From nobody Sun Jul 26 10:59:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783331159; cv=none; d=zohomail.com; s=zohoarc; b=HLyxOqiu9nQvbov10fj8jDsmC8GrBwwRrHO8qmA+f9I259bi4YOtOf1jc8QZKV51u9wb+oxS+tJi3YlykiKNyaf10KO9f+IKT1oPc9vVoZ97dIcWaML15IDSRSa3O2SbPaurZKTlJfZd1u4nHferqHLHHAck2vvTc6YLKWnwb/A= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783331159; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=7HeIz0x3Vg4GqOBlZv/iGgOTB+uhuxBJfASbtqqOY7o=; b=aEgk8yCUw0NQs2OkLRfBWp4/D50+Tw9h5bgZgzjaF9ulMZxjLrMxHJxDJ7fqt8mwhwLNNt2jPRbZoUUMy78O1asV/yY2EUv0Q0zRyeYOfRCk8mlLmzT5n1goRsn6qCn9AtbsyonDTssilt0qmgMBwBhWCYdD21qhvXI+2IS8TEk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783331159924933.7805683960827; Mon, 6 Jul 2026 02:45:59 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wgfrU-0004EF-I9; Mon, 06 Jul 2026 05:43:36 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrP-0004BD-JE; Mon, 06 Jul 2026 05:43:33 -0400 Received: from mx0a-001b2d01.pphosted.com ([148.163.156.1]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrJ-0003wa-SB; Mon, 06 Jul 2026 05:43:28 -0400 Received: from pps.filterd (m0356517.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 6669IWDF3783634; Mon, 6 Jul 2026 09:43:21 GMT Received: from ppma21.wdc07v.mail.ibm.com (5b.69.3da9.ip4.static.sl-reverse.com [169.61.105.91]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f6sw4gqwr-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:21 +0000 (GMT) Received: from pps.filterd (ppma21.wdc07v.mail.ibm.com [127.0.0.1]) by ppma21.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 6669YZMX028286; Mon, 6 Jul 2026 09:43:20 GMT Received: from smtprelay03.fra02v.mail.ibm.com ([9.218.2.224]) by ppma21.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4f7dgjw0gn-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:20 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (smtpav07.fra02v.mail.ibm.com [10.20.54.106]) by smtprelay03.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 6669hGGu47579436 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Mon, 6 Jul 2026 09:43:16 GMT Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 44EDF2004B; Mon, 6 Jul 2026 09:43:16 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 1BC6F2004E; Mon, 6 Jul 2026 09:43:16 +0000 (GMT) Received: from funtu2.ibm.com (unknown [9.111.193.81]) by smtpav07.fra02v.mail.ibm.com (Postfix) with ESMTP; Mon, 6 Jul 2026 09:43:16 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=7HeIz0x3Vg4GqOBlZ v/iGgOTB+uhuxBJfASbtqqOY7o=; b=Mo/y7MlK3ftsK6zGF3hJaXfQW/ZvqdMZc BZZQmXaLJH/r0hsd+5Xt6yap4dhGlrnYr9Fn4zJ3T6/g4eHk0xPQv0FYrYK+/U+a qvBjyrGH4XGejpeqbgiZfgJamCUScDnYoN/tVg2MLj5CsBEV9rywxcAdwfGYp1B/ h7dpIZwCRhyhrBAUT4nG0HmlJdyUdkO6uL6eKxSP9agkb5tK8SWY4yPF5QNHYFnK e1P61cZgcTJTJCYwMpvXTEDzlsTuWl8ZzJvMnOQAXVO5qJ7JkUucZkPok2VZP/i0 DCU7Ysdb/ydNGbNHQF3p+QORslJ74wxTy4yomWMuFNwEMsllNVJfw== From: Harald Freudenberger To: richard.henderson@linaro.org, iii@linux.ibm.com, david@kernel.org, thuth@redhat.com, berrange@redhat.com Cc: qemu-s390x@nongnu.org, qemu-devel@nongnu.org, linux-s390@vger.kernel.org, dengler@linux.ibm.com, borntraeger@linux.ibm.com, fcallies@linux.ibm.com, cohuck@redhat.com Subject: [PATCH v10 01/21] target/s390x: Fix wrong address handling in address loops Date: Mon, 6 Jul 2026 11:42:54 +0200 Message-ID: <20260706094317.17032-2-freude@linux.ibm.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260706094317.17032-1-freude@linux.ibm.com> References: <20260706094317.17032-1-freude@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-GUID: fuiIidox9XsdAgzYv4AU52_fsPoW-On4 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfX07qE+6LXgCwA ZRoFCZmh92uxAJ1yuoaoNvvzrm7BCRHbwOXjis9DqCMCxj97K5ya6LzwTdsIYrKmEA69uzIyOwW Wo0anBQ8eqhfkZ0hzUISN3txqcWTOLTFehg9rTt8zS5L/ncFjpFNVSeRpUPdDe6iPXK98OVsjse 2VulMpYvM+HOehpWJ5ir+Fu+yajZUizfnPULnUlZFlLsZCI+B6akMN4EME+6i5Neck1JZ4uGOiN kfG4ZOmTJMqU3QKkf+gGXmxjPovLCtqv74WAuwcD/rF68SAFpjnjH30Cy185ktFpWOvf0VKizEK 4jXhn9bzz1cGEthlSZ3JOy0fWhLEWI87GJotg6ktZ49CAD2+CbIQteIJTsKBC6/3PvAJbwdNEWj rJ6xshf3daDAyiYY/aK5Wra5v+QX0MeuZFA8cDUD1FRxLha6ZO+502jvb05Mtu9m8BSGdq3aQIz s2yfGD7GSNO+8L0ONdQ== X-Proofpoint-ORIG-GUID: fuiIidox9XsdAgzYv4AU52_fsPoW-On4 X-Authority-Analysis: v=2.4 cv=FqQ1OWrq c=1 sm=1 tr=0 ts=6a4b78b9 cx=c_pps a=GFwsV6G8L6GxiO2Y/PsHdQ==:117 a=GFwsV6G8L6GxiO2Y/PsHdQ==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=U7nrCbtTmkRpXpFmAIza:22 a=VnNF1IyMAAAA:8 a=JcvBkDReJmzHsdK6FyIA:9 X-Proofpoint-Spam-Info: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfX8Gp57f53L0GX 1kf+podd9GbON6A0DacQqe0h7zdhaarh/8+/BTP+D8q5Q/76vNcG0uPpFJ0PixqSluHtDgFOtIa TJgDK/QUsaQxFwS0GTNXIWHmaDEJcCU= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-06_01,2026-07-03_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 adultscore=0 impostorscore=0 clxscore=1015 malwarescore=0 lowpriorityscore=0 priorityscore=1501 bulkscore=0 suspectscore=0 spamscore=0 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607060094 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.156.1; envelope-from=freude@linux.ibm.com; helo=mx0a-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783331161586158501 Content-Type: text/plain; charset="utf-8" The loop increments addr by the element stride (+=3D 4) before calling wrap_address, but then overwrites the loop addr with the wrapped value. On the next iteration the stride is applied to the wrapped address of the previous element, not to the original unwrapped address. This results in every element after the first is read from a wrong (wrapped) address. Fixes: 9f17bfdab4 ("target/s390x: support SHA-512 extensions") Signed-off-by: Harald Freudenberger Reviewed-by: Holger Dengler --- target/s390x/tcg/crypto_helper.c | 12 ++++-------- 1 file changed, 4 insertions(+), 8 deletions(-) diff --git a/target/s390x/tcg/crypto_helper.c b/target/s390x/tcg/crypto_hel= per.c index ae392bce0e..8fe0a22219 100644 --- a/target/s390x/tcg/crypto_helper.c +++ b/target/s390x/tcg/crypto_helper.c @@ -126,8 +126,7 @@ static void sha512_read_icv(CPUS390XState *env, const i= nt mmu_idx, const MemOpIdx oi =3D make_memop_idx(MO_BE | MO_64 | MO_UNALN, mmu_idx= ); =20 for (int i =3D 0; i < 8; i++, addr +=3D 8) { - addr =3D wrap_address(env, addr); - a[i] =3D cpu_ldq_mmu(env, addr, oi, ra); + a[i] =3D cpu_ldq_mmu(env, wrap_address(env, addr), oi, ra); } } =20 @@ -137,8 +136,7 @@ static void sha512_write_ocv(CPUS390XState *env, const = int mmu_idx, const MemOpIdx oi =3D make_memop_idx(MO_BE | MO_64 | MO_UNALN, mmu_idx= ); =20 for (int i =3D 0; i < 8; i++, addr +=3D 8) { - addr =3D wrap_address(env, addr); - cpu_stq_mmu(env, addr, a[i], oi, ra); + cpu_stq_mmu(env, wrap_address(env, addr), a[i], oi, ra); } } =20 @@ -148,8 +146,7 @@ static void sha512_read_block(CPUS390XState *env, const= int mmu_idx, const MemOpIdx oi =3D make_memop_idx(MO_BE | MO_64 | MO_UNALN, mmu_idx= ); =20 for (int i =3D 0; i < 16; i++, addr +=3D 8) { - addr =3D wrap_address(env, addr); - a[i] =3D cpu_ldq_mmu(env, addr, oi, ra); + a[i] =3D cpu_ldq_mmu(env, wrap_address(env, addr), oi, ra); } } =20 @@ -159,8 +156,7 @@ static void sha512_read_mbl_be64(CPUS390XState *env, co= nst int mmu_idx, const MemOpIdx oi =3D make_memop_idx(MO_8, mmu_idx); =20 for (int i =3D 0; i < 16; i++, addr +=3D 1) { - addr =3D wrap_address(env, addr); - a[i] =3D cpu_ldb_mmu(env, addr, oi, ra); + a[i] =3D cpu_ldb_mmu(env, wrap_address(env, addr), oi, ra); } } =20 --=20 2.43.0 From nobody Sun Jul 26 10:59:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783331185; cv=none; d=zohomail.com; s=zohoarc; b=kuyR+9ghGQtJRXOWqKJ7NZdGgTj2LRbfgfDKHsBUHaZYU1hR0tP1JUC9nlDZHNPsa20PqxXQryCDO8cHIgrovI2WH/G6Q6K1VotUic37jK91BqXNdeClHrvNV5+iliNN24Tu6xEMShb6tkyjgwkZV9oOejCMeGq9VGA6p+8VZUk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783331185; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=8zXhT8nCihtpU902ms6sJNqrEMY4fLeK2F589yvHrwI=; b=StvoTdV4EXt0MdN6OPrTInqH760wmRm7X2wHaWs4npia8XyOu3OuJHIs6egjh+8Z+I9I96vI7cROy1avLhjdMBgBcMiMrkDF6DIGlzvhIhJM+WOR/pHXYFVOjLqr0KU+Ys1z8oukUyjJi0knLi1Oc5cPBUYMZ2MX+YNxrmavKto= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783331185262713.3866380539484; Mon, 6 Jul 2026 02:46:25 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wgfrW-0004Fs-2q; Mon, 06 Jul 2026 05:43:38 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrP-0004B9-Bg; Mon, 06 Jul 2026 05:43:31 -0400 Received: from mx0a-001b2d01.pphosted.com ([148.163.156.1]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrJ-0003wV-Ox; Mon, 06 Jul 2026 05:43:28 -0400 Received: from pps.filterd (m0353729.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 6669I9Ck4014395; Mon, 6 Jul 2026 09:43:21 GMT Received: from ppma11.dal12v.mail.ibm.com (db.9e.1632.ip4.static.sl-reverse.com [50.22.158.219]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f6suqgp7w-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:20 +0000 (GMT) Received: from pps.filterd (ppma11.dal12v.mail.ibm.com [127.0.0.1]) by ppma11.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 6669YaI2030211; Mon, 6 Jul 2026 09:43:20 GMT Received: from smtprelay03.fra02v.mail.ibm.com ([9.218.2.224]) by ppma11.dal12v.mail.ibm.com (PPS) with ESMTPS id 4f7f6xvnqd-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:20 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (smtpav07.fra02v.mail.ibm.com [10.20.54.106]) by smtprelay03.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 6669hG2u54985078 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Mon, 6 Jul 2026 09:43:16 GMT Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 79A7420040; Mon, 6 Jul 2026 09:43:16 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 479012004D; Mon, 6 Jul 2026 09:43:16 +0000 (GMT) Received: from funtu2.ibm.com (unknown [9.111.193.81]) by smtpav07.fra02v.mail.ibm.com (Postfix) with ESMTP; Mon, 6 Jul 2026 09:43:16 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=8zXhT8nCihtpU902m s6sJNqrEMY4fLeK2F589yvHrwI=; b=NUERh1NyoLXzcx4gtXlgItCs6KXlfLXj0 /+R6zu5AdysQdEfFXlcWkYsFmdUH1mhyYNUkE/yHxsEQcCPgWSEiUutSUyC278bl hSpTJ9MDKReAFUGfi2PTPnuVoddnfZxogYslFjc+NSXQzhi5b7c7sEUP16uefSxm RUOm5OUcIpNOodpzZgM4QUZc6/QYfOG6a5hDDg8XN9csCq9R70ISETddJVVcnQ2k 39gS7CqSo5CnvQncpeBwkVHqQWQpdIDO1rFYlb+v1S201YEVp20D7ABFpn+rSiUP VgFyfrcTsqYsPknz7fbXQE0JVmra0kje+o76mJCOonrQ2N/as705A== From: Harald Freudenberger To: richard.henderson@linaro.org, iii@linux.ibm.com, david@kernel.org, thuth@redhat.com, berrange@redhat.com Cc: qemu-s390x@nongnu.org, qemu-devel@nongnu.org, linux-s390@vger.kernel.org, dengler@linux.ibm.com, borntraeger@linux.ibm.com, fcallies@linux.ibm.com, cohuck@redhat.com Subject: [PATCH v10 02/21] target/s390x: Rework s390 cpacf implementations Date: Mon, 6 Jul 2026 11:42:55 +0200 Message-ID: <20260706094317.17032-3-freude@linux.ibm.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260706094317.17032-1-freude@linux.ibm.com> References: <20260706094317.17032-1-freude@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Spam-Info: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfXxFTROR3Y/tCM JE59sWVxk+lldyci0da261EwDHjNtlpP6NPwM6CL/1eSoxVyZoKJ7S524a9/6ew17ErvHhBDdUj 1uFN0zDwuQxyo1TfsINouAlLznWys0E= X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfX70H/mEXwpOUb 86etPUeKD5Z6jjWup+bjtvkYDfQJF5USWji7fgnSD9rNF7IO0Z1jJNxwk6XpjibLKkWK0elaT8i ylzBgXUT2pEqqtaWmf17C82qWjV5oChn9baezd1UCZPCoGYiyx9wRaWTduI/3l6XsbFptkZ3Qz2 /R3Hg4gubmd3wssPxp/nHDo2lOlYYaZL2ucEm/UAtbvrWeujGaSKNKnZD3EMOmus0TL8NTa9Ikd IWDRjUwy12GsA7GzaHUfeE+dfucqVXLoVSWtLtOf4nbQ+fzh9qv5tgoxoy2w5GWovKw3N2xsqU2 Uaiu9qCDV2AXdbvvr07OcOPYVgF+OaSSJZMobNT+jNJwla1jE9YogSqt8Ff+Hdnl8cc/YJoBv2a MNALMj4YJJ5llfihRRrwl1PC80p4u0yQGC9MJPqMtgJg418pnepN2cthMJH1NUqWL9/Ui7zcWL/ BNqTJ+4YWXycz0HB+zw== X-Proofpoint-GUID: dNijCf3dLBZGMwOnoyiAQbZqHlw2z_g3 X-Authority-Analysis: v=2.4 cv=Oot/DS/t c=1 sm=1 tr=0 ts=6a4b78b9 cx=c_pps a=aDMHemPKRhS1OARIsFnwRA==:117 a=aDMHemPKRhS1OARIsFnwRA==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=uAbxVGIbfxUO_5tXvNgY:22 a=VnNF1IyMAAAA:8 a=84LnHXV9oTY3brs8VqgA:9 X-Proofpoint-ORIG-GUID: dNijCf3dLBZGMwOnoyiAQbZqHlw2z_g3 X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-06_01,2026-07-03_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 bulkscore=0 lowpriorityscore=0 clxscore=1015 impostorscore=0 phishscore=0 malwarescore=0 suspectscore=0 spamscore=0 adultscore=0 priorityscore=1501 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607060094 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.156.1; envelope-from=freude@linux.ibm.com; helo=mx0a-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783331185786158500 Content-Type: text/plain; charset="utf-8" Fix missing parts for MSA 9 kdsa and rework the cpacf handling code so that further extensions can be made in a clean and structured way. Introduce a new header file to hold defines, structs and function prototypes around s390 cpacf. Use the cpcaf function defines in the existing code. Reviewed-by: Holger Dengler Tested-by: Holger Dengler Reviewed-by: Ilya Leoshkevich Signed-off-by: Harald Freudenberger --- target/s390x/tcg/cpacf.h | 226 +++++++++++++++++++++++++++++++ target/s390x/tcg/crypto_helper.c | 90 ++++++++++-- target/s390x/tcg/insn-data.h.inc | 1 + target/s390x/tcg/translate.c | 2 + 4 files changed, 306 insertions(+), 13 deletions(-) create mode 100644 target/s390x/tcg/cpacf.h diff --git a/target/s390x/tcg/cpacf.h b/target/s390x/tcg/cpacf.h new file mode 100644 index 0000000000..05596e0645 --- /dev/null +++ b/target/s390x/tcg/cpacf.h @@ -0,0 +1,226 @@ +/* + * s390x cpacf + * + * This work is licensed under the terms of the GNU GPL, version 2 or late= r. + * See the COPYING file in the top-level directory. + */ + +#ifndef S390X_CPACF_H +#define S390X_CPACF_H + +/* + * Function codes for the KM instruction + */ +#define CPACF_KM_QUERY 0x00 +#define CPACF_KM_DEA 0x01 +#define CPACF_KM_TDEA_128 0x02 +#define CPACF_KM_TDEA_192 0x03 +#define CPACF_KM_AES_128 0x12 +#define CPACF_KM_AES_192 0x13 +#define CPACF_KM_AES_256 0x14 +#define CPACF_KM_PAES_128 0x1a +#define CPACF_KM_PAES_192 0x1b +#define CPACF_KM_PAES_256 0x1c +#define CPACF_KM_XTS_128 0x32 +#define CPACF_KM_XTS_256 0x34 +#define CPACF_KM_PXTS_128 0x3a +#define CPACF_KM_PXTS_256 0x3c +#define CPACF_KM_FULL_XTS_128 0x52 +#define CPACF_KM_FULL_XTS_256 0x54 +#define CPACF_KM_FULL_PXTS_128 0x5a +#define CPACF_KM_FULL_PXTS_256 0x5c + +/* + * Function codes for the KMC instruction + */ +#define CPACF_KMC_QUERY 0x00 +#define CPACF_KMC_DEA 0x01 +#define CPACF_KMC_TDEA_128 0x02 +#define CPACF_KMC_TDEA_192 0x03 +#define CPACF_KMC_AES_128 0x12 +#define CPACF_KMC_AES_192 0x13 +#define CPACF_KMC_AES_256 0x14 +#define CPACF_KMC_PAES_128 0x1a +#define CPACF_KMC_PAES_192 0x1b +#define CPACF_KMC_PAES_256 0x1c +#define CPACF_KMC_PRNG 0x43 + +/* + * Function codes for the KMCTR instruction + */ +#define CPACF_KMCTR_QUERY 0x00 +#define CPACF_KMCTR_DEA 0x01 +#define CPACF_KMCTR_TDEA_128 0x02 +#define CPACF_KMCTR_TDEA_192 0x03 +#define CPACF_KMCTR_AES_128 0x12 +#define CPACF_KMCTR_AES_192 0x13 +#define CPACF_KMCTR_AES_256 0x14 +#define CPACF_KMCTR_PAES_128 0x1a +#define CPACF_KMCTR_PAES_192 0x1b +#define CPACF_KMCTR_PAES_256 0x1c + +/* + * Function codes for the KIMD instruction + */ +#define CPACF_KIMD_QUERY 0x00 +#define CPACF_KIMD_SHA_1 0x01 +#define CPACF_KIMD_SHA_256 0x02 +#define CPACF_KIMD_SHA_512 0x03 +#define CPACF_KIMD_SHA3_224 0x20 +#define CPACF_KIMD_SHA3_256 0x21 +#define CPACF_KIMD_SHA3_384 0x22 +#define CPACF_KIMD_SHA3_512 0x23 +#define CPACF_KIMD_SHAKE_128 0x24 +#define CPACF_KIMD_SHAKE_256 0x25 +#define CPACF_KIMD_GHASH 0x41 + +/* + * Function codes for the KLMD instruction + */ +#define CPACF_KLMD_QUERY 0x00 +#define CPACF_KLMD_SHA_1 0x01 +#define CPACF_KLMD_SHA_256 0x02 +#define CPACF_KLMD_SHA_512 0x03 +#define CPACF_KLMD_SHA3_224 0x20 +#define CPACF_KLMD_SHA3_256 0x21 +#define CPACF_KLMD_SHA3_384 0x22 +#define CPACF_KLMD_SHA3_512 0x23 +#define CPACF_KLMD_SHAKE_128 0x24 +#define CPACF_KLMD_SHAKE_256 0x25 + +/* + * function codes for the KMAC instruction + */ +#define CPACF_KMAC_QUERY 0x00 +#define CPACF_KMAC_DEA 0x01 +#define CPACF_KMAC_TDEA_128 0x02 +#define CPACF_KMAC_TDEA_192 0x03 +#define CPACF_KMAC_AES_128 0x12 +#define CPACF_KMAC_AES_192 0x13 +#define CPACF_KMAC_AES_256 0x14 +#define CPACF_KMAC_PAES_128 0x1A +#define CPACF_KMAC_PAES_192 0x1B +#define CPACF_KMAC_PAES_256 0x1C +#define CPACF_KMAC_HMAC_SHA_224 0x70 +#define CPACF_KMAC_HMAC_SHA_256 0x71 +#define CPACF_KMAC_HMAC_SHA_384 0x72 +#define CPACF_KMAC_HMAC_SHA_512 0x73 +#define CPACF_KMAC_PHMAC_SHA_224 0x78 +#define CPACF_KMAC_PHMAC_SHA_256 0x79 +#define CPACF_KMAC_PHMAC_SHA_384 0x7a +#define CPACF_KMAC_PHMAC_SHA_512 0x7b + +/* + * Function codes for the PCKMO instruction + */ +#define CPACF_PCKMO_QUERY 0x00 +#define CPACF_PCKMO_ENC_DES_KEY 0x01 +#define CPACF_PCKMO_ENC_TDES_128_KEY 0x02 +#define CPACF_PCKMO_ENC_TDES_192_KEY 0x03 +#define CPACF_PCKMO_ENC_AES_128_KEY 0x12 +#define CPACF_PCKMO_ENC_AES_192_KEY 0x13 +#define CPACF_PCKMO_ENC_AES_256_KEY 0x14 +#define CPACF_PCKMO_ENC_AES_XTS_128_DOUBLE_KEY 0x14 +#define CPACF_PCKMO_ENC_AES_XTS_256_DOUBLE_KEY 0x16 +#define CPACF_PCKMO_ENC_ECC_P256_KEY 0x20 +#define CPACF_PCKMO_ENC_ECC_P384_KEY 0x21 +#define CPACF_PCKMO_ENC_ECC_P521_KEY 0x22 +#define CPACF_PCKMO_ENC_ECC_ED25519_KEY 0x28 +#define CPACF_PCKMO_ENC_ECC_ED448_KEY 0x29 +#define CPACF_PCKMO_ENC_HMAC_512_KEY 0x76 +#define CPACF_PCKMO_ENC_HMAC_1024_KEY 0x7a + +/* + * Function codes for the PRNO instruction + */ +#define CPACF_PRNO_QUERY 0x00 +#define CPACF_PRNO_SHA512_DRNG_GEN 0x03 +#define CPACF_PRNO_SHA512_DRNG_SEED 0x83 +#define CPACF_PRNO_TRNG_Q_R2C_RATIO 0x70 +#define CPACF_PRNO_TRNG 0x72 + +/* + * Function codes for the KMA instruction + */ +#define CPACF_KMA_QUERY 0x00 +#define CPACF_KMA_GCM_AES_128 0x12 +#define CPACF_KMA_GCM_AES_192 0x13 +#define CPACF_KMA_GCM_AES_256 0x14 +#define CPACF_KMA_GCM_PAES_128 0x1A +#define CPACF_KMA_GCM_PAES_192 0x1B +#define CPACF_KMA_GCM_PAES_256 0x1C + +/* + * Function codes for the KMF instruction + */ +#define CPACF_KMF_QUERY 0 +#define CPACF_KMF_DEA 1 +#define CPACF_KMF_TDEA_128 2 +#define CPACF_KMF_TDEA_192 3 +#define CPACF_KMF_AES_128 18 +#define CPACF_KMF_AES_192 19 +#define CPACF_KMF_AES_256 20 +#define CPACF_KMF_PAES_128 26 +#define CPACF_KMF_PAES_192 27 +#define CPACF_KMF_PAES_256 28 + +/* + * Function codes for the KMO instruction + */ +#define CPACF_KMO_QUERY 0 +#define CPACF_KMO_DEA 1 +#define CPACF_KMO_TDEA_128 2 +#define CPACF_KMO_TDEA_192 3 +#define CPACF_KMO_AES_128 18 +#define CPACF_KMO_AES_192 19 +#define CPACF_KMO_AES_256 20 +#define CPACF_KMO_PAES_128 26 +#define CPACF_KMO_PAES_192 27 +#define CPACF_KMO_PAES_256 28 + +/* + * Function codes for the PCC instruction + */ +#define CPACF_PCC_QUERY 0 +#define CPACF_PCC_CMAC_DEA 1 +#define CPACF_PCC_CMAC_TDEA_128 2 +#define CPACF_PCC_CMAC_TDEA_192 3 +#define CPACF_PCC_CMAC_AES_128 18 +#define CPACF_PCC_CMAC_AES_192 19 +#define CPACF_PCC_CMAC_AES_256 20 +#define CPACF_PCC_CMAC_PAES_128 26 +#define CPACF_PCC_CMAC_PAES_192 27 +#define CPACF_PCC_CMAC_PAES_256 28 +#define CPACF_PCC_XTS_AES_128 50 +#define CPACF_PCC_XTS_AES_256 52 +#define CPACF_PCC_XTS_PAES_128 58 +#define CPACF_PCC_XTS_PAES_256 60 +#define CPACF_PCC_SM_P256 64 +#define CPACF_PCC_SM_P384 65 +#define CPACF_PCC_SM_P521 66 +#define CPACF_PCC_SM_ED25519 72 +#define CPACF_PCC_SM_ED448 73 +#define CPACF_PCC_SM_X25519 80 +#define CPACF_PCC_SM_X448 81 + +/* + * Function codes for the KDSA instruction + */ +#define CPACF_KDSA_QUERY 0 +#define CPACF_KDSA_VERIFY_P256 1 +#define CPACF_KDSA_VERIFY_P384 2 +#define CPACF_KDSA_VERIFY_P521 3 +#define CPACF_KDSA_SIGN_P256 9 +#define CPACF_KDSA_SIGN_P384 10 +#define CPACF_KDSA_SIGN_P521 11 +#define CPACF_KDSA_PSIGN_P256 17 +#define CPACF_KDSA_PSIGN_P384 18 +#define CPACF_KDSA_PSIGN_P521 19 +#define CPACF_KDSA_VERIFY_ED25519 32 +#define CPACF_KDSA_VERIFY_ED448 36 +#define CPACF_KDSA_SIGN_ED25519 40 +#define CPACF_KDSA_SIGN_ED448 44 +#define CPACF_KDSA_PSIGN_ED25519 48 +#define CPACF_KDSA_PSIGN_ED448 52 + +#endif /* S390X_CPACF_H */ diff --git a/target/s390x/tcg/crypto_helper.c b/target/s390x/tcg/crypto_hel= per.c index 8fe0a22219..987bc72ae9 100644 --- a/target/s390x/tcg/crypto_helper.c +++ b/target/s390x/tcg/crypto_helper.c @@ -19,6 +19,7 @@ #include "exec/helper-proto.h" #include "accel/tcg/cpu-ldst-common.h" #include "accel/tcg/cpu-mmu-index.h" +#include "target/s390x/tcg/cpacf.h" =20 static uint64_t R(uint64_t x, int c) { @@ -268,6 +269,57 @@ static void fill_buf_random(CPUS390XState *env, const = int mmu_idx, uintptr_t ra, } } =20 +static int cpacf_kimd(CPUS390XState *env, const int mmu_idx, const uintptr= _t ra, + uint32_t r1, uint32_t r2, uint32_t r3, uint8_t fc) +{ + int rc =3D 0; + + switch (fc) { + case CPACF_KIMD_SHA_512: + rc =3D cpacf_sha512(env, mmu_idx, ra, env->regs[1], &env->regs[r2], + &env->regs[r2 + 1], S390_FEAT_TYPE_KIMD); + break; + default: + tcg_s390_program_interrupt(env, PGM_SPECIFICATION, ra); + } + + return rc; +} + +static int cpacf_klmd(CPUS390XState *env, const int mmu_idx, const uintptr= _t ra, + uint32_t r1, uint32_t r2, uint32_t r3, uint8_t fc) +{ + int rc =3D 0; + + switch (fc) { + case CPACF_KLMD_SHA_512: + rc =3D cpacf_sha512(env, mmu_idx, ra, env->regs[1], &env->regs[r2], + &env->regs[r2 + 1], S390_FEAT_TYPE_KLMD); + break; + default: + tcg_s390_program_interrupt(env, PGM_SPECIFICATION, ra); + } + + return rc; +} + +static int cpacf_ppno(CPUS390XState *env, const int mmu_idx, uintptr_t ra, + uint32_t r1, uint32_t r2, uint32_t r3, uint8_t fc) +{ + int rc =3D 0; + + switch (fc) { + case CPACF_PRNO_TRNG: + fill_buf_random(env, mmu_idx, ra, &env->regs[r1], &env->regs[r1 + = 1]); + fill_buf_random(env, mmu_idx, ra, &env->regs[r2], &env->regs[r2 + = 1]); + break; + default: + tcg_s390_program_interrupt(env, PGM_SPECIFICATION, ra); + } + + return rc; +} + uint32_t HELPER(msa)(CPUS390XState *env, uint32_t r1, uint32_t r2, uint32_= t r3, uint32_t type) { @@ -278,13 +330,15 @@ uint32_t HELPER(msa)(CPUS390XState *env, uint32_t r1,= uint32_t r2, uint32_t r3, uint8_t subfunc[16] =3D { 0 }; uint64_t param_addr; MemOpIdx oi; + int rc =3D 0; =20 switch (type) { - case S390_FEAT_TYPE_KMAC: + case S390_FEAT_TYPE_KDSA: case S390_FEAT_TYPE_KIMD: case S390_FEAT_TYPE_KLMD: - case S390_FEAT_TYPE_PCKMO: + case S390_FEAT_TYPE_KMAC: case S390_FEAT_TYPE_PCC: + case S390_FEAT_TYPE_PCKMO: if (mod) { tcg_s390_program_interrupt(env, PGM_SPECIFICATION, ra); } @@ -296,25 +350,35 @@ uint32_t HELPER(msa)(CPUS390XState *env, uint32_t r1,= uint32_t r2, uint32_t r3, tcg_s390_program_interrupt(env, PGM_SPECIFICATION, ra); } =20 - switch (fc) { - case 0: /* query subfunction */ + /* handle query subfunction */ + if (fc =3D=3D 0) { oi =3D make_memop_idx(MO_8, mmu_idx); - for (int i =3D 0; i < 16; i++) { + for (int i =3D 0; i < sizeof(subfunc); i++) { param_addr =3D wrap_address(env, env->regs[1] + i); cpu_stb_mmu(env, param_addr, subfunc[i], oi, ra); } + goto out; + } + + switch (type) { + case S390_FEAT_TYPE_KIMD: + rc =3D cpacf_kimd(env, mmu_idx, ra, r1, r2, r3, fc); break; - case 3: /* CPACF_*_SHA_512 */ - return cpacf_sha512(env, mmu_idx, ra, env->regs[1], &env->regs[r2], - &env->regs[r2 + 1], type); - case 114: /* CPACF_PRNO_TRNG */ - fill_buf_random(env, mmu_idx, ra, &env->regs[r1], &env->regs[r1 + = 1]); - fill_buf_random(env, mmu_idx, ra, &env->regs[r2], &env->regs[r2 + = 1]); + case S390_FEAT_TYPE_KLMD: + rc =3D cpacf_klmd(env, mmu_idx, ra, r1, r2, r3, fc); + break; + case S390_FEAT_TYPE_PPNO: + rc =3D cpacf_ppno(env, mmu_idx, ra, r1, r2, r3, fc); + break; + case S390_FEAT_TYPE_KDSA: + case S390_FEAT_TYPE_KMAC: + /* subfunctions (other than query) are not implemented yet */ + tcg_s390_program_interrupt(env, PGM_OPERATION, ra); break; default: - /* we don't implement any other subfunction yet */ g_assert_not_reached(); } =20 - return 0; +out: + return rc; } diff --git a/target/s390x/tcg/insn-data.h.inc b/target/s390x/tcg/insn-data.= h.inc index 0d5392eac5..6a0a7aacda 100644 --- a/target/s390x/tcg/insn-data.h.inc +++ b/target/s390x/tcg/insn-data.h.inc @@ -1015,6 +1015,7 @@ D(0xb92e, KM, RRE, MSA, 0, 0, 0, 0, msa, 0, S390_FEAT_TYPE_KM) D(0xb92f, KMC, RRE, MSA, 0, 0, 0, 0, msa, 0, S390_FEAT_TYPE_KMC) D(0xb929, KMA, RRF_b, MSA8, 0, 0, 0, 0, msa, 0, S390_FEAT_TYPE_KMA) + D(0xb93a, KDSA, RRE, MSA9, 0, 0, 0, 0, msa, 0, S390_FEAT_TYPE_KDS= A) E(0xb93c, PPNO, RRE, MSA5, 0, 0, 0, 0, msa, 0, S390_FEAT_TYPE_PPN= O, IF_IO) D(0xb93e, KIMD, RRE, MSA, 0, 0, 0, 0, msa, 0, S390_FEAT_TYPE_KIM= D) D(0xb93f, KLMD, RRE, MSA, 0, 0, 0, 0, msa, 0, S390_FEAT_TYPE_KLM= D) diff --git a/target/s390x/tcg/translate.c b/target/s390x/tcg/translate.c index 82165ac1ec..cef1b55149 100644 --- a/target/s390x/tcg/translate.c +++ b/target/s390x/tcg/translate.c @@ -2592,6 +2592,7 @@ static DisasJumpType op_msa(DisasContext *s, DisasOps= *o) /* FALL THROUGH */ case S390_FEAT_TYPE_PCKMO: case S390_FEAT_TYPE_PCC: + case S390_FEAT_TYPE_KDSA: break; default: g_assert_not_reached(); @@ -6046,6 +6047,7 @@ enum DisasInsnEnum { #define FAC_MSA4 S390_FEAT_MSA_EXT_4 /* msa-extension-4 facility */ #define FAC_MSA5 S390_FEAT_MSA_EXT_5 /* msa-extension-5 facility */ #define FAC_MSA8 S390_FEAT_MSA_EXT_8 /* msa-extension-8 facility */ +#define FAC_MSA9 S390_FEAT_MSA_EXT_9 /* msa-extension-9 facility */ #define FAC_ECT S390_FEAT_EXTRACT_CPU_TIME #define FAC_PCI S390_FEAT_ZPCI /* z/PCI facility */ #define FAC_AIS S390_FEAT_ADAPTER_INT_SUPPRESSION --=20 2.43.0 From nobody Sun Jul 26 10:59:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783331155; cv=none; d=zohomail.com; s=zohoarc; b=KfCoYFKl3364lObJrq+Ww9x2OD9z18kCPfAJN9oznKQu5Gri+nC3Zhab+vFPy+476zVuy4Qrtlti704T2GbAArhY7AaiKKY72NcfOYD197Qdu4E25ytTSfKWmk06HD468gUk0HnFOpwqBpS37VT9VywPobiC6QoWrmxovk2Xjjw= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783331155; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=csJ0NhSYtK/h4MKSl77xZnWqARgyPFiJb5autleJ6jY=; b=A1QK3TNQnF76siKp0fEMEYJDSRBgYDmbRtDD4dYW0qr9ETIisvORk9khtMo/sXasOjCAoSWnbQHOGdzPHTerMn17hTVU/SNb/RcmZOmmDJ2n2TIl1vVQ8i4GPBdP9Wi2WsfKznevz1XA61/dZ8q6Au4zMl9C9UR5AOkAlfR1hAw= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783331155046556.4165292317755; Mon, 6 Jul 2026 02:45:55 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wgfrb-0004IO-MK; Mon, 06 Jul 2026 05:43:43 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrW-0004GV-Nh; Mon, 06 Jul 2026 05:43:38 -0400 Received: from mx0b-001b2d01.pphosted.com ([148.163.158.5]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrP-0003xg-K4; Mon, 06 Jul 2026 05:43:38 -0400 Received: from pps.filterd (m0356516.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 6669IUVd3826475; Mon, 6 Jul 2026 09:43:22 GMT Received: from ppma21.wdc07v.mail.ibm.com (5b.69.3da9.ip4.static.sl-reverse.com [169.61.105.91]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f6qkn8vja-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:21 +0000 (GMT) Received: from pps.filterd (ppma21.wdc07v.mail.ibm.com [127.0.0.1]) by ppma21.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 6669YafC028294; Mon, 6 Jul 2026 09:43:21 GMT Received: from smtprelay03.fra02v.mail.ibm.com ([9.218.2.224]) by ppma21.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4f7dgjw0gp-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:20 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (smtpav07.fra02v.mail.ibm.com [10.20.54.106]) by smtprelay03.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 6669hGWC54133116 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Mon, 6 Jul 2026 09:43:16 GMT Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id BA6A22004E; Mon, 6 Jul 2026 09:43:16 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 7EE362004B; Mon, 6 Jul 2026 09:43:16 +0000 (GMT) Received: from funtu2.ibm.com (unknown [9.111.193.81]) by smtpav07.fra02v.mail.ibm.com (Postfix) with ESMTP; Mon, 6 Jul 2026 09:43:16 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=csJ0NhSYtK/h4MKSl 77xZnWqARgyPFiJb5autleJ6jY=; b=h0BINjgfFXDv0sPO4tv/eqBqA1Kw276Uk BKStZpS8wT7KcQ8+it9khuAppxJdESzg97mymH3BNs3eRnlYQhobZnNGdwAB6Ts6 auUs9Iy5mTB5dcrGKdGt81wSiyoQeL1ON1alXVcyKCIzq5A9CGASde+y6m+X93rn KiFW7ssvQQS0fym5RSpYShGKF4krnm/c+dMrljU0mZZgnc1Nmaw3xyy2H9zi2Plf zGRA7I9xpAAgm+tG+c9nNgFZW0DEOMLbw3+xB7g5UQszTdwVyO+TFrMFvrIrDR0R vI41JPmnOKxgiAa5EZHwg3xccdUe2Blamlxm3d3LqmjebMWewsKdg== From: Harald Freudenberger To: richard.henderson@linaro.org, iii@linux.ibm.com, david@kernel.org, thuth@redhat.com, berrange@redhat.com Cc: qemu-s390x@nongnu.org, qemu-devel@nongnu.org, linux-s390@vger.kernel.org, dengler@linux.ibm.com, borntraeger@linux.ibm.com, fcallies@linux.ibm.com, cohuck@redhat.com Subject: [PATCH v10 03/21] target/s390x: Move cpacf sha512 code into a new file Date: Mon, 6 Jul 2026 11:42:56 +0200 Message-ID: <20260706094317.17032-4-freude@linux.ibm.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260706094317.17032-1-freude@linux.ibm.com> References: <20260706094317.17032-1-freude@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Authority-Analysis: v=2.4 cv=Q/XiJY2a c=1 sm=1 tr=0 ts=6a4b78b9 cx=c_pps a=GFwsV6G8L6GxiO2Y/PsHdQ==:117 a=GFwsV6G8L6GxiO2Y/PsHdQ==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=Y2IxJ9c9Rs8Kov3niI8_:22 a=VnNF1IyMAAAA:8 a=UGG5zPGqAAAA:8 a=yMKeI-deMsSePwiaAVEA:9 a=17ibUXfGiVyGqR_YBevW:22 X-Proofpoint-GUID: dv3n2y_B6lvcZOBkF7Di2yBfxe8XhHxU X-Proofpoint-ORIG-GUID: dv3n2y_B6lvcZOBkF7Di2yBfxe8XhHxU X-Proofpoint-Spam-Info: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfXygnhvvKdiSTX L9DMQhIhb500fjmzZ12UI8wGAOcahve6aEplR/0VqeT5j9nvI7c8cX09N3e4IVg2KMhGmx5Uqfe 7bw1N8rygKbukBQ60mnaflx2Ufe6/Qg= X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfX3D+zGlGRXxeE 6DRypkCV3LnsMiOeHZewNKyqI+tGDXV5ziBYYbC9zVFEyaDHxaEyy1xNDHSJYh1u8BGYTJiWrCs YHmItiSeC5QorMqbHZG7JVB0C+fA0lQ8qTucbLSbrb/r/HBTr2exeCTf+3X5Rl9pWrE5sxhU/ug hP7WXAaSRirhu89atDWH0Rs/UrCdGm7/rv7l0XPUQQcxJWUz9oimd7lVHvgHtH0MXw0jW6FtUnq pFalUD63F9t3FoZ/QPUmWHGXJHJQ04xPDDvrkWB+LMK51mtq6i1cUi9VhIy+zSARn7AIZc6KZC9 58hjubtwBvpG3FiJ8FvTfrpGR9Qln5JoxYKkh95tHZsHnFU+X6C1/ibxRxzd33HXfsjTufyA0XQ Kw5LnnNrN++FeFFvZSpoLHDcmbcwhDQKewkdgw9/6LWnEu/zxPnhV7Cg6CYW/0ElBRZs6/C5lEW JMrwXoSe9q7b0HMaIEA== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-06_01,2026-07-03_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 adultscore=0 impostorscore=0 spamscore=0 phishscore=0 priorityscore=1501 bulkscore=0 clxscore=1015 lowpriorityscore=0 suspectscore=0 malwarescore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607060094 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.158.5; envelope-from=freude@linux.ibm.com; helo=mx0b-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783331155640158500 Content-Type: text/plain; charset="utf-8" Move the cpacf sha512 implementation into a new file cpacf_sha512.c. Add this new file to the build and use the cpacf.h header file storing function the prototypes. Tested-by: Holger Dengler Reviewed-by: Finn Callies Reviewed-by: Ilya Leoshkevich Signed-off-by: Harald Freudenberger Reviewed-by: Holger Dengler --- target/s390x/tcg/cpacf.h | 5 + target/s390x/tcg/cpacf_sha512.c | 241 +++++++++++++++++++++++++++++++ target/s390x/tcg/crypto_helper.c | 222 ---------------------------- target/s390x/tcg/meson.build | 1 + 4 files changed, 247 insertions(+), 222 deletions(-) create mode 100644 target/s390x/tcg/cpacf_sha512.c diff --git a/target/s390x/tcg/cpacf.h b/target/s390x/tcg/cpacf.h index 05596e0645..6de79a2f8f 100644 --- a/target/s390x/tcg/cpacf.h +++ b/target/s390x/tcg/cpacf.h @@ -223,4 +223,9 @@ #define CPACF_KDSA_PSIGN_ED25519 48 #define CPACF_KDSA_PSIGN_ED448 52 =20 +/* from cpacf_sha512.c */ +int cpacf_sha512(CPUS390XState *env, const int mmu_idx, uintptr_t ra, + uint64_t param_addr, uint64_t *message_reg, uint64_t *len= _reg, + uint32_t type); + #endif /* S390X_CPACF_H */ diff --git a/target/s390x/tcg/cpacf_sha512.c b/target/s390x/tcg/cpacf_sha51= 2.c new file mode 100644 index 0000000000..28e5dcf7bf --- /dev/null +++ b/target/s390x/tcg/cpacf_sha512.c @@ -0,0 +1,241 @@ +/* + * s390 cpacf sha512 + * + * Copyright (C) 2022 Jason A. Donenfeld . All Rights Re= served. + * + * Authors: + * Jason A. Donenfeld + * + * This work is licensed under the terms of the GNU GPL, version 2 or late= r. + * See the COPYING file in the top-level directory. + */ + +#include "qemu/osdep.h" +#include "s390x-internal.h" +#include "tcg_s390x.h" +#include "exec/helper-proto.h" +#include "accel/tcg/cpu-ldst-common.h" +#include "accel/tcg/cpu-mmu-index.h" +#include "target/s390x/tcg/cpacf.h" + +static uint64_t R(uint64_t x, int c) +{ + return (x >> c) | (x << (64 - c)); +} +static uint64_t Ch(uint64_t x, uint64_t y, uint64_t z) +{ + return (x & y) ^ (~x & z); +} +static uint64_t Maj(uint64_t x, uint64_t y, uint64_t z) +{ + return (x & y) ^ (x & z) ^ (y & z); +} +static uint64_t Sigma0(uint64_t x) +{ + return R(x, 28) ^ R(x, 34) ^ R(x, 39); +} +static uint64_t Sigma1(uint64_t x) +{ + return R(x, 14) ^ R(x, 18) ^ R(x, 41); +} +static uint64_t sigma0(uint64_t x) +{ + return R(x, 1) ^ R(x, 8) ^ (x >> 7); +} +static uint64_t sigma1(uint64_t x) +{ + return R(x, 19) ^ R(x, 61) ^ (x >> 6); +} + +static const uint64_t K[80] =3D { + 0x428a2f98d728ae22ULL, 0x7137449123ef65cdULL, 0xb5c0fbcfec4d3b2fULL, + 0xe9b5dba58189dbbcULL, 0x3956c25bf348b538ULL, 0x59f111f1b605d019ULL, + 0x923f82a4af194f9bULL, 0xab1c5ed5da6d8118ULL, 0xd807aa98a3030242ULL, + 0x12835b0145706fbeULL, 0x243185be4ee4b28cULL, 0x550c7dc3d5ffb4e2ULL, + 0x72be5d74f27b896fULL, 0x80deb1fe3b1696b1ULL, 0x9bdc06a725c71235ULL, + 0xc19bf174cf692694ULL, 0xe49b69c19ef14ad2ULL, 0xefbe4786384f25e3ULL, + 0x0fc19dc68b8cd5b5ULL, 0x240ca1cc77ac9c65ULL, 0x2de92c6f592b0275ULL, + 0x4a7484aa6ea6e483ULL, 0x5cb0a9dcbd41fbd4ULL, 0x76f988da831153b5ULL, + 0x983e5152ee66dfabULL, 0xa831c66d2db43210ULL, 0xb00327c898fb213fULL, + 0xbf597fc7beef0ee4ULL, 0xc6e00bf33da88fc2ULL, 0xd5a79147930aa725ULL, + 0x06ca6351e003826fULL, 0x142929670a0e6e70ULL, 0x27b70a8546d22ffcULL, + 0x2e1b21385c26c926ULL, 0x4d2c6dfc5ac42aedULL, 0x53380d139d95b3dfULL, + 0x650a73548baf63deULL, 0x766a0abb3c77b2a8ULL, 0x81c2c92e47edaee6ULL, + 0x92722c851482353bULL, 0xa2bfe8a14cf10364ULL, 0xa81a664bbc423001ULL, + 0xc24b8b70d0f89791ULL, 0xc76c51a30654be30ULL, 0xd192e819d6ef5218ULL, + 0xd69906245565a910ULL, 0xf40e35855771202aULL, 0x106aa07032bbd1b8ULL, + 0x19a4c116b8d2d0c8ULL, 0x1e376c085141ab53ULL, 0x2748774cdf8eeb99ULL, + 0x34b0bcb5e19b48a8ULL, 0x391c0cb3c5c95a63ULL, 0x4ed8aa4ae3418acbULL, + 0x5b9cca4f7763e373ULL, 0x682e6ff3d6b2b8a3ULL, 0x748f82ee5defb2fcULL, + 0x78a5636f43172f60ULL, 0x84c87814a1f0ab72ULL, 0x8cc702081a6439ecULL, + 0x90befffa23631e28ULL, 0xa4506cebde82bde9ULL, 0xbef9a3f7b2c67915ULL, + 0xc67178f2e372532bULL, 0xca273eceea26619cULL, 0xd186b8c721c0c207ULL, + 0xeada7dd6cde0eb1eULL, 0xf57d4f7fee6ed178ULL, 0x06f067aa72176fbaULL, + 0x0a637dc5a2c898a6ULL, 0x113f9804bef90daeULL, 0x1b710b35131c471bULL, + 0x28db77f523047d84ULL, 0x32caab7b40c72493ULL, 0x3c9ebe0a15c9bebcULL, + 0x431d67c49c100d4cULL, 0x4cc5d4becb3e42b6ULL, 0x597f299cfc657e2aULL, + 0x5fcb6fab3ad6faecULL, 0x6c44198c4a475817ULL +}; + +/* a is icv/ocv, w is a single message block. w will get reused internally= . */ +static void sha512_bda(uint64_t a[8], uint64_t w[16]) +{ + uint64_t t, z[8], b[8]; + int i, j; + + memcpy(z, a, sizeof(z)); + for (i =3D 0; i < 80; i++) { + memcpy(b, a, sizeof(b)); + + t =3D a[7] + Sigma1(a[4]) + Ch(a[4], a[5], a[6]) + K[i] + w[i % 16= ]; + b[7] =3D t + Sigma0(a[0]) + Maj(a[0], a[1], a[2]); + b[3] +=3D t; + for (j =3D 0; j < 8; ++j) { + a[(j + 1) % 8] =3D b[j]; + } + if (i % 16 =3D=3D 15) { + for (j =3D 0; j < 16; ++j) { + w[j] +=3D w[(j + 9) % 16] + sigma0(w[(j + 1) % 16]) + + sigma1(w[(j + 14) % 16]); + } + } + } + + for (i =3D 0; i < 8; i++) { + a[i] +=3D z[i]; + } +} + +/* a is icv/ocv, w is a single message block that needs be64 conversion. */ +static void sha512_bda_be64(uint64_t a[8], uint64_t w[16]) +{ + uint64_t t[16]; + int i; + + for (i =3D 0; i < 16; i++) { + t[i] =3D be64_to_cpu(w[i]); + } + sha512_bda(a, t); +} + +static void sha512_read_icv(CPUS390XState *env, const int mmu_idx, + uint64_t addr, uint64_t a[8], uintptr_t ra) +{ + const MemOpIdx oi =3D make_memop_idx(MO_BE | MO_64 | MO_UNALN, mmu_idx= ); + + for (int i =3D 0; i < 8; i++, addr +=3D 8) { + a[i] =3D cpu_ldq_mmu(env, wrap_address(env, addr), oi, ra); + } +} + +static void sha512_write_ocv(CPUS390XState *env, const int mmu_idx, + uint64_t addr, uint64_t a[8], uintptr_t ra) +{ + const MemOpIdx oi =3D make_memop_idx(MO_BE | MO_64 | MO_UNALN, mmu_idx= ); + + for (int i =3D 0; i < 8; i++, addr +=3D 8) { + cpu_stq_mmu(env, wrap_address(env, addr), a[i], oi, ra); + } +} + +static void sha512_read_block(CPUS390XState *env, const int mmu_idx, + uint64_t addr, uint64_t a[16], uintptr_t ra) +{ + const MemOpIdx oi =3D make_memop_idx(MO_BE | MO_64 | MO_UNALN, mmu_idx= ); + + for (int i =3D 0; i < 16; i++, addr +=3D 8) { + a[i] =3D cpu_ldq_mmu(env, wrap_address(env, addr), oi, ra); + } +} + +static void sha512_read_mbl_be64(CPUS390XState *env, const int mmu_idx, + uint64_t addr, uint8_t a[16], uintptr_t r= a) +{ + const MemOpIdx oi =3D make_memop_idx(MO_8, mmu_idx); + + for (int i =3D 0; i < 16; i++, addr +=3D 1) { + a[i] =3D cpu_ldb_mmu(env, wrap_address(env, addr), oi, ra); + } +} + +int cpacf_sha512(CPUS390XState *env, const int mmu_idx, uintptr_t ra, + uint64_t param_addr, uint64_t *message_reg, uint64_t *len= _reg, + uint32_t type) +{ + enum { MAX_BLOCKS_PER_RUN =3D 64 }; /* Arbitrary: keep interactivity. = */ + uint64_t len =3D *len_reg, a[8], processed =3D 0; + int i, message_reg_len =3D 64; + + g_assert(type =3D=3D S390_FEAT_TYPE_KIMD || type =3D=3D S390_FEAT_TYPE= _KLMD); + + if (!(env->psw.mask & PSW_MASK_64)) { + len =3D (uint32_t)len; + message_reg_len =3D (env->psw.mask & PSW_MASK_32) ? 32 : 24; + } + + /* KIMD: length has to be properly aligned. */ + if (type =3D=3D S390_FEAT_TYPE_KIMD && !QEMU_IS_ALIGNED(len, 128)) { + tcg_s390_program_interrupt(env, PGM_SPECIFICATION, ra); + } + + sha512_read_icv(env, mmu_idx, param_addr, a, ra); + + /* Process full blocks first. */ + for (; len >=3D 128; len -=3D 128, processed +=3D 128) { + uint64_t w[16]; + + if (processed >=3D MAX_BLOCKS_PER_RUN * 128) { + break; + } + + sha512_read_block(env, mmu_idx, *message_reg + processed, w, ra); + sha512_bda(a, w); + } + + /* KLMD: Process partial/empty block last. */ + if (type =3D=3D S390_FEAT_TYPE_KLMD && len < 128) { + const MemOpIdx oi =3D make_memop_idx(MO_8, mmu_idx); + uint8_t x[128]; + + /* Read the remainder of the message byte-per-byte. */ + for (i =3D 0; i < len; i++) { + uint64_t addr =3D wrap_address(env, *message_reg + processed += i); + + x[i] =3D cpu_ldb_mmu(env, addr, oi, ra); + } + /* Pad the remainder with zero and set the top bit. */ + memset(x + len, 0, 128 - len); + x[len] =3D 128; + + /* + * Place the MBL either into this block (if there is space left), + * or use an additional one. + */ + if (len < 112) { + sha512_read_mbl_be64(env, mmu_idx, param_addr + 64, x + 112, r= a); + } + sha512_bda_be64(a, (uint64_t *)x); + + if (len >=3D 112) { + memset(x, 0, 112); + sha512_read_mbl_be64(env, mmu_idx, param_addr + 64, x + 112, r= a); + sha512_bda_be64(a, (uint64_t *)x); + } + + processed +=3D len; + len =3D 0; + } + + /* + * Modify memory after we read all inputs and modify registers only af= ter + * writing memory succeeded. + * + * TODO: if writing fails halfway through (e.g., when crossing page + * boundaries), we're in trouble. We'd need something like access_prep= are(). + */ + sha512_write_ocv(env, mmu_idx, param_addr, a, ra); + *message_reg =3D deposit64(*message_reg, 0, message_reg_len, + *message_reg + processed); + *len_reg -=3D processed; + return !len ? 0 : 3; +} diff --git a/target/s390x/tcg/crypto_helper.c b/target/s390x/tcg/crypto_hel= per.c index 987bc72ae9..dba46baa0d 100644 --- a/target/s390x/tcg/crypto_helper.c +++ b/target/s390x/tcg/crypto_helper.c @@ -21,228 +21,6 @@ #include "accel/tcg/cpu-mmu-index.h" #include "target/s390x/tcg/cpacf.h" =20 -static uint64_t R(uint64_t x, int c) -{ - return (x >> c) | (x << (64 - c)); -} -static uint64_t Ch(uint64_t x, uint64_t y, uint64_t z) -{ - return (x & y) ^ (~x & z); -} -static uint64_t Maj(uint64_t x, uint64_t y, uint64_t z) -{ - return (x & y) ^ (x & z) ^ (y & z); -} -static uint64_t Sigma0(uint64_t x) -{ - return R(x, 28) ^ R(x, 34) ^ R(x, 39); -} -static uint64_t Sigma1(uint64_t x) -{ - return R(x, 14) ^ R(x, 18) ^ R(x, 41); -} -static uint64_t sigma0(uint64_t x) -{ - return R(x, 1) ^ R(x, 8) ^ (x >> 7); -} -static uint64_t sigma1(uint64_t x) -{ - return R(x, 19) ^ R(x, 61) ^ (x >> 6); -} - -static const uint64_t K[80] =3D { - 0x428a2f98d728ae22ULL, 0x7137449123ef65cdULL, 0xb5c0fbcfec4d3b2fULL, - 0xe9b5dba58189dbbcULL, 0x3956c25bf348b538ULL, 0x59f111f1b605d019ULL, - 0x923f82a4af194f9bULL, 0xab1c5ed5da6d8118ULL, 0xd807aa98a3030242ULL, - 0x12835b0145706fbeULL, 0x243185be4ee4b28cULL, 0x550c7dc3d5ffb4e2ULL, - 0x72be5d74f27b896fULL, 0x80deb1fe3b1696b1ULL, 0x9bdc06a725c71235ULL, - 0xc19bf174cf692694ULL, 0xe49b69c19ef14ad2ULL, 0xefbe4786384f25e3ULL, - 0x0fc19dc68b8cd5b5ULL, 0x240ca1cc77ac9c65ULL, 0x2de92c6f592b0275ULL, - 0x4a7484aa6ea6e483ULL, 0x5cb0a9dcbd41fbd4ULL, 0x76f988da831153b5ULL, - 0x983e5152ee66dfabULL, 0xa831c66d2db43210ULL, 0xb00327c898fb213fULL, - 0xbf597fc7beef0ee4ULL, 0xc6e00bf33da88fc2ULL, 0xd5a79147930aa725ULL, - 0x06ca6351e003826fULL, 0x142929670a0e6e70ULL, 0x27b70a8546d22ffcULL, - 0x2e1b21385c26c926ULL, 0x4d2c6dfc5ac42aedULL, 0x53380d139d95b3dfULL, - 0x650a73548baf63deULL, 0x766a0abb3c77b2a8ULL, 0x81c2c92e47edaee6ULL, - 0x92722c851482353bULL, 0xa2bfe8a14cf10364ULL, 0xa81a664bbc423001ULL, - 0xc24b8b70d0f89791ULL, 0xc76c51a30654be30ULL, 0xd192e819d6ef5218ULL, - 0xd69906245565a910ULL, 0xf40e35855771202aULL, 0x106aa07032bbd1b8ULL, - 0x19a4c116b8d2d0c8ULL, 0x1e376c085141ab53ULL, 0x2748774cdf8eeb99ULL, - 0x34b0bcb5e19b48a8ULL, 0x391c0cb3c5c95a63ULL, 0x4ed8aa4ae3418acbULL, - 0x5b9cca4f7763e373ULL, 0x682e6ff3d6b2b8a3ULL, 0x748f82ee5defb2fcULL, - 0x78a5636f43172f60ULL, 0x84c87814a1f0ab72ULL, 0x8cc702081a6439ecULL, - 0x90befffa23631e28ULL, 0xa4506cebde82bde9ULL, 0xbef9a3f7b2c67915ULL, - 0xc67178f2e372532bULL, 0xca273eceea26619cULL, 0xd186b8c721c0c207ULL, - 0xeada7dd6cde0eb1eULL, 0xf57d4f7fee6ed178ULL, 0x06f067aa72176fbaULL, - 0x0a637dc5a2c898a6ULL, 0x113f9804bef90daeULL, 0x1b710b35131c471bULL, - 0x28db77f523047d84ULL, 0x32caab7b40c72493ULL, 0x3c9ebe0a15c9bebcULL, - 0x431d67c49c100d4cULL, 0x4cc5d4becb3e42b6ULL, 0x597f299cfc657e2aULL, - 0x5fcb6fab3ad6faecULL, 0x6c44198c4a475817ULL -}; - -/* a is icv/ocv, w is a single message block. w will get reused internally= . */ -static void sha512_bda(uint64_t a[8], uint64_t w[16]) -{ - uint64_t t, z[8], b[8]; - int i, j; - - memcpy(z, a, sizeof(z)); - for (i =3D 0; i < 80; i++) { - memcpy(b, a, sizeof(b)); - - t =3D a[7] + Sigma1(a[4]) + Ch(a[4], a[5], a[6]) + K[i] + w[i % 16= ]; - b[7] =3D t + Sigma0(a[0]) + Maj(a[0], a[1], a[2]); - b[3] +=3D t; - for (j =3D 0; j < 8; ++j) { - a[(j + 1) % 8] =3D b[j]; - } - if (i % 16 =3D=3D 15) { - for (j =3D 0; j < 16; ++j) { - w[j] +=3D w[(j + 9) % 16] + sigma0(w[(j + 1) % 16]) + - sigma1(w[(j + 14) % 16]); - } - } - } - - for (i =3D 0; i < 8; i++) { - a[i] +=3D z[i]; - } -} - -/* a is icv/ocv, w is a single message block that needs be64 conversion. */ -static void sha512_bda_be64(uint64_t a[8], uint64_t w[16]) -{ - uint64_t t[16]; - int i; - - for (i =3D 0; i < 16; i++) { - t[i] =3D be64_to_cpu(w[i]); - } - sha512_bda(a, t); -} - -static void sha512_read_icv(CPUS390XState *env, const int mmu_idx, - uint64_t addr, uint64_t a[8], uintptr_t ra) -{ - const MemOpIdx oi =3D make_memop_idx(MO_BE | MO_64 | MO_UNALN, mmu_idx= ); - - for (int i =3D 0; i < 8; i++, addr +=3D 8) { - a[i] =3D cpu_ldq_mmu(env, wrap_address(env, addr), oi, ra); - } -} - -static void sha512_write_ocv(CPUS390XState *env, const int mmu_idx, - uint64_t addr, uint64_t a[8], uintptr_t ra) -{ - const MemOpIdx oi =3D make_memop_idx(MO_BE | MO_64 | MO_UNALN, mmu_idx= ); - - for (int i =3D 0; i < 8; i++, addr +=3D 8) { - cpu_stq_mmu(env, wrap_address(env, addr), a[i], oi, ra); - } -} - -static void sha512_read_block(CPUS390XState *env, const int mmu_idx, - uint64_t addr, uint64_t a[16], uintptr_t ra) -{ - const MemOpIdx oi =3D make_memop_idx(MO_BE | MO_64 | MO_UNALN, mmu_idx= ); - - for (int i =3D 0; i < 16; i++, addr +=3D 8) { - a[i] =3D cpu_ldq_mmu(env, wrap_address(env, addr), oi, ra); - } -} - -static void sha512_read_mbl_be64(CPUS390XState *env, const int mmu_idx, - uint64_t addr, uint8_t a[16], uintptr_t r= a) -{ - const MemOpIdx oi =3D make_memop_idx(MO_8, mmu_idx); - - for (int i =3D 0; i < 16; i++, addr +=3D 1) { - a[i] =3D cpu_ldb_mmu(env, wrap_address(env, addr), oi, ra); - } -} - -static int cpacf_sha512(CPUS390XState *env, const int mmu_idx, uintptr_t r= a, - uint64_t param_addr, uint64_t *message_reg, - uint64_t *len_reg, uint32_t type) -{ - enum { MAX_BLOCKS_PER_RUN =3D 64 }; /* Arbitrary: keep interactivity. = */ - uint64_t len =3D *len_reg, a[8], processed =3D 0; - int i, message_reg_len =3D 64; - - g_assert(type =3D=3D S390_FEAT_TYPE_KIMD || type =3D=3D S390_FEAT_TYPE= _KLMD); - - if (!(env->psw.mask & PSW_MASK_64)) { - len =3D (uint32_t)len; - message_reg_len =3D (env->psw.mask & PSW_MASK_32) ? 32 : 24; - } - - /* KIMD: length has to be properly aligned. */ - if (type =3D=3D S390_FEAT_TYPE_KIMD && !QEMU_IS_ALIGNED(len, 128)) { - tcg_s390_program_interrupt(env, PGM_SPECIFICATION, ra); - } - - sha512_read_icv(env, mmu_idx, param_addr, a, ra); - - /* Process full blocks first. */ - for (; len >=3D 128; len -=3D 128, processed +=3D 128) { - uint64_t w[16]; - - if (processed >=3D MAX_BLOCKS_PER_RUN * 128) { - break; - } - - sha512_read_block(env, mmu_idx, *message_reg + processed, w, ra); - sha512_bda(a, w); - } - - /* KLMD: Process partial/empty block last. */ - if (type =3D=3D S390_FEAT_TYPE_KLMD && len < 128) { - const MemOpIdx oi =3D make_memop_idx(MO_8, mmu_idx); - uint8_t x[128]; - - /* Read the remainder of the message byte-per-byte. */ - for (i =3D 0; i < len; i++) { - uint64_t addr =3D wrap_address(env, *message_reg + processed += i); - - x[i] =3D cpu_ldb_mmu(env, addr, oi, ra); - } - /* Pad the remainder with zero and set the top bit. */ - memset(x + len, 0, 128 - len); - x[len] =3D 128; - - /* - * Place the MBL either into this block (if there is space left), - * or use an additional one. - */ - if (len < 112) { - sha512_read_mbl_be64(env, mmu_idx, param_addr + 64, x + 112, r= a); - } - sha512_bda_be64(a, (uint64_t *)x); - - if (len >=3D 112) { - memset(x, 0, 112); - sha512_read_mbl_be64(env, mmu_idx, param_addr + 64, x + 112, r= a); - sha512_bda_be64(a, (uint64_t *)x); - } - - processed +=3D len; - len =3D 0; - } - - /* - * Modify memory after we read all inputs and modify registers only af= ter - * writing memory succeeded. - * - * TODO: if writing fails halfway through (e.g., when crossing page - * boundaries), we're in trouble. We'd need something like access_prep= are(). - */ - sha512_write_ocv(env, mmu_idx, param_addr, a, ra); - *message_reg =3D deposit64(*message_reg, 0, message_reg_len, - *message_reg + processed); - *len_reg -=3D processed; - return !len ? 0 : 3; -} - static void fill_buf_random(CPUS390XState *env, const int mmu_idx, uintptr= _t ra, uint64_t *buf_reg, uint64_t *len_reg) { diff --git a/target/s390x/tcg/meson.build b/target/s390x/tcg/meson.build index 36cb0e079e..54a87393a3 100644 --- a/target/s390x/tcg/meson.build +++ b/target/s390x/tcg/meson.build @@ -5,6 +5,7 @@ s390x_ss.add(when: 'CONFIG_TCG', if_true: files( )) s390x_common_ss.add(when: 'CONFIG_TCG', if_true: files( 'cc_helper.c', + 'cpacf_sha512.c', 'crypto_helper.c', 'excp_helper.c', 'fpu_helper.c', --=20 2.43.0 From nobody Sun Jul 26 10:59:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783331222; cv=none; d=zohomail.com; s=zohoarc; b=YPrW1pnZW2kNpIlf3PamDKiHX4Ivd92llPvFZPqzMwtJEegnW3OrO4oTGi6E3dyPwrNHEhjlsagWIaKNtMzz4u7DwWcPHSqbYjVdOG49M5hBNFk9HVYU6/ABBsE1zSuGetL35CcS2W+0vvjVqdzRVhNewEEX/7IfWTKS/v+Sy04= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783331222; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=cvh4omc2kqG1xHa+RsM00nDL95QmYWXsc0QKAZsRJLc=; b=Rvt6/vAhJJ+KjbzQraJFqk2WhKEStOuMCm5DbAomzEPEYl1IJsrHVC5SlzukhvX6XcYZKAPLxRmcBEXG4XyO8BVqK2B6hGunP4M01aCehcTa7157PhXzbOBZ9Of3EUSjKnnJ4CaW0w1MkJWd9+r+5p9O/OVgDoP9XQN9OXZhdjE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783331222583867.1175322547853; Mon, 6 Jul 2026 02:47:02 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wgfra-0004I3-SJ; Mon, 06 Jul 2026 05:43:42 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrT-0004CU-9Z; Mon, 06 Jul 2026 05:43:35 -0400 Received: from mx0a-001b2d01.pphosted.com ([148.163.156.1]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrN-0003xK-US; Mon, 06 Jul 2026 05:43:34 -0400 Received: from pps.filterd (m0360083.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 6669IWR13890512; Mon, 6 Jul 2026 09:43:22 GMT Received: from ppma21.wdc07v.mail.ibm.com (5b.69.3da9.ip4.static.sl-reverse.com [169.61.105.91]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f6sp3gsqp-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:22 +0000 (GMT) Received: from pps.filterd (ppma21.wdc07v.mail.ibm.com [127.0.0.1]) by ppma21.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 6669Yd6L028342; Mon, 6 Jul 2026 09:43:21 GMT Received: from smtprelay04.fra02v.mail.ibm.com ([9.218.2.228]) by ppma21.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4f7dgjw0gq-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:21 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (smtpav07.fra02v.mail.ibm.com [10.20.54.106]) by smtprelay04.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 6669hHEk25363010 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Mon, 6 Jul 2026 09:43:17 GMT Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id EF9D420040; Mon, 6 Jul 2026 09:43:16 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id BD9302004F; Mon, 6 Jul 2026 09:43:16 +0000 (GMT) Received: from funtu2.ibm.com (unknown [9.111.193.81]) by smtpav07.fra02v.mail.ibm.com (Postfix) with ESMTP; Mon, 6 Jul 2026 09:43:16 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=cvh4omc2kqG1xHa+R sM00nDL95QmYWXsc0QKAZsRJLc=; b=bSXbz2OahN3nfyZKQYje8X1yrMsFh6XBG ludyk8/KNRy8VOxi7C/5bFvA8Qc/3uB0z+NQh1xTQc8QK15oxfiq/WkTiftv6clk M3zyH9LPMBznSmS1GLWvJppKCLPwTIyze2dvGd3RwuNvvzNHIy5EpVnAbnHFctaL OU9LWOEzORGv3xHGZNpwE3qkMYhlXvDpbTdte3oFevalHoT82UvHoaUHPLcuDWrz rH8aMPIMm7BwEc2zbvWQXNssvR8XMX6ZftBnbQBrccZRtxCZk3guvjUKhH1Y6lGt ejflC2WQ8/BDcOQv9UGs8tk7BOgLW1hT1mbL2XyzZwPyBO738orOQ== From: Harald Freudenberger To: richard.henderson@linaro.org, iii@linux.ibm.com, david@kernel.org, thuth@redhat.com, berrange@redhat.com Cc: qemu-s390x@nongnu.org, qemu-devel@nongnu.org, linux-s390@vger.kernel.org, dengler@linux.ibm.com, borntraeger@linux.ibm.com, fcallies@linux.ibm.com, cohuck@redhat.com Subject: [PATCH v10 04/21] target/s390x: Support cpacf sha256 Date: Mon, 6 Jul 2026 11:42:57 +0200 Message-ID: <20260706094317.17032-5-freude@linux.ibm.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260706094317.17032-1-freude@linux.ibm.com> References: <20260706094317.17032-1-freude@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Authority-Analysis: v=2.4 cv=KsJ9H2WN c=1 sm=1 tr=0 ts=6a4b78ba cx=c_pps a=GFwsV6G8L6GxiO2Y/PsHdQ==:117 a=GFwsV6G8L6GxiO2Y/PsHdQ==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=iQ6ETzBq9ecOQQE5vZCe:22 a=VnNF1IyMAAAA:8 a=Oku5TADFz1XGWIWXx1gA:9 X-Proofpoint-Spam-Info: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfX7pu54Ggylae3 9MVxZekNcp+e2CNn2P5LqD04aQQF44Rj4+LlgroSHhuJvKYrqvao+Vd6q45mpR/yNbAyJBu2irU 9p0RYpiZ059uBtr6Wf5WAPnypmUAupc= X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfX5edvPeCF+wa8 w0phKJx+d9ve5DizyE8kTgbKk6F7zmwxfXBDac2HzW89Z4iSzkhJ2MCt88C8vl8OGiyozIbrFYu x4oK8cbjpx4f0IKxeMsWd/PnGngwWdYLlP6aw6CnvLF1rl0oDIOOeYwgivWPbyw2RC4iCOM/9RY y+mkv6eVj8Vjr/ASmwQdqon60xFMUJEtB86UN8EFLza3eVgjojk4rz2MUEhd9cALpBc7FCG9h9O hdCMDPyxACcLMmf3md6OMENfaXMdQ+jf6xZd0zK9+3Fp/T3560pyH7FIqwuCaEURlazQALtOkrD FIqRbfMNo3lDKTlhjwuadG4QOjdUK7rCCo5x4BOQ9N6a7ocNHoXt3ytt5KPeoUqXHzQRz8f/nha jOW7xQ5HdwpTZlMfxXmu6pLaHx2aXFil2mirjrnl7orIbBwpdbtyqdxdUDhWTf/PQJ6W5ZVztMr a8u5NICLRZKymPmRPZQ== X-Proofpoint-ORIG-GUID: q8um12y7RhdbNDV_TBF5CpVzDQP48Mtu X-Proofpoint-GUID: q8um12y7RhdbNDV_TBF5CpVzDQP48Mtu X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-06_01,2026-07-03_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 impostorscore=0 malwarescore=0 spamscore=0 adultscore=0 clxscore=1015 suspectscore=0 lowpriorityscore=0 priorityscore=1501 bulkscore=0 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607060094 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.156.1; envelope-from=freude@linux.ibm.com; helo=mx0a-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783331223952158500 Content-Type: text/plain; charset="utf-8" Add a new file cpacf_sha256.c which implements sha256. Add support for the sha256 subfuction for CPACF kimd and klmd. Tested-by: Holger Dengler Reviewed-by: Finn Callies Reviewed-by: Ilya Leoshkevich Signed-off-by: Harald Freudenberger --- target/s390x/gen-features.c | 2 + target/s390x/tcg/cpacf.h | 5 + target/s390x/tcg/cpacf_sha256.c | 228 +++++++++++++++++++++++++++++++ target/s390x/tcg/crypto_helper.c | 8 ++ target/s390x/tcg/meson.build | 1 + 5 files changed, 244 insertions(+) create mode 100644 target/s390x/tcg/cpacf_sha256.c diff --git a/target/s390x/gen-features.c b/target/s390x/gen-features.c index 8218e6470e..5cf5b92c37 100644 --- a/target/s390x/gen-features.c +++ b/target/s390x/gen-features.c @@ -916,7 +916,9 @@ static uint16_t qemu_V7_1[] =3D { */ static uint16_t qemu_MAX[] =3D { S390_FEAT_MSA_EXT_5, + S390_FEAT_KIMD_SHA_256, S390_FEAT_KIMD_SHA_512, + S390_FEAT_KLMD_SHA_256, S390_FEAT_KLMD_SHA_512, S390_FEAT_PRNO_TRNG, }; diff --git a/target/s390x/tcg/cpacf.h b/target/s390x/tcg/cpacf.h index 6de79a2f8f..d295b49699 100644 --- a/target/s390x/tcg/cpacf.h +++ b/target/s390x/tcg/cpacf.h @@ -223,6 +223,11 @@ #define CPACF_KDSA_PSIGN_ED25519 48 #define CPACF_KDSA_PSIGN_ED448 52 =20 +/* from cpacf_sha256.c */ +int cpacf_sha256(CPUS390XState *env, const int mmu_idx, uintptr_t ra, + uint64_t param_addr, uint64_t *message_reg, uint64_t *len= _reg, + uint32_t type); + /* from cpacf_sha512.c */ int cpacf_sha512(CPUS390XState *env, const int mmu_idx, uintptr_t ra, uint64_t param_addr, uint64_t *message_reg, uint64_t *len= _reg, diff --git a/target/s390x/tcg/cpacf_sha256.c b/target/s390x/tcg/cpacf_sha25= 6.c new file mode 100644 index 0000000000..48b2a602a0 --- /dev/null +++ b/target/s390x/tcg/cpacf_sha256.c @@ -0,0 +1,228 @@ +/* + * s390 cpacf sha256 + * + * Authors: + * Harald Freudenberger + * + * The sha256 implementation here is more or less a copy-and-paste + * from Jason A. Donenfeld's implementation of sha 512 with adaptions + * for sha 256. + * + * This work is licensed under the terms of the GNU GPL, version 2 or late= r. + * See the COPYING file in the top-level directory. + */ + +#include "qemu/osdep.h" +#include "s390x-internal.h" +#include "tcg_s390x.h" +#include "exec/helper-proto.h" +#include "accel/tcg/cpu-ldst-common.h" +#include "accel/tcg/cpu-mmu-index.h" +#include "target/s390x/tcg/cpacf.h" + +static uint32_t R(uint32_t x, int c) +{ + return (x >> c) | (x << (32 - c)); +} +static uint32_t Ch(uint32_t x, uint32_t y, uint32_t z) +{ + return (x & y) ^ (~x & z); +} +static uint32_t Maj(uint32_t x, uint32_t y, uint32_t z) +{ + return (x & y) ^ (x & z) ^ (y & z); +} +static uint32_t Sigma0(uint32_t x) +{ + return R(x, 2) ^ R(x, 13) ^ R(x, 22); +} +static uint32_t Sigma1(uint32_t x) +{ + return R(x, 6) ^ R(x, 11) ^ R(x, 25); +} +static uint32_t sigma0(uint32_t x) +{ + return R(x, 7) ^ R(x, 18) ^ (x >> 3); +} +static uint32_t sigma1(uint32_t x) +{ + return R(x, 17) ^ R(x, 19) ^ (x >> 10); +} + +static const uint32_t K[64] =3D { + 0x428a2f98, 0x71374491, 0xb5c0fbcf, 0xe9b5dba5, 0x3956c25b, 0x59f111f1, + 0x923f82a4, 0xab1c5ed5, 0xd807aa98, 0x12835b01, 0x243185be, 0x550c7dc3, + 0x72be5d74, 0x80deb1fe, 0x9bdc06a7, 0xc19bf174, 0xe49b69c1, 0xefbe4786, + 0x0fc19dc6, 0x240ca1cc, 0x2de92c6f, 0x4a7484aa, 0x5cb0a9dc, 0x76f988da, + 0x983e5152, 0xa831c66d, 0xb00327c8, 0xbf597fc7, 0xc6e00bf3, 0xd5a79147, + 0x06ca6351, 0x14292967, 0x27b70a85, 0x2e1b2138, 0x4d2c6dfc, 0x53380d13, + 0x650a7354, 0x766a0abb, 0x81c2c92e, 0x92722c85, 0xa2bfe8a1, 0xa81a664b, + 0xc24b8b70, 0xc76c51a3, 0xd192e819, 0xd6990624, 0xf40e3585, 0x106aa070, + 0x19a4c116, 0x1e376c08, 0x2748774c, 0x34b0bcb5, 0x391c0cb3, 0x4ed8aa4a, + 0x5b9cca4f, 0x682e6ff3, 0x748f82ee, 0x78a5636f, 0x84c87814, 0x8cc70208, + 0x90befffa, 0xa4506ceb, 0xbef9a3f7, 0xc67178f2, +}; + +/* a is icv/ocv, w is a single message block. w will get reused internally= . */ +static void sha256_bda(uint32_t a[8], uint32_t w[16]) +{ + uint32_t t, z[8], b[8]; + int i, j; + + memcpy(z, a, sizeof(z)); + for (i =3D 0; i < 64; i++) { + memcpy(b, a, sizeof(b)); + + t =3D a[7] + Sigma1(a[4]) + Ch(a[4], a[5], a[6]) + K[i] + w[i % 16= ]; + b[7] =3D t + Sigma0(a[0]) + Maj(a[0], a[1], a[2]); + b[3] +=3D t; + for (j =3D 0; j < 8; ++j) { + a[(j + 1) % 8] =3D b[j]; + } + if (i % 16 =3D=3D 15) { + for (j =3D 0; j < 16; ++j) { + w[j] +=3D w[(j + 9) % 16] + sigma0(w[(j + 1) % 16]) + + sigma1(w[(j + 14) % 16]); + } + } + } + + for (i =3D 0; i < 8; i++) { + a[i] +=3D z[i]; + } +} + +/* a is icv/ocv, w is a single message block that needs be32 conversion. */ +static void sha256_bda_be32(uint32_t a[8], uint32_t w[16]) +{ + uint32_t t[16]; + int i; + + for (i =3D 0; i < 16; i++) { + t[i] =3D be32_to_cpu(w[i]); + } + sha256_bda(a, t); +} + +static void sha256_read_icv(CPUS390XState *env, const int mmu_idx, + uint64_t addr, uint32_t a[8], uintptr_t ra) +{ + const MemOpIdx oi =3D make_memop_idx(MO_BE | MO_32 | MO_UNALN, mmu_idx= ); + + for (int i =3D 0; i < 8; i++, addr +=3D 4) { + a[i] =3D cpu_ldl_mmu(env, wrap_address(env, addr), oi, ra); + } +} + +static void sha256_write_ocv(CPUS390XState *env, const int mmu_idx, + uint64_t addr, uint32_t a[8], uintptr_t ra) +{ + const MemOpIdx oi =3D make_memop_idx(MO_BE | MO_32 | MO_UNALN, mmu_idx= ); + + for (int i =3D 0; i < 8; i++, addr +=3D 4) { + cpu_stl_mmu(env, wrap_address(env, addr), a[i], oi, ra); + } +} + +static void sha256_read_block(CPUS390XState *env, const int mmu_idx, + uint64_t addr, uint32_t a[16], uintptr_t ra) +{ + const MemOpIdx oi =3D make_memop_idx(MO_BE | MO_32 | MO_UNALN, mmu_idx= ); + + for (int i =3D 0; i < 16; i++, addr +=3D 4) { + a[i] =3D cpu_ldl_mmu(env, wrap_address(env, addr), oi, ra); + } +} + +static void sha256_read_mbl_be32(CPUS390XState *env, const int mmu_idx, + uint64_t addr, uint8_t a[8], uintptr_t ra) +{ + const MemOpIdx oi =3D make_memop_idx(MO_8, mmu_idx); + + for (int i =3D 0; i < 8; i++, addr +=3D 1) { + a[i] =3D cpu_ldb_mmu(env, wrap_address(env, addr), oi, ra); + } +} + +int cpacf_sha256(CPUS390XState *env, const int mmu_idx, uintptr_t ra, + uint64_t param_addr, uint64_t *message_reg, uint64_t *len= _reg, + uint32_t type) +{ + enum { MAX_BLOCKS_PER_RUN =3D 128 }; /* 128 * 64 =3D 8K */ + uint64_t len =3D *len_reg, processed =3D 0; + int i, message_reg_len =3D 64; + uint32_t a[8]; + + g_assert(type =3D=3D S390_FEAT_TYPE_KIMD || type =3D=3D S390_FEAT_TYPE= _KLMD); + + if (!(env->psw.mask & PSW_MASK_64)) { + len =3D (uint32_t)len; + message_reg_len =3D (env->psw.mask & PSW_MASK_32) ? 32 : 24; + } + + /* KIMD: length has to be properly aligned. */ + if (type =3D=3D S390_FEAT_TYPE_KIMD && !QEMU_IS_ALIGNED(len, 64)) { + tcg_s390_program_interrupt(env, PGM_SPECIFICATION, ra); + } + + sha256_read_icv(env, mmu_idx, param_addr, a, ra); + + /* Process full blocks first. */ + for (; len >=3D 64; len -=3D 64, processed +=3D 64) { + uint32_t w[16]; + + if (processed >=3D MAX_BLOCKS_PER_RUN * 64) { + break; + } + + sha256_read_block(env, mmu_idx, *message_reg + processed, w, ra); + sha256_bda(a, w); + } + + /* KLMD: Process partial/empty block last. */ + if (type =3D=3D S390_FEAT_TYPE_KLMD && len < 64) { + const MemOpIdx oi =3D make_memop_idx(MO_8, mmu_idx); + uint8_t x[64]; + + /* Read the remainder of the message byte-per-byte. */ + for (i =3D 0; i < len; i++) { + uint64_t addr =3D wrap_address(env, *message_reg + processed += i); + + x[i] =3D cpu_ldb_mmu(env, addr, oi, ra); + } + /* Pad the remainder with zero and set the top bit. */ + memset(x + len, 0, 64 - len); + x[len] =3D 0x80; + + /* + * Place the MBL either into this block (if there is space left), + * or use an additional one. + */ + if (len < 56) { + sha256_read_mbl_be32(env, mmu_idx, param_addr + 32, x + 56, ra= ); + } + sha256_bda_be32(a, (uint32_t *)x); + + if (len >=3D 56) { + memset(x, 0, 56); + sha256_read_mbl_be32(env, mmu_idx, param_addr + 32, x + 56, ra= ); + sha256_bda_be32(a, (uint32_t *)x); + } + + processed +=3D len; + len =3D 0; + } + + /* + * Modify memory after we read all inputs and modify registers only af= ter + * writing memory succeeded. + * + * TODO: if writing fails halfway through (e.g., when crossing page + * boundaries), we're in trouble. We'd need something like access_prep= are(). + */ + sha256_write_ocv(env, mmu_idx, param_addr, a, ra); + *message_reg =3D deposit64(*message_reg, 0, message_reg_len, + *message_reg + processed); + *len_reg -=3D processed; + return !len ? 0 : 3; +} diff --git a/target/s390x/tcg/crypto_helper.c b/target/s390x/tcg/crypto_hel= per.c index dba46baa0d..6c296f6731 100644 --- a/target/s390x/tcg/crypto_helper.c +++ b/target/s390x/tcg/crypto_helper.c @@ -53,6 +53,10 @@ static int cpacf_kimd(CPUS390XState *env, const int mmu_= idx, const uintptr_t ra, int rc =3D 0; =20 switch (fc) { + case CPACF_KIMD_SHA_256: + rc =3D cpacf_sha256(env, mmu_idx, ra, env->regs[1], &env->regs[r2], + &env->regs[r2 + 1], S390_FEAT_TYPE_KIMD); + break; case CPACF_KIMD_SHA_512: rc =3D cpacf_sha512(env, mmu_idx, ra, env->regs[1], &env->regs[r2], &env->regs[r2 + 1], S390_FEAT_TYPE_KIMD); @@ -70,6 +74,10 @@ static int cpacf_klmd(CPUS390XState *env, const int mmu_= idx, const uintptr_t ra, int rc =3D 0; =20 switch (fc) { + case CPACF_KLMD_SHA_256: + rc =3D cpacf_sha256(env, mmu_idx, ra, env->regs[1], &env->regs[r2], + &env->regs[r2 + 1], S390_FEAT_TYPE_KLMD); + break; case CPACF_KLMD_SHA_512: rc =3D cpacf_sha512(env, mmu_idx, ra, env->regs[1], &env->regs[r2], &env->regs[r2 + 1], S390_FEAT_TYPE_KLMD); diff --git a/target/s390x/tcg/meson.build b/target/s390x/tcg/meson.build index 54a87393a3..8ae8da9708 100644 --- a/target/s390x/tcg/meson.build +++ b/target/s390x/tcg/meson.build @@ -5,6 +5,7 @@ s390x_ss.add(when: 'CONFIG_TCG', if_true: files( )) s390x_common_ss.add(when: 'CONFIG_TCG', if_true: files( 'cc_helper.c', + 'cpacf_sha256.c', 'cpacf_sha512.c', 'crypto_helper.c', 'excp_helper.c', --=20 2.43.0 From nobody Sun Jul 26 10:59:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783331056; cv=none; d=zohomail.com; s=zohoarc; b=Ze71KFaczBvVI2q0UClqYoiNNWSnZbBLReVEGB1k2c6uLbwvP3FGJeO+vMXNMvqwEcfiui9NeyNqRg8fSeE3LsN9U+xg8Hz+iGbXcPCKvD2usj1DOBL4PfRtoPzoXCqbgNUdbYYQQiLUCLxTlf69vB03GC0ky0g5UVdpMzA33WY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783331056; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=6DbcMv132mHO4W0y3Ej3kNLdsmim3hr4A6Qu0lKcrJk=; b=NL1mwpvMV/+EfRqUplgiOUyHYLo+YjHGT4eXePaeC13/EMyegM8GRiS+kAv4z5+e7F9/lBZPKbcRIampqAX4IaH+23HDvcF3R3TSpFVnt3fZ1AIgoJe75zO2ezb9RGEoqZg6SkXT4C7ZdDH96eK8LAbm0PSLPEMDELHZy7HHZ68= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783331056247124.06272282777718; Mon, 6 Jul 2026 02:44:16 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wgfrW-0004GX-SI; Mon, 06 Jul 2026 05:43:38 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrR-0004Bf-AJ; Mon, 06 Jul 2026 05:43:33 -0400 Received: from mx0a-001b2d01.pphosted.com ([148.163.156.1]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrL-0003x5-HV; Mon, 06 Jul 2026 05:43:32 -0400 Received: from pps.filterd (m0360083.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 6669IFL93890034; Mon, 6 Jul 2026 09:43:22 GMT Received: from ppma22.wdc07v.mail.ibm.com (5c.69.3da9.ip4.static.sl-reverse.com [169.61.105.92]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f6sp3gsqr-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:22 +0000 (GMT) Received: from pps.filterd (ppma22.wdc07v.mail.ibm.com [127.0.0.1]) by ppma22.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 6669YaLe006337; Mon, 6 Jul 2026 09:43:21 GMT Received: from smtprelay04.fra02v.mail.ibm.com ([9.218.2.228]) by ppma22.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4f7cvvw578-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:21 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (smtpav07.fra02v.mail.ibm.com [10.20.54.106]) by smtprelay04.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 6669hHOK25363012 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Mon, 6 Jul 2026 09:43:17 GMT Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 303352004B; Mon, 6 Jul 2026 09:43:17 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 0021E20043; Mon, 6 Jul 2026 09:43:17 +0000 (GMT) Received: from funtu2.ibm.com (unknown [9.111.193.81]) by smtpav07.fra02v.mail.ibm.com (Postfix) with ESMTP; Mon, 6 Jul 2026 09:43:16 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=6DbcMv132mHO4W0y3 Ej3kNLdsmim3hr4A6Qu0lKcrJk=; b=O0VTDY07PtWaIqaY6E6GDjHrkJgTUKAD1 te6xcMnpYKCCMBr4boCqWMLBkXtovqwMxcvCSc625wqVRtM0T4QmKjp/oflKEzms Igz6lYZkjJF0FfEBGHtPKL4aQLya+5H+QK2PASCfziTR4cwMcXlO8Ly7XmFd8CIf ICZYiFNEnP7jTzfacnpcbgzLbvNqvSKTn5FGNsJqbuiyM8+Pxt6b3PQ1DzGmAKjs pMj6TXFE/eehAgRH2zH6M4xQdfI0l/QKOUMF0fOpJFWTL1JJzdqdtbTC+95EPgqR KRfNwUfgA+/owBw1cYnpoLsDaky6SmLGS79Z8iA0icyGmueF8dkiQ== From: Harald Freudenberger To: richard.henderson@linaro.org, iii@linux.ibm.com, david@kernel.org, thuth@redhat.com, berrange@redhat.com Cc: qemu-s390x@nongnu.org, qemu-devel@nongnu.org, linux-s390@vger.kernel.org, dengler@linux.ibm.com, borntraeger@linux.ibm.com, fcallies@linux.ibm.com, cohuck@redhat.com Subject: [PATCH v10 05/21] target/s390x: Support AES ECB for cpacf km instruction Date: Mon, 6 Jul 2026 11:42:58 +0200 Message-ID: <20260706094317.17032-6-freude@linux.ibm.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260706094317.17032-1-freude@linux.ibm.com> References: <20260706094317.17032-1-freude@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Authority-Analysis: v=2.4 cv=KsJ9H2WN c=1 sm=1 tr=0 ts=6a4b78ba cx=c_pps a=5BHTudwdYE3Te8bg5FgnPg==:117 a=5BHTudwdYE3Te8bg5FgnPg==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=iQ6ETzBq9ecOQQE5vZCe:22 a=VnNF1IyMAAAA:8 a=UeJqcyLMtA2A8E2_xXgA:9 X-Proofpoint-Spam-Info: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfX6b06vzv95T8n izcFbrx5fyszvJlfQn2iTNShcEGOua1GbhMRWqxc5XE96bx6rYzhoOMJNoPt0LqJAOLd3056Txz gnQBSYVdqnMst9WE4hdhsrKrRbrF6LE= X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfX9bxBkcMxukiZ JAZy4aWb9h+ICmSlrSNSGP5UR9hsHqxAsD3yo6bmYQ5n4mQfY4AxqtN4mEZHNx4Imn7E5s3Nk4c FG+7ZjO+8gRMpXEwQ5aGlNbLuxrm1zGOG7dUj1beQKmHMipuHKKeZh/Y4HLsqHrYjIkCA7ecsw0 qdirsRpHKZW0JCQmFq2rQ3JKlsvm7V98OHbAdsg2WV8dn/iGg42Rmswik1GYA3JmK6CYwgDzK6y iS8B11RNVMPwujyB7RHzcV5phQznAOwE8+eHQGE1nnwU0vUbWldjgNWxX3I7yYwnqIMZgv+0gWY UzPgYbcVZE3h1MvCg0VUR7kGy3aLV2ojyzeBsFXQyTo71kq5Lc0jETE4DE9lZOGowOerqExTMf1 UmuTfUrUBJzqVOpJcBh3CvfXgRHsP2Td1K83MCuC3BZg8WfbjP5s8XOlptIIk3LrEHq2SQnbH9d 6f81F1rgLsXzmkgsZOg== X-Proofpoint-ORIG-GUID: lrf46tvrn8HN2p0TEFovbD80CUNa-VNo X-Proofpoint-GUID: lrf46tvrn8HN2p0TEFovbD80CUNa-VNo X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-06_01,2026-07-03_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 impostorscore=0 malwarescore=0 spamscore=0 adultscore=0 clxscore=1015 suspectscore=0 lowpriorityscore=0 priorityscore=1501 bulkscore=0 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607060094 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.156.1; envelope-from=freude@linux.ibm.com; helo=mx0a-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783331057577158500 Content-Type: text/plain; charset="utf-8" Support the subfunctions CPACF_KM_AES_128, CPACF_KM_AES_192 and CPACF_KM_AES_256 for the cpacf km instruction. Tested-by: Holger Dengler Reviewed-by: Finn Callies Signed-off-by: Harald Freudenberger --- target/s390x/gen-features.c | 3 + target/s390x/tcg/cpacf.h | 6 ++ target/s390x/tcg/cpacf_aes.c | 112 +++++++++++++++++++++++++++++++ target/s390x/tcg/crypto_helper.c | 24 +++++++ target/s390x/tcg/meson.build | 1 + 5 files changed, 146 insertions(+) create mode 100644 target/s390x/tcg/cpacf_aes.c diff --git a/target/s390x/gen-features.c b/target/s390x/gen-features.c index 5cf5b92c37..a35d1fd2f9 100644 --- a/target/s390x/gen-features.c +++ b/target/s390x/gen-features.c @@ -921,6 +921,9 @@ static uint16_t qemu_MAX[] =3D { S390_FEAT_KLMD_SHA_256, S390_FEAT_KLMD_SHA_512, S390_FEAT_PRNO_TRNG, + S390_FEAT_KM_AES_128, + S390_FEAT_KM_AES_192, + S390_FEAT_KM_AES_256, }; =20 /****** END FEATURE DEFS ******/ diff --git a/target/s390x/tcg/cpacf.h b/target/s390x/tcg/cpacf.h index d295b49699..ca1850c976 100644 --- a/target/s390x/tcg/cpacf.h +++ b/target/s390x/tcg/cpacf.h @@ -233,4 +233,10 @@ int cpacf_sha512(CPUS390XState *env, const int mmu_idx= , uintptr_t ra, uint64_t param_addr, uint64_t *message_reg, uint64_t *len= _reg, uint32_t type); =20 +/* from cpacf_aes.c */ +int cpacf_aes_ecb(CPUS390XState *env, const int mmu_idx, uintptr_t ra, + uint64_t param_addr, uint64_t *dst_ptr_reg, + uint64_t *src_ptr_reg, uint64_t *src_len_reg, + uint32_t type, uint8_t fc, uint8_t mod); + #endif /* S390X_CPACF_H */ diff --git a/target/s390x/tcg/cpacf_aes.c b/target/s390x/tcg/cpacf_aes.c new file mode 100644 index 0000000000..3b0676b7d5 --- /dev/null +++ b/target/s390x/tcg/cpacf_aes.c @@ -0,0 +1,112 @@ +/* + * s390 cpacf aes + * + * Authors: + * Harald Freudenberger + * + * This work is licensed under the terms of the GNU GPL, version 2 or late= r. + * See the COPYING file in the top-level directory. + */ + +#include "qemu/osdep.h" +#include "s390x-internal.h" +#include "tcg_s390x.h" +#include "accel/tcg/cpu-ldst-common.h" +#include "accel/tcg/cpu-mmu-index.h" +#include "crypto/aes.h" +#include "target/s390x/tcg/cpacf.h" + +static void aes_read_block(CPUS390XState *env, const int mmu_idx, + uint64_t addr, uint8_t *a, uintptr_t ra) +{ + const MemOpIdx oi =3D make_memop_idx(MO_8, mmu_idx); + + for (int i =3D 0; i < AES_BLOCK_SIZE; i++, addr +=3D 1) { + uint64_t _addr =3D wrap_address(env, addr); + a[i] =3D cpu_ldb_mmu(env, _addr, oi, ra); + } +} + +static void aes_write_block(CPUS390XState *env, const int mmu_idx, + uint64_t addr, uint8_t *a, uintptr_t ra) +{ + const MemOpIdx oi =3D make_memop_idx(MO_8, mmu_idx); + + for (int i =3D 0; i < AES_BLOCK_SIZE; i++, addr +=3D 1) { + uint64_t _addr =3D wrap_address(env, addr); + cpu_stb_mmu(env, _addr, a[i], oi, ra); + } +} + +int cpacf_aes_ecb(CPUS390XState *env, const int mmu_idx, uintptr_t ra, + uint64_t param_addr, uint64_t *dst_ptr_reg, + uint64_t *src_ptr_reg, uint64_t *src_len_reg, + uint32_t type, uint8_t fc, uint8_t mod) +{ + enum { MAX_BLOCKS_PER_RUN =3D 8192 / AES_BLOCK_SIZE }; + const MemOpIdx oi =3D make_memop_idx(MO_8, mmu_idx); + uint8_t in[AES_BLOCK_SIZE], out[AES_BLOCK_SIZE]; + uint64_t addr, len =3D *src_len_reg, done =3D 0; + int i, keysize, addr_reg_size =3D 64; + uint8_t key[32]; + AES_KEY exkey; + + g_assert(type =3D=3D S390_FEAT_TYPE_KM); + switch (fc) { + case CPACF_KM_AES_128: + keysize =3D 16; + break; + case CPACF_KM_AES_192: + keysize =3D 24; + break; + case CPACF_KM_AES_256: + keysize =3D 32; + break; + default: + g_assert_not_reached(); + } + + if (!(env->psw.mask & PSW_MASK_64)) { + len =3D (uint32_t)len; + addr_reg_size =3D (env->psw.mask & PSW_MASK_32) ? 32 : 24; + } + + /* length has to be properly aligned. */ + if (!QEMU_IS_ALIGNED(len, AES_BLOCK_SIZE)) { + tcg_s390_program_interrupt(env, PGM_SPECIFICATION, ra); + } + + /* fetch key from param block */ + for (i =3D 0; i < keysize; i++) { + addr =3D wrap_address(env, param_addr + i); + key[i] =3D cpu_ldb_mmu(env, addr, oi, ra); + } + + /* expand key */ + if (mod) { + AES_set_decrypt_key(key, keysize * 8, &exkey); + } else { + AES_set_encrypt_key(key, keysize * 8, &exkey); + } + + /* process up to MAX_BLOCKS_PER_RUN aes blocks */ + for (i =3D 0; i < MAX_BLOCKS_PER_RUN && len >=3D AES_BLOCK_SIZE; i++) { + aes_read_block(env, mmu_idx, *src_ptr_reg + done, in, ra); + if (mod) { + AES_decrypt(in, out, &exkey); + } else { + AES_encrypt(in, out, &exkey); + } + aes_write_block(env, mmu_idx, *dst_ptr_reg + done, out, ra); + len -=3D AES_BLOCK_SIZE; + done +=3D AES_BLOCK_SIZE; + } + + *src_ptr_reg =3D deposit64(*src_ptr_reg, 0, addr_reg_size, + *src_ptr_reg + done); + *dst_ptr_reg =3D deposit64(*dst_ptr_reg, 0, addr_reg_size, + *dst_ptr_reg + done); + *src_len_reg -=3D done; + + return !len ? 0 : 3; +} diff --git a/target/s390x/tcg/crypto_helper.c b/target/s390x/tcg/crypto_hel= per.c index 6c296f6731..3907b9748c 100644 --- a/target/s390x/tcg/crypto_helper.c +++ b/target/s390x/tcg/crypto_helper.c @@ -89,6 +89,27 @@ static int cpacf_klmd(CPUS390XState *env, const int mmu_= idx, const uintptr_t ra, return rc; } =20 +static int cpacf_km(CPUS390XState *env, const int mmu_idx, uintptr_t ra, + uint32_t r1, uint32_t r2, uint32_t r3, + uint8_t fc, uint8_t mod) +{ + int rc =3D 0; + + switch (fc) { + case CPACF_KM_AES_128: + case CPACF_KM_AES_192: + case CPACF_KM_AES_256: + rc =3D cpacf_aes_ecb(env, mmu_idx, ra, env->regs[1], + &env->regs[r1], &env->regs[r2], &env->regs[r2 += 1], + S390_FEAT_TYPE_KM, fc, mod); + break; + default: + tcg_s390_program_interrupt(env, PGM_SPECIFICATION, ra); + } + + return rc; +} + static int cpacf_ppno(CPUS390XState *env, const int mmu_idx, uintptr_t ra, uint32_t r1, uint32_t r2, uint32_t r3, uint8_t fc) { @@ -153,6 +174,9 @@ uint32_t HELPER(msa)(CPUS390XState *env, uint32_t r1, u= int32_t r2, uint32_t r3, case S390_FEAT_TYPE_KLMD: rc =3D cpacf_klmd(env, mmu_idx, ra, r1, r2, r3, fc); break; + case S390_FEAT_TYPE_KM: + rc =3D cpacf_km(env, mmu_idx, ra, r1, r2, r3, fc, mod); + break; case S390_FEAT_TYPE_PPNO: rc =3D cpacf_ppno(env, mmu_idx, ra, r1, r2, r3, fc); break; diff --git a/target/s390x/tcg/meson.build b/target/s390x/tcg/meson.build index 8ae8da9708..6f2e75764b 100644 --- a/target/s390x/tcg/meson.build +++ b/target/s390x/tcg/meson.build @@ -5,6 +5,7 @@ s390x_ss.add(when: 'CONFIG_TCG', if_true: files( )) s390x_common_ss.add(when: 'CONFIG_TCG', if_true: files( 'cc_helper.c', + 'cpacf_aes.c', 'cpacf_sha256.c', 'cpacf_sha512.c', 'crypto_helper.c', --=20 2.43.0 From nobody Sun Jul 26 10:59:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783331159; cv=none; d=zohomail.com; s=zohoarc; b=J5MQOFFJE0lU9OgtjTw/N6eDfQeFYIoY/3/uQcoTBEteD808/BGcv/oHbKJ4N23g1LGiGuEqJcRvOrtSsw8JdUgchSKw8gaCOXlY7wdAXc5FDyH9uDX2FvcoOdoNr2I1PSke7zOLbMIGGwzpoobDzAGj7azKiiuFlUr7sU2F4LA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783331159; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=ShPhbJCxXTEhrQ1Ddu2AwxjX3mXKCDAHoOI7s3tiXTI=; b=hOEmDvBaXKL6EuM7o4pxcS9dvUUPMkxUw/2GzeyD3BrMgbs73FuOg6vbcBlC3zShecK4JzvxFF/gkiTDtnUz3OCTPfw7C0ytSqzH8TLAEamAiPwikG/21gjJGxFYmQEdkYF+tpakDjpSTmlb8NnR8LTPnWaSt3SWo3aH2jQNPtM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783331159196524.6467604890503; Mon, 6 Jul 2026 02:45:59 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wgfrU-0004DW-2W; Mon, 06 Jul 2026 05:43:36 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrP-0004BC-G1; Mon, 06 Jul 2026 05:43:33 -0400 Received: from mx0b-001b2d01.pphosted.com ([148.163.158.5]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrJ-0003wh-V7; Mon, 06 Jul 2026 05:43:28 -0400 Received: from pps.filterd (m0360072.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 6669IN2K3133959; Mon, 6 Jul 2026 09:43:22 GMT Received: from ppma23.wdc07v.mail.ibm.com (5d.69.3da9.ip4.static.sl-reverse.com [169.61.105.93]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f6stsh919-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:21 +0000 (GMT) Received: from pps.filterd (ppma23.wdc07v.mail.ibm.com [127.0.0.1]) by ppma23.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 6669YiCr005938; Mon, 6 Jul 2026 09:43:21 GMT Received: from smtprelay04.fra02v.mail.ibm.com ([9.218.2.228]) by ppma23.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4f7e0h4w44-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:21 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (smtpav07.fra02v.mail.ibm.com [10.20.54.106]) by smtprelay04.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 6669hHLv23397074 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Mon, 6 Jul 2026 09:43:17 GMT Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 5AE9620043; Mon, 6 Jul 2026 09:43:17 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 34D3020040; Mon, 6 Jul 2026 09:43:17 +0000 (GMT) Received: from funtu2.ibm.com (unknown [9.111.193.81]) by smtpav07.fra02v.mail.ibm.com (Postfix) with ESMTP; Mon, 6 Jul 2026 09:43:17 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=ShPhbJCxXTEhrQ1Dd u2AwxjX3mXKCDAHoOI7s3tiXTI=; b=faSLWwFVbABDXbVVb5LXvgbk60IZXJKFi nm/t+Hvy4L7V56ns77sWLTdyg03WOd9MR4WZNkbvenC7xYrtudHRO3VmUWx9yeaI 9ePqpxy906p444D26yRmhBxfGQZAY77d4Eh5Pg8Q4yJyN0KexhO9T+nWop+8xHZO Rwnl2N7sgfSD1LCsnMLkEhbtmXmPs3wbbR9AacOQx1SST4ctPNiro8uwvRubdigr S1XFgb1eIg4UHEtkeAKOIbgNX8hAxGpMtCv7ZOHR8kYP5FL/3dP/wMCcPPVZhe2l B1VSQBYmCHrkJlcQ8ZAWEho7OM+d0p+vFFIrSf1FGsALQjlVK/oFA== From: Harald Freudenberger To: richard.henderson@linaro.org, iii@linux.ibm.com, david@kernel.org, thuth@redhat.com, berrange@redhat.com Cc: qemu-s390x@nongnu.org, qemu-devel@nongnu.org, linux-s390@vger.kernel.org, dengler@linux.ibm.com, borntraeger@linux.ibm.com, fcallies@linux.ibm.com, cohuck@redhat.com Subject: [PATCH v10 06/21] target/s390x: Support AES CBC for cpacf kmc instruction Date: Mon, 6 Jul 2026 11:42:59 +0200 Message-ID: <20260706094317.17032-7-freude@linux.ibm.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260706094317.17032-1-freude@linux.ibm.com> References: <20260706094317.17032-1-freude@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-ORIG-GUID: 6mNElxp6LU_-QsTo-AUQb0eMV_64qeij X-Proofpoint-Spam-Info: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfX3uxKHfgFC2Qx HrMs+rMa/dRLZQIEKOuZbNMhUErXIDal3E1B21GhTFgYAKePj2AAc/B94PUceMnRiCZNmBJeKnt AHf2zAboeQDuM+qjBpNH5uJoV9EPsFY= X-Authority-Analysis: v=2.4 cv=DKW/JSNb c=1 sm=1 tr=0 ts=6a4b78ba cx=c_pps a=3Bg1Hr4SwmMryq2xdFQyZA==:117 a=3Bg1Hr4SwmMryq2xdFQyZA==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=RzCfie-kr_QcCd8fBx8p:22 a=VnNF1IyMAAAA:8 a=4s_zGP7M7QCs5o7xjogA:9 X-Proofpoint-GUID: 6mNElxp6LU_-QsTo-AUQb0eMV_64qeij X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfX9pYlTSpwkdT6 EmzLo+Xo8qadGMaf0mYXvDcVGA4OXNPBUpxKpNO5uY0YkvxmiiTd0S+N4ShC3oJmDkU9PtHTsVE gVgwfzS7PSxD2frdl+2luYnB0GFi4VfK+Vcvc7O3yZfn+KdAGyiALFzRyyQm2f0sIsJjYrC80yg XaZVgMF+PT1eFeeRoNeEDga7M2KIFdp8hLej6u+W9vHDBdWCAip+BLNxtKfcGiL+IS2zv0dfI4k s5aCWmanHipm8JTN6JvNwpoXWPMQ7fUitFhVAv1i05uk0Erolpw3AUufBur5Ee4+C/twgbPCITU XHgtv9EHMMSYO/CQNVB9gZqnDVCqIEDzdQ9KSs6AvC1V2E5vuBMRYdzVfMXAEAPZwrG3tSNu148 SaVsHcIJajlWVJh8b1UtIl5zS5LoGgtppgMzFKwOrJjxpDwkyXeIf8LV/XQ0s6qVO8SB9srqrMn BnSXSQv0ocp8VmARvCA== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-06_01,2026-07-03_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 spamscore=0 bulkscore=0 clxscore=1015 phishscore=0 impostorscore=0 priorityscore=1501 adultscore=0 lowpriorityscore=0 suspectscore=0 malwarescore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607060094 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.158.5; envelope-from=freude@linux.ibm.com; helo=mx0b-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783331159576158500 Content-Type: text/plain; charset="utf-8" Support the subfunctions CPACF_KMC_AES_128, CPACF_KMC_AES_192 and CPACF_KMC_AES_256 for the cpacf kmc instruction. Tested-by: Holger Dengler Reviewed-by: Finn Callies Reviewed-by: Ilya Leoshkevich Signed-off-by: Harald Freudenberger --- target/s390x/gen-features.c | 3 + target/s390x/tcg/cpacf.h | 4 ++ target/s390x/tcg/cpacf_aes.c | 103 +++++++++++++++++++++++++++++++ target/s390x/tcg/crypto_helper.c | 24 +++++++ 4 files changed, 134 insertions(+) diff --git a/target/s390x/gen-features.c b/target/s390x/gen-features.c index a35d1fd2f9..9c0c0b229f 100644 --- a/target/s390x/gen-features.c +++ b/target/s390x/gen-features.c @@ -924,6 +924,9 @@ static uint16_t qemu_MAX[] =3D { S390_FEAT_KM_AES_128, S390_FEAT_KM_AES_192, S390_FEAT_KM_AES_256, + S390_FEAT_KMC_AES_128, + S390_FEAT_KMC_AES_192, + S390_FEAT_KMC_AES_256, }; =20 /****** END FEATURE DEFS ******/ diff --git a/target/s390x/tcg/cpacf.h b/target/s390x/tcg/cpacf.h index ca1850c976..572c588d38 100644 --- a/target/s390x/tcg/cpacf.h +++ b/target/s390x/tcg/cpacf.h @@ -238,5 +238,9 @@ int cpacf_aes_ecb(CPUS390XState *env, const int mmu_idx= , uintptr_t ra, uint64_t param_addr, uint64_t *dst_ptr_reg, uint64_t *src_ptr_reg, uint64_t *src_len_reg, uint32_t type, uint8_t fc, uint8_t mod); +int cpacf_aes_cbc(CPUS390XState *env, const int mmu_idx, uintptr_t ra, + uint64_t param_addr, uint64_t *dst_ptr_reg, + uint64_t *src_ptr_reg, uint64_t *src_len_reg, + uint32_t type, uint8_t fc, uint8_t mod); =20 #endif /* S390X_CPACF_H */ diff --git a/target/s390x/tcg/cpacf_aes.c b/target/s390x/tcg/cpacf_aes.c index 3b0676b7d5..add91876c6 100644 --- a/target/s390x/tcg/cpacf_aes.c +++ b/target/s390x/tcg/cpacf_aes.c @@ -110,3 +110,106 @@ int cpacf_aes_ecb(CPUS390XState *env, const int mmu_i= dx, uintptr_t ra, =20 return !len ? 0 : 3; } + +static void aes_xor(const uint8_t *src1, const uint8_t *src2, uint8_t *dst) +{ + for (int i =3D 0; i < AES_BLOCK_SIZE; i++) { + dst[i] =3D src1[i] ^ src2[i]; + } +} + +int cpacf_aes_cbc(CPUS390XState *env, const int mmu_idx, uintptr_t ra, + uint64_t param_addr, uint64_t *dst_ptr_reg, + uint64_t *src_ptr_reg, uint64_t *src_len_reg, + uint32_t type, uint8_t fc, uint8_t mod) +{ + enum { MAX_BLOCKS_PER_RUN =3D 8192 / AES_BLOCK_SIZE }; + uint8_t in[AES_BLOCK_SIZE], out[AES_BLOCK_SIZE], buf[AES_BLOCK_SIZE]; + const MemOpIdx oi =3D make_memop_idx(MO_8, mmu_idx); + uint64_t addr, len =3D *src_len_reg, done =3D 0; + int i, keysize, addr_reg_size =3D 64; + uint8_t key[32], iv[AES_BLOCK_SIZE]; + AES_KEY exkey; + + g_assert(type =3D=3D S390_FEAT_TYPE_KMC); + + switch (fc) { + case CPACF_KMC_AES_128: + keysize =3D 16; + break; + case CPACF_KMC_AES_192: + keysize =3D 24; + break; + case CPACF_KMC_AES_256: + keysize =3D 32; + break; + default: + g_assert_not_reached(); + } + + if (!(env->psw.mask & PSW_MASK_64)) { + len =3D (uint32_t)len; + addr_reg_size =3D (env->psw.mask & PSW_MASK_32) ? 32 : 24; + } + + /* length has to be properly aligned. */ + if (!QEMU_IS_ALIGNED(len, AES_BLOCK_SIZE)) { + tcg_s390_program_interrupt(env, PGM_SPECIFICATION, ra); + } + + /* fetch iv from param block */ + for (i =3D 0; i < AES_BLOCK_SIZE; i++) { + addr =3D wrap_address(env, param_addr + i); + iv[i] =3D cpu_ldb_mmu(env, addr, oi, ra); + } + + /* fetch key from param block */ + for (i =3D 0; i < keysize; i++) { + addr =3D wrap_address(env, param_addr + AES_BLOCK_SIZE + i); + key[i] =3D cpu_ldb_mmu(env, addr, oi, ra); + } + + /* expand key */ + if (mod) { + AES_set_decrypt_key(key, keysize * 8, &exkey); + } else { + AES_set_encrypt_key(key, keysize * 8, &exkey); + } + + /* process up to MAX_BLOCKS_PER_RUN aes blocks */ + for (i =3D 0; i < MAX_BLOCKS_PER_RUN && len >=3D AES_BLOCK_SIZE; i++) { + aes_read_block(env, mmu_idx, *src_ptr_reg + done, in, ra); + if (mod) { + /* decrypt in =3D> buf */ + AES_decrypt(in, buf, &exkey); + /* buf xor iv =3D> out */ + aes_xor(buf, iv, out); + /* prep iv for next round */ + memcpy(iv, in, AES_BLOCK_SIZE); + } else { + /* in xor iv =3D> buf */ + aes_xor(in, iv, buf); + /* encrypt buf =3D> out */ + AES_encrypt(buf, out, &exkey); + /* prep iv for next round */ + memcpy(iv, out, AES_BLOCK_SIZE); + } + aes_write_block(env, mmu_idx, *dst_ptr_reg + done, out, ra); + len -=3D AES_BLOCK_SIZE; + done +=3D AES_BLOCK_SIZE; + } + + /* update iv in param block */ + for (i =3D 0; i < AES_BLOCK_SIZE; i++) { + addr =3D wrap_address(env, param_addr + i); + cpu_stb_mmu(env, addr, iv[i], oi, ra); + } + + *src_ptr_reg =3D deposit64(*src_ptr_reg, 0, addr_reg_size, + *src_ptr_reg + done); + *dst_ptr_reg =3D deposit64(*dst_ptr_reg, 0, addr_reg_size, + *dst_ptr_reg + done); + *src_len_reg -=3D done; + + return !len ? 0 : 3; +} diff --git a/target/s390x/tcg/crypto_helper.c b/target/s390x/tcg/crypto_hel= per.c index 3907b9748c..1fe1d7157b 100644 --- a/target/s390x/tcg/crypto_helper.c +++ b/target/s390x/tcg/crypto_helper.c @@ -110,6 +110,27 @@ static int cpacf_km(CPUS390XState *env, const int mmu_= idx, uintptr_t ra, return rc; } =20 +static int cpacf_kmc(CPUS390XState *env, const int mmu_idx, uintptr_t ra, + uint32_t r1, uint32_t r2, uint32_t r3, + uint8_t fc, uint8_t mod) +{ + int rc =3D 0; + + switch (fc) { + case CPACF_KMC_AES_128: + case CPACF_KMC_AES_192: + case CPACF_KMC_AES_256: + rc =3D cpacf_aes_cbc(env, mmu_idx, ra, env->regs[1], + &env->regs[r1], &env->regs[r2], &env->regs[r2 += 1], + S390_FEAT_TYPE_KMC, fc, mod); + break; + default: + tcg_s390_program_interrupt(env, PGM_SPECIFICATION, ra); + } + + return rc; +} + static int cpacf_ppno(CPUS390XState *env, const int mmu_idx, uintptr_t ra, uint32_t r1, uint32_t r2, uint32_t r3, uint8_t fc) { @@ -177,6 +198,9 @@ uint32_t HELPER(msa)(CPUS390XState *env, uint32_t r1, u= int32_t r2, uint32_t r3, case S390_FEAT_TYPE_KM: rc =3D cpacf_km(env, mmu_idx, ra, r1, r2, r3, fc, mod); break; + case S390_FEAT_TYPE_KMC: + rc =3D cpacf_kmc(env, mmu_idx, ra, r1, r2, r3, fc, mod); + break; case S390_FEAT_TYPE_PPNO: rc =3D cpacf_ppno(env, mmu_idx, ra, r1, r2, r3, fc); break; --=20 2.43.0 From nobody Sun Jul 26 10:59:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783331156; cv=none; d=zohomail.com; s=zohoarc; b=d2w3S1+IOz5efzvIpFgziKnXu8YuPcbR+ILYDckhcNR7DzdjVoP8x9drXhDhPEWYnaMpwrFIsDa5wobPUybun3bcD9OrrLGSQU97tcHx1qR1QStq0RU5tikCuMNc+85o0EVBVdxn4ZdDwu++C5wY+n/4UWj6R8eGG/CK+i/8IMo= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783331156; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=YNbbQWmzKx0TfEgnZHrAiTORIx5fuxK+HrjJzUlXayU=; b=NBOR5LGxZRv2zkg1zf0fGpDDnRL3cs9wyhmuDWhlbxbRGlgsfuQP5S5ShsKIC7ezMyAiFpPJyFeq5XP/b9+vZ2+C+cH2RYUJ0o/jgAzG8rBb2Z7y9PIYe0RKO+NVjGJkNYkQ5tfUUBao0LkDDs43Kv4h7OkjdNxMjHguN7gDFPA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783331156306954.2050132425878; Mon, 6 Jul 2026 02:45:56 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wgfrW-0004GW-QH; Mon, 06 Jul 2026 05:43:38 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrR-0004Bh-Ah; Mon, 06 Jul 2026 05:43:33 -0400 Received: from mx0b-001b2d01.pphosted.com ([148.163.158.5]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrL-0003x1-IF; Mon, 06 Jul 2026 05:43:32 -0400 Received: from pps.filterd (m0356516.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 6669IK2v3826396; Mon, 6 Jul 2026 09:43:22 GMT Received: from ppma13.dal12v.mail.ibm.com (dd.9e.1632.ip4.static.sl-reverse.com [50.22.158.221]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f6qkn8vjb-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:22 +0000 (GMT) Received: from pps.filterd (ppma13.dal12v.mail.ibm.com [127.0.0.1]) by ppma13.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 6669YaAv021100; Mon, 6 Jul 2026 09:43:21 GMT Received: from smtprelay04.fra02v.mail.ibm.com ([9.218.2.228]) by ppma13.dal12v.mail.ibm.com (PPS) with ESMTPS id 4f7eqfvs1s-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:21 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (smtpav07.fra02v.mail.ibm.com [10.20.54.106]) by smtprelay04.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 6669hHBw23397076 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Mon, 6 Jul 2026 09:43:17 GMT Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 87D6D20040; Mon, 6 Jul 2026 09:43:17 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 5FA6E2004E; Mon, 6 Jul 2026 09:43:17 +0000 (GMT) Received: from funtu2.ibm.com (unknown [9.111.193.81]) by smtpav07.fra02v.mail.ibm.com (Postfix) with ESMTP; Mon, 6 Jul 2026 09:43:17 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=YNbbQWmzKx0TfEgnZ HrAiTORIx5fuxK+HrjJzUlXayU=; b=D6YZm0EicS0buRC7Ije8a+qHsQV0+2IVQ ZNIVQQDHzUOzAnLYHqRbs15PUERmDhjvGJsuDJ6qpmtYwZzb8WV2Y/J0GzGr0wSb CwG1DHoPX0cHGPSScxo3UlOmzbgvCE6D8loKXX2pzRzclol4ZEUoYBrS2An4/vV1 T8/6EDg1XkkxM8+MOCpyFANvCVVLKWvz0zP48cbd9RGxZvPA7KPz2IhSfTxn1sN6 xZDiKYk8fQimxRapWo07VJsPiNWp8Q8lcXcLWE4+ewElk91Dpaq2XNacyhno/5qA /qPnXQGb8M0AdqGhtZ4gLvT9zgojSjlxvaL+Vc6whYIrudwJXVPlA== From: Harald Freudenberger To: richard.henderson@linaro.org, iii@linux.ibm.com, david@kernel.org, thuth@redhat.com, berrange@redhat.com Cc: qemu-s390x@nongnu.org, qemu-devel@nongnu.org, linux-s390@vger.kernel.org, dengler@linux.ibm.com, borntraeger@linux.ibm.com, fcallies@linux.ibm.com, cohuck@redhat.com Subject: [PATCH v10 07/21] target/s390x: Support AES CTR for cpacf kmctr instruction Date: Mon, 6 Jul 2026 11:43:00 +0200 Message-ID: <20260706094317.17032-8-freude@linux.ibm.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260706094317.17032-1-freude@linux.ibm.com> References: <20260706094317.17032-1-freude@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Authority-Analysis: v=2.4 cv=Q/XiJY2a c=1 sm=1 tr=0 ts=6a4b78ba cx=c_pps a=AfN7/Ok6k8XGzOShvHwTGQ==:117 a=AfN7/Ok6k8XGzOShvHwTGQ==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=Y2IxJ9c9Rs8Kov3niI8_:22 a=VnNF1IyMAAAA:8 a=LQnWXxm1RwZjr7XDrSkA:9 X-Proofpoint-GUID: 9fvMJDhV_VyQA8K3iLC5CBGqLGhaude2 X-Proofpoint-ORIG-GUID: 9fvMJDhV_VyQA8K3iLC5CBGqLGhaude2 X-Proofpoint-Spam-Info: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfX5FgCs1vZho3m 1rJ7Qo0jlnZnGnq9+HNMnCTE6aKsJwVbDJ4hlQ/g/kuBROkFC30n+sr9KW52tSMy9cEv3X4A9gH fZ4KeZHpr+Vg+ObN8ANsWRhH+veDrxk= X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfXwpZmHI/KoJ3b zLgaAHUqh9fBRaqHA5r/IvVA6BBU+Um0HDCsW8oErOkU973VM3GtzVCe8Dtc2pEQs0qw2gzAeZ4 j2hiWYtHSJKfL/xe2gvRUxijB+0R3Ttr4vqJBnjE7vCANiS2AuG9IMAiu/b+z54RzBzmyfRZf1B VDro1U2lNPRBqXCdK0LZPW/ACQwiMRS9YDNqSmplQ8UDp3Xkjxbw8vIodzAPNCmsXwPtIPV/y+6 Qy/b0dZObi9Am+rXWuzpdrMNNQjsRwzBWFhWdK1aWqPUWJ4RwjkJoWyIRPhYLy38JkUN/IGqyoQ +kYpl6MfnUz48CD1cL6ZTADFb2H/eb4C0ibzKAUv5KHYbK+xPiZsfpGT7knsx2gNu4Hj7fwE3dC uZk2OZEaLhoqTNu7AYWeBO/tbosaKMe1VLPYWKu02tQKC34KGnB/8SqkKE/ZHirJIhQ7NJ7pMwb gDiViE6p7UxiTr+2vGQ== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-06_01,2026-07-03_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 adultscore=0 impostorscore=0 spamscore=0 phishscore=0 priorityscore=1501 bulkscore=0 clxscore=1015 lowpriorityscore=0 suspectscore=0 malwarescore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607060094 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.158.5; envelope-from=freude@linux.ibm.com; helo=mx0b-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783331157563158500 Content-Type: text/plain; charset="utf-8" Support the subfunctions CPACF_KMCTR_AES_128, CPACF_KMCTR_AES_192 and CPACF_KMCTR_AES_256 for the cpacf kmctr instruction. Reviewed-by: Finn Callies Reviewed-by: Ilya Leoshkevich Signed-off-by: Harald Freudenberger --- target/s390x/gen-features.c | 3 ++ target/s390x/tcg/cpacf.h | 5 +++ target/s390x/tcg/cpacf_aes.c | 77 ++++++++++++++++++++++++++++++++ target/s390x/tcg/crypto_helper.c | 24 ++++++++++ 4 files changed, 109 insertions(+) diff --git a/target/s390x/gen-features.c b/target/s390x/gen-features.c index 9c0c0b229f..59c2a47539 100644 --- a/target/s390x/gen-features.c +++ b/target/s390x/gen-features.c @@ -927,6 +927,9 @@ static uint16_t qemu_MAX[] =3D { S390_FEAT_KMC_AES_128, S390_FEAT_KMC_AES_192, S390_FEAT_KMC_AES_256, + S390_FEAT_KMCTR_AES_128, + S390_FEAT_KMCTR_AES_192, + S390_FEAT_KMCTR_AES_256, }; =20 /****** END FEATURE DEFS ******/ diff --git a/target/s390x/tcg/cpacf.h b/target/s390x/tcg/cpacf.h index 572c588d38..3707308661 100644 --- a/target/s390x/tcg/cpacf.h +++ b/target/s390x/tcg/cpacf.h @@ -242,5 +242,10 @@ int cpacf_aes_cbc(CPUS390XState *env, const int mmu_id= x, uintptr_t ra, uint64_t param_addr, uint64_t *dst_ptr_reg, uint64_t *src_ptr_reg, uint64_t *src_len_reg, uint32_t type, uint8_t fc, uint8_t mod); +int cpacf_aes_ctr(CPUS390XState *env, const int mmu_idx, uintptr_t ra, + uint64_t param_addr, uint64_t *dst_ptr_reg, + uint64_t *src_ptr_reg, uint64_t *src_len_reg, + uint64_t *ctr_ptr_reg, uint32_t type, + uint8_t fc, uint8_t mod); =20 #endif /* S390X_CPACF_H */ diff --git a/target/s390x/tcg/cpacf_aes.c b/target/s390x/tcg/cpacf_aes.c index add91876c6..3d6aa19df2 100644 --- a/target/s390x/tcg/cpacf_aes.c +++ b/target/s390x/tcg/cpacf_aes.c @@ -213,3 +213,80 @@ int cpacf_aes_cbc(CPUS390XState *env, const int mmu_id= x, uintptr_t ra, =20 return !len ? 0 : 3; } + +int cpacf_aes_ctr(CPUS390XState *env, const int mmu_idx, uintptr_t ra, + uint64_t param_addr, uint64_t *dst_ptr_reg, + uint64_t *src_ptr_reg, uint64_t *src_len_reg, + uint64_t *ctr_ptr_reg, uint32_t type, + uint8_t fc, uint8_t mod) +{ + enum { MAX_BLOCKS_PER_RUN =3D 8192 / AES_BLOCK_SIZE }; + const MemOpIdx oi =3D make_memop_idx(MO_8, mmu_idx); + uint8_t ctr[AES_BLOCK_SIZE], buf[AES_BLOCK_SIZE]; + uint8_t in[AES_BLOCK_SIZE], out[AES_BLOCK_SIZE]; + uint64_t addr, len =3D *src_len_reg, done =3D 0; + int i, keysize, addr_reg_size =3D 64; + uint8_t key[32]; + AES_KEY exkey; + + g_assert(type =3D=3D S390_FEAT_TYPE_KMCTR); + + switch (fc) { + case CPACF_KMCTR_AES_128: + keysize =3D 16; + break; + case CPACF_KMCTR_AES_192: + keysize =3D 24; + break; + case CPACF_KMCTR_AES_256: + keysize =3D 32; + break; + default: + g_assert_not_reached(); + } + + if (!(env->psw.mask & PSW_MASK_64)) { + len =3D (uint32_t)len; + addr_reg_size =3D (env->psw.mask & PSW_MASK_32) ? 32 : 24; + } + + /* length has to be properly aligned. */ + if (!QEMU_IS_ALIGNED(len, AES_BLOCK_SIZE)) { + tcg_s390_program_interrupt(env, PGM_SPECIFICATION, ra); + } + + /* fetch key from param block */ + for (i =3D 0; i < keysize; i++) { + addr =3D wrap_address(env, param_addr + i); + key[i] =3D cpu_ldb_mmu(env, addr, oi, ra); + } + + /* expand key */ + AES_set_encrypt_key(key, keysize * 8, &exkey); + + /* process up to MAX_BLOCKS_PER_RUN aes blocks */ + for (i =3D 0; i < MAX_BLOCKS_PER_RUN && len >=3D AES_BLOCK_SIZE; i++) { + /* read in nonce/ctr =3D> ctr */ + aes_read_block(env, mmu_idx, *ctr_ptr_reg + done, ctr, ra); + /* encrypt ctr =3D> buf */ + AES_encrypt(ctr, buf, &exkey); + /* read in one block of input data =3D> in */ + aes_read_block(env, mmu_idx, *src_ptr_reg + done, in, ra); + /* xor input data with encrypted ctr =3D> out */ + aes_xor(in, buf, out); + /* write out the processed block */ + aes_write_block(env, mmu_idx, *dst_ptr_reg + done, out, ra); + len -=3D AES_BLOCK_SIZE; + done +=3D AES_BLOCK_SIZE; + } + + *src_ptr_reg =3D deposit64(*src_ptr_reg, 0, addr_reg_size, + *src_ptr_reg + done); + *dst_ptr_reg =3D deposit64(*dst_ptr_reg, 0, addr_reg_size, + *dst_ptr_reg + done); + *ctr_ptr_reg =3D deposit64(*ctr_ptr_reg, 0, addr_reg_size, + *ctr_ptr_reg + done); + *src_len_reg -=3D done; + + return !len ? 0 : 3; +} diff --git a/target/s390x/tcg/crypto_helper.c b/target/s390x/tcg/crypto_hel= per.c index 1fe1d7157b..9be8a14a80 100644 --- a/target/s390x/tcg/crypto_helper.c +++ b/target/s390x/tcg/crypto_helper.c @@ -131,6 +131,27 @@ static int cpacf_kmc(CPUS390XState *env, const int mmu= _idx, uintptr_t ra, return rc; } =20 +static int cpacf_kmctr(CPUS390XState *env, const int mmu_idx, uintptr_t ra, + uint32_t r1, uint32_t r2, uint32_t r3, + uint8_t fc, uint8_t mod) +{ + int rc =3D 0; + + switch (fc) { + case CPACF_KMCTR_AES_128: + case CPACF_KMCTR_AES_192: + case CPACF_KMCTR_AES_256: + rc =3D cpacf_aes_ctr(env, mmu_idx, ra, env->regs[1], + &env->regs[r1], &env->regs[r2], &env->regs[r2 += 1], + &env->regs[r3], S390_FEAT_TYPE_KMCTR, fc, mod); + break; + default: + tcg_s390_program_interrupt(env, PGM_SPECIFICATION, ra); + } + + return rc; +} + static int cpacf_ppno(CPUS390XState *env, const int mmu_idx, uintptr_t ra, uint32_t r1, uint32_t r2, uint32_t r3, uint8_t fc) { @@ -201,6 +222,9 @@ uint32_t HELPER(msa)(CPUS390XState *env, uint32_t r1, u= int32_t r2, uint32_t r3, case S390_FEAT_TYPE_KMC: rc =3D cpacf_kmc(env, mmu_idx, ra, r1, r2, r3, fc, mod); break; + case S390_FEAT_TYPE_KMCTR: + rc =3D cpacf_kmctr(env, mmu_idx, ra, r1, r2, r3, fc, mod); + break; case S390_FEAT_TYPE_PPNO: rc =3D cpacf_ppno(env, mmu_idx, ra, r1, r2, r3, fc); break; --=20 2.43.0 From nobody Sun Jul 26 10:59:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783331077; cv=none; d=zohomail.com; s=zohoarc; b=ZOc5aLHseebV0pQZoujvtzz/WlhX6RoOXuln1uYPju5DETIUXHJCa+oGfJELWQKBqjEWsImdkQ5P/SLXMzS/S0u7e5EAWBiyoXp4u+A5LlSK1GmPtQJaRNJbRchsRosBYRcthEsR5arvYsmVQ3ZOHUNHscxR92G6VBC0aPSbLfo= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783331077; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=6K2/aGKo4zl5Q0Q1X6JKN0MRm24eGYnHs0LZDXPvgYk=; b=AGYSLTCLXi8JleNI3jMSaY6x9krPP52suV8d5kmIRgeyzE/G9C8nhcrlL3qaozFwvqsoyHsw1IgA+pLstRTz4NBaV6mmbtYrvQN2nFKp+X9MuFfSt4eMosmC8lLAXzYxleRoRpq/RuTK6klTlxMINpGkW5wFd1jcLGCbPjdQSNU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783331077062899.6846204179483; Mon, 6 Jul 2026 02:44:37 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wgfra-0004Hy-5P; Mon, 06 Jul 2026 05:43:42 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrU-0004EB-Cz; Mon, 06 Jul 2026 05:43:36 -0400 Received: from mx0a-001b2d01.pphosted.com ([148.163.156.1]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrP-0003y5-Gs; Mon, 06 Jul 2026 05:43:35 -0400 Received: from pps.filterd (m0356517.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 6669IOIT3783318; Mon, 6 Jul 2026 09:43:23 GMT Received: from ppma21.wdc07v.mail.ibm.com (5b.69.3da9.ip4.static.sl-reverse.com [169.61.105.91]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f6sw4gqws-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:22 +0000 (GMT) Received: from pps.filterd (ppma21.wdc07v.mail.ibm.com [127.0.0.1]) by ppma21.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 6669YeQ5028347; Mon, 6 Jul 2026 09:43:21 GMT Received: from smtprelay04.fra02v.mail.ibm.com ([9.218.2.228]) by ppma21.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4f7dgjw0gs-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:21 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (smtpav07.fra02v.mail.ibm.com [10.20.54.106]) by smtprelay04.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 6669hHns23397078 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Mon, 6 Jul 2026 09:43:17 GMT Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id B2CD82004B; Mon, 6 Jul 2026 09:43:17 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 8C11120043; Mon, 6 Jul 2026 09:43:17 +0000 (GMT) Received: from funtu2.ibm.com (unknown [9.111.193.81]) by smtpav07.fra02v.mail.ibm.com (Postfix) with ESMTP; Mon, 6 Jul 2026 09:43:17 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=6K2/aGKo4zl5Q0Q1X 6JKN0MRm24eGYnHs0LZDXPvgYk=; b=Fvzd323gGGyeDvR5jHglQ3kNLJWRXxVZi i1nJ5WUHenaoVePZxZzBgTHJa3SyfhSUzrClY8KJ6WdnzYiGIMHJxZpxSrvpWRmC Mh0e/xyvgdF5f9MuTtVyGzjtKQx4+RkmNdupnMK8tRkyIJtQ2R7/zWfzC2iohv9U h/waKIqIOMGsRvtdjiqo4CTcmbF+1thawcDkOB199aa+zhlmunzgJlLikyv2vr3H EWpCeVAX0Rrchzct+LAHVYsK48+u3woMUYQDOfyr9L/a6Zqc3hVNKaRKdg7TqktB 5p8LQaNCwAtP3mRH08z2f8OrjeqMxfENuk+Su4LlllTXlwiybwZbw== From: Harald Freudenberger To: richard.henderson@linaro.org, iii@linux.ibm.com, david@kernel.org, thuth@redhat.com, berrange@redhat.com Cc: qemu-s390x@nongnu.org, qemu-devel@nongnu.org, linux-s390@vger.kernel.org, dengler@linux.ibm.com, borntraeger@linux.ibm.com, fcallies@linux.ibm.com, cohuck@redhat.com Subject: [PATCH v10 08/21] target/s390x: Minimal AES XTS support for cpacf pcc instruction Date: Mon, 6 Jul 2026 11:43:01 +0200 Message-ID: <20260706094317.17032-9-freude@linux.ibm.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260706094317.17032-1-freude@linux.ibm.com> References: <20260706094317.17032-1-freude@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-GUID: qj1TfJ8Lie37xd41Yc2E8i_Md8qyZQwa X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfX4p8fDQnqclnG Eu6Az/gFz4Sw5ptmgzFhJCnlEWMdHGNt2gP8uMMLBBRG/j2feu20MZbm7hVlyBhg2cp5X72ss9I 780xjC9Jxbh+XfEX1eVb6bo17hqAGGR6SjRDTl72kxb38VOrkn+yOcSOYtbpPh4kaqH+R3vt3R3 V+m4EzsumIB0F4+26UfmkUYCGQEqmeMXm4dJtJhH1iArptuuVeG6GRwaMi2k18MY9wlSvNTj3yo W2s1v7PqFRcLFe83h3EsM6tbuX5v2GLCjXHD90Y+Kv4kZEFqWj2eU8kqgCQcFU0PCchp0VL0tja a40Up4f7/zKIh5APgRrigbybInvWdTnSApdQNB2sIt8SPY48hhcF/fZbdB1kwW8n9xFgbIE5w8S HCKkN7CtdEI5z7l3Sr8saCmmNsIlSE3LitalrJkJEEZeJt9TIZcLKRCirVQje3JCNY3b7Rpj9vv y1ei0ZDvuMsNIQL0otg== X-Proofpoint-ORIG-GUID: qj1TfJ8Lie37xd41Yc2E8i_Md8qyZQwa X-Authority-Analysis: v=2.4 cv=FqQ1OWrq c=1 sm=1 tr=0 ts=6a4b78bb cx=c_pps a=GFwsV6G8L6GxiO2Y/PsHdQ==:117 a=GFwsV6G8L6GxiO2Y/PsHdQ==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=U7nrCbtTmkRpXpFmAIza:22 a=VnNF1IyMAAAA:8 a=gr50lgQh3SlUKNVXMSoA:9 X-Proofpoint-Spam-Info: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfX6iRkJtA+lmtf S3y5vrWt29qYjG5M5n7/qDqDB+VpCIYKhrIacrQMeBxU3Rttwz7VFogxGLlH1+9YocsmBm5wqB7 HYmihF0HwL33lERnVL5arYqGYG1r15w= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-06_01,2026-07-03_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 adultscore=0 impostorscore=0 clxscore=1015 malwarescore=0 lowpriorityscore=0 priorityscore=1501 bulkscore=0 suspectscore=0 spamscore=0 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607060094 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.156.1; envelope-from=freude@linux.ibm.com; helo=mx0a-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783331079152158500 Content-Type: text/plain; charset="utf-8" Support CPACF pcc subfunctions PCC-Compute-XTS-Parameter-AES-128 and PCC-Compute-XTS-Parameter-AES-128 but only for the special case block sequential number is 0. However, this covers the s390 AES XTS implementation in the Linux kernel and Libica and thus also Opencryptoki clear key via Libica. Signed-off-by: Harald Freudenberger Tested-by: Holger Dengler Reviewed-by: Holger Dengler --- target/s390x/gen-features.c | 2 + target/s390x/tcg/cpacf.h | 2 + target/s390x/tcg/cpacf_aes.c | 63 ++++++++++++++++++++++++++++++++ target/s390x/tcg/crypto_helper.c | 20 ++++++++++ 4 files changed, 87 insertions(+) diff --git a/target/s390x/gen-features.c b/target/s390x/gen-features.c index 59c2a47539..1b6a874b90 100644 --- a/target/s390x/gen-features.c +++ b/target/s390x/gen-features.c @@ -930,6 +930,8 @@ static uint16_t qemu_MAX[] =3D { S390_FEAT_KMCTR_AES_128, S390_FEAT_KMCTR_AES_192, S390_FEAT_KMCTR_AES_256, + S390_FEAT_PCC_XTS_AES_128, + S390_FEAT_PCC_XTS_AES_256, }; =20 /****** END FEATURE DEFS ******/ diff --git a/target/s390x/tcg/cpacf.h b/target/s390x/tcg/cpacf.h index 3707308661..2e8ed72758 100644 --- a/target/s390x/tcg/cpacf.h +++ b/target/s390x/tcg/cpacf.h @@ -247,5 +247,7 @@ int cpacf_aes_ctr(CPUS390XState *env, const int mmu_idx= , uintptr_t ra, uint64_t *src_ptr_reg, uint64_t *src_len_reg, uint64_t *ctr_ptr_reg, uint32_t type, uint8_t fc, uint8_t mod); +int cpacf_aes_pcc(CPUS390XState *env, const int mmu_idx, uintptr_t ra, + uint64_t param_addr, uint8_t fc); =20 #endif /* S390X_CPACF_H */ diff --git a/target/s390x/tcg/cpacf_aes.c b/target/s390x/tcg/cpacf_aes.c index 3d6aa19df2..f41b7dc541 100644 --- a/target/s390x/tcg/cpacf_aes.c +++ b/target/s390x/tcg/cpacf_aes.c @@ -290,3 +290,66 @@ int cpacf_aes_ctr(CPUS390XState *env, const int mmu_id= x, uintptr_t ra, =20 return !len ? 0 : 3; } + +int cpacf_aes_pcc(CPUS390XState *env, const int mmu_idx, uintptr_t ra, + uint64_t param_addr, uint8_t fc) +{ + uint8_t key[32], tweak[AES_BLOCK_SIZE], buf[AES_BLOCK_SIZE]; + const MemOpIdx oi =3D make_memop_idx(MO_8, mmu_idx); + int keysize, i; + uint64_t addr; + AES_KEY exkey; + + switch (fc) { + case CPACF_PCC_XTS_AES_128: + keysize =3D 16; + break; + case CPACF_PCC_XTS_AES_256: + keysize =3D 32; + break; + default: + g_assert_not_reached(); + } + + /* fetch block sequence nr from param block into buf */ + for (i =3D 0; i < AES_BLOCK_SIZE; i++) { + addr =3D wrap_address(env, param_addr + keysize + AES_BLOCK_SIZE += i); + buf[i] =3D cpu_ldb_mmu(env, addr, oi, ra); + } + + /* is the block sequence nr 0 ? */ + for (i =3D 0; i < AES_BLOCK_SIZE && !buf[i]; i++) { + ; + } + if (i < AES_BLOCK_SIZE) { + /* no, sorry handling of non zero block sequence is not implemente= d */ + tcg_s390_program_interrupt(env, PGM_SPECIFICATION, ra); + return 1; + } + + /* fetch key from param block */ + for (i =3D 0; i < keysize; i++) { + addr =3D wrap_address(env, param_addr + i); + key[i] =3D cpu_ldb_mmu(env, addr, oi, ra); + } + + /* fetch tweak from param block into tweak */ + for (i =3D 0; i < AES_BLOCK_SIZE; i++) { + addr =3D wrap_address(env, param_addr + keysize + i); + tweak[i] =3D cpu_ldb_mmu(env, addr, oi, ra); + } + + /* expand key */ + AES_set_encrypt_key(key, keysize * 8, &exkey); + + /* encrypt tweak */ + AES_encrypt(tweak, buf, &exkey); + + /* store encrypted tweak into xts parameter field of the param block */ + for (i =3D 0; i < AES_BLOCK_SIZE; i++) { + addr =3D wrap_address(env, param_addr + keysize + 3 * AES_BLOCK_SI= ZE + i); + cpu_stb_mmu(env, addr, buf[i], oi, ra); + } + + return 0; +} diff --git a/target/s390x/tcg/crypto_helper.c b/target/s390x/tcg/crypto_hel= per.c index 9be8a14a80..1d447cef30 100644 --- a/target/s390x/tcg/crypto_helper.c +++ b/target/s390x/tcg/crypto_helper.c @@ -169,6 +169,23 @@ static int cpacf_ppno(CPUS390XState *env, const int mm= u_idx, uintptr_t ra, return rc; } =20 +static int cpacf_pcc(CPUS390XState *env, const int mmu_idx, uintptr_t ra, + uint8_t fc) +{ + int rc =3D 0; + + switch (fc) { + case CPACF_PCC_XTS_AES_128: + case CPACF_PCC_XTS_AES_256: + rc =3D cpacf_aes_pcc(env, mmu_idx, ra, env->regs[1], fc); + break; + default: + tcg_s390_program_interrupt(env, PGM_SPECIFICATION, ra); + } + + return rc; +} + uint32_t HELPER(msa)(CPUS390XState *env, uint32_t r1, uint32_t r2, uint32_= t r3, uint32_t type) { @@ -225,6 +242,9 @@ uint32_t HELPER(msa)(CPUS390XState *env, uint32_t r1, u= int32_t r2, uint32_t r3, case S390_FEAT_TYPE_KMCTR: rc =3D cpacf_kmctr(env, mmu_idx, ra, r1, r2, r3, fc, mod); break; + case S390_FEAT_TYPE_PCC: + rc =3D cpacf_pcc(env, mmu_idx, ra, fc); + break; case S390_FEAT_TYPE_PPNO: rc =3D cpacf_ppno(env, mmu_idx, ra, r1, r2, r3, fc); break; --=20 2.43.0 From nobody Sun Jul 26 10:59:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783331167; cv=none; d=zohomail.com; s=zohoarc; b=SGPOGdMeGL13B3GLpDWTg7jI/npfbOMEJs2HX1WIERZBNfA9vXc3MiD57jNrDy2w3C0fWhkL7ubO6RRXcLKJfBplhOpITxQgFwgAvsQ0aJ9wszA+bqcPY/GCKTdonheYE6Haj2lkdzxFzNIHcKANWUcXrYLAL9ttEJOavPKfBjg= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783331167; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=o1x6KBb1VQ07421LND+pPC33UIDdSB9H/6OFMNnsHPY=; b=Y73gfZouxDApgFkpLRvL3D2FVi3WTWrQN/qiajqAqPkxtuqMjsygK4Qymp0QvDHk7rupT/8G44kvHg/mpDazuNBRuJo1GQlj4lJIFw3l6Cfue6eo1z7kJdNZtdAoHjyOUu0jwqiPHVilIKLlw4JfaR/2cJEYI+UdJ7UbTjilnhg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783331167341334.1057791528443; Mon, 6 Jul 2026 02:46:07 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wgfrb-0004I4-5i; Mon, 06 Jul 2026 05:43:43 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrV-0004Fn-Ty; Mon, 06 Jul 2026 05:43:37 -0400 Received: from mx0a-001b2d01.pphosted.com ([148.163.156.1]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrP-0003xX-Ky; Mon, 06 Jul 2026 05:43:37 -0400 Received: from pps.filterd (m0353729.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 6669IRps4015302; Mon, 6 Jul 2026 09:43:22 GMT Received: from ppma12.dal12v.mail.ibm.com (dc.9e.1632.ip4.static.sl-reverse.com [50.22.158.220]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f6suqgp81-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:22 +0000 (GMT) Received: from pps.filterd (ppma12.dal12v.mail.ibm.com [127.0.0.1]) by ppma12.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 6669YcGX024940; Mon, 6 Jul 2026 09:43:21 GMT Received: from smtprelay04.fra02v.mail.ibm.com ([9.218.2.228]) by ppma12.dal12v.mail.ibm.com (PPS) with ESMTPS id 4f7cgpw71p-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:21 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (smtpav07.fra02v.mail.ibm.com [10.20.54.106]) by smtprelay04.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 6669hIpT23397080 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Mon, 6 Jul 2026 09:43:18 GMT Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id DD0A520040; Mon, 6 Jul 2026 09:43:17 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id B70932004E; Mon, 6 Jul 2026 09:43:17 +0000 (GMT) Received: from funtu2.ibm.com (unknown [9.111.193.81]) by smtpav07.fra02v.mail.ibm.com (Postfix) with ESMTP; Mon, 6 Jul 2026 09:43:17 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=o1x6KBb1VQ07421LN D+pPC33UIDdSB9H/6OFMNnsHPY=; b=itNID3XSCy2PIaQcFOBJEEiuYQaeyRlwY ikQiEPnAkGTGmmTdr7ULP3k4TbuX362gHcH3zAK8pKVkvvqqMostWxBlAD9c+1Ug Q/RzhugT+isaoMl7nL979qtNnXgbZqq49g2zlNsr5i2kuXFl6yW2UzB+6NkxrDud pOWOkwTEhC7T/mQPJ/+d5QtzND60bR9uMHHBGapHYM2JTRpkkAWqv43T+PxT80U8 EdVYcUajpM93CjWTi848lHL7n7q9dGsphC0uQd65rG+w8m81SRbPzEubilMqqnkM YBKfIMlYv5ucOsBw6L3/E4B+dbdo6HrEnccW/58Udgj5xAvxbw4dw== From: Harald Freudenberger To: richard.henderson@linaro.org, iii@linux.ibm.com, david@kernel.org, thuth@redhat.com, berrange@redhat.com Cc: qemu-s390x@nongnu.org, qemu-devel@nongnu.org, linux-s390@vger.kernel.org, dengler@linux.ibm.com, borntraeger@linux.ibm.com, fcallies@linux.ibm.com, cohuck@redhat.com Subject: [PATCH v10 09/21] target/s390x: Support AES XTS for cpacf km instruction Date: Mon, 6 Jul 2026 11:43:02 +0200 Message-ID: <20260706094317.17032-10-freude@linux.ibm.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260706094317.17032-1-freude@linux.ibm.com> References: <20260706094317.17032-1-freude@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Spam-Info: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfXzjxdZQHdmlCa jYAZlLYX09iKVE3wnAjRaxgPX8iqPTRxeOy8RSmI5rvhk8qzSlTc3b8js9Bj2Y+FhccnwyWI7cm ke7EpvPxrdb0bTU3hiJPKVHWCXipiGc= X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfX03cJh+knIRvK +AyRm+diuJ7e1d8Dg8sRQWY4qWBinKAT9kCzNmw0PyuAVke31WonYYSNWvyTIeHwWeBy5ePcgq2 FBDi4dLlgENBtc7SuC7kvM1r7H/wT6GvgbdEaaYPQh4NQnaMP64pvYnNoscZLSyf0iLLxIVQ1B9 BBjiruPvpp51F/4dZLMXJHU1VFa56278sQEbxEL2i50dtXoGKW2iyMQxahWYuJQgoQ/cpNXwm+C 85+ojcOyWbBObhEoDjQkF0baA7zKl3BXH65wk2N96yrXMax43K979+2dQ2gmuWeHSMnR/flf/Xe J4KX1vOIbNzH43AuiJdFE6h7VX8OqAUJUe3tYQy5/XGwqku6cAi78X3eV/wCown2muZzhLXKaOa T74SN3UCLjpAsh10jE50+LZLIvRLreTndRvtLVhFFOrAQrwAiNL1juQT5Xa0WGCIhF8ho58gQ5c 5gy19e+p//pFnGi1baA== X-Proofpoint-GUID: sUue7kIlBLqQ44I5ZhW148JEMwT3h7Vr X-Authority-Analysis: v=2.4 cv=Oot/DS/t c=1 sm=1 tr=0 ts=6a4b78ba cx=c_pps a=bLidbwmWQ0KltjZqbj+ezA==:117 a=bLidbwmWQ0KltjZqbj+ezA==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=uAbxVGIbfxUO_5tXvNgY:22 a=VnNF1IyMAAAA:8 a=zF3DBZfHWt6I_7Vt9OoA:9 X-Proofpoint-ORIG-GUID: sUue7kIlBLqQ44I5ZhW148JEMwT3h7Vr X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-06_01,2026-07-03_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 bulkscore=0 lowpriorityscore=0 clxscore=1015 impostorscore=0 phishscore=0 malwarescore=0 suspectscore=0 spamscore=0 adultscore=0 priorityscore=1501 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607060094 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.156.1; envelope-from=freude@linux.ibm.com; helo=mx0a-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783331167595158500 Content-Type: text/plain; charset="utf-8" Support the subfunctions XTS-AES-128 and XTS-AES-256 for the cpacf km instruction. Tested-by: Holger Dengler Signed-off-by: Harald Freudenberger Reviewed-by: Holger Dengler --- target/s390x/gen-features.c | 2 + target/s390x/tcg/cpacf.h | 4 ++ target/s390x/tcg/cpacf_aes.c | 108 +++++++++++++++++++++++++++++++ target/s390x/tcg/crypto_helper.c | 6 ++ 4 files changed, 120 insertions(+) diff --git a/target/s390x/gen-features.c b/target/s390x/gen-features.c index 1b6a874b90..f9b1a40c7c 100644 --- a/target/s390x/gen-features.c +++ b/target/s390x/gen-features.c @@ -924,6 +924,8 @@ static uint16_t qemu_MAX[] =3D { S390_FEAT_KM_AES_128, S390_FEAT_KM_AES_192, S390_FEAT_KM_AES_256, + S390_FEAT_KM_XTS_AES_128, + S390_FEAT_KM_XTS_AES_256, S390_FEAT_KMC_AES_128, S390_FEAT_KMC_AES_192, S390_FEAT_KMC_AES_256, diff --git a/target/s390x/tcg/cpacf.h b/target/s390x/tcg/cpacf.h index 2e8ed72758..e585b77766 100644 --- a/target/s390x/tcg/cpacf.h +++ b/target/s390x/tcg/cpacf.h @@ -249,5 +249,9 @@ int cpacf_aes_ctr(CPUS390XState *env, const int mmu_idx= , uintptr_t ra, uint8_t fc, uint8_t mod); int cpacf_aes_pcc(CPUS390XState *env, const int mmu_idx, uintptr_t ra, uint64_t param_addr, uint8_t fc); +int cpacf_aes_xts(CPUS390XState *env, const int mmu_idx, uintptr_t ra, + uint64_t param_addr, uint64_t *dst_ptr_reg, + uint64_t *src_ptr_reg, uint64_t *src_len_reg, + uint32_t type, uint8_t fc, uint8_t mod); =20 #endif /* S390X_CPACF_H */ diff --git a/target/s390x/tcg/cpacf_aes.c b/target/s390x/tcg/cpacf_aes.c index f41b7dc541..4a28cc3d7c 100644 --- a/target/s390x/tcg/cpacf_aes.c +++ b/target/s390x/tcg/cpacf_aes.c @@ -353,3 +353,111 @@ int cpacf_aes_pcc(CPUS390XState *env, const int mmu_i= dx, uintptr_t ra, =20 return 0; } + +static void aes_xts_prep_next_tweak(uint8_t tweak[AES_BLOCK_SIZE]) +{ + uint8_t carry; + int i; + + carry =3D tweak[AES_BLOCK_SIZE - 1] >> 7; + + for (i =3D AES_BLOCK_SIZE - 1; i > 0; i--) { + tweak[i] =3D (uint8_t)((tweak[i] << 1) | (tweak[i - 1] >> 7)); + } + + tweak[i] =3D (uint8_t)(tweak[i] << 1); + tweak[i] ^=3D (uint8_t)(0x87 & (uint8_t)(-(int8_t)carry)); +} + +int cpacf_aes_xts(CPUS390XState *env, const int mmu_idx, uintptr_t ra, + uint64_t param_addr, uint64_t *dst_ptr_reg, + uint64_t *src_ptr_reg, uint64_t *src_len_reg, + uint32_t type, uint8_t fc, uint8_t mod) +{ + enum { MAX_BLOCKS_PER_RUN =3D 8192 / AES_BLOCK_SIZE }; + uint8_t buf1[AES_BLOCK_SIZE], buf2[AES_BLOCK_SIZE]; + const MemOpIdx oi =3D make_memop_idx(MO_8, mmu_idx); + uint64_t addr, len =3D *src_len_reg, done =3D 0; + uint8_t key[32], tweak[AES_BLOCK_SIZE]; + int i, keysize, addr_reg_size =3D 64; + AES_KEY exkey; + + g_assert(type =3D=3D S390_FEAT_TYPE_KM); + + switch (fc) { + case CPACF_KM_XTS_128: + keysize =3D 16; + break; + case CPACF_KM_XTS_256: + keysize =3D 32; + break; + default: + g_assert_not_reached(); + } + + if (!(env->psw.mask & PSW_MASK_64)) { + len =3D (uint32_t)len; + addr_reg_size =3D (env->psw.mask & PSW_MASK_32) ? 32 : 24; + } + + /* length has to be properly aligned. */ + if (!QEMU_IS_ALIGNED(len, AES_BLOCK_SIZE)) { + tcg_s390_program_interrupt(env, PGM_SPECIFICATION, ra); + } + + /* fetch key from param block */ + for (i =3D 0; i < keysize; i++) { + addr =3D wrap_address(env, param_addr + i); + key[i] =3D cpu_ldb_mmu(env, addr, oi, ra); + } + + /* expand key */ + if (mod) { + AES_set_decrypt_key(key, keysize * 8, &exkey); + } else { + AES_set_encrypt_key(key, keysize * 8, &exkey); + } + + /* fetch tweak from param block */ + for (i =3D 0; i < AES_BLOCK_SIZE; i++) { + addr =3D wrap_address(env, param_addr + keysize + i); + tweak[i] =3D cpu_ldb_mmu(env, addr, oi, ra); + } + + /* process up to MAX_BLOCKS_PER_RUN aes blocks */ + for (i =3D 0; i < MAX_BLOCKS_PER_RUN && len >=3D AES_BLOCK_SIZE; i++) { + /* fetch one AES block into buf1 */ + aes_read_block(env, mmu_idx, *src_ptr_reg + done, buf1, ra); + /* buf1 xor tweak =3D> buf2 */ + aes_xor(buf1, tweak, buf2); + if (mod) { + /* decrypt buf2 =3D> buf1 */ + AES_decrypt(buf2, buf1, &exkey); + } else { + /* encrypt buf2 =3D> buf1 */ + AES_encrypt(buf2, buf1, &exkey); + } + /* buf1 xor tweak =3D> buf2 */ + aes_xor(buf1, tweak, buf2); + /* prep tweak for next round */ + aes_xts_prep_next_tweak(tweak); + /* write out this processed block from buf2 */ + aes_write_block(env, mmu_idx, *dst_ptr_reg + done, buf2, ra); + len -=3D AES_BLOCK_SIZE; + done +=3D AES_BLOCK_SIZE; + } + + /* update tweak in param block */ + for (i =3D 0; i < AES_BLOCK_SIZE; i++) { + addr =3D wrap_address(env, param_addr + keysize + i); + cpu_stb_mmu(env, addr, tweak[i], oi, ra); + } + + *src_ptr_reg =3D deposit64(*src_ptr_reg, 0, addr_reg_size, + *src_ptr_reg + done); + *dst_ptr_reg =3D deposit64(*dst_ptr_reg, 0, addr_reg_size, + *dst_ptr_reg + done); + *src_len_reg -=3D done; + + return !len ? 0 : 3; +} diff --git a/target/s390x/tcg/crypto_helper.c b/target/s390x/tcg/crypto_hel= per.c index 1d447cef30..564f7fa243 100644 --- a/target/s390x/tcg/crypto_helper.c +++ b/target/s390x/tcg/crypto_helper.c @@ -103,6 +103,12 @@ static int cpacf_km(CPUS390XState *env, const int mmu_= idx, uintptr_t ra, &env->regs[r1], &env->regs[r2], &env->regs[r2 += 1], S390_FEAT_TYPE_KM, fc, mod); break; + case CPACF_KM_XTS_128: + case CPACF_KM_XTS_256: + rc =3D cpacf_aes_xts(env, mmu_idx, ra, env->regs[1], + &env->regs[r1], &env->regs[r2], &env->regs[r2 += 1], + S390_FEAT_TYPE_KM, fc, mod); + break; default: tcg_s390_program_interrupt(env, PGM_SPECIFICATION, ra); } --=20 2.43.0 From nobody Sun Jul 26 10:59:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783331270; cv=none; d=zohomail.com; s=zohoarc; b=Z9dyJydcSbTNt3b1XdchZjXiq36F0nl1Pv+bc6BRav5OvyqWq+/3o0Eom5dfoEBcjFSzxN6Ifsgc8pMbmcOyiMdOPLJeK2MQeE6LK1PINHY/FKLlBNx6zJVTXUPtZyVH0VXvTnBVEcBR11VFPZkvvBJA7Vvhr5LlxsujEYOA1M8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783331270; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=F+UMGpZQYY5oCtCadl4DVVSQMMO7Tg14YadLoyTOYQE=; b=AZa1FPgFP2Dkp1OjO4l+AqYbWR7T5ieIgbv80uDBaTeUWwVNXqaxGB5I6HgRVcSovJ62AyChcjTcxKcb+BOCn6vz7Usu5uaHqZiYtxyaM8PHGx3mgZANdCBQwSV4nHQObMFzXBbrfQcZDysjGBjGpePSVRfgRHtrb3q5RBzhCbo= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178333127046933.32984607751075; Mon, 6 Jul 2026 02:47:50 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wgfra-0004I2-N2; Mon, 06 Jul 2026 05:43:42 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrU-0004EC-DM; Mon, 06 Jul 2026 05:43:36 -0400 Received: from mx0a-001b2d01.pphosted.com ([148.163.156.1]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrP-0003yE-NP; Mon, 06 Jul 2026 05:43:36 -0400 Received: from pps.filterd (m0356517.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 6669IPa03783398; Mon, 6 Jul 2026 09:43:23 GMT Received: from ppma11.dal12v.mail.ibm.com (db.9e.1632.ip4.static.sl-reverse.com [50.22.158.219]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f6sw4gqwt-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:22 +0000 (GMT) Received: from pps.filterd (ppma11.dal12v.mail.ibm.com [127.0.0.1]) by ppma11.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 6669YdvM030257; Mon, 6 Jul 2026 09:43:21 GMT Received: from smtprelay05.fra02v.mail.ibm.com ([9.218.2.225]) by ppma11.dal12v.mail.ibm.com (PPS) with ESMTPS id 4f7f6xvnqg-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:21 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (smtpav07.fra02v.mail.ibm.com [10.20.54.106]) by smtprelay05.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 6669hIh138470016 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Mon, 6 Jul 2026 09:43:18 GMT Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 132542004B; Mon, 6 Jul 2026 09:43:18 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id E13B020043; Mon, 6 Jul 2026 09:43:17 +0000 (GMT) Received: from funtu2.ibm.com (unknown [9.111.193.81]) by smtpav07.fra02v.mail.ibm.com (Postfix) with ESMTP; Mon, 6 Jul 2026 09:43:17 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=F+UMGpZQYY5oCtCad l4DVVSQMMO7Tg14YadLoyTOYQE=; b=ivihnyrz/F8lgQvPQ0D/DyR844NxwS+VZ ua+38yDxOCrEg8OVynQ4MQMpK1G/MHU6bK/xg6CyNzPmVT18GUcheytrBKL+9+Rk Mg5+74/YzY0HhlGZx152cAgBHT96BJpb+c6SVnGPyErv00sFGPAqvcEk8RFzid5o OfrRTAWIlVMkVwbEuPFXfcUU2BqidbwqJt42YCUwL4JxHtgZoxeZTaWCX1VgEHxh g+8o5g8yEaDLkES9lpecUfxfgQyQiKGUxsn/sEo+sONvKwNn1iSMiLdlKEvypaeJ rlFC11eESCBq+8elI+6i4gyPL8dCzXor7iYRn98vwCg5jfTf3dp+w== From: Harald Freudenberger To: richard.henderson@linaro.org, iii@linux.ibm.com, david@kernel.org, thuth@redhat.com, berrange@redhat.com Cc: qemu-s390x@nongnu.org, qemu-devel@nongnu.org, linux-s390@vger.kernel.org, dengler@linux.ibm.com, borntraeger@linux.ibm.com, fcallies@linux.ibm.com, cohuck@redhat.com Subject: [PATCH v10 10/21] target/s390x: Base support for cpacf protected keys Date: Mon, 6 Jul 2026 11:43:03 +0200 Message-ID: <20260706094317.17032-11-freude@linux.ibm.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260706094317.17032-1-freude@linux.ibm.com> References: <20260706094317.17032-1-freude@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-GUID: pTsxVVqC9Bs1EizzAavB_vsjS68Atfja X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfX6q5fxfOtNokB fM4mthAwMY346pZij64DOUHo/Me1LYMNU9nZhBalOjBUwUdMn8xuKAC1R10jIuJwUKh78w9zij3 dup3fKshpK6oZJm6bFT4Wih6G9xHPjJrX66IUJndiN9OssOYgAAA/f+YUk0KBLR8OcnjiAHwTYm BkB2fYe+ZAD78iNN80TouHnBwFQFmjbZRoE1SQj8Sc4FRoEOjZruzeWbjn8vf9qcvc1uAO9Mxjs 5E0L5GWCo+y0kR4hf9xi5AWMDu69zIM3o+jJ44d8YoiFgT1xaR2uUbrZzzg8HUor+ja0acUJ12Y jAK57/qO65vfhOtWvNDetOq1WkVFqDsabPAgg9Yoa6bvRfmvp1IYVEdzikxL+K6o37p1geOJOQF 6iyfwbdU/HYzdWDNpjW7bcuGQ6vZbqkBMzXGxQNM1mAFrUbM5FP9fOZo1MYlGKggpT2zk/4/f27 Q8j2m9TluLh1RiAtmGA== X-Proofpoint-ORIG-GUID: pTsxVVqC9Bs1EizzAavB_vsjS68Atfja X-Authority-Analysis: v=2.4 cv=FqQ1OWrq c=1 sm=1 tr=0 ts=6a4b78ba cx=c_pps a=aDMHemPKRhS1OARIsFnwRA==:117 a=aDMHemPKRhS1OARIsFnwRA==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=U7nrCbtTmkRpXpFmAIza:22 a=VnNF1IyMAAAA:8 a=pDJEeJrE-AQHYYEhGn0A:9 X-Proofpoint-Spam-Info: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfXzEXoPrD85wdt HBPSE8kqX1k24KQPr7MZyI+HjY+4FwISN90VpcyLWkLQBWQl6eaizTATLy/DCXvDgK0ygg96v+0 WslPovQHMz1ePKr0ziWZK4EOVNxvMk8= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-06_01,2026-07-03_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 adultscore=0 impostorscore=0 clxscore=1015 malwarescore=0 lowpriorityscore=0 priorityscore=1501 bulkscore=0 suspectscore=0 spamscore=0 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607060094 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.156.1; envelope-from=freude@linux.ibm.com; helo=mx0a-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783331272190158500 Content-Type: text/plain; charset="utf-8" Add base support for cpacf protected key handling. The qemu version provided here is only a fake intended to make protected key available for developing and testing purpose: * The protected key is 'derived' from the clear key by xoring the fixed pattern 0xAAAA... onto the key value. * The AES Wrapping Key Verification Pattern is a fixed value of 32 bytes 0xFACEFACE... Add preprocessor defines for the xor pattern and wkvp used to construct ('encrypt') a protected key from a clear key value with this implementation. Also add some static functions to 'encrypt' from clear key to protected key and 'decrypt' back to cpacf_aes.c. The preprocessor defines shall be used later in testcases to construct and decode protected keys. Signed-off-by: Harald Freudenberger --- target/s390x/tcg/cpacf.h | 25 +++++++++++++++++++++++ target/s390x/tcg/cpacf_aes.c | 39 ++++++++++++++++++++++++++++++++++++ 2 files changed, 64 insertions(+) diff --git a/target/s390x/tcg/cpacf.h b/target/s390x/tcg/cpacf.h index e585b77766..df7f258443 100644 --- a/target/s390x/tcg/cpacf.h +++ b/target/s390x/tcg/cpacf.h @@ -254,4 +254,29 @@ int cpacf_aes_xts(CPUS390XState *env, const int mmu_id= x, uintptr_t ra, uint64_t *src_ptr_reg, uint64_t *src_len_reg, uint32_t type, uint8_t fc, uint8_t mod); =20 +/* + * Support for protected key cpacf functions. Note that this is + * a fake implementation intended for debugging and development. + * Do not use for production load ! + */ + +/* + * Hard coded pattern xored with the AES clear key + * to 'produce' the protected key. + */ +#define PROTKEY_XOR_PATTERN { \ + 0xAA, 0xAA, 0xAA, 0xAA, 0xAA, 0xAA, 0xAA, 0xAA, \ + 0xAA, 0xAA, 0xAA, 0xAA, 0xAA, 0xAA, 0xAA, 0xAA, \ + 0xAA, 0xAA, 0xAA, 0xAA, 0xAA, 0xAA, 0xAA, 0xAA, \ + 0xAA, 0xAA, 0xAA, 0xAA, 0xAA, 0xAA, 0xAA, 0xAA } + +/* + * Hard coded wkvp ("Wrapping Key Verification Pattern") + */ +#define PROTKEY_WKVP { \ + 0x0F, 0x0A, 0x0C, 0x0E, 0x0F, 0x0A, 0x0C, 0x0E, \ + 0x0F, 0x0A, 0x0C, 0x0E, 0x0F, 0x0A, 0x0C, 0x0E, \ + 0x0F, 0x0A, 0x0C, 0x0E, 0x0F, 0x0A, 0x0C, 0x0E, \ + 0x0F, 0x0A, 0x0C, 0x0E, 0x0F, 0x0A, 0x0C, 0x0E } + #endif /* S390X_CPACF_H */ diff --git a/target/s390x/tcg/cpacf_aes.c b/target/s390x/tcg/cpacf_aes.c index 4a28cc3d7c..6702006b66 100644 --- a/target/s390x/tcg/cpacf_aes.c +++ b/target/s390x/tcg/cpacf_aes.c @@ -461,3 +461,42 @@ int cpacf_aes_xts(CPUS390XState *env, const int mmu_id= x, uintptr_t ra, =20 return !len ? 0 : 3; } + +/* + * Support for protected key cpacf functions. Note that this is + * a fake implementation intended for debugging and development. + * Do not use for production load ! + */ + +/* + * Hard coded pattern xored with the AES clear key + * to 'produce' the protected key. + */ +static const uint8_t protkey_xor_pattern[32] =3D PROTKEY_XOR_PATTERN; + +/* + * Hard coded wkvp ("Wrapping Key Verification Pattern") + */ +static const uint8_t protkey_wkvp[32] =3D PROTKEY_WKVP; + +/* + * 'encrypt' the clear key value into a protected key + * by xor-ing the protkey_xor_pattern onto it. + */ +static void encrypt_clrkey(uint8_t *key, int keysize) +{ + for (int i =3D 0; i < keysize; i++) { + key[i] ^=3D protkey_xor_pattern[i]; + } +} + +/* + * 'decrypt' the protected key by reverting the xor + * of the protkey_xor_pattern onto the clear key value. + */ +static void decrypt_protkey(uint8_t *key, int keysize) +{ + for (int i =3D 0; i < keysize; i++) { + key[i] ^=3D protkey_xor_pattern[i]; + } +} --=20 2.43.0 From nobody Sun Jul 26 10:59:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783331162; cv=none; d=zohomail.com; s=zohoarc; b=TX28uX0G2lvUIXzDQJDlA/9wEfIwI7ih9ngeH94bCFCH8B2Op/fzaQHjrw72osEXD8FBTHVU13ZT+Yhbyvwgqus8MhSkvjAX+PmbnxpoGnEZy7xrSlYORIgAg5QT/EiGoTdkUW6ytvS8lzY6PhFj9ZoemNanKban16pUK1tRXWs= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783331162; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=4jDaDveEQjx3M9gQgGm7WqdzDPE7p/UTV3IR3bqedqw=; b=b+YHzP3vCPqDBlkqKvmSpU+A9jlj5Ry3PcAdcpxUc58rGL6PE6GAhA/s8KB+5yo8J3n1qkVNXZz9HLxk3jSytCjcHS/w5U80JHR/KmZj6O8go4MZrqRGGu6F0tVLT23xbs6YG8Yu/FG0uXbfeBSL0i5wQJh94UfMLO1mBXHBikA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783331162224557.4904076282261; Mon, 6 Jul 2026 02:46:02 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wgfrn-0004Qf-9r; Mon, 06 Jul 2026 05:43:56 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrl-0004Pt-Bl; Mon, 06 Jul 2026 05:43:53 -0400 Received: from mx0a-001b2d01.pphosted.com ([148.163.156.1]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrj-0003xi-DM; Mon, 06 Jul 2026 05:43:53 -0400 Received: from pps.filterd (m0353729.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 6669IYN14015378; Mon, 6 Jul 2026 09:43:23 GMT Received: from ppma21.wdc07v.mail.ibm.com (5b.69.3da9.ip4.static.sl-reverse.com [169.61.105.91]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f6suqgp84-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:23 +0000 (GMT) Received: from pps.filterd (ppma21.wdc07v.mail.ibm.com [127.0.0.1]) by ppma21.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 6669Ya7Z028303; Mon, 6 Jul 2026 09:43:22 GMT Received: from smtprelay05.fra02v.mail.ibm.com ([9.218.2.225]) by ppma21.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4f7dgjw0gu-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:22 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (smtpav07.fra02v.mail.ibm.com [10.20.54.106]) by smtprelay05.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 6669hI6746727530 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Mon, 6 Jul 2026 09:43:18 GMT Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 3D8B62004E; Mon, 6 Jul 2026 09:43:18 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 175C720040; Mon, 6 Jul 2026 09:43:18 +0000 (GMT) Received: from funtu2.ibm.com (unknown [9.111.193.81]) by smtpav07.fra02v.mail.ibm.com (Postfix) with ESMTP; Mon, 6 Jul 2026 09:43:18 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=4jDaDveEQjx3M9gQg Gm7WqdzDPE7p/UTV3IR3bqedqw=; b=FXC1Bwiwg0zQ0PjArf3VfkFJZik3aoXI7 6221BlJOTTYBldwFQH6F5vtoJewex68j7/dEgRQoGCZwv0P/lDdPYu+cG1EqmWvY r1ZrYShn7hWBj1tfAx5Ic1hWrvO+5uOuhIGDicXKw3IejiUVz46jvUMHXtO2NDpz jQpWV49ptu/28I3VvelrSbtpJvymE0RVGASbvf4m90dX0oqHTx04GVyl9pQVdvs9 kzmlpCTrskIvmUOs1lxhz6f/xx29PVZAqMostsCkALWDwOJkunj7fZyjlsoadibN fFZ1T3ibX4ZAMS4dLid03Mbdo+UjtUzO1I9svZr/jIh9Hmpq6BpUw== From: Harald Freudenberger To: richard.henderson@linaro.org, iii@linux.ibm.com, david@kernel.org, thuth@redhat.com, berrange@redhat.com Cc: qemu-s390x@nongnu.org, qemu-devel@nongnu.org, linux-s390@vger.kernel.org, dengler@linux.ibm.com, borntraeger@linux.ibm.com, fcallies@linux.ibm.com, cohuck@redhat.com Subject: [PATCH v10 11/21] target/s390x: Support pckmo encrypt AES subfunctions Date: Mon, 6 Jul 2026 11:43:04 +0200 Message-ID: <20260706094317.17032-12-freude@linux.ibm.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260706094317.17032-1-freude@linux.ibm.com> References: <20260706094317.17032-1-freude@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Spam-Info: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfX2wKHrP3OF7T8 eHor9y5XjDI+U7DaQ8Gd6O/q6JJal0QCSbdAjw9X26k/2BpPu0lm0H7X+V46x5R3Ew3BW5xl7Yd bnepXtuNVFORrB0byUUPp+T6mRSQjQM= X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfXzqv/EgdHkw9h v9uQhfItp++SgkKsV2b0J7qFBEnlCprgJGRMxzttnzmVhOjExkgActrioPwMOknwUQhAehwoIZB yqN7We6B+D7NiTSqt2jNxnf70f8qd3dJgYzbmDj2tVkacCML9AxuiZ7OzRafsmleQRv/jINuXWI kmNUIvE0fcGf+jsZ9w3Nwdp3LZP7SVsX0bk97+OwmZ3Cf8hHNRwDGTspO8ZQ94vf810A41deMPV 0lS0YcC9QLMjg6FJ9HUY8JtYhgCZbukJ/4m/LWQSelm5ovailIS0jNOgF6Lu5x7KpeiC/kUZKP2 kwpzH9qEyeK8xWBCkLSoImG07J89/4LTcU5qpFOfBA4ftwj1rTTn1jc/QkbQDsiz30lR6xx/2jf OBM2x7spHvCQB08NO1Vp7jzxhk2neXbWZ2Qs0w8TKf7QCWZaTSuqMNmoBxNMJylTsd5bodgYqmW anyeDw16CSogDkMzPeQ== X-Proofpoint-GUID: VBpHvLdiaMkdZMHaEiTC_VFsRRYMtKX9 X-Authority-Analysis: v=2.4 cv=Oot/DS/t c=1 sm=1 tr=0 ts=6a4b78bb cx=c_pps a=GFwsV6G8L6GxiO2Y/PsHdQ==:117 a=GFwsV6G8L6GxiO2Y/PsHdQ==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=uAbxVGIbfxUO_5tXvNgY:22 a=VnNF1IyMAAAA:8 a=Z4AAViVgUL_E5abT2tgA:9 X-Proofpoint-ORIG-GUID: VBpHvLdiaMkdZMHaEiTC_VFsRRYMtKX9 X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-06_01,2026-07-03_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 bulkscore=0 lowpriorityscore=0 clxscore=1015 impostorscore=0 phishscore=0 malwarescore=0 suspectscore=0 spamscore=0 adultscore=0 priorityscore=1501 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607060094 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.156.1; envelope-from=freude@linux.ibm.com; helo=mx0a-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783331163660158500 Content-Type: text/plain; charset="utf-8" Support the subfuctions PCKMO-Encrypt-AES-128-Key, PCKMO-Encrypt-AES-192-Key and PCKMO-Encrypt-AES-256-Key. These subfunctions derive a protected key from an AES clear key by encrypting it with an internal AES wrapping key. More details can be found in the "z/Architecture Prinziples of Operation" document. Signed-off-by: Harald Freudenberger Tested-by: Holger Dengler Reviewed-by: Finn Callies --- target/s390x/gen-features.c | 3 +++ target/s390x/tcg/cpacf.h | 4 +++ target/s390x/tcg/cpacf_aes.c | 45 ++++++++++++++++++++++++++++++++ target/s390x/tcg/crypto_helper.c | 21 +++++++++++++++ target/s390x/tcg/translate.c | 9 +++++-- 5 files changed, 80 insertions(+), 2 deletions(-) diff --git a/target/s390x/gen-features.c b/target/s390x/gen-features.c index f9b1a40c7c..d3e69aaca6 100644 --- a/target/s390x/gen-features.c +++ b/target/s390x/gen-features.c @@ -934,6 +934,9 @@ static uint16_t qemu_MAX[] =3D { S390_FEAT_KMCTR_AES_256, S390_FEAT_PCC_XTS_AES_128, S390_FEAT_PCC_XTS_AES_256, + S390_FEAT_PCKMO_AES_128, + S390_FEAT_PCKMO_AES_192, + S390_FEAT_PCKMO_AES_256, }; =20 /****** END FEATURE DEFS ******/ diff --git a/target/s390x/tcg/cpacf.h b/target/s390x/tcg/cpacf.h index df7f258443..7512c0ea4c 100644 --- a/target/s390x/tcg/cpacf.h +++ b/target/s390x/tcg/cpacf.h @@ -279,4 +279,8 @@ int cpacf_aes_xts(CPUS390XState *env, const int mmu_idx= , uintptr_t ra, 0x0F, 0x0A, 0x0C, 0x0E, 0x0F, 0x0A, 0x0C, 0x0E, \ 0x0F, 0x0A, 0x0C, 0x0E, 0x0F, 0x0A, 0x0C, 0x0E } =20 +/* from cpacf_aes.c */ +int cpacf_aes_pckmo(CPUS390XState *env, const int mmu_idx, uintptr_t ra, + uint64_t param_addr, uint8_t fc); + #endif /* S390X_CPACF_H */ diff --git a/target/s390x/tcg/cpacf_aes.c b/target/s390x/tcg/cpacf_aes.c index 6702006b66..37c616ca5c 100644 --- a/target/s390x/tcg/cpacf_aes.c +++ b/target/s390x/tcg/cpacf_aes.c @@ -500,3 +500,48 @@ static void decrypt_protkey(uint8_t *key, int keysize) key[i] ^=3D protkey_xor_pattern[i]; } } + +int cpacf_aes_pckmo(CPUS390XState *env, const int mmu_idx, uintptr_t ra, + uint64_t param_addr, uint8_t fc) +{ + const MemOpIdx oi =3D make_memop_idx(MO_8, mmu_idx); + uint8_t key[32]; + int keysize, i; + uint64_t addr; + + switch (fc) { + case CPACF_PCKMO_ENC_AES_128_KEY: + keysize =3D 16; + break; + case CPACF_PCKMO_ENC_AES_192_KEY: + keysize =3D 24; + break; + case CPACF_PCKMO_ENC_AES_256_KEY: + keysize =3D 32; + break; + default: + g_assert_not_reached(); + } + + /* fetch key from param block */ + for (i =3D 0; i < keysize; i++) { + addr =3D wrap_address(env, param_addr + i); + key[i] =3D cpu_ldb_mmu(env, addr, oi, ra); + } + + /* 'derive' the protected key from the clear key */ + encrypt_clrkey(key, keysize); + + /* store the protected key into param block */ + for (i =3D 0; i < keysize; i++) { + addr =3D wrap_address(env, param_addr + i); + cpu_stb_mmu(env, addr, key[i], oi, ra); + } + /* followed by the fake wkvp */ + for (i =3D 0; i < sizeof(protkey_wkvp); i++) { + addr =3D wrap_address(env, param_addr + keysize + i); + cpu_stb_mmu(env, addr, protkey_wkvp[i], oi, ra); + } + + return 0; +} diff --git a/target/s390x/tcg/crypto_helper.c b/target/s390x/tcg/crypto_hel= per.c index 564f7fa243..08151e916f 100644 --- a/target/s390x/tcg/crypto_helper.c +++ b/target/s390x/tcg/crypto_helper.c @@ -192,6 +192,24 @@ static int cpacf_pcc(CPUS390XState *env, const int mmu= _idx, uintptr_t ra, return rc; } =20 +static int cpacf_pckmo(CPUS390XState *env, const int mmu_idx, uintptr_t ra, + uint8_t fc) +{ + int rc =3D 0; + + switch (fc) { + case CPACF_PCKMO_ENC_AES_128_KEY: + case CPACF_PCKMO_ENC_AES_192_KEY: + case CPACF_PCKMO_ENC_AES_256_KEY: + rc =3D cpacf_aes_pckmo(env, mmu_idx, ra, env->regs[1], fc); + break; + default: + tcg_s390_program_interrupt(env, PGM_SPECIFICATION, ra); + } + + return rc; +} + uint32_t HELPER(msa)(CPUS390XState *env, uint32_t r1, uint32_t r2, uint32_= t r3, uint32_t type) { @@ -251,6 +269,9 @@ uint32_t HELPER(msa)(CPUS390XState *env, uint32_t r1, u= int32_t r2, uint32_t r3, case S390_FEAT_TYPE_PCC: rc =3D cpacf_pcc(env, mmu_idx, ra, fc); break; + case S390_FEAT_TYPE_PCKMO: + rc =3D cpacf_pckmo(env, mmu_idx, ra, fc); + break; case S390_FEAT_TYPE_PPNO: rc =3D cpacf_ppno(env, mmu_idx, ra, r1, r2, r3, fc); break; diff --git a/target/s390x/tcg/translate.c b/target/s390x/tcg/translate.c index cef1b55149..d7a99e6c1e 100644 --- a/target/s390x/tcg/translate.c +++ b/target/s390x/tcg/translate.c @@ -2558,6 +2558,7 @@ static DisasJumpType op_msa(DisasContext *s, DisasOps= *o) int r2 =3D have_field(s, r2) ? get_field(s, r2) : 0; int r3 =3D have_field(s, r3) ? get_field(s, r3) : 0; TCGv_i32 t_r1, t_r2, t_r3, type; + bool update_cc =3D true; =20 switch (s->insn->data) { case S390_FEAT_TYPE_KMA: @@ -2589,8 +2590,10 @@ static DisasJumpType op_msa(DisasContext *s, DisasOp= s *o) gen_program_exception(s, PGM_SPECIFICATION); return DISAS_NORETURN; } - /* FALL THROUGH */ + break; case S390_FEAT_TYPE_PCKMO: + update_cc =3D false; + /* FALL THROUGH */ case S390_FEAT_TYPE_PCC: case S390_FEAT_TYPE_KDSA: break; @@ -2603,7 +2606,9 @@ static DisasJumpType op_msa(DisasContext *s, DisasOps= *o) t_r3 =3D tcg_constant_i32(r3); type =3D tcg_constant_i32(s->insn->data); gen_helper_msa(cc_op, tcg_env, t_r1, t_r2, t_r3, type); - set_cc_static(s); + if (update_cc) { + set_cc_static(s); + } return DISAS_NEXT; } =20 --=20 2.43.0 From nobody Sun Jul 26 10:59:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783331218; cv=none; d=zohomail.com; s=zohoarc; b=O1tKqBesy5/B2LyH2s+G59uh5YYQnsURQuG98YtKCOjA9qfDneNLzHxUcyeG7Yow7O/A0VVnzB0JkYoWDSaYAAU2p9G6q4UK1QqBVy5xoEjnXxMbpQlnLKfB2UKYSFudM4HYW225o6C3ndCdz+zDLkQhIRTNarx4jiCMlU4vU8Q= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783331218; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=fGK4vzmR98dM3k81eGaJ1Lj2CARSQVwiNYxFZKtTMf4=; b=YuNBpTPOdiScQU4HN8NV9AEqROo3wxPpl3ylDae2qYPpUH84NFsDrH3ixmv5+iiIhuihYy/qTNR/NSWTECV6hu5LtD/fdj0DDO8v4ixjzHUpbA9VSZ04wfFtL+lvum9QyO6VG/keCcga0c2GrgJ+stP2lykI+bdl50ISxc1bN78= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783331218132419.57283176645933; Mon, 6 Jul 2026 02:46:58 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wgfrc-0004Jk-PQ; Mon, 06 Jul 2026 05:43:44 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrU-0004EY-MQ; Mon, 06 Jul 2026 05:43:36 -0400 Received: from mx0a-001b2d01.pphosted.com ([148.163.156.1]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrP-0003yA-M3; Mon, 06 Jul 2026 05:43:36 -0400 Received: from pps.filterd (m0353729.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 6669IELp4014985; Mon, 6 Jul 2026 09:43:23 GMT Received: from ppma22.wdc07v.mail.ibm.com (5c.69.3da9.ip4.static.sl-reverse.com [169.61.105.92]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f6suqgp85-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:23 +0000 (GMT) Received: from pps.filterd (ppma22.wdc07v.mail.ibm.com [127.0.0.1]) by ppma22.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 6669Yf6P006450; Mon, 6 Jul 2026 09:43:22 GMT Received: from smtprelay05.fra02v.mail.ibm.com ([9.218.2.225]) by ppma22.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4f7cvvw57c-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:22 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (smtpav07.fra02v.mail.ibm.com [10.20.54.106]) by smtprelay05.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 6669hI4P46727532 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Mon, 6 Jul 2026 09:43:18 GMT Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 6817220040; Mon, 6 Jul 2026 09:43:18 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 421892004B; Mon, 6 Jul 2026 09:43:18 +0000 (GMT) Received: from funtu2.ibm.com (unknown [9.111.193.81]) by smtpav07.fra02v.mail.ibm.com (Postfix) with ESMTP; Mon, 6 Jul 2026 09:43:18 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=fGK4vzmR98dM3k81e GaJ1Lj2CARSQVwiNYxFZKtTMf4=; b=SIKaC0WpGKsHaFKsot3ItzEtUnad57m5g pJ4Fm+pfmJXpf8R7wFaHJSnYejbgU+z8eI4T2W8pd8AcjAAQnuWuz/+k1PpQvFsV Mh1VnMd/4bYQWYhGw1hzRQZxIoVNGr28mpdCmT3qtyLtpMoAYJ+B0dYRBIjyHNIp vr/+Oj1K0pVtCAF/1UeCOGsdod7Be+B8kVnJ1JyH6lW8PZdMyR8XKRcdJhDxmjEK YQQ8DtmnSFq0w3GqcqJJ9aMrCOgpbeWdctjC1dzhbpbM7dHW/RXvMFlYtigdaoqS PBTTvhY/96gxRBNrmHUbhnDOSVOzEnRcbBZdOP3UPwo4kZ1zwpisA== From: Harald Freudenberger To: richard.henderson@linaro.org, iii@linux.ibm.com, david@kernel.org, thuth@redhat.com, berrange@redhat.com Cc: qemu-s390x@nongnu.org, qemu-devel@nongnu.org, linux-s390@vger.kernel.org, dengler@linux.ibm.com, borntraeger@linux.ibm.com, fcallies@linux.ibm.com, cohuck@redhat.com Subject: [PATCH v10 12/21] target/s390x: Support protected key AES ECB for cpacf km instruction Date: Mon, 6 Jul 2026 11:43:05 +0200 Message-ID: <20260706094317.17032-13-freude@linux.ibm.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260706094317.17032-1-freude@linux.ibm.com> References: <20260706094317.17032-1-freude@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Spam-Info: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfX5b5chHtnZ/1w 0Y+HR/3zm6ZVKlS9u2xeXI9TM4it1AyBmFhI0+q6qeUjLDLpJfA24nqsMHGDE57Ib824M2NahcR d62WUcdaFWFFYhdC+bx5aMKWWIfLMn4= X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfXwRA6KNibi3A2 ngmVt3aVxubUB5pQHHx+KbftQ75EsG8hRgjin65k1TWQBk3kF+WY523ZdM16/ARfmGk2eAKLjR8 w9r/0mACvSmf84wf4VvVUzGGDOfy43nGLyzZRuII+SduhV/4Z7vDDRqz46WL2MAUDIDYNkrhKYw WyXhhj4K4Bv8GJgMuA9OUdADtTgR36/bkHZ7HuxTYPVlsm/xXL1JHD4tHcSUFuuySO5YMO/hVpw 7Ufd5WhQFvUsnH+3j9O0T6LOlyWeGNQoWnGS/aa3acATdmElFXR+xGh/MxDs4Ek62FR24XvrPv5 ZpnTNcud+jqT+PytYMGzODr0YgZsD4cTtFlE6NytHKXiED9sms1SvDdm+KQXkt347RKIME+oy9Z +ItRJqQBeIByN+hoe13qXnI35t641CQfcFPz1vu8kRSQOx/xEmdaidEbn3OkbVFUIN/ovuk5LjS WeLlCZc3jEFPuOk016A== X-Proofpoint-GUID: OlGIvxqc4IQqvHt7e-WXGxyp2YHM_6ee X-Authority-Analysis: v=2.4 cv=Oot/DS/t c=1 sm=1 tr=0 ts=6a4b78bb cx=c_pps a=5BHTudwdYE3Te8bg5FgnPg==:117 a=5BHTudwdYE3Te8bg5FgnPg==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=uAbxVGIbfxUO_5tXvNgY:22 a=VnNF1IyMAAAA:8 a=WpPIafo2g3WOFiBud6QA:9 X-Proofpoint-ORIG-GUID: OlGIvxqc4IQqvHt7e-WXGxyp2YHM_6ee X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-06_01,2026-07-03_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 bulkscore=0 lowpriorityscore=0 clxscore=1015 impostorscore=0 phishscore=0 malwarescore=0 suspectscore=0 spamscore=0 adultscore=0 priorityscore=1501 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607060094 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.156.1; envelope-from=freude@linux.ibm.com; helo=mx0a-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783331219814158500 Content-Type: text/plain; charset="utf-8" Support the subfunctions CPACF_KM_PAES_128, CPACF_KM_PAES_192 and CPACF_KM_PAES_256 for the cpacf km instruction. Tested-by: Holger Dengler Reviewed-by: Finn Callies Signed-off-by: Harald Freudenberger --- target/s390x/gen-features.c | 3 ++ target/s390x/tcg/cpacf.h | 4 ++ target/s390x/tcg/cpacf_aes.c | 86 ++++++++++++++++++++++++++++++++ target/s390x/tcg/crypto_helper.c | 7 +++ 4 files changed, 100 insertions(+) diff --git a/target/s390x/gen-features.c b/target/s390x/gen-features.c index d3e69aaca6..71e0e41d6e 100644 --- a/target/s390x/gen-features.c +++ b/target/s390x/gen-features.c @@ -924,6 +924,9 @@ static uint16_t qemu_MAX[] =3D { S390_FEAT_KM_AES_128, S390_FEAT_KM_AES_192, S390_FEAT_KM_AES_256, + S390_FEAT_KM_EAES_128, + S390_FEAT_KM_EAES_192, + S390_FEAT_KM_EAES_256, S390_FEAT_KM_XTS_AES_128, S390_FEAT_KM_XTS_AES_256, S390_FEAT_KMC_AES_128, diff --git a/target/s390x/tcg/cpacf.h b/target/s390x/tcg/cpacf.h index 7512c0ea4c..cc545fb703 100644 --- a/target/s390x/tcg/cpacf.h +++ b/target/s390x/tcg/cpacf.h @@ -282,5 +282,9 @@ int cpacf_aes_xts(CPUS390XState *env, const int mmu_idx= , uintptr_t ra, /* from cpacf_aes.c */ int cpacf_aes_pckmo(CPUS390XState *env, const int mmu_idx, uintptr_t ra, uint64_t param_addr, uint8_t fc); +int cpacf_paes_ecb(CPUS390XState *env, const int mmu_idx, uintptr_t ra, + uint64_t param_addr, uint64_t *dst_ptr_reg, + uint64_t *src_ptr_reg, uint64_t *src_len_reg, + uint32_t type, uint8_t fc, uint8_t mod); =20 #endif /* S390X_CPACF_H */ diff --git a/target/s390x/tcg/cpacf_aes.c b/target/s390x/tcg/cpacf_aes.c index 37c616ca5c..b7f1dc99e9 100644 --- a/target/s390x/tcg/cpacf_aes.c +++ b/target/s390x/tcg/cpacf_aes.c @@ -545,3 +545,89 @@ int cpacf_aes_pckmo(CPUS390XState *env, const int mmu_= idx, uintptr_t ra, =20 return 0; } + +int cpacf_paes_ecb(CPUS390XState *env, const int mmu_idx, uintptr_t ra, + uint64_t param_addr, uint64_t *dst_ptr_reg, + uint64_t *src_ptr_reg, uint64_t *src_len_reg, + uint32_t type, uint8_t fc, uint8_t mod) +{ + enum { MAX_BLOCKS_PER_RUN =3D 8192 / AES_BLOCK_SIZE }; + const MemOpIdx oi =3D make_memop_idx(MO_8, mmu_idx); + uint8_t in[AES_BLOCK_SIZE], out[AES_BLOCK_SIZE]; + uint64_t addr, len =3D *src_len_reg, done =3D 0; + int i, keysize, addr_reg_size =3D 64; + uint8_t key[32], wkvp[32]; + AES_KEY exkey; + + g_assert(type =3D=3D S390_FEAT_TYPE_KM); + + switch (fc) { + case CPACF_KM_PAES_128: + keysize =3D 16; + break; + case CPACF_KM_PAES_192: + keysize =3D 24; + break; + case CPACF_KM_PAES_256: + keysize =3D 32; + break; + default: + g_assert_not_reached(); + } + + if (!(env->psw.mask & PSW_MASK_64)) { + len =3D (uint32_t)len; + addr_reg_size =3D (env->psw.mask & PSW_MASK_32) ? 32 : 24; + } + + /* length has to be properly aligned. */ + if (!QEMU_IS_ALIGNED(len, AES_BLOCK_SIZE)) { + tcg_s390_program_interrupt(env, PGM_SPECIFICATION, ra); + } + + /* fetch and check wkvp from param block */ + for (i =3D 0; i < sizeof(wkvp); i++) { + addr =3D wrap_address(env, param_addr + keysize + i); + wkvp[i] =3D cpu_ldb_mmu(env, addr, oi, ra); + } + if (memcmp(wkvp, protkey_wkvp, sizeof(wkvp))) { + /* wkvp mismatch -> return with cc 1 */ + return 1; + } + + /* fetch protected key from param block */ + for (i =3D 0; i < keysize; i++) { + addr =3D wrap_address(env, param_addr + i); + key[i] =3D cpu_ldb_mmu(env, addr, oi, ra); + } + /* decrypt the protected key */ + decrypt_protkey(key, keysize); + + /* expand key */ + if (mod) { + AES_set_decrypt_key(key, keysize * 8, &exkey); + } else { + AES_set_encrypt_key(key, keysize * 8, &exkey); + } + + /* process up to MAX_BLOCKS_PER_RUN aes blocks */ + for (i =3D 0; i < MAX_BLOCKS_PER_RUN && len >=3D AES_BLOCK_SIZE; i++) { + aes_read_block(env, mmu_idx, *src_ptr_reg + done, in, ra); + if (mod) { + AES_decrypt(in, out, &exkey); + } else { + AES_encrypt(in, out, &exkey); + } + aes_write_block(env, mmu_idx, *dst_ptr_reg + done, out, ra); + len -=3D AES_BLOCK_SIZE; + done +=3D AES_BLOCK_SIZE; + } + + *src_ptr_reg =3D deposit64(*src_ptr_reg, 0, addr_reg_size, + *src_ptr_reg + done); + *dst_ptr_reg =3D deposit64(*dst_ptr_reg, 0, addr_reg_size, + *dst_ptr_reg + done); + *src_len_reg -=3D done; + + return !len ? 0 : 3; +} diff --git a/target/s390x/tcg/crypto_helper.c b/target/s390x/tcg/crypto_hel= per.c index 08151e916f..b00351d8c1 100644 --- a/target/s390x/tcg/crypto_helper.c +++ b/target/s390x/tcg/crypto_helper.c @@ -103,6 +103,13 @@ static int cpacf_km(CPUS390XState *env, const int mmu_= idx, uintptr_t ra, &env->regs[r1], &env->regs[r2], &env->regs[r2 += 1], S390_FEAT_TYPE_KM, fc, mod); break; + case CPACF_KM_PAES_128: + case CPACF_KM_PAES_192: + case CPACF_KM_PAES_256: + rc =3D cpacf_paes_ecb(env, mmu_idx, ra, env->regs[1], + &env->regs[r1], &env->regs[r2], &env->regs[r2 = + 1], + S390_FEAT_TYPE_KM, fc, mod); + break; case CPACF_KM_XTS_128: case CPACF_KM_XTS_256: rc =3D cpacf_aes_xts(env, mmu_idx, ra, env->regs[1], --=20 2.43.0 From nobody Sun Jul 26 10:59:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783331149; cv=none; d=zohomail.com; s=zohoarc; b=nnLVcRsRPM5EZHk38Oz49iov18h8XdsDOAuvigKoDja7FyKkZvbEhDgKzRXUJidU1ZwpJvV0W9x3ar/d1HXodlh11Jy5i4iPik92wcBlgbP9je3nRQvP1dkKqgItygvp7iUeN3DhdQntiAry486yoSBmG6wsz4EmS89XqB+7+J4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783331149; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=EUxSq0ch+fjod2kbFSmYLduJjGhTs+iBHG49KqeoWs0=; b=WF2QjrlIrVW4PArMwuVxUuRu/HCX7lpeuMdLHJwAO3BTM1QoAwvqr4o9ZjomcLdIvjB308bfNYMImeuDuVkA8I+JjKpxLqGy83LZPYigPNXca/6DPwdOMuasD72bXfBXiT00h/w8CAxBO54IVX4RJi43V+pEqq2wdvcSEpuwwgM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783331149074875.9763396577001; Mon, 6 Jul 2026 02:45:49 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wgfrX-0004Gr-II; Mon, 06 Jul 2026 05:43:39 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrT-0004CV-9E; Mon, 06 Jul 2026 05:43:35 -0400 Received: from mx0b-001b2d01.pphosted.com ([148.163.158.5]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrP-0003xo-IE; Mon, 06 Jul 2026 05:43:34 -0400 Received: from pps.filterd (m0356516.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 6669IT6U3826471; Mon, 6 Jul 2026 09:43:23 GMT Received: from ppma23.wdc07v.mail.ibm.com (5d.69.3da9.ip4.static.sl-reverse.com [169.61.105.93]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f6qkn8vjd-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:23 +0000 (GMT) Received: from pps.filterd (ppma23.wdc07v.mail.ibm.com [127.0.0.1]) by ppma23.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 6669YhfV005904; Mon, 6 Jul 2026 09:43:22 GMT Received: from smtprelay05.fra02v.mail.ibm.com ([9.218.2.225]) by ppma23.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4f7e0h4w48-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:22 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (smtpav07.fra02v.mail.ibm.com [10.20.54.106]) by smtprelay05.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 6669hIlU38470024 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Mon, 6 Jul 2026 09:43:18 GMT Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 92D062004B; Mon, 6 Jul 2026 09:43:18 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 6C96620043; Mon, 6 Jul 2026 09:43:18 +0000 (GMT) Received: from funtu2.ibm.com (unknown [9.111.193.81]) by smtpav07.fra02v.mail.ibm.com (Postfix) with ESMTP; Mon, 6 Jul 2026 09:43:18 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=EUxSq0ch+fjod2kbF SmYLduJjGhTs+iBHG49KqeoWs0=; b=ag9AcoJyXbgE33MswTcBmAIRqzQjK126K 6/tkoaNvvbsKJo96A31UDHBELopba2GYiNkVWuKw+AXM+UL6b/6ZdEmi87ahOiSt 1Y7hY8wVpJuYDdxEaSNRPrB4M5KYF3cQiik/iJQVjxuKiOKBcoZUUqF7Sy6NmZRO C/TIkpzI8lF8TycxbzKXJxpEDxnyk9YXrw03zAKfQhQBg3tGHEHQa97VTQrS4l9g AA2zOloYDf+tasw1H4adCFu4U8AiFLGvZ9/ETVfaaHKdYoUSeQlbwxi0PiyEtckc BlZ4Yn6nZ3Oo3YaoGkbU8u6ATcep51Tc5fA2stBLXM/j/p2LAEXlA== From: Harald Freudenberger To: richard.henderson@linaro.org, iii@linux.ibm.com, david@kernel.org, thuth@redhat.com, berrange@redhat.com Cc: qemu-s390x@nongnu.org, qemu-devel@nongnu.org, linux-s390@vger.kernel.org, dengler@linux.ibm.com, borntraeger@linux.ibm.com, fcallies@linux.ibm.com, cohuck@redhat.com Subject: [PATCH v10 13/21] target/s390x: Support protected key AES CBC for cpacf kmc instruction Date: Mon, 6 Jul 2026 11:43:06 +0200 Message-ID: <20260706094317.17032-14-freude@linux.ibm.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260706094317.17032-1-freude@linux.ibm.com> References: <20260706094317.17032-1-freude@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Authority-Analysis: v=2.4 cv=Q/XiJY2a c=1 sm=1 tr=0 ts=6a4b78bb cx=c_pps a=3Bg1Hr4SwmMryq2xdFQyZA==:117 a=3Bg1Hr4SwmMryq2xdFQyZA==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=Y2IxJ9c9Rs8Kov3niI8_:22 a=VnNF1IyMAAAA:8 a=1XR5bUzyU_lZOmb26nMA:9 X-Proofpoint-GUID: c9SJBVSLJqirDN2ibj2Ut_GVROipuMuy X-Proofpoint-ORIG-GUID: c9SJBVSLJqirDN2ibj2Ut_GVROipuMuy X-Proofpoint-Spam-Info: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfXyzmkQLFhNjCP HFm8vw8GylS1zJt1vR2P3QsN26r+XDaP2uk1mPTHJFgQJpQ3eLXZNdbmD0yFMMhb/R6Ni6e2kh2 jCFj3jkfheCeuVHE5FDPFKobBXTDlFk= X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfXz9BTak8eYb0v 3SLyaVq7JtmL/7SogpZZyuUM3MRd7KNtqf2VlzXj0rfo6E1qfMw5xJ8FU7CANZzzmI6cvEHswCh LeZu9YB3NXyEJyUp3ZVkBSKNKOBG5fctjm0pNs8Z/Y/0hrw5cFozK7/0L4jOk6V3KT0z5q28zLf 7ilReQ94V/T0WsCO6jWDMHOOP8PQdNreDwEY8ezD7XprczynqitCfvaWDLRLyMP0KuTCNTHVWPf D3a9dSpZTFIhGrdJyespNTj1queWgo70uGlReG6nO4xomz5CxgWvodoEIUwf0+udO5ARjxIVZFN YQBOu/o11PdYhfSSl70OWIRERAiPN+w4xtu0dHzNGfa6mthPlb28kumhSy2t8zqs7CJ/thWwE7Y y33ZXqXKFS8tPr1MlLDFtgw56BiGEDfe/hcvuk1VvT8Y8CpspZ9YGxX6ZNilHNTD6Na6juIcpfN 5ye+YBjKPkMbfYrrm+g== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-06_01,2026-07-03_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 adultscore=0 impostorscore=0 spamscore=0 phishscore=0 priorityscore=1501 bulkscore=0 clxscore=1015 lowpriorityscore=0 suspectscore=0 malwarescore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607060094 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.158.5; envelope-from=freude@linux.ibm.com; helo=mx0b-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783331149408158500 Content-Type: text/plain; charset="utf-8" Support the subfunctions CPACF_KMC_PAES_128, CPACF_KMC_PAES_192 and CPACF_KMC_PAES_256 for the cpacf kmc instruction. Tested-by: Holger Dengler Reviewed-by: Finn Callies Signed-off-by: Harald Freudenberger --- target/s390x/gen-features.c | 3 + target/s390x/tcg/cpacf.h | 4 ++ target/s390x/tcg/cpacf_aes.c | 108 +++++++++++++++++++++++++++++++ target/s390x/tcg/crypto_helper.c | 7 ++ 4 files changed, 122 insertions(+) diff --git a/target/s390x/gen-features.c b/target/s390x/gen-features.c index 71e0e41d6e..074c53aecd 100644 --- a/target/s390x/gen-features.c +++ b/target/s390x/gen-features.c @@ -932,6 +932,9 @@ static uint16_t qemu_MAX[] =3D { S390_FEAT_KMC_AES_128, S390_FEAT_KMC_AES_192, S390_FEAT_KMC_AES_256, + S390_FEAT_KMC_EAES_128, + S390_FEAT_KMC_EAES_192, + S390_FEAT_KMC_EAES_256, S390_FEAT_KMCTR_AES_128, S390_FEAT_KMCTR_AES_192, S390_FEAT_KMCTR_AES_256, diff --git a/target/s390x/tcg/cpacf.h b/target/s390x/tcg/cpacf.h index cc545fb703..b0d484c3cb 100644 --- a/target/s390x/tcg/cpacf.h +++ b/target/s390x/tcg/cpacf.h @@ -286,5 +286,9 @@ int cpacf_paes_ecb(CPUS390XState *env, const int mmu_id= x, uintptr_t ra, uint64_t param_addr, uint64_t *dst_ptr_reg, uint64_t *src_ptr_reg, uint64_t *src_len_reg, uint32_t type, uint8_t fc, uint8_t mod); +int cpacf_paes_cbc(CPUS390XState *env, const int mmu_idx, uintptr_t ra, + uint64_t param_addr, uint64_t *dst_ptr_reg, + uint64_t *src_ptr_reg, uint64_t *src_len_reg, + uint32_t type, uint8_t fc, uint8_t mod); =20 #endif /* S390X_CPACF_H */ diff --git a/target/s390x/tcg/cpacf_aes.c b/target/s390x/tcg/cpacf_aes.c index b7f1dc99e9..bb3488e38f 100644 --- a/target/s390x/tcg/cpacf_aes.c +++ b/target/s390x/tcg/cpacf_aes.c @@ -631,3 +631,111 @@ int cpacf_paes_ecb(CPUS390XState *env, const int mmu_= idx, uintptr_t ra, =20 return !len ? 0 : 3; } + +int cpacf_paes_cbc(CPUS390XState *env, const int mmu_idx, uintptr_t ra, + uint64_t param_addr, uint64_t *dst_ptr_reg, + uint64_t *src_ptr_reg, uint64_t *src_len_reg, + uint32_t type, uint8_t fc, uint8_t mod) +{ + enum { MAX_BLOCKS_PER_RUN =3D 8192 / AES_BLOCK_SIZE }; + uint8_t in[AES_BLOCK_SIZE], out[AES_BLOCK_SIZE], buf[AES_BLOCK_SIZE]; + const MemOpIdx oi =3D make_memop_idx(MO_8, mmu_idx); + uint8_t key[32], wkvp[32], iv[AES_BLOCK_SIZE]; + uint64_t addr, len =3D *src_len_reg, done =3D 0; + int i, keysize, addr_reg_size =3D 64; + AES_KEY exkey; + + g_assert(type =3D=3D S390_FEAT_TYPE_KMC); + + switch (fc) { + case CPACF_KMC_PAES_128: + keysize =3D 16; + break; + case CPACF_KMC_PAES_192: + keysize =3D 24; + break; + case CPACF_KMC_PAES_256: + keysize =3D 32; + break; + default: + g_assert_not_reached(); + } + + if (!(env->psw.mask & PSW_MASK_64)) { + len =3D (uint32_t)len; + addr_reg_size =3D (env->psw.mask & PSW_MASK_32) ? 32 : 24; + } + + /* length has to be properly aligned. */ + if (!QEMU_IS_ALIGNED(len, AES_BLOCK_SIZE)) { + tcg_s390_program_interrupt(env, PGM_SPECIFICATION, ra); + } + + /* fetch and check wkvp from param block */ + for (i =3D 0; i < sizeof(wkvp); i++) { + addr =3D wrap_address(env, param_addr + AES_BLOCK_SIZE + keysize += i); + wkvp[i] =3D cpu_ldb_mmu(env, addr, oi, ra); + } + if (memcmp(wkvp, protkey_wkvp, sizeof(wkvp))) { + /* wkvp mismatch -> return with cc 1 */ + return 1; + } + + /* fetch iv from param block */ + for (i =3D 0; i < AES_BLOCK_SIZE; i++) { + addr =3D wrap_address(env, param_addr + i); + iv[i] =3D cpu_ldb_mmu(env, addr, oi, ra); + } + + /* fetch protected key from param block */ + for (i =3D 0; i < keysize; i++) { + addr =3D wrap_address(env, param_addr + AES_BLOCK_SIZE + i); + key[i] =3D cpu_ldb_mmu(env, addr, oi, ra); + } + /* decrypt the protected key */ + decrypt_protkey(key, keysize); + + /* expand key */ + if (mod) { + AES_set_decrypt_key(key, keysize * 8, &exkey); + } else { + AES_set_encrypt_key(key, keysize * 8, &exkey); + } + + /* process up to MAX_BLOCKS_PER_RUN aes blocks */ + for (i =3D 0; i < MAX_BLOCKS_PER_RUN && len >=3D AES_BLOCK_SIZE; i++) { + aes_read_block(env, mmu_idx, *src_ptr_reg + done, in, ra); + if (mod) { + /* decrypt in =3D> buf */ + AES_decrypt(in, buf, &exkey); + /* buf xor iv =3D> out */ + aes_xor(buf, iv, out); + /* prep iv for next round */ + memcpy(iv, in, AES_BLOCK_SIZE); + } else { + /* in xor iv =3D> buf */ + aes_xor(in, iv, buf); + /* encrypt buf =3D> out */ + AES_encrypt(buf, out, &exkey); + /* prep iv for next round */ + memcpy(iv, out, AES_BLOCK_SIZE); + } + aes_write_block(env, mmu_idx, *dst_ptr_reg + done, out, ra); + len -=3D AES_BLOCK_SIZE; + done +=3D AES_BLOCK_SIZE; + } + + /* update iv in param block */ + for (i =3D 0; i < AES_BLOCK_SIZE; i++) { + addr =3D wrap_address(env, param_addr + i); + cpu_stb_mmu(env, addr, iv[i], oi, ra); + } + + *src_ptr_reg =3D deposit64(*src_ptr_reg, 0, addr_reg_size, + *src_ptr_reg + done); + *dst_ptr_reg =3D deposit64(*dst_ptr_reg, 0, addr_reg_size, + *dst_ptr_reg + done); + *src_len_reg -=3D done; + + return !len ? 0 : 3; +} diff --git a/target/s390x/tcg/crypto_helper.c b/target/s390x/tcg/crypto_hel= per.c index b00351d8c1..237ce744b7 100644 --- a/target/s390x/tcg/crypto_helper.c +++ b/target/s390x/tcg/crypto_helper.c @@ -137,6 +137,13 @@ static int cpacf_kmc(CPUS390XState *env, const int mmu= _idx, uintptr_t ra, &env->regs[r1], &env->regs[r2], &env->regs[r2 += 1], S390_FEAT_TYPE_KMC, fc, mod); break; + case CPACF_KMC_PAES_128: + case CPACF_KMC_PAES_192: + case CPACF_KMC_PAES_256: + rc =3D cpacf_paes_cbc(env, mmu_idx, ra, env->regs[1], + &env->regs[r1], &env->regs[r2], &env->regs[r2 = + 1], + S390_FEAT_TYPE_KMC, fc, mod); + break; default: tcg_s390_program_interrupt(env, PGM_SPECIFICATION, ra); } --=20 2.43.0 From nobody Sun Jul 26 10:59:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783331061; cv=none; d=zohomail.com; s=zohoarc; b=J/v+ag2jtjPtexS3tdfADYFcJkKNtGX34ZXajNtkfjAxS/zgraHAxq5MnewwhGHFaYTU9wFL9RxiLRjalMtYIs2lU96khrA3Nkoa/aNbqYnYCQH2fKG/Jf2sWGGKU2zF3sGqiCbC2Xb2mdz0bASUGTO6prv5Zr9NMdP0aRaDxsU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783331061; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=2bRnNmzn8zKV9kO1+0GIK5NM2b/Ji9wu7DWH+5dYf3g=; b=QS7A6A/Lvvq41o6OJsgnydrYYZyitei7pb/8caBCa791ZLYSrIBIwhPmETcw/pOcAvkVEiEzrP4qtDomDAIwsUPdv5nwU4p9FDy/AJupspLcPlsMCxYPlnnQ8sTFTLdlUqJZkwYM5qufiLzwm3MD/t5DB8fN7sNBeTopIzCu+uo= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783331061343608.9621689476917; Mon, 6 Jul 2026 02:44:21 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wgfra-0004I0-A4; Mon, 06 Jul 2026 05:43:42 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrU-0004EE-GR; Mon, 06 Jul 2026 05:43:36 -0400 Received: from mx0b-001b2d01.pphosted.com ([148.163.158.5]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrP-0003y8-ML; Mon, 06 Jul 2026 05:43:36 -0400 Received: from pps.filterd (m0356516.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 6669ILbT3826404; Mon, 6 Jul 2026 09:43:23 GMT Received: from ppma21.wdc07v.mail.ibm.com (5b.69.3da9.ip4.static.sl-reverse.com [169.61.105.91]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f6qkn8vjf-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:23 +0000 (GMT) Received: from pps.filterd (ppma21.wdc07v.mail.ibm.com [127.0.0.1]) by ppma21.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 6669Yaqi028290; Mon, 6 Jul 2026 09:43:22 GMT Received: from smtprelay05.fra02v.mail.ibm.com ([9.218.2.225]) by ppma21.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4f7dgjw0gx-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:22 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (smtpav07.fra02v.mail.ibm.com [10.20.54.106]) by smtprelay05.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 6669hIkB38470026 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Mon, 6 Jul 2026 09:43:18 GMT Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id BD52320043; Mon, 6 Jul 2026 09:43:18 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 978EA20040; Mon, 6 Jul 2026 09:43:18 +0000 (GMT) Received: from funtu2.ibm.com (unknown [9.111.193.81]) by smtpav07.fra02v.mail.ibm.com (Postfix) with ESMTP; Mon, 6 Jul 2026 09:43:18 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=2bRnNmzn8zKV9kO1+ 0GIK5NM2b/Ji9wu7DWH+5dYf3g=; b=dxDAOB/5DP848SDktzCGcVyT6iq54qIZL WRYWSSufW8mYoSALwSlgQ5BkWnnNcN9zbt4+gaXznQzJR0vuO05DRlLu29oHldEN NIDhw2LdAYstTwFr3Lca2cDtuoZTDOelmmgknQdDex/yRkDOkMCePLxrzSGeK5h/ xuOodsYWSF4xwxyI2vUHu/Ch+rhPNdoLSQH5YK2cnyJ6qNMsa40P37kVszjsQZhr OIn6lPve9X1lgMLJlMoN6cpSyOj+aGUQu1mctrv6ElsCPZz439mYWAYWaIWR90pr +yy6XHl1i6vwAzxhpavgShuwjIRLwVGqSha08qDE57UNQT2WaUYnw== From: Harald Freudenberger To: richard.henderson@linaro.org, iii@linux.ibm.com, david@kernel.org, thuth@redhat.com, berrange@redhat.com Cc: qemu-s390x@nongnu.org, qemu-devel@nongnu.org, linux-s390@vger.kernel.org, dengler@linux.ibm.com, borntraeger@linux.ibm.com, fcallies@linux.ibm.com, cohuck@redhat.com Subject: [PATCH v10 14/21] target/s390x: Support protected key AES CTR for cpacf kmctr instruction Date: Mon, 6 Jul 2026 11:43:07 +0200 Message-ID: <20260706094317.17032-15-freude@linux.ibm.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260706094317.17032-1-freude@linux.ibm.com> References: <20260706094317.17032-1-freude@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Authority-Analysis: v=2.4 cv=Q/XiJY2a c=1 sm=1 tr=0 ts=6a4b78bb cx=c_pps a=GFwsV6G8L6GxiO2Y/PsHdQ==:117 a=GFwsV6G8L6GxiO2Y/PsHdQ==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=Y2IxJ9c9Rs8Kov3niI8_:22 a=VnNF1IyMAAAA:8 a=f59o6tnjY-_5Ge3baHwA:9 X-Proofpoint-GUID: OtvpYnvHd_xmYBE_erGlscQhPw0cWkA_ X-Proofpoint-ORIG-GUID: OtvpYnvHd_xmYBE_erGlscQhPw0cWkA_ X-Proofpoint-Spam-Info: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfXyD3WNUb5mSbY zsz+77e2W9oAKkXv4ldSiLRF7BP+nrToQY2+xpZiV8j8MHFMl+g0MQ5rgz8HAoCDCHdPA6YMPRD sfsrlFHoEEJQ+8RdPO8wttcB4+uWCMQ= X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfXzffylNnHL+TB uGLbPNBP+oM/kajLGo8UbKtz5subfrXzpUkGz2jpS5lxY8M+OHFYXTAkE/5wMB3UNHdN+6AjzSa onDf9lF+3rMzyYfyRD3ggII4dZQqpD5tlw2z6Lncidri5XVAEdGKBWJdVAdVV/roDhnXFdjJX5q qi07TLcrREWm4k+Xk+bNQMAip8H1cZvY4g7KbtWonwZajNbqeM3op+xXSZDnofnmeWBFAeBQGuv hnrjEJuxk16Jm599as1FbOTBKy5lSc1oIEFWwIQNfPhprfBlgCKJWeAz2JW8b9AmQmWO7XdN9Q/ AbiXd8wMoYcabKbQRrtUGlihd6/VCXXZbpYfPCNSrp90mkVqobELRKSDHtx6UytR6B+RGVojMa0 EGlTIBxws6aedgx4bWoYntyuAh4mVnyLok7IxdMLB7/z7DgyB7WrJPL+uEjLLgzgwu0Mp6ngd+P IM2VdOXKFme6t429gTw== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-06_01,2026-07-03_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 adultscore=0 impostorscore=0 spamscore=0 phishscore=0 priorityscore=1501 bulkscore=0 clxscore=1015 lowpriorityscore=0 suspectscore=0 malwarescore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607060094 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.158.5; envelope-from=freude@linux.ibm.com; helo=mx0b-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783331063107158500 Content-Type: text/plain; charset="utf-8" Support the subfunctions CPACF_KMCTR_PAES_128, CPACF_KMCTR_PAES_192 and CPACF_KMCTR_PAES_256 for the cpacf kmctr instruction. Signed-off-by: Harald Freudenberger --- target/s390x/gen-features.c | 3 ++ target/s390x/tcg/cpacf.h | 5 ++ target/s390x/tcg/cpacf_aes.c | 89 ++++++++++++++++++++++++++++++++ target/s390x/tcg/crypto_helper.c | 7 +++ 4 files changed, 104 insertions(+) diff --git a/target/s390x/gen-features.c b/target/s390x/gen-features.c index 074c53aecd..4a131dc191 100644 --- a/target/s390x/gen-features.c +++ b/target/s390x/gen-features.c @@ -938,6 +938,9 @@ static uint16_t qemu_MAX[] =3D { S390_FEAT_KMCTR_AES_128, S390_FEAT_KMCTR_AES_192, S390_FEAT_KMCTR_AES_256, + S390_FEAT_KMCTR_EAES_128, + S390_FEAT_KMCTR_EAES_192, + S390_FEAT_KMCTR_EAES_256, S390_FEAT_PCC_XTS_AES_128, S390_FEAT_PCC_XTS_AES_256, S390_FEAT_PCKMO_AES_128, diff --git a/target/s390x/tcg/cpacf.h b/target/s390x/tcg/cpacf.h index b0d484c3cb..6071f21fb6 100644 --- a/target/s390x/tcg/cpacf.h +++ b/target/s390x/tcg/cpacf.h @@ -290,5 +290,10 @@ int cpacf_paes_cbc(CPUS390XState *env, const int mmu_i= dx, uintptr_t ra, uint64_t param_addr, uint64_t *dst_ptr_reg, uint64_t *src_ptr_reg, uint64_t *src_len_reg, uint32_t type, uint8_t fc, uint8_t mod); +int cpacf_paes_ctr(CPUS390XState *env, const int mmu_idx, uintptr_t ra, + uint64_t param_addr, uint64_t *dst_ptr_reg, + uint64_t *src_ptr_reg, uint64_t *src_len_reg, + uint64_t *ctr_ptr_reg, uint32_t type, + uint8_t fc, uint8_t mod); =20 #endif /* S390X_CPACF_H */ diff --git a/target/s390x/tcg/cpacf_aes.c b/target/s390x/tcg/cpacf_aes.c index bb3488e38f..c52df6510f 100644 --- a/target/s390x/tcg/cpacf_aes.c +++ b/target/s390x/tcg/cpacf_aes.c @@ -739,3 +739,92 @@ int cpacf_paes_cbc(CPUS390XState *env, const int mmu_i= dx, uintptr_t ra, =20 return !len ? 0 : 3; } + +int cpacf_paes_ctr(CPUS390XState *env, const int mmu_idx, uintptr_t ra, + uint64_t param_addr, uint64_t *dst_ptr_reg, + uint64_t *src_ptr_reg, uint64_t *src_len_reg, + uint64_t *ctr_ptr_reg, uint32_t type, + uint8_t fc, uint8_t mod) +{ + enum { MAX_BLOCKS_PER_RUN =3D 8192 / AES_BLOCK_SIZE }; + const MemOpIdx oi =3D make_memop_idx(MO_8, mmu_idx); + uint8_t ctr[AES_BLOCK_SIZE], buf[AES_BLOCK_SIZE]; + uint8_t in[AES_BLOCK_SIZE], out[AES_BLOCK_SIZE]; + uint64_t addr, len =3D *src_len_reg, done =3D 0; + int i, keysize, addr_reg_size =3D 64; + uint8_t key[32], wkvp[32]; + AES_KEY exkey; + + g_assert(type =3D=3D S390_FEAT_TYPE_KMCTR); + + switch (fc) { + case CPACF_KMCTR_PAES_128: + keysize =3D 16; + break; + case CPACF_KMCTR_PAES_192: + keysize =3D 24; + break; + case CPACF_KMCTR_PAES_256: + keysize =3D 32; + break; + default: + g_assert_not_reached(); + } + + if (!(env->psw.mask & PSW_MASK_64)) { + len =3D (uint32_t)len; + addr_reg_size =3D (env->psw.mask & PSW_MASK_32) ? 32 : 24; + } + + /* length has to be properly aligned. */ + if (!QEMU_IS_ALIGNED(len, AES_BLOCK_SIZE)) { + tcg_s390_program_interrupt(env, PGM_SPECIFICATION, ra); + } + + /* fetch and check wkvp from param block */ + for (i =3D 0; i < sizeof(wkvp); i++) { + addr =3D wrap_address(env, param_addr + keysize + i); + wkvp[i] =3D cpu_ldb_mmu(env, addr, oi, ra); + } + if (memcmp(wkvp, protkey_wkvp, sizeof(wkvp))) { + /* wkvp mismatch -> return with cc 1 */ + return 1; + } + + /* fetch protected key from param block */ + for (i =3D 0; i < keysize; i++) { + addr =3D wrap_address(env, param_addr + i); + key[i] =3D cpu_ldb_mmu(env, addr, oi, ra); + } + /* decrypt the protected key */ + decrypt_protkey(key, keysize); + + /* expand key */ + AES_set_encrypt_key(key, keysize * 8, &exkey); + + /* process up to MAX_BLOCKS_PER_RUN aes blocks */ + for (i =3D 0; i < MAX_BLOCKS_PER_RUN && len >=3D AES_BLOCK_SIZE; i++) { + /* read in nonce/ctr =3D> ctr */ + aes_read_block(env, mmu_idx, *ctr_ptr_reg + done, ctr, ra); + /* encrypt ctr =3D> buf */ + AES_encrypt(ctr, buf, &exkey); + /* read in one block of input data =3D> in */ + aes_read_block(env, mmu_idx, *src_ptr_reg + done, in, ra); + /* exor input data with encrypted ctr =3D> out */ + aes_xor(in, buf, out); + /* write out the processed block */ + aes_write_block(env, mmu_idx, *dst_ptr_reg + done, out, ra); + len -=3D AES_BLOCK_SIZE; + done +=3D AES_BLOCK_SIZE; + } + + *src_ptr_reg =3D deposit64(*src_ptr_reg, 0, addr_reg_size, + *src_ptr_reg + done); + *dst_ptr_reg =3D deposit64(*dst_ptr_reg, 0, addr_reg_size, + *dst_ptr_reg + done); + *ctr_ptr_reg =3D deposit64(*ctr_ptr_reg, 0, addr_reg_size, + *ctr_ptr_reg + done); + *src_len_reg -=3D done; + + return !len ? 0 : 3; +} diff --git a/target/s390x/tcg/crypto_helper.c b/target/s390x/tcg/crypto_hel= per.c index 237ce744b7..73b2a6557c 100644 --- a/target/s390x/tcg/crypto_helper.c +++ b/target/s390x/tcg/crypto_helper.c @@ -165,6 +165,13 @@ static int cpacf_kmctr(CPUS390XState *env, const int m= mu_idx, uintptr_t ra, &env->regs[r1], &env->regs[r2], &env->regs[r2 += 1], &env->regs[r3], S390_FEAT_TYPE_KMCTR, fc, mod); break; + case CPACF_KMCTR_PAES_128: + case CPACF_KMCTR_PAES_192: + case CPACF_KMCTR_PAES_256: + rc =3D cpacf_paes_ctr(env, mmu_idx, ra, env->regs[1], + &env->regs[r1], &env->regs[r2], &env->regs[r2 = + 1], + &env->regs[r3], S390_FEAT_TYPE_KMCTR, fc, mod); + break; default: tcg_s390_program_interrupt(env, PGM_SPECIFICATION, ra); } --=20 2.43.0 From nobody Sun Jul 26 10:59:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783331265; cv=none; d=zohomail.com; s=zohoarc; b=Xt4ydtAgY14IL/MqdIDqVqRPowFj/kjmr0jthudW7BKtlDAdTeYYFNVs0vYba72guI9EU5+dFSfMaTeGVsCZTuUlB7ltCTr/1vYF9T+2O41tVq0vNCSYdvppofsPZAwHti/yytrA+fRPHCNp0KwiY2zkAJ6Exfl/Ry97IWx1bvk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783331265; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=5ZDJn3v5xKdDEk2InqnnkkZDLDWxYfvl5nccwPf70rU=; b=GEoYgXMKxrwW2q9CWQcGWayKa+6Lpb+5rY/KqWJ3mJsTpX6DUiK4OqFAo+QtmzNjd8ZoDTyO7p6GPuQ8RMHWUA/4fsvfw7s0RQp0dpLPj3kdLdubM/ANSdfwFMbZJvKk7r4Mpp1X9MSQCtnz5Dhkl6yNCeFRfkNukOCTaYQoLzc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 17833312653491007.9245989406845; Mon, 6 Jul 2026 02:47:45 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wgfrc-0004Jl-P9; Mon, 06 Jul 2026 05:43:44 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrV-0004Fl-S2; Mon, 06 Jul 2026 05:43:37 -0400 Received: from mx0b-001b2d01.pphosted.com ([148.163.158.5]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrP-0003yN-Nt; Mon, 06 Jul 2026 05:43:37 -0400 Received: from pps.filterd (m0353725.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 6669J73u3152814; Mon, 6 Jul 2026 09:43:23 GMT Received: from ppma23.wdc07v.mail.ibm.com (5d.69.3da9.ip4.static.sl-reverse.com [169.61.105.93]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f6rkdhdbc-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:23 +0000 (GMT) Received: from pps.filterd (ppma23.wdc07v.mail.ibm.com [127.0.0.1]) by ppma23.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 6669YaFs005588; Mon, 6 Jul 2026 09:43:23 GMT Received: from smtprelay01.fra02v.mail.ibm.com ([9.218.2.227]) by ppma23.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4f7e0h4w4a-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:22 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (smtpav07.fra02v.mail.ibm.com [10.20.54.106]) by smtprelay01.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 6669hJGJ54722916 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Mon, 6 Jul 2026 09:43:19 GMT Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id E903020040; Mon, 6 Jul 2026 09:43:18 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id C14AE2004B; Mon, 6 Jul 2026 09:43:18 +0000 (GMT) Received: from funtu2.ibm.com (unknown [9.111.193.81]) by smtpav07.fra02v.mail.ibm.com (Postfix) with ESMTP; Mon, 6 Jul 2026 09:43:18 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=5ZDJn3v5xKdDEk2In qnnkkZDLDWxYfvl5nccwPf70rU=; b=T2LC0/zyxk8ASPtzRPvhaPzEc0/AbfB+Z YyXnJ9e1aYiJWLGJv8nM/Qyhrt/kEcIwPqNUS/qBxS9877l7w1WlQlJ/0FYYzv5e joWWunTfRN77PR5HEqLCoKmIH5IE9PA5Q/0YanZX+ydQtz8C6+5RIvwDL4NUbjZc Acb/xVCcJtCz+1ReNJyPmHBjYcRyasmfAdz2+o0ZzTptYeD6E59wq9DkEAoZnbdI WJ5YrDTqSbNf5IbyYlZSauw1jdXdMFKluw12a5xfZNonWTA/eihub2CCcr30x46d LZofimufThzW9MrR80YZcr5TGNtp4bD2GAr+ZwjbHj3pucNIrl4MQ== From: Harald Freudenberger To: richard.henderson@linaro.org, iii@linux.ibm.com, david@kernel.org, thuth@redhat.com, berrange@redhat.com Cc: qemu-s390x@nongnu.org, qemu-devel@nongnu.org, linux-s390@vger.kernel.org, dengler@linux.ibm.com, borntraeger@linux.ibm.com, fcallies@linux.ibm.com, cohuck@redhat.com Subject: [PATCH v10 15/21] target/s390x: Minimal protected key AES XTS support for cpacf pcc instruction Date: Mon, 6 Jul 2026 11:43:08 +0200 Message-ID: <20260706094317.17032-16-freude@linux.ibm.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260706094317.17032-1-freude@linux.ibm.com> References: <20260706094317.17032-1-freude@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Authority-Analysis: v=2.4 cv=M7J97Sws c=1 sm=1 tr=0 ts=6a4b78bb cx=c_pps a=3Bg1Hr4SwmMryq2xdFQyZA==:117 a=3Bg1Hr4SwmMryq2xdFQyZA==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=V8glGbnc2Ofi9Qvn3v5h:22 a=VnNF1IyMAAAA:8 a=EmLOupEv2CnJZljdqbQA:9 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfXzScByt7Ud3mD CeLiSGjsHpkbIFd8erooCDxDoseegKAAy9tLchLJ5Hj/Le79omJEWP+JiORp1J/vElcmaoCth1e hhM3r0Lfje7VUPwG7MVJAwQU9qjng98VZgVXgOV4wV3UrzmH9C3e3J2e5HbfFcvS8kM7L1Di/bb wUrQD36b1fxAi7lVcfK/ADU0S7ruyUJxqtA7Vw3hgxHEP3+kH0NYWW3U2SacdVddYE/seML8hfZ 0g1W0ZgrWnpLbF92HcLjlsse//aVasqjGpKMUkRuKus2V50LKTASK/E0WcETZoI065gO2hsUbNn MbZS1WU6ST8ogrksYjgJrVb0hCfcSdtnQab8RDAY73xWq/1YXWYLFnNlxpKpE7EAhBtcqWYGoEd bSa/bJ9zCwlFb4s42Ecz9daEwlHdJuMaweibg33jDRHIo3moSyUsBpaMaqqMI6SRoC2ibMXNsmv MTx0sS5peAK67f27e9Q== X-Proofpoint-Spam-Info: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfXwLFB1orI+sgV Q4hmkszq+uNEusg6i1gnAft6RmpxsRLddRrCL+q2rWN/19wHzt8up4kBjZEnMGS1+g4OIc92BCQ YEgLKwsNpxsyDZtqgsHfnO8YCZq5hDY= X-Proofpoint-GUID: mB9_96BB1b8l34XBE1d0RHzGDu11iymT X-Proofpoint-ORIG-GUID: mB9_96BB1b8l34XBE1d0RHzGDu11iymT X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-06_01,2026-07-03_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 suspectscore=0 lowpriorityscore=0 malwarescore=0 clxscore=1015 adultscore=0 priorityscore=1501 bulkscore=0 spamscore=0 impostorscore=0 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607060094 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.158.5; envelope-from=freude@linux.ibm.com; helo=mx0b-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783331266254158500 Content-Type: text/plain; charset="utf-8" Support CPACF pcc subfunctions PCC-Compute-XTS-Parameter-Encrypted-AES-128 and PCC-Compute-XTS-Parameter-Encrypted-AES-128 but only for the special case block sequential number is 0. However, this covers the s390 PAES XTS implementation in the Linux kernel. Signed-off-by: Harald Freudenberger Tested-by: Holger Dengler --- target/s390x/gen-features.c | 2 + target/s390x/tcg/cpacf.h | 2 + target/s390x/tcg/cpacf_aes.c | 77 ++++++++++++++++++++++++++++++++ target/s390x/tcg/crypto_helper.c | 4 ++ 4 files changed, 85 insertions(+) diff --git a/target/s390x/gen-features.c b/target/s390x/gen-features.c index 4a131dc191..126bacb281 100644 --- a/target/s390x/gen-features.c +++ b/target/s390x/gen-features.c @@ -943,6 +943,8 @@ static uint16_t qemu_MAX[] =3D { S390_FEAT_KMCTR_EAES_256, S390_FEAT_PCC_XTS_AES_128, S390_FEAT_PCC_XTS_AES_256, + S390_FEAT_PCC_XTS_EAES_128, + S390_FEAT_PCC_XTS_EAES_256, S390_FEAT_PCKMO_AES_128, S390_FEAT_PCKMO_AES_192, S390_FEAT_PCKMO_AES_256, diff --git a/target/s390x/tcg/cpacf.h b/target/s390x/tcg/cpacf.h index 6071f21fb6..9dc197388e 100644 --- a/target/s390x/tcg/cpacf.h +++ b/target/s390x/tcg/cpacf.h @@ -295,5 +295,7 @@ int cpacf_paes_ctr(CPUS390XState *env, const int mmu_id= x, uintptr_t ra, uint64_t *src_ptr_reg, uint64_t *src_len_reg, uint64_t *ctr_ptr_reg, uint32_t type, uint8_t fc, uint8_t mod); +int cpacf_paes_pcc(CPUS390XState *env, const int mmu_idx, uintptr_t ra, + uint64_t param_addr, uint8_t fc); =20 #endif /* S390X_CPACF_H */ diff --git a/target/s390x/tcg/cpacf_aes.c b/target/s390x/tcg/cpacf_aes.c index c52df6510f..df4cd7ae70 100644 --- a/target/s390x/tcg/cpacf_aes.c +++ b/target/s390x/tcg/cpacf_aes.c @@ -828,3 +828,80 @@ int cpacf_paes_ctr(CPUS390XState *env, const int mmu_i= dx, uintptr_t ra, =20 return !len ? 0 : 3; } + +int cpacf_paes_pcc(CPUS390XState *env, const int mmu_idx, uintptr_t ra, + uint64_t param_addr, uint8_t fc) +{ + uint8_t key[32], wkvp[32], tweak[AES_BLOCK_SIZE], buf[AES_BLOCK_SIZE]; + const MemOpIdx oi =3D make_memop_idx(MO_8, mmu_idx); + int keysize, i; + uint64_t addr; + AES_KEY exkey; + + switch (fc) { + case CPACF_PCC_XTS_PAES_128: + keysize =3D 16; + break; + case CPACF_PCC_XTS_PAES_256: + keysize =3D 32; + break; + default: + g_assert_not_reached(); + } + + /* fetch and check wkvp from param block */ + for (i =3D 0; i < sizeof(wkvp); i++) { + addr =3D wrap_address(env, param_addr + keysize + i); + wkvp[i] =3D cpu_ldb_mmu(env, addr, oi, ra); + } + if (memcmp(wkvp, protkey_wkvp, sizeof(wkvp))) { + /* wkvp mismatch -> return with cc 1 */ + return 1; + } + + /* fetch block sequence nr from param block into buf */ + for (i =3D 0; i < AES_BLOCK_SIZE; i++) { + addr =3D wrap_address(env, param_addr + keysize + + sizeof(wkvp) + AES_BLOCK_SIZE + i); + buf[i] =3D cpu_ldb_mmu(env, addr, oi, ra); + } + + /* is the block sequence nr 0 ? */ + for (i =3D 0; i < AES_BLOCK_SIZE && !buf[i]; i++) { + ; + } + if (i < AES_BLOCK_SIZE) { + /* no, sorry handling of non zero block sequence is not implemente= d */ + tcg_s390_program_interrupt(env, PGM_SPECIFICATION, ra); + return 1; + } + + /* fetch protected key from param block */ + for (i =3D 0; i < keysize; i++) { + addr =3D wrap_address(env, param_addr + i); + key[i] =3D cpu_ldb_mmu(env, addr, oi, ra); + } + /* decrypt the protected key */ + decrypt_protkey(key, keysize); + + /* fetch tweak from param block into tweak */ + for (i =3D 0; i < AES_BLOCK_SIZE; i++) { + addr =3D wrap_address(env, param_addr + keysize + sizeof(wkvp) + i= ); + tweak[i] =3D cpu_ldb_mmu(env, addr, oi, ra); + } + + /* expand key */ + AES_set_encrypt_key(key, keysize * 8, &exkey); + + /* encrypt tweak */ + AES_encrypt(tweak, buf, &exkey); + + /* store encrypted tweak into xts parameter field of the param block */ + for (i =3D 0; i < AES_BLOCK_SIZE; i++) { + addr =3D wrap_address(env, param_addr + keysize + + sizeof(wkvp) + 3 * AES_BLOCK_SIZE + i); + cpu_stb_mmu(env, addr, buf[i], oi, ra); + } + + return 0; +} diff --git a/target/s390x/tcg/crypto_helper.c b/target/s390x/tcg/crypto_hel= per.c index 73b2a6557c..5e924b78f5 100644 --- a/target/s390x/tcg/crypto_helper.c +++ b/target/s390x/tcg/crypto_helper.c @@ -206,6 +206,10 @@ static int cpacf_pcc(CPUS390XState *env, const int mmu= _idx, uintptr_t ra, case CPACF_PCC_XTS_AES_256: rc =3D cpacf_aes_pcc(env, mmu_idx, ra, env->regs[1], fc); break; + case CPACF_PCC_XTS_PAES_128: + case CPACF_PCC_XTS_PAES_256: + rc =3D cpacf_paes_pcc(env, mmu_idx, ra, env->regs[1], fc); + break; default: tcg_s390_program_interrupt(env, PGM_SPECIFICATION, ra); } --=20 2.43.0 From nobody Sun Jul 26 10:59:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783331098; cv=none; d=zohomail.com; s=zohoarc; b=b12qk9HfdFdgiy+K0d45EwFTpuu/ZpjQ02jedYWgiKZb3c4qVkyp3UjVeXDTE/5MT45cgDZ/t9SJBfoHJJrVx20S6Zsb+7AJ6emY3pP6DFN97dib9aSdlh3wAROd7vTXp8BkjKqyBw6PyGcU1zS3+hHu6ZdyAgCCRmFHp9TDPg0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783331098; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=5LBOX/J+l5c2FVyRrgtLWBGZM+2t3/9Oo6ByW74VPus=; b=T6JewI/f+rJbaGEfIa/ljFF1u+ET0ZuN05bAPrPxPoYTZ30WeRWMfV4UZhyTGWP2Gu8+wClVg6yVBOzoFGb5gw744jp7IWh9131XJRJphw1mElVxsCZTy+9VzqntlroKPNqWQYB059G+eOJq9fqvduNvnSCj1F/h1WjS0tVtZFY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783331098502964.3582625746035; Mon, 6 Jul 2026 02:44:58 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wgfrw-0004SP-JG; Mon, 06 Jul 2026 05:44:04 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrl-0004QU-Vt; Mon, 06 Jul 2026 05:43:54 -0400 Received: from mx0a-001b2d01.pphosted.com ([148.163.156.1]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrj-0003yR-Dq; Mon, 06 Jul 2026 05:43:53 -0400 Received: from pps.filterd (m0360083.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 6669IDFd3890018; Mon, 6 Jul 2026 09:43:24 GMT Received: from ppma21.wdc07v.mail.ibm.com (5b.69.3da9.ip4.static.sl-reverse.com [169.61.105.91]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f6sp3gsqw-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:24 +0000 (GMT) Received: from pps.filterd (ppma21.wdc07v.mail.ibm.com [127.0.0.1]) by ppma21.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 6669YeQ6028347; Mon, 6 Jul 2026 09:43:23 GMT Received: from smtprelay01.fra02v.mail.ibm.com ([9.218.2.227]) by ppma21.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4f7dgjw0gy-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:23 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (smtpav07.fra02v.mail.ibm.com [10.20.54.106]) by smtprelay01.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 6669hJac54722918 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Mon, 6 Jul 2026 09:43:19 GMT Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 263002004B; Mon, 6 Jul 2026 09:43:19 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id ED3CA20043; Mon, 6 Jul 2026 09:43:18 +0000 (GMT) Received: from funtu2.ibm.com (unknown [9.111.193.81]) by smtpav07.fra02v.mail.ibm.com (Postfix) with ESMTP; Mon, 6 Jul 2026 09:43:18 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=5LBOX/J+l5c2FVyRr gtLWBGZM+2t3/9Oo6ByW74VPus=; b=Lk/PN+yWVO6bbVRsPTiCz4Qk1pi8IKsDd axFxHXFj5QCwORJVIz+nThHsXapzr/nrkbyQjDxSkj/MEFr3panUOmmBrYIj8mCv jq17wnhpUk5EjgYz/+UP3PbWF0jjHImXh157HlzCkchDvCQvPgt9Aq+5naGIqyw/ cCdcM9VfsAP2kPDG4xak3LKT96JTQ6qwoth/hQXr5ArwUj1LoVZwH9MQ1Ij6xO2D 5f9TsuFFZ/f/9ekGXHaQ6+W11YaPeijbiAbvIm5mW7WUfEZMifo0tQ36wahu4m3h AxeKqsyCLy4O5mzlrze72ONo+T4QBYI4yF2rhGEcHq5pF9wCo9d2w== From: Harald Freudenberger To: richard.henderson@linaro.org, iii@linux.ibm.com, david@kernel.org, thuth@redhat.com, berrange@redhat.com Cc: qemu-s390x@nongnu.org, qemu-devel@nongnu.org, linux-s390@vger.kernel.org, dengler@linux.ibm.com, borntraeger@linux.ibm.com, fcallies@linux.ibm.com, cohuck@redhat.com Subject: [PATCH v10 16/21] target/s390x: Support protected key AES XTS for cpacf km instruction Date: Mon, 6 Jul 2026 11:43:09 +0200 Message-ID: <20260706094317.17032-17-freude@linux.ibm.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260706094317.17032-1-freude@linux.ibm.com> References: <20260706094317.17032-1-freude@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Authority-Analysis: v=2.4 cv=KsJ9H2WN c=1 sm=1 tr=0 ts=6a4b78bc cx=c_pps a=GFwsV6G8L6GxiO2Y/PsHdQ==:117 a=GFwsV6G8L6GxiO2Y/PsHdQ==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=iQ6ETzBq9ecOQQE5vZCe:22 a=VnNF1IyMAAAA:8 a=_Jmc02WdQjUAVPbgbKgA:9 X-Proofpoint-Spam-Info: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfXxSHd4a2d03Ph Oi5ke/wKa74I5vohf5koRuGMQtd3rzVjBR7w58bhBAC4DqTvkcWsSbUOcKt6bkI5TRISwQ4oIaK +1IjhNHH68f4EWDbV6dcnDMoVh7Hc+k= X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfX9sO6jxc3WV/L B02jWJD+w7PyASwl5CNnL6kzGrV+lwzK9K1dyXnpGLvSO1hJtdT1YyjfiD6yPYOdqQf0sV3GbNf XSetIwrBYAZQ58QIzUvqfAKS9bfQ87XXsYBEHNbslVMIneKxPMOfx1vUPhj8id5iPQTvNk/NgoO NgoNjay3xjFPUxgta6cgKM+IOTdZfZGd3hVvGnHwurND1P9yqDOVpefSBx1JA9h9NuN3YGHx1TE WUnMuQItOaXHSjYhlZIz53CeynRmOSFheRkQj9cb84YsofZbXf6LPhFzDc7tDYQiPJJH6JOknVG 1cC5AiKLqs0nho/f1PeYt/u4NloZUgaRjJqb99wpfS71/KkGla3+Kc5yyRVR6atHhJqx2ylUvhp hViXIGmR9+Gr4uBgPrquZZxcOIgMbOmd3xfQdj4oRriU78S7U1sjl7omYOjErjX0PnPNiAwp3tn Y0YXVboEhas5ftoPKkQ== X-Proofpoint-ORIG-GUID: UOjANTV_Lbfus0_O56S8MLMIoiZIEx0I X-Proofpoint-GUID: UOjANTV_Lbfus0_O56S8MLMIoiZIEx0I X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-06_01,2026-07-03_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 impostorscore=0 malwarescore=0 spamscore=0 adultscore=0 clxscore=1015 suspectscore=0 lowpriorityscore=0 priorityscore=1501 bulkscore=0 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607060094 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.156.1; envelope-from=freude@linux.ibm.com; helo=mx0a-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783331099241158500 Content-Type: text/plain; charset="utf-8" Support the subfunctions CPACF_KM_PXTS_128 and CPACF_KM_PXTS_256 for the cpacf km instruction. Tested-by: Holger Dengler Signed-off-by: Harald Freudenberger --- target/s390x/gen-features.c | 2 + target/s390x/tcg/cpacf.h | 4 ++ target/s390x/tcg/cpacf_aes.c | 105 +++++++++++++++++++++++++++++++ target/s390x/tcg/crypto_helper.c | 6 ++ 4 files changed, 117 insertions(+) diff --git a/target/s390x/gen-features.c b/target/s390x/gen-features.c index 126bacb281..c4c59c3504 100644 --- a/target/s390x/gen-features.c +++ b/target/s390x/gen-features.c @@ -929,6 +929,8 @@ static uint16_t qemu_MAX[] =3D { S390_FEAT_KM_EAES_256, S390_FEAT_KM_XTS_AES_128, S390_FEAT_KM_XTS_AES_256, + S390_FEAT_KM_XTS_EAES_128, + S390_FEAT_KM_XTS_EAES_256, S390_FEAT_KMC_AES_128, S390_FEAT_KMC_AES_192, S390_FEAT_KMC_AES_256, diff --git a/target/s390x/tcg/cpacf.h b/target/s390x/tcg/cpacf.h index 9dc197388e..b2223b4d64 100644 --- a/target/s390x/tcg/cpacf.h +++ b/target/s390x/tcg/cpacf.h @@ -297,5 +297,9 @@ int cpacf_paes_ctr(CPUS390XState *env, const int mmu_id= x, uintptr_t ra, uint8_t fc, uint8_t mod); int cpacf_paes_pcc(CPUS390XState *env, const int mmu_idx, uintptr_t ra, uint64_t param_addr, uint8_t fc); +int cpacf_paes_xts(CPUS390XState *env, const int mmu_idx, uintptr_t ra, + uint64_t param_addr, uint64_t *dst_ptr_reg, + uint64_t *src_ptr_reg, uint64_t *src_len_reg, + uint32_t type, uint8_t fc, uint8_t mod); =20 #endif /* S390X_CPACF_H */ diff --git a/target/s390x/tcg/cpacf_aes.c b/target/s390x/tcg/cpacf_aes.c index df4cd7ae70..0c3cbb29e3 100644 --- a/target/s390x/tcg/cpacf_aes.c +++ b/target/s390x/tcg/cpacf_aes.c @@ -905,3 +905,108 @@ int cpacf_paes_pcc(CPUS390XState *env, const int mmu_= idx, uintptr_t ra, =20 return 0; } + +int cpacf_paes_xts(CPUS390XState *env, const int mmu_idx, uintptr_t ra, + uint64_t param_addr, uint64_t *dst_ptr_reg, + uint64_t *src_ptr_reg, uint64_t *src_len_reg, + uint32_t type, uint8_t fc, uint8_t mod) +{ + enum { MAX_BLOCKS_PER_RUN =3D 8192 / AES_BLOCK_SIZE }; + uint8_t buf1[AES_BLOCK_SIZE], buf2[AES_BLOCK_SIZE]; + const MemOpIdx oi =3D make_memop_idx(MO_8, mmu_idx); + uint8_t key[32], wkvp[32], tweak[AES_BLOCK_SIZE]; + uint64_t addr, len =3D *src_len_reg, done =3D 0; + int i, keysize, addr_reg_size =3D 64; + AES_KEY exkey; + + g_assert(type =3D=3D S390_FEAT_TYPE_KM); + + switch (fc) { + case CPACF_KM_PXTS_128: + keysize =3D 16; + break; + case CPACF_KM_PXTS_256: + keysize =3D 32; + break; + default: + g_assert_not_reached(); + } + + if (!(env->psw.mask & PSW_MASK_64)) { + len =3D (uint32_t)len; + addr_reg_size =3D (env->psw.mask & PSW_MASK_32) ? 32 : 24; + } + + /* length has to be properly aligned. */ + if (!QEMU_IS_ALIGNED(len, AES_BLOCK_SIZE)) { + tcg_s390_program_interrupt(env, PGM_SPECIFICATION, ra); + } + + /* fetch and check wkvp from param block */ + for (i =3D 0; i < sizeof(wkvp); i++) { + addr =3D wrap_address(env, param_addr + keysize + i); + wkvp[i] =3D cpu_ldb_mmu(env, addr, oi, ra); + } + if (memcmp(wkvp, protkey_wkvp, sizeof(wkvp))) { + /* wkvp mismatch -> return with cc 1 */ + return 1; + } + + /* fetch protected key from param block */ + for (i =3D 0; i < keysize; i++) { + addr =3D wrap_address(env, param_addr + i); + key[i] =3D cpu_ldb_mmu(env, addr, oi, ra); + } + /* decrypt the protected key */ + decrypt_protkey(key, keysize); + + /* expand key */ + if (mod) { + AES_set_decrypt_key(key, keysize * 8, &exkey); + } else { + AES_set_encrypt_key(key, keysize * 8, &exkey); + } + + /* fetch tweak from param block */ + for (i =3D 0; i < AES_BLOCK_SIZE; i++) { + addr =3D wrap_address(env, param_addr + keysize + sizeof(wkvp) + i= ); + tweak[i] =3D cpu_ldb_mmu(env, addr, oi, ra); + } + + /* process up to MAX_BLOCKS_PER_RUN aes blocks */ + for (i =3D 0; i < MAX_BLOCKS_PER_RUN && len >=3D AES_BLOCK_SIZE; i++) { + /* fetch one AES block into buf1 */ + aes_read_block(env, mmu_idx, *src_ptr_reg + done, buf1, ra); + /* buf1 xor tweak =3D> buf2 */ + aes_xor(buf1, tweak, buf2); + if (mod) { + /* decrypt buf2 =3D> buf1 */ + AES_decrypt(buf2, buf1, &exkey); + } else { + /* encrypt buf2 =3D> buf1 */ + AES_encrypt(buf2, buf1, &exkey); + } + /* buf1 xor tweak =3D> buf2 */ + aes_xor(buf1, tweak, buf2); + /* prep tweak for next round */ + aes_xts_prep_next_tweak(tweak); + /* write out this processed block from buf2 */ + aes_write_block(env, mmu_idx, *dst_ptr_reg + done, buf2, ra); + len -=3D AES_BLOCK_SIZE; + done +=3D AES_BLOCK_SIZE; + } + + /* update tweak in param block */ + for (i =3D 0; i < AES_BLOCK_SIZE; i++) { + addr =3D wrap_address(env, param_addr + keysize + sizeof(wkvp) + i= ); + cpu_stb_mmu(env, addr, tweak[i], oi, ra); + } + + *src_ptr_reg =3D deposit64(*src_ptr_reg, 0, addr_reg_size, + *src_ptr_reg + done); + *dst_ptr_reg =3D deposit64(*dst_ptr_reg, 0, addr_reg_size, + *dst_ptr_reg + done); + *src_len_reg -=3D done; + + return !len ? 0 : 3; +} diff --git a/target/s390x/tcg/crypto_helper.c b/target/s390x/tcg/crypto_hel= per.c index 5e924b78f5..6172012979 100644 --- a/target/s390x/tcg/crypto_helper.c +++ b/target/s390x/tcg/crypto_helper.c @@ -116,6 +116,12 @@ static int cpacf_km(CPUS390XState *env, const int mmu_= idx, uintptr_t ra, &env->regs[r1], &env->regs[r2], &env->regs[r2 += 1], S390_FEAT_TYPE_KM, fc, mod); break; + case CPACF_KM_PXTS_128: + case CPACF_KM_PXTS_256: + rc =3D cpacf_paes_xts(env, mmu_idx, ra, env->regs[1], + &env->regs[r1], &env->regs[r2], &env->regs[r2 = + 1], + S390_FEAT_TYPE_KM, fc, mod); + break; default: tcg_s390_program_interrupt(env, PGM_SPECIFICATION, ra); } --=20 2.43.0 From nobody Sun Jul 26 10:59:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783331269; cv=none; d=zohomail.com; s=zohoarc; b=RQ1M9a9uGu7y7b9xhlO9X1yYjcxSqgoGimJl+wx2zDimOYGlZ2DbRFACGW3qccpd1fqt4ueEI9NqDL1unBEE5CMF5otvYY49sGsdkcm+7kInYHig6vL6QJpQni2eRyqQ8emGZkKhroEA1sQ2ZIBAeuTOpZIgsEFt0V9e33QAzSQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783331269; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=v1Qbf2f72aNF/0uKTzWmJUlSJiFyzb/LM9TrkMNSRlk=; b=Lii2XzooxGHmhLub/3ijofYYZnYa9sF3bZZXihKYlmKiGzf6PS9COrchJ+MhIF8tXVwhSqJX/Lmq9sCzTYTvjbcmxfH/B8Mcisvb7MRvtOVs+ZuNPy9Ru6N+JfpZEdiVZuDL2cNdzQuxYaNIoQ5ydEvn/LQKwd0KdFGs1iHhTuc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178333126969773.75111316661344; Mon, 6 Jul 2026 02:47:49 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wgfrV-0004Fm-Va; Mon, 06 Jul 2026 05:43:37 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrT-0004CT-8f; Mon, 06 Jul 2026 05:43:35 -0400 Received: from mx0a-001b2d01.pphosted.com ([148.163.156.1]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrP-0003xz-Nm; Mon, 06 Jul 2026 05:43:34 -0400 Received: from pps.filterd (m0360083.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 6669IMJ93890105; Mon, 6 Jul 2026 09:43:24 GMT Received: from ppma13.dal12v.mail.ibm.com (dd.9e.1632.ip4.static.sl-reverse.com [50.22.158.221]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f6sp3gsqv-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:24 +0000 (GMT) Received: from pps.filterd (ppma13.dal12v.mail.ibm.com [127.0.0.1]) by ppma13.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 6669YbAj021110; Mon, 6 Jul 2026 09:43:23 GMT Received: from smtprelay01.fra02v.mail.ibm.com ([9.218.2.227]) by ppma13.dal12v.mail.ibm.com (PPS) with ESMTPS id 4f7eqfvs1v-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:23 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (smtpav07.fra02v.mail.ibm.com [10.20.54.106]) by smtprelay01.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 6669hJXl54722920 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Mon, 6 Jul 2026 09:43:19 GMT Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 7319120040; Mon, 6 Jul 2026 09:43:19 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 2A2DB2004E; Mon, 6 Jul 2026 09:43:19 +0000 (GMT) Received: from funtu2.ibm.com (unknown [9.111.193.81]) by smtpav07.fra02v.mail.ibm.com (Postfix) with ESMTP; Mon, 6 Jul 2026 09:43:19 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=v1Qbf2f72aNF/0uKT zWmJUlSJiFyzb/LM9TrkMNSRlk=; b=qwtHqNTzVmOCs6pgBUnO+icv/3OPyGDs2 kkm71LIkVIvVycc0QgA7rx5vl2/DZ2lYAv9ZAyctFd7rNLWH7jFSXiogmtCXFJuj A+frwt7/90sYQXtRRNRrYa0EYJ1FOV96BQs9JTQeuROtqcRgvKN+4lMEdfGkqKS1 JCymaPZw7nVWiivk+kSut9G5s3kSeoqXTck4ty4soXuqRSKbaRI/p26MIeVyebgH KANN66dj9xJ3MkmVuopsh+gmZXfUdMoZzgPS7p2P7C9oBlyRDX6ucAmCxiyI5CCm znR55WLkGmU1scF7KWFlui/OY2RLkoS0nHzG8G04/tn4QxppT7hVw== From: Harald Freudenberger To: richard.henderson@linaro.org, iii@linux.ibm.com, david@kernel.org, thuth@redhat.com, berrange@redhat.com Cc: qemu-s390x@nongnu.org, qemu-devel@nongnu.org, linux-s390@vger.kernel.org, dengler@linux.ibm.com, borntraeger@linux.ibm.com, fcallies@linux.ibm.com, cohuck@redhat.com Subject: [PATCH v10 17/21] docs/s390: Document CPACF instructions support Date: Mon, 6 Jul 2026 11:43:10 +0200 Message-ID: <20260706094317.17032-18-freude@linux.ibm.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260706094317.17032-1-freude@linux.ibm.com> References: <20260706094317.17032-1-freude@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Authority-Analysis: v=2.4 cv=KsJ9H2WN c=1 sm=1 tr=0 ts=6a4b78bc cx=c_pps a=AfN7/Ok6k8XGzOShvHwTGQ==:117 a=AfN7/Ok6k8XGzOShvHwTGQ==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=iQ6ETzBq9ecOQQE5vZCe:22 a=VnNF1IyMAAAA:8 a=IlYB4z8HrC9mJJy16gAA:9 a=5wi_FRADO1KgGG3s:21 a=O8hF6Hzn-FEA:10 X-Proofpoint-Spam-Info: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfX6m8jIdpdcVRg mX8R+/0MUtDYA+rGrowPS76nP+gBF4JIP1hA+tHtXO06R8yy3uX0Q0CcXaZ4RCZIMSg12hObRmI XF/YXtFOU+ElMKTEU7H7C+3Bcq79PDs= X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfX8U2af+sEeizf 2tTgfCl7YDZ5lsucBHHvNqc+95n4s2c2yPsEq6cZC+aSOLbk0/KYEJ5iotC4wUWBllGHT1qhgKw kdjjxRjYjQI180aLd17k5U3/ummXJBJ7PjS7O3ijwjApvff0hnQ9SsGOsq3R/l4UA0CEXjvkPUg 8GogtJKzyuEeA+4a5lZDQ8WMun0cw/2BSzCjn8Z7NG8LD9VMoN+pKJdmmLx1gzbYV/mnxdjmUSu eyy5kB2P0XAy2VZ5xPxmJWmtuVqK2zg7VIl6Nl9iTWAWCWLcz2TgilxrIaCLGVDcvDpTwY3DF6F 4eai4kkoauoS7Ot3PzpKAdmHwvlSxVScfKcVlcm60WpmP85AHCoDSwfmiltItP0RjjpUojl9r+6 ycdsa7SB/C/FGdVE2ogjT+ZZam17uh8W1KbSqZSfxfPfu732mlgzR11ny3QHevzxDuHu5m8BNeD 8mWb0D1w2VUHd12NbiA== X-Proofpoint-ORIG-GUID: _5X0mTMFwnmaMCgkKPtnPdjS_CTazI1O X-Proofpoint-GUID: _5X0mTMFwnmaMCgkKPtnPdjS_CTazI1O X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-06_01,2026-07-03_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 impostorscore=0 malwarescore=0 spamscore=0 adultscore=0 clxscore=1015 suspectscore=0 lowpriorityscore=0 priorityscore=1501 bulkscore=0 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607060094 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.156.1; envelope-from=freude@linux.ibm.com; helo=mx0a-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783331270208158500 Content-Type: text/plain; charset="utf-8" Add a first document covering the Qemu s390 CPACF instructions and functions supported. Signed-off-by: Harald Freudenberger Reviewed-by: Finn Callies --- docs/system/s390x/cpacf.rst | 144 +++++++++++++++++++++++++++++++++++ docs/system/target-s390x.rst | 1 + 2 files changed, 145 insertions(+) create mode 100644 docs/system/s390x/cpacf.rst diff --git a/docs/system/s390x/cpacf.rst b/docs/system/s390x/cpacf.rst new file mode 100644 index 0000000000..1c3a07c59d --- /dev/null +++ b/docs/system/s390x/cpacf.rst @@ -0,0 +1,144 @@ +CPACF Support +=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D + +CPACF +----- + +CP Assist for Cryptographic Function (CPACF) is a hardware-integrated +coprocessor feature built into every processor core of IBM Z and +LinuxONE mainframes (s390x architecture). It provides high-speed, +hardware-accelerated encryption and hashing directly on the CPU. + +CPACF provides a set of z/Architecture instructions (known as Message +Security Assist or MSA) that execute cryptographic operations +synchronously with the main processor. + +- Symmetric Encryption: Support for AES (128, 192, 256-bit), DES, and + Triple-DES (TDES). +- Hashing: Acceleration for SHA-1, SHA-2 (up to SHA-512), SHA-3 and + SHAKE. +- Random Number Generation: Pseudo Random Number Generator (PRNG) and + a hardware-based True Random Number Generator (TRNG). +- Asymmetric Support: Elliptic Curve Cryptography (ECC) primitives + P-256, P-384, P-521, Montgomery/Edwards curves (e.g., Ed25519). + +Documentation about CPACF instructions is publicly available and +can be found in the "z/Architecture Principles of Operation" +accessible at the IBM documentation hub https://www.ibm.com/docs/en. +For example the latest version as a pdf is available here: +https://www.ibm.com/support/pages/zvm/library/other/22783214.pdf + + +CPACF instructions +------------------ + +Here is a list of implemented CPACF instructions and the supported +functions for each instruction: + +KDSA (COMPUTE DIGITAL SIGNATURE AUTHENTICATION) +- Function code 0x00 - Function Query + +KIMD (COMPUTE INTERMEDIATE MESSAGE DIGEST) +- Function code 0x00 - Function Query +- Function code 0x02 - CPACF_KIMD_SHA_256 +- Function code 0x03 - CPACF_KIMD_SHA_512 + +KLMD (COMPUTE LAST MESSAGE DIGEST) +- Function code 0x00 - Function Query +- Function code 0x02 - CPACF_KLMD_SHA_256 +- Function code 0x03 - CPACF_KLMD_SHA_512 + +KM (CIPHER MESSAGE) +- Function code 0x00 - Function Query +- Function code 0x12 - CPACF_KM_AES_128 +- Function code 0x13 - CPACF_KM_AES_192 +- Function code 0x14 - CPACF_KM_AES_256 +- Function code 0x1a - CPACF_KM_PAES_128 +- Function code 0x1b - CPACF_KM_PAES_192 +- Function code 0x1c - CPACF_KM_PAES_256 +- Function code 0x32 - CPACF_KM_XTS_128 +- Function code 0x34 - CPACF_KM_XTS_256 +- Function code 0x3a - CPACF_KM_PXTS_128 +- Function code 0x3c - CPACF_KM_PXTS_256 + +KMAC (COMPUTE MESSAGE AUTHENTICATION CODE) +- Function code 0x00 - Function Query + +KMC (CIPHER MESSAGE WITH CHAINING) +- Function code 0x00 - Function Query +- Function code 0x12 - CPACF_KMC_AES_128 +- Function code 0x13 - CPACF_KMC_AES_192 +- Function code 0x14 - CPACF_KMC_AES_256 +- Function code 0x1a - CPACF_KMC_PAES_128 +- Function code 0x1b - CPACF_KMC_PAES_192 +- Function code 0x1c - CPACF_KMC_PAES_256 + +KMCTR (CIPHER MESSAGE WITH COUNTER) +- Function code 0x00 - Function Query +- Function code 0x12 - CPACF_KMCTR_AES_128 +- Function code 0x13 - CPACF_KMCTR_AES_192 +- Function code 0x14 - CPACF_KMCTR_AES_256 +- Function code 0x1a - CPACF_KMCTR_PAES_128 +- Function code 0x1b - CPACF_KMCTR_PAES_192 +- Function code 0x1c - CPACF_KMCTR_PAES_256 + +KMF (CIPHER MESSAGE WITH CIPHER FEEDBACK) +- not supported + +KMO (CIPHER MESSAGE WITH OUTPUT FEEDBACK) +- not supported + +PCC (PERFORM CRYPTOGRAPHIC COMPUTATION) +- Function code 0x00 - Function Query +- Function code 0x32 - compute XTS param AES-128 +- Function code 0x34 - compute XTS param AES-256 +- Function code 0x3a - compute XTS param Encrypted AES-128 +- Function code 0x3c - compute XTS param Encrypted AES-256 + +PCKMO (PERFORM CRYPTOGRAPHIC KEY MANAGEMENT OPERATION) +- Function code 0x00 - Function Query +- Function code 0x12 - CPACF_PCKMO_ENC_AES_128_KEY +- Function code 0x13 - CPACF_PCKMO_ENC_AES_192_KEY +- Function code 0x14 - CPACF_PCKMO_ENC_AES_256_KEY + +PRNO (PERFORM RANDOM NUMBER OPERATION) +- Function code 0x00 - Function Query +- Function code 0x72 - CPACF_PRNO_TRNG + +Note that the use of a not supported CPACF instruction (KMF and KMO) +or invocation of a not listed function will result in a Specification +Exception. + +Not listed CPACF instructions (KMA, KMF, KMO) cause an Operation +Exception when used. Not listed functions cause a Specification +Exception when called. If only the query function is listed (KDSA), +then the query function will return a function status word with all +but the query function bit set to 0. + + +Protected key support +--------------------- + +The qemu version for protected key support is only a fake provided +here for developing and testing purpose: + +- The protected key is _derived_ from the clear key by xoring the + fixed pattern 0xAAAA... onto the key value. +- The AES Wrapping Key Verification Pattern is a fixed value of 32 + bytes 0xFACEFACE... + +The PCKMO instruction implementation does exactly this - _derive_ a +_protected_ key from the clear key given by xor 0xAAAA... and writing +the fixed value for the WKVP of 0xFACEFACE into the blob. +The other subfunctions of the CPACF instructions dealing with +protected key treat the protected key blob by first checking for the +WKVP (against the fixed value of 0xFACEFACE...) and second +_decrypting_ the key value by xoring 0xAAAA... and then execute the +clear key operation with the decrypted key value. +This is suitable for testing purpose but such keys are not for real +production load and would open up a huge security breach! + +For more details about protected keys see the "z/Architecture +Principles of Operation" document chapter "General Instructions" +sub-chapter "Protection of Cryptographic Keys" and again the +implementation here does NOT implement what is explained there. diff --git a/docs/system/target-s390x.rst b/docs/system/target-s390x.rst index 94c981e732..49159826eb 100644 --- a/docs/system/target-s390x.rst +++ b/docs/system/target-s390x.rst @@ -35,3 +35,4 @@ Architectural features s390x/bootdevices s390x/protvirt s390x/cpu-topology + s390x/cpacf --=20 2.43.0 From nobody Sun Jul 26 10:59:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783331247; cv=none; d=zohomail.com; s=zohoarc; b=S7OqTaTzI5+AtGrVUcDZHGBPLAg2PxKNSn3Ilw1GmiEKQerljMDkcc4WgZm1mp/u2ovooyNywzMhfsi9hQAHrJHVkfYXTqab73udlVwGIaPvtdxcofO2EnV7kLnZhmkx/CzrBNh/AYyqi/w+OvG4pUnGU4ri8IhfOCt3uQLrMbo= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783331247; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=C5DK+UnxXWoRqDO0GzUFfM+DFq3wC9PBYP/qJ5dH16Q=; b=maFbd2JuE0dQRzRH4CAfulw6Pxlk3sLv0Tk6FIkr05VqllsD/6fWYNRzbvTLxtfvcnK8VmBJWMYprRuz5Wt1/wpOwgRW7aXCGOojOfljCr7Lr2NLM+090emkHOPHMXu2/htnH28fk3/Lnly+pVl+oXc5mGg0+8ctB1tbSdLZGgE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783331247878679.5712650266069; Mon, 6 Jul 2026 02:47:27 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wgfrc-0004Iz-7A; Mon, 06 Jul 2026 05:43:44 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrU-0004EK-Iz; Mon, 06 Jul 2026 05:43:36 -0400 Received: from mx0a-001b2d01.pphosted.com ([148.163.156.1]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrP-0003yC-HU; Mon, 06 Jul 2026 05:43:36 -0400 Received: from pps.filterd (m0353729.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 6669IJeM4015112; Mon, 6 Jul 2026 09:43:25 GMT Received: from ppma21.wdc07v.mail.ibm.com (5b.69.3da9.ip4.static.sl-reverse.com [169.61.105.91]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f6suqgp87-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:24 +0000 (GMT) Received: from pps.filterd (ppma21.wdc07v.mail.ibm.com [127.0.0.1]) by ppma21.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 6669Ya7c028303; Mon, 6 Jul 2026 09:43:23 GMT Received: from smtprelay01.fra02v.mail.ibm.com ([9.218.2.227]) by ppma21.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4f7dgjw0h2-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:23 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (smtpav07.fra02v.mail.ibm.com [10.20.54.106]) by smtprelay01.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 6669hJ8K54722922 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Mon, 6 Jul 2026 09:43:19 GMT Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id A274E20040; Mon, 6 Jul 2026 09:43:19 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 774F420043; Mon, 6 Jul 2026 09:43:19 +0000 (GMT) Received: from funtu2.ibm.com (unknown [9.111.193.81]) by smtpav07.fra02v.mail.ibm.com (Postfix) with ESMTP; Mon, 6 Jul 2026 09:43:19 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=pp1; bh=C5DK+U nxXWoRqDO0GzUFfM+DFq3wC9PBYP/qJ5dH16Q=; b=FLLkMDZ6SHQJtNE8uZh/VQ UwtiwSeVUsCWZAiCyCIPz+D7jzvSiAt5MI9sU738zwJpJOvWiQK49L0TrBhb8LYj hCC31exbfWx3vv2pxJjitVwuB4Ms+ttgG4c5Os+I0pO34dU+cAV4LWW1IcBeGsh5 2UUlg3pXolUNHUKvJ4yiIgkYNYATV89yWxbCQsaNOctZ25t6VfW/50AktnWFrwkC Iih54zNNtZcwpygkfeMWVZodPUTYfQLMxLDL3Yb26xswoik3v9Ug6q7ZZVB4HHrs OW4IRI0OmQ1E1yMAi3yaiCFzi7N+U8M56gBYAUYdn8gyZjK0f8IrniM1O9NltHHA == From: Harald Freudenberger To: richard.henderson@linaro.org, iii@linux.ibm.com, david@kernel.org, thuth@redhat.com, berrange@redhat.com Cc: qemu-s390x@nongnu.org, qemu-devel@nongnu.org, linux-s390@vger.kernel.org, dengler@linux.ibm.com, borntraeger@linux.ibm.com, fcallies@linux.ibm.com, cohuck@redhat.com Subject: [PATCH v10 18/21] crypto: Add aes-helpers file to support some AES modes Date: Mon, 6 Jul 2026 11:43:11 +0200 Message-ID: <20260706094317.17032-19-freude@linux.ibm.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260706094317.17032-1-freude@linux.ibm.com> References: <20260706094317.17032-1-freude@linux.ibm.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Spam-Info: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfX9sBS3b3OFRVf 6W3ISnlLT6vZq7pJTui0xaWytS0vouJuBC6f58dA0XwJnE805FBBQh9rOSYYX4DOq0/MkuGNHBT F115mW2w1MZBMypoD81H3Q4c+/Zs/n4= X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfXyMiVe7Qxu2ln vzLKJjEqe8N5M+I8yCIRExWdBpSPuFMdEQ18zL5KSJ0p6ubMxqI7Dn4DclCDZXuMj3xNm5DAUxK 1/57ZYKumgsL7nfs1eZVD8S3A5AxcegSDanpWhfWNp4+Te84saK0jaK6nY33eEDlE0vuwqjgtJh b25rwYEDQJHpoJcE50TpB1rFkJfCKiyJ7r1abBV5QRV5CQGMoLgu/ljMN8nq3z8twDuFmVPtjsD D7ElB3ytbXP8W609/ohxWCwaKEVjCeXV9cwsxRA3G2t1VXZYwhGWqbc3/D+B3CdynjmTG8M87Ga iGwq2I6vzgbaFYFx+SUM57tqzgpgJg0YMLw+UspwOKMhP38Tp5Q4+bp+sOdmarpEXiMqqIQEexJ EVSCGym14j6iBhRWqdp3WE9v2xGNuMoTU5WDzKbEs6d16b8K8uhL5y8EhJWaIaW/HDGb0tEmswI 6oQzyiAIkanLsS7RLHg== X-Proofpoint-GUID: 8ZAKNanbUyd0d4xyZHI8Lgk6Hz2ZW3qQ X-Authority-Analysis: v=2.4 cv=Oot/DS/t c=1 sm=1 tr=0 ts=6a4b78bc cx=c_pps a=GFwsV6G8L6GxiO2Y/PsHdQ==:117 a=GFwsV6G8L6GxiO2Y/PsHdQ==:17 a=IkcTkHD0fZMA:10 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=uAbxVGIbfxUO_5tXvNgY:22 a=VnNF1IyMAAAA:8 a=ZNJHLeKVfsBpcIed2koA:9 a=3ZKOabzyN94A:10 a=QEXdDO2ut3YA:10 X-Proofpoint-ORIG-GUID: 8ZAKNanbUyd0d4xyZHI8Lgk6Hz2ZW3qQ X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-06_01,2026-07-03_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 bulkscore=0 lowpriorityscore=0 clxscore=1015 impostorscore=0 phishscore=0 malwarescore=0 suspectscore=0 spamscore=0 adultscore=0 priorityscore=1501 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607060094 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.156.1; envelope-from=freude@linux.ibm.com; helo=mx0a-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783331248111158500 Add a new file crypto/aes-helpers.c with simple functions to support some AES modes: - AES cbc: AES_cbc_encrypt() AES_cbc_decrypt() - AES ctr: AES_ctr_encrypt() - AES xts: AES_xts_encrypt() AES_xts_decrypt() and some AES related helpers: - AES_xor() - AES_xts_prep_next_tweak() Signed-off-by: Harald Freudenberger Reviewed-by: Finn Callies --- crypto/aes-helpers.c | 106 +++++++++++++++++++++++++++++++++++++++++++ crypto/meson.build | 1 + include/crypto/aes.h | 14 ++++++ 3 files changed, 121 insertions(+) create mode 100644 crypto/aes-helpers.c diff --git a/crypto/aes-helpers.c b/crypto/aes-helpers.c new file mode 100644 index 0000000000..065a7afabf --- /dev/null +++ b/crypto/aes-helpers.c @@ -0,0 +1,106 @@ +/* + * AES helper functions and mode implementations + * + * Authors: + * Harald Freudenberger + * + * This work is licensed under the terms of the GNU GPL, version 2 or late= r. + * See the COPYING file in the top-level directory. + */ + +#include +#include +#include "crypto/aes.h" + +void AES_xor(const unsigned char *src1, const unsigned char *src2, + unsigned char *dst) +{ + int i; + + for (i =3D 0; i < AES_BLOCK_SIZE; i++) { + dst[i] =3D src1[i] ^ src2[i]; + } +} + +void AES_cbc_encrypt(const unsigned char *in, unsigned char *out, + unsigned char *iv, const AES_KEY *key) +{ + unsigned char buf[AES_BLOCK_SIZE]; + + /* in xor iv =3D> buf */ + AES_xor(in, iv, buf); + /* encrypt buf =3D> out */ + AES_encrypt(buf, out, key); + /* prep iv for next round */ + memcpy(iv, out, AES_BLOCK_SIZE); +} + +void AES_cbc_decrypt(const unsigned char *in, unsigned char *out, + unsigned char *iv, const AES_KEY *key) +{ + unsigned char buf[AES_BLOCK_SIZE]; + + /* decrypt in =3D> buf */ + AES_decrypt(in, buf, key); + /* buf xor iv =3D> out */ + AES_xor(buf, iv, out); + /* prep iv for next round */ + memcpy(iv, in, AES_BLOCK_SIZE); +} + +void AES_ctr_encrypt(const unsigned char *in, unsigned char *out, + const unsigned char *ctr, const AES_KEY *key) +{ + unsigned char buf[AES_BLOCK_SIZE]; + + /* encrypt ctr =3D> buf */ + AES_encrypt(ctr, buf, key); + /* exor input data with encrypted ctr =3D> out */ + AES_xor(in, buf, out); +} + +/* Tweak calculation for AES XTS. + * Multiply tweak by =CE=B1 (x) in GF(2^128) per IEEE 1619-2007. The tweak + * is a 128-bit little-endian integer (tweak[0]=3DLSB, tweak[15]=3DMSB). + * This implementation has been verified on litte and big endian. + */ +void AES_xts_prep_next_tweak(unsigned char *tweak) +{ + unsigned char carry; + int i; + + carry =3D tweak[AES_BLOCK_SIZE - 1] >> 7; + + for (i =3D AES_BLOCK_SIZE - 1; i > 0; i--) { + tweak[i] =3D (unsigned char)((tweak[i] << 1) | (tweak[i - 1] >> 7)= ); + } + + tweak[i] =3D (unsigned char)(tweak[i] << 1); + tweak[i] ^=3D (unsigned char)(0x87 & (unsigned char)(-(unsigned char)c= arry)); +} + +void AES_xts_encrypt(const unsigned char *in, unsigned char *out, + const unsigned char *tweak, const AES_KEY *key) +{ + unsigned char buf1[AES_BLOCK_SIZE], buf2[AES_BLOCK_SIZE]; + + /* in xor tweak =3D> buf1 */ + AES_xor(in, tweak, buf1); + /* encrypt buf1 =3D> buf2 */ + AES_encrypt(buf1, buf2, key); + /* buf2 xor tweak =3D> out */ + AES_xor(buf2, tweak, out); +} + +void AES_xts_decrypt(const unsigned char *in, unsigned char *out, + const unsigned char *tweak, const AES_KEY *key) +{ + unsigned char buf1[AES_BLOCK_SIZE], buf2[AES_BLOCK_SIZE]; + + /* in xor tweak =3D> buf1 */ + AES_xor(in, tweak, buf1); + /* encrypt buf1 =3D> buf2 */ + AES_decrypt(buf1, buf2, key); + /* buf2 xor tweak =3D> out */ + AES_xor(buf2, tweak, out); +} diff --git a/crypto/meson.build b/crypto/meson.build index b51597a879..675f27311c 100644 --- a/crypto/meson.build +++ b/crypto/meson.build @@ -55,6 +55,7 @@ system_ss.add(when: gnutls, if_true: files('tls-cipher-su= ites.c')) =20 util_ss.add(files( 'aes.c', + 'aes-helpers.c', 'clmul.c', 'init.c', 'sm4.c', diff --git a/include/crypto/aes.h b/include/crypto/aes.h index 381f24c902..df6239cb9c 100644 --- a/include/crypto/aes.h +++ b/include/crypto/aes.h @@ -37,4 +37,18 @@ AES_Td0[x] =3D Si[x].[0e, 09, 0d, 0b]; =20 extern const uint32_t AES_Te0[256], AES_Td0[256]; =20 +void AES_xor(const unsigned char *src1, const unsigned char *src2, + unsigned char *dst); +void AES_cbc_encrypt(const unsigned char *in, unsigned char *out, + unsigned char *iv, const AES_KEY *key); +void AES_cbc_decrypt(const unsigned char *in, unsigned char *out, + unsigned char *iv, const AES_KEY *key); +void AES_ctr_encrypt(const unsigned char *in, unsigned char *out, + const unsigned char *ctr, const AES_KEY *key); +void AES_xts_prep_next_tweak(unsigned char *tweak); +void AES_xts_encrypt(const unsigned char *in, unsigned char *out, + const unsigned char *tweak, const AES_KEY *key); +void AES_xts_decrypt(const unsigned char *in, unsigned char *out, + const unsigned char *tweak, const AES_KEY *key); + #endif --=20 2.43.0 From nobody Sun Jul 26 10:59:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783331128; cv=none; d=zohomail.com; s=zohoarc; b=REhrot7egSPMSwU5P7uo9J8SRoz0Xu9Rngpp9ckIQB1PmMtY/t+DuOkf8pP2lqLYh7X6RLB3UNEY/IJ8Kov0vy6xSJUE6FwD6fRqnUXrfuSTmjnfWDgrkIIv0HdtPlHWGDB6v6Bbs8gmO0cAquXljuz8edfHQGXe6254gFq6Er0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783331128; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Ze+ofQ249c2bgpyuG2nNIbxolu8buY+EOcQgqBE2SmE=; b=WReJffqf3PbGum0Z34P7rENgRcQSp67wW0atoZ02IVysMhfpzFEC4dH4DZjsiAMu7w/wTPkBygoZpTCRtyoILMBxfi/AjkmxWCZwvtTP62kSW8PXn3vQf6a7zwTwT/qec0feeRVRLed11CaYYiKJ9moCRNxIOQlFROV9pdg7Xcs= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783331128897582.6916881507019; Mon, 6 Jul 2026 02:45:28 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wgfs0-0004TM-N3; Mon, 06 Jul 2026 05:44:08 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrn-0004Qg-8x; Mon, 06 Jul 2026 05:43:56 -0400 Received: from mx0a-001b2d01.pphosted.com ([148.163.156.1]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrj-0003y1-Ek; Mon, 06 Jul 2026 05:43:55 -0400 Received: from pps.filterd (m0356517.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 6669IOVi3783329; Mon, 6 Jul 2026 09:43:25 GMT Received: from ppma13.dal12v.mail.ibm.com (dd.9e.1632.ip4.static.sl-reverse.com [50.22.158.221]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f6sw4gqwv-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:24 +0000 (GMT) Received: from pps.filterd (ppma13.dal12v.mail.ibm.com [127.0.0.1]) by ppma13.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 6669YeUD021143; Mon, 6 Jul 2026 09:43:23 GMT Received: from smtprelay01.fra02v.mail.ibm.com ([9.218.2.227]) by ppma13.dal12v.mail.ibm.com (PPS) with ESMTPS id 4f7eqfvs21-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:23 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (smtpav07.fra02v.mail.ibm.com [10.20.54.106]) by smtprelay01.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 6669hJrv50397646 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Mon, 6 Jul 2026 09:43:20 GMT Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id D928F20040; Mon, 6 Jul 2026 09:43:19 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id A6AE22004B; Mon, 6 Jul 2026 09:43:19 +0000 (GMT) Received: from funtu2.ibm.com (unknown [9.111.193.81]) by smtpav07.fra02v.mail.ibm.com (Postfix) with ESMTP; Mon, 6 Jul 2026 09:43:19 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=Ze+ofQ249c2bgpyuG 2nNIbxolu8buY+EOcQgqBE2SmE=; b=fWY780G8AFnynM2zw3wHphquRKMuPg05H Unju/iXOZKbR4LHJ2MgikbcmFP/aWKRQt4yIDNGZJTEEBDJ5QnU4A10ApFNSrk0a +O88KJx1ru/GxWMkjsMjDb92xpitlyb0R3Yzl9qAFHWVPl4iieDD/C2Lpix39JRO LisL6yZhS6D6gLgVdaliHx9LiDNWmdUD0rYOLtYv33GfB0a7C/HKc8oPJKkr0mpu CZwpJgzBXcUXmsSm4QVtWMIFE1/F/FkQCDwS47h7auIR1fgxKgVMJURNKsNfKYn7 46emrcmJPrFZDELQW+IV4S9KIIXuz+FtCSd745wPyshoit3zB5bxQ== From: Harald Freudenberger To: richard.henderson@linaro.org, iii@linux.ibm.com, david@kernel.org, thuth@redhat.com, berrange@redhat.com Cc: qemu-s390x@nongnu.org, qemu-devel@nongnu.org, linux-s390@vger.kernel.org, dengler@linux.ibm.com, borntraeger@linux.ibm.com, fcallies@linux.ibm.com, cohuck@redhat.com Subject: [PATCH v10 19/21] target/s390x: Use generic AES helper functions Date: Mon, 6 Jul 2026 11:43:12 +0200 Message-ID: <20260706094317.17032-20-freude@linux.ibm.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260706094317.17032-1-freude@linux.ibm.com> References: <20260706094317.17032-1-freude@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-GUID: ovfanZAc0jXWzru0zpSN5ue--deS78JV X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfXzzDxisu8gsNj skHnFXGZZRqrtmlUelMjIvi8be6SIbcziZcWPwu8LcMqcnWd91mKQKpKdBSZPoszlKfNGew16bp 64MV8dItZ99hMVBodmBIyYcI0Z+qH3u+Z74RGkJO6vpF+B8RtcjiHuhCS37+gQcmKMShVd7n8n2 r7aVCyo/j6AjNNZ9Bpn7eO6huswdN9Kx0C/1A4Sfg8BFsB939CGrXFDEkY4nV9YLx46gON2lHB0 zP9pDtwJlFqWvk6CfNgqm3LpiQWgFxtjocM9aPcfv/nZCTaQ0EnzNXu22lOYIgItLYrDJiHyH70 wP5dF5sOzsYsClDNKqVo2jdaKqSpuLguvzAjcUPP8Qc/uVQa/Y3Duo5SyUufCphDqcsfk4mAvrj teG6+OFu3YiDCm4hhSG+hIW4EEHbIxd1IqFvdfhFmvBASlYK+C6ZPUr+F06FoqagVTpcSrcMdbq mGLzmEELJlJqnfmoxYQ== X-Proofpoint-ORIG-GUID: ovfanZAc0jXWzru0zpSN5ue--deS78JV X-Authority-Analysis: v=2.4 cv=FqQ1OWrq c=1 sm=1 tr=0 ts=6a4b78bc cx=c_pps a=AfN7/Ok6k8XGzOShvHwTGQ==:117 a=AfN7/Ok6k8XGzOShvHwTGQ==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=U7nrCbtTmkRpXpFmAIza:22 a=VnNF1IyMAAAA:8 a=ccJ9v8fwxLVEcBnUSYMA:9 X-Proofpoint-Spam-Info: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfX0vaLAzKapJmN jHzgVrzH2WsYdQ69aMdjL+pY47FKaNIE14iZ1DkVwf6W7Zm0coIb/rqC1eRCi30iVQ3od4ihZvf f74DS9IpSFnLmYWwA4C6TFbI7Iqiqps= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-06_01,2026-07-03_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 adultscore=0 impostorscore=0 clxscore=1015 malwarescore=0 lowpriorityscore=0 priorityscore=1501 bulkscore=0 suspectscore=0 spamscore=0 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607060094 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.156.1; envelope-from=freude@linux.ibm.com; helo=mx0a-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783331129417158500 Content-Type: text/plain; charset="utf-8" Rewrite the cpacf implementations to use the generic AES helper functions from crypto/aes-helpers.c Signed-off-by: Harald Freudenberger Reviewed-by: Finn Callies --- target/s390x/tcg/cpacf_aes.c | 124 ++++++++++------------------------- 1 file changed, 36 insertions(+), 88 deletions(-) diff --git a/target/s390x/tcg/cpacf_aes.c b/target/s390x/tcg/cpacf_aes.c index 0c3cbb29e3..4298a0eac6 100644 --- a/target/s390x/tcg/cpacf_aes.c +++ b/target/s390x/tcg/cpacf_aes.c @@ -111,20 +111,13 @@ int cpacf_aes_ecb(CPUS390XState *env, const int mmu_i= dx, uintptr_t ra, return !len ? 0 : 3; } =20 -static void aes_xor(const uint8_t *src1, const uint8_t *src2, uint8_t *dst) -{ - for (int i =3D 0; i < AES_BLOCK_SIZE; i++) { - dst[i] =3D src1[i] ^ src2[i]; - } -} - int cpacf_aes_cbc(CPUS390XState *env, const int mmu_idx, uintptr_t ra, uint64_t param_addr, uint64_t *dst_ptr_reg, uint64_t *src_ptr_reg, uint64_t *src_len_reg, uint32_t type, uint8_t fc, uint8_t mod) { enum { MAX_BLOCKS_PER_RUN =3D 8192 / AES_BLOCK_SIZE }; - uint8_t in[AES_BLOCK_SIZE], out[AES_BLOCK_SIZE], buf[AES_BLOCK_SIZE]; + uint8_t in[AES_BLOCK_SIZE], out[AES_BLOCK_SIZE]; const MemOpIdx oi =3D make_memop_idx(MO_8, mmu_idx); uint64_t addr, len =3D *src_len_reg, done =3D 0; int i, keysize, addr_reg_size =3D 64; @@ -180,19 +173,11 @@ int cpacf_aes_cbc(CPUS390XState *env, const int mmu_i= dx, uintptr_t ra, for (i =3D 0; i < MAX_BLOCKS_PER_RUN && len >=3D AES_BLOCK_SIZE; i++) { aes_read_block(env, mmu_idx, *src_ptr_reg + done, in, ra); if (mod) { - /* decrypt in =3D> buf */ - AES_decrypt(in, buf, &exkey); - /* buf xor iv =3D> out */ - aes_xor(buf, iv, out); - /* prep iv for next round */ - memcpy(iv, in, AES_BLOCK_SIZE); + /* decrypt in =3D> out */ + AES_cbc_decrypt(in, out, iv, &exkey); } else { - /* in xor iv =3D> buf */ - aes_xor(in, iv, buf); - /* encrypt buf =3D> out */ - AES_encrypt(buf, out, &exkey); - /* prep iv for next round */ - memcpy(iv, out, AES_BLOCK_SIZE); + /* encrypt in =3D> out */ + AES_cbc_encrypt(in, out, iv, &exkey); } aes_write_block(env, mmu_idx, *dst_ptr_reg + done, out, ra); len -=3D AES_BLOCK_SIZE; @@ -222,11 +207,10 @@ int cpacf_aes_ctr(CPUS390XState *env, const int mmu_i= dx, uintptr_t ra, { enum { MAX_BLOCKS_PER_RUN =3D 8192 / AES_BLOCK_SIZE }; const MemOpIdx oi =3D make_memop_idx(MO_8, mmu_idx); - uint8_t ctr[AES_BLOCK_SIZE], buf[AES_BLOCK_SIZE]; uint8_t in[AES_BLOCK_SIZE], out[AES_BLOCK_SIZE]; uint64_t addr, len =3D *src_len_reg, done =3D 0; + uint8_t ctr[AES_BLOCK_SIZE], key[32]; int i, keysize, addr_reg_size =3D 64; - uint8_t key[32]; AES_KEY exkey; =20 g_assert(type =3D=3D S390_FEAT_TYPE_KMCTR); @@ -268,12 +252,10 @@ int cpacf_aes_ctr(CPUS390XState *env, const int mmu_i= dx, uintptr_t ra, for (i =3D 0; i < MAX_BLOCKS_PER_RUN && len >=3D AES_BLOCK_SIZE; i++) { /* read in nonce/ctr =3D> ctr */ aes_read_block(env, mmu_idx, *ctr_ptr_reg + done, ctr, ra); - /* encrypt ctr =3D> buf */ - AES_encrypt(ctr, buf, &exkey); /* read in one block of input data =3D> in */ aes_read_block(env, mmu_idx, *src_ptr_reg + done, in, ra); - /* xor input data with encrypted ctr =3D> out */ - aes_xor(in, buf, out); + /* encrypt ctr and xor with in =3D> out */ + AES_ctr_encrypt(in, out, ctr, &exkey); /* write out the processed block */ aes_write_block(env, mmu_idx, *dst_ptr_reg + done, out, ra); len -=3D AES_BLOCK_SIZE; @@ -354,28 +336,13 @@ int cpacf_aes_pcc(CPUS390XState *env, const int mmu_i= dx, uintptr_t ra, return 0; } =20 -static void aes_xts_prep_next_tweak(uint8_t tweak[AES_BLOCK_SIZE]) -{ - uint8_t carry; - int i; - - carry =3D tweak[AES_BLOCK_SIZE - 1] >> 7; - - for (i =3D AES_BLOCK_SIZE - 1; i > 0; i--) { - tweak[i] =3D (uint8_t)((tweak[i] << 1) | (tweak[i - 1] >> 7)); - } - - tweak[i] =3D (uint8_t)(tweak[i] << 1); - tweak[i] ^=3D (uint8_t)(0x87 & (uint8_t)(-(int8_t)carry)); -} - int cpacf_aes_xts(CPUS390XState *env, const int mmu_idx, uintptr_t ra, uint64_t param_addr, uint64_t *dst_ptr_reg, uint64_t *src_ptr_reg, uint64_t *src_len_reg, uint32_t type, uint8_t fc, uint8_t mod) { enum { MAX_BLOCKS_PER_RUN =3D 8192 / AES_BLOCK_SIZE }; - uint8_t buf1[AES_BLOCK_SIZE], buf2[AES_BLOCK_SIZE]; + uint8_t in[AES_BLOCK_SIZE], out[AES_BLOCK_SIZE]; const MemOpIdx oi =3D make_memop_idx(MO_8, mmu_idx); uint64_t addr, len =3D *src_len_reg, done =3D 0; uint8_t key[32], tweak[AES_BLOCK_SIZE]; @@ -426,23 +393,19 @@ int cpacf_aes_xts(CPUS390XState *env, const int mmu_i= dx, uintptr_t ra, =20 /* process up to MAX_BLOCKS_PER_RUN aes blocks */ for (i =3D 0; i < MAX_BLOCKS_PER_RUN && len >=3D AES_BLOCK_SIZE; i++) { - /* fetch one AES block into buf1 */ - aes_read_block(env, mmu_idx, *src_ptr_reg + done, buf1, ra); - /* buf1 xor tweak =3D> buf2 */ - aes_xor(buf1, tweak, buf2); + /* fetch one AES block into in */ + aes_read_block(env, mmu_idx, *src_ptr_reg + done, in, ra); if (mod) { - /* decrypt buf2 =3D> buf1 */ - AES_decrypt(buf2, buf1, &exkey); + /* decrypt in =3D> out */ + AES_xts_decrypt(in, out, tweak, &exkey); } else { - /* encrypt buf2 =3D> buf1 */ - AES_encrypt(buf2, buf1, &exkey); + /* encrypt in =3D> out */ + AES_xts_encrypt(in, out, tweak, &exkey); } - /* buf1 xor tweak =3D> buf2 */ - aes_xor(buf1, tweak, buf2); /* prep tweak for next round */ - aes_xts_prep_next_tweak(tweak); - /* write out this processed block from buf2 */ - aes_write_block(env, mmu_idx, *dst_ptr_reg + done, buf2, ra); + AES_xts_prep_next_tweak(tweak); + /* write out this processed block from out */ + aes_write_block(env, mmu_idx, *dst_ptr_reg + done, out, ra); len -=3D AES_BLOCK_SIZE; done +=3D AES_BLOCK_SIZE; } @@ -638,7 +601,7 @@ int cpacf_paes_cbc(CPUS390XState *env, const int mmu_id= x, uintptr_t ra, uint32_t type, uint8_t fc, uint8_t mod) { enum { MAX_BLOCKS_PER_RUN =3D 8192 / AES_BLOCK_SIZE }; - uint8_t in[AES_BLOCK_SIZE], out[AES_BLOCK_SIZE], buf[AES_BLOCK_SIZE]; + uint8_t in[AES_BLOCK_SIZE], out[AES_BLOCK_SIZE]; const MemOpIdx oi =3D make_memop_idx(MO_8, mmu_idx); uint8_t key[32], wkvp[32], iv[AES_BLOCK_SIZE]; uint64_t addr, len =3D *src_len_reg, done =3D 0; @@ -706,19 +669,11 @@ int cpacf_paes_cbc(CPUS390XState *env, const int mmu_= idx, uintptr_t ra, for (i =3D 0; i < MAX_BLOCKS_PER_RUN && len >=3D AES_BLOCK_SIZE; i++) { aes_read_block(env, mmu_idx, *src_ptr_reg + done, in, ra); if (mod) { - /* decrypt in =3D> buf */ - AES_decrypt(in, buf, &exkey); - /* buf xor iv =3D> out */ - aes_xor(buf, iv, out); - /* prep iv for next round */ - memcpy(iv, in, AES_BLOCK_SIZE); + /* decrypt in =3D> out */ + AES_cbc_decrypt(in, out, iv, &exkey); } else { - /* in xor iv =3D> buf */ - aes_xor(in, iv, buf); - /* encrypt buf =3D> out */ - AES_encrypt(buf, out, &exkey); - /* prep iv for next round */ - memcpy(iv, out, AES_BLOCK_SIZE); + /* encrypt in =3D> out */ + AES_cbc_encrypt(in, out, iv, &exkey); } aes_write_block(env, mmu_idx, *dst_ptr_reg + done, out, ra); len -=3D AES_BLOCK_SIZE; @@ -748,11 +703,10 @@ int cpacf_paes_ctr(CPUS390XState *env, const int mmu_= idx, uintptr_t ra, { enum { MAX_BLOCKS_PER_RUN =3D 8192 / AES_BLOCK_SIZE }; const MemOpIdx oi =3D make_memop_idx(MO_8, mmu_idx); - uint8_t ctr[AES_BLOCK_SIZE], buf[AES_BLOCK_SIZE]; uint8_t in[AES_BLOCK_SIZE], out[AES_BLOCK_SIZE]; + uint8_t ctr[AES_BLOCK_SIZE], key[32], wkvp[32]; uint64_t addr, len =3D *src_len_reg, done =3D 0; int i, keysize, addr_reg_size =3D 64; - uint8_t key[32], wkvp[32]; AES_KEY exkey; =20 g_assert(type =3D=3D S390_FEAT_TYPE_KMCTR); @@ -806,12 +760,10 @@ int cpacf_paes_ctr(CPUS390XState *env, const int mmu_= idx, uintptr_t ra, for (i =3D 0; i < MAX_BLOCKS_PER_RUN && len >=3D AES_BLOCK_SIZE; i++) { /* read in nonce/ctr =3D> ctr */ aes_read_block(env, mmu_idx, *ctr_ptr_reg + done, ctr, ra); - /* encrypt ctr =3D> buf */ - AES_encrypt(ctr, buf, &exkey); /* read in one block of input data =3D> in */ aes_read_block(env, mmu_idx, *src_ptr_reg + done, in, ra); - /* exor input data with encrypted ctr =3D> out */ - aes_xor(in, buf, out); + /* encrypt ctr and xor with in =3D> out */ + AES_ctr_encrypt(in, out, ctr, &exkey); /* write out the processed block */ aes_write_block(env, mmu_idx, *dst_ptr_reg + done, out, ra); len -=3D AES_BLOCK_SIZE; @@ -912,7 +864,7 @@ int cpacf_paes_xts(CPUS390XState *env, const int mmu_id= x, uintptr_t ra, uint32_t type, uint8_t fc, uint8_t mod) { enum { MAX_BLOCKS_PER_RUN =3D 8192 / AES_BLOCK_SIZE }; - uint8_t buf1[AES_BLOCK_SIZE], buf2[AES_BLOCK_SIZE]; + uint8_t in[AES_BLOCK_SIZE], out[AES_BLOCK_SIZE]; const MemOpIdx oi =3D make_memop_idx(MO_8, mmu_idx); uint8_t key[32], wkvp[32], tweak[AES_BLOCK_SIZE]; uint64_t addr, len =3D *src_len_reg, done =3D 0; @@ -975,23 +927,19 @@ int cpacf_paes_xts(CPUS390XState *env, const int mmu_= idx, uintptr_t ra, =20 /* process up to MAX_BLOCKS_PER_RUN aes blocks */ for (i =3D 0; i < MAX_BLOCKS_PER_RUN && len >=3D AES_BLOCK_SIZE; i++) { - /* fetch one AES block into buf1 */ - aes_read_block(env, mmu_idx, *src_ptr_reg + done, buf1, ra); - /* buf1 xor tweak =3D> buf2 */ - aes_xor(buf1, tweak, buf2); + /* fetch one AES block into in */ + aes_read_block(env, mmu_idx, *src_ptr_reg + done, in, ra); if (mod) { - /* decrypt buf2 =3D> buf1 */ - AES_decrypt(buf2, buf1, &exkey); + /* decrypt in =3D> out */ + AES_xts_decrypt(in, out, tweak, &exkey); } else { - /* encrypt buf2 =3D> buf1 */ - AES_encrypt(buf2, buf1, &exkey); + /* encrypt in =3D> out */ + AES_xts_encrypt(in, out, tweak, &exkey); } - /* buf1 xor tweak =3D> buf2 */ - aes_xor(buf1, tweak, buf2); /* prep tweak for next round */ - aes_xts_prep_next_tweak(tweak); - /* write out this processed block from buf2 */ - aes_write_block(env, mmu_idx, *dst_ptr_reg + done, buf2, ra); + AES_xts_prep_next_tweak(tweak); + /* write out this processed block from out */ + aes_write_block(env, mmu_idx, *dst_ptr_reg + done, out, ra); len -=3D AES_BLOCK_SIZE; done +=3D AES_BLOCK_SIZE; } --=20 2.43.0 From nobody Sun Jul 26 10:59:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783331080; cv=none; d=zohomail.com; s=zohoarc; b=g208fa1fgIB6YT+SRnHx+J799u/zABLixU1Cm4neHKsy/tl9JdB11JraroA0PmKF3bqqU4AJO0v2O8AcACNHnI20dOY7yYui5S49Q6kVFEo5l0SqlLsurhayYDxbUgZjLMrroeolMHFu/wqZbWXrNAb8I/bNhbo6z6auPPzhZB8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783331080; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=SMcfvUuy1FF4Yj2Z98N8Bq+9kGrY0iMwV3cE0YsF+Wg=; b=RXnb9RjvRo8EEw8hEHfva0qvd6DkAVLk0KryQV46/FSoUDp1Ig4vlecTr+emWfR3GwmX8XSLH2cQqzGjbPrWGZ+z009ucA6+IWNcGf7rZonnyuvbt7GROOU7ZI24ha/EvDLs+doOexHxrrxsCfloBA21uvo8qcTjFEM+XeeL5EA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783331080920687.0950442286363; Mon, 6 Jul 2026 02:44:40 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wgfs1-0004TN-Jo; Mon, 06 Jul 2026 05:44:09 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfro-0004Qw-C4; Mon, 06 Jul 2026 05:43:57 -0400 Received: from mx0a-001b2d01.pphosted.com ([148.163.156.1]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrj-0003yW-Ek; Mon, 06 Jul 2026 05:43:56 -0400 Received: from pps.filterd (m0360083.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 6669IGGS3890041; Mon, 6 Jul 2026 09:43:25 GMT Received: from ppma23.wdc07v.mail.ibm.com (5d.69.3da9.ip4.static.sl-reverse.com [169.61.105.93]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f6sp3gsr3-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:25 +0000 (GMT) Received: from pps.filterd (ppma23.wdc07v.mail.ibm.com [127.0.0.1]) by ppma23.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 6669Ydp6005612; Mon, 6 Jul 2026 09:43:24 GMT Received: from smtprelay06.fra02v.mail.ibm.com ([9.218.2.230]) by ppma23.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4f7e0h4w4d-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:24 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (smtpav07.fra02v.mail.ibm.com [10.20.54.106]) by smtprelay06.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 6669hKSo29950316 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Mon, 6 Jul 2026 09:43:20 GMT Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 370932004B; Mon, 6 Jul 2026 09:43:20 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id DE58820043; Mon, 6 Jul 2026 09:43:19 +0000 (GMT) Received: from funtu2.ibm.com (unknown [9.111.193.81]) by smtpav07.fra02v.mail.ibm.com (Postfix) with ESMTP; Mon, 6 Jul 2026 09:43:19 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=SMcfvUuy1FF4Yj2Z9 8N8Bq+9kGrY0iMwV3cE0YsF+Wg=; b=B7C9GrRGPQinYhADMIHrOdknB4GbU/pu5 GnPHU6u8ghyZJbs6HwHSBLdIKW+JHrwWZ0tUV9rwxoziz+2Bpx2b9i5wlChL/vvd lhp5phrHvq7AB5+aTpBq/WeMJb3idiCELq1WnfpM1AkCWQFhlmpo+KSBokzd3BxT 4pduppXy5VIw1nZF2Qo3VakStuda3PBJDn+OyTXj9HBjKinXcABqK4mNe2dH6BBS h7mS/OgTAIHHFX7yc9gq4oGT0y8Mgi76OzDE/NuygKy5bwdDz15RaoCsvM1nsz0z j1k4lp9uyJ09l1GLTcVJbBi12QuXjJovTZQV6Gh1sPhzoWU5YrJDw== From: Harald Freudenberger To: richard.henderson@linaro.org, iii@linux.ibm.com, david@kernel.org, thuth@redhat.com, berrange@redhat.com Cc: qemu-s390x@nongnu.org, qemu-devel@nongnu.org, linux-s390@vger.kernel.org, dengler@linux.ibm.com, borntraeger@linux.ibm.com, fcallies@linux.ibm.com, cohuck@redhat.com Subject: [PATCH v10 20/21] target/s390x: Improve fetch and store mem from and to guest Date: Mon, 6 Jul 2026 11:43:13 +0200 Message-ID: <20260706094317.17032-21-freude@linux.ibm.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260706094317.17032-1-freude@linux.ibm.com> References: <20260706094317.17032-1-freude@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Authority-Analysis: v=2.4 cv=KsJ9H2WN c=1 sm=1 tr=0 ts=6a4b78bd cx=c_pps a=3Bg1Hr4SwmMryq2xdFQyZA==:117 a=3Bg1Hr4SwmMryq2xdFQyZA==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=iQ6ETzBq9ecOQQE5vZCe:22 a=VnNF1IyMAAAA:8 a=SH-LS3B6E9p2pXL9WtEA:9 a=ZDSMja1iq-x7GFnX:21 X-Proofpoint-Spam-Info: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfX6GB7zy8FDNNj g+tjZAombq5Ycr5jd/MEEfuklQTu4pUWlb49jkZchFXzuRUyWb+Yes1aM5mXYInz/mh3F5I7UOY 6z2z5XDHn1GL3/l5jXGI3f7QXDUVh3o= X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfXzWto1CdHcy2X wz611oCMee4NCwnCypP3qsRUzoEx/QuYonRoEHQY8PUrMlerc9438XFfd8JgnC6JrNwHM3XPlzp zUOvjLVorH0fUu3zuVQyxPJ+1pQi8k5NZHN1CpofO1eJEykT+WFLh5nG1KF5FPApUlpZ7n+LRRT i8H+SsqAP679+d6feGUwm3JvWbhbBo29hpkezJsagpnCMFNAq6PZoAqIowFxymsDbHGcqssJac9 HomHs2XrHzA9qhznAH5aZIeBMBnnTzZ/6VA3pIVtwhhZWI+GhK3vLsGoMazRtwtZyQasMNCbZPM ojXnCx7xtgKVSgQ4by6iZN3fWm8hZKwn8SW7eZTmTKKHMbcURF9J+IAuPJAZh28y3hMrYbRn1Tp R5axWHFwA81h4xg9cdC0ulzAWuODMhmIbX1zjOT9X5uhaYCtfCzeOEvn6UmsJIQHh6e89onO+28 4Gi5yj3Q+sak5S7iHVQ== X-Proofpoint-ORIG-GUID: i-Sab2cZsFIsqfqShN6gRlW_1GeFjapa X-Proofpoint-GUID: i-Sab2cZsFIsqfqShN6gRlW_1GeFjapa X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-06_01,2026-07-03_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 impostorscore=0 malwarescore=0 spamscore=0 adultscore=0 clxscore=1015 suspectscore=0 lowpriorityscore=0 priorityscore=1501 bulkscore=0 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607060094 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.156.1; envelope-from=freude@linux.ibm.com; helo=mx0a-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783331083175158500 Content-Type: text/plain; charset="utf-8" Introduce helper functions: * copy_from_guest_wrap() * copy_to_guest_wrap() for copy some memory from guest into a local buffer and the reverse direction. Rework the other functions to use these helpers. By doing so some local variables could be removed also and the code is better readable now. Suggested-by: Ilya Leoshkevich Signed-off-by: Harald Freudenberger --- target/s390x/tcg/cpacf_aes.c | 305 ++++++++++++++--------------------- 1 file changed, 124 insertions(+), 181 deletions(-) diff --git a/target/s390x/tcg/cpacf_aes.c b/target/s390x/tcg/cpacf_aes.c index 4298a0eac6..15124f3274 100644 --- a/target/s390x/tcg/cpacf_aes.c +++ b/target/s390x/tcg/cpacf_aes.c @@ -16,37 +16,64 @@ #include "crypto/aes.h" #include "target/s390x/tcg/cpacf.h" =20 -static void aes_read_block(CPUS390XState *env, const int mmu_idx, - uint64_t addr, uint8_t *a, uintptr_t ra) +/* + * helper function to copy some memory from guest to a local buffer + */ +static inline void copy_from_guest_wrap(CPUS390XState *env, const int mmu_= idx, + const uintptr_t ra, uint64_t guest= _addr, + uint8_t *dest, size_t len) { const MemOpIdx oi =3D make_memop_idx(MO_8, mmu_idx); =20 - for (int i =3D 0; i < AES_BLOCK_SIZE; i++, addr +=3D 1) { - uint64_t _addr =3D wrap_address(env, addr); - a[i] =3D cpu_ldb_mmu(env, _addr, oi, ra); + for (size_t i =3D 0; i < len; i++, guest_addr++) { + uint64_t waddr =3D wrap_address(env, guest_addr); + dest[i] =3D cpu_ldb_mmu(env, waddr, oi, ra); } } =20 -static void aes_write_block(CPUS390XState *env, const int mmu_idx, - uint64_t addr, uint8_t *a, uintptr_t ra) +/* + * helper function to copy from a local buffer to guest memory + */ +static inline void copy_to_guest_wrap(CPUS390XState *env, const int mmu_id= x, + const uintptr_t ra, uint64_t guest_a= ddr, + const uint8_t *src, size_t len) { const MemOpIdx oi =3D make_memop_idx(MO_8, mmu_idx); =20 - for (int i =3D 0; i < AES_BLOCK_SIZE; i++, addr +=3D 1) { - uint64_t _addr =3D wrap_address(env, addr); - cpu_stb_mmu(env, _addr, a[i], oi, ra); + for (size_t i =3D 0; i < len; i++, guest_addr++) { + uint64_t waddr =3D wrap_address(env, guest_addr); + cpu_stb_mmu(env, waddr, src[i], oi, ra); } } =20 +/* + * read exactly one AES block from guest memory into a local buffer + */ +static inline void aes_read_block(CPUS390XState *env, const int mmu_idx, + const uintptr_t ra, uint64_t guest_addr, + uint8_t *buf) +{ + copy_from_guest_wrap(env, mmu_idx, ra, guest_addr, buf, AES_BLOCK_SIZE= ); +} + +/* + * write exactly one AES block from local buffer to guest memory + */ +static void aes_write_block(CPUS390XState *env, const int mmu_idx, + const uintptr_t ra, uint64_t guest_addr, + uint8_t *buf) +{ + copy_to_guest_wrap(env, mmu_idx, ra, guest_addr, buf, AES_BLOCK_SIZE); +} + int cpacf_aes_ecb(CPUS390XState *env, const int mmu_idx, uintptr_t ra, uint64_t param_addr, uint64_t *dst_ptr_reg, uint64_t *src_ptr_reg, uint64_t *src_len_reg, uint32_t type, uint8_t fc, uint8_t mod) { enum { MAX_BLOCKS_PER_RUN =3D 8192 / AES_BLOCK_SIZE }; - const MemOpIdx oi =3D make_memop_idx(MO_8, mmu_idx); uint8_t in[AES_BLOCK_SIZE], out[AES_BLOCK_SIZE]; - uint64_t addr, len =3D *src_len_reg, done =3D 0; + uint64_t len =3D *src_len_reg, done =3D 0; int i, keysize, addr_reg_size =3D 64; uint8_t key[32]; AES_KEY exkey; @@ -77,10 +104,7 @@ int cpacf_aes_ecb(CPUS390XState *env, const int mmu_idx= , uintptr_t ra, } =20 /* fetch key from param block */ - for (i =3D 0; i < keysize; i++) { - addr =3D wrap_address(env, param_addr + i); - key[i] =3D cpu_ldb_mmu(env, addr, oi, ra); - } + copy_from_guest_wrap(env, mmu_idx, ra, param_addr, key, keysize); =20 /* expand key */ if (mod) { @@ -91,13 +115,13 @@ int cpacf_aes_ecb(CPUS390XState *env, const int mmu_id= x, uintptr_t ra, =20 /* process up to MAX_BLOCKS_PER_RUN aes blocks */ for (i =3D 0; i < MAX_BLOCKS_PER_RUN && len >=3D AES_BLOCK_SIZE; i++) { - aes_read_block(env, mmu_idx, *src_ptr_reg + done, in, ra); + aes_read_block(env, mmu_idx, ra, *src_ptr_reg + done, in); if (mod) { AES_decrypt(in, out, &exkey); } else { AES_encrypt(in, out, &exkey); } - aes_write_block(env, mmu_idx, *dst_ptr_reg + done, out, ra); + aes_write_block(env, mmu_idx, ra, *dst_ptr_reg + done, out); len -=3D AES_BLOCK_SIZE; done +=3D AES_BLOCK_SIZE; } @@ -118,8 +142,7 @@ int cpacf_aes_cbc(CPUS390XState *env, const int mmu_idx= , uintptr_t ra, { enum { MAX_BLOCKS_PER_RUN =3D 8192 / AES_BLOCK_SIZE }; uint8_t in[AES_BLOCK_SIZE], out[AES_BLOCK_SIZE]; - const MemOpIdx oi =3D make_memop_idx(MO_8, mmu_idx); - uint64_t addr, len =3D *src_len_reg, done =3D 0; + uint64_t len =3D *src_len_reg, done =3D 0; int i, keysize, addr_reg_size =3D 64; uint8_t key[32], iv[AES_BLOCK_SIZE]; AES_KEY exkey; @@ -151,16 +174,11 @@ int cpacf_aes_cbc(CPUS390XState *env, const int mmu_i= dx, uintptr_t ra, } =20 /* fetch iv from param block */ - for (i =3D 0; i < AES_BLOCK_SIZE; i++) { - addr =3D wrap_address(env, param_addr + i); - iv[i] =3D cpu_ldb_mmu(env, addr, oi, ra); - } + copy_from_guest_wrap(env, mmu_idx, ra, param_addr, iv, AES_BLOCK_SIZE); =20 /* fetch key from param block */ - for (i =3D 0; i < keysize; i++) { - addr =3D wrap_address(env, param_addr + AES_BLOCK_SIZE + i); - key[i] =3D cpu_ldb_mmu(env, addr, oi, ra); - } + copy_from_guest_wrap(env, mmu_idx, ra, + param_addr + AES_BLOCK_SIZE, key, keysize); =20 /* expand key */ if (mod) { @@ -171,7 +189,7 @@ int cpacf_aes_cbc(CPUS390XState *env, const int mmu_idx= , uintptr_t ra, =20 /* process up to MAX_BLOCKS_PER_RUN aes blocks */ for (i =3D 0; i < MAX_BLOCKS_PER_RUN && len >=3D AES_BLOCK_SIZE; i++) { - aes_read_block(env, mmu_idx, *src_ptr_reg + done, in, ra); + aes_read_block(env, mmu_idx, ra, *src_ptr_reg + done, in); if (mod) { /* decrypt in =3D> out */ AES_cbc_decrypt(in, out, iv, &exkey); @@ -179,16 +197,13 @@ int cpacf_aes_cbc(CPUS390XState *env, const int mmu_i= dx, uintptr_t ra, /* encrypt in =3D> out */ AES_cbc_encrypt(in, out, iv, &exkey); } - aes_write_block(env, mmu_idx, *dst_ptr_reg + done, out, ra); + aes_write_block(env, mmu_idx, ra, *dst_ptr_reg + done, out); len -=3D AES_BLOCK_SIZE; done +=3D AES_BLOCK_SIZE; } =20 /* update iv in param block */ - for (i =3D 0; i < AES_BLOCK_SIZE; i++) { - addr =3D wrap_address(env, param_addr + i); - cpu_stb_mmu(env, addr, iv[i], oi, ra); - } + copy_to_guest_wrap(env, mmu_idx, ra, param_addr, iv, AES_BLOCK_SIZE); =20 *src_ptr_reg =3D deposit64(*src_ptr_reg, 0, addr_reg_size, *src_ptr_reg + done); @@ -206,9 +221,8 @@ int cpacf_aes_ctr(CPUS390XState *env, const int mmu_idx= , uintptr_t ra, uint8_t fc, uint8_t mod) { enum { MAX_BLOCKS_PER_RUN =3D 8192 / AES_BLOCK_SIZE }; - const MemOpIdx oi =3D make_memop_idx(MO_8, mmu_idx); uint8_t in[AES_BLOCK_SIZE], out[AES_BLOCK_SIZE]; - uint64_t addr, len =3D *src_len_reg, done =3D 0; + uint64_t len =3D *src_len_reg, done =3D 0; uint8_t ctr[AES_BLOCK_SIZE], key[32]; int i, keysize, addr_reg_size =3D 64; AES_KEY exkey; @@ -240,10 +254,7 @@ int cpacf_aes_ctr(CPUS390XState *env, const int mmu_id= x, uintptr_t ra, } =20 /* fetch key from param block */ - for (i =3D 0; i < keysize; i++) { - addr =3D wrap_address(env, param_addr + i); - key[i] =3D cpu_ldb_mmu(env, addr, oi, ra); - } + copy_from_guest_wrap(env, mmu_idx, ra, param_addr, key, keysize); =20 /* expand key */ AES_set_encrypt_key(key, keysize * 8, &exkey); @@ -251,13 +262,13 @@ int cpacf_aes_ctr(CPUS390XState *env, const int mmu_i= dx, uintptr_t ra, /* process up to MAX_BLOCKS_PER_RUN aes blocks */ for (i =3D 0; i < MAX_BLOCKS_PER_RUN && len >=3D AES_BLOCK_SIZE; i++) { /* read in nonce/ctr =3D> ctr */ - aes_read_block(env, mmu_idx, *ctr_ptr_reg + done, ctr, ra); + aes_read_block(env, mmu_idx, ra, *ctr_ptr_reg + done, ctr); /* read in one block of input data =3D> in */ - aes_read_block(env, mmu_idx, *src_ptr_reg + done, in, ra); + aes_read_block(env, mmu_idx, ra, *src_ptr_reg + done, in); /* encrypt ctr and xor with in =3D> out */ AES_ctr_encrypt(in, out, ctr, &exkey); /* write out the processed block */ - aes_write_block(env, mmu_idx, *dst_ptr_reg + done, out, ra); + aes_write_block(env, mmu_idx, ra, *dst_ptr_reg + done, out); len -=3D AES_BLOCK_SIZE; done +=3D AES_BLOCK_SIZE; } @@ -277,9 +288,7 @@ int cpacf_aes_pcc(CPUS390XState *env, const int mmu_idx= , uintptr_t ra, uint64_t param_addr, uint8_t fc) { uint8_t key[32], tweak[AES_BLOCK_SIZE], buf[AES_BLOCK_SIZE]; - const MemOpIdx oi =3D make_memop_idx(MO_8, mmu_idx); int keysize, i; - uint64_t addr; AES_KEY exkey; =20 switch (fc) { @@ -294,10 +303,9 @@ int cpacf_aes_pcc(CPUS390XState *env, const int mmu_id= x, uintptr_t ra, } =20 /* fetch block sequence nr from param block into buf */ - for (i =3D 0; i < AES_BLOCK_SIZE; i++) { - addr =3D wrap_address(env, param_addr + keysize + AES_BLOCK_SIZE += i); - buf[i] =3D cpu_ldb_mmu(env, addr, oi, ra); - } + copy_from_guest_wrap(env, mmu_idx, ra, + param_addr + keysize + AES_BLOCK_SIZE, + buf, AES_BLOCK_SIZE); =20 /* is the block sequence nr 0 ? */ for (i =3D 0; i < AES_BLOCK_SIZE && !buf[i]; i++) { @@ -310,16 +318,11 @@ int cpacf_aes_pcc(CPUS390XState *env, const int mmu_i= dx, uintptr_t ra, } =20 /* fetch key from param block */ - for (i =3D 0; i < keysize; i++) { - addr =3D wrap_address(env, param_addr + i); - key[i] =3D cpu_ldb_mmu(env, addr, oi, ra); - } + copy_from_guest_wrap(env, mmu_idx, ra, param_addr, key, keysize); =20 /* fetch tweak from param block into tweak */ - for (i =3D 0; i < AES_BLOCK_SIZE; i++) { - addr =3D wrap_address(env, param_addr + keysize + i); - tweak[i] =3D cpu_ldb_mmu(env, addr, oi, ra); - } + copy_from_guest_wrap(env, mmu_idx, ra, + param_addr + keysize, tweak, AES_BLOCK_SIZE); =20 /* expand key */ AES_set_encrypt_key(key, keysize * 8, &exkey); @@ -328,10 +331,9 @@ int cpacf_aes_pcc(CPUS390XState *env, const int mmu_id= x, uintptr_t ra, AES_encrypt(tweak, buf, &exkey); =20 /* store encrypted tweak into xts parameter field of the param block */ - for (i =3D 0; i < AES_BLOCK_SIZE; i++) { - addr =3D wrap_address(env, param_addr + keysize + 3 * AES_BLOCK_SI= ZE + i); - cpu_stb_mmu(env, addr, buf[i], oi, ra); - } + copy_to_guest_wrap(env, mmu_idx, ra, + param_addr + keysize + 3 * AES_BLOCK_SIZE, + buf, AES_BLOCK_SIZE); =20 return 0; } @@ -343,8 +345,7 @@ int cpacf_aes_xts(CPUS390XState *env, const int mmu_idx= , uintptr_t ra, { enum { MAX_BLOCKS_PER_RUN =3D 8192 / AES_BLOCK_SIZE }; uint8_t in[AES_BLOCK_SIZE], out[AES_BLOCK_SIZE]; - const MemOpIdx oi =3D make_memop_idx(MO_8, mmu_idx); - uint64_t addr, len =3D *src_len_reg, done =3D 0; + uint64_t len =3D *src_len_reg, done =3D 0; uint8_t key[32], tweak[AES_BLOCK_SIZE]; int i, keysize, addr_reg_size =3D 64; AES_KEY exkey; @@ -373,10 +374,7 @@ int cpacf_aes_xts(CPUS390XState *env, const int mmu_id= x, uintptr_t ra, } =20 /* fetch key from param block */ - for (i =3D 0; i < keysize; i++) { - addr =3D wrap_address(env, param_addr + i); - key[i] =3D cpu_ldb_mmu(env, addr, oi, ra); - } + copy_from_guest_wrap(env, mmu_idx, ra, param_addr, key, keysize); =20 /* expand key */ if (mod) { @@ -386,15 +384,13 @@ int cpacf_aes_xts(CPUS390XState *env, const int mmu_i= dx, uintptr_t ra, } =20 /* fetch tweak from param block */ - for (i =3D 0; i < AES_BLOCK_SIZE; i++) { - addr =3D wrap_address(env, param_addr + keysize + i); - tweak[i] =3D cpu_ldb_mmu(env, addr, oi, ra); - } + copy_from_guest_wrap(env, mmu_idx, ra, + param_addr + keysize, tweak, AES_BLOCK_SIZE); =20 /* process up to MAX_BLOCKS_PER_RUN aes blocks */ for (i =3D 0; i < MAX_BLOCKS_PER_RUN && len >=3D AES_BLOCK_SIZE; i++) { /* fetch one AES block into in */ - aes_read_block(env, mmu_idx, *src_ptr_reg + done, in, ra); + aes_read_block(env, mmu_idx, ra, *src_ptr_reg + done, in); if (mod) { /* decrypt in =3D> out */ AES_xts_decrypt(in, out, tweak, &exkey); @@ -405,16 +401,14 @@ int cpacf_aes_xts(CPUS390XState *env, const int mmu_i= dx, uintptr_t ra, /* prep tweak for next round */ AES_xts_prep_next_tweak(tweak); /* write out this processed block from out */ - aes_write_block(env, mmu_idx, *dst_ptr_reg + done, out, ra); + aes_write_block(env, mmu_idx, ra, *dst_ptr_reg + done, out); len -=3D AES_BLOCK_SIZE; done +=3D AES_BLOCK_SIZE; } =20 /* update tweak in param block */ - for (i =3D 0; i < AES_BLOCK_SIZE; i++) { - addr =3D wrap_address(env, param_addr + keysize + i); - cpu_stb_mmu(env, addr, tweak[i], oi, ra); - } + copy_to_guest_wrap(env, mmu_idx, ra, + param_addr + keysize, tweak, AES_BLOCK_SIZE); =20 *src_ptr_reg =3D deposit64(*src_ptr_reg, 0, addr_reg_size, *src_ptr_reg + done); @@ -467,10 +461,8 @@ static void decrypt_protkey(uint8_t *key, int keysize) int cpacf_aes_pckmo(CPUS390XState *env, const int mmu_idx, uintptr_t ra, uint64_t param_addr, uint8_t fc) { - const MemOpIdx oi =3D make_memop_idx(MO_8, mmu_idx); uint8_t key[32]; - int keysize, i; - uint64_t addr; + int keysize; =20 switch (fc) { case CPACF_PCKMO_ENC_AES_128_KEY: @@ -487,24 +479,17 @@ int cpacf_aes_pckmo(CPUS390XState *env, const int mmu= _idx, uintptr_t ra, } =20 /* fetch key from param block */ - for (i =3D 0; i < keysize; i++) { - addr =3D wrap_address(env, param_addr + i); - key[i] =3D cpu_ldb_mmu(env, addr, oi, ra); - } + copy_from_guest_wrap(env, mmu_idx, ra, param_addr, key, keysize); =20 /* 'derive' the protected key from the clear key */ encrypt_clrkey(key, keysize); =20 /* store the protected key into param block */ - for (i =3D 0; i < keysize; i++) { - addr =3D wrap_address(env, param_addr + i); - cpu_stb_mmu(env, addr, key[i], oi, ra); - } + copy_to_guest_wrap(env, mmu_idx, ra, param_addr, key, keysize); /* followed by the fake wkvp */ - for (i =3D 0; i < sizeof(protkey_wkvp); i++) { - addr =3D wrap_address(env, param_addr + keysize + i); - cpu_stb_mmu(env, addr, protkey_wkvp[i], oi, ra); - } + copy_to_guest_wrap(env, mmu_idx, ra, + param_addr + keysize, + protkey_wkvp, sizeof(protkey_wkvp)); =20 return 0; } @@ -515,9 +500,8 @@ int cpacf_paes_ecb(CPUS390XState *env, const int mmu_id= x, uintptr_t ra, uint32_t type, uint8_t fc, uint8_t mod) { enum { MAX_BLOCKS_PER_RUN =3D 8192 / AES_BLOCK_SIZE }; - const MemOpIdx oi =3D make_memop_idx(MO_8, mmu_idx); uint8_t in[AES_BLOCK_SIZE], out[AES_BLOCK_SIZE]; - uint64_t addr, len =3D *src_len_reg, done =3D 0; + uint64_t len =3D *src_len_reg, done =3D 0; int i, keysize, addr_reg_size =3D 64; uint8_t key[32], wkvp[32]; AES_KEY exkey; @@ -549,20 +533,15 @@ int cpacf_paes_ecb(CPUS390XState *env, const int mmu_= idx, uintptr_t ra, } =20 /* fetch and check wkvp from param block */ - for (i =3D 0; i < sizeof(wkvp); i++) { - addr =3D wrap_address(env, param_addr + keysize + i); - wkvp[i] =3D cpu_ldb_mmu(env, addr, oi, ra); - } + copy_from_guest_wrap(env, mmu_idx, ra, + param_addr + keysize, wkvp, sizeof(wkvp)); if (memcmp(wkvp, protkey_wkvp, sizeof(wkvp))) { /* wkvp mismatch -> return with cc 1 */ return 1; } =20 /* fetch protected key from param block */ - for (i =3D 0; i < keysize; i++) { - addr =3D wrap_address(env, param_addr + i); - key[i] =3D cpu_ldb_mmu(env, addr, oi, ra); - } + copy_from_guest_wrap(env, mmu_idx, ra, param_addr, key, keysize); /* decrypt the protected key */ decrypt_protkey(key, keysize); =20 @@ -575,13 +554,13 @@ int cpacf_paes_ecb(CPUS390XState *env, const int mmu_= idx, uintptr_t ra, =20 /* process up to MAX_BLOCKS_PER_RUN aes blocks */ for (i =3D 0; i < MAX_BLOCKS_PER_RUN && len >=3D AES_BLOCK_SIZE; i++) { - aes_read_block(env, mmu_idx, *src_ptr_reg + done, in, ra); + aes_read_block(env, mmu_idx, ra, *src_ptr_reg + done, in); if (mod) { AES_decrypt(in, out, &exkey); } else { AES_encrypt(in, out, &exkey); } - aes_write_block(env, mmu_idx, *dst_ptr_reg + done, out, ra); + aes_write_block(env, mmu_idx, ra, *dst_ptr_reg + done, out); len -=3D AES_BLOCK_SIZE; done +=3D AES_BLOCK_SIZE; } @@ -602,9 +581,8 @@ int cpacf_paes_cbc(CPUS390XState *env, const int mmu_id= x, uintptr_t ra, { enum { MAX_BLOCKS_PER_RUN =3D 8192 / AES_BLOCK_SIZE }; uint8_t in[AES_BLOCK_SIZE], out[AES_BLOCK_SIZE]; - const MemOpIdx oi =3D make_memop_idx(MO_8, mmu_idx); uint8_t key[32], wkvp[32], iv[AES_BLOCK_SIZE]; - uint64_t addr, len =3D *src_len_reg, done =3D 0; + uint64_t len =3D *src_len_reg, done =3D 0; int i, keysize, addr_reg_size =3D 64; AES_KEY exkey; =20 @@ -635,26 +613,20 @@ int cpacf_paes_cbc(CPUS390XState *env, const int mmu_= idx, uintptr_t ra, } =20 /* fetch and check wkvp from param block */ - for (i =3D 0; i < sizeof(wkvp); i++) { - addr =3D wrap_address(env, param_addr + AES_BLOCK_SIZE + keysize += i); - wkvp[i] =3D cpu_ldb_mmu(env, addr, oi, ra); - } + copy_from_guest_wrap(env, mmu_idx, ra, + param_addr + AES_BLOCK_SIZE + keysize, + wkvp, sizeof(wkvp)); if (memcmp(wkvp, protkey_wkvp, sizeof(wkvp))) { /* wkvp mismatch -> return with cc 1 */ return 1; } =20 /* fetch iv from param block */ - for (i =3D 0; i < AES_BLOCK_SIZE; i++) { - addr =3D wrap_address(env, param_addr + i); - iv[i] =3D cpu_ldb_mmu(env, addr, oi, ra); - } + copy_from_guest_wrap(env, mmu_idx, ra, param_addr, iv, AES_BLOCK_SIZE); =20 /* fetch protected key from param block */ - for (i =3D 0; i < keysize; i++) { - addr =3D wrap_address(env, param_addr + AES_BLOCK_SIZE + i); - key[i] =3D cpu_ldb_mmu(env, addr, oi, ra); - } + copy_from_guest_wrap(env, mmu_idx, ra, + param_addr + AES_BLOCK_SIZE, key, keysize); /* decrypt the protected key */ decrypt_protkey(key, keysize); =20 @@ -667,7 +639,7 @@ int cpacf_paes_cbc(CPUS390XState *env, const int mmu_id= x, uintptr_t ra, =20 /* process up to MAX_BLOCKS_PER_RUN aes blocks */ for (i =3D 0; i < MAX_BLOCKS_PER_RUN && len >=3D AES_BLOCK_SIZE; i++) { - aes_read_block(env, mmu_idx, *src_ptr_reg + done, in, ra); + aes_read_block(env, mmu_idx, ra, *src_ptr_reg + done, in); if (mod) { /* decrypt in =3D> out */ AES_cbc_decrypt(in, out, iv, &exkey); @@ -675,16 +647,13 @@ int cpacf_paes_cbc(CPUS390XState *env, const int mmu_= idx, uintptr_t ra, /* encrypt in =3D> out */ AES_cbc_encrypt(in, out, iv, &exkey); } - aes_write_block(env, mmu_idx, *dst_ptr_reg + done, out, ra); + aes_write_block(env, mmu_idx, ra, *dst_ptr_reg + done, out); len -=3D AES_BLOCK_SIZE; done +=3D AES_BLOCK_SIZE; } =20 /* update iv in param block */ - for (i =3D 0; i < AES_BLOCK_SIZE; i++) { - addr =3D wrap_address(env, param_addr + i); - cpu_stb_mmu(env, addr, iv[i], oi, ra); - } + copy_to_guest_wrap(env, mmu_idx, ra, param_addr, iv, AES_BLOCK_SIZE); =20 *src_ptr_reg =3D deposit64(*src_ptr_reg, 0, addr_reg_size, *src_ptr_reg + done); @@ -702,10 +671,9 @@ int cpacf_paes_ctr(CPUS390XState *env, const int mmu_i= dx, uintptr_t ra, uint8_t fc, uint8_t mod) { enum { MAX_BLOCKS_PER_RUN =3D 8192 / AES_BLOCK_SIZE }; - const MemOpIdx oi =3D make_memop_idx(MO_8, mmu_idx); uint8_t in[AES_BLOCK_SIZE], out[AES_BLOCK_SIZE]; uint8_t ctr[AES_BLOCK_SIZE], key[32], wkvp[32]; - uint64_t addr, len =3D *src_len_reg, done =3D 0; + uint64_t len =3D *src_len_reg, done =3D 0; int i, keysize, addr_reg_size =3D 64; AES_KEY exkey; =20 @@ -736,20 +704,15 @@ int cpacf_paes_ctr(CPUS390XState *env, const int mmu_= idx, uintptr_t ra, } =20 /* fetch and check wkvp from param block */ - for (i =3D 0; i < sizeof(wkvp); i++) { - addr =3D wrap_address(env, param_addr + keysize + i); - wkvp[i] =3D cpu_ldb_mmu(env, addr, oi, ra); - } + copy_from_guest_wrap(env, mmu_idx, ra, + param_addr + keysize, wkvp, sizeof(wkvp)); if (memcmp(wkvp, protkey_wkvp, sizeof(wkvp))) { /* wkvp mismatch -> return with cc 1 */ return 1; } =20 /* fetch protected key from param block */ - for (i =3D 0; i < keysize; i++) { - addr =3D wrap_address(env, param_addr + i); - key[i] =3D cpu_ldb_mmu(env, addr, oi, ra); - } + copy_from_guest_wrap(env, mmu_idx, ra, param_addr, key, keysize); /* decrypt the protected key */ decrypt_protkey(key, keysize); =20 @@ -759,13 +722,13 @@ int cpacf_paes_ctr(CPUS390XState *env, const int mmu_= idx, uintptr_t ra, /* process up to MAX_BLOCKS_PER_RUN aes blocks */ for (i =3D 0; i < MAX_BLOCKS_PER_RUN && len >=3D AES_BLOCK_SIZE; i++) { /* read in nonce/ctr =3D> ctr */ - aes_read_block(env, mmu_idx, *ctr_ptr_reg + done, ctr, ra); + aes_read_block(env, mmu_idx, ra, *ctr_ptr_reg + done, ctr); /* read in one block of input data =3D> in */ - aes_read_block(env, mmu_idx, *src_ptr_reg + done, in, ra); + aes_read_block(env, mmu_idx, ra, *src_ptr_reg + done, in); /* encrypt ctr and xor with in =3D> out */ AES_ctr_encrypt(in, out, ctr, &exkey); /* write out the processed block */ - aes_write_block(env, mmu_idx, *dst_ptr_reg + done, out, ra); + aes_write_block(env, mmu_idx, ra, *dst_ptr_reg + done, out); len -=3D AES_BLOCK_SIZE; done +=3D AES_BLOCK_SIZE; } @@ -785,9 +748,7 @@ int cpacf_paes_pcc(CPUS390XState *env, const int mmu_id= x, uintptr_t ra, uint64_t param_addr, uint8_t fc) { uint8_t key[32], wkvp[32], tweak[AES_BLOCK_SIZE], buf[AES_BLOCK_SIZE]; - const MemOpIdx oi =3D make_memop_idx(MO_8, mmu_idx); int keysize, i; - uint64_t addr; AES_KEY exkey; =20 switch (fc) { @@ -802,21 +763,17 @@ int cpacf_paes_pcc(CPUS390XState *env, const int mmu_= idx, uintptr_t ra, } =20 /* fetch and check wkvp from param block */ - for (i =3D 0; i < sizeof(wkvp); i++) { - addr =3D wrap_address(env, param_addr + keysize + i); - wkvp[i] =3D cpu_ldb_mmu(env, addr, oi, ra); - } + copy_from_guest_wrap(env, mmu_idx, ra, + param_addr + keysize, wkvp, sizeof(wkvp)); if (memcmp(wkvp, protkey_wkvp, sizeof(wkvp))) { /* wkvp mismatch -> return with cc 1 */ return 1; } =20 /* fetch block sequence nr from param block into buf */ - for (i =3D 0; i < AES_BLOCK_SIZE; i++) { - addr =3D wrap_address(env, param_addr + keysize + - sizeof(wkvp) + AES_BLOCK_SIZE + i); - buf[i] =3D cpu_ldb_mmu(env, addr, oi, ra); - } + copy_from_guest_wrap(env, mmu_idx, ra, + param_addr + keysize + sizeof(wkvp) + AES_BLOCK_S= IZE, + buf, AES_BLOCK_SIZE); =20 /* is the block sequence nr 0 ? */ for (i =3D 0; i < AES_BLOCK_SIZE && !buf[i]; i++) { @@ -829,18 +786,14 @@ int cpacf_paes_pcc(CPUS390XState *env, const int mmu_= idx, uintptr_t ra, } =20 /* fetch protected key from param block */ - for (i =3D 0; i < keysize; i++) { - addr =3D wrap_address(env, param_addr + i); - key[i] =3D cpu_ldb_mmu(env, addr, oi, ra); - } + copy_from_guest_wrap(env, mmu_idx, ra, param_addr, key, keysize); /* decrypt the protected key */ decrypt_protkey(key, keysize); =20 /* fetch tweak from param block into tweak */ - for (i =3D 0; i < AES_BLOCK_SIZE; i++) { - addr =3D wrap_address(env, param_addr + keysize + sizeof(wkvp) + i= ); - tweak[i] =3D cpu_ldb_mmu(env, addr, oi, ra); - } + copy_from_guest_wrap(env, mmu_idx, ra, + param_addr + keysize + sizeof(wkvp), + tweak, AES_BLOCK_SIZE); =20 /* expand key */ AES_set_encrypt_key(key, keysize * 8, &exkey); @@ -849,11 +802,9 @@ int cpacf_paes_pcc(CPUS390XState *env, const int mmu_i= dx, uintptr_t ra, AES_encrypt(tweak, buf, &exkey); =20 /* store encrypted tweak into xts parameter field of the param block */ - for (i =3D 0; i < AES_BLOCK_SIZE; i++) { - addr =3D wrap_address(env, param_addr + keysize + - sizeof(wkvp) + 3 * AES_BLOCK_SIZE + i); - cpu_stb_mmu(env, addr, buf[i], oi, ra); - } + copy_to_guest_wrap(env, mmu_idx, ra, + param_addr + keysize + sizeof(wkvp) + 3 * AES_BLOCK= _SIZE, + buf, AES_BLOCK_SIZE); =20 return 0; } @@ -865,9 +816,8 @@ int cpacf_paes_xts(CPUS390XState *env, const int mmu_id= x, uintptr_t ra, { enum { MAX_BLOCKS_PER_RUN =3D 8192 / AES_BLOCK_SIZE }; uint8_t in[AES_BLOCK_SIZE], out[AES_BLOCK_SIZE]; - const MemOpIdx oi =3D make_memop_idx(MO_8, mmu_idx); uint8_t key[32], wkvp[32], tweak[AES_BLOCK_SIZE]; - uint64_t addr, len =3D *src_len_reg, done =3D 0; + uint64_t len =3D *src_len_reg, done =3D 0; int i, keysize, addr_reg_size =3D 64; AES_KEY exkey; =20 @@ -895,20 +845,15 @@ int cpacf_paes_xts(CPUS390XState *env, const int mmu_= idx, uintptr_t ra, } =20 /* fetch and check wkvp from param block */ - for (i =3D 0; i < sizeof(wkvp); i++) { - addr =3D wrap_address(env, param_addr + keysize + i); - wkvp[i] =3D cpu_ldb_mmu(env, addr, oi, ra); - } + copy_from_guest_wrap(env, mmu_idx, ra, + param_addr + keysize, wkvp, sizeof(wkvp)); if (memcmp(wkvp, protkey_wkvp, sizeof(wkvp))) { /* wkvp mismatch -> return with cc 1 */ return 1; } =20 /* fetch protected key from param block */ - for (i =3D 0; i < keysize; i++) { - addr =3D wrap_address(env, param_addr + i); - key[i] =3D cpu_ldb_mmu(env, addr, oi, ra); - } + copy_from_guest_wrap(env, mmu_idx, ra, param_addr, key, keysize); /* decrypt the protected key */ decrypt_protkey(key, keysize); =20 @@ -920,15 +865,14 @@ int cpacf_paes_xts(CPUS390XState *env, const int mmu_= idx, uintptr_t ra, } =20 /* fetch tweak from param block */ - for (i =3D 0; i < AES_BLOCK_SIZE; i++) { - addr =3D wrap_address(env, param_addr + keysize + sizeof(wkvp) + i= ); - tweak[i] =3D cpu_ldb_mmu(env, addr, oi, ra); - } + copy_from_guest_wrap(env, mmu_idx, ra, + param_addr + keysize + sizeof(wkvp), + tweak, AES_BLOCK_SIZE); =20 /* process up to MAX_BLOCKS_PER_RUN aes blocks */ for (i =3D 0; i < MAX_BLOCKS_PER_RUN && len >=3D AES_BLOCK_SIZE; i++) { /* fetch one AES block into in */ - aes_read_block(env, mmu_idx, *src_ptr_reg + done, in, ra); + aes_read_block(env, mmu_idx, ra, *src_ptr_reg + done, in); if (mod) { /* decrypt in =3D> out */ AES_xts_decrypt(in, out, tweak, &exkey); @@ -939,16 +883,15 @@ int cpacf_paes_xts(CPUS390XState *env, const int mmu_= idx, uintptr_t ra, /* prep tweak for next round */ AES_xts_prep_next_tweak(tweak); /* write out this processed block from out */ - aes_write_block(env, mmu_idx, *dst_ptr_reg + done, out, ra); + aes_write_block(env, mmu_idx, ra, *dst_ptr_reg + done, out); len -=3D AES_BLOCK_SIZE; done +=3D AES_BLOCK_SIZE; } =20 /* update tweak in param block */ - for (i =3D 0; i < AES_BLOCK_SIZE; i++) { - addr =3D wrap_address(env, param_addr + keysize + sizeof(wkvp) + i= ); - cpu_stb_mmu(env, addr, tweak[i], oi, ra); - } + copy_to_guest_wrap(env, mmu_idx, ra, + param_addr + keysize + sizeof(wkvp), + tweak, AES_BLOCK_SIZE); =20 *src_ptr_reg =3D deposit64(*src_ptr_reg, 0, addr_reg_size, *src_ptr_reg + done); --=20 2.43.0 From nobody Sun Jul 26 10:59:15 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1783331200; cv=none; d=zohomail.com; s=zohoarc; b=EaXzxHbgmKcv2+MJAZoLb2cdJUB1Djxl98eTosJUvQHeCHzbqva+hL8Jeo/Y0bSpAqhh3CV+NT3uiEWH7XefK4AvnL1oFUIXnN0Rz+tpX9CMyoVOYHgAa2KiGOcVqhS33hshsmj9W20+yczt3Q3t/OQj8z02SduOatPrFqarCZk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783331200; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=GwjciZXvg5/NnsjaQ4z90uAqPuDQ4r7VWcJT1I8ezDs=; b=HI1Aowjvvba4x/zKUwruApTriNel3D0IU7ojH2Mdt/XeVidwfudHz2OkLvuN4qNI8qy9gwgfAdDklIYC1CZ8OlEIwSwdc89inQAg54F9vlei4XY6nbi1cI0LeVwx+Cv5RGImoM39itY5zU6vzNpo2kqffbDQZ/ou59TgJtAQ28k= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783331200618792.3478275490901; Mon, 6 Jul 2026 02:46:40 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wgfrb-0004IA-IB; Mon, 06 Jul 2026 05:43:43 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrZ-0004HQ-6A; Mon, 06 Jul 2026 05:43:41 -0400 Received: from mx0b-001b2d01.pphosted.com ([148.163.158.5]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgfrR-0003zS-DZ; Mon, 06 Jul 2026 05:43:40 -0400 Received: from pps.filterd (m0360072.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 6669IG983133839; Mon, 6 Jul 2026 09:43:27 GMT Received: from ppma21.wdc07v.mail.ibm.com (5b.69.3da9.ip4.static.sl-reverse.com [169.61.105.91]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f6stsh91g-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:26 +0000 (GMT) Received: from pps.filterd (ppma21.wdc07v.mail.ibm.com [127.0.0.1]) by ppma21.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 6669Yd6M028342; Mon, 6 Jul 2026 09:43:25 GMT Received: from smtprelay07.fra02v.mail.ibm.com ([9.218.2.229]) by ppma21.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4f7dgjw0h9-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 06 Jul 2026 09:43:25 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (smtpav07.fra02v.mail.ibm.com [10.20.54.106]) by smtprelay07.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 6669hLDW43778490 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Mon, 6 Jul 2026 09:43:21 GMT Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id E943C20043; Mon, 6 Jul 2026 09:43:20 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 3A8652004E; Mon, 6 Jul 2026 09:43:20 +0000 (GMT) Received: from funtu2.ibm.com (unknown [9.111.193.81]) by smtpav07.fra02v.mail.ibm.com (Postfix) with ESMTP; Mon, 6 Jul 2026 09:43:20 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=GwjciZXvg5/NnsjaQ 4z90uAqPuDQ4r7VWcJT1I8ezDs=; b=T5uH7EfTixpuLpLNGrU0npMI5RPeOyqG8 9/JCAGGPixw50hzJ1xHtKuYV8cZhJ1a1iLirumlhyI4A+jh7pxfyOOiwGkB+PD04 xsiA5mdeKOwvvnga8xEOX3Lewhs1Nqj8pDo6Nkghj34qGvD6JV4oGiF57GrOx+R4 pUdgW65ENUxHb91tJwVRJp1UwgpaITp7IHX1rrHrPWfugRvPfkFST5Um/W3p8xNL tQsh5YmblQZ5i7qdwTgdJ199wMteSR//DFJF3T4LwlJhg7di39ojs1VfSfKP1t/y Gs95KdBXBs0L7fNVA4yHAMbeFmtmwzZrCmQ1inzEwfjzDuDavDVUA== From: Harald Freudenberger To: richard.henderson@linaro.org, iii@linux.ibm.com, david@kernel.org, thuth@redhat.com, berrange@redhat.com Cc: qemu-s390x@nongnu.org, qemu-devel@nongnu.org, linux-s390@vger.kernel.org, dengler@linux.ibm.com, borntraeger@linux.ibm.com, fcallies@linux.ibm.com, cohuck@redhat.com Subject: [PATCH v10 21/21] tests/tcg/s390x: Add tests for CPACF instructions Date: Mon, 6 Jul 2026 11:43:14 +0200 Message-ID: <20260706094317.17032-22-freude@linux.ibm.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260706094317.17032-1-freude@linux.ibm.com> References: <20260706094317.17032-1-freude@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-ORIG-GUID: dPFXUHHLnyj6FNLGcIjQJRZAyHHh7HJN X-Proofpoint-Spam-Info: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfX4TvwvxYNYTvP 6Q3icMwkj3Vu2/p2kyjOEQ8myPIfmwAN/AqAgua6EjzP1eBEcbha3KR+CJozbU5V0iY9v4++GcK mqSD4GU4kMOgucWVjiH31O6WJEE29P0= X-Authority-Analysis: v=2.4 cv=DKW/JSNb c=1 sm=1 tr=0 ts=6a4b78be cx=c_pps a=GFwsV6G8L6GxiO2Y/PsHdQ==:117 a=GFwsV6G8L6GxiO2Y/PsHdQ==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=RzCfie-kr_QcCd8fBx8p:22 a=VnNF1IyMAAAA:8 a=tYchGEmKu5sGAc5sY1IA:9 a=9gp5PUktWgSiYFtD:21 X-Proofpoint-GUID: dPFXUHHLnyj6FNLGcIjQJRZAyHHh7HJN X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzA2MDA5NCBTYWx0ZWRfX1YCIJizr717d +qcJRXj4WW5CmfAEF6PRL9yUp3MnPWxUFkz2kYtA5ecyRLXt5bvipplW91CNagj82TQsgc42iYi dcTn3x+LS4DqQPKqU4HKE7O+wQB+rw7536HgXM5X/gAyx03lpbx5MvUbR/xzDuMQhfjYIkf612y d1jb3qPnijLursqXmxZkMxHWJGhv7Sam38+WGeilMOTqUjgsoj/GBa31VC+rX+l/i+PmNr1gLyR wtksk56w5z6bw+828mlr7KW8MdioEdDpJOPR5N4DQEAgYFem9Gzsnl2eMJpMws9wUnTi7naB3bA GAcHlEJQvc4zWHUykPeBvfDKEreO51rnkEmVDc7TShKRgQLguoiUuXdG5ww76tkdwjdFfmQ6+WJ zJV3SoCPremPtJXpszGXucqPQNs84ATRrWdTLC451YziH45fhPbT3mkuNWDNTYmZJF4UfyAQ/Oc 4cAC+mUZhtGix/PXikg== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-06_01,2026-07-03_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 spamscore=0 bulkscore=0 clxscore=1015 phishscore=0 impostorscore=0 priorityscore=1501 adultscore=0 lowpriorityscore=0 suspectscore=0 malwarescore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607060094 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.158.5; envelope-from=freude@linux.ibm.com; helo=mx0b-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1783331201882158500 Content-Type: text/plain; charset="utf-8" Add simple tests for the CPACF instructions implemented: - kdsa - minimal as only query is implemented - kimd - query, sha256, sha512 - klmd - query, sha256, sha512 - km - query, aes 128, 192, 256 with clear and prot key - kmac - minimal as only query is implemented - kmc - query, aes 128, 192, 256 with clear and prot key - kmctr - query, aes 128, 192, 256 with clear and prot key - pcc - query, xts aes 128, 256 and prot key xts aes 128, 256 - prno - query, trng No test for pckmo as this is a privileged instruction. No test for kma, kmf, kmo as these instructions are currently not implemented at all. Signed-off-by: Harald Freudenberger --- target/s390x/tcg/cpacf.h | 7 + tests/tcg/s390x/Makefile.target | 9 + tests/tcg/s390x/cpacf-kdsa.c | 59 ++++ tests/tcg/s390x/cpacf-kimd.c | 164 +++++++++ tests/tcg/s390x/cpacf-klmd.c | 202 +++++++++++ tests/tcg/s390x/cpacf-km.c | 576 ++++++++++++++++++++++++++++++++ tests/tcg/s390x/cpacf-kmac.c | 59 ++++ tests/tcg/s390x/cpacf-kmc.c | 342 +++++++++++++++++++ tests/tcg/s390x/cpacf-kmctr.c | 354 ++++++++++++++++++++ tests/tcg/s390x/cpacf-pcc.c | 241 +++++++++++++ tests/tcg/s390x/cpacf-prno.c | 130 +++++++ tests/tcg/s390x/cpacf.h | 570 +++++++++++++++++++++++++++++++ 12 files changed, 2713 insertions(+) create mode 100644 tests/tcg/s390x/cpacf-kdsa.c create mode 100644 tests/tcg/s390x/cpacf-kimd.c create mode 100644 tests/tcg/s390x/cpacf-klmd.c create mode 100644 tests/tcg/s390x/cpacf-km.c create mode 100644 tests/tcg/s390x/cpacf-kmac.c create mode 100644 tests/tcg/s390x/cpacf-kmc.c create mode 100644 tests/tcg/s390x/cpacf-kmctr.c create mode 100644 tests/tcg/s390x/cpacf-pcc.c create mode 100644 tests/tcg/s390x/cpacf-prno.c create mode 100644 tests/tcg/s390x/cpacf.h diff --git a/target/s390x/tcg/cpacf.h b/target/s390x/tcg/cpacf.h index b2223b4d64..685fd773c2 100644 --- a/target/s390x/tcg/cpacf.h +++ b/target/s390x/tcg/cpacf.h @@ -223,6 +223,8 @@ #define CPACF_KDSA_PSIGN_ED25519 48 #define CPACF_KDSA_PSIGN_ED448 52 =20 +#ifndef CPACF_H_INCLUDE_FOR_TESTS + /* from cpacf_sha256.c */ int cpacf_sha256(CPUS390XState *env, const int mmu_idx, uintptr_t ra, uint64_t param_addr, uint64_t *message_reg, uint64_t *len= _reg, @@ -254,6 +256,8 @@ int cpacf_aes_xts(CPUS390XState *env, const int mmu_idx= , uintptr_t ra, uint64_t *src_ptr_reg, uint64_t *src_len_reg, uint32_t type, uint8_t fc, uint8_t mod); =20 +#endif /* CPACF_H_INCLUDE_FOR_TESTS */ + /* * Support for protected key cpacf functions. Note that this is * a fake implementation intended for debugging and development. @@ -279,6 +283,8 @@ int cpacf_aes_xts(CPUS390XState *env, const int mmu_idx= , uintptr_t ra, 0x0F, 0x0A, 0x0C, 0x0E, 0x0F, 0x0A, 0x0C, 0x0E, \ 0x0F, 0x0A, 0x0C, 0x0E, 0x0F, 0x0A, 0x0C, 0x0E } =20 +#ifndef CPACF_H_INCLUDE_FOR_TESTS + /* from cpacf_aes.c */ int cpacf_aes_pckmo(CPUS390XState *env, const int mmu_idx, uintptr_t ra, uint64_t param_addr, uint8_t fc); @@ -302,4 +308,5 @@ int cpacf_paes_xts(CPUS390XState *env, const int mmu_id= x, uintptr_t ra, uint64_t *src_ptr_reg, uint64_t *src_len_reg, uint32_t type, uint8_t fc, uint8_t mod); =20 +#endif /* CPACF_H_INCLUDE_FOR_TESTS */ #endif /* S390X_CPACF_H */ diff --git a/tests/tcg/s390x/Makefile.target b/tests/tcg/s390x/Makefile.tar= get index 0ca030ded0..68e6a1816d 100644 --- a/tests/tcg/s390x/Makefile.target +++ b/tests/tcg/s390x/Makefile.target @@ -50,6 +50,15 @@ TESTS+=3Dcvb TESTS+=3Dts TESTS+=3Dex-smc TESTS+=3Ddivide-to-integer +TESTS+=3Dcpacf-kdsa +TESTS+=3Dcpacf-kimd +TESTS+=3Dcpacf-klmd +TESTS+=3Dcpacf-km +TESTS+=3Dcpacf-kmac +TESTS+=3Dcpacf-kmc +TESTS+=3Dcpacf-kmctr +TESTS+=3Dcpacf-pcc +TESTS+=3Dcpacf-prno =20 cdsg: CFLAGS+=3D-pthread cdsg: LDFLAGS+=3D-pthread diff --git a/tests/tcg/s390x/cpacf-kdsa.c b/tests/tcg/s390x/cpacf-kdsa.c new file mode 100644 index 0000000000..ba4b94e1a3 --- /dev/null +++ b/tests/tcg/s390x/cpacf-kdsa.c @@ -0,0 +1,59 @@ +/* + * Simple test for the CPACF KDSA instruction + * + * This work is licensed under the terms of the GNU GPL, version 2 or late= r. + * See the COPYING file in the top-level directory. + */ + +#include +#include +#include +#include +#include "cpacf.h" + +#define QUERY_BLOCK_SIZE 16 + +/* expected kdsa query block */ +static uint8_t exp_query_block[QUERY_BLOCK_SIZE] =3D { + 0x80, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, +}; + +static int test_kdsa_query(void) +{ + uint8_t query_block[QUERY_BLOCK_SIZE] =3D {0}; + unsigned long cc =3D 0; + int i, rc =3D 0; + + cpacf_kdsa(CPACF_KDSA_QUERY, query_block, NULL, 0, &cc); + + /* compare with expected query block */ + for (i =3D 0; i < QUERY_BLOCK_SIZE; i++) { + if (query_block[i] !=3D exp_query_block[i]) { + rc++; + break; + } + } + + if (rc) { + printf("%s failed\n", __func__); + } + + return rc; +} + +int main(void) +{ + int rc; + + /* Test query function */ + rc =3D test_kdsa_query(); + + /* As of now only KDSA query is implemented */ + + if (rc) { + printf("cpacf-kdsa: %d failures\n", rc); + } + + return rc ? EXIT_FAILURE : EXIT_SUCCESS; +} diff --git a/tests/tcg/s390x/cpacf-kimd.c b/tests/tcg/s390x/cpacf-kimd.c new file mode 100644 index 0000000000..a086c3bd53 --- /dev/null +++ b/tests/tcg/s390x/cpacf-kimd.c @@ -0,0 +1,164 @@ +/* + * Simple test for CPACF KIMD instruction + * + * This work is licensed under the terms of the GNU GPL, version 2 or late= r. + * See the COPYING file in the top-level directory. + */ + +#include +#include +#include +#include +#include "cpacf.h" + +#define QUERY_BLOCK_SIZE 16 + +/* expected kimd query block */ +static uint8_t exp_query_block[QUERY_BLOCK_SIZE] =3D { + 0xB0, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, +}; + +/* SHA-256 test data */ +static const uint8_t sha256in[] =3D { + 0x5a, 0x86, 0xb7, 0x37, 0xea, 0xea, 0x8e, 0xe9, + 0x76, 0xa0, 0xa2, 0x4d, 0xa6, 0x3e, 0x7e, 0xd7, + 0xee, 0xfa, 0xd1, 0x8a, 0x10, 0x1c, 0x12, 0x11, + 0xe2, 0xb3, 0x65, 0x0c, 0x51, 0x87, 0xc2, 0xa8, + 0xa6, 0x50, 0x54, 0x72, 0x08, 0x25, 0x1f, 0x6d, + 0x42, 0x37, 0xe6, 0x61, 0xc7, 0xbf, 0x4c, 0x77, + 0xf3, 0x35, 0x39, 0x03, 0x94, 0xc3, 0x7f, 0xa1, + 0xa9, 0xf9, 0xbe, 0x83, 0x6a, 0xc2, 0x85, 0x09 +}; + +/* SHA-512 test data */ +static const uint8_t sha512in[] =3D { + 0xfd, 0x22, 0x03, 0xe4, 0x67, 0x57, 0x4e, 0x83, + 0x4a, 0xb0, 0x7c, 0x90, 0x97, 0xae, 0x16, 0x45, + 0x32, 0xf2, 0x4b, 0xe1, 0xeb, 0x5d, 0x88, 0xf1, + 0xaf, 0x77, 0x48, 0xce, 0xff, 0x0d, 0x2c, 0x67, + 0xa2, 0x1f, 0x4e, 0x40, 0x97, 0xf9, 0xd3, 0xbb, + 0x4e, 0x9f, 0xbf, 0x97, 0x18, 0x6e, 0x0d, 0xb6, + 0xdb, 0x01, 0x00, 0x23, 0x0a, 0x52, 0xb4, 0x53, + 0xd4, 0x21, 0xf8, 0xab, 0x9c, 0x9a, 0x60, 0x43, + 0xaa, 0x32, 0x95, 0xea, 0x20, 0xd2, 0xf0, 0x6a, + 0x2f, 0x37, 0x47, 0x0d, 0x8a, 0x99, 0x07, 0x5f, + 0x1b, 0x8a, 0x83, 0x36, 0xf6, 0x22, 0x8c, 0xf0, + 0x8b, 0x59, 0x42, 0xfc, 0x1f, 0xb4, 0x29, 0x9c, + 0x7d, 0x24, 0x80, 0xe8, 0xe8, 0x2b, 0xce, 0x17, + 0x55, 0x40, 0xbd, 0xfa, 0xd7, 0x75, 0x2b, 0xc9, + 0x5b, 0x57, 0x7f, 0x22, 0x95, 0x15, 0x39, 0x4f, + 0x3a, 0xe5, 0xce, 0xc8, 0x70, 0xa4, 0xb2, 0xf8 +}; + +/* query test for kimd + * returns > 0 on failure, otherwise 0 + */ +static int test_kimd_query(void) +{ + uint8_t query_block[QUERY_BLOCK_SIZE] =3D {0}; + unsigned long cc =3D 0; + int i, rc =3D 0; + + cpacf_kimd(CPACF_KIMD_QUERY, query_block, NULL, 0, &cc); + + /* compare with expected query block */ + for (i =3D 0; i < QUERY_BLOCK_SIZE; i++) { + if (query_block[i] !=3D exp_query_block[i]) { + rc++; + break; + } + } + + if (rc) { + printf("%s failed\n", __func__); + } + + return rc; +} + +/* subfunction CPACF_KIMD_SHA_256 test for kimd + * returns > 0 on failure, otherwise 0 + */ +static int test_kimd_sha256(void) +{ + uint32_t param[8]; + unsigned long cc =3D 0; + int rc =3D 0; + + /* Initialize SHA-256 hash values */ + param[0] =3D 0x6a09e667u; + param[1] =3D 0xbb67ae85u; + param[2] =3D 0x3c6ef372u; + param[3] =3D 0xa54ff53au; + param[4] =3D 0x510e527fu; + param[5] =3D 0x9b05688cu; + param[6] =3D 0x1f83d9abu; + param[7] =3D 0x5be0cd19u; + + /* Process input data */ + cpacf_kimd(CPACF_KIMD_SHA_256, param, sha256in, sizeof(sha256in), &cc); + + /* No check of the result in param block as this is an intermediate va= lue */ + + /* Check for correct condition code (should be 0 on success) */ + if (cc !=3D 0) { + printf("%s failed: unexpected cc=3D%lu\n", __func__, cc); + rc =3D 1; + } + + return rc; +} + +/* subfunction CPACF_KIMD_SHA_512 test for kimd + * returns > 0 on failure, otherwise 0 + */ +static int test_kimd_sha512(void) +{ + uint64_t param[8]; + unsigned long cc =3D 0; + int rc =3D 0; + + /* Initialize SHA-512 hash values */ + param[0] =3D 0x6a09e667f3bcc908lu; + param[1] =3D 0xbb67ae8584caa73blu; + param[2] =3D 0x3c6ef372fe94f82blu; + param[3] =3D 0xa54ff53a5f1d36f1lu; + param[4] =3D 0x510e527fade682d1lu; + param[5] =3D 0x9b05688c2b3e6c1flu; + param[6] =3D 0x1f83d9abfb41bd6blu; + param[7] =3D 0x5be0cd19137e2179lu; + + /* Process input data */ + cpacf_kimd(CPACF_KIMD_SHA_512, param, sha512in, sizeof(sha512in), &cc); + + /* No check of the result in param block as this is an intermediate va= lue */ + + /* Check for correct condition code (should be 0 on success) */ + if (cc !=3D 0) { + printf("%s failed: unexpected cc=3D%lu\n", __func__, cc); + rc =3D 1; + } + + return rc; +} + +int main(void) +{ + int rc =3D 0; + + /* Test query function */ + rc +=3D test_kimd_query(); + + /* Test SHA-256 */ + rc +=3D test_kimd_sha256(); + + /* Test SHA-512 */ + rc +=3D test_kimd_sha512(); + + if (rc) { + printf("cpacf-kimd: %d failures\n", rc); + } + + return rc ? EXIT_FAILURE : EXIT_SUCCESS; +} diff --git a/tests/tcg/s390x/cpacf-klmd.c b/tests/tcg/s390x/cpacf-klmd.c new file mode 100644 index 0000000000..3562227de8 --- /dev/null +++ b/tests/tcg/s390x/cpacf-klmd.c @@ -0,0 +1,202 @@ +/* + * Simple test for CPACF KLMD instruction + * + * This work is licensed under the terms of the GNU GPL, version 2 or late= r. + * See the COPYING file in the top-level directory. + */ + +#include +#include +#include +#include +#include "cpacf.h" + +#define QUERY_BLOCK_SIZE 16 + +/* expected klmd query block */ +static uint8_t exp_query_block[QUERY_BLOCK_SIZE] =3D { + 0xB0, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, +}; + +/* SHA-256 test data */ +static const uint8_t sha256in[] =3D { + 0x5a, 0x86, 0xb7, 0x37, 0xea, 0xea, 0x8e, 0xe9, + 0x76, 0xa0, 0xa2, 0x4d, 0xa6, 0x3e, 0x7e, 0xd7, + 0xee, 0xfa, 0xd1, 0x8a, 0x10, 0x1c, 0x12, 0x11, + 0xe2, 0xb3, 0x65, 0x0c, 0x51, 0x87, 0xc2, 0xa8, + 0xa6, 0x50, 0x54, 0x72, 0x08, 0x25, 0x1f, 0x6d, + 0x42, 0x37, 0xe6, 0x61, 0xc7, 0xbf, 0x4c, 0x77, + 0xf3, 0x35, 0x39, 0x03, 0x94, 0xc3, 0x7f, 0xa1, + 0xa9, 0xf9, 0xbe, 0x83, 0x6a, 0xc2, 0x85, 0x09 +}; + +static const uint8_t sha256md[] =3D { + 0x42, 0xe6, 0x1e, 0x17, 0x4f, 0xbb, 0x38, 0x97, + 0xd6, 0xdd, 0x6c, 0xef, 0x3d, 0xd2, 0x80, 0x2f, + 0xe6, 0x7b, 0x33, 0x19, 0x53, 0xb0, 0x61, 0x14, + 0xa6, 0x5c, 0x77, 0x28, 0x59, 0xdf, 0xc1, 0xaa +}; + +/* SHA-512 test data */ +static const uint8_t sha512in[] =3D { + 0xfd, 0x22, 0x03, 0xe4, 0x67, 0x57, 0x4e, 0x83, + 0x4a, 0xb0, 0x7c, 0x90, 0x97, 0xae, 0x16, 0x45, + 0x32, 0xf2, 0x4b, 0xe1, 0xeb, 0x5d, 0x88, 0xf1, + 0xaf, 0x77, 0x48, 0xce, 0xff, 0x0d, 0x2c, 0x67, + 0xa2, 0x1f, 0x4e, 0x40, 0x97, 0xf9, 0xd3, 0xbb, + 0x4e, 0x9f, 0xbf, 0x97, 0x18, 0x6e, 0x0d, 0xb6, + 0xdb, 0x01, 0x00, 0x23, 0x0a, 0x52, 0xb4, 0x53, + 0xd4, 0x21, 0xf8, 0xab, 0x9c, 0x9a, 0x60, 0x43, + 0xaa, 0x32, 0x95, 0xea, 0x20, 0xd2, 0xf0, 0x6a, + 0x2f, 0x37, 0x47, 0x0d, 0x8a, 0x99, 0x07, 0x5f, + 0x1b, 0x8a, 0x83, 0x36, 0xf6, 0x22, 0x8c, 0xf0, + 0x8b, 0x59, 0x42, 0xfc, 0x1f, 0xb4, 0x29, 0x9c, + 0x7d, 0x24, 0x80, 0xe8, 0xe8, 0x2b, 0xce, 0x17, + 0x55, 0x40, 0xbd, 0xfa, 0xd7, 0x75, 0x2b, 0xc9, + 0x5b, 0x57, 0x7f, 0x22, 0x95, 0x15, 0x39, 0x4f, + 0x3a, 0xe5, 0xce, 0xc8, 0x70, 0xa4, 0xb2, 0xf8 +}; + +static const uint8_t sha512md[] =3D { + 0xa2, 0x1b, 0x10, 0x77, 0xd5, 0x2b, 0x27, 0xac, + 0x54, 0x5a, 0xf6, 0x3b, 0x32, 0x74, 0x6c, 0x6e, + 0x3c, 0x51, 0xcb, 0x0c, 0xb9, 0xf2, 0x81, 0xeb, + 0x9f, 0x35, 0x80, 0xa6, 0xd4, 0x99, 0x6d, 0x5c, + 0x99, 0x17, 0xd2, 0xa6, 0xe4, 0x84, 0x62, 0x7a, + 0x9d, 0x5a, 0x06, 0xfa, 0x1b, 0x25, 0x32, 0x7a, + 0x9d, 0x71, 0x0e, 0x02, 0x73, 0x87, 0xfc, 0x3e, + 0x07, 0xd7, 0xc4, 0xd1, 0x4c, 0x60, 0x86, 0xcc +}; + +/* query test for klmd + * returns > 0 on failure, otherwise 0 + */ +static int test_klmd_query(void) +{ + uint8_t query_block[QUERY_BLOCK_SIZE] =3D {0}; + unsigned long cc =3D 0; + int i, rc =3D 0; + + cpacf_klmd(CPACF_KLMD_QUERY, query_block, NULL, 0, NULL, 0, &cc); + + /* compare with expected query block */ + for (i =3D 0; i < QUERY_BLOCK_SIZE; i++) { + if (query_block[i] !=3D exp_query_block[i]) { + rc++; + break; + } + } + + if (rc) { + printf("%s failed\n", __func__); + } + + return rc; +} + +/* subfunction CPACF_KLMD_SHA_256 test for klmd + * returns > 0 on failure, otherwise 0 + */ +static int test_klmd_sha256(void) +{ + uint8_t param[40]; /* 32 bytes hash + 8 bytes message bit length */ + uint32_t *hash =3D (uint32_t *)param; + uint64_t *mbl =3D (uint64_t *)(param + 32); + unsigned long cc =3D 0; + int rc =3D 0; + + /* Initialize SHA-256 hash values (H0-H7) */ + hash[0] =3D 0x6a09e667u; + hash[1] =3D 0xbb67ae85u; + hash[2] =3D 0x3c6ef372u; + hash[3] =3D 0xa54ff53au; + hash[4] =3D 0x510e527fu; + hash[5] =3D 0x9b05688cu; + hash[6] =3D 0x1f83d9abu; + hash[7] =3D 0x5be0cd19u; + + /* Set message bit length for KLMD */ + *mbl =3D sizeof(sha256in) * 8; + + /* Process input data with KLMD (finalize hash) */ + cpacf_klmd(CPACF_KLMD_SHA_256, param, sha256in, sizeof(sha256in), NULL= , 0, &cc); + + /* Check for correct condition code (should be 0 on success) */ + if (cc !=3D 0) { + printf("%s failed: unexpected cc=3D%lu\n", __func__, cc); + rc =3D 1; + } + + /* Compare hash result in param with expected message digest */ + if (memcmp(param, sha256md, sizeof(sha256md))) { + printf("%s failed: hash mismatch\n", __func__); + rc =3D 1; + } + + return rc; +} + +/* subfunction CPACF_KLMD_SHA_512 test for klmd + * returns > 0 on failure, otherwise 0 + */ +static int test_klmd_sha512(void) +{ + uint8_t param[80]; /* 64 bytes hash + 16 bytes message bit length */ + uint64_t *hash =3D (uint64_t *)param; + uint64_t *mbl_high =3D (uint64_t *)(param + 64); + uint64_t *mbl_low =3D (uint64_t *)(param + 72); + unsigned long cc =3D 0; + int rc =3D 0; + + /* Initialize SHA-512 hash values (H0-H7) */ + hash[0] =3D 0x6a09e667f3bcc908lu; + hash[1] =3D 0xbb67ae8584caa73blu; + hash[2] =3D 0x3c6ef372fe94f82blu; + hash[3] =3D 0xa54ff53a5f1d36f1lu; + hash[4] =3D 0x510e527fade682d1lu; + hash[5] =3D 0x9b05688c2b3e6c1flu; + hash[6] =3D 0x1f83d9abfb41bd6blu; + hash[7] =3D 0x5be0cd19137e2179lu; + + /* Set message bit length for KLMD (128-bit, high and low) */ + *mbl_high =3D 0; + *mbl_low =3D sizeof(sha512in) * 8; + + /* Process input data with KLMD (finalize hash) */ + cpacf_klmd(CPACF_KLMD_SHA_512, param, sha512in, sizeof(sha512in), NULL= , 0, &cc); + + /* Check for correct condition code (should be 0 on success) */ + if (cc !=3D 0) { + printf("%s failed: unexpected cc=3D%lu\n", __func__, cc); + rc =3D 1; + } + + /* Compare hash result in param with expected message digest */ + if (memcmp(param, sha512md, sizeof(sha512md))) { + printf("%s failed: hash mismatch\n", __func__); + rc =3D 1; + } + + return rc; +} + +int main(void) +{ + int rc =3D 0; + + /* Test query function */ + rc +=3D test_klmd_query(); + + /* Test SHA-256 */ + rc +=3D test_klmd_sha256(); + + /* Test SHA-512 */ + rc +=3D test_klmd_sha512(); + + if (rc) { + printf("cpacf-klmd: %d failures\n", rc); + } + + return rc ? EXIT_FAILURE : EXIT_SUCCESS; +} diff --git a/tests/tcg/s390x/cpacf-km.c b/tests/tcg/s390x/cpacf-km.c new file mode 100644 index 0000000000..024fdc9c58 --- /dev/null +++ b/tests/tcg/s390x/cpacf-km.c @@ -0,0 +1,576 @@ +/* + * Simple test for CPACF KM instruction + * + * This work is licensed under the terms of the GNU GPL, version 2 or late= r. + * See the COPYING file in the top-level directory. + */ + +#include +#include +#include +#include +#include "cpacf.h" + +#define QUERY_BLOCK_SIZE 16 + +/* expected km query block */ +static uint8_t exp_query_block[QUERY_BLOCK_SIZE] =3D { + 0x80, 0x00, 0x38, 0x38, 0x00, 0x00, 0x28, 0x28, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, +}; + +/* KM AES-128 test data */ +static const uint8_t kmaes128key[] =3D { + 0xed, 0xfd, 0xb2, 0x57, 0xcb, 0x37, 0xcd, 0xf1, + 0x82, 0xc5, 0x45, 0x5b, 0x0c, 0x0e, 0xfe, 0xbb +}; +static const uint8_t kmaes128plain[] =3D { + 0x16, 0x95, 0xfe, 0x47, 0x54, 0x21, 0xca, 0xce, + 0x35, 0x57, 0xda, 0xca, 0x01, 0xf4, 0x45, 0xff +}; +static const uint8_t kmaes128cipher[] =3D { + 0x78, 0x88, 0xbe, 0xae, 0x6e, 0x7a, 0x42, 0x63, + 0x32, 0xa7, 0xea, 0xa2, 0xf8, 0x08, 0xe6, 0x37 +}; + +/* KM AES-192 test data */ +static const uint8_t kmaes192key[] =3D { + 0x61, 0x39, 0x6c, 0x53, 0x0c, 0xc1, 0x74, 0x9a, + 0x5b, 0xab, 0x6f, 0xbc, 0xf9, 0x06, 0xfe, 0x67, + 0x2d, 0x0c, 0x4a, 0xb2, 0x01, 0xaf, 0x45, 0x54 +}; +static const uint8_t kmaes192plain[] =3D { + 0x60, 0xbc, 0xdb, 0x94, 0x16, 0xba, 0xc0, 0x8d, + 0x7f, 0xd0, 0xd7, 0x80, 0x35, 0x37, 0x40, 0xa5 +}; +static const uint8_t kmaes192cipher[] =3D { + 0x24, 0xf4, 0x0c, 0x4e, 0xec, 0xd9, 0xc4, 0x98, + 0x25, 0x00, 0x0f, 0xcb, 0x49, 0x72, 0x64, 0x7a +}; + +/* KM AES-256 test data */ +static const uint8_t kmaes256key[] =3D { + 0xcc, 0x22, 0xda, 0x78, 0x7f, 0x37, 0x57, 0x11, + 0xc7, 0x63, 0x02, 0xbe, 0xf0, 0x97, 0x9d, 0x8e, + 0xdd, 0xf8, 0x42, 0x82, 0x9c, 0x2b, 0x99, 0xef, + 0x3d, 0xd0, 0x4e, 0x23, 0xe5, 0x4c, 0xc2, 0x4b +}; +static const uint8_t kmaes256plain[] =3D { + 0xcc, 0xc6, 0x2c, 0x6b, 0x0a, 0x09, 0xa6, 0x71, + 0xd6, 0x44, 0x56, 0x81, 0x8d, 0xb2, 0x9a, 0x4d +}; +static const uint8_t kmaes256cipher[] =3D { + 0xdf, 0x86, 0x34, 0xca, 0x02, 0xb1, 0x3a, 0x12, + 0x5b, 0x78, 0x6e, 0x1d, 0xce, 0x90, 0x65, 0x8b +}; + +/* KM AES XTS-128 test data */ +static const uint8_t kmaesxts128key1[] =3D { + 0xa1, 0xb9, 0x0c, 0xba, 0x3f, 0x06, 0xac, 0x35, + 0x3b, 0x2c, 0x34, 0x38, 0x76, 0x08, 0x17, 0x62 +}; +static const uint8_t kmaesxts128key2[] =3D { + 0x09, 0x09, 0x23, 0x02, 0x6e, 0x91, 0x77, 0x18, + 0x15, 0xf2, 0x9d, 0xab, 0x01, 0x93, 0x2f, 0x2f +}; +static const uint8_t kmaesxts128sect[] =3D { + 0x4f, 0xae, 0xf7, 0x11, 0x7c, 0xda, 0x59, 0xc6, + 0x6e, 0x4b, 0x92, 0x01, 0x3e, 0x76, 0x8a, 0xd5 +}; +static const uint8_t kmaesxts128plain[] =3D { + 0xeb, 0xab, 0xce, 0x95, 0xb1, 0x4d, 0x3c, 0x8d, + 0x6f, 0xb3, 0x50, 0x39, 0x07, 0x90, 0x31, 0x1c +}; +static const uint8_t kmaesxts128cipher[] =3D { + 0x77, 0x8a, 0xe8, 0xb4, 0x3c, 0xb9, 0x8d, 0x5a, + 0x82, 0x50, 0x81, 0xd5, 0xbe, 0x47, 0x1c, 0x63 +}; + +/* KM AES XTS-256 test data */ +static const uint8_t kmaesxts256key1[] =3D { + 0x1e, 0xa6, 0x61, 0xc5, 0x8d, 0x94, 0x3a, 0x0e, + 0x48, 0x01, 0xe4, 0x2f, 0x4b, 0x09, 0x47, 0x14, + 0x9e, 0x7f, 0x9f, 0x8e, 0x3e, 0x68, 0xd0, 0xc7, + 0x50, 0x52, 0x10, 0xbd, 0x31, 0x1a, 0x0e, 0x7c +}; +static const uint8_t kmaesxts256key2[] =3D { + 0xd6, 0xe1, 0x3f, 0xfd, 0xf2, 0x41, 0x8d, 0x8d, + 0x19, 0x11, 0xc0, 0x04, 0xcd, 0xa5, 0x8d, 0xa3, + 0xd6, 0x19, 0xb7, 0xe2, 0xb9, 0x14, 0x1e, 0x58, + 0x31, 0x8e, 0xea, 0x39, 0x2c, 0xf4, 0x1b, 0x08 +}; +static const uint8_t kmaesxts256sect[] =3D { + 0xad, 0xf8, 0xd9, 0x26, 0x27, 0x46, 0x4a, 0xd2, + 0xf0, 0x42, 0x8e, 0x84, 0xa9, 0xf8, 0x75, 0x64 +}; +static const uint8_t kmaesxts256plain[] =3D { + 0x2e, 0xed, 0xea, 0x52, 0xcd, 0x82, 0x15, 0xe1, + 0xac, 0xc6, 0x47, 0xe8, 0x10, 0xbb, 0xc3, 0x64, + 0x2e, 0x87, 0x28, 0x7f, 0x8d, 0x2e, 0x57, 0xe3, + 0x6c, 0x0a, 0x24, 0xfb, 0xc1, 0x2a, 0x20, 0x2e +}; +static const uint8_t kmaesxts256cipher[] =3D { + 0xcb, 0xaa, 0xd0, 0xe2, 0xf6, 0xce, 0xa3, 0xf5, + 0x0b, 0x37, 0xf9, 0x34, 0xd4, 0x6a, 0x9b, 0x13, + 0x0b, 0x9d, 0x54, 0xf0, 0x7e, 0x34, 0xf3, 0x6a, + 0xf7, 0x93, 0xe8, 0x6f, 0x73, 0xc6, 0xd7, 0xdb +}; + +/* static byte array containing the WKVP */ +static const uint8_t protkey_wkvp[32] =3D PROTKEY_WKVP; + +/* query test for km + * returns > 0 on failure, otherwise 0 + */ +static int test_km_query(void) +{ + uint8_t query_block[QUERY_BLOCK_SIZE] =3D {0}; + unsigned long cc =3D 0; + int i, rc =3D 0; + + cpacf_km(CPACF_KM_QUERY, query_block, NULL, NULL, 0, &cc); + + /* compare with expected query block */ + for (i =3D 0; i < QUERY_BLOCK_SIZE; i++) { + if (query_block[i] !=3D exp_query_block[i]) { + rc++; + break; + } + } + + if (rc) { + printf("%s failed\n", __func__); + } + + return rc; +} + +/* subfunction CPACF_KM_AES_128 test for km + * returns > 0 on failure, otherwise 0 + */ +static int test_km_aes_128(void) +{ + uint8_t param[16]; /* key only, no IV for ECB mode */ + uint8_t output[16]; + unsigned long cc =3D 0; + int rc =3D 0; + + /* Setup parameter block: key only */ + memcpy(param, kmaes128key, sizeof(kmaes128key)); + + /* Encrypt */ + cpacf_km(CPACF_KM_AES_128, param, output, kmaes128plain, + sizeof(kmaes128plain), &cc); + + /* Check for correct condition code */ + if (cc !=3D 0) { + printf("%s failed: unexpected cc=3D%lu\n", __func__, cc); + rc =3D 1; + } + + /* Compare result with expected ciphertext */ + if (memcmp(output, kmaes128cipher, sizeof(kmaes128cipher))) { + printf("%s failed: output mismatch\n", __func__); + rc =3D 1; + } + + return rc; +} + +/* subfunction CPACF_KM_AES_192 test for km + * returns > 0 on failure, otherwise 0 + */ +static int test_km_aes_192(void) +{ + uint8_t param[24]; /* key only, no IV for ECB mode */ + uint8_t output[16]; + unsigned long cc =3D 0; + int rc =3D 0; + + /* Setup parameter block: key only */ + memcpy(param, kmaes192key, sizeof(kmaes192key)); + + /* Encrypt */ + cpacf_km(CPACF_KM_AES_192, param, output, kmaes192plain, + sizeof(kmaes192plain), &cc); + + /* Check for correct condition code */ + if (cc !=3D 0) { + printf("%s failed: unexpected cc=3D%lu\n", __func__, cc); + rc =3D 1; + } + + /* Compare result with expected ciphertext */ + if (memcmp(output, kmaes192cipher, sizeof(kmaes192cipher))) { + printf("%s failed: output mismatch\n", __func__); + rc =3D 1; + } + + return rc; +} + +/* subfunction CPACF_KM_AES_256 test for km + * returns > 0 on failure, otherwise 0 + */ +static int test_km_aes_256(void) +{ + uint8_t param[32]; /* key only, no IV for ECB mode */ + uint8_t output[16]; + unsigned long cc =3D 0; + int rc =3D 0; + + /* Setup parameter block: key only */ + memcpy(param, kmaes256key, sizeof(kmaes256key)); + + /* Encrypt */ + cpacf_km(CPACF_KM_AES_256, param, output, kmaes256plain, + sizeof(kmaes256plain), &cc); + + /* Check for correct condition code */ + if (cc !=3D 0) { + printf("%s failed: unexpected cc=3D%lu\n", __func__, cc); + rc =3D 1; + } + + /* Compare result with expected ciphertext */ + if (memcmp(output, kmaes256cipher, sizeof(kmaes256cipher))) { + printf("%s failed: output mismatch\n", __func__); + rc =3D 1; + } + + return rc; +} + +/* subfunction CPACF_KM_PAES_128 test for km + * returns > 0 on failure, otherwise 0 + */ +static int test_km_paes_128(void) +{ + uint8_t param[16 + 32]; /* protected key + wkvp */ + uint8_t output[16]; + unsigned long cc =3D 0; + int rc =3D 0; + + /* Setup parameter block: protected key + wkvp */ + memcpy(param, kmaes128key, sizeof(kmaes128key)); + encrypt_clrkey(param, sizeof(kmaes128key)); + memcpy(param + sizeof(kmaes128key), protkey_wkvp, sizeof(protkey_wkvp)= ); + + /* Encrypt */ + cpacf_km(CPACF_KM_PAES_128, param, output, kmaes128plain, + sizeof(kmaes128plain), &cc); + + /* Check for correct condition code */ + if (cc !=3D 0) { + printf("%s failed: unexpected cc=3D%lu\n", __func__, cc); + rc =3D 1; + } + + /* Compare result with expected ciphertext */ + if (memcmp(output, kmaes128cipher, sizeof(kmaes128cipher))) { + printf("%s failed: output mismatch\n", __func__); + rc =3D 1; + } + + return rc; +} + +/* subfunction CPACF_KM_PAES_192 test for km + * returns > 0 on failure, otherwise 0 + */ +static int test_km_paes_192(void) +{ + uint8_t param[24 + 32]; /* protected key + wkvp */ + uint8_t output[16]; + unsigned long cc =3D 0; + int rc =3D 0; + + /* Setup parameter block: protected key + wkvp */ + memcpy(param, kmaes192key, sizeof(kmaes192key)); + encrypt_clrkey(param, sizeof(kmaes192key)); + memcpy(param + sizeof(kmaes192key), protkey_wkvp, sizeof(protkey_wkvp)= ); + + /* Encrypt */ + cpacf_km(CPACF_KM_PAES_192, param, output, kmaes192plain, + sizeof(kmaes192plain), &cc); + + /* Check for correct condition code */ + if (cc !=3D 0) { + printf("%s failed: unexpected cc=3D%lu\n", __func__, cc); + rc =3D 1; + } + + /* Compare result with expected ciphertext */ + if (memcmp(output, kmaes192cipher, sizeof(kmaes192cipher))) { + printf("%s failed: output mismatch\n", __func__); + rc =3D 1; + } + + return rc; +} + +/* subfunction CPACF_KM_PAES_256 test for km + * returns > 0 on failure, otherwise 0 + */ +static int test_km_paes_256(void) +{ + uint8_t param[32 + 32]; /* protected key + wkvp */ + uint8_t output[16]; + unsigned long cc =3D 0; + int rc =3D 0; + + /* Setup parameter block: protected key + wkvp */ + memcpy(param, kmaes256key, sizeof(kmaes256key)); + encrypt_clrkey(param, sizeof(kmaes256key)); + memcpy(param + sizeof(kmaes256key), protkey_wkvp, sizeof(protkey_wkvp)= ); + + /* Encrypt */ + cpacf_km(CPACF_KM_PAES_256, param, output, kmaes256plain, + sizeof(kmaes256plain), &cc); + + /* Check for correct condition code */ + if (cc !=3D 0) { + printf("%s failed: unexpected cc=3D%lu\n", __func__, cc); + rc =3D 1; + } + + /* Compare result with expected ciphertext */ + if (memcmp(output, kmaes256cipher, sizeof(kmaes256cipher))) { + printf("%s failed: output mismatch\n", __func__); + rc =3D 1; + } + + return rc; +} + +/* subfunction CPACF_KM_XTS_128 test for km + * returns > 0 on failure, otherwise 0 + */ +static int test_km_xts_128(void) +{ + uint8_t param[16 + 16]; /* key + initial XTS value */ + uint8_t output[16]; + uint8_t init_xts[16]; + unsigned long cc =3D 0; + int rc =3D 0; + + /* First compute initial XTS value using key2 and sector */ + memcpy(param, kmaesxts128key2, sizeof(kmaesxts128key2)); + cpacf_km(CPACF_KM_AES_128, param, init_xts, kmaesxts128sect, + sizeof(kmaesxts128sect), &cc); + + if (cc !=3D 0) { + printf("%s failed: initial XTS computation cc=3D%lu\n", __func__, = cc); + return 1; + } + + /* Setup parameter block: key1 + initial XTS value */ + memcpy(param, kmaesxts128key1, sizeof(kmaesxts128key1)); + memcpy(param + 16, init_xts, sizeof(init_xts)); + + /* Encrypt */ + cpacf_km(CPACF_KM_XTS_128, param, output, kmaesxts128plain, + sizeof(kmaesxts128plain), &cc); + + /* Check for correct condition code */ + if (cc !=3D 0) { + printf("%s failed: unexpected cc=3D%lu\n", __func__, cc); + rc =3D 1; + } + + /* Compare result with expected ciphertext */ + if (memcmp(output, kmaesxts128cipher, sizeof(kmaesxts128cipher))) { + printf("%s failed: output mismatch\n", __func__); + rc =3D 1; + } + + return rc; +} + +/* subfunction CPACF_KM_XTS_256 test for km + * returns > 0 on failure, otherwise 0 + */ +static int test_km_xts_256(void) +{ + uint8_t param[32 + 16]; /* key + initial XTS value */ + uint8_t output[32]; + uint8_t init_xts[16]; + unsigned long cc =3D 0; + int rc =3D 0; + + /* First compute initial XTS value using key2 and sector */ + memcpy(param, kmaesxts256key2, sizeof(kmaesxts256key2)); + cpacf_km(CPACF_KM_AES_256, param, init_xts, kmaesxts256sect, + sizeof(kmaesxts256sect), &cc); + + if (cc !=3D 0) { + printf("%s failed: initial XTS computation cc=3D%lu\n", __func__, = cc); + return 1; + } + + /* Setup parameter block: key1 + initial XTS value */ + memcpy(param, kmaesxts256key1, sizeof(kmaesxts256key1)); + memcpy(param + 32, init_xts, sizeof(init_xts)); + + /* Encrypt */ + cpacf_km(CPACF_KM_XTS_256, param, output, kmaesxts256plain, + sizeof(kmaesxts256plain), &cc); + + /* Check for correct condition code */ + if (cc !=3D 0) { + printf("%s failed: unexpected cc=3D%lu\n", __func__, cc); + rc =3D 1; + } + + /* Compare result with expected ciphertext */ + if (memcmp(output, kmaesxts256cipher, sizeof(kmaesxts256cipher))) { + printf("%s failed: output mismatch\n", __func__); + rc =3D 1; + } + + return rc; +} + +/* subfunction CPACF_KM_PXTS_128 test for km + * returns > 0 on failure, otherwise 0 + */ +static int test_km_pxts_128(void) +{ + uint8_t param[16 + 32 + 16]; /* protected key + wkvp + initial XTS val= ue */ + uint8_t output[16]; + uint8_t init_xts[16]; + uint8_t key2_param[16 + 32]; + unsigned long cc =3D 0; + int rc =3D 0; + + /* First compute initial XTS value using protected key2 and sector */ + memcpy(key2_param, kmaesxts128key2, sizeof(kmaesxts128key2)); + encrypt_clrkey(key2_param, sizeof(kmaesxts128key2)); + memcpy(key2_param + sizeof(kmaesxts128key2), protkey_wkvp, sizeof(prot= key_wkvp)); + + cpacf_km(CPACF_KM_PAES_128, key2_param, init_xts, kmaesxts128sect, + sizeof(kmaesxts128sect), &cc); + + if (cc !=3D 0) { + printf("%s failed: initial XTS computation cc=3D%lu\n", __func__, = cc); + return 1; + } + + /* Setup parameter block: protected key1 + wkvp + initial XTS value */ + memcpy(param, kmaesxts128key1, sizeof(kmaesxts128key1)); + encrypt_clrkey(param, sizeof(kmaesxts128key1)); + memcpy(param + sizeof(kmaesxts128key1), protkey_wkvp, sizeof(protkey_w= kvp)); + memcpy(param + sizeof(kmaesxts128key1) + sizeof(protkey_wkvp), init_xt= s, sizeof(init_xts)); + + /* Encrypt */ + cpacf_km(CPACF_KM_PXTS_128, param, output, kmaesxts128plain, + sizeof(kmaesxts128plain), &cc); + + /* Check for correct condition code */ + if (cc !=3D 0) { + printf("%s failed: unexpected cc=3D%lu\n", __func__, cc); + rc =3D 1; + } + + /* Compare result with expected ciphertext */ + if (memcmp(output, kmaesxts128cipher, sizeof(kmaesxts128cipher))) { + printf("%s failed: output mismatch\n", __func__); + rc =3D 1; + } + + return rc; +} + +/* subfunction CPACF_KM_PXTS_256 test for km + * returns > 0 on failure, otherwise 0 + */ +static int test_km_pxts_256(void) +{ + uint8_t param[32 + 32 + 16]; /* protected key + wkvp + initial XTS val= ue */ + uint8_t output[32]; + uint8_t init_xts[16]; + uint8_t key2_param[32 + 32]; + unsigned long cc =3D 0; + int rc =3D 0; + + /* First compute initial XTS value using protected key2 and sector */ + memcpy(key2_param, kmaesxts256key2, sizeof(kmaesxts256key2)); + encrypt_clrkey(key2_param, sizeof(kmaesxts256key2)); + memcpy(key2_param + sizeof(kmaesxts256key2), protkey_wkvp, sizeof(prot= key_wkvp)); + + cpacf_km(CPACF_KM_PAES_256, key2_param, init_xts, kmaesxts256sect, + sizeof(kmaesxts256sect), &cc); + + if (cc !=3D 0) { + printf("%s failed: initial XTS computation cc=3D%lu\n", __func__, = cc); + return 1; + } + + /* Setup parameter block: protected key1 + wkvp + initial XTS value */ + memcpy(param, kmaesxts256key1, sizeof(kmaesxts256key1)); + encrypt_clrkey(param, sizeof(kmaesxts256key1)); + memcpy(param + sizeof(kmaesxts256key1), protkey_wkvp, sizeof(protkey_w= kvp)); + memcpy(param + sizeof(kmaesxts256key1) + sizeof(protkey_wkvp), init_xt= s, sizeof(init_xts)); + + /* Encrypt */ + cpacf_km(CPACF_KM_PXTS_256, param, output, kmaesxts256plain, + sizeof(kmaesxts256plain), &cc); + + /* Check for correct condition code */ + if (cc !=3D 0) { + printf("%s failed: unexpected cc=3D%lu\n", __func__, cc); + rc =3D 1; + } + + /* Compare result with expected ciphertext */ + if (memcmp(output, kmaesxts256cipher, sizeof(kmaesxts256cipher))) { + printf("%s failed: output mismatch\n", __func__); + rc =3D 1; + } + + return rc; +} + +int main(void) +{ + int rc =3D 0; + + /* Test query function */ + rc +=3D test_km_query(); + + /* Test AES-128 */ + rc +=3D test_km_aes_128(); + + /* Test AES-192 */ + rc +=3D test_km_aes_192(); + + /* Test AES-256 */ + rc +=3D test_km_aes_256(); + + /* Test PAES-128 */ + rc +=3D test_km_paes_128(); + + /* Test PAES-192 */ + rc +=3D test_km_paes_192(); + + /* Test PAES-256 */ + rc +=3D test_km_paes_256(); + + /* Test XTS-128 */ + rc +=3D test_km_xts_128(); + + /* Test XTS-256 */ + rc +=3D test_km_xts_256(); + + /* Test PXTS-128 */ + rc +=3D test_km_pxts_128(); + + /* Test PXTS-256 */ + rc +=3D test_km_pxts_256(); + + if (rc) { + printf("cpacf-km: %d failures\n", rc); + } + + return rc ? EXIT_FAILURE : EXIT_SUCCESS; +} diff --git a/tests/tcg/s390x/cpacf-kmac.c b/tests/tcg/s390x/cpacf-kmac.c new file mode 100644 index 0000000000..e5a122b74c --- /dev/null +++ b/tests/tcg/s390x/cpacf-kmac.c @@ -0,0 +1,59 @@ +/* + * Simple test for the CPACF KMAC instruction + * + * This work is licensed under the terms of the GNU GPL, version 2 or late= r. + * See the COPYING file in the top-level directory. + */ + +#include +#include +#include +#include +#include "cpacf.h" + +#define QUERY_BLOCK_SIZE 16 + +/* expected kmac query block */ +static uint8_t exp_query_block[QUERY_BLOCK_SIZE] =3D { + 0x80, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, +}; + +static int test_kmac_query(void) +{ + uint8_t query_block[QUERY_BLOCK_SIZE] =3D {0}; + unsigned long cc =3D 0; + int i, rc =3D 0; + + cpacf_kmac(CPACF_KMAC_QUERY, query_block, NULL, 0, &cc); + + /* compare with expected query block */ + for (i =3D 0; i < QUERY_BLOCK_SIZE; i++) { + if (query_block[i] !=3D exp_query_block[i]) { + rc++; + break; + } + } + + if (rc) { + printf("%s failed\n", __func__); + } + + return rc; +} + +int main(void) +{ + int rc; + + /* Test query function */ + rc =3D test_kmac_query(); + + /* As of now only KMAC query is implemented */ + + if (rc) { + printf("cpacf-kmac: %d failures\n", rc); + } + + return rc ? EXIT_FAILURE : EXIT_SUCCESS; +} diff --git a/tests/tcg/s390x/cpacf-kmc.c b/tests/tcg/s390x/cpacf-kmc.c new file mode 100644 index 0000000000..1ebd2e5d4a --- /dev/null +++ b/tests/tcg/s390x/cpacf-kmc.c @@ -0,0 +1,342 @@ +/* + * Simple test for CPACF KMC instruction + * + * This work is licensed under the terms of the GNU GPL, version 2 or late= r. + * See the COPYING file in the top-level directory. + */ + +#include +#include +#include +#include +#include "cpacf.h" + +#define QUERY_BLOCK_SIZE 16 + +/* expected kmc query block */ +static uint8_t exp_query_block[QUERY_BLOCK_SIZE] =3D { + 0x80, 0x00, 0x38, 0x38, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, +}; + +/* KMC AES-128 test data */ +static const uint8_t kmcaes128key[] =3D { + 0x1f, 0x8e, 0x49, 0x73, 0x95, 0x3f, 0x3f, 0xb0, + 0xbd, 0x6b, 0x16, 0x66, 0x2e, 0x9a, 0x3c, 0x17 +}; +static const uint8_t kmcaes128iv[] =3D { + 0x2f, 0xe2, 0xb3, 0x33, 0xce, 0xda, 0x8f, 0x98, + 0xf4, 0xa9, 0x9b, 0x40, 0xd2, 0xcd, 0x34, 0xa8 +}; +static const uint8_t kmcaes128plain[] =3D { + 0x45, 0xcf, 0x12, 0x96, 0x4f, 0xc8, 0x24, 0xab, + 0x76, 0x61, 0x6a, 0xe2, 0xf4, 0xbf, 0x08, 0x22 +}; +static const uint8_t kmcaes128cipher[] =3D { + 0x0f, 0x61, 0xc4, 0xd4, 0x4c, 0x51, 0x47, 0xc0, + 0x3c, 0x19, 0x5a, 0xd7, 0xe2, 0xcc, 0x12, 0xb2 +}; + +/* KMC AES-192 test data */ +static const uint8_t kmcaes192key[] =3D { + 0xba, 0x75, 0xf4, 0xd1, 0xd9, 0xd7, 0xcf, 0x7f, + 0x55, 0x14, 0x45, 0xd5, 0x6c, 0xc1, 0xa8, 0xab, + 0x2a, 0x07, 0x8e, 0x15, 0xe0, 0x49, 0xdc, 0x2c +}; +static const uint8_t kmcaes192iv[] =3D { + 0x53, 0x1c, 0xe7, 0x81, 0x76, 0x40, 0x16, 0x66, + 0xaa, 0x30, 0xdb, 0x94, 0xec, 0x4a, 0x30, 0xeb +}; +static const uint8_t kmcaes192plain[] =3D { + 0xc5, 0x1f, 0xc2, 0x76, 0x77, 0x4d, 0xad, 0x94, + 0xbc, 0xdc, 0x1d, 0x28, 0x91, 0xec, 0x86, 0x68 +}; +static const uint8_t kmcaes192cipher[] =3D { + 0x70, 0xdd, 0x95, 0xa1, 0x4e, 0xe9, 0x75, 0xe2, + 0x39, 0xdf, 0x36, 0xff, 0x4a, 0xee, 0x1d, 0x5d +}; + +/* KMC AES-256 test data */ +static const uint8_t kmcaes256key[] =3D { + 0x6e, 0xd7, 0x6d, 0x2d, 0x97, 0xc6, 0x9f, 0xd1, + 0x33, 0x95, 0x89, 0x52, 0x39, 0x31, 0xf2, 0xa6, + 0xcf, 0xf5, 0x54, 0xb1, 0x5f, 0x73, 0x8f, 0x21, + 0xec, 0x72, 0xdd, 0x97, 0xa7, 0x33, 0x09, 0x07 +}; +static const uint8_t kmcaes256iv[] =3D { + 0x85, 0x1e, 0x87, 0x64, 0x77, 0x6e, 0x67, 0x96, + 0xaa, 0xb7, 0x22, 0xdb, 0xb6, 0x44, 0xac, 0xe8 +}; +static const uint8_t kmcaes256plain[] =3D { + 0x62, 0x82, 0xb8, 0xc0, 0x5c, 0x5c, 0x15, 0x30, + 0xb9, 0x7d, 0x48, 0x16, 0xca, 0x43, 0x47, 0x62 +}; +static const uint8_t kmcaes256cipher[] =3D { + 0x6a, 0xcc, 0x04, 0x14, 0x2e, 0x10, 0x0a, 0x65, + 0xf5, 0x1b, 0x97, 0xad, 0xf5, 0x17, 0x2c, 0x41 +}; + +/* static byte array containing the WKVP */ +static const uint8_t protkey_wkvp[32] =3D PROTKEY_WKVP; + +/* query test for kmc + * returns > 0 on failure, otherwise 0 + */ +static int test_kmc_query(void) +{ + uint8_t query_block[QUERY_BLOCK_SIZE] =3D {0}; + unsigned long cc =3D 0; + int i, rc =3D 0; + + cpacf_kmc(CPACF_KMC_QUERY, query_block, NULL, NULL, 0, &cc); + + /* compare with expected query block */ + for (i =3D 0; i < QUERY_BLOCK_SIZE; i++) { + if (query_block[i] !=3D exp_query_block[i]) { + rc++; + break; + } + } + + if (rc) { + printf("%s failed\n", __func__); + } + + return rc; +} + +/* subfunction CPACF_KMC_AES_128 test for kmc + * returns > 0 on failure, otherwise 0 + */ +static int test_kmc_aes_128(void) +{ + uint8_t param[16 + 16]; /* IV + key */ + uint8_t output[16]; + unsigned long cc =3D 0; + int rc =3D 0; + + /* Setup parameter block: IV followed by key */ + memcpy(param, kmcaes128iv, sizeof(kmcaes128iv)); + memcpy(param + sizeof(kmcaes128iv), kmcaes128key, sizeof(kmcaes128key)= ); + + /* Encrypt */ + cpacf_kmc(CPACF_KMC_AES_128, param, output, kmcaes128plain, + sizeof(kmcaes128plain), &cc); + + /* Check for correct condition code */ + if (cc !=3D 0) { + printf("%s failed: unexpected cc=3D%lu\n", __func__, cc); + rc =3D 1; + } + + /* Compare result with expected ciphertext */ + if (memcmp(output, kmcaes128cipher, sizeof(kmcaes128cipher))) { + printf("%s failed: output mismatch\n", __func__); + rc =3D 1; + } + + return rc; +} + +/* subfunction CPACF_KMC_AES_192 test for kmc + * returns > 0 on failure, otherwise 0 + */ +static int test_kmc_aes_192(void) +{ + uint8_t param[16 + 24]; /* IV + key */ + uint8_t output[16]; + unsigned long cc =3D 0; + int rc =3D 0; + + /* Setup parameter block: IV followed by key */ + memcpy(param, kmcaes192iv, sizeof(kmcaes192iv)); + memcpy(param + sizeof(kmcaes192iv), kmcaes192key, sizeof(kmcaes192key)= ); + + /* Encrypt */ + cpacf_kmc(CPACF_KMC_AES_192, param, output, kmcaes192plain, + sizeof(kmcaes192plain), &cc); + + /* Check for correct condition code */ + if (cc !=3D 0) { + printf("%s failed: unexpected cc=3D%lu\n", __func__, cc); + rc =3D 1; + } + + /* Compare result with expected ciphertext */ + if (memcmp(output, kmcaes192cipher, sizeof(kmcaes192cipher))) { + printf("%s failed: output mismatch\n", __func__); + rc =3D 1; + } + + return rc; +} + +/* subfunction CPACF_KMC_AES_256 test for kmc + * returns > 0 on failure, otherwise 0 + */ +static int test_kmc_aes_256(void) +{ + uint8_t param[16 + 32]; /* IV + key */ + uint8_t output[16]; + unsigned long cc =3D 0; + int rc =3D 0; + + /* Setup parameter block: IV followed by key */ + memcpy(param, kmcaes256iv, sizeof(kmcaes256iv)); + memcpy(param + sizeof(kmcaes256iv), kmcaes256key, sizeof(kmcaes256key)= ); + + /* Encrypt */ + cpacf_kmc(CPACF_KMC_AES_256, param, output, kmcaes256plain, + sizeof(kmcaes256plain), &cc); + + /* Check for correct condition code */ + if (cc !=3D 0) { + printf("%s failed: unexpected cc=3D%lu\n", __func__, cc); + rc =3D 1; + } + + /* Compare result with expected ciphertext */ + if (memcmp(output, kmcaes256cipher, sizeof(kmcaes256cipher))) { + printf("%s failed: output mismatch\n", __func__); + rc =3D 1; + } + + return rc; +} + +/* subfunction CPACF_KMC_PAES_128 test for kmc + * returns > 0 on failure, otherwise 0 + */ +static int test_kmc_paes_128(void) +{ + uint8_t param[16 + 16 + 32]; /* IV + protected key + wkvp */ + uint8_t output[16]; + unsigned long cc =3D 0; + int rc =3D 0; + + /* Setup parameter block: IV + protected key + wkvp */ + memcpy(param, kmcaes128iv, sizeof(kmcaes128iv)); + memcpy(param + sizeof(kmcaes128iv), kmcaes128key, sizeof(kmcaes128key)= ); + encrypt_clrkey(param + sizeof(kmcaes128iv), sizeof(kmcaes128key)); + memcpy(param + sizeof(kmcaes128iv) + sizeof(kmcaes128key), protkey_wkv= p, sizeof(protkey_wkvp)); + + /* Encrypt */ + cpacf_kmc(CPACF_KMC_PAES_128, param, output, kmcaes128plain, + sizeof(kmcaes128plain), &cc); + + /* Check for correct condition code */ + if (cc !=3D 0) { + printf("%s failed: unexpected cc=3D%lu\n", __func__, cc); + rc =3D 1; + } + + /* Compare result with expected ciphertext */ + if (memcmp(output, kmcaes128cipher, sizeof(kmcaes128cipher))) { + printf("%s failed: output mismatch\n", __func__); + rc =3D 1; + } + + return rc; +} + +/* subfunction CPACF_KMC_PAES_192 test for kmc + * returns > 0 on failure, otherwise 0 + */ +static int test_kmc_paes_192(void) +{ + uint8_t param[16 + 24 + 32]; /* IV + protected key + wkvp */ + uint8_t output[16]; + unsigned long cc =3D 0; + int rc =3D 0; + + /* Setup parameter block: IV + protected key + wkvp */ + memcpy(param, kmcaes192iv, sizeof(kmcaes192iv)); + memcpy(param + sizeof(kmcaes192iv), kmcaes192key, sizeof(kmcaes192key)= ); + encrypt_clrkey(param + sizeof(kmcaes192iv), sizeof(kmcaes192key)); + memcpy(param + sizeof(kmcaes192iv) + sizeof(kmcaes192key), protkey_wkv= p, sizeof(protkey_wkvp)); + + /* Encrypt */ + cpacf_kmc(CPACF_KMC_PAES_192, param, output, kmcaes192plain, + sizeof(kmcaes192plain), &cc); + + /* Check for correct condition code */ + if (cc !=3D 0) { + printf("%s failed: unexpected cc=3D%lu\n", __func__, cc); + rc =3D 1; + } + + /* Compare result with expected ciphertext */ + if (memcmp(output, kmcaes192cipher, sizeof(kmcaes192cipher))) { + printf("%s failed: output mismatch\n", __func__); + rc =3D 1; + } + + return rc; +} + +/* subfunction CPACF_KMC_PAES_256 test for kmc + * returns > 0 on failure, otherwise 0 + */ +static int test_kmc_paes_256(void) +{ + uint8_t param[16 + 32 + 32]; /* IV + protected key + wkvp */ + uint8_t output[16]; + unsigned long cc =3D 0; + int rc =3D 0; + + /* Setup parameter block: IV + protected key + wkvp */ + memcpy(param, kmcaes256iv, sizeof(kmcaes256iv)); + memcpy(param + sizeof(kmcaes256iv), kmcaes256key, sizeof(kmcaes256key)= ); + encrypt_clrkey(param + sizeof(kmcaes256iv), sizeof(kmcaes256key)); + memcpy(param + sizeof(kmcaes256iv) + sizeof(kmcaes256key), protkey_wkv= p, sizeof(protkey_wkvp)); + + /* Encrypt */ + cpacf_kmc(CPACF_KMC_PAES_256, param, output, kmcaes256plain, + sizeof(kmcaes256plain), &cc); + + /* Check for correct condition code */ + if (cc !=3D 0) { + printf("%s failed: unexpected cc=3D%lu\n", __func__, cc); + rc =3D 1; + } + + /* Compare result with expected ciphertext */ + if (memcmp(output, kmcaes256cipher, sizeof(kmcaes256cipher))) { + printf("%s failed: output mismatch\n", __func__); + rc =3D 1; + } + + return rc; +} + +int main(void) +{ + int rc =3D 0; + + /* Test query function */ + rc +=3D test_kmc_query(); + + /* Test AES-128 */ + rc +=3D test_kmc_aes_128(); + + /* Test AES-192 */ + rc +=3D test_kmc_aes_192(); + + /* Test AES-256 */ + rc +=3D test_kmc_aes_256(); + + /* Test PAES-128 */ + rc +=3D test_kmc_paes_128(); + + /* Test PAES-192 */ + rc +=3D test_kmc_paes_192(); + + /* Test PAES-256 */ + rc +=3D test_kmc_paes_256(); + + if (rc) { + printf("cpacf-kmc: %d failures\n", rc); + } + + return rc ? EXIT_FAILURE : EXIT_SUCCESS; +} diff --git a/tests/tcg/s390x/cpacf-kmctr.c b/tests/tcg/s390x/cpacf-kmctr.c new file mode 100644 index 0000000000..5b9886988b --- /dev/null +++ b/tests/tcg/s390x/cpacf-kmctr.c @@ -0,0 +1,354 @@ +/* + * Simple test for CPACF KMCTR instruction + * + * This work is licensed under the terms of the GNU GPL, version 2 or late= r. + * See the COPYING file in the top-level directory. + */ + +#include +#include +#include +#include +#include "cpacf.h" + +#define QUERY_BLOCK_SIZE 16 + +/* expected kmctr query block */ +static uint8_t exp_query_block[QUERY_BLOCK_SIZE] =3D { + 0x80, 0x00, 0x38, 0x38, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, +}; + +/* KMCTR AES-128 test data */ +static const uint8_t kmctraes128key[] =3D { + 0xed, 0xfd, 0xb2, 0x57, 0xcb, 0x37, 0xcd, 0xf1, + 0x82, 0xc5, 0x45, 0x5b, 0x0c, 0x0e, 0xfe, 0xbb +}; +static const uint8_t kmctraes128plain[] =3D { + 0x16, 0x95, 0xfe, 0x47, 0x54, 0x21, 0xca, 0xce, + 0x35, 0x57, 0xda, 0xca, 0x01, 0xf4, 0x45, 0xff +}; +static const uint8_t kmctraes128cipher[] =3D { + 0x78, 0x88, 0xbe, 0xae, 0x6e, 0x7a, 0x42, 0x63, + 0x32, 0xa7, 0xea, 0xa2, 0xf8, 0x08, 0xe6, 0x37 +}; + +/* KMCTR AES-192 test data */ +static const uint8_t kmctraes192key[] =3D { + 0x61, 0x39, 0x6c, 0x53, 0x0c, 0xc1, 0x74, 0x9a, + 0x5b, 0xab, 0x6f, 0xbc, 0xf9, 0x06, 0xfe, 0x67, + 0x2d, 0x0c, 0x4a, 0xb2, 0x01, 0xaf, 0x45, 0x54 +}; +static const uint8_t kmctraes192plain[] =3D { + 0x60, 0xbc, 0xdb, 0x94, 0x16, 0xba, 0xc0, 0x8d, + 0x7f, 0xd0, 0xd7, 0x80, 0x35, 0x37, 0x40, 0xa5 +}; +static const uint8_t kmctraes192cipher[] =3D { + 0x24, 0xf4, 0x0c, 0x4e, 0xec, 0xd9, 0xc4, 0x98, + 0x25, 0x00, 0x0f, 0xcb, 0x49, 0x72, 0x64, 0x7a +}; + +/* KMCTR AES-256 test data */ +static const uint8_t kmctraes256key[] =3D { + 0xcc, 0x22, 0xda, 0x78, 0x7f, 0x37, 0x57, 0x11, + 0xc7, 0x63, 0x02, 0xbe, 0xf0, 0x97, 0x9d, 0x8e, + 0xdd, 0xf8, 0x42, 0x82, 0x9c, 0x2b, 0x99, 0xef, + 0x3d, 0xd0, 0x4e, 0x23, 0xe5, 0x4c, 0xc2, 0x4b +}; +static const uint8_t kmctraes256plain[] =3D { + 0xcc, 0xc6, 0x2c, 0x6b, 0x0a, 0x09, 0xa6, 0x71, + 0xd6, 0x44, 0x56, 0x81, 0x8d, 0xb2, 0x9a, 0x4d +}; +static const uint8_t kmctraes256cipher[] =3D { + 0xdf, 0x86, 0x34, 0xca, 0x02, 0xb1, 0x3a, 0x12, + 0x5b, 0x78, 0x6e, 0x1d, 0xce, 0x90, 0x65, 0x8b +}; + +/* static byte array containing the WKVP */ +static const uint8_t protkey_wkvp[32] =3D PROTKEY_WKVP; + +/* query test for kmctr + * returns > 0 on failure, otherwise 0 + */ +static int test_kmctr_query(void) +{ + uint8_t query_block[QUERY_BLOCK_SIZE] =3D {0}; + unsigned long cc =3D 0; + int i, rc =3D 0; + + cpacf_kmctr(CPACF_KMCTR_QUERY, query_block, NULL, NULL, 0, NULL, &cc); + + /* compare with expected query block */ + for (i =3D 0; i < QUERY_BLOCK_SIZE; i++) { + if (query_block[i] !=3D exp_query_block[i]) { + rc++; + break; + } + } + + if (rc) { + printf("%s failed\n", __func__); + } + + return rc; +} + +/* subfunction CPACF_KMCTR_AES_128 test for kmctr + * returns > 0 on failure, otherwise 0 + */ +static int test_kmctr_aes_128(void) +{ + uint8_t param[16]; /* Parameter block: AES-128 key */ + uint8_t src[16] =3D {0}; /* Source data (zeros for this test) */ + uint8_t counter[16]; /* Counter value */ + uint8_t output[16]; /* Output buffer */ + unsigned long cc =3D 0; + int rc =3D 0; + + /* Setup parameter block: key only */ + memcpy(param, kmctraes128key, sizeof(kmctraes128key)); + + /* Setup counter buffer */ + memcpy(counter, kmctraes128plain, sizeof(kmctraes128plain)); + + /* En/Decrypt src with given counter, note that src is all zero */ + cpacf_kmctr(CPACF_KMCTR_AES_128, param, output, src, + sizeof(src), counter, &cc); + + /* Check for correct condition code */ + if (cc !=3D 0) { + printf("%s failed: unexpected cc=3D%lu\n", __func__, cc); + rc =3D 1; + } + + /* Compare result with expected ciphertext */ + if (memcmp(output, kmctraes128cipher, sizeof(kmctraes128cipher))) { + printf("%s failed: output mismatch\n", __func__); + rc =3D 1; + } + + return rc; +} + +/* subfunction CPACF_KMCTR_AES_192 test for kmctr + * returns > 0 on failure, otherwise 0 + */ +static int test_kmctr_aes_192(void) +{ + uint8_t param[24]; /* Parameter block: AES-192 key */ + uint8_t src[16] =3D {0}; /* Source data (zeros for this test) */ + uint8_t counter[16]; /* Counter value */ + uint8_t output[16]; /* Output buffer */ + unsigned long cc =3D 0; + int rc =3D 0; + + /* Setup parameter block: key only */ + memcpy(param, kmctraes192key, sizeof(kmctraes192key)); + + /* Setup counter buffer */ + memcpy(counter, kmctraes192plain, sizeof(kmctraes192plain)); + + /* En/Decrypt src with given counter, note that src is all zero */ + cpacf_kmctr(CPACF_KMCTR_AES_192, param, output, src, + sizeof(src), counter, &cc); + + /* Check for correct condition code */ + if (cc !=3D 0) { + printf("%s failed: unexpected cc=3D%lu\n", __func__, cc); + rc =3D 1; + } + + /* Compare result with expected ciphertext */ + if (memcmp(output, kmctraes192cipher, sizeof(kmctraes192cipher))) { + printf("%s failed: output mismatch\n", __func__); + rc =3D 1; + } + + return rc; +} + +/* subfunction CPACF_KMCTR_AES_256 test for kmctr + * returns > 0 on failure, otherwise 0 + */ +static int test_kmctr_aes_256(void) +{ + uint8_t param[32]; /* Parameter block: AES-256 key */ + uint8_t src[16] =3D {0}; /* Source data (zeros for this test) */ + uint8_t counter[16]; /* Counter value */ + uint8_t output[16]; /* Output buffer */ + unsigned long cc =3D 0; + int rc =3D 0; + + /* Setup parameter block: key only */ + memcpy(param, kmctraes256key, sizeof(kmctraes256key)); + + /* Setup counter buffer */ + memcpy(counter, kmctraes256plain, sizeof(kmctraes256plain)); + + /* En/Decrypt src with given counter, note that src is all zero */ + cpacf_kmctr(CPACF_KMCTR_AES_256, param, output, src, + sizeof(src), counter, &cc); + + /* Check for correct condition code */ + if (cc !=3D 0) { + printf("%s failed: unexpected cc=3D%lu\n", __func__, cc); + rc =3D 1; + } + + /* Compare result with expected ciphertext */ + if (memcmp(output, kmctraes256cipher, sizeof(kmctraes256cipher))) { + printf("%s failed: output mismatch\n", __func__); + rc =3D 1; + } + + return rc; +} + +/* subfunction CPACF_KMCTR_PAES_128 test for kmctr + * returns > 0 on failure, otherwise 0 + */ +static int test_kmctr_paes_128(void) +{ + uint8_t param[16 + 32]; /* Parameter block: protected key + wkvp */ + uint8_t src[16] =3D {0}; /* Source data (zeros for this test) */ + uint8_t counter[16]; /* Counter value */ + uint8_t output[16]; /* Output buffer */ + unsigned long cc =3D 0; + int rc =3D 0; + + /* Setup parameter block: protected key + wkvp */ + memcpy(param, kmctraes128key, sizeof(kmctraes128key)); + encrypt_clrkey(param, sizeof(kmctraes128key)); + memcpy(param + sizeof(kmctraes128key), protkey_wkvp, sizeof(protkey_wk= vp)); + + /* Setup counter buffer */ + memcpy(counter, kmctraes128plain, sizeof(kmctraes128plain)); + + /* En/Decrypt src with given counter, note that src is all zero */ + cpacf_kmctr(CPACF_KMCTR_PAES_128, param, output, src, + sizeof(src), counter, &cc); + + /* Check for correct condition code */ + if (cc !=3D 0) { + printf("%s failed: unexpected cc=3D%lu\n", __func__, cc); + rc =3D 1; + } + + /* Compare result with expected ciphertext */ + if (memcmp(output, kmctraes128cipher, sizeof(kmctraes128cipher))) { + printf("%s failed: output mismatch\n", __func__); + rc =3D 1; + } + + return rc; +} + +/* subfunction CPACF_KMCTR_PAES_192 test for kmctr + * returns > 0 on failure, otherwise 0 + */ +static int test_kmctr_paes_192(void) +{ + uint8_t param[24 + 32]; /* Parameter block: protected key + wkvp */ + uint8_t src[16] =3D {0}; /* Source data (zeros for this test) */ + uint8_t counter[16]; /* Counter value */ + uint8_t output[16]; /* Output buffer */ + unsigned long cc =3D 0; + int rc =3D 0; + + /* Setup parameter block: protected key + wkvp */ + memcpy(param, kmctraes192key, sizeof(kmctraes192key)); + encrypt_clrkey(param, sizeof(kmctraes192key)); + memcpy(param + sizeof(kmctraes192key), protkey_wkvp, sizeof(protkey_wk= vp)); + + /* Setup counter buffer */ + memcpy(counter, kmctraes192plain, sizeof(kmctraes192plain)); + + /* En/Decrypt src with given counter, note that src is all zero */ + cpacf_kmctr(CPACF_KMCTR_PAES_192, param, output, src, + sizeof(src), counter, &cc); + + /* Check for correct condition code */ + if (cc !=3D 0) { + printf("%s failed: unexpected cc=3D%lu\n", __func__, cc); + rc =3D 1; + } + + /* Compare result with expected ciphertext */ + if (memcmp(output, kmctraes192cipher, sizeof(kmctraes192cipher))) { + printf("%s failed: output mismatch\n", __func__); + rc =3D 1; + } + + return rc; +} + +/* subfunction CPACF_KMCTR_PAES_256 test for kmctr + * returns > 0 on failure, otherwise 0 + */ +static int test_kmctr_paes_256(void) +{ + uint8_t param[32 + 32]; /* Parameter block: protected key + wkvp */ + uint8_t src[16] =3D {0}; /* Source data (zeros for this test) */ + uint8_t counter[16]; /* Counter value */ + uint8_t output[16]; /* Output buffer */ + unsigned long cc =3D 0; + int rc =3D 0; + + /* Setup parameter block: protected key + wkvp */ + memcpy(param, kmctraes256key, sizeof(kmctraes256key)); + encrypt_clrkey(param, sizeof(kmctraes256key)); + memcpy(param + sizeof(kmctraes256key), protkey_wkvp, sizeof(protkey_wk= vp)); + + /* Setup counter buffer */ + memcpy(counter, kmctraes256plain, sizeof(kmctraes256plain)); + + /* En/Decrypt src with given counter, note that src is all zero */ + cpacf_kmctr(CPACF_KMCTR_PAES_256, param, output, src, + sizeof(src), counter, &cc); + + /* Check for correct condition code */ + if (cc !=3D 0) { + printf("%s failed: unexpected cc=3D%lu\n", __func__, cc); + rc =3D 1; + } + + /* Compare result with expected ciphertext */ + if (memcmp(output, kmctraes256cipher, sizeof(kmctraes256cipher))) { + printf("%s failed: output mismatch\n", __func__); + rc =3D 1; + } + + return rc; +} + +int main(void) +{ + int rc =3D 0; + + /* Test query function */ + rc +=3D test_kmctr_query(); + + /* Test AES-128 */ + rc +=3D test_kmctr_aes_128(); + + /* Test AES-192 */ + rc +=3D test_kmctr_aes_192(); + + /* Test AES-256 */ + rc +=3D test_kmctr_aes_256(); + + /* Test PAES-128 */ + rc +=3D test_kmctr_paes_128(); + + /* Test PAES-192 */ + rc +=3D test_kmctr_paes_192(); + + /* Test PAES-256 */ + rc +=3D test_kmctr_paes_256(); + + if (rc) { + printf("cpacf-kmctr: %d failures\n", rc); + } + + return rc ? EXIT_FAILURE : EXIT_SUCCESS; +} diff --git a/tests/tcg/s390x/cpacf-pcc.c b/tests/tcg/s390x/cpacf-pcc.c new file mode 100644 index 0000000000..3ef86a5b65 --- /dev/null +++ b/tests/tcg/s390x/cpacf-pcc.c @@ -0,0 +1,241 @@ +/* + * Simple test for CPACF PCC instruction + * + * This work is licensed under the terms of the GNU GPL, version 2 or late= r. + * See the COPYING file in the top-level directory. + */ + +#include +#include +#include +#include +#include "cpacf.h" + +#define QUERY_BLOCK_SIZE 16 + +/* expected pcc query block */ +static uint8_t exp_query_block[QUERY_BLOCK_SIZE] =3D { + 0x80, 0x00, 0x00, 0x00, 0x00, 0x00, 0x28, 0x28, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, +}; + +/* PCC XTS AES-128 test data */ +static const uint8_t kmaes128key[] =3D { + 0xed, 0xfd, 0xb2, 0x57, 0xcb, 0x37, 0xcd, 0xf1, + 0x82, 0xc5, 0x45, 0x5b, 0x0c, 0x0e, 0xfe, 0xbb +}; +static const uint8_t kmaes128plain[] =3D { + 0x16, 0x95, 0xfe, 0x47, 0x54, 0x21, 0xca, 0xce, + 0x35, 0x57, 0xda, 0xca, 0x01, 0xf4, 0x45, 0xff +}; +static const uint8_t kmaes128cipher[] =3D { + 0x78, 0x88, 0xbe, 0xae, 0x6e, 0x7a, 0x42, 0x63, + 0x32, 0xa7, 0xea, 0xa2, 0xf8, 0x08, 0xe6, 0x37 +}; + +/* PCC XTS AES-256 test data */ +static const uint8_t kmaes256key[] =3D { + 0xcc, 0x22, 0xda, 0x78, 0x7f, 0x37, 0x57, 0x11, + 0xc7, 0x63, 0x02, 0xbe, 0xf0, 0x97, 0x9d, 0x8e, + 0xdd, 0xf8, 0x42, 0x82, 0x9c, 0x2b, 0x99, 0xef, + 0x3d, 0xd0, 0x4e, 0x23, 0xe5, 0x4c, 0xc2, 0x4b +}; +static const uint8_t kmaes256plain[] =3D { + 0xcc, 0xc6, 0x2c, 0x6b, 0x0a, 0x09, 0xa6, 0x71, + 0xd6, 0x44, 0x56, 0x81, 0x8d, 0xb2, 0x9a, 0x4d +}; +static const uint8_t kmaes256cipher[] =3D { + 0xdf, 0x86, 0x34, 0xca, 0x02, 0xb1, 0x3a, 0x12, + 0x5b, 0x78, 0x6e, 0x1d, 0xce, 0x90, 0x65, 0x8b +}; + +/* static byte array containing the WKVP */ +static const uint8_t protkey_wkvp[32] =3D PROTKEY_WKVP; + +/* query test for pcc + * returns > 0 on failure, otherwise 0 + */ +static int test_pcc_query(void) +{ + uint8_t query_block[QUERY_BLOCK_SIZE] =3D {0}; + unsigned long cc =3D 0; + int i, rc =3D 0; + + cpacf_pcc(CPACF_PCC_QUERY, query_block, &cc); + + /* compare with expected query block */ + for (i =3D 0; i < QUERY_BLOCK_SIZE; i++) { + if (query_block[i] !=3D exp_query_block[i]) { + rc++; + break; + } + } + + if (rc) { + printf("%s failed\n", __func__); + } + + return rc; +} + +/* subfunction CPACF_PCC_XTS_AES_128 test for pcc + * returns > 0 on failure, otherwise 0 + */ +static int test_pcc_xts_aes_128(void) +{ + uint8_t param[80]; + unsigned long cc =3D 0; + int rc =3D 0; + + /* Setup parameter block: key + plaintext + zeros */ + memcpy(param, kmaes128key, sizeof(kmaes128key)); + memcpy(param + 16, kmaes128plain, sizeof(kmaes128plain)); + /* Clear Block Sequential Number, Intermediate Bit Index, and XTS Para= meter */ + memset(param + 32, 0, 48); + + /* Execute PCC to compute XTS parameter */ + cpacf_pcc(CPACF_PCC_XTS_AES_128, param, &cc); + + /* Check for correct condition code */ + if (cc !=3D 0) { + printf("%s failed: unexpected cc=3D%lu\n", __func__, cc); + rc =3D 1; + } + + /* Compare computed XTS parameter (at offset 64) with expected cipher = */ + if (memcmp(param + 64, kmaes128cipher, sizeof(kmaes128cipher))) { + printf("%s failed: XTS parameter mismatch\n", __func__); + rc =3D 1; + } + + return rc; +} + +/* subfunction CPACF_PCC_XTS_AES_256 test for pcc + * returns > 0 on failure, otherwise 0 + */ +static int test_pcc_xts_aes_256(void) +{ + uint8_t param[96]; + unsigned long cc =3D 0; + int rc =3D 0; + + /* Setup parameter block: key + plaintext + zeros */ + memcpy(param, kmaes256key, sizeof(kmaes256key)); + memcpy(param + 32, kmaes256plain, sizeof(kmaes256plain)); + /* Clear Block Sequential Number, Intermediate Bit Index, and XTS Para= meter */ + memset(param + 48, 0, 48); + + /* Execute PCC to compute XTS parameter */ + cpacf_pcc(CPACF_PCC_XTS_AES_256, param, &cc); + + /* Check for correct condition code */ + if (cc !=3D 0) { + printf("%s failed: unexpected cc=3D%lu\n", __func__, cc); + rc =3D 1; + } + + /* Compare computed XTS parameter (at offset 80) with expected cipher = */ + if (memcmp(param + 80, kmaes256cipher, sizeof(kmaes256cipher))) { + printf("%s failed: XTS parameter mismatch\n", __func__); + rc =3D 1; + } + + return rc; +} + +/* subfunction CPACF_PCC_XTS_PAES_128 test for pcc + * returns > 0 on failure, otherwise 0 + */ +static int test_pcc_xts_paes_128(void) +{ + uint8_t param[112]; + unsigned long cc =3D 0; + int rc =3D 0; + + /* Setup parameter block: protected key + wkvp + plaintext + zeros */ + memcpy(param, kmaes128key, sizeof(kmaes128key)); + encrypt_clrkey(param, sizeof(kmaes128key)); + memcpy(param + 16, protkey_wkvp, sizeof(protkey_wkvp)); + memcpy(param + 48, kmaes128plain, sizeof(kmaes128plain)); + /* Clear Block Sequential Number, Intermediate Bit Index, and XTS Para= meter */ + memset(param + 64, 0, 48); + + /* Execute PCC to compute XTS parameter */ + cpacf_pcc(CPACF_PCC_XTS_PAES_128, param, &cc); + + /* Check for correct condition code */ + if (cc !=3D 0) { + printf("%s failed: unexpected cc=3D%lu\n", __func__, cc); + rc =3D 1; + } + + /* Compare computed XTS parameter (at offset 96) with expected cipher = */ + if (memcmp(param + 96, kmaes128cipher, sizeof(kmaes128cipher))) { + printf("%s failed: XTS parameter mismatch\n", __func__); + rc =3D 1; + } + + return rc; +} + +/* subfunction CPACF_PCC_XTS_PAES_256 test for pcc + * returns > 0 on failure, otherwise 0 + */ +static int test_pcc_xts_paes_256(void) +{ + uint8_t param[128]; + unsigned long cc =3D 0; + int rc =3D 0; + + /* Setup parameter block: protected key + wkvp + plaintext + zeros */ + memcpy(param, kmaes256key, sizeof(kmaes256key)); + encrypt_clrkey(param, sizeof(kmaes256key)); + memcpy(param + 32, protkey_wkvp, sizeof(protkey_wkvp)); + memcpy(param + 64, kmaes256plain, sizeof(kmaes256plain)); + /* Clear Block Sequential Number, Intermediate Bit Index, and XTS Para= meter */ + memset(param + 80, 0, 48); + + /* Execute PCC to compute XTS parameter */ + cpacf_pcc(CPACF_PCC_XTS_PAES_256, param, &cc); + + /* Check for correct condition code */ + if (cc !=3D 0) { + printf("%s failed: unexpected cc=3D%lu\n", __func__, cc); + rc =3D 1; + } + + /* Compare computed XTS parameter (at offset 112) with expected cipher= */ + if (memcmp(param + 112, kmaes256cipher, sizeof(kmaes256cipher))) { + printf("%s failed: XTS parameter mismatch\n", __func__); + rc =3D 1; + } + + return rc; +} + +int main(void) +{ + int rc =3D 0; + + /* Test query function */ + rc +=3D test_pcc_query(); + + /* Test XTS-AES-128 */ + rc +=3D test_pcc_xts_aes_128(); + + /* Test XTS-AES-256 */ + rc +=3D test_pcc_xts_aes_256(); + + /* Test XTS-PAES-128 */ + rc +=3D test_pcc_xts_paes_128(); + + /* Test XTS-PAES-256 */ + rc +=3D test_pcc_xts_paes_256(); + + if (rc) { + printf("cpacf-pcc: %d failures\n", rc); + } + + return rc ? EXIT_FAILURE : EXIT_SUCCESS; +} diff --git a/tests/tcg/s390x/cpacf-prno.c b/tests/tcg/s390x/cpacf-prno.c new file mode 100644 index 0000000000..133cd2e064 --- /dev/null +++ b/tests/tcg/s390x/cpacf-prno.c @@ -0,0 +1,130 @@ +/* + * Simple test for CPACF PRNO instruction + * + * This work is licensed under the terms of the GNU GPL, version 2 or late= r. + * See the COPYING file in the top-level directory. + */ + +#include +#include +#include +#include +#include +#include "cpacf.h" + +#define QUERY_BLOCK_SIZE 16 +#define TRNG_OUTPUT_SIZE 32 + +/* expected prno query block */ +static uint8_t exp_query_block[QUERY_BLOCK_SIZE] =3D { + 0x80, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x20, 0x00, +}; + +/* query test for prno + * returns > 0 on failure, otherwise 0 + */ +static int test_prno_query(void) +{ + uint8_t query_block[QUERY_BLOCK_SIZE] =3D {0}; + unsigned long cc =3D 0; + int i, rc =3D 0; + + cpacf_prno(CPACF_PRNO_QUERY, query_block, NULL, 0, NULL, 0, &cc); + + /* compare with expected query block */ + for (i =3D 0; i < QUERY_BLOCK_SIZE; i++) { + if (query_block[i] !=3D exp_query_block[i]) { + rc++; + break; + } + } + + if (rc) { + printf("%s failed\n", __func__); + } + + return rc; +} + +/* check for buffer is all zero */ +static bool is_all_zeros(const uint8_t *buf, size_t len) +{ + size_t i; + + for (i =3D 0; i < len; i++) { + if (buf[i] !=3D 0) { + return false; + } + } + + return true; +} + +/* subfunction CPACF_PRNO_TRNG test for prno + * returns > 0 on failure, otherwise 0 + */ +static int test_prno_trng(void) +{ + uint8_t output1[TRNG_OUTPUT_SIZE]; + uint8_t output2[TRNG_OUTPUT_SIZE]; + unsigned long cc =3D 0; + int rc =3D 0; + + /* Initialize outputs to detect if they get filled */ + memset(output1, 0, sizeof(output1)); + memset(output2, 0, sizeof(output2)); + + /* First TRNG call */ + cpacf_prno(CPACF_PRNO_TRNG, NULL, output1, sizeof(output1), NULL, 0, &= cc); + + /* Check for correct condition code */ + if (cc !=3D 0) { + printf("%s failed: unexpected cc=3D%lu on first call\n", __func__,= cc); + rc =3D 1; + } + /* Verify output is not all zeros */ + if (is_all_zeros(output1, TRNG_OUTPUT_SIZE)) { + printf("%s failed: output1 is all zeros\n", __func__); + rc =3D 1; + } + + /* Second TRNG call */ + cpacf_prno(CPACF_PRNO_TRNG, NULL, output2, sizeof(output2), NULL, 0, &= cc); + + /* Check for correct condition code */ + if (cc !=3D 0) { + printf("%s failed: unexpected cc=3D%lu on second call\n", __func__= , cc); + rc =3D 1; + } + /* Verify output is not all zeros */ + if (is_all_zeros(output2, TRNG_OUTPUT_SIZE)) { + printf("%s failed: output2 is all zeros\n", __func__); + rc =3D 1; + } + + /* Verify the two outputs are different */ + if (memcmp(output1, output2, TRNG_OUTPUT_SIZE) =3D=3D 0) { + printf("%s failed: two TRNG calls produced same output\n", __func_= _); + rc =3D 1; + } + + return rc; +} + +int main(void) +{ + int rc =3D 0; + + /* Test query function */ + rc +=3D test_prno_query(); + + /* Test TRNG */ + rc +=3D test_prno_trng(); + + if (rc) { + printf("cpacf-prno: %d failures\n", rc); + } + + return rc ? EXIT_FAILURE : EXIT_SUCCESS; +} diff --git a/tests/tcg/s390x/cpacf.h b/tests/tcg/s390x/cpacf.h new file mode 100644 index 0000000000..febb976e8c --- /dev/null +++ b/tests/tcg/s390x/cpacf.h @@ -0,0 +1,570 @@ +/* + * Defines and inline functions around testing CPACF instructions + * + * This work is licensed under the terms of the GNU GPL, version 2 or late= r. + * See the COPYING file in the top-level directory. + */ + +#ifndef _S390_CPACF_H_ +#define _S390_CPACF_H_ + +#define CPACF_H_INCLUDE_FOR_TESTS +#include "../../../target/s390x/tcg/cpacf.h" + +union register_pair { + unsigned __int128 pair; + struct { + unsigned long even; + unsigned long odd; + }; +}; + +/* + * Instruction opcodes for the CPACF instructions + */ +#define CPACF_KMAC 0xb91e /* MSA */ +#define CPACF_KM 0xb92e /* MSA */ +#define CPACF_KMC 0xb92f /* MSA */ +#define CPACF_KIMD 0xb93e /* MSA */ +#define CPACF_KLMD 0xb93f /* MSA */ +#define CPACF_PCKMO 0xb928 /* MSA3 */ +#define CPACF_KMF 0xb92a /* MSA4 */ +#define CPACF_KMO 0xb92b /* MSA4 */ +#define CPACF_PCC 0xb92c /* MSA4 */ +#define CPACF_KMCTR 0xb92d /* MSA4 */ +#define CPACF_PRNO 0xb93c /* MSA5 */ +#define CPACF_KMA 0xb929 /* MSA8 */ +#define CPACF_KDSA 0xb93a /* MSA9 */ + +/* + * 'encrypt' the clear key value into a protected key + * by xor-ing the protkey_xor_pattern onto it. + */ +static inline void encrypt_clrkey(uint8_t *key, int keysize) +{ + const uint8_t protkey_xor_pattern[32] =3D PROTKEY_XOR_PATTERN; + + for (int i =3D 0; i < keysize; i++) { + key[i] ^=3D protkey_xor_pattern[i]; + } +} + +/** + * cpacf_km() - executes the KM instruction + * @func: the function code passed to KM; see CPACF_KM_xxx defines + * @param: address of parameter block; see POP for details on each func + * @dest: address of destination memory area + * @src: address of source memory area + * @src_len: length of src operand in bytes + * + * Returns 0 for the query func, number of processed bytes for + * encryption/decryption funcs + */ +static inline int cpacf_km(unsigned long func, void *param, + uint8_t *dest, const uint8_t *src, long src_len, + unsigned long *cc) +{ + union register_pair d, s; + + *cc =3D 0; + d.even =3D (unsigned long)dest; + s.even =3D (unsigned long)src; + s.odd =3D (unsigned long)src_len; + asm volatile( + " lgr 0,%[fc]\n" + " lgr 1,%[pba]\n" + "0: .insn rre,%[opc] << 16,%[dst],%[src]\n" + " brc 1,0b\n" /* handle partial completion */ + " brc 8,2f\n" + " brc 4,1f\n" + " agsi %[__cc],1\n" + "1: agsi %[__cc],1\n" + "2:\n" + : [src] "+&d" (s.pair), [dst] "+&d" (d.pair), [__cc] "+Q"= (*cc) + : [fc] "d" (func), [pba] "d" ((unsigned long)param), + [opc] "i" (CPACF_KM) + : "cc", "memory", "0", "1"); + + return src_len - s.odd; +} + +/** + * cpacf_kmc() - executes the KMC instruction + * @func: the function code passed to KM; see CPACF_KMC_xxx defines + * @param: address of parameter block; see POP for details on each func + * @dest: address of destination memory area + * @src: address of source memory area + * @src_len: length of src operand in bytes + * + * Returns 0 for the query func, number of processed bytes for + * encryption/decryption funcs + */ +static inline int cpacf_kmc(unsigned long func, void *param, + uint8_t *dest, const uint8_t *src, long src_le= n, + unsigned long *cc) +{ + union register_pair d, s; + + *cc =3D 0; + d.even =3D (unsigned long)dest; + s.even =3D (unsigned long)src; + s.odd =3D (unsigned long)src_len; + asm volatile( + " lgr 0,%[fc]\n" + " lgr 1,%[pba]\n" + "0: .insn rre,%[opc] << 16,%[dst],%[src]\n" + " brc 1,0b\n" /* handle partial completion */ + " brc 8,2f\n" + " brc 4,1f\n" + " agsi %[__cc],1\n" + "1: agsi %[__cc],1\n" + "2:\n" + : [src] "+&d" (s.pair), [dst] "+&d" (d.pair), [__cc] "+Q"= (*cc) + : [fc] "d" (func), [pba] "d" ((unsigned long)param), + [opc] "i" (CPACF_KMC) + : "cc", "memory", "0", "1"); + + return src_len - s.odd; +} + +/** + * cpacf_kimd() - executes the KIMD instruction + * @func: the function code passed to KM; see CPACF_KIMD_xxx defines + * @param: address of parameter block; see POP for details on each func + * @src: address of source memory area + * @src_len: length of src operand in bytes + */ +static inline void cpacf_kimd(unsigned long func, void *param, + const uint8_t *src, long src_len, + unsigned long *cc) +{ + union register_pair s; + + *cc =3D 0; + s.even =3D (unsigned long)src; + s.odd =3D (unsigned long)src_len; + asm volatile( + " lgr 0,%[fc]\n" + " lgr 1,%[pba]\n" + "0: .insn rre,%[opc] << 16,0,%[src]\n" + " brc 1,0b\n" /* handle partial completion */ + " brc 8,2f\n" + " brc 4,1f\n" + " agsi %[__cc],1\n" + "1: agsi %[__cc],1\n" + "2:\n" + : [src] "+&d" (s.pair), [__cc] "+Q" (*cc) + : [fc] "d" (func), [pba] "d" ((unsigned long)(param)), + [opc] "i" (CPACF_KIMD) + : "cc", "memory", "0", "1"); +} + +/** + * cpacf_klmd() - executes the KLMD instruction + * @func: the function code passed to KM; see CPACF_KLMD_xxx defines + * @param: address of parameter block; see POP for details on each func + * @src: address of source memory area + * @src_len: length of src operand in bytes + */ +static inline void cpacf_klmd(unsigned long func, void *param, + const uint8_t *src, long src_len, + uint8_t *dest, long dest_len, + unsigned long *cc) +{ + union register_pair s,d; + + *cc =3D 0; + s.even =3D (unsigned long)src; + s.odd =3D (unsigned long)src_len; + d.even =3D (unsigned long)dest; + d.odd =3D (unsigned long)dest_len; + asm volatile( + " lgr 0,%[fc]\n" + " lgr 1,%[pba]\n" + "0: .insn rre,%[opc] << 16,%[dst],%[src]\n" + " brc 1,0b\n" /* handle partial completion */ + " brc 8,2f\n" + " brc 4,1f\n" + " agsi %[__cc],1\n" + "1: agsi %[__cc],1\n" + "2:\n" + : [src] "+&d" (s.pair), [dst] "+&d" (d.pair), [__cc] "+Q"= (*cc) + : [fc] "d" (func), [pba] "d" ((unsigned long)param), + [opc] "i" (CPACF_KLMD) + : "cc", "memory", "0", "1"); +} + +/** + * cpacf_kmac() - executes the KMAC instruction + * @func: the function code passed to KM; see CPACF_KMAC_xxx defines + * @param: address of parameter block; see POP for details on each func + * @src: address of source memory area + * @src_len: length of src operand in bytes + * + * Returns 0 for the query func, number of processed bytes for digest funcs + */ +static inline int cpacf_kmac(unsigned long func, void *param, + const uint8_t *src, long src_len, + unsigned long *cc) +{ + union register_pair s; + + *cc =3D 0; + s.even =3D (unsigned long)src; + s.odd =3D (unsigned long)src_len; + asm volatile( + " lgr 0,%[fc]\n" + " lgr 1,%[pba]\n" + "0: .insn rre,%[opc] << 16,0,%[src]\n" + " brc 1,0b\n" /* handle partial completion */ + " brc 8,2f\n" + " brc 4,1f\n" + " agsi %[__cc],1\n" + "1: agsi %[__cc],1\n" + "2:\n" + : [src] "+&d" (s.pair), [__cc] "+Q" (*cc) + : [fc] "d" (func), [pba] "d" ((unsigned long)param), + [opc] "i" (CPACF_KMAC) + : "cc", "memory", "0", "1"); + + return src_len - s.odd; +} + +static inline int cpacf_kmac_x(unsigned long *func, void *param, + const uint8_t *src, long src_len, + unsigned long *cc) +{ + union register_pair s; + unsigned long fc =3D *func; + + *cc =3D 0; + s.even =3D (unsigned long)src; + s.odd =3D (unsigned long)src_len; + asm volatile( + " lgr 0,%[fc]\n" + " lgr 1,%[pba]\n" + "0: .insn rre,%[opc] << 16,0,%[src]\n" + " brc 1,0b\n" /* handle partial completion */ + " brc 8,2f\n" + " brc 4,1f\n" + " agsi %[__cc],1\n" + "1: agsi %[__cc],1\n" + "2: lgr %[fc],0\n" + : [fc] "+d" (fc), [src] "+&d" (s.pair), [__cc] "+Q" (*cc) + : [pba] "d" ((unsigned long)param), + [opc] "i" (CPACF_KMAC) + : "cc", "memory", "0", "1"); + + *func =3D fc; + + return src_len - s.odd; +} + +/** + * cpacf_kmctr() - executes the KMCTR instruction + * @func: the function code passed to KMCTR; see CPACF_KMCTR_xxx defines + * @param: address of parameter block; see POP for details on each func + * @dest: address of destination memory area + * @src: address of source memory area + * @src_len: length of src operand in bytes + * @counter: address of counter value + * + * Returns 0 for the query func, number of processed bytes for + * encryption/decryption funcs + */ +static inline int cpacf_kmctr(unsigned long func, void *param, uint8_t *de= st, + const uint8_t *src, long src_len, uint8_t *c= ounter, + unsigned long *cc) +{ + union register_pair d, s, c; + + *cc =3D 0; + d.even =3D (unsigned long)dest; + s.even =3D (unsigned long)src; + s.odd =3D (unsigned long)src_len; + c.even =3D (unsigned long)counter; + asm volatile( + " lgr 0,%[fc]\n" + " lgr 1,%[pba]\n" + "0: .insn rrf,%[opc] << 16,%[dst],%[src],%[ctr],0\n" + " brc 1,0b\n" /* handle partial completion */ + " brc 8,2f\n" + " brc 4,1f\n" + " agsi %[__cc],1\n" + "1: agsi %[__cc],1\n" + "2:\n" + : [src] "+&d" (s.pair), [dst] "+&d" (d.pair), + [ctr] "+&d" (c.pair), [__cc] "+Q" (*cc) + : [fc] "d" (func), [pba] "d" ((unsigned long)param), + [opc] "i" (CPACF_KMCTR) + : "cc", "memory", "0", "1"); + + return src_len - s.odd; +} + +/** + * cpacf_prno() - executes the PRNO instruction + * @func: the function code passed to PRNO; see CPACF_PRNO_xxx defines + * @param: address of parameter block; see POP for details on each func + * @dest: address of destination memory area + * @dest_len: size of destination memory area in bytes + * @seed: address of seed data + * @seed_len: size of seed data in bytes + */ +static inline void cpacf_prno(unsigned long func, void *param, + uint8_t *dest, unsigned long dest_len, + const uint8_t *seed, unsigned long seed_len, + unsigned long *cc) +{ + union register_pair d, s; + + *cc =3D 0; + d.even =3D (unsigned long)dest; + d.odd =3D (unsigned long)dest_len; + s.even =3D (unsigned long)seed; + s.odd =3D (unsigned long)seed_len; + asm volatile ( + " lgr 0,%[fc]\n" + " lgr 1,%[pba]\n" + "0: .insn rre,%[opc] << 16,%[dst],%[seed]\n" + " brc 1,0b\n" /* handle partial completion */ + " brc 8,2f\n" + " brc 4,1f\n" + " agsi %[__cc],1\n" + "1: agsi %[__cc],1\n" + "2:\n" + : [dst] "+&d" (d.pair), [__cc] "+Q" (*cc) + : [fc] "d" (func), [pba] "d" ((unsigned long)param), + [seed] "d" (s.pair), [opc] "i" (CPACF_PRNO) + : "cc", "memory", "0", "1"); +} + +/** + * cpacf_trng() - executes the TRNG subfunction of the PRNO instruction + * @ucbuf: buffer for unconditioned data + * @ucbuf_len: amount of unconditioned data to fetch in bytes + * @cbuf: buffer for conditioned data + * @cbuf_len: amount of conditioned data to fetch in bytes + */ +static inline void cpacf_trng(uint8_t *ucbuf, unsigned long ucbuf_len, + uint8_t *cbuf, unsigned long cbuf_len, + unsigned long *cc) +{ + union register_pair u, c; + + *cc =3D 0; + u.even =3D (unsigned long)ucbuf; + u.odd =3D (unsigned long)ucbuf_len; + c.even =3D (unsigned long)cbuf; + c.odd =3D (unsigned long)cbuf_len; + asm volatile ( + " lghi 0,%[fc]\n" + "0: .insn rre,%[opc] << 16,%[ucbuf],%[cbuf]\n" + " brc 1,0b\n" /* handle partial completion */ + " brc 8,2f\n" + " brc 4,1f\n" + " agsi %[__cc],1\n" + "1: agsi %[__cc],1\n" + "2:\n" + : [ucbuf] "+&d" (u.pair), [cbuf] "+&d" (c.pair), [__cc] = "+Q" (*cc) + : [fc] "K" (CPACF_PRNO_TRNG), [opc] "i" (CPACF_PRNO) + : "cc", "memory", "0"); +} + +/** + * cpacf_pcc() - executes the PCC instruction + * @func: the function code passed to PCC; see CPACF_KM_xxx defines + * @param: address of parameter block; see POP for details on each func + */ +static inline void cpacf_pcc(unsigned long func, void *param, unsigned lon= g *cc) +{ + *cc =3D 0; + asm volatile( + " lgr 0,%[fc]\n" + " lgr 1,%[pba]\n" + "0: .insn rre,%[opc] << 16,0,0\n" /* PCC opcode */ + " brc 1,0b\n" /* handle partial completion */ + " brc 8,2f\n" + " brc 4,1f\n" + " agsi %[__cc],1\n" + "1: agsi %[__cc],1\n" + "2:\n" + : [__cc] "+Q" (*cc) + : [fc] "d" (func), [pba] "d" ((unsigned long)param), + [opc] "i" (CPACF_PCC) + : "cc", "memory", "0", "1"); +} + +/** + * cpacf_pckmo() - executes the PCKMO instruction + * @func: the function code passed to PCKMO; see CPACF_PCKMO_xxx defines + * @param: address of parameter block; see POP for details on each func + */ +static inline void cpacf_pckmo(long func, void *param) +{ + asm volatile( + " lgr 0,%[fc]\n" + " lgr 1,%[pba]\n" + " .insn rre,%[opc] << 16,0,0\n" /* PCKMO opcode */ + : + : [fc] "d" (func), [pba] "d" ((unsigned long)param), + [opc] "i" (CPACF_PCKMO) + : "cc", "memory", "0", "1"); +} + +/** + * cpacf_kma() - executes the KMA instruction + * @func: the function code passed to KMA; see CPACF_KMA_xxx defines + * @param: address of parameter block; see POP for details on each func + * @dest: address of destination memory area + * @src: address of source memory area + * @src_len: length of src operand in bytes + * @aad: address of additional authenticated data memory area + * @aad_len: length of aad operand in bytes + */ +static inline void cpacf_kma(unsigned long func, void *param, uint8_t *des= t, + const uint8_t *src, unsigned long src_len, + const uint8_t *aad, unsigned long aad_len, + unsigned long *cc) +{ + union register_pair d, s, a; + + *cc =3D 0; + d.even =3D (unsigned long)dest; + s.even =3D (unsigned long)src; + s.odd =3D (unsigned long)src_len; + a.even =3D (unsigned long)aad; + a.odd =3D (unsigned long)aad_len; + asm volatile( + " lgr 0,%[fc]\n" + " lgr 1,%[pba]\n" + "0: .insn rrf,%[opc] << 16,%[dst],%[src],%[aad],0\n" + " brc 1,0b\n" /* handle partial completion */ + " brc 8,2f\n" + " brc 4,1f\n" + " agsi %[__cc],1\n" + "1: agsi %[__cc],1\n" + "2:\n" + : [dst] "+&d" (d.pair), [src] "+&d" (s.pair), + [aad] "+&d" (a.pair), [__cc] "+Q" (*cc) + : [fc] "d" (func), [pba] "d" ((unsigned long)param), + [opc] "i" (CPACF_KMA) + : "cc", "memory", "0", "1"); +} + +/** + * cpacf_kmf() - executes the KMF instruction + * @func: the function code passed to KMF; see CPACF_KMF_xxx defines + * @param: address of parameter block; see POP for details on each func + * @dest: address of destination memory area + * @src: address of source memory area + * @src_len: length of src operand in bytes + * + * Returns 0 for the query func, number of processed bytes for + * encryption/decryption funcs + */ +static inline int cpacf_kmf(unsigned long func, void *param, + uint8_t *dest, const uint8_t *src, long src_le= n, + unsigned long *cc) +{ + union register_pair d, s; + + *cc =3D 0; + d.even =3D (unsigned long)dest; + s.even =3D (unsigned long)src; + s.odd =3D (unsigned long)src_len; + asm volatile( + " lgr 0,%[fc]\n" + " lgr 1,%[pba]\n" + "0: .insn rre,%[opc] << 16,%[dst],%[src]\n" + " brc 1,0b\n" /* handle partial completion */ + " brc 8,2f\n" + " brc 4,1f\n" + " agsi %[__cc],1\n" + "1: agsi %[__cc],1\n" + "2:\n" + : [src] "+&d" (s.pair), [dst] "+&d" (d.pair), [__cc] "+Q"= (*cc) + : [fc] "d" (func), [pba] "d" ((unsigned long)param), + [opc] "i" (CPACF_KMF) + : "cc", "memory", "0", "1"); + + return src_len - s.odd; +} + +/** + * cpacf_kmo() - executes the KMO instruction + * @func: the function code passed to KMO; see CPACF_KMO_xxx defines + * @param: address of parameter block; see POP for details on each func + * @dest: address of destination memory area + * @src: address of source memory area + * @src_len: length of src operand in bytes + * + * Returns 0 for the query func, number of processed bytes for + * encryption/decryption funcs + */ +static inline int cpacf_kmo(unsigned long func, void *param, + uint8_t *dest, const uint8_t *src, long src_le= n, + unsigned long *cc) +{ + union register_pair d, s; + + *cc =3D 0; + d.even =3D (unsigned long)dest; + s.even =3D (unsigned long)src; + s.odd =3D (unsigned long)src_len; + asm volatile( + " lgr 0,%[fc]\n" + " lgr 1,%[pba]\n" + "0: .insn rre,%[opc] << 16,%[dst],%[src]\n" + " brc 1,0b\n" /* handle partial completion */ + " brc 8,2f\n" + " brc 4,1f\n" + " agsi %[__cc],1\n" + "1: agsi %[__cc],1\n" + "2:\n" + : [src] "+&d" (s.pair), [dst] "+&d" (d.pair), [__cc] "+Q"= (*cc) + : [fc] "d" (func), [pba] "d" ((unsigned long)param), + [opc] "i" (CPACF_KMO) + : "cc", "memory", "0", "1"); + + return src_len - s.odd; +} + +/** + * cpacf_kdsa() - executes the KDSA instruction + * @func: the function code passed to KDSA; see CPACF_KDSA_xxx defines + * @param: address of parameter block; see POP for details on each func + * @src: address of source memory area + * @src_len: length of src operand in bytes + * + * Returns 0 for the query func, otherwise the condition code is checked + * and 0 returned on cc 0, otherwise a value !=3D 0 to indicate failure. + */ +static inline int cpacf_kdsa(unsigned long func, void *param, + const uint8_t *src, long src_len, + unsigned long *cc) +{ + union register_pair s; + + *cc =3D 0; + s.even =3D (unsigned long)src; + s.odd =3D (unsigned long)src_len; + asm volatile( + " lgr 0,%[fc]\n" + " lgr 1,%[pba]\n" + "0: .insn rre,%[opc] << 16,0,%[src]\n" + " brc 1,0b\n" /* handle partial completion */ + " brc 8,2f\n" + " brc 4,1f\n" + " agsi %[__cc],1\n" + "1: agsi %[__cc],1\n" + "2:\n" + : [src] "+&d" (s.pair), [__cc] "+Q" (*cc) + : [fc] "d" (func), [pba] "d" ((unsigned long)param), + [opc] "i" (CPACF_KDSA) + : "cc", "memory", "0", "1"); + + return (int)(*cc !=3D 0); +} + +#endif /* _S390_CPACF_H_ */ --=20 2.43.0