From 7fca0e8c613e0c2ac5701588c2e47f22a4ffff55 Mon Sep 17 00:00:00 2001 From: Thomas Cook Date: Mon, 10 Aug 2026 11:31:05 -0400 Subject: [PATCH 01/10] Support for ti am64x hw acceleration based on ti mcu plus sdk. --- wolfcrypt/benchmark/benchmark.c | 22 +- wolfcrypt/src/aes.c | 14 +- wolfcrypt/src/ecc.c | 4 + wolfcrypt/src/port/ti/ti-sa2ul_port.c | 927 ++++++++++++++++++++++ wolfcrypt/src/random.c | 3 + wolfcrypt/src/sha256.c | 4 + wolfcrypt/src/sha512.c | 4 + wolfcrypt/src/wc_port.c | 12 + wolfcrypt/test/test.c | 9 + wolfssl/wolfcrypt/aes.h | 7 + wolfssl/wolfcrypt/port/ti/ti-sa2ul_port.h | 33 + wolfssl/wolfcrypt/settings.h | 14 + wolfssl/wolfcrypt/sha256.h | 7 + wolfssl/wolfcrypt/sha512.h | 7 + wolfssl/wolfcrypt/types.h | 4 +- 15 files changed, 1056 insertions(+), 15 deletions(-) create mode 100644 wolfcrypt/src/port/ti/ti-sa2ul_port.c create mode 100644 wolfssl/wolfcrypt/port/ti/ti-sa2ul_port.h diff --git a/wolfcrypt/benchmark/benchmark.c b/wolfcrypt/benchmark/benchmark.c index b9f3981aeb7..d5eec15fcc8 100644 --- a/wolfcrypt/benchmark/benchmark.c +++ b/wolfcrypt/benchmark/benchmark.c @@ -222,6 +222,10 @@ #endif #endif +#ifdef WOLFSSL_TI_AM64X + #include +#endif + #ifdef WOLFSSL_ASYNC_CRYPT #include #endif @@ -729,6 +733,10 @@ static WC_INLINE void bench_append_memory_info(char* buffer, size_t size, #define fprintf(fp, ...) \ __android_log_print(ANDROID_LOG_DEBUG, "[WOLFCRYPT]", __VA_ARGS__) +#elif defined(TI_MCU_PLUS_SDK) + #include "kernel/nortos/dpl/common/printf.h" + #define printf printf_ + #else #if defined(XMALLOC_USER) || defined(FREESCALE_MQX) /* MQX classic needs for EXIT_FAILURE */ @@ -2592,7 +2600,11 @@ static void benchmark_static_init(int force) bench_pq_asym_algs = 0; bench_other_algs = 0; bench_pq_hash_sig_algs = 0; + #ifdef WOLFSSL_BENCHMARK_FIXED_CSV + csv_format = 1; + #else csv_format = 0; + #endif } } @@ -8877,13 +8889,15 @@ void bench_sha256(int useDeviceID) printf("InitSha256_ex failed, ret = %d\n", ret); goto exit; } - #ifdef WOLFSSL_PIC32MZ_HASH - wc_Sha256SizeSet(hash[i], numBlocks * bench_size); - #endif } bench_stats_start(&count, &start); do { + #ifdef WOLFSSL_PIC32MZ_HASH + for (i = 0; i < BENCH_MAX_PENDING; i++) { + wc_Sha256SizeSet(hash[i], numBlocks * bench_size); + } + #endif for (times = 0; times < numBlocks || pending > 0; ) { bench_async_poll(&pending); @@ -19428,7 +19442,7 @@ int wolfcrypt_benchmark_main(int argc, char** argv) argc--; argv++; } -#endif /* MAIN_NO_ARGS */ +#endif /* !MAIN_NO_ARGS */ #if defined(WOLFSSL_BENCHMARK_FIXED_CSV) /* when defined, we'll always output CSV regardless of params. diff --git a/wolfcrypt/src/aes.c b/wolfcrypt/src/aes.c index f7aa53f9eb1..fbcfc29c5be 100644 --- a/wolfcrypt/src/aes.c +++ b/wolfcrypt/src/aes.c @@ -3572,9 +3572,6 @@ WC_ALL_ARGS_NOT_NULL static WARN_UNUSED_RESULT int wc_AesEncrypt( { #if defined(MAX3266X_AES) word32 keySize; -#endif -#if defined(MAX3266X_CB) - int ret_cb; #endif word32 r; @@ -3716,12 +3713,12 @@ WC_ALL_ARGS_NOT_NULL static WARN_UNUSED_RESULT int wc_AesEncrypt( outBlock, (unsigned int)keySize); } #endif -#if defined(MAX3266X_CB) && defined(HAVE_AES_ECB) /* Can do a basic ECB block */ +#if (defined(WOLFSSL_TI_AM64X) || defined(MAX3266X_CB)) && defined(HAVE_AES_ECB) #ifndef WOLF_CRYPTO_CB_FIND if (aes->devId != INVALID_DEVID) #endif { - ret_cb = wc_CryptoCb_AesEcbEncrypt(aes, outBlock, inBlock, + int ret_cb = wc_CryptoCb_AesEcbEncrypt(aes, outBlock, inBlock, WC_AES_BLOCK_SIZE); if (ret_cb != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE)) return ret_cb; @@ -4448,9 +4445,6 @@ WC_ALL_ARGS_NOT_NULL static WARN_UNUSED_RESULT int wc_AesDecrypt( { #if defined(MAX3266X_AES) word32 keySize; -#endif -#if defined(MAX3266X_CB) - int ret_cb; #endif word32 r; @@ -4566,12 +4560,12 @@ WC_ALL_ARGS_NOT_NULL static WARN_UNUSED_RESULT int wc_AesDecrypt( } #endif -#if defined(MAX3266X_CB) && defined(HAVE_AES_ECB) /* Can do a basic ECB block */ +#if (defined(WOLFSSL_TI_AM64X) || defined(MAX3266X_CB)) && defined(HAVE_AES_ECB) #ifndef WOLF_CRYPTO_CB_FIND if (aes->devId != INVALID_DEVID) #endif { - ret_cb = wc_CryptoCb_AesEcbDecrypt(aes, outBlock, inBlock, + int ret_cb = wc_CryptoCb_AesEcbDecrypt(aes, outBlock, inBlock, WC_AES_BLOCK_SIZE); if (ret_cb != WC_NO_ERR_TRACE(CRYPTOCB_UNAVAILABLE)) return ret_cb; diff --git a/wolfcrypt/src/ecc.c b/wolfcrypt/src/ecc.c index 0cc84908060..6588deeb433 100644 --- a/wolfcrypt/src/ecc.c +++ b/wolfcrypt/src/ecc.c @@ -4409,6 +4409,10 @@ int wc_ecc_get_curve_size_from_id(int curve_id) return ecc_sets[curve_idx].size; } +#ifndef strcasecmp +int strcasecmp(const char *s1, const char *s2); +#endif + /* Returns the curve index that corresponds to a given curve name in * ecc_sets[] of ecc.c * diff --git a/wolfcrypt/src/port/ti/ti-sa2ul_port.c b/wolfcrypt/src/port/ti/ti-sa2ul_port.c new file mode 100644 index 00000000000..23e7e09a87f --- /dev/null +++ b/wolfcrypt/src/port/ti/ti-sa2ul_port.c @@ -0,0 +1,927 @@ +/* ti-sa2ul_port.c + * + * Copyright (C) 2006-2026 wolfSSL Inc. + * + * This file is part of wolfSSL. + * + * wolfSSL is free software; you can redistribute it and/or modify + * it under the terms of the GNU General Public License as published by + * the Free Software Foundation; either version 3 of the License, or + * (at your option) any later version. + * + * wolfSSL is distributed in the hope that it will be useful, + * but WITHOUT ANY WARRANTY; without even the implied warranty of + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + * GNU General Public License for more details. + * + * You should have received a copy of the GNU General Public License + * along with this program; if not, write to the Free Software + * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1335, USA + */ + + +#include + +#if defined(WOLFSSL_TI_AM64X) + +#ifndef WOLF_CRYPTO_CB + #error WOLFSSL_TI_SA2UL support requires ./configure --enable-cryptocb or WOLF_CRYPTO_CB to be defined +#endif + +#include +#include +#include +#include + +#ifdef NO_INLINE + #include +#else + #define WOLFSSL_MISC_INCLUDED + #include +#endif + +/* from ti mcu plus sdk... */ +#include "kernel/dpl/CacheP.h" +#include "security/security_common/drivers/crypto/crypto.h" +#include "security/security_common/drivers/crypto/rng/rng.h" +#include "security/security_common/drivers/crypto/sa2ul/sa2ul.h" + +static Crypto_Handle handle; +static Crypto_Context cryptoCtx XALIGNED(SA2UL_CACHELINE_ALIGNMENT); + +#ifndef WC_NO_RNG +#define RNG_NUM_DWORDS (4u) +static RNG_Handle rngHandle = NULL; +static void ti_sa2ul_trng_init(void) +{ + RNG_Handle handle = NULL; + if (gRngConfig[0].attrs->isOpen == 0) { + SA2UL_engineEnable(CSL_CP_ACE_CMD_STATUS_TRNG_EN_MASK); + handle = RNG_open(0); + if (handle != NULL) { + if (RNG_setup(handle) == RNG_RETURN_SUCCESS) { + rngHandle = handle; + } + else { + RNG_close(handle); + } + } + } + else { + /* already opened -- use existing handle */ + rngHandle = (RNG_Handle)&gRngConfig[0]; + } +} + +static int ti_sa2ul_trng_get(OS_Seed* os, byte* output, word32 sz) +{ + if (output == NULL && sz != 0) + return -1; + + while (sz) { + uint32_t random[RNG_NUM_DWORDS]; + uint8_t *ptr = (uint8_t *)random; + int copy_len; + if (RNG_read(rngHandle, random) != RNG_RETURN_SUCCESS) + return -1; + copy_len = RNG_NUM_DWORDS * 4; + if (sz < copy_len) + copy_len = sz; + XMEMCPY(output, ptr, copy_len); + output += copy_len; + sz -= copy_len; + } + + return 0; +} +#endif /* WC_NO_RNG */ + +static void _u8LeToU32(uint32_t *dest, uint8_t *src, uint32_t len) +{ + uint32_t i, t = 0; + + for (i=0; ikeylen == AES_128_KEY_SIZE) { + scParams.encKeySize = SA2UL_ENC_KEYSIZE_128; + } + else { + scParams.encKeySize = SA2UL_ENC_KEYSIZE_256; + } + XMEMCPY(&scParams.key[0], aes->devKey, aes->keylen); + XMEMCPY(&scParams.iv[0], aes->reg, AES_IV_SIZE); + scParams.inputLen = sz; + aes->scObj.totalLengthInBytes = sz; + + if (SA2UL_contextAlloc(cryptoCtx.drvHandle, + &aes->scObj, &scParams) != SystemP_SUCCESS) + { + return WC_HW_E; + } + + CacheP_wbInv((void *)in, sz, CacheP_TYPE_ALLD); + + if (SA2UL_contextProcess(&aes->scObj, in, sz, out) != SystemP_SUCCESS) + ret = WC_HW_E; + + (void)SA2UL_contextFree(&aes->scObj); + + XMEMCPY(aes->reg, out + sz - 16, 16); + + return ret; +} + +#ifdef HAVE_AES_DECRYPT +static int ti_sa2ul_AesCbcDecrypt(Aes* aes, byte* out, const byte* in, word32 sz) +{ + int ret = 0; + SA2UL_ContextParams scParams; + byte tmp_iv[16]; + + SA2UL_ContextParams_init(&scParams); + + scParams.opType = SA2UL_OP_ENC; + scParams.encAlg = SA2UL_ENC_ALG_AES; + scParams.encMode = SA2UL_ENC_MODE_CBC; + scParams.encDirection = SA2UL_ENC_DIR_DECRYPT; + if (aes->keylen == AES_128_KEY_SIZE) { + scParams.encKeySize = SA2UL_ENC_KEYSIZE_128; + } + else { + scParams.encKeySize = SA2UL_ENC_KEYSIZE_256; + } + XMEMCPY(&scParams.key[0], aes->devKey, aes->keylen); + XMEMCPY(&scParams.iv[0], aes->reg, AES_IV_SIZE); + scParams.inputLen = sz; + aes->scObj.totalLengthInBytes = sz; + + if (SA2UL_contextAlloc(cryptoCtx.drvHandle, + &aes->scObj, &scParams) != SystemP_SUCCESS) + { + return WC_HW_E; + } + + XMEMCPY(tmp_iv, in + sz - 16, 16); + + CacheP_wbInv((void *)in, sz, CacheP_TYPE_ALLD); + + if (SA2UL_contextProcess(&aes->scObj, in, sz, out) != SystemP_SUCCESS) + ret = WC_HW_E; + + (void)SA2UL_contextFree(&aes->scObj); + + XMEMCPY(aes->reg, tmp_iv, 16); + + return ret; +} +#endif /* HAVE_AES_DECRYPT */ +#endif /* HAVE_AES_CBC */ + +#ifdef HAVE_AES_ECB +static int ti_sa2ul_AesEcbEncrypt(Aes* aes, byte* out, const byte* in, word32 sz) +{ + int ret = 0; + SA2UL_ContextParams scParams; + + SA2UL_ContextParams_init(&scParams); + + scParams.opType = SA2UL_OP_ENC; + scParams.encAlg = SA2UL_ENC_ALG_AES; + scParams.encMode = SA2UL_ENC_MODE_ECB; + scParams.encDirection = SA2UL_ENC_DIR_ENCRYPT; + if (aes->keylen == AES_128_KEY_SIZE) { + scParams.encKeySize = SA2UL_ENC_KEYSIZE_128; + } + else { + scParams.encKeySize = SA2UL_ENC_KEYSIZE_256; + } + XMEMCPY(&scParams.key[0], aes->devKey, aes->keylen); + XMEMCPY(&scParams.iv[0], aes->reg, AES_IV_SIZE); + scParams.inputLen = sz; + aes->scObj.totalLengthInBytes = sz; + + if (SA2UL_contextAlloc(cryptoCtx.drvHandle, + &aes->scObj, &scParams) != SystemP_SUCCESS) + { + return WC_HW_E; + } + + CacheP_wbInv((void *)in, sz, CacheP_TYPE_ALLD); + + if (SA2UL_contextProcess(&aes->scObj, in, sz, out) != SystemP_SUCCESS) + ret = WC_HW_E; + + (void)SA2UL_contextFree(&aes->scObj); + + return ret; +} + +#ifdef HAVE_AES_DECRYPT +static int ti_sa2ul_AesEcbDecrypt(Aes* aes, byte* out, const byte* in, word32 sz) +{ + int ret = 0; + SA2UL_ContextParams scParams; + + SA2UL_ContextParams_init(&scParams); + + scParams.opType = SA2UL_OP_ENC; + scParams.encAlg = SA2UL_ENC_ALG_AES; + scParams.encMode = SA2UL_ENC_MODE_ECB; + scParams.encDirection = SA2UL_ENC_DIR_DECRYPT; + if (aes->keylen == AES_128_KEY_SIZE) { + scParams.encKeySize = SA2UL_ENC_KEYSIZE_128; + } + else { + scParams.encKeySize = SA2UL_ENC_KEYSIZE_256; + } + XMEMCPY(&scParams.key[0], aes->devKey, aes->keylen); + XMEMCPY(&scParams.iv[0], aes->reg, AES_IV_SIZE); + scParams.inputLen = sz; + aes->scObj.totalLengthInBytes = sz; + + if (SA2UL_contextAlloc(cryptoCtx.drvHandle, + &aes->scObj, &scParams) != SystemP_SUCCESS) + { + return WC_HW_E; + } + + CacheP_wbInv((void *)in, sz, CacheP_TYPE_ALLD); + + if (SA2UL_contextProcess(&aes->scObj, in, sz, out) != SystemP_SUCCESS) + ret = WC_HW_E; + + (void)SA2UL_contextFree(&aes->scObj); + + return ret; +} +#endif /* HAVE_AES_DECRYPT */ +#endif /* HAVE_AES_ECB */ + +#ifdef HAVE_AESGCM +static void _override_iv_with_ghash(Aes* aes, const byte* iv, word32 ivSz) +{ + SA2UL_SecCtx sc; + byte ivtmp[WC_AES_BLOCK_SIZE]; + + GHASH(&aes->gcm, NULL, 0, iv, ivSz, ivtmp, WC_AES_BLOCK_SIZE); + XMEMCPY(aes->scObj.ctxPrms.iv, ivtmp, WC_AES_BLOCK_SIZE); + _64byteReverseWords((uint32_t*)&sc, (uint32_t*)&aes->scObj.secCtx, sizeof(sc)); + _u8LeToU32(sc.u.enc.encAux3, ivtmp, WC_AES_BLOCK_SIZE); + _64byteReverseWords((uint32_t*)&aes->scObj.secCtx, (uint32_t*)&sc, sizeof(sc)); + CacheP_wbInv(&aes->scObj.secCtx, sizeof(sc), CacheP_TYPE_ALLD); +} + +static int ti_sa2ul_AesGcmEncrypt(Aes* aes, byte* out, + const byte* in, word32 sz, + const byte* iv, word32 ivSz, + byte* authTag, word32 authTagSz, + const byte* authIn, word32 authInSz) +{ + int ret = 0; + SA2UL_ContextParams scParams; + + SA2UL_ContextParams_init(&scParams); + + scParams.opType = SA2UL_OP_ENC; + scParams.encAlg = SA2UL_ENC_ALG_AES; + scParams.encMode = SA2UL_ENC_MODE_GCM; + scParams.encDirection = SA2UL_ENC_DIR_ENCRYPT; + if (aes->keylen == AES_128_KEY_SIZE) { + scParams.encKeySize = SA2UL_ENC_KEYSIZE_128; + } + else { + scParams.encKeySize = SA2UL_ENC_KEYSIZE_256; + } + XMEMCPY(scParams.key, aes->devKey, aes->keylen); + XMEMCPY(scParams.iv, iv, ivSz); + XMEMCPY(scParams.ghash, aes->gcm.H, WC_AES_BLOCK_SIZE); + if (authInSz <= sizeof(scParams.aad)) { + XMEMCPY(scParams.aad, authIn, authInSz); + scParams.aadLen = authInSz; + } + else { + scParams.aadLen = 0; + } + scParams.inputLen = sz; + aes->scObj.totalLengthInBytes = sz; + + if (SA2UL_contextAlloc(cryptoCtx.drvHandle, + &aes->scObj, &scParams) != SystemP_SUCCESS) + { + return WC_HW_E; + } + + if (ivSz != GCM_NONCE_MID_SZ) { + _override_iv_with_ghash(aes, iv, ivSz); + } + + CacheP_wbInv((void *)in, sz, CacheP_TYPE_ALLD); + + if (SA2UL_contextProcess(&aes->scObj, in, sz, out) != SystemP_SUCCESS) + ret = WC_HW_E; + + (void)SA2UL_contextFree(&aes->scObj); + + if (authTag) { + if (authInSz <= sizeof(scParams.aad)) { + XMEMCPY(authTag, aes->scObj.computedHash, authTagSz); + } + else { + ALIGN16 byte initialCounter[WC_AES_BLOCK_SIZE]; + ALIGN16 byte scratch[WC_AES_BLOCK_SIZE]; + GHASH(&aes->gcm, authIn, authInSz, out, sz, authTag, authTagSz); + if (ivSz == GCM_NONCE_MID_SZ) { + XMEMCPY(initialCounter, iv, ivSz); + initialCounter[WC_AES_BLOCK_SIZE-4] = 0; + initialCounter[WC_AES_BLOCK_SIZE-3] = 0; + initialCounter[WC_AES_BLOCK_SIZE-2] = 0; + initialCounter[WC_AES_BLOCK_SIZE-1] = 1; + } + else { + XMEMCPY(initialCounter, aes->scObj.ctxPrms.iv, WC_AES_BLOCK_SIZE); + } + ret = wc_AesEncryptDirect(aes, scratch, initialCounter); + xorbuf(authTag, scratch, authTagSz); + } + } + + return ret; +} + +#ifdef HAVE_AES_DECRYPT +static int ti_sa2ul_AesGcmDecrypt(Aes* aes, byte* out, + const byte* in, word32 sz, + const byte* iv, word32 ivSz, + const byte* authTag, word32 authTagSz, + const byte* authIn, word32 authInSz) +{ + int ret = 0; + SA2UL_ContextParams scParams; + + SA2UL_ContextParams_init(&scParams); + + scParams.opType = SA2UL_OP_ENC; + scParams.encAlg = SA2UL_ENC_ALG_AES; + scParams.encMode = SA2UL_ENC_MODE_GCM; + scParams.encDirection = SA2UL_ENC_DIR_DECRYPT; + if (aes->keylen == AES_128_KEY_SIZE) { + scParams.encKeySize = SA2UL_ENC_KEYSIZE_128; + } + else { + scParams.encKeySize = SA2UL_ENC_KEYSIZE_256; + } + XMEMCPY(scParams.key, aes->devKey, aes->keylen); + XMEMCPY(scParams.iv, iv, ivSz); + XMEMCPY(scParams.ghash, aes->gcm.H, WC_AES_BLOCK_SIZE); + XMEMCPY(scParams.aad, authIn, authInSz); + scParams.aadLen = authInSz; + scParams.inputLen = sz; + aes->scObj.totalLengthInBytes = sz; + + if (SA2UL_contextAlloc(cryptoCtx.drvHandle, + &aes->scObj, &scParams) != SystemP_SUCCESS) + { + return WC_HW_E; + } + + if (ivSz != GCM_NONCE_MID_SZ) { + _override_iv_with_ghash(aes, iv, ivSz); + } + + CacheP_wbInv((void *)in, sz, CacheP_TYPE_ALLD); + + if (SA2UL_contextProcess(&aes->scObj, in, sz, out) != SystemP_SUCCESS) + ret = WC_HW_E; + + (void)SA2UL_contextFree(&aes->scObj); + + if (authTag) { + if (authInSz <= sizeof(scParams.aad)) { + if (XMEMCMP(authTag, aes->scObj.computedHash, authTagSz) != 0) + ret = WC_NO_ERR_TRACE(AES_GCM_AUTH_E); + } + else { + ALIGN16 byte initialCounter[WC_AES_BLOCK_SIZE]; + ALIGN16 byte scratch[WC_AES_BLOCK_SIZE]; + ALIGN16 byte Tprime[WC_AES_BLOCK_SIZE]; + GHASH(&aes->gcm, authIn, authInSz, in, sz, Tprime, sizeof(Tprime)); + if (ivSz == GCM_NONCE_MID_SZ) { + XMEMCPY(initialCounter, iv, ivSz); + initialCounter[WC_AES_BLOCK_SIZE-4] = 0; + initialCounter[WC_AES_BLOCK_SIZE-3] = 0; + initialCounter[WC_AES_BLOCK_SIZE-2] = 0; + initialCounter[WC_AES_BLOCK_SIZE-1] = 1; + } + else { + XMEMCPY(initialCounter, aes->scObj.ctxPrms.iv, WC_AES_BLOCK_SIZE); + } + ret = wc_AesEncryptDirect(aes, scratch, initialCounter); + xorbuf(Tprime, scratch, sizeof(Tprime)); + if (XMEMCMP(authTag, Tprime, authTagSz) != 0) + ret = WC_NO_ERR_TRACE(AES_GCM_AUTH_E); + } + } + + return ret; +} +#endif /* HAVE_AES_DECRYPT */ +#endif /* HAVE_AESGCM */ +#endif /* !NO_AES */ + + +#if !defined(NO_SHA256) || defined(WOLFSSL_SHA512) +/* The ti mcu plus sdk sa2ul driver requires an output buffer of at least + * the size of the input buffer, and it will write data to it, though we don't + * use the data. So, we consider this a scratch buffer, but it also limits + * the amount of data we can hash at one time. */ +#define HASH_SCRATCH_SIZE 0x2000u +static byte hash_scratch[HASH_SCRATCH_SIZE] XALIGNED(SA2UL_CACHELINE_ALIGNMENT); +static volatile int sa2ul_hash_in_use = 0; + +#ifndef NO_SHA256 +static int ti_sa2ul_InitSha256_ctx(wc_Sha256* sha256) +{ + SA2UL_ContextParams scParams; + + SA2UL_ContextParams_init(&scParams); + + scParams.opType = SA2UL_OP_AUTH; + scParams.hashAlg = SA2UL_HASH_ALG_SHA2_256; + /* default length to all ff's, final will override when known */ + scParams.inputLen = 0xffffffffUL; + sha256->scObj.totalLengthInBytes = 0xffffffffUL; + + if (SA2UL_contextAlloc(cryptoCtx.drvHandle, + &sha256->scObj, &scParams) != SystemP_SUCCESS) + { + return WC_HW_E; + } + + sa2ul_hash_in_use = 1; + + return 0; +} + +static int ti_sa2ul_Sha256Free_ctx(wc_Sha256* sha256) +{ + (void)SA2UL_contextFree(&sha256->scObj); + XMEMSET(&sha256->scObj, 0, sizeof(sha256->scObj)); + + sa2ul_hash_in_use = 0; + + return 0; +} + +static int ti_sa2ul_Sha256Hash(wc_Sha256* sha256, const byte* in, + word32 inSz, byte* digest) +{ + int ret = 0; + byte* buffer = (byte*)sha256->buffer; + word32 blocksLen; + word32 partialLen; + + if (in == NULL && digest == NULL) + return WC_HW_E; + + if (sha256->scObj.txBytesCnt == 0 && sa2ul_hash_in_use == 1) { + sha256->flags |= WC_HASH_FLAG_ISCOPY; + return CRYPTOCB_UNAVAILABLE; + } + + if (in != NULL) { + /* update... */ + sha256->loLen += inSz; + + /* handle leftovers first */ + if (sha256->buffLen > 0) { + partialLen = min(inSz, WC_SHA256_BLOCK_SIZE - sha256->buffLen); + XMEMCPY(&buffer[sha256->buffLen], in, partialLen); + sha256->buffLen += partialLen; + in += partialLen; + inSz -= partialLen; + if (sha256->buffLen == WC_SHA256_BLOCK_SIZE) { + CacheP_wbInv((void *)buffer, WC_SHA256_BLOCK_SIZE, + CacheP_TYPE_ALLD); + if (sha256->scObj.txBytesCnt == 0) { + if (ti_sa2ul_InitSha256_ctx(sha256) != 0) + return WC_HW_E; + } + if (SA2UL_contextProcess(&sha256->scObj, buffer, + WC_SHA256_BLOCK_SIZE, hash_scratch) != SystemP_SUCCESS) + { + return WC_HW_E; + } + XMEMCPY(sha256->digest, &sha256->scObj.computedHash, + WC_SHA256_DIGEST_SIZE); + /* final will fall back to sw, and sw needs bytes reversed */ + ByteReverseWords(sha256->digest, sha256->digest, + WC_SHA256_DIGEST_SIZE); + sha256->buffLen = 0; + } + } + /* chunks of full blocks */ + while (inSz >= WC_SHA256_BLOCK_SIZE) { + blocksLen = min(sizeof(hash_scratch), + inSz & ~((word32)WC_SHA256_BLOCK_SIZE-1)); + CacheP_wbInv((void *)in, blocksLen, CacheP_TYPE_ALLD); + if (sha256->scObj.txBytesCnt == 0) { + if (ti_sa2ul_InitSha256_ctx(sha256) != 0) + return WC_HW_E; + } + if (SA2UL_contextProcess(&sha256->scObj, in, blocksLen, + hash_scratch) != SystemP_SUCCESS) { + return WC_HW_E; + } + XMEMCPY(sha256->digest, &sha256->scObj.computedHash, + WC_SHA256_DIGEST_SIZE); + ByteReverseWords(sha256->digest, sha256->digest, + WC_SHA256_DIGEST_SIZE); + in += blocksLen; + inSz -= blocksLen; + } + /* save leftovers */ + if (inSz > 0) { + XMEMCPY(&buffer[0], in, inSz); + sha256->buffLen = inSz; + } + } + else if (digest != NULL) { + /* final... */ + /* hash will be finalized in sw via fallback, but we need the driver + * to tear down the context in hw. To do that, we update the context + * length and push some final arbitrary data. It will not affect + * the hash */ + if (sha256->scObj.txBytesCnt != 0) { + sha256->scObj.ctxPrms.inputLen = sha256->scObj.txBytesCnt + + WC_SHA256_DIGEST_SIZE; + sha256->scObj.totalLengthInBytes = sha256->scObj.txBytesCnt + + WC_SHA256_DIGEST_SIZE; + CacheP_wbInv((void *)buffer, WC_SHA256_DIGEST_SIZE, CacheP_TYPE_ALLD); + if (SA2UL_contextProcess(&sha256->scObj, buffer, + WC_SHA256_DIGEST_SIZE, hash_scratch) != SystemP_SUCCESS) + { + ret = WC_HW_E; + } + (void)ti_sa2ul_Sha256Free_ctx(sha256); + } + ret = CRYPTOCB_UNAVAILABLE; /* fall back to sw */ + } + + return ret; +} +#endif /* !NO_SHA256 */ + +#ifdef WOLFSSL_SHA512 +static int ti_sa2ul_InitSha512_ctx(wc_Sha512* sha512) +{ + SA2UL_ContextParams scParams; + + SA2UL_ContextParams_init(&scParams); + + scParams.opType = SA2UL_OP_AUTH; + scParams.hashAlg = SA2UL_HASH_ALG_SHA2_512; + /* default length to all ff's, final will override when known */ + scParams.inputLen = 0xffffffffUL; + sha512->scObj.totalLengthInBytes = 0xffffffffUL; + + if (SA2UL_contextAlloc(cryptoCtx.drvHandle, + &sha512->scObj, &scParams) != SystemP_SUCCESS) + { + return WC_HW_E; + } + return 0; +} + +static int ti_sa2ul_Sha512Free_ctx(wc_Sha512* sha512) +{ + (void)SA2UL_contextFree(&sha512->scObj); + XMEMSET(&sha512->scObj, 0, sizeof(sha512->scObj)); + + return 0; +} + +static int ti_sa2ul_Sha512Hash(wc_Sha512* sha512, const byte* in, + word32 inSz, byte* digest) +{ + int ret = 0; + byte* buffer = (byte*)sha512->buffer; + word32 blocksLen; + word32 partialLen; + + if (in == NULL && digest == NULL) + return WC_HW_E; + + if (sha512->scObj.txBytesCnt == 0 && sa2ul_hash_in_use == 1) { + sha512->flags |= WC_HASH_FLAG_ISCOPY; + return CRYPTOCB_UNAVAILABLE; + } + + if (in != NULL) { + /* update... */ + sha512->loLen += inSz; + + /* handle leftovers first */ + if (sha512->buffLen > 0) { + partialLen = min(inSz, WC_SHA512_BLOCK_SIZE - sha512->buffLen); + XMEMCPY(&buffer[sha512->buffLen], in, partialLen); + sha512->buffLen += partialLen; + in += partialLen; + inSz -= partialLen; + if (sha512->buffLen == WC_SHA512_BLOCK_SIZE) { + CacheP_wbInv((void *)buffer, WC_SHA512_BLOCK_SIZE, CacheP_TYPE_ALLD); + if (sha512->scObj.txBytesCnt == 0) { + if (ti_sa2ul_InitSha512_ctx(sha512) != 0) + return WC_HW_E; + } + if (SA2UL_contextProcess(&sha512->scObj, buffer, + WC_SHA512_BLOCK_SIZE, hash_scratch) != SystemP_SUCCESS) + { + return WC_HW_E; + } + XMEMCPY(sha512->digest, &sha512->scObj.computedHash, + WC_SHA512_DIGEST_SIZE); + /* final will fall back to sw, and sw needs bytes reversed */ + ByteReverseWords64(sha512->digest, sha512->digest, + WC_SHA512_DIGEST_SIZE); + sha512->buffLen = 0; + } + } + /* chunks of full blocks */ + while (inSz >= WC_SHA512_BLOCK_SIZE) { + blocksLen = min(sizeof(hash_scratch), + inSz & ~((word32)WC_SHA512_BLOCK_SIZE-1)); + CacheP_wbInv((void *)in, blocksLen, CacheP_TYPE_ALLD); + if (sha512->scObj.txBytesCnt == 0) { + if (ti_sa2ul_InitSha512_ctx(sha512) != 0) + return WC_HW_E; + } + if (SA2UL_contextProcess(&sha512->scObj, in, blocksLen, + hash_scratch) != SystemP_SUCCESS) { + return WC_HW_E; + } + XMEMCPY(sha512->digest, &sha512->scObj.computedHash, + WC_SHA512_DIGEST_SIZE); + ByteReverseWords64(sha512->digest, sha512->digest, + WC_SHA512_DIGEST_SIZE); + in += blocksLen; + inSz -= blocksLen; + } + /* save leftovers */ + if (inSz > 0) { + XMEMCPY(&buffer[0], in, inSz); + sha512->buffLen = inSz; + } + } + else if (digest != NULL) { + /* final... */ + /* hash will be finalized in sw via fallback, but we need the driver + * to tear down the context in hw. To do that, we update the context + * length and push some final arbitrary data. It will not affect + * the hash */ + if (sha512->scObj.txBytesCnt != 0) { + sha512->scObj.ctxPrms.inputLen = sha512->scObj.txBytesCnt + + WC_SHA512_DIGEST_SIZE; + sha512->scObj.totalLengthInBytes = sha512->scObj.txBytesCnt + + WC_SHA512_DIGEST_SIZE; + CacheP_wbInv((void *)buffer, WC_SHA512_DIGEST_SIZE, CacheP_TYPE_ALLD); + if (SA2UL_contextProcess(&sha512->scObj, buffer, + WC_SHA512_DIGEST_SIZE, hash_scratch) != SystemP_SUCCESS) { + ret = WC_HW_E; + } + (void)ti_sa2ul_Sha512Free_ctx(sha512); + } + ret = CRYPTOCB_UNAVAILABLE; /* fall back to sw */ + } + + return ret; +} +#endif /* WOLFSSL_SHA512 */ +#endif /* !NO_SHA256 || WOLFSSL_SHA512 */ + +static int ti_sa2ul_CryptoDevCb(int devId, wc_CryptoInfo* info, void* devCtx) +{ + int ret = CRYPTOCB_UNAVAILABLE; + + WOLFSSL_ENTER("ti_sa2ul_CryptoDevCb"); + + (void)devCtx; + + if (info == NULL) + return BAD_FUNC_ARG; + if (devId == INVALID_DEVID) + return CRYPTOCB_UNAVAILABLE; + +#ifdef DEBUG_CRYPTOCB + wc_CryptoCb_InfoString(info); +#endif + + if (info->algo_type == WC_ALGO_TYPE_CIPHER) + { +#if !defined(NO_AES) + if (0) { + /* nothing */ + } +# if defined(HAVE_AES_CBC) + else if (info->cipher.type == WC_CIPHER_AES_CBC) { + Aes* aes = info->cipher.aescbc.aes; + if (aes == NULL) + return BAD_FUNC_ARG; + if (check_aes_keylength(aes->keylen) != 0) + return CRYPTOCB_UNAVAILABLE; /* fall back to sw */ + if (info->cipher.enc) { + ret = ti_sa2ul_AesCbcEncrypt(info->cipher.aescbc.aes, + info->cipher.aescbc.out, + info->cipher.aescbc.in, + info->cipher.aescbc.sz); + } +# ifdef HAVE_AES_DECRYPT + else { + ret = ti_sa2ul_AesCbcDecrypt(info->cipher.aescbc.aes, + info->cipher.aescbc.out, + info->cipher.aescbc.in, + info->cipher.aescbc.sz); + } +# endif /* HAVE_AES_DECRYPT */ + } +# endif /* HAVE_AES_CBC */ +# if defined(HAVE_AES_ECB) + else if (info->cipher.type == WC_CIPHER_AES_ECB) { + Aes* aes = info->cipher.aesecb.aes; + if (aes == NULL) + return BAD_FUNC_ARG; + if (check_aes_keylength(aes->keylen) != 0) + return CRYPTOCB_UNAVAILABLE; /* fall back to sw */ + if (info->cipher.enc) { + ret = ti_sa2ul_AesEcbEncrypt(info->cipher.aesecb.aes, + info->cipher.aesecb.out, + info->cipher.aesecb.in, + info->cipher.aesecb.sz); + } +# ifdef HAVE_AES_DECRYPT + else { + ret = ti_sa2ul_AesEcbDecrypt(info->cipher.aesecb.aes, + info->cipher.aesecb.out, + info->cipher.aesecb.in, + info->cipher.aesecb.sz); + } +# endif /* HAVE_AES_DECRYPT */ + } +# endif /* HAVE_AES_ECB */ +# if defined(HAVE_AESGCM) + else if (info->cipher.type == WC_CIPHER_AES_GCM) { + if (info->cipher.enc) { + Aes* aes = info->cipher.aesgcm_enc.aes; + if (aes == NULL) + return BAD_FUNC_ARG; + if (check_aes_keylength(aes->keylen) != 0 || + info->cipher.aesgcm_enc.sz == 0) { + return CRYPTOCB_UNAVAILABLE; /* fall back to sw */ + } + ret = ti_sa2ul_AesGcmEncrypt(aes, + info->cipher.aesgcm_enc.out, + info->cipher.aesgcm_enc.in, + info->cipher.aesgcm_enc.sz, + info->cipher.aesgcm_enc.iv, + info->cipher.aesgcm_enc.ivSz, + info->cipher.aesgcm_enc.authTag, + info->cipher.aesgcm_enc.authTagSz, + info->cipher.aesgcm_enc.authIn, + info->cipher.aesgcm_enc.authInSz); + } +# ifdef HAVE_AES_DECRYPT + else { + Aes* aes = info->cipher.aesgcm_dec.aes; + if (aes == NULL) + return BAD_FUNC_ARG; + if (check_aes_keylength(aes->keylen) != 0 || + info->cipher.aesgcm_dec.sz == 0) { + return CRYPTOCB_UNAVAILABLE; /* fall back to sw */ + } + ret = ti_sa2ul_AesGcmDecrypt(aes, + info->cipher.aesgcm_dec.out, + info->cipher.aesgcm_dec.in, + info->cipher.aesgcm_dec.sz, + info->cipher.aesgcm_dec.iv, + info->cipher.aesgcm_dec.ivSz, + info->cipher.aesgcm_dec.authTag, + info->cipher.aesgcm_dec.authTagSz, + info->cipher.aesgcm_dec.authIn, + info->cipher.aesgcm_dec.authInSz); + } +# endif /* HAVE_AES_DECRYPT */ + } +# endif /* HAVE_AESGCM */ +#endif /* !NO_AES */ + } + else if (info->algo_type == WC_ALGO_TYPE_HASH) + { +#if !defined(NO_SHA256) || defined(WOLFSSL_SHA512) + if (0) { + /* nothing */ + } +# ifndef NO_SHA256 + else if (info->hash.type == WC_HASH_TYPE_SHA256) { + if ((info->hash.sha256->flags & WC_HASH_FLAG_ISCOPY) == 0) { + ret = ti_sa2ul_Sha256Hash(info->hash.sha256, + info->hash.in, + info->hash.inSz, + info->hash.digest); + } + } +# endif /* !NO_SHA256 */ +# ifdef WOLFSSL_SHA512 + else if (info->hash.type == WC_HASH_TYPE_SHA512) { + if (info->hash.sha512->hashType == WC_HASH_TYPE_SHA512 && + (info->hash.sha512->flags & WC_HASH_FLAG_ISCOPY) == 0) { + ret = ti_sa2ul_Sha512Hash(info->hash.sha512, + info->hash.in, + info->hash.inSz, + info->hash.digest); + } + } +# endif /* WOLFSSL_SHA512 */ +#endif /* !NO_SHA256 || WOLFSSL_SHA512 */ + } +#ifndef WC_NO_RNG + else if (info->algo_type == WC_ALGO_TYPE_SEED) + { + ret = ti_sa2ul_trng_get(info->seed.os, + info->seed.seed, + info->seed.sz); + } +#endif /* WC_NO_RNG */ + + return ret; +} + +int ti_sa2ul_port_init(void) +{ + int ret = WC_HW_E; + +#ifndef WC_NO_RNG + ti_sa2ul_trng_init(); +#endif /* WC_NO_RNG */ + + handle = Crypto_open(&cryptoCtx); + if (handle != NULL) { + ret = wc_CryptoCb_RegisterDevice(WOLFSSL_TI_SA2UL_DEVID, + ti_sa2ul_CryptoDevCb, NULL); + } + return ret; +} + +#endif /* WOLFSSL_TI_AM64X */ \ No newline at end of file diff --git a/wolfcrypt/src/random.c b/wolfcrypt/src/random.c index 55d23d2e6e5..1c754b5e851 100644 --- a/wolfcrypt/src/random.c +++ b/wolfcrypt/src/random.c @@ -233,6 +233,9 @@ This library contains implementation for the random number generator. #include "cyhal_trng.h" /* Infineon/Cypress HAL RNG implementation */ #elif defined(WOLFSSL_MAX3266X) || defined(WOLFSSL_MAX3266X_OLD) #include "wolfssl/wolfcrypt/port/maxim/max3266x.h" +#elif defined(WOLFSSL_TI_AM64X) + #include +#elif defined(__ti__) /* ti clang toolchain */ #else #include #if defined(WOLFSSL_GETRANDOM) || defined(HAVE_GETRANDOM) diff --git a/wolfcrypt/src/sha256.c b/wolfcrypt/src/sha256.c index 5f0510f7c89..73e9725a088 100644 --- a/wolfcrypt/src/sha256.c +++ b/wolfcrypt/src/sha256.c @@ -346,6 +346,10 @@ static int InitSha256(wc_Sha256* sha256) sha256->hSession = NULL; #endif +#ifdef WOLFSSL_TI_AM64X + XMEMSET(&sha256->scObj, 0, sizeof(sha256->scObj)); +#endif + return 0; } diff --git a/wolfcrypt/src/sha512.c b/wolfcrypt/src/sha512.c index bac5fc9ef57..4fa3f06c2ce 100644 --- a/wolfcrypt/src/sha512.c +++ b/wolfcrypt/src/sha512.c @@ -959,6 +959,10 @@ static int InitSha512(wc_Sha512* sha512) #if defined(WOLFSSL_SHA512_HASHTYPE) sha512->hashType = WC_HASH_TYPE_SHA512; #endif /* WOLFSSL_SHA512_HASHTYPE */ + +#ifdef WOLFSSL_TI_AM64X + XMEMSET(&sha512->scObj, 0, sizeof(sha512->scObj)); +#endif return 0; } diff --git a/wolfcrypt/src/wc_port.c b/wolfcrypt/src/wc_port.c index 95527d195f8..0029343fb52 100644 --- a/wolfcrypt/src/wc_port.c +++ b/wolfcrypt/src/wc_port.c @@ -212,6 +212,10 @@ Threading/Mutex options: #include #endif +#ifdef WOLFSSL_TI_AM64X + #include +#endif + #ifdef WOLF_CRYPTO_CB #include #endif @@ -951,6 +955,14 @@ int wolfCrypt_Init(void) } #endif + #if defined(WOLFSSL_TI_AM64X) + ret = ti_sa2ul_port_init(); + if (ret != 0) { + WOLFSSL_MSG("TI AM64x Init Failed"); + WOLFCRYPT_INIT_RAISE_BAD_STATE(); + } + #endif + #if defined(WOLFSSL_ATMEL) || defined(WOLFSSL_ATECC508A) || \ defined(WOLFSSL_ATECC608A) || defined(WOLFSSL_MICROCHIP_TA100) ret = atmel_init(); diff --git a/wolfcrypt/test/test.c b/wolfcrypt/test/test.c index 260b6e94d22..02030efceed 100644 --- a/wolfcrypt/test/test.c +++ b/wolfcrypt/test/test.c @@ -355,6 +355,11 @@ static const byte const_byte_array[] = "A+Gd\0\0\0"; if ((_i & 7) != 0) WOLFSSL_DEBUG_PRINTF("\n"); \ } while(0) +#ifdef TI_MCU_PLUS_SDK +# include "kernel/nortos/dpl/common/printf.h" +# define printf printf_ +#endif + #include #include #include @@ -529,6 +534,10 @@ static const byte const_byte_array[] = "A+Gd\0\0\0"; #endif #endif +#ifdef WOLFSSL_TI_AM64X + #include +#endif + #ifdef _MSC_VER /* 4996 warning to use MS extensions e.g., strcpy_s instead of strncpy */ #pragma warning(disable: 4996) diff --git a/wolfssl/wolfcrypt/aes.h b/wolfssl/wolfcrypt/aes.h index 6b428203811..4be0ea3abe6 100644 --- a/wolfssl/wolfcrypt/aes.h +++ b/wolfssl/wolfcrypt/aes.h @@ -189,6 +189,10 @@ WOLFSSL_LOCAL void WC_ARG_NOT_NULL(1) GHASH(Gcm* gcm, const byte* a, #include "cy_crypto_common.h" #endif /* WOLFSSL_PSOC6_CRYPTO */ +#ifdef WOLFSSL_TI_AM64X + #include "security/security_common/drivers/crypto/crypto.h" +#endif + /* Backends that replace one or more AES mode entry points, either with a * hardware arm in aes.c or with a port file. Those entry points do not carry * the key-set guard, so the check is not applied on these builds. */ @@ -521,6 +525,9 @@ struct Aes { cy_stc_crypto_aes_gcm_state_t aes_gcm_state; #endif #endif /* WOLFSSL_PSOC6_CRYPTO */ +#ifdef WOLFSSL_TI_AM64X + XALIGNED(16) SA2UL_ContextObject scObj; +#endif /* Set to 1 once a key has been installed (wc_AesSetKey/SetKeyDirect/ * GcmSetKey), including when a crypto callback takes ownership of it. diff --git a/wolfssl/wolfcrypt/port/ti/ti-sa2ul_port.h b/wolfssl/wolfcrypt/port/ti/ti-sa2ul_port.h new file mode 100644 index 00000000000..e8b1c4cc527 --- /dev/null +++ b/wolfssl/wolfcrypt/port/ti/ti-sa2ul_port.h @@ -0,0 +1,33 @@ +/* ti-sa2ul_port.h + * + * Copyright (C) 2006-2026 wolfSSL Inc. + * + * This file is part of wolfSSL. + * + * wolfSSL is free software; you can redistribute it and/or modify + * it under the terms of the GNU General Public License as published by + * the Free Software Foundation; either version 3 of the License, or + * (at your option) any later version. + * + * wolfSSL is distributed in the hope that it will be useful, + * but WITHOUT ANY WARRANTY; without even the implied warranty of + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + * GNU General Public License for more details. + * + * You should have received a copy of the GNU General Public License + * along with this program; if not, write to the Free Software + * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1335, USA + */ +#ifndef _TI_SA2UL_PORT_H_ +#define _TI_SA2UL_PORT_H_ + +#if defined(WOLFSSL_TI_AM64X) + +#define WOLFSSL_TI_SA2UL_DEVID 8888 +#define WC_USE_DEVID WOLFSSL_TI_SA2UL_DEVID + +int ti_sa2ul_port_init(void); + +#endif /* WOLFSSL_TI_AM64X */ + +#endif /* _TI_SA2UL_PORT_H_ */ \ No newline at end of file diff --git a/wolfssl/wolfcrypt/settings.h b/wolfssl/wolfcrypt/settings.h index 85f98891574..83064a33dc4 100644 --- a/wolfssl/wolfcrypt/settings.h +++ b/wolfssl/wolfcrypt/settings.h @@ -2516,6 +2516,20 @@ #define NO_WOLFSSL_SHA256_INTERLEAVE #endif +#ifdef WOLFSSL_TI_AM64X + #define HAVE_AES_ECB + #define WOLFSSL_AES_128 + #define NO_AES_192 + #define WOLFSSL_AES_256 + #define WOLFSSL_AES_DIRECT + #define WOLFSSL_CMAC + #define WOLFSSL_SHA512 + #ifndef WOLF_CRYPTO_CB + #define WOLF_CRYPTO_CB + #endif + #define WOLFSSL_SHA512_HASHTYPE +#endif + #ifdef FREESCALE_LTC_TFM_RSA_4096_ENABLE #undef USE_CERT_BUFFERS_4096 #define USE_CERT_BUFFERS_4096 diff --git a/wolfssl/wolfcrypt/sha256.h b/wolfssl/wolfcrypt/sha256.h index b0134472ff5..556ec796861 100644 --- a/wolfssl/wolfcrypt/sha256.h +++ b/wolfssl/wolfcrypt/sha256.h @@ -167,6 +167,10 @@ #include "mcapi_error.h" #endif +#ifdef WOLFSSL_TI_AM64X + #include "security/security_common/drivers/crypto/sa2ul/sa2ul.h" +#endif + /* wc_Sha256 digest */ struct wc_Sha256 { @@ -254,6 +258,9 @@ struct wc_Sha256 { #ifdef WOLFSSL_HASH_FLAGS word32 flags; /* enum wc_HashFlags in hash.h */ #endif +#ifdef WOLFSSL_TI_AM64X + XALIGNED(16) SA2UL_ContextObject scObj; +#endif }; #ifndef WC_SHA256_TYPE_DEFINED diff --git a/wolfssl/wolfcrypt/sha512.h b/wolfssl/wolfcrypt/sha512.h index 8de7266446c..a03101a6832 100644 --- a/wolfssl/wolfcrypt/sha512.h +++ b/wolfssl/wolfcrypt/sha512.h @@ -147,6 +147,10 @@ #if defined(WOLFSSL_MAX3266X) || defined(WOLFSSL_MAX3266X_OLD) #include "wolfssl/wolfcrypt/port/maxim/max3266x.h" #endif +#ifdef WOLFSSL_TI_AM64X + #include "security/security_common/drivers/crypto/sa2ul/sa2ul.h" +#endif + /* wc_Sha512 digest */ struct wc_Sha512 { #if defined(PSOC6_HASH_SHA2) @@ -211,6 +215,9 @@ struct wc_Sha512 { int hashType; /* used to determine which SHA512 is used */ #endif /* WOLFSSL_SHA512_HASHTYPE */ #endif /* WOLFSSL_PSOC6_CRYPTO */ +#ifdef WOLFSSL_TI_AM64X + XALIGNED(16) SA2UL_ContextObject scObj; +#endif }; diff --git a/wolfssl/wolfcrypt/types.h b/wolfssl/wolfcrypt/types.h index 7a177b34eb2..b4ac9b8a9d3 100644 --- a/wolfssl/wolfcrypt/types.h +++ b/wolfssl/wolfcrypt/types.h @@ -2391,7 +2391,7 @@ WOLFSSL_API word32 CheckRunTimeSettings(void); #define PRAGMA_GCC_DIAG_POP /* null expansion */ #endif -#ifdef __clang__ +#if defined(__clang__) && !defined(__ti__) #define PRAGMA_CLANG_DIAG_PUSH _Pragma("clang diagnostic push") #define PRAGMA_CLANG(str) _Pragma(str) #define PRAGMA_CLANG_DIAG_POP _Pragma("clang diagnostic pop") @@ -2404,6 +2404,7 @@ WOLFSSL_API word32 CheckRunTimeSettings(void); #define PRAGMA_CLANG_DIAG_POP /* null expansion */ #endif +#ifndef __ti__ #ifndef PRAGMA_DIAG_PUSH #define PRAGMA_DIAG_PUSH /* null expansion */ #endif @@ -2413,6 +2414,7 @@ WOLFSSL_API word32 CheckRunTimeSettings(void); #ifndef PRAGMA_DIAG_POP #define PRAGMA_DIAG_POP /* null expansion */ #endif +#endif /* !__ti__ */ #define WC_CPP_CAT4_(a, b, c, d) a ## b ## c ## d #define WC_CPP_CAT4(a, b, c, d) WC_CPP_CAT4_(a, b, c, d) From 073bb7fd27240e597f21f59f4ae5b9158eb732b3 Mon Sep 17 00:00:00 2001 From: Thomas Cook Date: Mon, 10 Aug 2026 12:34:18 -0400 Subject: [PATCH 02/10] cleanup --- .wolfssl_known_macro_extras | 1 + wolfcrypt/src/include.am | 1 + wolfcrypt/src/port/ti/ti-sa2ul_port.c | 22 +++++++++++----------- wolfssl/wolfcrypt/include.am | 1 + wolfssl/wolfcrypt/port/ti/ti-sa2ul_port.h | 2 +- 5 files changed, 15 insertions(+), 12 deletions(-) diff --git a/.wolfssl_known_macro_extras b/.wolfssl_known_macro_extras index 688602cdc0b..63fe9f236d3 100644 --- a/.wolfssl_known_macro_extras +++ b/.wolfssl_known_macro_extras @@ -1161,6 +1161,7 @@ WOLFSSL_STSAFE_TAKES_SLOT WOLFSSL_TELIT_M2MB WOLFSSL_TEMPLATE_EXAMPLE WOLFSSL_THREADED_CRYPT +WOLFSSL_TI_AM64X WOLFSSL_TICKET_DECRYPT_NO_CREATE WOLFSSL_TICKET_ENC_AES128_GCM WOLFSSL_TICKET_ENC_AES256_CBC diff --git a/wolfcrypt/src/include.am b/wolfcrypt/src/include.am index 6bc3bb40cee..1b1d47d9f65 100644 --- a/wolfcrypt/src/include.am +++ b/wolfcrypt/src/include.am @@ -83,6 +83,7 @@ EXTRA_DIST += wolfcrypt/src/port/ti/ti-aes.c \ wolfcrypt/src/port/ti/ti-ccm.c \ wolfcrypt/src/port/ti/ti-c2000-aes.c \ wolfcrypt/src/port/ti/ti-c2000-entropy.c \ + wolfcrypt/src/port/ti/ti-sa2ul_port.c \ wolfcrypt/src/port/pic32/pic32mz-crypt.c \ wolfcrypt/src/port/nrf51.c \ wolfcrypt/src/port/aria/aria-crypt.c \ diff --git a/wolfcrypt/src/port/ti/ti-sa2ul_port.c b/wolfcrypt/src/port/ti/ti-sa2ul_port.c index 23e7e09a87f..fcfadc28579 100644 --- a/wolfcrypt/src/port/ti/ti-sa2ul_port.c +++ b/wolfcrypt/src/port/ti/ti-sa2ul_port.c @@ -193,7 +193,7 @@ static int ti_sa2ul_AesCbcDecrypt(Aes* aes, byte* out, const byte* in, word32 sz byte tmp_iv[16]; SA2UL_ContextParams_init(&scParams); - + scParams.opType = SA2UL_OP_ENC; scParams.encAlg = SA2UL_ENC_ALG_AES; scParams.encMode = SA2UL_ENC_MODE_CBC; @@ -277,7 +277,7 @@ static int ti_sa2ul_AesEcbDecrypt(Aes* aes, byte* out, const byte* in, word32 sz SA2UL_ContextParams scParams; SA2UL_ContextParams_init(&scParams); - + scParams.opType = SA2UL_OP_ENC; scParams.encAlg = SA2UL_ENC_ALG_AES; scParams.encMode = SA2UL_ENC_MODE_ECB; @@ -398,7 +398,7 @@ static int ti_sa2ul_AesGcmEncrypt(Aes* aes, byte* out, xorbuf(authTag, scratch, authTagSz); } } - + return ret; } @@ -475,7 +475,7 @@ static int ti_sa2ul_AesGcmDecrypt(Aes* aes, byte* out, ret = WC_NO_ERR_TRACE(AES_GCM_AUTH_E); } } - + return ret; } #endif /* HAVE_AES_DECRYPT */ @@ -483,7 +483,7 @@ static int ti_sa2ul_AesGcmDecrypt(Aes* aes, byte* out, #endif /* !NO_AES */ -#if !defined(NO_SHA256) || defined(WOLFSSL_SHA512) +#if !defined(NO_SHA256) || defined(WOLFSSL_SHA512) /* The ti mcu plus sdk sa2ul driver requires an output buffer of at least * the size of the input buffer, and it will write data to it, though we don't * use the data. So, we consider this a scratch buffer, but it also limits @@ -504,7 +504,7 @@ static int ti_sa2ul_InitSha256_ctx(wc_Sha256* sha256) /* default length to all ff's, final will override when known */ scParams.inputLen = 0xffffffffUL; sha256->scObj.totalLengthInBytes = 0xffffffffUL; - + if (SA2UL_contextAlloc(cryptoCtx.drvHandle, &sha256->scObj, &scParams) != SystemP_SUCCESS) { @@ -520,9 +520,9 @@ static int ti_sa2ul_Sha256Free_ctx(wc_Sha256* sha256) { (void)SA2UL_contextFree(&sha256->scObj); XMEMSET(&sha256->scObj, 0, sizeof(sha256->scObj)); - + sa2ul_hash_in_use = 0; - + return 0; } @@ -637,7 +637,7 @@ static int ti_sa2ul_InitSha512_ctx(wc_Sha512* sha512) /* default length to all ff's, final will override when known */ scParams.inputLen = 0xffffffffUL; sha512->scObj.totalLengthInBytes = 0xffffffffUL; - + if (SA2UL_contextAlloc(cryptoCtx.drvHandle, &sha512->scObj, &scParams) != SystemP_SUCCESS) { @@ -650,7 +650,7 @@ static int ti_sa2ul_Sha512Free_ctx(wc_Sha512* sha512) { (void)SA2UL_contextFree(&sha512->scObj); XMEMSET(&sha512->scObj, 0, sizeof(sha512->scObj)); - + return 0; } @@ -924,4 +924,4 @@ int ti_sa2ul_port_init(void) return ret; } -#endif /* WOLFSSL_TI_AM64X */ \ No newline at end of file +#endif /* WOLFSSL_TI_AM64X */ diff --git a/wolfssl/wolfcrypt/include.am b/wolfssl/wolfcrypt/include.am index a24c448a6e7..e68d157836d 100644 --- a/wolfssl/wolfcrypt/include.am +++ b/wolfssl/wolfcrypt/include.am @@ -101,6 +101,7 @@ noinst_HEADERS+= \ wolfssl/wolfcrypt/port/ti/ti-ccm.h \ wolfssl/wolfcrypt/port/ti/ti-c2000.h \ wolfssl/wolfcrypt/port/ti/ti-c2000-entropy.h \ + wolfssl/wolfcrypt/port/ti/ti-sa2ul_port.h \ wolfssl/wolfcrypt/port/nrf51.h \ wolfssl/wolfcrypt/port/nxp/ksdk_port.h \ wolfssl/wolfcrypt/port/nxp/dcp_port.h \ diff --git a/wolfssl/wolfcrypt/port/ti/ti-sa2ul_port.h b/wolfssl/wolfcrypt/port/ti/ti-sa2ul_port.h index e8b1c4cc527..a0fc9d7662d 100644 --- a/wolfssl/wolfcrypt/port/ti/ti-sa2ul_port.h +++ b/wolfssl/wolfcrypt/port/ti/ti-sa2ul_port.h @@ -30,4 +30,4 @@ int ti_sa2ul_port_init(void); #endif /* WOLFSSL_TI_AM64X */ -#endif /* _TI_SA2UL_PORT_H_ */ \ No newline at end of file +#endif /* _TI_SA2UL_PORT_H_ */ From 9cfd3ff4bb0e3eec0cd5da01e725287f7250b439 Mon Sep 17 00:00:00 2001 From: Thomas Cook Date: Mon, 17 Aug 2026 11:00:10 -0400 Subject: [PATCH 03/10] Add support for rng ctr-drbg mode --- wolfcrypt/src/port/ti/ti-sa2ul_port.c | 146 +++++++++++++++++++++- wolfssl/wolfcrypt/aes.h | 2 +- wolfssl/wolfcrypt/port/ti/ti-sa2ul_port.h | 1 + wolfssl/wolfcrypt/settings.h | 4 + 4 files changed, 146 insertions(+), 7 deletions(-) diff --git a/wolfcrypt/src/port/ti/ti-sa2ul_port.c b/wolfcrypt/src/port/ti/ti-sa2ul_port.c index fcfadc28579..010d30789ce 100644 --- a/wolfcrypt/src/port/ti/ti-sa2ul_port.c +++ b/wolfcrypt/src/port/ti/ti-sa2ul_port.c @@ -45,14 +45,51 @@ #include "security/security_common/drivers/crypto/crypto.h" #include "security/security_common/drivers/crypto/rng/rng.h" #include "security/security_common/drivers/crypto/sa2ul/sa2ul.h" +#include "drivers/sciclient.h" +#include "drivers/sciclient/include/tisci/security/tisci_soc_uid.h" static Crypto_Handle handle; static Crypto_Context cryptoCtx XALIGNED(SA2UL_CACHELINE_ALIGNMENT); +static uint32_t socUid[UID_LEN_WORDS]; +static int socUidAvail = 0; + +static int _getSocUid(void) +{ + if (socUidAvail == 0) + { + struct tisci_msg_get_soc_uid_req req = {0}; + const Sciclient_ReqPrm_t reqPrm = + { + TISCI_MSG_GET_SOC_UID, + TISCI_MSG_FLAG_AOP, + (const uint8_t *)&req, + sizeof(req), + SystemP_WAIT_FOREVER + }; + struct tisci_msg_get_soc_uid_resp resp; + Sciclient_RespPrm_t respPrm = + { + 0, + (uint8_t *) &resp, + sizeof(resp) + }; + + if (Sciclient_service(&reqPrm, &respPrm) != SystemP_SUCCESS || + respPrm.flags != TISCI_MSG_FLAG_ACK) + { + return -1; + } + XMEMCPY(socUid, resp.soc_uid, sizeof(socUid)); + socUidAvail = 1; + } + return 0; +} #ifndef WC_NO_RNG #define RNG_NUM_DWORDS (4u) static RNG_Handle rngHandle = NULL; -static void ti_sa2ul_trng_init(void) + +static void ti_sa2ul_trng_init_common(void) { RNG_Handle handle = NULL; if (gRngConfig[0].attrs->isOpen == 0) { @@ -73,7 +110,72 @@ static void ti_sa2ul_trng_init(void) } } -static int ti_sa2ul_trng_get(OS_Seed* os, byte* output, word32 sz) +#ifdef WOLFSSL_TI_AM64X_RNG_CTR_DRBG +static void ti_sa2ul_trng_init_drbg(void) +{ + if (_getSocUid() == 0) { + uint32_t initialSeed[RNG_DRBG_SEED_MAX_ARRY_SIZE_IN_DWORD]; + /* seed is 384 bits, uid is 256 bits, so copy uid 1.5x */ + XMEMCPY(initialSeed, socUid, sizeof(socUid)); + XMEMCPY(&initialSeed[8], socUid, sizeof(initialSeed) - sizeof(socUid)); + gRngConfig[0].attrs->mode = RNG_DRBG_MODE; + gRngConfig[0].attrs->seedValue = initialSeed; + gRngConfig[0].attrs->seedSizeInDwords = + RNG_DRBG_SEED_MAX_ARRY_SIZE_IN_DWORD; + ti_sa2ul_trng_init_common(); + } +} + +static int ti_sa2ul_trng_get_drbg(byte* output, word32 sz) +{ + CSL_Cp_aceTrngRegs *pTrngRegs = (CSL_Cp_aceTrngRegs *)gRngConfig[0].attrs->rngBaseAddr; + + if (output == NULL && sz != 0) + return -1; + + while (sz) { + uint32_t val; + uint32_t random[RNG_NUM_DWORDS]; + uint8_t *ptr = (uint8_t *)random; + int copy_len; + + /* wait for READY==1 (random data ready) */ + do { + val = CSL_REG_RD(&pTrngRegs->TRNG_STATUS); + } while ((val & CSL_CP_ACE_TRNG_STATUS_READY_MASK) != + CSL_CP_ACE_TRNG_STATUS_READY_MASK); + + random[0] = CSL_REG_RD(&pTrngRegs->TRNG_INPUT_0); + random[1] = CSL_REG_RD(&pTrngRegs->TRNG_INPUT_1); + random[2] = CSL_REG_RD(&pTrngRegs->TRNG_INPUT_2); + random[3] = CSL_REG_RD(&pTrngRegs->TRNG_INPUT_3); + /* ack the data read */ + CSL_REG_WR(&pTrngRegs->TRNG_STATUS, CSL_CP_ACE_TRNG_INTACK_READY_ACK_MASK); + + /* kick off next generate request */ + val = CSL_REG_RD(&pTrngRegs->TRNG_CONTROL); + val |= CSL_CP_ACE_TRNG_CONTROL_DATA_BLOCKS_MASK; + val |= CSL_CP_ACE_TRNG_CONTROL_REQUEST_DATA_MASK; + CSL_REG_WR(&pTrngRegs->TRNG_CONTROL, val); + + copy_len = RNG_NUM_DWORDS * 4; + if (sz < copy_len) + copy_len = sz; + XMEMCPY(output, ptr, copy_len); + output += copy_len; + sz -= copy_len; + } + + return 0; +} +#else +static void ti_sa2ul_trng_init_nrbg(void) +{ + gRngConfig[0].attrs->mode = RNG_DRBG_DISABLE_MODE; + ti_sa2ul_trng_init_common(); +} + +static int ti_sa2ul_trng_get_nrbg(byte* output, word32 sz) { if (output == NULL && sz != 0) return -1; @@ -94,6 +196,25 @@ static int ti_sa2ul_trng_get(OS_Seed* os, byte* output, word32 sz) return 0; } +#endif /* WOLFSSL_TI_AM64X_RNG_CTR_DRBG */ + +static void ti_sa2ul_trng_init(void) +{ +#ifdef WOLFSSL_TI_AM64X_RNG_CTR_DRBG + return ti_sa2ul_trng_init_drbg(); +#else + return ti_sa2ul_trng_init_nrbg(); +#endif +} + +static int ti_sa2ul_trng_get(byte* output, word32 sz) +{ +#ifdef WOLFSSL_TI_AM64X_RNG_CTR_DRBG + return ti_sa2ul_trng_get_drbg(output, sz); +#else + return ti_sa2ul_trng_get_nrbg(output, sz); +#endif +} #endif /* WC_NO_RNG */ static void _u8LeToU32(uint32_t *dest, uint8_t *src, uint32_t len) @@ -897,17 +1018,30 @@ static int ti_sa2ul_CryptoDevCb(int devId, wc_CryptoInfo* info, void* devCtx) #endif /* !NO_SHA256 || WOLFSSL_SHA512 */ } #ifndef WC_NO_RNG +# ifdef WOLFSSL_TI_AM64X_RNG_CTR_DRBG + else if (info->algo_type == WC_ALGO_TYPE_RNG) + { + ret = ti_sa2ul_trng_get(info->rng.out, info->rng.sz); + } +# else else if (info->algo_type == WC_ALGO_TYPE_SEED) { - ret = ti_sa2ul_trng_get(info->seed.os, - info->seed.seed, - info->seed.sz); + ret = ti_sa2ul_trng_get(info->seed.seed, info->seed.sz); } -#endif /* WC_NO_RNG */ +# endif +#endif /* !WC_NO_RNG */ return ret; } +void ti_sa2ul_soc_uid(byte* uid) +{ + if (_getSocUid() == 0) + XMEMCPY(uid, socUid, sizeof(socUid)); + else + XMEMSET(uid, 0xFFu, sizeof(socUid)); +} + int ti_sa2ul_port_init(void) { int ret = WC_HW_E; diff --git a/wolfssl/wolfcrypt/aes.h b/wolfssl/wolfcrypt/aes.h index 4be0ea3abe6..9d89e51d7cf 100644 --- a/wolfssl/wolfcrypt/aes.h +++ b/wolfssl/wolfcrypt/aes.h @@ -190,7 +190,7 @@ WOLFSSL_LOCAL void WC_ARG_NOT_NULL(1) GHASH(Gcm* gcm, const byte* a, #endif /* WOLFSSL_PSOC6_CRYPTO */ #ifdef WOLFSSL_TI_AM64X - #include "security/security_common/drivers/crypto/crypto.h" + #include "security/security_common/drivers/crypto/sa2ul/sa2ul.h" #endif /* Backends that replace one or more AES mode entry points, either with a diff --git a/wolfssl/wolfcrypt/port/ti/ti-sa2ul_port.h b/wolfssl/wolfcrypt/port/ti/ti-sa2ul_port.h index a0fc9d7662d..c7c5fe496da 100644 --- a/wolfssl/wolfcrypt/port/ti/ti-sa2ul_port.h +++ b/wolfssl/wolfcrypt/port/ti/ti-sa2ul_port.h @@ -27,6 +27,7 @@ #define WC_USE_DEVID WOLFSSL_TI_SA2UL_DEVID int ti_sa2ul_port_init(void); +void ti_sa2ul_soc_uid(uint8_t *uid); #endif /* WOLFSSL_TI_AM64X */ diff --git a/wolfssl/wolfcrypt/settings.h b/wolfssl/wolfcrypt/settings.h index 83064a33dc4..2154447ab93 100644 --- a/wolfssl/wolfcrypt/settings.h +++ b/wolfssl/wolfcrypt/settings.h @@ -2528,6 +2528,10 @@ #define WOLF_CRYPTO_CB #endif #define WOLFSSL_SHA512_HASHTYPE + #ifdef WOLFSSL_TI_AM64X_RNG_CTR_DRBG + #undef HAVE_HASHDRBG + #define WC_NO_HASHDRBG + #endif #endif #ifdef FREESCALE_LTC_TFM_RSA_4096_ENABLE From f642a241b18d867ca737d6467731e5604c37fee1 Mon Sep 17 00:00:00 2001 From: Thomas Cook Date: Thu, 27 Aug 2026 15:06:26 -0400 Subject: [PATCH 04/10] Refine build switches, add readme. --- .wolfssl_known_macro_extras | 3 ++ wolfcrypt/src/port/ti/README_sa2ul.md | 43 +++++++++++++++++++++++++++ wolfcrypt/src/port/ti/ti-sa2ul_port.c | 16 +++++----- wolfcrypt/src/sha256.c | 2 +- wolfcrypt/src/sha512.c | 2 +- wolfssl/wolfcrypt/aes.h | 2 +- wolfssl/wolfcrypt/sha256.h | 2 +- wolfssl/wolfcrypt/sha512.h | 2 +- 8 files changed, 59 insertions(+), 13 deletions(-) create mode 100644 wolfcrypt/src/port/ti/README_sa2ul.md diff --git a/.wolfssl_known_macro_extras b/.wolfssl_known_macro_extras index 63fe9f236d3..549484c778f 100644 --- a/.wolfssl_known_macro_extras +++ b/.wolfssl_known_macro_extras @@ -1162,6 +1162,9 @@ WOLFSSL_TELIT_M2MB WOLFSSL_TEMPLATE_EXAMPLE WOLFSSL_THREADED_CRYPT WOLFSSL_TI_AM64X +WOLFSSL_TI_AM64X_RNG_CTR_DRBG +WOLFSSL_TI_AM64X_NO_AES +WOLFSSL_TI_AM64X_NO_SHA WOLFSSL_TICKET_DECRYPT_NO_CREATE WOLFSSL_TICKET_ENC_AES128_GCM WOLFSSL_TICKET_ENC_AES256_CBC diff --git a/wolfcrypt/src/port/ti/README_sa2ul.md b/wolfcrypt/src/port/ti/README_sa2ul.md new file mode 100644 index 00000000000..3b8f5438e29 --- /dev/null +++ b/wolfcrypt/src/port/ti/README_sa2ul.md @@ -0,0 +1,43 @@ +# wolfSSL TI SA2UL Hardware Acceleration Port + +wolfSSL supports hardware acceleration on the TI AM6442 via the SA2UL peripheral. + +## SA2UL on the TI AM6442 + +The TI AM6442 is a multi-core SoC, with one dual-core Cortex-A53, two dual-core Cortex-R5F, +a Cortex-M4F, and a dedicated security core based on a Cortex-M3. This support has been +tested on the TMDS64EVM board (rev 101D). + +Basic hardware acceleration supported: +- TRNG (NRBG and CTR-DRBG SP800-90A) +- AES-ECB (128, 256) +- AES-CBC (128, 256) +- AES-GCM (128, 256) +- SHA256, SHA512 +- HMAC-SHA256, HMAC-SHA512 +- CMAC-AES (128, 256) + +Note: The wolfCrypt sa2ul support depends on the TI MCU Plus SDK. wolfBoot has +an example (ti-am64x.config) of how to compile with the MCU Plus SDK. + +### wolfSSL TI AM64x Hardware Acceleration Switches + +To enable all the above, with TRNG in NRBG mode, set the following build switch: + +**`WOLFSSL_TI_AM64X`** + +To change the TRNG to CTR-DRBG mode, then also set this switch: + +**`WOLFSSL_TI_AM64X_RNG_CTR_DRBG`** + +In addition, parts of the hardware acceleration can be disabled (in favor of +wolfCrypt software algorithms), with the following switches: + +**`WOLFSSL_TI_AM64X_NO_AES`** + +**`WOLFSSL_TI_AM64X_NO_SHA`** + +## Support + +For questions please email support@wolfssl.com + diff --git a/wolfcrypt/src/port/ti/ti-sa2ul_port.c b/wolfcrypt/src/port/ti/ti-sa2ul_port.c index 010d30789ce..be7f61a7106 100644 --- a/wolfcrypt/src/port/ti/ti-sa2ul_port.c +++ b/wolfcrypt/src/port/ti/ti-sa2ul_port.c @@ -245,7 +245,7 @@ static void _64byteReverseWords(uint32_t *dest, uint32_t *src, uint32_t len) } } -#ifndef NO_AES +#if !defined(NO_AES) && !defined(WOLFSSL_TI_AM64X_NO_AES) static int check_aes_keylength(word32 keylen) { /* mcuplussdk sa2ul driver only supports key lengths of 128 and 256 */ @@ -601,10 +601,10 @@ static int ti_sa2ul_AesGcmDecrypt(Aes* aes, byte* out, } #endif /* HAVE_AES_DECRYPT */ #endif /* HAVE_AESGCM */ -#endif /* !NO_AES */ +#endif /* !NO_AES && !WOLFSSL_TI_AM64X_NO_AES */ -#if !defined(NO_SHA256) || defined(WOLFSSL_SHA512) +#if !defined(WOLFSSL_TI_AM64X_NO_SHA) && (!defined(NO_SHA256) || defined(WOLFSSL_SHA512)) /* The ti mcu plus sdk sa2ul driver requires an output buffer of at least * the size of the input buffer, and it will write data to it, though we don't * use the data. So, we consider this a scratch buffer, but it also limits @@ -871,7 +871,7 @@ static int ti_sa2ul_Sha512Hash(wc_Sha512* sha512, const byte* in, return ret; } #endif /* WOLFSSL_SHA512 */ -#endif /* !NO_SHA256 || WOLFSSL_SHA512 */ +#endif /* !WOLFSSL_TI_AM64X_NO_SHA && (!NO_SHA256 || WOLFSSL_SHA512) */ static int ti_sa2ul_CryptoDevCb(int devId, wc_CryptoInfo* info, void* devCtx) { @@ -892,7 +892,7 @@ static int ti_sa2ul_CryptoDevCb(int devId, wc_CryptoInfo* info, void* devCtx) if (info->algo_type == WC_ALGO_TYPE_CIPHER) { -#if !defined(NO_AES) +#if !defined(NO_AES) && !defined(WOLFSSL_TI_AM64X_NO_AES) if (0) { /* nothing */ } @@ -986,11 +986,11 @@ static int ti_sa2ul_CryptoDevCb(int devId, wc_CryptoInfo* info, void* devCtx) # endif /* HAVE_AES_DECRYPT */ } # endif /* HAVE_AESGCM */ -#endif /* !NO_AES */ +#endif /* !NO_AES && !WOLFSSL_TI_AM64X_NO_AES */ } else if (info->algo_type == WC_ALGO_TYPE_HASH) { -#if !defined(NO_SHA256) || defined(WOLFSSL_SHA512) +#if !defined(WOLFSSL_TI_AM64X_NO_SHA) && (!defined(NO_SHA256) || defined(WOLFSSL_SHA512)) if (0) { /* nothing */ } @@ -1015,7 +1015,7 @@ static int ti_sa2ul_CryptoDevCb(int devId, wc_CryptoInfo* info, void* devCtx) } } # endif /* WOLFSSL_SHA512 */ -#endif /* !NO_SHA256 || WOLFSSL_SHA512 */ +#endif /* !WOLFSSL_TI_AM64X_NO_SHA && (!NO_SHA256 || WOLFSSL_SHA512) */ } #ifndef WC_NO_RNG # ifdef WOLFSSL_TI_AM64X_RNG_CTR_DRBG diff --git a/wolfcrypt/src/sha256.c b/wolfcrypt/src/sha256.c index 73e9725a088..914626918bd 100644 --- a/wolfcrypt/src/sha256.c +++ b/wolfcrypt/src/sha256.c @@ -346,7 +346,7 @@ static int InitSha256(wc_Sha256* sha256) sha256->hSession = NULL; #endif -#ifdef WOLFSSL_TI_AM64X +#if defined(WOLFSSL_TI_AM64X) && !defined(WOLFSSL_TI_AM64X_NO_SHA) XMEMSET(&sha256->scObj, 0, sizeof(sha256->scObj)); #endif diff --git a/wolfcrypt/src/sha512.c b/wolfcrypt/src/sha512.c index 4fa3f06c2ce..e837e0832b4 100644 --- a/wolfcrypt/src/sha512.c +++ b/wolfcrypt/src/sha512.c @@ -960,7 +960,7 @@ static int InitSha512(wc_Sha512* sha512) sha512->hashType = WC_HASH_TYPE_SHA512; #endif /* WOLFSSL_SHA512_HASHTYPE */ -#ifdef WOLFSSL_TI_AM64X +#if defined(WOLFSSL_TI_AM64X) && !defined(WOLFSSL_TI_AM64X_NO_SHA) XMEMSET(&sha512->scObj, 0, sizeof(sha512->scObj)); #endif return 0; diff --git a/wolfssl/wolfcrypt/aes.h b/wolfssl/wolfcrypt/aes.h index 9d89e51d7cf..0120b1b53ce 100644 --- a/wolfssl/wolfcrypt/aes.h +++ b/wolfssl/wolfcrypt/aes.h @@ -525,7 +525,7 @@ struct Aes { cy_stc_crypto_aes_gcm_state_t aes_gcm_state; #endif #endif /* WOLFSSL_PSOC6_CRYPTO */ -#ifdef WOLFSSL_TI_AM64X +#if defined(WOLFSSL_TI_AM64X) && !defined(WOLFSSL_TI_AM64X_NO_AES) XALIGNED(16) SA2UL_ContextObject scObj; #endif diff --git a/wolfssl/wolfcrypt/sha256.h b/wolfssl/wolfcrypt/sha256.h index 556ec796861..fdf498dbff0 100644 --- a/wolfssl/wolfcrypt/sha256.h +++ b/wolfssl/wolfcrypt/sha256.h @@ -258,7 +258,7 @@ struct wc_Sha256 { #ifdef WOLFSSL_HASH_FLAGS word32 flags; /* enum wc_HashFlags in hash.h */ #endif -#ifdef WOLFSSL_TI_AM64X +#if defined(WOLFSSL_TI_AM64X) && !defined(WOLFSSL_TI_AM64X_NO_SHA) XALIGNED(16) SA2UL_ContextObject scObj; #endif }; diff --git a/wolfssl/wolfcrypt/sha512.h b/wolfssl/wolfcrypt/sha512.h index a03101a6832..9984afd8c03 100644 --- a/wolfssl/wolfcrypt/sha512.h +++ b/wolfssl/wolfcrypt/sha512.h @@ -215,7 +215,7 @@ struct wc_Sha512 { int hashType; /* used to determine which SHA512 is used */ #endif /* WOLFSSL_SHA512_HASHTYPE */ #endif /* WOLFSSL_PSOC6_CRYPTO */ -#ifdef WOLFSSL_TI_AM64X +#if defined(WOLFSSL_TI_AM64X) && !defined(WOLFSSL_TI_AM64X_NO_SHA) XALIGNED(16) SA2UL_ContextObject scObj; #endif }; From ae15e0ea455033c6865255700e84bbc082ad177b Mon Sep 17 00:00:00 2001 From: Thomas Cook Date: Fri, 28 Aug 2026 11:00:53 -0400 Subject: [PATCH 05/10] fix rng --- wolfcrypt/src/port/ti/ti-sa2ul_port.c | 7 ++----- wolfcrypt/src/random.c | 6 ++++-- wolfssl/wolfcrypt/port/ti/ti-sa2ul_port.h | 5 +++++ wolfssl/wolfcrypt/settings.h | 9 +++------ 4 files changed, 14 insertions(+), 13 deletions(-) diff --git a/wolfcrypt/src/port/ti/ti-sa2ul_port.c b/wolfcrypt/src/port/ti/ti-sa2ul_port.c index be7f61a7106..016a5686474 100644 --- a/wolfcrypt/src/port/ti/ti-sa2ul_port.c +++ b/wolfcrypt/src/port/ti/ti-sa2ul_port.c @@ -207,7 +207,7 @@ static void ti_sa2ul_trng_init(void) #endif } -static int ti_sa2ul_trng_get(byte* output, word32 sz) +int ti_sa2ul_trng_get(byte* output, word32 sz) { #ifdef WOLFSSL_TI_AM64X_RNG_CTR_DRBG return ti_sa2ul_trng_get_drbg(output, sz); @@ -215,7 +215,7 @@ static int ti_sa2ul_trng_get(byte* output, word32 sz) return ti_sa2ul_trng_get_nrbg(output, sz); #endif } -#endif /* WC_NO_RNG */ +#endif /* !WC_NO_RNG */ static void _u8LeToU32(uint32_t *dest, uint8_t *src, uint32_t len) { @@ -1018,17 +1018,14 @@ static int ti_sa2ul_CryptoDevCb(int devId, wc_CryptoInfo* info, void* devCtx) #endif /* !WOLFSSL_TI_AM64X_NO_SHA && (!NO_SHA256 || WOLFSSL_SHA512) */ } #ifndef WC_NO_RNG -# ifdef WOLFSSL_TI_AM64X_RNG_CTR_DRBG else if (info->algo_type == WC_ALGO_TYPE_RNG) { ret = ti_sa2ul_trng_get(info->rng.out, info->rng.sz); } -# else else if (info->algo_type == WC_ALGO_TYPE_SEED) { ret = ti_sa2ul_trng_get(info->seed.seed, info->seed.sz); } -# endif #endif /* !WC_NO_RNG */ return ret; diff --git a/wolfcrypt/src/random.c b/wolfcrypt/src/random.c index 1c754b5e851..13704c0f398 100644 --- a/wolfcrypt/src/random.c +++ b/wolfcrypt/src/random.c @@ -233,8 +233,6 @@ This library contains implementation for the random number generator. #include "cyhal_trng.h" /* Infineon/Cypress HAL RNG implementation */ #elif defined(WOLFSSL_MAX3266X) || defined(WOLFSSL_MAX3266X_OLD) #include "wolfssl/wolfcrypt/port/maxim/max3266x.h" -#elif defined(WOLFSSL_TI_AM64X) - #include #elif defined(__ti__) /* ti clang toolchain */ #else #include @@ -248,6 +246,10 @@ This library contains implementation for the random number generator. #endif #endif +#if defined(WOLFSSL_TI_AM64X) + #include +#endif + #if defined(WOLFSSL_SILABS_SE_TYPES) #include #endif diff --git a/wolfssl/wolfcrypt/port/ti/ti-sa2ul_port.h b/wolfssl/wolfcrypt/port/ti/ti-sa2ul_port.h index c7c5fe496da..836a829f44a 100644 --- a/wolfssl/wolfcrypt/port/ti/ti-sa2ul_port.h +++ b/wolfssl/wolfcrypt/port/ti/ti-sa2ul_port.h @@ -26,8 +26,13 @@ #define WOLFSSL_TI_SA2UL_DEVID 8888 #define WC_USE_DEVID WOLFSSL_TI_SA2UL_DEVID +#ifdef WOLFSSL_TI_AM64X_RNG_CTR_DRBG + #define CUSTOM_RAND_GENERATE_BLOCK ti_sa2ul_trng_get +#endif + int ti_sa2ul_port_init(void); void ti_sa2ul_soc_uid(uint8_t *uid); +int ti_sa2ul_trng_get(byte* output, word32 sz); #endif /* WOLFSSL_TI_AM64X */ diff --git a/wolfssl/wolfcrypt/settings.h b/wolfssl/wolfcrypt/settings.h index 2154447ab93..bca00e209ef 100644 --- a/wolfssl/wolfcrypt/settings.h +++ b/wolfssl/wolfcrypt/settings.h @@ -2518,20 +2518,17 @@ #ifdef WOLFSSL_TI_AM64X #define HAVE_AES_ECB - #define WOLFSSL_AES_128 #define NO_AES_192 + #define NO_DEV_RANDOM + #define WOLFSSL_AES_128 #define WOLFSSL_AES_256 #define WOLFSSL_AES_DIRECT #define WOLFSSL_CMAC #define WOLFSSL_SHA512 + #define WOLFSSL_SHA512_HASHTYPE #ifndef WOLF_CRYPTO_CB #define WOLF_CRYPTO_CB #endif - #define WOLFSSL_SHA512_HASHTYPE - #ifdef WOLFSSL_TI_AM64X_RNG_CTR_DRBG - #undef HAVE_HASHDRBG - #define WC_NO_HASHDRBG - #endif #endif #ifdef FREESCALE_LTC_TFM_RSA_4096_ENABLE From ef2dcb4addc76f3fa47de19c52c7d7c349e773d5 Mon Sep 17 00:00:00 2001 From: Thomas Cook Date: Fri, 28 Aug 2026 11:22:37 -0400 Subject: [PATCH 06/10] Add block_size (bench_size) to parseable csv output --- wolfcrypt/benchmark/benchmark.c | 19 +++++++++++++------ 1 file changed, 13 insertions(+), 6 deletions(-) diff --git a/wolfcrypt/benchmark/benchmark.c b/wolfcrypt/benchmark/benchmark.c index d5eec15fcc8..05e1a5a2619 100644 --- a/wolfcrypt/benchmark/benchmark.c +++ b/wolfcrypt/benchmark/benchmark.c @@ -2449,7 +2449,11 @@ static const char* bench_result_words2[][6] = { }; /* how many kB to test (en/de)cryption */ #define NUM_BLOCKS 25 - #define BENCH_SIZE (1024uL) + #ifdef BENCH_SIZE_EMBEDDED + # define BENCH_SIZE BENCH_SIZE_EMBEDDED + #else + # define BENCH_SIZE (1024uL) + #endif #else #ifndef BENCH_NTIMES #define BENCH_NTIMES 100 @@ -3080,7 +3084,7 @@ static void bench_stats_sym_finish(const char* desc, int useDeviceID, #ifdef GENERATE_MACHINE_PARSEABLE_REPORT /* machine parseable CSV */ #ifdef HAVE_GET_CYCLES - printf("%s", "\"sym\",Algorithm,HW/SW,bytes_total," + printf("%s", "\"sym\",Algorithm,HW/SW,block_size,bytes_total," WOLFSSL_FIXED_TIME_UNIT "econds_total," WOLFSSL_FIXED_UNIT "/" WOLFSSL_FIXED_TIME_UNIT ",cycles_total,Cycles per byte," @@ -3092,7 +3096,7 @@ static void bench_stats_sym_finish(const char* desc, int useDeviceID, #endif ); #else - printf("%s", "\"sym\",Algorithm,HW/SW,bytes_total," + printf("%s", "\"sym\",Algorithm,HW/SW,block_size,bytes_total," WOLFSSL_FIXED_TIME_UNIT "econds_total," WOLFSSL_FIXED_UNIT "/" WOLFSSL_FIXED_TIME_UNIT ",cycles_total," @@ -3203,8 +3207,9 @@ static void bench_stats_sym_finish(const char* desc, int useDeviceID, #ifdef WOLFSSL_ESPIDF #ifdef HAVE_GET_CYCLES (void)XSNPRINTF(msg, sizeof(msg), - "sym,%s,%s,%lu," FLT_FMT "," FLT_FMT ",%lu,", desc, + "sym,%s,%s,%lu,%lu," FLT_FMT "," FLT_FMT ",%llu,", desc, BENCH_DEVID_GET_NAME(useDeviceID), + bench_size, bytes_processed, FLT_FMT_ARGS(total), FLT_FMT_ARGS(persec), (long unsigned int) total_cycles); @@ -3217,14 +3222,16 @@ static void bench_stats_sym_finish(const char* desc, int useDeviceID, #else #ifdef HAVE_GET_CYCLES (void)XSNPRINTF(msg, sizeof(msg), - "sym,%s,%s,%lu," FLT_FMT "," FLT_FMT ",%lu,", desc, + "sym,%s,%s,%lu,%llu," FLT_FMT "," FLT_FMT ",%llu,", desc, BENCH_DEVID_GET_NAME(useDeviceID), + bench_size, bytes_processed, FLT_FMT_ARGS(total), FLT_FMT_ARGS(persec), total_cycles); #else (void)XSNPRINTF(msg, sizeof(msg), - "sym,%s,%s,%lu," FLT_FMT "," FLT_FMT ",", desc, + "sym,%s,%s,%lu,%llu," FLT_FMT "," FLT_FMT ",", desc, BENCH_DEVID_GET_NAME(useDeviceID), + bench_size, bytes_processed, FLT_FMT_ARGS(total), FLT_FMT_ARGS(persec)); #endif From 175db412f1aa4ac13f03621e6cb9ef9966b21a96 Mon Sep 17 00:00:00 2001 From: Thomas Cook Date: Fri, 4 Sep 2026 19:16:17 -0400 Subject: [PATCH 07/10] resolve all fenrir issues --- wolfcrypt/src/port/ti/ti-sa2ul_port.c | 187 ++++++++++++++-------- wolfcrypt/src/random.c | 1 - wolfssl/wolfcrypt/aes.h | 2 +- wolfssl/wolfcrypt/port/ti/ti-sa2ul_port.h | 4 + wolfssl/wolfcrypt/settings.h | 1 + wolfssl/wolfcrypt/sha256.h | 2 +- wolfssl/wolfcrypt/sha512.h | 2 +- wolfssl/wolfcrypt/types.h | 5 +- 8 files changed, 133 insertions(+), 71 deletions(-) diff --git a/wolfcrypt/src/port/ti/ti-sa2ul_port.c b/wolfcrypt/src/port/ti/ti-sa2ul_port.c index 016a5686474..fe536d6d4a7 100644 --- a/wolfcrypt/src/port/ti/ti-sa2ul_port.c +++ b/wolfcrypt/src/port/ti/ti-sa2ul_port.c @@ -89,7 +89,7 @@ static int _getSocUid(void) #define RNG_NUM_DWORDS (4u) static RNG_Handle rngHandle = NULL; -static void ti_sa2ul_trng_init_common(void) +static int ti_sa2ul_trng_init_common(void) { RNG_Handle handle = NULL; if (gRngConfig[0].attrs->isOpen == 0) { @@ -108,13 +108,15 @@ static void ti_sa2ul_trng_init_common(void) /* already opened -- use existing handle */ rngHandle = (RNG_Handle)&gRngConfig[0]; } + return rngHandle == NULL; } #ifdef WOLFSSL_TI_AM64X_RNG_CTR_DRBG -static void ti_sa2ul_trng_init_drbg(void) +static uint32_t initialSeed[RNG_DRBG_SEED_MAX_ARRY_SIZE_IN_DWORD]; + +static int ti_sa2ul_trng_init_drbg(void) { if (_getSocUid() == 0) { - uint32_t initialSeed[RNG_DRBG_SEED_MAX_ARRY_SIZE_IN_DWORD]; /* seed is 384 bits, uid is 256 bits, so copy uid 1.5x */ XMEMCPY(initialSeed, socUid, sizeof(socUid)); XMEMCPY(&initialSeed[8], socUid, sizeof(initialSeed) - sizeof(socUid)); @@ -122,8 +124,9 @@ static void ti_sa2ul_trng_init_drbg(void) gRngConfig[0].attrs->seedValue = initialSeed; gRngConfig[0].attrs->seedSizeInDwords = RNG_DRBG_SEED_MAX_ARRY_SIZE_IN_DWORD; - ti_sa2ul_trng_init_common(); + return ti_sa2ul_trng_init_common(); } + return WC_HW_E; } static int ti_sa2ul_trng_get_drbg(byte* output, word32 sz) @@ -169,10 +172,10 @@ static int ti_sa2ul_trng_get_drbg(byte* output, word32 sz) return 0; } #else -static void ti_sa2ul_trng_init_nrbg(void) +static int ti_sa2ul_trng_init_nrbg(void) { gRngConfig[0].attrs->mode = RNG_DRBG_DISABLE_MODE; - ti_sa2ul_trng_init_common(); + return ti_sa2ul_trng_init_common(); } static int ti_sa2ul_trng_get_nrbg(byte* output, word32 sz) @@ -198,7 +201,7 @@ static int ti_sa2ul_trng_get_nrbg(byte* output, word32 sz) } #endif /* WOLFSSL_TI_AM64X_RNG_CTR_DRBG */ -static void ti_sa2ul_trng_init(void) +static int ti_sa2ul_trng_init(void) { #ifdef WOLFSSL_TI_AM64X_RNG_CTR_DRBG return ti_sa2ul_trng_init_drbg(); @@ -271,6 +274,9 @@ static int ti_sa2ul_AesCbcEncrypt(Aes* aes, byte* out, const byte* in, word32 sz int ret = 0; SA2UL_ContextParams scParams; + if (sz == 0 || (sz % WC_AES_BLOCK_SIZE) != 0) + return CRYPTOCB_UNAVAILABLE; + SA2UL_ContextParams_init(&scParams); scParams.opType = SA2UL_OP_ENC; @@ -301,7 +307,7 @@ static int ti_sa2ul_AesCbcEncrypt(Aes* aes, byte* out, const byte* in, word32 sz (void)SA2UL_contextFree(&aes->scObj); - XMEMCPY(aes->reg, out + sz - 16, 16); + XMEMCPY(aes->reg, out + sz - WC_AES_BLOCK_SIZE, WC_AES_BLOCK_SIZE); return ret; } @@ -311,7 +317,10 @@ static int ti_sa2ul_AesCbcDecrypt(Aes* aes, byte* out, const byte* in, word32 sz { int ret = 0; SA2UL_ContextParams scParams; - byte tmp_iv[16]; + byte tmp_iv[WC_AES_BLOCK_SIZE]; + + if (sz == 0) + return CRYPTOCB_UNAVAILABLE; SA2UL_ContextParams_init(&scParams); @@ -336,7 +345,7 @@ static int ti_sa2ul_AesCbcDecrypt(Aes* aes, byte* out, const byte* in, word32 sz return WC_HW_E; } - XMEMCPY(tmp_iv, in + sz - 16, 16); + XMEMCPY(tmp_iv, in + sz - WC_AES_BLOCK_SIZE, WC_AES_BLOCK_SIZE); CacheP_wbInv((void *)in, sz, CacheP_TYPE_ALLD); @@ -345,7 +354,7 @@ static int ti_sa2ul_AesCbcDecrypt(Aes* aes, byte* out, const byte* in, word32 sz (void)SA2UL_contextFree(&aes->scObj); - XMEMCPY(aes->reg, tmp_iv, 16); + XMEMCPY(aes->reg, tmp_iv, WC_AES_BLOCK_SIZE); return ret; } @@ -468,7 +477,9 @@ static int ti_sa2ul_AesGcmEncrypt(Aes* aes, byte* out, scParams.encKeySize = SA2UL_ENC_KEYSIZE_256; } XMEMCPY(scParams.key, aes->devKey, aes->keylen); - XMEMCPY(scParams.iv, iv, ivSz); + if (ivSz == GCM_NONCE_MID_SZ) { + XMEMCPY(scParams.iv, iv, GCM_NONCE_MID_SZ); + } XMEMCPY(scParams.ghash, aes->gcm.H, WC_AES_BLOCK_SIZE); if (authInSz <= sizeof(scParams.aad)) { XMEMCPY(scParams.aad, authIn, authInSz); @@ -497,7 +508,7 @@ static int ti_sa2ul_AesGcmEncrypt(Aes* aes, byte* out, (void)SA2UL_contextFree(&aes->scObj); - if (authTag) { + if (ret == 0 && authTag != NULL) { if (authInSz <= sizeof(scParams.aad)) { XMEMCPY(authTag, aes->scObj.computedHash, authTagSz); } @@ -516,7 +527,8 @@ static int ti_sa2ul_AesGcmEncrypt(Aes* aes, byte* out, XMEMCPY(initialCounter, aes->scObj.ctxPrms.iv, WC_AES_BLOCK_SIZE); } ret = wc_AesEncryptDirect(aes, scratch, initialCounter); - xorbuf(authTag, scratch, authTagSz); + if (ret == 0) + xorbuf(authTag, scratch, authTagSz); } } @@ -546,10 +558,17 @@ static int ti_sa2ul_AesGcmDecrypt(Aes* aes, byte* out, scParams.encKeySize = SA2UL_ENC_KEYSIZE_256; } XMEMCPY(scParams.key, aes->devKey, aes->keylen); - XMEMCPY(scParams.iv, iv, ivSz); + if (ivSz == GCM_NONCE_MID_SZ) { + XMEMCPY(scParams.iv, iv, GCM_NONCE_MID_SZ); + } XMEMCPY(scParams.ghash, aes->gcm.H, WC_AES_BLOCK_SIZE); - XMEMCPY(scParams.aad, authIn, authInSz); - scParams.aadLen = authInSz; + if (authInSz <= sizeof(scParams.aad)) { + XMEMCPY(scParams.aad, authIn, authInSz); + scParams.aadLen = authInSz; + } + else { + scParams.aadLen = 0; + } scParams.inputLen = sz; aes->scObj.totalLengthInBytes = sz; @@ -570,9 +589,9 @@ static int ti_sa2ul_AesGcmDecrypt(Aes* aes, byte* out, (void)SA2UL_contextFree(&aes->scObj); - if (authTag) { + if (ret == 0 && authTag != NULL) { if (authInSz <= sizeof(scParams.aad)) { - if (XMEMCMP(authTag, aes->scObj.computedHash, authTagSz) != 0) + if (ConstantCompare(authTag, aes->scObj.computedHash, authTagSz) != 0) ret = WC_NO_ERR_TRACE(AES_GCM_AUTH_E); } else { @@ -591,9 +610,11 @@ static int ti_sa2ul_AesGcmDecrypt(Aes* aes, byte* out, XMEMCPY(initialCounter, aes->scObj.ctxPrms.iv, WC_AES_BLOCK_SIZE); } ret = wc_AesEncryptDirect(aes, scratch, initialCounter); - xorbuf(Tprime, scratch, sizeof(Tprime)); - if (XMEMCMP(authTag, Tprime, authTagSz) != 0) - ret = WC_NO_ERR_TRACE(AES_GCM_AUTH_E); + if (ret == 0) { + xorbuf(Tprime, scratch, sizeof(Tprime)); + if (ConstantCompare(authTag, Tprime, authTagSz) != 0) + ret = WC_NO_ERR_TRACE(AES_GCM_AUTH_E); + } } } @@ -647,6 +668,26 @@ static int ti_sa2ul_Sha256Free_ctx(wc_Sha256* sha256) return 0; } +static int ti_sa2ul_Sha256Teardown(wc_Sha256* sha256) +{ + /* hash will be finalized in sw via fallback, but we need the driver + * to tear down the context in hw. To do that, we update the context + * length and push some final arbitrary data. It will not affect + * the hash */ + if (sha256->scObj.txBytesCnt != 0) { + byte buffer[WC_SHA256_DIGEST_SIZE]; + sha256->scObj.ctxPrms.inputLen = sha256->scObj.txBytesCnt + + WC_SHA256_DIGEST_SIZE; + sha256->scObj.totalLengthInBytes = sha256->scObj.txBytesCnt + + WC_SHA256_DIGEST_SIZE; + CacheP_wbInv((void *)buffer, WC_SHA256_DIGEST_SIZE, CacheP_TYPE_ALLD); + SA2UL_contextProcess(&sha256->scObj, buffer, + WC_SHA256_DIGEST_SIZE, hash_scratch); + (void)ti_sa2ul_Sha256Free_ctx(sha256); + } + return 0; +} + static int ti_sa2ul_Sha256Hash(wc_Sha256* sha256, const byte* in, word32 inSz, byte* digest) { @@ -722,23 +763,8 @@ static int ti_sa2ul_Sha256Hash(wc_Sha256* sha256, const byte* in, } else if (digest != NULL) { /* final... */ - /* hash will be finalized in sw via fallback, but we need the driver - * to tear down the context in hw. To do that, we update the context - * length and push some final arbitrary data. It will not affect - * the hash */ - if (sha256->scObj.txBytesCnt != 0) { - sha256->scObj.ctxPrms.inputLen = sha256->scObj.txBytesCnt + - WC_SHA256_DIGEST_SIZE; - sha256->scObj.totalLengthInBytes = sha256->scObj.txBytesCnt + - WC_SHA256_DIGEST_SIZE; - CacheP_wbInv((void *)buffer, WC_SHA256_DIGEST_SIZE, CacheP_TYPE_ALLD); - if (SA2UL_contextProcess(&sha256->scObj, buffer, - WC_SHA256_DIGEST_SIZE, hash_scratch) != SystemP_SUCCESS) - { - ret = WC_HW_E; - } - (void)ti_sa2ul_Sha256Free_ctx(sha256); - } + (void)ti_sa2ul_Sha256Teardown(sha256); + /* hash will be finalized in sw via fallback */ ret = CRYPTOCB_UNAVAILABLE; /* fall back to sw */ } @@ -764,6 +790,9 @@ static int ti_sa2ul_InitSha512_ctx(wc_Sha512* sha512) { return WC_HW_E; } + + sa2ul_hash_in_use = 1; + return 0; } @@ -772,6 +801,28 @@ static int ti_sa2ul_Sha512Free_ctx(wc_Sha512* sha512) (void)SA2UL_contextFree(&sha512->scObj); XMEMSET(&sha512->scObj, 0, sizeof(sha512->scObj)); + sa2ul_hash_in_use = 0; + + return 0; +} + +static int ti_sa2ul_Sha512Teardown(wc_Sha512* sha512) +{ + /* hash will be finalized in sw via fallback, but we need the driver + * to tear down the context in hw. To do that, we update the context + * length and push some final arbitrary data. It will not affect + * the hash */ + if (sha512->scObj.txBytesCnt != 0) { + byte buffer[WC_SHA512_DIGEST_SIZE]; + sha512->scObj.ctxPrms.inputLen = sha512->scObj.txBytesCnt + + WC_SHA512_DIGEST_SIZE; + sha512->scObj.totalLengthInBytes = sha512->scObj.txBytesCnt + + WC_SHA512_DIGEST_SIZE; + CacheP_wbInv((void *)buffer, WC_SHA512_DIGEST_SIZE, CacheP_TYPE_ALLD); + SA2UL_contextProcess(&sha512->scObj, buffer, + WC_SHA512_DIGEST_SIZE, hash_scratch); + (void)ti_sa2ul_Sha512Free_ctx(sha512); + } return 0; } @@ -849,22 +900,8 @@ static int ti_sa2ul_Sha512Hash(wc_Sha512* sha512, const byte* in, } else if (digest != NULL) { /* final... */ - /* hash will be finalized in sw via fallback, but we need the driver - * to tear down the context in hw. To do that, we update the context - * length and push some final arbitrary data. It will not affect - * the hash */ - if (sha512->scObj.txBytesCnt != 0) { - sha512->scObj.ctxPrms.inputLen = sha512->scObj.txBytesCnt + - WC_SHA512_DIGEST_SIZE; - sha512->scObj.totalLengthInBytes = sha512->scObj.txBytesCnt + - WC_SHA512_DIGEST_SIZE; - CacheP_wbInv((void *)buffer, WC_SHA512_DIGEST_SIZE, CacheP_TYPE_ALLD); - if (SA2UL_contextProcess(&sha512->scObj, buffer, - WC_SHA512_DIGEST_SIZE, hash_scratch) != SystemP_SUCCESS) { - ret = WC_HW_E; - } - (void)ti_sa2ul_Sha512Free_ctx(sha512); - } + (void)ti_sa2ul_Sha512Teardown(sha512); + /* hash will be finalized in sw via fallback */ ret = CRYPTOCB_UNAVAILABLE; /* fall back to sw */ } @@ -1017,16 +1054,35 @@ static int ti_sa2ul_CryptoDevCb(int devId, wc_CryptoInfo* info, void* devCtx) # endif /* WOLFSSL_SHA512 */ #endif /* !WOLFSSL_TI_AM64X_NO_SHA && (!NO_SHA256 || WOLFSSL_SHA512) */ } -#ifndef WC_NO_RNG - else if (info->algo_type == WC_ALGO_TYPE_RNG) - { - ret = ti_sa2ul_trng_get(info->rng.out, info->rng.sz); - } - else if (info->algo_type == WC_ALGO_TYPE_SEED) +#ifdef WOLF_CRYPTO_CB_FREE + else if (info->algo_type == WC_ALGO_TYPE_FREE) { - ret = ti_sa2ul_trng_get(info->seed.seed, info->seed.sz); +# if !defined(WOLFSSL_TI_AM64X_NO_SHA) && (!defined(NO_SHA256) || defined(WOLFSSL_SHA512)) + if (info->free.algo == WC_ALGO_TYPE_HASH) { + if (0) { + /* nothing */ + } +# ifndef NO_SHA256 + else if (info->free.type == WC_HASH_TYPE_SHA256) { + wc_Sha256* sha256 = (wc_Sha256*)info->free.obj; + if ((sha256->flags & WC_HASH_FLAG_ISCOPY) == 0) { + ret = ti_sa2ul_Sha256Teardown(sha256); + } + } +# endif /* !NO_SHA256 */ +# ifdef WOLFSSL_SHA512 + else if (info->free.type == WC_HASH_TYPE_SHA512) { + wc_Sha512* sha512 = (wc_Sha512*)info->free.obj; + if (sha512->hashType == WC_HASH_TYPE_SHA512 && + (sha512->flags & WC_HASH_FLAG_ISCOPY) == 0) { + ret = ti_sa2ul_Sha512Teardown(sha512); + } + } +# endif /* WOLFSSL_SHA512 */ + } +# endif /* !WOLFSSL_TI_AM64X_NO_SHA && (!NO_SHA256 || WOLFSSL_SHA512) */ } -#endif /* !WC_NO_RNG */ +#endif /* WOLF_CRYPTO_CB_FREE */ return ret; } @@ -1044,8 +1100,9 @@ int ti_sa2ul_port_init(void) int ret = WC_HW_E; #ifndef WC_NO_RNG - ti_sa2ul_trng_init(); -#endif /* WC_NO_RNG */ + if (ti_sa2ul_trng_init() != 0) + return ret; +#endif handle = Crypto_open(&cryptoCtx); if (handle != NULL) { diff --git a/wolfcrypt/src/random.c b/wolfcrypt/src/random.c index 13704c0f398..79475aebb6d 100644 --- a/wolfcrypt/src/random.c +++ b/wolfcrypt/src/random.c @@ -233,7 +233,6 @@ This library contains implementation for the random number generator. #include "cyhal_trng.h" /* Infineon/Cypress HAL RNG implementation */ #elif defined(WOLFSSL_MAX3266X) || defined(WOLFSSL_MAX3266X_OLD) #include "wolfssl/wolfcrypt/port/maxim/max3266x.h" -#elif defined(__ti__) /* ti clang toolchain */ #else #include #if defined(WOLFSSL_GETRANDOM) || defined(HAVE_GETRANDOM) diff --git a/wolfssl/wolfcrypt/aes.h b/wolfssl/wolfcrypt/aes.h index 0120b1b53ce..db933e4d42e 100644 --- a/wolfssl/wolfcrypt/aes.h +++ b/wolfssl/wolfcrypt/aes.h @@ -526,7 +526,7 @@ struct Aes { #endif #endif /* WOLFSSL_PSOC6_CRYPTO */ #if defined(WOLFSSL_TI_AM64X) && !defined(WOLFSSL_TI_AM64X_NO_AES) - XALIGNED(16) SA2UL_ContextObject scObj; + XALIGNED(SA2UL_CACHELINE_ALIGNMENT) SA2UL_ContextObject scObj; #endif /* Set to 1 once a key has been installed (wc_AesSetKey/SetKeyDirect/ diff --git a/wolfssl/wolfcrypt/port/ti/ti-sa2ul_port.h b/wolfssl/wolfcrypt/port/ti/ti-sa2ul_port.h index 836a829f44a..1b1553f5a93 100644 --- a/wolfssl/wolfcrypt/port/ti/ti-sa2ul_port.h +++ b/wolfssl/wolfcrypt/port/ti/ti-sa2ul_port.h @@ -23,11 +23,15 @@ #if defined(WOLFSSL_TI_AM64X) +#include "security/security_common/drivers/crypto/sa2ul/sa2ul.h" + #define WOLFSSL_TI_SA2UL_DEVID 8888 #define WC_USE_DEVID WOLFSSL_TI_SA2UL_DEVID #ifdef WOLFSSL_TI_AM64X_RNG_CTR_DRBG #define CUSTOM_RAND_GENERATE_BLOCK ti_sa2ul_trng_get +#else + #define CUSTOM_RAND_GENERATE_SEED ti_sa2ul_trng_get #endif int ti_sa2ul_port_init(void); diff --git a/wolfssl/wolfcrypt/settings.h b/wolfssl/wolfcrypt/settings.h index bca00e209ef..a5ce11f48bf 100644 --- a/wolfssl/wolfcrypt/settings.h +++ b/wolfssl/wolfcrypt/settings.h @@ -2529,6 +2529,7 @@ #ifndef WOLF_CRYPTO_CB #define WOLF_CRYPTO_CB #endif + #define WOLF_CRYPTO_CB_FREE #endif #ifdef FREESCALE_LTC_TFM_RSA_4096_ENABLE diff --git a/wolfssl/wolfcrypt/sha256.h b/wolfssl/wolfcrypt/sha256.h index fdf498dbff0..e023e11f7d6 100644 --- a/wolfssl/wolfcrypt/sha256.h +++ b/wolfssl/wolfcrypt/sha256.h @@ -259,7 +259,7 @@ struct wc_Sha256 { word32 flags; /* enum wc_HashFlags in hash.h */ #endif #if defined(WOLFSSL_TI_AM64X) && !defined(WOLFSSL_TI_AM64X_NO_SHA) - XALIGNED(16) SA2UL_ContextObject scObj; + XALIGNED(SA2UL_CACHELINE_ALIGNMENT) SA2UL_ContextObject scObj; #endif }; diff --git a/wolfssl/wolfcrypt/sha512.h b/wolfssl/wolfcrypt/sha512.h index 9984afd8c03..e81d1f63c47 100644 --- a/wolfssl/wolfcrypt/sha512.h +++ b/wolfssl/wolfcrypt/sha512.h @@ -216,7 +216,7 @@ struct wc_Sha512 { #endif /* WOLFSSL_SHA512_HASHTYPE */ #endif /* WOLFSSL_PSOC6_CRYPTO */ #if defined(WOLFSSL_TI_AM64X) && !defined(WOLFSSL_TI_AM64X_NO_SHA) - XALIGNED(16) SA2UL_ContextObject scObj; + XALIGNED(SA2UL_CACHELINE_ALIGNMENT) SA2UL_ContextObject scObj; #endif }; diff --git a/wolfssl/wolfcrypt/types.h b/wolfssl/wolfcrypt/types.h index b4ac9b8a9d3..aab8483bbc8 100644 --- a/wolfssl/wolfcrypt/types.h +++ b/wolfssl/wolfcrypt/types.h @@ -2404,17 +2404,18 @@ WOLFSSL_API word32 CheckRunTimeSettings(void); #define PRAGMA_CLANG_DIAG_POP /* null expansion */ #endif -#ifndef __ti__ #ifndef PRAGMA_DIAG_PUSH #define PRAGMA_DIAG_PUSH /* null expansion */ #endif #ifndef PRAGMA +/* for ti, PRAGMA is defined in the mcu plus sdk... */ +# if !(defined(__ti__) && defined(TI_MCU_PLUS_SDK)) #define PRAGMA(str) /* null expansion */ +# endif #endif #ifndef PRAGMA_DIAG_POP #define PRAGMA_DIAG_POP /* null expansion */ #endif -#endif /* !__ti__ */ #define WC_CPP_CAT4_(a, b, c, d) a ## b ## c ## d #define WC_CPP_CAT4(a, b, c, d) WC_CPP_CAT4_(a, b, c, d) From 3ca1833ae7ac9e574cd42b4d9fd1c977750583a7 Mon Sep 17 00:00:00 2001 From: Thomas Cook Date: Mon, 28 Sep 2026 12:14:59 -0400 Subject: [PATCH 08/10] Misc cleanup --- .wolfssl_known_macro_extras | 2 +- wolfcrypt/benchmark/benchmark.c | 4 +- wolfcrypt/src/aes.c | 4 +- wolfcrypt/src/include.am | 2 +- wolfcrypt/src/port/ti/README_sa2ul.md | 2 +- .../{ti-sa2ul_port.c => ti-sa2ul_r5_port.c} | 256 ++++++++++-------- wolfcrypt/src/random.c | 4 +- wolfcrypt/src/sha256.c | 12 +- wolfcrypt/src/sha512.c | 11 +- wolfcrypt/src/wc_port.c | 6 +- wolfcrypt/test/test.c | 4 +- wolfssl/wolfcrypt/aes.h | 4 +- wolfssl/wolfcrypt/include.am | 2 +- .../{ti-sa2ul_port.h => ti-sa2ul_r5_port.h} | 16 +- wolfssl/wolfcrypt/settings.h | 2 +- wolfssl/wolfcrypt/sha256.h | 4 +- wolfssl/wolfcrypt/sha512.h | 4 +- 17 files changed, 186 insertions(+), 153 deletions(-) rename wolfcrypt/src/port/ti/{ti-sa2ul_port.c => ti-sa2ul_r5_port.c} (83%) rename wolfssl/wolfcrypt/port/ti/{ti-sa2ul_port.h => ti-sa2ul_r5_port.h} (77%) diff --git a/.wolfssl_known_macro_extras b/.wolfssl_known_macro_extras index 549484c778f..ac0af31a04f 100644 --- a/.wolfssl_known_macro_extras +++ b/.wolfssl_known_macro_extras @@ -1161,7 +1161,7 @@ WOLFSSL_STSAFE_TAKES_SLOT WOLFSSL_TELIT_M2MB WOLFSSL_TEMPLATE_EXAMPLE WOLFSSL_THREADED_CRYPT -WOLFSSL_TI_AM64X +WOLFSSL_TI_AM64X_R5 WOLFSSL_TI_AM64X_RNG_CTR_DRBG WOLFSSL_TI_AM64X_NO_AES WOLFSSL_TI_AM64X_NO_SHA diff --git a/wolfcrypt/benchmark/benchmark.c b/wolfcrypt/benchmark/benchmark.c index 05e1a5a2619..9da2f3fd892 100644 --- a/wolfcrypt/benchmark/benchmark.c +++ b/wolfcrypt/benchmark/benchmark.c @@ -222,8 +222,8 @@ #endif #endif -#ifdef WOLFSSL_TI_AM64X - #include +#ifdef WOLFSSL_TI_AM64X_R5 + #include #endif #ifdef WOLFSSL_ASYNC_CRYPT diff --git a/wolfcrypt/src/aes.c b/wolfcrypt/src/aes.c index fbcfc29c5be..500c2d973a7 100644 --- a/wolfcrypt/src/aes.c +++ b/wolfcrypt/src/aes.c @@ -3713,7 +3713,7 @@ WC_ALL_ARGS_NOT_NULL static WARN_UNUSED_RESULT int wc_AesEncrypt( outBlock, (unsigned int)keySize); } #endif -#if (defined(WOLFSSL_TI_AM64X) || defined(MAX3266X_CB)) && defined(HAVE_AES_ECB) +#if (defined(WOLFSSL_TI_AM64X_R5) || defined(MAX3266X_CB)) && defined(HAVE_AES_ECB) #ifndef WOLF_CRYPTO_CB_FIND if (aes->devId != INVALID_DEVID) #endif @@ -4560,7 +4560,7 @@ WC_ALL_ARGS_NOT_NULL static WARN_UNUSED_RESULT int wc_AesDecrypt( } #endif -#if (defined(WOLFSSL_TI_AM64X) || defined(MAX3266X_CB)) && defined(HAVE_AES_ECB) +#if (defined(WOLFSSL_TI_AM64X_R5) || defined(MAX3266X_CB)) && defined(HAVE_AES_ECB) #ifndef WOLF_CRYPTO_CB_FIND if (aes->devId != INVALID_DEVID) #endif diff --git a/wolfcrypt/src/include.am b/wolfcrypt/src/include.am index 1b1d47d9f65..4b116a014cd 100644 --- a/wolfcrypt/src/include.am +++ b/wolfcrypt/src/include.am @@ -83,7 +83,7 @@ EXTRA_DIST += wolfcrypt/src/port/ti/ti-aes.c \ wolfcrypt/src/port/ti/ti-ccm.c \ wolfcrypt/src/port/ti/ti-c2000-aes.c \ wolfcrypt/src/port/ti/ti-c2000-entropy.c \ - wolfcrypt/src/port/ti/ti-sa2ul_port.c \ + wolfcrypt/src/port/ti/ti-sa2ul_r5_port.c \ wolfcrypt/src/port/pic32/pic32mz-crypt.c \ wolfcrypt/src/port/nrf51.c \ wolfcrypt/src/port/aria/aria-crypt.c \ diff --git a/wolfcrypt/src/port/ti/README_sa2ul.md b/wolfcrypt/src/port/ti/README_sa2ul.md index 3b8f5438e29..03a8ea5f588 100644 --- a/wolfcrypt/src/port/ti/README_sa2ul.md +++ b/wolfcrypt/src/port/ti/README_sa2ul.md @@ -24,7 +24,7 @@ an example (ti-am64x.config) of how to compile with the MCU Plus SDK. To enable all the above, with TRNG in NRBG mode, set the following build switch: -**`WOLFSSL_TI_AM64X`** +**`WOLFSSL_TI_AM64X_R5`** To change the TRNG to CTR-DRBG mode, then also set this switch: diff --git a/wolfcrypt/src/port/ti/ti-sa2ul_port.c b/wolfcrypt/src/port/ti/ti-sa2ul_r5_port.c similarity index 83% rename from wolfcrypt/src/port/ti/ti-sa2ul_port.c rename to wolfcrypt/src/port/ti/ti-sa2ul_r5_port.c index fe536d6d4a7..1c22eb70a51 100644 --- a/wolfcrypt/src/port/ti/ti-sa2ul_port.c +++ b/wolfcrypt/src/port/ti/ti-sa2ul_r5_port.c @@ -1,4 +1,4 @@ -/* ti-sa2ul_port.c +/* ti-sa2ul_r5_port.c * * Copyright (C) 2006-2026 wolfSSL Inc. * @@ -19,10 +19,9 @@ * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1335, USA */ - #include -#if defined(WOLFSSL_TI_AM64X) +#if defined(WOLFSSL_TI_AM64X_R5) #ifndef WOLF_CRYPTO_CB #error WOLFSSL_TI_SA2UL support requires ./configure --enable-cryptocb or WOLF_CRYPTO_CB to be defined @@ -31,7 +30,7 @@ #include #include #include -#include +#include #ifdef NO_INLINE #include @@ -274,8 +273,14 @@ static int ti_sa2ul_AesCbcEncrypt(Aes* aes, byte* out, const byte* in, word32 sz int ret = 0; SA2UL_ContextParams scParams; - if (sz == 0 || (sz % WC_AES_BLOCK_SIZE) != 0) - return CRYPTOCB_UNAVAILABLE; + if (aes == NULL) + return BAD_FUNC_ARG; + if (check_aes_keylength(aes->keylen) != 0) + return CRYPTOCB_UNAVAILABLE; /* fall back to sw */ + if (sz == 0) + return 0; + if ((sz % WC_AES_BLOCK_SIZE) != 0) + return BAD_FUNC_ARG; SA2UL_ContextParams_init(&scParams); @@ -319,8 +324,14 @@ static int ti_sa2ul_AesCbcDecrypt(Aes* aes, byte* out, const byte* in, word32 sz SA2UL_ContextParams scParams; byte tmp_iv[WC_AES_BLOCK_SIZE]; + if (aes == NULL) + return BAD_FUNC_ARG; + if (check_aes_keylength(aes->keylen) != 0) + return CRYPTOCB_UNAVAILABLE; /* fall back to sw */ if (sz == 0) - return CRYPTOCB_UNAVAILABLE; + return 0; + if ((sz % WC_AES_BLOCK_SIZE) != 0) + return BAD_FUNC_ARG; SA2UL_ContextParams_init(&scParams); @@ -367,6 +378,15 @@ static int ti_sa2ul_AesEcbEncrypt(Aes* aes, byte* out, const byte* in, word32 sz int ret = 0; SA2UL_ContextParams scParams; + if (aes == NULL) + return BAD_FUNC_ARG; + if (check_aes_keylength(aes->keylen) != 0) + return CRYPTOCB_UNAVAILABLE; /* fall back to sw */ + if (sz == 0) + return 0; + if ((sz % WC_AES_BLOCK_SIZE) != 0) + return BAD_FUNC_ARG; + SA2UL_ContextParams_init(&scParams); scParams.opType = SA2UL_OP_ENC; @@ -406,6 +426,15 @@ static int ti_sa2ul_AesEcbDecrypt(Aes* aes, byte* out, const byte* in, word32 sz int ret = 0; SA2UL_ContextParams scParams; + if (aes == NULL) + return BAD_FUNC_ARG; + if (check_aes_keylength(aes->keylen) != 0) + return CRYPTOCB_UNAVAILABLE; /* fall back to sw */ + if (sz == 0) + return 0; + if ((sz % WC_AES_BLOCK_SIZE) != 0) + return BAD_FUNC_ARG; + SA2UL_ContextParams_init(&scParams); scParams.opType = SA2UL_OP_ENC; @@ -464,6 +493,13 @@ static int ti_sa2ul_AesGcmEncrypt(Aes* aes, byte* out, int ret = 0; SA2UL_ContextParams scParams; + if (aes == NULL) + return BAD_FUNC_ARG; + if (check_aes_keylength(aes->keylen) != 0) + return CRYPTOCB_UNAVAILABLE; + if (sz == 0 || (sz % WC_AES_BLOCK_SIZE) != 0) + return CRYPTOCB_UNAVAILABLE; + SA2UL_ContextParams_init(&scParams); scParams.opType = SA2UL_OP_ENC; @@ -545,6 +581,13 @@ static int ti_sa2ul_AesGcmDecrypt(Aes* aes, byte* out, int ret = 0; SA2UL_ContextParams scParams; + if (aes == NULL) + return BAD_FUNC_ARG; + if (check_aes_keylength(aes->keylen) != 0) + return CRYPTOCB_UNAVAILABLE; + if (sz == 0 || (sz % WC_AES_BLOCK_SIZE) != 0) + return CRYPTOCB_UNAVAILABLE; + SA2UL_ContextParams_init(&scParams); scParams.opType = SA2UL_OP_ENC; @@ -658,34 +701,35 @@ static int ti_sa2ul_InitSha256_ctx(wc_Sha256* sha256) return 0; } -static int ti_sa2ul_Sha256Free_ctx(wc_Sha256* sha256) +static void ti_sa2ul_Sha256Free_ctx(wc_Sha256* sha256) { (void)SA2UL_contextFree(&sha256->scObj); - XMEMSET(&sha256->scObj, 0, sizeof(sha256->scObj)); sa2ul_hash_in_use = 0; - - return 0; } -static int ti_sa2ul_Sha256Teardown(wc_Sha256* sha256) +void ti_sa2ul_Sha256Teardown(wc_Sha256* sha256) { - /* hash will be finalized in sw via fallback, but we need the driver - * to tear down the context in hw. To do that, we update the context - * length and push some final arbitrary data. It will not affect - * the hash */ - if (sha256->scObj.txBytesCnt != 0) { - byte buffer[WC_SHA256_DIGEST_SIZE]; - sha256->scObj.ctxPrms.inputLen = sha256->scObj.txBytesCnt + - WC_SHA256_DIGEST_SIZE; - sha256->scObj.totalLengthInBytes = sha256->scObj.txBytesCnt + - WC_SHA256_DIGEST_SIZE; - CacheP_wbInv((void *)buffer, WC_SHA256_DIGEST_SIZE, CacheP_TYPE_ALLD); - SA2UL_contextProcess(&sha256->scObj, buffer, - WC_SHA256_DIGEST_SIZE, hash_scratch); - (void)ti_sa2ul_Sha256Free_ctx(sha256); + if (sha256 != NULL) { + /* hash will be finalized in sw via fallback, but we need the driver + * to tear down the context in hw. To do that, we update the context + * length and push some final arbitrary data. It will not affect + * the hash */ + if ((sha256->flags & WC_HASH_FLAG_ISCOPY) == 0 && + sha256->scObj.txBytesCnt != 0) + { + byte buffer[WC_SHA256_DIGEST_SIZE]; + sha256->scObj.ctxPrms.inputLen = sha256->scObj.txBytesCnt + + WC_SHA256_DIGEST_SIZE; + sha256->scObj.totalLengthInBytes = sha256->scObj.txBytesCnt + + WC_SHA256_DIGEST_SIZE; + CacheP_wbInv((void *)buffer, WC_SHA256_DIGEST_SIZE, CacheP_TYPE_ALLD); + SA2UL_contextProcess(&sha256->scObj, buffer, + WC_SHA256_DIGEST_SIZE, hash_scratch); + ti_sa2ul_Sha256Free_ctx(sha256); + } + XMEMSET(&sha256->scObj, 0, sizeof(sha256->scObj)); } - return 0; } static int ti_sa2ul_Sha256Hash(wc_Sha256* sha256, const byte* in, @@ -697,8 +741,9 @@ static int ti_sa2ul_Sha256Hash(wc_Sha256* sha256, const byte* in, word32 partialLen; if (in == NULL && digest == NULL) - return WC_HW_E; - + return BAD_FUNC_ARG; + if ((sha256->flags & WC_HASH_FLAG_ISCOPY) != 0) + return CRYPTOCB_UNAVAILABLE; if (sha256->scObj.txBytesCnt == 0 && sa2ul_hash_in_use == 1) { sha256->flags |= WC_HASH_FLAG_ISCOPY; return CRYPTOCB_UNAVAILABLE; @@ -763,7 +808,7 @@ static int ti_sa2ul_Sha256Hash(wc_Sha256* sha256, const byte* in, } else if (digest != NULL) { /* final... */ - (void)ti_sa2ul_Sha256Teardown(sha256); + ti_sa2ul_Sha256Teardown(sha256); /* hash will be finalized in sw via fallback */ ret = CRYPTOCB_UNAVAILABLE; /* fall back to sw */ } @@ -796,34 +841,36 @@ static int ti_sa2ul_InitSha512_ctx(wc_Sha512* sha512) return 0; } -static int ti_sa2ul_Sha512Free_ctx(wc_Sha512* sha512) +static void ti_sa2ul_Sha512Free_ctx(wc_Sha512* sha512) { (void)SA2UL_contextFree(&sha512->scObj); - XMEMSET(&sha512->scObj, 0, sizeof(sha512->scObj)); sa2ul_hash_in_use = 0; - - return 0; } -static int ti_sa2ul_Sha512Teardown(wc_Sha512* sha512) +void ti_sa2ul_Sha512Teardown(wc_Sha512* sha512) { - /* hash will be finalized in sw via fallback, but we need the driver - * to tear down the context in hw. To do that, we update the context - * length and push some final arbitrary data. It will not affect - * the hash */ - if (sha512->scObj.txBytesCnt != 0) { - byte buffer[WC_SHA512_DIGEST_SIZE]; - sha512->scObj.ctxPrms.inputLen = sha512->scObj.txBytesCnt + - WC_SHA512_DIGEST_SIZE; - sha512->scObj.totalLengthInBytes = sha512->scObj.txBytesCnt + - WC_SHA512_DIGEST_SIZE; - CacheP_wbInv((void *)buffer, WC_SHA512_DIGEST_SIZE, CacheP_TYPE_ALLD); - SA2UL_contextProcess(&sha512->scObj, buffer, - WC_SHA512_DIGEST_SIZE, hash_scratch); - (void)ti_sa2ul_Sha512Free_ctx(sha512); + if (sha512 != NULL) { + /* hash will be finalized in sw via fallback, but we need the driver + * to tear down the context in hw. To do that, we update the context + * length and push some final arbitrary data. It will not affect + * the hash */ + if (sha512->hashType == WC_HASH_TYPE_SHA512 && + (sha512->flags & WC_HASH_FLAG_ISCOPY) == 0 && + sha512->scObj.txBytesCnt != 0) + { + byte buffer[WC_SHA512_DIGEST_SIZE]; + sha512->scObj.ctxPrms.inputLen = sha512->scObj.txBytesCnt + + WC_SHA512_DIGEST_SIZE; + sha512->scObj.totalLengthInBytes = sha512->scObj.txBytesCnt + + WC_SHA512_DIGEST_SIZE; + CacheP_wbInv((void *)buffer, WC_SHA512_DIGEST_SIZE, CacheP_TYPE_ALLD); + SA2UL_contextProcess(&sha512->scObj, buffer, + WC_SHA512_DIGEST_SIZE, hash_scratch); + ti_sa2ul_Sha512Free_ctx(sha512); + } + XMEMSET(&sha512->scObj, 0, sizeof(sha512->scObj)); } - return 0; } static int ti_sa2ul_Sha512Hash(wc_Sha512* sha512, const byte* in, @@ -835,8 +882,11 @@ static int ti_sa2ul_Sha512Hash(wc_Sha512* sha512, const byte* in, word32 partialLen; if (in == NULL && digest == NULL) - return WC_HW_E; - + return BAD_FUNC_ARG; + if (sha512->hashType != WC_HASH_TYPE_SHA512 || + (sha512->flags & WC_HASH_FLAG_ISCOPY) != 0) { + return CRYPTOCB_UNAVAILABLE; + } if (sha512->scObj.txBytesCnt == 0 && sa2ul_hash_in_use == 1) { sha512->flags |= WC_HASH_FLAG_ISCOPY; return CRYPTOCB_UNAVAILABLE; @@ -900,7 +950,7 @@ static int ti_sa2ul_Sha512Hash(wc_Sha512* sha512, const byte* in, } else if (digest != NULL) { /* final... */ - (void)ti_sa2ul_Sha512Teardown(sha512); + ti_sa2ul_Sha512Teardown(sha512); /* hash will be finalized in sw via fallback */ ret = CRYPTOCB_UNAVAILABLE; /* fall back to sw */ } @@ -935,11 +985,6 @@ static int ti_sa2ul_CryptoDevCb(int devId, wc_CryptoInfo* info, void* devCtx) } # if defined(HAVE_AES_CBC) else if (info->cipher.type == WC_CIPHER_AES_CBC) { - Aes* aes = info->cipher.aescbc.aes; - if (aes == NULL) - return BAD_FUNC_ARG; - if (check_aes_keylength(aes->keylen) != 0) - return CRYPTOCB_UNAVAILABLE; /* fall back to sw */ if (info->cipher.enc) { ret = ti_sa2ul_AesCbcEncrypt(info->cipher.aescbc.aes, info->cipher.aescbc.out, @@ -958,11 +1003,6 @@ static int ti_sa2ul_CryptoDevCb(int devId, wc_CryptoInfo* info, void* devCtx) # endif /* HAVE_AES_CBC */ # if defined(HAVE_AES_ECB) else if (info->cipher.type == WC_CIPHER_AES_ECB) { - Aes* aes = info->cipher.aesecb.aes; - if (aes == NULL) - return BAD_FUNC_ARG; - if (check_aes_keylength(aes->keylen) != 0) - return CRYPTOCB_UNAVAILABLE; /* fall back to sw */ if (info->cipher.enc) { ret = ti_sa2ul_AesEcbEncrypt(info->cipher.aesecb.aes, info->cipher.aesecb.out, @@ -982,43 +1022,31 @@ static int ti_sa2ul_CryptoDevCb(int devId, wc_CryptoInfo* info, void* devCtx) # if defined(HAVE_AESGCM) else if (info->cipher.type == WC_CIPHER_AES_GCM) { if (info->cipher.enc) { - Aes* aes = info->cipher.aesgcm_enc.aes; - if (aes == NULL) - return BAD_FUNC_ARG; - if (check_aes_keylength(aes->keylen) != 0 || - info->cipher.aesgcm_enc.sz == 0) { - return CRYPTOCB_UNAVAILABLE; /* fall back to sw */ - } - ret = ti_sa2ul_AesGcmEncrypt(aes, - info->cipher.aesgcm_enc.out, - info->cipher.aesgcm_enc.in, - info->cipher.aesgcm_enc.sz, - info->cipher.aesgcm_enc.iv, - info->cipher.aesgcm_enc.ivSz, - info->cipher.aesgcm_enc.authTag, - info->cipher.aesgcm_enc.authTagSz, - info->cipher.aesgcm_enc.authIn, - info->cipher.aesgcm_enc.authInSz); + ret = ti_sa2ul_AesGcmEncrypt( + info->cipher.aesgcm_enc.aes, + info->cipher.aesgcm_enc.out, + info->cipher.aesgcm_enc.in, + info->cipher.aesgcm_enc.sz, + info->cipher.aesgcm_enc.iv, + info->cipher.aesgcm_enc.ivSz, + info->cipher.aesgcm_enc.authTag, + info->cipher.aesgcm_enc.authTagSz, + info->cipher.aesgcm_enc.authIn, + info->cipher.aesgcm_enc.authInSz); } # ifdef HAVE_AES_DECRYPT else { - Aes* aes = info->cipher.aesgcm_dec.aes; - if (aes == NULL) - return BAD_FUNC_ARG; - if (check_aes_keylength(aes->keylen) != 0 || - info->cipher.aesgcm_dec.sz == 0) { - return CRYPTOCB_UNAVAILABLE; /* fall back to sw */ - } - ret = ti_sa2ul_AesGcmDecrypt(aes, - info->cipher.aesgcm_dec.out, - info->cipher.aesgcm_dec.in, - info->cipher.aesgcm_dec.sz, - info->cipher.aesgcm_dec.iv, - info->cipher.aesgcm_dec.ivSz, - info->cipher.aesgcm_dec.authTag, - info->cipher.aesgcm_dec.authTagSz, - info->cipher.aesgcm_dec.authIn, - info->cipher.aesgcm_dec.authInSz); + ret = ti_sa2ul_AesGcmDecrypt( + info->cipher.aesgcm_dec.aes, + info->cipher.aesgcm_dec.out, + info->cipher.aesgcm_dec.in, + info->cipher.aesgcm_dec.sz, + info->cipher.aesgcm_dec.iv, + info->cipher.aesgcm_dec.ivSz, + info->cipher.aesgcm_dec.authTag, + info->cipher.aesgcm_dec.authTagSz, + info->cipher.aesgcm_dec.authIn, + info->cipher.aesgcm_dec.authInSz); } # endif /* HAVE_AES_DECRYPT */ } @@ -1033,23 +1061,18 @@ static int ti_sa2ul_CryptoDevCb(int devId, wc_CryptoInfo* info, void* devCtx) } # ifndef NO_SHA256 else if (info->hash.type == WC_HASH_TYPE_SHA256) { - if ((info->hash.sha256->flags & WC_HASH_FLAG_ISCOPY) == 0) { - ret = ti_sa2ul_Sha256Hash(info->hash.sha256, - info->hash.in, - info->hash.inSz, - info->hash.digest); - } + ret = ti_sa2ul_Sha256Hash(info->hash.sha256, + info->hash.in, + info->hash.inSz, + info->hash.digest); } # endif /* !NO_SHA256 */ # ifdef WOLFSSL_SHA512 else if (info->hash.type == WC_HASH_TYPE_SHA512) { - if (info->hash.sha512->hashType == WC_HASH_TYPE_SHA512 && - (info->hash.sha512->flags & WC_HASH_FLAG_ISCOPY) == 0) { - ret = ti_sa2ul_Sha512Hash(info->hash.sha512, - info->hash.in, - info->hash.inSz, - info->hash.digest); - } + ret = ti_sa2ul_Sha512Hash(info->hash.sha512, + info->hash.in, + info->hash.inSz, + info->hash.digest); } # endif /* WOLFSSL_SHA512 */ #endif /* !WOLFSSL_TI_AM64X_NO_SHA && (!NO_SHA256 || WOLFSSL_SHA512) */ @@ -1065,18 +1088,15 @@ static int ti_sa2ul_CryptoDevCb(int devId, wc_CryptoInfo* info, void* devCtx) # ifndef NO_SHA256 else if (info->free.type == WC_HASH_TYPE_SHA256) { wc_Sha256* sha256 = (wc_Sha256*)info->free.obj; - if ((sha256->flags & WC_HASH_FLAG_ISCOPY) == 0) { - ret = ti_sa2ul_Sha256Teardown(sha256); - } + ti_sa2ul_Sha256Teardown(sha256); + /* ret still == CRYPTOCB_UNAVAILABLE for any malloc cleanup */ } # endif /* !NO_SHA256 */ # ifdef WOLFSSL_SHA512 else if (info->free.type == WC_HASH_TYPE_SHA512) { wc_Sha512* sha512 = (wc_Sha512*)info->free.obj; - if (sha512->hashType == WC_HASH_TYPE_SHA512 && - (sha512->flags & WC_HASH_FLAG_ISCOPY) == 0) { - ret = ti_sa2ul_Sha512Teardown(sha512); - } + ti_sa2ul_Sha512Teardown(sha512); + /* ret still == CRYPTOCB_UNAVAILABLE for any malloc cleanup */ } # endif /* WOLFSSL_SHA512 */ } @@ -1112,4 +1132,4 @@ int ti_sa2ul_port_init(void) return ret; } -#endif /* WOLFSSL_TI_AM64X */ +#endif /* WOLFSSL_TI_AM64X_R5 */ diff --git a/wolfcrypt/src/random.c b/wolfcrypt/src/random.c index 79475aebb6d..b79f2c7a2c7 100644 --- a/wolfcrypt/src/random.c +++ b/wolfcrypt/src/random.c @@ -245,8 +245,8 @@ This library contains implementation for the random number generator. #endif #endif -#if defined(WOLFSSL_TI_AM64X) - #include +#if defined(WOLFSSL_TI_AM64X_R5) + #include #endif #if defined(WOLFSSL_SILABS_SE_TYPES) diff --git a/wolfcrypt/src/sha256.c b/wolfcrypt/src/sha256.c index 914626918bd..6e985bdb6f7 100644 --- a/wolfcrypt/src/sha256.c +++ b/wolfcrypt/src/sha256.c @@ -171,6 +171,10 @@ on the specific device platform. #include #endif +#ifdef WOLFSSL_TI_AM64X_R5 + #include +#endif + #if FIPS_VERSION3_GE(6,0,0) const unsigned int wolfCrypt_FIPS_sha256_ro_sanity[2] = { 0x1a2b3c4d, 0x00000014 }; @@ -330,6 +334,10 @@ static int InitSha256(wc_Sha256* sha256) sha256->used = 0; #endif +#if defined(WOLFSSL_TI_AM64X_R5) && !defined(WOLFSSL_TI_AM64X_NO_SHA) + ti_sa2ul_Sha256Teardown(sha256); +#endif + #if (defined(WOLFSSL_X86_64_BUILD) && defined(USE_INTEL_SPEEDUP) && \ (defined(HAVE_INTEL_AVX1) || defined(HAVE_INTEL_AVX2))) || \ (defined(WOLFSSL_ARMASM) && defined(__aarch64__) && \ @@ -346,10 +354,6 @@ static int InitSha256(wc_Sha256* sha256) sha256->hSession = NULL; #endif -#if defined(WOLFSSL_TI_AM64X) && !defined(WOLFSSL_TI_AM64X_NO_SHA) - XMEMSET(&sha256->scObj, 0, sizeof(sha256->scObj)); -#endif - return 0; } diff --git a/wolfcrypt/src/sha512.c b/wolfcrypt/src/sha512.c index e837e0832b4..64a52d8023e 100644 --- a/wolfcrypt/src/sha512.c +++ b/wolfcrypt/src/sha512.c @@ -127,6 +127,10 @@ #include #endif +#ifdef WOLFSSL_TI_AM64X_R5 + #include +#endif + #if defined(MAX3266X_SHA) /* Already brought in by sha512.h */ /* #include */ @@ -939,6 +943,10 @@ static int InitSha512(wc_Sha512* sha512) sha512->loLen = 0; sha512->hiLen = 0; +#if defined(WOLFSSL_TI_AM64X_R5) && !defined(WOLFSSL_TI_AM64X_NO_SHA) + ti_sa2ul_Sha512Teardown(sha512); +#endif + #if (defined(WOLFSSL_X86_64_BUILD) && defined(USE_INTEL_SPEEDUP) && \ (defined(HAVE_INTEL_AVX1) || defined(HAVE_INTEL_AVX2))) || \ defined(WOLFSSL_ARMASM) @@ -960,9 +968,6 @@ static int InitSha512(wc_Sha512* sha512) sha512->hashType = WC_HASH_TYPE_SHA512; #endif /* WOLFSSL_SHA512_HASHTYPE */ -#if defined(WOLFSSL_TI_AM64X) && !defined(WOLFSSL_TI_AM64X_NO_SHA) - XMEMSET(&sha512->scObj, 0, sizeof(sha512->scObj)); -#endif return 0; } diff --git a/wolfcrypt/src/wc_port.c b/wolfcrypt/src/wc_port.c index 0029343fb52..2fffcbbffff 100644 --- a/wolfcrypt/src/wc_port.c +++ b/wolfcrypt/src/wc_port.c @@ -212,8 +212,8 @@ Threading/Mutex options: #include #endif -#ifdef WOLFSSL_TI_AM64X - #include +#ifdef WOLFSSL_TI_AM64X_R5 + #include #endif #ifdef WOLF_CRYPTO_CB @@ -955,7 +955,7 @@ int wolfCrypt_Init(void) } #endif - #if defined(WOLFSSL_TI_AM64X) + #if defined(WOLFSSL_TI_AM64X_R5) ret = ti_sa2ul_port_init(); if (ret != 0) { WOLFSSL_MSG("TI AM64x Init Failed"); diff --git a/wolfcrypt/test/test.c b/wolfcrypt/test/test.c index 02030efceed..03d30e71cd9 100644 --- a/wolfcrypt/test/test.c +++ b/wolfcrypt/test/test.c @@ -534,8 +534,8 @@ static const byte const_byte_array[] = "A+Gd\0\0\0"; #endif #endif -#ifdef WOLFSSL_TI_AM64X - #include +#ifdef WOLFSSL_TI_AM64X_R5 + #include #endif #ifdef _MSC_VER diff --git a/wolfssl/wolfcrypt/aes.h b/wolfssl/wolfcrypt/aes.h index db933e4d42e..b0bed588b2b 100644 --- a/wolfssl/wolfcrypt/aes.h +++ b/wolfssl/wolfcrypt/aes.h @@ -189,7 +189,7 @@ WOLFSSL_LOCAL void WC_ARG_NOT_NULL(1) GHASH(Gcm* gcm, const byte* a, #include "cy_crypto_common.h" #endif /* WOLFSSL_PSOC6_CRYPTO */ -#ifdef WOLFSSL_TI_AM64X +#ifdef WOLFSSL_TI_AM64X_R5 #include "security/security_common/drivers/crypto/sa2ul/sa2ul.h" #endif @@ -525,7 +525,7 @@ struct Aes { cy_stc_crypto_aes_gcm_state_t aes_gcm_state; #endif #endif /* WOLFSSL_PSOC6_CRYPTO */ -#if defined(WOLFSSL_TI_AM64X) && !defined(WOLFSSL_TI_AM64X_NO_AES) +#if defined(WOLFSSL_TI_AM64X_R5) && !defined(WOLFSSL_TI_AM64X_NO_AES) XALIGNED(SA2UL_CACHELINE_ALIGNMENT) SA2UL_ContextObject scObj; #endif diff --git a/wolfssl/wolfcrypt/include.am b/wolfssl/wolfcrypt/include.am index e68d157836d..8d19b2a3ad7 100644 --- a/wolfssl/wolfcrypt/include.am +++ b/wolfssl/wolfcrypt/include.am @@ -101,7 +101,7 @@ noinst_HEADERS+= \ wolfssl/wolfcrypt/port/ti/ti-ccm.h \ wolfssl/wolfcrypt/port/ti/ti-c2000.h \ wolfssl/wolfcrypt/port/ti/ti-c2000-entropy.h \ - wolfssl/wolfcrypt/port/ti/ti-sa2ul_port.h \ + wolfssl/wolfcrypt/port/ti/ti-sa2ul_r5_port.h \ wolfssl/wolfcrypt/port/nrf51.h \ wolfssl/wolfcrypt/port/nxp/ksdk_port.h \ wolfssl/wolfcrypt/port/nxp/dcp_port.h \ diff --git a/wolfssl/wolfcrypt/port/ti/ti-sa2ul_port.h b/wolfssl/wolfcrypt/port/ti/ti-sa2ul_r5_port.h similarity index 77% rename from wolfssl/wolfcrypt/port/ti/ti-sa2ul_port.h rename to wolfssl/wolfcrypt/port/ti/ti-sa2ul_r5_port.h index 1b1553f5a93..7a4a9256656 100644 --- a/wolfssl/wolfcrypt/port/ti/ti-sa2ul_port.h +++ b/wolfssl/wolfcrypt/port/ti/ti-sa2ul_r5_port.h @@ -1,4 +1,4 @@ -/* ti-sa2ul_port.h +/* ti-sa2ul_r5_port.h * * Copyright (C) 2006-2026 wolfSSL Inc. * @@ -18,11 +18,13 @@ * along with this program; if not, write to the Free Software * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1335, USA */ -#ifndef _TI_SA2UL_PORT_H_ -#define _TI_SA2UL_PORT_H_ +#ifndef _TI_SA2UL_R5_PORT_H_ +#define _TI_SA2UL_R5_PORT_H_ -#if defined(WOLFSSL_TI_AM64X) +#if defined(WOLFSSL_TI_AM64X_R5) +#include +#include #include "security/security_common/drivers/crypto/sa2ul/sa2ul.h" #define WOLFSSL_TI_SA2UL_DEVID 8888 @@ -35,9 +37,11 @@ #endif int ti_sa2ul_port_init(void); +void ti_sa2ul_Sha256Teardown(wc_Sha256* sha256); +void ti_sa2ul_Sha512Teardown(wc_Sha512* sha512); void ti_sa2ul_soc_uid(uint8_t *uid); int ti_sa2ul_trng_get(byte* output, word32 sz); -#endif /* WOLFSSL_TI_AM64X */ +#endif /* WOLFSSL_TI_AM64X_R5 */ -#endif /* _TI_SA2UL_PORT_H_ */ +#endif /* _TI_SA2UL_R5_PORT_H_ */ diff --git a/wolfssl/wolfcrypt/settings.h b/wolfssl/wolfcrypt/settings.h index a5ce11f48bf..3c60ccf19a0 100644 --- a/wolfssl/wolfcrypt/settings.h +++ b/wolfssl/wolfcrypt/settings.h @@ -2516,7 +2516,7 @@ #define NO_WOLFSSL_SHA256_INTERLEAVE #endif -#ifdef WOLFSSL_TI_AM64X +#ifdef WOLFSSL_TI_AM64X_R5 #define HAVE_AES_ECB #define NO_AES_192 #define NO_DEV_RANDOM diff --git a/wolfssl/wolfcrypt/sha256.h b/wolfssl/wolfcrypt/sha256.h index e023e11f7d6..19c63ab30f5 100644 --- a/wolfssl/wolfcrypt/sha256.h +++ b/wolfssl/wolfcrypt/sha256.h @@ -167,7 +167,7 @@ #include "mcapi_error.h" #endif -#ifdef WOLFSSL_TI_AM64X +#ifdef WOLFSSL_TI_AM64X_R5 #include "security/security_common/drivers/crypto/sa2ul/sa2ul.h" #endif @@ -258,7 +258,7 @@ struct wc_Sha256 { #ifdef WOLFSSL_HASH_FLAGS word32 flags; /* enum wc_HashFlags in hash.h */ #endif -#if defined(WOLFSSL_TI_AM64X) && !defined(WOLFSSL_TI_AM64X_NO_SHA) +#if defined(WOLFSSL_TI_AM64X_R5) && !defined(WOLFSSL_TI_AM64X_NO_SHA) XALIGNED(SA2UL_CACHELINE_ALIGNMENT) SA2UL_ContextObject scObj; #endif }; diff --git a/wolfssl/wolfcrypt/sha512.h b/wolfssl/wolfcrypt/sha512.h index e81d1f63c47..6c761f10cac 100644 --- a/wolfssl/wolfcrypt/sha512.h +++ b/wolfssl/wolfcrypt/sha512.h @@ -147,7 +147,7 @@ #if defined(WOLFSSL_MAX3266X) || defined(WOLFSSL_MAX3266X_OLD) #include "wolfssl/wolfcrypt/port/maxim/max3266x.h" #endif -#ifdef WOLFSSL_TI_AM64X +#ifdef WOLFSSL_TI_AM64X_R5 #include "security/security_common/drivers/crypto/sa2ul/sa2ul.h" #endif @@ -215,7 +215,7 @@ struct wc_Sha512 { int hashType; /* used to determine which SHA512 is used */ #endif /* WOLFSSL_SHA512_HASHTYPE */ #endif /* WOLFSSL_PSOC6_CRYPTO */ -#if defined(WOLFSSL_TI_AM64X) && !defined(WOLFSSL_TI_AM64X_NO_SHA) +#if defined(WOLFSSL_TI_AM64X_R5) && !defined(WOLFSSL_TI_AM64X_NO_SHA) XALIGNED(SA2UL_CACHELINE_ALIGNMENT) SA2UL_ContextObject scObj; #endif }; From 72a6136de2fc995a7feee30864af50e67bd2a712 Mon Sep 17 00:00:00 2001 From: Thomas Cook Date: Tue, 29 Sep 2026 13:32:30 -0400 Subject: [PATCH 09/10] implement a proper mutex for sa2ul hardware --- wolfcrypt/src/port/ti/ti-sa2ul_r5_port.c | 194 +++++++++++++++-------- 1 file changed, 126 insertions(+), 68 deletions(-) diff --git a/wolfcrypt/src/port/ti/ti-sa2ul_r5_port.c b/wolfcrypt/src/port/ti/ti-sa2ul_r5_port.c index 1c22eb70a51..2bdc8222ba3 100644 --- a/wolfcrypt/src/port/ti/ti-sa2ul_r5_port.c +++ b/wolfcrypt/src/port/ti/ti-sa2ul_r5_port.c @@ -41,6 +41,7 @@ /* from ti mcu plus sdk... */ #include "kernel/dpl/CacheP.h" +#include "kernel/dpl/MutexArmP.h" #include "security/security_common/drivers/crypto/crypto.h" #include "security/security_common/drivers/crypto/rng/rng.h" #include "security/security_common/drivers/crypto/sa2ul/sa2ul.h" @@ -51,6 +52,20 @@ static Crypto_Handle handle; static Crypto_Context cryptoCtx XALIGNED(SA2UL_CACHELINE_ALIGNMENT); static uint32_t socUid[UID_LEN_WORDS]; static int socUidAvail = 0; +static uint32_t sa2ulHardwareMutex = MUTEX_ARM_UNLOCKED; + +static int ti_sa2ul_lock_mutex(void) +{ + if (try_lock_mutex(&sa2ulHardwareMutex) == MUTEX_ARM_LOCKED) + return CRYPTOCB_UNAVAILABLE; + + return 0; +} + +static void ti_sa2ul_unlock_mutex(void) +{ + unlock_mutex(&sa2ulHardwareMutex); +} static int _getSocUid(void) { @@ -276,12 +291,15 @@ static int ti_sa2ul_AesCbcEncrypt(Aes* aes, byte* out, const byte* in, word32 sz if (aes == NULL) return BAD_FUNC_ARG; if (check_aes_keylength(aes->keylen) != 0) - return CRYPTOCB_UNAVAILABLE; /* fall back to sw */ + return CRYPTOCB_UNAVAILABLE; if (sz == 0) return 0; if ((sz % WC_AES_BLOCK_SIZE) != 0) return BAD_FUNC_ARG; + if (ti_sa2ul_lock_mutex() != 0) + return CRYPTOCB_UNAVAILABLE; + SA2UL_ContextParams_init(&scParams); scParams.opType = SA2UL_OP_ENC; @@ -302,17 +320,21 @@ static int ti_sa2ul_AesCbcEncrypt(Aes* aes, byte* out, const byte* in, word32 sz if (SA2UL_contextAlloc(cryptoCtx.drvHandle, &aes->scObj, &scParams) != SystemP_SUCCESS) { - return WC_HW_E; + ret = WC_HW_E; } - CacheP_wbInv((void *)in, sz, CacheP_TYPE_ALLD); + if (ret == 0) { + CacheP_wbInv((void *)in, sz, CacheP_TYPE_ALLD); - if (SA2UL_contextProcess(&aes->scObj, in, sz, out) != SystemP_SUCCESS) - ret = WC_HW_E; + if (SA2UL_contextProcess(&aes->scObj, in, sz, out) != SystemP_SUCCESS) + ret = WC_HW_E; + + XMEMCPY(aes->reg, out + sz - WC_AES_BLOCK_SIZE, WC_AES_BLOCK_SIZE); + } (void)SA2UL_contextFree(&aes->scObj); - XMEMCPY(aes->reg, out + sz - WC_AES_BLOCK_SIZE, WC_AES_BLOCK_SIZE); + ti_sa2ul_unlock_mutex(); return ret; } @@ -327,12 +349,15 @@ static int ti_sa2ul_AesCbcDecrypt(Aes* aes, byte* out, const byte* in, word32 sz if (aes == NULL) return BAD_FUNC_ARG; if (check_aes_keylength(aes->keylen) != 0) - return CRYPTOCB_UNAVAILABLE; /* fall back to sw */ + return CRYPTOCB_UNAVAILABLE; if (sz == 0) return 0; if ((sz % WC_AES_BLOCK_SIZE) != 0) return BAD_FUNC_ARG; + if (ti_sa2ul_lock_mutex() != 0) + return CRYPTOCB_UNAVAILABLE; + SA2UL_ContextParams_init(&scParams); scParams.opType = SA2UL_OP_ENC; @@ -353,19 +378,23 @@ static int ti_sa2ul_AesCbcDecrypt(Aes* aes, byte* out, const byte* in, word32 sz if (SA2UL_contextAlloc(cryptoCtx.drvHandle, &aes->scObj, &scParams) != SystemP_SUCCESS) { - return WC_HW_E; + ret = WC_HW_E; } - XMEMCPY(tmp_iv, in + sz - WC_AES_BLOCK_SIZE, WC_AES_BLOCK_SIZE); + if (ret == 0) { + XMEMCPY(tmp_iv, in + sz - WC_AES_BLOCK_SIZE, WC_AES_BLOCK_SIZE); - CacheP_wbInv((void *)in, sz, CacheP_TYPE_ALLD); + CacheP_wbInv((void *)in, sz, CacheP_TYPE_ALLD); - if (SA2UL_contextProcess(&aes->scObj, in, sz, out) != SystemP_SUCCESS) - ret = WC_HW_E; + if (SA2UL_contextProcess(&aes->scObj, in, sz, out) != SystemP_SUCCESS) + ret = WC_HW_E; + + XMEMCPY(aes->reg, tmp_iv, WC_AES_BLOCK_SIZE); + } (void)SA2UL_contextFree(&aes->scObj); - XMEMCPY(aes->reg, tmp_iv, WC_AES_BLOCK_SIZE); + ti_sa2ul_unlock_mutex(); return ret; } @@ -381,12 +410,15 @@ static int ti_sa2ul_AesEcbEncrypt(Aes* aes, byte* out, const byte* in, word32 sz if (aes == NULL) return BAD_FUNC_ARG; if (check_aes_keylength(aes->keylen) != 0) - return CRYPTOCB_UNAVAILABLE; /* fall back to sw */ + return CRYPTOCB_UNAVAILABLE; if (sz == 0) return 0; if ((sz % WC_AES_BLOCK_SIZE) != 0) return BAD_FUNC_ARG; + if (ti_sa2ul_lock_mutex() != 0) + return CRYPTOCB_UNAVAILABLE; + SA2UL_ContextParams_init(&scParams); scParams.opType = SA2UL_OP_ENC; @@ -407,16 +439,20 @@ static int ti_sa2ul_AesEcbEncrypt(Aes* aes, byte* out, const byte* in, word32 sz if (SA2UL_contextAlloc(cryptoCtx.drvHandle, &aes->scObj, &scParams) != SystemP_SUCCESS) { - return WC_HW_E; + ret = WC_HW_E; } - CacheP_wbInv((void *)in, sz, CacheP_TYPE_ALLD); + if (ret == 0) { + CacheP_wbInv((void *)in, sz, CacheP_TYPE_ALLD); - if (SA2UL_contextProcess(&aes->scObj, in, sz, out) != SystemP_SUCCESS) - ret = WC_HW_E; + if (SA2UL_contextProcess(&aes->scObj, in, sz, out) != SystemP_SUCCESS) + ret = WC_HW_E; + } (void)SA2UL_contextFree(&aes->scObj); + ti_sa2ul_unlock_mutex(); + return ret; } @@ -429,12 +465,15 @@ static int ti_sa2ul_AesEcbDecrypt(Aes* aes, byte* out, const byte* in, word32 sz if (aes == NULL) return BAD_FUNC_ARG; if (check_aes_keylength(aes->keylen) != 0) - return CRYPTOCB_UNAVAILABLE; /* fall back to sw */ + return CRYPTOCB_UNAVAILABLE; if (sz == 0) return 0; if ((sz % WC_AES_BLOCK_SIZE) != 0) return BAD_FUNC_ARG; + if (ti_sa2ul_lock_mutex() != 0) + return CRYPTOCB_UNAVAILABLE; + SA2UL_ContextParams_init(&scParams); scParams.opType = SA2UL_OP_ENC; @@ -455,16 +494,20 @@ static int ti_sa2ul_AesEcbDecrypt(Aes* aes, byte* out, const byte* in, word32 sz if (SA2UL_contextAlloc(cryptoCtx.drvHandle, &aes->scObj, &scParams) != SystemP_SUCCESS) { - return WC_HW_E; + ret = WC_HW_E; } - CacheP_wbInv((void *)in, sz, CacheP_TYPE_ALLD); + if (ret == 0) { + CacheP_wbInv((void *)in, sz, CacheP_TYPE_ALLD); - if (SA2UL_contextProcess(&aes->scObj, in, sz, out) != SystemP_SUCCESS) - ret = WC_HW_E; + if (SA2UL_contextProcess(&aes->scObj, in, sz, out) != SystemP_SUCCESS) + ret = WC_HW_E; + } (void)SA2UL_contextFree(&aes->scObj); + ti_sa2ul_unlock_mutex(); + return ret; } #endif /* HAVE_AES_DECRYPT */ @@ -500,6 +543,9 @@ static int ti_sa2ul_AesGcmEncrypt(Aes* aes, byte* out, if (sz == 0 || (sz % WC_AES_BLOCK_SIZE) != 0) return CRYPTOCB_UNAVAILABLE; + if (ti_sa2ul_lock_mutex() != 0) + return CRYPTOCB_UNAVAILABLE; + SA2UL_ContextParams_init(&scParams); scParams.opType = SA2UL_OP_ENC; @@ -530,20 +576,24 @@ static int ti_sa2ul_AesGcmEncrypt(Aes* aes, byte* out, if (SA2UL_contextAlloc(cryptoCtx.drvHandle, &aes->scObj, &scParams) != SystemP_SUCCESS) { - return WC_HW_E; + ret = WC_HW_E; } - if (ivSz != GCM_NONCE_MID_SZ) { - _override_iv_with_ghash(aes, iv, ivSz); - } + if (ret == 0) { + if (ivSz != GCM_NONCE_MID_SZ) { + _override_iv_with_ghash(aes, iv, ivSz); + } - CacheP_wbInv((void *)in, sz, CacheP_TYPE_ALLD); + CacheP_wbInv((void *)in, sz, CacheP_TYPE_ALLD); - if (SA2UL_contextProcess(&aes->scObj, in, sz, out) != SystemP_SUCCESS) - ret = WC_HW_E; + if (SA2UL_contextProcess(&aes->scObj, in, sz, out) != SystemP_SUCCESS) + ret = WC_HW_E; + } (void)SA2UL_contextFree(&aes->scObj); + ti_sa2ul_unlock_mutex(); + if (ret == 0 && authTag != NULL) { if (authInSz <= sizeof(scParams.aad)) { XMEMCPY(authTag, aes->scObj.computedHash, authTagSz); @@ -588,6 +638,9 @@ static int ti_sa2ul_AesGcmDecrypt(Aes* aes, byte* out, if (sz == 0 || (sz % WC_AES_BLOCK_SIZE) != 0) return CRYPTOCB_UNAVAILABLE; + if (ti_sa2ul_lock_mutex() != 0) + return CRYPTOCB_UNAVAILABLE; + SA2UL_ContextParams_init(&scParams); scParams.opType = SA2UL_OP_ENC; @@ -618,20 +671,24 @@ static int ti_sa2ul_AesGcmDecrypt(Aes* aes, byte* out, if (SA2UL_contextAlloc(cryptoCtx.drvHandle, &aes->scObj, &scParams) != SystemP_SUCCESS) { - return WC_HW_E; + ret = WC_HW_E; } - if (ivSz != GCM_NONCE_MID_SZ) { - _override_iv_with_ghash(aes, iv, ivSz); - } + if (ret == 0) { + if (ivSz != GCM_NONCE_MID_SZ) { + _override_iv_with_ghash(aes, iv, ivSz); + } - CacheP_wbInv((void *)in, sz, CacheP_TYPE_ALLD); + CacheP_wbInv((void *)in, sz, CacheP_TYPE_ALLD); - if (SA2UL_contextProcess(&aes->scObj, in, sz, out) != SystemP_SUCCESS) - ret = WC_HW_E; + if (SA2UL_contextProcess(&aes->scObj, in, sz, out) != SystemP_SUCCESS) + ret = WC_HW_E; + } (void)SA2UL_contextFree(&aes->scObj); + ti_sa2ul_unlock_mutex(); + if (ret == 0 && authTag != NULL) { if (authInSz <= sizeof(scParams.aad)) { if (ConstantCompare(authTag, aes->scObj.computedHash, authTagSz) != 0) @@ -675,13 +732,18 @@ static int ti_sa2ul_AesGcmDecrypt(Aes* aes, byte* out, * the amount of data we can hash at one time. */ #define HASH_SCRATCH_SIZE 0x2000u static byte hash_scratch[HASH_SCRATCH_SIZE] XALIGNED(SA2UL_CACHELINE_ALIGNMENT); -static volatile int sa2ul_hash_in_use = 0; #ifndef NO_SHA256 static int ti_sa2ul_InitSha256_ctx(wc_Sha256* sha256) { SA2UL_ContextParams scParams; + if (ti_sa2ul_lock_mutex() != 0) { + /* mark as copy so we continue to fall back to software */ + sha256->flags |= WC_HASH_FLAG_ISCOPY; + return CRYPTOCB_UNAVAILABLE; + } + SA2UL_ContextParams_init(&scParams); scParams.opType = SA2UL_OP_AUTH; @@ -693,11 +755,10 @@ static int ti_sa2ul_InitSha256_ctx(wc_Sha256* sha256) if (SA2UL_contextAlloc(cryptoCtx.drvHandle, &sha256->scObj, &scParams) != SystemP_SUCCESS) { + ti_sa2ul_unlock_mutex(); return WC_HW_E; } - sa2ul_hash_in_use = 1; - return 0; } @@ -705,7 +766,7 @@ static void ti_sa2ul_Sha256Free_ctx(wc_Sha256* sha256) { (void)SA2UL_contextFree(&sha256->scObj); - sa2ul_hash_in_use = 0; + ti_sa2ul_unlock_mutex(); } void ti_sa2ul_Sha256Teardown(wc_Sha256* sha256) @@ -744,9 +805,13 @@ static int ti_sa2ul_Sha256Hash(wc_Sha256* sha256, const byte* in, return BAD_FUNC_ARG; if ((sha256->flags & WC_HASH_FLAG_ISCOPY) != 0) return CRYPTOCB_UNAVAILABLE; - if (sha256->scObj.txBytesCnt == 0 && sa2ul_hash_in_use == 1) { - sha256->flags |= WC_HASH_FLAG_ISCOPY; - return CRYPTOCB_UNAVAILABLE; + + if (sha256->scObj.txBytesCnt == 0 && + inSz + sha256->buffLen >= WC_SHA256_BLOCK_SIZE) + { + ret = ti_sa2ul_InitSha256_ctx(sha256); + if (ret != 0) + return ret; } if (in != NULL) { @@ -763,10 +828,6 @@ static int ti_sa2ul_Sha256Hash(wc_Sha256* sha256, const byte* in, if (sha256->buffLen == WC_SHA256_BLOCK_SIZE) { CacheP_wbInv((void *)buffer, WC_SHA256_BLOCK_SIZE, CacheP_TYPE_ALLD); - if (sha256->scObj.txBytesCnt == 0) { - if (ti_sa2ul_InitSha256_ctx(sha256) != 0) - return WC_HW_E; - } if (SA2UL_contextProcess(&sha256->scObj, buffer, WC_SHA256_BLOCK_SIZE, hash_scratch) != SystemP_SUCCESS) { @@ -785,10 +846,6 @@ static int ti_sa2ul_Sha256Hash(wc_Sha256* sha256, const byte* in, blocksLen = min(sizeof(hash_scratch), inSz & ~((word32)WC_SHA256_BLOCK_SIZE-1)); CacheP_wbInv((void *)in, blocksLen, CacheP_TYPE_ALLD); - if (sha256->scObj.txBytesCnt == 0) { - if (ti_sa2ul_InitSha256_ctx(sha256) != 0) - return WC_HW_E; - } if (SA2UL_contextProcess(&sha256->scObj, in, blocksLen, hash_scratch) != SystemP_SUCCESS) { return WC_HW_E; @@ -810,7 +867,7 @@ static int ti_sa2ul_Sha256Hash(wc_Sha256* sha256, const byte* in, /* final... */ ti_sa2ul_Sha256Teardown(sha256); /* hash will be finalized in sw via fallback */ - ret = CRYPTOCB_UNAVAILABLE; /* fall back to sw */ + ret = CRYPTOCB_UNAVAILABLE; } return ret; @@ -822,6 +879,12 @@ static int ti_sa2ul_InitSha512_ctx(wc_Sha512* sha512) { SA2UL_ContextParams scParams; + if (ti_sa2ul_lock_mutex() != 0) { + /* mark as copy so we continue to fall back to software */ + sha512->flags |= WC_HASH_FLAG_ISCOPY; + return CRYPTOCB_UNAVAILABLE; + } + SA2UL_ContextParams_init(&scParams); scParams.opType = SA2UL_OP_AUTH; @@ -833,11 +896,10 @@ static int ti_sa2ul_InitSha512_ctx(wc_Sha512* sha512) if (SA2UL_contextAlloc(cryptoCtx.drvHandle, &sha512->scObj, &scParams) != SystemP_SUCCESS) { + ti_sa2ul_unlock_mutex(); return WC_HW_E; } - sa2ul_hash_in_use = 1; - return 0; } @@ -845,7 +907,7 @@ static void ti_sa2ul_Sha512Free_ctx(wc_Sha512* sha512) { (void)SA2UL_contextFree(&sha512->scObj); - sa2ul_hash_in_use = 0; + ti_sa2ul_unlock_mutex(); } void ti_sa2ul_Sha512Teardown(wc_Sha512* sha512) @@ -887,9 +949,13 @@ static int ti_sa2ul_Sha512Hash(wc_Sha512* sha512, const byte* in, (sha512->flags & WC_HASH_FLAG_ISCOPY) != 0) { return CRYPTOCB_UNAVAILABLE; } - if (sha512->scObj.txBytesCnt == 0 && sa2ul_hash_in_use == 1) { - sha512->flags |= WC_HASH_FLAG_ISCOPY; - return CRYPTOCB_UNAVAILABLE; + + if (sha512->scObj.txBytesCnt == 0 && + inSz + sha512->buffLen >= WC_SHA512_BLOCK_SIZE) + { + ret = ti_sa2ul_InitSha512_ctx(sha512); + if (ret != 0) + return ret; } if (in != NULL) { @@ -905,10 +971,6 @@ static int ti_sa2ul_Sha512Hash(wc_Sha512* sha512, const byte* in, inSz -= partialLen; if (sha512->buffLen == WC_SHA512_BLOCK_SIZE) { CacheP_wbInv((void *)buffer, WC_SHA512_BLOCK_SIZE, CacheP_TYPE_ALLD); - if (sha512->scObj.txBytesCnt == 0) { - if (ti_sa2ul_InitSha512_ctx(sha512) != 0) - return WC_HW_E; - } if (SA2UL_contextProcess(&sha512->scObj, buffer, WC_SHA512_BLOCK_SIZE, hash_scratch) != SystemP_SUCCESS) { @@ -927,10 +989,6 @@ static int ti_sa2ul_Sha512Hash(wc_Sha512* sha512, const byte* in, blocksLen = min(sizeof(hash_scratch), inSz & ~((word32)WC_SHA512_BLOCK_SIZE-1)); CacheP_wbInv((void *)in, blocksLen, CacheP_TYPE_ALLD); - if (sha512->scObj.txBytesCnt == 0) { - if (ti_sa2ul_InitSha512_ctx(sha512) != 0) - return WC_HW_E; - } if (SA2UL_contextProcess(&sha512->scObj, in, blocksLen, hash_scratch) != SystemP_SUCCESS) { return WC_HW_E; @@ -952,7 +1010,7 @@ static int ti_sa2ul_Sha512Hash(wc_Sha512* sha512, const byte* in, /* final... */ ti_sa2ul_Sha512Teardown(sha512); /* hash will be finalized in sw via fallback */ - ret = CRYPTOCB_UNAVAILABLE; /* fall back to sw */ + ret = CRYPTOCB_UNAVAILABLE; } return ret; From 6fb7b7c9f7702f030f6cdc338cb4afdc598a35e1 Mon Sep 17 00:00:00 2001 From: Thomas Cook Date: Wed, 30 Sep 2026 15:26:23 -0400 Subject: [PATCH 10/10] address pr comments --- .wolfssl_known_macro_extras | 1 + wolfcrypt/benchmark/benchmark.c | 13 +- wolfcrypt/src/ecc.c | 4 +- wolfcrypt/src/port/ti/ti-sa2ul_r5_port.c | 383 +++++++++++-------- wolfcrypt/src/sha256.c | 12 +- wolfcrypt/src/sha512.c | 12 +- wolfcrypt/test/test.c | 1 + wolfssl/wolfcrypt/aes.h | 7 - wolfssl/wolfcrypt/port/ti/ti-sa2ul_r5_port.h | 2 - wolfssl/wolfcrypt/settings.h | 10 +- wolfssl/wolfcrypt/sha256.h | 7 - wolfssl/wolfcrypt/sha512.h | 6 - 12 files changed, 236 insertions(+), 222 deletions(-) diff --git a/.wolfssl_known_macro_extras b/.wolfssl_known_macro_extras index ac0af31a04f..9c4d5dd28bb 100644 --- a/.wolfssl_known_macro_extras +++ b/.wolfssl_known_macro_extras @@ -734,6 +734,7 @@ THREADED_SNIFFTEST TIF_NEED_FPU_LOAD TIME_T_NOT_LONG TI_DUMMY_BUILD +TI_MCU_PLUS_SDK TLS13_RSA_PSS_SIGN_CB_NO_PREHASH TSIP_AES_128_CTR TSIP_AES_256_CTR diff --git a/wolfcrypt/benchmark/benchmark.c b/wolfcrypt/benchmark/benchmark.c index 9da2f3fd892..06b2cfdb16d 100644 --- a/wolfcrypt/benchmark/benchmark.c +++ b/wolfcrypt/benchmark/benchmark.c @@ -3084,7 +3084,7 @@ static void bench_stats_sym_finish(const char* desc, int useDeviceID, #ifdef GENERATE_MACHINE_PARSEABLE_REPORT /* machine parseable CSV */ #ifdef HAVE_GET_CYCLES - printf("%s", "\"sym\",Algorithm,HW/SW,block_size,bytes_total," + printf("%s", "\"sym\",Algorithm,HW/SW,bytes_total," WOLFSSL_FIXED_TIME_UNIT "econds_total," WOLFSSL_FIXED_UNIT "/" WOLFSSL_FIXED_TIME_UNIT ",cycles_total,Cycles per byte," @@ -3096,7 +3096,7 @@ static void bench_stats_sym_finish(const char* desc, int useDeviceID, #endif ); #else - printf("%s", "\"sym\",Algorithm,HW/SW,block_size,bytes_total," + printf("%s", "\"sym\",Algorithm,HW/SW,bytes_total," WOLFSSL_FIXED_TIME_UNIT "econds_total," WOLFSSL_FIXED_UNIT "/" WOLFSSL_FIXED_TIME_UNIT ",cycles_total," @@ -3207,9 +3207,8 @@ static void bench_stats_sym_finish(const char* desc, int useDeviceID, #ifdef WOLFSSL_ESPIDF #ifdef HAVE_GET_CYCLES (void)XSNPRINTF(msg, sizeof(msg), - "sym,%s,%s,%lu,%lu," FLT_FMT "," FLT_FMT ",%llu,", desc, + "sym,%s,%s,%lu," FLT_FMT "," FLT_FMT ",%lu,", desc, BENCH_DEVID_GET_NAME(useDeviceID), - bench_size, bytes_processed, FLT_FMT_ARGS(total), FLT_FMT_ARGS(persec), (long unsigned int) total_cycles); @@ -3222,16 +3221,14 @@ static void bench_stats_sym_finish(const char* desc, int useDeviceID, #else #ifdef HAVE_GET_CYCLES (void)XSNPRINTF(msg, sizeof(msg), - "sym,%s,%s,%lu,%llu," FLT_FMT "," FLT_FMT ",%llu,", desc, + "sym,%s,%s,%llu," FLT_FMT "," FLT_FMT ",%llu,", desc, BENCH_DEVID_GET_NAME(useDeviceID), - bench_size, bytes_processed, FLT_FMT_ARGS(total), FLT_FMT_ARGS(persec), total_cycles); #else (void)XSNPRINTF(msg, sizeof(msg), - "sym,%s,%s,%lu,%llu," FLT_FMT "," FLT_FMT ",", desc, + "sym,%s,%s,%llu," FLT_FMT "," FLT_FMT ",", desc, BENCH_DEVID_GET_NAME(useDeviceID), - bench_size, bytes_processed, FLT_FMT_ARGS(total), FLT_FMT_ARGS(persec)); #endif diff --git a/wolfcrypt/src/ecc.c b/wolfcrypt/src/ecc.c index 6588deeb433..56a4dc71c74 100644 --- a/wolfcrypt/src/ecc.c +++ b/wolfcrypt/src/ecc.c @@ -4409,8 +4409,8 @@ int wc_ecc_get_curve_size_from_id(int curve_id) return ecc_sets[curve_idx].size; } -#ifndef strcasecmp -int strcasecmp(const char *s1, const char *s2); +#ifdef TI_MCU_PLUS_SDK + #include #endif /* Returns the curve index that corresponds to a given curve name in diff --git a/wolfcrypt/src/port/ti/ti-sa2ul_r5_port.c b/wolfcrypt/src/port/ti/ti-sa2ul_r5_port.c index 2bdc8222ba3..dae99409a0b 100644 --- a/wolfcrypt/src/port/ti/ti-sa2ul_r5_port.c +++ b/wolfcrypt/src/port/ti/ti-sa2ul_r5_port.c @@ -41,6 +41,7 @@ /* from ti mcu plus sdk... */ #include "kernel/dpl/CacheP.h" +#include "kernel/dpl/ClockP.h" #include "kernel/dpl/MutexArmP.h" #include "security/security_common/drivers/crypto/crypto.h" #include "security/security_common/drivers/crypto/rng/rng.h" @@ -49,10 +50,13 @@ #include "drivers/sciclient/include/tisci/security/tisci_soc_uid.h" static Crypto_Handle handle; -static Crypto_Context cryptoCtx XALIGNED(SA2UL_CACHELINE_ALIGNMENT); +static XALIGNED(SA2UL_CACHELINE_ALIGNMENT) Crypto_Context cryptoCtx; static uint32_t socUid[UID_LEN_WORDS]; static int socUidAvail = 0; + static uint32_t sa2ulHardwareMutex = MUTEX_ARM_UNLOCKED; +static XALIGNED(SA2UL_CACHELINE_ALIGNMENT) SA2UL_ContextParams scParams; +static XALIGNED(SA2UL_CACHELINE_ALIGNMENT) SA2UL_ContextObject scObj; static int ti_sa2ul_lock_mutex(void) { @@ -125,15 +129,51 @@ static int ti_sa2ul_trng_init_common(void) return rngHandle == NULL; } +static int ti_sa2ul_trng_init_nrbg(void) +{ + gRngConfig[0].attrs->mode = RNG_DRBG_DISABLE_MODE; + return ti_sa2ul_trng_init_common(); +} + +static int ti_sa2ul_trng_get_nrbg(byte* output, word32 sz) +{ + int ret = 0; + uint32_t random[RNG_NUM_DWORDS]; + + if (output == NULL && sz != 0) + return BAD_FUNC_ARG; + + while (sz) { + uint8_t *ptr = (uint8_t *)random; + int copy_len; + if (RNG_read(rngHandle, random) != RNG_RETURN_SUCCESS) { + ret = WC_HW_E; + goto cleanup_out; + } + copy_len = RNG_NUM_DWORDS * 4; + if (sz < copy_len) + copy_len = sz; + XMEMCPY(output, ptr, copy_len); + output += copy_len; + sz -= copy_len; + } + +cleanup_out: + ForceZero(random, sizeof(random)); + return ret; +} + #ifdef WOLFSSL_TI_AM64X_RNG_CTR_DRBG static uint32_t initialSeed[RNG_DRBG_SEED_MAX_ARRY_SIZE_IN_DWORD]; static int ti_sa2ul_trng_init_drbg(void) { if (_getSocUid() == 0) { - /* seed is 384 bits, uid is 256 bits, so copy uid 1.5x */ - XMEMCPY(initialSeed, socUid, sizeof(socUid)); - XMEMCPY(&initialSeed[8], socUid, sizeof(initialSeed) - sizeof(socUid)); + /* seed (384 bits) = 128-bit nonce + 256-bit uid */ + XMEMCPY(&initialSeed[4], socUid, sizeof(socUid)); + + RNG_close(rngHandle); + rngHandle = NULL; gRngConfig[0].attrs->mode = RNG_DRBG_MODE; gRngConfig[0].attrs->seedValue = initialSeed; gRngConfig[0].attrs->seedSizeInDwords = @@ -143,21 +183,29 @@ static int ti_sa2ul_trng_init_drbg(void) return WC_HW_E; } +#define TRNG_TIMEOUT_US (100000ULL) /* 100 ms */ static int ti_sa2ul_trng_get_drbg(byte* output, word32 sz) { + int ret = 0; + uint32_t random[RNG_NUM_DWORDS]; CSL_Cp_aceTrngRegs *pTrngRegs = (CSL_Cp_aceTrngRegs *)gRngConfig[0].attrs->rngBaseAddr; if (output == NULL && sz != 0) - return -1; + return BAD_FUNC_ARG; while (sz) { uint32_t val; - uint32_t random[RNG_NUM_DWORDS]; uint8_t *ptr = (uint8_t *)random; int copy_len; + uint64_t start_time; /* wait for READY==1 (random data ready) */ + start_time = ClockP_getTimeUsec(); do { + if (ClockP_getTimeUsec() - start_time > TRNG_TIMEOUT_US) { + ret = WC_HW_E; + goto cleanup_out; + } val = CSL_REG_RD(&pTrngRegs->TRNG_STATUS); } while ((val & CSL_CP_ACE_TRNG_STATUS_READY_MASK) != CSL_CP_ACE_TRNG_STATUS_READY_MASK); @@ -183,45 +231,29 @@ static int ti_sa2ul_trng_get_drbg(byte* output, word32 sz) sz -= copy_len; } - return 0; -} -#else -static int ti_sa2ul_trng_init_nrbg(void) -{ - gRngConfig[0].attrs->mode = RNG_DRBG_DISABLE_MODE; - return ti_sa2ul_trng_init_common(); -} - -static int ti_sa2ul_trng_get_nrbg(byte* output, word32 sz) -{ - if (output == NULL && sz != 0) - return -1; - - while (sz) { - uint32_t random[RNG_NUM_DWORDS]; - uint8_t *ptr = (uint8_t *)random; - int copy_len; - if (RNG_read(rngHandle, random) != RNG_RETURN_SUCCESS) - return -1; - copy_len = RNG_NUM_DWORDS * 4; - if (sz < copy_len) - copy_len = sz; - XMEMCPY(output, ptr, copy_len); - output += copy_len; - sz -= copy_len; - } - - return 0; +cleanup_out: + ForceZero(random, sizeof(random)); + return ret; } #endif /* WOLFSSL_TI_AM64X_RNG_CTR_DRBG */ static int ti_sa2ul_trng_init(void) { + int ret; + + ret = ti_sa2ul_trng_init_nrbg(); + #ifdef WOLFSSL_TI_AM64X_RNG_CTR_DRBG - return ti_sa2ul_trng_init_drbg(); -#else - return ti_sa2ul_trng_init_nrbg(); + /* use the nrbg to generate a 128-bit nonce for the drbg seed */ + if (ret == 0) { + ret = ti_sa2ul_trng_get_nrbg((byte*)&initialSeed[0], RNG_NUM_DWORDS * 4); + } + if (ret == 0) { + ret = ti_sa2ul_trng_init_drbg(); + } #endif + + return ret; } int ti_sa2ul_trng_get(byte* output, word32 sz) @@ -286,7 +318,6 @@ static int check_aes_keylength(word32 keylen) static int ti_sa2ul_AesCbcEncrypt(Aes* aes, byte* out, const byte* in, word32 sz) { int ret = 0; - SA2UL_ContextParams scParams; if (aes == NULL) return BAD_FUNC_ARG; @@ -315,24 +346,26 @@ static int ti_sa2ul_AesCbcEncrypt(Aes* aes, byte* out, const byte* in, word32 sz XMEMCPY(&scParams.key[0], aes->devKey, aes->keylen); XMEMCPY(&scParams.iv[0], aes->reg, AES_IV_SIZE); scParams.inputLen = sz; - aes->scObj.totalLengthInBytes = sz; + scObj.totalLengthInBytes = sz; if (SA2UL_contextAlloc(cryptoCtx.drvHandle, - &aes->scObj, &scParams) != SystemP_SUCCESS) + &scObj, &scParams) != SystemP_SUCCESS) { ret = WC_HW_E; } + ForceZero(scParams.key, sizeof(scParams.key)); + if (ret == 0) { CacheP_wbInv((void *)in, sz, CacheP_TYPE_ALLD); - if (SA2UL_contextProcess(&aes->scObj, in, sz, out) != SystemP_SUCCESS) + if (SA2UL_contextProcess(&scObj, in, sz, out) != SystemP_SUCCESS) ret = WC_HW_E; - - XMEMCPY(aes->reg, out + sz - WC_AES_BLOCK_SIZE, WC_AES_BLOCK_SIZE); + else + XMEMCPY(aes->reg, out + sz - WC_AES_BLOCK_SIZE, WC_AES_BLOCK_SIZE); } - (void)SA2UL_contextFree(&aes->scObj); + (void)SA2UL_contextFree(&scObj); ti_sa2ul_unlock_mutex(); @@ -343,7 +376,6 @@ static int ti_sa2ul_AesCbcEncrypt(Aes* aes, byte* out, const byte* in, word32 sz static int ti_sa2ul_AesCbcDecrypt(Aes* aes, byte* out, const byte* in, word32 sz) { int ret = 0; - SA2UL_ContextParams scParams; byte tmp_iv[WC_AES_BLOCK_SIZE]; if (aes == NULL) @@ -373,26 +405,28 @@ static int ti_sa2ul_AesCbcDecrypt(Aes* aes, byte* out, const byte* in, word32 sz XMEMCPY(&scParams.key[0], aes->devKey, aes->keylen); XMEMCPY(&scParams.iv[0], aes->reg, AES_IV_SIZE); scParams.inputLen = sz; - aes->scObj.totalLengthInBytes = sz; + scObj.totalLengthInBytes = sz; if (SA2UL_contextAlloc(cryptoCtx.drvHandle, - &aes->scObj, &scParams) != SystemP_SUCCESS) + &scObj, &scParams) != SystemP_SUCCESS) { ret = WC_HW_E; } + ForceZero(scParams.key, sizeof(scParams.key)); + if (ret == 0) { XMEMCPY(tmp_iv, in + sz - WC_AES_BLOCK_SIZE, WC_AES_BLOCK_SIZE); CacheP_wbInv((void *)in, sz, CacheP_TYPE_ALLD); - if (SA2UL_contextProcess(&aes->scObj, in, sz, out) != SystemP_SUCCESS) + if (SA2UL_contextProcess(&scObj, in, sz, out) != SystemP_SUCCESS) ret = WC_HW_E; - - XMEMCPY(aes->reg, tmp_iv, WC_AES_BLOCK_SIZE); + else + XMEMCPY(aes->reg, tmp_iv, WC_AES_BLOCK_SIZE); } - (void)SA2UL_contextFree(&aes->scObj); + (void)SA2UL_contextFree(&scObj); ti_sa2ul_unlock_mutex(); @@ -405,7 +439,6 @@ static int ti_sa2ul_AesCbcDecrypt(Aes* aes, byte* out, const byte* in, word32 sz static int ti_sa2ul_AesEcbEncrypt(Aes* aes, byte* out, const byte* in, word32 sz) { int ret = 0; - SA2UL_ContextParams scParams; if (aes == NULL) return BAD_FUNC_ARG; @@ -434,22 +467,24 @@ static int ti_sa2ul_AesEcbEncrypt(Aes* aes, byte* out, const byte* in, word32 sz XMEMCPY(&scParams.key[0], aes->devKey, aes->keylen); XMEMCPY(&scParams.iv[0], aes->reg, AES_IV_SIZE); scParams.inputLen = sz; - aes->scObj.totalLengthInBytes = sz; + scObj.totalLengthInBytes = sz; if (SA2UL_contextAlloc(cryptoCtx.drvHandle, - &aes->scObj, &scParams) != SystemP_SUCCESS) + &scObj, &scParams) != SystemP_SUCCESS) { ret = WC_HW_E; } + ForceZero(scParams.key, sizeof(scParams.key)); + if (ret == 0) { CacheP_wbInv((void *)in, sz, CacheP_TYPE_ALLD); - if (SA2UL_contextProcess(&aes->scObj, in, sz, out) != SystemP_SUCCESS) + if (SA2UL_contextProcess(&scObj, in, sz, out) != SystemP_SUCCESS) ret = WC_HW_E; } - (void)SA2UL_contextFree(&aes->scObj); + (void)SA2UL_contextFree(&scObj); ti_sa2ul_unlock_mutex(); @@ -460,7 +495,6 @@ static int ti_sa2ul_AesEcbEncrypt(Aes* aes, byte* out, const byte* in, word32 sz static int ti_sa2ul_AesEcbDecrypt(Aes* aes, byte* out, const byte* in, word32 sz) { int ret = 0; - SA2UL_ContextParams scParams; if (aes == NULL) return BAD_FUNC_ARG; @@ -489,22 +523,24 @@ static int ti_sa2ul_AesEcbDecrypt(Aes* aes, byte* out, const byte* in, word32 sz XMEMCPY(&scParams.key[0], aes->devKey, aes->keylen); XMEMCPY(&scParams.iv[0], aes->reg, AES_IV_SIZE); scParams.inputLen = sz; - aes->scObj.totalLengthInBytes = sz; + scObj.totalLengthInBytes = sz; if (SA2UL_contextAlloc(cryptoCtx.drvHandle, - &aes->scObj, &scParams) != SystemP_SUCCESS) + &scObj, &scParams) != SystemP_SUCCESS) { ret = WC_HW_E; } + ForceZero(scParams.key, sizeof(scParams.key)); + if (ret == 0) { CacheP_wbInv((void *)in, sz, CacheP_TYPE_ALLD); - if (SA2UL_contextProcess(&aes->scObj, in, sz, out) != SystemP_SUCCESS) + if (SA2UL_contextProcess(&scObj, in, sz, out) != SystemP_SUCCESS) ret = WC_HW_E; } - (void)SA2UL_contextFree(&aes->scObj); + (void)SA2UL_contextFree(&scObj); ti_sa2ul_unlock_mutex(); @@ -520,11 +556,12 @@ static void _override_iv_with_ghash(Aes* aes, const byte* iv, word32 ivSz) byte ivtmp[WC_AES_BLOCK_SIZE]; GHASH(&aes->gcm, NULL, 0, iv, ivSz, ivtmp, WC_AES_BLOCK_SIZE); - XMEMCPY(aes->scObj.ctxPrms.iv, ivtmp, WC_AES_BLOCK_SIZE); - _64byteReverseWords((uint32_t*)&sc, (uint32_t*)&aes->scObj.secCtx, sizeof(sc)); + XMEMCPY(scObj.ctxPrms.iv, ivtmp, WC_AES_BLOCK_SIZE); + _64byteReverseWords((uint32_t*)&sc, (uint32_t*)&scObj.secCtx, sizeof(sc)); _u8LeToU32(sc.u.enc.encAux3, ivtmp, WC_AES_BLOCK_SIZE); - _64byteReverseWords((uint32_t*)&aes->scObj.secCtx, (uint32_t*)&sc, sizeof(sc)); - CacheP_wbInv(&aes->scObj.secCtx, sizeof(sc), CacheP_TYPE_ALLD); + _64byteReverseWords((uint32_t*)&scObj.secCtx, (uint32_t*)&sc, sizeof(sc)); + CacheP_wbInv(&scObj.secCtx, sizeof(sc), CacheP_TYPE_ALLD); + ForceZero(&sc, sizeof(sc)); } static int ti_sa2ul_AesGcmEncrypt(Aes* aes, byte* out, @@ -534,7 +571,6 @@ static int ti_sa2ul_AesGcmEncrypt(Aes* aes, byte* out, const byte* authIn, word32 authInSz) { int ret = 0; - SA2UL_ContextParams scParams; if (aes == NULL) return BAD_FUNC_ARG; @@ -571,14 +607,16 @@ static int ti_sa2ul_AesGcmEncrypt(Aes* aes, byte* out, scParams.aadLen = 0; } scParams.inputLen = sz; - aes->scObj.totalLengthInBytes = sz; + scObj.totalLengthInBytes = sz; if (SA2UL_contextAlloc(cryptoCtx.drvHandle, - &aes->scObj, &scParams) != SystemP_SUCCESS) + &scObj, &scParams) != SystemP_SUCCESS) { ret = WC_HW_E; } + ForceZero(scParams.key, sizeof(scParams.key)); + if (ret == 0) { if (ivSz != GCM_NONCE_MID_SZ) { _override_iv_with_ghash(aes, iv, ivSz); @@ -586,17 +624,13 @@ static int ti_sa2ul_AesGcmEncrypt(Aes* aes, byte* out, CacheP_wbInv((void *)in, sz, CacheP_TYPE_ALLD); - if (SA2UL_contextProcess(&aes->scObj, in, sz, out) != SystemP_SUCCESS) + if (SA2UL_contextProcess(&scObj, in, sz, out) != SystemP_SUCCESS) ret = WC_HW_E; } - (void)SA2UL_contextFree(&aes->scObj); - - ti_sa2ul_unlock_mutex(); - if (ret == 0 && authTag != NULL) { if (authInSz <= sizeof(scParams.aad)) { - XMEMCPY(authTag, aes->scObj.computedHash, authTagSz); + XMEMCPY(authTag, scObj.computedHash, authTagSz); } else { ALIGN16 byte initialCounter[WC_AES_BLOCK_SIZE]; @@ -610,7 +644,7 @@ static int ti_sa2ul_AesGcmEncrypt(Aes* aes, byte* out, initialCounter[WC_AES_BLOCK_SIZE-1] = 1; } else { - XMEMCPY(initialCounter, aes->scObj.ctxPrms.iv, WC_AES_BLOCK_SIZE); + XMEMCPY(initialCounter, scObj.ctxPrms.iv, WC_AES_BLOCK_SIZE); } ret = wc_AesEncryptDirect(aes, scratch, initialCounter); if (ret == 0) @@ -618,6 +652,10 @@ static int ti_sa2ul_AesGcmEncrypt(Aes* aes, byte* out, } } + (void)SA2UL_contextFree(&scObj); + + ti_sa2ul_unlock_mutex(); + return ret; } @@ -629,7 +667,6 @@ static int ti_sa2ul_AesGcmDecrypt(Aes* aes, byte* out, const byte* authIn, word32 authInSz) { int ret = 0; - SA2UL_ContextParams scParams; if (aes == NULL) return BAD_FUNC_ARG; @@ -666,58 +703,63 @@ static int ti_sa2ul_AesGcmDecrypt(Aes* aes, byte* out, scParams.aadLen = 0; } scParams.inputLen = sz; - aes->scObj.totalLengthInBytes = sz; + scObj.totalLengthInBytes = sz; if (SA2UL_contextAlloc(cryptoCtx.drvHandle, - &aes->scObj, &scParams) != SystemP_SUCCESS) + &scObj, &scParams) != SystemP_SUCCESS) { ret = WC_HW_E; } + ForceZero(scParams.key, sizeof(scParams.key)); + if (ret == 0) { if (ivSz != GCM_NONCE_MID_SZ) { _override_iv_with_ghash(aes, iv, ivSz); } - - CacheP_wbInv((void *)in, sz, CacheP_TYPE_ALLD); - - if (SA2UL_contextProcess(&aes->scObj, in, sz, out) != SystemP_SUCCESS) - ret = WC_HW_E; } - (void)SA2UL_contextFree(&aes->scObj); - - ti_sa2ul_unlock_mutex(); - - if (ret == 0 && authTag != NULL) { - if (authInSz <= sizeof(scParams.aad)) { - if (ConstantCompare(authTag, aes->scObj.computedHash, authTagSz) != 0) - ret = WC_NO_ERR_TRACE(AES_GCM_AUTH_E); + if (ret == 0 && authTag != NULL && authInSz > sizeof(scParams.aad)) { + ALIGN16 byte initialCounter[WC_AES_BLOCK_SIZE]; + ALIGN16 byte scratch[WC_AES_BLOCK_SIZE]; + ALIGN16 byte Tprime[WC_AES_BLOCK_SIZE]; + GHASH(&aes->gcm, authIn, authInSz, in, sz, Tprime, sizeof(Tprime)); + if (ivSz == GCM_NONCE_MID_SZ) { + XMEMCPY(initialCounter, iv, ivSz); + initialCounter[WC_AES_BLOCK_SIZE-4] = 0; + initialCounter[WC_AES_BLOCK_SIZE-3] = 0; + initialCounter[WC_AES_BLOCK_SIZE-2] = 0; + initialCounter[WC_AES_BLOCK_SIZE-1] = 1; } else { - ALIGN16 byte initialCounter[WC_AES_BLOCK_SIZE]; - ALIGN16 byte scratch[WC_AES_BLOCK_SIZE]; - ALIGN16 byte Tprime[WC_AES_BLOCK_SIZE]; - GHASH(&aes->gcm, authIn, authInSz, in, sz, Tprime, sizeof(Tprime)); - if (ivSz == GCM_NONCE_MID_SZ) { - XMEMCPY(initialCounter, iv, ivSz); - initialCounter[WC_AES_BLOCK_SIZE-4] = 0; - initialCounter[WC_AES_BLOCK_SIZE-3] = 0; - initialCounter[WC_AES_BLOCK_SIZE-2] = 0; - initialCounter[WC_AES_BLOCK_SIZE-1] = 1; - } - else { - XMEMCPY(initialCounter, aes->scObj.ctxPrms.iv, WC_AES_BLOCK_SIZE); - } - ret = wc_AesEncryptDirect(aes, scratch, initialCounter); - if (ret == 0) { - xorbuf(Tprime, scratch, sizeof(Tprime)); - if (ConstantCompare(authTag, Tprime, authTagSz) != 0) - ret = WC_NO_ERR_TRACE(AES_GCM_AUTH_E); + XMEMCPY(initialCounter, scObj.ctxPrms.iv, WC_AES_BLOCK_SIZE); + } + ret = wc_AesEncryptDirect(aes, scratch, initialCounter); + if (ret == 0) { + xorbuf(Tprime, scratch, sizeof(Tprime)); + if (ConstantCompare(authTag, Tprime, authTagSz) != 0) { + ret = WC_NO_ERR_TRACE(AES_GCM_AUTH_E); } } } + if (ret == 0) { + CacheP_wbInv((void *)in, sz, CacheP_TYPE_ALLD); + if (SA2UL_contextProcess(&scObj, in, sz, out) != SystemP_SUCCESS) + ret = WC_HW_E; + } + + if (ret == 0 && authTag != NULL && authInSz <= sizeof(scParams.aad)) { + if (ConstantCompare(authTag, scObj.computedHash, authTagSz) != 0) { + ForceZero(out, sz); + ret = WC_NO_ERR_TRACE(AES_GCM_AUTH_E); + } + } + + (void)SA2UL_contextFree(&scObj); + + ti_sa2ul_unlock_mutex(); + return ret; } #endif /* HAVE_AES_DECRYPT */ @@ -731,13 +773,11 @@ static int ti_sa2ul_AesGcmDecrypt(Aes* aes, byte* out, * use the data. So, we consider this a scratch buffer, but it also limits * the amount of data we can hash at one time. */ #define HASH_SCRATCH_SIZE 0x2000u -static byte hash_scratch[HASH_SCRATCH_SIZE] XALIGNED(SA2UL_CACHELINE_ALIGNMENT); +static XALIGNED(SA2UL_CACHELINE_ALIGNMENT) byte hash_scratch[HASH_SCRATCH_SIZE]; #ifndef NO_SHA256 static int ti_sa2ul_InitSha256_ctx(wc_Sha256* sha256) { - SA2UL_ContextParams scParams; - if (ti_sa2ul_lock_mutex() != 0) { /* mark as copy so we continue to fall back to software */ sha256->flags |= WC_HASH_FLAG_ISCOPY; @@ -750,46 +790,51 @@ static int ti_sa2ul_InitSha256_ctx(wc_Sha256* sha256) scParams.hashAlg = SA2UL_HASH_ALG_SHA2_256; /* default length to all ff's, final will override when known */ scParams.inputLen = 0xffffffffUL; - sha256->scObj.totalLengthInBytes = 0xffffffffUL; + scObj.totalLengthInBytes = 0xffffffffUL; if (SA2UL_contextAlloc(cryptoCtx.drvHandle, - &sha256->scObj, &scParams) != SystemP_SUCCESS) + &scObj, &scParams) != SystemP_SUCCESS) { ti_sa2ul_unlock_mutex(); return WC_HW_E; } + sha256->devCtx = (void *)&scObj; + return 0; } static void ti_sa2ul_Sha256Free_ctx(wc_Sha256* sha256) { - (void)SA2UL_contextFree(&sha256->scObj); + (void)SA2UL_contextFree(&scObj); + + sha256->devCtx = NULL; ti_sa2ul_unlock_mutex(); } -void ti_sa2ul_Sha256Teardown(wc_Sha256* sha256) +static void ti_sa2ul_Sha256Teardown(wc_Sha256* sha256) { - if (sha256 != NULL) { + if (sha256 != NULL && sha256->devCtx == (void*)&scObj) { /* hash will be finalized in sw via fallback, but we need the driver * to tear down the context in hw. To do that, we update the context * length and push some final arbitrary data. It will not affect * the hash */ - if ((sha256->flags & WC_HASH_FLAG_ISCOPY) == 0 && - sha256->scObj.txBytesCnt != 0) - { - byte buffer[WC_SHA256_DIGEST_SIZE]; - sha256->scObj.ctxPrms.inputLen = sha256->scObj.txBytesCnt + - WC_SHA256_DIGEST_SIZE; - sha256->scObj.totalLengthInBytes = sha256->scObj.txBytesCnt + - WC_SHA256_DIGEST_SIZE; - CacheP_wbInv((void *)buffer, WC_SHA256_DIGEST_SIZE, CacheP_TYPE_ALLD); - SA2UL_contextProcess(&sha256->scObj, buffer, - WC_SHA256_DIGEST_SIZE, hash_scratch); - ti_sa2ul_Sha256Free_ctx(sha256); - } - XMEMSET(&sha256->scObj, 0, sizeof(sha256->scObj)); + byte buffer[WC_SHA256_DIGEST_SIZE]; + scObj.ctxPrms.inputLen = scObj.txBytesCnt + WC_SHA256_DIGEST_SIZE; + scObj.totalLengthInBytes = scObj.txBytesCnt + WC_SHA256_DIGEST_SIZE; + CacheP_wbInv((void *)buffer, WC_SHA256_DIGEST_SIZE, CacheP_TYPE_ALLD); + SA2UL_contextProcess(&scObj, buffer, + WC_SHA256_DIGEST_SIZE, hash_scratch); + ti_sa2ul_Sha256Free_ctx(sha256); + } +} + +static WC_INLINE void ti_sa2ul_Sha256AddLength(wc_Sha256* sha256, word32 len) +{ + word32 tmp = sha256->loLen; + if ((sha256->loLen += len) < tmp) { + sha256->hiLen++; } } @@ -806,7 +851,7 @@ static int ti_sa2ul_Sha256Hash(wc_Sha256* sha256, const byte* in, if ((sha256->flags & WC_HASH_FLAG_ISCOPY) != 0) return CRYPTOCB_UNAVAILABLE; - if (sha256->scObj.txBytesCnt == 0 && + if (sha256->devCtx != (void*)&scObj && inSz + sha256->buffLen >= WC_SHA256_BLOCK_SIZE) { ret = ti_sa2ul_InitSha256_ctx(sha256); @@ -816,7 +861,7 @@ static int ti_sa2ul_Sha256Hash(wc_Sha256* sha256, const byte* in, if (in != NULL) { /* update... */ - sha256->loLen += inSz; + ti_sa2ul_Sha256AddLength(sha256, inSz); /* handle leftovers first */ if (sha256->buffLen > 0) { @@ -828,12 +873,12 @@ static int ti_sa2ul_Sha256Hash(wc_Sha256* sha256, const byte* in, if (sha256->buffLen == WC_SHA256_BLOCK_SIZE) { CacheP_wbInv((void *)buffer, WC_SHA256_BLOCK_SIZE, CacheP_TYPE_ALLD); - if (SA2UL_contextProcess(&sha256->scObj, buffer, + if (SA2UL_contextProcess(&scObj, buffer, WC_SHA256_BLOCK_SIZE, hash_scratch) != SystemP_SUCCESS) { return WC_HW_E; } - XMEMCPY(sha256->digest, &sha256->scObj.computedHash, + XMEMCPY(sha256->digest, &scObj.computedHash, WC_SHA256_DIGEST_SIZE); /* final will fall back to sw, and sw needs bytes reversed */ ByteReverseWords(sha256->digest, sha256->digest, @@ -846,11 +891,11 @@ static int ti_sa2ul_Sha256Hash(wc_Sha256* sha256, const byte* in, blocksLen = min(sizeof(hash_scratch), inSz & ~((word32)WC_SHA256_BLOCK_SIZE-1)); CacheP_wbInv((void *)in, blocksLen, CacheP_TYPE_ALLD); - if (SA2UL_contextProcess(&sha256->scObj, in, blocksLen, + if (SA2UL_contextProcess(&scObj, in, blocksLen, hash_scratch) != SystemP_SUCCESS) { return WC_HW_E; } - XMEMCPY(sha256->digest, &sha256->scObj.computedHash, + XMEMCPY(sha256->digest, &scObj.computedHash, WC_SHA256_DIGEST_SIZE); ByteReverseWords(sha256->digest, sha256->digest, WC_SHA256_DIGEST_SIZE); @@ -877,8 +922,6 @@ static int ti_sa2ul_Sha256Hash(wc_Sha256* sha256, const byte* in, #ifdef WOLFSSL_SHA512 static int ti_sa2ul_InitSha512_ctx(wc_Sha512* sha512) { - SA2UL_ContextParams scParams; - if (ti_sa2ul_lock_mutex() != 0) { /* mark as copy so we continue to fall back to software */ sha512->flags |= WC_HASH_FLAG_ISCOPY; @@ -891,47 +934,53 @@ static int ti_sa2ul_InitSha512_ctx(wc_Sha512* sha512) scParams.hashAlg = SA2UL_HASH_ALG_SHA2_512; /* default length to all ff's, final will override when known */ scParams.inputLen = 0xffffffffUL; - sha512->scObj.totalLengthInBytes = 0xffffffffUL; + scObj.totalLengthInBytes = 0xffffffffUL; if (SA2UL_contextAlloc(cryptoCtx.drvHandle, - &sha512->scObj, &scParams) != SystemP_SUCCESS) + &scObj, &scParams) != SystemP_SUCCESS) { ti_sa2ul_unlock_mutex(); return WC_HW_E; } + sha512->devCtx = (void *)&scObj; + return 0; } static void ti_sa2ul_Sha512Free_ctx(wc_Sha512* sha512) { - (void)SA2UL_contextFree(&sha512->scObj); + (void)SA2UL_contextFree(&scObj); + + sha512->devCtx = NULL; ti_sa2ul_unlock_mutex(); } -void ti_sa2ul_Sha512Teardown(wc_Sha512* sha512) +static void ti_sa2ul_Sha512Teardown(wc_Sha512* sha512) { - if (sha512 != NULL) { + if (sha512 != NULL && sha512->devCtx == (void*)&scObj) { /* hash will be finalized in sw via fallback, but we need the driver * to tear down the context in hw. To do that, we update the context * length and push some final arbitrary data. It will not affect * the hash */ - if (sha512->hashType == WC_HASH_TYPE_SHA512 && - (sha512->flags & WC_HASH_FLAG_ISCOPY) == 0 && - sha512->scObj.txBytesCnt != 0) - { - byte buffer[WC_SHA512_DIGEST_SIZE]; - sha512->scObj.ctxPrms.inputLen = sha512->scObj.txBytesCnt + - WC_SHA512_DIGEST_SIZE; - sha512->scObj.totalLengthInBytes = sha512->scObj.txBytesCnt + - WC_SHA512_DIGEST_SIZE; - CacheP_wbInv((void *)buffer, WC_SHA512_DIGEST_SIZE, CacheP_TYPE_ALLD); - SA2UL_contextProcess(&sha512->scObj, buffer, - WC_SHA512_DIGEST_SIZE, hash_scratch); - ti_sa2ul_Sha512Free_ctx(sha512); - } - XMEMSET(&sha512->scObj, 0, sizeof(sha512->scObj)); + byte buffer[WC_SHA512_DIGEST_SIZE]; + scObj.ctxPrms.inputLen = scObj.txBytesCnt + + WC_SHA512_DIGEST_SIZE; + scObj.totalLengthInBytes = scObj.txBytesCnt + + WC_SHA512_DIGEST_SIZE; + CacheP_wbInv((void *)buffer, WC_SHA512_DIGEST_SIZE, CacheP_TYPE_ALLD); + SA2UL_contextProcess(&scObj, buffer, + WC_SHA512_DIGEST_SIZE, hash_scratch); + ti_sa2ul_Sha512Free_ctx(sha512); + } +} + +static WC_INLINE void ti_sa2ul_Sha512AddLength(wc_Sha512* sha512, word32 len) +{ + word32 tmp = sha512->loLen; + if ((sha512->loLen += len) < tmp) { + sha512->hiLen++; } } @@ -950,7 +999,7 @@ static int ti_sa2ul_Sha512Hash(wc_Sha512* sha512, const byte* in, return CRYPTOCB_UNAVAILABLE; } - if (sha512->scObj.txBytesCnt == 0 && + if (sha512->devCtx != (void*)&scObj && inSz + sha512->buffLen >= WC_SHA512_BLOCK_SIZE) { ret = ti_sa2ul_InitSha512_ctx(sha512); @@ -960,7 +1009,7 @@ static int ti_sa2ul_Sha512Hash(wc_Sha512* sha512, const byte* in, if (in != NULL) { /* update... */ - sha512->loLen += inSz; + ti_sa2ul_Sha512AddLength(sha512, inSz); /* handle leftovers first */ if (sha512->buffLen > 0) { @@ -971,12 +1020,12 @@ static int ti_sa2ul_Sha512Hash(wc_Sha512* sha512, const byte* in, inSz -= partialLen; if (sha512->buffLen == WC_SHA512_BLOCK_SIZE) { CacheP_wbInv((void *)buffer, WC_SHA512_BLOCK_SIZE, CacheP_TYPE_ALLD); - if (SA2UL_contextProcess(&sha512->scObj, buffer, + if (SA2UL_contextProcess(&scObj, buffer, WC_SHA512_BLOCK_SIZE, hash_scratch) != SystemP_SUCCESS) { return WC_HW_E; } - XMEMCPY(sha512->digest, &sha512->scObj.computedHash, + XMEMCPY(sha512->digest, &scObj.computedHash, WC_SHA512_DIGEST_SIZE); /* final will fall back to sw, and sw needs bytes reversed */ ByteReverseWords64(sha512->digest, sha512->digest, @@ -989,11 +1038,11 @@ static int ti_sa2ul_Sha512Hash(wc_Sha512* sha512, const byte* in, blocksLen = min(sizeof(hash_scratch), inSz & ~((word32)WC_SHA512_BLOCK_SIZE-1)); CacheP_wbInv((void *)in, blocksLen, CacheP_TYPE_ALLD); - if (SA2UL_contextProcess(&sha512->scObj, in, blocksLen, + if (SA2UL_contextProcess(&scObj, in, blocksLen, hash_scratch) != SystemP_SUCCESS) { return WC_HW_E; } - XMEMCPY(sha512->digest, &sha512->scObj.computedHash, + XMEMCPY(sha512->digest, &scObj.computedHash, WC_SHA512_DIGEST_SIZE); ByteReverseWords64(sha512->digest, sha512->digest, WC_SHA512_DIGEST_SIZE); diff --git a/wolfcrypt/src/sha256.c b/wolfcrypt/src/sha256.c index 6e985bdb6f7..891d8708e3d 100644 --- a/wolfcrypt/src/sha256.c +++ b/wolfcrypt/src/sha256.c @@ -171,10 +171,6 @@ on the specific device platform. #include #endif -#ifdef WOLFSSL_TI_AM64X_R5 - #include -#endif - #if FIPS_VERSION3_GE(6,0,0) const unsigned int wolfCrypt_FIPS_sha256_ro_sanity[2] = { 0x1a2b3c4d, 0x00000014 }; @@ -334,10 +330,6 @@ static int InitSha256(wc_Sha256* sha256) sha256->used = 0; #endif -#if defined(WOLFSSL_TI_AM64X_R5) && !defined(WOLFSSL_TI_AM64X_NO_SHA) - ti_sa2ul_Sha256Teardown(sha256); -#endif - #if (defined(WOLFSSL_X86_64_BUILD) && defined(USE_INTEL_SPEEDUP) && \ (defined(HAVE_INTEL_AVX1) || defined(HAVE_INTEL_AVX2))) || \ (defined(WOLFSSL_ARMASM) && defined(__aarch64__) && \ @@ -3604,6 +3596,10 @@ int wc_Sha256Copy(wc_Sha256* src, wc_Sha256* dst) } #endif +#if defined(WOLFSSL_TI_AM64X_R5) && !defined(WOLFSSL_TI_AM64X_NO_SHA) + dst->devCtx = NULL; +#endif + #ifdef WOLFSSL_HASH_FLAGS dst->flags |= WC_HASH_FLAG_ISCOPY; #endif diff --git a/wolfcrypt/src/sha512.c b/wolfcrypt/src/sha512.c index 64a52d8023e..67bab807abb 100644 --- a/wolfcrypt/src/sha512.c +++ b/wolfcrypt/src/sha512.c @@ -127,10 +127,6 @@ #include #endif -#ifdef WOLFSSL_TI_AM64X_R5 - #include -#endif - #if defined(MAX3266X_SHA) /* Already brought in by sha512.h */ /* #include */ @@ -943,10 +939,6 @@ static int InitSha512(wc_Sha512* sha512) sha512->loLen = 0; sha512->hiLen = 0; -#if defined(WOLFSSL_TI_AM64X_R5) && !defined(WOLFSSL_TI_AM64X_NO_SHA) - ti_sa2ul_Sha512Teardown(sha512); -#endif - #if (defined(WOLFSSL_X86_64_BUILD) && defined(USE_INTEL_SPEEDUP) && \ (defined(HAVE_INTEL_AVX1) || defined(HAVE_INTEL_AVX2))) || \ defined(WOLFSSL_ARMASM) @@ -3365,6 +3357,10 @@ int wc_Sha512Copy(wc_Sha512* src, wc_Sha512* dst) #endif /* WOLFSSL_USE_ESP32_CRYPT_HASH_HW */ +#if defined(WOLFSSL_TI_AM64X_R5) && !defined(WOLFSSL_TI_AM64X_NO_SHA) + dst->devCtx = NULL; +#endif + #ifdef WOLFSSL_HASH_FLAGS dst->flags |= WC_HASH_FLAG_ISCOPY; #endif diff --git a/wolfcrypt/test/test.c b/wolfcrypt/test/test.c index 03d30e71cd9..7e16ca6bad0 100644 --- a/wolfcrypt/test/test.c +++ b/wolfcrypt/test/test.c @@ -357,6 +357,7 @@ static const byte const_byte_array[] = "A+Gd\0\0\0"; #ifdef TI_MCU_PLUS_SDK # include "kernel/nortos/dpl/common/printf.h" +# undef printf # define printf printf_ #endif diff --git a/wolfssl/wolfcrypt/aes.h b/wolfssl/wolfcrypt/aes.h index b0bed588b2b..6b428203811 100644 --- a/wolfssl/wolfcrypt/aes.h +++ b/wolfssl/wolfcrypt/aes.h @@ -189,10 +189,6 @@ WOLFSSL_LOCAL void WC_ARG_NOT_NULL(1) GHASH(Gcm* gcm, const byte* a, #include "cy_crypto_common.h" #endif /* WOLFSSL_PSOC6_CRYPTO */ -#ifdef WOLFSSL_TI_AM64X_R5 - #include "security/security_common/drivers/crypto/sa2ul/sa2ul.h" -#endif - /* Backends that replace one or more AES mode entry points, either with a * hardware arm in aes.c or with a port file. Those entry points do not carry * the key-set guard, so the check is not applied on these builds. */ @@ -525,9 +521,6 @@ struct Aes { cy_stc_crypto_aes_gcm_state_t aes_gcm_state; #endif #endif /* WOLFSSL_PSOC6_CRYPTO */ -#if defined(WOLFSSL_TI_AM64X_R5) && !defined(WOLFSSL_TI_AM64X_NO_AES) - XALIGNED(SA2UL_CACHELINE_ALIGNMENT) SA2UL_ContextObject scObj; -#endif /* Set to 1 once a key has been installed (wc_AesSetKey/SetKeyDirect/ * GcmSetKey), including when a crypto callback takes ownership of it. diff --git a/wolfssl/wolfcrypt/port/ti/ti-sa2ul_r5_port.h b/wolfssl/wolfcrypt/port/ti/ti-sa2ul_r5_port.h index 7a4a9256656..1df2e5a9a56 100644 --- a/wolfssl/wolfcrypt/port/ti/ti-sa2ul_r5_port.h +++ b/wolfssl/wolfcrypt/port/ti/ti-sa2ul_r5_port.h @@ -37,8 +37,6 @@ #endif int ti_sa2ul_port_init(void); -void ti_sa2ul_Sha256Teardown(wc_Sha256* sha256); -void ti_sa2ul_Sha512Teardown(wc_Sha512* sha512); void ti_sa2ul_soc_uid(uint8_t *uid); int ti_sa2ul_trng_get(byte* output, word32 sz); diff --git a/wolfssl/wolfcrypt/settings.h b/wolfssl/wolfcrypt/settings.h index 3c60ccf19a0..5b64dcc8ab1 100644 --- a/wolfssl/wolfcrypt/settings.h +++ b/wolfssl/wolfcrypt/settings.h @@ -2517,14 +2517,10 @@ #endif #ifdef WOLFSSL_TI_AM64X_R5 - #define HAVE_AES_ECB - #define NO_AES_192 #define NO_DEV_RANDOM - #define WOLFSSL_AES_128 - #define WOLFSSL_AES_256 - #define WOLFSSL_AES_DIRECT - #define WOLFSSL_CMAC - #define WOLFSSL_SHA512 + #ifndef TI_MCU_PLUS_SDK + #define TI_MCU_PLUS_SDK + #endif #define WOLFSSL_SHA512_HASHTYPE #ifndef WOLF_CRYPTO_CB #define WOLF_CRYPTO_CB diff --git a/wolfssl/wolfcrypt/sha256.h b/wolfssl/wolfcrypt/sha256.h index 19c63ab30f5..b0134472ff5 100644 --- a/wolfssl/wolfcrypt/sha256.h +++ b/wolfssl/wolfcrypt/sha256.h @@ -167,10 +167,6 @@ #include "mcapi_error.h" #endif -#ifdef WOLFSSL_TI_AM64X_R5 - #include "security/security_common/drivers/crypto/sa2ul/sa2ul.h" -#endif - /* wc_Sha256 digest */ struct wc_Sha256 { @@ -258,9 +254,6 @@ struct wc_Sha256 { #ifdef WOLFSSL_HASH_FLAGS word32 flags; /* enum wc_HashFlags in hash.h */ #endif -#if defined(WOLFSSL_TI_AM64X_R5) && !defined(WOLFSSL_TI_AM64X_NO_SHA) - XALIGNED(SA2UL_CACHELINE_ALIGNMENT) SA2UL_ContextObject scObj; -#endif }; #ifndef WC_SHA256_TYPE_DEFINED diff --git a/wolfssl/wolfcrypt/sha512.h b/wolfssl/wolfcrypt/sha512.h index 6c761f10cac..b3323d17ccd 100644 --- a/wolfssl/wolfcrypt/sha512.h +++ b/wolfssl/wolfcrypt/sha512.h @@ -147,9 +147,6 @@ #if defined(WOLFSSL_MAX3266X) || defined(WOLFSSL_MAX3266X_OLD) #include "wolfssl/wolfcrypt/port/maxim/max3266x.h" #endif -#ifdef WOLFSSL_TI_AM64X_R5 - #include "security/security_common/drivers/crypto/sa2ul/sa2ul.h" -#endif /* wc_Sha512 digest */ struct wc_Sha512 { @@ -215,9 +212,6 @@ struct wc_Sha512 { int hashType; /* used to determine which SHA512 is used */ #endif /* WOLFSSL_SHA512_HASHTYPE */ #endif /* WOLFSSL_PSOC6_CRYPTO */ -#if defined(WOLFSSL_TI_AM64X_R5) && !defined(WOLFSSL_TI_AM64X_NO_SHA) - XALIGNED(SA2UL_CACHELINE_ALIGNMENT) SA2UL_ContextObject scObj; -#endif };