linux-crypto.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: Eric Biggers <ebiggers@kernel.org>
To: Segher Boessenkool <segher@kernel.crashing.org>
Cc: Herbert Xu <herbert@gondor.apana.org.au>,
	Venkat Rao Bagalkote <venkat88@linux.ibm.com>,
	Thorsten Leemhuis <linux@leemhuis.info>,
	Linux Crypto Mailing List <linux-crypto@vger.kernel.org>,
	LKML <linux-kernel@vger.kernel.org>,
	Linux Next Mailing List <linux-next@vger.kernel.org>,
	Madhavan Srinivasan <maddy@linux.ibm.com>,
	Stephen Rothwell <sfr@canb.auug.org.au>,
	Danny Tsen <dtsen@linux.ibm.com>,
	linuxppc-dev@lists.ozlabs.org
Subject: Re: [v2 PATCH] crypto: powerpc/poly1305 - Add poly1305_emit_arch wrapper
Date: Sat, 10 May 2025 16:19:19 -0700	[thread overview]
Message-ID: <20250510231919.GA134802@quark> (raw)
In-Reply-To: <20250510223401.GK30295@gate.crashing.org>

On Sat, May 10, 2025 at 05:34:01PM -0500, Segher Boessenkool wrote:
> Hi!
> 
> On Fri, May 09, 2025 at 10:33:08PM -0700, Eric Biggers wrote:
> > On Sat, May 10, 2025 at 01:10:22PM +0800, Herbert Xu wrote:
> > > On Fri, May 09, 2025 at 09:44:50PM -0700, Eric Biggers wrote:
> > > >
> > > > This fixes "-cpu Power10", but older CPUs (e.g. "-cpu POWER9") are still
> > > > failing.
> > > 
> > > You're right.  I'll revert this and apply the following patch
> > > instead.
> > > 
> > > BTW this thing is still hopelessly broken if it's called from
> > > softirq context because there is no SIMD fallback.  Yes I removed
> > > the SIMD check but it was already broken before that as it simply
> > > switched from the 4-block version to the 1-block version if SIMD
> > > is not available rather than actually doing something that is
> > > safe in softirq context.
> > > 
> > > Perhaps we should just remove this altogether until it's fixed.
> > 
> > Yes, the PowerPC Poly1305 code incorrectly uses VSX without first checking
> > crypto_simd_usable().  And PowerPC also doesn't support VSX in softirqs, or at
> > least it doesn't claim to (it doesn't override may_use_simd(), so it gets the
> > default from include/asm-generic/simd.h which returns false in softirq context).
> > Maybe add 'depends on BROKEN' to CRYPTO_POLY1305_P10 for now, and give the
> > PowerPC folks (Cc'ed) a chance to fix this before removing the code.
> 
> What doe "may_use_simd" even *mean*?  At its declaration site it says
> "whether it is allowable at this time to issue SIMD instructions or
> access the SIMD register file", but that is 100% meaningless, you can do
> SIMD in GPRs.
> 
> On PowerPC we have two separate register files dedicated to SIMD-like
> stuff, the VMX and the VSX register files.  Which of those is this
> function supposed to care about?
> 
> It looks like the whole "may_use_simd" thing is a misguided abstraction
> unfortunately :-(

may_use_simd() a.k.a crypto_simd_usable() is supposed to check whether vector /
SIMD registers can be used in the current context, provided that the appropriate
architecture-specific functions like kernel_fpu_begin() and kernel_fpu_end() are
used.  In the case of architectures that support the use of multiple sets of
vector / SIMD registers in kernel mode, it would have to check for the
intersection of the calling context requirements for all of them, since it
doesn't specify a particular set.

The reason that may_use_simd() a.k.a. crypto_simd_usable() got pulled out into
an abstraction shared across all architectures is that it's used by
non-architecture-specific code, such as crypto/simd.c, and also the crypto
self-tests which inject 'false' return values to test the no-SIMD code paths.

I think the users other than the self-tests are on the way out, though.  Most of
the users of crypto/simd.c just got removed, with CRYPTO_AES_GCM_P10 being the
last one.  A new non-architecture-specific user of crypto_simd_usable() just got
added in include/crypto/internal/sha2.h for some reason (despite me nacking the
patch), but that should be reverted.

So if it's really the case that VMX and VSX are both supported for kernel-mode
use but have different requirements on the calling context, you could make the
PowerPC crypto code use more precise checks like may_use_vsx().  Just the crypto
self-tests won't be able to test the no-SIMD code paths that way, unfortunately.

- Eric

  reply	other threads:[~2025-05-10 23:19 UTC|newest]

Thread overview: 47+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-04-28  4:56 [v4 PATCH 00/11] crypto: lib - Add partial block helper Herbert Xu
2025-04-28  4:56 ` [v4 PATCH 01/11] crypto: lib/sha256 - Move partial block handling out Herbert Xu
2025-04-28  4:56 ` [v4 PATCH 02/11] crypto: lib/poly1305 - Add block-only interface Herbert Xu
2025-04-28  4:56 ` [v4 PATCH 03/11] crypto: arm/poly1305 " Herbert Xu
2025-04-28  4:56 ` [v4 PATCH 04/11] crypto: arm64/poly1305 " Herbert Xu
2025-04-28  4:56 ` [v4 PATCH 05/11] crypto: mips/poly1305 " Herbert Xu
2025-04-28  4:56 ` [v4 PATCH 06/11] crypto: powerpc/poly1305 " Herbert Xu
2025-04-28  4:56 ` [v4 PATCH 07/11] crypto: x86/poly1305 " Herbert Xu
2025-04-28  4:56 ` [v4 PATCH 08/11] crypto: chacha20poly1305 - Use lib/crypto poly1305 Herbert Xu
2025-05-05 13:41   ` Cabiddu, Giovanni
2025-05-06  2:03     ` Herbert Xu
2025-05-06  2:05       ` [PATCH] crypto: lib/poly1305 - Build main library on LIB_POLY1305 and split generic code out Herbert Xu
2025-05-06 10:56         ` Cabiddu, Giovanni
2025-05-06 11:05           ` [v2 PATCH] " Herbert Xu
2025-05-06 11:30             ` Cabiddu, Giovanni
2025-04-28  4:56 ` [v4 PATCH 09/11] crypto: testmgr - Remove poly1305 Herbert Xu
2025-04-28  4:56 ` [v4 PATCH 10/11] crypto: poly1305 - Remove algorithm Herbert Xu
2025-04-28  4:56 ` [v4 PATCH 11/11] crypto: lib/poly1305 - Use block-only interface Herbert Xu
2025-05-07 11:03   ` Thorsten Leemhuis
2025-05-07 11:36     ` [PATCH] crypto: powerpc/poly1305 - Add missing poly1305_emit_arch Herbert Xu
2025-05-07 12:25       ` Thorsten Leemhuis
2025-05-08  9:16       ` Venkat Rao Bagalkote
2025-05-08  9:31         ` Herbert Xu
2025-05-08 10:01           ` Venkat Rao Bagalkote
2025-05-08 11:10             ` Herbert Xu
2025-05-08  9:45         ` Herbert Xu
2025-05-08 16:29           ` Eric Biggers
2025-05-09  0:53             ` Herbert Xu
2025-05-08  9:49         ` Herbert Xu
2025-05-08 11:39         ` Herbert Xu
2025-05-08 11:57           ` Venkat Rao Bagalkote
2025-05-08 11:59             ` Herbert Xu
2025-05-08 12:23             ` [PATCH] crypto: powerpc/poly1305 - Restore crypto_simd_usable test Herbert Xu
2025-05-08 15:05               ` Venkat Rao Bagalkote
2025-05-09 12:29                 ` [PATCH] crypto: powerpc/poly1305 - Fix input mixup in poly1305_emit_arch Herbert Xu
2025-05-10  4:44                   ` Eric Biggers
2025-05-10  5:10                     ` [v2 PATCH] crypto: powerpc/poly1305 - Add poly1305_emit_arch wrapper Herbert Xu
2025-05-10  5:33                       ` Eric Biggers
2025-05-10  5:49                         ` Herbert Xu
2025-05-10  5:50                           ` Herbert Xu
2025-05-10  6:02                             ` Eric Biggers
2025-05-10  9:13                         ` [PATCH] crypto: powerpc/poly1305 - Add SIMD fallback Herbert Xu
2025-05-10 22:34                         ` [v2 PATCH] crypto: powerpc/poly1305 - Add poly1305_emit_arch wrapper Segher Boessenkool
2025-05-10 23:19                           ` Eric Biggers [this message]
2025-05-11  2:10                           ` Herbert Xu
2025-05-12  5:13                       ` Venkat Rao Bagalkote
2025-05-09 14:16               ` [PATCH] crypto: powerpc/poly1305 - Restore crypto_simd_usable test Herbert Xu

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20250510231919.GA134802@quark \
    --to=ebiggers@kernel.org \
    --cc=dtsen@linux.ibm.com \
    --cc=herbert@gondor.apana.org.au \
    --cc=linux-crypto@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-next@vger.kernel.org \
    --cc=linux@leemhuis.info \
    --cc=linuxppc-dev@lists.ozlabs.org \
    --cc=maddy@linux.ibm.com \
    --cc=segher@kernel.crashing.org \
    --cc=sfr@canb.auug.org.au \
    --cc=venkat88@linux.ibm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).