Received: by 2002:a5b:505:0:0:0:0:0 with SMTP id o5csp967306ybp; Fri, 4 Oct 2019 07:42:05 -0700 (PDT) X-Google-Smtp-Source: APXvYqyIzUyC1xCINeuG/it4IXJ1fIlHFJf/mKH5YJ9+/LWr1Z6GYQM1wrEItzHWz9+dWzUUvHip X-Received: by 2002:a17:906:ecf9:: with SMTP id qt25mr12318139ejb.249.1570200125785; Fri, 04 Oct 2019 07:42:05 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1570200125; cv=none; d=google.com; s=arc-20160816; b=zmG+MU7tG/AbHgwepO0ytpNX6klTC7kE3hLJQTXH6KAEGwBn04oIh81GaxuFOr2sx1 207Qv5j2sy3MdG+HrUm7qH5csU3eyYT7bjJxvEnLDFO7Jy77cMKT8vKaf95TLvyfGh9o fIXF8Fpe/0YETUFLggL0GqqLUR7ze4qNlFmEaGLSdPoGTbHs2hr1DemAilvRlgUE6YTT E1cxi84bl3ZvjfvAyWrvpMXEi7FQCDB536CEm497SR3wwyfpCKtZDF+LsVbe5f59ZAqa pzPlup4ZP0HCBs5r33l2ySC9mbFT65TIdg8xnkDKUunAvnGPvx1LrkDAUHswWKDcOb9t aB0Q== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-transfer-encoding:cc:to:subject :message-id:date:from:in-reply-to:references:mime-version :dkim-signature; bh=1iRkJgnO4wVgTOHYGwPH4jyH8Xe5sWTO85OE+gYDCMw=; b=aRbGIDdYoy1fs3mjVrv6DWgDhtTWwX4hJKS7DxXZWpkPoQhxKQ9SXgI/RuXUrzh4G7 4YgtkzIt0pSfGmLatjTk8S4eIL7Do4MiZe3VX+cbLv3GHDEuntkk9drlZ0EkWgAVrK13 9UsVeba3f56MiVEQr0YwcnPm+v/JOOC5h6tP2dryUqOb0SVHMTXhv0q5u9yq6yWLIn14 s6D/aXeadpjwafxhloi/fczZpSHnqYV5paXjy3+h/JRMrfIvO3EhtJHox7QKpDmTaokD Ow2Ki+Ci6x12vwJ7ymEX2VIN1dhVKl6FaTItIIewv02fXvnj3NugqXOrPzK1vQA+WvO/ S5Ng== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@linaro.org header.s=google header.b=cCRQm4Ah; spf=pass (google.com: best guess record for domain of linux-crypto-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-crypto-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=linaro.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id n6si3463182edq.228.2019.10.04.07.41.40; Fri, 04 Oct 2019 07:42:05 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-crypto-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@linaro.org header.s=google header.b=cCRQm4Ah; spf=pass (google.com: best guess record for domain of linux-crypto-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-crypto-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=linaro.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S2389259AbfJDOjF (ORCPT + 99 others); Fri, 4 Oct 2019 10:39:05 -0400 Received: from mail-wr1-f68.google.com ([209.85.221.68]:37987 "EHLO mail-wr1-f68.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S2389260AbfJDOjF (ORCPT ); Fri, 4 Oct 2019 10:39:05 -0400 Received: by mail-wr1-f68.google.com with SMTP id w12so7549556wro.5 for ; Fri, 04 Oct 2019 07:39:03 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc:content-transfer-encoding; bh=1iRkJgnO4wVgTOHYGwPH4jyH8Xe5sWTO85OE+gYDCMw=; b=cCRQm4AhxWdJsZMyABy73ABvnGRYLxaQMBiPhGNjISMExnI1frj1bgCXIFqmxE7SWw QK7uzWDA07tkyyKaBJKPSMoKOlj4mgLA3kZ5bkYnnFyuXLlj7YeUZyYrmfWWNYuna9Tr 5CFAtvEtMAmDztutPXVa6tVMO8T05k2NIf1eSWnRtoqe1wKBhhDIbUzvEXJJgBihse2J Sarajq0hcV/9yCe9wdyKoCbuYk9E3houO3PdZorYneyfTkhcILAL0eoA/JZGD/xQZFtD /TxzyYDTt9BmLAH+iiZAtVL0d7fn0ctUi4iYXzxlsMmYujtlPYPe1KaBdirUfd7SbTCN 2DOQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc:content-transfer-encoding; bh=1iRkJgnO4wVgTOHYGwPH4jyH8Xe5sWTO85OE+gYDCMw=; b=DOTBxCALBZujD3pliHItYSfaU2jR7ozbeyoU/v/PO+FTlkzbiWkRHSsXiCxUM74i0x 1kWArfLfnWUnEA/M2ZUw/dWrWBceyTwVc3m6wJoc5cb1jzbMy4dTmWqE08AvZQIXeLhv NcQWjg8u9ySc4ZSdIA/f+WQ2Uo4xKt+ffIWCSj3gl+3D1dhQHbkOy+oysxTA33Td9pH0 68+xNihOJdkYysOKf/i+GUjnT6b6Wzxb9KEU8CSWPbWRDnQgypj+DtVamgSnEVW417pu C5uFyIYZJYTRgmw7bM3ViwCuwEOiLQ8YsYnK1VUveOL/mwjDgskB6DDOZqMoY62JsT2e LLzQ== X-Gm-Message-State: APjAAAWNMSTqpEBPx2zVJMJgRcQKDOgcpe7N852q4HG9as5ijdkFlgKn bunlUg//rHaaywE9TwK8VZVf6kzlkLMqgd1cbLlXsw== X-Received: by 2002:adf:e5cb:: with SMTP id a11mr11698232wrn.200.1570199943131; Fri, 04 Oct 2019 07:39:03 -0700 (PDT) MIME-Version: 1.0 References: <20191002141713.31189-1-ard.biesheuvel@linaro.org> <20191002141713.31189-6-ard.biesheuvel@linaro.org> <20191004134644.GE112631@zx2c4.com> In-Reply-To: From: Ard Biesheuvel Date: Fri, 4 Oct 2019 16:38:51 +0200 Message-ID: Subject: Re: [PATCH v2 05/20] crypto: mips/chacha - import accelerated 32r2 code from Zinc To: "Jason A. Donenfeld" Cc: "open list:HARDWARE RANDOM NUMBER GENERATOR CORE" , Herbert Xu , David Miller , Greg KH , Linus Torvalds , Samuel Neves , Dan Carpenter , Arnd Bergmann , Eric Biggers , Andy Lutomirski , Will Deacon , Marc Zyngier , Catalin Marinas , Martin Willi , Peter Zijlstra , Josh Poimboeuf , =?UTF-8?Q?Ren=C3=A9_van_Dorst?= Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Sender: linux-crypto-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-crypto@vger.kernel.org On Fri, 4 Oct 2019 at 16:38, Ard Biesheuvel wro= te: > > On Fri, 4 Oct 2019 at 15:46, Jason A. Donenfeld wrote: > > > > On Wed, Oct 02, 2019 at 04:16:58PM +0200, Ard Biesheuvel wrote: > > > This integrates the accelerated MIPS 32r2 implementation of ChaCha > > > into both the API and library interfaces of the kernel crypto stack. > > > > > > The significance of this is that, in addition to becoming available > > > as an accelerated library implementation, it can also be used by > > > existing crypto API code such as Adiantum (for block encryption on > > > ultra low performance cores) or IPsec using chacha20poly1305. These > > > are use cases that have already opted into using the abstract crypto > > > API. In order to support Adiantum, the core assembler routine has > > > been adapted to take the round count as a function argument rather > > > than hardcoding it to 20. > > > > Could you resubmit this with first my original commit and then with you= r > > changes on top? I'd like to see and be able to review exactly what's > > changed. If I recall correctly, Ren=C3=A9 and I were really starved for > > registers and tried pretty hard to avoid spilling to the stack, so I'm > > interested to learn how you crammed a bit more sauce in there. > > > > The round count is passed via the fifth function parameter, so it is > already on the stack. Reloading it for every block doesn't sound like > a huge deal to me. > > > I also wonder if maybe it'd be better to just leave this as is with 20 > > rounds, which it was previously optimized for, and just not do > > accelerated Adiantum for MIPS. Android has long since given up on the > > ISA entirely. > > Adiantum does not depend on Android - anyone running linux on his MIPS > router can use it if they want encrypted storage. But to answer your first question: sure, i will split off the changes.