Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
73 changes: 72 additions & 1 deletion .github/configs/pq-all.json
Original file line number Diff line number Diff line change
Expand Up @@ -228,5 +228,76 @@
{"name": "pkcs7-mldsa-only", "minutes": 0.5,
"comment": "PKCS#7 SignedData with ML-DSA as the only signature algorithm (no RSA, no ECC); guards the ML-DSA-only PKCS7 build path",
"configure": ["--enable-cryptonly", "--enable-mldsa",
"--enable-pkcs7", "--disable-rsa", "--disable-ecc"]}
"--enable-pkcs7", "--disable-rsa", "--disable-ecc"]},
{"name": "mldsa-smallest-mem", "minutes": 2,
"comment": "Smallest memory ML-DSA signing and verification; the only functional coverage of WOLFSSL_MLDSA_SIGN_SMALLEST_MEM and of VERIFY_SMALLEST_MEM with malloc",
"configure": ["--enable-cryptonly", "--enable-mldsa",
"CPPFLAGS=-DWOLFSSL_MLDSA_SIGN_SMALLEST_MEM -DWOLFSSL_MLDSA_VERIFY_SMALLEST_MEM -DWOLFSSL_MLDSA_MAKE_KEY_SMALL_MEM"]},
{"name": "mldsa-smallest-mem-checks", "minutes": 2,
"comment": "Smallest memory ML-DSA signing with the optional y and w0 rejection checks and the small code arms, which are otherwise never compiled",
"configure": ["--enable-cryptonly", "--enable-mldsa=yes,small",
"CPPFLAGS=-DWOLFSSL_MLDSA_SIGN_SMALLEST_MEM -DWOLFSSL_MLDSA_SIGN_CHECK_Y -DWOLFSSL_MLDSA_SIGN_CHECK_W0"]},
{"name": "mldsa-44-precalc-a-intelasm", "minutes": 2,
"comment": "ML-DSA-44 with one pre-calculated row of matrix A on the Intel assembly paths; the q88 decompose and w1 encode kernels take no dimension, so this pins that w is sized for a full vector",
"configure": ["--enable-cryptonly", "--enable-mldsa=44", "--enable-intelasm",
"CPPFLAGS=-DWOLFSSL_MLDSA_SIGN_SMALL_MEM_PRECALC_A=1"]},
{"name": "mldsa-precalc-a-saturated", "minutes": 2,
"comment": "Pre-calculated matrix A with more rows than any parameter set has, so maxK saturates at k and the streaming loops do not run at all",
"configure": ["--enable-cryptonly", "--enable-mldsa",
"CPPFLAGS=-DWOLFSSL_MLDSA_SIGN_SMALL_MEM_PRECALC_A=8"]},
{"name": "mldsa-precalc-a-split", "minutes": 2,
"comment": "Pre-calculated matrix A split part way, which is neither the single row nor the saturated case",
"configure": ["--enable-cryptonly", "--enable-mldsa",
"CPPFLAGS=-DWOLFSSL_MLDSA_SIGN_SMALL_MEM_PRECALC_A=2"]},
{"name": "mldsa-checks-default-signer", "minutes": 2,
"comment": "The y and w0 rejection checks on the default signer, the only combination that compiles the vector range check helper and its two call sites",
"configure": ["--enable-cryptonly", "--enable-mldsa",
"CPPFLAGS=-DWOLFSSL_MLDSA_SIGN_CHECK_Y -DWOLFSSL_MLDSA_SIGN_CHECK_W0"]},
{"name": "mldsa-cache-pub-vectors-verify-no-malloc", "minutes": 2,
"comment": "Cached public vectors alongside the pinned verify buffers, the combination whose key structure member clash stopped it building; the clashing member only exists when the small memory verify is selected too",
"configure": ["--enable-cryptonly", "--enable-mldsa",
"CPPFLAGS=-DWC_MLDSA_CACHE_PUB_VECTORS -DWOLFSSL_MLDSA_VERIFY_NO_MALLOC -DWOLFSSL_MLDSA_VERIFY_SMALL_MEM"]},
{"name": "mldsa-cache-matrix", "minutes": 2,
"comment": "Cached matrix A on the default full vector signer, the only build where the signing cache allocation test's key->a and aSet assertions are compiled",
"configure": ["--enable-cryptonly", "--enable-mldsa",
"CPPFLAGS=-DWC_MLDSA_CACHE_MATRIX_A"]},
{"name": "mldsa-cache-matrix-precalc-a", "minutes": 2,
"comment": "Cached matrix A with a pre-calculated row; the small memory signer streams A, so this exercises the sign and verify round trip rather than the cache assertions",
"configure": ["--enable-cryptonly", "--enable-mldsa",
"CPPFLAGS=-DWC_MLDSA_CACHE_MATRIX_A -DWOLFSSL_MLDSA_SIGN_SMALL_MEM_PRECALC_A=1"]},
{"name": "mldsa-cache-small-keygen", "minutes": 2,
"comment": "Every key cache alongside the small memory key generation, which must drop the caches of the key it replaces",
"configure": ["--enable-cryptonly", "--enable-mldsa",
"CPPFLAGS=-DWC_MLDSA_CACHE_PRIV_VECTORS -DWC_MLDSA_CACHE_PUB_VECTORS -DWOLFSSL_MLDSA_MAKE_KEY_SMALL_MEM"]},
{"name": "mldsa-no-check-key-small-mem", "minutes": 2,
"comment": "Key pair checking compiled out alongside the small memory key generation and the smallest memory signer, which leaves the whole vector helpers with no caller",
"configure": ["--enable-cryptonly", "--enable-mldsa",
"CPPFLAGS=-DWOLFSSL_MLDSA_NO_CHECK_KEY -DWOLFSSL_MLDSA_MAKE_KEY_SMALL_MEM -DWOLFSSL_MLDSA_SIGN_SMALLEST_MEM"]},
{"name": "mldsa-verify-only-no-malloc", "minutes": 2,
"comment": "Heapless verify-only ML-DSA named only by the canonical options; the no-malloc gate must select the pinned small memory verify or every verification fails with MEMORY_E",
"configure": ["--enable-cryptonly", "--enable-mldsa=verify-only",
"CPPFLAGS=-DWOLFSSL_NO_DILITHIUM_LEGACY_GATES -DWOLFSSL_NO_MALLOC"]},
{"name": "mldsa-no-check-key", "minutes": 3,
"comment": "Key pair checking compiled out, which is the only build that reaches the NOT_COMPILED_IN arm of wc_CheckPrivateKey; needs the OpenSSL compatibility layer so the X509_check_private_key callers and their tests are compiled too",
"configure": ["--enable-opensslall", "--enable-mldsa", "--enable-certgen",
"--enable-certreq", "CPPFLAGS=-DWOLFSSL_MLDSA_NO_CHECK_KEY"]},
{"name": "mldsa-no-legacy-gates-smallest", "minutes": 2,
"comment": "Canonical option names only; pins that SIGN_SMALLEST_MEM still implies SIGN_SMALL_MEM when the legacy name gates are opted out",
"configure": ["--enable-cryptonly", "--enable-mldsa",
"CPPFLAGS=-DWOLFSSL_NO_DILITHIUM_LEGACY_GATES -DWOLFSSL_MLDSA_SIGN_SMALLEST_MEM"]},
{"name": "mldsa-smallest-checks-no-verify", "minutes": 2,
"comment": "Smallest memory signing with the y and w0 checks and verify compiled out, which leaves neither vector range check helper with a caller",
"configure": ["--enable-cryptonly", "--enable-mldsa",
"CPPFLAGS=-DWOLFSSL_MLDSA_SIGN_SMALLEST_MEM -DWOLFSSL_MLDSA_SIGN_CHECK_Y -DWOLFSSL_MLDSA_SIGN_CHECK_W0 -DWOLFSSL_MLDSA_NO_VERIFY"]},
{"name": "mldsa-sign-only", "minutes": 2,
"comment": "Default signer with verify compiled out; the non constant time vector range check has no caller here",
"configure": ["--enable-cryptonly", "--enable-mldsa=make,sign"]},
{"name": "mldsa-verify-smallest-default-sign", "minutes": 2,
"comment": "Smallest memory verify paired with the default signer, a combination every other row avoids",
"configure": ["--enable-cryptonly", "--enable-mldsa",
"CPPFLAGS=-DWOLFSSL_MLDSA_VERIFY_SMALLEST_MEM"]},
{"name": "mldsa-small-check-w0-only", "minutes": 2,
"comment": "Small memory signing with the w0 check but not the y check, which decides whether the vector range check helper is reachable",
"configure": ["--enable-cryptonly", "--enable-mldsa",
"CPPFLAGS=-DWOLFSSL_MLDSA_SIGN_SMALL_MEM -DWOLFSSL_MLDSA_SIGN_CHECK_W0"]}
]
24 changes: 24 additions & 0 deletions .github/workflows/wolfCrypt-Wconversion.yml
Original file line number Diff line number Diff line change
Expand Up @@ -90,6 +90,30 @@ jobs:
"--enable-xmss",
"CPPFLAGS=-DWOLFSSL_MLDSA_SIGN_SMALL_MEM -DWOLFSSL_MLDSA_SIGN_SMALL_MEM_PRECALC -DWOLFSSL_WC_LMS_SERIALIZE_STATE -Wconversion -Warith-conversion -Wenum-conversion -Wfloat-conversion -Wsign-conversion -Wcast-qual"],
"check": false},
{"name": "smallest-mem", "minutes": 1,
"configure": ["--enable-cryptonly", "--enable-all-crypto",
"--disable-examples", "--disable-benchmark",
"--disable-crypttests", "--enable-mlkem",
"--enable-slhdsa=yes,sha2", "--enable-mldsa", "--enable-lms",
"--enable-xmss",
"CPPFLAGS=-DWOLFSSL_MLDSA_SIGN_SMALLEST_MEM -DWOLFSSL_MLDSA_VERIFY_SMALLEST_MEM -DWOLFSSL_MLDSA_MAKE_KEY_SMALL_MEM -Wconversion -Warith-conversion -Wenum-conversion -Wfloat-conversion -Wsign-conversion -Wcast-qual -Wdeclaration-after-statement"],
"check": false},
{"name": "smallest-mem-no-verify", "minutes": 1,
"configure": ["--enable-cryptonly", "--enable-all-crypto",
"--disable-examples", "--disable-benchmark",
"--disable-crypttests", "--enable-mlkem",
"--enable-slhdsa=yes,sha2", "--enable-mldsa", "--enable-lms",
"--enable-xmss",
"CPPFLAGS=-DWOLFSSL_MLDSA_SIGN_SMALLEST_MEM -DWOLFSSL_MLDSA_NO_VERIFY -Wconversion -Warith-conversion -Wenum-conversion -Wfloat-conversion -Wsign-conversion -Wcast-qual -Wdeclaration-after-statement"],
"check": false},
{"name": "precalc-a-intelasm", "minutes": 1,
"configure": ["--enable-cryptonly", "--enable-all-crypto",
"--enable-intelasm", "--disable-examples", "--disable-benchmark",
"--disable-crypttests", "--enable-mlkem",
"--enable-slhdsa=yes,sha2", "--enable-mldsa", "--enable-lms",
"--enable-xmss",
"CPPFLAGS=-DWOLFSSL_MLDSA_SIGN_SMALL_MEM_PRECALC_A=1 -Wconversion -Warith-conversion -Wenum-conversion -Wfloat-conversion -Wsign-conversion -Wcast-qual -Wdeclaration-after-statement"],
"check": false},
{"name": "precalc-a-no-int128", "minutes": 1,
"configure": ["--enable-cryptonly", "--enable-all-crypto",
"--disable-examples", "--disable-benchmark",
Expand Down
1 change: 1 addition & 0 deletions .wolfssl_known_macro_extras
Original file line number Diff line number Diff line change
Expand Up @@ -998,6 +998,7 @@ WOLFSSL_MANUALLY_SELECT_DEVICE_CONFIG
WOLFSSL_MCDC_ALLOC_SWEEP
WOLFSSL_MDK5
WOLFSSL_MICROCHIP_AESGCM
WOLFSSL_MLDSA_VERIFY_ALLOW_MALLOC
WOLFSSL_MLDSA_VERIFY_PRECOMP_A
WOLFSSL_MLKEM_ASM_TEST
WOLFSSL_MLKEM_INVNTT_UNROLL
Expand Down
17 changes: 17 additions & 0 deletions ChangeLog.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,20 @@
# wolfSSL Release (unreleased)

## Behavioral Changes

* **Behavioral change (`WOLFSSL_MLDSA_VERIFY_SMALLEST_MEM` allocates)**: the option no longer forces `WOLFSSL_MLDSA_VERIFY_NO_MALLOC`, so the smallest memory verify now allocates its scratch buffers rather than pinning them in `wc_MlDsaKey`, and the key structure is smaller. Define `WOLFSSL_MLDSA_VERIFY_NO_MALLOC` as well to keep the heapless verify. by @Frauschi

* **Behavioral change (`WOLFSSL_NO_MALLOC` pins the ML-DSA verify buffers)**: when ML-DSA verification is compiled in, `WOLFSSL_NO_MALLOC` now selects the small memory verify along with `WOLFSSL_MLDSA_VERIFY_NO_MALLOC`, including in builds that use the canonical option names. The verify scratch buffers then live in `wc_MlDsaKey`, which makes each key about 12 kB larger. Previously the no-malloc option selected nothing on its own, so without a working allocator verification failed with `MEMORY_E`. A build that defines `WOLFSSL_NO_MALLOC` but still has an allocator, through `WOLFSSL_STATIC_MEMORY` or `wolfSSL_SetAllocators()`, can keep the smaller key and the allocating verify by defining `WOLFSSL_MLDSA_VERIFY_ALLOW_MALLOC`. by @Frauschi

## Post-Quantum Cryptography (PQC)

* Fixed the ML-DSA key structure member clash that stopped `WC_MLDSA_CACHE_PUB_VECTORS` building alongside `WOLFSSL_MLDSA_VERIFY_NO_MALLOC`, renaming the verify scratch member `t1` to `vt1`. by @Frauschi
* Reduced the ML-DSA small memory heap footprint: signing keeps w1 only in encoded form, key generation encodes t a polynomial at a time, and the new `WOLFSSL_MLDSA_SIGN_SMALLEST_MEM` holds one polynomial of y, roughly halving the signing peak. by @Frauschi
* Sped up ML-DSA small memory signing by walking matrix A a column at a time so each polynomial of y is transformed once rather than once per row. `WOLFSSL_MLDSA_SMALL_MEM_POLY64` no longer applies to signing. by @Frauschi
* Fixed `--enable-mldsa=<level>` naming only a parameter set, which left key generation, signing and verification all disabled. by @Frauschi
* `wc_CheckPrivateKey()` now reports `NOT_COMPILED_IN` for an ML-DSA certificate and key when the key pair check is compiled out with `WOLFSSL_MLDSA_NO_CHECK_KEY`, rather than failing to build. Such a build cannot confirm the pair matches, so `wolfSSL_CTX_check_private_key()`, `wolfSSL_check_private_key()` and `wolfSSL_X509_check_private_key()` report a mismatch for it; loading the certificate and key is unaffected. by @Frauschi
* Fixed ML-DSA key generation with `WOLFSSL_MLDSA_MAKE_KEY_SMALL_MEM` keeping the matrix and vector caches (`WC_MLDSA_CACHE_*`) of the key it replaced. A key generated into an object that already held another key was signed and verified against the old key's cached values, so its signatures failed to verify. by @Frauschi

# wolfSSL Release 5.9.4 (Sep 25, 2026)

Release 5.9.4 has been developed according to wolfSSL's development and QA
Expand Down
13 changes: 13 additions & 0 deletions configure.ac
Original file line number Diff line number Diff line change
Expand Up @@ -2423,6 +2423,19 @@ then
ENABLED_MLDSA87=yes
fi

# Likewise, naming only a parameter set, for example --enable-mldsa=44,
# selects no operation, which would disable everything. verify-only names an
# operation, so it is unaffected.
if test "$ENABLED_MLDSA" != "no" && \
test "$ENABLED_MLDSA_MAKE_KEY" = "no" && \
test "$ENABLED_MLDSA_SIGN" = "no" && \
test "$ENABLED_MLDSA_VERIFY" = "no"
then
ENABLED_MLDSA_MAKE_KEY=yes
ENABLED_MLDSA_SIGN=yes
ENABLED_MLDSA_VERIFY=yes
fi

# XMSS
AC_ARG_ENABLE([xmss],
[AS_HELP_STRING([--enable-xmss],[Enable stateful XMSS/XMSS^MT signatures (default: disabled)])],
Expand Down
7 changes: 7 additions & 0 deletions tests/api/test_ossl_x509_crypto.c
Original file line number Diff line number Diff line change
Expand Up @@ -155,7 +155,14 @@ int test_wolfSSL_X509_check_private_key_mldsa(void)

ExpectNotNull(x509 = X509_load_certificate_file(
cases[i].certPath, SSL_FILETYPE_ASN1));
#ifdef WOLFSSL_MLDSA_CHECK_KEY
ExpectIntEQ(X509_check_private_key(x509, pkey), 1);
#else
/* Without the key pair check the match cannot be confirmed, so
* wc_CheckPrivateKey() reports NOT_COMPILED_IN and the pair is
* rejected. */
ExpectIntEQ(X509_check_private_key(x509, pkey), 0);
#endif

if (cases[i].mismatchCertPath != NULL) {
ExpectNotNull(mismatchX509 = X509_load_certificate_file(
Expand Down
156 changes: 154 additions & 2 deletions tests/unit-mcdc/test_wc_mldsa_whitebox.c
Original file line number Diff line number Diff line change
Expand Up @@ -219,7 +219,7 @@ static void wb_get_params(void)
* Drive independence pairs: both F (in range), left T (a<=nhi),
* right T with left F (a>=hi). Plus the vector-level (ret==1)&&(i<l).
* ------------------------------------------------------------------ */
#if !defined(WOLFSSL_MLDSA_NO_SIGN) || !defined(WOLFSSL_MLDSA_NO_VERIFY)
#ifndef WOLFSSL_MLDSA_NO_VERIFY
static void wb_check_low(void)
{
sword32 a[2 * MLDSA_N];
Expand Down Expand Up @@ -251,6 +251,7 @@ static void wb_check_low(void)
WB_NOTE("mldsa_check_low(>=hi) expected 0");
}

#ifndef WOLFSSL_MLDSA_VERIFY_SMALLEST_MEM
/* Vector level: two polynomials, both in range -> (ret==1)&&(i<l) walks
* both, returns 1; then a first-poly-out-of-range -> early ret 0. */
for (j = 0; j < 2 * MLDSA_N; j++) {
Expand All @@ -265,10 +266,154 @@ static void wb_check_low(void)
if (ret != 0) {
WB_NOTE("mldsa_vec_check_low_c(out) expected 0");
}
#endif
WB_OK("mldsa_check_low / vec_check_low_c operand pairs exercised");
}
#endif

#ifndef WOLFSSL_MLDSA_NO_SIGN
/* ------------------------------------------------------------------ *
* mldsa_check_low_ct / mldsa_vec_check_low_ct: the constant time forms
* gate every signing range check, so drive the four boundary values and
* confirm no early exit hides a later failure.
* ------------------------------------------------------------------ */
static void wb_check_low_ct(void)
{
sword32 a[2 * MLDSA_N];
sword32 hi = 1 << 17;
unsigned int j;
int ret = 0;

for (j = 0; j < 2 * MLDSA_N; j++) {
a[j] = 0;
}

/* Boundaries: hi-1 and -hi+1 are in range, hi and -hi are not. */
a[0] = hi - 1;
if (mldsa_check_low_ct(a, hi) != 1) {
WB_NOTE("mldsa_check_low_ct(hi-1) expected 1");
}
a[0] = -hi + 1;
if (mldsa_check_low_ct(a, hi) != 1) {
WB_NOTE("mldsa_check_low_ct(-hi+1) expected 1");
}
a[0] = hi;
if (mldsa_check_low_ct(a, hi) != 0) {
WB_NOTE("mldsa_check_low_ct(hi) expected 0");
}
a[0] = -hi;
if (mldsa_check_low_ct(a, hi) != 0) {
WB_NOTE("mldsa_check_low_ct(-hi) expected 0");
}

/* The last coefficient must count: an early exit would miss it. */
a[0] = 0;
a[MLDSA_N - 1] = hi;
if (mldsa_check_low_ct(a, hi) != 0) {
WB_NOTE("mldsa_check_low_ct(last coeff) expected 0");
}
a[MLDSA_N - 1] = 0;

/* Agreement with the branching form wherever both are compiled. */
#if !defined(WOLFSSL_MLDSA_NO_VERIFY)
for (j = 0; j < MLDSA_N; j++) {
a[j] = (j & 1) ? (hi - 1) : (-hi + 1);
}
ret = mldsa_check_low(a, hi);
if (mldsa_check_low_ct(a, hi) != ret) {
WB_NOTE("check_low_ct disagrees with check_low (in range)");
}
a[MLDSA_N / 2] = hi;
ret = mldsa_check_low(a, hi);
if (mldsa_check_low_ct(a, hi) != ret) {
WB_NOTE("check_low_ct disagrees with check_low (out of range)");
}
#else
(void)ret;
#endif

#if (defined(WOLFSSL_MLDSA_SIGN_CHECK_Y) && \
!defined(WOLFSSL_MLDSA_SIGN_SMALLEST_MEM)) || \
(defined(WOLFSSL_MLDSA_SIGN_CHECK_W0) && \
!defined(WOLFSSL_MLDSA_SIGN_SMALL_MEM))
/* Vector form must fail on a bad coefficient in the LAST polynomial,
* which only holds because it does not exit early. */
for (j = 0; j < 2 * MLDSA_N; j++) {
a[j] = 0;
}
if (mldsa_vec_check_low_ct(a, 2, hi) != 1) {
WB_NOTE("mldsa_vec_check_low_ct(in-range,l=2) expected 1");
}
a[2 * MLDSA_N - 1] = hi;
if (mldsa_vec_check_low_ct(a, 2, hi) != 0) {
WB_NOTE("mldsa_vec_check_low_ct(last poly) expected 0");
}
#endif

WB_OK("mldsa_check_low_ct / vec_check_low_ct boundaries exercised");
}
#endif

#if !defined(WOLFSSL_MLDSA_NO_SIGN) && \
defined(WOLFSSL_MLDSA_SIGN_SMALLEST_MEM)
/* ------------------------------------------------------------------ *
* mldsa_poly_checksum: the smallest memory signer binds the polynomial of y
* it regenerates for z to the one it used for w, raising BAD_COND_E when they
* differ. That branch needs a fault to reach, so the property is tested
* directly: any single changed coefficient must change the checksum.
* ------------------------------------------------------------------ */
static void wb_poly_checksum(void)
{
sword32 a[MLDSA_N];
sword32 base;
unsigned int j;
unsigned int pos[4];
unsigned int p;

for (j = 0; j < MLDSA_N; j++) {
a[j] = (sword32)(j * 7);
}
base = mldsa_poly_checksum(a);

/* Same input, same checksum: the comparison in the signer only fires
* on a real difference. */
if (mldsa_poly_checksum(a) != base) {
WB_NOTE("mldsa_poly_checksum is not deterministic");
}

/* First, last and two interior coefficients. The rotate in the
* checksum is what makes position matter. */
pos[0] = 0;
pos[1] = 1;
pos[2] = MLDSA_N / 2;
pos[3] = MLDSA_N - 1;
for (p = 0; p < 4; p++) {
sword32 keep = a[pos[p]];

a[pos[p]] = keep ^ 1;
if (mldsa_poly_checksum(a) == base) {
WB_NOTE("mldsa_poly_checksum missed a changed coefficient");
}
a[pos[p]] = keep;
}

/* Two coefficients swapped: same multiset, different polynomial. */
if (MLDSA_N >= 2) {
sword32 k0 = a[0];

a[0] = a[1];
a[1] = k0;
if (mldsa_poly_checksum(a) == base) {
WB_NOTE("mldsa_poly_checksum missed a reordering");
}
a[1] = a[0];
a[0] = k0;
}

WB_OK("mldsa_poly_checksum change detection exercised");
}
#endif /* WOLFSSL_MLDSA_SIGN_SMALLEST_MEM */

/* ------------------------------------------------------------------ *
* mldsa_check_hint: two inner loop decisions that the 3-outcome test
* above never reaches because their FALSE/TRUE pair only shows up with
Expand Down Expand Up @@ -1420,9 +1565,16 @@ int main(void)
return 0;
#else
wb_get_params();
#if !defined(WOLFSSL_MLDSA_NO_SIGN) || !defined(WOLFSSL_MLDSA_NO_VERIFY)
#ifndef WOLFSSL_MLDSA_NO_VERIFY
wb_check_low();
#endif
#ifndef WOLFSSL_MLDSA_NO_SIGN
wb_check_low_ct();
#endif
#if !defined(WOLFSSL_MLDSA_NO_SIGN) && \
defined(WOLFSSL_MLDSA_SIGN_SMALLEST_MEM)
wb_poly_checksum();
#endif
#ifndef WOLFSSL_MLDSA_NO_SIGN
#ifndef WOLFSSL_NO_ML_DSA_44
wb_make_hint_88();
Expand Down
Loading
Loading