Re: [PATCH] apparmor: use SHA-256 library API instead of crypto_shash API

From: John Johansen
Date: Sat May 17 2025 - 03:47:02 EST


On 5/14/25 14:57, Paul Moore wrote:
On Wed, May 14, 2025 at 12:22 AM Eric Biggers <ebiggers@xxxxxxxxxx> wrote:
On Mon, Apr 28, 2025 at 12:04:30PM -0700, Eric Biggers wrote:
From: Eric Biggers <ebiggers@xxxxxxxxxx>

This user of SHA-256 does not support any other algorithm, so the
crypto_shash abstraction provides no value. Just use the SHA-256
library API instead, which is much simpler and easier to use.

Signed-off-by: Eric Biggers <ebiggers@xxxxxxxxxx>
---

This patch is targeting the apparmor tree for 6.16.

security/apparmor/Kconfig | 3 +-
security/apparmor/crypto.c | 85 ++++++--------------------------------
2 files changed, 13 insertions(+), 75 deletions(-)

Any interest in taking this patch through the apparmor or security trees?

Something like this would need to go through the AppArmor tree. As a
FYI, the AppArmor devs are fairly busy at the moment so it may take a
bit for them to get around to this.

I am going to see how much of the backlog I can get through while traveling
replies might get batch because I will be mostly off line but hopefully
I can deal with most of it this weekend.