Conversation
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Crypt-only CMake state and extended-key-usage encoding remain incorrect for supported configurations.
Review effort: Balanced
Findings: 3
Open (3)
What changed in this PR
Adds no-heap certificate encoding support, configurable key-ID hashing, CMake crypt-only handling, and XATOI platform fallbacks.
Changes:
- Uses bounded stack buffers for certificate names and key identifiers.
- Adds SHA-3 key-ID support and dynamic SKID/AKID sizing.
- Adds CMake crypt-only plumbing, cache filtering, platform macros, and CI coverage.
| File | Description |
|---|---|
wolfssl/wolfcrypt/types.h |
Adds XATOI fallback for STRING_USER. |
wolfssl/wolfcrypt/asn.h |
Uses configured key-ID size. |
wolfssl/wolfcrypt/asn_public.h |
Selects key-ID hash and buffer sizes. |
wolfcrypt/src/asn.c |
Adds stack-based certificate encoding paths. |
wolfcrypt/test/test.c |
Tests no-heap CSR and key IDs. |
IDE/XCODE-FIPSv6/user_settings.h |
Defines XATOI. |
IDE/XCODE-FIPSv5/user_settings.h |
Defines XATOI. |
IDE/XCODE-FIPSv2/user_settings.h |
Defines XATOI. |
IDE/XCODE-FIPSv2/macOS-C++/M1/user_settings.h |
Defines XATOI. |
IDE/XCODE-FIPSv2/macOS-C++/Intel/user_settings.h |
Defines XATOI. |
IDE/WINCE/user_settings.h |
Defines XATOI. |
IDE/WICED-STUDIO/user_settings.h |
Defines XATOI. |
IDE/SimplicityStudio/user_settings.h |
Defines XATOI. |
IDE/GCC-ARM/Header/user_settings.h |
Defines XATOI. |
examples/configs/user_settings_template.h |
Documents the platform fallback. |
CMakeLists.txt |
Adds crypt-only and cache filtering logic. |
cmake/options.h.in |
Emits crypt-only macros. |
cmake/functions.cmake |
Tracks declared CMake options. |
.github/workflows/no-malloc.yml |
Expands no-heap certificate coverage. |
.github/workflows/cmake.yml |
Tests CMake option plumbing. |
.github/configs/os-check-linux.json |
Adds SHA-3 key-ID coverage. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
dgarske
force-pushed
the
cryptonly_nomalloc
branch
from
October 1, 2026 23:58
429056b to
bd1f752
Compare
| foreach(_o WOLFSSL_TLS | ||
| WOLFSSL_ALPN WOLFSSL_CRL_MONITOR WOLFSSL_DTLS WOLFSSL_DTLS13 | ||
| WOLFSSL_DTLS_CH_FRAG WOLFSSL_DTLS_CID WOLFSSL_DTLS_MTU | ||
| WOLFSSL_EARLYDATA WOLFSSL_ECH WOLFSSL_MCAST WOLFSSL_OCSP |
Comment on lines
+141
to
+143
| #elif defined(WOLFSSL_SHA3) && !defined(WOLFSSL_NOSHA3_256) | ||
| #define WC_ASN_KEYID_HASH_SHA3_256 | ||
| #define WC_ASN_KEYID_SZ 32 /* WC_SHA3_256_DIGEST_SIZE */ |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Description
Four independent CMake and wolfCrypt fixes for
WOLFSSL_NO_MALLOCbare-metal builds.Changes
WOLFCRYPT_ONLYoption & filter stray cache definesWOLFCRYPT_ONLYCMake option emitting-DWOLFCRYPT_ONLYand-DNO_TLS(matching--enable-cryptonly).WOLF*CMake cache variables to prevent macro pollution inoptions.h(e.g.,-DWOLFSSL_STATIC_MEMORY=yes).WOLFSSL_NO_MALLOC)wc_MakeCertReq_ex(),wc_MakeCert(), andSetKeyIdFromPublicKey()to use stack-based arrays bounded byWC_ASN_MAX_NAME_ENTRIESandMAX_PUBLIC_KEY_SZ.asn_public.h) for key IDs across SHA-1, SHA-256, and SHA-3.CTC_MAX_SKID_SIZEandCTC_MAX_AKID_SIZEbased on active hash family (32-byte minimum) and fixedwc_Sha256Hashcompile failures when SHA-256 is disabled.XATOIunderSTRING_USERand platform templatesXATOIfallback is available underSTRING_USERand added explicit definitions to platform templates (IDE/WICED-STUDIO, etc.) to prevent missing macro errors during OID parsing.Testing
cryptonly-sha3-keyidandcertreq_no_malloc_test()to CI; verified zero-alloc P-256 CSR generation and parsing.WOLFCRYPT_ONLYdefaults, macro output against./configure, and warning behavior on stray cache variables.no-heap-certCI configuration and platform template compilation withSTRING_USER.