Skip to content

Add crypto callback for wc_falcon_check_key - #11640

Open
padelsbach wants to merge 1 commit into
wolfSSL:masterfrom
padelsbach:falcon-cb-check-key
Open

padelsbach wants to merge 1 commit into
wolfSSL:masterfrom
padelsbach:falcon-cb-check-key

Conversation

@padelsbach

Copy link
Copy Markdown
Contributor

Description

Previously, wc_falcon_check_key() did not dispatch to the crypto callback. This sends the check to the callback as WC_PK_TYPE_PQC_SIG_CHECK_PRIV_KEY with WC_PQC_SIG_TYPE_FALCON, matching `wc_SlhDsaKey_CheckKey()

Testing

added unit tests

Checklist

  • added tests
  • updated/added doxygen
  • updated appropriate READMEs
  • Updated manual and documentation

Copilot AI balanced review requested due to automatic review settings October 3, 2026 03:55
@padelsbach
padelsbach force-pushed the falcon-cb-check-key branch from 0f64053 to 800b2b8 Compare October 3, 2026 03:57

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The new test fails in supported Falcon level-5-only builds, and the public API documentation remains outdated.

Review effort: Balanced
Findings: 1 Low severity

Open (1)
What changed in this PR

Adds Falcon private-key validation support to the crypto callback framework.

Changes:

  • Dispatches wc_falcon_check_key() through the Falcon crypto callback.
  • Adds callback behavior and fallback tests.
  • Updates internal return-value documentation.
File Description
wolfcrypt/​src/​falcon.c Adds Falcon key-check callback dispatch.
wolfcrypt/​test/​test.c Adds callback-path and error-handling tests.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread wolfcrypt/src/falcon.c
* PUBLIC_KEY_E when either half is not set, or when the stored public
* key h does not satisfy the defining relation h = g/f (mod q) for the
* private (f, g),
* private (f, g), the crypto callback result for a device backed key,
@padelsbach

Copy link
Copy Markdown
Contributor Author

jenkins retest this please

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants