Repository navigation
crypto: move ML-DSA fallback to cryptobackend - #2548
Merged
Merged
Conversation
Move ML-DSA backend dispatch and Go fallback out of crypto/mldsa to reduce standard-library patching. Keep the upstream key wrappers and operation bodies, with capability checks and copy-safe fallback state in cryptobackend/mldsa. Cache Go keys reconstructed for deterministic and unsupported operations, preserve caller-owned encodings and global randomness overrides, and regenerate the vendor and integration patches. Remove the obsolete TLS PRF test skip now that unsupported HMACs fall back to Go.
|
Azure Pipelines: Successfully started running 1 pipeline(s). There may be pipelines that require an authorized user to comment /azp run to run. |
Contributor
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
Cross-platform cryptographic dispatch remains high risk, particularly without native macOS execution.
Review effort: Balanced
Findings: None
What changed in this PR
Moves ML-DSA native dispatch and Go fallback logic into cryptobackend/mldsa, simplifying standard-library integration.
Changes:
- Adds copy-safe key wrappers and fallback dispatch.
- Preserves randomness, equality, encoding, and allocation behavior.
- Regenerates vendor and integration patches.
Patch consistency: Patches are happy!
| File | Description |
|---|---|
patches/0001-Vendor-external-dependencies.patch |
Vendors updated ML-DSA backend sources. |
patches/0002-Add-crypto-backends.patch |
Simplifies standard-library integration and updates tests/dependencies. |
cryptobackend/mldsa/key.go |
Adds shared key representations and equality logic. |
cryptobackend/mldsa/mldsa_msgostd.go |
Implements native dispatch and Go fallback. |
cryptobackend/mldsa/mldsa_nomsgostd.go |
Provides standalone declarations and stubs. |
cryptobackend/mldsa/mldsa_darwin.go |
Adapts Darwin native operations. |
cryptobackend/mldsa/mldsa_openssl.go |
Adapts OpenSSL native operations. |
cryptobackend/mldsa/mldsa_windows.go |
Adapts Windows native operations. |
cryptobackend/mldsa/nobackend.go |
Updates unavailable-backend stubs. |
cryptobackend/mldsa/init.go |
Removes obsolete initialization-only file. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
George Adams (gdams)
approved these changes
Oct 6, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Move ML-DSA capability checks, native dispatch, key representation and Go fallback into
cryptobackend/mldsato reduce the standard-library patch. Keep the upstream public key wrappers and operation bodies; the remaining production integration is one file (+11/-4), consisting of an import substitution and key-generation error propagation.Use copy-safe native private-key state with shared, once-only Go-key reconstruction for deterministic signing and unsupported operations. Honor overridden global randomness, preserve zero-value checks and mixed native/Go equality, and return independent key encodings. Native operation errors are propagated directly, not retried through Go.
Keep allocation tests enabled and use ML-DSA-65 to exercise Darwin native support. With the upgraded providers, the round-trip workload uses 10 Go allocations on CNG and OpenSSL, versus 8 with the previous integration; frozen v1.26.0 adds two. Darwin shares the 10-allocation budget based on escape analysis and provider CI, but the full standard-library workload still needs native macOS verification. Remove the obsolete Linux FIPS TLS PRF test skip, now covered by HMAC fallback.
Regenerate the vendor and integration patches without changing the Go submodule pointer or adding permanent backend tests.
Updates #2489.
Validation
Allocation counts cover Go heap allocations, not native allocations. No E2E/replay suites or throughput benchmarks were run.