Fix build failures when NO_AES_DECRYPT is defined - #11448
kaleb-himes wants to merge 1 commit into
Conversation
|
retest this please |
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #11448
Scan targets checked: none
Failed targets: wolfcrypt-src, wolfcrypt-bugs, wolfssl-src, wolfssl-bugs
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #11448
Scan targets checked: none
Failed targets: wolfcrypt-src, wolfcrypt-bugs, wolfssl-src, wolfssl-bugs
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #11448
Scan targets checked: none
Failed targets: wolfcrypt-src, wolfcrypt-bugs, wolfssl-src, wolfssl-bugs
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #11448
Scan targets checked: wolfcrypt-src, wolfcrypt-bugs, wolfssl-src, wolfssl-bugs
Findings: 2
2 finding(s) posted as inline comments (see file-level comments below)
This review was generated automatically by Fenrir. Reported findings require changes before merge.
65d8000 to
8c68122
Compare
8c68122 to
03af9a0
Compare
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #11448
Scan targets checked: wolfcrypt-src, wolfcrypt-bugs, wolfcrypt-port-bugs, wolfssl-src, wolfssl-bugs
Findings: 4
2 finding(s) posted as inline comments (see file-level comments below)
Required changes (2)
Software-async GCM decrypt configuration does not compile
File: wolfcrypt/src/aes.c:11732
Function: wc_AesGcmDecrypt
Category: Logic errors
wc_AesGcmDecrypt() now builds with HAVE_AESGCM_DECRYPT, but ASYNC_SW_AES_GCM_DECRYPT remains HAVE_AES_DECRYPT-only. Software-async builds with NO_AES_DECRYPT fail at line 12387.
Suggested fix: Guard the async operation enum and dispatcher with HAVE_AES_DECRYPT || HAVE_AESGCM_DECRYPT.
Accelerated GCM decrypt builds reference omitted assembly symbols
File: wolfcrypt/src/aes.c:11732
Function: wc_AesGcmDecrypt
Category: Logic errors
The new guard enables calls to 32-bit ARM and RISC-V GCM decrypt assembly symbols whose bodies remain HAVE_AES_DECRYPT-only. Accelerated NO_AES_DECRYPT builds fail to link.
Suggested fix: Apply the mode-specific guard to all referenced ARM32 and RISC-V GCM decrypt assembly bodies, including streaming helpers.
This review was generated automatically by Fenrir. Reported findings require changes before merge.
| if (wc_AesGcmEncrypt(aes, cipher, plain, WC_AES_BLOCK_SIZE, iv, sizeof(iv), | ||
| tag, sizeof(tag), NULL, 0) != WC_NO_ERR_TRACE(MISSING_KEY)) | ||
| ERROR_OUT(WC_TEST_RET_ENC_NC, out); | ||
| #if defined(HAVE_AES_DECRYPT) || defined(HAVE_AESGCM_DECRYPT) |
There was a problem hiding this comment.
Mode-specific decrypt paths lack successful-operation coverage · Weak or missing assertions
The new branches only assert MISSING_KEY; successful GCM and CCM decrypt KATs remain HAVE_AES_DECRYPT-only. The newly enabled mode-specific implementations are never functionally exercised.
Suggested fix: Run successful decrypt and authentication-failure KATs under the corresponding GCM and CCM mode-specific guards.
| } | ||
|
|
||
| #ifdef HAVE_AES_DECRYPT | ||
| #if defined(HAVE_AES_DECRYPT) || defined(HAVE_AESGCM_DECRYPT) |
There was a problem hiding this comment.
Cavium GCM-only decrypt build lacks its helper · Missing/incorrect platform conditionals
NitroxAesGcmDecrypt() is emitted when only HAVE_AESGCM_DECRYPT is set, but its NitroxAesDecrypt() callee remains under HAVE_AES_DECRYPT; Cavium NO_AES_DECRYPT builds fail. Adjacent #8240 concerns IV padding, not this guard.
Related known finding #8240 (similar but distinct): Both affect the Cavium Nitrox GCM decrypt wrapper, but #8240 passes uninitialized IV-tail bytes to hardware, whereas this candidate conditionally omits NitroxAesDecrypt and breaks GCM-only builds. The faulting operations, root causes, and required patches differ.
Suggested fix: Guard NitroxAesDecrypt() with HAVE_AES_DECRYPT || HAVE_AESGCM_DECRYPT, while keeping CBC entry points restricted to HAVE_AES_DECRYPT.
Basis: ISO/IEC 9899:1990 §6.7 requires an external definition for an identifier with external linkage that is used in an expression.
Description
Followup to: #11423
Fixes the NO_AES_DECRYPT builds which had fallen into disrepair somewhat both with and without TLS enabled.
How did you test?
Building on macOS both with and without
--enable-wolfcryptonlyChecklist