so then you find the commit that set it off
git show 91db696adea4d76017b1e1f45915a5cbf04e8da3
commit 91db696adea4d76017b1e1f45915a5cbf04e8da3
Author: David Howells <[email protected]>
Date: Mon Jan 26 11:46:58 2026 +0000
pkcs7: Allow authenticatedAttributes for ML-DSA
Allow the rejection of authenticatedAttributes in PKCS#7 (signedAttrs in
CMS) to be waived in the kernel config for ML-DSA when used for module
signing. This reflects the issue that openssl < 4.0 cannot do this and
openssl-4 has not yet been released.
This does not permit RSA, ECDSA or ECRDSA to be so waived (behaviour
unchanged).
(1) when people blame a project for not having functionality that's one thing
(2) when this fuckin guy says yeah backdoor in the kernel sounds like the right way to solve this that's another thing
(3) READ this shit "Allow authenticatedAttributes" => "Allow the rejection of authenticatedAttributes"
(4) WHEN USED FOR MODULE SIGNING!!!!!!!!!!
(5) oh i bet i'm about to see some behaviour that's so unchanged
