Skip to main content

ic_core/
cpu.rs

1//! CPU feature detection.
2//!
3//! Lives in `ic-core` so that both the implementation crates and the ontology
4//! can consult it without either depending on the other: `ic-cipher` uses it to
5//! pick a backend, and `ic-ontology` uses it to tell an agent which backend is
6//! live.
7//!
8//! Detection is compile-time when the feature is already enabled for the build
9//! (`-C target-cpu=native`, or an explicit `-C target-feature=+aes`), and
10//! runtime otherwise. Under `no_std` only the compile-time path exists, because
11//! runtime detection needs `std`.
12//!
13//! Every query here depends only on the CPU, never on key material, so none of
14//! it is a side channel.
15
16/// Whether x86 AES-NI is available.
17///
18/// x86 only, deliberately. The ARMv8 cryptographic extension is detected in
19/// `ic_cipher::aes::armv8_aes_available`, because selecting it also depends on
20/// a cargo feature that this crate has no business knowing about. Reporting it
21/// here would additionally make the ontology call an ARM build
22/// `hardware-accelerated`, which would be an overclaim: that label means the
23/// cipher and the carry-less multiply, and there is no `PMULL` GHASH backend.
24#[inline]
25#[must_use]
26pub fn has_aes() -> bool {
27    #[cfg(all(any(target_arch = "x86", target_arch = "x86_64"), feature = "std"))]
28    {
29        std::arch::is_x86_feature_detected!("aes")
30    }
31    #[cfg(all(
32        any(target_arch = "x86", target_arch = "x86_64"),
33        not(feature = "std"),
34        target_feature = "aes"
35    ))]
36    {
37        true
38    }
39    #[cfg(not(all(
40        any(target_arch = "x86", target_arch = "x86_64"),
41        any(feature = "std", target_feature = "aes")
42    )))]
43    {
44        false
45    }
46}
47
48/// Whether carry-less multiplication (`PCLMULQDQ`) is available.
49///
50/// The instruction GHASH needs, but not a sufficient condition for GHASH to use
51/// it: whether it will is [`has_ghash_clmul`], which is what to ask before
52/// concluding that AES-GCM is fast.
53#[inline]
54#[must_use]
55pub fn has_pclmulqdq() -> bool {
56    #[cfg(all(any(target_arch = "x86", target_arch = "x86_64"), feature = "std"))]
57    {
58        std::arch::is_x86_feature_detected!("pclmulqdq")
59    }
60    #[cfg(all(
61        any(target_arch = "x86", target_arch = "x86_64"),
62        not(feature = "std"),
63        target_feature = "pclmulqdq"
64    ))]
65    {
66        true
67    }
68    #[cfg(not(all(
69        any(target_arch = "x86", target_arch = "x86_64"),
70        any(feature = "std", target_feature = "pclmulqdq")
71    )))]
72    {
73        false
74    }
75}
76
77/// Whether GHASH will run on the carry-less multiply in this build.
78///
79/// Not the same question as [`has_pclmulqdq`]. The instruction is necessary but
80/// the backend also needs `ssse3` for its byte-reversal shuffle, and it exists
81/// only on x86-64 with `std`. A 32-bit x86 build on a CPU that has every one of
82/// those instructions still runs the portable GHASH.
83///
84/// This is the predicate `ic_cipher::gcm` dispatches on and the one the
85/// ontology reports from, so the two cannot disagree. They did: the report
86/// used to ask only whether the CPU had the instruction, and told agents on
87/// 32-bit x86 that AES-GCM was fast when it ran at a fortieth of the speed of
88/// ChaCha20-Poly1305.
89#[inline]
90#[must_use]
91pub fn has_ghash_clmul() -> bool {
92    #[cfg(all(target_arch = "x86_64", feature = "std"))]
93    {
94        std::arch::is_x86_feature_detected!("pclmulqdq")
95            && std::arch::is_x86_feature_detected!("ssse3")
96    }
97    #[cfg(not(all(target_arch = "x86_64", feature = "std")))]
98    {
99        false
100    }
101}
102
103#[cfg(test)]
104mod tests {
105    use super::*;
106
107    /// Detection must not panic and must be stable within a process — a
108    /// backend chosen once per key would otherwise be able to disagree with
109    /// itself.
110    #[test]
111    fn detection_is_total_and_stable() {
112        let a = has_aes();
113        let b = has_pclmulqdq();
114        for _ in 0..8 {
115            assert_eq!(has_aes(), a);
116            assert_eq!(has_pclmulqdq(), b);
117        }
118    }
119
120    /// On a non-x86 target both must report false rather than guessing.
121    #[test]
122    #[cfg(not(any(target_arch = "x86", target_arch = "x86_64")))]
123    fn non_x86_reports_no_acceleration() {
124        assert!(!has_aes());
125        assert!(!has_pclmulqdq());
126    }
127}