From: Tom Rini <trini@konsulko.com>
To: Raymond Mao <raymond.mao@linaro.org>
Cc: u-boot@lists.denx.de, manish.pandey2@arm.com,
"Stefan Bosch" <stefan_b@posteo.net>,
"Mario Six" <mario.six@gdsys.cc>,
"Andy Shevchenko" <andriy.shevchenko@linux.intel.com>,
"Michal Simek" <michal.simek@amd.com>,
"Tuomas Tynkkynen" <tuomas.tynkkynen@iki.fi>,
"Simon Glass" <sjg@chromium.org>,
"Ilias Apalodimas" <ilias.apalodimas@linaro.org>,
"Leo Yu-Chi Liang" <ycliang@andestech.com>,
"Andrejs Cainikovs" <andrejs.cainikovs@toradex.com>,
"Marek Vasut" <marek.vasut+renesas@mailbox.org>,
"Sean Anderson" <seanga2@gmail.com>,
"Jesse Taube" <mr.bossman075@gmail.com>,
"Bryan Brattlof" <bb@ti.com>,
"Leon M. Busch-George" <leon@georgemail.eu>,
"Sergei Antonov" <saproj@gmail.com>,
"Ilya Lukin" <4.shket@gmail.com>,
"Igor Opaniuk" <igor.opaniuk@gmail.com>,
"Heinrich Schuchardt" <xypron.glpk@gmx.de>,
"Alper Nebi Yasak" <alpernebiyasak@gmail.com>,
"AKASHI Takahiro" <akashi.tkhro@gmail.com>,
"Abdellatif El Khlifi" <abdellatif.elkhlifi@arm.com>,
"Alexander Gendin" <agendin@matrox.com>,
"Bin Meng" <bmeng@tinylab.org>,
"Vincent Stehlé" <vincent.stehle@arm.com>,
"Oleksandr Suvorov" <oleksandr.suvorov@foundries.io>
Subject: Re: [PATCH v4 04/29] lib: Adapt digest header files to MbedTLS
Date: Tue, 2 Jul 2024 18:15:52 -0600 [thread overview]
Message-ID: <20240703001552.GW38804@bill-the-cat> (raw)
In-Reply-To: <CAEfUkULVRD_SQWP9f9bjRutXi33aqiEaNhTWfdF9qKWvLhKJ1g@mail.gmail.com>
[-- Attachment #1: Type: text/plain, Size: 6623 bytes --]
On Tue, Jul 02, 2024 at 08:02:37PM -0400, Raymond Mao wrote:
> Hi Tom,
>
> On Tue, 2 Jul 2024 at 18:48, Tom Rini <trini@konsulko.com> wrote:
>
> > On Tue, Jul 02, 2024 at 11:22:40AM -0700, Raymond Mao wrote:
> >
> > > Adapt digest header files to support both original libs and MbedTLS
> > > by switching on/off MBEDTLS_LIB_CRYPTO.
> > > Introduce <alg>_LEGACY kconfig for legacy hash implementations.
> > [snip]
> > > diff --git a/lib/mbedtls/Kconfig b/lib/mbedtls/Kconfig
> > > index 3e9057f1acf..6662a9d20f1 100644
> > > --- a/lib/mbedtls/Kconfig
> > > +++ b/lib/mbedtls/Kconfig
> > > @@ -21,9 +21,105 @@ if LEGACY_CRYPTO
> > >
> > > config LEGACY_CRYPTO_BASIC
> > > bool "legacy basic crypto libraries"
> > > + select MD5_LEGACY if MD5
> > > + select SHA1_LEGACY if SHA1
> > > + select SHA256_LEGACY if SHA256
> > > + select SHA512_LEGACY if SHA512
> > > + select SHA384_LEGACY if SHA384
> > > + select SPL_MD5_LEGACY if MD5 && SPL
> > > + select SPL_SHA1_LEGACY if SHA1 && SPL
> > > + select SPL_SHA256_LEGACY if SHA256 && SPL
> > > + select SPL_SHA512_LEGACY if SHA512 && SPL
> > > + select SPL_SHA384_LEGACY if SHA384 && SPL
> > > help
> > > Enable legacy basic crypto libraries.
> > >
> > > +if LEGACY_CRYPTO_BASIC
> > > +
> > > +config SHA1_LEGACY
> > > + bool "Enable SHA1 support with legacy crypto library"
> > > + depends on LEGACY_CRYPTO_BASIC && SHA1
> > > + help
> > > + This option enables support of hashing using SHA1 algorithm
> > > + with legacy crypto library.
> > > +
> > > +config SHA256_LEGACY
> > > + bool "Enable SHA256 support with legacy crypto library"
> > > + depends on LEGACY_CRYPTO_BASIC && SHA256
> > > + help
> > > + This option enables support of hashing using SHA256 algorithm
> > > + with legacy crypto library.
> > > +
> > > +config SHA512_LEGACY
> > > + bool "Enable SHA512 support with legacy crypto library"
> > > + depends on LEGACY_CRYPTO_BASIC && SHA512
> > > + default y if TI_SECURE_DEVICE && FIT_SIGNATURE
> > > + help
> > > + This option enables support of hashing using SHA512 algorithm
> > > + with legacy crypto library.
> > > +
> > > +config SHA384_LEGACY
> > > + bool "Enable SHA384 support with legacy crypto library"
> > > + depends on LEGACY_CRYPTO_BASIC && SHA384
> > > + select SHA512_LEGACY
> > > + help
> > > + This option enables support of hashing using SHA384 algorithm
> > > + with legacy crypto library.
> > > +
> > > +config MD5_LEGACY
> > > + bool "Enable MD5 support with legacy crypto library"
> > > + depends on LEGACY_CRYPTO_BASIC && MD5
> > > + help
> > > + This option enables support of hashing using MD5 algorithm
> > > + with legacy crypto library.
> > > +
> > > +if SPL
> > > +
> > > +config SPL_SHA1_LEGACY
> > > + bool "Enable SHA1 support in SPL with legacy crypto library"
> > > + depends on LEGACY_CRYPTO_BASIC && SPL_SHA1
> > > + default y if SHA1 && LEGACY_CRYPTO_BASIC
> > > + help
> > > + This option enables support of hashing using SHA1 algorithm
> > > + with legacy crypto library.
> > > +
> > > +config SPL_SHA256_LEGACY
> > > + bool "Enable SHA256 support in SPL with legacy crypto library"
> > > + depends on LEGACY_CRYPTO_BASIC && SPL_SHA256
> > > + default y if SHA256 && LEGACY_CRYPTO_BASIC
> > > + help
> > > + This option enables support of hashing using SHA256 algorithm
> > > + with legacy crypto library.
> > > +
> > > +config SPL_SHA512_LEGACY
> > > + bool "Enable SHA512 support in SPL with legacy crypto library"
> > > + depends on LEGACY_CRYPTO_BASIC && SPL_SHA512
> > > + default y if SHA512 && LEGACY_CRYPTO_BASIC
> > > + help
> > > + This option enables support of hashing using SHA512 algorithm
> > > + with legacy crypto library.
> > > +
> > > +config SPL_SHA384_LEGACY
> > > + bool "Enable SHA384 support in SPL with legacy crypto library"
> > > + depends on LEGACY_CRYPTO_BASIC && SPL_SHA384
> > > + default y if SHA384 && LEGACY_CRYPTO_BASIC
> > > + select SPL_SHA512
> > > + help
> > > + This option enables support of hashing using SHA384 algorithm
> > > + with legacy crypto library.
> > > +
> > > +config SPL_MD5_LEGACY
> > > + bool "Enable MD5 support in SPL with legacy crypto library"
> > > + depends on LEGACY_CRYPTO_BASIC && SPL_MD5
> > > + default y if MD5 && LEGACY_CRYPTO_BASIC
> > > + help
> > > + This option enables support of hashing using MD5 algorithm
> > > + with legacy crypto library.
> > > +
> > > +endif # SPL
> > > +
> > > +endif # LEGACY_CRYPTO_BASIC
> > > +
> > > config LEGACY_CRYPTO_CERT
> > > bool "legacy certificate libraries"
> > > help
> >
> > This is all certainly moving in the right direction, but there's
> > dependency issues:
> > aarch64: w+ xilinx_zynqmp_kria
> > +(xilinx_zynqmp_kria)
> > +(xilinx_zynqmp_kria) WARNING: unmet direct dependencies detected for
> > SPL_MD5_LEGACY
> > +(xilinx_zynqmp_kria) Depends on [n]: LEGACY_CRYPTO [=y] && SPL [=y] &&
> > LEGACY_CRYPTO_BASIC [=y] && SPL_MD5 [=n]
> > +(xilinx_zynqmp_kria) Selected by [y]:
> > +(xilinx_zynqmp_kria) - LEGACY_CRYPTO_BASIC [=y] && LEGACY_CRYPTO [=y]
> > && MD5 [=y] && SPL [=y]
> >
>
> I am a bit confused by SPL_MD5, why it is [n] when both MD5 and SPL are [y].
> Of course we can replace 'SPL_MD5' with 'MD5 && SPL' to solve the warning,
> but I guess the wrong dependence is on SPL_MD5 but not the new added ones.
> ```
> config SPL_MD5
> bool "Support MD5 algorithm in SPL"
> depends on SPL
> ```
> I think it should be 'default y if SPL && MD5' instead of 'depends on SPL'.
>
> Similarly SPL_ASYMMETRIC_PUBLIC_KEY_SUBTYPE is not selected when both
> ASYMMETRIC_PUBLIC_KEY_SUBTYPE
> and SPL are selected;
> SPL_ASN1_DECODER is not selected when both ASN1_DECODER and SPL are
> selected.
>
> I think generally for each algorithm, 'SPL_<ALG>' config should be selected
> when both 'SPL' and '<ALG>' are selected.
>
> If you agree I can fix this in the next patch set.
Kconfig error messages are a bit difficult to understand at times, yes.
Please figure out what exactly the depends on / default y combinations
should be such that (a) there's no functional changes, and buildman size
comparison builds are good for that and (b) no warnings like this are
found.
--
Tom
[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 659 bytes --]
next prev parent reply other threads:[~2024-07-03 0:16 UTC|newest]
Thread overview: 81+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-07-02 18:22 [PATCH v4 00/29] Integrate MbedTLS v3.6 LTS with U-Boot Raymond Mao
2024-07-02 18:22 ` [PATCH v4 01/29] CI: Exclude MbedTLS subtree for CONFIG checks Raymond Mao
2024-07-02 18:22 ` [PATCH v4 02/29] mbedtls: Add script to update MbedTLS subtree Raymond Mao
2024-07-02 20:56 ` Tom Rini
2024-07-03 7:16 ` Jerome Forissier
2024-07-03 14:36 ` Raymond Mao
2024-07-03 14:35 ` Raymond Mao
2024-07-02 18:22 ` [PATCH v4 03/29] mbedtls: add mbedtls into the build system Raymond Mao
2024-07-02 18:22 ` [PATCH v4 04/29] lib: Adapt digest header files to MbedTLS Raymond Mao
2024-07-02 22:48 ` Tom Rini
2024-07-03 0:02 ` Raymond Mao
2024-07-03 0:15 ` Tom Rini [this message]
2024-07-02 18:22 ` [PATCH v4 05/29] md5: Remove md5 non-watchdog API Raymond Mao
2024-07-02 18:22 ` [PATCH v4 06/29] sha1: Remove sha1 " Raymond Mao
2024-07-03 7:39 ` Ilias Apalodimas
2024-07-02 18:22 ` [PATCH v4 07/29] mbedtls: add digest shim layer for MbedTLS Raymond Mao
2024-07-26 10:18 ` Ilias Apalodimas
2024-07-26 14:01 ` Tom Rini
2024-07-26 14:29 ` Raymond Mao
2024-07-02 18:22 ` [PATCH v4 08/29] hash: integrate hash on mbedtls Raymond Mao
2024-07-03 8:56 ` Ilias Apalodimas
2024-07-05 8:35 ` Simon Glass
2024-07-18 16:45 ` Raymond Mao
2024-07-19 15:05 ` Simon Glass
2024-07-19 15:25 ` Tom Rini
2024-07-20 12:36 ` Simon Glass
2024-07-20 17:13 ` Tom Rini
2024-07-21 10:08 ` Simon Glass
2024-07-22 14:21 ` Raymond Mao
2024-07-22 14:35 ` Raymond Mao
2024-07-18 16:49 ` Raymond Mao
2024-07-02 18:22 ` [PATCH v4 09/29] makefile: add mbedtls include directories Raymond Mao
2024-07-03 11:34 ` Ilias Apalodimas
2024-07-18 20:01 ` Raymond Mao
2024-07-18 20:12 ` Raymond Mao
2024-07-23 7:44 ` Ilias Apalodimas
2024-07-23 17:05 ` Raymond Mao
2024-07-02 18:22 ` [PATCH v4 10/29] mbedtls/external: support Microsoft Authentication Code Raymond Mao
2024-07-02 18:22 ` [PATCH v4 11/29] mbedtls/external: support PKCS9 Authenticate Attributes Raymond Mao
2024-07-02 18:22 ` [PATCH v4 12/29] mbedtls/external: support decoding multiple signer's cert Raymond Mao
2024-07-02 18:22 ` [PATCH v4 13/29] mbedtls/external: update MbedTLS PKCS7 test suites Raymond Mao
2024-07-02 18:22 ` [PATCH v4 14/29] public_key: move common functions to public key helper Raymond Mao
2024-07-03 11:31 ` Ilias Apalodimas
2024-07-02 18:22 ` [PATCH v4 15/29] x509: move common functions to x509 helper Raymond Mao
2024-07-03 9:36 ` Ilias Apalodimas
2024-07-02 18:22 ` [PATCH v4 16/29] pkcs7: move common functions to PKCS7 helper Raymond Mao
2024-07-03 9:33 ` Ilias Apalodimas
2024-07-02 18:22 ` [PATCH v4 17/29] mbedtls: add public key porting layer Raymond Mao
2024-07-03 11:46 ` Ilias Apalodimas
2024-07-18 20:39 ` Raymond Mao
2024-07-02 18:22 ` [PATCH v4 18/29] lib/crypto: Adapt public_key header with MbedTLS Raymond Mao
2024-07-29 13:28 ` Ilias Apalodimas
2024-07-02 18:22 ` [PATCH v4 19/29] mbedtls: add X509 cert parser porting layer Raymond Mao
2024-07-02 18:22 ` [PATCH v4 20/29] lib/crypto: Adapt x509_cert_parser to MbedTLS Raymond Mao
2024-07-29 13:19 ` Ilias Apalodimas
2024-07-29 13:55 ` Raymond Mao
2024-07-02 18:22 ` [PATCH v4 21/29] mbedtls: add PKCS7 parser porting layer Raymond Mao
2024-07-02 18:22 ` [PATCH v4 22/29] lib/crypto: Adapt PKCS7 parser to MbedTLS Raymond Mao
2024-07-02 18:22 ` [PATCH v4 23/29] mbedtls: add MSCode parser porting layer Raymond Mao
2024-07-26 10:09 ` Ilias Apalodimas
2024-07-26 14:04 ` Raymond Mao
2024-07-02 18:23 ` [PATCH v4 24/29] lib/crypto: Adapt mscode_parser to MbedTLS Raymond Mao
2024-07-30 8:03 ` Ilias Apalodimas
2024-07-30 14:07 ` Raymond Mao
2024-07-02 18:23 ` [PATCH v4 25/29] mbedtls: add RSA helper layer on MbedTLS Raymond Mao
2024-07-30 8:04 ` Ilias Apalodimas
2024-07-30 14:05 ` Raymond Mao
2024-07-02 18:23 ` [PATCH v4 26/29] lib/rypto: Adapt rsa_helper to MbedTLS Raymond Mao
2024-07-23 9:14 ` Ilias Apalodimas
2024-07-02 18:23 ` [PATCH v4 27/29] asn1_decoder: add build options for ASN1 decoder Raymond Mao
2024-07-02 18:23 ` [PATCH v4 28/29] test: Remove ASN1 library test Raymond Mao
2024-07-02 18:23 ` [PATCH v4 29/29] configs: enable MbedTLS as default setting Raymond Mao
2024-07-03 11:56 ` Ilias Apalodimas
2024-07-03 1:25 ` [PATCH v4 00/29] Integrate MbedTLS v3.6 LTS with U-Boot Tom Rini
2024-07-23 19:24 ` Raymond Mao
2024-07-23 20:45 ` Tom Rini
2024-07-24 14:36 ` Simon Glass
2024-07-24 14:34 ` Raymond Mao
2024-07-24 14:37 ` Simon Glass
2024-07-24 22:42 ` Tom Rini
2024-07-25 13:36 ` Raymond Mao
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20240703001552.GW38804@bill-the-cat \
--to=trini@konsulko.com \
--cc=4.shket@gmail.com \
--cc=abdellatif.elkhlifi@arm.com \
--cc=agendin@matrox.com \
--cc=akashi.tkhro@gmail.com \
--cc=alpernebiyasak@gmail.com \
--cc=andrejs.cainikovs@toradex.com \
--cc=andriy.shevchenko@linux.intel.com \
--cc=bb@ti.com \
--cc=bmeng@tinylab.org \
--cc=igor.opaniuk@gmail.com \
--cc=ilias.apalodimas@linaro.org \
--cc=leon@georgemail.eu \
--cc=manish.pandey2@arm.com \
--cc=marek.vasut+renesas@mailbox.org \
--cc=mario.six@gdsys.cc \
--cc=michal.simek@amd.com \
--cc=mr.bossman075@gmail.com \
--cc=oleksandr.suvorov@foundries.io \
--cc=raymond.mao@linaro.org \
--cc=saproj@gmail.com \
--cc=seanga2@gmail.com \
--cc=sjg@chromium.org \
--cc=stefan_b@posteo.net \
--cc=tuomas.tynkkynen@iki.fi \
--cc=u-boot@lists.denx.de \
--cc=vincent.stehle@arm.com \
--cc=xypron.glpk@gmx.de \
--cc=ycliang@andestech.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.