SHA-3: fix wrong digest on refused vector claim, v7 gates, build fixes - #11441
Merged
JacobBarthelmeh merged 20 commits intoOct 2, 2026
Merged
JacobBarthelmeh merged 20 commits into
JacobBarthelmeh merged 20 commits into
Conversation
kaleb-himes
force-pushed
the
PQ-FS-2026-Part3-SecurityReview-nofallback-P
branch
from
September 12, 2026 23:20
72b6fb7 to
8f9bc3c
Compare
Contributor
Author
|
@wolfSSL-Fenrir-bot review force |
kaleb-himes
dismissed
wolfSSL-Fenrir-bot’s stale review
September 13, 2026 15:39
Dismiss to re-request
kaleb-himes
dismissed
wolfSSL-Fenrir-bot’s stale review
September 15, 2026 15:04
Fenrir is bikeshedding now, only identifying items out of scope of this PR, dismissing automated review.
kaleb-himes
force-pushed
the
PQ-FS-2026-Part3-SecurityReview-nofallback-P
branch
2 times, most recently
from
September 15, 2026 15:42
9b24f36 to
2046115
Compare
kaleb-himes
force-pushed
the
PQ-FS-2026-Part3-SecurityReview-nofallback-P
branch
from
September 25, 2026 18:56
2046115 to
307decc
Compare
kaleb-himes
force-pushed
the
PQ-FS-2026-Part3-SecurityReview-nofallback-P
branch
from
October 1, 2026 02:20
ebdc1ea to
baa31e3
Compare
JacobBarthelmeh
approved these changes
Oct 1, 2026
SparkiDev
approved these changes
Oct 1, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
SHA-3: vector-register brackets, arm32 and PowerPC/RISC-V builds, FIPS v7 service gates
The vector-register claim around the Keccak-f[1600] permutation was taken after the
sponge had already been modified, so a refused claim left a corrupted context and a
retry returned success with the wrong digest. This fixes the brackets, pins the
implementation at build time for certifiable builds, and closes two build
configurations that did not link or selected the wrong block. Rebased on master after
the aarch64 claim work landed in #11423, so none of that is duplicated here.
Sha3Finalpads before claiming; a refused claim corrupts the contextsettings.h; configure refuses an explicit askwc_Sha3_SetFlagsaccepts the non-approved Keccak-256 pad under v7FIPS_NOT_ALLOWED_E, context-independent--enable-fips=v7with riscv64 or ppc64 asm does not link at allWC_SHA3_NO_ASMtakes the PowerPC asm arm with prototypes suppressedTwo of those are AES build plumbing rather than SHA-3: the
BUILD_FIPS_V7_PLUSblock in
src/include.amnever listed the RISC-V or ppc64 AES assembly, though thenon-FIPS block and both the v5 and v6 FIPS blocks do, so
--enable-fips=v7 --enable-riscv-asmfailed on undefined references to the AES entry points. FIPS v7on those two targets was unbuildable, which is also how it was found: the SHA-3 lane
work needed a FIPS v7 RISC-V build to test on and there wasn't one before now!
Scope: WC_C_DYNAMIC_FALLBACK
This PR targets
--enable-fips=v7(including--enable-linuxkm). It does not extendthe run-time C fallback anywhere, and it does not remove it anywhere it works today.
** v6 module has live graceful C runtime fallback but there are presently no plans to use the v6 module in kernel space. Will need to resolve those through an UPDT submission if the v6 module ever gets used as a KM.
It is compiled out only for the certifiable builds, where one build carrying two
implementations of a single algorithm would need a CAST for each under FIPS 140-3 IG
10.3.A GeneralNote1, and the SHAKE CAST only ever exercises the lane that was live
when it ran.
aarch64 with
WC_C_DYNAMIC_FALLBACKhas never compiled, on master either (6compile errors on both this branch and its base). This PR deliberately does not fix
that.
WC_C_DYNAMIC_FALLBACKis not supported in a certifiable build, so anever-built fallback path on aarch64 is not needed for the
--enable-fips=v7 --enable-linuxkmtarget and repairing it is out of scope here.The fallback arm requires
USE_INTEL_SPEEDUP, so it is not compiled on Arm at all:arm32 has zero fallback sites in every flavor, FIPS or not. That condition is what
keeps the new arm32 claim block from pulling the fallback arm into a target that has
no
sha3_blockto assign (5 compile errors without it). No fallbacks removed or addedby design.
Testing
14 configurations. Every measurement carries a control, so a number that cannot move
is reported as a failure rather than a pass.
--enable-all, fullmake checkWC_C_DYNAMIC_FALLBACKvs base (parity, not a fix)WC_C_DYNAMIC_FALLBACKvs base (no regression)WC_SHA3_NO_ASMon ppc64 picks C blockChecklist