pkgsrc-Bugs archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
pkg/60798: security/openssl: does not build on OpenBSD/arm64, and crashes once it does
>Number: 60798
>Category: pkg
>Synopsis: security/openssl: does not build on OpenBSD/arm64, and crashes once it does
>Confidential: no
>Severity: serious
>Priority: medium
>Responsible: pkg-manager
>State: open
>Class: sw-bug
>Submitter-Id: net
>Arrival-Date: Sat Sep 26 10:45:01 +0000 2026
>Originator: Showta Ishizaki
>Release: pkgsrc-current
>Organization:
>Environment:
System: OpenBSD 7.9 arm64
Architecture: aarch64
Machine: arm64
>Description:
Two things, one behind the other. security/openssl does not
build on OpenBSD/arm64, and with that fixed its own test suite
crashes. They are unrelated faults but you meet the second
only by clearing the first, so they are in one report.
1. The link of every DSO fails:
cc ... -Wl,-z,defs -shared ... -o engines/dasync.so ... -lcrypto
ld: error: undefined symbol: strcmp
ld: error: undefined symbol: memcpy
ld: error: undefined symbol: write
(read, pipe, close likewise)
OpenBSD's cc -shared does not link libc, and -Wl,-z,defs then
refuses the DSO. It is not only the engines: providers/legacy.so
and test/p_test.so, the provider module the test suite loads,
fail the same way.
OpenSSL has a target family for exactly this. Every BSD-* target
inherits bsd-gcc-shared, which carries -z defs; every
BSD-nodef-* inherits bsd-gcc-nodef-shared, which does not.
util/perl/OpenSSL/config.pm sends amd64-*-openbsd to
BSD-nodef-x86_64 and has a catch-all sending OpenBSD to
BSD-nodef-generic32 -- but that catch-all sits after the rules
that match on architecture, so anything with its own rule never
reaches it. arm64-*-*bsd* is one of those, and there is no
BSD-nodef-aarch64 for it to name.
2. With the link fixed, 30-test_evp.t dies:
not ok 5 - running evp_test ... evpciph_aes_stitched.txt
30-test_evp.t (Wstat: 256 Tests: 108 Failed: 1)
The aarch64 stitched AES+SHA implementations keep their SHA
round constants inside .text and reach them with adr:
.Lrcon:
.word 0x5a827999, ...
...
adr x8,.Lrcon
ldp q4,q5,[x8],32
OpenBSD maps .text execute-only on arm64, so that ldp reads a
page it may not read. egdb stops at asm_aescbc_sha1_hmac+4956,
and disassembling there shows that ldp, with the adr forty
bytes before it at +4916. Anything using
AES-CBC-HMAC-SHA1/256/512 hits it, not just the test.
Upstream fixed that one in master with f7feb2d937ac of
2025-10-01, "[aarch64] move constants to rodata". It is in
4.0.2; it is not on the 3.6 branch, nor on 3.5.
>How-To-Repeat:
cd security/openssl && make on OpenBSD 7.9/arm64. With the
first patch alone, make test TESTS=test_evp.
>Fix:
Four patches. For the link, a BSD-nodef-aarch64 target
(BSD-nodef-generic64 plus the aarch64 asm, the way
BSD-nodef-x86_64 is built) and a config.pm rule that picks it
for arm64-*-openbsd*, ahead of the generic arm64 rule. For the
crash, upstream's f7feb2d937ac split per file. Four new files:
patches/patch-Configurations_10-main.conf
patches/patch-crypto_aes_asm_aes-sha1-armv8.pl
patches/patch-crypto_aes_asm_aes-sha256-armv8.pl
patches/patch-crypto_aes_asm_aes-sha512-armv8.pl
The existing config.pm patch gains one hunk; distinfo and
PKGREVISION follow. Diff against pkgsrc-current of 2026-09-26
(Makefile 1.320, distinfo 1.190, config.pm patch 1.3).
Measured on OpenBSD 7.9/arm64. The link, with 3.6.4 configured
by a plain ./config both times:
target -z,defs build
without BSD-aarch64 present fails
with BSD-nodef-aarch64 gone rc=0
Without it, run through with make -k, five DSOs fail to link:
engines/dasync.so, loader_attic.so and ossltest.so,
providers/legacy.so and test/p_test.so. With it all of them
link, the five engines are there, and openssl version answers
"OpenSSL 3.6.4 25 Aug 2026".
The crash, with ./config no-shared no-module both times so that
the link fault is out of the way:
generated .S make test 30-test_evp.t
without .rodata 0, adr 4, adrp 0 rc=2 FAIL
with .rodata 1, adr 0, adrp 4 rc=0 PASS
The asm patches change the generated code on every aarch64
platform, not only where it was crashing, so I ran the same two
builds on macOS 26/arm64, where the assembler scheme is ios64
rather than linux64:
generated .S 30-test_evp.t
without __const 0, PAGEOFF 0, adr 4 PASS
with __const 1, PAGEOFF 4, adr 0 PASS
arm-xlate.pl turns .rodata into .section __TEXT,__const and
adrp/:lo12: into @PAGE/@PAGEOFF there, so the change is being
exercised -- the counts move -- and the tests pass either way.
Elsewhere nothing moves. Feeding config.pm's map_guess() the
string each system's uname produces, with and without the
patches, only arm64-*-openbsd changes: amd64 OpenBSD stays
BSD-nodef-x86_64, and amd64 FreeBSD, DragonFly and NetBSD stay
BSD-x86_64. On macOS pkgsrc names darwin64-arm64-cc itself, so
those rules are not consulted. The three asm files are
aarch64-only, and I have not touched the x86 or armv7 paths.
Upstream has the link fault open as issue #32473, where
providers/legacy.so fails the same way on OpenBSD/alpha. The
same gap in config.pm covers more than arm64 -- alpha,
sparc64 and i386 all have their own rule and so miss the
OpenBSD catch-all too, and for those three the nodef target
already exists (BSD-nodef-generic64, BSD-nodef-sparc64,
BSD-nodef-x86-elf), so each is one rule away. This patch
stays with arm64 because that is the machine I have.
One aside, since I had the release strategy open while checking
4.0.2. Upstream supports 3.6 until 2026-11-01, five weeks from
now; 4.0 until 2027-05-14; and 3.5, the LTS, until 2030-04-08.
Going to 4.0 is a different kind of step from the updates this
package has been taking. It removes engines outright, so the
five lib/engines-3 entries in PLIST go, and bin/c_rehash goes
with them ("openssl rehash" replaces it). It also drops SSLv3,
makes ASN1_STRING opaque, stops cleaning up through atexit(),
and changes the signatures of a good many X509 functions; with
SHLIB_VERSION going 3 to 4, everything linked against
libcrypto.so.3 wants rebuilding.
I could not find anything 3.6 added over 3.5 that a package in
the tree asks for. I raise it only because the date is close.
--- security/openssl/Makefile.orig
+++ security/openssl/Makefile
@@ -4,7 +4,7 @@
# is not possible for users who have bootstrapped without OpenSSL
# to install it and enable HTTPS fetching.
DISTNAME= openssl-3.6.4
-PKGREVISION= 1
+PKGREVISION= 2
CATEGORIES= security
MASTER_SITES= ${MASTER_SITE_GITHUB:=openssl/}
GITHUB_RELEASE= ${DISTNAME}
--- security/openssl/distinfo.orig
+++ security/openssl/distinfo
@@ -3,5 +3,9 @@
BLAKE2s (openssl-3.6.4.tar.gz) = a53beb887698b14996f8a98efb813a7e91b19d304c7b83e7ebfb1aa1ddcebbf2
SHA512 (openssl-3.6.4.tar.gz) = 9e7f4039082880357969c0857f33b20a6a4306d1b5e4f8fcbd7ec8dc41edc96e87c526a1db0b8259f5000c4ced84149b03547562ce4f9df35194634a7576dac0
Size (openssl-3.6.4.tar.gz) = 55003802 bytes
+SHA1 (patch-Configurations_10-main.conf) = da01e86d1f1914ba56a09b79a5dd00f286519f76
SHA1 (patch-Configurations_unix-Makefile.tmpl) = ea9b0a0c8de810362813d84a4f85c5ebdedf9fc6
-SHA1 (patch-util_perl_OpenSSL_config.pm) = 3ba3c23046bf69c7d348b4c1c8c8269d83cfa2b4
+SHA1 (patch-crypto_aes_asm_aes-sha1-armv8.pl) = 0d33a99a981be27a915e4a4df1fb013c6b2fe33e
+SHA1 (patch-crypto_aes_asm_aes-sha256-armv8.pl) = d28e1e7d27afb74317600f1c8cef5f396758419f
+SHA1 (patch-crypto_aes_asm_aes-sha512-armv8.pl) = 94976d5024e2f1a1acb3eef960f4ca520e26d11f
+SHA1 (patch-util_perl_OpenSSL_config.pm) = db0f513b314462771eaf8432250d52cc73a0fe11
--- security/openssl/patches/patch-util_perl_OpenSSL_config.pm.orig
+++ security/openssl/patches/patch-util_perl_OpenSSL_config.pm
@@ -4,9 +4,13 @@
fix default platform id (linux-ppc64) for big-endian PowerPC-based Linux
---- util/perl/OpenSSL/config.pm.orig 2024-04-09 12:12:22.000000000 +0000
+Pick BSD-nodef-aarch64 on OpenBSD/arm64; the generic arm64 rule matched
+first and gave it the -Wl,-z,defs target, which cannot link the engines
+there (see patch-Configurations_10-main.conf).
+
+--- util/perl/OpenSSL/config.pm.orig Tue Aug 25 11:48:34 2026
+++ util/perl/OpenSSL/config.pm
-@@ -130,6 +130,7 @@ my $guess_patterns = [
+@@ -130,6 +130,7 @@
sub {
my $hw = `/usr/sbin/sysctl -n hw.model || /sbin/sysctl -n hw.model`;
$hw =~ s@.*(.)86-class.*@i${1}86@;
@@ -14,7 +18,7 @@
return "${hw}-whatever-netbsd";
}
],
-@@ -579,29 +580,7 @@ EOF
+@@ -596,29 +597,7 @@
%config };
}
],
@@ -45,3 +49,11 @@
[ 'ppc64le-.*-linux2', { target => "linux-ppc64le" } ],
[ 'ppc-.*-linux2', { target => "linux-ppc" } ],
[ 'mips64.*-*-linux2',
+@@ -826,6 +805,7 @@
+ [ 'x86_64-.*-dragonfly.*', { target => "BSD-x86_64" } ],
+ [ 'amd64-.*-openbsd.*', { target => "BSD-nodef-x86_64" } ],
+ [ 'amd64-.*-.*bsd.*', { target => "BSD-x86_64" } ],
++ [ 'arm64-.*-openbsd.*', { target => "BSD-nodef-aarch64" } ],
+ [ 'arm64-.*-.*bsd.*', { target => "BSD-aarch64" } ],
+ [ 'armv6-.*-.*bsd.*', { target => "BSD-armv4" } ],
+ [ 'armv7-.*-.*bsd.*', { target => "BSD-armv4" } ],
--- /dev/null
+++ security/openssl/patches/patch-Configurations_10-main.conf
@@ -0,0 +1,25 @@
+$NetBSD$
+
+Add a BSD-nodef-aarch64 target and let ./config pick it on OpenBSD/arm64,
+the way amd64 already gets BSD-nodef-x86_64. OpenBSD's cc -shared does not
+link libc, so the -Wl,-z,defs that the BSD-* targets put on the engine DSOs
+fails with undefined strcmp/memcpy/write/read/pipe/close; the -nodef
+targets exist for exactly that.
+
+--- Configurations/10-main.conf.orig Thu Sep 17 20:48:47 2026
++++ Configurations/10-main.conf
+@@ -1261,6 +1261,14 @@
+ perlasm_scheme => "elf",
+ },
+
++ "BSD-nodef-aarch64" => {
++ inherit_from => [ "BSD-nodef-generic64" ],
++ lib_cppflags => add("-DL_ENDIAN"),
++ bn_ops => "SIXTY_FOUR_BIT_LONG",
++ asm_arch => 'aarch64',
++ perlasm_scheme => "linux64",
++ },
++
+ #### SCO/Caldera targets.
+ #
+ # Originally we had like unixware-*, unixware-*-pentium, unixware-*-p6, etc.
--- /dev/null
+++ security/openssl/patches/patch-crypto_aes_asm_aes-sha1-armv8.pl
@@ -0,0 +1,70 @@
+$NetBSD$
+
+Move the aarch64 stitched AES+SHA round constants out of .text.
+
+The constants sit in .text and are reached with adr, so reading them is a
+load from an executable page. OpenBSD maps .text execute-only on arm64, so
+the load faults and anything using the stitched ciphers dies with SIGSEGV
+(seen in test/recipes/30-test_evp.t on 7.9/arm64).
+
+This is upstream commit f7feb2d937ac of 2025-10-01, "[aarch64] move
+constants to rodata", which is in master but not on the 3.6 branch. It puts
+the constants in .rodata and reaches them with adrp + add :lo12: instead.
+
+--- crypto/aes/asm/aes-sha1-armv8.pl.orig
++++ crypto/aes/asm/aes-sha1-armv8.pl
+@@ -217,12 +217,14 @@
+ .global asm_aescbc_sha1_hmac
+ .type asm_aescbc_sha1_hmac,%function
+
++.rodata
+ .align 4
+ .Lrcon:
+ .word 0x5a827999, 0x5a827999, 0x5a827999, 0x5a827999
+ .word 0x6ed9eba1, 0x6ed9eba1, 0x6ed9eba1, 0x6ed9eba1
+ .word 0x8f1bbcdc, 0x8f1bbcdc, 0x8f1bbcdc, 0x8f1bbcdc
+ .word 0xca62c1d6, 0xca62c1d6, 0xca62c1d6, 0xca62c1d6
++.text
+
+ asm_aescbc_sha1_hmac:
+ AARCH64_VALID_CALL_TARGET
+@@ -276,7 +278,8 @@
+ ldp q10,q11,[x9],32 /* rk[2],rk[3] */
+ prfm PLDL1KEEP,[x0,64] /* pref next aes_ptr_in */
+ /* base address for sha round consts */
+- adr x8,.Lrcon
++ adrp x8,.Lrcon
++ add x8,x8,:lo12:.Lrcon
+ aese v0.16b,v9.16b
+ aesmc v0.16b,v0.16b
+ prfm PLDL1KEEP,[x1,64] /* pref next aes_ptr_out */
+@@ -1524,7 +1527,8 @@
+ */
+ .Lenc_short_cases:
+ ldp q8,q9,[x9],32
+- adr x8,.Lrcon /* rcon */
++ adrp x8,.Lrcon /* rcon */
++ add x8,x8,:lo12:.Lrcon
+ mov w15,0x80 /* sha padding word */
+ ldp q10,q11,[x9],32
+ lsl x11,x10,4 /* len = aes_blocks*16 */
+@@ -2427,7 +2431,8 @@
+ blt .Ldec_short_cases /* branch if < 12 */
+
+ /* base address for sha round consts */
+- adr x8,.Lrcon
++ adrp x8,.Lrcon
++ add x8,x8,:lo12:.Lrcon
+ ldp q4,q5,[x8],32 /* key0,key1 */
+ ldp q6,q7,[x8],32 /* key2,key3 */
+
+@@ -3867,7 +3872,8 @@
+ */
+ .Ldec_short_cases:
+ ldp q8,q9,[x9],32
+- adr x8,.Lrcon /* rcon */
++ adrp x8,.Lrcon /* rcon */
++ add x8,x8,:lo12:.Lrcon
+ ldp q10,q11,[x9],32
+ lsl x11,x10,4 /* len = aes_blocks*16 */
+
--- /dev/null
+++ security/openssl/patches/patch-crypto_aes_asm_aes-sha256-armv8.pl
@@ -0,0 +1,241 @@
+$NetBSD$
+
+Move the aarch64 stitched AES+SHA round constants out of .text.
+
+The constants sit in .text and are reached with adr, so reading them is a
+load from an executable page. OpenBSD maps .text execute-only on arm64, so
+the load faults and anything using the stitched ciphers dies with SIGSEGV
+(seen in test/recipes/30-test_evp.t on 7.9/arm64).
+
+This is upstream commit f7feb2d937ac of 2025-10-01, "[aarch64] move
+constants to rodata", which is in master but not on the 3.6 branch. It puts
+the constants in .rodata and reaches them with adrp + add :lo12: instead.
+
+--- crypto/aes/asm/aes-sha256-armv8.pl.orig
++++ crypto/aes/asm/aes-sha256-armv8.pl
+@@ -216,6 +216,7 @@
+ .global asm_aescbc_sha256_hmac
+ .type asm_aescbc_sha256_hmac,%function
+
++.rodata
+ .align 4
+ .Lrcon:
+ .word 0x428a2f98, 0x71374491, 0xb5c0fbcf, 0xe9b5dba5
+@@ -238,6 +239,7 @@
+ .Linit_sha_state:
+ .word 0x6a09e667, 0xbb67ae85, 0x3c6ef372, 0xa54ff53a
+ .word 0x510e527f, 0x9b05688c, 0x1f83d9ab, 0x5be0cd19
++.text
+
+ asm_aescbc_sha256_hmac:
+ AARCH64_VALID_CALL_TARGET
+@@ -253,7 +255,8 @@
+ stp d10,d11,[sp,#16]
+
+ /* address of sha init state consts */
+- adr x12,.Linit_sha_state
++ adrp x12,.Linit_sha_state
++ add x12,x12,:lo12:.Linit_sha_state
+ prfm PLDL1KEEP,[x1,0] /* pref next aes_ptr_out */
+ lsr x10,x2,4 /* aes_blocks = len/16 */
+
+@@ -296,7 +299,8 @@
+ aesmc v0.16b,v0.16b
+ prfm PLDL1KEEP,[x1,64] /* pref next aes_ptr_out */
+ /* base address for sha round consts */
+- adr x8,.Lrcon
++ adrp x8,.Lrcon
++ add x8,x8,:lo12:.Lrcon
+ ld1 {v12.16b},[x9],16 /* rk[4] */
+ aese v0.16b,v10.16b
+ aesmc v0.16b,v0.16b
+@@ -435,7 +439,8 @@
+ */
+ .Lenc_main_loop:
+ /* base address for sha round consts */
+- adr x8,.Lrcon
++ adrp x8,.Lrcon
++ add x8,x8,:lo12:.Lrcon
+ /*
+ * Because both mov, rev32 and eor have a busy cycle,this takes longer
+ * than it looks. That's OK since there are 6 cycles before we can use
+@@ -703,7 +708,8 @@
+ */
+ ld1 {v0.16b},[x0],16
+ /* base address for sha round consts */
+- adr x8,.Lrcon
++ adrp x8,.Lrcon
++ add x8,x8,:lo12:.Lrcon
+ ld1 {v4.16b},[x8],16 /* key0 */
+ ld1 {v5.16b},[x8],16 /* key1 */
+ ld1 {v6.16b},[x8],16 /* key2 */
+@@ -893,7 +899,8 @@
+ /* quad 0 */
+ .Lbm2fromQ0:
+ /* base address for sha round consts */
+- adr x8,.Lrcon
++ adrp x8,.Lrcon
++ add x8,x8,:lo12:.Lrcon
+
+ ld1 {v4.16b},[x8],16 /* key0 */
+ ld1 {v5.16b},[x8],16 /* key1 */
+@@ -1164,7 +1171,8 @@
+ */
+ 1:
+ /* base address for sha round consts */
+- adr x8,.Lrcon
++ adrp x8,.Lrcon
++ add x8,x8,:lo12:.Lrcon
+
+ ld1 {v4.16b},[x8],16 /* key0 */
+ ld1 {v5.16b},[x8],16 /* key1 */
+@@ -1323,7 +1331,8 @@
+ * do last sha of pad block
+ */
+ /* base address for sha round consts */
+- adr x8,.Lrcon
++ adrp x8,.Lrcon
++ add x8,x8,:lo12:.Lrcon
+
+ /* quad 0 */
+ ld1 {v4.16b},[x8],16 /* key0 */
+@@ -1460,7 +1469,8 @@
+ eor v28.16b, v28.16b, v28.16b
+ eor v29.16b, v29.16b, v29.16b
+ /* base address for sha round consts */
+- adr x8,.Lrcon
++ adrp x8,.Lrcon
++ add x8,x8,:lo12:.Lrcon
+ /* load o_key_pad partial hash */
+ ldp q24,q25,[x7]
+
+@@ -1641,7 +1651,8 @@
+ * already in place excepting the final word.
+ */
+ .Lenc_short_loop:
+- adr x8,.Lrcon /* rcon */
++ adrp x8,.Lrcon /* rcon */
++ add x8,x8,:lo12:.Lrcon
+ /* read next aes block, update aes_ptr_in */
+ ld1 {v0.16b},[x0],16
+ eor v0.16b,v0.16b,v3.16b /* xor w/prev value */
+@@ -2019,7 +2030,8 @@
+ */
+ 1:
+ /* base address for sha round consts */
+- adr x8,.Lrcon
++ adrp x8,.Lrcon
++ add x8,x8,:lo12:.Lrcon
+
+ ld1 {v4.16b},[x8],16 /* key0 */
+ ld1 {v5.16b},[x8],16 /* key1 */
+@@ -2180,7 +2192,8 @@
+ /* do final block */
+
+ /* base address for sha round consts */
+- adr x8,.Lrcon /* top of rcon */
++ adrp x8,.Lrcon /* top of rcon */
++ add x8,x8,:lo12:.Lrcon
+
+ /* quad 0 */
+ ld1 {v4.16b},[x8],16 /* key0 */
+@@ -2317,7 +2330,8 @@
+ eor v28.16b, v28.16b, v28.16b
+ eor v29.16b, v29.16b, v29.16b
+ /* base address for sha round consts */
+- adr x8,.Lrcon
++ adrp x8,.Lrcon
++ add x8,x8,:lo12:.Lrcon
+ /* load o_key_pad partial hash */
+ ldp q24,q25,[x7]
+
+@@ -2563,7 +2577,8 @@
+ lsr x10,x2,4 /* aes_blocks = len/16 */
+ stp d14,d15,[sp,#48]
+ /* address of sha init state consts */
+- adr x12,.Linit_sha_state
++ adrp x12,.Linit_sha_state
++ add x12,x12,:lo12:.Linit_sha_state
+ stp x19,x20,[sp,#64]
+
+ ldr x9, [x6, #CIPHER_KEY]
+@@ -2599,7 +2614,8 @@
+ prfm PLDL1KEEP,[x0,64] /* pref next aes_ptr_in */
+ prfm PLDL1KEEP,[x1,64] /* pref next aes_ptr_out */
+ /* base address for sha round consts */
+- adr x8,.Lrcon
++ adrp x8,.Lrcon
++ add x8,x8,:lo12:.Lrcon
+ /*
+ * do the first sha256 block on the plaintext
+ */
+@@ -2782,7 +2798,8 @@
+ prfm PLDL1KEEP,[x1,64]
+ mov v23.16b,v25.16b /* working EFGH <- EFGH */
+ /* base address for sha round consts */
+- adr x8,.Lrcon
++ adrp x8,.Lrcon
++ add x8,x8,:lo12:.Lrcon
+
+ /*
+ * aes xform 0, sha quad 0
+@@ -3036,7 +3053,8 @@
+ prfm PLDL1KEEP,[x1,64]
+ mov v23.16b,v25.16b /* working EFGH <- EFGH */
+ /* base address for sha round consts */
+- adr x8,.Lrcon
++ adrp x8,.Lrcon
++ add x8,x8,:lo12:.Lrcon
+ ld1 {v4.16b},[x8],16 /* key0 */
+ ld1 {v5.16b},[x8],16 /* key1 */
+
+@@ -3399,7 +3417,8 @@
+ */
+ .Ljoin_common:
+ /* base address for sha round consts */
+- adr x8,.Lrcon
++ adrp x8,.Lrcon
++ add x8,x8,:lo12:.Lrcon
+ mov w15,0x80 /* that's the 1 of the pad */
+ .Lpost_loop_Q0:
+ /* assume this was final block */
+@@ -3664,7 +3683,8 @@
+ /* read first aes block, bump aes_ptr_in */
+ ld1 {v0.16b},[x0]
+ ld1 {v31.16b},[x0],16
+- adr x8,.Lrcon
++ adrp x8,.Lrcon
++ add x8,x8,:lo12:.Lrcon
+ ld1 {v4.16b},[x8],16 /* key0 */
+ aesd v0.16b,v8.16b
+ aesimc v0.16b,v0.16b
+@@ -3845,7 +3865,8 @@
+
+ .Lzero_aes_blocks_left:
+ /* base address for sha round consts */
+- adr x8,.Lrcon
++ adrp x8,.Lrcon
++ add x8,x8,:lo12:.Lrcon
+ ld1 {v4.16b},[x8],16 /* key0 */
+ ld1 {v5.16b},[x8],16 /* key1 */
+
+@@ -3991,7 +4012,8 @@
+ * Calculate final HMAC
+ */
+ /* base address for sha round consts */
+- adr x8,.Lrcon
++ adrp x8,.Lrcon
++ add x8,x8,:lo12:.Lrcon
+ /* load o_key_pad partial hash */
+ ld1 {v24.16b},[x7],16
+ ld1 {v25.16b},[x7]
+@@ -4164,7 +4186,8 @@
+ */
+ .Ldec_short_cases:
+ ldp q8,q9,[x9],32
+- adr x8,.Lrcon /* rcon */
++ adrp x8,.Lrcon /* rcon */
++ add x8,x8,:lo12:.Lrcon
+ ldp q10,q11,[x9],32
+ lsl x11,x10,4 /* len=aes_blocks*16 */
+
--- /dev/null
+++ security/openssl/patches/patch-crypto_aes_asm_aes-sha512-armv8.pl
@@ -0,0 +1,51 @@
+$NetBSD$
+
+Move the aarch64 stitched AES+SHA round constants out of .text.
+
+The constants sit in .text and are reached with adr, so reading them is a
+load from an executable page. OpenBSD maps .text execute-only on arm64, so
+the load faults and anything using the stitched ciphers dies with SIGSEGV
+(seen in test/recipes/30-test_evp.t on 7.9/arm64).
+
+This is upstream commit f7feb2d937ac of 2025-10-01, "[aarch64] move
+constants to rodata", which is in master but not on the 3.6 branch. It puts
+the constants in .rodata and reaches them with adrp + add :lo12: instead.
+
+--- crypto/aes/asm/aes-sha512-armv8.pl.orig
++++ crypto/aes/asm/aes-sha512-armv8.pl
+@@ -310,6 +310,7 @@
+ .global asm_aescbc_sha512_hmac
+ .type asm_aescbc_sha512_hmac,%function
+
++.rodata
+ .align 6
+ .LK512:
+ .quad 0x428a2f98d728ae22,0x7137449123ef65cd
+@@ -354,6 +355,7 @@
+ .quad 0x5fcb6fab3ad6faec,0x6c44198c4a475817
+ .quad 0 // terminator
+
++.text
+ .align 4
+ asm_aescbc_sha512_hmac:
+ AARCH64_VALID_CALL_TARGET
+@@ -372,7 +374,8 @@
+ ldr x9, [x6, #CIPHER_KEY_ROUNDS]
+ mov x12, x7 /* backup x7 */
+
+- adr x10, .LK512
++ adrp x10, .LK512
++ add x10, x10, :lo12:.LK512
+
+ lsr x11, x2, #4 /* aes_block = len/16 */
+ cbz x11, .Lret /* return if aes_block = 0 */
+@@ -2087,7 +2090,8 @@
+ ldr x9, [x6, #CIPHER_KEY_ROUNDS]
+ mov x12, x7 /* backup x7 */
+
+- adr x10, .LK512
++ adrp x10, .LK512
++ add x10, x10, :lo12:.LK512
+
+ lsr x11, x2, #4 /* aes_block = len/16 */
+ cbz x11, .Ldec_ret /* return if aes_block = 0 */
Home |
Main Index |
Thread Index |
Old Index