Repository navigation
crypto: move Ed25519 fallback to cryptobackend - #2555
Merged
Quim Muntal (qmuntal) merged 1 commit intoOct 8, 2026
Merged
Conversation
Move Ed25519 native dispatch, key handling, and lazy Go fallbacks into cryptobackend. Keep the standard-library integration close to upstream and use core aliases for Go-only builds. Preserve mutable key encodings, deterministic crypto.Signer behavior, and allocation tests. Keep provider capability checks and propagate native operation errors without retrying through Go. Updates #2489.
|
Azure Pipelines: Successfully started running 1 pipeline(s). There may be pipelines that require an authorized user to comment /azp run to run. |
George Adams (gdams)
approved these changes
Oct 8, 2026
Contributor
There was a problem hiding this comment.
🔵 Needs a closer look
The security-sensitive cross-platform refactor lacks native macOS runtime validation and warrants final human review.
0 open findings
What changed in this PR
Moves Ed25519 dispatch, fallback logic, and key caching into cryptobackend/ed25519, simplifying standard-library integration.
Changes:
- Adds backend-aware Ed25519 key wrappers and lazy Go fallbacks.
- Preserves mutation semantics and capability-dependent allocation checks.
- Regenerates vendor and crypto-backend patches consistently.
Patches are happy!
| File | Description |
|---|---|
patches/0001-Vendor-external-dependencies.patch |
Vendors the refactored Ed25519 backend. |
patches/0002-Add-crypto-backends.patch |
Simplifies standard-library Ed25519 integration. |
cryptobackend/ed25519/key.go |
Adds key wrappers and lazy fallback caching. |
cryptobackend/ed25519/ed25519_msgostd.go |
Implements native dispatch and Go fallbacks. |
cryptobackend/ed25519/ed25519_nobackend_msgostd.go |
Provides direct Go aliases without native support. |
cryptobackend/ed25519/ed25519_nomsgostd.go |
Provides standalone stubs. |
cryptobackend/ed25519/ed25519_openssl.go |
Adapts OpenSSL primitives. |
cryptobackend/ed25519/ed25519_darwin.go |
Adapts Darwin primitives. |
cryptobackend/ed25519/ed25519_windows.go |
Defines unsupported Windows backend primitives. |
cryptobackend/ed25519/nobackend.go |
Defines unavailable backend primitives. |
cryptobackend/ed25519/init.go |
Removes obsolete initialization glue. |
🧠 Review effort: Balanced
Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updates #2489.
Move Ed25519 capability checks, native dispatch, key handling, and Go fallbacks into cryptobackend/ed25519. Remove the standard-library boring.go/notboring.go glue and reduce the production crypto/ed25519 patch to +6/-6.
Preserve mutable private-key seed/public-suffix semantics and owned public-key encodings. Cache Go private keys for deterministic crypto.Signer and PH/ctx operations, and construct Go public keys lazily only for PH/ctx verification. Native operation errors are not retried through Go. Windows and Go-only builds use direct core aliases. No dependency upgrades or permanent backend tests are added.
Keep allocation tests enabled with capability-dependent limits. Windows and Go-only round trips remain allocation-free. OpenSSL's fresh-public round trip measures four Go allocations, and warm verification with a reused public slice measures zero. Native generation and seed construction each add one wrapper allocation. These are allocation measurements, not throughput benchmarks.
Validation: Windows Ed25519 units, Golden/ref10/Wycheproof vectors, allocation checks, and enabled/disabled dependency rules; native OpenSSL 3.5.7 and Azure Linux OpenSSL 3.3.7 default/SymCrypt FIPS vectors and external ownership, mutation, global-randomness, concurrency, GC, and checkptr probes across current/v1.26/v1.0 modules; unsupported-provider controls; standalone module, source importers, public API checks, and focused TLS/X509 units. Darwin ARM64/AMD64 cross-builds pass. All 12 patches replay to the exact tested Go tree, and source/vendor copies match.
Native macOS runtime validation was unavailable. Go-only frozen v1.0 remains blocked by the existing unrelated SHA-512 Clone compile error, reproduced with the original Ed25519 source. No E2E/BoGo suite or throughput benchmarks were run.