Conversation
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #1277
Scan targets checked: wolfssh-src, wolfssh-bugs
Coverage: 2 of 5 in-scope changed file(s) opened by the reviewer; not opened: src/ssh.c, tests/auth.c, wolfssh/internal.h
Findings: 1
1 finding(s) posted as inline comments (see file-level comments below)
This review was generated automatically by Fenrir. Reported findings require changes before merge.
Review tier: Lite
b62a9b9 to
1739412
Compare
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #1277
Scan targets checked: wolfssh-src, wolfssh-bugs
Coverage: 2 of 5 in-scope changed file(s) opened by the reviewer; not opened: tests/auth.c, tests/unit.c, wolfssh/internal.h
Fenrir result: Approved ✅
No new issues found in the changed files.
Advisory only — this automated result does not count as a GitHub approval.
Review tier: Lite
Fenrir's latest completed scan found no issues; clearing the prior automated change request.
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
Cryptographic key handling and extensive compile-time configuration paths warrant final human review.
Review effort: Balanced
Findings: None
What changed in this PR
Adds private-only ML-DSA key support by deriving and caching the public key during loading.
Changes:
- Detects and documents ML-DSA public-key derivation support.
- Caches derived host public keys for KEX and manages their lifecycle.
- Adds unit and authentication regression coverage.
| File | Description |
|---|---|
wolfssh/internal.h |
Adds capability detection and cache fields. |
src/internal.c |
Derives, caches, uses, and clears ML-DSA public keys. |
src/ssh.c |
Clears caches when replacing certificate-store slots. |
configure.ac |
Detects the wolfSSL derivation API. |
README.md |
Documents private-only key behavior. |
tests/unit.c |
Tests derivation, caching, failures, and disabled levels. |
tests/auth.h |
Extends authentication test arguments for host certificates. |
tests/auth.c |
Adds end-to-end key, certificate, and user-auth tests. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Added support for loading private-only ML-DSA host keys. Uses wc_MlDsaKey_MakePublicKey() (wolfSSL/wolfssl#10985) to derive the public key when parsing private-only ML-DSA DER bytes. Extends WOLFSSH_PVT_KEY struct to cache raw ML-DSA public key. Updated SendKexGetSigningKey() to copy cached public key. Added ClearMlDsaHostPubKey() to manage chached public key.
Added tests for ML-DSA key derivation in end-to-end authentication, and coverage for load time derivcation and CTX caching and clearing.
For issue #1120