mirror of
https://github.com/u-boot/u-boot.git
synced 2025-04-23 05:08:24 +00:00

Port mbedtls with adapted libc header files. Add mbedtls default config header file. Optimize mbedtls default config by disabling unused features to reduce the target size. Add mbedtls kbuild makefile. Add Kconfig skeleton and config submenu entry for selecting crypto libraries between mbedtls and legacy ones. Add the mbedtls include directories into the build system. Port u-boot hash functions as MbedTLS crypto alternatives and set it as default. Subsequent patches will separate those Kconfigs into pairs of _LEGACY and _MBEDTLS for controlling the implementations of legacy crypto libraries and MbedTLS ones respectively. The motivation of moving and adapting *INT* macros from kernel.h to limits.h is to fulfill the MbedTLS building requirement. The conditional compilation statements in MbedTLS expects the *INT* macros as constant expressions, thus expressions like `((int)(~0U >> 1))` will not work. Prerequisite ------------ This patch series requires mbedtls git repo to be added as a subtree to the main U-Boot repo via: $ git subtree add --prefix lib/mbedtls/external/mbedtls \ https://github.com/Mbed-TLS/mbedtls.git \ v3.6.0 --squash Moreover, due to the Windows-style files from mbedtls git repo, we need to convert the CRLF endings to LF and do a commit manually: $ git add --renormalize . $ git commit Signed-off-by: Raymond Mao <raymond.mao@linaro.org>
78 lines
1.5 KiB
C
78 lines
1.5 KiB
C
/* SPDX-License-Identifier: GPL-2.0+ */
|
|
/*
|
|
* Copyright (c) 2024 Linaro Limited
|
|
* Author: Raymond Mao <raymond.mao@linaro.org>
|
|
*/
|
|
#ifndef SHA512_ALT_H
|
|
#define SHA512_ALT_H
|
|
|
|
#include <image.h>
|
|
#include <u-boot/sha512.h>
|
|
|
|
typedef struct mbedtls_sha512_context {
|
|
sha512_context *ubctx;
|
|
bool is384;
|
|
} mbedtls_sha512_context;
|
|
|
|
static inline void mbedtls_sha512_init(mbedtls_sha512_context *ctx)
|
|
{
|
|
}
|
|
|
|
static inline void mbedtls_sha512_free(mbedtls_sha512_context *ctx)
|
|
{
|
|
}
|
|
|
|
static inline void mbedtls_sha512_clone(mbedtls_sha512_context *dst,
|
|
const mbedtls_sha512_context *src)
|
|
{
|
|
*dst = *src;
|
|
}
|
|
|
|
static inline int mbedtls_sha512_starts(mbedtls_sha512_context *ctx, int is384)
|
|
{
|
|
if (is384)
|
|
sha384_starts(ctx->ubctx);
|
|
else
|
|
sha512_starts(ctx->ubctx);
|
|
|
|
ctx->is384 = is384;
|
|
return 0;
|
|
}
|
|
|
|
static inline int mbedtls_sha512_update(mbedtls_sha512_context *ctx,
|
|
const unsigned char *input,
|
|
size_t ilen)
|
|
{
|
|
if (ctx->is384)
|
|
sha384_update(ctx->ubctx, input, ilen);
|
|
else
|
|
sha512_update(ctx->ubctx, input, ilen);
|
|
|
|
return 0;
|
|
}
|
|
|
|
static inline int mbedtls_sha512_finish(mbedtls_sha512_context *ctx,
|
|
unsigned char *output)
|
|
{
|
|
if (ctx->is384)
|
|
sha384_finish(ctx->ubctx, output);
|
|
else
|
|
sha512_finish(ctx->ubctx, output);
|
|
|
|
return 0;
|
|
}
|
|
|
|
static inline int mbedtls_sha512(const unsigned char *input,
|
|
size_t ilen,
|
|
unsigned char *output,
|
|
int is384)
|
|
{
|
|
if (is384)
|
|
sha384_csum_wd(input, ilen, output, CHUNKSZ_SHA512);
|
|
else
|
|
sha512_csum_wd(input, ilen, output, CHUNKSZ_SHA512);
|
|
|
|
return 0;
|
|
}
|
|
|
|
#endif /* sha512_alt.h */
|