[PATCH 3/3] crypto: x86/aesni-intel - Add transitional selections

From: Eric Biggers

Date: Wed Sep 30 2026 - 15:09:43 EST


Make CRYPTO_AES_NI_INTEL select CRYPTO_AES, CRYPTO_CBC, and CRYPTO_XTS
so that systems with CRYPTO_AES_NI_INTEL enabled are guaranteed to still
get the algorithm needed for their systems to boot with LUKS / dm-crypt.

(Later, when CRYPTO_AES_NI_INTEL is removed entirely, I plan to turn it
into a 'transitional' symbol with these selections.)

While compatibility selections haven't been used for previous migrations
of architecture-optimized code into lib/crypto/, I think it's worthwhile
in this particular case.

Signed-off-by: Eric Biggers <ebiggers@xxxxxxxxxx>
---
arch/x86/crypto/Kconfig | 12 ++++++++++--
1 file changed, 10 insertions(+), 2 deletions(-)

diff --git a/arch/x86/crypto/Kconfig b/arch/x86/crypto/Kconfig
index c1842c2d7055..20f5e2a17e45 100644
--- a/arch/x86/crypto/Kconfig
+++ b/arch/x86/crypto/Kconfig
@@ -9,6 +9,9 @@ config CRYPTO_AES_NI_INTEL
select CRYPTO_LIB_AES
select CRYPTO_LIB_GF128MUL
select CRYPTO_SKCIPHER
+ select CRYPTO_AES
+ select CRYPTO_CBC
+ select CRYPTO_XTS
help
AEAD cipher: AES with GCM

@@ -16,8 +19,13 @@ config CRYPTO_AES_NI_INTEL
- AES-NI (AES new instructions)
- VAES (Vector AES)

- Note: this option no longer provides the accelerated XTS, CBC, CTR,
- and ECB code. For those just use CRYPTO_XTS, CRYPTO_CBC, etc.
+ The module controlled by this option (aesni-intel.ko) no longer
+ directly provides the accelerated ECB, CBC, CBC-CTS, CTR, XCTR, and
+ XTS code. Those are now provided by CRYPTO_AES (aes.ko) when the
+ corresponding mode option (CRYPTO_XTS, CRYPTO_CBC, etc.) is enabled.
+
+ To ensure dm-crypt continues to work in kconfigs with only this option
+ set, this option selects CRYPTO_AES, CRYPTO_CBC, and CRYPTO_XTS.

config CRYPTO_BLOWFISH_X86_64
tristate "Ciphers: Blowfish, modes: ECB, CBC"
--
2.55.0