Skip to content

Crypto: no unaligned 64-bit accesses on 32-bit ARM - #1908

Merged
idrassi merged 1 commit into
veracrypt:masterfrom
flatstik:arm32-unaligned-64bit
Oct 8, 2026
Merged

idrassi merged 1 commit into
veracrypt:masterfrom
flatstik:arm32-unaligned-64bit

Conversation

@flatstik

@flatstik flatstik commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

CRYPTOPP_ALLOW_UNALIGNED_DATA_ACCESS is defined whenever __ARM_FEATURE_UNALIGNED is set, which includes 32-bit ARMv6/ARMv7. There the hardware handles unaligned single-word loads and stores, but not LDRD/STRD/LDM, which the compiler uses for 64-bit words. With the macro defined:

  • Camellia's camellia_load64()/camellia_store64() dereference uint64 pointers instead of using memcpy,
  • Whirlpool's update passes unaligned input to HashMultipleBlocks() as uint64 * instead of copying it first,
  • misc.h reports an alignment of 1 for every type.

On an OpenWrt ARMv7 (cortex-a15, musl) build, veracrypt --text --test stopped with SIGBUS in camellia_set_key() (ldrd r0, [r0]) from EncryptionTest::TestXts(), because the static test key happened to be only 2-byte aligned (0x57b9de). Whether it crashes depends on where the linker places the test vectors, so other builds pass by luck; real keys and data can be unaligned too.

This defines the macro for AArch64 only among the ARM targets (unaligned 64-bit accesses are fine there); 32-bit ARM then uses the memcpy/aligned-copy paths. x86, x64 and powerpc are unchanged; MSVC does not define __ARM_FEATURE_UNALIGNED, so Windows ARM builds are unchanged too.

Tested: the ARMv7 build passes the self-tests under qemu-user with -cpu cortex-a15 and -cpu cortex-a7 (before: SIGBUS on cortex-a15).

CRYPTOPP_ALLOW_UNALIGNED_DATA_ACCESS was defined whenever
__ARM_FEATURE_UNALIGNED is set, which includes 32-bit ARMv6/ARMv7. There
the hardware handles unaligned single-word loads and stores, but not
LDRD/STRD/LDM, which the compiler uses for 64-bit words. Camellia
(camellia_load64/camellia_store64) and Whirlpool (HashMultipleBlocks on
unaligned input) then access 64-bit words through unaligned pointers.

camellia_set_key() raised SIGBUS in the XTS self-test on an ARMv7
(cortex-a15) build whose test key happened to be only 2-byte aligned.

Define the macro for AArch64 only among the ARM targets; on 32-bit ARM
the memcpy and aligned-copy paths are used instead.

Signed-off-by: Ville Takio <ville+git@takio.fi>
@idrassi

idrassi commented Oct 8, 2026

Copy link
Copy Markdown
Member

Thank you for the fix.

@idrassi
idrassi merged commit cb1d9a4 into veracrypt:master Oct 8, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants