* Fix vector register restore on error paths in Sha3Update().
* Add SP 800-185 check against KMAC_FIPS_MIN_KEY in KmacInit() and
KMAC_FIPS_MIN_OUTPUT in KmacFinal(), returning KMAC_MIN_KEYLEN_E and
BAD_LENGTH_E respectively on failure.
* Use word32 rather than byte for wc_Sha3.i, wc_Cshake.count, wc_Kmac.count, and
related, and add explicit range checking where needed, to fix a -Wconversion,
fix possible overruns, obviate 14 casts, and eliminate (negligible) runtime
overhead from masking and promotions.
* add missing null key checks to wc_ed25519_verify_msg_init(), wc_ed25519_verify_msg_update(), and wc_ed25519_verify_msg_final().
* add WC_ARG_NOT_NULL() attributes to args of static functions as appropriate.
* add FIPS >v6 gates to new null key tests and a new invalid hash size test in test_wc_ed25519_sign_verify_ctx_ph() and test_wc_ed25519_verify_streaming().
wolfssl/wolfcrypt/aes.h: if HAVE_FIPS && !WC_FIPS_AESGCM_ONE_SHOT_EXT_IV_ALLOWED, make wc_AesGcmEncrypt() a WOLFSSL_LOCAL, and if !_WC_BUILDING_AES_C, add a WC_DEPRECATED() attribute to it.
wolfssl/wolfcrypt/wc_compat.h, wolfssl/wolfcrypt/include.am, .wolfssl_known_macro_extras: add wc_compat.h: when HAVE_FIPS and !WC_FIPS_AESGCM_ONE_SHOT_EXT_IV_ALLOWED, shim wc_AesGcmEncrypt() to remap it to FIPS-allowed APIs.
wolfssl/wolfcrypt/types.h: at the end, #ifndef BUILDING_WOLFSSL, #include <wolfssl/wolfcrypt/wc_compat.h>, to assure transparent shimming of wc_AesGcmEncrypt() for all outside callers.
wolfcrypt/src/evp.c, wolfcrypt/src/hpke.c, wolfcrypt/src/pkcs7.c, wolfcrypt/benchmark/benchmark.c, wolfcrypt/test/test.c, wolfssl/ssl.h: #include <wolfssl/wolfcrypt/wc_compat.h> to shim in-library/in-module calls to wc_AesGcmEncrypt().
src/internal.c: in TicketEncDec(), add const attributes to constable input args, and fix swapped out/in in calls to wc_AesGcmEncrypt().
tests/api/test_aes.c: in test_wc_AesGcmEncryptDecrypt(), skip longIV test if WC_TEST_AES_GCM_ENCRYPT_NO_NONSTD_IV (defined by wc_compat.h when needed).
wolfssl/wolfcrypt/error-crypt.h, wolfssl/error-ssl.h, wolfcrypt/src/error.c, src/internal.c:
* add FIPS_WRONG_API_E;
* put several error codes back into sequence in wc_GetErrorString() switch().
* move wc_static_assert()s from headers to corresponding .c files, to eliminate dependency on wolfcrypt/types.h;
* remove unneeded #include <wolfssl/wolfcrypt/types.h> from error-crypt.h.
Added support for encoding and decoding keys in ASN.1.
Added support for X.509 certificates and CSRs.
Generated certificates and CSRs. Not fo FrodoKEM-640 as is not in the specs.
Regenerated the single-precision C sources so that sp_<N>_from_mp() converts
secret inputs (ECDH/ECDSA private keys and nonces) in constant time: a
fixed-count loop bounded by the output size with masked reads at/after
a->used, instead of looping a->used times (which leaked the value's
magnitude through the executed-instruction count).
Fixes the ct-callgrind constant-time failures for P-521 (ec_p521_kex,
ec_p521_sign) and hardens the same pattern across all curves and key sizes
(108 sp_*_from_mp functions in sp_c32/sp_c64, sp_arm32/sp_arm64/sp_armthumb/
sp_cortexm and sp_x86_64).
Verified (--enable-sp, gcc 15.2): ec_p521_kex diff 156 -> 0, ec_p521_sign
diff 367 -> 55 (tol 300); testwolfcrypt RSA/ECC KATs pass.
Generated by https://github.com/wolfSSL/scripts/pull/626
Under DEBUG_WOLFSSL the hash->type != type check in wc_HashUpdate,
wc_HashFinal and wc_HashFree fired for an uninitialized hash
(hash->type == WC_HASH_TYPE_NONE), returning BAD_FUNC_ARG where a non-debug
build returns HASH_TYPE_E from the type switch, so the returned error code
depended on whether DEBUG_WOLFSSL was defined. Only apply the mismatch check
to initialized hashes; the genuine init-then-wrong-type misuse check is
preserved.
```
==485951== Uninitialised value was created by a stack allocation
==485951== at 0x207D47: des3_key_wrap_test (test.c:12773)
```
and
```
==485951== Uninitialised value was created by a stack allocation
==485951== at 0x3A075E: test_wc_AesGcmArgMcdc (test_aes.c:8968)
```
The RISC-V ASM build provides its own AES-GCM implementation
(wolfcrypt/src/port/riscv/riscv-64-aes.c) rather than AES_GCM_decrypt_C, so
it does not clear the output buffer on authentication failure. Exclude it
from the zero-check, matching the other non-C decrypt paths. Fixes the
riscv64 multi-arch testwolfcrypt failure.
Skoll review of the auth-fail zero-check test in aesgcm_test:
- The guard listed WOLFSSL_ARMASM_NO_HW_CRYPTO and __aarch64__, which are
defined on default x86-64 builds, so the zero-check block was compiled out
and the assertion never actually ran there. They are subsumed by
WOLFSSL_ARMASM (the condition under which AES_GCM_decrypt_C is not the
decrypt path), so use that instead and the check runs on the C path.
- Exclude WC_AES_GCM_DEC_AUTH_EARLY (out is not written on an early-auth
failure) and WOLFSSL_ASYNC_CRYPT (a real async device may offload the
decrypt and not clear the output).
Verified: default make check passes with the zero-check now executing;
testwolfcrypt AES-GCM passes with --enable-aesni and with
-DWC_AES_GCM_DEC_AUTH_EARLY.
Review follow-ups for the constant-time AES-GCM decrypt output clear:
- Guard the output-masking pass with #ifndef WC_AES_GCM_DEC_AUTH_EARLY. In
that configuration the tag is verified before decryption and a mismatch
returns before any output is written, so the masking pass is a guaranteed
no-op; skipping it avoids a wasted O(sz) pass.
- Add a test in aesgcm_test: decrypt with a corrupted tag into a pre-filled
buffer and assert wc_AesGcmDecrypt returns AES_GCM_AUTH_E and, on the
software C path, that the output buffer is cleared to zero. The AES-NI/asm
decrypt paths and the FIPS module do not clear the output on auth failure,
so the zero check forces the C path (use_aesni = 0) and is limited to it
(and skipped under HAVE_FIPS). The AES_GCM_AUTH_E comparison uses
WC_NO_ERR_TRACE().
Verified (gcc 15.2): make check passes on the default (C path) build;
testwolfcrypt AES-GCM passes with --enable-aesni and with
-DWC_AES_GCM_DEC_AUTH_EARLY; ct-valgrind aes_gcm reports 0 errors.
AES_GCM_decrypt_C cleared the output on a tag mismatch with
'if (ret != 0) ForceZero(out, sz)'. That is a conditional branch on the
secret-dependent authentication result, which is not constant time and is
flagged by the ct-valgrind constant-time test (Conditional jump depends on
uninitialised value in AES_GCM_decrypt_C).
Mask the output with 'res' (already computed as all-ones on tag mismatch,
zero on match) instead of branching, matching the constant-time idiom used
for the tag comparison itself. C path only; the AES-NI/ASM paths are
unaffected.