From: Eric Farman <farman@linux.ibm.com>
To: Harald Freudenberger <freude@linux.ibm.com>,
richard.henderson@linaro.org, iii@linux.ibm.com,
david@kernel.org, thuth@redhat.com, berrange@redhat.com
Cc: qemu-s390x@nongnu.org, qemu-devel@nongnu.org,
linux-s390@vger.kernel.org, dengler@linux.ibm.com,
borntraeger@linux.ibm.com, fcallies@linux.ibm.com,
cohuck@redhat.com
Subject: Re: [PATCH v16 00/20] Extend qemu CPACF support
Date: Wed, 9 Sep 2026 10:51:18 -0400 [thread overview]
Message-ID: <cf1a40d2-5c8a-4b31-8bf4-aecbae966c79@linux.ibm.com> (raw)
In-Reply-To: <20260824083204.40877-1-freude@linux.ibm.com>
On 8/24/26 4:31 AM, Harald Freudenberger wrote:
> This patch series extends the s390 qemu CPACF support to be able to
> run a subset of the CPACF instruction cross platform. There have been
> requests on the kernel crypto mailing list about a way to test
> s390 specific crypto implementations. For example a way to test
> s390 CPACF exploitation code like the s390_aes.ko kernel module.
>
> So here now is a set of patches verified on x86 and s390 which
> over (slow but working) support for a subset of the subfunctions of
> some of the CPACF instructions.
>
> Test: There are some very basic tests included with this patch series
> suitable for some CI run. Better test coverage can be done by running
> a full blown Linux and use for example the in-kernel crypto modules.
> The 'usual' in-kernel crpyto modules will be automatically loaded
> which run a bunch of test cases. So there is now support for these
> kernel modules:
> * sha256_s390x (autoloaded, sha256)
> * sha512_s390x (autoloaded, sha512)
> * aes_s390x (autoloaded, clear key aes ecb, cbc, ctr, xts)
> * pkey_pckmo (autoloaded, derive AES protected key from clear key)
> * paes_s390x (not autoloaded, protected key aes ecb, cbc, ctr, xts)
> All these modules run selftests if configured by the kernel (which is
> enabled by default). Failures are reported via syslog. Additionally
> the aes testcases from libica can be run either inside such an qemu
> environment or with a static build executed with the qemu tcg
> application qemu-s390x --cpu max <static-build-libica-test>.
Applied for 11.2. Thank you!
>
> Changelog:
> v1: Initial version with
> - Related code restructured
> - Support KIMD SHA512 and thus SHA256
> - Support KMC AES-128, AES-192 and AES-256 and thus have basic AES
> support (ECB mode) enabled.
> - Support PCC Compute-XTS-Parameter-AES-128 and
> Compute-XTS-Parameter-AES-256 but only for block sequence number
> 0. This is a requirement for the next step:
> - Support KM XTS-AES-128 and KM XTS-AES-256. Together with the
> minimal PCC support this enables AES-XTS CPACF acceleration.
> v2: - Basic PCKMO support to be able to 'derive' an AES protected key
> from clear key. See header details.
> - Support protected key AES-ECB.
> - Support protected key AES-CBC.
> - Minimal protected key AES-XTS support for CPACF PCC.
> - Support protected key AES-XTS.
> - Support AES-CTR.
> - Support protected key AES-CTR.
> v3: - Reordered patches as suggested by Finn.
> - One small bug fix in CPACF_aes.c related to address translation.
> v4: - Rename of the parameters based on feedback from Janosch to
> make clear these are registers or ptrs to registers.
> Added Tested by from Holger. Fixed typo "face" -> "fake".
> v5: - Add documentation file docs/system/s390x/cpacf.rst which
> describes the state of the CPACF instructions and which
> functions are covered when this series is applied.
> First version sent to public mailing list qemu-s390x.
> v6: - Rebase/rework to build on current qemu head.
> - Add docs/system/s390x/cpacf.rst to target-s390x.rst
> - New file crypto/aes-helpers.c with some simple
> functions to support AES modes CBC, CTR and XTS.
> - Slight rewrite of the s390x CPACF implementations to
> use these generic AES mode implementations.
> v7: - Update on docs/system/s390x/cpacf.rst to mention
> the zArchicteture Principles of Operation document
> which describes all these CPACF instructions.
> v8: - Add a fix which deals with incorrect address handling
> in the sha512 implementation related to fetch and push
> data from/to memory.
> - Slight rework around the capcf function implementation and
> exception generation.
> - Added some more details to the new cpacf.rst file.
> - Fixed some typos and added some suggestions from Finn.
> - Fixed cc handling on return of PCKMO (must not update cc).
> Missing: simple test cases to verify that the implemented and not
> implemented cpacf functions and subfunctions work as expected. But
> see the statement about tests at the header.
> v9: - Add simple tests for all the implemented CPACF instructions but
> pckmo (which is a privileged instruction).
> - Reworked the Fix for wrong address to call the wrap function
> inline; rephrased commit header.
> - Improve the header file cpacf.h to hold defines for all the
> cpacf instruction functions and use them in the code.
> - one new commit comprising the base protected key support with
> exposing the xor pattern and wkvp and en/decrypt key functions
> via cpacf.h. So the testcases can use this header file.
> - one new commit which reworks the fetch memory and store memory
> from and to guest (suggested by Ilya Leoshkevich).
> v10: - Fixed v9 patch 3 (cpacf_sha512.c was missing)
> Please note that patch #10 "target/s390x: Base support for cpacf
> protected keys" produces a build warning ("unused function"). As
> by default the qemu build has warnings=errors enabled, this one
> patch does not build on it's own. If this is not acceptable, the
> hunk introducing the two functions may be moved to the next
> commit; another solution would be to merge with patch #11.
> v11: Fixed nearly all checkpatch findings - only the warnings about
> Maintainers may need update is still there.
> v12: - Very first patch is integrated in master and thus removed from
> this series.
> - New header file include/crypto/aes-headers.h as suggested by
> Daniel. Moved the patch which introduces the aes helpers before
> the actual AES cpacf implementations and reworked all the code
> to use these helpers.
> - Merged together "Base support for cpacf protected keys" and
> "Support pckmo encrypt AES subfunctions" to fix the broken
> build caused by unused functions.
> - Merged the changes from patch "Improve fetch and store mem from
> and to guest" directly into the code where it is introduced.
> v13: - reworked the helper functions to copy memory from and to
> guest. These are now inline functions located in
> target/s390x/tcg/crypto_helper.h and have been renamed and
> extended for u32 and u64 as well. Also the both sha
> implementations have been reworked to use these helper
> functions. See patch #4 for details.
> - fixed the wrong list of parameters docu in patch #5
> - added some Reviewed-by tags.
> - reworked the testcases to run (more or less) on real s390
> hardware. However this does not and can not work with protected
> keys.
> - rebased to current master head.
> v14: - fixed one wrong constant in target/s390x/tcg/cpacf.h
> - added 1 patch (patch #1) which fixes the missing privileged
> flag with the PCKMO instruction.
> - added a simple testcase for the PCKMO instruction (see
> tests/s390x/tcg/cpacf-pckmo.c for details).
> v15: - rebased to current master
> - new patch reworking the addressing mode check in the both
> sha256 and sha512 implementations. Also added early bail out.
> - In a similar way rework the checking for addressing mode in
> cpacf_aes.c (comes in with each algo implementation).
> - bail out early on length zero for the cpacf aes algs.
> - As suggested by Ilya splitted the cpacf.h into two header
> files cpacf-arch.h and cpacf.h.
> v16: - Fixed some places with wrong indentation.
> - Fix regression introduced with v15: sha256 and sha512 must bail
> out for KIMD only, but not for KLMD.
> - AI screening: PCKMO still clobbered CC. So fixed this.
> - AI screening: KDSA lacked the r2 even/nonzero check - fixed.
> - Updated cpacf docu to clearly state for KMA, KMF, KMO and KDSA
> which exception happens on which condition.
>
> Harald Freudenberger (20):
> target/s390x: Fix missing privileged flag at PCKMO instruction
> target/s390x: Rework s390 cpacf implementations
> target/s390x: Move cpacf sha512 code into a new file
> target/s390x: Support cpacf sha256
> target/s390x: Add helper functions for copy memory to and from guest
> target/s390x: Adjust addressing mode checks for sha512 and sha256
> crypto: Add aes-helpers file to support some AES modes
> target/s390x: Support AES ECB for cpacf km instruction
> target/s390x: Support AES CBC for cpacf kmc instruction
> target/s390x: Support AES CTR for cpacf kmctr instruction
> target/s390x: Minimal AES XTS support for cpacf pcc instruction
> target/s390x: Support AES XTS for cpacf km instruction
> target/s390x: Base support for cpacf protected keys and pckmo
> target/s390x: Support protected key AES ECB for cpacf km instruction
> target/s390x: Support protected key AES CBC for cpacf kmc instruction
> target/s390x: Support protected key AES CTR for cpacf kmctr
> instruction
> target/s390x: Minimal protected key AES XTS support for cpacf pcc
> instruction
> target/s390x: Support protected key AES XTS for cpacf km instruction
> docs/s390: Document CPACF instructions support
> tests/tcg/s390x: Add tests for CPACF instructions
>
> crypto/aes-helpers.c | 106 ++++
> crypto/meson.build | 1 +
> docs/system/s390x/cpacf.rst | 143 +++++
> docs/system/target-s390x.rst | 1 +
> include/crypto/aes-helpers.h | 109 ++++
> target/s390x/gen-features.c | 31 +
> target/s390x/tcg/cpacf-arch.h | 251 ++++++++
> target/s390x/tcg/cpacf.h | 63 ++
> target/s390x/tcg/cpacf_aes.c | 986 +++++++++++++++++++++++++++++++
> target/s390x/tcg/cpacf_sha256.c | 197 ++++++
> target/s390x/tcg/cpacf_sha512.c | 211 +++++++
> target/s390x/tcg/crypto_helper.c | 445 +++++++-------
> target/s390x/tcg/crypto_helper.h | 100 ++++
> target/s390x/tcg/insn-data.h.inc | 3 +-
> target/s390x/tcg/meson.build | 3 +
> target/s390x/tcg/translate.c | 16 +-
> tests/tcg/s390x/Makefile.target | 10 +
> tests/tcg/s390x/cpacf-kdsa.c | 58 ++
> tests/tcg/s390x/cpacf-kimd.c | 166 ++++++
> tests/tcg/s390x/cpacf-klmd.c | 206 +++++++
> tests/tcg/s390x/cpacf-km.c | 590 ++++++++++++++++++
> tests/tcg/s390x/cpacf-kmac.c | 58 ++
> tests/tcg/s390x/cpacf-kmc.c | 351 +++++++++++
> tests/tcg/s390x/cpacf-kmctr.c | 360 +++++++++++
> tests/tcg/s390x/cpacf-pcc.c | 245 ++++++++
> tests/tcg/s390x/cpacf-pckmo.c | 45 ++
> tests/tcg/s390x/cpacf-prno.c | 131 ++++
> tests/tcg/s390x/cpacf.h | 570 ++++++++++++++++++
> 28 files changed, 5230 insertions(+), 226 deletions(-)
> create mode 100644 crypto/aes-helpers.c
> create mode 100644 docs/system/s390x/cpacf.rst
> create mode 100644 include/crypto/aes-helpers.h
> create mode 100644 target/s390x/tcg/cpacf-arch.h
> create mode 100644 target/s390x/tcg/cpacf.h
> create mode 100644 target/s390x/tcg/cpacf_aes.c
> create mode 100644 target/s390x/tcg/cpacf_sha256.c
> create mode 100644 target/s390x/tcg/cpacf_sha512.c
> create mode 100644 target/s390x/tcg/crypto_helper.h
> create mode 100644 tests/tcg/s390x/cpacf-kdsa.c
> create mode 100644 tests/tcg/s390x/cpacf-kimd.c
> create mode 100644 tests/tcg/s390x/cpacf-klmd.c
> create mode 100644 tests/tcg/s390x/cpacf-km.c
> create mode 100644 tests/tcg/s390x/cpacf-kmac.c
> create mode 100644 tests/tcg/s390x/cpacf-kmc.c
> create mode 100644 tests/tcg/s390x/cpacf-kmctr.c
> create mode 100644 tests/tcg/s390x/cpacf-pcc.c
> create mode 100644 tests/tcg/s390x/cpacf-pckmo.c
> create mode 100644 tests/tcg/s390x/cpacf-prno.c
> create mode 100644 tests/tcg/s390x/cpacf.h
>
>
> base-commit: 9696bf5dc5a5bf0b4a9d05b6cdfe5f13990f97aa
> --
> 2.43.0
>
>
prev parent reply other threads:[~2026-09-09 14:51 UTC|newest]
Thread overview: 24+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-24 8:31 [PATCH v16 00/20] Extend qemu CPACF support Harald Freudenberger
2026-08-24 8:31 ` [PATCH v16 01/20] target/s390x: Fix missing privileged flag at PCKMO instruction Harald Freudenberger
2026-08-24 8:31 ` [PATCH v16 02/20] target/s390x: Rework s390 cpacf implementations Harald Freudenberger
2026-08-24 8:31 ` [PATCH v16 03/20] target/s390x: Move cpacf sha512 code into a new file Harald Freudenberger
2026-08-24 8:31 ` [PATCH v16 04/20] target/s390x: Support cpacf sha256 Harald Freudenberger
2026-08-24 8:31 ` [PATCH v16 05/20] target/s390x: Add helper functions for copy memory to and from guest Harald Freudenberger
2026-08-24 8:31 ` [PATCH v16 06/20] target/s390x: Adjust addressing mode checks for sha512 and sha256 Harald Freudenberger
2026-08-25 10:15 ` Eric Farman
2026-08-24 8:31 ` [PATCH v16 07/20] crypto: Add aes-helpers file to support some AES modes Harald Freudenberger
2026-08-24 8:31 ` [PATCH v16 08/20] target/s390x: Support AES ECB for cpacf km instruction Harald Freudenberger
2026-08-24 8:31 ` [PATCH v16 09/20] target/s390x: Support AES CBC for cpacf kmc instruction Harald Freudenberger
2026-08-24 8:31 ` [PATCH v16 10/20] target/s390x: Support AES CTR for cpacf kmctr instruction Harald Freudenberger
2026-08-24 8:31 ` [PATCH v16 11/20] target/s390x: Minimal AES XTS support for cpacf pcc instruction Harald Freudenberger
2026-08-24 8:31 ` [PATCH v16 12/20] target/s390x: Support AES XTS for cpacf km instruction Harald Freudenberger
2026-08-24 8:31 ` [PATCH v16 13/20] target/s390x: Base support for cpacf protected keys and pckmo Harald Freudenberger
2026-08-24 8:31 ` [PATCH v16 14/20] target/s390x: Support protected key AES ECB for cpacf km instruction Harald Freudenberger
2026-08-24 8:31 ` [PATCH v16 15/20] target/s390x: Support protected key AES CBC for cpacf kmc instruction Harald Freudenberger
2026-08-24 8:32 ` [PATCH v16 16/20] target/s390x: Support protected key AES CTR for cpacf kmctr instruction Harald Freudenberger
2026-08-24 8:32 ` [PATCH v16 17/20] target/s390x: Minimal protected key AES XTS support for cpacf pcc instruction Harald Freudenberger
2026-08-24 8:32 ` [PATCH v16 18/20] target/s390x: Support protected key AES XTS for cpacf km instruction Harald Freudenberger
2026-08-24 8:32 ` [PATCH v16 19/20] docs/s390: Document CPACF instructions support Harald Freudenberger
2026-08-24 8:32 ` [PATCH v16 20/20] tests/tcg/s390x: Add tests for CPACF instructions Harald Freudenberger
2026-09-09 1:00 ` Eric Farman
2026-09-09 14:51 ` Eric Farman [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=cf1a40d2-5c8a-4b31-8bf4-aecbae966c79@linux.ibm.com \
--to=farman@linux.ibm.com \
--cc=berrange@redhat.com \
--cc=borntraeger@linux.ibm.com \
--cc=cohuck@redhat.com \
--cc=david@kernel.org \
--cc=dengler@linux.ibm.com \
--cc=fcallies@linux.ibm.com \
--cc=freude@linux.ibm.com \
--cc=iii@linux.ibm.com \
--cc=linux-s390@vger.kernel.org \
--cc=qemu-devel@nongnu.org \
--cc=qemu-s390x@nongnu.org \
--cc=richard.henderson@linaro.org \
--cc=thuth@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.