BITS2BYTES(192) },
77         [RTE_CRYPTO_CIPHER_3DES_CTR] = {
78                 .supported = ALGO_SUPPORTED,
79                 .cipher_alg = SAM_CIPHER_3DES,
80                 .cipher_mode = SAM_CIPHER_CTR,
81                 .max_key_len = BITS2BYTES(192) },
82         [RTE_CRYPTO_CIPHER_3DES_ECB] = {
83                 .supported = ALGO_SUPPORTED,
84                 .cipher_alg = SAM_CIPHER_3DES,
85                 .cipher_mode = SAM_CIPHER_ECB,
86                 .max_key_len = BITS2BYTES(192) },
87         [RTE_CRYPTO_CIPHER_AES_CBC] = {
88                 .supported = ALGO_SUPPORTED,
89                 .cipher_alg = SAM_CIPHER_AES,
90                 .cipher_mode = SAM_CIPHER_CBC,
91                 .max_key_len = BITS2BYTES(256) },
92         [RTE_CRYPTO_CIPHER_AES_CTR] = {
93                 .supported = ALGO_SUPPORTED,
94                 .cipher_alg = SAM_CIPHER_AES,
95                 .cipher_mode = SAM_CIPHER_CTR,
96                 .max_key_len = BITS2BYTES(256) },
97         [RTE_CRYPTO_CIPHER_AES_ECB] = {
98                 .supported = ALGO_SUPPORTED,
99                 .cipher_alg = SAM_CIPHER_AES,
100                 .cipher_mode = SAM_CIPHER_ECB,
101                 .max_key_len = BITS2BYTES(256) },
102 };
103
104 /**
105  * Map of supported auth algorithms.
106  */
107 static const
108 struct auth_params_mapping auth_map[RTE_CRYPTO_AUTH_LIST_END] = {
109         [RTE_CRYPTO_AUTH_MD5_HMAC] = {
110                 .supported = ALGO_SUPPORTED,
111                 .auth_alg = SAM_AUTH_HMAC_MD5 },
112         [RTE_CRYPTO_AUTH_MD5] = {
113                 .supported = ALGO_SUPPORTED,
114                 .auth_alg = SAM_AUTH_HASH_MD5 },
115         [RTE_CRYPTO_AUTH_SHA1_HMAC] = {
116                 .supported = ALGO_SUPPORTED,
117                 .auth_alg = SAM_AUTH_HMAC_SHA1 },
118         [RTE_CRYPTO_AUTH_SHA1] = {
119                 .supported = ALGO_SUPPORTED,
120                 .auth_alg = SAM_AUTH_HASH_SHA1 },
121         [RTE_CRYPTO_AUTH_SHA224_HMAC] = {
122                 .supported = ALGO_SUPPORTED,
123                 .auth_alg = SAM_AUTH_HMAC_SHA2_224 },
124         [RTE_CRYPTO_AUTH_SHA224] = {
125                 .supported = ALGO_SUPPORTED,
126                 .auth_alg = SAM_AUTH_HASH_SHA2_224 },
127         [RTE_CRYPTO_AUTH_SHA256_HMAC] = {
128                 .supported = ALGO_SUPPORTED,
129                 .auth_alg = SAM_AUTH_HMAC_SHA2_256 },
130         [RTE_CRYPTO_AUTH_SHA256] = {
131                 .supported = ALGO_SUPPORTED,
132                 .auth_alg = SAM_AUTH_HASH_SHA2_256 },
133         [RTE_CRYPTO_AUTH_SHA384_HMAC] = {
134                 .supported = ALGO_SUPPORTED,
135                 .auth_alg = SAM_AUTH_HMAC_SHA2_384 },
136         [RTE_CRYPTO_AUTH_SHA384] = {
137                 .supported = ALGO_SUPPORTED,
138                 .auth_alg = SAM_AUTH_HASH_SHA2_384 },
139         [RTE_CRYPTO_AUTH_SHA512_HMAC] = {
140                 .supported = ALGO_SUPPORTED,
141                 .auth_alg = SAM_AUTH_HMAC_SHA2_512 },
142         [RTE_CRYPTO_AUTH_SHA512] = {
143                 .supported = ALGO_SUPPORTED,
144                 .auth_alg = SAM_AUTH_HASH_SHA2_512 },
145         [RTE_CRYPTO_AUTH_AES_GMAC] = {
146                 .supported = ALGO_SUPPORTED,
147                 .auth_alg = SAM_AUTH_AES_GMAC },
148 };
149
150 /**
151  * Map of supported aead algorithms.
152  */
153 static const
154 struct cipher_params_mapping aead_map[RTE_CRYPTO_AEAD_LIST_END] = {
155         [RTE_CRYPTO_AEAD_AES_GCM] = {
156                 .supported = ALGO_SUPPORTED,
157                 .cipher_alg = SAM_CIPHER_AES,
158                 .cipher_mode = SAM_CIPHER_GCM,
159                 .max_key_len = BITS2BYTES(256) },
160 };
161
162 /*
163  *-----------------------------------------------------------------------------
164  * Forward declarations.
165  *-----------------------------------------------------------------------------
166  */
167 static int cryptodev_mrvl_crypto_uninit(struct rte_vdev_device *vdev);
168
169 /*
170  *-----------------------------------------------------------------------------
171  * Session Preparation.
172  *-----------------------------------------------------------------------------
173  */
174
175 /**
176  * Get xform chain order.
177  *
178  * @param xform Pointer to configuration structure chain for crypto operations.
179  * @returns Order of crypto operations.
180  */
181 static enum mrvl_crypto_chain_order
182 mrvl_crypto_get_chain_order(const struct rte_crypto_sym_xform *xform)
183 {
184         /* Currently, Marvell supports max 2 operations in chain */
185         if (xform->next != NULL && xform->next->next != NULL)
186                 return MRVL_CRYPTO_CHAIN_NOT_SUPPORTED;
187
188         if (xform->next != NULL) {
189                 if ((xform->type == RTE_CRYPTO_SYM_XFORM_AUTH) &&
190                         (xform->next->type == RTE_CRYPTO_SYM_XFORM_CIPHER))
191                         return MRVL_CRYPTO_CHAIN_AUTH_CIPHER;
192
193                 if ((xform->type == RTE_CRYPTO_SYM_XFORM_CIPHER) &&
194                         (xform->next->type == RTE_CRYPTO_SYM_XFORM_AUTH))
195                         return MRVL_CRYPTO_CHAIN_CIPHER_AUTH;
196         } else {
197                 if (xform->type == RTE_CRYPTO_SYM_XFORM_AUTH)
198                         return MRVL_CRYPTO_CHAIN_AUTH_ONLY;
199
200                 if (xform->type == RTE_CRYPTO_SYM_XFORM_CIPHER)
201                         return MRVL_CRYPTO_CHAIN_CIPHER_ONLY;
202
203                 if (xform->type == RTE_CRYPTO_SYM_XFORM_AEAD)
204                         return MRVL_CRYPTO_CHAIN_COMBINED;
205         }
206         return MRVL_CRYPTO_CHAIN_NOT_SUPPORTED;
207 }
208
209 /**
210  * Set session parameters for cipher part.
211  *
212  * @param sess Crypto session pointer.
213  * @param cipher_xform Pointer to configuration structure for cipher operations.
214  * @returns 0 in case of success, negative value otherwise.
215  */
216 static int
217 mrvl_crypto_set_cipher_session_parameters(struct mrvl_crypto_session *sess,
218                 const struct rte_crypto_sym_xform *cipher_xform)
219 {
220         /* Make sure we've got proper struct */
221         if (cipher_xform->type != RTE_CRYPTO_SYM_XFORM_CIPHER) {
222                 MRVL_CRYPTO_LOG_ERR("Wrong xform struct provided!");
223                 return -EINVAL;
224         }
225
226         /* See if map data is present and valid */
227         if ((cipher_xform->cipher.algo > RTE_DIM(cipher_map)) ||
228                 (cipher_map[cipher_xform->cipher.algo].supported
229                         != ALGO_SUPPORTED)) {
230                 MRVL_CRYPTO_LOG_ERR("Cipher algorithm not supported!");
231                 return -EINVAL;
232         }
233
234         sess->cipher_iv_offset = cipher_xform->cipher.iv.offset;
235
236         sess->sam_sess_params.dir =
237                 (cipher_xform->cipher.op == RTE_CRYPTO_CIPHER_OP_ENCRYPT) ?
238                 SAM_DIR_ENCRYPT : SAM_DIR_DECRYPT;
239         sess->sam_sess_params.cipher_alg =
240                 cipher_map[cipher_xform->cipher.algo].cipher_alg;
241         sess->sam_sess_params.cipher_mode =
242                 cipher_map[cipher_xform->cipher.algo].cipher_mode;
243
244         /* Assume IV will be passed together with data. */
245         sess->sam_sess_params.cipher_iv = NULL;
246
247         /* Get max key length. */
248         if (cipher_xform->cipher.key.length >
249                 cipher_map[cipher_xform->cipher.algo].max_key_len) {
250                 MRVL_CRYPTO_LOG_ERR("Wrong key length!");
251                 return -EINVAL;
252         }
253
254         sess->sam_sess_params.cipher_key_len = cipher_xform->cipher.key.length;
255         sess->sam_sess_params.cipher_key = cipher_xform->cipher.key.data;
256
257         return 0;
258 }
259
260 /**
261  * Set session parameters for authentication part.
262  *
263  * @param sess Crypto session pointer.
264  * @param auth_xform Pointer to configuration structure for auth operations.
265  * @returns 0 in case of success, negative value otherwise.
266  */
267 static int
268 mrvl_crypto_set_auth_session_parameters(struct mrvl_crypto_session *sess,
269                 const struct rte_crypto_sym_xform *auth_xform)
270 {
271         /* Make sure we've got proper struct */
272         if (auth_xform->type != RTE_CRYPTO_SYM_XFORM_AUTH) {
273                 MRVL_CRYPTO_LOG_ERR("Wrong xform struct provided!");
274                 return -EINVAL;
275         }
276
277         /* See if map data is present and valid */
278         if ((auth_xform->auth.algo > RTE_DIM(auth_map)) ||
279                 (auth_map[auth_xform->auth.algo].supported != ALGO_SUPPORTED)) {
280                 MRVL_CRYPTO_LOG_ERR("Auth algorithm not supported!");
281                 return -EINVAL;
282         }
283
284         sess->sam_sess_params.dir =
285                 (auth_xform->auth.op == RTE_CRYPTO_AUTH_OP_GENERATE) ?
286                 SAM_DIR_ENCRYPT : SAM_DIR_DECRYPT;
287         sess->sam_sess_params.auth_alg =
288                 auth_map[auth_xform->auth.algo].auth_alg;
289         sess->sam_sess_params.u.basic.auth_icv_len =
290                 auth_xform->auth.digest_length;
291         /* auth_key must be NULL if auth algorithm does not use HMAC */
292         sess->sam_sess_params.auth_key = auth_xform->auth.key.length ?
293                                          auth_xform->auth.key.data : NULL;
294         sess->sam_sess_params.auth_key_len = auth_xform->auth.key.length;
295
296         return 0;
297 }
298
299 /**
300  * Set session parameters for aead part.
301  *
302  * @param sess Crypto session pointer.
303  * @param aead_xform Pointer to configuration structure for aead operations.
304  * @returns 0 in case of success, negative value otherwise.
305  */
306 static int
307 mrvl_crypto_set_aead_session_parameters(struct mrvl_crypto_session *sess,
308                 const struct rte_crypto_sym_xform *aead_xform)
309 {
310         /* Make sure we've got proper struct */
311         if (aead_xform->type != RTE_CRYPTO_SYM_XFORM_AEAD) {
312                 MRVL_CRYPTO_LOG_ERR("Wrong xform struct provided!");
313                 return -EINVAL;
314         }
315
316         /* See if map data is present and valid */
317         if ((aead_xform->aead.algo > RTE_DIM(aead_map)) ||
318                 (aead_map[aead_xform->aead.algo].supported
319                         != ALGO_SUPPORTED)) {
320                 MRVL_CRYPTO_LOG_ERR("AEAD algorithm not supported!");
321                 return -EINVAL;
322         }
323
324         sess->sam_sess_params.dir =
325                 (aead_xform->aead.op == RTE_CRYPTO_AEAD_OP_ENCRYPT) ?
326                 SAM_DIR_ENCRYPT : SAM_DIR_DECRYPT;
327         sess->sam_sess_params.cipher_alg =
328                 aead_map[aead_xform->aead.algo].cipher_alg;
329         sess->sam_sess_params.cipher_mode =
330                 aead_map[aead_xform->aead.algo].cipher_mode;
331
332         /* Assume IV will be passed together with data. */
333         sess->sam_sess_params.cipher_iv = NULL;
334
335         /* Get max key length. */
336         if (aead_xform->aead.key.length >
337                 aead_map[aead_xform->aead.algo].max_key_len) {
338                 MRVL_CRYPTO_LOG_ERR("Wrong key length!");
339                 return -EINVAL;
340         }
341
342         sess->sam_sess_params.cipher_key = aead_xform->aead.key.data;
343         sess->sam_sess_params.cipher_key_len = aead_xform->aead.key.length;
344
345         if (sess->sam_sess_params.cipher_mode == SAM_CIPHER_GCM)
346                 sess->sam_sess_params.auth_alg = SAM_AUTH_AES_GCM;
347
348         sess->sam_sess_params.u.basic.auth_icv_len =
349                 aead_xform->aead.digest_length;
350
351         sess->sam_sess_params.u.basic.auth_aad_len =
352                 aead_xform->aead.aad_length;
353
354         return 0;
355 }
356
357 /**
358  * Parse crypto transform chain and setup session parameters.
359  *
360  * @param dev Pointer to crypto device
361  * @param sess Poiner to crypto session
362  * @param xform Pointer to configuration structure chain for crypto operations.
363  * @returns 0 in case of success, negative value otherwise.
364  */
365 int
366 mrvl_crypto_set_session_parameters(struct mrvl_crypto_session *sess,
367                 const struct rte_crypto_sym_xform *xform)
368 {
369         const struct rte_crypto_sym_xform *cipher_xform = NULL;
370         const struct rte_crypto_sym_xform *auth_xform = NULL;
371         const struct rte_crypto_sym_xform *aead_xform = NULL;
372
373         /* Filter out spurious/broken requests */
374         if (xform == NULL)
375                 return -EINVAL;
376
377         sess->chain_order = mrvl_crypto_get_chain_order(xform);
378         switch (sess->chain_order) {
379         case MRVL_CRYPTO_CHAIN_CIPHER_AUTH:
380                 cipher_xform = xform;
381                 auth_xform = xform->next;
382                 break;
383         case MRVL_CRYPTO_CHAIN_AUTH_CIPHER:
384                 auth_xform = xform;
385                 cipher_xform = xform->next;
386                 break;
387         case MRVL_CRYPTO_CHAIN_CIPHER_ONLY:
388                 cipher_xform = xform;
389                 break;
390         case MRVL_CRYPTO_CHAIN_AUTH_ONLY:
391                 auth_xform = xform;
392                 break;
393         case MRVL_CRYPTO_CHAIN_COMBINED:
394                 aead_xform = xform;
395                 break;
396         default:
397                 return -EINVAL;
398         }
399
400         if ((cipher_xform != NULL) &&
401                 (mrvl_crypto_set_cipher_session_parameters(
402                         sess, cipher_xform) < 0)) {
403                 MRVL_CRYPTO_LOG_ERR("Invalid/unsupported cipher parameters");
404                 return -EINVAL;
405         }
406
407         if ((auth_xform != NULL) &&
408                 (mrvl_crypto_set_auth_session_parameters(
409                         sess, auth_xform) < 0)) {
410                 MRVL_CRYPTO_LOG_ERR("Invalid/unsupported auth parameters");
411                 return -EINVAL;
412         }
413
414         if ((aead_xform != NULL) &&
415                 (mrvl_crypto_set_aead_session_parameters(
416                         sess, aead_xform) < 0)) {
417                 MRVL_CRYPTO_LOG_ERR("Invalid/unsupported aead parameters");
418                 return -EINVAL;
419         }
420
421         return 0;
422 }
423
424 /*
425  *-----------------------------------------------------------------------------
426  * Process Operations
427  *-----------------------------------------------------------------------------
428  */
429
430 /**
431  * Prepare a single request.
432  *
433  * This function basically translates DPDK crypto request into one
434  * understandable by MUDSK's SAM. If this is a first request in a session,
435  * it starts the session.
436  *
437  * @param request Pointer to pre-allocated && reset request buffer [Out].
438  * @param src_bd Pointer to pre-allocated source descriptor [Out].
439  * @param dst_bd Pointer to pre-allocated destination descriptor [Out].
440  * @param op Pointer to DPDK crypto operation struct [In].
441  */
442 static inline int
443 mrvl_request_prepare(struct sam_cio_op_params *request,
444                 struct sam_buf_info *src_bd,
445                 struct sam_buf_info *dst_bd,
446                 struct rte_crypto_op *op)
447 {
448         struct mrvl_crypto_session *sess;
449         struct rte_mbuf *dst_mbuf;
450         uint8_t *digest;
451
452         if (unlikely(op->sess_type == RTE_CRYPTO_OP_SESSIONLESS)) {
453                 MRVL_CRYPTO_LOG_ERR("MRVL CRYPTO PMD only supports session "
454                                 "oriented requests, op (%p) is sessionless.",
455                                 op);
456                 return -EINVAL;
457         }
458
459         sess = (struct mrvl_crypto_session *)get_sym_session_private_data(
460                         op->sym->session, cryptodev_driver_id);
461         if (unlikely(sess == NULL)) {
462                 MRVL_CRYPTO_LOG_ERR("Session was not created for this device");
463                 return -EINVAL;
464         }
465
466         /*
467          * If application delivered us null dst buffer, it means it expects
468          * us to deliver the result in src buffer.
469          */
470         dst_mbuf = op->sym->m_dst ? op->sym->m_dst : op->sym->m_src;
471
472         request->sa = sess->sam_sess;
473         request->cookie = op;
474
475         /* Single buffers only, sorry. */
476         request->num_bufs = 1;
477         request->src = src_bd;
478         src_bd->vaddr = rte_pktmbuf_mtod(op->sym->m_src, void *);
479         src_bd->paddr = rte_pktmbuf_iova(op->sym->m_src);
480         src_bd->len = rte_pktmbuf_data_len(op->sym->m_src);
481
482         /* Empty source. */
483         if (rte_pktmbuf_data_len(op->sym->m_src) == 0) {
484                 /* EIP does not support 0 length buffers. */
485                 MRVL_CRYPTO_LOG_ERR("Buffer length == 0 not supported!");
486                 return -1;
487         }
488
489         /* Empty destination. */
490         if (rte_pktmbuf_data_len(dst_mbuf) == 0) {
491                 /* Make dst buffer fit at least source data. */
492                 if (rte_pktmbuf_append(dst_mbuf,
493                         rte_pktmbuf_data_len(op->sym->m_src)) == NULL) {
494                         MRVL_CRYPTO_LOG_ERR("Unable to set big enough dst buffer!");
495                         return -1;
496                 }
497         }
498
499         request->dst = dst_bd;
500         dst_bd->vaddr = rte_pktmbuf_mtod(dst_mbuf, void *);
501         dst_bd->paddr = rte_pktmbuf_iova(dst_mbuf);
502
503         /*
504          * We can use all available space in dst_mbuf,
505          * not only what's used currently.
506          */
507         dst_bd->len = dst_mbuf->buf_len - rte_pktmbuf_headroom(dst_mbuf);
508
509         if (sess->chain_order == MRVL_CRYPTO_CHAIN_COMBINED) {
510                 request->cipher_len = op->sym->aead.data.length;
511                 request->cipher_offset = op->sym->aead.data.offset;
512                 request->cipher_iv = rte_crypto_op_ctod_offset(op, uint8_t *,
513                         sess->cipher_iv_offset);
514
515                 request->auth_aad = op->sym->aead.aad.data;
516                 request->auth_offset = request->cipher_offset;
517                 request->auth_len = request->cipher_len;
518         } else {
519                 request->cipher_len = op->sym->cipher.data.length;
520                 request->cipher_offset = op->sym->cipher.data.offset;
521                 request->cipher_iv = rte_crypto_op_ctod_offset(op, uint8_t *,
522                                 sess->cipher_iv_offset);
523
524                 request->auth_offset = op->sym->auth.data.offset;
525                 request->auth_len = op->sym->auth.data.length;
526         }
527
528         digest = sess->chain_order == MRVL_CRYPTO_CHAIN_COMBINED ?
529                 op->sym->aead.digest.data : op->sym->auth.digest.data;
530         if (digest == NULL) {
531                 /* No auth - no worry. */
532                 return 0;
533         }
534
535         request->auth_icv_offset = request->auth_offset + request->auth_len;
536
537         /*
538          * EIP supports only scenarios where ICV(digest buffer) is placed at
539          * auth_icv_offset. Any other placement means risking errors.
540          */
541         if (sess->sam_sess_params.dir == SAM_DIR_ENCRYPT) {
542                 /*
543                  * This should be the most common case anyway,
544                  * EIP will overwrite DST buffer at auth_icv_offset.
545                  */
546                 if (rte_pktmbuf_mtod_offset(
547                                 dst_mbuf, uint8_t *,
548                                 request->auth_icv_offset) == digest) {
549                         return 0;
550                 }
551         } else {/* sess->sam_sess_params.dir == SAM_DIR_DECRYPT */
552                 /*
553                  * EIP will look for digest at auth_icv_offset
554                  * offset in SRC buffer.
555                  */
556                 if (rte_pktmbuf_mtod_offset(
557                                 op->sym->m_src, uint8_t *,
558                                 request->auth_icv_offset) == digest) {
559                         return 0;
560                 }
561         }
562
563         /*
564          * If we landed here it means that digest pointer is
565          * at different than expected place.
566          */
567         return -1;
568 }
569
570 /*
571  *-----------------------------------------------------------------------------
572  * PMD Framework handlers
573  *-----------------------------------------------------------------------------
574  */
575
576 /**
577  * Enqueue burst.
578  *
579  * @param queue_pair Pointer to queue pair.
580  * @param ops Pointer to ops requests array.
581  * @param nb_ops Number of elements in ops requests array.
582  * @returns Number of elements consumed from ops.
583  */
584 static uint16_t
585 mrvl_crypto_pmd_enqueue_burst(void *queue_pair, struct rte_crypto_op **ops,
586                 uint16_t nb_ops)
587 {
588         uint16_t iter_ops = 0;
589         uint16_t to_enq = 0;
590         uint16_t consumed = 0;
591         int ret;
592         struct sam_cio_op_params requests[nb_ops];
593         /*
594          * DPDK uses single fragment buffers, so we can KISS descriptors.
595          * SAM does not store bd pointers, so on-stack scope will be enough.
596          */
597         struct sam_buf_info src_bd[nb_ops];
598         struct sam_buf_info dst_bd[nb_ops];
599         struct mrvl_crypto_qp *qp = (struct mrvl_crypto_qp *)queue_pair;
600
601         if (nb_ops == 0)
602                 return 0;
603
604         /* Prepare the burst. */
605         memset(&requests, 0, sizeof(requests));
606
607         /* Iterate through */
608         for (; iter_ops < nb_ops; ++iter_ops) {
609                 if (mrvl_request_prepare(&requests[iter_ops],
610                                         &src_bd[iter_ops],
611                                         &dst_bd[iter_ops],
612                                         ops[iter_ops]) < 0) {
613                         MRVL_CRYPTO_LOG_ERR(
614                                 "Error while parameters preparation!");
615                         qp->stats.enqueue_err_count++;
616                         ops[iter_ops]->status = RTE_CRYPTO_OP_STATUS_ERROR;
617
618                         /*
619                          * Number of handled ops is increased
620                          * (even if the result of handling is error).
621                          */
622                         ++consumed;
623                         break;
624                 }
625
626                 ops[iter_ops]->status =
627                         RTE_CRYPTO_OP_STATUS_NOT_PROCESSED;
628
629                 /* Increase the number of ops to enqueue. */
630                 ++to_enq;
631         } /* for (; iter_ops < nb_ops;... */
632
633         if (to_enq > 0) {
634                 /* Send the burst */
635                 ret = sam_cio_enq(qp->cio, requests, &to_enq);
636                 consumed += to_enq;
637                 if (ret < 0) {
638                         /*
639                          * Trust SAM that in this case returned value will be at
640                          * some point correct (now it is returned unmodified).
641                          */
642                         qp->stats.enqueue_err_count += to_enq;
643                         for (iter_ops = 0; iter_ops < to_enq; ++iter_ops)
644                                 ops[iter_ops]->status =
645                                         RTE_CRYPTO_OP_STATUS_ERROR;
646                 }
647         }
648
649         qp->stats.enqueued_count += to_enq;
650         return consumed;
651 }
652
653 /**
654  * Dequeue burst.
655  *
656  * @param queue_pair Pointer to queue pair.
657  * @param ops Pointer to ops requests array.
658  * @param nb_ops Number of elements in ops requests array.
659  * @returns Number of elements dequeued.
660  */
661 static uint16_t
662 mrvl_crypto_pmd_dequeue_burst(void *queue_pair,
663                 struct rte_crypto_op **ops,
664                 uint16_t nb_ops)
665 {
666         int ret;
667         struct mrvl_crypto_qp *qp = queue_pair;
668         struct sam_cio *cio = qp->cio;
669         struct sam_cio_op_result results[nb_ops];
670         uint16_t i;
671
672         ret = sam_cio_deq(cio, results, &nb_ops);
673         if (ret < 0) {
674                 /* Count all dequeued as error. */
675                 qp->stats.dequeue_err_count += nb_ops;
676
677                 /* But act as they were dequeued anyway*/
678                 qp->stats.dequeued_count += nb_ops;
679
680                 return 0;
681         }
682
683         /* Unpack and check results. */
684         for (i = 0; i < nb_ops; ++i) {
685                 ops[i] = results[i].cookie;
686
687                 switch (results[i].status) {
688                 case SAM_CIO_OK:
689                         ops[i]->status = RTE_CRYPTO_OP_STATUS_SUCCESS;
690                         break;
691                 case SAM_CIO_ERR_ICV:
692                         MRVL_CRYPTO_LOG_DBG("CIO returned SAM_CIO_ERR_ICV.");
693                         ops[i]->status = RTE_CRYPTO_OP_STATUS_AUTH_FAILED;
694                         break;
695                 default:
696                         MRVL_CRYPTO_LOG_DBG(
697                                 "CIO returned Error: %d", results[i].status);
698                         ops[i]->status = RTE_CRYPTO_OP_STATUS_ERROR;
699                         break;
700                 }
701         }
702
703         qp->stats.dequeued_count += nb_ops;
704         return nb_ops;
705 }
706
707 /**
708  * Create a new crypto device.
709  *
710  * @param name Driver name.
711  * @param vdev Pointer to device structure.
712  * @param init_params Pointer to initialization parameters.
713  * @returns 0 in case of success, negative value otherwise.
714  */
715 static int
716 cryptodev_mrvl_crypto_create(const char *name,
717                 struct rte_vdev_device *vdev,
718                 struct mrvl_pmd_init_params *init_params)
719 {
720         struct rte_cryptodev *dev;
721         struct mrvl_crypto_private *internals;
722         struct sam_init_params  sam_params;
723         int ret;
724
725         dev = rte_cryptodev_pmd_create(name, &vdev->device,
726                         &init_params->common);
727         if (dev == NULL) {
728                 MRVL_CRYPTO_LOG_ERR("failed to create cryptodev vdev");
729                 goto init_error;
730         }
731
732         dev->driver_id = cryptodev_driver_id;
733         dev->dev_ops = rte_mrvl_crypto_pmd_ops;
734
735         /* Register rx/tx burst functions for data path. */
736         dev->enqueue_burst = mrvl_crypto_pmd_enqueue_burst;
737         dev->dequeue_burst = mrvl_crypto_pmd_dequeue_burst;
738
739         dev->feature_flags = RTE_CRYPTODEV_FF_SYMMETRIC_CRYPTO |
740                         RTE_CRYPTODEV_FF_SYM_OPERATION_CHAINING |
741                         RTE_CRYPTODEV_FF_HW_ACCELERATED |
742                         RTE_CRYPTODEV_FF_OOP_SGL_IN_LB_OUT |
743                         RTE_CRYPTODEV_FF_OOP_LB_IN_LB_OUT;
744
745         /* Set vector instructions mode supported */
746         internals = dev->data->dev_private;
747
748         internals->max_nb_qpairs = init_params->common.max_nb_queue_pairs;
749         internals->max_nb_sessions = init_params->max_nb_sessions;
750
751         /*
752          * ret == -EEXIST is correct, it means DMA
753          * has been already initialized.
754          */
755         ret = mv_sys_dma_mem_init(MRVL_MUSDK_DMA_MEMSIZE);
756         if (ret < 0) {
757                 if (ret != -EEXIST)
758                         return ret;
759
760                 MRVL_CRYPTO_LOG_INFO(
761                         "DMA memory has been already initialized by a different driver.");
762         }
763
764         sam_params.max_num_sessions = internals->max_nb_sessions;
765
766         return sam_init(&sam_params);
767
768 init_error:
769         MRVL_CRYPTO_LOG_ERR(
770                 "driver %s: %s failed", init_params->common.name, __func__);
771
772         cryptodev_mrvl_crypto_uninit(vdev);
773         return -EFAULT;
774 }
775
776 /** Parse integer from integer argument */
777 static int
778 parse_integer_arg(const char *key __rte_unused,
779                 const char *value, void *extra_args)
780 {
781         int *i = (int *) extra_args;
782
783         *i = atoi(value);
784         if (*i < 0) {
785                 MRVL_CRYPTO_LOG_ERR("Argument has to be positive.\n");
786                 return -EINVAL;
787         }
788
789         return 0;
790 }
791
792 /** Parse name */
793 static int
794 parse_name_arg(const char *key __rte_unused,
795                 const char *value, void *extra_args)
796 {
797         struct rte_cryptodev_pmd_init_params *params = extra_args;
798
799         if (strlen(value) >= RTE_CRYPTODEV_NAME_MAX_LEN - 1) {
800                 MRVL_CRYPTO_LOG_ERR("Invalid name %s, should be less than "
801                                 "%u bytes.\n", value,
802                                 RTE_CRYPTODEV_NAME_MAX_LEN - 1);
803                 return -EINVAL;
804         }
805
806         strncpy(params->name, value, RTE_CRYPTODEV_NAME_MAX_LEN);
807
808         return 0;
809 }
810
811 static int
812 mrvl_pmd_parse_input_args(struct mrvl_pmd_init_params *params,
813                          const char *input_args)
814 {
815         struct rte_kvargs *kvlist = NULL;
816         int ret = 0;
817
818         if (params == NULL)
819                 return -EINVAL;
820
821         if (input_args) {
822                 kvlist = rte_kvargs_parse(input_args,
823                                           mrvl_pmd_valid_params);
824                 if (kvlist == NULL)
825                         return -1;
826
827                 /* Common VDEV parameters */
828                 ret = rte_kvargs_process(kvlist,
829                                          RTE_CRYPTODEV_PMD_MAX_NB_QP_ARG,
830                                          &parse_integer_arg,
831                                          &params->common.max_nb_queue_pairs);
832                 if (ret < 0)
833                         goto free_kvlist;
834
835                 ret = rte_kvargs_process(kvlist,
836                                          RTE_CRYPTODEV_PMD_SOCKET_ID_ARG,
837                                          &parse_integer_arg,
838                                          &params->common.socket_id);
839                 if (ret < 0)
840                         goto free_kvlist;
841
842                 ret = rte_kvargs_process(kvlist,
843                                          RTE_CRYPTODEV_PMD_NAME_ARG,
844                                          &parse_name_arg,
845                                          &params->common);
846                 if (ret < 0)
847                         goto free_kvlist;
848
849                 ret = rte_kvargs_process(kvlist,
850                                          MRVL_PMD_MAX_NB_SESS_ARG,
851                                          &parse_integer_arg,
852                                          params);
853                 if (ret < 0)
854                         goto free_kvlist;
855
856         }
857
858 free_kvlist:
859         rte_kvargs_free(kvlist);
860         return ret;
861 }
862
863 /**
864  * Initialize the crypto device.
865  *
866  * @param vdev Pointer to device structure.
867  * @returns 0 in case of success, negative value otherwise.
868  */
869 static int
870 cryptodev_mrvl_crypto_init(struct rte_vdev_device *vdev)
871 {
872         struct mrvl_pmd_init_params init_params = {
873                 .common = {
874                         .name = "",
875                         .private_data_size =
876                                 sizeof(struct mrvl_crypto_private),
877                         .max_nb_queue_pairs =
878                                 sam_get_num_inst() * sam_get_num_cios(0),
879                         .socket_id = rte_socket_id()
880                 },
881                 .max_nb_sessions = MRVL_PMD_DEFAULT_MAX_NB_SESSIONS
882         };
883
884         const char *name, *args;
885         int ret;
886
887         name = rte_vdev_device_name(vdev);
888         if (name == NULL)
889                 return -EINVAL;
890         args = rte_vdev_device_args(vdev);
891
892         ret = mrvl_pmd_parse_input_args(&init_params, args);
893         if (ret) {
894                 RTE_LOG(ERR, PMD,
895                         "Failed to parse initialisation arguments[%s]\n",
896                         args);
897                 return -EINVAL;
898         }
899
900         return cryptodev_mrvl_crypto_create(name, vdev, &init_params);
901 }
902
903 /**
904  * Uninitialize the crypto device
905  *
906  * @param vdev Pointer to device structure.
907  * @returns 0 in case of success, negative value otherwise.
908  */
909 static int
910 cryptodev_mrvl_crypto_uninit(struct rte_vdev_device *vdev)
911 {
912         struct rte_cryptodev *cryptodev;
913         const char *name = rte_vdev_device_name(vdev);
914
915         if (name == NULL)
916                 return -EINVAL;
917
918         RTE_LOG(INFO, PMD,
919                 "Closing Marvell crypto device %s on numa socket %u\n",
920                 name, rte_socket_id());
921
922         sam_deinit();
923
924         cryptodev = rte_cryptodev_pmd_get_named_dev(name);
925         if (cryptodev == NULL)
926                 return -ENODEV;
927
928         return rte_cryptodev_pmd_destroy(cryptodev);
929 }
930
931 /**
932  * Basic driver handlers for use in the constructor.
933  */
934 static struct rte_vdev_driver cryptodev_mrvl_pmd_drv = {
935         .probe = cryptodev_mrvl_crypto_init,
936         .remove = cryptodev_mrvl_crypto_uninit
937 };
938
939 static struct cryptodev_driver mrvl_crypto_drv;
940
941 /* Register the driver in constructor. */
942 RTE_PMD_REGISTER_VDEV(CRYPTODEV_NAME_MRVL_PMD, cryptodev_mrvl_pmd_drv);
943 RTE_PMD_REGISTER_PARAM_STRING(CRYPTODEV_NAME_MRVL_PMD,
944         "max_nb_queue_pairs=<int> "
945         "max_nb_sessions=<int> "
946         "socket_id=<int>");
947 RTE_PMD_REGISTER_CRYPTO_DRIVER(mrvl_crypto_drv, cryptodev_mrvl_pmd_drv.driver,
948                 cryptodev_driver_id);