Fix AES key wrap pad build with FIPS v5.2 modules - #217
Merged
Merged
Conversation
FIPS modules before v5.3 declare wc_AesEncryptDirect() and wc_AesDecryptDirect() as returning void. The RFC 5649 key wrap with padding code assigns their return value, so builds against a FIPS v5.2.x wolfSSL with key wrap enabled fail with "void value not ignored as it ought to be". Add small wrappers that return the wolfSSL result where one exists and 0 otherwise, using the same FIPS_VERSION_GE(5, 3) guard as the existing wc_CmacFree() calls.
Test6 makes the token storage directory read-only to force a persistence failure. Privileged users such as root bypass directory permissions, so the copy succeeds and the test fails, for example when building the Debian package as root inside a container. Probe whether a file can still be created in the directory after making it read-only and skip the check if so.
The FIPS v5.2.3 and v5.2.4 modules declare wc_AesEncryptDirect() and wc_AesDecryptDirect() as returning int when WOLFSSL_ARMASM is defined, unlike v5.2.1 which returns void there too. The wrappers treated all FIPS modules before v5.3 as void and discarded the result, so an AES failure in key wrap with padding could be reported as success. Return the result for ARM assembly builds of FIPS v5.2.3 and later. FIPS_VERSION3_GE() is checked for first as older wolfSSL releases do not define it.
lealem47
approved these changes
Sep 30, 2026
dgarske
approved these changes
Sep 30, 2026
aidangarske
added a commit
to aidangarske/wolfPKCS11
that referenced
this pull request
Sep 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
FIPS modules before v5.3 declare
wc_AesEncryptDirect()andwc_AesDecryptDirect()as returningvoid. The RFC 5649 key wrap with padding code (418f443) assigns their return value, so building against a FIPS v5.2.x wolfSSL with--enable-aeskeywrapfails:This currently breaks the IGEL-NSS-wolfPKCS11-Debian12 Jenkins job, which builds against wolfSSL 5.9.4 with the FIPS v5.2.4 module.
wp11_AesEncryptDirect()/wp11_AesDecryptDirect()wrappers that return the wolfSSL result where one exists and 0 otherwise, using the sameFIPS_VERSION_GE(5, 3)guard as the existingwc_CmacFree()calls.copyobject_token_testTest6 makes the token storage directory read-only to force a persistence failure. Root bypasses directory permissions, so the test fails when run as root (as the Debian package build in that job does). It now probes whether the directory is still writable and skips the check if so. As a normal user it runs as before.Tested in a
debian:12container against wolfSSL v5.9.4-stable with the FIPS v5.2.4 module (generated withfips-check-PILOT.sh v5.2.4, IGEL job configure flags) and against non-FIPS v5.9.4-stable, using the Debian package configure options (--enable-aesctr --enable-aesccm --enable-aeskeywrap --enable-aesecb --enable-nss):make checkas root passes on both (55 pass, 2 skip, 0 fail), includingaes_keywrap_pad_test.copyobject_token_testas a non-root user still runs and passes Test6 in full.