/usr/src/linux-headers-5.15.0-181/include/crypto
NameSizeModeActions
internal/-0755rm
acompress.h90730644editdlrm
aead.h188320644editdlrm
aes.h25630644editdlrm
akcipher.h132320644editdlrm
algapi.h75450644editdlrm
arc4.h4840644editdlrm
asym_tpm_subtype.h5210644editdlrm
authenc.h6350644editdlrm
b128ops.h24710644editdlrm
blake2b.h16370644editdlrm
blake2s.h26800644editdlrm
blowfish.h4150644editdlrm
cast5.h5900644editdlrm
cast6.h6070644editdlrm
cast_common.h2320644editdlrm
chacha.h33950644editdlrm
chacha20poly1305.h16990644editdlrm
cryptd.h20500644editdlrm
ctr.h14560644editdlrm
curve25519.h20650644editdlrm
des.h17240644editdlrm
dh.h25740644editdlrm
drbg.h92090644editdlrm
ecc_curve.h13370644editdlrm
ecdh.h24870644editdlrm
engine.h42090644editdlrm
gcm.h8670644editdlrm
gf128mul.h96470644editdlrm
ghash.h3880644editdlrm
hash.h348590644editdlrm
hash_info.h9980644editdlrm
hmac.h1730644editdlrm
if_alg.h68440644editdlrm
kpp.h101440644editdlrm
md5.h4970644editdlrm
nhpoly1305.h22360644editdlrm
null.h3460644editdlrm
padlock.h4380644editdlrm
pcrypt.h8150644editdlrm
pkcs7.h11810644editdlrm
poly1305.h25000644editdlrm
public_key.h24400644editdlrm
rng.h67480644editdlrm
scatterwalk.h39890644editdlrm
serpent.h6960644editdlrm
sha1.h12100644editdlrm
sha1_base.h25120644editdlrm
sha2.h38490644editdlrm
sha3.h8790644editdlrm
sha256_base.h26210644editdlrm
sha512_base.h32550644editdlrm
skcipher.h204280644editdlrm
sm2.h7490644editdlrm
sm3.h8970644editdlrm
sm3_base.h26080644editdlrm
sm4.h11440644editdlrm
streebog.h9490644editdlrm
twofish.h7430644editdlrm
xts.h11250644editdlrm
Edit: /usr/src/linux-headers-5.15.0-181/include/crypto/chacha.h (3395B)
/* SPDX-License-Identifier: GPL-2.0 */ /* * Common values and helper functions for the ChaCha and XChaCha stream ciphers. * * XChaCha extends ChaCha's nonce to 192 bits, while provably retaining ChaCha's * security. Here they share the same key size, tfm context, and setkey * function; only their IV size and encrypt/decrypt function differ. * * The ChaCha paper specifies 20, 12, and 8-round variants. In general, it is * recommended to use the 20-round variant ChaCha20. However, the other * variants can be needed in some performance-sensitive scenarios. The generic * ChaCha code currently allows only the 20 and 12-round variants. */ #ifndef _CRYPTO_CHACHA_H #define _CRYPTO_CHACHA_H #include #include /* 32-bit stream position, then 96-bit nonce (RFC7539 convention) */ #define CHACHA_IV_SIZE 16 #define CHACHA_KEY_SIZE 32 #define CHACHA_BLOCK_SIZE 64 #define CHACHAPOLY_IV_SIZE 12 #define CHACHA_STATE_WORDS (CHACHA_BLOCK_SIZE / sizeof(u32)) /* 192-bit nonce, then 64-bit stream position */ #define XCHACHA_IV_SIZE 32 void chacha_block_generic(u32 *state, u8 *stream, int nrounds); static inline void chacha20_block(u32 *state, u8 *stream) { chacha_block_generic(state, stream, 20); } void hchacha_block_arch(const u32 *state, u32 *out, int nrounds); void hchacha_block_generic(const u32 *state, u32 *out, int nrounds); static inline void hchacha_block(const u32 *state, u32 *out, int nrounds) { if (IS_ENABLED(CONFIG_CRYPTO_ARCH_HAVE_LIB_CHACHA)) hchacha_block_arch(state, out, nrounds); else hchacha_block_generic(state, out, nrounds); } enum chacha_constants { /* expand 32-byte k */ CHACHA_CONSTANT_EXPA = 0x61707865U, CHACHA_CONSTANT_ND_3 = 0x3320646eU, CHACHA_CONSTANT_2_BY = 0x79622d32U, CHACHA_CONSTANT_TE_K = 0x6b206574U }; static inline void chacha_init_consts(u32 *state) { state[0] = CHACHA_CONSTANT_EXPA; state[1] = CHACHA_CONSTANT_ND_3; state[2] = CHACHA_CONSTANT_2_BY; state[3] = CHACHA_CONSTANT_TE_K; } void chacha_init_arch(u32 *state, const u32 *key, const u8 *iv); static inline void chacha_init_generic(u32 *state, const u32 *key, const u8 *iv) { chacha_init_consts(state); state[4] = key[0]; state[5] = key[1]; state[6] = key[2]; state[7] = key[3]; state[8] = key[4]; state[9] = key[5]; state[10] = key[6]; state[11] = key[7]; state[12] = get_unaligned_le32(iv + 0); state[13] = get_unaligned_le32(iv + 4); state[14] = get_unaligned_le32(iv + 8); state[15] = get_unaligned_le32(iv + 12); } static inline void chacha_init(u32 *state, const u32 *key, const u8 *iv) { if (IS_ENABLED(CONFIG_CRYPTO_ARCH_HAVE_LIB_CHACHA)) chacha_init_arch(state, key, iv); else chacha_init_generic(state, key, iv); } void chacha_crypt_arch(u32 *state, u8 *dst, const u8 *src, unsigned int bytes, int nrounds); void chacha_crypt_generic(u32 *state, u8 *dst, const u8 *src, unsigned int bytes, int nrounds); static inline void chacha_crypt(u32 *state, u8 *dst, const u8 *src, unsigned int bytes, int nrounds) { if (IS_ENABLED(CONFIG_CRYPTO_ARCH_HAVE_LIB_CHACHA)) chacha_crypt_arch(state, dst, src, bytes, nrounds); else chacha_crypt_generic(state, dst, src, bytes, nrounds); } static inline void chacha20_crypt(u32 *state, u8 *dst, const u8 *src, unsigned int bytes) { chacha_crypt(state, dst, src, bytes, 20); } #endif /* _CRYPTO_CHACHA_H */