Skip to content

ecc: keep ECC_MAXSIZE at least MAX_ECC_BYTES - #11690

Merged
SparkiDev merged 1 commit into
wolfSSL:masterfrom
Frauschi:ecc-maxsize-max-ecc-bytes
Oct 8, 2026
Merged

SparkiDev merged 1 commit into
wolfSSL:masterfrom
Frauschi:ecc-maxsize-max-ecc-bytes

Conversation

@Frauschi

@Frauschi Frauschi commented Oct 8, 2026 •

Copy link
Copy Markdown
Member

Description

Follow-up to review feedback on #11484: MAX_ECC_BYTES should never be larger than ECC_MAXSIZE, but nothing enforced that.

Without SAKKE, ECC_MAXSIZE is fixed at 66 bytes, while MAX_ECC_BYTES follows MAX_ECC_BITS. --with-max-ecc-bits and the CMake WOLFSSL_MAX_ECC_BITS option accept up to 1024, which gives MAX_ECC_BYTES = 128 against ECC_MAXSIZE = 66. In that build wc_ecc_set_curve() still refuses curves the build was sized for, and the ECC_MAXSIZE buffers are smaller than the curve size.

This grows ECC_MAXSIZE and ECC_MAXSIZE_GEN with MAX_ECC_BYTES when it exceeds 66, and adds wc_static_assert(MAX_ECC_BYTES <= ECC_MAXSIZE) so the two cannot drift apart again (e.g. a MAX_ECC_BITS override past SAKKE's 128 bytes). Default builds are unchanged.

Testing

  • --enable-ecccustcurves --with-max-ecc-bits=1024: the static assert alone fails to compile on master; with this change it builds, and the ecc API tests and testwolfcrypt pass.
  • --enable-all (SAKKE) and a default ./configure: build, ecc API tests and testwolfcrypt pass.

ECC_MAXSIZE was fixed at 66 bytes without SAKKE, while MAX_ECC_BYTES
follows MAX_ECC_BITS, which --with-max-ecc-bits and the CMake
WOLFSSL_MAX_ECC_BITS option can raise to 1024. Such a build had
MAX_ECC_BYTES of 128 against an ECC_MAXSIZE of 66, so curves the build
was sized for were still refused by wc_ecc_set_curve() and the
ECC_MAXSIZE buffers were smaller than the curve size.

Grow ECC_MAXSIZE and ECC_MAXSIZE_GEN with MAX_ECC_BYTES when it exceeds
66, and add a static assert so the two cannot drift apart again, for
example through a MAX_ECC_BITS override past SAKKE's 128 bytes.
Copilot AI balanced review requested due to automatic review settings October 8, 2026 08:05

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The focused sizing change is consistent with existing ECC buffer usage and preserves default behavior.

0 open findings

What changed in this PR

Ensures ECC buffer sizing tracks configured maximum curve sizes.

Changes:

  • Expands ECC_MAXSIZE and generation buffers above 66 bytes.
  • Adds a compile-time sizing invariant.
File Description
wolfssl/​wolfcrypt/​ecc.h Updates ECC size constants and adds a static assertion.

🧠 Review effort: Balanced


Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.

@SparkiDev SparkiDev self-assigned this Oct 8, 2026
@SparkiDev
SparkiDev merged commit c02cf6c into wolfSSL:master Oct 8, 2026
400 checks passed
@Frauschi
Frauschi deleted the ecc-maxsize-max-ecc-bytes branch October 9, 2026 06:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants