linux-crypto.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: Eric Biggers <ebiggers@kernel.org>
To: Vegard Nossum <vegard.nossum@oracle.com>
Cc: Jon Kohler <jon@nutanix.com>,
	Herbert Xu <herbert@gondor.apana.org.au>,
	"David S. Miller" <davem@davemloft.net>,
	"linux-crypto@vger.kernel.org" <linux-crypto@vger.kernel.org>,
	Stephan Mueller <smueller@chronox.de>,
	Marcus Meissner <meissner@suse.de>,
	Jarod Wilson <jarod@redhat.com>,
	Neil Horman <nhorman@tuxdriver.com>,
	John Haxby <john.haxby@oracle.com>
Subject: Re: 6.17 Regression: loading trusted.ko with fips=1 fails due to crypto/testmgr.c: desupport SHA-1 for FIPS 140
Date: Mon, 6 Oct 2025 08:48:33 -0700	[thread overview]
Message-ID: <20251006154833.GB1637@sol> (raw)
In-Reply-To: <45ed5ca2-f371-4030-9fc7-0a8bfc142b41@oracle.com>

On Mon, Oct 06, 2025 at 12:44:09PM +0200, Vegard Nossum wrote:
> 
> On 05/10/2025 01:24, Eric Biggers wrote:
> > Submitting a broken, untested, and incomplete patch that makes the
> > kernel fail to boot and dm-crypt.ko fail to load isn't a great strategy.
> 
> Wow, that's a highly unfair characterization :-( The patch was tested,
> but the dm-crypt failure only appears in certain configurations that
> includes both the hardware and the specific kernel config. Furthermore,
> I think the underlying bug was merely exposed by the patch to deprecate
> SHA-1 but I'm not looking to point fingers so I'm not going to say more
> about that.

To be clear, the patch introduced at least two bugs that broke basic
functionality: the dm-crypt one (related to trusted_tpm1.c) where
dm-crypt.ko failed to load, and the ipv6-sr one where the kernel failed
to boot at all.

- Eric

      reply	other threads:[~2025-10-06 15:49 UTC|newest]

Thread overview: 11+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-05-21 12:55 [PATCH] crypto/testmgr.c: desupport SHA-1 for FIPS 140 Vegard Nossum
2025-06-13  9:35 ` Herbert Xu
2025-10-04  3:00 ` 6.17 Regression: loading trusted.ko with fips=1 fails due to " Jon Kohler
2025-10-04  6:43   ` Vegard Nossum
2025-10-04 14:58     ` Jon Kohler
2025-10-04 23:24       ` Eric Biggers
2025-10-05  3:16         ` Theodore Ts'o
2025-10-05  7:29           ` Vegard Nossum
2025-10-05 22:10             ` Theodore Ts'o
2025-10-06 10:44         ` Vegard Nossum
2025-10-06 15:48           ` Eric Biggers [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20251006154833.GB1637@sol \
    --to=ebiggers@kernel.org \
    --cc=davem@davemloft.net \
    --cc=herbert@gondor.apana.org.au \
    --cc=jarod@redhat.com \
    --cc=john.haxby@oracle.com \
    --cc=jon@nutanix.com \
    --cc=linux-crypto@vger.kernel.org \
    --cc=meissner@suse.de \
    --cc=nhorman@tuxdriver.com \
    --cc=smueller@chronox.de \
    --cc=vegard.nossum@oracle.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).