Skip to content

aes: add AES-128/192/256-OFB - #509

Open
MarkAtwood wants to merge 1 commit into
wolfSSL:masterfrom
MarkAtwood:aes-ofb
Open

MarkAtwood wants to merge 1 commit into
wolfSSL:masterfrom
MarkAtwood:aes-ofb

Conversation

@MarkAtwood

@MarkAtwood MarkAtwood commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

no AES-OFB in wolfprovider, so as default provider this fails:

$ openssl enc -aes-256-ofb ...
...inner_evp_generic_fetch:unsupported... Algorithm (AES-256-OFB : 78)

wolfcrypt already has it (WOLFSSL_AES_OFB), this adds 128/192/256 next to CFB with openssl's names and OIDs. tests compare against the default provider plus NIST CAVP OFBMMT vectors both directions, split updates and re-init. tested on cd8836f, openssl 3.5.4, wolfssl 5.9.4, default, replace-default, and fips ready all pass, openssl enc output matches stock openssl

Copilot AI balanced review requested due to automatic review settings October 7, 2026 18:56

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

OFB currently reports incorrect block-size metadata and has unsafe context duplication and build-configuration behavior.

3 open findings
What changed in this PR

Adds AES-128/192/256-OFB support backed by wolfCrypt.

Changes:

  • Registers OFB cipher implementations, names, and OIDs.
  • Adds streaming OFB processing and feature gating.
  • Adds interoperability and NIST vector tests.
File Description
README.md Documents OFB support.
include/​wolfprovider/​alg_funcs.h Declares OFB names and dispatch tables.
include/​wolfprovider/​settings.h Adds the OFB feature flag.
src/​wp_aes_stream.c Implements OFB processing.
src/​wp_wolfprov.c Registers OFB algorithms.
test/​test_cipher.c Adds OFB interoperability and KAT coverage.
test/​unit.c Registers OFB tests.
test/​unit.h Declares OFB tests.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/wp_aes_stream.c
Comment on lines +670 to +678
if (ctx->enc) {
rc = wc_AesOfbEncrypt(&ctx->aes, out, in, chunk);
}
else {
rc = wc_AesOfbDecrypt(&ctx->aes, out, in, chunk);
}
if (rc != 0) {
WOLFPROV_MSG_DEBUG_RETCODE(WP_LOG_LEVEL_DEBUG,
"wc_AesOfbEncrypt/wc_AesOfbDecrypt", rc);
Comment thread src/wp_aes_stream.c
*/
#ifdef WP_HAVE_AESOFB
/** wp_aes256ofb_functions */
IMPLEMENT_AES_STREAM(ofb, OFB, 0, 256, 128)
Comment thread src/wp_aes_stream.c
Comment on lines +1072 to +1074
IMPLEMENT_AES_STREAM(ofb, OFB, 0, 192, 128)
/** wp_aes128ofb_functions */
IMPLEMENT_AES_STREAM(ofb, OFB, 0, 128, 128)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants