summaryrefslogtreecommitdiff
path: root/src/lib/libcrypto/bn
diff options
context:
space:
mode:
authortb <>2023-04-16 08:55:44 +0000
committertb <>2023-04-16 08:55:44 +0000
commit1f25ebb0ceb7351c559b0f9d57fd89a48d2ece1b (patch)
treec3f5d9c9754bc9c7b25d9b9fb6c87a1d9fea872a /src/lib/libcrypto/bn
parentcb351a75b0dca69e477f6bcb8ec72f16aabba808 (diff)
downloadopenbsd-1f25ebb0ceb7351c559b0f9d57fd89a48d2ece1b.tar.gz
openbsd-1f25ebb0ceb7351c559b0f9d57fd89a48d2ece1b.tar.bz2
openbsd-1f25ebb0ceb7351c559b0f9d57fd89a48d2ece1b.zip
Mark public bn_nist and ec_nist API for removal
The faster nist code is rife with problematic C. While this is generally considered to be a pleonasm nowadays, here it specifically refers to aliasing issues and other flavors of undefined behavior. With compilers and standardization committees becoming seemingly more determined about making C even more unusable than it already is, this code has resulted in miscompilations and generally is a target rich environment for fuzzers to feast on. We're better off without it. Go look while it's still there. It's some of the very worst we have to offer. ok jsing
Diffstat (limited to 'src/lib/libcrypto/bn')
-rw-r--r--src/lib/libcrypto/bn/bn.h4
1 files changed, 3 insertions, 1 deletions
diff --git a/src/lib/libcrypto/bn/bn.h b/src/lib/libcrypto/bn/bn.h
index ba6c25ba0a..d6f77288c1 100644
--- a/src/lib/libcrypto/bn/bn.h
+++ b/src/lib/libcrypto/bn/bn.h
@@ -1,4 +1,4 @@
1/* $OpenBSD: bn.h,v 1.57 2022/12/17 15:56:25 jsing Exp $ */ 1/* $OpenBSD: bn.h,v 1.58 2023/04/16 08:55:44 tb Exp $ */
2/* Copyright (C) 1995-1997 Eric Young (eay@cryptsoft.com) 2/* Copyright (C) 1995-1997 Eric Young (eay@cryptsoft.com)
3 * All rights reserved. 3 * All rights reserved.
4 * 4 *
@@ -612,6 +612,7 @@ int BN_GF2m_arr2poly(const int p[], BIGNUM *a);
612 612
613#endif 613#endif
614 614
615#if !defined(LIBRESSL_NEXT_API) || defined(LIBRESSL_INTERNAL)
615/* faster mod functions for the 'NIST primes' 616/* faster mod functions for the 'NIST primes'
616 * 0 <= a < p^2 */ 617 * 0 <= a < p^2 */
617int BN_nist_mod_192(BIGNUM *r, const BIGNUM *a, const BIGNUM *p, BN_CTX *ctx); 618int BN_nist_mod_192(BIGNUM *r, const BIGNUM *a, const BIGNUM *p, BN_CTX *ctx);
@@ -625,6 +626,7 @@ const BIGNUM *BN_get0_nist_prime_224(void);
625const BIGNUM *BN_get0_nist_prime_256(void); 626const BIGNUM *BN_get0_nist_prime_256(void);
626const BIGNUM *BN_get0_nist_prime_384(void); 627const BIGNUM *BN_get0_nist_prime_384(void);
627const BIGNUM *BN_get0_nist_prime_521(void); 628const BIGNUM *BN_get0_nist_prime_521(void);
629#endif
628 630
629/* Primes from RFC 2409 */ 631/* Primes from RFC 2409 */
630BIGNUM *get_rfc2409_prime_768(BIGNUM *bn); 632BIGNUM *get_rfc2409_prime_768(BIGNUM *bn);