* [PATCH v2 0/3] PBL: enable hash functions for Vendor Authorized Boot
@ 2026-09-30 8:28 Michael Tretter
2026-09-30 8:28 ` [PATCH v2 1/3] crypto: make sha384 and sha512 available in PBL Michael Tretter
` (2 more replies)
0 siblings, 3 replies; 4+ messages in thread
From: Michael Tretter @ 2026-09-30 8:28 UTC (permalink / raw)
To: Sascha Hauer, BAREBOX; +Cc: Michael Tretter
Altera's Vendor Authorized Boot (VAB) uses a sha384 hash for verifying
the second stage boot loader.
As preparation for adding VAB, make the sha384 and sha512 hash functions
available in the PBL.
Loading the second stage loader from flash and verifying the signature
will follow as separate patch series.
Signed-off-by: Michael Tretter <m.tretter@pengutronix.de>
---
Changes in v2:
- Rename sha256.c to sha.c
- Move one-shot helper from header to sha.c
- Link to v1: https://patch.msgid.link/20260928-crypto-pbl-sha384-v1-0-bc7095590123@pengutronix.de
---
Michael Tretter (3):
crypto: make sha384 and sha512 available in PBL
PBL: rename sha256.c to generic sha.c
PBL: add oneshot helper for sha384 and sha512
crypto/Makefile | 1 +
crypto/sha4.c | 11 ++++-----
include/crypto/pbl-sha.h | 13 +++++++++++
pbl/Makefile | 2 +-
pbl/sha.c | 58 ++++++++++++++++++++++++++++++++++++++++++++++++
pbl/sha256.c | 28 -----------------------
6 files changed, 79 insertions(+), 34 deletions(-)
---
base-commit: b3ce2a440f44b0166f9b9e9a3a80bbbfa52a0ef3
change-id: 20260928-crypto-pbl-sha384-e59cd7b4cd1d
Best regards,
--
Michael Tretter <m.tretter@pengutronix.de>
^ permalink raw reply [flat|nested] 4+ messages in thread
* [PATCH v2 1/3] crypto: make sha384 and sha512 available in PBL
2026-09-30 8:28 [PATCH v2 0/3] PBL: enable hash functions for Vendor Authorized Boot Michael Tretter
@ 2026-09-30 8:28 ` Michael Tretter
2026-09-30 8:28 ` [PATCH v2 2/3] PBL: rename sha256.c to generic sha.c Michael Tretter
2026-09-30 8:28 ` [PATCH v2 3/3] PBL: add oneshot helper for sha384 and sha512 Michael Tretter
2 siblings, 0 replies; 4+ messages in thread
From: Michael Tretter @ 2026-09-30 8:28 UTC (permalink / raw)
To: Sascha Hauer, BAREBOX; +Cc: Michael Tretter
On Agilex 5 with VAB (Vendor Authorized Boot), the second stage boot
loader is verified with a sha384 checksum.
Make the sha384 and sha512 functions available in the PBL to be able to
use these functions for vendor authorized boot.
Signed-off-by: Michael Tretter <m.tretter@pengutronix.de>
---
Changes in v2:
- None
---
crypto/Makefile | 1 +
crypto/sha4.c | 11 ++++++-----
include/crypto/pbl-sha.h | 7 +++++++
3 files changed, 14 insertions(+), 5 deletions(-)
diff --git a/crypto/Makefile b/crypto/Makefile
index 2ac023c3e2fd..6f745a883123 100644
--- a/crypto/Makefile
+++ b/crypto/Makefile
@@ -13,6 +13,7 @@ obj-$(CONFIG_DIGEST_SHA256_GENERIC) += sha2.o
pbl-y += sha2.o digest.o
obj-$(CONFIG_DIGEST_SHA384_GENERIC) += sha4.o
obj-$(CONFIG_DIGEST_SHA512_GENERIC) += sha4.o
+pbl-y += sha4.o
obj-pbl-y += memneq.o
obj-$(CONFIG_CRYPTO_PBKDF2) += pbkdf2.o
diff --git a/crypto/sha4.c b/crypto/sha4.c
index 8c94f5011dc2..c700c1a37756 100644
--- a/crypto/sha4.c
+++ b/crypto/sha4.c
@@ -20,6 +20,7 @@
#include <crypto/sha.h>
#include <crypto/internal.h>
+#include <crypto/pbl-sha.h>
static inline u64 Ch(u64 x, u64 y, u64 z)
{
@@ -126,7 +127,7 @@ sha512_transform(u64 *state, const u8 *input)
state[4] += e; state[5] += f; state[6] += g; state[7] += h;
}
-static int
+int
sha512_init(struct digest *desc)
{
struct sha512_state *sctx = digest_ctx(desc);
@@ -143,7 +144,7 @@ sha512_init(struct digest *desc)
return 0;
}
-static int sha384_init(struct digest *desc)
+int sha384_init(struct digest *desc)
{
struct sha512_state *sctx = digest_ctx(desc);
sctx->state[0] = SHA384_H0;
@@ -159,7 +160,7 @@ static int sha384_init(struct digest *desc)
return 0;
}
-static int sha512_update(struct digest *desc, const void *in,
+int sha512_update(struct digest *desc, const void *in,
unsigned long len)
{
struct sha512_state *sctx = digest_ctx(desc);
@@ -195,7 +196,7 @@ static int sha512_update(struct digest *desc, const void *in,
return 0;
}
-static int sha512_final(struct digest *desc, u8 *hash)
+int sha512_final(struct digest *desc, u8 *hash)
{
struct sha512_state *sctx = digest_ctx(desc);
static u8 padding[128] = { 0x80, };
@@ -226,7 +227,7 @@ static int sha512_final(struct digest *desc, u8 *hash)
return 0;
}
-static int sha384_final(struct digest *desc, u8 *hash)
+int sha384_final(struct digest *desc, u8 *hash)
{
u8 D[64];
diff --git a/include/crypto/pbl-sha.h b/include/crypto/pbl-sha.h
index 3ccd5151e1a6..dbfb79647462 100644
--- a/include/crypto/pbl-sha.h
+++ b/include/crypto/pbl-sha.h
@@ -24,4 +24,11 @@ static inline int pbl_sha256_ce(const void *buf, size_t len, u8 out[SHA256_DIGES
}
#endif
+int sha512_init(struct digest *desc);
+int sha512_update(struct digest *desc, const void *data, unsigned long len);
+int sha512_final(struct digest *desc, u8 *out);
+
+int sha384_init(struct digest *desc);
+int sha384_final(struct digest *desc, u8 *out);
+
#endif /* __PBL-SHA_H_ */
--
2.47.3
^ permalink raw reply [flat|nested] 4+ messages in thread
* [PATCH v2 2/3] PBL: rename sha256.c to generic sha.c
2026-09-30 8:28 [PATCH v2 0/3] PBL: enable hash functions for Vendor Authorized Boot Michael Tretter
2026-09-30 8:28 ` [PATCH v2 1/3] crypto: make sha384 and sha512 available in PBL Michael Tretter
@ 2026-09-30 8:28 ` Michael Tretter
2026-09-30 8:28 ` [PATCH v2 3/3] PBL: add oneshot helper for sha384 and sha512 Michael Tretter
2 siblings, 0 replies; 4+ messages in thread
From: Michael Tretter @ 2026-09-30 8:28 UTC (permalink / raw)
To: Sascha Hauer, BAREBOX; +Cc: Michael Tretter
Remove the references to SHA-256 to avoid name confusion when adding
support for SHA-512 and SHA-384.
Signed-off-by: Michael Tretter <m.tretter@pengutronix.de>
---
Changes in v2:
- New patch
---
pbl/Makefile | 2 +-
pbl/{sha256.c => sha.c} | 2 +-
2 files changed, 2 insertions(+), 2 deletions(-)
diff --git a/pbl/Makefile b/pbl/Makefile
index 9cbd4816402c..bef313df10cc 100644
--- a/pbl/Makefile
+++ b/pbl/Makefile
@@ -7,7 +7,7 @@ pbl-$(CONFIG_PBL_CONSTRUCTORS) += ctors.o
pbl-y += misc.o
pbl-y += string.o
pbl-y += malloc.o
-pbl-y += sha256.o
+pbl-y += sha.o
pbl-$(CONFIG_HAVE_IMAGE_COMPRESSION) += decomp.o
pbl-$(CONFIG_LIBFDT) += fdt.o
pbl-$(CONFIG_PBL_CONSOLE) += console.o
diff --git a/pbl/sha256.c b/pbl/sha.c
similarity index 87%
rename from pbl/sha256.c
rename to pbl/sha.c
index 04cc64a77d85..f08e554ea4c8 100644
--- a/pbl/sha256.c
+++ b/pbl/sha.c
@@ -1,6 +1,6 @@
// SPDX-License-Identifier: GPL-2.0-only
/*
- * pbl_sha256() - one-shot SHA-256 for the PBL, picking the best available
+ * pbl_sha*() - one-shot SHA functions for the PBL, picking the best available
* implementation.
*/
--
2.47.3
^ permalink raw reply [flat|nested] 4+ messages in thread
* [PATCH v2 3/3] PBL: add oneshot helper for sha384 and sha512
2026-09-30 8:28 [PATCH v2 0/3] PBL: enable hash functions for Vendor Authorized Boot Michael Tretter
2026-09-30 8:28 ` [PATCH v2 1/3] crypto: make sha384 and sha512 available in PBL Michael Tretter
2026-09-30 8:28 ` [PATCH v2 2/3] PBL: rename sha256.c to generic sha.c Michael Tretter
@ 2026-09-30 8:28 ` Michael Tretter
2 siblings, 0 replies; 4+ messages in thread
From: Michael Tretter @ 2026-09-30 8:28 UTC (permalink / raw)
To: Sascha Hauer, BAREBOX; +Cc: Michael Tretter
Similar to the oneshot helper for sha256, add helpers for sha384 and
sha512.
The helper functions don't use the ARMv8 Crypto Extensions, yet.
Signed-off-by: Michael Tretter <m.tretter@pengutronix.de>
---
Changes in v2:
- Move implementation from header to pbl/sha.c
---
include/crypto/pbl-sha.h | 6 ++++++
pbl/sha.c | 30 ++++++++++++++++++++++++++++++
2 files changed, 36 insertions(+)
diff --git a/include/crypto/pbl-sha.h b/include/crypto/pbl-sha.h
index dbfb79647462..dc5d5ccdadd6 100644
--- a/include/crypto/pbl-sha.h
+++ b/include/crypto/pbl-sha.h
@@ -28,7 +28,13 @@ int sha512_init(struct digest *desc);
int sha512_update(struct digest *desc, const void *data, unsigned long len);
int sha512_final(struct digest *desc, u8 *out);
+/* One-shot SHA-512 that picks the best transform available in the PBL. */
+void pbl_sha512(const void *buf, size_t len, u8 out[SHA512_DIGEST_SIZE]);
+
int sha384_init(struct digest *desc);
int sha384_final(struct digest *desc, u8 *out);
+/* One-shot SHA-384 that picks the best transform available in the PBL. */
+void pbl_sha384(const void *buf, size_t len, u8 out[SHA384_DIGEST_SIZE]);
+
#endif /* __PBL-SHA_H_ */
diff --git a/pbl/sha.c b/pbl/sha.c
index f08e554ea4c8..81ffab9123dc 100644
--- a/pbl/sha.c
+++ b/pbl/sha.c
@@ -26,3 +26,33 @@ void pbl_sha256(const void *buf, size_t len, u8 out[static SHA256_DIGEST_SIZE])
pbl_sha256_generic(buf, len, out);
}
+
+static void pbl_sha512_generic(const void *buf, size_t len, u8 *out)
+{
+ struct sha512_state state = { };
+ struct digest d = { .ctx = &state, .length = SHA512_DIGEST_SIZE };
+
+ sha512_init(&d);
+ sha512_update(&d, buf, len);
+ sha512_final(&d, out);
+}
+
+void pbl_sha512(const void *buf, size_t len, u8 out[static SHA512_DIGEST_SIZE])
+{
+ pbl_sha512_generic(buf, len, out);
+}
+
+static void pbl_sha384_generic(const void *buf, size_t len, u8 *out)
+{
+ struct sha512_state state = { };
+ struct digest d = { .ctx = &state, .length = SHA384_DIGEST_SIZE };
+
+ sha384_init(&d);
+ sha512_update(&d, buf, len);
+ sha384_final(&d, out);
+}
+
+void pbl_sha384(const void *buf, size_t len, u8 out[static SHA384_DIGEST_SIZE])
+{
+ pbl_sha384_generic(buf, len, out);
+}
--
2.47.3
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-09-30 8:30 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-30 8:28 [PATCH v2 0/3] PBL: enable hash functions for Vendor Authorized Boot Michael Tretter
2026-09-30 8:28 ` [PATCH v2 1/3] crypto: make sha384 and sha512 available in PBL Michael Tretter
2026-09-30 8:28 ` [PATCH v2 2/3] PBL: rename sha256.c to generic sha.c Michael Tretter
2026-09-30 8:28 ` [PATCH v2 3/3] PBL: add oneshot helper for sha384 and sha512 Michael Tretter
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox