1 /*
2  * Copyright (c) 2018 Mellanox Technologies. All rights reserved.
3  *
4  * This software is available to you under a choice of one of two
5  * licenses.  You may choose to be licensed under the terms of the GNU
6  * General Public License (GPL) Version 2, available from the file
7  * COPYING in the main directory of this source tree, or the
8  * OpenIB.org BSD license below:
9  *
10  *     Redistribution and use in source and binary forms, with or
11  *     without modification, are permitted provided that the following
12  *     conditions are met:
13  *
14  *      - Redistributions of source code must retain the above
15  *        copyright notice, this list of conditions and the following
16  *        disclaimer.
17  *
18  *      - Redistributions in binary form must reproduce the above
19  *        copyright notice, this list of conditions and the following
20  *        disclaimer in the documentation and/or other materials
21  *        provided with the distribution.
22  *
23  * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
24  * EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
25  * MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
26  * NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS
27  * BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN
28  * ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
29  * CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
30  * SOFTWARE.
31  *
32  */
33 
34 #ifndef __MLX5_ACCEL_TLS_H__
35 #define __MLX5_ACCEL_TLS_H__
36 
37 #include <linux/mlx5/driver.h>
38 #include <linux/tls.h>
39 
40 #ifdef CONFIG_MLX5_TLS
41 int mlx5_ktls_create_key(struct mlx5_core_dev *mdev,
42 			 struct tls_crypto_info *crypto_info,
43 			 u32 *p_key_id);
44 void mlx5_ktls_destroy_key(struct mlx5_core_dev *mdev, u32 key_id);
45 
mlx5_accel_is_ktls_tx(struct mlx5_core_dev * mdev)46 static inline bool mlx5_accel_is_ktls_tx(struct mlx5_core_dev *mdev)
47 {
48 	return MLX5_CAP_GEN(mdev, tls_tx);
49 }
50 
mlx5_accel_is_ktls_rx(struct mlx5_core_dev * mdev)51 static inline bool mlx5_accel_is_ktls_rx(struct mlx5_core_dev *mdev)
52 {
53 	return MLX5_CAP_GEN(mdev, tls_rx);
54 }
55 
mlx5_accel_is_ktls_device(struct mlx5_core_dev * mdev)56 static inline bool mlx5_accel_is_ktls_device(struct mlx5_core_dev *mdev)
57 {
58 	if (!mlx5_accel_is_ktls_tx(mdev) &&
59 	    !mlx5_accel_is_ktls_rx(mdev))
60 		return false;
61 
62 	if (!MLX5_CAP_GEN(mdev, log_max_dek))
63 		return false;
64 
65 	return MLX5_CAP_TLS(mdev, tls_1_2_aes_gcm_128);
66 }
67 
mlx5e_ktls_type_check(struct mlx5_core_dev * mdev,struct tls_crypto_info * crypto_info)68 static inline bool mlx5e_ktls_type_check(struct mlx5_core_dev *mdev,
69 					 struct tls_crypto_info *crypto_info)
70 {
71 	switch (crypto_info->cipher_type) {
72 	case TLS_CIPHER_AES_GCM_128:
73 		if (crypto_info->version == TLS_1_2_VERSION)
74 			return MLX5_CAP_TLS(mdev,  tls_1_2_aes_gcm_128);
75 		break;
76 	}
77 
78 	return false;
79 }
80 #else
mlx5_accel_is_ktls_tx(struct mlx5_core_dev * mdev)81 static inline bool mlx5_accel_is_ktls_tx(struct mlx5_core_dev *mdev)
82 { return false; }
83 
mlx5_accel_is_ktls_rx(struct mlx5_core_dev * mdev)84 static inline bool mlx5_accel_is_ktls_rx(struct mlx5_core_dev *mdev)
85 { return false; }
86 
87 static inline int
mlx5_ktls_create_key(struct mlx5_core_dev * mdev,struct tls_crypto_info * crypto_info,u32 * p_key_id)88 mlx5_ktls_create_key(struct mlx5_core_dev *mdev,
89 		     struct tls_crypto_info *crypto_info,
90 		     u32 *p_key_id) { return -ENOTSUPP; }
91 static inline void
mlx5_ktls_destroy_key(struct mlx5_core_dev * mdev,u32 key_id)92 mlx5_ktls_destroy_key(struct mlx5_core_dev *mdev, u32 key_id) {}
93 
94 static inline bool
mlx5_accel_is_ktls_device(struct mlx5_core_dev * mdev)95 mlx5_accel_is_ktls_device(struct mlx5_core_dev *mdev) { return false; }
96 static inline bool
mlx5e_ktls_type_check(struct mlx5_core_dev * mdev,struct tls_crypto_info * crypto_info)97 mlx5e_ktls_type_check(struct mlx5_core_dev *mdev,
98 		      struct tls_crypto_info *crypto_info) { return false; }
99 #endif
100 
101 enum {
102 	MLX5_ACCEL_TLS_TX = BIT(0),
103 	MLX5_ACCEL_TLS_RX = BIT(1),
104 	MLX5_ACCEL_TLS_V12 = BIT(2),
105 	MLX5_ACCEL_TLS_V13 = BIT(3),
106 	MLX5_ACCEL_TLS_LRO = BIT(4),
107 	MLX5_ACCEL_TLS_IPV6 = BIT(5),
108 	MLX5_ACCEL_TLS_AES_GCM128 = BIT(30),
109 	MLX5_ACCEL_TLS_AES_GCM256 = BIT(31),
110 };
111 
112 struct mlx5_ifc_tls_flow_bits {
113 	u8         src_port[0x10];
114 	u8         dst_port[0x10];
115 	union mlx5_ifc_ipv6_layout_ipv4_layout_auto_bits src_ipv4_src_ipv6;
116 	union mlx5_ifc_ipv6_layout_ipv4_layout_auto_bits dst_ipv4_dst_ipv6;
117 	u8         ipv6[0x1];
118 	u8         direction_sx[0x1];
119 	u8         reserved_at_2[0x1e];
120 };
121 
122 #ifdef CONFIG_MLX5_FPGA_TLS
123 int mlx5_accel_tls_add_flow(struct mlx5_core_dev *mdev, void *flow,
124 			    struct tls_crypto_info *crypto_info,
125 			    u32 start_offload_tcp_sn, u32 *p_swid,
126 			    bool direction_sx);
127 void mlx5_accel_tls_del_flow(struct mlx5_core_dev *mdev, u32 swid,
128 			     bool direction_sx);
129 int mlx5_accel_tls_resync_rx(struct mlx5_core_dev *mdev, __be32 handle,
130 			     u32 seq, __be64 rcd_sn);
131 bool mlx5_accel_is_tls_device(struct mlx5_core_dev *mdev);
132 u32 mlx5_accel_tls_device_caps(struct mlx5_core_dev *mdev);
133 int mlx5_accel_tls_init(struct mlx5_core_dev *mdev);
134 void mlx5_accel_tls_cleanup(struct mlx5_core_dev *mdev);
135 
136 #else
137 
138 static inline int
mlx5_accel_tls_add_flow(struct mlx5_core_dev * mdev,void * flow,struct tls_crypto_info * crypto_info,u32 start_offload_tcp_sn,u32 * p_swid,bool direction_sx)139 mlx5_accel_tls_add_flow(struct mlx5_core_dev *mdev, void *flow,
140 			struct tls_crypto_info *crypto_info,
141 			u32 start_offload_tcp_sn, u32 *p_swid,
142 			bool direction_sx) { return -ENOTSUPP; }
mlx5_accel_tls_del_flow(struct mlx5_core_dev * mdev,u32 swid,bool direction_sx)143 static inline void mlx5_accel_tls_del_flow(struct mlx5_core_dev *mdev, u32 swid,
144 					   bool direction_sx) { }
mlx5_accel_tls_resync_rx(struct mlx5_core_dev * mdev,__be32 handle,u32 seq,__be64 rcd_sn)145 static inline int mlx5_accel_tls_resync_rx(struct mlx5_core_dev *mdev, __be32 handle,
146 					   u32 seq, __be64 rcd_sn) { return 0; }
mlx5_accel_is_tls_device(struct mlx5_core_dev * mdev)147 static inline bool mlx5_accel_is_tls_device(struct mlx5_core_dev *mdev)
148 {
149 	return mlx5_accel_is_ktls_device(mdev);
150 }
mlx5_accel_tls_device_caps(struct mlx5_core_dev * mdev)151 static inline u32 mlx5_accel_tls_device_caps(struct mlx5_core_dev *mdev) { return 0; }
mlx5_accel_tls_init(struct mlx5_core_dev * mdev)152 static inline int mlx5_accel_tls_init(struct mlx5_core_dev *mdev) { return 0; }
mlx5_accel_tls_cleanup(struct mlx5_core_dev * mdev)153 static inline void mlx5_accel_tls_cleanup(struct mlx5_core_dev *mdev) { }
154 #endif
155 
156 #endif	/* __MLX5_ACCEL_TLS_H__ */
157