Commit Graph
11897 Commits
Author SHA1 Message Date
JacobBarthelmehandGitHub c1ee61c8d1 Merge pull request #10888 from SparkiDev/kmac_cshake
KMAC and cSHAKE: Add new algorithms
2026-07-17 16:49:25 -06:00
JacobBarthelmehandGitHub 25b5636c30 Merge pull request #10808 from aidankeefe2022/fenrir-fixes-jun29-ak
Fix: WolfCrypt 7 fenrir fixes
2026-07-17 15:49:14 -06:00
philljjandGitHub 98f4d6f955 Merge pull request #10721 from JacobBarthelmeh/dev_2
Defensive code additions for sanity checks on input arguments with Base64, PEM write, mp_read_unsigned_bin
2026-07-17 15:34:35 -05:00
JacobBarthelmehandGitHub 6283bd6db8 Merge pull request #10891 from rlm2002/fipsEcc
add mp_clear(order) before freeing in _ecc_import_private_key_ex()
2026-07-17 13:35:41 -06:00
philljjandGitHub dc1c77e079 Merge pull request #10830 from padelsbach/ed25519-cryptocb-only
Add crypto callback only mode for ed25519
2026-07-17 11:42:31 -05:00
Sean Parkinson 78df69d051 FrodoKEM: ASN.1 keys, X.509 certicates
Added support for encoding and decoding keys in ASN.1.
Added support for X.509 certificates and CSRs.
Generated certificates and CSRs. Not fo FrodoKEM-640 as is not in the specs.
2026-07-17 22:38:55 +10:00
Sean Parkinson 607d7cfdb3 FrodoKEM: Initial implementation
Supports Fast C code, small C code, small stack and assembly for x86_64, Aarch64, Aarch32, Thumb2.
2026-07-17 22:38:55 +10:00
jackctj117andGitHub 2c5e135bf9 Merge pull request #10934 from kaleb-himes/ISOLATED-FIXES
Bare minimum change set to stabalize fips-ready
2026-07-16 16:25:34 -06:00
JacobBarthelmehandGitHub 4e27e2ca63 Merge pull request #10893 from SparkiDev/riscv64_asm_1
RISC-V 64-bit: rework assembly code.
2026-07-16 16:10:46 -06:00
JacobBarthelmehandGitHub 5418d6cfdc Merge pull request #10927 from danielinux/fix-error-consistency-with-debug
Hash: consistent error code for uninitialized wc_Hash ops under DEBUG_WOLFSSL
2026-07-16 15:06:51 -06:00
kaleb-himes 432d5e375d Bare minimum change set to stabalize fips-ready 2026-07-16 11:03:07 -06:00
Aidan Keefe 15d2b469e0 https://fenrir.wolfssl.com/finding/6438
https://fenrir.wolfssl.com/finding/5414

https://fenrir.wolfssl.com/finding/5414

https://fenrir.wolfssl.com/finding/5415

https://fenrir.wolfssl.com/finding/6165

https://fenrir.wolfssl.com/finding/6167

https://fenrir.wolfssl.com/finding/6177

https://fenrir.wolfssl.com/finding/6166

skoll issues
2026-07-16 11:01:48 -06:00
JacobBarthelmehandGitHub 08539e40a6 Merge pull request #10903 from miyazakh/f_issues_SCE
[Renesas RA6M4] Fix Renesas RA6M4 SCE session-key generation issues
2026-07-16 10:04:52 -06:00
Sean Parkinson 3606633b22 RISC-V 64-bit: rework assembly code.
Assembly code generated from scripts.
Have separate assembly files and new inline code.
2026-07-16 09:39:09 +10:00
Daniele Lacamera 546b78c14c hash: consistent error code for uninitialized wc_Hash ops under debug
Under DEBUG_WOLFSSL the hash->type != type check in wc_HashUpdate,
wc_HashFinal and wc_HashFree fired for an uninitialized hash
(hash->type == WC_HASH_TYPE_NONE), returning BAD_FUNC_ARG where a non-debug
build returns HASH_TYPE_E from the type switch, so the returned error code
depended on whether DEBUG_WOLFSSL was defined. Only apply the mismatch check
to initialized hashes; the genuine init-then-wrong-type misuse check is
preserved.
2026-07-15 23:44:40 +02:00
Daniel PouzznerandGitHub fc74ebdc74 Merge pull request #10885 from philljj/fips_v7_guards
random.c: fix fips v7 define guards.
2026-07-15 16:34:22 -05:00
JacobBarthelmehandGitHub 05c84bcd94 Merge pull request #10908 from LinuxJedi/valgrind-fixes
Fix a couple of Valgrind hits
2026-07-15 15:27:49 -06:00
Tobias FrauenschlägerandDaniele Lacamera 9d86960672 Fix AES GCM decrypt auth tag failure test 2026-07-15 15:10:52 +02:00
Andrew Hutchings 8066fbceaa Fix a couple of Valgrind hits
```
==485951==  Uninitialised value was created by a stack allocation
==485951==    at 0x207D47: des3_key_wrap_test (test.c:12773)
```

and

```
==485951==  Uninitialised value was created by a stack allocation
==485951==    at 0x3A075E: test_wc_AesGcmArgMcdc (test_aes.c:8968)
```
2026-07-15 11:28:45 +01:00
Tobias FrauenschlägerandGitHub 986fed770c Merge pull request #10907 from SparkiDev/asm_include_fix
Include the correct wolfSSL header for inline C asm.
2026-07-15 10:44:47 +02:00
Tobias FrauenschlägerandGitHub c327ea36bf Merge pull request #10904 from aidangarske/fix/pkcs7-stream-signed-content
Fix PKCS7 streamed SignedData dropping content
2026-07-15 09:43:34 +02:00
Sean Parkinson b0dfa35bbe Include the correct wolfSSL header for inline C asm.
wolfssl/wolfcrypt/libwolfssl_sources_asm.h is for assembly files.
wolfssl/wolfcrypt/libwolfssl_sources.h is for C files.
2026-07-15 17:40:19 +10:00
Tobias FrauenschlägerandGitHub 2494da4a46 Merge pull request #10895 from danielinux/aes-gcm-fix-ct-compare
AES-GCM: constant-time output clear on decrypt auth failure
2026-07-15 08:54:27 +02:00
aidan garske 9b1aad457d Fix PKCS7 streamed SignedData dropping content 2026-07-14 16:47:31 -07:00
JacobBarthelmehandGitHub 26538a252c Merge pull request #10884 from kareem-wolfssl/zd22127_2
Adjust wolfEntropy size calculation and error out if an invalid combination of settings is given.
2026-07-14 16:12:50 -06:00
Hideki Miyazaki c0c2588baf addressed review comments 2026-07-15 06:03:03 +09:00
Hideki Miyazaki 3fac5bf57b Addressed comments 2026-07-15 06:03:03 +09:00
Hideki Miyazaki 36a9e4404e fix fenrir issues for Renesas SCE 2026-07-15 06:03:02 +09:00
Daniele Lacamera 3ad29463ff test: exclude WOLFSSL_RISCV_ASM from AES-GCM auth-fail zero-check
The RISC-V ASM build provides its own AES-GCM implementation
(wolfcrypt/src/port/riscv/riscv-64-aes.c) rather than AES_GCM_decrypt_C, so
it does not clear the output buffer on authentication failure. Exclude it
from the zero-check, matching the other non-C decrypt paths. Fixes the
riscv64 multi-arch testwolfcrypt failure.
2026-07-14 20:17:48 +02:00
Daniele Lacamera 601ad77e15 test: fix AES-GCM auth-fail zero-check guard (review + run on x86)
Skoll review of the auth-fail zero-check test in aesgcm_test:

- The guard listed WOLFSSL_ARMASM_NO_HW_CRYPTO and __aarch64__, which are
  defined on default x86-64 builds, so the zero-check block was compiled out
  and the assertion never actually ran there. They are subsumed by
  WOLFSSL_ARMASM (the condition under which AES_GCM_decrypt_C is not the
  decrypt path), so use that instead and the check runs on the C path.

- Exclude WC_AES_GCM_DEC_AUTH_EARLY (out is not written on an early-auth
  failure) and WOLFSSL_ASYNC_CRYPT (a real async device may offload the
  decrypt and not clear the output).

Verified: default make check passes with the zero-check now executing;
testwolfcrypt AES-GCM passes with --enable-aesni and with
-DWC_AES_GCM_DEC_AUTH_EARLY.
2026-07-14 19:53:01 +02:00
Paul Adelsbach d8e26d713e Fix test issues in ed25519 2026-07-14 09:08:12 -07:00
Paul Adelsbach cd0f29b690 Add missing (void) on unused param in wc_ed25519_sign_msg_ex 2026-07-14 09:08:12 -07:00
Paul Adelsbach e109a3b070 Adjust location of WOLFSSL_EDDSA_CHECK_PRIV_ON_SIGN in ed25519_sign 2026-07-14 09:08:12 -07:00
Paul Adelsbach c3750d28be Add make_pub and check_key hooks for ed25519 cryptocb only 2026-07-14 09:08:12 -07:00
Paul Adelsbach bba8b5ffdd Add missing checks for WOLF_CRYPTO_CB_ONLY_ED25519, add test case for no swdev 2026-07-14 09:08:12 -07:00
Paul Adelsbach 5e784db069 Add crypto callback only mode for ed25519 2026-07-14 09:08:12 -07:00
JacobBarthelmehandGitHub 6722de5635 Merge pull request #10882 from kareem-wolfssl/zd22127
Use safe sum in PKCS7_VerifySignedData.
2026-07-14 10:00:50 -06:00
JacobBarthelmehandGitHub 7b501242b8 Merge pull request #10876 from danielinux/mcdc-test-coverage
Mcdc test coverage campaign - part 2
2026-07-14 09:59:45 -06:00
Daniele Lacamera 23ad1c1d7a AES-GCM: skip output clear for AUTH_EARLY; test auth-fail output zeroing
Review follow-ups for the constant-time AES-GCM decrypt output clear:

- Guard the output-masking pass with #ifndef WC_AES_GCM_DEC_AUTH_EARLY. In
  that configuration the tag is verified before decryption and a mismatch
  returns before any output is written, so the masking pass is a guaranteed
  no-op; skipping it avoids a wasted O(sz) pass.

- Add a test in aesgcm_test: decrypt with a corrupted tag into a pre-filled
  buffer and assert wc_AesGcmDecrypt returns AES_GCM_AUTH_E and, on the
  software C path, that the output buffer is cleared to zero. The AES-NI/asm
  decrypt paths and the FIPS module do not clear the output on auth failure,
  so the zero check forces the C path (use_aesni = 0) and is limited to it
  (and skipped under HAVE_FIPS). The AES_GCM_AUTH_E comparison uses
  WC_NO_ERR_TRACE().

Verified (gcc 15.2): make check passes on the default (C path) build;
testwolfcrypt AES-GCM passes with --enable-aesni and with
-DWC_AES_GCM_DEC_AUTH_EARLY; ct-valgrind aes_gcm reports 0 errors.
2026-07-14 17:12:42 +02:00
Daniele Lacamera 9dffa3ce63 AES-GCM: constant-time output clear on decrypt auth failure
AES_GCM_decrypt_C cleared the output on a tag mismatch with
'if (ret != 0) ForceZero(out, sz)'. That is a conditional branch on the
secret-dependent authentication result, which is not constant time and is
flagged by the ct-valgrind constant-time test (Conditional jump depends on
uninitialised value in AES_GCM_decrypt_C).

Mask the output with 'res' (already computed as all-ones on tag mismatch,
zero on match) instead of branching, matching the constant-time idiom used
for the tag comparison itself. C path only; the AES-NI/ASM paths are
unaffected.
2026-07-14 10:43:25 +02:00
Daniel PouzznerandGitHub e87f7e83c7 Merge pull request #10867 from philljj/wc_const_comp
memory.c: add wc_ConstantCompare wrapper.
2026-07-14 00:57:47 -05:00
philljjandGitHub ef50d85430 Merge pull request #10881 from douzzer/20260710-linuxkm-fixes
20260710-linuxkm-fixes
2026-07-13 22:22:42 -05:00
Daniel Pouzzner 2cf826f03d KCAPI and linuxkm fixes from peer review:
linuxkm/lkcapi_aes_glue.c: zero the ephemeral ivOut in AesGcmCrypt_1().

wolfcrypt/src/port/kcapi/kcapi_aes.c: tighten the test on the return value from kcapi_aead_decrypt().
2026-07-13 17:12:20 -05:00
jordan 3c06b0e6db random.c: correct comment per review. 2026-07-13 12:13:58 -05:00
Mattia MoffaandGitHub 0568743c55 Merge pull request #10880 from dgarske/stm32_bare2
Fix STM32 DHUK AES-CBC in-place decrypt chaining IV and correct stale CTR comment
2026-07-13 18:03:33 +02:00
Daniele Lacamera d868aa2299 sha: reorder update arg guards to make the empty-update decision coverable
wc_ShaUpdate, wc_Sha3Update, wc_Shake128_Update and wc_Shake256_Update
guarded inputs as:
    if (obj == NULL || (data == NULL && len > 0)) return BAD_FUNC_ARG;
    if (data == NULL && len == 0) return 0;
The first guard rejected (data==NULL, len>0) before the second decision,
so that decision's len==0 condition could only ever be observed true --
its MC/DC independence pair was structurally unreachable.

Reorder to the same idiom sha256.c/sha512.c already use:
    if (obj == NULL) return BAD_FUNC_ARG;
    if (data == NULL && len == 0) return 0;   /* (NULL,len>0) now reaches: len==0 false */
    if (data == NULL) return BAD_FUNC_ARG;
Behavior is identical for every input; the existing DIGEST_UPDATE_TEST
cases wc_*Update(&dgst, NULL, 1) and (&dgst, NULL, 0) now exercise both
sides of the decision. Closes the four guard-ordering MC/DC residuals in
the sha campaign module (sha.c and sha3.c).
2026-07-13 11:19:23 +02:00
Sean Parkinson 136e8da738 KMAC and cSHAKE: Add new algorithms
Add KMAC and cSHAKE as defined in SP 800-185.
Fixed the SHA-3 assembly usage on AMD chips to use the faster BMI version.
2026-07-13 17:48:56 +10:00
Tobias FrauenschlägerandGitHub 54694f9264 Merge pull request #10887 from night1rider/fix-benchmark
Clamp benchmark numBlocks to at least 1 so large block sizes still run.
2026-07-13 08:54:02 +02:00
Tobias FrauenschlägerandGitHub 4ab0a87f36 Merge pull request #10889 from SparkiDev/regression_fixes_27
Fixes from regression testing
2026-07-13 08:47:02 +02:00
Sean Parkinson a6e4bb79ba Fixes from regression testing
test.c: moved flattenAltNames_test to have appropriate guards
api.c: Updated guards around calls in test_wolfSSL_session_cache_api_direct
2026-07-13 10:49:43 +10:00