From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1753338AbaA3S5a (ORCPT ); Thu, 30 Jan 2014 13:57:30 -0500 Received: from cam-admin0.cambridge.arm.com ([217.140.96.50]:38670 "EHLO cam-admin0.cambridge.arm.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751204AbaA3S53 (ORCPT ); Thu, 30 Jan 2014 13:57:29 -0500 Date: Thu, 30 Jan 2014 18:56:45 +0000 From: Will Deacon To: Ard Biesheuvel Cc: "linux-kernel@vger.kernel.org" , Catalin Marinas , "tglx@linutronix.de" , "mingo@redhat.com" , "hpa@zytor.com" , "x86@kernel.org" , "gregkh@linuxfoundation.org" , "akpm@linux-foundation.org" , "arnd@arndb.de" , "linux-arm-kernel@lists.infradead.org" Subject: Re: [PATCH 5/5] arm64: add Crypto Extensions based synchronous core AES cipher Message-ID: <20140130185645.GC4437@mudshark.cambridge.arm.com> References: <1391014246-9715-1-git-send-email-ard.biesheuvel@linaro.org> <1391014246-9715-6-git-send-email-ard.biesheuvel@linaro.org> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <1391014246-9715-6-git-send-email-ard.biesheuvel@linaro.org> User-Agent: Mutt/1.5.21 (2010-09-15) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Hi Ard, On Wed, Jan 29, 2014 at 04:50:46PM +0000, Ard Biesheuvel wrote: > diff --git a/arch/arm64/crypto/aes-ce-cipher.c b/arch/arm64/crypto/aes-ce-cipher.c > new file mode 100644 > index 000000000000..b5a5d5d6e4b8 > --- /dev/null > +++ b/arch/arm64/crypto/aes-ce-cipher.c > @@ -0,0 +1,103 @@ > +/* > + * linux/arch/arm64/crypto/aes-ce-cipher.c > + * > + * Copyright (C) 2013 Linaro Ltd > + * > + * This program is free software; you can redistribute it and/or modify > + * it under the terms of the GNU General Public License version 2 as > + * published by the Free Software Foundation. > + */ > + > +#include > +#include > +#include > +#include > +#include > + > +MODULE_DESCRIPTION("Synchronous AES cipher using ARMv8 Crypto Extensions"); > +MODULE_AUTHOR("Ard Biesheuvel "); > +MODULE_LICENSE("GPL"); > + > +static void aes_cipher_encrypt(struct crypto_tfm *tfm, u8 dst[], u8 const src[]) > +{ > + struct crypto_aes_ctx *ctx = crypto_tfm_ctx(tfm); > + u32 rounds = 6 + ctx->key_length / 4; Can you document these constants please? > + > + kernel_neon_begin(); > + > + __asm__(" ld1 {v0.16b}, [%[in]] ;" > + " ld1 {v1.16b}, [%[key]], #16 ;" > + "0: aese v0.16b, v1.16b ;" > + " subs %[rounds], %[rounds], #1 ;" > + " ld1 {v1.16b}, [%[key]], #16 ;" > + " beq 1f ;" > + " aesmc v0.16b, v0.16b ;" > + " b 0b ;" > + "1: eor v0.16b, v0.16b, v1.16b ;" > + " st1 {v0.16b}, [%[out]] ;" > + : : > + [out] "r"(dst), > + [in] "r"(src), > + [rounds] "r"(rounds), > + [key] "r"(ctx->key_enc) > + : "cc"); You probably need a memory output to stop this being re-ordered by the compiler. Can GCC not generate the addressing modes you need directly, allowing you to avoid moving everything into registers? > + kernel_neon_end(); > +} > + > +static void aes_cipher_decrypt(struct crypto_tfm *tfm, u8 dst[], u8 const src[]) > +{ > + struct crypto_aes_ctx *ctx = crypto_tfm_ctx(tfm); > + u32 rounds = 6 + ctx->key_length / 4; > + > + kernel_neon_begin(); > + > + __asm__(" ld1 {v0.16b}, [%[in]] ;" > + " ld1 {v1.16b}, [%[key]], #16 ;" > + "0: aesd v0.16b, v1.16b ;" > + " ld1 {v1.16b}, [%[key]], #16 ;" > + " subs %[rounds], %[rounds], #1 ;" > + " beq 1f ;" > + " aesimc v0.16b, v0.16b ;" > + " b 0b ;" > + "1: eor v0.16b, v0.16b, v1.16b ;" > + " st1 {v0.16b}, [%[out]] ;" > + : : > + [out] "r"(dst), > + [in] "r"(src), > + [rounds] "r"(rounds), > + [key] "r"(ctx->key_dec) > + : "cc"); Same comments here. FWIW: I spoke to the guy at ARM who designed the crypto instructions and he reckons your code works :) Cheers, Will "got a B in maths" Deacon