Skip to content

Add Microchip PolarFire SoC Athena F5200 (TeraFire) crypto callback port - #11688

Open
dgarske wants to merge 1 commit into
wolfSSL:masterfrom
dgarske:mpfs_athena
Open

dgarske wants to merge 1 commit into
wolfSSL:masterfrom
dgarske:mpfs_athena

Conversation

@dgarske

@dgarske dgarske commented Oct 8, 2026 •

Copy link
Copy Markdown
Member

Offloads SHA-384 and AES-256-CTR to the Athena F5200 user cryptoprocessor on the "S" grade PolarFire SoC parts, through the wolfCrypt crypto callback. The engine is driven by Microchip's Crypto Abstraction Library (CAL), which is referenced by include path and never vendored.

What it adds

  • wolfcrypt/src/port/microchip/mpfs_athena.c - engine bring-up, callback dispatch, self-test
  • wolfssl/wolfcrypt/port/microchip/mpfs_athena.h - API and tunables
  • configure.ac - --with-mpfs-athena=PATH, pointing at the CAL directory
  • .github/workflows/mpfs-athena-compile.yml - compiles the port against the CAL in CI

WOLFSSL_MICROCHIP_MPFS selects the SoC family and offloads nothing on its own; WOLFSSL_MPFS_ATHENA says the part carries the engine, since a non-"S" device has none. Which engines are offloaded follows the ordinary WOLFSSL_SHA384 and WOLFSSL_AES_COUNTER gates, and each builds independently.

Two things worth knowing before review. --with-mpfs-athena forces a static-only build, because the CAL archive is non-PIC and cannot be linked into a shared library. And every CAL transaction is taken under wolfSSL_CryptHwMutex*, with the CALSymEncrypt/CALSymTrfRes pair held as a unit, because CAL is configured with one resource handle and the engine is a single block; WOLFSSL_CRYPT_HW_MUTEX is enabled unless the build is SINGLE_THREADED.

Hardware / test status

Validated end-to-end on an MPFS250TS Video Kit (M-mode on the E51, UART0 at 115200), running wolfBoot's image verify and the port's own known-answer tests. The self-test counts callback entries as well as comparing digests: without that, a failed registration computes the right answer in software and a digest-only test still passes.

CI compiles the port against the CAL headers from the public hart-software-services repository at a pinned commit, in four configurations - both engines, each engine alone, and with the self-test dropped - and checks that every CAL symbol it references is defined in the archive. It is a host compile rather than a cross compile on purpose: both CAL archives are soft-float lp64 and Ubuntu's riscv64 glibc is lp64d only, so -mabi=lp64 cannot be satisfied there, while the breakage the job guards against - a CAL header rename, or a refactor in aes.c, sha512.c or cryptocb.h - is visible to any compiler. The target ABI is proven by building for the board.

SHA-384 and AES-256-CTR only. The CAL also exposes SHA-1/224/256/512, AES-128/192, AES-GCM/CCM, HMAC, DRBG and the public-key engines; those are left in software rather than shipped untested. ECDSA P-384 verify is the most useful next addition. M-mode bare metal only: the CAL archives are non-PIC and bake in physical addresses, so they cannot go into a shared library or Linux user space.

@dgarske dgarske self-assigned this Oct 8, 2026
Copilot AI balanced review requested due to automatic review settings October 8, 2026 03:13

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Build compatibility, callback registration, feature-gated compilation, and CAL concurrency issues remain unresolved.

6 open findings
What changed in this PR

Adds PolarFire SoC Athena F5200 hardware acceleration for SHA-384 and AES-256-CTR through wolfCrypt callbacks.

Changes:

  • Implements Athena initialization, dispatch, state management, and self-tests.
  • Adds Autotools integration and public configuration APIs.
  • Adds cross-compilation CI and hardware integration documentation.
File Description
.github/​workflows/​mpfs-athena-compile.yml Cross-compiles against pinned CAL sources.
.wolfssl_known_macro_extras Registers port configuration macros.
configure.ac Adds the CAL path option and build gates.
wolfcrypt/​src/​include.am Adds port sources and documentation.
wolfcrypt/​src/​port/​microchip/​README.md Documents setup, behavior, and limitations.
wolfcrypt/​src/​port/​microchip/​mpfs_athena.c Implements the crypto callback port.
wolfcrypt/​test/​test.c Runs the Athena self-test.
wolfssl/​wolfcrypt/​include.am Installs the public port header.
wolfssl/​wolfcrypt/​port/​microchip/​mpfs_athena.h Defines APIs and tunables.
wolfssl/​wolfcrypt/​settings.h Enables required callback features and device ID.

🧠 Review effort: Balanced


Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.

Comment thread configure.ac
Comment thread wolfcrypt/src/port/microchip/mpfs_athena.c Outdated
Comment thread wolfcrypt/src/port/microchip/mpfs_athena.c Outdated
Comment thread wolfcrypt/src/port/microchip/mpfs_athena.c
Comment thread wolfssl/wolfcrypt/settings.h
Comment thread wolfcrypt/src/port/microchip/README.md

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment on lines +72 to +75
- leg: aesctr-only
extra: '-UWOLFSSL_SHA384 -UWOLFSSL_SHA512'
- leg: sha384-only
extra: '-UWOLFSSL_AES_COUNTER'
Comment thread configure.ac
Comment on lines +4090 to +4091
if test "x$withval" = "xno" || test "x$withval" = "xyes"; then
AC_MSG_ERROR([--with-mpfs-athena needs the path to the Microchip user-crypto (CAL) directory])
Comment on lines +572 to +577
if (dstCtx == NULL) {
/* dst keeps the buffers this handler allocated; wc_Sha384Free() on it
* releases them, so only the stale engine pointer has to go. */
dst->devCtx = NULL;
return MEMORY_E;
}
Comment thread wolfcrypt/test/test.c
TEST_PASS("RTL8735B HUK self-test passed!\n");
#endif

#ifdef WOLFSSL_MPFS_ATHENA
Comment on lines +163 to +166
- **CI compiles the port but cannot run it.** `.github/workflows/mpfs-athena-compile.yml`
cross-compiles it for `rv64imac` against the CAL headers from the public
hart-software-services repository at a pinned commit, and checks that every
CAL symbol it references is defined in the archive. Functional correctness is
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants