Skip to content

Add ML-DSA coverage to the wolfCrypt crypto callback test - #11611

Merged
philljj merged 1 commit into
wolfSSL:masterfrom
dgarske:mldsa_cryptocb
Oct 3, 2026
Merged

philljj merged 1 commit into
wolfSSL:masterfrom
dgarske:mldsa_cryptocb

Conversation

@dgarske

@dgarske dgarske commented Sep 30, 2026

Copy link
Copy Markdown
Member

Description

myCryptoDevCb supports SLH-DSA and Falcon (WC_PK_TYPE_PQC_SIG_*) but lacked ML-DSA handling. Because mldsa_test() runs under cryptocb_test() using callback key devIds, ML-DSA operations previously fell back to software without verifying callback execution.

Key Changes:

  • wolfcrypt/test/test.c: Added WC_PQC_SIG_TYPE_MLDSA callback handling for keygen, pure/pre-hash signing, and verification, complete with post-test hit counter assertions.
  • .github/configs/pq-all.json: Added cryptocb configurations (verify-only, yes,draft, sign,verify).
  • Signature Verification: Preserves SIG_VERIFY_E error returns matching wc_MlDsaKey_VerifyCtx() behavior.

Note: Software fallback remains for WOLFSSL_MLDSA_NO_CTX due to context ambiguity.

Testing

Validated using testwolfcrypt across multiple build configurations:

  • Default cryptocb ML-DSA build.
  • no-ctx, draft, verify-only, make, sign,verify, single-level, and swdev variants.
  • make check passed with --enable-all --enable-experimental --enable-all-quantum-crypto --enable-cryptocb --enable-cryptocbutils.
  • Clean compilation verified under strict GCC/Clang warning flags (-pedantic, -Wconversion, -Wsign-conversion, -Wcast-qual) with ML-DSA, SLH-DSA, and Falcon enabled concurrently.

@dgarske dgarske self-assigned this Sep 30, 2026
Copilot AI balanced review requested due to automatic review settings September 30, 2026 17:59
@dgarske
dgarske requested a review from anhu September 30, 2026 18:00

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The new pre-hash callback paths are not exercised or independently asserted.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Adds ML-DSA routing validation to wolfCrypt’s crypto callback tests.

Changes:

  • Implements ML-DSA keygen, signing, and verification callback paths.
  • Adds callback hit counters and PQ configuration coverage.
File Description
wolfcrypt/​test/​test.c Adds ML-DSA callback handling and assertions.
.github/​configs/​pq-all.json Adds three ML-DSA callback configurations.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread wolfcrypt/test/test.c
@dgarske
dgarske force-pushed the mldsa_cryptocb branch 2 times, most recently from 29864b4 to 26431dc Compare September 30, 2026 23:54
@dgarske dgarske assigned anhu and wolfSSL-Bot and unassigned dgarske Sep 30, 2026
@anhu
anhu requested review from anhu and wolfSSL-Bot October 1, 2026 21:13
anhu
anhu previously approved these changes Oct 1, 2026
@anhu anhu removed their assignment Oct 1, 2026
@philljj philljj self-assigned this Oct 2, 2026

@philljj philljj left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

merge conflict in test.c

@padelsbach

Copy link
Copy Markdown
Contributor

jenkins retest this please

@dgarske
dgarske requested a review from philljj October 2, 2026 17:54
@dgarske dgarske assigned wolfSSL-Bot and unassigned dgarske Oct 2, 2026
@philljj philljj assigned dgarske and unassigned wolfSSL-Bot Oct 3, 2026
@philljj
philljj merged commit a8d1ab3 into wolfSSL:master Oct 3, 2026
395 of 396 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants