| ci: require explicit branches filter for pull_request trigger main, openhitls-0.3, openhitls-0.2 Cherry-picked from: https://gitcode.com/openHiTLS/openhitls/merge_requests/1801 | 1 个月前 |
| fix: address security review findings on rsa, bn, sha2, mldsa, cmac and CI - ci: run the riscv64 self-hosted job on push only, so untrusted PR code cannot execute on the self-hosted runner - sha2: gate the multi-buffer SHA256 path on the ARM SHA2 extension at init to avoid SIGILL on cores without it; add missing input checks to the one-shot CRYPT_SHA256_MB - mldsa: decrement the loop counter in the ARMv8 UseHint32/88 routines; the missing decrement emitted a 17th 64-byte chunk store, writing 64 bytes past each w[i] polynomial during signature verification. Add an SDV case with a canary after the last polynomial to guard the bound - rsa: reject inLen < 2 in CRYPT_RSA_VerifyPkcsV15Type2TLS before reading in[0]/in[1] to prevent an out-of-bounds read with a malformed short modulus - bn: BN_GenPrime now retries only on a composite candidate and aborts on real errors, preventing an infinite loop when the rand source fails persistently (aligned with OpenSSL behavior) - cmac: replace NULL + 0 pointer arithmetic on empty updates with an index loop to remove undefined behavior - curve25519: clear the partially duplicated key context on the DupCtx failure path - benchmark: reject -l values beyond the fixed buffer size Cherry-picked from: https://gitcode.com/openHiTLS/openhitls/merge_requests/1803 | 1 个月前 |
| Harden Constant-Time Crypto and Secret Handling Reduce timing and data-remanence exposure across BN, symmetric, asymmetric, post-quantum, PAKE, PKCS#12, CLI, and TLS code. Bound PKCS#1 v1.5 type 2 decoding for short inputs and use one masked decoder for TLS and non-TLS paths. Restrict SPAKE2+ responder registration data and add validation modes. Harden cryptographic arithmetic and sensitive-data cleanup. Extend regression coverage for ECC field operations, scalar multiplication, and RSA decoding boundaries. Remove the deprecated RSA-BSSA factor injection control. Cherry-picked from: https://gitcode.com/openHiTLS/openhitls/merge_requests/1906 | 11 天前 |
| fix: mask infinity handling in ECC point add affine ECP_NistPointAddAffine/ECP_NistPointAddAffineMont: replace the data-dependent BN_IsZero early return for the point at infinity with a constant-time masked selection via BN_CopyWithMask, matching the asm implementation. The equal-point exceptional case keeps its branch, which cannot be hit inside a single scalar multiplication. spake2plus: compute the prover/verifier shares with the constant-time ECC_PointMul instead of the variable-time ECC_PointMulAdd, so the ephemeral and password-derived scalars are not exposed through the wNAF recoding. Cherry-picked from: https://gitcode.com/openHiTLS/openhitls/merge_requests/1897 | 10 天前 |
| | 1 天前 |
| | 1 天前 |
| feat: CDP, IDP, and DeltaCrl encoding/decoding capability trimming Signed-off-by: Lzhjian <liuzhijian24@huawei.com> Cherry-picked from: https://gitcode.com/openHiTLS/openhitls/merge_requests/1636 | 3 个月前 |
| Support Pure cmake build build: Migrate build system from Python/JSON/CMake hybrid to pure CMake The previous build system mixed Python scripts and JSON configuration files with CMake, scattering build logic across multiple languages and formats. This made the system hard to understand and maintain, and required a Python interpreter at configure time. The build system has been rewritten entirely in CMake. Feature flags, dependency resolution, platform detection, compiler options, and config-header generation are now all expressed natively in CMake. For more details, see the "Build and Installation" section in README.md. | 6 个月前 |
| | 1 天前 |
| | 22 天前 |
| | 1 天前 |
| Complete HSS and PQC verification support Align HSS public keys and multi-level verification with RFC 8554. Extend X.509 and CMS interoperability coverage for hash-based keys. Reject unsupported CMS digests and invalid keyCertSign usage. Cherry-picked from: https://gitcode.com/openHiTLS/openhitls/merge_requests/1855 | 1 天前 |
| | 21 小时前 |
| | 1 天前 |
| add .clang-format file # message auto-generated for no-merge-commit merge: merge main into main add .clang-format file Created-by: dumb Author-id: 822999 MR-id: 4358051 Commit-by: Liu-Ermeng Merged-by: tlhcd E2E-issues: Description: add .clang-format file See merge request: openHiTLS/openhitls!49 | 1 年前 |
| | 2 个月前 |
| feat: build system improvements and cross-platform support (macOS) Major Features: - Multi-compiler/linker configuration system with toolchain support - Auto-manage Secure C (libboundscheck) dependency - Dynamic provider library names for CMVP modes (ISO19790, SM) - macOS/Darwin platform support with unified POSIX abstractions - Cross-platform build improvements and optimizations Build System: - Add toolchain management for cross-compilation - Support nested 'common' format in compile config - with _EXTRA/_REMOVE/_OVERRIDE in common flags, we can add remove by per compiler - Unify toolchain naming convention (arch-vendor-os-abi-compiler) Platform Support: - Unify Linux and Darwin sources under POSIX - Add Darwin support for SAL and build flags - Add Darwin support for REC wrapper functions (WIP) - Cross-platform ops count macros for benchmarking - Platform-specific library extension detection (.dylib vs .so) Cherry-picked from: https://gitcode.com/openHiTLS/openhitls/merge_requests/652 | 11 个月前 |
| | 5 个月前 |
| | 1 个月前 |
| | 3 个月前 |
| docs: update CONTRIBUTING-zh.md - Changing the serial number. Signed-off-by: zhoutianli <2093795515@qq.com> Cherry-picked from: https://gitcode.com/openHiTLS/openhitls/merge_requests/1282 | 5 个月前 |
| openhitls repo init | 1 年前 |
| | 25 天前 |
| | 25 天前 |
| | 2 个月前 |
| | 2 个月前 |
| | 1 年前 |