mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Eric Biggers <ebiggers@kernel.org>
To: Itai Handler <itai.handler@gmail.com>
Cc: Milan Broz <gmazyland@gmail.com>,
	Alasdair Kergon <agk@redhat.com>,
	Mike Snitzer <snitzer@kernel.org>,
	Mikulas Patocka <mpatocka@redhat.com>,
	Benjamin Marzinski <bmarzins@redhat.com>,
	Jonathan Corbet <corbet@lwn.net>,
	Shuah Khan <skhan@linuxfoundation.org>,
	Randy Dunlap <rdunlap@infradead.org>,
	dm-devel@lists.linux.dev, linux-doc@vger.kernel.org,
	linux-kernel@vger.kernel.org
Subject: Re: [PATCH v2 0/1] dm-crypt: allow encryption sector size up to PAGE_SIZE
Date: Tue, 22 Sep 2026 21:34:57 +0000	[thread overview]
Message-ID: <20260922213457.GA3536981@google.com> (raw)
In-Reply-To: <20260922134945.667305-1-itai.handler@gmail.com>

On Tue, Sep 22, 2026 at 04:49:45PM +0300, Itai Handler wrote:
> Storage is not the use case - crypto offload is.
> 
> Where the cipher is a hardware engine driven over DMA, the per-request
> cost is a descriptor setup and a round trip, and that cost dominates.
> Making the request sixteen times larger amortises it. With the in-tree
> qce driver on an arm64 64k-page board, plain dm-crypt over a ramdisk,
> MB/s:

That isn't a real use case, though.  Using the QCE driver is *much*
slower than just using the encryption on the CPU, even on long messages.
That's been established in many previous discussions and is now even
admitted by the maintainers of the QCE driver.  The QCE driver even
(incredibly) uses more CPU time than just doing the crypto on the CPU,
due to all its driver, scheduling, and IRQ overhead.  The pending
patches to add BAM locking will make it even slower.

The fix is to not use QCE.  (And also ensure that
CONFIG_CRYPTO_AES_ARM64_CE_BLK=y is set, to get the ARMv8 CE accelerated
code.  But even on legacy CPUs without ARMv8 CE, QCE is still slower.)

Unsurprisingly, the numbers in this patch's cover letter show this as
well, with much higher throughput reported for the CPU-based encryption.

(Also note that QCE is currently marked as BROKEN upstream.)

I really do not think dm-crypt should accept changes to further
accommodate obsolete and problematic external crypto engines like this.

- Eric

  reply	other threads:[~2026-09-22 21:35 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-22 12:03 Itai Handler
2026-09-22 12:03 ` [PATCH v2 1/1] " Itai Handler
2026-09-22 12:34 ` [PATCH v2 0/1] " Itai Handler
2026-09-22 13:07 ` Milan Broz
2026-09-22 13:49   ` Itai Handler
2026-09-22 21:34     ` Eric Biggers [this message]
2026-09-23  7:29       ` Itai Handler
2026-09-23  9:58         ` Mikulas Patocka
2026-09-23 11:39           ` Itai Handler
2026-09-23 11:59             ` Mikulas Patocka
2026-09-23 12:43               ` Itai Handler
2026-09-23 15:28             ` David Laight
2026-09-23 15:42               ` Itai Handler

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260922213457.GA3536981@google.com \
    --to=ebiggers@kernel.org \
    --cc=agk@redhat.com \
    --cc=bmarzins@redhat.com \
    --cc=corbet@lwn.net \
    --cc=dm-devel@lists.linux.dev \
    --cc=gmazyland@gmail.com \
    --cc=itai.handler@gmail.com \
    --cc=linux-doc@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mpatocka@redhat.com \
    --cc=rdunlap@infradead.org \
    --cc=skhan@linuxfoundation.org \
    --cc=snitzer@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®