crypto: complete OpenSSL evacuation — libsecp256k1 EC math + ctaes + RNG + drop BIP70/rpcssl #47
Labels
No labels
enhancement
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
SubGeniusFinance/Offerings-to-Cthulhu#47
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Goal
Finish what #33 starts. #33 removes OpenSSL from signature encoding consensus (the strict-DER parser is now OFF's own code); it explicitly leaves the EC math on OpenSSL's
ECDSA_verify. This issue removes OpenSSL from everything that's left — EC math, wallet AES, RNG, GUI payment protocol, RPC TLS — so neither daemon nor wallet linkslibssl/libcryptoat all. Retires the OpenSSL-1.0.2 build pin.Why
EC_KEYAPIs that OpenSSL 3 deleted. Drop the link → build against modern OpenSSL (unused) or nothing. Single biggest source of the multi-step build dance.key.cppEC paths are long-dead upstream.Hard prerequisite
#33 (BIP66) must be active on mainnet (h=1,055,555) before the verify swap. libsecp256k1 only accepts strict-DER; swapping verify before every newly-mined block is guaranteed strict-DER risks rejecting a legitimately-mined block = consensus split. Order is non-negotiable. (This issue was filed automatically at activation for that reason.)
Scope — seven sub-tasks, roughly independent
src/secp256k1/, wire into the build. Pin the commit Bitcoin Core 0.12–0.13 shipped (matches the EC math OFF already validates).key.cpp/pubkey.cpp). The consensus-sensitive step.key.cpp). Not consensus-critical (only affects what we emit). Free win: RFC6979 deterministic nonces.crypter.cpp). In-tree constant-time AES-256-CBC. Acceptance gate: round-trip lock/unlock/spend on a pre-change encrypted wallet.dat.random.cpp): replaceRAND_bytes/RAND_addwith Core's modern RNG (platform entropy + ChaCha20).paymentserver.cppX.509 path) — a-lcryptoX.509 user, no merchant use case.-rpcssl(rpcserver.cppboost::asio::sslcontext @ ~L626,rpcprotocol.hSSLIOStreamDevice, the-rpcssl*options ininit.cpp). This is the-lssl(TLS) user — distinct sub-library from the-lcryptousers above, so the final unlink can't happen while it lives. Pure deletion, zero consensus surface: every RPC consumer is on loopback and TLS is terminated at the reverse proxy. Upstream deleted it in 0.12 alongside the libevent HTTP-server rewrite, but OFF can just drop the SSL branch and keep the plaintextboost::asiopath bound to 127.0.0.1 — no libevent migration required. Deprecate in favor of stunnel/SSH tunnels.Payoff commit
Remove
-lssl -lcryptofrom the link — gated on both sub-task 6 (BIP70, the-lcrypto/X.509 user) and sub-task 7 (rpcssl, the-lssl/TLS user) being gone, since those are the only consumers of the respective libs left after 1–5. Then drop OpenSSL fromdepends/+configure.ac, delete thebignum.hwrappers. Build works against system OpenSSL 3 (unused) or with OpenSSL entirely absent. The 1.0.2 pin is gone.Test plan
Sequencing / risk
Blocks: depends on #33 (BIP66). Drafted 2026-06-27; primer in #development-off. Filed automatically at #33 mainnet activation.
Triage: out of scope for v2.1.0-Nodens, targeted at v2.1.1+.
Nodens is deliberately a small, already-soaked release: the Phase-2 ACP first-light wiring (#40), the RFC 6598 netbase fix (#44),
-miningaddress(#46), and the #48 fresh-datadir init fix. The OpenSSL evacuation is a large crypto-surface migration (EC math → libsecp256k1, ctaes, RNG, BIP70/rpcssl removal) with no height gate forcing its schedule — bundling it into a release whose job is checkpoint first-light would put the riskiest possible change in the least appropriate vehicle.Its
[post-#33]prerequisite is now satisfied (BIP66 strict-DER activated cleanly at h=1,055,555 and #33 is closed), so this is genuinely unblocked — just queued behind Nodens. Leaving open.Full-tree dependency survey complete (2026-07-30). Every claim in the issue body checks out, and the survey found two subsystems the subtask list missed — one of them is now the hardest item in the evacuation:
src/crypto/. Consensus hashing — txid double-SHA256,Hash160,OP_SHA256/OP_HASH160, BIP32 HMAC-SHA512 — runs entirely on OpenSSL viahash.{h,cpp}. Upstream's nativesrc/crypto/(0.11) never reached this fork. Mechanical, bit-identical port, but a real subtask this issue didn't list.bignum.hdeclaresclass CBigNum : public BIGNUM— literally inheriting the OpenSSL struct, impossible on 1.1+/3.x — and its consumers are the script interpreter's arithmetic opcodes,SetCompact/GetCompacttarget math, the retarget path, andGetBlockWork. Retiring it meansarith_uint256for work/target plusCScriptNumfor script (upstream PR #4988 lineage, with its ≤4-byte-operand equivalence argument) — the single most consensus-hazardous step here, deserving its own release + soak. Extra wrinkle: the LWMA-3 work back-portedarith_uint256-idiom code into CBigNum (see the note at the top ofpow.cpp), which must be unwound.Other confirmations: no vendored libsecp256k1 anywhere (sign AND verify are OpenSSL
EC_KEY, incl. hand-rolledEC_KEY_regenerate_key+ SEC1 pubkey recovery with directsig->r/sig->saccess); the Quark PoW is already OpenSSL-free;-lssl -lcryptoare injected into globalLIBSbyconfigure.acso the link is invisible at the Makefile level;db.cpp's<openssl/rand.h>is a dead include; and the #33 prerequisite is satisfied (BIP66 active on mainnet since h=1,055,555, 2026-07-23).The validated, phased implementation plan — 5 phases across ~5 releases, cheapest → most hazardous, with per-phase acceptance gates (bit-exact
EVP_BytesToKeyKDF for wallet compat, reindex-from-zero for the verify swap, script-vector equivalence for CScriptNum) — lands atresearch/issue47-openssl-evacuation-plan.mdvia PR #56. Phases 0–2 (banner/dead-include trivia,-rpcssl+ BIP70 deletions, RNG/cleanse/ctaes) have zero consensus surface and can start any time.Plan amended (same doc,
research/issue47-openssl-evacuation-plan.md, now merged): the sibling dobbscoin-source tree turns out to be a maintainer-owned donor for most phases — genuine Core 0.10 layout, already modernized to build on OpenSSL 3. It carriessrc/crypto/native hashing, vendored secp256k1 with the sign path wired, an OpenSSL-3-safeecwrapper(verify + SEC1 recovery),CScriptNumplus upstream's scriptnum equivalence-test harness (including the test-only reference bignum.h), opaque-safe BIGNUM wrappers for KGW/DigiShield pow math, and a proven-compatibleEVP_BytesToKeycrypter in heap-CTX form.Strategic consequence — new milestone M1: "builds on OpenSSL 3" and "OpenSSL-free" are separable. Porting the donor's compat patterns retires the OpenSSL-1.0.2 build pin at ~v2.1.2, long before full evacuation; phases 3-5 then proceed on security/consensus-hygiene grounds rather than build pain. One caveat documented: OFF's interpreter is 0.8-lineage, so CScriptNum semantics get ported into it rather than lifting the 0.10 interpreter wholesale.