U-Boot Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Tom Rini <trini@konsulko.com>
To: Raymond Mao <raymond.mao@linaro.org>
Cc: u-boot@lists.denx.de, Stefan Bosch <stefan_b@posteo.net>,
	Andy Shevchenko <andriy.shevchenko@linux.intel.com>,
	Michal Simek <michal.simek@amd.com>,
	Tuomas Tynkkynen <tuomas.tynkkynen@iki.fi>,
	Simon Glass <sjg@chromium.org>,
	Ilias Apalodimas <ilias.apalodimas@linaro.org>,
	Leo Yu-Chi Liang <ycliang@andestech.com>,
	Andrejs Cainikovs <andrejs.cainikovs@toradex.com>,
	Marek Vasut <marek.vasut+renesas@mailbox.org>,
	Sean Anderson <seanga2@gmail.com>,
	Heinrich Schuchardt <xypron.glpk@gmx.de>,
	Jesse Taube <mr.bossman075@gmail.com>, Bryan Brattlof <bb@ti.com>,
	"Leon M. Busch-George" <leon@georgemail.eu>,
	Igor Opaniuk <igor.opaniuk@gmail.com>,
	Ilya Lukin <4.shket@gmail.com>, Sergei Antonov <saproj@gmail.com>,
	Alper Nebi Yasak <alpernebiyasak@gmail.com>,
	Abdellatif El Khlifi <abdellatif.elkhlifi@arm.com>,
	AKASHI Takahiro <akashi.tkhro@gmail.com>,
	Alexander Gendin <agendin@matrox.com>,
	Bin Meng <bmeng@tinylab.org>,
	Oleksandr Suvorov <oleksandr.suvorov@foundries.io>
Subject: Re: [PATCH v3 03/25] mbedtls: add mbedtls into the build system
Date: Wed, 29 May 2024 12:42:55 -0600	[thread overview]
Message-ID: <20240529184255.GC3714513@bill-the-cat> (raw)
In-Reply-To: <CAEfUkUJj5Y+uVmRXx+=DP-6O7dpNcMjSA1jADKaJo07RSsBjHw@mail.gmail.com>

[-- Attachment #1: Type: text/plain, Size: 4890 bytes --]

On Wed, May 29, 2024 at 02:38:10PM -0400, Raymond Mao wrote:
> Hi Tom,
> 
> On Wed, 29 May 2024 at 14:01, Tom Rini <trini@konsulko.com> wrote:
> 
> > On Wed, May 29, 2024 at 01:42:16PM -0400, Raymond Mao wrote:
> > > Hi Tom,
> > >
> > > On Wed, 29 May 2024 at 12:58, Tom Rini <trini@konsulko.com> wrote:
> > >
> > > > On Tue, May 28, 2024 at 07:09:14AM -0700, Raymond Mao wrote:
> > > >
> > > > > Port mbedtls with dummy libc header files.
> > > > > Add mbedtls default config header file.
> > > > > Optimize mbedtls default config by disabling unused features to
> > > > > reduce the target size.
> > > > > Add mbedtls kbuild makefile.
> > > > > Add Kconfig and mbedtls config submenu.
> > > > [snip]
> > > > > diff --git a/lib/mbedtls/Kconfig b/lib/mbedtls/Kconfig
> > > > > new file mode 100644
> > > > > index 00000000000..d6e77d56871
> > > > > --- /dev/null
> > > > > +++ b/lib/mbedtls/Kconfig
> > > > > @@ -0,0 +1,25 @@
> > > > > +menuconfig MBEDTLS_LIB
> > > > > +     bool "Use mbedtls libraries"
> > > > > +     select MBEDTLS_LIB_CRYPTO
> > > > > +     select MBEDTLS_LIB_X509
> > > > > +     help
> > > > > +       Enable mbedtls libraries
> > > > > +
> > > > > +if MBEDTLS_LIB
> > > > > +
> > > > > +config MBEDTLS_LIB_CRYPTO
> > > > > +     bool "Crypto library"
> > > > > +     help
> > > > > +       Enable mbedtls crypto library
> > > > > +
> > > > > +config MBEDTLS_LIB_X509
> > > > > +     bool "X509 library"
> > > > > +     help
> > > > > +       Enable mbedtls X509 library
> > > > > +
> > > > > +config MBEDTLS_LIB_TLS
> > > > > +     bool "TLS library"
> > > > > +     help
> > > > > +       Enable mbedtls TLS library
> > > > > +
> > > > > +endif # MBEDTLS_LIB
> > > >
> > > > We need much more granularity here, and to re-think some existing
> > > > symbols too perhaps. What we should be able to do is pick mbedTLS or
> > > > "legacy SW implementation" or "HW implementation" for the various
> > > > algorithms, and that in turn can have some higher level grouping to it.
> > > > This should then negate a bunch of the Makefile work you're doing as we
> > > > won't have CONFIG_SHA256 enabled as we'll have
> > CONFIG_MBEDTLS_LIB_SHA256
> > > > or whatever enabled.
> > > >
> > >
> > > I think we should use CONFIG_MBEDTLS_LIB_[CRYPTO,X509,TLS] for high-level
> > > grouping.
> > > Underneath, the CONFIG_SHA[1,256,512] switches (and other crypto options)
> > > can be
> > > used as sub build options in both MbedTLS and "legacy libs".
> > >
> > > Take hash as an example, if the users prefer to use MbedTLS other than
> > > "legacy libs" for
> > > hash operation, CONFIG_MBEDTLS_LIB_CRYPTO should be defined as the main
> > > switch
> > > (the users can still prefer to use "legacy libs" for X509 by
> > > keeping  CONFIG_MBEDTLS_LIB_X509
> > > disabled).
> > > Then enable the algorithms they need (e.g. CONFIG_SHA256) - the algorithm
> > > options works
> > > for both MbedTLS and "legacy libs".
> > >
> > > HW implementations with MbedTLS (aka, Alternative algorithms in MbedTLS)
> > is
> > > another
> > > topic which is not covered in this patch set (It needs to migrate each
> > > vendor's solution under
> > > MbedTLS alternative algorithm).
> > > Current patch set is focused on SW implementation with MbedTLS.
> >
> > The "easy" problem with what's in v3 is that X509 and CRYPTO are
> > select'd under the main heading.
> 
> Not sure if I get what you mentioned, currently all MbedTLS options are
> under
> Library routines > Security support
> Do you think we should keep them in other places?
> 
> 
> > The harder problem is that we
> > intentionally have granularity for SHA256, SHA512, etc, etc and all of
> > that goes away with the current Kconfig option if you select mbedTLS. We
> > need to bring that back. And we shouldn't need to have all of the ifneq
> > statements in Makefiles because both CONFIG_SHA256 and
> > CONFIG_MBEDLTS_LIB_CRYPTO_SHA256 will not be true (Or possibly,
> > CONFIG_SHA256 gates things U-Boot's internal API for sha256'ing
> > something and CONFIG_LEGACY_SHA256 controls building lib/sha256.c).
> >
> > I think we should not introduce new ones like CONFIG_LEGACY_,
> CONFIG_SHA[1,256,512] should be used no matter whether MbedTLS is
> enabled or not.
> I understand your concern, I will bring CONFIG_SHA[1,256,512] back when
> MbedTLS is enabled. Those options should control the options in the MbedTLS
> default config file.

My concern is that we do not have the correct level of granularity, and
that can partly be seen by the number of ifneq(...) statements being
added around already conditional logic. We should have almost none of
those, in the end, is what I'm saying. We have a mechanism for
configuring the build, Kconfig, and that should drive the decisions as
much as possible.

-- 
Tom

[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 659 bytes --]

  reply	other threads:[~2024-05-29 18:43 UTC|newest]

Thread overview: 64+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-05-28 14:09 [PATCH v3 00/25] [RFC] Integrate MbedTLS v3.6 LTS with U-Boot Raymond Mao
2024-05-28 14:09 ` [PATCH v3 01/25] CI: Exclude MbedTLS subtree for CONFIG checks Raymond Mao
2024-05-28 14:09 ` [PATCH v3 02/25] mbedtls: Add script to update MbedTLS subtree Raymond Mao
2024-05-31  6:32   ` Ilias Apalodimas
2024-06-04 20:10     ` Andy Shevchenko
2024-06-05  7:11       ` Ilias Apalodimas
2024-06-05  9:27         ` Andy Shevchenko
2024-05-28 14:09 ` [PATCH v3 03/25] mbedtls: add mbedtls into the build system Raymond Mao
2024-05-29 16:58   ` Tom Rini
2024-05-29 17:42     ` Raymond Mao
2024-05-29 18:01       ` Tom Rini
2024-05-29 18:38         ` Raymond Mao
2024-05-29 18:42           ` Tom Rini [this message]
2024-05-29 19:42             ` Raymond Mao
2024-05-29 19:47               ` Tom Rini
2024-05-30 14:37                 ` Raymond Mao
2024-05-30 15:47                   ` Ilias Apalodimas
2024-05-30 16:14                     ` Raymond Mao
2024-05-30 20:17                 ` Ilias Apalodimas
2024-05-31 17:07                   ` Raymond Mao
2024-06-04 17:47                     ` Tom Rini
2024-05-31  6:37   ` Ilias Apalodimas
2024-06-04 20:17   ` Andy Shevchenko
2024-06-04 21:50     ` Raymond Mao
2024-06-05  9:30       ` Andy Shevchenko
2024-06-05  9:35         ` Ilias Apalodimas
2024-06-05 10:17           ` Andy Shevchenko
2024-06-05 13:30             ` Ilias Apalodimas
2024-06-05 14:28               ` Raymond Mao
2024-06-05 15:20               ` Tom Rini
2024-05-28 14:09 ` [PATCH v3 04/25] lib: Adapt digest header files to MbedTLS Raymond Mao
2024-05-28 14:09 ` [PATCH v3 05/25] md5: Remove md5 non-watchdog API Raymond Mao
2024-05-31  6:39   ` Ilias Apalodimas
2024-05-31  6:46   ` Michal Simek
2024-05-28 14:09 ` [PATCH v3 06/25] mbedtls: add digest shim layer for MbedTLS Raymond Mao
2024-05-31  6:45   ` Ilias Apalodimas
2024-05-28 14:09 ` [PATCH v3 07/25] hash: integrate hash on mbedtls Raymond Mao
2024-05-28 14:09 ` [PATCH v3 08/25] makefile: add mbedtls include directories Raymond Mao
2024-05-28 14:09 ` [PATCH v3 09/25] mbedtls/external: support Microsoft Authentication Code Raymond Mao
2024-05-28 14:09 ` [PATCH v3 10/25] mbedtls/external: support PKCS9 Authenticate Attributes Raymond Mao
2024-05-28 14:09 ` [PATCH v3 11/25] mbedtls/external: support decoding multiple signer's cert Raymond Mao
2024-05-28 14:09 ` [PATCH v3 12/25] mbedtls/external: update MbedTLS PKCS7 test suites Raymond Mao
2024-05-28 14:09 ` [PATCH v3 13/25] mbedtls: add public key porting layer Raymond Mao
2024-05-28 14:09 ` [PATCH v3 14/25] lib/crypto: Adapt public_key header with MbedTLS Raymond Mao
2024-05-28 14:09 ` [PATCH v3 15/25] mbedtls: add X509 cert parser porting layer Raymond Mao
2024-05-31 11:42   ` Ilias Apalodimas
2024-06-04 16:05     ` Raymond Mao
2024-06-04 16:53       ` Ilias Apalodimas
2024-06-04 18:01         ` Tom Rini
2024-05-28 14:09 ` [PATCH v3 16/25] lib/crypto: Adapt x509_cert_parser to MbedTLS Raymond Mao
2024-05-28 14:09 ` [PATCH v3 17/25] mbedtls: add PKCS7 parser porting layer Raymond Mao
2024-05-28 14:09 ` [PATCH v3 18/25] lib/crypto: Adapt PKCS7 parser to MbedTLS Raymond Mao
2024-05-28 14:09 ` [PATCH v3 19/25] mbedtls: add MSCode parser porting layer Raymond Mao
2024-05-31 10:03   ` Ilias Apalodimas
2024-06-04 16:26     ` Raymond Mao
2024-05-28 14:09 ` [PATCH v3 20/25] lib/crypto: Adapt mscode_parser to MbedTLS Raymond Mao
2024-05-28 14:09 ` [PATCH v3 21/25] mbedtls: add RSA helper layer on MbedTLS Raymond Mao
2024-05-31  9:59   ` Ilias Apalodimas
2024-06-04 16:43     ` Raymond Mao
2024-05-28 14:09 ` [PATCH v3 22/25] lib/rypto: Adapt rsa_helper to MbedTLS Raymond Mao
2024-05-28 14:09 ` [PATCH v3 23/25] asn1_decoder: remove ASN1 decoder when using MbedTLS Raymond Mao
2024-05-28 14:09 ` [PATCH v3 24/25] test: Remove ASN1 library test Raymond Mao
2024-05-31  6:50   ` Ilias Apalodimas
2024-05-28 14:09 ` [PATCH v3 25/25] configs: enable MbedTLS as default setting Raymond Mao

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20240529184255.GC3714513@bill-the-cat \
    --to=trini@konsulko.com \
    --cc=4.shket@gmail.com \
    --cc=abdellatif.elkhlifi@arm.com \
    --cc=agendin@matrox.com \
    --cc=akashi.tkhro@gmail.com \
    --cc=alpernebiyasak@gmail.com \
    --cc=andrejs.cainikovs@toradex.com \
    --cc=andriy.shevchenko@linux.intel.com \
    --cc=bb@ti.com \
    --cc=bmeng@tinylab.org \
    --cc=igor.opaniuk@gmail.com \
    --cc=ilias.apalodimas@linaro.org \
    --cc=leon@georgemail.eu \
    --cc=marek.vasut+renesas@mailbox.org \
    --cc=michal.simek@amd.com \
    --cc=mr.bossman075@gmail.com \
    --cc=oleksandr.suvorov@foundries.io \
    --cc=raymond.mao@linaro.org \
    --cc=saproj@gmail.com \
    --cc=seanga2@gmail.com \
    --cc=sjg@chromium.org \
    --cc=stefan_b@posteo.net \
    --cc=tuomas.tynkkynen@iki.fi \
    --cc=u-boot@lists.denx.de \
    --cc=xypron.glpk@gmx.de \
    --cc=ycliang@andestech.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox