pkgsrc-Bugs archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

pkg/60798: security/openssl: does not build on OpenBSD/arm64, and crashes once it does



>Number:         60798
>Category:       pkg
>Synopsis:       security/openssl: does not build on OpenBSD/arm64, and crashes once it does
>Confidential:   no
>Severity:       serious
>Priority:       medium
>Responsible:    pkg-manager
>State:          open
>Class:          sw-bug
>Submitter-Id:   net
>Arrival-Date:   Sat Sep 26 10:45:01 +0000 2026
>Originator:     Showta Ishizaki
>Release:        pkgsrc-current
>Organization:
>Environment:
System: OpenBSD 7.9 arm64
Architecture: aarch64
Machine: arm64
>Description:
	Two things, one behind the other.  security/openssl does not
	build on OpenBSD/arm64, and with that fixed its own test suite
	crashes.  They are unrelated faults but you meet the second
	only by clearing the first, so they are in one report.

	1. The link of every DSO fails:

	  cc ... -Wl,-z,defs -shared ... -o engines/dasync.so ... -lcrypto
	  ld: error: undefined symbol: strcmp
	  ld: error: undefined symbol: memcpy
	  ld: error: undefined symbol: write
	  (read, pipe, close likewise)

	OpenBSD's cc -shared does not link libc, and -Wl,-z,defs then
	refuses the DSO.  It is not only the engines: providers/legacy.so
	and test/p_test.so, the provider module the test suite loads,
	fail the same way.

	OpenSSL has a target family for exactly this.  Every BSD-* target
	inherits bsd-gcc-shared, which carries -z defs; every
	BSD-nodef-* inherits bsd-gcc-nodef-shared, which does not.
	util/perl/OpenSSL/config.pm sends amd64-*-openbsd to
	BSD-nodef-x86_64 and has a catch-all sending OpenBSD to
	BSD-nodef-generic32 -- but that catch-all sits after the rules
	that match on architecture, so anything with its own rule never
	reaches it.  arm64-*-*bsd* is one of those, and there is no
	BSD-nodef-aarch64 for it to name.

	2. With the link fixed, 30-test_evp.t dies:

	  not ok 5 - running evp_test ... evpciph_aes_stitched.txt
	  30-test_evp.t (Wstat: 256 Tests: 108 Failed: 1)

	The aarch64 stitched AES+SHA implementations keep their SHA
	round constants inside .text and reach them with adr:

	  .Lrcon:
	          .word   0x5a827999, ...
	  ...
	          adr     x8,.Lrcon
	          ldp     q4,q5,[x8],32

	OpenBSD maps .text execute-only on arm64, so that ldp reads a
	page it may not read.  egdb stops at asm_aescbc_sha1_hmac+4956,
	and disassembling there shows that ldp, with the adr forty
	bytes before it at +4916.  Anything using
	AES-CBC-HMAC-SHA1/256/512 hits it, not just the test.

	Upstream fixed that one in master with f7feb2d937ac of
	2025-10-01, "[aarch64] move constants to rodata".  It is in
	4.0.2; it is not on the 3.6 branch, nor on 3.5.

>How-To-Repeat:
	cd security/openssl && make on OpenBSD 7.9/arm64.  With the
	first patch alone, make test TESTS=test_evp.

>Fix:
	Four patches.  For the link, a BSD-nodef-aarch64 target
	(BSD-nodef-generic64 plus the aarch64 asm, the way
	BSD-nodef-x86_64 is built) and a config.pm rule that picks it
	for arm64-*-openbsd*, ahead of the generic arm64 rule.  For the
	crash, upstream's f7feb2d937ac split per file.  Four new files:

	  patches/patch-Configurations_10-main.conf
	  patches/patch-crypto_aes_asm_aes-sha1-armv8.pl
	  patches/patch-crypto_aes_asm_aes-sha256-armv8.pl
	  patches/patch-crypto_aes_asm_aes-sha512-armv8.pl

	The existing config.pm patch gains one hunk; distinfo and
	PKGREVISION follow.  Diff against pkgsrc-current of 2026-09-26
	(Makefile 1.320, distinfo 1.190, config.pm patch 1.3).

	Measured on OpenBSD 7.9/arm64.  The link, with 3.6.4 configured
	by a plain ./config both times:

	                  target              -z,defs   build
	  without      BSD-aarch64            present   fails
	  with         BSD-nodef-aarch64      gone      rc=0

	Without it, run through with make -k, five DSOs fail to link:
	engines/dasync.so, loader_attic.so and ossltest.so,
	providers/legacy.so and test/p_test.so.  With it all of them
	link, the five engines are there, and openssl version answers
	"OpenSSL 3.6.4 25 Aug 2026".

	The crash, with ./config no-shared no-module both times so that
	the link fault is out of the way:

	                  generated .S               make test  30-test_evp.t
	  without      .rodata 0, adr 4, adrp 0      rc=2       FAIL
	  with         .rodata 1, adr 0, adrp 4      rc=0       PASS

	The asm patches change the generated code on every aarch64
	platform, not only where it was crashing, so I ran the same two
	builds on macOS 26/arm64, where the assembler scheme is ios64
	rather than linux64:

	                  generated .S                 30-test_evp.t
	  without      __const 0, PAGEOFF 0, adr 4     PASS
	  with         __const 1, PAGEOFF 4, adr 0     PASS

	arm-xlate.pl turns .rodata into .section __TEXT,__const and
	adrp/:lo12: into @PAGE/@PAGEOFF there, so the change is being
	exercised -- the counts move -- and the tests pass either way.

	Elsewhere nothing moves.  Feeding config.pm's map_guess() the
	string each system's uname produces, with and without the
	patches, only arm64-*-openbsd changes: amd64 OpenBSD stays
	BSD-nodef-x86_64, and amd64 FreeBSD, DragonFly and NetBSD stay
	BSD-x86_64.  On macOS pkgsrc names darwin64-arm64-cc itself, so
	those rules are not consulted.  The three asm files are
	aarch64-only, and I have not touched the x86 or armv7 paths.

	Upstream has the link fault open as issue #32473, where
	providers/legacy.so fails the same way on OpenBSD/alpha.  The
	same gap in config.pm covers more than arm64 -- alpha,
	sparc64 and i386 all have their own rule and so miss the
	OpenBSD catch-all too, and for those three the nodef target
	already exists (BSD-nodef-generic64, BSD-nodef-sparc64,
	BSD-nodef-x86-elf), so each is one rule away.  This patch
	stays with arm64 because that is the machine I have.

	One aside, since I had the release strategy open while checking
	4.0.2.  Upstream supports 3.6 until 2026-11-01, five weeks from
	now; 4.0 until 2027-05-14; and 3.5, the LTS, until 2030-04-08.

	Going to 4.0 is a different kind of step from the updates this
	package has been taking.  It removes engines outright, so the
	five lib/engines-3 entries in PLIST go, and bin/c_rehash goes
	with them ("openssl rehash" replaces it).  It also drops SSLv3,
	makes ASN1_STRING opaque, stops cleaning up through atexit(),
	and changes the signatures of a good many X509 functions; with
	SHLIB_VERSION going 3 to 4, everything linked against
	libcrypto.so.3 wants rebuilding.

	I could not find anything 3.6 added over 3.5 that a package in
	the tree asks for.  I raise it only because the date is close.
	--- security/openssl/Makefile.orig
	+++ security/openssl/Makefile
	@@ -4,7 +4,7 @@
	 # is not possible for users who have bootstrapped without OpenSSL
	 # to install it and enable HTTPS fetching.
	 DISTNAME=	openssl-3.6.4
	-PKGREVISION=	1
	+PKGREVISION=	2
	 CATEGORIES=	security
	 MASTER_SITES=	${MASTER_SITE_GITHUB:=openssl/}
	 GITHUB_RELEASE=	${DISTNAME}
	--- security/openssl/distinfo.orig
	+++ security/openssl/distinfo
	@@ -3,5 +3,9 @@
	 BLAKE2s (openssl-3.6.4.tar.gz) = a53beb887698b14996f8a98efb813a7e91b19d304c7b83e7ebfb1aa1ddcebbf2
	 SHA512 (openssl-3.6.4.tar.gz) = 9e7f4039082880357969c0857f33b20a6a4306d1b5e4f8fcbd7ec8dc41edc96e87c526a1db0b8259f5000c4ced84149b03547562ce4f9df35194634a7576dac0
	 Size (openssl-3.6.4.tar.gz) = 55003802 bytes
	+SHA1 (patch-Configurations_10-main.conf) = da01e86d1f1914ba56a09b79a5dd00f286519f76
	 SHA1 (patch-Configurations_unix-Makefile.tmpl) = ea9b0a0c8de810362813d84a4f85c5ebdedf9fc6
	-SHA1 (patch-util_perl_OpenSSL_config.pm) = 3ba3c23046bf69c7d348b4c1c8c8269d83cfa2b4
	+SHA1 (patch-crypto_aes_asm_aes-sha1-armv8.pl) = 0d33a99a981be27a915e4a4df1fb013c6b2fe33e
	+SHA1 (patch-crypto_aes_asm_aes-sha256-armv8.pl) = d28e1e7d27afb74317600f1c8cef5f396758419f
	+SHA1 (patch-crypto_aes_asm_aes-sha512-armv8.pl) = 94976d5024e2f1a1acb3eef960f4ca520e26d11f
	+SHA1 (patch-util_perl_OpenSSL_config.pm) = db0f513b314462771eaf8432250d52cc73a0fe11
	--- security/openssl/patches/patch-util_perl_OpenSSL_config.pm.orig
	+++ security/openssl/patches/patch-util_perl_OpenSSL_config.pm
	@@ -4,9 +4,13 @@
 
	 fix default platform id (linux-ppc64) for big-endian PowerPC-based Linux
 
	---- util/perl/OpenSSL/config.pm.orig	2024-04-09 12:12:22.000000000 +0000
	+Pick BSD-nodef-aarch64 on OpenBSD/arm64; the generic arm64 rule matched
	+first and gave it the -Wl,-z,defs target, which cannot link the engines
	+there (see patch-Configurations_10-main.conf).
	+
	+--- util/perl/OpenSSL/config.pm.orig	Tue Aug 25 11:48:34 2026
	 +++ util/perl/OpenSSL/config.pm
	-@@ -130,6 +130,7 @@ my $guess_patterns = [
	+@@ -130,6 +130,7 @@
	        sub {
	            my $hw = `/usr/sbin/sysctl -n hw.model || /sbin/sysctl -n hw.model`;
	            $hw =~  s@.*(.)86-class.*@i${1}86@;
	@@ -14,7 +18,7 @@
	            return "${hw}-whatever-netbsd";
	        }
	      ],
	-@@ -579,29 +580,7 @@ EOF
	+@@ -596,29 +597,7 @@
	                       %config };
	          }
	        ],
	@@ -45,3 +49,11 @@
	        [ 'ppc64le-.*-linux2',      { target => "linux-ppc64le" } ],
	        [ 'ppc-.*-linux2',          { target => "linux-ppc" } ],
	        [ 'mips64.*-*-linux2',
	+@@ -826,6 +805,7 @@
	+       [ 'x86_64-.*-dragonfly.*',  { target => "BSD-x86_64" } ],
	+       [ 'amd64-.*-openbsd.*',     { target => "BSD-nodef-x86_64" } ],
	+       [ 'amd64-.*-.*bsd.*',       { target => "BSD-x86_64" } ],
	++      [ 'arm64-.*-openbsd.*',     { target => "BSD-nodef-aarch64" } ],
	+       [ 'arm64-.*-.*bsd.*',       { target => "BSD-aarch64" } ],
	+       [ 'armv6-.*-.*bsd.*',       { target => "BSD-armv4" } ],
	+       [ 'armv7-.*-.*bsd.*',       { target => "BSD-armv4" } ],
	--- /dev/null
	+++ security/openssl/patches/patch-Configurations_10-main.conf
	@@ -0,0 +1,25 @@
	+$NetBSD$
	+
	+Add a BSD-nodef-aarch64 target and let ./config pick it on OpenBSD/arm64,
	+the way amd64 already gets BSD-nodef-x86_64.  OpenBSD's cc -shared does not
	+link libc, so the -Wl,-z,defs that the BSD-* targets put on the engine DSOs
	+fails with undefined strcmp/memcpy/write/read/pipe/close; the -nodef
	+targets exist for exactly that.
	+
	+--- Configurations/10-main.conf.orig	Thu Sep 17 20:48:47 2026
	++++ Configurations/10-main.conf
	+@@ -1261,6 +1261,14 @@
	+         perlasm_scheme   => "elf",
	+     },
	+ 
	++    "BSD-nodef-aarch64" => {
	++        inherit_from     => [ "BSD-nodef-generic64" ],
	++        lib_cppflags     => add("-DL_ENDIAN"),
	++        bn_ops           => "SIXTY_FOUR_BIT_LONG",
	++        asm_arch         => 'aarch64',
	++        perlasm_scheme   => "linux64",
	++    },
	++
	+ #### SCO/Caldera targets.
	+ #
	+ # Originally we had like unixware-*, unixware-*-pentium, unixware-*-p6, etc.
	--- /dev/null
	+++ security/openssl/patches/patch-crypto_aes_asm_aes-sha1-armv8.pl
	@@ -0,0 +1,70 @@
	+$NetBSD$
	+
	+Move the aarch64 stitched AES+SHA round constants out of .text.
	+
	+The constants sit in .text and are reached with adr, so reading them is a
	+load from an executable page.  OpenBSD maps .text execute-only on arm64, so
	+the load faults and anything using the stitched ciphers dies with SIGSEGV
	+(seen in test/recipes/30-test_evp.t on 7.9/arm64).
	+
	+This is upstream commit f7feb2d937ac of 2025-10-01, "[aarch64] move
	+constants to rodata", which is in master but not on the 3.6 branch.  It puts
	+the constants in .rodata and reaches them with adrp + add :lo12: instead.
	+
	+--- crypto/aes/asm/aes-sha1-armv8.pl.orig
	++++ crypto/aes/asm/aes-sha1-armv8.pl
	+@@ -217,12 +217,14 @@
	+ .global asm_aescbc_sha1_hmac
	+ .type	asm_aescbc_sha1_hmac,%function
	+ 
	++.rodata
	+ .align	4
	+ .Lrcon:
	+ 	.word	0x5a827999, 0x5a827999, 0x5a827999, 0x5a827999
	+ 	.word	0x6ed9eba1, 0x6ed9eba1, 0x6ed9eba1, 0x6ed9eba1
	+ 	.word	0x8f1bbcdc, 0x8f1bbcdc, 0x8f1bbcdc, 0x8f1bbcdc
	+ 	.word	0xca62c1d6, 0xca62c1d6, 0xca62c1d6, 0xca62c1d6
	++.text
	+ 
	+ asm_aescbc_sha1_hmac:
	+ 	AARCH64_VALID_CALL_TARGET
	+@@ -276,7 +278,8 @@
	+ 	ldp		q10,q11,[x9],32		/* rk[2],rk[3] */
	+ 	prfm		PLDL1KEEP,[x0,64]	/* pref next aes_ptr_in */
	+ 	/* base address for sha round consts */
	+-	adr		x8,.Lrcon
	++	adrp		x8,.Lrcon
	++	add		x8,x8,:lo12:.Lrcon
	+ 	aese		v0.16b,v9.16b
	+ 	aesmc		v0.16b,v0.16b
	+ 	prfm		PLDL1KEEP,[x1,64]	/* pref next aes_ptr_out  */
	+@@ -1524,7 +1527,8 @@
	+  */
	+ .Lenc_short_cases:
	+ 	ldp		q8,q9,[x9],32
	+-	adr		x8,.Lrcon			/* rcon */
	++	adrp		x8,.Lrcon			/* rcon */
	++	add		x8,x8,:lo12:.Lrcon
	+ 	mov		w15,0x80			/* sha padding word */
	+ 	ldp		q10,q11,[x9],32
	+ 	lsl		x11,x10,4			/* len = aes_blocks*16 */
	+@@ -2427,7 +2431,8 @@
	+ 	blt		.Ldec_short_cases	/* branch if < 12 */
	+ 
	+ 	/* base address for sha round consts */
	+-	adr		x8,.Lrcon
	++	adrp		x8,.Lrcon
	++	add		x8,x8,:lo12:.Lrcon
	+ 	ldp		q4,q5,[x8],32		/* key0,key1 */
	+ 	ldp		q6,q7,[x8],32		/* key2,key3 */
	+ 
	+@@ -3867,7 +3872,8 @@
	+  */
	+ .Ldec_short_cases:
	+ 	ldp		q8,q9,[x9],32
	+-	adr		x8,.Lrcon		/* rcon */
	++	adrp		x8,.Lrcon		/* rcon */
	++	add		x8,x8,:lo12:.Lrcon
	+ 	ldp		q10,q11,[x9],32
	+ 	lsl		x11,x10,4		/* len = aes_blocks*16 */
	+ 
	--- /dev/null
	+++ security/openssl/patches/patch-crypto_aes_asm_aes-sha256-armv8.pl
	@@ -0,0 +1,241 @@
	+$NetBSD$
	+
	+Move the aarch64 stitched AES+SHA round constants out of .text.
	+
	+The constants sit in .text and are reached with adr, so reading them is a
	+load from an executable page.  OpenBSD maps .text execute-only on arm64, so
	+the load faults and anything using the stitched ciphers dies with SIGSEGV
	+(seen in test/recipes/30-test_evp.t on 7.9/arm64).
	+
	+This is upstream commit f7feb2d937ac of 2025-10-01, "[aarch64] move
	+constants to rodata", which is in master but not on the 3.6 branch.  It puts
	+the constants in .rodata and reaches them with adrp + add :lo12: instead.
	+
	+--- crypto/aes/asm/aes-sha256-armv8.pl.orig
	++++ crypto/aes/asm/aes-sha256-armv8.pl
	+@@ -216,6 +216,7 @@
	+ .global	asm_aescbc_sha256_hmac
	+ .type	asm_aescbc_sha256_hmac,%function
	+ 
	++.rodata
	+ .align	4
	+ .Lrcon:
	+ 	.word	0x428a2f98, 0x71374491, 0xb5c0fbcf, 0xe9b5dba5
	+@@ -238,6 +239,7 @@
	+ .Linit_sha_state:
	+ 	.word	0x6a09e667, 0xbb67ae85, 0x3c6ef372, 0xa54ff53a
	+ 	.word	0x510e527f, 0x9b05688c, 0x1f83d9ab, 0x5be0cd19
	++.text
	+ 
	+ asm_aescbc_sha256_hmac:
	+ 	AARCH64_VALID_CALL_TARGET
	+@@ -253,7 +255,8 @@
	+ 	stp		d10,d11,[sp,#16]
	+ 
	+ 	/* address of sha init state consts */
	+-	adr		x12,.Linit_sha_state
	++	adrp		x12,.Linit_sha_state
	++	add		x12,x12,:lo12:.Linit_sha_state
	+ 	prfm		PLDL1KEEP,[x1,0]	/* pref next aes_ptr_out */
	+ 	lsr		x10,x2,4		/* aes_blocks = len/16 */
	+ 
	+@@ -296,7 +299,8 @@
	+ 	aesmc		v0.16b,v0.16b
	+ 	prfm		PLDL1KEEP,[x1,64]	/* pref next aes_ptr_out  */
	+ 	/* base address for sha round consts */
	+-	adr		x8,.Lrcon
	++	adrp		x8,.Lrcon
	++	add		x8,x8,:lo12:.Lrcon
	+ 	ld1		{v12.16b},[x9],16	/* rk[4] */
	+ 	aese		v0.16b,v10.16b
	+ 	aesmc		v0.16b,v0.16b
	+@@ -435,7 +439,8 @@
	+ 	 */
	+ .Lenc_main_loop:
	+ 	/* base address for sha round consts */
	+-	adr		x8,.Lrcon
	++	adrp		x8,.Lrcon
	++	add		x8,x8,:lo12:.Lrcon
	+ 	/*
	+ 	 * Because both mov, rev32 and eor have a busy cycle,this takes longer
	+ 	 * than it looks. That's OK since there are 6 cycles before we can use
	+@@ -703,7 +708,8 @@
	+ 	 */
	+ 	ld1		{v0.16b},[x0],16
	+ 	/* base address for sha round consts */
	+-	adr		x8,.Lrcon
	++	adrp		x8,.Lrcon
	++	add		x8,x8,:lo12:.Lrcon
	+ 	ld1		{v4.16b},[x8],16	/* key0 */
	+ 	ld1		{v5.16b},[x8],16	/* key1 */
	+ 	ld1		{v6.16b},[x8],16	/* key2 */
	+@@ -893,7 +899,8 @@
	+ /* quad 0 */
	+ .Lbm2fromQ0:
	+ 	/* base address for sha round consts */
	+-	adr		x8,.Lrcon
	++	adrp		x8,.Lrcon
	++	add		x8,x8,:lo12:.Lrcon
	+ 
	+ 	ld1		{v4.16b},[x8],16	/* key0 */
	+ 	ld1		{v5.16b},[x8],16	/* key1 */
	+@@ -1164,7 +1171,8 @@
	+  */
	+ 1:
	+ 	/* base address for sha round consts */
	+-	adr		x8,.Lrcon
	++	adrp		x8,.Lrcon
	++	add		x8,x8,:lo12:.Lrcon
	+ 
	+ 	ld1		{v4.16b},[x8],16	/* key0 */
	+ 	ld1		{v5.16b},[x8],16	/* key1 */
	+@@ -1323,7 +1331,8 @@
	+ 	 * do last sha of pad block
	+ 	 */
	+ 	/* base address for sha round consts */
	+-	adr		x8,.Lrcon
	++	adrp		x8,.Lrcon
	++	add		x8,x8,:lo12:.Lrcon
	+ 
	+ 	/* quad 0 */
	+ 	ld1		{v4.16b},[x8],16	/* key0 */
	+@@ -1460,7 +1469,8 @@
	+ 	eor		v28.16b, v28.16b, v28.16b
	+ 	eor		v29.16b, v29.16b, v29.16b
	+ 	/* base address for sha round consts */
	+-	adr		x8,.Lrcon
	++	adrp		x8,.Lrcon
	++	add		x8,x8,:lo12:.Lrcon
	+ 	/* load o_key_pad partial hash */
	+ 	ldp		q24,q25,[x7]
	+ 
	+@@ -1641,7 +1651,8 @@
	+  * already in place excepting the final word.
	+  */
	+ .Lenc_short_loop:
	+-	adr		x8,.Lrcon			/* rcon */
	++	adrp		x8,.Lrcon			/* rcon */
	++	add		x8,x8,:lo12:.Lrcon
	+ 	/* read next aes block, update aes_ptr_in */
	+ 	ld1		{v0.16b},[x0],16
	+ 	eor		v0.16b,v0.16b,v3.16b		/* xor w/prev value */
	+@@ -2019,7 +2030,8 @@
	+  */
	+ 1:
	+ 	/* base address for sha round consts */
	+-	adr		x8,.Lrcon
	++	adrp		x8,.Lrcon
	++	add		x8,x8,:lo12:.Lrcon
	+ 
	+ 	ld1		{v4.16b},[x8],16	/* key0 */
	+ 	ld1		{v5.16b},[x8],16	/* key1 */
	+@@ -2180,7 +2192,8 @@
	+ 	/* do final block */
	+ 
	+ 	/* base address for sha round consts */
	+-	adr		x8,.Lrcon		/* top of rcon */
	++	adrp		x8,.Lrcon		/* top of rcon */
	++	add		x8,x8,:lo12:.Lrcon
	+ 
	+ 	/* quad 0 */
	+ 	ld1		{v4.16b},[x8],16	/* key0 */
	+@@ -2317,7 +2330,8 @@
	+ 	eor		v28.16b, v28.16b, v28.16b
	+ 	eor		v29.16b, v29.16b, v29.16b
	+ 	/* base address for sha round consts */
	+-	adr		x8,.Lrcon
	++	adrp		x8,.Lrcon
	++	add		x8,x8,:lo12:.Lrcon
	+ 	/* load o_key_pad partial hash */
	+ 	ldp		q24,q25,[x7]
	+ 
	+@@ -2563,7 +2577,8 @@
	+ 	lsr		x10,x2,4		/* aes_blocks = len/16 */
	+ 	stp		d14,d15,[sp,#48]
	+ 	/* address of sha init state consts */
	+-	adr		x12,.Linit_sha_state
	++	adrp		x12,.Linit_sha_state
	++	add		x12,x12,:lo12:.Linit_sha_state
	+ 	stp		x19,x20,[sp,#64]
	+ 
	+ 	ldr		x9, [x6, #CIPHER_KEY]
	+@@ -2599,7 +2614,8 @@
	+ 	prfm		PLDL1KEEP,[x0,64]	/* pref next aes_ptr_in */
	+ 	prfm		PLDL1KEEP,[x1,64]	/* pref next aes_ptr_out */
	+ 	/* base address for sha round consts */
	+-	adr		x8,.Lrcon
	++	adrp		x8,.Lrcon
	++	add		x8,x8,:lo12:.Lrcon
	+ 	/*
	+ 	 * do the first sha256 block on the plaintext
	+ 	 */
	+@@ -2782,7 +2798,8 @@
	+ 	prfm		PLDL1KEEP,[x1,64]
	+ 	mov		v23.16b,v25.16b		/* working EFGH <- EFGH */
	+ 	/* base address for sha round consts */
	+-	adr		x8,.Lrcon
	++	adrp		x8,.Lrcon
	++	add		x8,x8,:lo12:.Lrcon
	+ 
	+ 	/*
	+ 	 * aes xform 0, sha quad 0
	+@@ -3036,7 +3053,8 @@
	+ 	prfm		PLDL1KEEP,[x1,64]
	+ 	mov		v23.16b,v25.16b		/* working EFGH <- EFGH */
	+ 	/* base address for sha round consts */
	+-	adr		x8,.Lrcon
	++	adrp		x8,.Lrcon
	++	add		x8,x8,:lo12:.Lrcon
	+ 	ld1		{v4.16b},[x8],16	/* key0 */
	+ 	ld1		{v5.16b},[x8],16	/* key1 */
	+ 
	+@@ -3399,7 +3417,8 @@
	+  */
	+ .Ljoin_common:
	+ 	/* base address for sha round consts */
	+-	adr		x8,.Lrcon
	++	adrp		x8,.Lrcon
	++	add		x8,x8,:lo12:.Lrcon
	+ 	mov		w15,0x80	/* that's the 1 of the pad */
	+ .Lpost_loop_Q0:
	+ 	/* assume this was final block */
	+@@ -3664,7 +3683,8 @@
	+ 	/* read first aes block, bump aes_ptr_in */
	+ 	ld1		{v0.16b},[x0]
	+ 	ld1		{v31.16b},[x0],16
	+-	adr		x8,.Lrcon
	++	adrp		x8,.Lrcon
	++	add		x8,x8,:lo12:.Lrcon
	+ 	ld1		{v4.16b},[x8],16	/* key0 */
	+ 	aesd		v0.16b,v8.16b
	+ 	aesimc		v0.16b,v0.16b
	+@@ -3845,7 +3865,8 @@
	+ 
	+ .Lzero_aes_blocks_left:
	+ 	/* base address for sha round consts */
	+-	adr		x8,.Lrcon
	++	adrp		x8,.Lrcon
	++	add		x8,x8,:lo12:.Lrcon
	+ 	ld1		{v4.16b},[x8],16	/* key0 */
	+ 	ld1		{v5.16b},[x8],16	/* key1 */
	+ 
	+@@ -3991,7 +4012,8 @@
	+ 	 * Calculate final HMAC
	+ 	 */
	+ 	/* base address for sha round consts */
	+-	adr		x8,.Lrcon
	++	adrp		x8,.Lrcon
	++	add		x8,x8,:lo12:.Lrcon
	+ 	/* load o_key_pad partial hash */
	+ 	ld1		{v24.16b},[x7],16
	+ 	ld1		{v25.16b},[x7]
	+@@ -4164,7 +4186,8 @@
	+  */
	+ .Ldec_short_cases:
	+ 	ldp		q8,q9,[x9],32
	+-	adr		x8,.Lrcon		/* rcon */
	++	adrp		x8,.Lrcon		/* rcon */
	++	add		x8,x8,:lo12:.Lrcon
	+ 	ldp		q10,q11,[x9],32
	+ 	lsl		x11,x10,4		/* len=aes_blocks*16 */
	+ 
	--- /dev/null
	+++ security/openssl/patches/patch-crypto_aes_asm_aes-sha512-armv8.pl
	@@ -0,0 +1,51 @@
	+$NetBSD$
	+
	+Move the aarch64 stitched AES+SHA round constants out of .text.
	+
	+The constants sit in .text and are reached with adr, so reading them is a
	+load from an executable page.  OpenBSD maps .text execute-only on arm64, so
	+the load faults and anything using the stitched ciphers dies with SIGSEGV
	+(seen in test/recipes/30-test_evp.t on 7.9/arm64).
	+
	+This is upstream commit f7feb2d937ac of 2025-10-01, "[aarch64] move
	+constants to rodata", which is in master but not on the 3.6 branch.  It puts
	+the constants in .rodata and reaches them with adrp + add :lo12: instead.
	+
	+--- crypto/aes/asm/aes-sha512-armv8.pl.orig
	++++ crypto/aes/asm/aes-sha512-armv8.pl
	+@@ -310,6 +310,7 @@
	+ .global asm_aescbc_sha512_hmac
	+ .type	asm_aescbc_sha512_hmac,%function
	+ 
	++.rodata
	+ .align 6
	+ .LK512:
	+ 	.quad	0x428a2f98d728ae22,0x7137449123ef65cd
	+@@ -354,6 +355,7 @@
	+ 	.quad	0x5fcb6fab3ad6faec,0x6c44198c4a475817
	+ 	.quad	0	// terminator
	+ 
	++.text
	+ 	.align	4
	+ asm_aescbc_sha512_hmac:
	+ 	AARCH64_VALID_CALL_TARGET
	+@@ -372,7 +374,8 @@
	+ 	ldr		x9, [x6, #CIPHER_KEY_ROUNDS]
	+ 	mov		x12, x7				/* backup x7 */
	+ 
	+-	adr		x10, .LK512
	++	adrp		x10, .LK512
	++	add		x10, x10, :lo12:.LK512
	+ 
	+ 	lsr		x11, x2, #4			/* aes_block = len/16 */
	+ 	cbz		x11, .Lret			/* return if aes_block = 0 */
	+@@ -2087,7 +2090,8 @@
	+ 	ldr		x9, [x6, #CIPHER_KEY_ROUNDS]
	+ 	mov		x12, x7			/* backup x7 */
	+ 
	+-	adr		x10, .LK512
	++	adrp		x10, .LK512
	++	add		x10, x10, :lo12:.LK512
	+ 
	+ 	lsr		x11, x2, #4		/* aes_block = len/16 */
	+ 	cbz		x11, .Ldec_ret		/* return if aes_block = 0 */




Home | Main Index | Thread Index | Old Index