Skip to content

Fix AES key wrap pad build with FIPS v5.2 modules - #217

Merged
lealem47 merged 3 commits into
wolfSSL:masterfrom
LinuxJedi:fix-fips-aes-direct-void
Sep 30, 2026
Merged

lealem47 merged 3 commits into
wolfSSL:masterfrom
LinuxJedi:fix-fips-aes-direct-void

Conversation

@LinuxJedi

Copy link
Copy Markdown
Member

FIPS modules before v5.3 declare wc_AesEncryptDirect() and wc_AesDecryptDirect() as returning void. The RFC 5649 key wrap with padding code (418f443) assigns their return value, so building against a FIPS v5.2.x wolfSSL with --enable-aeskeywrap fails:

src/internal.c: In function 'wp11_AesKeyUnwrapRaw':
src/internal.c:17286:17: error: void value not ignored as it ought to be

This currently breaks the IGEL-NSS-wolfPKCS11-Debian12 Jenkins job, which builds against wolfSSL 5.9.4 with the FIPS v5.2.4 module.

  • Add wp11_AesEncryptDirect() / wp11_AesDecryptDirect() wrappers that return the wolfSSL result where one exists and 0 otherwise, using the same FIPS_VERSION_GE(5, 3) guard as the existing wc_CmacFree() calls.
  • copyobject_token_test Test6 makes the token storage directory read-only to force a persistence failure. Root bypasses directory permissions, so the test fails when run as root (as the Debian package build in that job does). It now probes whether the directory is still writable and skips the check if so. As a normal user it runs as before.

Tested in a debian:12 container against wolfSSL v5.9.4-stable with the FIPS v5.2.4 module (generated with fips-check-PILOT.sh v5.2.4, IGEL job configure flags) and against non-FIPS v5.9.4-stable, using the Debian package configure options (--enable-aesctr --enable-aesccm --enable-aeskeywrap --enable-aesecb --enable-nss):

  • Before: FIPS build fails with the three errors above.
  • After: make check as root passes on both (55 pass, 2 skip, 0 fail), including aes_keywrap_pad_test.
  • copyobject_token_test as a non-root user still runs and passes Test6 in full.

FIPS modules before v5.3 declare wc_AesEncryptDirect() and
wc_AesDecryptDirect() as returning void. The RFC 5649 key wrap with
padding code assigns their return value, so builds against a FIPS
v5.2.x wolfSSL with key wrap enabled fail with "void value not ignored
as it ought to be".

Add small wrappers that return the wolfSSL result where one exists and
0 otherwise, using the same FIPS_VERSION_GE(5, 3) guard as the existing
wc_CmacFree() calls.
Test6 makes the token storage directory read-only to force a
persistence failure. Privileged users such as root bypass directory
permissions, so the copy succeeds and the test fails, for example when
building the Debian package as root inside a container.

Probe whether a file can still be created in the directory after making
it read-only and skip the check if so.
The FIPS v5.2.3 and v5.2.4 modules declare wc_AesEncryptDirect() and
wc_AesDecryptDirect() as returning int when WOLFSSL_ARMASM is defined,
unlike v5.2.1 which returns void there too. The wrappers treated all
FIPS modules before v5.3 as void and discarded the result, so an AES
failure in key wrap with padding could be reported as success.

Return the result for ARM assembly builds of FIPS v5.2.3 and later.
FIPS_VERSION3_GE() is checked for first as older wolfSSL releases do
not define it.
@lealem47
lealem47 merged commit 15691bd into wolfSSL:master Sep 30, 2026
82 checks passed
@LinuxJedi
LinuxJedi deleted the fix-fips-aes-direct-void branch September 30, 2026 15:37
aidangarske added a commit to aidangarske/wolfPKCS11 that referenced this pull request Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants