drivers: implement SEC driver - #5894
Conversation
cde343e to
fef17de
Compare
|
What's kunpeng? Are there more kunpengs than HiSilicon kunpengs? |
HiSilicon is a vendor, and Kunpeng is a product. Thanks for your review. |
|
If I've understood it correctly this is all HiSilicon specific. How about putting the files below Public functions and structs prefixed with Public headers (used outside the driver) should preferably go into Private headers (used inside the driver only) should go into the driver directory and should hopefully not need to be reached outside of that directory. |
Thank very much for your patient guidance.
Please help me review it at your convenience. Is the above correct? |
OK
There's no need to change that since you're using a
All non-static symbols should have a |
fe036de to
4682670
Compare
update: |
|
The commits with |
|
Please squash in the review commits to make it easier to review the individual commits. |
drivers: crypto: hisilicon: implement QM driver
Please define SQ.
Please define SQE and BD.
|
drivers: crypto: hisilicon: implement SEC driver
Missing space: "SEC (Security Engine)"
|
|
Third commit subject should be "drivers: crypto: hisilicon: implement SEC ciphers". |
Why not done in the previous commits?
s/d06/D06/ and should be a separate commit.
I think a better description for what's left would be "d06: crypto: enable SEC acceleration", wouldn't it? |
Good point,I'll deal with it immediately! |
jforissier
left a comment
There was a problem hiding this comment.
Comments on "drivers: implement for kunpeng compile".
jforissier
left a comment
There was a problem hiding this comment.
Some more comments on "drivers: implement qm driver". Similar comments apply to SEC too.
f0f548a to
a96707c
Compare
| */ | ||
| #include "hisi_qm.h" | ||
|
|
||
| #define CFG_RDY_BIT 0x1 |
There was a problem hiding this comment.
CFG_ prefix is reserved to configuration switches. Use QM_FVT_CFG_RDY_BIT IIUC.
| C_MODE_CCM = 0x5, | ||
| C_MODE_GCM = 0x6, | ||
| C_MODE_XTS = 0x7, | ||
| C_MODE_CBC_CS = 0x9, |
This comment was marked as resolved.
This comment was marked as resolved.
Sorry, something went wrong.
| }; | ||
|
|
||
| enum hisi_drv_status { | ||
| DRVCRYPT_NO_ERR = 0, |
There was a problem hiding this comment.
These are HISI_QM specific error code. Please prefix with HISI_QM_DRVCRYPT_ or like.
| struct hisi_qp *qp_array; | ||
| struct mutex qp_lock; /* protect the qp instance */ | ||
|
|
||
| int32_t (*dev_status_check)(struct hisi_qm *qm); |
There was a problem hiding this comment.
is expected to return an enum hisi_drv_status, not a raw int32 right?
There was a problem hiding this comment.
please fix straight in 1st commit "drivers: crypto: hisilicon: implement QM driver"
| *@param qm: Handle of Queue Management module | ||
| *@return success: 0,fail: -DRVCRYPT_EBUSY/DRVCRYPT_EINVAL | ||
| */ | ||
| int32_t hisi_qm_init(struct hisi_qm *qm); |
There was a problem hiding this comment.
Why not returning type enum hisi_drv_status. It would make the implementation better and prevent one messes up between several kinds of return value enums. This comment applies to all hsis_xxx() function returning these error codes.
Note I don't think you need a negative value. Testing a non-zero retrun code would be sufficient to detect an error condition.
etienne-lms
left a comment
There was a problem hiding this comment.
Main issue to address: many functions are declared to return a TEE_Result value whereas they return an enum hisi_drv_status value.
| asm volatile ("dsb ishst" : : : "memory"); | ||
| } | ||
|
|
||
| static inline __noprof void dsb_osh(void) |
There was a problem hiding this comment.
db_osh() deserves a specific commit.
There was a problem hiding this comment.
Great idea, I will handle it as soon as possible.
| { | ||
| uint32_t val = 0; | ||
|
|
||
| /* return 0 mailbox ready, -ETIMEDOUT hardware timeout */ |
There was a problem hiding this comment.
this function is expected to return a TEE_result compliant value.
There was a problem hiding this comment.
Did I misunderstand your meaning?
static TEE_Result qm_mb(struct hisi_qm *qm, uint8_t cmd, vaddr_t dma_addr,
uint16_t qn, uint8_t op)to
static enum hisi_drv_status qm_mb(struct hisi_qm *qm, uint8_t cmd, vaddr_t dma_addr,
uint16_t qn, uint8_t op)Is this what you meant? @etienne-lms
There was a problem hiding this comment.
Sorry if I was not very clear. I'll try to make it short
The many functions that return a value like HISI_QM_DRVCRYPT_xxx should be declared as:
enum hisi_drv_status <function_label>(...).
All functions that return a value like TEE_SUCCESS or TEE_ERROR_xxxshould be declared as:TEE_Result <function_label>(...)`
Make sure not to mix both unless what return values are not reliable.
There was a problem hiding this comment.
I think I understand now. Thank you for your patient explanation. I will handle it as soon as possible!
|
|
||
| if (qm_wait_mb_ready(qm)) { | ||
| EMSG("QM mailbox is busy"); | ||
| return HISI_QM_DRVCRYPT_EBUSY; |
This comment was marked as resolved.
This comment was marked as resolved.
Sorry, something went wrong.
| case QM_SQC_VFT: | ||
| data = (SHIFT_U64(base, QM_SQC_VFT_START_SQN_SHIFT) | | ||
| QM_SQC_VFT_VALID | | ||
| SHIFT_U64((number - 1), QM_SQC_VFT_SQ_NUM_SHIFT)); |
There was a problem hiding this comment.
can remove outer parentheses
| { | ||
| struct sec_cipher_ctx *c_ctx = NULL; | ||
| size_t padding_size = 0; | ||
| TEE_Result ret = 0; |
There was a problem hiding this comment.
prefer use a TEE_Result defined value rather than 0. E.g. TEE_SUCCESS, or TEE_ERROR_GENERIC, or ...
| struct acc_device *sec_dev = NULL, *cur_dev = NULL; | ||
| uint32_t max_qp_num = 0; | ||
| uint32_t free_qp_num; | ||
| struct hisi_qm *qm; |
| { | ||
| struct hisi_qm *qm = &sec_dev->qm; | ||
| uint32_t val = 0; | ||
| uint32_t ret = 0; |
There was a problem hiding this comment.
Recommendation: enum hisi_drv_status ret = HISI_QM_DRVCRYPT_NO_ERRere and at many other places.
| uint8_t t = 0; | ||
| int i = 0; | ||
|
|
||
| for (i = 0, t = 0; i < AES_SM4_IV_SIZE; i++) { |
There was a problem hiding this comment.
can remove t = 0, it is already inittialilzed to 0.
8e0424c to
975f2f1
Compare
| register_phys_mem_pgdir(MEM_AREA_IO_NSEC, LPC_BASE, LPC_SIZE); | ||
| register_phys_mem_pgdir(MEM_AREA_IO_SEC, SEC_BASE, SEC_SIZE); | ||
|
|
||
| void itr_core_handler(void) |
There was a problem hiding this comment.
please rebase in master tip. Platforms no more need to implement itr_core_handler() since #6030 has been merged.
There was a problem hiding this comment.
I'll do it as soon as possible.
|
|
||
| $(call force,CFG_CRYPTO_DRIVER,y) | ||
| CFG_CRYPTO_DRIVER_DEBUG ?= 0 | ||
|
|
There was a problem hiding this comment.
nitpicking: i suggestion to remove the empty lines above and below.
There was a problem hiding this comment.
No, is a kind suggestion, thx
| */ | ||
| #include "hisi_qm.h" | ||
|
|
||
| #define QM_FVT_CFG_RDY_BIT 0x1 |
There was a problem hiding this comment.
nitpicking: using a tabulation bewteen macro name and assigned value make the file easier to read:
#define QM_FVT_CFG_RDY_BIT 0x1
/* Doorbell */
#define QM_DOORBELL_SQ_CQ_BASE 0x1000
#define QM_DB_CMD_SHIFT 12
#define QM_DB_RAND_DATA_SHIFT 16
#define QM_DB_INDEX_SHIFT 32
#define QM_DB_PRIORITY_SHIFT 48
#define QM_DB_RAND_DATA 0x5a
#define QM_DOORBELL_CMD_SQ 0
#define QM_DOORBELL_CMD_CQ 1
(...)| {.reg_name = "QM_DFX_WB_SQE_FROM_ACC_CNT", .reg_offset = 0x104058}, | ||
| {.reg_name = "QM_DFX_ACC_FINISH_CNT ", .reg_offset = 0x104060}, | ||
| {.reg_name = "QM_DFX_CQE_ERR_CNT ", .reg_offset = 0x1040b4}, | ||
| {.reg_name = NULL, 0} |
There was a problem hiding this comment.
could replace all 2 space chars with a signle one (applies from line 109 to line 119).
There was a problem hiding this comment.
sorry, on coding style, add a space char after an opening brace { and another space char before the closing brace }.
{ .reg_name = "QM_DFX_ACC_FINISH_CNT ", .reg_offset = 0x104060 },
{ .reg_name = "QM_DFX_CQE_ERR_CNT ", .reg_offset = 0x1040b4 },
{ .reg_name = NULL, 0 }| { | ||
| uint32_t val = 0; | ||
|
|
||
| /* return 0 mailbox ready, HISI_QM_DRVCRYPT_ETMOUT hardware timeout */ |
This comment was marked as resolved.
This comment was marked as resolved.
Sorry, something went wrong.
| } | ||
|
|
||
| ret = cipher_algo_check(algo); | ||
| if (ret != 0) |
| } | ||
|
|
||
| c_ctx->offs = 0; | ||
| (*ctx) = c_ctx; |
There was a problem hiding this comment.
parentheses not needed
| return; | ||
|
|
||
| hisi_qm_release_qp(c_ctx->qp); | ||
| memset(c_ctx->key, 0, c_ctx->key_len); |
There was a problem hiding this comment.
should use memzero_explicit() instead of memset().
| static TEE_Result sec_cipher_init(struct drvcrypt_cipher_init *dinit) | ||
| { | ||
| struct sec_cipher_ctx *c_ctx = NULL; | ||
| TEE_Result ret = 0; |
| dupdate->src.data, dupdate->src.length); | ||
|
|
||
| ret = sec_do_cipher_task(c_ctx->qp, c_ctx); | ||
| if (ret != 0) |
There was a problem hiding this comment.
s/ret != 0/ret/ here and at all other places where applicable.
|
@xiaoxuZeng, please don't use commit merge in your patch series. You need to rebase your series on top of master branch tip instead. |
etienne-lms
left a comment
There was a problem hiding this comment.
I found some issues. Please rebase your changes, i'll review them afterward.
|
|
||
| if (!iv && iv_len != 0) { | ||
| EMSG("Iv is NULL"); | ||
| if (!iv && iv_len != TEE_SUCCESS) { |
There was a problem hiding this comment.
typo: iv_len is not a TEE_Resuslt value.
Replace with if (!iv && iv_len)
| paddr_t sqe_dma; | ||
| paddr_t cqe_dma; | ||
|
|
||
| enum TEE_Result (*fill_sqe)(void *sqe, void *msg); |
There was a problem hiding this comment.
s/TEE_Result/enum hisi_drv_status/
Ditto at line below.
| #define __HISI_SEC_H__ | ||
|
|
||
| #include "hisi_qm.h" | ||
| #include <initcall.h> |
There was a problem hiding this comment.
swap the 2 lines.
include <> first, then include "".
I will handle it as soon as possible. Thank you! |
|
@xiaoxuZeng, please don't use commit merges in your patch series. You need to rebase your series on top of master branch tip instead. |
e73e3d4 to
2ecb37f
Compare
|
For commit "core: arm64: add dsb_osh", in the description I think it should say "osh data barrier" instead of "ishst memory barrier". Feel free to create a new pull request with this commit only. That would allow getting that commit merged before the rest of this PR and help the reviewing a little bit. |
yeh, I have created a new PR, Thanks. |
The Hisilicon QM is a Queue Management module. In order to unify the interface between accelerator and software, a unified queue management module QM is used to interact with software. Each accelerator module integrates a QM. Software issues tasks to the SQ (Submmision Queue),and the QM obtains the address of the SQE (Submmision Queue Element). The BD (Buffer Description, same as SQE) information is sent to the accelerator. After the task processing is complete, the accelerator applies for a write-back address from the QM to write back the SQ. Signed-off-by: Xiaoxu Zeng <zengxiaoxu@huawei.com>
The Hisilicon SEC (Security Engine) is a hardware security acceleration module, which is used to enhance the security-related functions of the processor. Signed-off-by: Xiaoxu Zeng <zengxiaoxu@huawei.com>
Add the Hisilicon SEC as a drvcrypt cipher provider. Supported for DES-ECB/CBC 3DES-ECB/CBC AES-ECB/CBC/CTR SM4-ECB/CBC/CTR. Signed-off-by: Xiaoxu Zeng <zengxiaoxu@huawei.com>
|
This pull request has been marked as a stale pull request because it has been open (more than) 30 days with no activity. Remove the stale label or add a comment, otherwise this pull request will automatically be closed in 5 days. Note, that you can always re-open a closed issue at any time. |
Sec is a Security Engine for cipher, digest, HMAC, authenc.
Qm is a queue management device include by Sec.
This PR just implement sec cipher function.
digest, HMAC, authenc. will add on next PR, when we finished development and test.