[PATCH v10 00/21] target/s390x: Extend qemu CPACF support

Harald Freudenberger posted 21 patches 2 weeks, 6 days ago
Patches applied successfully (tree, apply log)
git fetch https://github.com/patchew-project/qemu tags/patchew/20260706094317.17032-1-freude@linux.ibm.com
Maintainers: "Daniel P. Berrangé" <berrange@redhat.com>, Cornelia Huck <cohuck@redhat.com>, Eric Farman <farman@linux.ibm.com>, Matthew Rosato <mjrosato@linux.ibm.com>, Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>, Richard Henderson <richard.henderson@linaro.org>, Ilya Leoshkevich <iii@linux.ibm.com>, David Hildenbrand <david@kernel.org>
There is a newer version of this series
crypto/aes-helpers.c             | 106 ++++
crypto/meson.build               |   1 +
docs/system/s390x/cpacf.rst      | 144 +++++
docs/system/target-s390x.rst     |   1 +
include/crypto/aes.h             |  14 +
target/s390x/gen-features.c      |  31 ++
target/s390x/tcg/cpacf.h         | 312 +++++++++++
target/s390x/tcg/cpacf_aes.c     | 903 +++++++++++++++++++++++++++++++
target/s390x/tcg/cpacf_sha256.c  | 228 ++++++++
target/s390x/tcg/cpacf_sha512.c  | 241 +++++++++
target/s390x/tcg/crypto_helper.c | 426 ++++++++-------
target/s390x/tcg/insn-data.h.inc |   1 +
target/s390x/tcg/meson.build     |   3 +
target/s390x/tcg/translate.c     |  11 +-
tests/tcg/s390x/Makefile.target  |   9 +
tests/tcg/s390x/cpacf-kdsa.c     |  59 ++
tests/tcg/s390x/cpacf-kimd.c     | 164 ++++++
tests/tcg/s390x/cpacf-klmd.c     | 202 +++++++
tests/tcg/s390x/cpacf-km.c       | 576 ++++++++++++++++++++
tests/tcg/s390x/cpacf-kmac.c     |  59 ++
tests/tcg/s390x/cpacf-kmc.c      | 342 ++++++++++++
tests/tcg/s390x/cpacf-kmctr.c    | 354 ++++++++++++
tests/tcg/s390x/cpacf-pcc.c      | 241 +++++++++
tests/tcg/s390x/cpacf-prno.c     | 130 +++++
tests/tcg/s390x/cpacf.h          | 570 +++++++++++++++++++
25 files changed, 4911 insertions(+), 217 deletions(-)
create mode 100644 crypto/aes-helpers.c
create mode 100644 docs/system/s390x/cpacf.rst
create mode 100644 target/s390x/tcg/cpacf.h
create mode 100644 target/s390x/tcg/cpacf_aes.c
create mode 100644 target/s390x/tcg/cpacf_sha256.c
create mode 100644 target/s390x/tcg/cpacf_sha512.c
create mode 100644 tests/tcg/s390x/cpacf-kdsa.c
create mode 100644 tests/tcg/s390x/cpacf-kimd.c
create mode 100644 tests/tcg/s390x/cpacf-klmd.c
create mode 100644 tests/tcg/s390x/cpacf-km.c
create mode 100644 tests/tcg/s390x/cpacf-kmac.c
create mode 100644 tests/tcg/s390x/cpacf-kmc.c
create mode 100644 tests/tcg/s390x/cpacf-kmctr.c
create mode 100644 tests/tcg/s390x/cpacf-pcc.c
create mode 100644 tests/tcg/s390x/cpacf-prno.c
create mode 100644 tests/tcg/s390x/cpacf.h
[PATCH v10 00/21] target/s390x: Extend qemu CPACF support
Posted by Harald Freudenberger 2 weeks, 6 days ago
This patch series extends the s390 qemu CPACF support to be able to
run a subset of the CPACF instruction cross platform. There have been
requests on the kernel crypto mailing list about a way to test
s390 specific crypto implementations. For example a way to test
s390 CPACF exploitation code like the s390_aes.ko kernel module.

So here now is a set of patches verified on x86 and s390 which
over (slow but working) support for a subset of the subfunctions of
some of the CPACF instructions.

Test: There are some very basic tests included with this patch series
suitable for some CI run. Better test coverage can be done by running
a full blown Linux and use for example the in-kernel crypto modules.
The 'usual' in-kernel crpyto modules will be automatically loaded
which run a bunch of test cases. So there is now support for these
kernel modules:
* sha256_s390x (autoloaded, sha256)
* sha512_s390x (autoloaded, sha512)
* aes_s390x (autoloaded, clear key aes ecb, cbc, ctr, xts)
* pkey_pckmo (autoloaded, derive AES protected key from clear key)
* paes_s390x (not autoloaded, protected key aes ecb, cbc, ctr, xts)
All these modules run selftests if configured by the kernel (which is
enabled by default). Failures are reported via syslog. Additionally
the aes testcases from libica can be run either inside such an qemu
environment or with a static build executed with the qemu tcg
application qemu-s390x --cpu max <static-build-libica-test>.

Changelog:
v1: Initial version with
    - Related code restructured
    - Support KIMD SHA512 and thus SHA256
    - Support KMC AES-128, AES-192 and AES-256 and thus have basic AES
      support (ECB mode) enabled.
    - Support PCC Compute-XTS-Parameter-AES-128 and
      Compute-XTS-Parameter-AES-256 but only for block sequence number
      0. This is a requirement for the next step:
    - Support KM XTS-AES-128 and KM XTS-AES-256. Together with the
      minimal PCC support this enables AES-XTS CPACF acceleration.
v2: - Basic PCKMO support to be able to 'derive' an AES protected key
      from clear key. See header details.
    - Support protected key AES-ECB.
    - Support protected key AES-CBC.
    - Minimal protected key AES-XTS support for CPACF PCC.
    - Support protected key AES-XTS.
    - Support AES-CTR.
    - Support protected key AES-CTR.
v3: - Reordered patches as suggested by Finn.
    - One small bug fix in CPACF_aes.c related to address translation.
v4: - Rename of the parameters based on feedback from Janosch to
      make clear these are registers or ptrs to registers.
      Added Tested by from Holger. Fixed typo "face" -> "fake".
v5: - Add documentation file docs/system/s390x/cpacf.rst which
      describes the state of the CPACF instructions and which
      functions are covered when this series is applied.
      First version sent to public mailing list qemu-s390x.
v6: - Rebase/rework to build on current qemu head.
    - Add docs/system/s390x/cpacf.rst to target-s390x.rst
    - New file crypto/aes-helpers.c with some simple
      functions to support AES modes CBC, CTR and XTS.
    - Slight rewrite of the s390x CPACF implementations to
      use these generic AES mode implementations.
v7: - Update on docs/system/s390x/cpacf.rst to mention
      the zArchicteture Principles of Operation document
      which describes all these CPACF instructions.
v8: - Add a fix which deals with incorrect address handling
      in the sha512 implementation related to fetch and push
      data from/to memory.
    - Slight rework around the capcf function implementation and
      exception generation.
    - Added some more details to the new cpacf.rst file.
    - Fixed some typos and added some suggestions from Finn.
    - Fixed cc handling on return of PCKMO (must not update cc).
    Missing: simple test cases to verify that the implemented and not
    implemented cpacf functions and subfunctions work as expected. But
    see the statement about tests at the header.
v9: - Add simple tests for all the implemented CPACF instructions but
      pckmo (which is a privileged instruction).
    - Reworked the Fix for wrong address to call the wrap function
      inline; rephrased commit header.
    - Improve the header file cpacf.h to hold defines for all the
      cpacf instruction functions and use them in the code.
    - one new commit comprising the base protected key support with
      exposing the xor pattern and wkvp and en/decrypt key functions
      via cpacf.h. So the testcases can use this header file.
    - one new commit which reworks the fetch memory and store memory
      from and to guest (suggested by Ilya Leoshkevich).
v10: - Fixed v9 patch 3 (cpacf_sha512.c was missing)
     Please note that patch #10 "target/s390x: Base support for cpacf
     protected keys" produces a build warning ("unused function"). As
     by default the qemu build has warnings=errors enabled, this one
     patch does not build on it's own. If this is not acceptable, the
     hunk introducing the two functions may be moved to the next
     commit; another solution would be to merge with patch #11.

Harald Freudenberger (21):
  target/s390x: Fix wrong address handling in address loops
  target/s390x: Rework s390 cpacf implementations
  target/s390x: Move cpacf sha512 code into a new file
  target/s390x: Support cpacf sha256
  target/s390x: Support AES ECB for cpacf km instruction
  target/s390x: Support AES CBC for cpacf kmc instruction
  target/s390x: Support AES CTR for cpacf kmctr instruction
  target/s390x: Minimal AES XTS support for cpacf pcc instruction
  target/s390x: Support AES XTS for cpacf km instruction
  target/s390x: Base support for cpacf protected keys
  target/s390x: Support pckmo encrypt AES subfunctions
  target/s390x: Support protected key AES ECB for cpacf km instruction
  target/s390x: Support protected key AES CBC for cpacf kmc instruction
  target/s390x: Support protected key AES CTR for cpacf kmctr
    instruction
  target/s390x: Minimal protected key AES XTS support for cpacf pcc
    instruction
  target/s390x: Support protected key AES XTS for cpacf km instruction
  docs/s390: Document CPACF instructions support
  crypto: Add aes-helpers file to support some AES modes
  target/s390x: Use generic AES helper functions
  target/s390x: Improve fetch and store mem from and to guest
  tests/tcg/s390x: Add tests for CPACF instructions

 crypto/aes-helpers.c             | 106 ++++
 crypto/meson.build               |   1 +
 docs/system/s390x/cpacf.rst      | 144 +++++
 docs/system/target-s390x.rst     |   1 +
 include/crypto/aes.h             |  14 +
 target/s390x/gen-features.c      |  31 ++
 target/s390x/tcg/cpacf.h         | 312 +++++++++++
 target/s390x/tcg/cpacf_aes.c     | 903 +++++++++++++++++++++++++++++++
 target/s390x/tcg/cpacf_sha256.c  | 228 ++++++++
 target/s390x/tcg/cpacf_sha512.c  | 241 +++++++++
 target/s390x/tcg/crypto_helper.c | 426 ++++++++-------
 target/s390x/tcg/insn-data.h.inc |   1 +
 target/s390x/tcg/meson.build     |   3 +
 target/s390x/tcg/translate.c     |  11 +-
 tests/tcg/s390x/Makefile.target  |   9 +
 tests/tcg/s390x/cpacf-kdsa.c     |  59 ++
 tests/tcg/s390x/cpacf-kimd.c     | 164 ++++++
 tests/tcg/s390x/cpacf-klmd.c     | 202 +++++++
 tests/tcg/s390x/cpacf-km.c       | 576 ++++++++++++++++++++
 tests/tcg/s390x/cpacf-kmac.c     |  59 ++
 tests/tcg/s390x/cpacf-kmc.c      | 342 ++++++++++++
 tests/tcg/s390x/cpacf-kmctr.c    | 354 ++++++++++++
 tests/tcg/s390x/cpacf-pcc.c      | 241 +++++++++
 tests/tcg/s390x/cpacf-prno.c     | 130 +++++
 tests/tcg/s390x/cpacf.h          | 570 +++++++++++++++++++
 25 files changed, 4911 insertions(+), 217 deletions(-)
 create mode 100644 crypto/aes-helpers.c
 create mode 100644 docs/system/s390x/cpacf.rst
 create mode 100644 target/s390x/tcg/cpacf.h
 create mode 100644 target/s390x/tcg/cpacf_aes.c
 create mode 100644 target/s390x/tcg/cpacf_sha256.c
 create mode 100644 target/s390x/tcg/cpacf_sha512.c
 create mode 100644 tests/tcg/s390x/cpacf-kdsa.c
 create mode 100644 tests/tcg/s390x/cpacf-kimd.c
 create mode 100644 tests/tcg/s390x/cpacf-klmd.c
 create mode 100644 tests/tcg/s390x/cpacf-km.c
 create mode 100644 tests/tcg/s390x/cpacf-kmac.c
 create mode 100644 tests/tcg/s390x/cpacf-kmc.c
 create mode 100644 tests/tcg/s390x/cpacf-kmctr.c
 create mode 100644 tests/tcg/s390x/cpacf-pcc.c
 create mode 100644 tests/tcg/s390x/cpacf-prno.c
 create mode 100644 tests/tcg/s390x/cpacf.h


base-commit: 20553466cc47af6a8c95f665b601fce3c852e503
--
2.43.0
Re: [PATCH v10 00/21] target/s390x: Extend qemu CPACF support
Posted by Cornelia Huck 2 weeks, 5 days ago
On Mon, Jul 06 2026, Harald Freudenberger <freude@linux.ibm.com> wrote:

> This patch series extends the s390 qemu CPACF support to be able to
> run a subset of the CPACF instruction cross platform. There have been
> requests on the kernel crypto mailing list about a way to test
> s390 specific crypto implementations. For example a way to test
> s390 CPACF exploitation code like the s390_aes.ko kernel module.
>
> So here now is a set of patches verified on x86 and s390 which
> over (slow but working) support for a subset of the subfunctions of
> some of the CPACF instructions.

Hi,

I wanted to pick this, but unfortunately, there are some problems with
it, as spotted by checkpatch (sadly, I did not see this earlier, and
softfreeze is upon us...)

- Licensing information: new files (e.g. cpacf.h) must use an SPDX
  identifier instead of licence boilerplate text - this needs to be fixed
- some files are using tabs instead of spaces in some places
- there are also some other moans (less important), but you may want to
  look at them anyway (the long lines are not really a problem)

Cornelia
Re: [PATCH v10 00/21] target/s390x: Extend qemu CPACF support
Posted by Harald Freudenberger 2 weeks, 4 days ago
On 2026-07-07 11:38, Cornelia Huck wrote:
> On Mon, Jul 06 2026, Harald Freudenberger <freude@linux.ibm.com> wrote:
> 
>> This patch series extends the s390 qemu CPACF support to be able to
>> run a subset of the CPACF instruction cross platform. There have been
>> requests on the kernel crypto mailing list about a way to test
>> s390 specific crypto implementations. For example a way to test
>> s390 CPACF exploitation code like the s390_aes.ko kernel module.
>> 
>> So here now is a set of patches verified on x86 and s390 which
>> over (slow but working) support for a subset of the subfunctions of
>> some of the CPACF instructions.
> 
> Hi,
> 
> I wanted to pick this, but unfortunately, there are some problems with
> it, as spotted by checkpatch (sadly, I did not see this earlier, and
> softfreeze is upon us...)
> 
> - Licensing information: new files (e.g. cpacf.h) must use an SPDX
>   identifier instead of licence boilerplate text - this needs to be 
> fixed
> - some files are using tabs instead of spaces in some places
> - there are also some other moans (less important), but you may want to
>   look at them anyway (the long lines are not really a problem)
> 
> Cornelia

Yes, I saw these checkpatch complains but as nobody else seems to obey
to the checkpatch findings I ignored most of them. However, will fix
the license and tabs things and then let's see what remains.
Re: [PATCH v10 00/21] target/s390x: Extend qemu CPACF support
Posted by Daniel P. Berrangé 2 weeks, 3 days ago
On Tue, Jul 07, 2026 at 04:02:28PM +0200, Harald Freudenberger wrote:
> On 2026-07-07 11:38, Cornelia Huck wrote:
> > On Mon, Jul 06 2026, Harald Freudenberger <freude@linux.ibm.com> wrote:
> > 
> > > This patch series extends the s390 qemu CPACF support to be able to
> > > run a subset of the CPACF instruction cross platform. There have been
> > > requests on the kernel crypto mailing list about a way to test
> > > s390 specific crypto implementations. For example a way to test
> > > s390 CPACF exploitation code like the s390_aes.ko kernel module.
> > > 
> > > So here now is a set of patches verified on x86 and s390 which
> > > over (slow but working) support for a subset of the subfunctions of
> > > some of the CPACF instructions.
> > 
> > Hi,
> > 
> > I wanted to pick this, but unfortunately, there are some problems with
> > it, as spotted by checkpatch (sadly, I did not see this earlier, and
> > softfreeze is upon us...)
> > 
> > - Licensing information: new files (e.g. cpacf.h) must use an SPDX
> >   identifier instead of licence boilerplate text - this needs to be
> > fixed
> > - some files are using tabs instead of spaces in some places
> > - there are also some other moans (less important), but you may want to
> >   look at them anyway (the long lines are not really a problem)
> > 
> > Cornelia
> 
> Yes, I saw these checkpatch complains but as nobody else seems to obey
> to the checkpatch findings I ignored most of them.

That is very much the wrong conclusion to draw. Our existing in-tree
code may not be clean on checkpatch, because we change checkpatch
rules over time but we don't retrospectively change existing code.

New code is expected to be clean with checkpatch unless there are
some genuine false positives which can't be reasonably avoided.

With regards,
Daniel
-- 
|: https://berrange.com       ~~        https://hachyderm.io/@berrange :|
|: https://libvirt.org          ~~          https://entangle-photo.org :|
|: https://pixelfed.art/berrange   ~~    https://fstop138.berrange.com :|
Re: [PATCH v10 00/21] target/s390x: Extend qemu CPACF support
Posted by Cornelia Huck 2 weeks, 4 days ago
On Mon, Jul 06 2026, Harald Freudenberger <freude@linux.ibm.com> wrote:

> Harald Freudenberger (21):
>   target/s390x: Fix wrong address handling in address loops

I've picked the first patch as a bugfix.

>   target/s390x: Rework s390 cpacf implementations
>   target/s390x: Move cpacf sha512 code into a new file
>   target/s390x: Support cpacf sha256
>   target/s390x: Support AES ECB for cpacf km instruction
>   target/s390x: Support AES CBC for cpacf kmc instruction
>   target/s390x: Support AES CTR for cpacf kmctr instruction
>   target/s390x: Minimal AES XTS support for cpacf pcc instruction
>   target/s390x: Support AES XTS for cpacf km instruction
>   target/s390x: Base support for cpacf protected keys
>   target/s390x: Support pckmo encrypt AES subfunctions
>   target/s390x: Support protected key AES ECB for cpacf km instruction
>   target/s390x: Support protected key AES CBC for cpacf kmc instruction
>   target/s390x: Support protected key AES CTR for cpacf kmctr
>     instruction
>   target/s390x: Minimal protected key AES XTS support for cpacf pcc
>     instruction
>   target/s390x: Support protected key AES XTS for cpacf km instruction
>   docs/s390: Document CPACF instructions support
>   crypto: Add aes-helpers file to support some AES modes
>   target/s390x: Use generic AES helper functions
>   target/s390x: Improve fetch and store mem from and to guest
>   tests/tcg/s390x: Add tests for CPACF instructions