Page MenuHomeFreeBSD

libcrypto: Work around strict aliasing violations in bn_nist.c
ClosedPublic

Authored by jrtc27 on Jul 24 2022, 1:24 AM.
Tags
None
Referenced Files
F110934744: D35885.id108501.diff
Tue, Feb 25, 2:57 AM
Unknown Object (File)
Mon, Feb 24, 2:18 PM
Unknown Object (File)
Mon, Feb 24, 6:19 AM
Unknown Object (File)
Sun, Feb 23, 8:59 PM
Unknown Object (File)
Fri, Feb 21, 5:18 AM
Unknown Object (File)
Fri, Feb 14, 4:42 PM
Unknown Object (File)
Fri, Feb 14, 3:48 PM
Unknown Object (File)
Sun, Feb 9, 3:59 AM
Subscribers

Details

Summary

This file is full of strict aliasing violations. Previously it was only
optimised in ways that broke the code by CHERI LLVM, but now it appears
that the in-tree LLVM also breaks it for RISC-V, resulting in broken
ECDSA signature validation with error messages like the following:

root@unmatched:/usr/src # ssh-keygen -l -f /etc/ssh/ssh_host_ecdsa_key
/etc/ssh/ssh_host_ecdsa_key is not a key file.
root@unmatched:/usr/src # git fetch
fatal: unable to access 'https://git.FreeBSD.org/src.git/': error:1012606B:elliptic curve routines:EC_POINT_set_affine_coordinates:point is not on curve

Obtained from: CheriBSD
MFC after: 1 week

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable