Skip to content

crypto: move Ed25519 fallback to cryptobackend - #2555

Merged
Quim Muntal (qmuntal) merged 1 commit into
microsoft/mainfrom
dev/qmuntal/ed25519-fallback
Oct 8, 2026
Merged

Quim Muntal (qmuntal) merged 1 commit into
microsoft/mainfrom
dev/qmuntal/ed25519-fallback

Conversation

@qmuntal

Copy link
Copy Markdown
Member

Updates #2489.

Move Ed25519 capability checks, native dispatch, key handling, and Go fallbacks into cryptobackend/ed25519. Remove the standard-library boring.go/notboring.go glue and reduce the production crypto/ed25519 patch to +6/-6.

Preserve mutable private-key seed/public-suffix semantics and owned public-key encodings. Cache Go private keys for deterministic crypto.Signer and PH/ctx operations, and construct Go public keys lazily only for PH/ctx verification. Native operation errors are not retried through Go. Windows and Go-only builds use direct core aliases. No dependency upgrades or permanent backend tests are added.

Keep allocation tests enabled with capability-dependent limits. Windows and Go-only round trips remain allocation-free. OpenSSL's fresh-public round trip measures four Go allocations, and warm verification with a reused public slice measures zero. Native generation and seed construction each add one wrapper allocation. These are allocation measurements, not throughput benchmarks.

Validation: Windows Ed25519 units, Golden/ref10/Wycheproof vectors, allocation checks, and enabled/disabled dependency rules; native OpenSSL 3.5.7 and Azure Linux OpenSSL 3.3.7 default/SymCrypt FIPS vectors and external ownership, mutation, global-randomness, concurrency, GC, and checkptr probes across current/v1.26/v1.0 modules; unsupported-provider controls; standalone module, source importers, public API checks, and focused TLS/X509 units. Darwin ARM64/AMD64 cross-builds pass. All 12 patches replay to the exact tested Go tree, and source/vendor copies match.

Native macOS runtime validation was unavailable. Go-only frozen v1.0 remains blocked by the existing unrelated SHA-512 Clone compile error, reproduced with the original Ed25519 source. No E2E/BoGo suite or throughput benchmarks were run.

Move Ed25519 native dispatch, key handling, and lazy Go fallbacks into
cryptobackend. Keep the standard-library integration close to upstream
and use core aliases for Go-only builds.

Preserve mutable key encodings, deterministic crypto.Signer behavior,
and allocation tests. Keep provider capability checks and propagate
native operation errors without retrying through Go.

Updates #2489.
@qmuntal
Quim Muntal (qmuntal) requested a review from a team as a code owner October 8, 2026 10:37
Copilot AI balanced review requested due to automatic review settings October 8, 2026 10:37
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

The security-sensitive cross-platform refactor lacks native macOS runtime validation and warrants final human review.

0 open findings

What changed in this PR

Moves Ed25519 dispatch, fallback logic, and key caching into cryptobackend/ed25519, simplifying standard-library integration.

Changes:

  • Adds backend-aware Ed25519 key wrappers and lazy Go fallbacks.
  • Preserves mutation semantics and capability-dependent allocation checks.
  • Regenerates vendor and crypto-backend patches consistently.

Patches are happy!

File Description
patches/​0001-Vendor-external-dependencies.patch Vendors the refactored Ed25519 backend.
patches/​0002-Add-crypto-backends.patch Simplifies standard-library Ed25519 integration.
cryptobackend/​ed25519/​key.go Adds key wrappers and lazy fallback caching.
cryptobackend/​ed25519/​ed25519_msgostd.go Implements native dispatch and Go fallbacks.
cryptobackend/​ed25519/​ed25519_nobackend_msgostd.go Provides direct Go aliases without native support.
cryptobackend/​ed25519/​ed25519_nomsgostd.go Provides standalone stubs.
cryptobackend/​ed25519/​ed25519_openssl.go Adapts OpenSSL primitives.
cryptobackend/​ed25519/​ed25519_darwin.go Adapts Darwin primitives.
cryptobackend/​ed25519/​ed25519_windows.go Defines unsupported Windows backend primitives.
cryptobackend/​ed25519/​nobackend.go Defines unavailable backend primitives.
cryptobackend/​ed25519/​init.go Removes obsolete initialization glue.

🧠 Review effort: Balanced


Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.

@qmuntal
Quim Muntal (qmuntal) merged commit e2d75cd into microsoft/main Oct 8, 2026
60 checks passed
@qmuntal
Quim Muntal (qmuntal) deleted the dev/qmuntal/ed25519-fallback branch October 8, 2026 11:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants