Add CB_ONLY mode for ML-DSA - #11214
padelsbach wants to merge 8 commits into
Conversation
|
|
jenkins retest this please |
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #11214
Scan targets checked: wolfcrypt-bugs, wolfcrypt-port-bugs, wolfcrypt-rs-bugs, wolfcrypt-src, wolfssl-bugs, wolfssl-src
Findings: 12
11 finding(s) posted as inline comments (see file-level comments below)
Required changes (1)
test_mldsa_pkcs12 still generates an ML-DSA key without a WC_MLDSA_HAVE_NATIVE gate
File: tests/api/test_mldsa.c:30178
Function: test_mldsa_pkcs12
Category: Conditional compilation / Missing edge-case coverage
The PR adds defined(WC_MLDSA_HAVE_NATIVE) to the other key-generating ML-DSA tests but not this one. It calls wc_MlDsaKey_MakeKey at line 30267 on an INVALID_DEVID key and asserts 0; under WOLF_CRYPTO_CB_ONLY_MLDSA that returns NO_VALID_DEVID, so make check fails in builds with PKCS#12 and DES3 enabled.
Recommendation: Add defined(WC_MLDSA_HAVE_NATIVE) to this test's preprocessor condition.
Referenced code: tests/api/test_mldsa.c:30178-30179 (2 lines)
This review was generated automatically by Fenrir. Reported findings require changes before merge.
f870cdd to
e6979f8
Compare
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #11214
Scan targets checked: wolfcrypt-port-bugs, wolfcrypt-rs-bugs, wolfcrypt-src, wolfssl-bugs, wolfssl-src
Failed targets: wolfcrypt-bugs
Findings: 5
5 finding(s) posted as inline comments (see file-level comments below)
This review was generated automatically by Fenrir. Reported findings require changes before merge.
e6979f8 to
2cc3fb1
Compare
|
Retest this please. FAIL: scripts/resume.test |
|
Retest this please. (no logs) |
2df1656 to
f5286a0
Compare
philljj
left a comment
There was a problem hiding this comment.
merge conflict in wc_mldsa.c
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #11214
Scan targets checked: wolfcrypt-bugs, wolfcrypt-port-bugs, wolfcrypt-rs-bugs, wolfcrypt-src, wolfssl-bugs, wolfssl-src
Findings: 6
6 finding(s) posted as inline comments (see file-level comments below)
This review was generated automatically by Fenrir. Reported findings require changes before merge.
3f59c3a to
8722392
Compare
60cde42 to
bd9ea1b
Compare
4e471a7 to
936413f
Compare
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Several seeded and internal-interface ML-DSA APIs bypass existing callback operations and become unusable with device-owned keys.
Review effort: Balanced
Findings: 2
Open (2)
What changed in this PR
Adds callback-only ML-DSA support to reduce binary size when cryptography is offloaded.
Changes:
- Removes native ML-DSA and assembly paths in callback-only builds.
- Adds callback dispatch for key generation, signing, verification, and key checks.
- Adds configuration validation and callback-only CI coverage.
| File | Description |
|---|---|
.github/workflows/cryptocb-only.yml |
Adds ML-DSA callback-only CI configurations. |
configure.ac |
Enables ML-DSA stripping for --enable-cryptocb=only. |
tests/api.c |
Gates native ML-DSA CRL testing. |
tests/api/test_mldsa.c |
Gates native implementation tests. |
tests/api/test_mldsa_legacy.c |
Gates the native legacy shim test. |
wolfcrypt/src/cryptocb.c |
Documents the new callback-only option. |
wolfcrypt/src/wc_mldsa.c |
Implements ML-DSA callback-only dispatch and stripping. |
wolfcrypt/src/wc_mldsa_asm.S |
Excludes ML-DSA assembly implementations. |
wolfcrypt/test/test.c |
Adds callback dispatch and refusal tests. |
wolfssl/wolfcrypt/settings.h |
Validates callback-only configuration. |
wolfssl/wolfcrypt/wc_mldsa.h |
Exposes native-implementation availability. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
Retest this please. (PRB valgrind hung) |
936413f to
d9b0597
Compare
410641f to
0ae42d8
Compare
|
jenkins retest this please |

Description
Saves approx 28kB when enabled and offloaded.
Testing
New test cases
Checklist