Repository navigation
Commit c8f1ee4
committed
deps: enable AVX-512 OpenSSL asm with clang
Node.js ships two pre-generated sets of OpenSSL assembly: `asm`, which
contains the AVX-512 routines, and `asm_avx2`, which does not. The set is
picked in deps/openssl/openssl.gyp based on `gas_version` or
`nasm_version`, but configure.py only reports `gas_version` when the
compiler is not clang, because clang uses its own integrated assembler
and has no GNU assembler version to report. Consequently every clang
build silently falls back to the AVX-512-less `asm_avx2` set, with no
warning.
The result is that `ossl_vaes_vpclmulqdq_capable()` is assembled as a
stub that always returns 0, so OpenSSL never selects
`ossl_aes_gcm_encrypt_avx512()` and uses the older AES-NI path instead.
On a Zen 5 machine this costs roughly 1.6x on AES-256-GCM, 1.7x on
ChaCha20-Poly1305 and 1.8x on RSA-2048 signing. This is not limited to
custom builds: BUILDING.md documents that the official linux-x64
binaries are produced with clang, and the shipped v25.x and v26.x
binaries contain the stub.
Accept `llvm_version` in the condition, the way deps/openssl/openssl.gypi
already does for the AVX2 set. clang's integrated assembler has handled
AVX512IFMA since 3.9 and VAES / VPCLMULQDQ since 6.0; 8.0 is used as a
conservative floor, well below the clang 19.1 that Node.js already
requires.1 parent c3de450 commit c8f1ee4
1 file changed
Lines changed: 4 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
36 | 36 | | |
37 | 37 | | |
38 | 38 | | |
39 | | - | |
| 39 | + | |
| 40 | + | |
40 | 41 | | |
41 | 42 | | |
42 | 43 | | |
| |||
114 | 115 | | |
115 | 116 | | |
116 | 117 | | |
117 | | - | |
| 118 | + | |
| 119 | + | |
118 | 120 | | |
119 | 121 | | |
120 | 122 | | |
| |||
0 commit comments