Commit Graph
1066 Commits
Author SHA1 Message Date
Tobias FrauenschlägerandGitHub b844cdcce0 Merge pull request #10421 from kojo1/pha
TLS 1.3 PHA with OCSP Stapling
2026-07-31 09:07:29 +02:00
Daniel PouzznerandGitHub 8ec8bd6876 Merge pull request #11015 from SparkiDev/asm_fixes_5
RISC-V 64-bit assembly: AES-GCM decrypt fix
2026-07-30 18:20:14 -05:00
David GarskeandGitHub 643d209dba Merge pull request #10961 from anhu/crl_unknown_ext
New API for CRL unknown extension callback
2026-07-30 09:00:23 -07:00
Sean Parkinson e9d411ed09 RISC-V 64-bit assembly: AES-GCM decrypt fix
Fix for when decrypting into the same buffer.

Also fixed test on PPC64/32.
2026-07-30 16:50:52 +10:00
Daniel PouzznerandGitHub f69903778f Merge pull request #11001 from SparkiDev/regression_fixes_28
Regression testing fixes
2026-07-29 22:02:19 -05:00
Sean Parkinson 119901c227 Regression testing fixes
wc_mlkem.h/test_mlkem.c: Respect WC_NO_CONSTRUCTORS guard.

settings.h, fe_operations.h: move WOLFSSL_CURVE25519_USE_ED25519 derivation into settings.h so the assembler sees it; fixes fe_cmov_table undefined on ARM32.

ge_448.c: shift the product instead of the byte in six sc448_* loops, dodging a GCC ARM32 NEON miscompile that produced wrong ed448 signatures; table shrunk [56]→[28].
2026-07-29 14:59:47 +10:00
Sean ParkinsonandGitHub 9c5436b853 Merge pull request #10968 from Frauschi/fenrir_tls
Fenrir fixes
2026-07-28 11:31:19 +10:00
Sean ParkinsonandGitHub 495296a739 Merge pull request #10625 from julek-wolfssl/client-custom-ext
Add SSL_CTX_add_client_custom_ext (OpenSSL-compat client custom extensions)
2026-07-28 09:22:47 +10:00
Daniel Pouzzner 1693b08b3e tests/api/test_kdf.c: fix NO_SHA in test_wc_KdfFeatureCoverage(). 2026-07-24 16:39:55 -05:00
Daniel Pouzzner 142109db24 test/:
* fixes for NO_DH;
* fixes in test_wc_ed448_import_public() and test_wc_Ed448DecisionCoverage() for FIPS v6;
* fixes in tests/api/test_sha3.c for KMAC keysize in FIPS builds.
2026-07-24 16:39:54 -05:00
JacobBarthelmehandGitHub acff4d62a1 Merge pull request #10883 from night1rider/Extend-ECIES
Add AES-GCM DEM, CryptoCb support, and devId threading to ECIES
2026-07-24 14:02:32 -06:00
Anthony Hu 73f1a7b665 More tests 2026-07-24 14:34:17 -04:00
night1rider 3062dea0b6 Use the existing KEY32 macro and a named fake overhead constant in the new ECIES tests 2026-07-24 10:21:20 -06:00
night1rider c00e7260be Add AES-GCM DEM, CryptoCb support, and devId threading to ECIES
Add AES-GCM (128/256) as an ECIES DEM next to the AES-CBC/CTR+HMAC modes. Only the encryption key comes from the KDF; the mac salt is bound as GCM AAD and the 16-byte tag replaces the HMAC. The GCM DEM honors all three IV build modes, and default fixed-nonce GCM is gated behind the new WOLFSSL_ECIES_STATIC_GCM_NONCE opt-in. Adds ECIES CryptoCb encrypt/decrypt, the WOLF_CRYPTO_CB ctx getters, devId/heap threading into the DEM primitives, and test/benchmark/CI coverage.
2026-07-24 10:19:40 -06:00
Sean ParkinsonandGitHub 674a77b5a1 Merge pull request #10953 from embhorn/zd22167
Bound CKS extension allocation in TLSX_CKS_Parse
2026-07-24 10:40:29 +10:00
Sean ParkinsonandGitHub 15afad7f8f Merge pull request #10902 from rlm2002/coverity
2020714 Coverity fixes
2026-07-24 10:38:13 +10:00
Sean ParkinsonandGitHub 2b90784463 Merge pull request #10952 from embhorn/zd22171
Fix off-by-one OOB NUL write in GetCertName (classic ASN parser)
2026-07-24 10:37:30 +10:00
Sean ParkinsonandGitHub f7571db708 Merge pull request #10896 from julek-wolfssl/julek-dev/openvpn-set0-crls
X509_STORE_CTX_set0_crls: implement for OpenVPN
2026-07-24 10:18:40 +10:00
Sean ParkinsonandGitHub 3254e75598 Merge pull request #10811 from kareem-wolfssl/gh10746
Correct alert type for missing supported_versions in HRR and avoid sending duplicate protocol_version alerts.
2026-07-24 09:45:14 +10:00
Sean ParkinsonandGitHub 98edc78599 Merge pull request #10769 from rizlik/dtls13_max_handshake_sz
dtls13: add check over handshake message length
2026-07-24 09:35:37 +10:00
Sean ParkinsonandGitHub 7b829b92b7 Merge pull request #10777 from gasbytes/rsa-pkcs-v1.5-negative-test
RSA pkcs#1 v1.5 negative tests
2026-07-24 08:56:24 +10:00
Anthony Hu 8b0e0b9683 New API for CRL unknown extension callback
Adds public entry points mirroring the existing X.509 unknown extension callback so callers can register a handler for unrecognized CRL extensions instead of failing with ASN_CRIT_EXT_E.
2026-07-23 15:30:16 -04:00
Sean ParkinsonandGitHub e6c3bb4403 Merge pull request #10827 from danielinux/falcon-native
Falcon: native implementation replacing liboqs, with crypto callbacks and ARM acceleration. Deprecate liboqs support.
2026-07-23 21:17:10 +10:00
Takashi Kojo 60817b08c6 Fix repeated TLS 1.3 PHA over write_dup 2026-07-23 07:46:13 +09:00
Takashi Kojo 6d0dca2950 Post handsake authentication with client end OCSP 2026-07-23 07:42:20 +09:00
David GarskeandGitHub 983e1090d7 Merge pull request #10922 from aidangarske/fenrir-asn-strict
Enforce RFC 5280 extension MUSTs under WOLFSSL_NO_ASN_STRICT and validate DTLS 1.3 legacy_session_id echo
2026-07-22 14:12:33 -07:00
Juliusz Sosinowicz ccc8068b05 X509_STORE_CTX_set0_crls: implement for OpenVPN
OpenVPN master keeps CRLs in its own stack and passes them to each
verification with X509_STORE_CTX_set0_crls from its cert verify
callback. CRLs are no longer loaded into the store.

- Add wolfSSL_X509_STORE_CTX_set0_crls. The ctx borrows the stack.
- Check the ctx CRLs in X509StoreVerifyCert. They can revoke a cert the
  CertManager accepted and can satisfy the CRL requirement when the
  CertManager has no CRL loaded. The check runs after the date override
  handling so that a revocation is not masked by an overridden date
  error. A stale CRL in the stack does not fail the check when another
  CRL vouches for the cert.
- Add CheckCertCRLFromCm to check a cert against a caller-owned CRL
  using the cm of the store for CRL signature verification. The CRL
  object is not modified and the cached verification result of the
  entries is not used because it is only valid for the owning cm.
- Pass the good result of the cert verify callback to the following
  verify callbacks in DoVerifyCallback. In OpenSSL the cert verify
  callback replaces chain verification so the verify callbacks only see
  its result. OpenVPN needs this to run its per-cert verification.
- Re-add OpenVPN master to CI testing.
2026-07-22 13:31:03 +02:00
Tobias Frauenschläger 64271d24ec Send unexpected_message alert on EndOfEarlyData in DTLS 1.3
RFC 9147 section 5.6.1 states that EndOfEarlyData is not used in DTLS 1.3
and that a receiver must terminate the connection with an
unexpected_message alert. Dtls13CheckEpoch grouped end_of_early_data into
the default case that returns SANITY_MSG_E without sending any alert, and
the DTLS 1.3 handshake dispatch in DoProcessReplyEx did not send a fatal
alert on error the way the DTLS 1.2 path does, so the connection was
dropped silently. Add an explicit end_of_early_data case that sends the
unexpected_message alert, and mirror the DTLS 1.2 SendFatalAlertOnly
handling in the DTLS 1.3 dispatch so other handshake errors are also
reported rather than dropped silently.

Fixes F-6987.
2026-07-22 13:07:55 +02:00
Tobias Frauenschläger d350914231 Enforce attribute certificate validity period in VerifyX509Acert
VerifyX509Acert parsed the acert and checked the signature but never
validated the notBefore and notAfter dates, so wolfSSL_X509_ACERT_verify
and wc_VerifyX509Acert accepted expired or not-yet-valid attribute
certificates whenever the signature was good. Call CheckDate for both
validity bounds before signature verification. CheckDate returns the
proper date error and honors the runtime skip-date control. Also correct
ParseX509Acert to report ASN_AFTER_DATE_E instead of ASN_BEFORE_DATE_E
when the notAfter date check fails.

Fixes F-6986.
2026-07-22 13:07:55 +02:00
Daniele Lacamera 0030571532 Falcon: guard private-key export on prvKeySet, and test it
wc_falcon_export_private_only and wc_falcon_export_private did not check
prvKeySet, so exporting from a key with only a level set copied the
uninitialized key->k and returned 0 -- unlike wc_falcon_export_public, which
guards on pubKeySet. Add the matching prvKeySet guard to both (before the
length check), and cover it in test_wc_falcon_error_paths alongside the
existing export_public no-key case. The prior test could not exercise the
guard because the guard did not exist.
2026-07-22 09:52:27 +02:00
Daniele Lacamera 9fc9b181eb Falcon: address third round of review feedback (doc/naming/test)
- wc_falcon.c: replace the stale "Phase 1: verification only" file banner
  (the file now holds keygen/sign/verify cores).
- falcon.c: fix the garbled wc_falcon_verify_msg doc comment (removed a
  non-existent contextLen parameter; state the level-dependent BUFFER_E
  bound and the *res convention).
- wc_falcon.c: name the sign compression-fit retry bound
  FALCON_SIGN_MAX_ENCODE_RETRIES (was a bare 32) and document why the
  bound is safe, mirroring FALCON_SIGN_MAX_RESTARTS in wc_falcon_sign.c.
- test_falcon.c: add a direct wc_falcon_import_private_only concat(priv,pub)
  test that recovers the public key and signs+verifies from that single
  import, covering the recover-pub-from-concat path end to end.
2026-07-22 09:52:27 +02:00
Daniele Lacamera d7275eb1ad Falcon: drop last HAVE_LIBOQS reference (check-source-text)
test_wc_falcon_sign_verify in tests/api/test_signature.c was merged to
master gated on HAVE_FALCON && HAVE_LIBOQS.  With liboqs removed the
macro is defined nowhere, so the test was dead code and check-source-text
failed with 'unrecognized macros used: HAVE_LIBOQS'.

Gate it on WC_FALCON_HAVE_NATIVE_SIGN like the rest of the native
signing tests, and replace the obsolete liboqs-RNG comment.  The tree
now has zero HAVE_LIBOQS references, so no .wolfssl_known_macro_extras
entry is needed.
2026-07-22 09:52:26 +02:00
Daniele Lacamera a311654d45 Falcon: address review findings (zeroization, PRNG errors, check_key)
Remaining fixes from the second review round:

- keygen: falcon_compute_public's scratch buffer holds NTT(f) (private-key
  material) in its tail; wc_ForceZero it before both frees (the
  f-not-invertible reject path and the success path). Also zeroize the
  internally allocated hwork for consistency with the tmpbuf hardening.

- sampler: falcon_sampler_z's rejection loop never consulted the sticky
  PRNG error flag, so a mid-signature SHAKE256 squeeze failure could make
  berexp deterministically reject and the loop spin forever. Check p.err
  each iteration and bail out; the returned value is discarded since
  falcon_sign_core rejects the whole signature once p.err is set.
  falcon_prng_init now frees the SHAKE256 context when a later init step
  fails (plugs a device-context leak in WOLFSSL_ASYNC_CRYPT builds), and
  falcon_prng_refill early-returns once the error is latched instead of
  re-issuing failing squeezes.

- codec: guard the bits-dependent shifts in falcon_trim_i8_encode/decode
  against out-of-range widths (defense in depth; callers only pass 5..8).

- check_key: implement the cryptographic private/public cross-check that
  91ebd89d7 documented as a follow-up. New falcon_native_check_key decodes
  (f, g) from the private key and h from the public key and verifies the
  defining relation h*f == g (mod q, mod X^n + 1) slot-wise in the NTT
  domain (falcon_ntt keeps values canonical in [0, q)); a slot with
  NTT(f) == 0 is rejected too, as keygen only emits invertible f.
  wc_falcon_check_key dispatches to it whenever the native signing core is
  compiled in, and falls back to the presence check in verify-only /
  callback-only builds. Doxygen updated to the actual contract, and a unit
  test added: a mismatched pair (public half from a different key) must
  fail with PUBLIC_KEY_E. This also strengthens the keypair validation
  done via wc_falcon_check_key in asn.c.
2026-07-22 09:52:26 +02:00
Daniele Lacamera 493bc46cb7 Falcon: address review feedback (zephyr sources, configure sub-options, footprint)
Four fixes from PR review:

- zephyr/CMakeLists.txt: the native port split falcon.c into wc_falcon_*.c
  translation units; add the portable sources so a Zephyr build with Falcon
  links. x86-64 asm/AVX2 and the NEON backend are left out (not selected by any
  Zephyr config).

- configure.ac: fold the standalone --enable-falcon-{asm,double,avx2,neon}
  switches into comma-separated sub-options of --enable-falcon
  (e.g. --enable-falcon=avx2), matching the common wolfSSL idiom. avx2/neon
  imply the double backend after arch-gating so ignoring an unsupported vector
  backend does not clobber an explicit 'double'. Sweep the qemu-falcon-neon doc
  to the new spelling.

- configure.ac: align the Falcon line in the two feature summaries.

- falcon.c/falcon.h: drop the duplicate public-key copy kept behind the private
  key. Its only remaining reader was wc_falcon_check_key, whose compare was
  against a copy of the same bytes and so could never detect a real mismatch;
  wc_falcon_export_private already rebuilds the concat layout on demand. Shrink
  key->k from FALCON_MAX_PRV_KEY_SIZE to FALCON_MAX_KEY_SIZE (saves 1793 bytes
  per key at level 5). check_key now verifies both halves are present and
  documents a full cryptographic cross-check as a follow-up. Update the unit
  test that relied on the old in-memory-copy compare.
2026-07-22 09:52:26 +02:00
Daniele Lacamera 15430f6e1c Falcon: address Fenrir review findings
- falcon.c (wc_falcon_import_private_only): call falcon_store_pub_behind_priv
  unconditionally after setting prvKeySet. The raw-size branch previously only
  synced the behind-private public copy in the concat layout, so importing a
  public key first and then a raw private key left key->k + KEY_SIZE zero and
  made wc_falcon_check_key return a false PUBLIC_KEY_E. Added a regression case
  to test_wc_falcon_check_key covering the public-then-raw-private ordering.
- wc_falcon.c (native sign cleanup): free the sampler's SHAKE256 context with
  wc_Shake256_Free(&spc.p.shake) when it was initialized, before ForceZero.
  Without it, WOLFSSL_ASYNC_CRYPT + WC_ASYNC_ENABLE_SHA3 builds leaked the
  async device context allocated by wc_InitShake256 on every sign, unlike the
  keygen and hash-to-point paths which already free their SHAKE contexts.
2026-07-22 09:52:26 +02:00
Daniele Lacamera 75b7b1b366 Falcon: add tests/api/test_falcon.c API unit tests
Falcon had crypto-level coverage (KAT + native round-trip in
wolfcrypt/test/test.c) but, unlike ML-DSA and SLH-DSA, no dedicated
tests/api/ unit test exercising the public wc_falcon_* / wc_Falcon_* API
surface. This adds one, wired into the unit test runner as the "falcon"
group.

Coverage (both Falcon-512 / L1 and Falcon-1024 / L5, which are always
compiled together):
- sizes:        size/priv_size/pub_size/sig_size vs the spec constants,
                get_level round-trip, and NULL / unset-level rejection.
- make_key:     NULL and unset-level rejection; real keygen -> check_key.
- sign_vfy:     sign -> verify; wrong-message and one-byte tamper rejected;
                too-small buffer -> BUFFER_E with the required length set;
                verify with no public key -> BAD_FUNC_ARG.
- import_export: public / private-only (raw) / private (concat) / export_key
                round-trips, each re-signed or verified, plus too-small
                (BUFFER_E) and wrong-size (BAD_FUNC_ARG) paths.
- check_key:    valid pass; corrupted public copy, public-only and
                private-only keys all fail (PUBLIC_KEY_E); NULL rejected.
- der:          KeyToDer / PrivateKeyToDer / PublicKeyToDer round-trips via
                PrivateKeyDecode / PublicKeyDecode, size-query (NULL output),
                and the SetAsymKeyDer too-small contract (BAD_FUNC_ARG).
- error_paths:  exhaustive NULL / bad-level / wrong-size / no-key-set
                argument sanitising for every public entry point.

Tests requiring key generation or signing are gated on
WC_FALCON_HAVE_NATIVE_SIGN so the file also builds in
WOLFSSL_FALCON_VERIFY_ONLY and WOLF_CRYPTO_CB_ONLY_FALCON configurations;
size and argument-sanitising tests run in every HAVE_FALCON build.

Verified: 7/7 pass under both --enable-falcon-avx2 and the default
constant-time build; compiles clean with WOLFSSL_FALCON_VERIFY_ONLY.
2026-07-22 09:52:26 +02:00
Lealem Amedie 9548753bb3 Remove embedding of macros within a function call 2026-07-21 18:40:13 -06:00
Kareem 27657088e7 Unify alert sent when HRR does not contain supported_versions to missing_extension.
Run truncated extensions check in DoTls13ServerHello regardless of downgrade flag state.
2026-07-21 16:54:23 -07:00
Kareem 459905e1ab Also handle alerts for alternate DoTls13ServerHello call path.
Fix incorrect illegal_parameter alert for missing supported_versions.  This is a missing extension rather than an extra/unexpected extension.
2026-07-21 16:32:32 -07:00
Lealem Amedie 527154dc85 Testing: AES GCM opps with IV < 96-bits now returns WC_FIPS_NOT_APPROVED with FIPS 2026-07-21 13:59:57 -06:00
Ruby Martin 33f37b9836 initialize uninitialized variables in tests 2026-07-21 09:50:17 -06:00
Ruby Martin 94e157f5ad Direct compare paramTo->check_time == 11 to prevent store_truncates_time_t 2026-07-21 09:50:17 -06:00
philljjandGitHub 4a7695ef13 Merge pull request #10928 from Frauschi/pkcs7_fix
Fix two PKCS#7/CMS Go-interop gaps: SignedData DigestInfo verify + EnvelopedData definite [0] decrypt
2026-07-21 09:46:57 -05:00
Sean ParkinsonandGitHub a048395345 Merge pull request #10941 from Frauschi/rfc_compliance
Compliance to new RFCs
2026-07-21 16:19:33 +10:00
philljjandGitHub 104f685ca9 Merge pull request #10948 from SparkiDev/ed25519_fixes_2
Ed25519 tests: Fix to pass regression testing
2026-07-20 21:54:32 -05:00
Sean ParkinsonandGitHub ca53afe35d Merge pull request #10785 from stenslae/ml-dsa-ssl-error-queue-fix
openssl compat errors and mldsa oid fix
2026-07-21 10:08:11 +10:00
Daniel PouzznerandGitHub 69a994e62b Merge pull request #10945 from ejohnstown/ocsp-fail
OCSP: opt-in fail-closed on missing responder
2026-07-20 16:42:04 -05:00
JacobBarthelmehandGitHub 39a607384c Merge pull request #10920 from douzzer/20260713-WC_FIPS_AESGCM_ONE_SHOT_EXT_IV_ALLOWED-etc
20260713-WC_FIPS_AESGCM_ONE_SHOT_EXT_IV_ALLOWED-etc
2026-07-20 13:27:24 -06:00
Eric Blankenhorn 91ca43f1ac Bound CKS extension allocation in TLSX_CKS_Parse 2026-07-20 14:19:37 -05:00
Eric Blankenhorn ec73081c7e Fix off-by-one OOB NUL write in GetCertName (classic ASN parser) 2026-07-20 12:38:34 -05:00