Commit Graph
5 Commits
Author SHA1 Message Date
Ville Takio 425cea6c9c Crypto: fix portable C code on big-endian CPUs (#1899)
* Crypto: fix portable C code on big-endian CPUs

On big-endian CPUs (e.g. MIPS and PowerPC) the portable C code of
several algorithms assumes a little-endian host, so ciphertext, hashes
and derived keys are wrong and "veracrypt --text --test" fails:

- Twofish: the key-dependent S-box bytes are read back from 32-bit
  words through a union, and blocks are loaded/stored as native words.
- Camellia: blocks and keys are always byte-swapped to big-endian.
- Kuznyechik: keys and blocks are loaded/stored as native 64-bit words
  while the tables expect the little-endian interpretation.
- SHA-256/SHA-512: message words, length and digest are always
  byte-swapped.
- BLAKE2s: the parameter block and message words are read as native
  little-endian data. The parameter block is now built from its fields,
  so it is right for any parameters, not only the ones VeraCrypt uses.
- Streebog: the existing big-endian code path is never enabled, and
  BSWAP64 used by it is not defined (its buffer512 initializer also has
  one pair of braces too many). Its add512() also differs from the
  little-endian one, which drops a carry on purpose (existing volumes
  depend on it); do the same limb arithmetic on big-endian.
- misc.h: the rotate-based bswap_32 (non-Linux, non-Apple, non-MSVC
  builds) lacks outer parentheses, so "bswap_32(a) ^ b" is parsed
  wrongly, and the fallback bswap_64 does not parenthesise its argument.
- PBKDF2: the block number is always byte-swapped.

Swap only where the host byte order differs from the data, and enable
the Streebog big-endian path. On big-endian hosts the message words,
keys and blocks of SHA-2, BLAKE2s, Twofish and Kuznyechik are read and
written byte-wise (new VcLoad*/VcStore* inline helpers in misc.h), so
these paths also work on misaligned buffers on strict-alignment CPUs.
On little-endian CPUs the code is unchanged: the object files of all
touched sources are byte-identical before and after this change
(checked on x86_64, aarch64 and mipsel). With it, all self-tests pass on
mips (big-endian) under qemu.

Signed-off-by: Ville Takio <ville+git@takio.fi>

* Volume: avoid unaligned 64-bit header and test vector accesses

The volume header (de)serialisation and TestXtsAES read and write 64-bit
fields through casted pointers into byte buffers at offsets that are
only 4-byte aligned (e.g. the header field at offset 12). CPUs that trap
on misaligned access without kernel fix-up (SPARC, MIPS64 on some
systems, qemu-user) then fail with SIGBUS in "veracrypt --test" and when
creating or opening any volume. Use memcpy instead, and have
DeserializeEntryAt check that the whole entry, not only its start, lies
inside the header.

The XTS code also accesses its local byte arrays (whitening values,
data unit number) through uint64 pointers; declare them 8-byte aligned
instead of relying on the compiler's stack layout.

Signed-off-by: Ville Takio <ville+git@takio.fi>

* Volume: test multi-block PBKDF2 output and the Streebog carry case

The PBKDF2 self-tests only check the first 4 bytes of each derivation,
so the block counter of the second and later output blocks is never
checked. Also compare the complete output of a 192-byte derivation for
every PRF, which covers the later blocks and how they are joined, and
hash a message whose block sum hits the carry case of Streebog's
add512(), which has to stay bit-compatible across CPUs. The message
buffer is 8-byte aligned, as the portable Streebog code reads it as
64-bit words. The expected values are those of the existing
little-endian code, and match independent implementations for all five
PRFs (Python hashlib/hmac, OpenSSL for Whirlpool, gostcrypto for
Streebog).

Signed-off-by: Ville Takio <ville+git@takio.fi>

---------

Signed-off-by: Ville Takio <ville+git@takio.fi>
2026-10-04 09:51:59 +09:00
Ville Takio d24b82102a Linux: fall back to FUSE when dmsetup is not installed (#1898)
Without dmsetup, MountVolumeNative fails with "dmsetup not found in
system directories" instead of using the FUSE path, so on systems that
do not ship device-mapper tools (for example OpenWrt) every mount and
the filesystem formatting step of --create need an explicit
--mount-options=nokernelcrypto. Treat a missing dmsetup like the other
cases where kernel crypto cannot be used.

Signed-off-by: Ville Takio <ville+git@takio.fi>
2026-10-03 11:00:48 +09:00
Ville Takio 5c7f60dfcf Crypto: use VC_INLINE for the ARM CPU_Query helpers (#1886)
C99 inline without static does not emit a function body, so aarch64
builds at -O0/-Os fail to link DetectArmFeatures (undefined reference
to CPU_QueryAES / CPU_QuerySHA2). Use VC_INLINE like the other helpers
in cpu.c.

Signed-off-by: Ville Takio <ville+git@takio.fi>
2026-09-30 20:52:30 +09:00
Ville Takio a15c996f4f Crypto: fix NOASM link failures on x86 (#1896)
With NOASM=1 on x86/x64 the assembler module Aes_hw_cpu is not built,
but cpu.h still defines TC_AES_HW_CPU, so Cipher.cpp references
aes_hw_cpu_encrypt/decrypt. cpu.c also still declares and calls
TrySHA256, which Sha2Intel.c omits when CRYPTOPP_DISABLE_ASM is set
(NOASM passes CRYPTOPP_DISABLE_X86ASM, which implies it), and this
happens whenever __SHA__ is defined (-msha, -march=native) or
CRYPTOPP_SHANI_AVAILABLE is set.

- cpu.h: define TC_AES_HW_CPU on x86 only without CRYPTOPP_DISABLE_ASM
- cpu.c: declare and call TrySHA256 only under the same condition
  Sha2Intel.c uses to build it (not _UEFI, not CRYPTOPP_DISABLE_ASM)

Both follow the compiler target, so cross builds need no ARCH override.

Signed-off-by: Ville Takio <ville+git@takio.fi>
2026-09-30 15:49:18 +09:00
Ville Takio 81cd94f18f Linux: rewrite mount.veracrypt in POSIX sh (#1895)
Use POSIX sh and collect VeraCrypt arguments as quoted positional
parameters. Preserve whitespace in option values and keep wildcard
characters literal.

Handle calls without an option list and skip flags supplied between
the mountpoint and -o.

Collect system, nokernelcrypto, headerbak, and timestamp into one
--mount-options argument. Previously, only system had a mapping to
that argument; the remaining options went to the filesystem options.

Reject the obsolete truecrypt option before invoking VeraCrypt.

Validation: 32 cases passed under both Bash and dash using a stub
executable, with comparisons against the original helper.

Signed-off-by: Ville Takio <ville+git@takio.fi>
2026-09-30 15:06:28 +09:00