Skip to content

Argon2: fix build with -march=x86-64-v3/v4 and XOP targets - #1906

Merged
idrassi merged 2 commits into
veracrypt:masterfrom
flatstik:argon2-avx2-build
Oct 5, 2026
Merged

idrassi merged 2 commits into
veracrypt:masterfrom
flatstik:argon2-avx2-build

Conversation

@flatstik

@flatstik flatstik commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Fixes #1867 (the build error also reported in #1871). Alternative to #1890, opened at @puleglot's request.

When squashing: the first commit message says Fixes #1871, please change that to Refs #1871, since #1871 is mainly about the Ubuntu 22.04 CI runner, which this doesn't touch.

blamka-round-opt.h picked its SSE2, AVX2 or AVX-512 definitions only from the compiler flags. With global flags such as -march=x86-64-v3 or -march=x86-64-v4 (Ubuntu 26.04, distribution builds, -march=native), opt_sse2.c, and with v4 also opt_avx2.c, got definitions that don't match their code, and the build failed.

Changes:

  • opt_sse2.c defines ARGON2_BLAMKA_SSE2 and opt_avx2.c defines ARGON2_BLAMKA_AVX2 before including the header, and the header uses that to select the variant. Any other includer still gets the old selection by compiler flags.
  • No new compiler options, so this works with old compilers (no -mno-avx512f needed) and also covers the plain objects used by NOASM=1 builds.
  • With XOP targets (-march=bdver*), the header skipped its _mm_roti_epi64 fallback, but the include that declares the intrinsic was commented out. The #include <x86intrin.h> that is already guarded by __XOP__ && (__GNUC__ || __clang__) is enabled again; MSVC and the Windows driver never take that branch.

Testing:

  • opt_sse2.c, opt_avx2.c -mavx2 and opt_avx2.c without -mavx2 (as in NOASM=1) compile without errors or warnings (-Wall -Wextra) with GCC 10, 12, 14.2 and Clang 19.1.7, for default, x86-64-v2, x86-64-v3, x86-64-v4, bdver2, bdver4, znver4 (not known to GCC 10), skylake-avx512 and native. On master, the v3, v4, bdver2, bdver4, znver4, skylake-avx512 and native builds (on an AVX2 host) fail.
  • Objects built with the default flags (and with NOASM=1-style plain objects) are byte-identical to master.
  • A small harness hashes with argon2id_hash_raw through the AVX2 path, the SSE2 path, and the portable code (forced with ld --wrap on x86-64, where HasSSE2() is always 1). All three give identical hashes, which also match an unmodified master build, with GCC 14 and Clang 19 for default and -march=x86-64-v3 flags. The Argon2i/Argon2id self-tests pass through the AVX2 and SSE2 paths with GCC 10, GCC 14 and Clang 19 for default and -march=x86-64-v3 flags.
  • The v4 and XOP builds are compile-tested only; I have no such CPU.

blamka-round-opt.h picked its SSE2, AVX2 or AVX-512 definitions only from
the compiler flags. With global flags such as -march=x86-64-v3 or
-march=x86-64-v4, opt_sse2.c (and with v4 also opt_avx2.c) saw __AVX2__
or __AVX512F__ and got definitions that do not match its code, so the
build failed.

Let opt_sse2.c and opt_avx2.c select the variant they implement, and
fall back to the compiler flags for other includers. This needs no new
compiler options, so it also works with old compilers and with the
plain objects used by NOASM=1 builds.

With XOP targets (-march=bdver*), the header skipped its
_mm_roti_epi64 fallback but did not include the intrinsic; include
<x86intrin.h> for GCC and Clang there.

Hashes are identical through the AVX2, SSE2 and reference code paths,
and match an unmodified build.

Fixes veracrypt#1867
Fixes veracrypt#1871
The #else/#endif comments still named __AVX2__ and __AVX512F__, but the
branches are now selected by ARGON2_BLAMKA_USE_SSE2/AVX2.

Refs veracrypt#1867
@idrassi

idrassi commented Oct 5, 2026

Copy link
Copy Markdown
Member

Thanks, I prefer this approach.

@idrassi
idrassi merged commit 4f76ff7 into veracrypt:master Oct 5, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Argon2: opt_sse2.c fails to compile when the global CFLAGS enable AVX2 (-march=native / -march=x86-64-v3)

2 participants