* [PATCH] Allow hmac(sha512) for unpriviledged users
@ 2026-10-03 16:03 Justin M. Forbes
2026-10-03 16:18 ` Eric Biggers
0 siblings, 1 reply; 5+ messages in thread
From: Justin M. Forbes @ 2026-10-03 16:03 UTC (permalink / raw)
To: Herbert Xu, David S. Miller, linux-crypto, linux-kernel; +Cc: Justin M. Forbes
By default users cannot run sha512hmac with the current set up. This
is problematic because our kernel builds call this for FIPS compliance.
Rather than have anyone turn off af_alg_restrict all together, let's
allow a common use case.
Signed-off-by: Justin M. Forbes <jforbes@fedoraproject.org>
---
crypto/algif_hash.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/crypto/algif_hash.c b/crypto/algif_hash.c
index 6e8b5fb82a7f..0d3ec5760de6 100644
--- a/crypto/algif_hash.c
+++ b/crypto/algif_hash.c
@@ -23,7 +23,7 @@ static const struct af_alg_allowlist_entry hash_allowlist[] = {
{ "hmac(sha224)" }, /* iwd */
{ "hmac(sha256)" }, /* iwd */
{ "hmac(sha384)" }, /* iwd */
- { "hmac(sha512)" }, /* iwd, sha512hmac */
+ { "hmac(sha512)", AF_ALG_UNPRIVILEGED }, /* iwd, sha512hmac */
{ "md4" }, /* iwd */
{ "md5" }, /* iwd */
{ "sha1", AF_ALG_UNPRIVILEGED }, /* iwd, iproute2 < 7.0 */
--
2.55.0
^ permalink raw reply [flat|nested] 5+ messages in thread* Re: [PATCH] Allow hmac(sha512) for unpriviledged users
2026-10-03 16:03 [PATCH] Allow hmac(sha512) for unpriviledged users Justin M. Forbes
@ 2026-10-03 16:18 ` Eric Biggers
2026-10-03 17:05 ` Justin Forbes
0 siblings, 1 reply; 5+ messages in thread
From: Eric Biggers @ 2026-10-03 16:18 UTC (permalink / raw)
To: Justin M. Forbes; +Cc: Herbert Xu, David S. Miller, linux-crypto, linux-kernel
On Sat, Oct 03, 2026 at 10:03:02AM -0600, Justin M. Forbes wrote:
> By default users cannot run sha512hmac with the current set up. This
> is problematic because our kernel builds call this for FIPS compliance.
> Rather than have anyone turn off af_alg_restrict all together, let's
> allow a common use case.
>
> Signed-off-by: Justin M. Forbes <jforbes@fedoraproject.org>
The fips hook in dracut was taken into account already, and it runs as
root. So this patch shouldn't be needed. Can you clarify why you think
it is needed?
- Eric
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH] Allow hmac(sha512) for unpriviledged users
2026-10-03 16:18 ` Eric Biggers
@ 2026-10-03 17:05 ` Justin Forbes
2026-10-03 17:37 ` Eric Biggers
0 siblings, 1 reply; 5+ messages in thread
From: Justin Forbes @ 2026-10-03 17:05 UTC (permalink / raw)
To: Eric Biggers; +Cc: Herbert Xu, David S. Miller, linux-crypto, linux-kernel
On Sat, Oct 03, 2026 at 06:18:59PM +0200, Eric Biggers wrote:
> On Sat, Oct 03, 2026 at 10:03:02AM -0600, Justin M. Forbes wrote:
> > By default users cannot run sha512hmac with the current set up. This
> > is problematic because our kernel builds call this for FIPS compliance.
> > Rather than have anyone turn off af_alg_restrict all together, let's
> > allow a common use case.
> >
> > Signed-off-by: Justin M. Forbes <jforbes@fedoraproject.org>
>
> The fips hook in dracut was taken into account already, and it runs as
> root. So this patch shouldn't be needed. Can you clarify why you think
> it is needed?
>
> - Eric
Specifically for the case of Fedora and all Red Hat kernels, we call
sha512hmac to sign the kernel, and a couple of UKI images that are
created during the kernel build. Users on Fedora 45 and newer are now
unable to build the kernel from spec without turning off af_alg_restrict
all together, while any user can build a kernel on Fedora 44 or older.
Justin
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH] Allow hmac(sha512) for unpriviledged users
2026-10-03 17:05 ` Justin Forbes
@ 2026-10-03 17:37 ` Eric Biggers
2026-10-03 17:43 ` Justin Forbes
0 siblings, 1 reply; 5+ messages in thread
From: Eric Biggers @ 2026-10-03 17:37 UTC (permalink / raw)
To: Justin Forbes; +Cc: Herbert Xu, David S. Miller, linux-crypto, linux-kernel
On Sat, Oct 03, 2026 at 11:05:31AM -0600, Justin Forbes wrote:
> On Sat, Oct 03, 2026 at 06:18:59PM +0200, Eric Biggers wrote:
> > On Sat, Oct 03, 2026 at 10:03:02AM -0600, Justin M. Forbes wrote:
> > > By default users cannot run sha512hmac with the current set up. This
> > > is problematic because our kernel builds call this for FIPS compliance.
> > > Rather than have anyone turn off af_alg_restrict all together, let's
> > > allow a common use case.
> > >
> > > Signed-off-by: Justin M. Forbes <jforbes@fedoraproject.org>
> >
> > The fips hook in dracut was taken into account already, and it runs as
> > root. So this patch shouldn't be needed. Can you clarify why you think
> > it is needed?
> >
> > - Eric
>
> Specifically for the case of Fedora and all Red Hat kernels, we call
> sha512hmac to sign the kernel, and a couple of UKI images that are
> created during the kernel build. Users on Fedora 45 and newer are now
> unable to build the kernel from spec without turning off af_alg_restrict
> all together, while any user can build a kernel on Fedora 44 or older.
I see, it's in redhat/kernel.spec.template in the Fedora kernel source
tree which is used when packaging the kernel into an RPM package.
Please make that super clear in your commit message, because it wasn't
clear you were talking about something different from the use in dracut.
I guess the actual diff is fine then, since something like this that's
being used should continue to be allowed.
Of course, this is yet another gratuitous use of AF_ALG, as I've
explained previously
(https://lore.kernel.org/r/20260504173952.GA2291@sol/). Depending
AF_ALG to build the kernel (vs. just using OpenSSL for example) is even
more misguided than using it in the integrity check itself, as at least
there are FIPS boundary considerations for the integrity check itself,
but those are irrelevant for the build tools.
So even though this will keep being allowed for now, please work to get
this fixed to not need AF_ALG. Note also that Fedora 45 explicitly
deprecates AF_ALG (https://lwn.net/Articles/1088489/) on top of the
already-documented upstream deprecation.
- Eric
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH] Allow hmac(sha512) for unpriviledged users
2026-10-03 17:37 ` Eric Biggers
@ 2026-10-03 17:43 ` Justin Forbes
0 siblings, 0 replies; 5+ messages in thread
From: Justin Forbes @ 2026-10-03 17:43 UTC (permalink / raw)
To: Eric Biggers; +Cc: Herbert Xu, David S. Miller, linux-crypto, linux-kernel
On Sat, Oct 03, 2026 at 07:37:44PM +0200, Eric Biggers wrote:
> On Sat, Oct 03, 2026 at 11:05:31AM -0600, Justin Forbes wrote:
> > On Sat, Oct 03, 2026 at 06:18:59PM +0200, Eric Biggers wrote:
> > > On Sat, Oct 03, 2026 at 10:03:02AM -0600, Justin M. Forbes wrote:
> > > > By default users cannot run sha512hmac with the current set up. This
> > > > is problematic because our kernel builds call this for FIPS compliance.
> > > > Rather than have anyone turn off af_alg_restrict all together, let's
> > > > allow a common use case.
> > > >
> > > > Signed-off-by: Justin M. Forbes <jforbes@fedoraproject.org>
> > >
> > > The fips hook in dracut was taken into account already, and it runs as
> > > root. So this patch shouldn't be needed. Can you clarify why you think
> > > it is needed?
> > >
> > > - Eric
> >
> > Specifically for the case of Fedora and all Red Hat kernels, we call
> > sha512hmac to sign the kernel, and a couple of UKI images that are
> > created during the kernel build. Users on Fedora 45 and newer are now
> > unable to build the kernel from spec without turning off af_alg_restrict
> > all together, while any user can build a kernel on Fedora 44 or older.
>
> I see, it's in redhat/kernel.spec.template in the Fedora kernel source
> tree which is used when packaging the kernel into an RPM package.
> Please make that super clear in your commit message, because it wasn't
> clear you were talking about something different from the use in dracut.
>
> I guess the actual diff is fine then, since something like this that's
> being used should continue to be allowed.
>
> Of course, this is yet another gratuitous use of AF_ALG, as I've
> explained previously
> (https://lore.kernel.org/r/20260504173952.GA2291@sol/). Depending
> AF_ALG to build the kernel (vs. just using OpenSSL for example) is even
> more misguided than using it in the integrity check itself, as at least
> there are FIPS boundary considerations for the integrity check itself,
> but those are irrelevant for the build tools.
>
> So even though this will keep being allowed for now, please work to get
> this fixed to not need AF_ALG. Note also that Fedora 45 explicitly
> deprecates AF_ALG (https://lwn.net/Articles/1088489/) on top of the
> already-documented upstream deprecation.
>
> - Eric
Understood. I am one of the people behind that change. Basically it
means we backported all of this into 7.2 to make sure that Fedora 45
ships with it by default. The hope is that we can get this all worked
out to the point that we can turn off AF_ALG all together by Fedora 46.
But this piece in particular caught me by surprise, and this will give
us time to get it fixed properly.
Thanks,
Justin
^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2026-10-03 17:43 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-03 16:03 [PATCH] Allow hmac(sha512) for unpriviledged users Justin M. Forbes
2026-10-03 16:18 ` Eric Biggers
2026-10-03 17:05 ` Justin Forbes
2026-10-03 17:37 ` Eric Biggers
2026-10-03 17:43 ` Justin Forbes
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®