From: Kuan-Wei Chiu <visitorckw@gmail.com>
Extend the base64 API to support multiple variants (standard, URL-safe,
and IMAP) as defined in RFC 4648 and RFC 3501. The API now takes a
variant parameter and an option to control padding. Update NVMe auth
code to use the new interface with BASE64_STD.
Signed-off-by: Kuan-Wei Chiu <visitorckw@gmail.com>
Co-developed-by: Guan-Chun Wu <409411716@gms.tku.edu.tw>
Signed-off-by: Guan-Chun Wu <409411716@gms.tku.edu.tw>
---
drivers/nvme/common/auth.c | 4 ++--
include/linux/base64.h | 10 ++++++++--
lib/base64.c | 39 ++++++++++++++++++++++----------------
3 files changed, 33 insertions(+), 20 deletions(-)
diff --git a/drivers/nvme/common/auth.c b/drivers/nvme/common/auth.c
index 91e273b89..5fecb53cb 100644
--- a/drivers/nvme/common/auth.c
+++ b/drivers/nvme/common/auth.c
@@ -178,7 +178,7 @@ struct nvme_dhchap_key *nvme_auth_extract_key(unsigned char *secret,
if (!key)
return ERR_PTR(-ENOMEM);
- key_len = base64_decode(secret, allocated_len, key->key);
+ key_len = base64_decode(secret, allocated_len, key->key, true, BASE64_STD);
if (key_len < 0) {
pr_debug("base64 key decoding error %d\n",
key_len);
@@ -663,7 +663,7 @@ int nvme_auth_generate_digest(u8 hmac_id, u8 *psk, size_t psk_len,
if (ret)
goto out_free_digest;
- ret = base64_encode(digest, digest_len, enc);
+ ret = base64_encode(digest, digest_len, enc, true, BASE64_STD);
if (ret < hmac_len) {
ret = -ENOKEY;
goto out_free_digest;
diff --git a/include/linux/base64.h b/include/linux/base64.h
index 660d4cb1e..a2c6c9222 100644
--- a/include/linux/base64.h
+++ b/include/linux/base64.h
@@ -8,9 +8,15 @@
#include <linux/types.h>
+enum base64_variant {
+ BASE64_STD, /* RFC 4648 (standard) */
+ BASE64_URLSAFE, /* RFC 4648 (base64url) */
+ BASE64_IMAP, /* RFC 3501 */
+};
+
#define BASE64_CHARS(nbytes) DIV_ROUND_UP((nbytes) * 4, 3)
-int base64_encode(const u8 *src, int len, char *dst);
-int base64_decode(const char *src, int len, u8 *dst);
+int base64_encode(const u8 *src, int len, char *dst, bool padding, enum base64_variant variant);
+int base64_decode(const char *src, int len, u8 *dst, bool padding, enum base64_variant variant);
#endif /* _LINUX_BASE64_H */
diff --git a/lib/base64.c b/lib/base64.c
index b736a7a43..1af557785 100644
--- a/lib/base64.c
+++ b/lib/base64.c
@@ -1,12 +1,12 @@
// SPDX-License-Identifier: GPL-2.0
/*
- * base64.c - RFC4648-compliant base64 encoding
+ * base64.c - Base64 with support for multiple variants
*
* Copyright (c) 2020 Hannes Reinecke, SUSE
*
* Based on the base64url routines from fs/crypto/fname.c
- * (which are using the URL-safe base64 encoding),
- * modified to use the standard coding table from RFC4648 section 4.
+ * (which are using the URL-safe Base64 encoding),
+ * modified to support multiple Base64 variants.
*/
#include <linux/kernel.h>
@@ -15,26 +15,31 @@
#include <linux/string.h>
#include <linux/base64.h>
-static const char base64_table[65] =
- "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/";
+static const char base64_tables[][65] = {
+ [BASE64_STD] = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/",
+ [BASE64_URLSAFE] = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789-_",
+ [BASE64_IMAP] = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+,",
+};
/**
- * base64_encode() - base64-encode some binary data
+ * base64_encode() - Base64-encode some binary data
* @src: the binary data to encode
* @srclen: the length of @src in bytes
- * @dst: (output) the base64-encoded string. Not NUL-terminated.
+ * @dst: (output) the Base64-encoded string. Not NUL-terminated.
+ * @padding: whether to append '=' padding characters
+ * @variant: which base64 variant to use
*
- * Encodes data using base64 encoding, i.e. the "Base 64 Encoding" specified
- * by RFC 4648, including the '='-padding.
+ * Encodes data using the selected Base64 variant.
*
- * Return: the length of the resulting base64-encoded string in bytes.
+ * Return: the length of the resulting Base64-encoded string in bytes.
*/
-int base64_encode(const u8 *src, int srclen, char *dst)
+int base64_encode(const u8 *src, int srclen, char *dst, bool padding, enum base64_variant variant)
{
u32 ac = 0;
int bits = 0;
int i;
char *cp = dst;
+ const char *base64_table = base64_tables[variant];
for (i = 0; i < srclen; i++) {
ac = (ac << 8) | src[i];
@@ -57,25 +62,27 @@ int base64_encode(const u8 *src, int srclen, char *dst)
EXPORT_SYMBOL_GPL(base64_encode);
/**
- * base64_decode() - base64-decode a string
+ * base64_decode() - Base64-decode a string
* @src: the string to decode. Doesn't need to be NUL-terminated.
* @srclen: the length of @src in bytes
* @dst: (output) the decoded binary data
+ * @padding: whether to append '=' padding characters
+ * @variant: which base64 variant to use
*
- * Decodes a string using base64 encoding, i.e. the "Base 64 Encoding"
- * specified by RFC 4648, including the '='-padding.
+ * Decodes a string using the selected Base64 variant.
*
* This implementation hasn't been optimized for performance.
*
* Return: the length of the resulting decoded binary data in bytes,
- * or -1 if the string isn't a valid base64 string.
+ * or -1 if the string isn't a valid Base64 string.
*/
-int base64_decode(const char *src, int srclen, u8 *dst)
+int base64_decode(const char *src, int srclen, u8 *dst, bool padding, enum base64_variant variant)
{
u32 ac = 0;
int bits = 0;
int i;
u8 *bp = dst;
+ const char *base64_table = base64_tables[variant];
for (i = 0; i < srclen; i++) {
const char *p = strchr(base64_table, src[i]);
--
2.34.1
On Thu, Sep 25, 2025 at 11:59 PM Guan-Chun Wu <409411716@gms.tku.edu.tw> wrote: > > From: Kuan-Wei Chiu <visitorckw@gmail.com> > > Extend the base64 API to support multiple variants (standard, URL-safe, > and IMAP) as defined in RFC 4648 and RFC 3501. The API now takes a > variant parameter and an option to control padding. Update NVMe auth > code to use the new interface with BASE64_STD. > > Signed-off-by: Kuan-Wei Chiu <visitorckw@gmail.com> > Co-developed-by: Guan-Chun Wu <409411716@gms.tku.edu.tw> > Signed-off-by: Guan-Chun Wu <409411716@gms.tku.edu.tw> > --- > drivers/nvme/common/auth.c | 4 ++-- > include/linux/base64.h | 10 ++++++++-- > lib/base64.c | 39 ++++++++++++++++++++++---------------- > 3 files changed, 33 insertions(+), 20 deletions(-) > > diff --git a/drivers/nvme/common/auth.c b/drivers/nvme/common/auth.c > index 91e273b89..5fecb53cb 100644 > --- a/drivers/nvme/common/auth.c > +++ b/drivers/nvme/common/auth.c > @@ -178,7 +178,7 @@ struct nvme_dhchap_key *nvme_auth_extract_key(unsigned char *secret, > if (!key) > return ERR_PTR(-ENOMEM); > > - key_len = base64_decode(secret, allocated_len, key->key); > + key_len = base64_decode(secret, allocated_len, key->key, true, BASE64_STD); > if (key_len < 0) { > pr_debug("base64 key decoding error %d\n", > key_len); > @@ -663,7 +663,7 @@ int nvme_auth_generate_digest(u8 hmac_id, u8 *psk, size_t psk_len, > if (ret) > goto out_free_digest; > > - ret = base64_encode(digest, digest_len, enc); > + ret = base64_encode(digest, digest_len, enc, true, BASE64_STD); > if (ret < hmac_len) { > ret = -ENOKEY; > goto out_free_digest; > diff --git a/include/linux/base64.h b/include/linux/base64.h > index 660d4cb1e..a2c6c9222 100644 > --- a/include/linux/base64.h > +++ b/include/linux/base64.h > @@ -8,9 +8,15 @@ > > #include <linux/types.h> > > +enum base64_variant { > + BASE64_STD, /* RFC 4648 (standard) */ > + BASE64_URLSAFE, /* RFC 4648 (base64url) */ > + BASE64_IMAP, /* RFC 3501 */ > +}; > + > #define BASE64_CHARS(nbytes) DIV_ROUND_UP((nbytes) * 4, 3) > > -int base64_encode(const u8 *src, int len, char *dst); > -int base64_decode(const char *src, int len, u8 *dst); > +int base64_encode(const u8 *src, int len, char *dst, bool padding, enum base64_variant variant); > +int base64_decode(const char *src, int len, u8 *dst, bool padding, enum base64_variant variant); > > #endif /* _LINUX_BASE64_H */ > diff --git a/lib/base64.c b/lib/base64.c > index b736a7a43..1af557785 100644 > --- a/lib/base64.c > +++ b/lib/base64.c > @@ -1,12 +1,12 @@ > // SPDX-License-Identifier: GPL-2.0 > /* > - * base64.c - RFC4648-compliant base64 encoding > + * base64.c - Base64 with support for multiple variants > * > * Copyright (c) 2020 Hannes Reinecke, SUSE > * > * Based on the base64url routines from fs/crypto/fname.c > - * (which are using the URL-safe base64 encoding), > - * modified to use the standard coding table from RFC4648 section 4. > + * (which are using the URL-safe Base64 encoding), > + * modified to support multiple Base64 variants. > */ > > #include <linux/kernel.h> > @@ -15,26 +15,31 @@ > #include <linux/string.h> > #include <linux/base64.h> > > -static const char base64_table[65] = > - "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/"; > +static const char base64_tables[][65] = { > + [BASE64_STD] = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/", > + [BASE64_URLSAFE] = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789-_", > + [BASE64_IMAP] = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+,", > +}; > > /** > - * base64_encode() - base64-encode some binary data > + * base64_encode() - Base64-encode some binary data > * @src: the binary data to encode > * @srclen: the length of @src in bytes > - * @dst: (output) the base64-encoded string. Not NUL-terminated. > + * @dst: (output) the Base64-encoded string. Not NUL-terminated. > + * @padding: whether to append '=' padding characters > + * @variant: which base64 variant to use > * > - * Encodes data using base64 encoding, i.e. the "Base 64 Encoding" specified > - * by RFC 4648, including the '='-padding. > + * Encodes data using the selected Base64 variant. > * > - * Return: the length of the resulting base64-encoded string in bytes. > + * Return: the length of the resulting Base64-encoded string in bytes. > */ > -int base64_encode(const u8 *src, int srclen, char *dst) > +int base64_encode(const u8 *src, int srclen, char *dst, bool padding, enum base64_variant variant) Padding isn't actually implemented in this commit? That seems a bit confusing. I think it would ideally be implemented in the same commit that adds it. That could be before or after the commit that optimizes the encode/decode implementations. Best, Caleb > { > u32 ac = 0; > int bits = 0; > int i; > char *cp = dst; > + const char *base64_table = base64_tables[variant]; > > for (i = 0; i < srclen; i++) { > ac = (ac << 8) | src[i]; > @@ -57,25 +62,27 @@ int base64_encode(const u8 *src, int srclen, char *dst) > EXPORT_SYMBOL_GPL(base64_encode); > > /** > - * base64_decode() - base64-decode a string > + * base64_decode() - Base64-decode a string > * @src: the string to decode. Doesn't need to be NUL-terminated. > * @srclen: the length of @src in bytes > * @dst: (output) the decoded binary data > + * @padding: whether to append '=' padding characters > + * @variant: which base64 variant to use > * > - * Decodes a string using base64 encoding, i.e. the "Base 64 Encoding" > - * specified by RFC 4648, including the '='-padding. > + * Decodes a string using the selected Base64 variant. > * > * This implementation hasn't been optimized for performance. > * > * Return: the length of the resulting decoded binary data in bytes, > - * or -1 if the string isn't a valid base64 string. > + * or -1 if the string isn't a valid Base64 string. > */ > -int base64_decode(const char *src, int srclen, u8 *dst) > +int base64_decode(const char *src, int srclen, u8 *dst, bool padding, enum base64_variant variant) > { > u32 ac = 0; > int bits = 0; > int i; > u8 *bp = dst; > + const char *base64_table = base64_tables[variant]; > > for (i = 0; i < srclen; i++) { > const char *p = strchr(base64_table, src[i]); > -- > 2.34.1 > >
On Tue, Sep 30, 2025 at 04:56:17PM -0700, Caleb Sander Mateos wrote: > On Thu, Sep 25, 2025 at 11:59 PM Guan-Chun Wu <409411716@gms.tku.edu.tw> wrote: > > > > From: Kuan-Wei Chiu <visitorckw@gmail.com> > > > > Extend the base64 API to support multiple variants (standard, URL-safe, > > and IMAP) as defined in RFC 4648 and RFC 3501. The API now takes a > > variant parameter and an option to control padding. Update NVMe auth > > code to use the new interface with BASE64_STD. > > > > Signed-off-by: Kuan-Wei Chiu <visitorckw@gmail.com> > > Co-developed-by: Guan-Chun Wu <409411716@gms.tku.edu.tw> > > Signed-off-by: Guan-Chun Wu <409411716@gms.tku.edu.tw> > > --- > > drivers/nvme/common/auth.c | 4 ++-- > > include/linux/base64.h | 10 ++++++++-- > > lib/base64.c | 39 ++++++++++++++++++++++---------------- > > 3 files changed, 33 insertions(+), 20 deletions(-) > > > > diff --git a/drivers/nvme/common/auth.c b/drivers/nvme/common/auth.c > > index 91e273b89..5fecb53cb 100644 > > --- a/drivers/nvme/common/auth.c > > +++ b/drivers/nvme/common/auth.c > > @@ -178,7 +178,7 @@ struct nvme_dhchap_key *nvme_auth_extract_key(unsigned char *secret, > > if (!key) > > return ERR_PTR(-ENOMEM); > > > > - key_len = base64_decode(secret, allocated_len, key->key); > > + key_len = base64_decode(secret, allocated_len, key->key, true, BASE64_STD); > > if (key_len < 0) { > > pr_debug("base64 key decoding error %d\n", > > key_len); > > @@ -663,7 +663,7 @@ int nvme_auth_generate_digest(u8 hmac_id, u8 *psk, size_t psk_len, > > if (ret) > > goto out_free_digest; > > > > - ret = base64_encode(digest, digest_len, enc); > > + ret = base64_encode(digest, digest_len, enc, true, BASE64_STD); > > if (ret < hmac_len) { > > ret = -ENOKEY; > > goto out_free_digest; > > diff --git a/include/linux/base64.h b/include/linux/base64.h > > index 660d4cb1e..a2c6c9222 100644 > > --- a/include/linux/base64.h > > +++ b/include/linux/base64.h > > @@ -8,9 +8,15 @@ > > > > #include <linux/types.h> > > > > +enum base64_variant { > > + BASE64_STD, /* RFC 4648 (standard) */ > > + BASE64_URLSAFE, /* RFC 4648 (base64url) */ > > + BASE64_IMAP, /* RFC 3501 */ > > +}; > > + > > #define BASE64_CHARS(nbytes) DIV_ROUND_UP((nbytes) * 4, 3) > > > > -int base64_encode(const u8 *src, int len, char *dst); > > -int base64_decode(const char *src, int len, u8 *dst); > > +int base64_encode(const u8 *src, int len, char *dst, bool padding, enum base64_variant variant); > > +int base64_decode(const char *src, int len, u8 *dst, bool padding, enum base64_variant variant); > > > > #endif /* _LINUX_BASE64_H */ > > diff --git a/lib/base64.c b/lib/base64.c > > index b736a7a43..1af557785 100644 > > --- a/lib/base64.c > > +++ b/lib/base64.c > > @@ -1,12 +1,12 @@ > > // SPDX-License-Identifier: GPL-2.0 > > /* > > - * base64.c - RFC4648-compliant base64 encoding > > + * base64.c - Base64 with support for multiple variants > > * > > * Copyright (c) 2020 Hannes Reinecke, SUSE > > * > > * Based on the base64url routines from fs/crypto/fname.c > > - * (which are using the URL-safe base64 encoding), > > - * modified to use the standard coding table from RFC4648 section 4. > > + * (which are using the URL-safe Base64 encoding), > > + * modified to support multiple Base64 variants. > > */ > > > > #include <linux/kernel.h> > > @@ -15,26 +15,31 @@ > > #include <linux/string.h> > > #include <linux/base64.h> > > > > -static const char base64_table[65] = > > - "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/"; > > +static const char base64_tables[][65] = { > > + [BASE64_STD] = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/", > > + [BASE64_URLSAFE] = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789-_", > > + [BASE64_IMAP] = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+,", > > +}; > > > > /** > > - * base64_encode() - base64-encode some binary data > > + * base64_encode() - Base64-encode some binary data > > * @src: the binary data to encode > > * @srclen: the length of @src in bytes > > - * @dst: (output) the base64-encoded string. Not NUL-terminated. > > + * @dst: (output) the Base64-encoded string. Not NUL-terminated. > > + * @padding: whether to append '=' padding characters > > + * @variant: which base64 variant to use > > * > > - * Encodes data using base64 encoding, i.e. the "Base 64 Encoding" specified > > - * by RFC 4648, including the '='-padding. > > + * Encodes data using the selected Base64 variant. > > * > > - * Return: the length of the resulting base64-encoded string in bytes. > > + * Return: the length of the resulting Base64-encoded string in bytes. > > */ > > -int base64_encode(const u8 *src, int srclen, char *dst) > > +int base64_encode(const u8 *src, int srclen, char *dst, bool padding, enum base64_variant variant) > > Padding isn't actually implemented in this commit? That seems a bit > confusing. I think it would ideally be implemented in the same commit > that adds it. That could be before or after the commit that optimizes > the encode/decode implementations. > > Best, > Caleb > Got it, thanks for pointing that out. We'll address it in the next version. Best regards, Guan-Chun > > { > > u32 ac = 0; > > int bits = 0; > > int i; > > char *cp = dst; > > + const char *base64_table = base64_tables[variant]; > > > > for (i = 0; i < srclen; i++) { > > ac = (ac << 8) | src[i]; > > @@ -57,25 +62,27 @@ int base64_encode(const u8 *src, int srclen, char *dst) > > EXPORT_SYMBOL_GPL(base64_encode); > > > > /** > > - * base64_decode() - base64-decode a string > > + * base64_decode() - Base64-decode a string > > * @src: the string to decode. Doesn't need to be NUL-terminated. > > * @srclen: the length of @src in bytes > > * @dst: (output) the decoded binary data > > + * @padding: whether to append '=' padding characters > > + * @variant: which base64 variant to use > > * > > - * Decodes a string using base64 encoding, i.e. the "Base 64 Encoding" > > - * specified by RFC 4648, including the '='-padding. > > + * Decodes a string using the selected Base64 variant. > > * > > * This implementation hasn't been optimized for performance. > > * > > * Return: the length of the resulting decoded binary data in bytes, > > - * or -1 if the string isn't a valid base64 string. > > + * or -1 if the string isn't a valid Base64 string. > > */ > > -int base64_decode(const char *src, int srclen, u8 *dst) > > +int base64_decode(const char *src, int srclen, u8 *dst, bool padding, enum base64_variant variant) > > { > > u32 ac = 0; > > int bits = 0; > > int i; > > u8 *bp = dst; > > + const char *base64_table = base64_tables[variant]; > > > > for (i = 0; i < srclen; i++) { > > const char *p = strchr(base64_table, src[i]); > > -- > > 2.34.1 > > > >
© 2016 - 2025 Red Hat, Inc.