Conversation
Add a generated pure-Go implementation of the Classic McEliece Round 4 KEM parameter sets: - mceliece348864 / mceliece348864f - mceliece460896 / mceliece460896f - mceliece6688128 / mceliece6688128f - mceliece6960119 / mceliece6960119f - mceliece8192128 / mceliece8192128f The parameter-set code is generated from shared templates (internal/mceliecegen) to keep the variants consistent while preserving the differences required by the official submission: f/non-f key generation, unaligned 6960119 public-key packing, and 8192128 support handling. Public CIRCL KEM wrappers are added and all ten schemes are registered in kem/schemes. Tests verify generated keys, ciphertexts, and shared secrets against the official Round 4 KAT vectors. To keep the package hermetic and small, the committed testdata archive holds only the first vector per variant (the coverage the default run checks); set CIRCL_MCELIECE_KAT_ARCHIVE to the full official gzip archive together with CIRCL_MCELIECE_FULL_KAT to run the complete set out of tree. Signed-off-by: qnfm <uzinag@163.com>
…dition The Gaussian elimination in pkGen / pkGenFromSK dominates key generation and repeats a single masked GF(2) row addition (dst[i] ^= src[i] & mask) over PKNRows * SysN/8 bytes. Factor the operation into internal/matops.AddMasked, which on amd64 selects the widest kernel the CPU supports: - AVX-512 (preferred): avo-generated kernel over 64-byte ZMM blocks, gated on cpu.X86.HasAVX512F && HasAVX512BW. - AVX2: avo-generated kernel over 32-byte YMM blocks, gated on cpu.X86.HasAVX2. - everything else and the purego build tag: constant-time word-wise Go fallback (8 bytes/iter, mask broadcast arithmetically). A word-wise generic tail finishes any bytes past the last full vector block. Every path processes the full buffer and derives the per-byte mask without branching on the secret pivot mask, so no data-dependent timing is introduced. Both asm kernels are avo-generated by a nested internal/asm module in line with the keccakf1600/kyber convention, keeping avo out of the main module dependencies. Dedicated tests drive each kernel directly so both stay covered regardless of host features. Signed-off-by: qnfm <uzinag@163.com>
|
|
||
| go 1.26.0 | ||
|
|
||
| require github.com/mmcloughlin/avo v0.6.0 |
|
Same as #378 |
…mplates - Ciphertext padding no longer panics (remote DoS). Only mceliece6960119 and mceliece6960119f set CheckPadding (PKNRows = 119*13 = 1547, not a multiple of 8). core.Decapsulate rejected a correctly sized ciphertext with non-zero padding bits by returning an error, and the higher-level PrivateKey.DecapsulateTo turns any such error into panic(err). Scheme.Decapsulate only length-checks before calling DecapsulateTo, so an attacker-controlled ciphertext could crash any application that decapsulates it. Match the reference implementation (operations.c) instead: always run the full decapsulation and, when the padding bits are non-zero, deterministically mangle the shared secret (OR in the all-ones padding mask) rather than returning an error. This is the same constant-time implicit-rejection strategy already used for decryption failure, keeps Decapsulate error-free for correctly sized ciphertexts, and removes the panic path. The padding mask is derived solely from the public ciphertext, so no secret-dependent behaviour is introduced. - Generator now emits the three test templates. kat_test.go.tmpl, kem_test.go.tmpl and public_mceliece_test.go.tmpl were present but never rendered by mceliecegen, so the committed *_test.go files were orphaned "DO NOT EDIT" output that go generate could not reproduce. Wire kem_test and public_mceliece_test into generateScheme, and restore the KATHashes scheme field (one pinned count=0 NIST KAT digest per variant) that kat_test.go.tmpl consumes. Regeneration reproduces the existing test files byte-for-byte, so the CI generate-diff check now actually covers them. Signed-off-by: qnfm <uzinag@163.com>
Signed-off-by: qnfm <uzinag@163.com>
qnfm
force-pushed
the
mceliece-round4
branch
from
September 22, 2026 05:41
2d444be to
2c2f1ef
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


add avx512/avx2 and pure go round4 Classic Mceliece