Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 13 additions & 0 deletions .github/configs/pq-all.json
Original file line number Diff line number Diff line change
Expand Up @@ -154,6 +154,19 @@
"--enable-dtls-mtu", "--enable-dtls-frag-ch", "--enable-dtlscid",
"--enable-mlkem=make,enc,dec,768", "--disable-qt",
"CPPFLAGS=-pedantic -Wdeclaration-after-statement -Wnull-dereference -DWOLFCRYPT_TEST_LINT -DNO_WOLFSSL_CIPHER_SUITE_TEST -DTEST_LIBWOLFSSL_SOURCES_INCLUSION_SEQUENCE"]},
{"name": "slhdsa-only-asm", "minutes": 3,
"comment": "SLH-DSA with the Intel assembly but without ML-KEM/ML-DSA; the 8-way AVX512 Keccak permutation is emitted for those, so this catches SLH-DSA calling a symbol the SHA-3 assembly did not build. Linking is checked on any runner, but the 8-way code only executes on an AVX512F+AVX512BW one",
"configure": ["--enable-intelasm", "--enable-sp-asm",
"--enable-slhdsa=yes,sha2", "--disable-mlkem", "--disable-mldsa"]},
{"name": "slhdsa-no-shake-x8", "minutes": 3,
"comment": "SLH-DSA with the Intel assembly but the eight-way AVX512 Keccak path pinned off, so the four-way path is covered whatever the runner CPU; paired with slhdsa-only-asm, a KAT that passes here and fails there isolates the eight-way code",
"configure": ["--enable-intelasm", "--enable-sp-asm", "--enable-slhdsa",
"CPPFLAGS=-DWOLFSSL_SLHDSA_NO_SHAKE_X8"]},
{"name": "lms-slhdsa-no-hash-raw", "minutes": 3,
"comment": "No raw hash access, as the PSA and hardware SHA-256 ports have; wc_Sha256HashBlock() is not built, so this catches LMS, SLH-DSA or the test suite calling it anyway",
"configure": ["--enable-lms", "--enable-xmss",
"--enable-slhdsa=yes,sha2",
"CPPFLAGS=-DWOLFSSL_NO_HASH_RAW"]},
{"name": "mldsa-no-asn1-opensslextra", "minutes": 2.8,
"configure": ["--enable-intelasm", "--enable-sp-asm",
"--enable-dilithium=yes", "--enable-opensslextra",
Expand Down
2 changes: 1 addition & 1 deletion .wolfssl_known_macro_extras
Original file line number Diff line number Diff line change
Expand Up @@ -987,7 +987,6 @@ WOLFSSL_LINUXKM_USE_GET_RANDOM_KPROBES
WOLFSSL_LINUXKM_USE_GET_RANDOM_USER_KRETPROBE
WOLFSSL_LINUXKM_USE_MUTEXES
WOLFSSL_LMS_CACHE_BITS
WOLFSSL_LMS_FULL_HASH
WOLFSSL_LMS_MAX_HEIGHT
WOLFSSL_LMS_MAX_LEVELS
WOLFSSL_LMS_ROOT_LEVELS
Expand Down Expand Up @@ -1130,6 +1129,7 @@ WOLFSSL_SHA3_PPC64_BLOCKS_N
WOLFSSL_SHUTDOWNONCE
WOLFSSL_SILABS_TRNG
WOLFSSL_SLHDSA_FULL_HASH
WOLFSSL_SLHDSA_NO_SHAKE_X8
WOLFSSL_SLHDSA_NO_VERIFY_ONLY
WOLFSSL_SNIFFER_NO_RECOVERY
WOLFSSL_SP_FAST_NCT_EXPTMOD
Expand Down
22 changes: 22 additions & 0 deletions ChangeLog.md
Original file line number Diff line number Diff line change
Expand Up @@ -622,6 +622,24 @@ PR stands for Pull Request, and PR <NUMBER> references a GitHub pull request num
* Migrate internal ML-KEM consumers to canonical wc_MlKemKey API by @Frauschi (PR 10571)
* Add PQ documentation for LMS, ML-DSA, ML-KEM, XMSS by @kaleb-himes (PR 10514)
* Various leak / alloc and zeroization fixes for SLH-DSA by @Frauschi (PR 10698)
* Hash the block after the pre-computed PK.seed midstate directly for the
SLH-DSA SHA2 parameter sets, rather than copying a hash object and
streaming two updates into it for every hash. by @Frauschi
* Use the 8-way AVX512 Keccak permutation for the SLH-DSA WOTS+ chains on
capable CPUs, which the four-way AVX2 path had to itself. by @Frauschi
* Extended the 8-way AVX512 Keccak permutation to the SLH-DSA FORS subtrees.
by @Frauschi
* Give each SLH-DSA WOTS+ public key and FORS subtree one Keccak state to
reuse, instead of allocating one per group of hashes. A SHAKE-128s
signature now makes about twelve times fewer allocations. by @Frauschi
* Use the 8-way AVX512 Keccak permutation when completing the WOTS+ chains of
an SLH-DSA signature, which speeds up verification. The 8-way verify path
holds its Keccak state and chain values on the stack for the length of one
WOTS+ public key, so peak stack during verification grows by about 2.3 kB on
AVX512 builds; WOLFSSL_SMALL_STACK moves them to the heap. by @Frauschi
* Give a whole SLH-DSA XMSS subtree one set of WOTS+ buffers to reuse. A
SHAKE-128s signature now makes about 1000 allocations where it made about
144000. by @Frauschi

## TLS/DTLS

Expand Down Expand Up @@ -729,6 +747,10 @@ PR stands for Pull Request, and PR <NUMBER> references a GitHub pull request num
* Fixed the SGX build to not require fcntl.h. by @JacobBarthelmeh (PR 10524)
* Various linuxkm Fenrir fixes by @douzzer (PR 10688)
* Various bsdkm fixes and cleanup by @philljj (PR 10565)
* Added `WOLFSSL_HAVE_SHA256_HASH_BLOCK` to report whether
`wc_Sha256HashBlock()` is built. LMS gated its use on a macro that was
never defined, so ports without the software SHA-256 transform called a
function that was not compiled. by @Frauschi

## Bug Fixes

Expand Down
4 changes: 1 addition & 3 deletions tests/api/test_sha256.c
Original file line number Diff line number Diff line change
Expand Up @@ -220,9 +220,7 @@ int test_wc_Sha256Transform(void)
int test_wc_Sha256HashBlock_unaligned(void)
{
EXPECT_DECLS;
#if defined(WOLFSSL_HAVE_LMS) && !defined(WOLFSSL_LMS_FULL_HASH) && \
!defined(NO_SHA256) && !defined(WOLFSSL_KCAPI_HASH) && \
!defined(WOLF_CRYPTO_CB_ONLY_SHA256)
#ifdef WOLFSSL_HAVE_SHA256_HASH_BLOCK
wc_Sha256 sha256;
byte buf[WC_SHA256_BLOCK_SIZE * 2];
byte aligned[WC_SHA256_DIGEST_SIZE];
Expand Down
65 changes: 65 additions & 0 deletions tests/api/test_slhdsa.c
Original file line number Diff line number Diff line change
Expand Up @@ -855,6 +855,47 @@ int test_wc_slhdsa_verify(void)
/*
* Test combined sign and verify for all parameter sets.
*/
#if defined(WOLFSSL_HAVE_SLHDSA) && !defined(WOLFSSL_SLHDSA_VERIFY_ONLY)
/* Number of single bit flips applied across one signature. */
#define TEST_SLHDSA_NEG_FLIPS 9

/* Verify has to reject a flipped signature bit, a changed message or context,
* and an absent context. The inputs are restored before returning. */
static int slhdsa_verify_reject(SlhDsaKey* key, byte* ctx, byte ctxSz,
byte* msg, word32 msgSz, byte* sig, word32 sigLen)
{
EXPECT_DECLS;
word32 off;
int i;

for (i = 0; (i < TEST_SLHDSA_NEG_FLIPS) && EXPECT_SUCCESS(); i++) {
/* Evenly spaced, first and last byte included. */
off = (word32)i * (sigLen - 1) / (TEST_SLHDSA_NEG_FLIPS - 1);
sig[off] ^= 0x01;
ExpectIntEQ(wc_SlhDsaKey_Verify(key, ctx, ctxSz, msg, msgSz, sig,
sigLen), WC_NO_ERR_TRACE(SIG_VERIFY_E));
sig[off] ^= 0x01;
}

msg[0] ^= 0x01;
ExpectIntEQ(wc_SlhDsaKey_Verify(key, ctx, ctxSz, msg, msgSz, sig, sigLen),
WC_NO_ERR_TRACE(SIG_VERIFY_E));
msg[0] ^= 0x01;

ctx[0] ^= 0x01;
ExpectIntEQ(wc_SlhDsaKey_Verify(key, ctx, ctxSz, msg, msgSz, sig, sigLen),
WC_NO_ERR_TRACE(SIG_VERIFY_E));
ctx[0] ^= 0x01;

ExpectIntEQ(wc_SlhDsaKey_Verify(key, NULL, 0, msg, msgSz, sig, sigLen),
WC_NO_ERR_TRACE(SIG_VERIFY_E));
ExpectIntEQ(wc_SlhDsaKey_Verify(key, ctx, ctxSz, msg, msgSz, sig, sigLen),
0);

return EXPECT_RESULT();
}
#endif /* WOLFSSL_HAVE_SLHDSA && !WOLFSSL_SLHDSA_VERIFY_ONLY */

int test_wc_slhdsa_sign_vfy(void)
{
EXPECT_DECLS;
Expand Down Expand Up @@ -886,6 +927,8 @@ int test_wc_slhdsa_sign_vfy(void)
ExpectIntEQ(sigLen, WC_SLHDSA_SHAKE128S_SIG_LEN);
ExpectIntEQ(wc_SlhDsaKey_Verify(&key, ctx, sizeof(ctx), msg, sizeof(msg),
sig, sigLen), 0);
ExpectIntEQ(slhdsa_verify_reject(&key, ctx, (byte)sizeof(ctx), msg,
(word32)sizeof(msg), sig, sigLen), TEST_SUCCESS);

wc_SlhDsaKey_Free(&key);
#endif
Expand All @@ -901,6 +944,8 @@ int test_wc_slhdsa_sign_vfy(void)
ExpectIntEQ(sigLen, WC_SLHDSA_SHAKE128F_SIG_LEN);
ExpectIntEQ(wc_SlhDsaKey_Verify(&key, ctx, sizeof(ctx), msg, sizeof(msg),
sig, sigLen), 0);
ExpectIntEQ(slhdsa_verify_reject(&key, ctx, (byte)sizeof(ctx), msg,
(word32)sizeof(msg), sig, sigLen), TEST_SUCCESS);

wc_SlhDsaKey_Free(&key);
#endif
Expand All @@ -916,6 +961,8 @@ int test_wc_slhdsa_sign_vfy(void)
ExpectIntEQ(sigLen, (word32)wc_SlhDsaKey_SigSize(&key));
ExpectIntEQ(wc_SlhDsaKey_Verify(&key, ctx, sizeof(ctx), msg, sizeof(msg),
sig, sigLen), 0);
ExpectIntEQ(slhdsa_verify_reject(&key, ctx, (byte)sizeof(ctx), msg,
(word32)sizeof(msg), sig, sigLen), TEST_SUCCESS);

wc_SlhDsaKey_Free(&key);
#endif
Expand All @@ -931,6 +978,8 @@ int test_wc_slhdsa_sign_vfy(void)
ExpectIntEQ(sigLen, WC_SLHDSA_SHAKE192F_SIG_LEN);
ExpectIntEQ(wc_SlhDsaKey_Verify(&key, ctx, sizeof(ctx), msg, sizeof(msg),
sig, sigLen), 0);
ExpectIntEQ(slhdsa_verify_reject(&key, ctx, (byte)sizeof(ctx), msg,
(word32)sizeof(msg), sig, sigLen), TEST_SUCCESS);

wc_SlhDsaKey_Free(&key);
#endif
Expand All @@ -946,6 +995,8 @@ int test_wc_slhdsa_sign_vfy(void)
ExpectIntEQ(sigLen, WC_SLHDSA_SHAKE256S_SIG_LEN);
ExpectIntEQ(wc_SlhDsaKey_Verify(&key, ctx, sizeof(ctx), msg, sizeof(msg),
sig, sigLen), 0);
ExpectIntEQ(slhdsa_verify_reject(&key, ctx, (byte)sizeof(ctx), msg,
(word32)sizeof(msg), sig, sigLen), TEST_SUCCESS);

wc_SlhDsaKey_Free(&key);
#endif
Expand All @@ -961,6 +1012,8 @@ int test_wc_slhdsa_sign_vfy(void)
ExpectIntEQ(sigLen, WC_SLHDSA_SHAKE256F_SIG_LEN);
ExpectIntEQ(wc_SlhDsaKey_Verify(&key, ctx, sizeof(ctx), msg, sizeof(msg),
sig, sigLen), 0);
ExpectIntEQ(slhdsa_verify_reject(&key, ctx, (byte)sizeof(ctx), msg,
(word32)sizeof(msg), sig, sigLen), TEST_SUCCESS);

wc_SlhDsaKey_Free(&key);
#endif
Expand All @@ -976,6 +1029,8 @@ int test_wc_slhdsa_sign_vfy(void)
ExpectIntEQ(sigLen, WC_SLHDSA_SHA2_128S_SIG_LEN);
ExpectIntEQ(wc_SlhDsaKey_Verify(&key, ctx, sizeof(ctx), msg, sizeof(msg),
sig, sigLen), 0);
ExpectIntEQ(slhdsa_verify_reject(&key, ctx, (byte)sizeof(ctx), msg,
(word32)sizeof(msg), sig, sigLen), TEST_SUCCESS);
wc_SlhDsaKey_Free(&key);
#endif
#ifdef WOLFSSL_SLHDSA_PARAM_SHA2_128F
Expand All @@ -988,6 +1043,8 @@ int test_wc_slhdsa_sign_vfy(void)
ExpectIntEQ(sigLen, WC_SLHDSA_SHA2_128F_SIG_LEN);
ExpectIntEQ(wc_SlhDsaKey_Verify(&key, ctx, sizeof(ctx), msg, sizeof(msg),
sig, sigLen), 0);
ExpectIntEQ(slhdsa_verify_reject(&key, ctx, (byte)sizeof(ctx), msg,
(word32)sizeof(msg), sig, sigLen), TEST_SUCCESS);
wc_SlhDsaKey_Free(&key);
#endif
#ifdef WOLFSSL_SLHDSA_PARAM_SHA2_192S
Expand All @@ -1000,6 +1057,8 @@ int test_wc_slhdsa_sign_vfy(void)
ExpectIntEQ(sigLen, WC_SLHDSA_SHA2_192S_SIG_LEN);
ExpectIntEQ(wc_SlhDsaKey_Verify(&key, ctx, sizeof(ctx), msg, sizeof(msg),
sig, sigLen), 0);
ExpectIntEQ(slhdsa_verify_reject(&key, ctx, (byte)sizeof(ctx), msg,
(word32)sizeof(msg), sig, sigLen), TEST_SUCCESS);
wc_SlhDsaKey_Free(&key);
#endif
#ifdef WOLFSSL_SLHDSA_PARAM_SHA2_192F
Expand All @@ -1012,6 +1071,8 @@ int test_wc_slhdsa_sign_vfy(void)
ExpectIntEQ(sigLen, WC_SLHDSA_SHA2_192F_SIG_LEN);
ExpectIntEQ(wc_SlhDsaKey_Verify(&key, ctx, sizeof(ctx), msg, sizeof(msg),
sig, sigLen), 0);
ExpectIntEQ(slhdsa_verify_reject(&key, ctx, (byte)sizeof(ctx), msg,
(word32)sizeof(msg), sig, sigLen), TEST_SUCCESS);
wc_SlhDsaKey_Free(&key);
#endif
#ifdef WOLFSSL_SLHDSA_PARAM_SHA2_256S
Expand All @@ -1024,6 +1085,8 @@ int test_wc_slhdsa_sign_vfy(void)
ExpectIntEQ(sigLen, WC_SLHDSA_SHA2_256S_SIG_LEN);
ExpectIntEQ(wc_SlhDsaKey_Verify(&key, ctx, sizeof(ctx), msg, sizeof(msg),
sig, sigLen), 0);
ExpectIntEQ(slhdsa_verify_reject(&key, ctx, (byte)sizeof(ctx), msg,
(word32)sizeof(msg), sig, sigLen), TEST_SUCCESS);
wc_SlhDsaKey_Free(&key);
#endif
#ifdef WOLFSSL_SLHDSA_PARAM_SHA2_256F
Expand All @@ -1036,6 +1099,8 @@ int test_wc_slhdsa_sign_vfy(void)
ExpectIntEQ(sigLen, WC_SLHDSA_SHA2_256F_SIG_LEN);
ExpectIntEQ(wc_SlhDsaKey_Verify(&key, ctx, sizeof(ctx), msg, sizeof(msg),
sig, sigLen), 0);
ExpectIntEQ(slhdsa_verify_reject(&key, ctx, (byte)sizeof(ctx), msg,
(word32)sizeof(msg), sig, sigLen), TEST_SUCCESS);
wc_SlhDsaKey_Free(&key);
#endif
#endif /* WOLFSSL_SLHDSA_SHA2 */
Expand Down
4 changes: 2 additions & 2 deletions tests/unit-mcdc/mcdc_fault_hash.h
Original file line number Diff line number Diff line change
Expand Up @@ -207,7 +207,7 @@ MCDC_FH_MAYBE_UNUSED static int mcdc_fh_Sha256Final(wc_Sha256* sha, byte* hash)
return MCDC_FH_ERR;
return wc_Sha256Final(sha, hash);
}
#if defined(WOLFSSL_HAVE_LMS) && !defined(WOLFSSL_LMS_FULL_HASH)
#ifdef WOLFSSL_HAVE_SHA256_HASH_BLOCK
MCDC_FH_MAYBE_UNUSED static int mcdc_fh_Sha256HashBlock(wc_Sha256* sha, const unsigned char* data,
unsigned char* hash)
{
Expand Down Expand Up @@ -385,7 +385,7 @@ MCDC_FH_MAYBE_UNUSED static int mcdc_fh_AesSetKeyDirect(Aes* aes, const byte* ke
#define wc_Sha256Update(a, b, c) mcdc_fh_Sha256Update((a), (b), (c))
#undef wc_Sha256Final
#define wc_Sha256Final(a, b) mcdc_fh_Sha256Final((a), (b))
#if defined(WOLFSSL_HAVE_LMS) && !defined(WOLFSSL_LMS_FULL_HASH)
#ifdef WOLFSSL_HAVE_SHA256_HASH_BLOCK
#undef wc_Sha256HashBlock
#define wc_Sha256HashBlock(a, b, c) \
mcdc_fh_Sha256HashBlock((a), (b), (c))
Expand Down
19 changes: 17 additions & 2 deletions wolfcrypt/src/sha256.c
Original file line number Diff line number Diff line change
Expand Up @@ -146,6 +146,14 @@ on the specific device platform.
#endif
#endif

/* The arms below and the WOLFSSL_KCAPI_HASH block compile no software
* transform, so the cross-check inside the software arm never reaches them. */
#if defined(WOLFSSL_HAVE_SHA256_HASH_BLOCK) && \
(defined(WOLFSSL_TI_HASH) || defined(WOLFSSL_CRYPTOCELL) || \
defined(MAX3266X_SHA) || defined(WOLFSSL_KCAPI_HASH))
#error "WOLFSSL_HAVE_SHA256_HASH_BLOCK set without a SHA-256 transform"
#endif

#if defined(WOLFSSL_TI_HASH)
/* #include <wolfcrypt/src/port/ti/ti-hash.c> included by wc_port.c */
#elif defined(WOLFSSL_CRYPTOCELL)
Expand Down Expand Up @@ -1884,6 +1892,12 @@ static WC_INLINE int Transform_Sha256_Len(wc_Sha256* sha256, const byte* data,
#endif
/* End wc_ software implementation */

/* The port list behind WOLFSSL_HAVE_SHA256_HASH_BLOCK in sha256.h has to
* agree with the arms that select a transform here. */
#if defined(WOLFSSL_HAVE_SHA256_HASH_BLOCK) && !defined(XTRANSFORM)
#error "WOLFSSL_HAVE_SHA256_HASH_BLOCK set without a SHA-256 transform"
#endif

#ifdef XTRANSFORM

static WC_INLINE void AddLength(wc_Sha256* sha256, word32 len)
Expand Down Expand Up @@ -2422,7 +2436,7 @@ static WC_INLINE int Transform_Sha256_Len(wc_Sha256* sha256, const byte* data,
}
#endif /* OPENSSL_EXTRA || HAVE_CURL */

#if defined(WOLFSSL_HAVE_LMS) && !defined(WOLFSSL_LMS_FULL_HASH)
#ifdef WOLFSSL_HAVE_SHA256_HASH_BLOCK
/* One block will be used from data.
* hash must be big enough to hold all of digest output.
*/
Expand Down Expand Up @@ -2465,6 +2479,7 @@ static WC_INLINE int Transform_Sha256_Len(wc_Sha256* sha256, const byte* data,
word32 buf[WC_SHA256_DIGEST_SIZE / sizeof(word32)];
ByteReverseWords(buf, sha256->digest, WC_SHA256_DIGEST_SIZE);
XMEMCPY(hash, buf, WC_SHA256_DIGEST_SIZE);
ForceZero(buf, sizeof(buf));
}
#endif
else {
Expand Down Expand Up @@ -2531,7 +2546,7 @@ static WC_INLINE int Transform_Sha256_Len(wc_Sha256* sha256, const byte* data,

return ret;
}
#endif /* WOLFSSL_HAVE_LMS && !WOLFSSL_LMS_FULL_HASH */
#endif /* WOLFSSL_HAVE_SHA256_HASH_BLOCK */
#endif /* !WOLFSSL_KCAPI_HASH */

#endif /* XTRANSFORM */
Expand Down
8 changes: 5 additions & 3 deletions wolfcrypt/src/sha3_asm.S
Original file line number Diff line number Diff line change
Expand Up @@ -36870,7 +36870,7 @@ _sha3_256_blocksx4_seed_64_avx2:
#endif /* HAVE_INTEL_AVX512 */
#endif /* NO_AVX512_SUPPORT */
#ifdef HAVE_INTEL_AVX512
#if defined(WOLFSSL_HAVE_FRODOKEM) || defined(WOLFSSL_HAVE_MLKEM) || defined(WOLFSSL_HAVE_MLDSA)
#if defined(WOLFSSL_HAVE_FRODOKEM) || defined(WOLFSSL_HAVE_MLKEM) || defined(WOLFSSL_HAVE_MLDSA) || defined(WOLFSSL_HAVE_SLHDSA)
#ifndef __APPLE__
.data
#else
Expand Down Expand Up @@ -36978,7 +36978,7 @@ L_sha3_x8_avx512_r:
.quad 0x8000000080008008,0x8000000080008008
.quad 0x8000000080008008,0x8000000080008008
.quad 0x8000000080008008,0x8000000080008008
#endif /* defined(WOLFSSL_HAVE_FRODOKEM) || defined(WOLFSSL_HAVE_MLKEM) || defined(WOLFSSL_HAVE_MLDSA) */
#endif /* defined(WOLFSSL_HAVE_FRODOKEM) || defined(WOLFSSL_HAVE_MLKEM) || defined(WOLFSSL_HAVE_MLDSA) || defined(WOLFSSL_HAVE_SLHDSA) */
#ifdef WOLFSSL_HAVE_FRODOKEM
#ifndef __APPLE__
.text
Expand Down Expand Up @@ -39922,7 +39922,7 @@ L_sha3_blocksx8_out_avx512_done:
.size sha3_blocksx8_out_avx512,.-sha3_blocksx8_out_avx512
#endif /* __APPLE__ */
#endif /* WOLFSSL_HAVE_FRODOKEM */
#if defined(WOLFSSL_HAVE_MLKEM) || defined(WOLFSSL_HAVE_MLDSA)
#if defined(WOLFSSL_HAVE_MLKEM) || defined(WOLFSSL_HAVE_MLDSA) || defined(WOLFSSL_HAVE_SLHDSA)
#ifndef __APPLE__
.text
.globl sha3_blocksx8_avx512
Expand Down Expand Up @@ -42801,6 +42801,8 @@ _sha3_blocksx8_avx512:
#ifndef __APPLE__
.size sha3_blocksx8_avx512,.-sha3_blocksx8_avx512
#endif /* __APPLE__ */
#endif /* defined(WOLFSSL_HAVE_MLKEM) || defined(WOLFSSL_HAVE_MLDSA) || defined(WOLFSSL_HAVE_SLHDSA) */
#if defined(WOLFSSL_HAVE_MLKEM) || defined(WOLFSSL_HAVE_MLDSA)
#ifndef __APPLE__
.data
#else
Expand Down
15 changes: 15 additions & 0 deletions wolfcrypt/src/sha3_asm.asm
Original file line number Diff line number Diff line change
Expand Up @@ -36889,6 +36889,9 @@ ENDIF
IFDEF WOLFSSL_HAVE_MLDSA
wc_masm_cond_2 = 1
ENDIF
IFDEF WOLFSSL_HAVE_SLHDSA
wc_masm_cond_2 = 1
ENDIF
IF wc_masm_cond_2
_DATA SEGMENT
ALIGN 16
Expand Down Expand Up @@ -39954,6 +39957,9 @@ ENDIF
IFDEF WOLFSSL_HAVE_MLDSA
wc_masm_cond_3 = 1
ENDIF
IFDEF WOLFSSL_HAVE_SLHDSA
wc_masm_cond_3 = 1
ENDIF
IF wc_masm_cond_3
_TEXT SEGMENT READONLY PARA
sha3_blocksx8_avx512 PROC
Expand Down Expand Up @@ -42842,6 +42848,15 @@ sha3_blocksx8_avx512 PROC
ret
sha3_blocksx8_avx512 ENDP
_TEXT ENDS
ENDIF
wc_masm_cond_4 = 0
IFDEF WOLFSSL_HAVE_MLKEM
wc_masm_cond_4 = 1
ENDIF
IFDEF WOLFSSL_HAVE_MLDSA
wc_masm_cond_4 = 1
ENDIF
IF wc_masm_cond_4
_DATA SEGMENT
ALIGN 16
L_sha3_128_blocksx8_seed_avx512_end_mark QWORD 8000000000000000h, 8000000000000000h
Expand Down
Loading
Loading