mirror of
https://github.com/LineageOS/android_kernel_samsung_msm8226.git
synced 2026-09-28 00:00:22 +02:00
FIPS140-2 certification asks to do a Power on Known Answer tests on each algorithm which is getting certified. This patch implements the self tests and hardcoded test vectors. Also, we need to verify the integrity of kernel as soon as it boots up. This patch also adds an ioctl for integrity test along with ioctl to query FIPS status (pass / fail) from user land. also, The piece of code is added for FIPS compliance DRBG under drivers/char/hw_random This change is already merged to KK mainline. Change-Id: I7f3355602d5c2dfaefce0c0e4f9225fde0c5f485 Signed-off-by: Dinesh K Garg <dineshg@codeaurora.org>
34 lines
842 B
C
34 lines
842 B
C
#ifndef _UAPI_FIPS_STATUS__H
|
|
#define _UAPI_FIPS_STATUS__H
|
|
|
|
#include <linux/types.h>
|
|
#include <linux/ioctl.h>
|
|
|
|
/**
|
|
* fips_status: global FIPS140-2 status
|
|
* @FIPS140_STATUS_NA:
|
|
* Not a FIPS140-2 compliant Build.
|
|
* The flag status won't
|
|
* change throughout
|
|
* the lifetime
|
|
* @FIPS140_STATUS_PASS_CRYPTO:
|
|
* KAT self tests are passed.
|
|
* @FIPS140_STATUS_QCRYPTO_ALLOWED:
|
|
* Integrity test is passed.
|
|
* @FIPS140_STATUS_PASS:
|
|
* All tests are passed and build
|
|
* is in FIPS140-2 mode
|
|
* @FIPS140_STATUS_FAIL:
|
|
* One of the test is failed.
|
|
* This will block all requests
|
|
* to crypto modules
|
|
*/
|
|
enum fips_status {
|
|
FIPS140_STATUS_NA = 0,
|
|
FIPS140_STATUS_PASS_CRYPTO = 1,
|
|
FIPS140_STATUS_QCRYPTO_ALLOWED = 2,
|
|
FIPS140_STATUS_PASS = 3,
|
|
FIPS140_STATUS_FAIL = 0xFF
|
|
};
|
|
#endif /* _UAPI_FIPS_STATUS__H */
|