Repository navigation
Crypto: no unaligned 64-bit accesses on 32-bit ARM - #1908
Merged
Merged
Conversation
CRYPTOPP_ALLOW_UNALIGNED_DATA_ACCESS was defined whenever __ARM_FEATURE_UNALIGNED is set, which includes 32-bit ARMv6/ARMv7. There the hardware handles unaligned single-word loads and stores, but not LDRD/STRD/LDM, which the compiler uses for 64-bit words. Camellia (camellia_load64/camellia_store64) and Whirlpool (HashMultipleBlocks on unaligned input) then access 64-bit words through unaligned pointers. camellia_set_key() raised SIGBUS in the XTS self-test on an ARMv7 (cortex-a15) build whose test key happened to be only 2-byte aligned. Define the macro for AArch64 only among the ARM targets; on 32-bit ARM the memcpy and aligned-copy paths are used instead. Signed-off-by: Ville Takio <ville+git@takio.fi>
This was referenced Oct 7, 2026
Member
|
Thank you for the fix. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
CRYPTOPP_ALLOW_UNALIGNED_DATA_ACCESSis defined whenever__ARM_FEATURE_UNALIGNEDis set, which includes 32-bit ARMv6/ARMv7. There the hardware handles unaligned single-word loads and stores, but notLDRD/STRD/LDM, which the compiler uses for 64-bit words. With the macro defined:camellia_load64()/camellia_store64()dereferenceuint64pointers instead of usingmemcpy,HashMultipleBlocks()asuint64 *instead of copying it first,misc.hreports an alignment of 1 for every type.On an OpenWrt ARMv7 (cortex-a15, musl) build,
veracrypt --text --teststopped with SIGBUS incamellia_set_key()(ldrd r0, [r0]) fromEncryptionTest::TestXts(), because the static test key happened to be only 2-byte aligned (0x57b9de). Whether it crashes depends on where the linker places the test vectors, so other builds pass by luck; real keys and data can be unaligned too.This defines the macro for AArch64 only among the ARM targets (unaligned 64-bit accesses are fine there); 32-bit ARM then uses the
memcpy/aligned-copy paths. x86, x64 and powerpc are unchanged; MSVC does not define__ARM_FEATURE_UNALIGNED, so Windows ARM builds are unchanged too.Tested: the ARMv7 build passes the self-tests under qemu-user with
-cpu cortex-a15and-cpu cortex-a7(before: SIGBUS on cortex-a15).