aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorEneas U de Queiroz <cotequeiroz@gmail.com>2022-06-21 15:21:44 -0300
committerHauke Mehrtens <hauke@hauke-m.de>2022-06-27 22:34:07 +0200
commitf91b0d7a92c5927db9eb6610628d931e3104cd41 (patch)
tree0605edd4d11dc47bb6b1548fe832335ae15346f7
parent2b392383e62ce37b2be13e1cf4dc6c328e32d2ee (diff)
downloadupstream-f91b0d7a92c5927db9eb6610628d931e3104cd41.tar.gz
upstream-f91b0d7a92c5927db9eb6610628d931e3104cd41.tar.bz2
upstream-f91b0d7a92c5927db9eb6610628d931e3104cd41.zip
wolfssl: disable AES-NI by default for x86_64
WolfSSL is crashing with an illegal opcode in some x86_64 CPUs that have AES instructions but lack other extensions that are used by WolfSSL when AES-NI is enabled. Disable the option by default for now until the issue is properly fixed. People can enable them in a custom build if they are sure it will work for them. Signed-off-by: Eneas U de Queiroz <cotequeiroz@gmail.com> (cherry picked from commit 0bd536723303ccd178e289690d073740c928bb34)
-rw-r--r--package/libs/wolfssl/Config.in7
1 files changed, 6 insertions, 1 deletions
diff --git a/package/libs/wolfssl/Config.in b/package/libs/wolfssl/Config.in
index 3d264e7743..eca9572c49 100644
--- a/package/libs/wolfssl/Config.in
+++ b/package/libs/wolfssl/Config.in
@@ -68,7 +68,7 @@ config WOLFSSL_ASM_CAPABLE
choice
prompt "Hardware Acceleration"
- default WOLFSSL_HAS_CPU_CRYPTO if WOLFSSL_ASM_CAPABLE
+ default WOLFSSL_HAS_CPU_CRYPTO if WOLFSSL_ASM_CAPABLE && !x86_64
default WOLFSSL_HAS_NO_HW
config WOLFSSL_HAS_NO_HW
@@ -80,6 +80,7 @@ choice
help
This will use Intel AESNI insturctions or armv8 Crypto Extensions.
Either of them should easily outperform hardware crypto in WolfSSL.
+ Beware that for Intel, the CPU has to support SSE4 instructions.
config WOLFSSL_HAS_AFALG
bool "AF_ALG"
@@ -96,5 +97,9 @@ choice
bool "/dev/crypto - full"
select WOLFSSL_HAS_DEVCRYPTO
endchoice
+if x86_64 && WOLFSSL_HAS_CPU_CRYPTO
+ comment "WARNING: make sure your CPU supports SSE4 instructions"
+ comment "WolfSSL may crash with an invalid opcode exception"
+endif
endif