Skip to content

Add missing return code handling for mldsa_vec_expand_mask. - #11463

Open
kareem-wolfssl wants to merge 1 commit into
wolfSSL:masterfrom
kareem-wolfssl:gh11454
Open

kareem-wolfssl wants to merge 1 commit into
wolfSSL:masterfrom
kareem-wolfssl:gh11454

Conversation

@kareem-wolfssl

Copy link
Copy Markdown
Contributor

Description

Fixes #11454

Testing

Built in tests

Checklist

  • added tests
  • updated/added doxygen
  • updated appropriate READMEs
  • Updated manual and documentation

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The corrected error propagation lacks a regression test that verifies the exact failure is returned.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

Adds error propagation for ML-DSA mask expansion during signing.

Changes:

  • Checks mldsa_vec_expand_mask() results.
  • Stops both signing paths immediately on failure.
File summaries
File Description
wolfcrypt/src/wc_mldsa.c Handles mask-expansion errors in standard and small-memory signing paths.
Review details
  • Files reviewed: 1/1 changed files
  • Comments generated: 1
  • Review effort level: Balanced

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread wolfcrypt/src/wc_mldsa.c
Comment on lines +9506 to +9510
ret = mldsa_vec_expand_mask(&key->shake, priv_rand_seed, kappa,
params->gamma1_bits, y, params->l, key->heap);
if (ret != 0) {
break;
}
@github-actions

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ML-DSA signing ignores errors returned by mldsa_vec_expand_mask

2 participants