From: "Daniel P. Berrangé" <berrange@redhat.com>
To: qemu-devel@nongnu.org
Cc: "Eric Blake" <eblake@redhat.com>,
"Daniel P. Berrangé" <berrange@redhat.com>,
"Gerd Hoffmann" <kraxel@redhat.com>,
"Markus Armbruster" <armbru@redhat.com>
Subject: [PATCH 00/18] crypto: misc cleanup and introduce gnutls backend driver
Date: Tue, 6 Jul 2021 10:59:06 +0100 [thread overview]
Message-ID: <20210706095924.764117-1-berrange@redhat.com> (raw)
Currently the crypto layer has a choice of backend drivers
* builtin - AES/DES for ciphers using in-tree impl,
glib for hash / hmac
* gcrypt - all ciphers and al hash/hmac algs
* nettle - all ciphers and al hash/hmac algs
We currently default to nettle because that minimizes the
deps from QEMU, as gnutls already pulls in nettle.
In retrospect, however, this was the wrong metric to optimize
for. Instead we should have picked backend based on the
performance of the drivers.
The nettle impls have some limited CPU hardware acceleration,
but aside from in ECB mode, nettle is slower than gcrypt in
every case. In the most important AES-XTS case used for luks
disk encryption, nettle is achieves just 15% of the performance
of gcrypt. It is clear we should prefer gcrypt over nettle.
gnutls uses nettle internally and also exposes many of the
ciphers for direct usage. Unexpectedly, gnutls is actually
faster than nettle, despite using nettle. The reason for
this is that gnutls provides CPU accelerated code for handling
CBC and XTS modes. This lets gnutls get in the same ballpark as
gcrypt for the most important encryption modes. It is also good
for hash impls.
This series thus does a number of things
- Introduce gnutls as a backe driver
- Change priority order gnutls > gcrypt > nettle > builtin
- Cleanup cruft from older versions of crypto libraries
- Make some tests more robust and easier to debug
- Drop support for built-in XTS impl, as it is too slow
to be useful for LUKS
- Drop support for built-in DES impl, to minize amount of
custom crypto code carried. VNC password auth will
require use of an grypt/nettle/gnutls
Daniel P. Berrangé (18):
crypto: remove conditional around 3DES crypto test cases
crypto: remove obsolete crypto test condition
crypto: skip essiv ivgen tests if AES+ECB isn't available
crypto: use &error_fatal in crypto tests
crypto: fix gcrypt min version 1.8 regression
crypto: drop gcrypt thread initialization code
crypto: drop custom XTS support in gcrypt driver
crypto: add crypto tests for single block DES-ECB and DES-CBC
crypto: delete built-in DES implementation
crypto: delete built-in XTS cipher mode support
crypto: rename des-rfb cipher to just des
crypto: flip priority of backends to prefer gcrypt
crypto: introduce build system for gnutls crypto backend
crypto: add gnutls cipher provider
crypto: add gnutls hash provider
crypto: add gnutls hmac provider
crypto: add gnutls pbkdf provider
crypto: prefer gnutls as the crypto backend if new enough
crypto/cipher-builtin.c.inc | 132 ----------
crypto/cipher-gcrypt.c.inc | 143 +----------
crypto/cipher-gnutls.c.inc | 325 +++++++++++++++++++++++++
crypto/cipher-nettle.c.inc | 26 +-
crypto/cipher.c | 30 +--
crypto/desrfb.c | 416 --------------------------------
crypto/hash-gnutls.c | 104 ++++++++
crypto/hmac-gnutls.c | 136 +++++++++++
crypto/init.c | 62 -----
crypto/meson.build | 9 +-
crypto/pbkdf-gnutls.c | 90 +++++++
meson.build | 102 +++++---
qapi/crypto.json | 4 +-
tests/unit/test-crypto-cipher.c | 31 ++-
tests/unit/test-crypto-hash.c | 12 +-
tests/unit/test-crypto-hmac.c | 28 +--
tests/unit/test-crypto-ivgen.c | 14 +-
tests/unit/test-crypto-pbkdf.c | 5 +-
ui/vnc.c | 20 +-
19 files changed, 814 insertions(+), 875 deletions(-)
create mode 100644 crypto/cipher-gnutls.c.inc
delete mode 100644 crypto/desrfb.c
create mode 100644 crypto/hash-gnutls.c
create mode 100644 crypto/hmac-gnutls.c
create mode 100644 crypto/pbkdf-gnutls.c
--
2.31.1
next reply other threads:[~2021-07-06 10:06 UTC|newest]
Thread overview: 43+ messages / expand[flat|nested] mbox.gz Atom feed top
2021-07-06 9:59 Daniel P. Berrangé [this message]
2021-07-06 9:59 ` [PATCH 01/18] crypto: remove conditional around 3DES crypto test cases Daniel P. Berrangé
2021-07-08 18:27 ` Eric Blake
2021-07-06 9:59 ` [PATCH 02/18] crypto: remove obsolete crypto test condition Daniel P. Berrangé
2021-07-08 18:28 ` Eric Blake
2021-07-06 9:59 ` [PATCH 03/18] crypto: skip essiv ivgen tests if AES+ECB isn't available Daniel P. Berrangé
2021-07-08 18:29 ` Eric Blake
2021-07-06 9:59 ` [PATCH 04/18] crypto: use &error_fatal in crypto tests Daniel P. Berrangé
2021-07-08 18:33 ` Eric Blake
2021-07-06 9:59 ` [PATCH 05/18] crypto: fix gcrypt min version 1.8 regression Daniel P. Berrangé
2021-07-08 18:34 ` Eric Blake
2021-07-06 9:59 ` [PATCH 06/18] crypto: drop gcrypt thread initialization code Daniel P. Berrangé
2021-07-08 18:36 ` Eric Blake
2021-07-06 9:59 ` [PATCH 07/18] crypto: drop custom XTS support in gcrypt driver Daniel P. Berrangé
2021-07-08 18:40 ` Eric Blake
2021-07-06 9:59 ` [PATCH 08/18] crypto: add crypto tests for single block DES-ECB and DES-CBC Daniel P. Berrangé
2021-07-08 18:50 ` Eric Blake
2021-07-09 13:53 ` Daniel P. Berrangé
2021-07-06 9:59 ` [PATCH 09/18] crypto: delete built-in DES implementation Daniel P. Berrangé
2021-07-08 18:54 ` Eric Blake
2021-07-06 9:59 ` [PATCH 10/18] crypto: delete built-in XTS cipher mode support Daniel P. Berrangé
2021-07-08 18:56 ` Eric Blake
2021-07-06 9:59 ` [PATCH 11/18] crypto: rename des-rfb cipher to just des Daniel P. Berrangé
2021-07-07 12:47 ` Markus Armbruster
2021-07-07 13:48 ` Daniel P. Berrangé
2021-07-08 14:41 ` Markus Armbruster
2021-07-09 13:59 ` Daniel P. Berrangé
2021-07-08 19:50 ` Eric Blake
2021-07-06 9:59 ` [PATCH 12/18] crypto: flip priority of backends to prefer gcrypt Daniel P. Berrangé
2021-07-08 18:59 ` Eric Blake
2021-07-06 9:59 ` [PATCH 13/18] crypto: introduce build system for gnutls crypto backend Daniel P. Berrangé
2021-07-08 19:03 ` Eric Blake
2021-07-06 9:59 ` [PATCH 14/18] crypto: add gnutls cipher provider Daniel P. Berrangé
2021-07-08 19:13 ` Eric Blake
2021-07-06 9:59 ` [PATCH 15/18] crypto: add gnutls hash provider Daniel P. Berrangé
2021-07-08 19:29 ` Eric Blake
2021-07-06 9:59 ` [PATCH 16/18] crypto: add gnutls hmac provider Daniel P. Berrangé
2021-07-08 19:35 ` Eric Blake
2021-07-09 14:03 ` Daniel P. Berrangé
2021-07-06 9:59 ` [PATCH 17/18] crypto: add gnutls pbkdf provider Daniel P. Berrangé
2021-07-08 19:43 ` Eric Blake
2021-07-06 9:59 ` [PATCH 18/18] crypto: prefer gnutls as the crypto backend if new enough Daniel P. Berrangé
2021-07-08 19:52 ` Eric Blake
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20210706095924.764117-1-berrange@redhat.com \
--to=berrange@redhat.com \
--cc=armbru@redhat.com \
--cc=eblake@redhat.com \
--cc=kraxel@redhat.com \
--cc=qemu-devel@nongnu.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).