I wonder if a non-hardware accelerated encryption algorithm is good enough for a FS that also has checksums. The CPU is already busy with checksimming, so doesn't this considerably slow down writes?
Both Chacha20 and Poly1305 are optimized (by design) for running on general purpose CPUs. AES-GCM using AES-NI instructions is still faster, but not that much [0].