Commit aaf407b
authored
Update Rust crate aws-lc-rs to v1.18.0 (#2569)
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| [aws-lc-rs](https://redirect.github.com/aws/aws-lc-rs) |
workspace.dependencies | minor | `1.17.3` → `1.18.0` |
---
### Release Notes
<details>
<summary>aws/aws-lc-rs (aws-lc-rs)</summary>
###
[`v1.18.0`](https://redirect.github.com/aws/aws-lc-rs/releases/tag/v1.18.0):
aws-lc-rs v1.18.0
[Compare
Source](https://redirect.github.com/aws/aws-lc-rs/compare/v1.17.3...v1.18.0)
#### AWS-LC-FIPS module updated to 4.x
This release switches `aws-lc-fips-sys` (used via the `fips` feature)
from the AWS-LC-FIPS 3.x branch to [AWS-LC-FIPS
4.0](https://redirect.github.com/aws/aws-lc/releases/tag/v4.0.0).
- **If your project requires FIPS compliance, please consult your local
FIPS compliance experts before upgrading.** The FIPS v3 module shipped
in aws-lc-rs v1.17.x is FIPS 140-3 validated ([Certificate
#​5314](https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/5314)
static, [Certificate
#​5298](https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/5298)
dynamic). The 4.x module has completed validation testing by an
accredited lab and has been submitted to NIST for certification. Refer
to the [CMVP Modules In Progress
List](https://csrc.nist.gov/Projects/cryptographic-module-validation-program/modules-in-process/Modules-In-Process-List)
for its current status, and to
[FIPS.md](https://redirect.github.com/aws/aws-lc/blob/main/crypto/fipsmodule/FIPS.md)
for security policies and supported operating environments.
- Consumers who need to remain on the FIPS 3.x module should pin
`aws-lc-rs` to `<1.18.0`. See the Cargo Book on [Specifying
Dependencies](https://doc.rust-lang.org/cargo/reference/specifying-dependencies.html).
| AWS-LC-FIPS module | aws-lc-rs |
| ------------------ | --------- |
| 2.0.x | <1.12.0 |
| 3.0.x | <1.18.0 |
| 4.x | *latest* |
#### What's Changed
- Switch `aws-lc-fips-sys` to AWS-LC's "FIPS 4.0" branch by
[@​justsmth](https://redirect.github.com/justsmth) in
[#​1185](https://redirect.github.com/aws/aws-lc-rs/pull/1185)
- `aws-lc-fips-sys` v0.13.16 -> v0.14.0. Please see the call-out above.
- **The ML-DSA signature APIs are now stable** 🎉 by
[@​justsmth](https://redirect.github.com/justsmth) in
[#​1188](https://redirect.github.com/aws/aws-lc-rs/pull/1188) and
[#​1189](https://redirect.github.com/aws/aws-lc-rs/pull/1189)
- `PqdsaKeyPair`, `PqdsaPublicKey`, `PqdsaPrivateKey`,
`PqdsaSigningAlgorithm`, `PqdsaVerificationAlgorithm`, and the
`ML_DSA_44` / `ML_DSA_65` / `ML_DSA_87` algorithms (and their `_SIGNING`
counterparts) now live in `aws_lc_rs::signature`. ML-DSA no longer
requires the `unstable` feature, and is now available under `fips` --
the FIPS 4.0 module provides ML-DSA, which is what had kept these APIs
unstable. See our updated [API
documentation](https://docs.rs/aws-lc-rs/latest/aws_lc_rs/signature/index.html).
- Please migrate any use of `aws_lc_rs::unstable::signature` to
`aws_lc_rs::signature`. The `unstable::signature` module remains as
deprecated aliases and will be removed in a future release.
- `PqdsaKeyPair::to_pkcs8` has been renamed to `to_pkcs8v1`, since
elsewhere in the module an unqualified `to_pkcs8` means
[PKCS#8](https://redirect.github.com/PKCS/aws-lc-rs/issues/8) v2. A
deprecated `to_pkcs8` alias remains available under the `unstable`
feature.
- Existing `unstable` consumers continue to compile, with deprecation
warnings. Two cases need a source change: builds using
`#![deny(warnings)]`, and code that glob-imports both `signature::*` and
`unstable::signature::*`, which now needs an explicit import to
disambiguate.
- **Behavior change:**
`PqdsaVerificationAlgorithm::parsed_verify_digest_sig` now always
returns `Unspecified`. Digest-then-verify is not an operation defined by
FIPS 204 -- pure ML-DSA signs the message itself, and the pre-hash
variant (HashML-DSA) uses a distinct domain separator that this API does
not implement.
- Add out-of-place AEAD sealing by
[@​iainmcgin](https://redirect.github.com/iainmcgin) in
[#​1183](https://redirect.github.com/aws/aws-lc-rs/pull/1183)
- Adds `seal_separate_out_of_place` to `LessSafeKey` and
`TlsRecordSealingKey`. Every sealing entry point was previously
in-place, so a caller whose plaintext was borrowed or shared had to copy
it into a scratch buffer purely to make it mutable. This mirrors the
existing `open_separate_gather`, so the sealing and opening directions
now match.
- Add `rsa::KeyPair::from_components` for constructing RSA key pairs
from raw components by
[@​justsmth](https://redirect.github.com/justsmth) in
[#​1175](https://redirect.github.com/aws/aws-lc-rs/pull/1175)
- Adds `rsa::KeyPairComponents` and `rsa::KeyPair::from_components`,
matching ring 0.17, so a signing key can be built from formats such as
JWK without first encoding the components as DER. Unlike ring, `d` and
the CRT parameters are validated at construction using `RSA_check_key`,
so keys with inconsistent or placeholder values that ring accepts may be
rejected. Unnecessary generic bounds were also removed from
`PublicKeyComponents`.
- Automatically optimize aws-lc for size when opt-level is "s" or "z" by
[@​justsmth](https://redirect.github.com/justsmth) in
[#​1159](https://redirect.github.com/aws/aws-lc-rs/pull/1159)
- The builder now enables AWS-LC's size-optimized configuration
(`OPENSSL_SMALL`, and no AVX-512 assembly on x86\_64) whenever Cargo is
already building for size. In CI, a small binary exercising SHA-256,
AES-256-GCM, and ECDSA P-256 is **36-50% smaller** at `opt-level=z` than
at `opt-level=3`: 50% on x86\_64 Linux, 48% on aarch64 macOS, 39% on
x86\_64 Windows, 36% on aarch64 Linux. Your own savings depend on how
much of AWS-LC your binary retains.
- No algorithms are removed and outputs are unchanged; the trade-off is
slower elliptic-curve performance. Set `AWS_LC_SYS_SMALL=1`/`=0` to
force it on or off independently of opt-level.
- FIPS builds do not opt in automatically: `aws-lc-fips-sys` requires an
explicit `AWS_LC_FIPS_SYS_SMALL=1`, and warns when it is set.
- Partially addresses
[#​745](https://redirect.github.com/aws/aws-lc-rs/issues/745); the
default size under `opt-level=3` footprint is unchanged.
- Export native library build metadata from the -sys crates by
[@​justsmth](https://redirect.github.com/justsmth) in
[#​1187](https://redirect.github.com/aws/aws-lc-rs/pull/1187),
including original commits from
[@​glebpom](https://redirect.github.com/glebpom) in
[#​1184](https://redirect.github.com/aws/aws-lc-rs/pull/1184)
- Downstream build scripts compiling C code against AWS-LC can now
locate our artifacts via `DEP_AWS_LC_*` / `DEP_AWS_LC_FIPS_*` (`libdir`,
`libcrypto_path`, `link_kind`, and `libssl_path` with `ssl`),
consistently across the CC, CMake, and system-library build paths.
Existing linker directives are unchanged. On Windows, the `*_path`
values are the link-time artifact (import library), not the runtime DLL.
- Key wrap hardening by
[@​justsmth](https://redirect.github.com/justsmth) in
[#​1190](https://redirect.github.com/aws/aws-lc-rs/pull/1190) and
[#​1191](https://redirect.github.com/aws/aws-lc-rs/pull/1191)
- `KeyEncryptionKey::unwrap` no longer underflows on ciphertexts shorter
than 8 bytes. Since the ciphertext is untrusted input, builds with
`overflow-checks = true` would panic instead of returning the documented
`Err(Unspecified)`; default release builds were unaffected.
- `KeyEncryptionKey` now zeroizes its key material on drop, consistent
with the other key types in this crate.
- docs(signature): correct outdated note about signing a separate digest
by
[@​WesleyRosenblum](https://redirect.github.com/WesleyRosenblum)
in [#​1186](https://redirect.github.com/aws/aws-lc-rs/pull/1186)
##### Upstream AWS-LC (v5.5.0)
`aws-lc-sys` v0.44.0 aligns with [AWS-LC
v5.5.0](https://redirect.github.com/aws/aws-lc/releases/tag/v5.5.0)
(previously v5.2.0). See also the release notes for
[v5.3.0](https://redirect.github.com/aws/aws-lc/releases/tag/v5.3.0) and
[v5.4.0](https://redirect.github.com/aws/aws-lc/releases/tag/v5.4.0).
##### Build Improvements
- Fix bindings copy from read-only prebuilt AWS-LC install by
[@​justsmth](https://redirect.github.com/justsmth) in
[#​1194](https://redirect.github.com/aws/aws-lc-rs/pull/1194)
- Copies into `OUT_DIR` now remove any stale destination first and leave
the fresh copy writable, so building against a read-only prebuilt
install (e.g. the Nix store) no longer fails with `Permission denied` on
a build-script rerun. An `OUT_DIR` already poisoned by an earlier build
now recovers without a `cargo clean`.
##### Issues Being Closed
- ML-DSA stabilization? --
[#​964](https://redirect.github.com/aws/aws-lc-rs/issues/964)
- Expose out-of-place AEAD sealing --
[#​1182](https://redirect.github.com/aws/aws-lc-rs/issues/1182)
- Construct an RSA Key pair from raw private components --
[#​791](https://redirect.github.com/aws/aws-lc-rs/issues/791)
- aws-lc-sys build script fails to copy bindings from read only prebuild
aws-lc on repeat runs --
[#​1193](https://redirect.github.com/aws/aws-lc-rs/issues/1193)
#### Other Merged PRs
- ci: fix mdbook test failure and run docs checks on PRs by
[@​justsmth](https://redirect.github.com/justsmth) in
[#​1181](https://redirect.github.com/aws/aws-lc-rs/pull/1181)
- Publish script fixes: cargo clean failure, and verify aws-lc-rs
against minimum published sys crates by
[@​justsmth](https://redirect.github.com/justsmth) in
[#​1179](https://redirect.github.com/aws/aws-lc-rs/pull/1179)
- Prepare aws-lc-sys v0.44.0 by
[@​justsmth](https://redirect.github.com/justsmth) in
[#​1199](https://redirect.github.com/aws/aws-lc-rs/pull/1199)
- Prepare aws-lc-rs v1.18.0 by
[@​justsmth](https://redirect.github.com/justsmth) in
[#​1200](https://redirect.github.com/aws/aws-lc-rs/pull/1200)
#### New Contributors
- [@​iainmcgin](https://redirect.github.com/iainmcgin) made their
first contribution in
[#​1183](https://redirect.github.com/aws/aws-lc-rs/pull/1183)
- [@​glebpom](https://redirect.github.com/glebpom) made their
first contribution in
[#​1184](https://redirect.github.com/aws/aws-lc-rs/pull/1184)
(landed via
[#​1187](https://redirect.github.com/aws/aws-lc-rs/pull/1187))
**Full Changelog**:
<aws/aws-lc-rs@v1.17.3...v1.18.0>
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- Between 12:00 AM and 03:59 AM, only on Monday (`* 0-3 * * 1`)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/j178/prek).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4yOS41IiwidXBkYXRlZEluVmVyIjoiNDQuMjkuNSIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJpbnRlcm5hbCJdfQ==-->
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>1 parent 3ddddfd commit aaf407b
1 file changed
Lines changed: 4 additions & 4 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
0 commit comments