From Fedora Project Wiki
(Add trackers)
 
(9 intermediate revisions by 2 users not shown)
Line 5: Line 5:
<!-- A sentence or two summarizing what this change is and what it will do. This information is used for the overall changeset summary page for each release.  
<!-- A sentence or two summarizing what this change is and what it will do. This information is used for the overall changeset summary page for each release.  
Note that motivation for the change should be in the Benefit to Fedora section below, and this part should answer the question "What?" rather than "Why?". -->
Note that motivation for the change should be in the Benefit to Fedora section below, and this part should answer the question "What?" rather than "Why?". -->
Because of changes to the PKCS #11 spec in PKCS #11 v3.0, NSS needs to change the definition of CK_GCM_PARAMS in a source incompatible way. Upstream made this change in NSS 3.52.
Because of changes to the PKCS #11 spec in PKCS #11 v3.0, NSS needs to change the definition of the CK_GCM_PARAMS structure in a source incompatible way. Upstream made this change in NSS 3.52. This change does not affect the ABI. Old programs compiled with older versions of NSS will still work. Only packages that use NSS and directly call AES GCM are affected.


== Owner ==
== Owner ==
Line 13: Line 13:
-->
-->
* Name: [[User:rrelyea| Bob Relyea]]
* Name: [[User:rrelyea| Bob Relyea]]
* Owners of other packages are unknown.
<!-- Include you email address that you can be reached should people want to contact you about helping with your change, status is requested, or technical issues need to be resolved. If the change proposal is owned by a SIG, please also add a primary contact person. -->
<!-- Include you email address that you can be reached should people want to contact you about helping with your change, status is requested, or technical issues need to be resolved. If the change proposal is owned by a SIG, please also add a primary contact person. -->
* Email: rrelyea@redhat.com
* Email: rrelyea@redhat.com
Line 25: Line 24:


== Current status ==
== Current status ==
[[Category:ChangePageIncomplete]]
[[Category:ChangeAcceptedF34]]
<!-- When your change proposal page is completed and ready for review and announcement -->
<!-- When your change proposal page is completed and ready for review and announcement -->
<!-- remove Category:ChangePageIncomplete and change it to Category:ChangeReadyForWrangler -->
<!-- remove Category:ChangePageIncomplete and change it to Category:ChangeReadyForWrangler -->
Line 44: Line 43:
CLOSED as NEXTRELEASE -> change is completed and verified and will be delivered in next release under development
CLOSED as NEXTRELEASE -> change is completed and verified and will be delivered in next release under development
-->
-->
* FESCo issue: <will be assigned by the Wrangler>
* FESCo issue: [https://pagure.io/fesco/issue/2400 #2400]
* Tracker bug: <will be assigned by the Wrangler>
* Tracker bug: [https://bugzilla.redhat.com/show_bug.cgi?id=1866878 #1866878]
* Release notes tracker: <will be assigned by the Wrangler>
* Release notes tracker: [https://pagure.io/fedora-docs/release-notes/issue/544 #544]


== Detailed Description ==
== Detailed Description ==


<!-- Expand on the summary, if appropriate.  A couple sentences suffices to explain the goal, but the more details you can provide the better. -->
<!-- Expand on the summary, if appropriate.  A couple sentences suffices to explain the goal, but the more details you can provide the better. -->
PKCS #11 2.40 had a mismatch between the SPEC and the released header file for CK_GCM_PARAMS. The latter is controlling. We created or header based on the former. In PKCS #11 v3.0 the reconciled this, but it left us with. The new (to NSS) definition has a new field ulIvBits, which must be set correctly.
PKCS #11 2.40 had a mismatch between the spec and the released header file for the CK_GCM_PARAMS structure. The latter is controlling. We created our header based on the former. In PKCS #11 v3.0 the reconciled this, but it left us with and incompatible header. The new (to NSS) definition has a new field ulIvBits, which must be set correctly (see below).


To solve this, the NSS 3.52 headers has both definitions: CK_NSS_GCM_PARAMS is the original NSS definition and CK_GCM_PARAMS_V3 is the new (to NSS) definition. CK_GCM_PARAMS takes on one or the other based on the definition of NSS_PKCS11_2_0_COMPAT.
To solve this, the NSS 3.52 headers has definitions for both structures: CK_NSS_GCM_PARAMS is the original NSS definition and CK_GCM_PARAMS_V3 is the new (to NSS) definition matching the current spec. CK_GCM_PARAMS will take on the definition of CK_GCM_PARAM_V3 by default, and CK_NSS_GCM_PARAMS if the code is compiled with NSS_PKCS11_2_0_COMPAT defined.


The current NSS builds in fedora have changes the sense of this #define to NSS_PKCS11_3_0_STRICT to get the new behavior, and keep the old behavior by default. NSS builds will automatically switch back to the upstream default in Fedora 34. None of the changes below actually requires setting the NSS_PKCS11_3_STRICT define, though doing so can test that all but option 1 is functioning.
The current NSS builds in fedora have changes the sense of this #define so defining NSS_PKCS11_3_0_STRICT to gets the new behavior, and keep the old behavior by default. NSS builds will automatically switch back to the upstream default in Fedora 34. None of the changes below actually requires setting the NSS_PKCS11_3_STRICT define, though doing so can test that all but option 1 is functioning. These changes can be made in the current fedora as long as you have NSS 3.52.


Applications can fix this the following ways:
Applications can fix this the following ways:
Line 65: Line 64:
or compile with -DNSS_PKCS11_2_0_COMPAT
or compile with -DNSS_PKCS11_2_0_COMPAT


your app will compile and run using current and older versions of NSS, but may break on newer tokens that use the new definition (same as the previous behavior.
your app will compile and run using current and older versions of NSS (no need for nss 3.52), but may break on newer tokens that use the new definition (same as the previous behavior). Do this if your packages needs to compile in enviroments that have old versions of nss.


---------------------------------------------------------------
---------------------------------------------------------------
Line 71: Line 70:
option 2
option 2


rename CK_GCM_PARAMS to CK_NSS_GCM_PARAMS (this will now require nss >= 3.52 to compile, but won't change based on NSS_PKCS11_2_0_COMPAT). Like option 2 it may break on newer tokens.
rename all occurances of CK_GCM_PARAMS to CK_NSS_GCM_PARAMS (this will now require nss >= 3.52 to compile, but won't change based on NSS_PKCS11_2_0_COMPAT or NSS_PKCS11_3_0_STRICT). Like option 1 it may break on newer tokens.


------------------------------------------------------------------
------------------------------------------------------------------
Line 77: Line 76:
option 3
option 3


rename CK_GCM_PARAMS to CK_GCM_PARAMS_V3 and set ulIvBits to ulIvLen*8.
rename all occurances of CK_GCM_PARAMS to CK_GCM_PARAMS_V3 and set ulIvBits to ulIvLen*8.


This will require nss >= 3.52 to compile and to run. Should run on all run tokens.
This will require nss >= 3.52 to compile and to run. Should run on all new tokens. May break on older tokens.


-----------------------------------------------------------------
-----------------------------------------------------------------
Line 85: Line 84:
option 4
option 4


Move to PK11_AEADOp  interface, which all requires nss >= 3.52 to compile and run,  but it's less surprising and the dependency will be picked up automatically because you are using a new for 3.52 interface.  
Move to PK11_AEADOp  interface, which all requires nss >= 3.52 to compile and run,  but it's less surprising and the dependency will be picked up automatically because you are using a new for 3.52 interface, so it will continue to work against all tokens.  
----------------------------------
----------------------------------


Line 131: Line 130:
<!-- What work do other developers have to accomplish to complete the feature in time for release?  Is it a large change affecting many parts of the distribution or is it a very isolated change? What are those changes?-->
<!-- What work do other developers have to accomplish to complete the feature in time for release?  Is it a large change affecting many parts of the distribution or is it a very isolated change? What are those changes?-->


Developers need to choose one of these options by fedora 34 or their rebuilt packages will fail at runtime.
Developers need to choose one of the options listed in the description by fedora 34 or their rebuilt packages will fail at runtime.


option 1
#define NSS_PKCS11_2_0_COMPAT 1
or compile with -DNSS_PKCS11_2_0_COMPAT
your app will compile and run using current and older versions of NSS, but may break on newer tokens that use the new definition (same as the previous behavior.
---------------------------------------------------------------
option 2


rename CK_GCM_PARAMS to CK_NSS_GCM_PARAMS (this will now require nss >= 3.52 to compile, but won't change based on NSS_PKCS11_2_0_COMPAT). Like option 2 it may break on newer tokens.
* Release engineering: [https://pagure.io/releng/issue/9486 #Releng issue number 9486]  
 
------------------------------------------------------------------
 
option 3
 
rename CK_GCM_PARAMS to CK_GCM_PARAMS_V3 and set ulIvBits to ulIvLen*8.
 
This will require nss >= 3.52 to compile and to run. Should run on all run tokens.
 
-----------------------------------------------------------------
 
option 4
 
Move to PK11_AEADOp  interface, which all requires nss >= 3.52 to compile and run,  but it's less surprising and the dependency will be picked up automatically because you are using a new for 3.52 interface.
----------------------------------
 
Option 4 is the preferred solution. It takes advantage the the PKCS #11 v3 interface for  AES_GCM while removing any PCKS #11 param structure dependency in the application. It also handles backward compatibility on older tokens and automatically detects which flavor of data structure is supported. It also would help with applications that support two or more of AES_GCM, AES_CCM, and CHACHA_POLY.
 
* Release engineering: [https://pagure.io/releng/issues/9486 #Releng issue number 9486]  
<!-- Does this feature require coordination with release engineering (e.g. changes to installer image generation or update package delivery)?  Is a mass rebuild required?  include a link to the releng issue.  
<!-- Does this feature require coordination with release engineering (e.g. changes to installer image generation or update package delivery)?  Is a mass rebuild required?  include a link to the releng issue.  
The issue is required to be filed prior to feature submission, to ensure that someone is on board to do any process development work and testing, and that all changes make it into the pipeline; a bullet point in a change is not sufficient communication -->
The issue is required to be filed prior to feature submission, to ensure that someone is on board to do any process development work and testing, and that all changes make it into the pipeline; a bullet point in a change is not sufficient communication -->
Line 219: Line 188:
== Dependencies ==
== Dependencies ==
<!-- What other packages (RPMs) depend on this package?  Are there changes outside the developers' control on which completion of this change depends?  In other words, completion of another change owned by someone else and might cause you to not be able to finish on time or that you would need to coordinate?  Other upstream projects like the kernel (if this is not a kernel change)? -->
<!-- What other packages (RPMs) depend on this package?  Are there changes outside the developers' control on which completion of this change depends?  In other words, completion of another change owned by someone else and might cause you to not be able to finish on time or that you would need to coordinate?  Other upstream projects like the kernel (if this is not a kernel change)? -->
nss-3.52 or greater.
nss-3.52 or greater. nss-3.52 is now available in all supported versions of fedora.


<!-- REQUIRED FOR SYSTEM WIDE CHANGES -->
<!-- REQUIRED FOR SYSTEM WIDE CHANGES -->


== Contingency Plan ==
== Contingency Plan ==
Line 233: Line 201:
<!-- Does finishing this feature block the release, or can we ship with the feature in incomplete state? -->
<!-- Does finishing this feature block the release, or can we ship with the feature in incomplete state? -->
* Blocks release?  Yes, but only for critical packages.
* Blocks release?  Yes, but only for critical packages.
* Blocks product? Fedora.next (rhel9) <!-- Applicable for Changes that blocks specific product release/Fedora.next -->
 


== Documentation ==
== Documentation ==

Latest revision as of 17:15, 6 August 2020

NSS CK_GCM_PARAMS change

Summary

Because of changes to the PKCS #11 spec in PKCS #11 v3.0, NSS needs to change the definition of the CK_GCM_PARAMS structure in a source incompatible way. Upstream made this change in NSS 3.52. This change does not affect the ABI. Old programs compiled with older versions of NSS will still work. Only packages that use NSS and directly call AES GCM are affected.

Owner

Current status

Detailed Description

PKCS #11 2.40 had a mismatch between the spec and the released header file for the CK_GCM_PARAMS structure. The latter is controlling. We created our header based on the former. In PKCS #11 v3.0 the reconciled this, but it left us with and incompatible header. The new (to NSS) definition has a new field ulIvBits, which must be set correctly (see below).

To solve this, the NSS 3.52 headers has definitions for both structures: CK_NSS_GCM_PARAMS is the original NSS definition and CK_GCM_PARAMS_V3 is the new (to NSS) definition matching the current spec. CK_GCM_PARAMS will take on the definition of CK_GCM_PARAM_V3 by default, and CK_NSS_GCM_PARAMS if the code is compiled with NSS_PKCS11_2_0_COMPAT defined.

The current NSS builds in fedora have changes the sense of this #define so defining NSS_PKCS11_3_0_STRICT to gets the new behavior, and keep the old behavior by default. NSS builds will automatically switch back to the upstream default in Fedora 34. None of the changes below actually requires setting the NSS_PKCS11_3_STRICT define, though doing so can test that all but option 1 is functioning. These changes can be made in the current fedora as long as you have NSS 3.52.

Applications can fix this the following ways:

option 1

#define NSS_PKCS11_2_0_COMPAT 1

or compile with -DNSS_PKCS11_2_0_COMPAT

your app will compile and run using current and older versions of NSS (no need for nss 3.52), but may break on newer tokens that use the new definition (same as the previous behavior). Do this if your packages needs to compile in enviroments that have old versions of nss.


option 2

rename all occurances of CK_GCM_PARAMS to CK_NSS_GCM_PARAMS (this will now require nss >= 3.52 to compile, but won't change based on NSS_PKCS11_2_0_COMPAT or NSS_PKCS11_3_0_STRICT). Like option 1 it may break on newer tokens.


option 3

rename all occurances of CK_GCM_PARAMS to CK_GCM_PARAMS_V3 and set ulIvBits to ulIvLen*8.

This will require nss >= 3.52 to compile and to run. Should run on all new tokens. May break on older tokens.


option 4

Move to PK11_AEADOp interface, which all requires nss >= 3.52 to compile and run, but it's less surprising and the dependency will be picked up automatically because you are using a new for 3.52 interface, so it will continue to work against all tokens.


Option 4 is the preferred solution. It takes advantage the the PKCS #11 v3 interface for AES_GCM while removing any PCKS #11 param structure dependency in the application. It also handles backward compatibility on older tokens and automatically detects which flavor of data structure is supported. It also would help with applications that support two or more of AES_GCM, AES_CCM, and CHACHA_POLY.

Benefit to Fedora

This change will keep fedora with the NSS upstream as well as make Fedora compliant with the official OASIS PKCS #11 spec.

Scope

  • Proposal owners:

NSS 3.52 has already had builds made with the reverse sense. NSS will need to be rebuilt at the start of Fedora 34.

  • Other developers:

Developers need to choose one of the options listed in the description by fedora 34 or their rebuilt packages will fail at runtime.


I believe there is no additional release engineering requirements for this bug. Only packages which use CK_AES_GCM_PARAMS need action and the action can happen outside the release process.

  • Policies and guidelines:

There isn't any policy or guideline changes needed for this change.

  • Trademark approval: N/A (not needed for this Change)

Upgrade/compatibility impact

There is no upgrade impact. There will be a source level incompatibility on rebuild at fedora 34. This change is to allow a transition in fedora 33 where source code can be updated in ways that work in both fedora 33 and fedora 34 after recompile. There are no binary compatibility issues (old applications compiled with the old version of nss will continue to work).

How To Test

  1. . Grep for CK_AES_GCM_PARAMS in our source tree. If it does not appear, no further action is needed.
  2. . If you choose options 2-4, you can do a normal test build and run your normal tests against any version of nss > 3.52
  3. . If you think you don't need to make a change, compile your package with -DNSS_PKCS11_3_0_STRICT and run your normal tests. If everything works should should not need further action.
  4. . option 1 would require building NSS without the patch and then rebuilding with your package. Only use option 1 if you need to build your package against older versions of nss.

NOTE: The effect of not changing will create a runtime issue where your AES_GCM call will fail after recompiling.


User Experience

Users who don't build their own packages will see no issues. Users that build their own packages and use classic NSS AES_GCM will see runtime failures after a rebuild unless they update their packages.

Dependencies

nss-3.52 or greater. nss-3.52 is now available in all supported versions of fedora.


Contingency Plan

  • Contingency mechanism:

If critical packages are not updated, the NSS team can turn off the automatic move in fedora 34. If non-critical packages do not update, then they will just fail on the first rebuild in fedora 34. Libreswan is the only critical package we know of at this time that is affected. Upstream already has the appropriate changes.

  • Contingency deadline: beta freeze
  • Blocks release? Yes, but only for critical packages.


Documentation

Description contains the notes that upstream is working on, modified for fedora. I'll include links once upstream has released them.

Release Notes

Replicate the description in the release notes of fedora 33 and fedora 34. Users can make their own changes in fedora 33 before fedora 34 is released.