Skip to content

SLH-DSA: accept (NULL, 0) message in SignWithRandom/SignDeterministic - #11641

Draft
Arpan0995 wants to merge 1 commit into
wolfSSL:masterfrom
Arpan0995:slhdsa-signwithrandom-empty-msg
Draft

Arpan0995 wants to merge 1 commit into
wolfSSL:masterfrom
Arpan0995:slhdsa-signwithrandom-empty-msg

Conversation

@Arpan0995

Copy link
Copy Markdown

Description

Commit 916de9c (#11381) made the sign and verify entry points accept an empty message passed as (NULL, 0). #11055, merged after it, added crypto callback support to wc_SlhDsaKey_SignWithRandom() together with an argument check of its own, and that check rejects msg == NULL for any length. As a result, wc_SlhDsaKey_SignWithRandom() and wc_SlhDsaKey_SignDeterministic(), which calls it, return BAD_FUNC_ARG for (NULL, 0), while wc_SlhDsaKey_Sign() and wc_SlhDsaKey_Verify() accept it. Both commits are in v5.9.4-stable.

This uses the same check as wc_SlhDsaKey_Sign(), so a NULL msg is rejected only when msgSz is not 0. As in Sign() and Verify(), a NULL message is then replaced with a one-byte static stand-in before the crypto callback dispatch, so devices and the hash code never see a NULL pointer. The stand-in is a one-element array to match the Coverity ARRAY_VS_SINGLETON change in #11457. The doxygen for SignDeterministic, SignWithRandom, Sign and Verify, and the source comments for the first two, are updated to match.

Testing

./configure --enable-slhdsa --enable-cryptocb
make
./wolfcrypt/test/testwolfcrypt
./tests/unit.test --api --group slhdsa

and the same with:

./configure --enable-slhdsa --enable-cryptocb --enable-smallstack \
    --disable-shared \
    CFLAGS="-O1 -g -fsanitize=address,undefined -fno-sanitize-recover=undefined" \
    LDFLAGS="-fsanitize=address,undefined"
  • wolfcrypt/test/test.c: the SHAKE128F empty-message block in slhdsa_test_param() now also signs with wc_SlhDsaKey_SignDeterministic(NULL, 0) and verifies the result with wc_SlhDsaKey_Verify(NULL, 0). With --enable-cryptocb this also runs under the crypto callback test.
  • tests/api/test_slhdsa.c: test_wc_SlhdsaDecisionCoverage() calls SignWithRandom() with (NULL, 0) and a too-small sigSz, which now passes the argument check and returns BAD_LENGTH_E. The existing msg == NULL probe with a nonzero msgSz still expects BAD_FUNC_ARG.

Without the wc_slhdsa.c change, both new checks fail with BAD_FUNC_ARG. With it, testwolfcrypt (including the crypto callback test) and the slhdsa API group pass in both builds. Tested on macOS (arm64) with Apple clang.

Checklist

  • added tests
  • updated/added doxygen
  • updated appropriate READMEs
  • Updated manual and documentation

wc_SlhDsaKey_SignWithRandom() rejected msg == NULL for any length, so it
and wc_SlhDsaKey_SignDeterministic() returned BAD_FUNC_ARG for an empty
message passed as (NULL, 0), unlike wc_SlhDsaKey_Sign() and Verify().
Use the same check as Sign() and, like Sign(), replace a NULL message
with a one-byte static stand-in before the crypto callback dispatch.
Update the doxygen and source comments, and add tests for the (NULL, 0)
case.
Copilot AI balanced review requested due to automatic review settings October 3, 2026 14:20
@wolfSSL-Bot

Copy link
Copy Markdown

Can one of the admins verify this patch?

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The implementation safely aligns API behavior, callback handling, tests, and documentation without unresolved issues.

Review effort: Balanced
Findings: None

What changed in this PR

Enables SLH-DSA randomized and deterministic signing APIs to accept empty messages as (NULL, 0), aligning them with existing sign/verify behavior.

Changes:

  • Permits and safely canonicalizes (NULL, 0) messages before callback dispatch.
  • Adds round-trip and argument-validation coverage.
  • Updates public and source documentation.
File Description
wolfcrypt/​src/​wc_slhdsa.c Updates validation and empty-message handling.
wolfcrypt/​test/​test.c Adds deterministic empty-message round-trip coverage.
tests/​api/​test_slhdsa.c Tests argument-check behavior for (NULL, 0).
doc/​dox_comments/​header_files/​wc_slhdsa.h Documents accepted empty-message semantics.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants