* [PATCH 0/2] PBL: enable hash functions for Vendor Authorized Boot
@ 2026-09-28 12:25 Michael Tretter
2026-09-28 12:25 ` [PATCH 1/2] crypto: make sha384 and sha512 available in PBL Michael Tretter
2026-09-28 12:25 ` [PATCH 2/2] PBL: add oneshot helper for sha384 and sha512 Michael Tretter
0 siblings, 2 replies; 6+ messages in thread
From: Michael Tretter @ 2026-09-28 12:25 UTC (permalink / raw)
To: Sascha Hauer, BAREBOX; +Cc: Michael Tretter
Altera's Vendor Authorized Boot (VAB) uses a sha384 hash for verifying
the second stage boot loader.
As preparation for adding VAB, make the sha384 and sha512 hash functions
available in the PBL.
Loading the second stage loader from flash and verifying the signature
will follow as separate patch series.
Signed-off-by: Michael Tretter <m.tretter@pengutronix.de>
---
Michael Tretter (2):
crypto: make sha384 and sha512 available in PBL
PBL: add oneshot helper for sha384 and sha512
crypto/Makefile | 1 +
crypto/sha4.c | 11 ++++++-----
include/crypto/pbl-sha.h | 29 +++++++++++++++++++++++++++++
3 files changed, 36 insertions(+), 5 deletions(-)
---
base-commit: 4a752d2303440195e12ed1a4e642b0be5b450b8e
change-id: 20260928-crypto-pbl-sha384-e59cd7b4cd1d
Best regards,
--
Michael Tretter <m.tretter@pengutronix.de>
^ permalink raw reply [flat|nested] 6+ messages in thread* [PATCH 1/2] crypto: make sha384 and sha512 available in PBL 2026-09-28 12:25 [PATCH 0/2] PBL: enable hash functions for Vendor Authorized Boot Michael Tretter @ 2026-09-28 12:25 ` Michael Tretter 2026-09-28 12:25 ` [PATCH 2/2] PBL: add oneshot helper for sha384 and sha512 Michael Tretter 1 sibling, 0 replies; 6+ messages in thread From: Michael Tretter @ 2026-09-28 12:25 UTC (permalink / raw) To: Sascha Hauer, BAREBOX; +Cc: Michael Tretter On Agilex 5 with VAB (Vendor Authorized Boot), the second stage boot loader is verified with a sha384 checksum. Make the sha384 and sha512 functions available in the PBL to be able to use these functions for vendor authorized boot. Signed-off-by: Michael Tretter <m.tretter@pengutronix.de> --- crypto/Makefile | 1 + crypto/sha4.c | 11 ++++++----- include/crypto/pbl-sha.h | 7 +++++++ 3 files changed, 14 insertions(+), 5 deletions(-) diff --git a/crypto/Makefile b/crypto/Makefile index 2ac023c3e2fd..6f745a883123 100644 --- a/crypto/Makefile +++ b/crypto/Makefile @@ -13,6 +13,7 @@ obj-$(CONFIG_DIGEST_SHA256_GENERIC) += sha2.o pbl-y += sha2.o digest.o obj-$(CONFIG_DIGEST_SHA384_GENERIC) += sha4.o obj-$(CONFIG_DIGEST_SHA512_GENERIC) += sha4.o +pbl-y += sha4.o obj-pbl-y += memneq.o obj-$(CONFIG_CRYPTO_PBKDF2) += pbkdf2.o diff --git a/crypto/sha4.c b/crypto/sha4.c index 8c94f5011dc2..c700c1a37756 100644 --- a/crypto/sha4.c +++ b/crypto/sha4.c @@ -20,6 +20,7 @@ #include <crypto/sha.h> #include <crypto/internal.h> +#include <crypto/pbl-sha.h> static inline u64 Ch(u64 x, u64 y, u64 z) { @@ -126,7 +127,7 @@ sha512_transform(u64 *state, const u8 *input) state[4] += e; state[5] += f; state[6] += g; state[7] += h; } -static int +int sha512_init(struct digest *desc) { struct sha512_state *sctx = digest_ctx(desc); @@ -143,7 +144,7 @@ sha512_init(struct digest *desc) return 0; } -static int sha384_init(struct digest *desc) +int sha384_init(struct digest *desc) { struct sha512_state *sctx = digest_ctx(desc); sctx->state[0] = SHA384_H0; @@ -159,7 +160,7 @@ static int sha384_init(struct digest *desc) return 0; } -static int sha512_update(struct digest *desc, const void *in, +int sha512_update(struct digest *desc, const void *in, unsigned long len) { struct sha512_state *sctx = digest_ctx(desc); @@ -195,7 +196,7 @@ static int sha512_update(struct digest *desc, const void *in, return 0; } -static int sha512_final(struct digest *desc, u8 *hash) +int sha512_final(struct digest *desc, u8 *hash) { struct sha512_state *sctx = digest_ctx(desc); static u8 padding[128] = { 0x80, }; @@ -226,7 +227,7 @@ static int sha512_final(struct digest *desc, u8 *hash) return 0; } -static int sha384_final(struct digest *desc, u8 *hash) +int sha384_final(struct digest *desc, u8 *hash) { u8 D[64]; diff --git a/include/crypto/pbl-sha.h b/include/crypto/pbl-sha.h index 3ccd5151e1a6..dbfb79647462 100644 --- a/include/crypto/pbl-sha.h +++ b/include/crypto/pbl-sha.h @@ -24,4 +24,11 @@ static inline int pbl_sha256_ce(const void *buf, size_t len, u8 out[SHA256_DIGES } #endif +int sha512_init(struct digest *desc); +int sha512_update(struct digest *desc, const void *data, unsigned long len); +int sha512_final(struct digest *desc, u8 *out); + +int sha384_init(struct digest *desc); +int sha384_final(struct digest *desc, u8 *out); + #endif /* __PBL-SHA_H_ */ -- 2.47.3 ^ permalink raw reply [flat|nested] 6+ messages in thread
* [PATCH 2/2] PBL: add oneshot helper for sha384 and sha512 2026-09-28 12:25 [PATCH 0/2] PBL: enable hash functions for Vendor Authorized Boot Michael Tretter 2026-09-28 12:25 ` [PATCH 1/2] crypto: make sha384 and sha512 available in PBL Michael Tretter @ 2026-09-28 12:25 ` Michael Tretter 2026-09-29 7:08 ` Sascha Hauer 1 sibling, 1 reply; 6+ messages in thread From: Michael Tretter @ 2026-09-28 12:25 UTC (permalink / raw) To: Sascha Hauer, BAREBOX; +Cc: Michael Tretter Similar to the oneshot helper for sha256, add helpers for sha384 and sha512. The helper functions don't use the ARMv8 Crypto Extensions, yet. Signed-off-by: Michael Tretter <m.tretter@pengutronix.de> --- include/crypto/pbl-sha.h | 22 ++++++++++++++++++++++ 1 file changed, 22 insertions(+) diff --git a/include/crypto/pbl-sha.h b/include/crypto/pbl-sha.h index dbfb79647462..8a20e0a2b84b 100644 --- a/include/crypto/pbl-sha.h +++ b/include/crypto/pbl-sha.h @@ -28,7 +28,29 @@ int sha512_init(struct digest *desc); int sha512_update(struct digest *desc, const void *data, unsigned long len); int sha512_final(struct digest *desc, u8 *out); +static inline void pbl_sha512(const void *buf, size_t len, + u8 out[SHA512_DIGEST_SIZE]) +{ + struct sha512_state state = { }; + struct digest d = { .ctx = &state, .length = SHA512_DIGEST_SIZE }; + + sha512_init(&d); + sha512_update(&d, buf, len); + sha512_final(&d, out); +} + int sha384_init(struct digest *desc); int sha384_final(struct digest *desc, u8 *out); +static inline void pbl_sha384(const void *buf, size_t len, + u8 out[SHA384_DIGEST_SIZE]) +{ + struct sha512_state state = { }; + struct digest d = { .ctx = &state, .length = SHA384_DIGEST_SIZE }; + + sha384_init(&d); + sha512_update(&d, buf, len); + sha384_final(&d, out); +} + #endif /* __PBL-SHA_H_ */ -- 2.47.3 ^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [PATCH 2/2] PBL: add oneshot helper for sha384 and sha512 2026-09-28 12:25 ` [PATCH 2/2] PBL: add oneshot helper for sha384 and sha512 Michael Tretter @ 2026-09-29 7:08 ` Sascha Hauer 2026-09-29 8:36 ` Michael Tretter 0 siblings, 1 reply; 6+ messages in thread From: Sascha Hauer @ 2026-09-29 7:08 UTC (permalink / raw) To: Michael Tretter; +Cc: BAREBOX, Michael Tretter On 2026-09-28 14:25, Michael Tretter wrote: > Similar to the oneshot helper for sha256, add helpers for sha384 and > sha512. > > The helper functions don't use the ARMv8 Crypto Extensions, yet. > > Signed-off-by: Michael Tretter <m.tretter@pengutronix.de> > --- > include/crypto/pbl-sha.h | 22 ++++++++++++++++++++++ > 1 file changed, 22 insertions(+) > > diff --git a/include/crypto/pbl-sha.h b/include/crypto/pbl-sha.h > index dbfb79647462..8a20e0a2b84b 100644 > --- a/include/crypto/pbl-sha.h > +++ b/include/crypto/pbl-sha.h > @@ -28,7 +28,29 @@ int sha512_init(struct digest *desc); > int sha512_update(struct digest *desc, const void *data, unsigned long len); > int sha512_final(struct digest *desc, u8 *out); > > +static inline void pbl_sha512(const void *buf, size_t len, > + u8 out[SHA512_DIGEST_SIZE]) > +{ > + struct sha512_state state = { }; > + struct digest d = { .ctx = &state, .length = SHA512_DIGEST_SIZE }; > + > + sha512_init(&d); > + sha512_update(&d, buf, len); > + sha512_final(&d, out); > +} Instead of making these static inline functions, could you follow the template in pbl/sha256.c to give future developers an idea how for example the crypto extensions should be implemented? Sascha -- Pengutronix e.K. | | Steuerwalder Str. 21 | http://www.pengutronix.de/ | 31137 Hildesheim, Germany | Phone: +49-5121-206917-0 | Amtsgericht Hildesheim, HRA 2686 | Fax: +49-5121-206917-5555 | ^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [PATCH 2/2] PBL: add oneshot helper for sha384 and sha512 2026-09-29 7:08 ` Sascha Hauer @ 2026-09-29 8:36 ` Michael Tretter 2026-09-29 11:09 ` Sascha Hauer 0 siblings, 1 reply; 6+ messages in thread From: Michael Tretter @ 2026-09-29 8:36 UTC (permalink / raw) To: Sascha Hauer; +Cc: BAREBOX On Tue, 29 Sep 2026 07:08:56 +0000, Sascha Hauer wrote: > On 2026-09-28 14:25, Michael Tretter wrote: > > Similar to the oneshot helper for sha256, add helpers for sha384 and > > sha512. > > > > The helper functions don't use the ARMv8 Crypto Extensions, yet. > > > > Signed-off-by: Michael Tretter <m.tretter@pengutronix.de> > > --- > > include/crypto/pbl-sha.h | 22 ++++++++++++++++++++++ > > 1 file changed, 22 insertions(+) > > > > diff --git a/include/crypto/pbl-sha.h b/include/crypto/pbl-sha.h > > index dbfb79647462..8a20e0a2b84b 100644 > > --- a/include/crypto/pbl-sha.h > > +++ b/include/crypto/pbl-sha.h > > @@ -28,7 +28,29 @@ int sha512_init(struct digest *desc); > > int sha512_update(struct digest *desc, const void *data, unsigned long len); > > int sha512_final(struct digest *desc, u8 *out); > > > > +static inline void pbl_sha512(const void *buf, size_t len, > > + u8 out[SHA512_DIGEST_SIZE]) > > +{ > > + struct sha512_state state = { }; > > + struct digest d = { .ctx = &state, .length = SHA512_DIGEST_SIZE }; > > + > > + sha512_init(&d); > > + sha512_update(&d, buf, len); > > + sha512_final(&d, out); > > +} > > Instead of making these static inline functions, could you follow the > template in pbl/sha256.c to give future developers an idea how for > example the crypto extensions should be implemented? I implemented this as static inline to avoid the decision, if I should add pbl/sha384.c and pbl/sha512.c modules, or if I should change pbl/sha256.c to a more generic pbl/sha.c. I tend to the second option. Do you have any preference? Michael ^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [PATCH 2/2] PBL: add oneshot helper for sha384 and sha512 2026-09-29 8:36 ` Michael Tretter @ 2026-09-29 11:09 ` Sascha Hauer 0 siblings, 0 replies; 6+ messages in thread From: Sascha Hauer @ 2026-09-29 11:09 UTC (permalink / raw) To: Michael Tretter; +Cc: BAREBOX On 2026-09-29 10:36, Michael Tretter wrote: > On Tue, 29 Sep 2026 07:08:56 +0000, Sascha Hauer wrote: > > On 2026-09-28 14:25, Michael Tretter wrote: > > > Similar to the oneshot helper for sha256, add helpers for sha384 and > > > sha512. > > > > > > The helper functions don't use the ARMv8 Crypto Extensions, yet. > > > > > > Signed-off-by: Michael Tretter <m.tretter@pengutronix.de> > > > --- > > > include/crypto/pbl-sha.h | 22 ++++++++++++++++++++++ > > > 1 file changed, 22 insertions(+) > > > > > > diff --git a/include/crypto/pbl-sha.h b/include/crypto/pbl-sha.h > > > index dbfb79647462..8a20e0a2b84b 100644 > > > --- a/include/crypto/pbl-sha.h > > > +++ b/include/crypto/pbl-sha.h > > > @@ -28,7 +28,29 @@ int sha512_init(struct digest *desc); > > > int sha512_update(struct digest *desc, const void *data, unsigned long len); > > > int sha512_final(struct digest *desc, u8 *out); > > > > > > +static inline void pbl_sha512(const void *buf, size_t len, > > > + u8 out[SHA512_DIGEST_SIZE]) > > > +{ > > > + struct sha512_state state = { }; > > > + struct digest d = { .ctx = &state, .length = SHA512_DIGEST_SIZE }; > > > + > > > + sha512_init(&d); > > > + sha512_update(&d, buf, len); > > > + sha512_final(&d, out); > > > +} > > > > Instead of making these static inline functions, could you follow the > > template in pbl/sha256.c to give future developers an idea how for > > example the crypto extensions should be implemented? > > I implemented this as static inline to avoid the decision, if I should > add pbl/sha384.c and pbl/sha512.c modules, or if I should change > pbl/sha256.c to a more generic pbl/sha.c. I tend to the second option. > Do you have any preference? Damn, that's the decision I thought I had pushed to you with my last mail ;) As I do not anticipate that file becoming too big, so I tend to the second option as well. Sascha -- Pengutronix e.K. | | Steuerwalder Str. 21 | http://www.pengutronix.de/ | 31137 Hildesheim, Germany | Phone: +49-5121-206917-0 | Amtsgericht Hildesheim, HRA 2686 | Fax: +49-5121-206917-5555 | ^ permalink raw reply [flat|nested] 6+ messages in thread
end of thread, other threads:[~2026-09-29 11:11 UTC | newest] Thread overview: 6+ messages (download: mbox.gz / follow: Atom feed) -- links below jump to the message on this page -- 2026-09-28 12:25 [PATCH 0/2] PBL: enable hash functions for Vendor Authorized Boot Michael Tretter 2026-09-28 12:25 ` [PATCH 1/2] crypto: make sha384 and sha512 available in PBL Michael Tretter 2026-09-28 12:25 ` [PATCH 2/2] PBL: add oneshot helper for sha384 and sha512 Michael Tretter 2026-09-29 7:08 ` Sascha Hauer 2026-09-29 8:36 ` Michael Tretter 2026-09-29 11:09 ` Sascha Hauer
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox