crypto: arm/ghash - fix big-endian bug in ghash
authorArd Biesheuvel <ard.biesheuvel@linaro.org>
Mon, 23 Mar 2015 20:33:09 +0000 (21:33 +0100)
committerHerbert Xu <herbert@gondor.apana.org.au>
Tue, 24 Mar 2015 11:24:56 +0000 (22:24 +1100)
This fixes a bug in the new v8 Crypto Extensions GHASH code
that only manifests itself in big-endian mode.

Signed-off-by: Ard Biesheuvel <ard.biesheuvel@linaro.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
arch/arm/crypto/ghash-ce-core.S

index e643a15eadf24039a872052b11b3b0328059682c..f6ab8bcc9efe7f1b8e11b1b42f2530a55dd25b1b 100644 (file)
@@ -40,7 +40,7 @@
         *                         struct ghash_key const *k, const char *head)
         */
 ENTRY(pmull_ghash_update)
-       vld1.         {SHASH}, [r3]
+       vld1.64         {SHASH}, [r3]
        vld1.64         {XL}, [r1]
        vmov.i8         MASK, #0xe1
        vext.8          SHASH2, SHASH, SHASH, #8