#include <sys/types.h>
#include <sys/kmem.h>
#include <sys/cmn_err.h>
#include <sys/ddi.h>
#include <sys/sunddi.h>
#include <sys/ksynch.h>
#include <sys/crypto/common.h>
#include <sys/crypto/impl.h>
#define KCF_MAX_POLICY 512
static kmutex_t policy_tab_mutex;
static kcf_policy_desc_t **policy_tab = NULL;
static uint_t policy_tab_num = 0;
static uint_t policy_tab_max = KCF_MAX_POLICY;
static int kcf_policy_add_entry(kcf_policy_desc_t *);
static kcf_policy_desc_t *kcf_policy_alloc_desc(int);
void
kcf_policy_tab_init(void)
{
mutex_init(&policy_tab_mutex, NULL, MUTEX_DRIVER, NULL);
policy_tab = kmem_zalloc(policy_tab_max * sizeof (kcf_policy_desc_t *),
KM_SLEEP);
}
static int
kcf_policy_add_entry(kcf_policy_desc_t *policy_desc)
{
uint_t i = 0;
ASSERT(policy_tab != NULL);
ASSERT(MUTEX_HELD(&policy_tab_mutex));
while (i < KCF_MAX_POLICY && policy_tab[i] != NULL)
i++;
if (i == KCF_MAX_POLICY) {
cmn_err(CE_WARN, "out of policy entries");
return (CRYPTO_HOST_MEMORY);
}
policy_tab[i] = policy_desc;
KCF_POLICY_REFHOLD(policy_desc);
policy_tab_num++;
return (CRYPTO_SUCCESS);
}
void
kcf_policy_remove_by_name(char *module_name, uint_t *count,
crypto_mech_name_t **array)
{
kcf_policy_desc_t *policy_desc;
int i;
ASSERT(policy_tab != NULL);
ASSERT(policy_tab_num != (uint_t)-1);
mutex_enter(&policy_tab_mutex);
for (i = 0; i < KCF_MAX_POLICY; i++) {
if ((policy_desc = policy_tab[i]) != NULL &&
policy_desc->pd_prov_type == CRYPTO_SW_PROVIDER) {
ASSERT(policy_desc->pd_name != NULL);
if (strncmp(module_name, policy_desc->pd_name,
MAXNAMELEN) == 0) {
*count = policy_desc->pd_disabled_count;
*array = policy_desc->pd_disabled_mechs;
mutex_destroy(&policy_desc->pd_mutex);
kmem_free(policy_desc->pd_name,
strlen(policy_desc->pd_name) + 1);
kmem_free(policy_desc,
sizeof (kcf_policy_desc_t));
policy_tab[i] = NULL;
policy_tab_num--;
break;
}
}
}
if (i == KCF_MAX_POLICY) {
*count = 0;
*array = NULL;
}
mutex_exit(&policy_tab_mutex);
}
void
kcf_policy_remove_by_dev(char *name, uint_t instance, uint_t *count,
crypto_mech_name_t **array)
{
kcf_policy_desc_t *policy_desc;
int i;
ASSERT(policy_tab != NULL);
ASSERT(policy_tab_num != (uint_t)-1);
mutex_enter(&policy_tab_mutex);
for (i = 0; i < KCF_MAX_POLICY; i++) {
if ((policy_desc = policy_tab[i]) != NULL &&
policy_desc->pd_prov_type == CRYPTO_HW_PROVIDER &&
strncmp(policy_desc->pd_name, name, MAXNAMELEN) == 0 &&
policy_desc->pd_instance == instance) {
*count = policy_desc->pd_disabled_count;
*array = policy_desc->pd_disabled_mechs;
mutex_destroy(&policy_desc->pd_mutex);
kmem_free(policy_desc->pd_name,
strlen(policy_desc->pd_name) + 1);
kmem_free(policy_desc, sizeof (kcf_policy_desc_t));
policy_tab[i] = NULL;
policy_tab_num--;
break;
}
}
if (i == KCF_MAX_POLICY) {
*count = 0;
*array = NULL;
}
mutex_exit(&policy_tab_mutex);
}
kcf_policy_desc_t *
kcf_policy_lookup_by_name(char *module_name)
{
kcf_policy_desc_t *policy_desc;
uint_t i;
mutex_enter(&policy_tab_mutex);
for (i = 0; i < KCF_MAX_POLICY; i++) {
if ((policy_desc = policy_tab[i]) != NULL &&
policy_desc->pd_prov_type == CRYPTO_SW_PROVIDER) {
ASSERT(policy_desc->pd_name != NULL);
if (strncmp(module_name, policy_desc->pd_name,
MAXNAMELEN) == 0) {
KCF_POLICY_REFHOLD(policy_desc);
mutex_exit(&policy_tab_mutex);
return (policy_desc);
}
}
}
mutex_exit(&policy_tab_mutex);
return (NULL);
}
kcf_policy_desc_t *
kcf_policy_lookup_by_dev(char *name, uint_t instance)
{
kcf_policy_desc_t *policy_desc;
uint_t i;
mutex_enter(&policy_tab_mutex);
for (i = 0; i < KCF_MAX_POLICY; i++) {
if ((policy_desc = policy_tab[i]) != NULL &&
policy_desc->pd_prov_type == CRYPTO_HW_PROVIDER &&
strncmp(policy_desc->pd_name, name, MAXNAMELEN) == 0 &&
policy_desc->pd_instance == instance) {
KCF_POLICY_REFHOLD(policy_desc);
mutex_exit(&policy_tab_mutex);
return (policy_desc);
}
}
mutex_exit(&policy_tab_mutex);
return (NULL);
}
int
kcf_policy_load_soft_disabled(char *module_name, uint_t new_count,
crypto_mech_name_t *new_array, uint_t *prev_count,
crypto_mech_name_t **prev_array)
{
kcf_policy_desc_t *new_desc, *policy_desc = NULL;
uint_t i;
int rv;
new_desc = kcf_policy_alloc_desc(KM_SLEEP);
new_desc->pd_prov_type = CRYPTO_SW_PROVIDER;
new_desc->pd_name = kmem_alloc(strlen(module_name) + 1, KM_SLEEP);
(void) strcpy(new_desc->pd_name, module_name);
mutex_enter(&policy_tab_mutex);
for (i = 0; i < KCF_MAX_POLICY; i++) {
if (policy_tab[i] != NULL &&
policy_tab[i]->pd_prov_type == CRYPTO_SW_PROVIDER) {
ASSERT(policy_tab[i]->pd_name != NULL);
if (strncmp(policy_tab[i]->pd_name, module_name,
MAXNAMELEN) == 0) {
policy_desc = policy_tab[i];
break;
}
}
}
if (policy_desc == NULL) {
rv = kcf_policy_add_entry(new_desc);
if (rv != CRYPTO_SUCCESS) {
mutex_exit(&policy_tab_mutex);
kcf_policy_free_desc(new_desc);
return (rv);
}
policy_desc = new_desc;
} else {
kcf_policy_free_desc(new_desc);
}
mutex_enter(&policy_desc->pd_mutex);
*prev_count = policy_desc->pd_disabled_count;
*prev_array = policy_desc->pd_disabled_mechs;
policy_desc->pd_disabled_count = new_count;
policy_desc->pd_disabled_mechs = new_array;
mutex_exit(&policy_desc->pd_mutex);
mutex_exit(&policy_tab_mutex);
return (CRYPTO_SUCCESS);
}
int
kcf_policy_load_dev_disabled(char *name, uint_t instance, uint_t new_count,
crypto_mech_name_t *new_array, uint_t *prev_count,
crypto_mech_name_t **prev_array)
{
kcf_policy_desc_t *new_desc, *policy_desc = NULL;
uint_t i;
int rv;
new_desc = kcf_policy_alloc_desc(KM_SLEEP);
new_desc->pd_prov_type = CRYPTO_HW_PROVIDER;
new_desc->pd_name = kmem_alloc(strlen(name) + 1, KM_SLEEP);
(void) strcpy(new_desc->pd_name, name);
new_desc->pd_instance = instance;
mutex_enter(&policy_tab_mutex);
for (i = 0; i < KCF_MAX_POLICY; i++) {
if (policy_tab[i] != NULL &&
policy_tab[i]->pd_prov_type == CRYPTO_HW_PROVIDER &&
strncmp(policy_tab[i]->pd_name, name, MAXNAMELEN) == 0 &&
policy_tab[i]->pd_instance == instance) {
policy_desc = policy_tab[i];
break;
}
}
if (policy_desc == NULL) {
rv = kcf_policy_add_entry(new_desc);
if (rv != CRYPTO_SUCCESS) {
mutex_exit(&policy_tab_mutex);
kcf_policy_free_desc(new_desc);
return (rv);
}
policy_desc = new_desc;
} else {
kcf_policy_free_desc(new_desc);
}
mutex_enter(&policy_desc->pd_mutex);
*prev_count = policy_desc->pd_disabled_count;
*prev_array = policy_desc->pd_disabled_mechs;
policy_desc->pd_disabled_count = new_count;
policy_desc->pd_disabled_mechs = new_array;
mutex_exit(&policy_desc->pd_mutex);
mutex_exit(&policy_tab_mutex);
return (CRYPTO_SUCCESS);
}
static kcf_policy_desc_t *
kcf_policy_alloc_desc(int km_flag)
{
kcf_policy_desc_t *desc;
if ((desc = kmem_zalloc(sizeof (kcf_policy_desc_t), km_flag)) == NULL)
return (NULL);
mutex_init(&desc->pd_mutex, NULL, MUTEX_DEFAULT, NULL);
return (desc);
}
void
kcf_policy_free_desc(kcf_policy_desc_t *desc)
{
if (desc == NULL)
return;
mutex_destroy(&desc->pd_mutex);
ASSERT(desc->pd_name != NULL);
kmem_free(desc->pd_name, strlen(desc->pd_name) + 1);
if (desc->pd_disabled_mechs != NULL)
kmem_free(desc->pd_disabled_mechs, sizeof (crypto_mech_name_t) *
desc->pd_disabled_count);
kmem_free(desc, sizeof (kcf_policy_desc_t));
}