Marek Knápek
c727c4032a
Get rid of LTC_FAST_TYPE_PTR_CAST entirely.
...
As it might be dangerous to use it.
This introduces `LTC_FAST_TYPE_{ASSIGN,MASK,XOR{2,3}}()` in order to
replace the potential unaligned loads.
This fixes the following UBSAN errors:
src/modes/ctr/ctr_encrypt.c:56:66: runtime error: load of misaligned address 0x7ffea07ee82f for type 'LTC_FAST_TYPE', which requires 8 byte alignment
src/modes/ctr/ctr_encrypt.c:56:64: runtime error: store to misaligned address 0x7ffea07ee82f for type 'LTC_FAST_TYPE', which requires 8 byte alignment
tests/store_test.c:66:91: runtime error: load of misaligned address 0x7ffdd32f0d9f for type 'LTC_FAST_TYPE', which requires 8 byte alignment
tests/store_test.c:66:52: runtime error: load of misaligned address 0x7ffdd32f0d71 for type 'LTC_FAST_TYPE', which requires 8 byte alignment
tests/store_test.c:66:50: runtime error: store to misaligned address 0x7ffdd32f0dc1 for type 'LTC_FAST_TYPE', which requires 8 byte alignment
src/mac/pmac/pmac_process.c:40:50: runtime error: load of misaligned address 0x57c89c4329ec for type 'LTC_FAST_TYPE', which requires 8 byte alignment
src/mac/xcbc/xcbc_process.c:35:60: runtime error: load of misaligned address 0x57c89c432ccc for type 'LTC_FAST_TYPE', which requires 8 byte alignment
src/mac/f9/f9_process.c:39:58: runtime error: load of misaligned address 0x5c2b1a1d2c14 for type 'LTC_FAST_TYPE', which requires 8 byte alignment
src/encauth/gcm/gcm_process.c:82:58: runtime error: load of misaligned address 0x596b3e6aa354 for type 'LTC_FAST_TYPE', which requires 8 byte alignment
2026-07-31 10:45:09 +02:00
Marek Knápek
471f143078
Fix UBSAN errors
...
src/encauth/siv/siv.c:164:19: runtime error: null pointer passed as argument 2, which is declared to never be null
/usr/include/string.h:44:28: note: nonnull attribute specified here
src/misc/compare_testvector.c:63:25: runtime error: null pointer passed as argument 2, which is declared to never be null
/usr/include/string.h:65:33: note: nonnull attribute specified here
2026-07-31 10:44:16 +02:00
karel-m
c5607aff6b
Merge pull request #784 from libtom/pr/msvc-fallthrough
...
Fix LTC_FALLTHROUGH related error reported by MSVC compiler
2026-07-30 16:48:17 +02:00
Karel Miko
23fca6ed39
Fix LTC_FALLTHROUGH related error reported by MSVC compiler
2026-07-30 16:01:06 +02:00
Steffen Jaeckel
79f2b5762d
Merge pull request #777 from libtom/pr/siv-zero-ad
...
SIV properly handle zero AD components
2026-07-30 15:42:03 +02:00
Karel Miko
511252c49e
update SIV doc - fix adnum; explain no associated data vs. empty associated data
2026-07-30 15:39:27 +02:00
Karel Miko
cff7442824
SIV properly handle zero AD components
2026-07-30 15:39:27 +02:00
Steffen Jaeckel
f5fe918ab8
Merge pull request #755 from libtom/fix-warnings
...
Fix warnings
2026-07-30 15:37:58 +02:00
Karel Miko
074a354151
fix build failures with -std=c99
2026-07-30 15:22:33 +02:00
Karel Miko
0b6f0e1232
fix clang warnings -Wimplicit-fallthrough (while keeping /* FALLTHROUGH */ for some code review tools)
2026-07-30 15:22:33 +02:00
Karel Miko
26605163a4
fix clang warnings -Wmissing-variable-declarations
2026-07-30 15:22:33 +02:00
Karel Miko
317994fb1b
fix clang warnings -Wstrict-prototypes -Wmissing-prototypes in tests+demos
2026-07-30 15:22:33 +02:00
Karel Miko
661fcd6486
fix UBSanitizer issue: applying non-zero offset to null pointer
2026-07-30 15:22:33 +02:00
Karel Miko
5c8ac18bd1
fix UBSanitizer issue: memcpy/memcmp require non-null pointers even when the length is zero
2026-07-30 15:22:33 +02:00
Karel Miko
76a9ece653
fix UBSanitizer issue: left-shifting negative integer is undefined behavior
2026-07-30 15:22:33 +02:00
Karel Miko
509da35eee
fix clang warning: 'err' may be used uninitialized
2026-07-30 15:22:33 +02:00
karel-m
612f211bbc
Merge pull request #783 from libtom/pr/der-misc-issues
...
various DER related fixes/improvements
2026-07-29 23:50:05 +02:00
Karel Miko
209df8ae1a
hardening pkcs8_get_children against uninitialized output pointers
2026-07-28 16:33:09 +02:00
Karel Miko
5c7757d0a5
various DER related fixes/improvements
2026-07-28 00:10:29 +02:00
Steffen Jaeckel
a8ed78c2ca
Merge pull request #780 from libtom/pr/argon2-parallelism-overflow
...
Argon2 enforce parallelism max 2^24-1
2026-07-21 11:07:46 +02:00
Karel Miko
fcadf67bbb
Argon2 enforce parallelism max 2^24-1
2026-07-21 11:02:31 +02:00
Steffen Jaeckel
b7b04ffd37
Merge pull request #778 from libtom/pr/eax-taglen
...
EAX properly handle taglen boundaries
2026-07-21 10:59:19 +02:00
Karel Miko
39f5e1fae8
EAX properly handle taglen boundaries
2026-07-21 10:56:44 +02:00
Steffen Jaeckel
84aec00adc
Merge pull request #776 from libtom/pr/ccm-nonce
...
Fix issue #775 - CCM nonce is 7..13 bytes
2026-07-21 10:56:27 +02:00
Karel Miko
e00b22d939
CCM nonce is 7..13 bytes
2026-07-21 10:53:25 +02:00
Steffen Jaeckel
1027dcfaf6
Merge pull request #765 from libtom/pr/fix-issue764
...
Fix issue #764 - small-subgroup attack
2026-07-21 10:53:14 +02:00
Karel Miko
bc95a1fd2d
hardening ecc_shared_secret against small-subgroup attacks
2026-05-25 16:18:14 +02:00
Karel Miko
ec7c05f94e
fix issue #764 as suggested by @yaotushaozhu
2026-05-25 14:11:27 +02:00
Karel Miko
afb09869f7
failing test for issue #764 - small-subgroup attack regression test
2026-05-25 13:56:48 +02:00
Steffen Jaeckel
a68fa19bc2
Merge pull request #732 from libtom/pr/sm3-hash
...
SM3 hash function
2026-05-19 13:31:48 +02:00
Steffen Jaeckel
c17e5ed051
Update makefiles
2026-05-19 13:29:49 +02:00
Karel Miko
6c885c7732
SM3 hash function
2026-05-19 13:29:36 +02:00
Steffen Jaeckel
291d847c10
Merge pull request #752 from libtom/pr/AES-GCM-SIV
...
RFC 8452 - AES-GCM-SIV
2026-05-19 13:14:53 +02:00
Karel Miko
96d2d09d7a
Update makefiles
2026-05-19 13:12:32 +02:00
Karel Miko
37a2e345a4
AES-GCM-SIV
2026-05-19 13:12:32 +02:00
Steffen Jaeckel
8512e3e891
Merge pull request #759 from libtom/pr/KMAC128-256
...
KMAC as defined in NIST SP 800-185
2026-05-19 13:05:06 +02:00
Karel Miko
7bcdb63950
Update makefiles
2026-05-19 13:03:25 +02:00
Karel Miko
9b268d6258
KMAC - NIST SP 800-185
2026-05-19 13:03:25 +02:00
Steffen Jaeckel
6e4dcfcc11
Merge pull request #760 from libtom/pr/ARIA
...
ARIA block cipher (RFC 5794)
2026-05-19 10:22:37 +02:00
Steffen Jaeckel
05ad38ab66
With ARIA added, we can now decrypt ARIA encrypted PEM files.
...
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-05-17 13:49:10 +02:00
Karel Miko
2f6b257def
Update makefiles
2026-05-16 11:38:42 +02:00
Karel Miko
4d513a02fc
ARIA block cipher (RFC 5794)
2026-05-16 11:38:38 +02:00
Steffen Jaeckel
8b5af49b94
Merge pull request #754 from libtom/pr/shake128-256
...
RFC 8702: RSA-PSS-SHAKE128/256 and ECDSA-SHAKE128/256
2026-05-06 09:48:25 +02:00
Karel Miko
1e4d471a9f
RFC 8702: RSA-PSS-SHAKE128/256 and ECDSA-SHAKE128/256
2026-05-06 09:23:52 +02:00
Steffen Jaeckel
efd7f24f1a
Merge pull request #753 from libtom/pr/wycheproof-pk-stricter-checks
...
Stricter checks (RSA OAEP, X25519, X448) - based on wycheproof results
2026-05-05 07:42:48 +02:00
Karel Miko
2c375b3a3c
RSA OAEP - reject ciphertext values 0 and 1
2026-05-05 07:42:20 +02:00
Karel Miko
71f45fedbc
x25519/x448 - reject all-zero shared secrets
2026-05-05 07:40:06 +02:00
Steffen Jaeckel
efad039f19
Merge pull request #751 from libtom/more-fixes-and-improvements
...
More fixes and improvements
2026-05-04 15:32:59 +02:00
Steffen Jaeckel
a724483a0b
Add gcm_hw_pmul_is_supported()
...
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-05-04 10:47:11 +02:00
Steffen Jaeckel
c05b3088b4
Use __has_attribute() for target attribute.
...
... and bring aarch64/PMULL in similar shape as x86/PCLMUL.
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-05-04 10:47:05 +02:00