On Mon, Oct 06, 2025 at 03:45:46PM -0400, Simo Sorce wrote:
Note: this may change going forward, but I am confident that as issues
arise people will propose upstream patches to keep it as close as
possible within acceptable parameters for upstream behavior.
What I'm curious about is what falls within the acceptable parameters
of *distro* behavior. If NIST-certified labs really insist that
certifying requires making the kernel completely unsupportable from a
commercial perspective, at what point will *distros* decide to give it
up as a bad idea, or to have a completely different binary kernel
package that only crazy customers would be willing to use?
If there is something beyond hard-disabling CONFIG_CRYPTO_SHA1 which
all distributions could agree with --- what would that set of patches
look like, and would it be evenly vaguely upstream acceptable. It
could even hidden behind CONFIG_BROKEN. :-)
- Ted