Skip to content

Fix build failures when NO_AES_DECRYPT is defined - #11448

Open
kaleb-himes wants to merge 1 commit into
wolfSSL:masterfrom
kaleb-himes:Fix-AES-Decrypt-Only-Builds
Open

kaleb-himes wants to merge 1 commit into
wolfSSL:masterfrom
kaleb-himes:Fix-AES-Decrypt-Only-Builds

Conversation

@kaleb-himes

Copy link
Copy Markdown
Contributor

Description

Followup to: #11423

Fixes the NO_AES_DECRYPT builds which had fallen into disrepair somewhat both with and without TLS enabled.

How did you test?

Building on macOS both with and without --enable-wolfcryptonly

Checklist

  • added tests (well updated tests)
  • updated/added doxygen
  • updated appropriate READMEs
  • Updated manual and documentation

@kaleb-himes

Copy link
Copy Markdown
Contributor Author

retest this please

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #11448

Scan targets checked: none
Failed targets: wolfcrypt-src, wolfcrypt-bugs, wolfssl-src, wolfssl-bugs

⚠️ Review incomplete — one or more scan targets failed before findings could be produced. See the Fenrir PR review detail page for logs.

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #11448

Scan targets checked: none
Failed targets: wolfcrypt-src, wolfcrypt-bugs, wolfssl-src, wolfssl-bugs

⚠️ Review incomplete — one or more scan targets failed before findings could be produced. See the Fenrir PR review detail page for logs.

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #11448

Scan targets checked: none
Failed targets: wolfcrypt-src, wolfcrypt-bugs, wolfssl-src, wolfssl-bugs

⚠️ Review incomplete — one or more scan targets failed before findings could be produced. See the Fenrir PR review detail page for logs.

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #11448

Scan targets checked: wolfcrypt-src, wolfcrypt-bugs, wolfssl-src, wolfssl-bugs

Findings: 2
2 finding(s) posted as inline comments (see file-level comments below)

This review was generated automatically by Fenrir. Reported findings require changes before merge.

Comment thread wolfssl/wolfcrypt/settings.h Outdated
Comment thread wolfssl/internal.h Outdated
@kaleb-himes
kaleb-himes force-pushed the Fix-AES-Decrypt-Only-Builds branch from 65d8000 to 8c68122 Compare September 13, 2026 18:23

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #11448

Scan targets checked: wolfcrypt-src, wolfcrypt-bugs, wolfcrypt-port-bugs, wolfssl-src, wolfssl-bugs
Findings: 4
2 finding(s) posted as inline comments (see file-level comments below)

Required changes (2)

Software-async GCM decrypt configuration does not compile

File: wolfcrypt/src/aes.c:11732
Function: wc_AesGcmDecrypt
Category: Logic errors

wc_AesGcmDecrypt() now builds with HAVE_AESGCM_DECRYPT, but ASYNC_SW_AES_GCM_DECRYPT remains HAVE_AES_DECRYPT-only. Software-async builds with NO_AES_DECRYPT fail at line 12387.

Suggested fix: Guard the async operation enum and dispatcher with HAVE_AES_DECRYPT || HAVE_AESGCM_DECRYPT.


Accelerated GCM decrypt builds reference omitted assembly symbols

File: wolfcrypt/src/aes.c:11732
Function: wc_AesGcmDecrypt
Category: Logic errors

The new guard enables calls to 32-bit ARM and RISC-V GCM decrypt assembly symbols whose bodies remain HAVE_AES_DECRYPT-only. Accelerated NO_AES_DECRYPT builds fail to link.

Suggested fix: Apply the mode-specific guard to all referenced ARM32 and RISC-V GCM decrypt assembly bodies, including streaming helpers.


This review was generated automatically by Fenrir. Reported findings require changes before merge.

Comment thread wolfcrypt/test/test.c
if (wc_AesGcmEncrypt(aes, cipher, plain, WC_AES_BLOCK_SIZE, iv, sizeof(iv),
tag, sizeof(tag), NULL, 0) != WC_NO_ERR_TRACE(MISSING_KEY))
ERROR_OUT(WC_TEST_RET_ENC_NC, out);
#if defined(HAVE_AES_DECRYPT) || defined(HAVE_AESGCM_DECRYPT)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Mode-specific decrypt paths lack successful-operation coverage · Weak or missing assertions

The new branches only assert MISSING_KEY; successful GCM and CCM decrypt KATs remain HAVE_AES_DECRYPT-only. The newly enabled mode-specific implementations are never functionally exercised.

Suggested fix: Run successful decrypt and authentication-failure KATs under the corresponding GCM and CCM mode-specific guards.

}

#ifdef HAVE_AES_DECRYPT
#if defined(HAVE_AES_DECRYPT) || defined(HAVE_AESGCM_DECRYPT)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cavium GCM-only decrypt build lacks its helper · Missing/incorrect platform conditionals

NitroxAesGcmDecrypt() is emitted when only HAVE_AESGCM_DECRYPT is set, but its NitroxAesDecrypt() callee remains under HAVE_AES_DECRYPT; Cavium NO_AES_DECRYPT builds fail. Adjacent #8240 concerns IV padding, not this guard.

Related known finding #8240 (similar but distinct): Both affect the Cavium Nitrox GCM decrypt wrapper, but #8240 passes uninitialized IV-tail bytes to hardware, whereas this candidate conditionally omits NitroxAesDecrypt and breaks GCM-only builds. The faulting operations, root causes, and required patches differ.

Suggested fix: Guard NitroxAesDecrypt() with HAVE_AES_DECRYPT || HAVE_AESGCM_DECRYPT, while keeping CBC entry points restricted to HAVE_AES_DECRYPT.
Basis: ISO/IEC 9899:1990 §6.7 requires an external definition for an identifier with external linkage that is used in an expression.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants