Re: [PATCH] lib/crypto: sparc/aes-xts: Add optimization using the AES opcodes

From: Eric Biggers

Date: Tue Sep 29 2026 - 17:28:31 EST


On Tue, Sep 29, 2026 at 11:12:18PM +0200, Stian Halseth wrote:
> Since commit 94efa0c9fb36 ("crypto: aes - Add XTS support using
> library"), xts(aes) on sparc64 is xts-aes-lib. sparc64 has no
> aes_xts_*_arch(), so that goes block by block through aes_encrypt(),
> where 7.2 got the xts template over ecb-aes-sparc64. On a SPARC M7,
> AES-256-XTS through AF_ALG fell from 390 to 144 MiB/s.
>
> Implement aes_xts_encrypt_arch() and aes_xts_decrypt_arch() with the AES
> opcodes, for AES-128 and AES-256, two blocks per iteration. AES-192,
> which IEEE 1619 does not specify, and data that is not 8-byte aligned
> are left to the generic code.

It's a little late to be adding new optimized code in 7.3. But yes,
full AES-XTS performance requires that it be implemented directly, so we
should add this optimized AES-XTS code in 7.4 (assuming people still
care about SPARC, which I guess you do). For 7.3 let's just suppress
"xts-aes-lib" on sparc. I left it out of the patch
https://lore.kernel.org/linux-crypto/20260925202353.10763-1-ebiggers@xxxxxxxxxx/
, but I guess it should be included after all.

- Eric