Re: [PATCH v2 00/20] Migrate x86 and RISC-V accelerated AES modes into library

From: Ard Biesheuvel

Date: Wed Sep 30 2026 - 09:33:07 EST




On Mon, 28 Sep 2026, at 00:42, Eric Biggers wrote:
> This series applies to v7.3-rc4. It can also be retrieved from:
>
> git fetch
> https://git.kernel.org/pub/scm/linux/kernel/git/ebiggers/linux.git
> aes-lib-x86-riscv-v2
>
> Patch 1 was already applied to libcrypto-fixes, but is resent to make
> this series applicable directly to v7.3-rc4 (ensuring that the Sashiko
> review runs). Patches 2-20 are targeting libcrypto-next for 7.4.
>
> This series migrates the x86 and RISC-V accelerated implementations of
> the AES modes ECB, CBC, CBC-CTS, CTR, XCTR, and XTS into lib/crypto/.
>
> This makes the corresponding library APIs be properly accelerated on
> these architectures, while still accelerating crypto_skcipher as well
> (via the library-based code in crypto/aes.c).
>
> It removes a lot of redundant glue code, since crypto API boilerplate no
> longer needs to be duplicated per-architecture.
>
> Finally, it fixes the longstanding issue where these optimizations were
> disabled by default.
>
> In the case of RISC-V, this series handles all remaining AES code in
> arch/riscv/crypto/. In the case of x86, AES-GCM is still left in
> arch/x86/crypto/ for now; it will be handled later. Other architectures
> will be handled later as well.
>
> For various reasons, aesni-intel_asm.S (the x86-accelerated ECB, CBC,
> CBC-CTS, CTR, and XTS code that doesn't use AVX or VAES) is replaced
> with new functions written from scratch. The other assembly functions
> are kept but are modified slightly for integration into the library.
>
> Changed in v2:
> - Fixed 32-bit x86 bisection hazards by making aesni-intel depend on
> CONFIG_64BIT earlier in the series.
>
> - Fixed handling of lengths over S32_MAX in RISC-V CTR code.
>
> - Restored selection of CRYPTO_SKCIPHER by CRYPTO_AES_NI_INTEL, since
> it is still needed.
>
> - Made the 32-bit x86 XTS code spill the tweaks to the stack rather
> than to the destination buffer.
>
> - Removed the no-longer-needed single block special case from the
> RISC-V CBC-CTS assembly code.
>
> - Made x86 CBC-CTS encryption and decryption share more code.
>
> - Reordered the function parameters in aes-xts-avx-x86_64.S and
> aes-ctr-avx-x86_64.S.
>
> - Other miscellaneous cleanups.
>
> Eric Biggers (20):
> crypto: aes - Fix undesired override of some optimized AES modes
> lib/crypto: aes-xctr: Pass counter by value to aes_xctr_arch()
> lib/crypto: x86/aes: Clean up aes-aesni.S in preparation for AES modes
> lib/crypto: x86/aes-ecb: Add AES-NI optimization
> lib/crypto: x86/aes-cbc: Add AES-NI optimization
> lib/crypto: x86/aes-ctr: Add AES-NI optimization
> lib/crypto: x86/aes-xts: Add AES-NI optimization
> crypto: x86/aes - Drop superseded 32-bit build support
> crypto: x86/aes-ecb - Remove superseded ECB skcipher
> crypto: x86/aes-cbc - Remove superseded CBC skciphers
> crypto: x86/aes-ctr - Remove superseded CTR skcipher
> crypto: x86/aes-xts - Remove superseded XTS skcipher
> lib/crypto: x86/aes-ctr: Migrate AVX-optimized code into library
> lib/crypto: x86/aes-xts: Migrate AVX-optimized code into library
> lib/crypto: riscv/aes: Copy aes-macros.S to library
> lib/crypto: riscv/aes: Pass key struct to assembly code
> lib/crypto: riscv/aes-ecb: Migrate optimized code into library
> lib/crypto: riscv/aes-cbc: Migrate optimized code into library
> lib/crypto: riscv/aes-ctr: Migrate optimized code into library
> lib/crypto: riscv/aes-xts: Migrate optimized code into library
>

For the series,

Reviewed-by: Ard Biesheuvel <ardb@xxxxxxxxxx>