RE: [PATCH v5 04/19] crypto: cmh - add SHA-2/SHA-3/SHAKE ahash

From: Ousherovitch, Alex

Date: Thu Oct 08 2026 - 14:20:23 EST


On Thu, Oct 08, 2026 at 07:20:26PM +1100, Herbert Xu wrote:
> So it sounds like the info is there. Is it possible to transform
> this to the format that we use?

Not on this device -- there is no canonical state to transcribe.

The working state exists only inside the core, in SCA-masked (two-share)
form; the mask entropy is generated and consumed entirely in hardware
and never leaves it, so software cannot reconstruct the plain chaining
state. The only snapshot the device offers is a fixed-size opaque
container (a flat word array with a CRC, no portable layout) -- not the
canonical state and not convertible to it. Keyed modes (HMAC) cannot be
snapshotted at all.

So export()/import() has nothing to transcribe. v6 therefore does what
you described: for the hashes (SHA-2/SHA-3, SM3) and HMAC the driver
registers with the generic fallback and hardware-accelerates .digest()
only; the incremental and export/import paths use the generic state.
SHAKE/cSHAKE/KMAC and the standalone Poly1305 are dropped per your
earlier note.

> I would appreciate it if you can break the series into smaller
> chunks. Perhaps add the algorithms which are the least problematic
> first.

Will do -- a few self-contained, bisect-clean series, least problematic
first, each sent once the previous is applied. Tentatively:

1. Core: platform driver (probe, DMA, mailbox/VCQ, transaction
manager) + DT binding + MAINTAINERS; registers no algorithms.
2. Symmetric: AES, SM4, ChaCha20-Poly1305, and the DRBG hwrng.
3. Hashes: SHA-2/SHA-3, SM3, HMAC (fallback/digest-only as above).
4. Asymmetric and post-quantum algorithms and their key-management
interface.

I'll start with (1); happy to adjust the granularity.

Thanks,
Alex