From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-dl1-f45.google.com (mail-dl1-f45.google.com [74.125.82.45]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6F8561E260C for ; Thu, 28 May 2026 03:22:41 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.82.45 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779938563; cv=none; b=VallYdJeRqgn2f+sOPf01bd/z+dUenFR0+S93ylBJp5rk+bVp40oSRnfZBsbMDBDnhW4fJxZAFOZ+ZAhRG5AUTqgj2I5Fw/6glAx0cK6LRsxNE2y8erIBIcuPQxRiacTdEoLiKG9e4hwX66Kg7qj+YqbW/SXB9gvg4BGadK1/YU= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779938563; c=relaxed/simple; bh=vWJnK3diqFBH9eqDvCJbWUB6NnB5rmR1E8QNfkVIIuo=; h=From:To:Cc:Subject:Date:Message-Id:MIME-Version; b=nhAKoduDbd5KfayU1F0zHn4FHGaxLiH9RtixSFzMk4GFIWtQODp4IiS9HAfRRcOoaB3WBPVgHE2znvBwSwuQeFbETYUCznzpm3bkaTAOvDdM3jXUitIVbiq/A2XEzlCEplCEqeEQD8o8lDv6T7vbVnpfvNJbEWdKZr1l40ZgfCY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=Zvgc2otL; arc=none smtp.client-ip=74.125.82.45 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="Zvgc2otL" Received: by mail-dl1-f45.google.com with SMTP id a92af1059eb24-136b46c3540so5097003c88.1 for ; Wed, 27 May 2026 20:22:41 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1779938560; x=1780543360; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=/hEQ9PkY1ueCi/OLNjUH4FCjzB8j6L3rLuWkZunHiu4=; b=Zvgc2otLcDha6cpWfADATeyZi3Zm+ryei9XTnY+z9Y+SwZPszf7jPkziHKNw6qBxgF YoTLtupJ47GhqWlVkGPxk0qghR0+mkWtFLgzcE5Ex7klmznjF/hJXiwZZUn2xZLucnuY BhjheFBsAcNmtAXVhcJtE2CKO3VcI6BZgenkKL54e8iWig4RUcn3ev3G+an5cNGvsgdl uo7rrfJnqpEVzrUQ3OuRXpj6PHvsLxzYv0+frxGk93+OLUd6ILX/U2l2OaV2yHoILS3k dYOugQEsfumRVonod1IDU1HHtBvqv8w9wkw1gd1IRM1FaSzrqRdS1YKK0q0t/wO1ZyyJ UYdw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779938560; x=1780543360; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=/hEQ9PkY1ueCi/OLNjUH4FCjzB8j6L3rLuWkZunHiu4=; b=rIFS5LdjVgzXSicMpFBwX3taMWB4yZpOvRhhcqBF8UquzsptpFyhTKRMDJONESJk2b dFyFD18dDHcWP1JnSoCBKnwZQLxy5lC4gLr33dVGaW/2FH6cROPp203m1XQVR/vfxD9c L70XIXEZRthNGHFvrLGCxy1qElPf20HeQynydn3+wL62SMvVBd4ARPiCX+o/S05tVvas L+WEBhbZSU+2MemuUa865zbVg1E/QNds9c5bPSvt+dheR8US1/TJNEq+IrcTtNMFLZWB K9gAu/mDt7027DwzPuAMW/+BbsJXtn9qPtZ9NncWhjrDENNC+EmSJ+r/bMsd9OzLOnT8 zz5w== X-Forwarded-Encrypted: i=1; AFNElJ9R29MeRnAgzc5wTpH6Q/uTWQXK+nVYnt1JyTNGWZQ2agUqDj2bYJBBl8/hQQCp/y2DkNdLUPcim+cGGTk=@vger.kernel.org X-Gm-Message-State: AOJu0Ywg/eTcefZJTJtf12mNfCQ3acGKQv2W4TTSK9oMmBYpAUUUmM2u dnfi/ONLGiMjMW6qer9Uxi3LcW2dIOZmM2Woe2+uaQxPgfjINUap6Iea X-Gm-Gg: Acq92OF5V5s8zYngdzsckat2MDqyYAaEJo+l5T9R8HKCfOuuuAWAmsKx9L6YlZ2VcfM TXchydOs4FIHhKcoR9TJttMYeSGML6Cfh309fortxf0Cp5N529uaGAaHidKS2mjX+0ylSjJ8t5W 4IbMsLnGHF5OPYKYL5yKpTxMoFwRf6HInkHz/onf30gptzHAel3F3D09EOtiMmcobF0ZU0/Wbwu D0EXy52V4uuFSHv6XG9e7veQfjWAckD4aQLok+yHYTICu190/nJTwNJnNTCm8wrsFyDdr02NeO2 wS8/AQTOMHp41PKLvv8S9djXGtqDZgMIhZbNlEahvsW92TS+82v6GKoPC/7puCQKbk5XIAffnwd XHSfIiwz+cU8Sjah5qwINQRswQIfqEsn/EF7ovzNEnLzXE2zefGNNyqotCMKX9IzGrmTsR0mgnx 2pQrcCOvHQNY7UlzBppLf0etbJTbIvagZYlelOzaOx3n2wYRebfwC+tcTD2go= X-Received: by 2002:a05:701b:2411:b0:12a:6c4b:9cf0 with SMTP id a92af1059eb24-1365f70f902mr6031946c88.3.1779938560450; Wed, 27 May 2026 20:22:40 -0700 (PDT) Received: from ewan-server.tailb932da.ts.net ([154.26.185.247]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-1366aa88c7esm11650007c88.10.2026.05.27.20.22.37 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 27 May 2026 20:22:40 -0700 (PDT) From: Ewan Hai To: seanjc@google.com, pbonzini@redhat.com, tglx@kernel.org, mingo@redhat.com, bp@alien8.de, dave.hansen@linux.intel.com, x86@kernel.org, hpa@zytor.com, kvm@vger.kernel.org, linux-kernel@vger.kernel.org Cc: binbin.wu@linux.intel.com, ewanhai@zhaoxin.com, cobechen@zhaoxin.com, tonywwang@zhaoxin.com Subject: [PATCH v2 0/5] KVM: x86: Expose Zhaoxin CPUID 0xC0000001 EDX cryptographic features Date: Thu, 28 May 2026 11:22:29 +0800 Message-Id: <20260528032234.1322565-1-ewandevelop@gmail.com> X-Mailer: git-send-email 2.34.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit This series exposes five groups of Zhaoxin-specific CPUID 0xC0000001 EDX feature bits to KVM guests. Each group corresponds to a category of unprivileged cryptographic or RNG instructions that have been present in Zhaoxin processors but not yet advertised by KVM. All instructions covered here are unprivileged (no CPL restriction) and available in all CPU modes (real / V86 / compat / protected / long), with no associated MSR control. Each feature is reported as a (X, X_EN) pair where the two bits are redundant by hardware design (set or cleared together), and both are CPUID-level reporting bits requiring no KVM emulation. The five feature groups: 1. SM2 (bits 0, 1): SM2 elliptic-curve public-key cryptography algorithm per GM/T 0003-2012. Used for key generation, encryption/decryption, digital signatures, and key exchange in Chinese cryptographic standards. 2. CCS (bits 4, 5): SM3 hash algorithm per GM/T 0004-2012 and SM4 block cipher per GM/T 0002-2012 (supports ECB / CBC / CFB / OFB / CTR plus CBC-MAC / CFB-MAC). Foundational primitives for Chinese cryptographic protocols. 3. RNG2 (bits 22, 23): Second-generation hardware RNG exposed via the REP XRNG2 instruction. Two on-die RNG sources selectable per call, with raw and post-processed output modes. Provides high-quality entropy for cryptographic operations. 4. PHE2 (bits 25, 26): SHA-384 and SHA-512 hardware acceleration per FIPS 180-3, exposed via REP XSHA384 and REP XSHA512. Used by TLS, SSH, file integrity, and signature schemes. 5. RSA (bits 27, 28): Big-number modular exponentiation (REP XMODEXP, A^B mod M) and modular multiplication (REP MONTMUL2, A*B mod M), supporting operand sizes from 256 to 32768 bits. Used for RSA and related public-key operations. References: The instruction encodings, control-word formats, and per-feature semantics referenced in the individual patches are documented in: - GMI Instruction Set Reference (SM2 / SM3 / SM4) - PadLock Instruction Reference (XRNG2 / XSHA384 / XSHA512 / XMODEXP / MONTMUL2) Both available from https://kib.kiev.ua/x86docs/Zhaoxin/ Changes since v1: - Move the X86_FEATURE_xx definitions from arch/x86/kvm/reverse_cpuid.h into arch/x86/include/asm/cpufeatures.h, filling the unused bit positions in word 5 (which is reserved for CPUID 0xC0000001 EDX), per Sean's review feedback. - Tighten wording in each commit message: "user-mode" -> "unprivileged (no CPL restriction)", since the instructions execute at any CPL. v1: https://lore.kernel.org/all/20260513124846.1622462-1-ewandevelop@gmail.com/ Ewan Hai (5): KVM: x86: Expose Zhaoxin SM2 CPUID feature KVM: x86: Expose Zhaoxin CCS (SM3 + SM4) CPUID feature KVM: x86: Expose Zhaoxin RNG2 CPUID feature KVM: x86: Expose Zhaoxin PHE2 CPUID feature KVM: x86: Expose Zhaoxin RSA CPUID feature arch/x86/include/asm/cpufeatures.h | 10 ++++++++++ arch/x86/kvm/cpuid.c | 10 ++++++++++ 2 files changed, 20 insertions(+) base-commit: 50897c955902c93ae71c38698abb910525ebdc89 -- 2.34.1