Skip to content

Add support for SHAKE - #523

Open
padelsbach wants to merge 7 commits into
wolfSSL:mainfrom
padelsbach:crypto-cb-shake
Open

padelsbach wants to merge 7 commits into
wolfSSL:mainfrom
padelsbach:crypto-cb-shake

Conversation

@padelsbach

@padelsbach padelsbach commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

Follows patterns from SHA3

@padelsbach
padelsbach marked this pull request as ready for review September 18, 2026 20:41
@padelsbach padelsbach assigned padelsbach and bigbrett and unassigned padelsbach Sep 18, 2026

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #523

Scan targets checked: wolfhsm-core-bugs, wolfhsm-crypto-bugs, wolfhsm-src

Findings: 5
5 finding(s) posted as inline comments (see file-level comments below)

This review was generated automatically by Fenrir. Reported findings require changes before merge.

Comment thread test-refactor/client-server/wh_test_crypto_shake.c
Comment thread src/wh_client_crypto.c
Comment thread src/wh_client_crypto.c Outdated
Comment thread src/wh_client_crypto.c
Comment thread test-refactor/client-server/wh_test_crypto_shake.c
@bigbrett

Copy link
Copy Markdown
Contributor

@padelsbach plz investigate fenrir issues and resolve + assign me back the bot if ready to go. That said we don't want to merge unless the upstream wolfCrypt stuff is all in first

@padelsbach padelsbach assigned bigbrett and padelsbach and unassigned padelsbach and bigbrett Sep 21, 2026
@padelsbach padelsbach changed the title Add crypto callback for SHAKE Add support for SHAKE Sep 25, 2026
Copilot AI balanced review requested due to automatic review settings October 3, 2026 03:32

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Missing-server responses are not consistently converted into software fallback signals, causing SHAKE operations to fail in mixed-feature deployments.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Adds SHAKE128/256 offload support following the existing SHA3 client/server architecture.

Changes:

  • Adds SHAKE wire messages, client APIs, callbacks, and server handling.
  • Adds extensive functional, validation, and fallback tests.
  • Adds SHAKE build variants and updates the wolfSSL dependency revision.
File Description
wolfhsm/​wh_message_crypto.h Defines SHAKE wire formats and limits.
wolfhsm/​wh_client_crypto.h Declares SHAKE client APIs.
src/​wh_message_crypto.c Implements message translation.
src/​wh_client_crypto.c Implements SHAKE client offload.
src/​wh_client_cryptocb.c Adds wolfCrypt callback dispatch.
src/​wh_server_crypto.c Adds server-side SHAKE processing.
test-refactor/​client-server/​wh_test_crypto_shake.c Adds comprehensive SHAKE tests.
test-refactor/​wh_test_list.c Registers the new tests.
test-refactor/​posix/​Makefile Adds SHAKE build variants.
test/​config/​user_settings.h Configures SHAKE and dependent algorithms.
test/​Makefile Configures wolfCrypt certificate paths.
test/​wh_test_check_struct_padding.c Checks new message padding.
test-refactor/​misc/​wh_test_check_struct_padding.c Checks refactored-build padding.
.github/​workflows/​build-and-test-refactor.yml Tests individual SHAKE configurations.
.github/​actions/​checkout-wolfssl/​action.yml Pins the required wolfSSL revision.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/wh_client_cryptocb.c
Comment on lines +745 to +749
#ifdef WOLF_CRYPTO_CB_SHAKE_XOF
if (info->hash.shakeOp != WC_SHAKE_OP_NONE) {
ret = _handleShakeXof(ctx, info);
break;
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants