Add support for SHAKE - #523
padelsbach wants to merge 7 commits into
Conversation
a7b236f to
c242d8b
Compare
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #523
Scan targets checked: wolfhsm-core-bugs, wolfhsm-crypto-bugs, wolfhsm-src
Findings: 5
5 finding(s) posted as inline comments (see file-level comments below)
This review was generated automatically by Fenrir. Reported findings require changes before merge.
|
@padelsbach plz investigate fenrir issues and resolve + assign me back the bot if ready to go. That said we don't want to merge unless the upstream wolfCrypt stuff is all in first |
d767420 to
e8f26b1
Compare
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Missing-server responses are not consistently converted into software fallback signals, causing SHAKE operations to fail in mixed-feature deployments.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Adds SHAKE128/256 offload support following the existing SHA3 client/server architecture.
Changes:
- Adds SHAKE wire messages, client APIs, callbacks, and server handling.
- Adds extensive functional, validation, and fallback tests.
- Adds SHAKE build variants and updates the wolfSSL dependency revision.
| File | Description |
|---|---|
wolfhsm/wh_message_crypto.h |
Defines SHAKE wire formats and limits. |
wolfhsm/wh_client_crypto.h |
Declares SHAKE client APIs. |
src/wh_message_crypto.c |
Implements message translation. |
src/wh_client_crypto.c |
Implements SHAKE client offload. |
src/wh_client_cryptocb.c |
Adds wolfCrypt callback dispatch. |
src/wh_server_crypto.c |
Adds server-side SHAKE processing. |
test-refactor/client-server/wh_test_crypto_shake.c |
Adds comprehensive SHAKE tests. |
test-refactor/wh_test_list.c |
Registers the new tests. |
test-refactor/posix/Makefile |
Adds SHAKE build variants. |
test/config/user_settings.h |
Configures SHAKE and dependent algorithms. |
test/Makefile |
Configures wolfCrypt certificate paths. |
test/wh_test_check_struct_padding.c |
Checks new message padding. |
test-refactor/misc/wh_test_check_struct_padding.c |
Checks refactored-build padding. |
.github/workflows/build-and-test-refactor.yml |
Tests individual SHAKE configurations. |
.github/actions/checkout-wolfssl/action.yml |
Pins the required wolfSSL revision. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| #ifdef WOLF_CRYPTO_CB_SHAKE_XOF | ||
| if (info->hash.shakeOp != WC_SHAKE_OP_NONE) { | ||
| ret = _handleShakeXof(ctx, info); | ||
| break; | ||
| } |

Follows patterns from SHA3