netdev.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* [PATCH 0/2] crypto: make the sha1 library optional
@ 2022-07-09 21:18 Eric Biggers
  2022-07-09 21:18 ` [PATCH 1/2] crypto: move lib/sha1.c into lib/crypto/ Eric Biggers
                   ` (2 more replies)
  0 siblings, 3 replies; 10+ messages in thread
From: Eric Biggers @ 2022-07-09 21:18 UTC (permalink / raw)
  To: linux-crypto; +Cc: linux-kernel, netdev, Jason A . Donenfeld 

This series makes it possible to build the kernel without SHA-1 support,
although for now this is only possible in minimal configurations, due to
the uses of SHA-1 in the networking subsystem.

Eric Biggers (2):
  crypto: move lib/sha1.c into lib/crypto/
  crypto: make the sha1 library optional

 crypto/Kconfig          | 1 +
 init/Kconfig            | 1 +
 lib/Makefile            | 2 +-
 lib/crypto/Kconfig      | 3 +++
 lib/crypto/Makefile     | 3 +++
 lib/{ => crypto}/sha1.c | 0
 net/ipv6/Kconfig        | 1 +
 7 files changed, 10 insertions(+), 1 deletion(-)
 rename lib/{ => crypto}/sha1.c (100%)


base-commit: 79e6e2f3f3ff345947075341781e900e4f70db81
-- 
2.37.0


^ permalink raw reply	[flat|nested] 10+ messages in thread

* [PATCH 1/2] crypto: move lib/sha1.c into lib/crypto/
  2022-07-09 21:18 [PATCH 0/2] crypto: make the sha1 library optional Eric Biggers
@ 2022-07-09 21:18 ` Eric Biggers
  2022-07-11 14:58   ` Jason A. Donenfeld
  2022-07-09 21:18 ` [PATCH 2/2] crypto: make the sha1 library optional Eric Biggers
  2022-07-15  8:50 ` [PATCH 0/2] " Herbert Xu
  2 siblings, 1 reply; 10+ messages in thread
From: Eric Biggers @ 2022-07-09 21:18 UTC (permalink / raw)
  To: linux-crypto; +Cc: linux-kernel, netdev, Jason A . Donenfeld 

From: Eric Biggers <ebiggers@google.com>

SHA-1 is a crypto algorithm (or at least was intended to be -- it's not
considered secure anymore), so move it out of the top-level library
directory and into lib/crypto/.

Signed-off-by: Eric Biggers <ebiggers@google.com>
---
 lib/Makefile            | 2 +-
 lib/crypto/Makefile     | 2 ++
 lib/{ => crypto}/sha1.c | 0
 3 files changed, 3 insertions(+), 1 deletion(-)
 rename lib/{ => crypto}/sha1.c (100%)

diff --git a/lib/Makefile b/lib/Makefile
index f99bf61f8bbc67..67482f5ec0e899 100644
--- a/lib/Makefile
+++ b/lib/Makefile
@@ -29,7 +29,7 @@ endif
 
 lib-y := ctype.o string.o vsprintf.o cmdline.o \
 	 rbtree.o radix-tree.o timerqueue.o xarray.o \
-	 idr.o extable.o sha1.o irq_regs.o argv_split.o \
+	 idr.o extable.o irq_regs.o argv_split.o \
 	 flex_proportions.o ratelimit.o show_mem.o \
 	 is_single_threaded.o plist.o decompress.o kobject_uevent.o \
 	 earlycpio.o seq_buf.o siphash.o dec_and_lock.o \
diff --git a/lib/crypto/Makefile b/lib/crypto/Makefile
index 26be2bbe09c59e..d28111ba54fcb2 100644
--- a/lib/crypto/Makefile
+++ b/lib/crypto/Makefile
@@ -34,6 +34,8 @@ libpoly1305-y					:= poly1305-donna32.o
 libpoly1305-$(CONFIG_ARCH_SUPPORTS_INT128)	:= poly1305-donna64.o
 libpoly1305-y					+= poly1305.o
 
+obj-y						+= sha1.o
+
 obj-$(CONFIG_CRYPTO_LIB_SHA256)			+= libsha256.o
 libsha256-y					:= sha256.o
 
diff --git a/lib/sha1.c b/lib/crypto/sha1.c
similarity index 100%
rename from lib/sha1.c
rename to lib/crypto/sha1.c
-- 
2.37.0


^ permalink raw reply related	[flat|nested] 10+ messages in thread

* [PATCH 2/2] crypto: make the sha1 library optional
  2022-07-09 21:18 [PATCH 0/2] crypto: make the sha1 library optional Eric Biggers
  2022-07-09 21:18 ` [PATCH 1/2] crypto: move lib/sha1.c into lib/crypto/ Eric Biggers
@ 2022-07-09 21:18 ` Eric Biggers
  2022-07-11 14:59   ` Jason A. Donenfeld
  2022-07-11 18:03   ` Jakub Kicinski
  2022-07-15  8:50 ` [PATCH 0/2] " Herbert Xu
  2 siblings, 2 replies; 10+ messages in thread
From: Eric Biggers @ 2022-07-09 21:18 UTC (permalink / raw)
  To: linux-crypto; +Cc: linux-kernel, netdev, Jason A . Donenfeld 

From: Eric Biggers <ebiggers@google.com>

Since the Linux RNG no longer uses sha1_transform(), the SHA-1 library
is no longer needed unconditionally.  Make it possible to build the
Linux kernel without the SHA-1 library by putting it behind a kconfig
option, and selecting this new option from the kconfig options that gate
the remaining users: CRYPTO_SHA1 for crypto/sha1_generic.c, BPF for
kernel/bpf/core.c, and IPV6 for net/ipv6/addrconf.c.

Unfortunately, since BPF is selected by NET, for now this can only make
a difference for kernels built without networking support.

Signed-off-by: Eric Biggers <ebiggers@google.com>
---
 crypto/Kconfig      | 1 +
 init/Kconfig        | 1 +
 lib/crypto/Kconfig  | 3 +++
 lib/crypto/Makefile | 3 ++-
 net/ipv6/Kconfig    | 1 +
 5 files changed, 8 insertions(+), 1 deletion(-)

diff --git a/crypto/Kconfig b/crypto/Kconfig
index 59489a300cd100..bf15ca5eb9d367 100644
--- a/crypto/Kconfig
+++ b/crypto/Kconfig
@@ -880,6 +880,7 @@ config CRYPTO_RMD160
 config CRYPTO_SHA1
 	tristate "SHA1 digest algorithm"
 	select CRYPTO_HASH
+	select CRYPTO_LIB_SHA1
 	help
 	  SHA-1 secure hash standard (FIPS 180-1/DFIPS 180-2).
 
diff --git a/init/Kconfig b/init/Kconfig
index c984afc489dead..d8d0b4bdfe4195 100644
--- a/init/Kconfig
+++ b/init/Kconfig
@@ -1472,6 +1472,7 @@ config HAVE_PCSPKR_PLATFORM
 # interpreter that classic socket filters depend on
 config BPF
 	bool
+	select CRYPTO_LIB_SHA1
 
 menuconfig EXPERT
 	bool "Configure standard kernel features (expert users)"
diff --git a/lib/crypto/Kconfig b/lib/crypto/Kconfig
index 2082af43d51fbe..9ff549f63540fa 100644
--- a/lib/crypto/Kconfig
+++ b/lib/crypto/Kconfig
@@ -121,6 +121,9 @@ config CRYPTO_LIB_CHACHA20POLY1305
 	select CRYPTO_LIB_POLY1305
 	select CRYPTO_ALGAPI
 
+config CRYPTO_LIB_SHA1
+	tristate
+
 config CRYPTO_LIB_SHA256
 	tristate
 
diff --git a/lib/crypto/Makefile b/lib/crypto/Makefile
index d28111ba54fcb2..919cbb2c220d61 100644
--- a/lib/crypto/Makefile
+++ b/lib/crypto/Makefile
@@ -34,7 +34,8 @@ libpoly1305-y					:= poly1305-donna32.o
 libpoly1305-$(CONFIG_ARCH_SUPPORTS_INT128)	:= poly1305-donna64.o
 libpoly1305-y					+= poly1305.o
 
-obj-y						+= sha1.o
+obj-$(CONFIG_CRYPTO_LIB_SHA1)			+= libsha1.o
+libsha1-y					:= sha1.o
 
 obj-$(CONFIG_CRYPTO_LIB_SHA256)			+= libsha256.o
 libsha256-y					:= sha256.o
diff --git a/net/ipv6/Kconfig b/net/ipv6/Kconfig
index bf2e5e5fe14273..658bfed1df8b17 100644
--- a/net/ipv6/Kconfig
+++ b/net/ipv6/Kconfig
@@ -7,6 +7,7 @@
 menuconfig IPV6
 	tristate "The IPv6 protocol"
 	default y
+	select CRYPTO_LIB_SHA1
 	help
 	  Support for IP version 6 (IPv6).
 
-- 
2.37.0


^ permalink raw reply related	[flat|nested] 10+ messages in thread

* Re: [PATCH 1/2] crypto: move lib/sha1.c into lib/crypto/
  2022-07-09 21:18 ` [PATCH 1/2] crypto: move lib/sha1.c into lib/crypto/ Eric Biggers
@ 2022-07-11 14:58   ` Jason A. Donenfeld
  0 siblings, 0 replies; 10+ messages in thread
From: Jason A. Donenfeld @ 2022-07-11 14:58 UTC (permalink / raw)
  To: Eric Biggers; +Cc: linux-crypto, linux-kernel, netdev

On Sat, Jul 09, 2022 at 02:18:48PM -0700, Eric Biggers wrote:
> From: Eric Biggers <ebiggers@google.com>
> 
> SHA-1 is a crypto algorithm (or at least was intended to be -- it's not
> considered secure anymore), so move it out of the top-level library
> directory and into lib/crypto/.
> 
> Signed-off-by: Eric Biggers <ebiggers@google.com>

Thanks for this.

Reviewed-by: Jason A. Donenfeld <Jason@zx2c4.com>

^ permalink raw reply	[flat|nested] 10+ messages in thread

* Re: [PATCH 2/2] crypto: make the sha1 library optional
  2022-07-09 21:18 ` [PATCH 2/2] crypto: make the sha1 library optional Eric Biggers
@ 2022-07-11 14:59   ` Jason A. Donenfeld
  2022-07-11 18:03   ` Jakub Kicinski
  1 sibling, 0 replies; 10+ messages in thread
From: Jason A. Donenfeld @ 2022-07-11 14:59 UTC (permalink / raw)
  To: Eric Biggers; +Cc: linux-crypto, linux-kernel, netdev

On Sat, Jul 09, 2022 at 02:18:49PM -0700, Eric Biggers wrote:
> From: Eric Biggers <ebiggers@google.com>
> 
> Since the Linux RNG no longer uses sha1_transform(), the SHA-1 library
> is no longer needed unconditionally.  Make it possible to build the
> Linux kernel without the SHA-1 library by putting it behind a kconfig
> option, and selecting this new option from the kconfig options that gate
> the remaining users: CRYPTO_SHA1 for crypto/sha1_generic.c, BPF for
> kernel/bpf/core.c, and IPV6 for net/ipv6/addrconf.c.
> 
> Unfortunately, since BPF is selected by NET, for now this can only make
> a difference for kernels built without networking support.

Seems like a step in the right direction, thanks.

Reviewed-by: Jason A. Donenfeld <Jason@zx2c4.com>

^ permalink raw reply	[flat|nested] 10+ messages in thread

* Re: [PATCH 2/2] crypto: make the sha1 library optional
  2022-07-09 21:18 ` [PATCH 2/2] crypto: make the sha1 library optional Eric Biggers
  2022-07-11 14:59   ` Jason A. Donenfeld
@ 2022-07-11 18:03   ` Jakub Kicinski
  2022-07-15  1:18     ` Alexei Starovoitov
  1 sibling, 1 reply; 10+ messages in thread
From: Jakub Kicinski @ 2022-07-11 18:03 UTC (permalink / raw)
  To: Eric Biggers
  Cc: linux-crypto, linux-kernel, netdev, Jason A . Donenfeld , bpf

On Sat,  9 Jul 2022 14:18:49 -0700 Eric Biggers wrote:
> Since the Linux RNG no longer uses sha1_transform(), the SHA-1 library
> is no longer needed unconditionally.  Make it possible to build the
> Linux kernel without the SHA-1 library by putting it behind a kconfig
> option, and selecting this new option from the kconfig options that gate
> the remaining users: CRYPTO_SHA1 for crypto/sha1_generic.c, BPF for
> kernel/bpf/core.c, and IPV6 for net/ipv6/addrconf.c.
> 
> Unfortunately, since BPF is selected by NET, for now this can only make
> a difference for kernels built without networking support.

> diff --git a/init/Kconfig b/init/Kconfig
> index c984afc489dead..d8d0b4bdfe4195 100644
> --- a/init/Kconfig
> +++ b/init/Kconfig
> @@ -1472,6 +1472,7 @@ config HAVE_PCSPKR_PLATFORM
>  # interpreter that classic socket filters depend on
>  config BPF
>  	bool
> +	select CRYPTO_LIB_SHA1
>  

Let's give it an explicit CC: bpf@

> diff --git a/net/ipv6/Kconfig b/net/ipv6/Kconfig
> index bf2e5e5fe14273..658bfed1df8b17 100644
> --- a/net/ipv6/Kconfig
> +++ b/net/ipv6/Kconfig
> @@ -7,6 +7,7 @@
>  menuconfig IPV6
>  	tristate "The IPv6 protocol"
>  	default y
> +	select CRYPTO_LIB_SHA1
>  	help
>  	  Support for IP version 6 (IPv6).

FWIW:
Acked-by: Jakub Kicinski <kuba@kernel.org>

^ permalink raw reply	[flat|nested] 10+ messages in thread

* Re: [PATCH 2/2] crypto: make the sha1 library optional
  2022-07-11 18:03   ` Jakub Kicinski
@ 2022-07-15  1:18     ` Alexei Starovoitov
  0 siblings, 0 replies; 10+ messages in thread
From: Alexei Starovoitov @ 2022-07-15  1:18 UTC (permalink / raw)
  To: Jakub Kicinski
  Cc: Eric Biggers, Linux Crypto Mailing List, LKML,
	Network Development, Jason A . Donenfeld, bpf

On Mon, Jul 11, 2022 at 11:22 AM Jakub Kicinski <kuba@kernel.org> wrote:
>
> On Sat,  9 Jul 2022 14:18:49 -0700 Eric Biggers wrote:
> > Since the Linux RNG no longer uses sha1_transform(), the SHA-1 library
> > is no longer needed unconditionally.  Make it possible to build the
> > Linux kernel without the SHA-1 library by putting it behind a kconfig
> > option, and selecting this new option from the kconfig options that gate
> > the remaining users: CRYPTO_SHA1 for crypto/sha1_generic.c, BPF for
> > kernel/bpf/core.c, and IPV6 for net/ipv6/addrconf.c.
> >
> > Unfortunately, since BPF is selected by NET, for now this can only make
> > a difference for kernels built without networking support.
>
> > diff --git a/init/Kconfig b/init/Kconfig
> > index c984afc489dead..d8d0b4bdfe4195 100644
> > --- a/init/Kconfig
> > +++ b/init/Kconfig
> > @@ -1472,6 +1472,7 @@ config HAVE_PCSPKR_PLATFORM
> >  # interpreter that classic socket filters depend on
> >  config BPF
> >       bool
> > +     select CRYPTO_LIB_SHA1
> >
>
> Let's give it an explicit CC: bpf@
>
> > diff --git a/net/ipv6/Kconfig b/net/ipv6/Kconfig
> > index bf2e5e5fe14273..658bfed1df8b17 100644
> > --- a/net/ipv6/Kconfig
> > +++ b/net/ipv6/Kconfig
> > @@ -7,6 +7,7 @@
> >  menuconfig IPV6
> >       tristate "The IPv6 protocol"
> >       default y
> > +     select CRYPTO_LIB_SHA1
> >       help
> >         Support for IP version 6 (IPv6).
>
> FWIW:
> Acked-by: Jakub Kicinski <kuba@kernel.org>

Acked-by: Alexei Starovoitov <ast@kernel.org>

I believe I found the right full patch set in lore.
In the future (if there are follow ups)
please cc the full patchset to us.
Thanks!

^ permalink raw reply	[flat|nested] 10+ messages in thread

* Re: [PATCH 0/2] crypto: make the sha1 library optional
  2022-07-09 21:18 [PATCH 0/2] crypto: make the sha1 library optional Eric Biggers
  2022-07-09 21:18 ` [PATCH 1/2] crypto: move lib/sha1.c into lib/crypto/ Eric Biggers
  2022-07-09 21:18 ` [PATCH 2/2] crypto: make the sha1 library optional Eric Biggers
@ 2022-07-15  8:50 ` Herbert Xu
  2022-07-18 17:49   ` Randy Dunlap
  2 siblings, 1 reply; 10+ messages in thread
From: Herbert Xu @ 2022-07-15  8:50 UTC (permalink / raw)
  To: Eric Biggers; +Cc: linux-crypto, linux-kernel, netdev, Jason

Eric Biggers <ebiggers@kernel.org> wrote:
> This series makes it possible to build the kernel without SHA-1 support,
> although for now this is only possible in minimal configurations, due to
> the uses of SHA-1 in the networking subsystem.
> 
> Eric Biggers (2):
>  crypto: move lib/sha1.c into lib/crypto/
>  crypto: make the sha1 library optional
> 
> crypto/Kconfig          | 1 +
> init/Kconfig            | 1 +
> lib/Makefile            | 2 +-
> lib/crypto/Kconfig      | 3 +++
> lib/crypto/Makefile     | 3 +++
> lib/{ => crypto}/sha1.c | 0
> net/ipv6/Kconfig        | 1 +
> 7 files changed, 10 insertions(+), 1 deletion(-)
> rename lib/{ => crypto}/sha1.c (100%)
> 
> 
> base-commit: 79e6e2f3f3ff345947075341781e900e4f70db81

All applied.  Thanks.
-- 
Email: Herbert Xu <herbert@gondor.apana.org.au>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt

^ permalink raw reply	[flat|nested] 10+ messages in thread

* Re: [PATCH 0/2] crypto: make the sha1 library optional
  2022-07-15  8:50 ` [PATCH 0/2] " Herbert Xu
@ 2022-07-18 17:49   ` Randy Dunlap
  2022-07-19  3:48     ` Eric Biggers
  0 siblings, 1 reply; 10+ messages in thread
From: Randy Dunlap @ 2022-07-18 17:49 UTC (permalink / raw)
  To: Herbert Xu, Eric Biggers; +Cc: linux-crypto, linux-kernel, netdev, Jason



On 7/15/22 01:50, Herbert Xu wrote:
> Eric Biggers <ebiggers@kernel.org> wrote:
>> This series makes it possible to build the kernel without SHA-1 support,
>> although for now this is only possible in minimal configurations, due to
>> the uses of SHA-1 in the networking subsystem.
>>
>> Eric Biggers (2):
>>  crypto: move lib/sha1.c into lib/crypto/
>>  crypto: make the sha1 library optional
>>
>> crypto/Kconfig          | 1 +
>> init/Kconfig            | 1 +
>> lib/Makefile            | 2 +-
>> lib/crypto/Kconfig      | 3 +++
>> lib/crypto/Makefile     | 3 +++
>> lib/{ => crypto}/sha1.c | 0
>> net/ipv6/Kconfig        | 1 +
>> 7 files changed, 10 insertions(+), 1 deletion(-)
>> rename lib/{ => crypto}/sha1.c (100%)
>>
>>
>> base-commit: 79e6e2f3f3ff345947075341781e900e4f70db81
> 
> All applied.  Thanks.

Eric,
linux-next-20220718 has a build error:

ERROR: modpost: missing MODULE_LICENSE() in lib/crypto/libsha1.o

-- 
~Randy

^ permalink raw reply	[flat|nested] 10+ messages in thread

* Re: [PATCH 0/2] crypto: make the sha1 library optional
  2022-07-18 17:49   ` Randy Dunlap
@ 2022-07-19  3:48     ` Eric Biggers
  0 siblings, 0 replies; 10+ messages in thread
From: Eric Biggers @ 2022-07-19  3:48 UTC (permalink / raw)
  To: Randy Dunlap; +Cc: Herbert Xu, linux-crypto, linux-kernel, netdev, Jason

On Mon, Jul 18, 2022 at 10:49:07AM -0700, Randy Dunlap wrote:
> 
> 
> On 7/15/22 01:50, Herbert Xu wrote:
> > Eric Biggers <ebiggers@kernel.org> wrote:
> >> This series makes it possible to build the kernel without SHA-1 support,
> >> although for now this is only possible in minimal configurations, due to
> >> the uses of SHA-1 in the networking subsystem.
> >>
> >> Eric Biggers (2):
> >>  crypto: move lib/sha1.c into lib/crypto/
> >>  crypto: make the sha1 library optional
> >>
> >> crypto/Kconfig          | 1 +
> >> init/Kconfig            | 1 +
> >> lib/Makefile            | 2 +-
> >> lib/crypto/Kconfig      | 3 +++
> >> lib/crypto/Makefile     | 3 +++
> >> lib/{ => crypto}/sha1.c | 0
> >> net/ipv6/Kconfig        | 1 +
> >> 7 files changed, 10 insertions(+), 1 deletion(-)
> >> rename lib/{ => crypto}/sha1.c (100%)
> >>
> >>
> >> base-commit: 79e6e2f3f3ff345947075341781e900e4f70db81
> > 
> > All applied.  Thanks.
> 
> Eric,
> linux-next-20220718 has a build error:
> 
> ERROR: modpost: missing MODULE_LICENSE() in lib/crypto/libsha1.o

Thanks, https://lore.kernel.org/r/20220719030415.32113-1-ebiggers@kernel.org
fixes this.

- Eric

^ permalink raw reply	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2022-07-19  3:48 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2022-07-09 21:18 [PATCH 0/2] crypto: make the sha1 library optional Eric Biggers
2022-07-09 21:18 ` [PATCH 1/2] crypto: move lib/sha1.c into lib/crypto/ Eric Biggers
2022-07-11 14:58   ` Jason A. Donenfeld
2022-07-09 21:18 ` [PATCH 2/2] crypto: make the sha1 library optional Eric Biggers
2022-07-11 14:59   ` Jason A. Donenfeld
2022-07-11 18:03   ` Jakub Kicinski
2022-07-15  1:18     ` Alexei Starovoitov
2022-07-15  8:50 ` [PATCH 0/2] " Herbert Xu
2022-07-18 17:49   ` Randy Dunlap
2022-07-19  3:48     ` Eric Biggers

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).