Received: by 2002:ab2:69cc:0:b0:1fd:c486:4f03 with SMTP id n12csp468406lqp; Tue, 11 Jun 2024 09:28:46 -0700 (PDT) X-Forwarded-Encrypted: i=3; AJvYcCVBiMVFUabKOx+j1UkMC18BM9xUgy5FrR8H9EKCI8dqZElwTCSe+/v7GCC0FXmLVyuEzVfRhx0PwlLZcOwrMRt0dgHIw2elJzx/9ng8nA== X-Google-Smtp-Source: AGHT+IFb22LPuNOHH4AOZCEmu0YM5Pwy3iaO5yd3kitxUWYpmKd1CkU88qt5pC11ke1HHOcj7MvQ X-Received: by 2002:a05:6512:404:b0:52b:8ad9:cf0a with SMTP id 2adb3069b0e04-52bb9fc5e89mr8619645e87.51.1718123326338; Tue, 11 Jun 2024 09:28:46 -0700 (PDT) ARC-Seal: i=2; a=rsa-sha256; t=1718123326; cv=pass; d=google.com; s=arc-20160816; b=HMiCehqi2vOQRiDzbARs8mWl4LZ5g6j/5RSTk/PssIqWCnlZbgPJ8kGLzmsiZhTpLT O69pE7BP6pgcYQh3MpUlZ5Pd1y9d7C/J31+MNnYcem2/wB/NrqTvWyby+gnMNSMr0nkR ysw7CL7JFhNl7MoAsU1413nidr/r8rlLjxXRJp4XjyY7jRugfUlLIxRCW1/yd8qXNhCq cSCIVjEi5lbX3apm+IoZYj1nrIKlDRmp3DMzizaIzFLKHSCu62OQyWrM6FavSJ028l99 e5/IfRcrB0Inj0JVn4Bzp8jy0x4lx+ja6Jz+BmZU++6r7AyMk3Vp6VzpGyeS8qFjXH4K 8Ofw== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:list-unsubscribe:list-subscribe :list-id:precedence:dkim-signature; bh=BG7XPsDBrgukiLlYYahx3Tk9saQ0mEeAf77iSA+2xAk=; fh=8AVhgKBs+sjpiOt5hMt9abX6rYOouXbp4qCqu58u2RI=; b=QF3FKyAfR6ZFi7TA7cNnLBUrBQLM05EcZ8BWj2JFNky1+Xlxe+W3M5dF8HbGktaO// 3Sbzj4QFsuzMDTnsQR1G85z2Ma91hF1rgUAykL9I6PiCGaDb/jz6s0aQd2twzEKHzH2x KMprJrCX0Rx5TxBy8CO52qiK9iI39vRQ91W+6CuJUIoQHJB9M4xfkMOKMO7SW8EpiFP3 OgwS5hjRtHHnOJoPcugyDdynaL4kZ+7wDrbXseogR/62Yx9ZiYhtlsp9PkeTC8UFYHcR CZpEloLzvE3Rd+GPFywk+s3fugFmN7SugQoceKdvF+FhX5EpyEn8Ax4cx3CGDHC/Mlx+ 9MmA==; dara=google.com ARC-Authentication-Results: i=2; mx.google.com; dkim=pass header.i=@google.com header.s=20230601 header.b=OizTeFwj; arc=pass (i=1 spf=pass spfdomain=google.com dkim=pass dkdomain=google.com dmarc=pass fromdomain=google.com); spf=pass (google.com: domain of linux-crypto+bounces-4900-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:4601:e00::3 as permitted sender) smtp.mailfrom="linux-crypto+bounces-4900-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Return-Path: Received: from am.mirrors.kernel.org (am.mirrors.kernel.org. [2604:1380:4601:e00::3]) by mx.google.com with ESMTPS id a640c23a62f3a-a6ef59378e6si408289966b.986.2024.06.11.09.28.46 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 11 Jun 2024 09:28:46 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-crypto+bounces-4900-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:4601:e00::3 as permitted sender) client-ip=2604:1380:4601:e00::3; Authentication-Results: mx.google.com; dkim=pass header.i=@google.com header.s=20230601 header.b=OizTeFwj; arc=pass (i=1 spf=pass spfdomain=google.com dkim=pass dkdomain=google.com dmarc=pass fromdomain=google.com); spf=pass (google.com: domain of linux-crypto+bounces-4900-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:4601:e00::3 as permitted sender) smtp.mailfrom="linux-crypto+bounces-4900-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Received: from smtp.subspace.kernel.org (wormhole.subspace.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by am.mirrors.kernel.org (Postfix) with ESMTPS id 1EDBD1F24783 for ; Tue, 11 Jun 2024 16:28:25 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id D9DAC3BBCE; Tue, 11 Jun 2024 16:28:14 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="OizTeFwj" X-Original-To: linux-crypto@vger.kernel.org Received: from mail-oi1-f171.google.com (mail-oi1-f171.google.com [209.85.167.171]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3B43943AAE for ; Tue, 11 Jun 2024 16:28:13 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.167.171 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1718123294; cv=none; b=VSRPKNLdsfwa77QmOaq/xeh1Jd9Ln8UGYtSVTPa+2p+z9K/f17gVD/BfSApaG5lXzAdRWdtbkNWK79ipdox3D82rz6HtV+s6wQL8FjE967Y4wErz3Xu+uWyKqbelbP8XK21yhtOojZ1Vs65H0Bfc5GABJAS0PfNl+MqAH8At59Y= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1718123294; c=relaxed/simple; bh=N4evEqm5Lsj9muDRZ0FKGlEsgvOKjl0qugGTleH/ab8=; h=MIME-Version:References:In-Reply-To:From:Date:Message-ID:Subject: To:Cc:Content-Type; b=bXYkniy54JewNoTMk8fZIJd5EKBV1NPWsWYWwecr6YqL8RupipFJlVzZGTOmP/z9d85Py0CXksYuwboZsPJILYQ+sLIXCkZLtpNvPt8e231if1jhwNKBq7ydl7a8LeGGPYD8nUFmWx81MgASAHgBC4RqioIXrRqXsGWo4+DQPqg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=OizTeFwj; arc=none smtp.client-ip=209.85.167.171 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=google.com Received: by mail-oi1-f171.google.com with SMTP id 5614622812f47-3d22368713aso1801750b6e.1 for ; Tue, 11 Jun 2024 09:28:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20230601; t=1718123292; x=1718728092; darn=vger.kernel.org; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:from:to:cc:subject:date :message-id:reply-to; bh=BG7XPsDBrgukiLlYYahx3Tk9saQ0mEeAf77iSA+2xAk=; b=OizTeFwjBU81njD45yxQT2wWY3Eodu/9OIU5Hg4n1NA1r58jVM9QenP8mB+dRc7lEv Dwb0Z45eMdGk/GNGRR/kaOSM+cO7BcnPeQw5KEVNAeKK+5y+24od82A+dYRk0TQfaaG5 Ko5TK1i/d1qE+0PrUgn6yXwsMA+2SYtMo+FxPEsTvK02NznyZVP/IAXRVcDumy9si3Vm E/Qt3Nq6kdPu0fvDs4fhfMOet99oYPOxUR4bB64H2AsbyB9vwp+RmSHDy4KyurNG83Zx ShD2fVSXur3+4qOL4l/XNg/HqLHyyUIgVmEcUkDOq0sRrCgIeBElI/2KGXPZyJVF/NYn Ga3w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1718123292; x=1718728092; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=BG7XPsDBrgukiLlYYahx3Tk9saQ0mEeAf77iSA+2xAk=; b=RYBuSpnRX39c/Jan4S0vk0iR8r6YnGOgp8i0vFOiijeYMzcmG3NVDLQHJf8CKYDb0v 6hD3j13L2VzSEDFMDp4ATsnK3K43wwyF4wcI0CAnnBhNsdH1AGOQNmItHnHylpeXuaXu IRhkzTNVX0ha/s202nrTAZ5QmW50wqJjOnHohOFs+tFkCc4JirJlxIARafynBlRvbRdW aB3eePV9hWt93UzdY3xPsNz69sjRCQNObxT0JY+LqI4k8JoV8j7b319BuepH8Ijuke7Y +FELHneFiO6Pma6K1DeNgAUIxfJX+ri61NoBaKxke5J0+hy6ZifK+UzRXowaa3kM6fFn NPww== X-Gm-Message-State: AOJu0Yx5yc8Vj24zX6aDNRyKb36FvAc5U3X5lAi1ghYvkfGNilUPLbqo KP0ZV9uIkLoxt9D1vjhedQ8YGpfsPvb/TwkAL/S7btXDQbv9wcABlhbNSZFuOJJQCaUS7abEYmw rTh2HxsPZi5HkqGIXPJhfWOHezBrRTX4vc7FN X-Received: by 2002:a05:6808:2183:b0:3d2:1f88:3e86 with SMTP id 5614622812f47-3d21f88455amr12786369b6e.37.1718123292024; Tue, 11 Jun 2024 09:28:12 -0700 (PDT) Precedence: bulk X-Mailing-List: linux-crypto@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 References: <20240611034822.36603-1-ebiggers@kernel.org> In-Reply-To: <20240611034822.36603-1-ebiggers@kernel.org> From: Sami Tolvanen Date: Tue, 11 Jun 2024 09:27:32 -0700 Message-ID: Subject: Re: [PATCH v5 00/15] Optimize dm-verity and fsverity using multibuffer hashing To: Eric Biggers Cc: linux-crypto@vger.kernel.org, fsverity@lists.linux.dev, dm-devel@lists.linux.dev, x86@kernel.org, linux-arm-kernel@lists.infradead.org, Ard Biesheuvel , Bart Van Assche , Herbert Xu Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Hi Eric, On Mon, Jun 10, 2024 at 8:49=E2=80=AFPM Eric Biggers = wrote: > > On many modern CPUs, it is possible to compute the SHA-256 hash of two > equal-length messages in about the same time as a single message, if all > the instructions are interleaved. This is because each SHA-256 (and > also most other cryptographic hash functions) is inherently serialized > and therefore can't always take advantage of the CPU's full throughput. > > An earlier attempt to support multibuffer hashing in Linux was based > around the ahash API. That approach had some major issues, as does the > alternative ahash-based approach proposed by Herbert (see my response at > https://lore.kernel.org/linux-crypto/20240610164258.GA3269@sol.localdomai= n/). > This patchset instead takes a much simpler approach of just adding a > synchronous API for hashing equal-length messages. > > This works well for dm-verity and fsverity, which use Merkle trees and > therefore hash large numbers of equal-length messages. Thank you for continuing to work on this! Improving dm-verity performance is a high priority for Android, and this patch series shows very promising results. FWIW, I would like to see this merged upstream, and any ahash improvements handled in follow-up patches. For the series: Reviewed-by: Sami Tolvanen Sami