Repository navigation
Conversation
psa_config.h only looked at the AES block cipher core, so two non-constant-time configurations passed its check. GHASH. Only the 64-bit GHASH wolfCrypt builds with no GCM method set is masked. GCM_SMALL and GCM_WORD32 branch on the hash subkey, and GCM_TABLE and GCM_TABLE_4BIT index tables with secret data, as does anything built with AES_GCM_GMULT_NCT. Without WORD64_AVAILABLE (NO_64BIT, a 16-bit CPU) aes.c falls back to the branching word32 multiply even with no method set. The check now rejects all of these when HAVE_AESGCM is set, whatever the AES backend: a hardware AES core does not imply a hardware GHASH (settings.h itself selects GCM_TABLE for an LTC part without the GCM engine). psa_config.h includes types.h for WORD64_AVAILABLE. Assembly. WOLFSSL_ARMASM was counted as a hardware AES backend. Every Arm port picks its AES path at run time from cpuid and falls back to T-table assembly, the Thumb2 and WOLFSSL_ARMASM_NO_HW_CRYPTO builds always use it, and WOLFSSL_AES_TOUCH_LINES has no effect on any of them. That is the reason WOLFSSL_AESNI is already left out, so WOLFSSL_ARMASM leaves the list and gets its own error. The PowerPC assembly (WOLFSSL_PPC64_ASM, WOLFSSL_PPC32_ASM) is refused the same way: it too selects vector AES at run time and falls back to a T-table core (L_AES_PPC32_te). WOLFSSL_RISCV_ASM stays on the list only with the scalar or vector crypto extension: the base RISC-V assembly uses a T-table AES (L_AES_base_te) and a GHASH that branches on each bit, while the extensions use the AES instructions and clmul or vghsh, and run all of GCM in assembly, so the C GHASH check is skipped for them. FIPS. The aes.c in FIPS v2 (WCv4-stable) and v5 (WCv5.0-RC12) has neither WC_AES_BITSLICED nor WOLFSSL_AES_TOUCH_LINES, so before v6 those macros no longer satisfy the check. FIPS v5 masks GHASH only under AES_GCM_GMULT_CT, and v2 never does. WOLFPSA_AES_FAST waives all of it, as it already did for the AES core. It stays a single waiver, so a build refused only for its GHASH gives up the constant-time AES core with it; the Zephyr README says so. On Zephyr, the wolfSSL module's default GHASH is already the masked one, so only a build that selects a GHASH table or CONFIG_WOLFCRYPT_ASM now needs CONFIG_WOLFPSA_AES_FAST. build-test/psa-config-policy.sh preprocesses psa_config.h against the sibling wolfSSL and checks which configurations it accepts and which wolfPSA error each refused one stops on, with WOLFPSA_AES_FAST as the control for every refusal. It uses build-test/user_settings.h, so it can take the bitsliced core away and reach the generic AES refusal, and it covers the FIPS cases through an empty wolfcrypt/fips.h stub, since a plain wolfSSL tree has none. The build matrix runs it against both wolfSSL refs, and a new aes-fast-gcm-table lane builds the waiver with a GHASH table.
There was a problem hiding this comment.
🟢 Approval recommended
The policy changes are internally consistent and comprehensively covered by targeted configuration tests.
0 open findings
What changed in this PR
Strengthens wolfPSA’s constant-time AES policy to reject unsafe GHASH and assembly configurations.
Changes:
- Adds GHASH, assembly-backend, RISC-V, and FIPS policy checks.
- Documents the expanded
WOLFPSA_AES_FASTwaiver. - Adds policy tests and CI coverage across supported wolfSSL versions.
| File | Description |
|---|---|
src/psa_config.h |
Enforces constant-time AES and GHASH configurations. |
build-test/psa-config-policy.sh |
Tests accepted, rejected, and waived configurations. |
.github/workflows/build-config-matrix.yml |
Runs policy tests and adds a table-GHASH waiver build. |
zephyr/Kconfig |
Updates waiver guidance for GHASH and Arm assembly. |
zephyr/README.md |
Documents the expanded policy and trade-offs. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Member
Author
|
@wolfSSL-Fenrir-bot review balanced |
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #34
No scan targets match the changed files in this PR. Review skipped.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
src/psa_config.hrefuses a build whose AES is not constant time, but it only looked at the AES block cipher core. Two non-constant-time setups passed it:GCM_SMALLandGCM_WORD32branch on the hash subkey,GCM_TABLEandGCM_TABLE_4BITindex tables with secret data, and so does anything built withAES_GCM_GMULT_NCT. WithoutWORD64_AVAILABLE(NO_64BIT, a 16-bit CPU),aes.cfalls back to the branching word32 multiply even with no method set.WOLFSSL_ARMASMwas on the hardware backend list. Every Arm port picks its AES path at run time and falls back to T-table assembly, andWOLFSSL_AES_TOUCH_LINEShas no effect on it. That is whyWOLFSSL_AESNIwas already left off the list. The PowerPC and base RISC-V assembly have the same problem.This is the wolfPSA side of wolfSSL/wolfssl#11691, which made the Zephyr module's constant-time AES option cover GHASH and refuse the Arm assembly.
Changes
HAVE_AESGCM: refusesGCM_SMALL,GCM_WORD32,GCM_TABLE,GCM_TABLE_4BIT,AES_GCM_GMULT_NCTand a build withoutWORD64_AVAILABLE, whatever the AES backend. A hardware AES core does not imply a hardware GHASH:settings.hitself selectsGCM_TABLEfor an LTC part without the GCM engine.psa_config.hnow includestypes.hforWORD64_AVAILABLE.WOLFSSL_ARMASM,WOLFSSL_PPC64_ASM,WOLFSSL_PPC32_ASM) leave the hardware list and get their own errors.L_AES_base_te) and a GHASH that branches on each bit. The extensions use the AES instructions plusclmulorvghshand run all of GCM in assembly, so the C GHASH check is skipped for them.aes.cin FIPS v2 and v5 has neitherWC_AES_BITSLICEDnorWOLFSSL_AES_TOUCH_LINES, so before v6 those macros no longer satisfy the check. FIPS v5 masks GHASH only underAES_GCM_GMULT_CT, and v2 never does.WOLFPSA_AES_FASTwaives all of it, as it already did for the AES core. It stays the single opt-out, so a build refused only for its GHASH gives up the constant-time AES core with it;zephyr/README.mdsays so. Each error message names the change that fixes it.Behaviour change
These configurations built before and now stop with a
wolfPSA:error unlessWOLFPSA_AES_FASTis defined:GCM_SMALL. That includes a wolfSSL autoconf build, whose AES-GCM default is the 4-bit table.WOLFSSL_ARMASM, the PowerPC assembly, and RISC-V assembly without the crypto extensions. On Zephyr this isCONFIG_WOLFCRYPT_ASMon AArch64, ARMv7-M, ARMv8-M mainline and 32-bit Cortex-A/R.On Zephyr the wolfSSL module's default GHASH is already the masked one, so a default build is unaffected.
Testing
build-test/psa-config-policy.shpreprocessespsa_config.hagainst the sibling wolfSSL withbuild-test/user_settings.h. It runs 37 cases: each refused configuration must stop on its specificwolfPSA:error, and each refusal has aWOLFPSA_AES_FASTcontrol that must pass. The FIPS cases run through an emptywolfcrypt/fips.hstub, since a plain wolfSSL tree has none. It passes against wolfSSL master andv5.9.4-stable, and removing a branch from the check makes it fail.build-config-matrix.ymlruns the script against both wolfSSL refs, and a newaes-fast-gcm-tablelane builds the waiver with a GHASH table.libwolfpsa.abuilds by default and withAES_FAST=1; thebaselineandaes-fast-gcm-tablelanes build.native_sim/native/64. Onmps2/an521,psa_smokeon the module's Kconfig config builds without assembly (constant-time AES, masked GHASH), is refused withCONFIG_WOLFCRYPT_ASM=y, and builds again withCONFIG_WOLFPSA_AES_FAST=y.