diff options
| author | Linus Torvalds <torvalds@linux-foundation.org> | 2026-08-19 17:25:42 -0700 |
|---|---|---|
| committer | Linus Torvalds <torvalds@linux-foundation.org> | 2026-08-19 17:25:42 -0700 |
| commit | a4ff2be345d0abc943da8dd8da98151843b750dc (patch) | |
| tree | da64a462ec69df460299cfec5e0d61534daa8c7c /Documentation/crypto | |
| parent | a51ec5e8e5dae80824239f0344210060cb92a4b0 (diff) | |
| parent | 7537036a2e6fe96f8ed82034f755c54714a0e417 (diff) | |
| download | linux-next-a4ff2be345d0abc943da8dd8da98151843b750dc.tar.gz linux-next-a4ff2be345d0abc943da8dd8da98151843b750dc.zip | |
Merge tag 'v7.3-p1' of git://git.kernel.org/pub/scm/linux/kernel/git/herbert/crypto-2.6
Pull crypto update from Herbert Xu:
"API:
- Add af_alg_restrict sysctl and white list
- Fix potential suspend/resume races in hwrng
Algorithms:
- Optimize vli additive operations using compiler builtins in ecc
Drivers:
- Remove unsafe/deprecated algorithms from qce
- Mark qce as BROKEN
- Add runtime PM and interconnect bandwidth scaling support to qce
- Remove crypto_rng from qcom, sun8i and caam
- Fix SG list issues in iaa
- Fix SEV init path bugs in ccp"
* tag 'v7.3-p1' of git://git.kernel.org/pub/scm/linux/kernel/git/herbert/crypto-2.6: (122 commits)
crypto: lskcipher - propagate errors from unaligned crypt
crypto: keembay - use crypto_memneq() to compare CCM AEAD tags
crypto: keembay - use crypto_memneq() to compare GCM AEAD tags
crypto: sa2ul - use crypto_memneq() to compare AEAD tag
hwrng: drivers - use named initializers for acpi_device_id
crypto: qce - fix CCM AAD buffer underallocation
crypto: iaa - unmap dst before software fallback on decompress
crypto: iaa - use bounce buffer for multi-sg decompress input
crypto: iaa - avoid counting fallback decompression bytes
crypto: iaa - fall back to software for multi-entry scatterlists
hwrng: core - Stop/start hwrng_fillfn() kthread before/after suspend-resume
crypto: hisilicon/sec2 - fix CCM algorithm long packet failure
crypto: eip93 - use struct_size() and flexible array for ring allocation
crypto: krb5 - use kfree_sensitive() for derived key buffers
crypto: af_alg - Stop after finding name in allowlist
crypto: af_alg - Replace 'bool privileged' with flags
crypto: af_alg - Make cbc(paes) privileged-only
hwrng: imx-rngc - Disable clock on registration failure
crypto: qat - remove dead ADF_HEX code
crypto: qce - simplify qce_handle_request
...
Diffstat (limited to 'Documentation/crypto')
| -rw-r--r-- | Documentation/crypto/architecture.rst | 2 | ||||
| -rw-r--r-- | Documentation/crypto/userspace-if.rst | 13 |
2 files changed, 11 insertions, 4 deletions
diff --git a/Documentation/crypto/architecture.rst b/Documentation/crypto/architecture.rst index 249b54d0849f..ec2e99d99aff 100644 --- a/Documentation/crypto/architecture.rst +++ b/Documentation/crypto/architecture.rst @@ -95,7 +95,7 @@ additional templates may enclose other templates, such as :: - template1(template2(single block cipher))) + template1(template2(single block cipher)) The kernel crypto API may provide multiple implementations of a template diff --git a/Documentation/crypto/userspace-if.rst b/Documentation/crypto/userspace-if.rst index ab93300c8e04..d6194346e366 100644 --- a/Documentation/crypto/userspace-if.rst +++ b/Documentation/crypto/userspace-if.rst @@ -1,3 +1,5 @@ +.. _crypto_userspace_interface: + User Space Interface ==================== @@ -12,9 +14,14 @@ AF_ALG is insecure and is deprecated. Originally added to the kernel in 2010, most kernel developers now consider it to be a mistake. Support for hardware accelerators, which was the original purpose of AF_ALG, has been removed. -AF_ALG continues to be supported only for backwards compatibility. On systems -where no programs using AF_ALG remain, the support for it should be disabled by -disabling ``CONFIG_CRYPTO_USER_API_*``. +AF_ALG continues to be supported only for backwards compatibility. + +Starting in Linux v7.3, the set of algorithms supported by AF_ALG is limited by +default. See :ref:`/proc/sys/crypto/af_alg_restrict <af_alg_restrict>`. + +On systems where no programs using AF_ALG remain, the support for it should be +disabled entirely by setting ``/proc/sys/crypto/af_alg_restrict`` to 2 or by +disabling ``CONFIG_CRYPTO_USER_API_*`` in the kernel configuration. Deprecation ----------- |
