1: a31d53569b9d ! 1: 3b7dec192576 crypto: fips: add fips_exception kernel boot parameter and fips_allows() helper @@ Metadata Author: Jose Ignacio Tornos Martinez   ## Commit message ## - crypto: fips: add fips_exception kernel boot parameter and fips_allows() helper + crypto: fips: add fips_exception kernel boot parameter and fips_allows_exception() helper  Add a new kernel boot parameter fips_exception= to allow documented exceptions to strict FIPS compliance when full compliance @@ Commit message functionality is required.  The parameter is stored in a static variable and accessed through the - exported fips_allows() helper function, which returns true if FIPS is - not enabled or the requested exception bit is set. It is not meant - for fully FIPS-compliant features. + exported fips_allows_exception() helper function, which returns true + when FIPS is enabled and the requested exception bit is set. This + makes fips_allows_exception() an explicit "is this FIPS exception + active?" check, only meaningful when FIPS mode is on.  - For !CONFIG_CRYPTO_FIPS, fips_allows() is a trivial static inline - returning true. + For !CONFIG_CRYPTO_FIPS, fips_allows_exception() is a trivial static + inline returning false (no FIPS means no FIPS exceptions).  The parameter is exposed as a read-only sysctl at /proc/sys/crypto/fips_exception for runtime inspection. As with @@ crypto/fips.c: EXPORT_SYMBOL_GPL(fips_enabled);   +static unsigned long fips_exception;  + -+int fips_allows(unsigned long feature) ++int fips_allows_exception(unsigned long feature)  +{ -+ return !fips_enabled || ++ return fips_enabled &&  + (fips_exception & feature);  +} -+EXPORT_SYMBOL_GPL(fips_allows); ++EXPORT_SYMBOL_GPL(fips_allows_exception);  + /* Process kernel command-line parameter at boot time. fips=0 or fips=1 */ static int __init fips_enable(char *str) @@ include/linux/fips.h  void fips_fail_notify(void);  +/* -+ * fips_allows - check if a not fully FIPS-compliant feature is allowed -+ * via an explicit boot-time exception (fips_exception=). -+ * Not for fully FIPS-compliant features. ++ * fips_allows_exception - check if a FIPS exception is active ++ * Returns true when FIPS is enabled and the requested exception ++ * bit is set via the fips_exception= boot parameter.  + */ -+int fips_allows(unsigned long feature); ++int fips_allows_exception(unsigned long feature);  #else #define fips_enabled 0  static inline void fips_fail_notify(void) {} -+static inline int fips_allows(unsigned long feature) ++static inline int fips_allows_exception(unsigned long feature)  +{ -+ return 1; ++ return 0;  +}  #endif 2: e7dc61f4c1f3 < -: ------------ wifi: mac80211: allow keys to driver with fips_exception 3: 6b5a0cc45d8f < -: ------------ wifi: iwlwifi: restore FIPS-disabled features with fips_exception 4: 29878fc29e6d < -: ------------ wifi: iwlwifi: use software crypto for management frames in FIPS exception mode -: ------------ > 2: fafc848b9de7 wifi: iwlwifi: enable MFP_CAPABLE in FIPS mode -: ------------ > 3: f72914c50813 wifi: iwlwifi: fix RX AMPDU and A-MSDU in FIPS mode 5: 3a8c5112bc54 ! 4: c16408759e13 wifi: iwlwifi: reduce encryption error message to debug level in FIPS mode @@ Commit message before keys are installed. This triggers the warning: "iwlwifi: Unhandled alg: 0x707"  - This is expected behavior — mac80211 software crypto handles + This is expected behavior -- mac80211 software crypto handles decryption on the host CPU. Reduce the message from IWL_WARN to IWL_DEBUG_RX in FIPS mode to avoid false-positive warnings during normal operation, while preserving warnings for actual @@ Commit message Signed-off-by: Jose Ignacio Tornos Martinez   ## drivers/net/wireless/intel/iwlwifi/mvm/rxmq.c ## -@@ - */ - #include  - #include  -+#include  - #include "iwl-trans.h" - #include "mvm.h" - #include "fw-api.h"  @@ drivers/net/wireless/intel/iwlwifi/mvm/rxmq.c: static int iwl_mvm_rx_crypto(struct iwl_mvm *mvm, struct ieee80211_sta *sta, return 0; case RX_MPDU_RES_STATUS_SEC_CMAC_GMAC_ENC: