Skip to content

crypto: use openssl as the workspace's crypto backend - #1747

Merged
Xynnn007 merged 1 commit into
confidential-containers:mainfrom
Xynnn007:crypto
Oct 10, 2026
Merged

Xynnn007 merged 1 commit into
confidential-containers:mainfrom
Xynnn007:crypto

Conversation

@Xynnn007

@Xynnn007 Xynnn007 commented Sep 21, 2026 •

Copy link
Copy Markdown
Member

Now we cannot assure that we only use one cryptography suites in the whole stack. That means we cannot let the whole stack only use openssl, or only use rustls.

Thus, the distinguishment of rustls and openssl does not make sense anymore. This patch is a following up for #1673, removing the rustls suites and choose openssl.

The main aim is to lower the maintaince and reduce dependencies without breaking current compilation.

Close #1673

@Xynnn007

Xynnn007 commented Oct 8, 2026

Copy link
Copy Markdown
Member Author

Rebased to resolve the conflicts in Cargo.lock

@Xynnn007

Xynnn007 commented Oct 8, 2026

Copy link
Copy Markdown
Member Author

The AA building error is caused by libnvat. fixed by #1794
CDH error is caused by serial test. fixed by #1795

@stevenhorsman stevenhorsman left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Apart from one AGENTs.md typo this looks good and it's great to clean up the codebase. Thanks!

Comment thread AGENTS.md Outdated
Comment on lines +89 to +90
(including `--no-default-features` presets). `attestation-agent`, `image-rs`, and `ocicrypt-rs`
lint multiple production feature combinations, including selected `--no-default-features` presets.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think there was a copy-paste issue here?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Oh yes. Let me fix it.

@mythi

mythi commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Overall, I think this is the right direction. One question about the logistics: we haven't shipped a release with the openssl based crypto (i.e., have our crates configured with openssl feature enabled). This one big commit is fairly big thing to revert if someting stops working. Should we ship one release with a an easy fallback feature switch before removing all rust crypto code?

@Xynnn007

Xynnn007 commented Oct 9, 2026

Copy link
Copy Markdown
Member Author

Overall, I think this is the right direction. One question about the logistics: we haven't shipped a release with the openssl based crypto (i.e., have our crates configured with openssl feature enabled). This one big commit is fairly big thing to revert if someting stops working. Should we ship one release with a an easy fallback feature switch before removing all rust crypto code?

This is a good question. I do not have a good answer for this and I'd like to hear for wiser brains. cc @confidential-containers/guest-components-maintainers

@Xynnn007

Xynnn007 commented Oct 9, 2026

Copy link
Copy Markdown
Member Author

Oh. Looks like we can add a label and then trigger the kata-ci to see if it works. Let me take a try.

@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Published the CoCo guest extension images for 67682c5 (workflow run):

ubuntu24.04

version: "67682c5d9ff64ccbdeb210c1e238c9dc85379bf7"
variant: "ubuntu24.04"
container_image: "ghcr.io/confidential-containers/guest-components/coco-extension-pr"
extension_image: "ghcr.io/confidential-containers/guest-components/coco-extension-disk-pr"

ubuntu26.04

version: "67682c5d9ff64ccbdeb210c1e238c9dc85379bf7"
variant: "ubuntu26.04"
container_image: "ghcr.io/confidential-containers/guest-components/coco-extension-pr"
extension_image: "ghcr.io/confidential-containers/guest-components/coco-extension-disk-pr"

Now we cannot assure that we only use one cryptography suites in the
whole stack. That means we cannot let the whole stack only use openssl,
or only use rustls.

Thus, the distinguishment of rustls and openssl does not make sense
anymore. This patch follows confidential-containers#1673, removing the rustls suites and choose
openssl.

The main aim is to lower the maintaince and reduce dependencies without
breaking current compilation.

Signed-off-by: Xynnn007 <xynnn@linux.alibaba.com>
@Xynnn007

Copy link
Copy Markdown
Member Author

CoCo tests look good kata-containers/kata-containers#14008. rebased to resolve conflict in Cargo.lock.

@Xynnn007
Xynnn007 merged commit 13404cc into confidential-containers:main Oct 10, 2026
43 checks passed
@Xynnn007
Xynnn007 deleted the crypto branch October 10, 2026 02:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Crypto | Keep only one crypto choice

3 participants