Page MenuHomeFreeBSD

arm64: enable ossl accelerated AES-GCM on arm64
Needs ReviewPublic

Authored by gallatin on Mon, Sep 28, 5:22 PM.
Tags
None
Referenced Files
F173955230: D60097.diff
Tue, Sep 29, 3:22 PM
F173951586: D60097.id187905.diff
Tue, Sep 29, 2:41 PM
F173874945: D60097.id187905.diff
Tue, Sep 29, 1:22 AM
F173874672: D60097.diff
Tue, Sep 29, 1:19 AM
F173857994: D60097.id187905.diff
Mon, Sep 28, 10:48 PM
F173847063: D60097.diff
Mon, Sep 28, 9:07 PM
Subscribers

Details

Reviewers
markj
andrew
ngie
Summary

Connect the baseline OpenSSL ARMv8 fused AES-GCM kernels to the OCF
ossl driver. Advertise the algorithm only when the system-wide capability set
includes both AES and PMULL.

On arm64, re-run ossl_cpuid via a sysinit() that runs at SI_ORDER_LAST,
since the ossl device attaches before arm64 populates elf_hwcap when
ossl is built into the kernel or pre-loaded at boot.

Prefer OSSL over armv8crypto for AES-GCM sessions while retaining
armv8crypto as a fallback.

This provides about a 50% speedup for a Netflix ktls workload on a small
neoverse N1 board.

Test Plan
  • Run real Netflix AES-GCM ktls (done)

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Skipped
Unit
Tests Skipped

Event Timeline

Run real Netflix AES-GCM ktls (done)

Have you run tools/tools/crypto/cryptocheck.c against this? That would give you more complete coverage.

Run real Netflix AES-GCM ktls (done)

Have you run tools/tools/crypto/cryptocheck.c against this? That would give you more complete coverage.

I was not aware of that, so I just ran it in response to your comment. I assume this is passing:

# kldload /d/cryptodev.ko
# ./cryptocheck -v -d ossl -a aes-gcm -z > log
#  grep -Ei 'mismatch|failed|didn.t fail|not supported' log
#

Thank you!