From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0a-001b2d01.pphosted.com (mx0a-001b2d01.pphosted.com [148.163.156.1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0C6A33B18A for ; Wed, 1 Jul 2026 16:47:11 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.156.1 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782924436; cv=none; b=I58XfrAegcnHclzc/a+le7aBOaL67tcssYi2+POgjfVFPhqvSSVtr3TDystxMvUYqtFClXXJYVVPtG1LX5TwT6OTllV0aR7QkcXgeqRqPIv7FlRbaOt/ocLrGFz0XGsUECrGAlzzH8piEIzUgU3+/ESXN4cucbj1dVxacY91n84= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782924436; c=relaxed/simple; bh=rox9IW9EoGotZZlG64a3WATtWe+I1IlN5VU03MdLqBE=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=AWrfozWMwkBWKT3f5yF7mJrROao0+DtxKb4LzQhP+QrSxjXVx3gvUxuRvq3JoIVhAMY9pbArXnZLDxztAjLDwNeqDUmKlz+qYIYJC9CR08UDavXKAgSsFOUkZvzzC9gg0JARi73mPWizQiNOgTRlw5y8SDTEWN8BYua4UbmUb8k= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=eiNrQ14F; arc=none smtp.client-ip=148.163.156.1 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="eiNrQ14F" Received: from pps.filterd (m0360083.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 661AIR4k609469; Wed, 1 Jul 2026 16:46:58 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=gE5lWr997+YWr6T55 QY8qJWAwwZ0wQ38SfgIcNQqk8M=; b=eiNrQ14FZ/S+gerb372plBXJVD8ceQl2Z vrZ/EutkcaEaxZJwzFhEGhDsJYaMgyZOOGUlfRe6MZLsd8DSQAfPsksTHTSLn824 H9oleTPec8GFdKhZJ7royD6um2u2T8b0uL7KcjwMgcAJ411mHarq4k3tASfUYhPP FsnmFo76pDnVVodtiMuA7bq+/bx0n8BxSYGcO4rxupK5yrqhSBnieUx2Sf2KlHX9 qwnyYBA0gMpGfGvuAvWixi8JJU+nszdwho0fC0PP9AjKJyXNuCBE4W3AE50TnVTc K41IdPfFMOT+hkvwu7/x6eat9sb+2FItULi3e/ybl8jaSi4eagHNw== Received: from ppma22.wdc07v.mail.ibm.com (5c.69.3da9.ip4.static.sl-reverse.com [169.61.105.92]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4f26pe5nkm-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 01 Jul 2026 16:46:57 +0000 (GMT) Received: from pps.filterd (ppma22.wdc07v.mail.ibm.com [127.0.0.1]) by ppma22.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 661GYx1L019774; Wed, 1 Jul 2026 16:46:56 GMT Received: from smtprelay06.fra02v.mail.ibm.com ([9.218.2.230]) by ppma22.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4f2s7w894g-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 01 Jul 2026 16:46:56 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (smtpav07.fra02v.mail.ibm.com [10.20.54.106]) by smtprelay06.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 661Gkq6Z24969682 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 1 Jul 2026 16:46:52 GMT Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 6AC7120043; Wed, 1 Jul 2026 16:46:52 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 388B520063; Wed, 1 Jul 2026 16:46:52 +0000 (GMT) Received: from funtu2.ibm.com (unknown [9.111.187.249]) by smtpav07.fra02v.mail.ibm.com (Postfix) with ESMTP; Wed, 1 Jul 2026 16:46:52 +0000 (GMT) From: Harald Freudenberger To: richard.henderson@linaro.org, iii@linux.ibm.com, david@kernel.org, thuth@redhat.com, berrange@redhat.com Cc: qemu-s390x@nongnu.org, qemu-devel@nongnu.org, linux390-list@tuxmaker.boeblingen.de.ibm.com, linux-s390@vger.kernel.org, dengler@linux.ibm.com, borntraeger@linux.ibm.com, fcallies@linux.ibm.com, cohuck@redhat.com Subject: [PATCH v9 03/21] target/s390x: Move cpacf sha512 code into a new file Date: Wed, 1 Jul 2026 18:46:26 +0200 Message-ID: <20260701164650.95760-4-freude@linux.ibm.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260701164650.95760-1-freude@linux.ibm.com> References: <20260701164650.95760-1-freude@linux.ibm.com> Precedence: bulk X-Mailing-List: linux-s390@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-TM-AS-GCONF: 00 X-Proofpoint-GUID: AGCVdkfZ3KC7hVeBcdKhxI-qk4lC3eik X-Proofpoint-Spam-Info: AW1haW4tMjYwNzAxMDE3MyBTYWx0ZWRfX1qcNA+PKnJMS rFVCFXdL5GkwHY0NJEbbh/8wMniWzwkJks35bVqtAp2p1fyIzXoU49uedGil+11baMnb4NAnm9o pWT0VLHyUkA7C931h9PlAuqFUUSjUDg= X-Authority-Analysis: v=2.4 cv=edsNubEH c=1 sm=1 tr=0 ts=6a454481 cx=c_pps a=5BHTudwdYE3Te8bg5FgnPg==:117 a=5BHTudwdYE3Te8bg5FgnPg==:17 a=RAioF0-LDSMA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=iQ6ETzBq9ecOQQE5vZCe:22 a=VnNF1IyMAAAA:8 a=zrV7DtJrW_FN7HXsPcMA:9 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzAxMDE3MyBTYWx0ZWRfX9+5LapANE0kp XxUJCRR0twS+mfy/a7oXjPSz0jG4UoNA7GQoVomE1Re9ufUXBvzmJY6B/2jk2esEtdd5po9qLza 9PG8QMLqXMR8KvKkh65VVQRsiiJc7lZ4FhT7mUor5AbWamuc1iBSe4FAfVp2bDrQWxbFZ5QCQjw Ns+4m2dArX4cAS2ZmqdyfIPHeYhrXKxGQ27uBPDiHP24eP0tUuwlZEy0uQhChMVWshzZQ9BLuU2 zUF7o58VQjyYXGYdQC0j0Bf9TVtjC3/fzk9RYl2e3PCl8XbkSoF5jFK+WBXuw9f3IDD5rJjkGFK wx8ggxTpDXo9NKYGCxrhrrogfSm+oDqV3tvofxTmmJroRvNBp3wKwA2HI4/ArCRghzRCT9MX8fE mQ5EMTI6a+tVmnDZCx7Kqr+Nsl+E7pBU5nSAaKlV2M2imm3ZGJ73C/qKU0axUroxRQ66Imy1hLS mTD3i6fUqEfpQmCeKnA== X-Proofpoint-ORIG-GUID: AGCVdkfZ3KC7hVeBcdKhxI-qk4lC3eik X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-01_03,2026-06-26_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 priorityscore=1501 malwarescore=0 adultscore=0 impostorscore=0 bulkscore=0 spamscore=0 suspectscore=0 clxscore=1015 lowpriorityscore=0 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607010173 Move the cpacf sha512 implementation into a new file cpacf_sha512.c. Add this new file to the build and use the cpacf.h header file storing function the prototypes. Tested-by: Holger Dengler Reviewed-by: Finn Callies Reviewed-by: Ilya Leoshkevich Signed-off-by: Harald Freudenberger --- target/s390x/tcg/cpacf.h | 5 + target/s390x/tcg/crypto_helper.c | 222 ------------------------------- target/s390x/tcg/meson.build | 1 + 3 files changed, 6 insertions(+), 222 deletions(-) diff --git a/target/s390x/tcg/cpacf.h b/target/s390x/tcg/cpacf.h index 05596e0645..6de79a2f8f 100644 --- a/target/s390x/tcg/cpacf.h +++ b/target/s390x/tcg/cpacf.h @@ -223,4 +223,9 @@ #define CPACF_KDSA_PSIGN_ED25519 48 #define CPACF_KDSA_PSIGN_ED448 52 +/* from cpacf_sha512.c */ +int cpacf_sha512(CPUS390XState *env, const int mmu_idx, uintptr_t ra, + uint64_t param_addr, uint64_t *message_reg, uint64_t *len_reg, + uint32_t type); + #endif /* S390X_CPACF_H */ diff --git a/target/s390x/tcg/crypto_helper.c b/target/s390x/tcg/crypto_helper.c index 987bc72ae9..dba46baa0d 100644 --- a/target/s390x/tcg/crypto_helper.c +++ b/target/s390x/tcg/crypto_helper.c @@ -21,228 +21,6 @@ #include "accel/tcg/cpu-mmu-index.h" #include "target/s390x/tcg/cpacf.h" -static uint64_t R(uint64_t x, int c) -{ - return (x >> c) | (x << (64 - c)); -} -static uint64_t Ch(uint64_t x, uint64_t y, uint64_t z) -{ - return (x & y) ^ (~x & z); -} -static uint64_t Maj(uint64_t x, uint64_t y, uint64_t z) -{ - return (x & y) ^ (x & z) ^ (y & z); -} -static uint64_t Sigma0(uint64_t x) -{ - return R(x, 28) ^ R(x, 34) ^ R(x, 39); -} -static uint64_t Sigma1(uint64_t x) -{ - return R(x, 14) ^ R(x, 18) ^ R(x, 41); -} -static uint64_t sigma0(uint64_t x) -{ - return R(x, 1) ^ R(x, 8) ^ (x >> 7); -} -static uint64_t sigma1(uint64_t x) -{ - return R(x, 19) ^ R(x, 61) ^ (x >> 6); -} - -static const uint64_t K[80] = { - 0x428a2f98d728ae22ULL, 0x7137449123ef65cdULL, 0xb5c0fbcfec4d3b2fULL, - 0xe9b5dba58189dbbcULL, 0x3956c25bf348b538ULL, 0x59f111f1b605d019ULL, - 0x923f82a4af194f9bULL, 0xab1c5ed5da6d8118ULL, 0xd807aa98a3030242ULL, - 0x12835b0145706fbeULL, 0x243185be4ee4b28cULL, 0x550c7dc3d5ffb4e2ULL, - 0x72be5d74f27b896fULL, 0x80deb1fe3b1696b1ULL, 0x9bdc06a725c71235ULL, - 0xc19bf174cf692694ULL, 0xe49b69c19ef14ad2ULL, 0xefbe4786384f25e3ULL, - 0x0fc19dc68b8cd5b5ULL, 0x240ca1cc77ac9c65ULL, 0x2de92c6f592b0275ULL, - 0x4a7484aa6ea6e483ULL, 0x5cb0a9dcbd41fbd4ULL, 0x76f988da831153b5ULL, - 0x983e5152ee66dfabULL, 0xa831c66d2db43210ULL, 0xb00327c898fb213fULL, - 0xbf597fc7beef0ee4ULL, 0xc6e00bf33da88fc2ULL, 0xd5a79147930aa725ULL, - 0x06ca6351e003826fULL, 0x142929670a0e6e70ULL, 0x27b70a8546d22ffcULL, - 0x2e1b21385c26c926ULL, 0x4d2c6dfc5ac42aedULL, 0x53380d139d95b3dfULL, - 0x650a73548baf63deULL, 0x766a0abb3c77b2a8ULL, 0x81c2c92e47edaee6ULL, - 0x92722c851482353bULL, 0xa2bfe8a14cf10364ULL, 0xa81a664bbc423001ULL, - 0xc24b8b70d0f89791ULL, 0xc76c51a30654be30ULL, 0xd192e819d6ef5218ULL, - 0xd69906245565a910ULL, 0xf40e35855771202aULL, 0x106aa07032bbd1b8ULL, - 0x19a4c116b8d2d0c8ULL, 0x1e376c085141ab53ULL, 0x2748774cdf8eeb99ULL, - 0x34b0bcb5e19b48a8ULL, 0x391c0cb3c5c95a63ULL, 0x4ed8aa4ae3418acbULL, - 0x5b9cca4f7763e373ULL, 0x682e6ff3d6b2b8a3ULL, 0x748f82ee5defb2fcULL, - 0x78a5636f43172f60ULL, 0x84c87814a1f0ab72ULL, 0x8cc702081a6439ecULL, - 0x90befffa23631e28ULL, 0xa4506cebde82bde9ULL, 0xbef9a3f7b2c67915ULL, - 0xc67178f2e372532bULL, 0xca273eceea26619cULL, 0xd186b8c721c0c207ULL, - 0xeada7dd6cde0eb1eULL, 0xf57d4f7fee6ed178ULL, 0x06f067aa72176fbaULL, - 0x0a637dc5a2c898a6ULL, 0x113f9804bef90daeULL, 0x1b710b35131c471bULL, - 0x28db77f523047d84ULL, 0x32caab7b40c72493ULL, 0x3c9ebe0a15c9bebcULL, - 0x431d67c49c100d4cULL, 0x4cc5d4becb3e42b6ULL, 0x597f299cfc657e2aULL, - 0x5fcb6fab3ad6faecULL, 0x6c44198c4a475817ULL -}; - -/* a is icv/ocv, w is a single message block. w will get reused internally. */ -static void sha512_bda(uint64_t a[8], uint64_t w[16]) -{ - uint64_t t, z[8], b[8]; - int i, j; - - memcpy(z, a, sizeof(z)); - for (i = 0; i < 80; i++) { - memcpy(b, a, sizeof(b)); - - t = a[7] + Sigma1(a[4]) + Ch(a[4], a[5], a[6]) + K[i] + w[i % 16]; - b[7] = t + Sigma0(a[0]) + Maj(a[0], a[1], a[2]); - b[3] += t; - for (j = 0; j < 8; ++j) { - a[(j + 1) % 8] = b[j]; - } - if (i % 16 == 15) { - for (j = 0; j < 16; ++j) { - w[j] += w[(j + 9) % 16] + sigma0(w[(j + 1) % 16]) + - sigma1(w[(j + 14) % 16]); - } - } - } - - for (i = 0; i < 8; i++) { - a[i] += z[i]; - } -} - -/* a is icv/ocv, w is a single message block that needs be64 conversion. */ -static void sha512_bda_be64(uint64_t a[8], uint64_t w[16]) -{ - uint64_t t[16]; - int i; - - for (i = 0; i < 16; i++) { - t[i] = be64_to_cpu(w[i]); - } - sha512_bda(a, t); -} - -static void sha512_read_icv(CPUS390XState *env, const int mmu_idx, - uint64_t addr, uint64_t a[8], uintptr_t ra) -{ - const MemOpIdx oi = make_memop_idx(MO_BE | MO_64 | MO_UNALN, mmu_idx); - - for (int i = 0; i < 8; i++, addr += 8) { - a[i] = cpu_ldq_mmu(env, wrap_address(env, addr), oi, ra); - } -} - -static void sha512_write_ocv(CPUS390XState *env, const int mmu_idx, - uint64_t addr, uint64_t a[8], uintptr_t ra) -{ - const MemOpIdx oi = make_memop_idx(MO_BE | MO_64 | MO_UNALN, mmu_idx); - - for (int i = 0; i < 8; i++, addr += 8) { - cpu_stq_mmu(env, wrap_address(env, addr), a[i], oi, ra); - } -} - -static void sha512_read_block(CPUS390XState *env, const int mmu_idx, - uint64_t addr, uint64_t a[16], uintptr_t ra) -{ - const MemOpIdx oi = make_memop_idx(MO_BE | MO_64 | MO_UNALN, mmu_idx); - - for (int i = 0; i < 16; i++, addr += 8) { - a[i] = cpu_ldq_mmu(env, wrap_address(env, addr), oi, ra); - } -} - -static void sha512_read_mbl_be64(CPUS390XState *env, const int mmu_idx, - uint64_t addr, uint8_t a[16], uintptr_t ra) -{ - const MemOpIdx oi = make_memop_idx(MO_8, mmu_idx); - - for (int i = 0; i < 16; i++, addr += 1) { - a[i] = cpu_ldb_mmu(env, wrap_address(env, addr), oi, ra); - } -} - -static int cpacf_sha512(CPUS390XState *env, const int mmu_idx, uintptr_t ra, - uint64_t param_addr, uint64_t *message_reg, - uint64_t *len_reg, uint32_t type) -{ - enum { MAX_BLOCKS_PER_RUN = 64 }; /* Arbitrary: keep interactivity. */ - uint64_t len = *len_reg, a[8], processed = 0; - int i, message_reg_len = 64; - - g_assert(type == S390_FEAT_TYPE_KIMD || type == S390_FEAT_TYPE_KLMD); - - if (!(env->psw.mask & PSW_MASK_64)) { - len = (uint32_t)len; - message_reg_len = (env->psw.mask & PSW_MASK_32) ? 32 : 24; - } - - /* KIMD: length has to be properly aligned. */ - if (type == S390_FEAT_TYPE_KIMD && !QEMU_IS_ALIGNED(len, 128)) { - tcg_s390_program_interrupt(env, PGM_SPECIFICATION, ra); - } - - sha512_read_icv(env, mmu_idx, param_addr, a, ra); - - /* Process full blocks first. */ - for (; len >= 128; len -= 128, processed += 128) { - uint64_t w[16]; - - if (processed >= MAX_BLOCKS_PER_RUN * 128) { - break; - } - - sha512_read_block(env, mmu_idx, *message_reg + processed, w, ra); - sha512_bda(a, w); - } - - /* KLMD: Process partial/empty block last. */ - if (type == S390_FEAT_TYPE_KLMD && len < 128) { - const MemOpIdx oi = make_memop_idx(MO_8, mmu_idx); - uint8_t x[128]; - - /* Read the remainder of the message byte-per-byte. */ - for (i = 0; i < len; i++) { - uint64_t addr = wrap_address(env, *message_reg + processed + i); - - x[i] = cpu_ldb_mmu(env, addr, oi, ra); - } - /* Pad the remainder with zero and set the top bit. */ - memset(x + len, 0, 128 - len); - x[len] = 128; - - /* - * Place the MBL either into this block (if there is space left), - * or use an additional one. - */ - if (len < 112) { - sha512_read_mbl_be64(env, mmu_idx, param_addr + 64, x + 112, ra); - } - sha512_bda_be64(a, (uint64_t *)x); - - if (len >= 112) { - memset(x, 0, 112); - sha512_read_mbl_be64(env, mmu_idx, param_addr + 64, x + 112, ra); - sha512_bda_be64(a, (uint64_t *)x); - } - - processed += len; - len = 0; - } - - /* - * Modify memory after we read all inputs and modify registers only after - * writing memory succeeded. - * - * TODO: if writing fails halfway through (e.g., when crossing page - * boundaries), we're in trouble. We'd need something like access_prepare(). - */ - sha512_write_ocv(env, mmu_idx, param_addr, a, ra); - *message_reg = deposit64(*message_reg, 0, message_reg_len, - *message_reg + processed); - *len_reg -= processed; - return !len ? 0 : 3; -} - static void fill_buf_random(CPUS390XState *env, const int mmu_idx, uintptr_t ra, uint64_t *buf_reg, uint64_t *len_reg) { diff --git a/target/s390x/tcg/meson.build b/target/s390x/tcg/meson.build index 36cb0e079e..54a87393a3 100644 --- a/target/s390x/tcg/meson.build +++ b/target/s390x/tcg/meson.build @@ -5,6 +5,7 @@ s390x_ss.add(when: 'CONFIG_TCG', if_true: files( )) s390x_common_ss.add(when: 'CONFIG_TCG', if_true: files( 'cc_helper.c', + 'cpacf_sha512.c', 'crypto_helper.c', 'excp_helper.c', 'fpu_helper.c', -- 2.43.0