* [PATCH 0/2] crypto: make the sha1 library optional
@ 2022-07-09 21:18 Eric Biggers
2022-07-09 21:18 ` [PATCH 1/2] crypto: move lib/sha1.c into lib/crypto/ Eric Biggers
` (2 more replies)
0 siblings, 3 replies; 10+ messages in thread
From: Eric Biggers @ 2022-07-09 21:18 UTC (permalink / raw)
To: linux-crypto; +Cc: linux-kernel, netdev, Jason A . Donenfeld
This series makes it possible to build the kernel without SHA-1 support,
although for now this is only possible in minimal configurations, due to
the uses of SHA-1 in the networking subsystem.
Eric Biggers (2):
crypto: move lib/sha1.c into lib/crypto/
crypto: make the sha1 library optional
crypto/Kconfig | 1 +
init/Kconfig | 1 +
lib/Makefile | 2 +-
lib/crypto/Kconfig | 3 +++
lib/crypto/Makefile | 3 +++
lib/{ => crypto}/sha1.c | 0
net/ipv6/Kconfig | 1 +
7 files changed, 10 insertions(+), 1 deletion(-)
rename lib/{ => crypto}/sha1.c (100%)
base-commit: 79e6e2f3f3ff345947075341781e900e4f70db81
--
2.37.0
^ permalink raw reply [flat|nested] 10+ messages in thread
* [PATCH 1/2] crypto: move lib/sha1.c into lib/crypto/
2022-07-09 21:18 [PATCH 0/2] crypto: make the sha1 library optional Eric Biggers
@ 2022-07-09 21:18 ` Eric Biggers
2022-07-11 14:58 ` Jason A. Donenfeld
2022-07-09 21:18 ` [PATCH 2/2] crypto: make the sha1 library optional Eric Biggers
2022-07-15 8:50 ` [PATCH 0/2] " Herbert Xu
2 siblings, 1 reply; 10+ messages in thread
From: Eric Biggers @ 2022-07-09 21:18 UTC (permalink / raw)
To: linux-crypto; +Cc: linux-kernel, netdev, Jason A . Donenfeld
From: Eric Biggers <ebiggers@google.com>
SHA-1 is a crypto algorithm (or at least was intended to be -- it's not
considered secure anymore), so move it out of the top-level library
directory and into lib/crypto/.
Signed-off-by: Eric Biggers <ebiggers@google.com>
---
lib/Makefile | 2 +-
lib/crypto/Makefile | 2 ++
lib/{ => crypto}/sha1.c | 0
3 files changed, 3 insertions(+), 1 deletion(-)
rename lib/{ => crypto}/sha1.c (100%)
diff --git a/lib/Makefile b/lib/Makefile
index f99bf61f8bbc67..67482f5ec0e899 100644
--- a/lib/Makefile
+++ b/lib/Makefile
@@ -29,7 +29,7 @@ endif
lib-y := ctype.o string.o vsprintf.o cmdline.o \
rbtree.o radix-tree.o timerqueue.o xarray.o \
- idr.o extable.o sha1.o irq_regs.o argv_split.o \
+ idr.o extable.o irq_regs.o argv_split.o \
flex_proportions.o ratelimit.o show_mem.o \
is_single_threaded.o plist.o decompress.o kobject_uevent.o \
earlycpio.o seq_buf.o siphash.o dec_and_lock.o \
diff --git a/lib/crypto/Makefile b/lib/crypto/Makefile
index 26be2bbe09c59e..d28111ba54fcb2 100644
--- a/lib/crypto/Makefile
+++ b/lib/crypto/Makefile
@@ -34,6 +34,8 @@ libpoly1305-y := poly1305-donna32.o
libpoly1305-$(CONFIG_ARCH_SUPPORTS_INT128) := poly1305-donna64.o
libpoly1305-y += poly1305.o
+obj-y += sha1.o
+
obj-$(CONFIG_CRYPTO_LIB_SHA256) += libsha256.o
libsha256-y := sha256.o
diff --git a/lib/sha1.c b/lib/crypto/sha1.c
similarity index 100%
rename from lib/sha1.c
rename to lib/crypto/sha1.c
--
2.37.0
^ permalink raw reply related [flat|nested] 10+ messages in thread
* [PATCH 2/2] crypto: make the sha1 library optional
2022-07-09 21:18 [PATCH 0/2] crypto: make the sha1 library optional Eric Biggers
2022-07-09 21:18 ` [PATCH 1/2] crypto: move lib/sha1.c into lib/crypto/ Eric Biggers
@ 2022-07-09 21:18 ` Eric Biggers
2022-07-11 14:59 ` Jason A. Donenfeld
2022-07-11 18:03 ` Jakub Kicinski
2022-07-15 8:50 ` [PATCH 0/2] " Herbert Xu
2 siblings, 2 replies; 10+ messages in thread
From: Eric Biggers @ 2022-07-09 21:18 UTC (permalink / raw)
To: linux-crypto; +Cc: linux-kernel, netdev, Jason A . Donenfeld
From: Eric Biggers <ebiggers@google.com>
Since the Linux RNG no longer uses sha1_transform(), the SHA-1 library
is no longer needed unconditionally. Make it possible to build the
Linux kernel without the SHA-1 library by putting it behind a kconfig
option, and selecting this new option from the kconfig options that gate
the remaining users: CRYPTO_SHA1 for crypto/sha1_generic.c, BPF for
kernel/bpf/core.c, and IPV6 for net/ipv6/addrconf.c.
Unfortunately, since BPF is selected by NET, for now this can only make
a difference for kernels built without networking support.
Signed-off-by: Eric Biggers <ebiggers@google.com>
---
crypto/Kconfig | 1 +
init/Kconfig | 1 +
lib/crypto/Kconfig | 3 +++
lib/crypto/Makefile | 3 ++-
net/ipv6/Kconfig | 1 +
5 files changed, 8 insertions(+), 1 deletion(-)
diff --git a/crypto/Kconfig b/crypto/Kconfig
index 59489a300cd100..bf15ca5eb9d367 100644
--- a/crypto/Kconfig
+++ b/crypto/Kconfig
@@ -880,6 +880,7 @@ config CRYPTO_RMD160
config CRYPTO_SHA1
tristate "SHA1 digest algorithm"
select CRYPTO_HASH
+ select CRYPTO_LIB_SHA1
help
SHA-1 secure hash standard (FIPS 180-1/DFIPS 180-2).
diff --git a/init/Kconfig b/init/Kconfig
index c984afc489dead..d8d0b4bdfe4195 100644
--- a/init/Kconfig
+++ b/init/Kconfig
@@ -1472,6 +1472,7 @@ config HAVE_PCSPKR_PLATFORM
# interpreter that classic socket filters depend on
config BPF
bool
+ select CRYPTO_LIB_SHA1
menuconfig EXPERT
bool "Configure standard kernel features (expert users)"
diff --git a/lib/crypto/Kconfig b/lib/crypto/Kconfig
index 2082af43d51fbe..9ff549f63540fa 100644
--- a/lib/crypto/Kconfig
+++ b/lib/crypto/Kconfig
@@ -121,6 +121,9 @@ config CRYPTO_LIB_CHACHA20POLY1305
select CRYPTO_LIB_POLY1305
select CRYPTO_ALGAPI
+config CRYPTO_LIB_SHA1
+ tristate
+
config CRYPTO_LIB_SHA256
tristate
diff --git a/lib/crypto/Makefile b/lib/crypto/Makefile
index d28111ba54fcb2..919cbb2c220d61 100644
--- a/lib/crypto/Makefile
+++ b/lib/crypto/Makefile
@@ -34,7 +34,8 @@ libpoly1305-y := poly1305-donna32.o
libpoly1305-$(CONFIG_ARCH_SUPPORTS_INT128) := poly1305-donna64.o
libpoly1305-y += poly1305.o
-obj-y += sha1.o
+obj-$(CONFIG_CRYPTO_LIB_SHA1) += libsha1.o
+libsha1-y := sha1.o
obj-$(CONFIG_CRYPTO_LIB_SHA256) += libsha256.o
libsha256-y := sha256.o
diff --git a/net/ipv6/Kconfig b/net/ipv6/Kconfig
index bf2e5e5fe14273..658bfed1df8b17 100644
--- a/net/ipv6/Kconfig
+++ b/net/ipv6/Kconfig
@@ -7,6 +7,7 @@
menuconfig IPV6
tristate "The IPv6 protocol"
default y
+ select CRYPTO_LIB_SHA1
help
Support for IP version 6 (IPv6).
--
2.37.0
^ permalink raw reply related [flat|nested] 10+ messages in thread
* Re: [PATCH 1/2] crypto: move lib/sha1.c into lib/crypto/
2022-07-09 21:18 ` [PATCH 1/2] crypto: move lib/sha1.c into lib/crypto/ Eric Biggers
@ 2022-07-11 14:58 ` Jason A. Donenfeld
0 siblings, 0 replies; 10+ messages in thread
From: Jason A. Donenfeld @ 2022-07-11 14:58 UTC (permalink / raw)
To: Eric Biggers; +Cc: linux-crypto, linux-kernel, netdev
On Sat, Jul 09, 2022 at 02:18:48PM -0700, Eric Biggers wrote:
> From: Eric Biggers <ebiggers@google.com>
>
> SHA-1 is a crypto algorithm (or at least was intended to be -- it's not
> considered secure anymore), so move it out of the top-level library
> directory and into lib/crypto/.
>
> Signed-off-by: Eric Biggers <ebiggers@google.com>
Thanks for this.
Reviewed-by: Jason A. Donenfeld <Jason@zx2c4.com>
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [PATCH 2/2] crypto: make the sha1 library optional
2022-07-09 21:18 ` [PATCH 2/2] crypto: make the sha1 library optional Eric Biggers
@ 2022-07-11 14:59 ` Jason A. Donenfeld
2022-07-11 18:03 ` Jakub Kicinski
1 sibling, 0 replies; 10+ messages in thread
From: Jason A. Donenfeld @ 2022-07-11 14:59 UTC (permalink / raw)
To: Eric Biggers; +Cc: linux-crypto, linux-kernel, netdev
On Sat, Jul 09, 2022 at 02:18:49PM -0700, Eric Biggers wrote:
> From: Eric Biggers <ebiggers@google.com>
>
> Since the Linux RNG no longer uses sha1_transform(), the SHA-1 library
> is no longer needed unconditionally. Make it possible to build the
> Linux kernel without the SHA-1 library by putting it behind a kconfig
> option, and selecting this new option from the kconfig options that gate
> the remaining users: CRYPTO_SHA1 for crypto/sha1_generic.c, BPF for
> kernel/bpf/core.c, and IPV6 for net/ipv6/addrconf.c.
>
> Unfortunately, since BPF is selected by NET, for now this can only make
> a difference for kernels built without networking support.
Seems like a step in the right direction, thanks.
Reviewed-by: Jason A. Donenfeld <Jason@zx2c4.com>
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [PATCH 2/2] crypto: make the sha1 library optional
2022-07-09 21:18 ` [PATCH 2/2] crypto: make the sha1 library optional Eric Biggers
2022-07-11 14:59 ` Jason A. Donenfeld
@ 2022-07-11 18:03 ` Jakub Kicinski
2022-07-15 1:18 ` Alexei Starovoitov
1 sibling, 1 reply; 10+ messages in thread
From: Jakub Kicinski @ 2022-07-11 18:03 UTC (permalink / raw)
To: Eric Biggers
Cc: linux-crypto, linux-kernel, netdev, Jason A . Donenfeld , bpf
On Sat, 9 Jul 2022 14:18:49 -0700 Eric Biggers wrote:
> Since the Linux RNG no longer uses sha1_transform(), the SHA-1 library
> is no longer needed unconditionally. Make it possible to build the
> Linux kernel without the SHA-1 library by putting it behind a kconfig
> option, and selecting this new option from the kconfig options that gate
> the remaining users: CRYPTO_SHA1 for crypto/sha1_generic.c, BPF for
> kernel/bpf/core.c, and IPV6 for net/ipv6/addrconf.c.
>
> Unfortunately, since BPF is selected by NET, for now this can only make
> a difference for kernels built without networking support.
> diff --git a/init/Kconfig b/init/Kconfig
> index c984afc489dead..d8d0b4bdfe4195 100644
> --- a/init/Kconfig
> +++ b/init/Kconfig
> @@ -1472,6 +1472,7 @@ config HAVE_PCSPKR_PLATFORM
> # interpreter that classic socket filters depend on
> config BPF
> bool
> + select CRYPTO_LIB_SHA1
>
Let's give it an explicit CC: bpf@
> diff --git a/net/ipv6/Kconfig b/net/ipv6/Kconfig
> index bf2e5e5fe14273..658bfed1df8b17 100644
> --- a/net/ipv6/Kconfig
> +++ b/net/ipv6/Kconfig
> @@ -7,6 +7,7 @@
> menuconfig IPV6
> tristate "The IPv6 protocol"
> default y
> + select CRYPTO_LIB_SHA1
> help
> Support for IP version 6 (IPv6).
FWIW:
Acked-by: Jakub Kicinski <kuba@kernel.org>
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [PATCH 2/2] crypto: make the sha1 library optional
2022-07-11 18:03 ` Jakub Kicinski
@ 2022-07-15 1:18 ` Alexei Starovoitov
0 siblings, 0 replies; 10+ messages in thread
From: Alexei Starovoitov @ 2022-07-15 1:18 UTC (permalink / raw)
To: Jakub Kicinski
Cc: Eric Biggers, Linux Crypto Mailing List, LKML,
Network Development, Jason A . Donenfeld, bpf
On Mon, Jul 11, 2022 at 11:22 AM Jakub Kicinski <kuba@kernel.org> wrote:
>
> On Sat, 9 Jul 2022 14:18:49 -0700 Eric Biggers wrote:
> > Since the Linux RNG no longer uses sha1_transform(), the SHA-1 library
> > is no longer needed unconditionally. Make it possible to build the
> > Linux kernel without the SHA-1 library by putting it behind a kconfig
> > option, and selecting this new option from the kconfig options that gate
> > the remaining users: CRYPTO_SHA1 for crypto/sha1_generic.c, BPF for
> > kernel/bpf/core.c, and IPV6 for net/ipv6/addrconf.c.
> >
> > Unfortunately, since BPF is selected by NET, for now this can only make
> > a difference for kernels built without networking support.
>
> > diff --git a/init/Kconfig b/init/Kconfig
> > index c984afc489dead..d8d0b4bdfe4195 100644
> > --- a/init/Kconfig
> > +++ b/init/Kconfig
> > @@ -1472,6 +1472,7 @@ config HAVE_PCSPKR_PLATFORM
> > # interpreter that classic socket filters depend on
> > config BPF
> > bool
> > + select CRYPTO_LIB_SHA1
> >
>
> Let's give it an explicit CC: bpf@
>
> > diff --git a/net/ipv6/Kconfig b/net/ipv6/Kconfig
> > index bf2e5e5fe14273..658bfed1df8b17 100644
> > --- a/net/ipv6/Kconfig
> > +++ b/net/ipv6/Kconfig
> > @@ -7,6 +7,7 @@
> > menuconfig IPV6
> > tristate "The IPv6 protocol"
> > default y
> > + select CRYPTO_LIB_SHA1
> > help
> > Support for IP version 6 (IPv6).
>
> FWIW:
> Acked-by: Jakub Kicinski <kuba@kernel.org>
Acked-by: Alexei Starovoitov <ast@kernel.org>
I believe I found the right full patch set in lore.
In the future (if there are follow ups)
please cc the full patchset to us.
Thanks!
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [PATCH 0/2] crypto: make the sha1 library optional
2022-07-09 21:18 [PATCH 0/2] crypto: make the sha1 library optional Eric Biggers
2022-07-09 21:18 ` [PATCH 1/2] crypto: move lib/sha1.c into lib/crypto/ Eric Biggers
2022-07-09 21:18 ` [PATCH 2/2] crypto: make the sha1 library optional Eric Biggers
@ 2022-07-15 8:50 ` Herbert Xu
2022-07-18 17:49 ` Randy Dunlap
2 siblings, 1 reply; 10+ messages in thread
From: Herbert Xu @ 2022-07-15 8:50 UTC (permalink / raw)
To: Eric Biggers; +Cc: linux-crypto, linux-kernel, netdev, Jason
Eric Biggers <ebiggers@kernel.org> wrote:
> This series makes it possible to build the kernel without SHA-1 support,
> although for now this is only possible in minimal configurations, due to
> the uses of SHA-1 in the networking subsystem.
>
> Eric Biggers (2):
> crypto: move lib/sha1.c into lib/crypto/
> crypto: make the sha1 library optional
>
> crypto/Kconfig | 1 +
> init/Kconfig | 1 +
> lib/Makefile | 2 +-
> lib/crypto/Kconfig | 3 +++
> lib/crypto/Makefile | 3 +++
> lib/{ => crypto}/sha1.c | 0
> net/ipv6/Kconfig | 1 +
> 7 files changed, 10 insertions(+), 1 deletion(-)
> rename lib/{ => crypto}/sha1.c (100%)
>
>
> base-commit: 79e6e2f3f3ff345947075341781e900e4f70db81
All applied. Thanks.
--
Email: Herbert Xu <herbert@gondor.apana.org.au>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [PATCH 0/2] crypto: make the sha1 library optional
2022-07-15 8:50 ` [PATCH 0/2] " Herbert Xu
@ 2022-07-18 17:49 ` Randy Dunlap
2022-07-19 3:48 ` Eric Biggers
0 siblings, 1 reply; 10+ messages in thread
From: Randy Dunlap @ 2022-07-18 17:49 UTC (permalink / raw)
To: Herbert Xu, Eric Biggers; +Cc: linux-crypto, linux-kernel, netdev, Jason
On 7/15/22 01:50, Herbert Xu wrote:
> Eric Biggers <ebiggers@kernel.org> wrote:
>> This series makes it possible to build the kernel without SHA-1 support,
>> although for now this is only possible in minimal configurations, due to
>> the uses of SHA-1 in the networking subsystem.
>>
>> Eric Biggers (2):
>> crypto: move lib/sha1.c into lib/crypto/
>> crypto: make the sha1 library optional
>>
>> crypto/Kconfig | 1 +
>> init/Kconfig | 1 +
>> lib/Makefile | 2 +-
>> lib/crypto/Kconfig | 3 +++
>> lib/crypto/Makefile | 3 +++
>> lib/{ => crypto}/sha1.c | 0
>> net/ipv6/Kconfig | 1 +
>> 7 files changed, 10 insertions(+), 1 deletion(-)
>> rename lib/{ => crypto}/sha1.c (100%)
>>
>>
>> base-commit: 79e6e2f3f3ff345947075341781e900e4f70db81
>
> All applied. Thanks.
Eric,
linux-next-20220718 has a build error:
ERROR: modpost: missing MODULE_LICENSE() in lib/crypto/libsha1.o
--
~Randy
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [PATCH 0/2] crypto: make the sha1 library optional
2022-07-18 17:49 ` Randy Dunlap
@ 2022-07-19 3:48 ` Eric Biggers
0 siblings, 0 replies; 10+ messages in thread
From: Eric Biggers @ 2022-07-19 3:48 UTC (permalink / raw)
To: Randy Dunlap; +Cc: Herbert Xu, linux-crypto, linux-kernel, netdev, Jason
On Mon, Jul 18, 2022 at 10:49:07AM -0700, Randy Dunlap wrote:
>
>
> On 7/15/22 01:50, Herbert Xu wrote:
> > Eric Biggers <ebiggers@kernel.org> wrote:
> >> This series makes it possible to build the kernel without SHA-1 support,
> >> although for now this is only possible in minimal configurations, due to
> >> the uses of SHA-1 in the networking subsystem.
> >>
> >> Eric Biggers (2):
> >> crypto: move lib/sha1.c into lib/crypto/
> >> crypto: make the sha1 library optional
> >>
> >> crypto/Kconfig | 1 +
> >> init/Kconfig | 1 +
> >> lib/Makefile | 2 +-
> >> lib/crypto/Kconfig | 3 +++
> >> lib/crypto/Makefile | 3 +++
> >> lib/{ => crypto}/sha1.c | 0
> >> net/ipv6/Kconfig | 1 +
> >> 7 files changed, 10 insertions(+), 1 deletion(-)
> >> rename lib/{ => crypto}/sha1.c (100%)
> >>
> >>
> >> base-commit: 79e6e2f3f3ff345947075341781e900e4f70db81
> >
> > All applied. Thanks.
>
> Eric,
> linux-next-20220718 has a build error:
>
> ERROR: modpost: missing MODULE_LICENSE() in lib/crypto/libsha1.o
Thanks, https://lore.kernel.org/r/20220719030415.32113-1-ebiggers@kernel.org
fixes this.
- Eric
^ permalink raw reply [flat|nested] 10+ messages in thread
end of thread, other threads:[~2022-07-19 3:48 UTC | newest]
Thread overview: 10+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2022-07-09 21:18 [PATCH 0/2] crypto: make the sha1 library optional Eric Biggers
2022-07-09 21:18 ` [PATCH 1/2] crypto: move lib/sha1.c into lib/crypto/ Eric Biggers
2022-07-11 14:58 ` Jason A. Donenfeld
2022-07-09 21:18 ` [PATCH 2/2] crypto: make the sha1 library optional Eric Biggers
2022-07-11 14:59 ` Jason A. Donenfeld
2022-07-11 18:03 ` Jakub Kicinski
2022-07-15 1:18 ` Alexei Starovoitov
2022-07-15 8:50 ` [PATCH 0/2] " Herbert Xu
2022-07-18 17:49 ` Randy Dunlap
2022-07-19 3:48 ` Eric Biggers
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).