Skip to content

20260727-fips-dev-no-post - #11031

Open
douzzer wants to merge 42 commits into
wolfSSL:masterfrom
douzzer:20260727-fips-dev-no-post
Open

20260727-fips-dev-no-post#11031
douzzer wants to merge 42 commits into
wolfSSL:masterfrom
douzzer:20260727-fips-dev-no-post

Conversation

@douzzer

@douzzer douzzer commented Aug 1, 2026

Copy link
Copy Markdown
Contributor

tested with

wolfssl-multi-test.sh ... all

@douzzer
douzzer marked this pull request as draft August 1, 2026 03:46
@github-actions

github-actions Bot commented Aug 1, 2026

Copy link
Copy Markdown

MemBrowse Memory Report

gcc-arm-cortex-m4

  • FLASH: .rodata.CSWTCH.1 +8 B, .rodata.str1.1 +122 B (+0.1%, 201,239 B / 262,144 B, total: 77% used)

gcc-arm-cortex-m4-crypto-only

  • FLASH: .rodata.CSWTCH.1 +8 B, .rodata.str1.1 +122 B (+0.1%, 175,250 B / 262,144 B, total: 67% used)

gcc-arm-cortex-m4-openssl-compat

  • FLASH: .rodata +128 B, .text +64 B (+0.0%, 773,036 B / 1,048,576 B, total: 74% used)

gcc-arm-cortex-m4-pkcs7

  • FLASH: .rodata.CSWTCH.1 +8 B, .rodata.str1.1 +122 B (+0.1%, 214,038 B / 262,144 B, total: 82% used)

gcc-arm-cortex-m4-pq

  • FLASH: .rodata +128 B (+0.0%, 281,216 B / 1,048,576 B, total: 27% used)

gcc-arm-cortex-m4-rsa-only

  • FLASH: .rodata +136 B (+0.0%, 327,328 B / 1,048,576 B, total: 31% used)

gcc-arm-cortex-m4-tls13

  • FLASH: .rodata.CSWTCH.1 +8 B, .rodata.str1.1 +122 B (+0.1%, 237,385 B / 262,144 B, total: 91% used)

gcc-arm-cortex-m7

  • FLASH: .rodata.CSWTCH.1 +8 B, .rodata.str1.1 +122 B (+0.1%, 201,239 B / 262,144 B, total: 77% used)

gcc-arm-cortex-m7-pq

  • FLASH: .rodata +128 B (+0.0%, 281,792 B / 1,048,576 B, total: 27% used)

gcc-arm-cortex-m7-tls13

  • FLASH: .rodata.CSWTCH.1 +8 B, .rodata.str1.1 +122 B (+0.1%, 237,449 B / 262,144 B, total: 91% used)

linuxkm-standard

  • Data: __patchable_function_entries -40 B (-0.1%, 49,184 B)

stm32-sim-stm32h753

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #11031

Scan targets checked: linuxkm-bugs, linuxkm-src, wolfcrypt-bugs, wolfcrypt-port-bugs, wolfcrypt-rs-bugs, wolfcrypt-src, wolfssl-bugs, wolfssl-src
Findings: 5
4 finding(s) posted as inline comments (see file-level comments below)

Medium (1)

Unguarded verifyCore reference in non-PIE FIPS seg_map under WOLFSSL_FIPS_DEV_NO_POST

File: linuxkm/module_hooks.c:1291
Function: seg_map (file-scope, #elif defined(HAVE_FIPS) branch)
Category: Incorrect error handling

The extern declaration of verifyCore (line 119) is now gated with !defined(WOLFSSL_FIPS_DEV_NO_POST), and the primary seg_map initializer (line 1223) got the matching && !defined(WOLFSSL_FIPS_DEV_NO_POST) guard, but the parallel seg_map used when WC_SYM_RELOC_TABLES is undefined (line 1290) was not updated to match, so it references the undeclared verifyCore symbol when building with --enable-fips=dev-no-post and PIE reloc tables disabled.

Recommendation: Add && !defined(WOLFSSL_FIPS_DEV_NO_POST) to the #if at line 1290, matching line 1223.

Referenced code: linuxkm/module_hooks.c:1291-1294 (4 lines)


This review was generated automatically by Fenrir. Findings are non-blocking.

@douzzer
douzzer force-pushed the 20260727-fips-dev-no-post branch from c212bc1 to 107fc6d Compare August 3, 2026 04:17

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #11031

Scan targets checked: linuxkm-bugs, linuxkm-src, wolfcrypt-bugs, wolfcrypt-port-bugs, wolfcrypt-rs-bugs, wolfcrypt-src, wolfssl-bugs, wolfssl-src

Findings: 3
3 finding(s) posted as inline comments (see file-level comments below)

This review was generated automatically by Fenrir. Findings are non-blocking.

Comment thread linuxkm/lkcapi_sha_glue.c
Comment thread linuxkm/lkcapi_sha_glue.c
@douzzer
douzzer force-pushed the 20260727-fips-dev-no-post branch from 107fc6d to 976257d Compare August 3, 2026 23:52

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #11031

Scan targets checked: linuxkm-bugs, linuxkm-src, wolfcrypt-bugs, wolfcrypt-port-bugs, wolfcrypt-rs-bugs, wolfcrypt-src, wolfssl-bugs, wolfssl-src

Findings: 2
2 finding(s) posted as inline comments (see file-level comments below)

This review was generated automatically by Fenrir. Findings are non-blocking.

Comment thread linuxkm/x86_vector_register_glue.c
Comment thread src/internal.c
Comment thread src/internal.c
Comment thread linuxkm/x86_vector_register_glue.c
@douzzer
douzzer force-pushed the 20260727-fips-dev-no-post branch from 547791b to e42afa6 Compare August 4, 2026 07:04
@douzzer
douzzer marked this pull request as ready for review August 4, 2026 07:04
@github-actions

github-actions Bot commented Aug 4, 2026

Copy link
Copy Markdown

retest this please

@Frauschi Frauschi left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🐺 Skoll Code Review

Overall recommendation: REQUEST_CHANGES
Findings: 33 total — 24 posted, 10 skipped

Posted findings

  • [Critical] Infinite recursion in Transform_Sha512() C-fallback path — self-call replaced _Transform_Sha512()wolfcrypt/src/sha512.c:1287-1288
  • [High] WC_C_DYNAMIC_FALLBACK raw-buffer gating in sha512.c is not scoped to the x86-64/AVX backend, producing wrong digestswolfcrypt/src/sha512.c:2013,2248,2304,2610
  • [High] Removing the per-context sha_method field leaves two dangling references in tests/swdev/swdev.ctests/swdev/swdev.c:352,448
  • [High] wc_AesGcmInit() hardcodes encrypt mode, so the FIPS short-nonce rejection breaks AES-GCM decryption via the public streaming API and the EVP compat layerwolfcrypt/src/aes.c:14078-14082, 13992-14002
  • [High] wc_InitDhKey_ex() returns FIPS_NOT_ALLOWED_E leaving the mp_ints uninitialized, and src/tls.c then frees themwolfcrypt/src/dh.c:966-973
  • [High] --enable-fips=v5-kcapi silently loses every "-dev" feature overrideconfigure.ac:657-664
  • [High] FIPS_DEVREADY_MAJOR=7 contradicts commit 606415c's stated MAJOR=8, and makes ready/dev/dev-no-post indistinguishable from v7configure.ac:695-704
  • [Medium] kernel-settings "-dh" reset leaves enable_dh set-but-empty, defeating AC_ARG_ENABLE's default and building DH when it should be excludedconfigure.ac:1886-1891
  • [Medium] WC_DH_INITIAL_RUNTIME_ENABLEMENT=1 only triggers on an exact enable_dh=yes, so --enable-dh=nonblock and --enable-openssh build permanently-disabled DHconfigure.ac:6362-6369, 1744
  • [Medium] bench_falconKeySign() never checks WC_ALLOC_VAR results, NULL-dereferencing msg on allocation failurewolfcrypt/benchmark/benchmark.c:15806-15847
  • [Medium] mldsa_param_{44,65,87}_vfy_test() double-encode an already WC_TEST_RET_ENC-encoded return valuewolfcrypt/test/test.c:56147-56160, 57149-57162, 58510-58523
  • [Medium] random.c: two DRBG_FAILURE comparisons were not converted to WC_NO_ERR_TRACEwolfcrypt/src/random.c:816, 1014
  • [Medium] wc_dh_enable()/wc_dh_disable() are a non-atomic read-modify-write on a plain volatile intwolfcrypt/src/dh.c:60-81
  • [Medium] wc_DhGeneratePublic() and wc_DhGenerateParams() are not covered by the DH enablement checkwolfcrypt/src/dh.c
  • [Medium] linuxkm_affinity_lock can now fail with INTERRUPTED_E / WC_ACCEL_INHIBIT_E, which wc_rng_bank_checkout treats as fatallinuxkm/lkcapi_sha_glue.c:2068-2094
  • [Low] FIPS_UNAPPROVED_E error string is missing a space at the concatenation boundarywolfcrypt/src/error.c:746-748
  • [Low] wc_frodokem_mat.c re-key blocks read aes->use_aesni, which only exists under WOLFSSL_AESNIwolfcrypt/src/wc_frodokem_mat.c:1732-1742, 2054-2064
  • [Low] falcon.c: wc_MemZero_Add registers sizeof(pointer) instead of sizeof(falcon_sampler_ctx)wolfcrypt/src/falcon.c:8313-8314
  • [Low] configure --help prints the literal string ${ENABLED_DH_DEFAULT} for --enable-dhconfigure.ac:6379
  • [Low] fips-dev-no-post.yml: the fuzzing seed is the shell PID and is never echoed, and the adjacent comment about '$' in the heredoc is now wrong.github/workflows/fips-dev-no-post.yml:87-89,116
  • [Low] sha256.c: #undef WC_C_DYNAMIC_FALLBACK precedes the header includes, so this TU can see a different struct layoutwolfcrypt/src/sha256.c:46-53, wolfcrypt/src/sha512.c:68-76
  • [Low] tests/api/test_cmac.c drops KCAPI coverage without explanationtests/api/test_cmac.c:374-378, 421-425
  • [Low] tests/unit.c uses wc_dh_enable()/WC_DH_HAVE_RUNTIME_ENABLEMENT without including dh.htests/unit.c:82-84
  • [Info] falcon.c: FALCON_MULHI now additionally requires HAVE___UINT128_T, silently dropping to the 4-multiply fallbackwolfcrypt/src/falcon.c:1152-1156
Skipped findings
  • [High] --enable-fips=v7 no longer defines WOLFSSL_FIPS_READY, flipping the build from FIPS 186-4 to 186-5
  • [High] AES-GCM short-nonce rejection is gated on HAVE_FIPS with no version qualifier, changing behavior of shipped FIPS v5/v6 modules and breaking their tests
  • [High] Out of scope: 24 cicd findings on CI files this PR does not touch
  • [Medium] Already answered by the commit messages -- intentional, with stated rationale
  • [Medium] test_wc_AesGcmDecisionCoverage / test_wc_AesGcmArgMcdc expectations do not match the implementation's FIPS gating
  • [Medium] FIPS optest -DNO_DH rule names a target kbuild never builds, so the flag is silently dropped
  • [Low] settings.h dropped the #undefs before defining HAVE_FIPS_VERSION_MAJOR/_MINOR/_PATCH
  • [Low] x86_vector_register_glue.c: new fuzzing code has a misindented unbraced warning and assigns an out-of-enumeration value to the enum-typed flags parameter
  • [Info] falcon.c: WC_DECLARE_VAR heap argument reads as a dereference before the NULL check
  • [Medium] wc_DhGeneratePublic() and wc_DhGenerateParams() are not covered by the DH enablement check

Review generated by Skoll via Claude/Codex

Comment thread wolfcrypt/src/sha512.c Outdated
Comment thread wolfcrypt/src/sha512.c Outdated
Comment thread wolfssl/wolfcrypt/sha512.h
Comment thread wolfcrypt/src/aes.c Outdated
Comment thread wolfcrypt/src/dh.c
Comment thread .github/workflows/fips-dev-no-post.yml
Comment thread wolfcrypt/src/sha256.c Outdated
Comment thread tests/api/test_cmac.c
Comment thread tests/unit.c
Comment thread wolfcrypt/src/falcon.c Outdated
@Frauschi Frauschi assigned douzzer and unassigned wolfSSL-Bot Aug 4, 2026
@douzzer
douzzer force-pushed the 20260727-fips-dev-no-post branch 2 times, most recently from 5fec377 to 2468fe7 Compare August 5, 2026 03:32

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #11031

Scan targets checked: linuxkm-bugs, linuxkm-src, wolfcrypt-bugs, wolfcrypt-port-bugs, wolfcrypt-rs-bugs, wolfcrypt-src, wolfssl-src
Failed targets: wolfssl-bugs

Findings: 3
3 finding(s) posted as inline comments (see file-level comments below)

This review was generated automatically by Fenrir. Findings are non-blocking.

@douzzer
douzzer force-pushed the 20260727-fips-dev-no-post branch from 2468fe7 to a4ae192 Compare August 5, 2026 04:52
douzzer added 26 commits August 5, 2026 00:04
wolfcrypt/src/rsa.c: wrap wc_hash2mgf in a targeted -Wswitch-enum pragma

configure.ac: rename $ENABLE_ORIGINAL -> $ENABLE_ORIGINAL_KYBER to disambiguate.

wolfssl/wolfcrypt/types.h: tighten a braced-group guard with __STRICT_ANSI__
(pedantic-mode correctness).

wolfssl/internal.h: add the WOLFSSL_API_PREFIX_MAP mapping for TLSX_CKS_Parse.
Refactor WC_C_DYNAMIC_FALLBACK architecture to allow per-call alternation
between asm and C:

* Under WC_C_DYNAMIC_FALLBACK keep the block buffer as the raw big-endian stream
and byte-reverse just-in-time inside the C transform, so a given wc_Sha256 /
wc_Sha512 instance may switch between the vectorized and pure-C transforms per
call without producing a wrong digest.

* Add Transform_*_C_from_raw / Transform_*_Len_C_from_raw JIT-reversing
adapters; the dispatchers early-out through them on (method == C) ||
SAVE_VECTOR_REGISTERS2 failure; caller-side method-keyed ByteReverse sites are
compiled out under the raw-buffer convention and the final block's length words
are written unconditionally big-endian.

* Remove the init-time CAN_SAVE_VECTOR_REGISTERS pin from Sha*_SetTransform so
the recorded method reflects pure CPU capability (enabling fall-forward, not
only fallback).  Update the bulk paths to check the transform return and not
advance on failure.

* The raw-buffer convention is scoped to WC_C_DYNAMIC_FALLBACK specifically --
not to WC_NO_INTERNAL_FUNCTION_POINTERS -- because only the fallback build can
change transform mid-object; a plain no-function-pointers build picks one method
and keeps it, so it retains the conventional host-endian buffer (no change from
incumbent code).

* Drop the per-object `.sha_method` member.  Method selection is a property of
the CPU, not of the hash object, so it becomes a file-scope static in each .c,
set once (Sha*_SetTransform() early- returns when already set) and read by every
instance.  Shrinks both structs.

* When WOLFSSL_AESNI is enabled without the rest of USE_INTEL_SPEEDUP, `#undef
WC_C_DYNAMIC_FALLBACK` -- AES-NI alone satisfies WC_HAVE_VECTOR_SPEEDUPS but
leaves SHA with no vectorized transform to fall back from, and the caller-side
gating would otherwise suppress a byte-reversal that is still required.
WOLFSSL_DEBUG_TRACE_ERROR_CODES support for internal DRBG errors.

Converts the DRBG internal status #defines (DRBG_SUCCESS/DRBG_FAILURE,
WC_DRBG_*) to enums, that are wrapped in WC_ERR_TRACE() when
WOLFSSL_DEBUG_TRACE_ERROR_CODES.

Deploys well-known error codes and WC_NO_ERR_TRACE() as needed throughout.
…i_rsa_glue.c, linuxkm/lkcapi_sha_glue.c, wolfcrypt/test/test.c:

* Use defined(WC_HAVE_RNG_BANKREF), not defined(WC_RNG_BANK_SUPPORT), as the feature sensor for RNG bankrefs.

* Add DRBG_KAT_FIPS_E and DRBG_CONT_FIPS_E to the list of immediate-failure errors in wc_rng_bank_init().
…sm}:

The AVX2 constant-time table-lookup routines seed a broadcast vector with a
legacy-SSE GPR->XMM move (movd/movq), which writes bits [127:0] and leaves
[255:128] UNMODIFIED, then read the register at full YMM width via
vpermd %ymm,%ymm(zeroed),%ymm (a lane-0 broadcast across all 256 bits). If a
prior vector op left the upper lane non-zero, the broadcast is corrupt and the
constant-time selection returns the wrong table entry -- a wrong ECC point/entry
in sp_{256,384,521}_get_{point_33,entry_64,entry_65}_avx2 and
sp_{2048,3072,4096}_get_from_table_avx2, or a wrong X25519 public key from
fe_cmov_table_avx2. Deterministic given register history; surfaces as
intermittent failures because it depends on the upper lane being dirty on entry.
Under kernel_fpu_begin (which does not zero YMM) a dirty upper lane is ambient,
which is why ED25519 asm was kept disabled in kernel mode. Fix: emit the VEX
form (vmovd for 32-bit source, vmovq for 64-bit), which zeroes [255:128].
…, wolfcrypt/test/test.h, wolfcrypt/test/test.c: Falcon fixes and cleanups:

wolfcrypt/src/falcon.c:

* define _WC_BUILDING_FALCON_C;

* add #error arch guards -- WOLFSSL_FALCON_FPR_ASM requires x86-64
(wc_falcon_fpr_x86_64_asm.S), WOLFSSL_FALCON_FFT_AVX2 requires an x86 target,
WOLFSSL_FALCON_FFT_NEON requires AArch64 (ARM32 NEON lacks the double-precision
lanes used by float64x2_t);

* drop the unused FALCON_PRIMES forward declaration;

* fix u->U literals and an (sword64)z0*(sword64)z0 overflow;

* tightened __uint128_t guard.

wolfcrypt/benchmark/benchmark.c:

* falcon message buffer -> WC_ALLOC_VAR;

* bench wiring for the experimental algs.

wolfcrypt/test/test.h: add frodokem_test / falcon_test externs.

wolfcrypt/test/test.c: mldsa/falcon WC_ALLOC_VAR conversions.

configure.ac: update all-quantum-crypto with the experimental algorithms.
…_func() /

err_sys_with_errno_func() taking __FILE__ and __LINE__, with function-like
macros preserving every existing call site; failure messages now carry file and
line ("wolfSSL error, %s L %d: %s").

tests/suites.c: client_test / server_test failure reports go to stderr
(printf -> fprintf(stderr, ...)).
…tions:

Under WC_C_DYNAMIC_FALLBACK, SAVE_VECTOR_REGISTERS2() can fail on any call, so
two calls on the same object can dispatch differently.  Each of these
algorithms had state that silently assumed a single dispatch for its lifetime.

wolfcrypt/src/wc_mldsa.c: add MLDSA_NTT_AVX2()/MLDSA_INVNTT_AVX2() selecting
the "full" AVX2 NTT/invNTT under WC_C_DYNAMIC_FALLBACK.  The non-full variants
leave NTT-domain coefficients in a permuted, lane-interleaved order that only
their matching consumers understand, whereas the full variants and the C
implementations use standard order.  NTT-domain data at rest (cached s1/s2/t0
vectors, the challenge polynomial) can be produced and consumed by
differently-dispatched calls, so its representation must be dispatch-invariant.
Without fallback, dispatch is invariant and the ~2%/~4% faster permuted-order
variants are kept.  Both pipelines are bit-identical end to end.

wolfcrypt/src/wc_mlkem_poly.c: in mlkem_derive_secret(), re-initialize the
shared SHAKE-256 object under WC_C_DYNAMIC_FALLBACK.  The buffer-stuffing
shortcut assumes a freshly initialized (zeroed) sponge, which no longer holds
once the C fallback legs of mlkem_gen_matrix()/mlkem_get_noise() drive the XOF
on that object and leave it mid-squeeze.

wolfcrypt/src/wc_slhdsa.c: in slhdsakey_fors_sign(), replace the
CAN_SAVE_VECTOR_REGISTERS() test with an actual SAVE_VECTOR_REGISTERS2() == 0
acquisition and a matching RESTORE_VECTOR_REGISTERS(), so the region is held
rather than merely predicted to be available.

wolfcrypt/src/wc_frodokem_mat.c: in the AES row kernels of
frodokem_mul_add_as_plus_e_aes() and frodokem_mul_add_sa_plus_e_aes(), re-key
with wc_AesSetKeyDirect() when IS_INTEL_AESNI() but !aes->use_aesni.  The
kernels consume aes->key directly, which holds an AES-NI-layout schedule only
if SetKey ran with vector registers available; under fallback a failed
SAVE_VECTOR_REGISTERS2() inside SetKey returns success having keyed only the
C-fallback schedule.  Re-keying happens inside the held region, where the
nested save always succeeds.  Loop conditions gain (ret == 0) so a re-key
failure stops the run.

wolfssl/wolfcrypt/settings.h: with the above, ML-KEM, ML-DSA, SLH-DSA and
FrodoKEM are fuzzer-clean, so the DEBUG_VECTOR_REGISTER_ACCESS_FUZZING
exclusion narrows from the _WC_BUILDING_WC_MLKEM_POLY_C / _WC_BUILDING_WC_MLDSA_C
/ _WC_BUILDING_WC_SLHDSA_C set to _WC_BUILDING_FALCON_C alone.  Falcon stays
excluded because it uses FP or vector registers in all of its asm
implementations and there is no option yet to build the C-no-FP implementation
alongside them.

tests/api/test_mldsa.c: in test_mldsa_encode_w1_large_values(), pin dispatch to
the C path with WC_DEBUG_SET_VECTOR_REGISTERS_RETVAL() for the duration of the
test and restore it afterward.  The two calls being compared are only specified
-- and only equal -- on the valid input domain, so letting the fuzzer send them
down different (AVX2 vs C) implementations is not a meaningful comparison.
MAYBE_INHIBIT vector-register save mode for the convenience of the DRBG glue
logic.

Add WC_SVR_FLAG_MAYBE_INHIBIT = 2 (WC_SVR_FLAG_FUZZ becomes 4), and add
SAVE_VECTOR_REGISTERS_MAYBE_INHIBIT() / RESTORE_VECTOR_REGISTERS_MAYBE_INHIBITED()
macros, routing through wc_{save,restore}_vector_registers_x86(WC_SVR_FLAG_MAYBE_INHIBIT).

linuxkm/x86_vector_register_glue.c: implement the mode.  A _MAYBE_INHIBIT call
must be outermost (BAD_STATE_E otherwise, and a warning on the matching restore
at non-outermost depth).  The fuzzer check moves ahead of the inhibit decision
so that a fuzzed failure converts into an inhibited (rather than failed)
acquisition when _MAYBE_INHIBIT is set; a real inability to use SIMD
(preempt_count() != 0 && !may_use_simd()) does the same.  The restore path
treats _MAYBE_INHIBIT like _INHIBIT when deciding whether registers were
actually taken.

Note, under fuzzer vector disablement,
wc_save_vector_registers_x86(WC_SVR_FLAG_MAYBE_INHIBIT) returns 0 with affinity
locked, as though explicit WC_SVR_FLAG_INHIBIT were passed.  Thus on 0 return,
the caller must use `CAN_SAVE_VECTOR_REGISTERS()` to discover whether vector
registers are actually usable.
… SAVE_VECTOR_REGISTERS_MAYBE_INHIBIT() and RESTORE_VECTOR_REGISTERS_MAYBE_INHIBITED(), and in wc_linuxkm_rng_bank_init(), disable vector ops only if FIPS <v7.
…tement-expr

definitions with __extension__ at both arms (the fuzzing arm and the plain arm)
so -pedantic builds (which the kernel-settings CI configs use) don't drown in
"ISO C forbids braced-groups within expressions" across the hundreds of
expansion sites.
…nable-fips=dev-no-post.

Notes:

* EXTRA_CPPFLAGS carries -Werror in the base configure line, because the
  autotools -Werror is gated on a VCS checkout being detected in the configure
  CWD and these are VPATH builds, which would otherwise silently get no -Werror
  at all.

* The fuzzing cell's WC_DEBUG_VECTOR_REGISTERS_FUZZING_SEED is $$, which changes
  from run to run.

* The two out-of-tree kernel-module cells (linuxkm, linuxkm-all-asm) are
  commented out, with a note that out-of-tree module builds don't work yet.
…PTO_FIPS) != defined(HAVE_FIPS) more informative.
…iables

exported to the linuxkm sub-make.

linuxkm/Kbuild:
* Feature-detect $(intcmp) (GNU make >= 4.4) into $(HAVE_INTCMP).
* Derive FIPS_OPTEST_NO_DH from $(HAVE_FIPS_VERSION_MAJOR) via $(intcmp) when
  available; otherwise $(error) with instructions to supply it on the make
  command line. When set, build the optest wrapper with -DNO_DH -- DH is not
  optested at FIPS v7+ even when the module has DH, because its APIs have no
  FIPS wrappers.
* Same $(intcmp)/$(error) treatment for NO_PIE_FLAG (target kernel < 5.11), and
  change its test from `ifdef NO_PIE_FLAG` to an explicit
  `ifeq "$(NO_PIE_FLAG)" "0"` so an explicitly-zero value means what it says.
* Add $(CFLAGS_AUTO_VECTORIZE_DISABLE) to benchmark.o ccflags-y and drop its
  unused asflags-y line.
…IPS_DEV from the gate for implicit defining of WC_TEST_NO_ECC_SIGN_VERIFY_ZERO_DIGEST.
…SL_DEBUG_TRACE_ERROR_CODES_SUPPORT, facilitating opt-in per-file error tracing in debug campaigns.
…a_param_*_vfy_test(), test_mldsa_decode_level(), and mldsa_test().
.github/workflows/fips-dev-no-post.yml: add reporting of fuzzing seed.

wolfcrypt/src/aes.c, tests/api/test_aes.c, .wolfssl_known_macro_extras:

* change FIPS AES-GCM nonce size restrictions from from opt-out (WC_FIPS_AESGCM_ALLOW_SHORT_NONCES) to opt-in (WC_FIPS_AESGCM_NO_SHORT_NONCES).
* apply restrictions only on encryption operations, never on decryption.

configure.ac: fix HAVE_FIPS_VERSION of fips-ready; fix enable_dh setup in KERNEL_MODE_DEFAULTS setup; fix help message for --enable-dh.

linuxkm/x86_vector_register_glue.c: add dump_stack() on each BUG/WARNING message that didn't already have it.

src/tls.c: fix a couple leaks in TLSX_KeyShare_GenDhKey().

tests/swdev/swdev.c: gate src->sha_method access in swdev_sha256_copy_state() and swdev_sha512_copy_state() appropriately.

tests/unit.c: conditionally include dh.h, to assure wc_dh_enable() is available.

wolfcrypt/src/dh.c:
* in wc_InitDhKey_ex(), zero the key at entry unless null, remove duplicate key->trustedGroup = 0, and call wc_FreeDhKey() on error at end.
* add missing wc_dh_enabled checks in  wc_DhGeneratePublic() and wc_DhGenerateParams().

wolfcrypt/src/error.c: fix missing space in FIPS_UNAPPROVED_E string.

b/wolfssl/wolfcrypt/settings.h: sense __SIZEOF_INT128__ and if defined, but HAVE___INT128_T and/or HAVE___UINT128_T are undefined, define them.

wolfcrypt/src/falcon.c: tweak the gate on __uint128_t availability to lean solely on HAVE___UINT128_T.

wolfcrypt/src/random.c: fix a couple missed WC_NO_ERR_TRACE() wrappers.

wolfcrypt/src/rng_bank.c: properly tolerate WC_ACCEL_INHIBIT_E as a retval from bank->affinity_lock_cb().

wolfcrypt/src/sha256.c, wolfcrypt/src/sha512.c: move #undef WC_C_DYNAMIC_FALLBACK for WOLFSSL_AESNI without USE_INTEL_SPEEDUP to follow all includes, assuring no struct layout conflict.

wolfcrypt/src/sha512.c: fix wrong call in intelasm Transform_Sha512() !WC_C_DYNAMIC_FALLBACK SHA512_C path.

wolfcrypt/test/test.c: fix double-WC_TEST_RET_ENC_EC() in mldsa_param_*_vfy_test().
…ating around WC_C_DYNAMIC_FALLBACK: use WC_SHA{256,512}_RAW_BE_BUFFER to indicate big-endian buffer.

tests/swdev/swdev.c: fix typos (FIPS_VERSION3_LT, not FIPS_VERSION_LT).
…_UINT128_T

to avoid inadvertent configuration shifts -- HAVE___UINT128_T is a backend
selector (SP_WORD_SIZE, CURVED25519_128BIT, CURVED448_128BIT), not merely a
type-availability macro;

wolfcrypt/src/falcon.c: accept either defined(__SIZEOF_INT128__) or
defined(HAVE___UINT128_T) in FALCON_MULHI() implementation selector.

wolfssl/wolfcrypt/sp_int.h: fix size of struct sp_ecc_ctx when
SP_WORD_SIZE == 64 (as when HAVE___UINT128_T is defined), fixing assert
failure in sp_c64.c sp_ecc_verify_256_nb().  The P-256-only bucket was sized
against the C32 layout (verify ctx 2376 <= 2560); the C64 ctx is 2640.  The
384 and 521 buckets are equally word-size-blind but currently pass at 64 bits
on margin (3600 <= 3840, 4560 <= 5280).
linuxkm/x86_vector_register_glue.c: in wc_save_vector_registers_x86(), properly squelch the hard-IRQ call warning if flags & WC_SVR_FLAG_MAYBE_INHIBIT;

src/internal.c: in AllocKey(), properly set key_inited = 1 if wc_SlhDsaKey_Init() succeeds;

.github/workflows/fips-dev-no-post.yml: test -DWC_FIPS_AESGCM_NO_SHORT_NONCES.
@douzzer
douzzer force-pushed the 20260727-fips-dev-no-post branch from a4ae192 to c09717d Compare August 5, 2026 05:09

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #11031

Scan targets checked: linuxkm-bugs, linuxkm-src, wolfcrypt-bugs, wolfcrypt-port-bugs, wolfcrypt-rs-bugs, wolfcrypt-src, wolfssl-bugs
Failed targets: wolfssl-src

Findings: 4
4 finding(s) posted as inline comments (see file-level comments below)

This review was generated automatically by Fenrir. Findings are non-blocking.

Comment thread wolfcrypt/src/aes.c
Comment thread tests/swdev/swdev.c
Comment thread tests/swdev/swdev.c
Comment thread wolfcrypt/test/test.c
@douzzer

douzzer commented Aug 5, 2026

Copy link
Copy Markdown
Contributor Author

retest this please
(java tooling on PRB-ppc-test)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants