Commit 5566e1ea10 for openssl.org
commit 5566e1ea100ca84c1b41757f41da3e8b88163e94
Author: Richard Levitte <levitte@openssl.foundation>
Date: Tue Sep 22 14:33:45 2026 +0200
cipher_aes_hw_aesni.c: fix linux-x32 build failure
The VAES GCM code is enabled by an ISA check (__x86_64__ & co),
which the x32 ABI satisfies: x32 is a 64-bit platform with a 32-bit
size_t. There, comparing the size_t ivlen against 2^61 is always
false, which -Wtype-limits (via --strict-warnings) turns
into a build failure.
Only perform the check where size_t is wide enough to violate
the limit.
Fixes: 63b996e752ac "AES-GCM enabled with AVX512 vAES and vPCLMULQDQ."
Assisted-by: Pi:moonshotai/kimi-k3
Reviewed-by: Matt Caswell <matt@openssl.foundation>
Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org>
Merge-date: Fri Oct 9 22:26:45 2026
Merged-from: https://github.com/openssl/openssl/pull/32925
diff --git a/providers/implementations/ciphers/cipher_aes_hw_aesni.c b/providers/implementations/ciphers/cipher_aes_hw_aesni.c
index dce9c1bc57..003d0d9ed3 100644
--- a/providers/implementations/ciphers/cipher_aes_hw_aesni.c
+++ b/providers/implementations/ciphers/cipher_aes_hw_aesni.c
@@ -311,8 +311,10 @@ static int vaes_gcm_setiv(PROV_GCM_CTX *ctx, const unsigned char *iv,
gcmctx->mres = 0;
/* IV is limited by 2^64 bits, thus 2^61 bytes */
+#if SIZE_MAX > 0xFFFFFFFFu
if (ivlen > (U64(1) << 61))
return 0;
+#endif
ossl_aes_gcm_setiv_avx512(gcmctx->key, gcmctx, iv, ivlen);