Skip to content

[OpenSSL] Fix -Wunsafe-buffer-usage violations in crypto/openssl - #75644

Open
csaavedra wants to merge 1 commit into
WebKit:mainfrom
csaavedra:eng/OpenSSL-Fix-Wunsafe-buffer-usage-violations-in-crypto-openssl
Open

csaavedra wants to merge 1 commit into
WebKit:mainfrom
csaavedra:eng/OpenSSL-Fix-Wunsafe-buffer-usage-violations-in-crypto-openssl

Conversation

@csaavedra

@csaavedra csaavedra commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

a1cffc0

[OpenSSL] Fix -Wunsafe-buffer-usage violations in crypto/openssl
https://bugs.webkit.org/show_bug.cgi?id=326062

Reviewed by NOBODY (OOPS!).

None of the ports that build the OpenSSL WebCrypto backend enable
-Wunsafe-buffer-usage, so three violations have gone unnoticed. They become
errors as soon as the backend is built on a port that does and treats
warnings as fatal, which is the case for GTK and WPE (bug 286932).

No new tests, no change in behaviour.

* Source/WebCore/crypto/openssl/CryptoAlgorithmRSA_OAEPOpenSSL.cpp:
(WebCore::CryptoAlgorithmRSA_OAEP::platformEncrypt):
(WebCore::CryptoAlgorithmRSA_OAEP::platformDecrypt): Use unsafeMakeSpan()
for the buffer returned by OPENSSL_malloc().
* Source/WebCore/crypto/openssl/CryptoKeyRSAOpenSSL.cpp:
(WebCore::exponentVectorToUInt32): Iterate over a span of the vector instead
of doing arithmetic on its end iterator.
* Source/WebCore/crypto/openssl/OpenSSLUtilities.cpp:
(WebCore::AESKey::~AESKey): Use secureZeroBytes(). Unlike memset(), it is
not a dead store the compiler may drop, so the key material is actually
cleared.

a1cffc0

Misc iOS, visionOS, tvOS & watchOS macOS Linux Windows
✅ 🧪 style ✅ 🛠 ios ✅ 🛠 mac ✅ 🛠 wpe ✅ 🛠 win
✅ 🧪 bindings ✅ 🛠 ios-sim ✅ 🛠 mac-AS-debug ✅ 🧪 wpe-wk2 ⏳ 🧪 win-tests
✅ 🧪 webkitperl ✅ 🧪 ios-wk2 ✅ 🧪 api-mac   🧪 api-wpe
✅ 🧪 ios-wk2-wpt loading 🧪 api-mac-debug
✅ 🧪 api-ios ✅ 🧪 mac-wk2 ✅ 🛠 gtk3-gcc
✅ 🛠 ios-safer-cpp ✅ 🧪 mac-AS-debug-wk2 ✅ 🛠 gtk
✅ 🛠 vision ✅ 🧪 gtk-wk2
✅ 🛠 vision-sim ✅ 🧪 mac-intel-wk2 ✅ 🧪 api-gtk
✅ 🧪 vision-wk2 ✅ 🛠 mac-safer-cpp ✅ 🛠 playstation
✅ 🛠 tv ✅ 🧪 mac-site-isolation
✅ 🛠 tv-sim
✅ 🛠 watch
✅ 🛠 watch-sim

https://bugs.webkit.org/show_bug.cgi?id=326062

Reviewed by NOBODY (OOPS!).

None of the ports that build the OpenSSL WebCrypto backend enable
-Wunsafe-buffer-usage, so three violations have gone unnoticed. They become
errors as soon as the backend is built on a port that does and treats
warnings as fatal, which is the case for GTK and WPE (bug 286932).

No new tests, no change in behaviour.

* Source/WebCore/crypto/openssl/CryptoAlgorithmRSA_OAEPOpenSSL.cpp:
(WebCore::CryptoAlgorithmRSA_OAEP::platformEncrypt):
(WebCore::CryptoAlgorithmRSA_OAEP::platformDecrypt): Use unsafeMakeSpan()
for the buffer returned by OPENSSL_malloc().
* Source/WebCore/crypto/openssl/CryptoKeyRSAOpenSSL.cpp:
(WebCore::exponentVectorToUInt32): Iterate over a span of the vector instead
of doing arithmetic on its end iterator.
* Source/WebCore/crypto/openssl/OpenSSLUtilities.cpp:
(WebCore::AESKey::~AESKey): Use secureZeroBytes(). Unlike memset(), it is
not a dead store the compiler may drop, so the key material is actually
cleared.
@csaavedra csaavedra self-assigned this Oct 2, 2026
@csaavedra csaavedra added the WebCore Misc. For miscellaneous bugs in the WebCore framework (and not JavaScriptCore or WebKit). label Oct 2, 2026
@csaavedra
csaavedra requested review from a team and cdumez October 2, 2026 11:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

WebCore Misc. For miscellaneous bugs in the WebCore framework (and not JavaScriptCore or WebKit).

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants