mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Eric Biggers <ebiggers@kernel.org>
To: Justin Forbes <jforbes@fedoraproject.org>
Cc: Herbert Xu <herbert@gondor.apana.org.au>,
	"David S. Miller" <davem@davemloft.net>,
	linux-crypto@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH] Allow hmac(sha512) for unpriviledged users
Date: Sat, 3 Oct 2026 19:37:44 +0200	[thread overview]
Message-ID: <20261003173744.GA158720@quark> (raw)
In-Reply-To: <asE128W4CxHDCFiB@fedora64.linuxtx.org>

On Sat, Oct 03, 2026 at 11:05:31AM -0600, Justin Forbes wrote:
> On Sat, Oct 03, 2026 at 06:18:59PM +0200, Eric Biggers wrote:
> > On Sat, Oct 03, 2026 at 10:03:02AM -0600, Justin M. Forbes wrote:
> > > By default users cannot run sha512hmac with the current set up. This
> > > is problematic because our kernel builds call this for FIPS compliance.
> > > Rather than have anyone turn off af_alg_restrict all together, let's
> > > allow a common use case.
> > > 
> > > Signed-off-by: Justin M. Forbes <jforbes@fedoraproject.org>
> > 
> > The fips hook in dracut was taken into account already, and it runs as
> > root.  So this patch shouldn't be needed.  Can you clarify why you think
> > it is needed?
> > 
> > - Eric
> 
> Specifically for the case of Fedora and all Red Hat kernels, we call
> sha512hmac to sign the kernel, and a couple of UKI images that are
> created during the kernel build. Users on Fedora 45 and newer are now
> unable to build the kernel from spec without turning off af_alg_restrict
> all together, while any user can build a kernel on Fedora 44 or older.

I see, it's in redhat/kernel.spec.template in the Fedora kernel source
tree which is used when packaging the kernel into an RPM package.
Please make that super clear in your commit message, because it wasn't
clear you were talking about something different from the use in dracut.

I guess the actual diff is fine then, since something like this that's
being used should continue to be allowed.

Of course, this is yet another gratuitous use of AF_ALG, as I've
explained previously
(https://lore.kernel.org/r/20260504173952.GA2291@sol/).  Depending
AF_ALG to build the kernel (vs. just using OpenSSL for example) is even
more misguided than using it in the integrity check itself, as at least
there are FIPS boundary considerations for the integrity check itself,
but those are irrelevant for the build tools.

So even though this will keep being allowed for now, please work to get
this fixed to not need AF_ALG.  Note also that Fedora 45 explicitly
deprecates AF_ALG (https://lwn.net/Articles/1088489/) on top of the
already-documented upstream deprecation.

- Eric

  reply	other threads:[~2026-10-03 17:37 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-03 16:03 Justin M. Forbes
2026-10-03 16:18 ` Eric Biggers
2026-10-03 17:05   ` Justin Forbes
2026-10-03 17:37     ` Eric Biggers [this message]
2026-10-03 17:43       ` Justin Forbes

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261003173744.GA158720@quark \
    --to=ebiggers@kernel.org \
    --cc=davem@davemloft.net \
    --cc=herbert@gondor.apana.org.au \
    --cc=jforbes@fedoraproject.org \
    --cc=linux-crypto@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®