mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH v7 00/12] crypto: qce - Fix crypto self-test failures
@ 2026-09-10 13:00 Bartosz Golaszewski
  2026-09-10 13:00 ` [PATCH v7 01/12] crypto: qce - Fix HMAC self-test failures for empty messages Bartosz Golaszewski
                   ` (12 more replies)
  0 siblings, 13 replies; 18+ messages in thread
From: Bartosz Golaszewski @ 2026-09-10 13:00 UTC (permalink / raw)
  To: Thara Gopinath, Herbert Xu, David S. Miller, Stanimir Varbanov,
	Eneas U de Queiroz, Kuldeep Singh, Eric Biggers,
	Demi Marie Obenour, Bjorn Andersson, Konrad Dybcio
  Cc: linux-crypto, linux-arm-msm, linux-kernel, brgl,
	Bartosz Golaszewski, stable

This iteration - in addition to the previous fixes - proposes to split
the QCE driver into a core part necessary to bind to the QCE DT node and
enable runtime power management in order to allow to drop the
interconnect votes, and the crypto part registering the crypto
algorithms. The core module is then enabled in arm64 defconfig while the
crypto part stays disabled by default.

The QCE hardware crypto engine has several limitations that cause it to
produce incorrect results or stall on certain inputs. This series fixes
several bugs and adds workaround allowing the deiver to pass crypto
self-tests.

The failures addressed are:

- HMAC self-test failures for empty messages
- AES-XTS returning success on zero-length input (should be -EINVAL)
- AES-CTR: partial final block causes the engine to stall, output IV
  derivation was incorrect
- AES-XTS with key1 == key2 is not supported by the CE
- AES-CCM: partial final block and fragmented payload both stall the
  engine

All fixes were tested on an SM8650 QRD board with
CONFIG_CRYPTO_SELFTESTS=y and CONFIG_CRYPTO_SELFTESTS_FULL=y.

Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
---
Changes in v7:
- Add follow-up changes converting the QCE crypto driver to auxiliary
  bus, adding the core QCE driver under drivers/soc/ registering the
  auxiliary device and removing the BROKEN Kconfig label
- Link to v6: https://patch.msgid.link/20260717-qce-fix-self-tests-v6-0-455775fe5f6c@oss.qualcomm.com

Changes in v6:
- Handle all zero-length HMAC finalizations (like imported state with
  data already hashed), not only the genuinely empty message case
- Add an additional patch addressing the fragmented skcipher payload
  issue
- Link to v5: https://patch.msgid.link/20260706-qce-fix-self-tests-v5-0-86f461ff1829@oss.qualcomm.com

Changes in v5:
- Dropped patch 1/8 that's already queued
- Use the pre-allocated fallback ahash for HMAC transforms (Herbert)
- Link to v4: https://patch.msgid.link/20260622-qce-fix-self-tests-v4-0-4f82ffa716c6@oss.qualcomm.com

Changes in v4:
- Remove remaining ECB and DES3 bits
- Pick up tags
- Link to v3: https://patch.msgid.link/20260617-qce-fix-self-tests-v3-0-ecc2b4dedcfd@oss.qualcomm.com

Changes in v3:
- Remove even more algorithms and dead code in patch 1/8
- Link to v2: https://patch.msgid.link/20260615-qce-fix-self-tests-v2-0-dc911f1aad42@oss.qualcomm.com

Changes in v2:
- Add fixes for the full suite of crypto self-tests
- Add Fixes and Cc tags
- Link to v1: https://patch.msgid.link/20260610-qce_selftest_fix-v1-0-1b0504783a46@oss.qualcomm.com/

---
Bartosz Golaszewski (10):
      crypto: qce - Fix HMAC self-test failures for empty messages
      crypto: qce - Reject empty messages for AES-XTS
      crypto: qce - Use a fallback for AES-CTR with a partial final block
      crypto: qce - Use fallback for fragmented skcipher payloads
      crypto: qce - Use a fallback for CCM with a partial final block
      crypto: qce - Use fallback for CCM with a fragmented payload
      crypto: qce - remove the BROKEN label
      crypto: qce - convert to auxiliary bus
      soc: qcom: add core driver for the Qualcomm Crypto Engine
      arm64: defconfig: enable the Qualcomm Crypto Engine core driver

Kuldeep Singh (2):
      crypto: qce - Fix CTR-AES for partial block requests
      crypto: qce - Fix xts-aes-qce for weak keys

 arch/arm64/configs/defconfig  |  1 +
 drivers/crypto/Kconfig        |  4 +-
 drivers/crypto/qce/aead.c     | 44 ++++++++++++++++----
 drivers/crypto/qce/cipher.h   |  1 +
 drivers/crypto/qce/common.h   |  1 -
 drivers/crypto/qce/core.c     | 93 +++++++++++++++++++------------------------
 drivers/crypto/qce/core.h     |  5 ++-
 drivers/crypto/qce/sha.c      | 70 ++++++++++++++++++++++----------
 drivers/crypto/qce/skcipher.c | 62 ++++++++++++++++++++++-------
 drivers/soc/qcom/Kconfig      | 11 +++++
 drivers/soc/qcom/Makefile     |  1 +
 drivers/soc/qcom/qce-core.c   | 87 ++++++++++++++++++++++++++++++++++++++++
 12 files changed, 283 insertions(+), 97 deletions(-)
---
base-commit: c0b0cbecdd2bdd74c9e76409e6ae67b3e65d737a
change-id: 20260610-qce-fix-self-tests-492ffd2ef955

Best regards,
-- 
Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>


^ permalink raw reply	[flat|nested] 18+ messages in thread

end of thread, other threads:[~2026-09-11 18:57 UTC | newest]

Thread overview: 18+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-10 13:00 [PATCH v7 00/12] crypto: qce - Fix crypto self-test failures Bartosz Golaszewski
2026-09-10 13:00 ` [PATCH v7 01/12] crypto: qce - Fix HMAC self-test failures for empty messages Bartosz Golaszewski
2026-09-10 13:00 ` [PATCH v7 02/12] crypto: qce - Reject empty messages for AES-XTS Bartosz Golaszewski
2026-09-10 13:00 ` [PATCH v7 03/12] crypto: qce - Fix CTR-AES for partial block requests Bartosz Golaszewski
2026-09-10 13:00 ` [PATCH v7 04/12] crypto: qce - Use a fallback for AES-CTR with a partial final block Bartosz Golaszewski
2026-09-10 13:00 ` [PATCH v7 05/12] crypto: qce - Use fallback for fragmented skcipher payloads Bartosz Golaszewski
2026-09-10 13:00 ` [PATCH v7 06/12] crypto: qce - Fix xts-aes-qce for weak keys Bartosz Golaszewski
2026-09-10 13:00 ` [PATCH v7 07/12] crypto: qce - Use a fallback for CCM with a partial final block Bartosz Golaszewski
2026-09-10 13:00 ` [PATCH v7 08/12] crypto: qce - Use fallback for CCM with a fragmented payload Bartosz Golaszewski
2026-09-10 13:00 ` [PATCH v7 09/12] crypto: qce - remove the BROKEN label Bartosz Golaszewski
2026-09-10 14:31   ` Eric Biggers
2026-09-11 11:14     ` Bartosz Golaszewski
2026-09-11 18:35       ` Demi Marie Obenour
2026-09-10 13:00 ` [PATCH v7 10/12] crypto: qce - convert to auxiliary bus Bartosz Golaszewski
2026-09-10 13:00 ` [PATCH v7 11/12] soc: qcom: add core driver for the Qualcomm Crypto Engine Bartosz Golaszewski
2026-09-11 18:57   ` Uwe Kleine-König
2026-09-10 13:00 ` [PATCH v7 12/12] arm64: defconfig: enable the Qualcomm Crypto Engine core driver Bartosz Golaszewski
2026-09-11 18:34 ` [PATCH v7 00/12] crypto: qce - Fix crypto self-test failures Demi Marie Obenour

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®