Re: [PATCH v13 12/18] target/s390x: Support protected key AES ECB for cpacf km instruction

Ilya Leoshkevich <[email protected]> Wed, 5 Aug 2026 00:48:54 +0200
Newsgroups gmane.comp.emulators.qemu
Message-ID <[email protected]>

On 8/3/26 18:12, Harald Freudenberger wrote:
> Support the subfunctions CPACF_KM_PAES_128, CPACF_KM_PAES_192
> and CPACF_KM_PAES_256 for the cpacf km instruction.
> 
> Tested-by: Holger Dengler <[email protected]>
> Reviewed-by: Finn Callies <[email protected]>
> Signed-off-by: Harald Freudenberger <[email protected]>
> ---
>   target/s390x/gen-features.c      |  3 ++
>   target/s390x/tcg/cpacf.h         |  4 ++
>   target/s390x/tcg/cpacf_aes.c     | 91 ++++++++++++++++++++++++++++++++
>   target/s390x/tcg/crypto_helper.c |  7 +++
>   4 files changed, 105 insertions(+)

[...]

> +
> +    /* process up to MAX_BLOCKS_PER_RUN aes blocks */
> +    for (i = 0; i < MAX_BLOCKS_PER_RUN && len >= AES_BLOCK_SIZE; i++) {
> +        aes_read_block(env, mmu_idx, ra, *src_ptr_reg + done, in);
> +        if (mod) {
> +            AES_decrypt(in, out, &exkey);
> +        } else {
> +            AES_encrypt(in, out, &exkey);
> +        }
> +        aes_write_block(env, mmu_idx, ra, *dst_ptr_reg + done, out);
> +        len -= AES_BLOCK_SIZE;
> +        done += AES_BLOCK_SIZE;
> +    }
> +
> +    *src_ptr_reg = deposit64(*src_ptr_reg, 0, addr_reg_size,
> +                             *src_ptr_reg + done);
> +    *dst_ptr_reg = deposit64(*dst_ptr_reg, 0, addr_reg_size,
> +                             *dst_ptr_reg + done);
> +    *src_len_reg -= done;

Should we update registers after each iteration?
Otherwise there may be interesting effects due to swapped out pages when
running in system emulation.
Blocks crossing the page boundary is a similar issue, not sure if it's
that easy to solve.

[...]