mirror of
https://github.com/tinygo-org/tinygo.git
synced 2026-08-12 06:53:40 +00:00
loader, crypto/internal/entropy: fix 32 MiB RAM overflow on microcontrollers
Go 1.26 added a CPU jitter-based SP 800-90B entropy source for FIPS 140-3 compliance (crypto/internal/entropy/v1.0.0). It declares a 32 MiB global ScratchBuffer ([1<<25]byte) used for memory access timing noise. On systems with virtual memory this stays in .noptrbss and is lazily paged, but on baremetal targets it becomes static RAM, causing fatal overflow (e.g. pybadge with 192 KB SRAM reports 33 MB overflow). Since FIPS jitter entropy is never used on TinyGo targets (fips140.Enabled is always false, so drbg.Read falls through to sysrand.Read), provide a TinyGo overlay that replaces ScratchBuffer with [0]byte and stubs out all entropy functions with panics.
This commit is contained in:
@@ -268,6 +268,16 @@ func pathsToOverride(goMinor int, needsSyscallPackage bool) map[string]bool {
|
||||
paths["crypto/internal/boring/sig/"] = false
|
||||
}
|
||||
|
||||
if goMinor >= 26 {
|
||||
// Go 1.26 added a CPU jitter entropy source for FIPS 140-3 that
|
||||
// allocates a 32 MiB global buffer (ScratchBuffer [1<<25]byte).
|
||||
// This is fine on systems with virtual memory, but causes RAM
|
||||
// overflow on microcontrollers. Replace with a zero-size stub
|
||||
// since TinyGo targets never use FIPS jitter entropy.
|
||||
paths["crypto/internal/entropy/"] = true
|
||||
paths["crypto/internal/entropy/v1.0.0/"] = false
|
||||
}
|
||||
|
||||
if needsSyscallPackage {
|
||||
paths["syscall/"] = true // include syscall/js
|
||||
paths["internal/syscall/"] = true
|
||||
|
||||
Reference in New Issue
Block a user