Skip to content

crypto: move ML-DSA fallback to cryptobackend - #2548

Merged
Quim Muntal (qmuntal) merged 1 commit into
microsoft/mainfrom
dev/qmuntal/mldsa-fallback
Oct 6, 2026
Merged

Quim Muntal (qmuntal) merged 1 commit into
microsoft/mainfrom
dev/qmuntal/mldsa-fallback

Conversation

@qmuntal

Copy link
Copy Markdown
Member

Move ML-DSA capability checks, native dispatch, key representation and Go fallback into cryptobackend/mldsa to reduce the standard-library patch. Keep the upstream public key wrappers and operation bodies; the remaining production integration is one file (+11/-4), consisting of an import substitution and key-generation error propagation.

Use copy-safe native private-key state with shared, once-only Go-key reconstruction for deterministic signing and unsupported operations. Honor overridden global randomness, preserve zero-value checks and mixed native/Go equality, and return independent key encodings. Native operation errors are propagated directly, not retried through Go.

Keep allocation tests enabled and use ML-DSA-65 to exercise Darwin native support. With the upgraded providers, the round-trip workload uses 10 Go allocations on CNG and OpenSSL, versus 8 with the previous integration; frozen v1.26.0 adds two. Darwin shares the 10-allocation budget based on escape analysis and provider CI, but the full standard-library workload still needs native macOS verification. Remove the obsolete Linux FIPS TLS PRF test skip, now covered by HMAC fallback.

Regenerate the vendor and integration patches without changing the Go submodule pointer or adding permanent backend tests.

Updates #2489.

Validation

  • Windows ARM64 native/fallback ML-DSA units, global randomness checks and allocation tests with current and frozen v1.26.0 modules; frozen v1.0 unavailable-API checks.
  • Windows AMD64 native/fallback race tests and development diagnostics for copied-key concurrency, encoding ownership, mixed equality and public-key lifetime.
  • Darwin ARM64/AMD64 nocgo full-standard-library and standalone backend cross-builds, including current/frozen ML-DSA test binaries. Native macOS execution remains for CI.
  • During development, Linux ARM64 OpenSSL 3.5.7 native ML-DSA units/vectors and allocation checks, plus OpenSSL 3.3.7 default/SymCrypt FIPS fallback checks. The final rebase did not change those production sources.
  • Restored TLS PRF units passed on Windows native/fallback and Linux OpenSSL default/SymCrypt FIPS providers.
  • Standalone module consistency, dependency rules, source/vendor equality and all 13 patches reproducing the tested tree.

Allocation counts cover Go heap allocations, not native allocations. No E2E/replay suites or throughput benchmarks were run.

Move ML-DSA backend dispatch and Go fallback out of crypto/mldsa to
reduce standard-library patching. Keep the upstream key wrappers and
operation bodies, with capability checks and copy-safe fallback state
in cryptobackend/mldsa.

Cache Go keys reconstructed for deterministic and unsupported operations,
preserve caller-owned encodings and global randomness overrides, and
regenerate the vendor and integration patches.

Remove the obsolete TLS PRF test skip now that unsupported HMACs fall
back to Go.
@qmuntal
Quim Muntal (qmuntal) requested a review from a team as a code owner October 6, 2026 15:36
Copilot AI balanced review requested due to automatic review settings October 6, 2026 15:36
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Cross-platform cryptographic dispatch remains high risk, particularly without native macOS execution.

Review effort: Balanced
Findings: None

What changed in this PR

Moves ML-DSA native dispatch and Go fallback logic into cryptobackend/mldsa, simplifying standard-library integration.

Changes:

  • Adds copy-safe key wrappers and fallback dispatch.
  • Preserves randomness, equality, encoding, and allocation behavior.
  • Regenerates vendor and integration patches.

Patch consistency: Patches are happy!

File Description
patches/​0001-Vendor-external-dependencies.patch Vendors updated ML-DSA backend sources.
patches/​0002-Add-crypto-backends.patch Simplifies standard-library integration and updates tests/dependencies.
cryptobackend/​mldsa/​key.go Adds shared key representations and equality logic.
cryptobackend/​mldsa/​mldsa_msgostd.go Implements native dispatch and Go fallback.
cryptobackend/​mldsa/​mldsa_nomsgostd.go Provides standalone declarations and stubs.
cryptobackend/​mldsa/​mldsa_darwin.go Adapts Darwin native operations.
cryptobackend/​mldsa/​mldsa_openssl.go Adapts OpenSSL native operations.
cryptobackend/​mldsa/​mldsa_windows.go Adapts Windows native operations.
cryptobackend/​mldsa/​nobackend.go Updates unavailable-backend stubs.
cryptobackend/​mldsa/​init.go Removes obsolete initialization-only file.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@qmuntal
Quim Muntal (qmuntal) merged commit b7e2b81 into microsoft/main Oct 6, 2026
61 checks passed
@qmuntal
Quim Muntal (qmuntal) deleted the dev/qmuntal/mldsa-fallback branch October 6, 2026 17:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants