Add crypto callback for Frodo-kem - #11238
padelsbach wants to merge 5 commits into
Conversation
43ab6f8 to
a96b311
Compare
b81945c to
327628e
Compare
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #11238
Scan targets checked: wolfcrypt-bugs, wolfcrypt-port-bugs, wolfcrypt-rs-bugs, wolfcrypt-src, wolfssl-bugs, wolfssl-src
Findings: 7
7 finding(s) posted as inline comments (see file-level comments below)
This review was generated automatically by Fenrir. Reported findings require changes before merge.
d465827 to
daad8ce
Compare
260f7f2 to
7577775
Compare
|
jenkins retest this please |
97061da to
8bada36
Compare
8bada36 to
61a4d75
Compare
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Finder-based cleanup can dispatch duplicate device frees, and the new configure mapping lacks direct CI coverage.
Review effort: Balanced
Findings: 1
Open (2)
What changed in this PR
Adds FrodoKEM crypto-callback offloading and a callback-only mode that removes native lattice operations.
Changes:
- Routes FrodoKEM key generation, encapsulation, decapsulation, and cleanup through crypto callbacks.
- Strips portable and assembly implementations in callback-only builds.
- Adds configuration, CI, and callback-dispatch tests.
| File | Description |
|---|---|
wolfssl/wolfcrypt/wc_frodokem.h |
Adds device context and native-mode marker. |
wolfssl/wolfcrypt/settings.h |
Validates callback-only configuration. |
wolfcrypt/test/test.c |
Adds callback and finder tests. |
wolfcrypt/src/wc_frodokem.c |
Implements callback routing and native stripping. |
wolfcrypt/src/wc_frodokem_mat.c |
Excludes native matrix operations. |
wolfcrypt/src/wc_frodokem_asm.S |
Excludes x86 assembly. |
wolfcrypt/src/wc_frodokem_asm.asm |
Excludes Windows x86 assembly. |
wolfcrypt/src/port/arm/thumb2-frodokem-asm.S |
Excludes Thumb-2 assembly. |
wolfcrypt/src/port/arm/thumb2-frodokem-asm_c.c |
Excludes inline Thumb-2 assembly. |
wolfcrypt/src/port/arm/armv8-frodokem-asm.S |
Excludes AArch64 assembly. |
wolfcrypt/src/port/arm/armv8-frodokem-asm.asm |
Excludes ARM assembler implementation. |
wolfcrypt/src/port/arm/armv8-frodokem-asm_c.c |
Excludes inline AArch64 assembly. |
wolfcrypt/src/port/arm/armv8-32-frodokem-asm.S |
Excludes ARMv8-32 assembly. |
wolfcrypt/src/port/arm/armv8-32-frodokem-asm_c.c |
Excludes inline ARMv8-32 assembly. |
wolfcrypt/src/cryptocb.c |
Enables finder-based PQC KEM dispatch. |
tests/api/test_frodokem.c |
Skips native-only tests in callback-only mode. |
configure.ac |
Adds FrodoKEM to cryptocb=only. |
.github/workflows/cryptocb-only.yml |
Adds callback-only CI configurations. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
jenkins retest this please |
5024198 to
bd9e516
Compare
|
jenkins retest this please |
3e05ce4 to
a2bec77
Compare
|
jenkins retest this please |
a2bec77 to
2c85d38
Compare


Description
Includes CB_ONLY mode which saves approx 22kB when enabled and offloaded.
Also includes a minor fix for WOLF_CRYPTO_CB_FIND.
Testing
New unit tests
Checklist