diff --git a/src/encryption/core.rs b/src/encryption/core.rs index 7ffd4d2..6fa89c4 100644 --- a/src/encryption/core.rs +++ b/src/encryption/core.rs @@ -283,12 +283,11 @@ impl ZeroKnowledgeEncryptor { true } - // Runtime detection for AArch64 crypto extensions + // NEON is default on every aarch64 target, so a cfg!(target_feature = "neon") + // check is const true and says nothing about AES (Cortex-A72 / Pi 3-4: NEON, no AES). #[cfg(not(target_feature = "aes"))] { - // ARM crypto extensions are usually available on modern ARM64 - // ring library will use them automatically if available - return cfg!(target_feature = "neon"); + std::arch::is_aarch64_feature_detected!("aes") } } @@ -605,6 +604,21 @@ impl ZeroKnowledgeEncryptor { mod tests { use super::*; + // Both probes fold to const true under compile-time aes, so the cfg short-circuit is pinned too. + #[cfg(any(target_arch = "x86", target_arch = "x86_64", target_arch = "aarch64"))] + #[test] + fn test_hardware_acceleration_matches_platform_probe() { + let reported = ZeroKnowledgeEncryptor::new() + .unwrap() + .hardware_acceleration_enabled(); + + #[cfg(any(target_arch = "x86", target_arch = "x86_64"))] + assert_eq!(reported, std::arch::is_x86_feature_detected!("aes")); + + #[cfg(target_arch = "aarch64")] + assert_eq!(reported, std::arch::is_aarch64_feature_detected!("aes")); + } + #[test] fn test_encrypt_decrypt_roundtrip() { let encryptor = ZeroKnowledgeEncryptor::new().unwrap(); diff --git a/src/encryption/mod.rs b/src/encryption/mod.rs index e55e13d..f6b6589 100644 --- a/src/encryption/mod.rs +++ b/src/encryption/mod.rs @@ -6,7 +6,7 @@ //! # Features //! - **AES-256-GCM. Not configurable by design.** Authenticated encryption with ring library //! - HKDF-SHA256 key derivation with domain separation (RFC 5869) -//! - Hardware acceleration detection and usage (AES-NI) +//! - Hardware acceleration capability detection (AES-NI / Armv8 Crypto Extension) //! - Per-tenant key isolation with cryptographic guarantees //! - Zero-knowledge guarantees: storage never sees plaintext or keys diff --git a/src/metrics.rs b/src/metrics.rs index b9a9120..7d9f0c6 100644 --- a/src/metrics.rs +++ b/src/metrics.rs @@ -20,7 +20,8 @@ pub struct OperationMetrics { /// Encryption operation time in microseconds (None if not performed) pub encryption_time_micros: Option, - /// Whether hardware acceleration was used (for SHA, AES, etc.) + /// Whether the CPU reports AES hardware (AES-NI / Armv8 Crypto Extension). + /// Informational only: the crypto backend dispatches on its own detection. pub hardware_accelerated: bool, }