All of lore.kernel.org
 help / color / mirror / Atom feed
From: Eric Biggers <ebiggers@kernel.org>
To: Richard Weinberger <richard.weinberger@gmail.com>
Cc: Dominique Martinet <asmadeus@codewreck.org>,
	demiobenour@gmail.com,
	Harald Freudenberger <freude@linux.ibm.com>,
	acme@kernel.org, adrian.hunter@intel.com,
	alexander.shishkin@linux.intel.com, ardb@kernel.org,
	axboe@kernel.dk, corbet@lwn.net, davem@davemloft.net,
	edumazet@google.com, herbert@gondor.apana.org.au,
	horms@kernel.org, io-uring@vger.kernel.org, irogers@google.com,
	james.clark@linaro.org, jolsa@kernel.org, kuba@kernel.org,
	kuniyu@google.com, linux-crypto@vger.kernel.org,
	linux-doc@vger.kernel.org, linux-kernel@vger.kernel.org,
	linux-perf-users@vger.kernel.org, mark.rutland@arm.com,
	mingo@redhat.com, namhyung@kernel.org, netdev@vger.kernel.org,
	pabeni@redhat.com, peterz@infradead.org,
	skhan@linuxfoundation.org, willemb@google.com,
	linux-s390@vger.kernel.org
Subject: Re: [PATCH 2/3] AF_ALG: Drop support for off-CPU cryptography
Date: Mon, 27 Jul 2026 17:20:04 +0000	[thread overview]
Message-ID: <20260727172004.GA877700@google.com> (raw)
In-Reply-To: <CAFLxGvzaAH+ZGr-OFo=Li1aOxgwBjjR76T7m1CjFaL-6w3KPPQ@mail.gmail.com>

On Sun, Jul 26, 2026 at 10:10:48PM +0200, Richard Weinberger wrote:
> On Sun, Jul 26, 2026 at 5:52 PM Eric Biggers <ebiggers@kernel.org> wrote:
> > Then I would suggest that skcipher_bind() should check if the name is
> > "cbc(paes)", and if so use 0 instead of AF_ALG_CRYPTOAPI_MASK.  Please
> > go ahead and send a patch against mainline (for v7.2-rc6) if you're
> > interested.
> 
> Patch sent.
> 
> > On cryptodev/master (future 7.3) it should get an entry in the new
> > skcipher_allowlist as well: { "cbc(paes)", true }.  That would be a
> > separate patch.
> 
> Do you mind a new field in struct af_alg_allowlist_entry which indicates
> that  AF_ALG_CRYPTOAPI_MASK should get bypassed?
> 
> bool bypass_apimask;?

Let's wait and see if it's needed for another algorithm before
generalizing this.

Note: if it does happen, the list definitions should start using
designated initializers so that it's clear what the bools are.
Alternatively, it could be a flags field with possible values
AF_ALG_UNPRIVILEGED and AF_ALG_ALLOW_OFF_CPU.

- Eric

  reply	other threads:[~2026-07-27 17:20 UTC|newest]

Thread overview: 37+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-05-23 19:43 [PATCH 0/3] AF_ALG: Remove support for AIO and old-style drivers Demi Marie Obenour
2026-05-23 19:43 ` Demi Marie Obenour via B4 Relay
2026-05-23 19:43 ` [PATCH 1/3] net: Remove support for AIO on sockets Demi Marie Obenour
2026-05-23 19:43   ` Demi Marie Obenour via B4 Relay
2026-05-25  8:03   ` Christoph Hellwig
2026-05-26 15:58     ` Jens Axboe
2026-05-27  8:13       ` Christoph Hellwig
2026-05-28 16:56         ` Jens Axboe
2026-05-29 13:59           ` Christoph Hellwig
2026-05-27  1:40   ` Jakub Kicinski
2026-05-30  0:47   ` sashiko-bot
2026-05-23 19:43 ` [PATCH 2/3] AF_ALG: Drop support for off-CPU cryptography Demi Marie Obenour
2026-05-23 19:43   ` Demi Marie Obenour via B4 Relay
2026-05-30  0:47   ` sashiko-bot
2026-06-03 13:33   ` Harald Freudenberger
2026-07-24 15:35     ` Dominique Martinet
2026-07-24 16:00       ` Eric Biggers
2026-07-24 16:32         ` Dominique Martinet
2026-07-24 18:09           ` Eric Biggers
2026-07-25  7:37             ` Dominique Martinet
2026-07-25 10:18               ` Simon Richter
2026-07-25 17:38               ` Demi Marie Obenour
2026-07-25 17:49               ` Eric Biggers
2026-07-27 23:40                 ` Dominique Martinet
2026-07-24 20:35           ` Demi Marie Obenour
2026-07-25 20:55           ` Richard Weinberger
2026-07-25 22:04             ` Eric Biggers
2026-07-25 23:09               ` Eric Biggers
2026-07-26  7:30                 ` Richard Weinberger
2026-07-26  7:28               ` Richard Weinberger
2026-07-26 15:50                 ` Eric Biggers
2026-07-26 20:10                   ` Richard Weinberger
2026-07-27 17:20                     ` Eric Biggers [this message]
2026-05-23 19:43 ` [PATCH 3/3] AF_ALG: Document that it is *always* slower Demi Marie Obenour
2026-05-23 19:43   ` Demi Marie Obenour via B4 Relay
2026-05-30  0:47   ` sashiko-bot
2026-05-29  6:09 ` [PATCH 0/3] AF_ALG: Remove support for AIO and old-style drivers Herbert Xu

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260727172004.GA877700@google.com \
    --to=ebiggers@kernel.org \
    --cc=acme@kernel.org \
    --cc=adrian.hunter@intel.com \
    --cc=alexander.shishkin@linux.intel.com \
    --cc=ardb@kernel.org \
    --cc=asmadeus@codewreck.org \
    --cc=axboe@kernel.dk \
    --cc=corbet@lwn.net \
    --cc=davem@davemloft.net \
    --cc=demiobenour@gmail.com \
    --cc=edumazet@google.com \
    --cc=freude@linux.ibm.com \
    --cc=herbert@gondor.apana.org.au \
    --cc=horms@kernel.org \
    --cc=io-uring@vger.kernel.org \
    --cc=irogers@google.com \
    --cc=james.clark@linaro.org \
    --cc=jolsa@kernel.org \
    --cc=kuba@kernel.org \
    --cc=kuniyu@google.com \
    --cc=linux-crypto@vger.kernel.org \
    --cc=linux-doc@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-perf-users@vger.kernel.org \
    --cc=linux-s390@vger.kernel.org \
    --cc=mark.rutland@arm.com \
    --cc=mingo@redhat.com \
    --cc=namhyung@kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=peterz@infradead.org \
    --cc=richard.weinberger@gmail.com \
    --cc=skhan@linuxfoundation.org \
    --cc=willemb@google.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.