Repository navigation
Conversation
Contributor
There was a problem hiding this comment.
🟡 Changes recommended
Build compatibility, callback registration, feature-gated compilation, and CAL concurrency issues remain unresolved.
6 open findings
Force static-only CAL builds to avoid linking non-PIC objects · New Serialize CAL transactions for the single shared resource · New Avoid undeclared wc_AesSetKeyDirect dependency · New Guard self-test buffer sizes when SHA384 is disabled · New Register Athena device before labeling benchmark results · New Enable AES-CTR in the documented Athena configure command · New
What changed in this PR
Adds PolarFire SoC Athena F5200 hardware acceleration for SHA-384 and AES-256-CTR through wolfCrypt callbacks.
Changes:
- Implements Athena initialization, dispatch, state management, and self-tests.
- Adds Autotools integration and public configuration APIs.
- Adds cross-compilation CI and hardware integration documentation.
| File | Description |
|---|---|
.github/workflows/mpfs-athena-compile.yml |
Cross-compiles against pinned CAL sources. |
.wolfssl_known_macro_extras |
Registers port configuration macros. |
configure.ac |
Adds the CAL path option and build gates. |
wolfcrypt/src/include.am |
Adds port sources and documentation. |
wolfcrypt/src/port/microchip/README.md |
Documents setup, behavior, and limitations. |
wolfcrypt/src/port/microchip/mpfs_athena.c |
Implements the crypto callback port. |
wolfcrypt/test/test.c |
Runs the Athena self-test. |
wolfssl/wolfcrypt/include.am |
Installs the public port header. |
wolfssl/wolfcrypt/port/microchip/mpfs_athena.h |
Defines APIs and tunables. |
wolfssl/wolfcrypt/settings.h |
Enables required callback features and device ID. |
🧠 Review effort: Balanced
Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.
Contributor
There was a problem hiding this comment.
🟡 Changes recommended
Configuration, CI coverage, registration handling, and a SHA-384 copy failure path contain unresolved correctness issues.
5 open findings
6 resolved since last review
Guard self-test buffer sizes when SHA384 is disabled Avoid undeclared wc_AesSetKeyDirect dependency Serialize CAL transactions for the single shared resource Force static-only CAL builds to avoid linking non-PIC objects Register Athena device before labeling benchmark results Enable AES-CTR in the documented Athena configure command
🧠 Review effort: Balanced
Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.
Comment on lines
+72
to
+75
| - leg: aesctr-only | ||
| extra: '-UWOLFSSL_SHA384 -UWOLFSSL_SHA512' | ||
| - leg: sha384-only | ||
| extra: '-UWOLFSSL_AES_COUNTER' |
Comment on lines
+4090
to
+4091
| if test "x$withval" = "xno" || test "x$withval" = "xyes"; then | ||
| AC_MSG_ERROR([--with-mpfs-athena needs the path to the Microchip user-crypto (CAL) directory]) |
Comment on lines
+572
to
+577
| if (dstCtx == NULL) { | ||
| /* dst keeps the buffers this handler allocated; wc_Sha384Free() on it | ||
| * releases them, so only the stale engine pointer has to go. */ | ||
| dst->devCtx = NULL; | ||
| return MEMORY_E; | ||
| } |
| TEST_PASS("RTL8735B HUK self-test passed!\n"); | ||
| #endif | ||
|
|
||
| #ifdef WOLFSSL_MPFS_ATHENA |
Comment on lines
+163
to
+166
| - **CI compiles the port but cannot run it.** `.github/workflows/mpfs-athena-compile.yml` | ||
| cross-compiles it for `rv64imac` against the CAL headers from the public | ||
| hart-software-services repository at a pinned commit, and checks that every | ||
| CAL symbol it references is defined in the archive. Functional correctness is |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Offloads SHA-384 and AES-256-CTR to the Athena F5200 user cryptoprocessor on the "S" grade PolarFire SoC parts, through the wolfCrypt crypto callback. The engine is driven by Microchip's Crypto Abstraction Library (CAL), which is referenced by include path and never vendored.
What it adds
wolfcrypt/src/port/microchip/mpfs_athena.c- engine bring-up, callback dispatch, self-testwolfssl/wolfcrypt/port/microchip/mpfs_athena.h- API and tunablesconfigure.ac---with-mpfs-athena=PATH, pointing at the CAL directory.github/workflows/mpfs-athena-compile.yml- compiles the port against the CAL in CIWOLFSSL_MICROCHIP_MPFSselects the SoC family and offloads nothing on its own;WOLFSSL_MPFS_ATHENAsays the part carries the engine, since a non-"S" device has none. Which engines are offloaded follows the ordinaryWOLFSSL_SHA384andWOLFSSL_AES_COUNTERgates, and each builds independently.Two things worth knowing before review.
--with-mpfs-athenaforces a static-only build, because the CAL archive is non-PIC and cannot be linked into a shared library. And every CAL transaction is taken underwolfSSL_CryptHwMutex*, with theCALSymEncrypt/CALSymTrfRespair held as a unit, because CAL is configured with one resource handle and the engine is a single block;WOLFSSL_CRYPT_HW_MUTEXis enabled unless the build isSINGLE_THREADED.Hardware / test status
Validated end-to-end on an MPFS250TS Video Kit (M-mode on the E51, UART0 at 115200), running wolfBoot's image verify and the port's own known-answer tests. The self-test counts callback entries as well as comparing digests: without that, a failed registration computes the right answer in software and a digest-only test still passes.
CI compiles the port against the CAL headers from the public hart-software-services repository at a pinned commit, in four configurations - both engines, each engine alone, and with the self-test dropped - and checks that every CAL symbol it references is defined in the archive. It is a host compile rather than a cross compile on purpose: both CAL archives are soft-float
lp64and Ubuntu's riscv64 glibc islp64donly, so-mabi=lp64cannot be satisfied there, while the breakage the job guards against - a CAL header rename, or a refactor inaes.c,sha512.corcryptocb.h- is visible to any compiler. The target ABI is proven by building for the board.SHA-384 and AES-256-CTR only. The CAL also exposes SHA-1/224/256/512, AES-128/192, AES-GCM/CCM, HMAC, DRBG and the public-key engines; those are left in software rather than shipped untested. ECDSA P-384 verify is the most useful next addition. M-mode bare metal only: the CAL archives are non-PIC and bake in physical addresses, so they cannot go into a shared library or Linux user space.