From: Eric Biggers <ebiggers@kernel.org>
To: Maxim Fomin <maxim@fomin.one>
Cc: cryptsetup@lists.linux.dev
Subject: Re: Cryptsetup and hardware accelerated AES-XTS
Date: Sun, 21 Jul 2024 08:58:08 -0700 [thread overview]
Message-ID: <20240721155808.GA1224@sol.localdomain> (raw)
In-Reply-To: <KOXKGdgZv9MEFCpmK5MItFMeEE77NA2Wh2kmbbrFNGSlAovd2WUVNvDdY6972_nqYKJlmOZrV9SyIQLwp0h3YHtjMhYZp3BfhLsXVpsixG4=@fomin.one>
On Sun, Jul 21, 2024 at 09:14:02AM +0000, Maxim Fomin wrote:
>
> On Saturday, July 20th, 2024 at 6:36 PM, Eric Biggers <ebiggers@kernel.org> wrote:
>
> >
> >
> > On Sat, Jul 20, 2024 at 12:15:23PM +0000, Maxim Fomin wrote:
> >
> > > Hi!
> > >
> > > Recently linux kernel got[1] faster AES-XTS on modern x86_64 CPUs thanks to VAES and AVX-10/512. I decided to dig deeper into this issue and found the article[2] from 2020 stating that dm-crypt can be configured to use faster (synchronous and hardware accelerated) algorithms with 'capi:' prefix. Can cryptsetup be configured to ask dm-crypt to use hardware accelerated algorithms?
> > >
> > > [1] https://lore.kernel.org/lkml/20240403004404.GC2576@sol.localdomain/T/#m83293b2699f9a5da04fc5780ee402191dace3926
> > >
> > > [2] https://blog.cloudflare.com/speeding-up-linux-disk-encryption/
> > >
> > > Best regards,
> > > Maxim
> >
> >
> > You don't need to use "capi:". Just make sure CONFIG_CRYPTO_AES_NI_INTEL=y is
> > enabled in your kernel (which it already should have been since it was needed
> > for AES-NI acceleration before), and the new code will be used automatically if
> > your CPU supports it.
> >
> > - Eric
>
> I have heard that on some Intel CPUs AVX-512 is ignored (although it is
> supported) because of downclocking. I have rocketlake i5-11600K. How I can
> check which algorithm is actually used? How I can force cryptsetup/dm-crypt to
> enable AVX-512 version if it is not used?
>
The way to tell which AES-XTS implementation is used by default on a particular
system is to check /proc/crypto for which "xts(aes)" has the highest priority.
There is a way to change algorithm priorities to override the default, but there
isn't much reason to think that people would be able to make a better choice
than the kernel's default. The implementation that uses 512-bit vectors
(xts-aes-vaes-avx10_512) is only deprioritized on Ice Lake and Tiger Lake, so it
won't happen on your system anyway as it uses Rocket Lake. On CPUs where the
deprioritization of xts-aes-vaes-avx10_512 does happen, there is a reason for
it, and it is only 512-bit vectors that are disabled, *not* AVX-512 entirely.
- Eric
next prev parent reply other threads:[~2024-07-21 15:58 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-07-20 12:15 Cryptsetup and hardware accelerated AES-XTS Maxim Fomin
2024-07-20 17:36 ` Eric Biggers
2024-07-21 9:14 ` Maxim Fomin
2024-07-21 15:58 ` Eric Biggers [this message]
2024-07-22 10:36 ` Maxim Fomin
2024-07-22 15:32 ` Eric Biggers
2024-07-22 8:25 ` Milan Broz
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20240721155808.GA1224@sol.localdomain \
--to=ebiggers@kernel.org \
--cc=cryptsetup@lists.linux.dev \
--cc=maxim@fomin.one \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.