Conversation
bdfa40b to
e32f041
Compare
78f445b to
852a886
Compare
852a886 to
4d32079
Compare
c102b40 to
83ed1b0
Compare
83ed1b0 to
cc9b941
Compare
openwrt-ai
left a comment
There was a problem hiding this comment.
Blocking: the dirty-patch CI failure and the dangling quickassist-c3xxx dependency. The rest are packaging/init-script fixes.
Generated by Claude Code
|
Sorry, in this pull request you are adding more than 80 patches, I am not going to review it or merge it, because it is quite a lot. |
cc9b941 to
80cddb5
Compare
openwrt-ai
left a comment
There was a problem hiding this comment.
Blocking: the QAT_NONE default makes the x86_64 build fail in configure. The earlier Makefile/init-script threads are untouched by this push and still stand.
Generated by Claude Code
1cb8aa2 to
9adb526
Compare
9adb526 to
f52ebcf
Compare
f52ebcf to
b4f4e8a
Compare
openwrt-ai
left a comment
There was a problem hiding this comment.
Commit checks
b4f4e8a9"openssl-qat: add package" — the body enumerates four build fixes, but the commit also addspatches/0004-use-multiprocess-userstart-for-v2-config.patch(a runtime change,icp_sal_userStart→icp_sal_userStartMultiProcess) andfiles/qatengine.cnf.example. Both change engine behaviour rather than fix the build and should be named in the message.
Generated by Claude Code
b4f4e8a to
ffc527f
Compare
f844366 to
6602741
Compare
openwrt-ai
left a comment
There was a problem hiding this comment.
Commit checks
66027410"openssl-qat: add package" — the body enumerates four build fixes, but the commit also addspatches/0004-use-multiprocess-userstart-for-v2-config.patch(a runtime change,icp_sal_userStart→icp_sal_userStartMultiProcess) andfiles/qatengine.cnf.example. Both change engine behaviour rather than fix the build and should be named in the message.
Generated by Claude Code
6602741 to
2f0a7d7
Compare
2f0a7d7 to
6904dd1
Compare
6904dd1 to
7f08065
Compare
|
@openwrt-ai Fixed - amended the openssl-qat commit message (now 7f08065) to describe the icp_sal_userStartMultiProcess() runtime fix (required for the v2/"[SSL]" config format quickassist-c2xxx ships - without it cpaCyGetNumInstances() silently returns 0) and the qatengine.cnf.example addition, alongside the four build fixes already listed. |
7f08065 to
cfeb637
Compare
|
Status of the x86_64 job, so it doesn't look like a problem with this PR's code: 1. Stale test container (repo-wide). The x86_64 test container is built 2. kmods built by this PR are not available to the test container. I reproduced the test locally (real
One correction to my earlier reply about |
|
Hi @BKPepe, thanks for looking at this, and understood that 80+ patch files is a lot to review. For context on what they are: 67 of the 82 are 40 lines or fewer including the patch header, and nearly all are mechanical fixes needed to build the old vendor driver with a current toolchain and kernel: missing prototypes / I can reduce the review surface without changing the result: group them into roughly 10 thematic patches (kernel API compat, missing prototypes/static/includes, fallthrough, build system, musl/userspace, and the vendor backports), and I'd verify that the fully patched source tree is byte-identical before and after. Would that be acceptable to you? And if this simply isn't something you want in the feed, that's fine. I'd just like to know whether it's worth continuing here or whether another maintainer could take a look. |
Intel QuickAssist Technology v1.5 kernel driver, kernel modules (icp_qa_al, usdm_drv) and userspace utilities for the Atom C2000/ Rangeley SoC family (e.g. C2358), ported forward to work with modern (6.12+) kernels. Verified end-to-end on real hardware: kernel modules load, firmware initializes, and the vendor SDKs own cpa_sample_code benchmark drives real symmetric/asymmetric crypto through the accelerator (~6.7 Gbit/s AES128-CBC, zero test failures). Full report: mab-wien/qat-c2xxx-patches#1 This has existed as a third-party feed since 2020 (https://github.com/dl12345/quickassist-openwrt-denverton) but was never submitted here. See openwrt#30510 for the discussion that led to this PR. The vendor source archive (Intels original download URL has been dead for years) is mirrored as a GitHub release asset with a verified sha256 matching the original PKG_HASH already carried by the feed package. Signed-off-by: Mark Abe <github@mab.wien> Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
OpenSSL engine (Intels QAT_Engine) for hardware crypto offload through QuickAssist Technology, wired up to depend on the quickassist-c2xxx package added in the previous commit. Getting this to build against the QAT1.5/c2xxx vendor driver on a current OpenWrt SDK required several fixes beyond the upstream QAT_Engine source: --with-qat_dir pointed at a build dir that CONFIG_AUTOREMOVE wipes (now points at the staging_dir copy left by quickassist-c2xxx), the c2xxx driver generation predates the X25519/X448 curves QAT_Engines default build assumes hardware support for (disabled for this driver), a musl/glibc pthread_yield difference, and OpenSSL 3.5 having removed RSA_SSLV23_PADDING that QAT_Engine 0.6.4 still references. Beyond the build, getting the engine to actually find QAT instances at runtime needed icp_sal_userStart() replaced with icp_sal_userStartMultiProcess(): only the latter resolves pProcessName to a per-process config section via icp_adf_userProcessToStart(), which the v2/"simplified" config format quickassist-c2xxx ships (ConfigVersion=2, NumProcesses-based [SSL] section) requires - without it cpaCyGetNumInstances() silently returns 0 even with a correctly configured section. files/qatengine.cnf.example ships a ready-to-use openssl.cnf snippet pointing the engine at that same [SSL] section name, since QAT_Engine otherwise defaults to "SHIM". Verified building cleanly (not yet hardware-tested against the kernel crypto API / strongSwan-XFRM path - see openwrt#30510 for where that stands). Signed-off-by: Mark Abe <github@mab.wien> Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
cfeb637 to
4779730
Compare
Summary
Adds
quickassist-c2xxx(Intel QuickAssist Technology v1.5 kernel driver + userspace utilities for Atom C2000/Rangeley SoCs, e.g. C2358) andopenssl-qat(the QAT OpenSSL engine wired up against it), ported forward to build and run on current kernels (6.12+).Opened per the discussion in #30510, specifically in response to:
What is verified
cpa_sample_codebenchmark drives real symmetric/asymmetric crypto through the accelerator (~6.7 Gbit/s AES128-CBC, zero failures), and the QAT OpenSSL engine comes up as[ available ]. Full report: QAT1.5 kernel 6.12 port: real-hardware validation (cpa_sample_code), 73 patches mab-wien/qat-c2xxx-patches#1/tmp, without replacing the installed stack). Both kernel modules load cleanly (no dmesg warnings), the device comes up (state=up),qat.init stop/start icp_dev0works, the engine with the shippedqatengine.cnf.exampleis[ available ], and RSA-2048 signatures made through the engine verify in software.openssl speed rsa2048goes from ~150 to ~1260-1290 sign/s and from ~5100 to ~11200-11600 verify/s (single process, 3 s runs).mastersnapshot SDK, 6.18.52): both packages and both kernel modules (icp_qa_al,usdm_drv) build cleanly - https://github.com/openwrt/packages/actions/runs/35404989582test_entrypoint.shfrom openwrt/actions-shared-workflows): reproduced locally against the apks built by CI, the generic checks pass for both packages.quickassist-c2xxxships atest-version.shoverride becauseadf_ctl/icp_gige_watchdogdo not report a version.Known CI limitations (not caused by this PR)
The x86_64 test job cannot pass at the moment, for two independent reasons (details in this comment):
openwrt/rootfs:x86_64-masterwas last published on 2026-05-29 and points at a kmods index that no longer exists, soapk updatefails before any test runs. This affects other PRs as well (e.g. meshtasticd: update to 2.7.26 #30548, modemmanager: fix custom initial EPS bearer username #30543). The publishing job was fixed in ci: fix registry image namespaces docker#213, the next weekly rebuild is due 2026-09-21.kmod-crypto-qat-c2xxx,kmod-crypto-qat-c2xxx-usdm), because the workflow only stagespackages_ci/*while feed kmods end up inbin/targets/<target>/packages/.About the patches
quickassist-c2xxxcarries 82 patches against the vendor source. 67 of them are 40 lines or fewer including the header and are mechanical build/API fixes for the old vendor driver (missing prototypes /static/extern/ includes for-Werror, fallthrough annotations, kernel 6.x API changes such as PCIe AER,dma_set_mask,vm_flags_set,proc_ops,class_create(), IOMMU, and ccflags/ldflags plumbing). Most of the line count is a single vendor backport (0002, ~5.9k of ~8.8k lines).What is NOT yet verified
ip xfrm/IPsec through this driver)QAT_C3XXX(Denverton) - present as a sibling Kconfig choice inherited from the existing feed package, but noquickassist-c3xxxpackage exists yet; out of scope for this PRBackground
drivers/crypto/intel/qat/covers DH895xCC, C3XXX (Denverton), C62X, 4XXX/420XX/6XXX - but not C2XXX/Rangeley, so the vendor driver remains the only option for this specific chip.quickassist-c2xxx(Intel's original download URL has been dead for years) is mirrored as a GitHub release asset with a verified sha256sum.Open questions for reviewers
cc @dl12345 @lecoq