From: Herbert Xu <herbert@gondor.apana.org.au>
To: "Ousherovitch, Alex" <aousherovitch@rambus.com>
Cc: Albert Ou <aou@eecs.berkeley.edu>,
Conor Dooley <conor+dt@kernel.org>,
"David S. Miller" <davem@davemloft.net>,
Jonathan Corbet <corbet@lwn.net>,
Krzysztof Kozlowski <krzk+dt@kernel.org>,
Palmer Dabbelt <palmer@dabbelt.com>,
Paul Walmsley <pjw@kernel.org>, Rob Herring <robh@kernel.org>,
"Krishnamoorthy, Saravanakrishnan" <skrishnamoorthy@rambus.com>,
Shuah Khan <shuah@kernel.org>, Alexandre Ghiti <alex@ghiti.fr>,
"devicetree@vger.kernel.org" <devicetree@vger.kernel.org>,
"Wittenauer, Joel" <Joel.Wittenauer@cryptography.com>,
"linux-api@vger.kernel.org" <linux-api@vger.kernel.org>,
"linux-crypto@vger.kernel.org" <linux-crypto@vger.kernel.org>,
"linux-doc@vger.kernel.org" <linux-doc@vger.kernel.org>,
"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
"linux-kselftest@vger.kernel.org"
<linux-kselftest@vger.kernel.org>,
"linux-riscv@lists.infradead.org"
<linux-riscv@lists.infradead.org>,
Shuah Khan <skhan@linuxfoundation.org>,
"Nguyen, Thi" <thin@rambus.com>
Subject: Re: [PATCH v5 04/19] crypto: cmh - add SHA-2/SHA-3/SHAKE ahash
Date: Mon, 28 Sep 2026 15:17:17 +1000 [thread overview]
Message-ID: <arn4XYwPYt6i2k7d@gondor.apana.org.au> (raw)
In-Reply-To: <LV8PR04MB9006374FD8621EBF3C7E7F6CD7822@LV8PR04MB9006.namprd04.prod.outlook.com>
On Wed, Sep 23, 2026 at 08:50:55PM +0000, Ousherovitch, Alex wrote:
>
> - shake128/256, cshake, kmac and poly1305 have no matching provider
> registered in this tree, so the allocation fails and the transform can't
> be created at all. NO_FALLBACK is required to instantiate them.
Hang on, if an algorithm isn't even implemented in generic C for
the Crypto API, then it should not be implemented by a driver
either.
The reason these algorithms aren't in the Crypto API is because
they have no users.
So please drop them.
> - sha2, sha3 and sm3 do have a software provider, so the transform loads,
> but the auto-fallback can't stand in for the hardware on the streaming
> path: our exported state is the opaque HW save/restore checkpoint, not
> the canonical state, so a multi-part export/import round-trip through the
> fallback misinterprets it (and for SHA-2/SHA-3 the statesize exceeds
> HASH_MAX_STATESIZE, so ahash_do_req_chain() returns -ENOSYS). A one-shot
> digest could still use the software provider, but a fallback that only
> covers one-shot and corrupts streaming isn't usable.
Sorry, that is not supported by our API. If you cannot export the
hash state in a compatible format, then you will have to switch over
to fallbacks and only support digest operations.
Please also elaborate what you mean by opaque checkpoint, does it
contain the entire hash state or not?
Cheers,
--
Email: Herbert Xu <herbert@gondor.apana.org.au>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt
next prev parent reply other threads:[~2026-09-28 5:17 UTC|newest]
Thread overview: 26+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-17 22:59 [PATCH v5 00/19] crypto: cmh - add Rambus CryptoManager Hub driver Alex Ousherovitch
2026-09-17 22:59 ` [PATCH v5 01/19] dt-bindings: crypto: add Rambus CryptoManager Hub Alex Ousherovitch
2026-09-28 18:18 ` Rob Herring
2026-09-17 22:59 ` [PATCH v5 02/19] crypto: cmh - add core platform driver Alex Ousherovitch
2026-09-17 22:59 ` [PATCH v5 03/19] crypto: cmh - add key provisioning and management Alex Ousherovitch
2026-09-17 22:59 ` [PATCH v5 04/19] crypto: cmh - add SHA-2/SHA-3/SHAKE ahash Alex Ousherovitch
2026-09-23 5:47 ` Herbert Xu
2026-09-23 20:50 ` Ousherovitch, Alex
2026-09-28 5:17 ` Herbert Xu [this message]
2026-09-17 22:59 ` [PATCH v5 05/19] crypto: cmh - add HMAC ahash Alex Ousherovitch
2026-09-17 22:59 ` [PATCH v5 06/19] crypto: cmh - add CSHAKE/KMAC ahash Alex Ousherovitch
2026-09-17 22:59 ` [PATCH v5 07/19] crypto: cmh - add SM3 ahash Alex Ousherovitch
2026-09-17 22:59 ` [PATCH v5 08/19] crypto: cmh - add AES skcipher/aead/cmac Alex Ousherovitch
2026-09-17 22:59 ` [PATCH v5 09/19] crypto: cmh - add SM4 skcipher/aead/cmac/xcbc Alex Ousherovitch
2026-09-17 22:59 ` [PATCH v5 10/19] crypto: cmh - add ChaCha20-Poly1305 Alex Ousherovitch
2026-09-17 22:59 ` [PATCH v5 11/19] crypto: cmh - add DRBG hwrng Alex Ousherovitch
2026-09-17 22:59 ` [PATCH v5 12/19] crypto: cmh - add RSA akcipher Alex Ousherovitch
2026-09-17 22:59 ` [PATCH v5 13/19] crypto: cmh - add ECDSA/SM2 sig Alex Ousherovitch
2026-09-17 22:59 ` [PATCH v5 14/19] crypto: cmh - add ECDH/X25519 kpp Alex Ousherovitch
2026-09-17 22:59 ` [PATCH v5 15/19] crypto: cmh - add ML-KEM/ML-DSA (QSE) Alex Ousherovitch
2026-09-17 22:59 ` [PATCH v5 16/19] crypto: cmh - add SLH-DSA/LMS/XMSS (HCQ) Alex Ousherovitch
2026-09-17 22:59 ` [PATCH v5 17/19] Documentation: ioctl: add CMH ioctl documentation and register 'J' Alex Ousherovitch
2026-09-17 22:59 ` [PATCH v5 18/19] selftests: crypto: cmh - add kselftest for management ioctl Alex Ousherovitch
2026-09-17 22:59 ` [PATCH v5 19/19] MAINTAINERS: add Rambus CryptoManager Hub (CMH) Alex Ousherovitch
2026-09-23 5:48 ` [PATCH v5 00/19] crypto: cmh - add Rambus CryptoManager Hub driver Herbert Xu
2026-09-23 17:42 ` Ousherovitch, Alex
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=arn4XYwPYt6i2k7d@gondor.apana.org.au \
--to=herbert@gondor.apana.org.au \
--cc=Joel.Wittenauer@cryptography.com \
--cc=alex@ghiti.fr \
--cc=aou@eecs.berkeley.edu \
--cc=aousherovitch@rambus.com \
--cc=conor+dt@kernel.org \
--cc=corbet@lwn.net \
--cc=davem@davemloft.net \
--cc=devicetree@vger.kernel.org \
--cc=krzk+dt@kernel.org \
--cc=linux-api@vger.kernel.org \
--cc=linux-crypto@vger.kernel.org \
--cc=linux-doc@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-kselftest@vger.kernel.org \
--cc=linux-riscv@lists.infradead.org \
--cc=palmer@dabbelt.com \
--cc=pjw@kernel.org \
--cc=robh@kernel.org \
--cc=shuah@kernel.org \
--cc=skhan@linuxfoundation.org \
--cc=skrishnamoorthy@rambus.com \
--cc=thin@rambus.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®