* [PATCH 0/2] PBL: enable hash functions for Vendor Authorized Boot
@ 2026-09-28 12:25 Michael Tretter
2026-09-28 12:25 ` [PATCH 1/2] crypto: make sha384 and sha512 available in PBL Michael Tretter
0 siblings, 1 reply; 2+ messages in thread
From: Michael Tretter @ 2026-09-28 12:25 UTC (permalink / raw)
To: Sascha Hauer, BAREBOX; +Cc: Michael Tretter
Altera's Vendor Authorized Boot (VAB) uses a sha384 hash for verifying
the second stage boot loader.
As preparation for adding VAB, make the sha384 and sha512 hash functions
available in the PBL.
Loading the second stage loader from flash and verifying the signature
will follow as separate patch series.
Signed-off-by: Michael Tretter <m.tretter@pengutronix.de>
---
Michael Tretter (2):
crypto: make sha384 and sha512 available in PBL
PBL: add oneshot helper for sha384 and sha512
crypto/Makefile | 1 +
crypto/sha4.c | 11 ++++++-----
include/crypto/pbl-sha.h | 29 +++++++++++++++++++++++++++++
3 files changed, 36 insertions(+), 5 deletions(-)
---
base-commit: 4a752d2303440195e12ed1a4e642b0be5b450b8e
change-id: 20260928-crypto-pbl-sha384-e59cd7b4cd1d
Best regards,
--
Michael Tretter <m.tretter@pengutronix.de>
^ permalink raw reply [flat|nested] 2+ messages in thread
* [PATCH 1/2] crypto: make sha384 and sha512 available in PBL
2026-09-28 12:25 [PATCH 0/2] PBL: enable hash functions for Vendor Authorized Boot Michael Tretter
@ 2026-09-28 12:25 ` Michael Tretter
0 siblings, 0 replies; 2+ messages in thread
From: Michael Tretter @ 2026-09-28 12:25 UTC (permalink / raw)
To: Sascha Hauer, BAREBOX; +Cc: Michael Tretter
On Agilex 5 with VAB (Vendor Authorized Boot), the second stage boot
loader is verified with a sha384 checksum.
Make the sha384 and sha512 functions available in the PBL to be able to
use these functions for vendor authorized boot.
Signed-off-by: Michael Tretter <m.tretter@pengutronix.de>
---
crypto/Makefile | 1 +
crypto/sha4.c | 11 ++++++-----
include/crypto/pbl-sha.h | 7 +++++++
3 files changed, 14 insertions(+), 5 deletions(-)
diff --git a/crypto/Makefile b/crypto/Makefile
index 2ac023c3e2fd..6f745a883123 100644
--- a/crypto/Makefile
+++ b/crypto/Makefile
@@ -13,6 +13,7 @@ obj-$(CONFIG_DIGEST_SHA256_GENERIC) += sha2.o
pbl-y += sha2.o digest.o
obj-$(CONFIG_DIGEST_SHA384_GENERIC) += sha4.o
obj-$(CONFIG_DIGEST_SHA512_GENERIC) += sha4.o
+pbl-y += sha4.o
obj-pbl-y += memneq.o
obj-$(CONFIG_CRYPTO_PBKDF2) += pbkdf2.o
diff --git a/crypto/sha4.c b/crypto/sha4.c
index 8c94f5011dc2..c700c1a37756 100644
--- a/crypto/sha4.c
+++ b/crypto/sha4.c
@@ -20,6 +20,7 @@
#include <crypto/sha.h>
#include <crypto/internal.h>
+#include <crypto/pbl-sha.h>
static inline u64 Ch(u64 x, u64 y, u64 z)
{
@@ -126,7 +127,7 @@ sha512_transform(u64 *state, const u8 *input)
state[4] += e; state[5] += f; state[6] += g; state[7] += h;
}
-static int
+int
sha512_init(struct digest *desc)
{
struct sha512_state *sctx = digest_ctx(desc);
@@ -143,7 +144,7 @@ sha512_init(struct digest *desc)
return 0;
}
-static int sha384_init(struct digest *desc)
+int sha384_init(struct digest *desc)
{
struct sha512_state *sctx = digest_ctx(desc);
sctx->state[0] = SHA384_H0;
@@ -159,7 +160,7 @@ static int sha384_init(struct digest *desc)
return 0;
}
-static int sha512_update(struct digest *desc, const void *in,
+int sha512_update(struct digest *desc, const void *in,
unsigned long len)
{
struct sha512_state *sctx = digest_ctx(desc);
@@ -195,7 +196,7 @@ static int sha512_update(struct digest *desc, const void *in,
return 0;
}
-static int sha512_final(struct digest *desc, u8 *hash)
+int sha512_final(struct digest *desc, u8 *hash)
{
struct sha512_state *sctx = digest_ctx(desc);
static u8 padding[128] = { 0x80, };
@@ -226,7 +227,7 @@ static int sha512_final(struct digest *desc, u8 *hash)
return 0;
}
-static int sha384_final(struct digest *desc, u8 *hash)
+int sha384_final(struct digest *desc, u8 *hash)
{
u8 D[64];
diff --git a/include/crypto/pbl-sha.h b/include/crypto/pbl-sha.h
index 3ccd5151e1a6..dbfb79647462 100644
--- a/include/crypto/pbl-sha.h
+++ b/include/crypto/pbl-sha.h
@@ -24,4 +24,11 @@ static inline int pbl_sha256_ce(const void *buf, size_t len, u8 out[SHA256_DIGES
}
#endif
+int sha512_init(struct digest *desc);
+int sha512_update(struct digest *desc, const void *data, unsigned long len);
+int sha512_final(struct digest *desc, u8 *out);
+
+int sha384_init(struct digest *desc);
+int sha384_final(struct digest *desc, u8 *out);
+
#endif /* __PBL-SHA_H_ */
--
2.47.3
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-09-28 12:26 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-28 12:25 [PATCH 0/2] PBL: enable hash functions for Vendor Authorized Boot Michael Tretter
2026-09-28 12:25 ` [PATCH 1/2] crypto: make sha384 and sha512 available in PBL Michael Tretter
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox