Fix FIPS static release build on x86_64 for gcc-8,11,12 on ubuntu #755
+2,495
−2,061
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Issues:
Resolves
CryptoAlg-1489
Description of changes:
This PR fixes the gcc release build for static FIPS on Ubuntu 20.04/22.04. gcc-8, 11, and 12 were failing due to some unrecognized instructions.
Call-outs:
notrack jmp *%rax
was failing, because there were no commas between theInstructionArg
..long 1f - 0f
was failing becausedelocate.go
was incorrectly recognizing1f
as an offset, when it should be aLocalLabelRef
. OurOffset
rule was too lax and recognized all number references as "offsets", regardless of what was appended at the end. I've added![[A-Z]
to the end of theOffset
rule to reject any additional charactors.gcc-8
The gcc-8 assembler will attempt to optimize function pointers used in multiple places under a.data.rel.ro.local
section, butdelocate.go
does not have the ability to handle.data
sections. It’s unclear why this is specific to only gcc-8, but we speculate that this was unwanted behavior and was removed in subsequent versions of the gcc compiler. We get around this by definingpkey_pss_init
as two separate functions for signing and verifying.Testing:
New CI for all these dimensions
By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license and
the ISC license.