Skip to content

internal: derive WOLFSSH_NO_MLDSA when every level is off - #1289

Open
stenslae wants to merge 1 commit into
wolfSSL:masterfrom
stenslae:fix-mldsa-all-levels-off
Open

stenslae wants to merge 1 commit into
wolfSSL:masterfrom
stenslae:fix-mldsa-all-levels-off

Conversation

@stenslae

Copy link
Copy Markdown
Member

Defined WOLFSSH_NO_MLDSA when all three level macros are set. Added test_MlDsaLevelsDisabled to ensure keygen runs WS_NOT_COMPILED when all levels are off, and wraped ML-DSA-44 keys in macro checks. Exercised no-mldsa44 and no-levels in CI.

With 44, 65 and 87 all off, keygen and key loading still took ML-DSA.
@stenslae stenslae self-assigned this Sep 30, 2026
Copilot AI balanced review requested due to automatic review settings September 30, 2026 21:04

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #1289

Scan targets checked: wolfssh-src, wolfssh-bugs
Coverage: 2 of 3 in-scope changed file(s) opened by the reviewer; not opened: src/internal.c

Fenrir result: Approved ✅

No new issues found in the changed files.

Advisory only — this automated result does not count as a GitHub approval.

Review tier: Lite

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Crypto feature gating and its CI configurations warrant final human verification.

Review effort: Balanced
Findings: None

What changed in this PR

This PR makes wolfSSH disable ML-DSA when all three ML-DSA levels are disabled, with checks for the resulting configuration.

Changes:

  • Derives WOLFSSH_NO_MLDSA from the three level-disable macros.
  • Adds a unit check and CI configurations for disabled levels.
  • Guards ML-DSA-44 test data and updates the feature documentation.
File Description
wolfssh/​internal.h Derives the all-levels-disabled macro.
tests/​unit.c Checks disabled-level behavior and guards ML-DSA-44 test data.
src/​internal.c Documents the derived macro.
.github/​workflows/​mldsa-composite-config.yml Adds CI configurations and output checks.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@stenslae stenslae assigned wolfSSL-Bot and unassigned stenslae Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants