It turns out the Intel/AMD AES-NI implementation of XTS regressed hard from the Retpolines functionality merged nearly three years ago for mitigating Spectre… But now the crypto performance with the AES-NI XTS implementation is set to recover from that regression with a huge improvement thanks to a new set of patches…
Source: Phoronix – AES-NI XTS To See 2~3x Performance Recovery After Regressing Hard From Retpolines