[PATCH v2 1/2] PBL: add pbl_sha256()
Sascha Hauer <[email protected]> Mon, 27 Jul 2026 14:59:44 +0200
| Newsgroups | org.infradead.lists.barebox |
|---|---|
| Message-ID | <[email protected]> |
The PBL open-codes SHA-256 as sha256_init()/sha256_update()/sha256_final() wherever it needs to hash a blob, which always uses the generic C transform. Add pbl_sha256(), a one-shot helper that hides this behind a single call and is free to pick the best transform available in the PBL. For now it only wraps the generic C implementation; an accelerated path is added on top in a later commit. Convert pbl_barebox_verify() in pbl/decomp.c to the new helper as the first user. Signed-off-by: Sascha Hauer <[email protected]> --- include/crypto/pbl-sha.h | 4 ++++ pbl/Makefile | 1 + pbl/decomp.c | 6 +----- pbl/sha256.c | 25 +++++++++++++++++++++++++ 4 files changed, 31 insertions(+), 5 deletions(-) diff --git a/include/crypto/pbl-sha.h b/include/crypto/pbl-sha.h index 7d323ab479..2508448ab4 100644 --- a/include/crypto/pbl-sha.h +++ b/include/crypto/pbl-sha.h @@ -3,6 +3,7 @@ #define __PBL_SHA_H_ +#include <crypto/sha.h> #include <digest.h> #include <types.h> @@ -10,4 +11,7 @@ int sha256_init(struct digest *desc); int sha256_update(struct digest *desc, const void *data, unsigned long len); int sha256_final(struct digest *desc, u8 *out); +/* One-shot SHA-256 that picks the best transform available in the PBL. */ +void pbl_sha256(const void *buf, size_t len, u8 out[SHA256_DIGEST_SIZE]); + #endif /* __PBL-SHA_H_ */ diff --git a/pbl/Makefile b/pbl/Makefile index 45cfbf5fba..4506f192fe 100644 --- a/pbl/Makefile +++ b/pbl/Makefile @@ -6,6 +6,7 @@ pbl-y += misc.o pbl-y += string.o pbl-y += malloc.o +pbl-y += sha256.o pbl-$(CONFIG_HAVE_IMAGE_COMPRESSION) += decomp.o pbl-$(CONFIG_LIBFDT) += fdt.o pbl-$(CONFIG_PBL_CONSOLE) += console.o diff --git a/pbl/decomp.c b/pbl/decomp.c index 1539a6b67e..2b3c35012f 100644 --- a/pbl/decomp.c +++ b/pbl/decomp.c @@ -58,8 +58,6 @@ extern unsigned char sha_sum_end[]; int pbl_barebox_verify(const void *compressed_start, unsigned int len, const void *hash, unsigned int hash_len) { - struct sha256_state sha_state = { 0 }; - struct digest d = { .ctx = &sha_state }; char computed_hash[SHA256_DIGEST_SIZE]; int i; const char *char_hash = hash; @@ -67,9 +65,7 @@ int pbl_barebox_verify(const void *compressed_start, unsigned int len, if (hash_len != SHA256_DIGEST_SIZE) return -1; - sha256_init(&d); - sha256_update(&d, compressed_start, len); - sha256_final(&d, computed_hash); + pbl_sha256(compressed_start, len, computed_hash); if (IS_ENABLED(CONFIG_DEBUG_LL)) { puts_ll("CH "); diff --git a/pbl/sha256.c b/pbl/sha256.c new file mode 100644 index 0000000000..853d6bcbf6 --- /dev/null +++ b/pbl/sha256.c @@ -0,0 +1,25 @@ +// SPDX-License-Identifier: GPL-2.0-only +/* + * pbl_sha256() - one-shot SHA-256 for the PBL, picking the best available + * implementation. + */ + +#include <common.h> +#include <crypto/sha.h> +#include <crypto/pbl-sha.h> +#include <digest.h> + +static void pbl_sha256_generic(const void *buf, size_t len, u8 *out) +{ + struct sha256_state state = { }; + struct digest d = { .ctx = &state, .length = SHA256_DIGEST_SIZE }; + + sha256_init(&d); + sha256_update(&d, buf, len); + sha256_final(&d, out); +} + +void pbl_sha256(const void *buf, size_t len, u8 out[static SHA256_DIGEST_SIZE]) +{ + pbl_sha256_generic(buf, len, out); +} -- 2.47.3