• Ard Biesheuvel's avatar
    crypto: arm/aes-neonbs - resolve fallback cipher at runtime · b56f5cbc
    Ard Biesheuvel authored
    Currently, the bit sliced NEON AES code for ARM has a link time
    dependency on the scalar ARM asm implementation, which it uses as a
    fallback to perform CBC encryption and the encryption of the initial
    XTS tweak.
    
    The bit sliced NEON code is both fast and time invariant, which makes
    it a reasonable default on hardware that supports it. However, the
    ARM asm code it pulls in is not time invariant, and due to the way it
    is linked in, cannot be overridden by the new generic time invariant
    driver. In fact, it will not be used at all, given that the ARM asm
    code registers itself as a cipher with a priority that exceeds the
    priority of the fixed time cipher.
    
    So remove the link time dependency, and allocate the fallback cipher
    via the crypto API. Note that this requires this driver's module_init
    call to be replaced with late_initcall, so that the (possibly generic)
    fallback cipher is guaranteed to be available when the builtin test
    is performed at registration time.
    Signed-off-by: default avatarArd Biesheuvel <ard.biesheuvel@linaro.org>
    Signed-off-by: default avatarHerbert Xu <herbert@gondor.apana.org.au>
    b56f5cbc
aes-neonbs-glue.c 10.9 KB