Page MenuHomeFreeBSD

libcrypto: Work around strict aliasing violations in bn_nist.c
ClosedPublic

Authored by jrtc27 on Jul 24 2022, 1:24 AM.
Tags
None
Referenced Files
Unknown Object (File)
Fri, Nov 8, 10:30 AM
Unknown Object (File)
Fri, Nov 8, 9:40 AM
Unknown Object (File)
Mon, Oct 28, 10:25 AM
Unknown Object (File)
Oct 3 2024, 7:16 PM
Unknown Object (File)
Oct 3 2024, 9:07 AM
Unknown Object (File)
Oct 1 2024, 11:13 AM
Unknown Object (File)
Sep 30 2024, 9:29 PM
Unknown Object (File)
Sep 8 2024, 4:33 PM
Subscribers

Details

Summary

This file is full of strict aliasing violations. Previously it was only
optimised in ways that broke the code by CHERI LLVM, but now it appears
that the in-tree LLVM also breaks it for RISC-V, resulting in broken
ECDSA signature validation with error messages like the following:

root@unmatched:/usr/src # ssh-keygen -l -f /etc/ssh/ssh_host_ecdsa_key
/etc/ssh/ssh_host_ecdsa_key is not a key file.
root@unmatched:/usr/src # git fetch
fatal: unable to access 'https://git.FreeBSD.org/src.git/': error:1012606B:elliptic curve routines:EC_POINT_set_affine_coordinates:point is not on curve

Obtained from: CheriBSD
MFC after: 1 week

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable