[PATCH] Allow hmac(sha512) for unpriviledged users

From: Justin M. Forbes

Date: Sat Oct 03 2026 - 12:03:38 EST


By default users cannot run sha512hmac with the current set up. This
is problematic because our kernel builds call this for FIPS compliance.
Rather than have anyone turn off af_alg_restrict all together, let's
allow a common use case.

Signed-off-by: Justin M. Forbes <jforbes@xxxxxxxxxxxxxxxxx>
---
crypto/algif_hash.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/crypto/algif_hash.c b/crypto/algif_hash.c
index 6e8b5fb82a7f..0d3ec5760de6 100644
--- a/crypto/algif_hash.c
+++ b/crypto/algif_hash.c
@@ -23,7 +23,7 @@ static const struct af_alg_allowlist_entry hash_allowlist[] = {
{ "hmac(sha224)" }, /* iwd */
{ "hmac(sha256)" }, /* iwd */
{ "hmac(sha384)" }, /* iwd */
- { "hmac(sha512)" }, /* iwd, sha512hmac */
+ { "hmac(sha512)", AF_ALG_UNPRIVILEGED }, /* iwd, sha512hmac */
{ "md4" }, /* iwd */
{ "md5" }, /* iwd */
{ "sha1", AF_ALG_UNPRIVILEGED }, /* iwd, iproute2 < 7.0 */
--
2.55.0