From nobody Sat Jul 25 07:59:52 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1784721451; cv=none; d=zohomail.com; s=zohoarc; b=VtQ2Vg4V09jm6zaRuUttcNVPOiQEmOE10JUE34odBnM2N7/FB1JxCxqtxk8GF+PV4bNt+yKB2MPsmkGCsgGlGXOekeT9TObBN20xKDXc5PITlG/CMjMzl1ztXBdSoqGBAL1adWE6oIPfBTakqoRXongfhcOxUdL0ejG0zeLOH9c= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784721451; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=GiLFcBzUpKgZYAJfyD+McEUqoQAItqUWSK0qlop6eng=; b=bvPQyjZwa2ydtcOeD7aIvnQOl3J9QcGXz88EzvuCrBNwfSB/JCtkbH74bCTngoz6eFYBp1N7oAKRXTZM4LNV3fwrbnEJOxRBxS6gqwCzLEjCZyifa90LuP+tic0MoRmQ7puoc3G1In2L0CqBJ5HepiFOtzYldGjZxdUbl9/0sAM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784721451034298.29238472346185; Wed, 22 Jul 2026 04:57:31 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmVZb-0002M5-Nc; Wed, 22 Jul 2026 07:57:15 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmVZa-0002Lu-Ix for qemu-devel@nongnu.org; Wed, 22 Jul 2026 07:57:14 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmVZY-0003B6-NF for qemu-devel@nongnu.org; Wed, 22 Jul 2026 07:57:14 -0400 Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-161-sKxNVeBePV24xz2CJ4odAA-1; Wed, 22 Jul 2026 07:57:07 -0400 Received: from mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.93]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 65C6218007F7; Wed, 22 Jul 2026 11:57:06 +0000 (UTC) Received: from berrange.com (unknown [10.44.49.82]) by mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 1BB121800901; Wed, 22 Jul 2026 11:57:02 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1784721431; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=GiLFcBzUpKgZYAJfyD+McEUqoQAItqUWSK0qlop6eng=; b=clYyf4o4aefBlHct6qvgC/AvoWpcFQzVM70HEvIpNSUAIzm1SxLhjWvRvo4PEEPNgz9D7/ i9Enzha2E1+d9sgeSmoVt/gg+AmJXDZjkVIFJySoR+htcTGUMLyuQMhqid+/PGTGFjSxS3 62SzUZ7KSFPVgbBw1QFBhFfghzeD34k= X-MC-Unique: sKxNVeBePV24xz2CJ4odAA-1 X-Mimecast-MFC-AGG-ID: sKxNVeBePV24xz2CJ4odAA_1784721426 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: Thomas Huth , Pierrick Bouvier , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , devel@lists.libvirt.org, =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Paolo Bonzini , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= Subject: [PATCH for 11.1] crypto: deprecate the AF_ALG crypto backend Date: Wed, 22 Jul 2026 12:57:00 +0100 Message-ID: <20260722115701.716516-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.93 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: permerror client-ip=170.10.129.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.01, SPF_HELO_PASS=-0.001, T_SPF_PERMERROR=0.01 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1784721453070158500 Linux 7.1 has deprecated the AF_ALG crypto backend: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit= /?id=3Da67afb1884ba815079bd43d5c998e155e03b08b6 And has documented it to be always slower than userspace crypto: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit= /?id=3D5624ea54f3ba5c83d2e5503411a31a8be0278c1e as a result of dropping support for zero-copy and hardware accelerators: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit= /?id=3D7524070f26d8d347c26787dc297fb844baa26abf https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit= /?id=3Dffdd2bc378953b525aca61902534e753f1f8e734 The main use case for the AF_ALG impl was to improve the performance of virtio-crypto with the cryptodev-backend-builtin driver. In practice this did not matter since 'cryptodev-backend-lkcf' can do offload to the kernel via the keyctl syscall, and 'cryptodev-vhost-user' can offload to an external process which can optionally integrate with hardware accelerators without kernel assistance. The AF_ALG backend has no user visible configuration options at runtime, it is unconditionally tried with any use of the cipher APIs. So it does not strictly have to go through the deprecation process, however, it is left available initially in case there was an unexpected use case that relies on it which may be faster with old kernels before the above Linux commits. Suggested-by: Thomas Huth Signed-off-by: Daniel P. Berrang=C3=A9 Reviewed-by: C=C3=A9dric Le Goater Reviewed-by: Philippe Mathieu-Daud=C3=A9 --- docs/about/deprecated.rst | 21 +++++++++++++++++++++ meson.build | 6 ++++++ 2 files changed, 27 insertions(+) diff --git a/docs/about/deprecated.rst b/docs/about/deprecated.rst index 0c656a968f..54b2662752 100644 --- a/docs/about/deprecated.rst +++ b/docs/about/deprecated.rst @@ -416,6 +416,27 @@ ABI is long-obsolete. We are therefore deprecating bot= h OABI support and NWFPE emulation, and they will be removed in a future QEMU release. =20 +Build features +-------------- + +Crypto AF_ALG backend +--------------------- + +The use of the AF_ALG backend for cryptography has been deprecated +with no replacement. + +The AF_ALG interface is deprecated by Linux 7.1 and all support +for hardware accelerators has been removed. It will thus always be +slower than userspace crypto due to the overhead of copying data +to kernel space. The GNUTLS, Nettle and GCrypt libraries supported +by QEMU all include a variety of hardware optimized crypto +implementations which should suffice for typical needs. + +For the virtio-crypto device, the 'cryptodev-backend-lkcf' backend +can offload some operations to the kernel via the keyctl syscall, +and the 'cryptodev-vhost-user' backend can offload the device +backend to an external process which can integrate with crypto +accelerators. =20 Backwards compatibility ----------------------- diff --git a/meson.build b/meson.build index 164328ded8..02cbe6445a 100644 --- a/meson.build +++ b/meson.build @@ -5053,3 +5053,9 @@ if not actually_reloc and (host_os =3D=3D 'windows' o= r get_option('relocatable')) message('QEMU will have to be installed under ' + get_option('prefix') += '.') message('Use --disable-relocatable to remove this warning.') endif + +if get_option('crypto_afalg').enabled() + warning('Use of the AF_ALG crypto backend is deprecated, ' + + 'since Linux 7.1 has deprecated the AF_ALG interface ' + + 'and removed its ability to use hardware accelerators.') +endif --=20 2.55.0