Use byte ctxLen in wc_dilithium_verify_ctx_msg cdef (F-4014)
The CFFI cdef declared wc_dilithium_verify_ctx_msg with word32 ctxLen while the sign variants use byte ctxLen. wolfSSL's real API (wc_MlDsaKey_VerifyCtx in wolfcrypt/wc_mldsa.h, which the wc_dilithium_verify_ctx_msg macro forwards to) takes byte ctxLen, matching FIPS 204's 255-byte context cap. The mismatched cdef made CFFI marshal a 4-byte word32 into a 1-byte slot, silently truncating any ctxLen > 255 to its low byte. Declare ctxLen as byte to match the sign cdef and the underlying API.pull/141/head
parent
a59a4f8b96
commit
8bb46362b7
|
|
@ -1350,7 +1350,7 @@ def build_ffi(local_wolfssl, features):
|
|||
int wc_dilithium_import_public(const byte* in, word32 inLen, dilithium_key* key);
|
||||
int wc_dilithium_sign_ctx_msg(const byte* ctx, byte ctxLen, const byte* msg, word32 msgLen, byte* sig, word32* sigLen, dilithium_key* key, WC_RNG* rng);
|
||||
int wc_dilithium_sign_ctx_msg_with_seed(const byte* ctx, byte ctxLen, const byte* msg, word32 msgLen, byte* sig, word32* sigLen, dilithium_key* key, const byte* seed);
|
||||
int wc_dilithium_verify_ctx_msg(const byte* sig, word32 sigLen, const byte* ctx, word32 ctxLen, const byte* msg, word32 msgLen, int* res, dilithium_key* key);
|
||||
int wc_dilithium_verify_ctx_msg(const byte* sig, word32 sigLen, const byte* ctx, byte ctxLen, const byte* msg, word32 msgLen, int* res, dilithium_key* key);
|
||||
typedef dilithium_key MlDsaKey;
|
||||
int wc_MlDsaKey_GetPrivLen(MlDsaKey* key, int* len);
|
||||
int wc_MlDsaKey_GetPubLen(MlDsaKey* key, int* len);
|
||||
|
|
|
|||
Loading…
Reference in New Issue