Commit 5566e1ea10 for openssl.org

commit 5566e1ea100ca84c1b41757f41da3e8b88163e94
Author: Richard Levitte <levitte@openssl.foundation>
Date:   Tue Sep 22 14:33:45 2026 +0200

    cipher_aes_hw_aesni.c: fix linux-x32 build failure

    The VAES GCM code is enabled by an ISA check (__x86_64__ & co),
    which the x32 ABI satisfies: x32 is a 64-bit platform with a 32-bit
    size_t.  There, comparing the size_t ivlen against 2^61 is always
    false, which -Wtype-limits (via --strict-warnings) turns
    into a build failure.

    Only perform the check where size_t is wide enough to violate
    the limit.

    Fixes: 63b996e752ac "AES-GCM enabled with AVX512 vAES and vPCLMULQDQ."
    Assisted-by: Pi:moonshotai/kimi-k3
    Reviewed-by: Matt Caswell <matt@openssl.foundation>
    Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org>
    Merge-date: Fri Oct  9 22:26:45 2026
    Merged-from: https://github.com/openssl/openssl/pull/32925

diff --git a/providers/implementations/ciphers/cipher_aes_hw_aesni.c b/providers/implementations/ciphers/cipher_aes_hw_aesni.c
index dce9c1bc57..003d0d9ed3 100644
--- a/providers/implementations/ciphers/cipher_aes_hw_aesni.c
+++ b/providers/implementations/ciphers/cipher_aes_hw_aesni.c
@@ -311,8 +311,10 @@ static int vaes_gcm_setiv(PROV_GCM_CTX *ctx, const unsigned char *iv,
     gcmctx->mres = 0;

     /* IV is limited by 2^64 bits, thus 2^61 bytes */
+#if SIZE_MAX > 0xFFFFFFFFu
     if (ivlen > (U64(1) << 61))
         return 0;
+#endif

     ossl_aes_gcm_setiv_avx512(gcmctx->key, gcmctx, iv, ivlen);