On 8/24/26 4:31 AM, Harald Freudenberger wrote:
> This patch series extends the s390 qemu CPACF support to be able to
> run a subset of the CPACF instruction cross platform. There have been
> requests on the kernel crypto mailing list about a way to test
> s390 specific crypto implementations. For example a way to test
> s390 CPACF exploitation code like the s390_aes.ko kernel module.
>
> So here now is a set of patches verified on x86 and s390 which
> over (slow but working) support for a subset of the subfunctions of
> some of the CPACF instructions.
>
> Test: There are some very basic tests included with this patch series
> suitable for some CI run. Better test coverage can be done by running
> a full blown Linux and use for example the in-kernel crypto modules.
> The 'usual' in-kernel crpyto modules will be automatically loaded
> which run a bunch of test cases. So there is now support for these
> kernel modules:
> * sha256_s390x (autoloaded, sha256)
> * sha512_s390x (autoloaded, sha512)
> * aes_s390x (autoloaded, clear key aes ecb, cbc, ctr, xts)
> * pkey_pckmo (autoloaded, derive AES protected key from clear key)
> * paes_s390x (not autoloaded, protected key aes ecb, cbc, ctr, xts)
> All these modules run selftests if configured by the kernel (which is
> enabled by default). Failures are reported via syslog. Additionally
> the aes testcases from libica can be run either inside such an qemu
> environment or with a static build executed with the qemu tcg
> application qemu-s390x --cpu max <static-build-libica-test>.
Applied for 11.2. Thank you!
>
> Changelog:
> v1: Initial version with
> - Related code restructured
> - Support KIMD SHA512 and thus SHA256
> - Support KMC AES-128, AES-192 and AES-256 and thus have basic AES
> support (ECB mode) enabled.
> - Support PCC Compute-XTS-Parameter-AES-128 and
> Compute-XTS-Parameter-AES-256 but only for block sequence number
> 0. This is a requirement for the next step:
> - Support KM XTS-AES-128 and KM XTS-AES-256. Together with the
> minimal PCC support this enables AES-XTS CPACF acceleration.
> v2: - Basic PCKMO support to be able to 'derive' an AES protected key
> from clear key. See header details.
> - Support protected key AES-ECB.
> - Support protected key AES-CBC.
> - Minimal protected key AES-XTS support for CPACF PCC.
> - Support protected key AES-XTS.
> - Support AES-CTR.
> - Support protected key AES-CTR.
> v3: - Reordered patches as suggested by Finn.
> - One small bug fix in CPACF_aes.c related to address translation.
> v4: - Rename of the parameters based on feedback from Janosch to
> make clear these are registers or ptrs to registers.
> Added Tested by from Holger. Fixed typo "face" -> "fake".
> v5: - Add documentation file docs/system/s390x/cpacf.rst which
> describes the state of the CPACF instructions and which
> functions are covered when this series is applied.
> First version sent to public mailing list qemu-s390x.
> v6: - Rebase/rework to build on current qemu head.
> - Add docs/system/s390x/cpacf.rst to target-s390x.rst
> - New file crypto/aes-helpers.c with some simple
> functions to support AES modes CBC, CTR and XTS.
> - Slight rewrite of the s390x CPACF implementations to
> use these generic AES mode implementations.
> v7: - Update on docs/system/s390x/cpacf.rst to mention
> the zArchicteture Principles of Operation document
> which describes all these CPACF instructions.
> v8: - Add a fix which deals with incorrect address handling
> in the sha512 implementation related to fetch and push
> data from/to memory.
> - Slight rework around the capcf function implementation and
> exception generation.
> - Added some more details to the new cpacf.rst file.
> - Fixed some typos and added some suggestions from Finn.
> - Fixed cc handling on return of PCKMO (must not update cc).
> Missing: simple test cases to verify that the implemented and not
> implemented cpacf functions and subfunctions work as expected. But
> see the statement about tests at the header.
> v9: - Add simple tests for all the implemented CPACF instructions but
> pckmo (which is a privileged instruction).
> - Reworked the Fix for wrong address to call the wrap function
> inline; rephrased commit header.
> - Improve the header file cpacf.h to hold defines for all the
> cpacf instruction functions and use them in the code.
> - one new commit comprising the base protected key support with
> exposing the xor pattern and wkvp and en/decrypt key functions
> via cpacf.h. So the testcases can use this header file.
> - one new commit which reworks the fetch memory and store memory
> from and to guest (suggested by Ilya Leoshkevich).
> v10: - Fixed v9 patch 3 (cpacf_sha512.c was missing)
> Please note that patch #10 "target/s390x: Base support for cpacf
> protected keys" produces a build warning ("unused function"). As
> by default the qemu build has warnings=errors enabled, this one
> patch does not build on it's own. If this is not acceptable, the
> hunk introducing the two functions may be moved to the next
> commit; another solution would be to merge with patch #11.
> v11: Fixed nearly all checkpatch findings - only the warnings about
> Maintainers may need update is still there.
> v12: - Very first patch is integrated in master and thus removed from
> this series.
> - New header file include/crypto/aes-headers.h as suggested by
> Daniel. Moved the patch which introduces the aes helpers before
> the actual AES cpacf implementations and reworked all the code
> to use these helpers.
> - Merged together "Base support for cpacf protected keys" and
> "Support pckmo encrypt AES subfunctions" to fix the broken
> build caused by unused functions.
> - Merged the changes from patch "Improve fetch and store mem from
> and to guest" directly into the code where it is introduced.
> v13: - reworked the helper functions to copy memory from and to
> guest. These are now inline functions located in
> target/s390x/tcg/crypto_helper.h and have been renamed and
> extended for u32 and u64 as well. Also the both sha
> implementations have been reworked to use these helper
> functions. See patch #4 for details.
> - fixed the wrong list of parameters docu in patch #5
> - added some Reviewed-by tags.
> - reworked the testcases to run (more or less) on real s390
> hardware. However this does not and can not work with protected
> keys.
> - rebased to current master head.
> v14: - fixed one wrong constant in target/s390x/tcg/cpacf.h
> - added 1 patch (patch #1) which fixes the missing privileged
> flag with the PCKMO instruction.
> - added a simple testcase for the PCKMO instruction (see
> tests/s390x/tcg/cpacf-pckmo.c for details).
> v15: - rebased to current master
> - new patch reworking the addressing mode check in the both
> sha256 and sha512 implementations. Also added early bail out.
> - In a similar way rework the checking for addressing mode in
> cpacf_aes.c (comes in with each algo implementation).
> - bail out early on length zero for the cpacf aes algs.
> - As suggested by Ilya splitted the cpacf.h into two header
> files cpacf-arch.h and cpacf.h.
> v16: - Fixed some places with wrong indentation.
> - Fix regression introduced with v15: sha256 and sha512 must bail
> out for KIMD only, but not for KLMD.
> - AI screening: PCKMO still clobbered CC. So fixed this.
> - AI screening: KDSA lacked the r2 even/nonzero check - fixed.
> - Updated cpacf docu to clearly state for KMA, KMF, KMO and KDSA
> which exception happens on which condition.
>
> Harald Freudenberger (20):
> target/s390x: Fix missing privileged flag at PCKMO instruction
> target/s390x: Rework s390 cpacf implementations
> target/s390x: Move cpacf sha512 code into a new file
> target/s390x: Support cpacf sha256
> target/s390x: Add helper functions for copy memory to and from guest
> target/s390x: Adjust addressing mode checks for sha512 and sha256
> crypto: Add aes-helpers file to support some AES modes
> target/s390x: Support AES ECB for cpacf km instruction
> target/s390x: Support AES CBC for cpacf kmc instruction
> target/s390x: Support AES CTR for cpacf kmctr instruction
> target/s390x: Minimal AES XTS support for cpacf pcc instruction
> target/s390x: Support AES XTS for cpacf km instruction
> target/s390x: Base support for cpacf protected keys and pckmo
> target/s390x: Support protected key AES ECB for cpacf km instruction
> target/s390x: Support protected key AES CBC for cpacf kmc instruction
> target/s390x: Support protected key AES CTR for cpacf kmctr
> instruction
> target/s390x: Minimal protected key AES XTS support for cpacf pcc
> instruction
> target/s390x: Support protected key AES XTS for cpacf km instruction
> docs/s390: Document CPACF instructions support
> tests/tcg/s390x: Add tests for CPACF instructions
>
> crypto/aes-helpers.c | 106 ++++
> crypto/meson.build | 1 +
> docs/system/s390x/cpacf.rst | 143 +++++
> docs/system/target-s390x.rst | 1 +
> include/crypto/aes-helpers.h | 109 ++++
> target/s390x/gen-features.c | 31 +
> target/s390x/tcg/cpacf-arch.h | 251 ++++++++
> target/s390x/tcg/cpacf.h | 63 ++
> target/s390x/tcg/cpacf_aes.c | 986 +++++++++++++++++++++++++++++++
> target/s390x/tcg/cpacf_sha256.c | 197 ++++++
> target/s390x/tcg/cpacf_sha512.c | 211 +++++++
> target/s390x/tcg/crypto_helper.c | 445 +++++++-------
> target/s390x/tcg/crypto_helper.h | 100 ++++
> target/s390x/tcg/insn-data.h.inc | 3 +-
> target/s390x/tcg/meson.build | 3 +
> target/s390x/tcg/translate.c | 16 +-
> tests/tcg/s390x/Makefile.target | 10 +
> tests/tcg/s390x/cpacf-kdsa.c | 58 ++
> tests/tcg/s390x/cpacf-kimd.c | 166 ++++++
> tests/tcg/s390x/cpacf-klmd.c | 206 +++++++
> tests/tcg/s390x/cpacf-km.c | 590 ++++++++++++++++++
> tests/tcg/s390x/cpacf-kmac.c | 58 ++
> tests/tcg/s390x/cpacf-kmc.c | 351 +++++++++++
> tests/tcg/s390x/cpacf-kmctr.c | 360 +++++++++++
> tests/tcg/s390x/cpacf-pcc.c | 245 ++++++++
> tests/tcg/s390x/cpacf-pckmo.c | 45 ++
> tests/tcg/s390x/cpacf-prno.c | 131 ++++
> tests/tcg/s390x/cpacf.h | 570 ++++++++++++++++++
> 28 files changed, 5230 insertions(+), 226 deletions(-)
> create mode 100644 crypto/aes-helpers.c
> create mode 100644 docs/system/s390x/cpacf.rst
> create mode 100644 include/crypto/aes-helpers.h
> create mode 100644 target/s390x/tcg/cpacf-arch.h
> create mode 100644 target/s390x/tcg/cpacf.h
> create mode 100644 target/s390x/tcg/cpacf_aes.c
> create mode 100644 target/s390x/tcg/cpacf_sha256.c
> create mode 100644 target/s390x/tcg/cpacf_sha512.c
> create mode 100644 target/s390x/tcg/crypto_helper.h
> create mode 100644 tests/tcg/s390x/cpacf-kdsa.c
> create mode 100644 tests/tcg/s390x/cpacf-kimd.c
> create mode 100644 tests/tcg/s390x/cpacf-klmd.c
> create mode 100644 tests/tcg/s390x/cpacf-km.c
> create mode 100644 tests/tcg/s390x/cpacf-kmac.c
> create mode 100644 tests/tcg/s390x/cpacf-kmc.c
> create mode 100644 tests/tcg/s390x/cpacf-kmctr.c
> create mode 100644 tests/tcg/s390x/cpacf-pcc.c
> create mode 100644 tests/tcg/s390x/cpacf-pckmo.c
> create mode 100644 tests/tcg/s390x/cpacf-prno.c
> create mode 100644 tests/tcg/s390x/cpacf.h
>
>
> base-commit: 9696bf5dc5a5bf0b4a9d05b6cdfe5f13990f97aa
> --
> 2.43.0
>
>