Skip to content

Add CB_ONLY mode for ML-DSA - #11214

Open
padelsbach wants to merge 8 commits into
wolfSSL:masterfrom
padelsbach:cbonly-mldsa
Open

padelsbach wants to merge 8 commits into
wolfSSL:masterfrom
padelsbach:cbonly-mldsa

Conversation

@padelsbach

Copy link
Copy Markdown
Contributor

Description

Saves approx 28kB when enabled and offloaded.

Testing

New test cases

Checklist

  • added tests
  • updated/added doxygen
  • updated appropriate READMEs
  • Updated manual and documentation

@github-actions

github-actions Bot commented Aug 20, 2026 •

Copy link
Copy Markdown

@padelsbach

padelsbach commented Aug 20, 2026 •

Copy link
Copy Markdown
Contributor Author

jenkins retest this please

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #11214

Scan targets checked: wolfcrypt-bugs, wolfcrypt-port-bugs, wolfcrypt-rs-bugs, wolfcrypt-src, wolfssl-bugs, wolfssl-src
Findings: 12
11 finding(s) posted as inline comments (see file-level comments below)

Required changes (1)

test_mldsa_pkcs12 still generates an ML-DSA key without a WC_MLDSA_HAVE_NATIVE gate

File: tests/api/test_mldsa.c:30178
Function: test_mldsa_pkcs12
Category: Conditional compilation / Missing edge-case coverage

The PR adds defined(WC_MLDSA_HAVE_NATIVE) to the other key-generating ML-DSA tests but not this one. It calls wc_MlDsaKey_MakeKey at line 30267 on an INVALID_DEVID key and asserts 0; under WOLF_CRYPTO_CB_ONLY_MLDSA that returns NO_VALID_DEVID, so make check fails in builds with PKCS#12 and DES3 enabled.

Recommendation: Add defined(WC_MLDSA_HAVE_NATIVE) to this test's preprocessor condition.

Referenced code: tests/api/test_mldsa.c:30178-30179 (2 lines)


This review was generated automatically by Fenrir. Reported findings require changes before merge.

@padelsbach
padelsbach force-pushed the cbonly-mldsa branch 5 times, most recently from f870cdd to e6979f8 Compare August 24, 2026 20:39

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #11214

Scan targets checked: wolfcrypt-port-bugs, wolfcrypt-rs-bugs, wolfcrypt-src, wolfssl-bugs, wolfssl-src
Failed targets: wolfcrypt-bugs

Findings: 5
5 finding(s) posted as inline comments (see file-level comments below)

This review was generated automatically by Fenrir. Reported findings require changes before merge.

Comment thread tests/api/test_mldsa.c
Comment thread tests/api/test_mldsa.c
Comment thread wolfcrypt/src/wc_mldsa.c Outdated
Comment thread wolfcrypt/src/wc_mldsa.c
Comment thread wolfcrypt/test/test.c
Comment thread tests/api/test_mldsa.c
Comment thread tests/api/test_mldsa.c
Comment thread wolfcrypt/src/wc_mldsa.c Outdated
Comment thread wolfcrypt/src/wc_mldsa.c
Comment thread wolfcrypt/test/test.c
@philljj

philljj commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

Retest this please.

FAIL: scripts/resume.test

Comment thread wolfcrypt/src/wc_mldsa.c Outdated
Comment thread wolfcrypt/src/wc_mldsa.c Outdated
@philljj philljj assigned padelsbach and unassigned wolfSSL-Bot Aug 27, 2026
@padelsbach padelsbach assigned wolfSSL-Bot and unassigned padelsbach Aug 27, 2026
@philljj

philljj commented Aug 31, 2026

Copy link
Copy Markdown
Contributor

Retest this please.

(no logs)

@philljj
philljj self-requested a review August 31, 2026 19:44
@padelsbach
padelsbach force-pushed the cbonly-mldsa branch 2 times, most recently from 2df1656 to f5286a0 Compare September 3, 2026 03:38

@philljj philljj left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

merge conflict in wc_mldsa.c

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #11214

Scan targets checked: wolfcrypt-bugs, wolfcrypt-port-bugs, wolfcrypt-rs-bugs, wolfcrypt-src, wolfssl-bugs, wolfssl-src

Findings: 6
6 finding(s) posted as inline comments (see file-level comments below)

This review was generated automatically by Fenrir. Reported findings require changes before merge.

Comment thread wolfcrypt/src/wc_mldsa.c
Comment thread wolfcrypt/src/wc_mldsa.c
Comment thread wolfcrypt/test/test.c
Comment thread wolfcrypt/src/cryptocb.c
Comment thread wolfssl/wolfcrypt/cryptocb.h
Comment thread wolfcrypt/test/test.c Outdated
@philljj philljj assigned padelsbach and unassigned wolfSSL-Bot Sep 8, 2026
@padelsbach padelsbach assigned wolfSSL-Bot and unassigned padelsbach Sep 8, 2026
@padelsbach
padelsbach force-pushed the cbonly-mldsa branch 2 times, most recently from 3f59c3a to 8722392 Compare September 17, 2026 06:06
@philljj philljj self-assigned this Sep 29, 2026
@padelsbach
padelsbach force-pushed the cbonly-mldsa branch 2 times, most recently from 4e471a7 to 936413f Compare October 1, 2026 16:50
Copilot AI balanced review requested due to automatic review settings October 1, 2026 16:50

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Several seeded and internal-interface ML-DSA APIs bypass existing callback operations and become unusable with device-owned keys.

Review effort: Balanced
Findings: 2 Medium severity

Open (2)
What changed in this PR

Adds callback-only ML-DSA support to reduce binary size when cryptography is offloaded.

Changes:

  • Removes native ML-DSA and assembly paths in callback-only builds.
  • Adds callback dispatch for key generation, signing, verification, and key checks.
  • Adds configuration validation and callback-only CI coverage.
File Description
.github/​workflows/​cryptocb-only.yml Adds ML-DSA callback-only CI configurations.
configure.ac Enables ML-DSA stripping for --enable-cryptocb=only.
tests/​api.c Gates native ML-DSA CRL testing.
tests/​api/​test_mldsa.c Gates native implementation tests.
tests/​api/​test_mldsa_legacy.c Gates the native legacy shim test.
wolfcrypt/​src/​cryptocb.c Documents the new callback-only option.
wolfcrypt/​src/​wc_mldsa.c Implements ML-DSA callback-only dispatch and stripping.
wolfcrypt/​src/​wc_mldsa_asm.S Excludes ML-DSA assembly implementations.
wolfcrypt/​test/​test.c Adds callback dispatch and refusal tests.
wolfssl/​wolfcrypt/​settings.h Validates callback-only configuration.
wolfssl/​wolfcrypt/​wc_mldsa.h Exposes native-implementation availability.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread wolfcrypt/src/wc_mldsa.c
Comment thread wolfcrypt/test/test.c
@philljj

philljj commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Retest this please.

(PRB valgrind hung)

@padelsbach

Copy link
Copy Markdown
Contributor Author

jenkins retest this please

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants