freenode
Kernel & Low-Level

Kernel moves x86 and RISC-V AES acceleration into crypto library

Hardware-optimized AES modes become the default path for library callers, ending years of duplicated glue and disabled-by-default speedups.

Eric Biggers has posted work that migrates the accelerated AES implementations for x86 and RISC-V into the kernel's shared crypto library, targeting the 7.4 cycle. The move covers ECB, CBC, CBC-CTS, CTR, XCTR, and XTS.

Until now, those optimized paths lived in per-architecture crypto trees and were wired mainly through the traditional skcipher API. Library callers on the same CPUs often saw no hardware acceleration at all, and the fast paths were disabled by default. After the migration, the library APIs themselves are accelerated on these platforms, while skcipher users still benefit through the shared AES code.

The consolidation also removes large amounts of redundant crypto-API boilerplate that each architecture had to maintain. On RISC-V it clears the remaining AES code from the architecture tree. On x86, AES-GCM is left for a later pass, and other architectures will follow.

Along the way, Biggers rewrote the non-AVX AES-NI assembly used for several modes. The new XTS code fixes a longstanding flaw in the old path, which spilled encrypted tweaks into the destination buffer. Those tweaks are secret material and must not be visible to anything that lacks the key; the replacement keeps them in registers on 64-bit builds or on the stack on 32-bit.

Library CTR and XTS performance is brought in line with the architecture-specific skcipher algorithms they supersede. Priorities for the library-backed algorithms stay conservative for now and will rise once the remaining AVX-optimized pieces are folded in.