Re: [PATCH v4 00/16] Support the ASPEED HACE crypto command

Cédric Le Goater <[email protected]>
Newsgroups org.nongnu.qemu-arm,org.nongnu.qemu-devel
Message-ID <[email protected]>
On 8/11/26 08:01, Jamin Lin wrote:
> The ASPEED HACE model only emulated the hash command; the crypto (cipher)
> command was stubbed out. On the AST2700 the kernel runs the crypto driver
> self-tests at boot, so without crypto emulation booting floods the log
> with failures:
> 
>    root@ast2700-default:~# dmesg | grep "self"
> [    6.078446] alg: self-tests for ctr(des) using aspeed-ctr-des failed (rc=-22)
> [    6.079295] alg: self-tests for ctr(des) using aspeed-ctr-des failed (rc=-22)
> [    6.089924] alg: self-tests for ctr(des3_ede) using aspeed-ctr-tdes failed (rc=-22)
> [    6.090629] alg: self-tests for ctr(des3_ede) using aspeed-ctr-tdes failed (rc=-22)
> [    6.100134] alg: self-tests for cbc(des3_ede) using aspeed-cbc-tdes failed (rc=-22)
> [    6.100416] alg: self-tests for ecb(des3_ede) using aspeed-ecb-tdes failed (rc=-22)
> [    6.100576] alg: self-tests for cbc(des3_ede) using aspeed-cbc-tdes failed (rc=-22)
> [    6.101411] alg: self-tests for ecb(des3_ede) using aspeed-ecb-tdes failed (rc=-22)
> [    6.152954] alg: self-tests for ecb(des) using aspeed-ecb-des failed (rc=-22)
> [    6.153701] alg: self-tests for ecb(des) using aspeed-ecb-des failed (rc=-22)
> [    6.180101] alg: self-tests for cbc(des) using aspeed-cbc-des failed (rc=-22)
> [    6.180747] alg: self-tests for cbc(des) using aspeed-cbc-des failed (rc=-22)
> [    6.206437] alg: self-tests for ctr(aes) using aspeed-ctr-aes failed (rc=-22)
> [    6.206910] alg: self-tests for ctr(aes) using aspeed-ctr-aes failed (rc=-22)
> [    6.215313] alg: self-tests for cbc(aes) using aspeed-cbc-aes failed (rc=-22)
> [    6.215698] alg: self-tests for cbc(aes) using aspeed-cbc-aes failed (rc=-22)
> [    6.227173] alg: self-tests for ecb(aes) using aspeed-ecb-aes failed (rc=-22)
> [    6.228027] alg: self-tests for ecb(aes) using aspeed-ecb-aes failed (rc=-22)
> [    6.276878] alg: self-tests for gcm(aes) using aspeed-gcm-aes failed (rc=-22)
> [    6.277541] alg: self-tests for gcm(aes) using aspeed-gcm-aes failed (rc=-22)
> 
> This series implements the HACE crypto command: AES/DES/3DES in ECB/CBC/CTR
> over direct and scatter-gather DMA, and AES-GCM with 64-bit DMA on the
> AST2700. It also adds GCM to the qcrypto cipher API (gcrypt backend) that
> the AST2700 path needs, plus qtest and unit-test coverage.
> 
> With crypto emulated the self-tests pass, the warnings above disappear, and
> the temporary 'cryptomgr.notests=1' boot workaround in the AST2700
> functional tests is dropped.
> 
> Note: the GNUTLS crypto backend does not support AES-CTR mode.
> 
> v1:
>    1. Support the crypto command in direct access mode
>    2. Support scatter-gather mode for the crypto command
>    3. Support the AES-GCM mode for the crypto command
>    4. Support 64-bit DMA for the crypto command
>    5. Test the crypto command
>    6. Drop the AST2700 crypto self-test/model workaround
> 
> v2:
>    1. Add AES-GCM to the nettle and gnutls crypto backends
>    2. Skip crypto tests for cipher modes the
>      compiled backend does not support, via qcrypto_cipher_supports()
>    3.  Check qcrypto_cipher_supports() before running a
>      crypt command and report the mode as unimplemented when the backend lacks it
> 
> v3:
>    1. remove the duplicate CRYPT_IRQ_EN definition.
>    2. remove the unuse CRYPT_CMD_DST_SG_CTRL definition.
>    3. Drop "Drop the AST2700 crypto self-test workaround" patch because GNUTLS
>       backend does not support AES-CTR mode.
> 
> v4:
>    1. Add GCM tag mask
> 
> Jamin Lin (16):
>    hw/misc/aspeed_hace: Support the crypto command in direct access mode
>    tests/qtest/aspeed-hace: Test the crypto command on the AST2500
>    hw/misc/aspeed_hace: Support scatter-gather mode for the crypto
>      command
>    hw/misc/aspeed_hace: Support the CTR mode for the crypto command
>    tests/qtest/aspeed-hace: Test the crypto command on the AST2600
>    tests/qtest/aspeed-hace: Test the crypto command on the AST1030
>    crypto/cipher: Add GCM to QCryptoCipherMode
>    crypto/cipher: Add setaad/gettag for AEAD modes
>    crypto/cipher-gcrypt: Implement AES-GCM
>    crypto/cipher-nettle: Implement AES-GCM
>    crypto/cipher-gnutls: Implement AES-GCM
>    tests/unit/test-crypto-cipher: Test AES-GCM mode
>    hw/misc/aspeed_hace: Support 64-bit DMA for the crypto command
>    hw/misc/aspeed_hace: Support the AES-GCM mode for the crypto command
>    hw/misc/aspeed_hace: Enable the crypto command on the AST2700
>    tests/qtest/aspeed-hace: Test the crypto command on the AST2700
> 
>   qapi/crypto.json                |   4 +-
>   crypto/cipherpriv.h             |   8 +
>   include/crypto/cipher.h         |  36 ++
>   include/hw/misc/aspeed_hace.h   |   1 -
>   tests/qtest/aspeed-hace-utils.h |  20 +
>   crypto/cipher.c                 |  32 ++
>   hw/misc/aspeed_hace.c           | 461 ++++++++++++++++++++-
>   tests/qtest/aspeed-hace-utils.c | 693 ++++++++++++++++++++++++++++++++
>   tests/qtest/aspeed_hace-test.c  |  18 +
>   tests/qtest/ast2700-hace-test.c |   9 +
>   tests/unit/test-crypto-cipher.c | 240 +++++++++++
>   crypto/cipher-gcrypt.c.inc      | 101 +++++
>   crypto/cipher-gnutls.c.inc      | 154 +++++++
>   crypto/cipher-nettle.c.inc      | 128 ++++++
>   tests/qtest/meson.build         |   6 +-
>   15 files changed, 1886 insertions(+), 25 deletions(-)
> 

Applied to

     https://github.com/legoater/qemu aspeed-next

Thanks,

C.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.