Repository navigation
crypto: use openssl as the workspace's crypto backend - #1747
Conversation
|
Rebased to resolve the conflicts in |
stevenhorsman
left a comment
There was a problem hiding this comment.
Apart from one AGENTs.md typo this looks good and it's great to clean up the codebase. Thanks!
| (including `--no-default-features` presets). `attestation-agent`, `image-rs`, and `ocicrypt-rs` | ||
| lint multiple production feature combinations, including selected `--no-default-features` presets. |
There was a problem hiding this comment.
I think there was a copy-paste issue here?
|
Overall, I think this is the right direction. One question about the logistics: we haven't shipped a release with the openssl based crypto (i.e., have our crates configured with openssl feature enabled). This one big commit is fairly big thing to revert if someting stops working. Should we ship one release with a an easy fallback feature switch before removing all rust crypto code? |
This is a good question. I do not have a good answer for this and I'd like to hear for wiser brains. cc @confidential-containers/guest-components-maintainers |
|
Oh. Looks like we can add a label and then trigger the kata-ci to see if it works. Let me take a try. |
|
Published the CoCo guest extension images for 67682c5 (workflow run): ubuntu24.04version: "67682c5d9ff64ccbdeb210c1e238c9dc85379bf7"
variant: "ubuntu24.04"
container_image: "ghcr.io/confidential-containers/guest-components/coco-extension-pr"
extension_image: "ghcr.io/confidential-containers/guest-components/coco-extension-disk-pr"ubuntu26.04version: "67682c5d9ff64ccbdeb210c1e238c9dc85379bf7"
variant: "ubuntu26.04"
container_image: "ghcr.io/confidential-containers/guest-components/coco-extension-pr"
extension_image: "ghcr.io/confidential-containers/guest-components/coco-extension-disk-pr" |
Now we cannot assure that we only use one cryptography suites in the whole stack. That means we cannot let the whole stack only use openssl, or only use rustls. Thus, the distinguishment of rustls and openssl does not make sense anymore. This patch follows confidential-containers#1673, removing the rustls suites and choose openssl. The main aim is to lower the maintaince and reduce dependencies without breaking current compilation. Signed-off-by: Xynnn007 <xynnn@linux.alibaba.com>
|
CoCo tests look good kata-containers/kata-containers#14008. rebased to resolve conflict in Cargo.lock. |
Now we cannot assure that we only use one cryptography suites in the whole stack. That means we cannot let the whole stack only use openssl, or only use rustls.
Thus, the distinguishment of rustls and openssl does not make sense anymore. This patch is a following up for #1673, removing the rustls suites and choose openssl.
The main aim is to lower the maintaince and reduce dependencies without breaking current compilation.
Close #1673