Bug 14641

Summary: Cortex A72 should not assume Crypto extension
Product: [Build System, Metadata & Runtime] OE-Core Reporter: José Dapena Paz <jdapena>
Component: oe-core otherAssignee: Jon Mason <jon.mason>
Status: RESOLVED FIXED QA Contact:
Severity: normal    
Priority: Undecided CC: jon.mason, richard.purdie, ross.burton, workjagadeesh
Version: 3.4.1   
Target Milestone: ---   
Hardware: Other   
OS: arm64   
Whiteboard:
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: No (bug/feature does not impact docs)

Description José Dapena Paz 2021-12-02 07:58:15 UTC
The include for tunings of Cortex A72, at https://git.yoctoproject.org/poky/tree/meta/conf/machine/include/arm/armv8a/tune-cortexa72.inc?h=yocto-3.4&id=f6d1126fff213460dc6954a5d5fc168606d76b66 is assuming CRC and Crypto extensions are available in all Cortex A72 devices.

This is not true, at least for Raspberry PI 4, with SOC BCM2711.

It is Cortex A72 as seen at https://www.raspberrypi.com/products/raspberry-pi-4-model-b/specifications/

But AES extension is not available as can be seen in this discussion https://forums.raspberrypi.com/viewtopic.php?t=243410 and also in cpuinfo:

# cat /proc/cpuinfo 
processor	: 0
BogoMIPS	: 108.00
Features	: fp asimd evtstrm crc32 cpuid

Assuming this makes boringssl crash with SIGILL. This is because, as it is built with +crc+crypto, it assumes extension is available instead of using runtime check, as it is seen in this code:

OPENSSL_INLINE int CRYPTO_is_ARMv8_AES_capable(void) {
#if defined(OPENSSL_STATIC_ARMCAP_AES) || defined(__ARM_FEATURE_CRYPTO)
  return 1;
#elif defined(OPENSSL_STATIC_ARMCAP)
  return 0;
#else
  return CRYPTO_is_ARMv8_AES_capable_at_runtime();
#endif
}
Comment 1 Jagadeesh Krishnanjanappa 2021-12-05 11:43:00 UTC
A patch to separate out crc+crypto to cortexa72-crypto has be submitted for review [https://lists.openembedded.org/g/openembedded-core/message/159190|here]. The default cortexa72 tune builds for only armv8a.

Regards,
Jagadeesh
Comment 2 José Dapena Paz 2021-12-05 17:07:21 UTC
That should fix the issue.

It is still not fixing the problem with Raspberrypi4, as now cortexa72 will default to no crc32 extension support. But I think that part should likely be fixed in Rpi4 side, adding specific tuning for crc32 only, without crypto.

Thanks!
Comment 3 Jagadeesh Krishnanjanappa 2021-12-05 18:33:47 UTC
An updated patch (https://lists.openembedded.org/g/openembedded-core/message/159199) which separates out crc and crypto tune features based on your comment.

    The newly added
    * cortexa72-crc tune builds programs for armv8a with crc.
    * cortexa72-crc-crypto builds programs for armv8a with crc and crypto.

    The default tune cortexa72 builds programs with armv8a only.

Regards,
Jagadeesh
Comment 4 José Dapena Paz 2021-12-06 19:58:11 UTC
Yes, that looks great to me. Next step would be in meta-raspberrypi side once landed, so it defaults to the CRC flavour.

Thanks!
Comment 5 Jon Mason 2021-12-09 15:20:37 UTC
Fixed in OE-Core rev: 2568d537087adb0b592aa250bf628a7b48c3a9d3