Repository navigation
Restore ECC salted sessions and key import without ECC_TIMING_RESISTANT - #619
Merged
Merged
Conversation
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The no-harden CI job does not compile either changed vendor SPDM path.
Review effort: Balanced
Findings: 1
What changed in this PR
Restores ECC operations in wolfSSL builds without ECC_TIMING_RESISTANT.
Changes:
- Re-enables ECC secret encryption and unblinded private-key public derivation.
- Re-enables SPDM requester key generation.
- Adds regression tests and no-harden CI coverage.
| File | Description |
|---|---|
src/tpm2_wrap.c |
Restores non-hardened ECC paths. |
tests/unit_tests.c |
Tests ECC secret encryption and private-only imports. |
.github/workflows/make-test-swtpm.yml |
Adds no-harden testing. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
aidangarske
approved these changes
Oct 1, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Description
Regression in v4.2.0. Broken by #582 (items 1 and 2), #597 (item 3). ZD 22550
A wolfSSL build without
ECC_TIMING_RESISTANT(auser_settings.hbuild that omits it, or--disable-harden) getsNOT_COMPILED_INfrom three ECC paths insrc/tpm2_wrap.cthat worked in v4.1.0. Reported by a customer aswolfTPM2_StartSessionfailing while building the encrypted salt.1. ECC salted sessions and import seeds
wolfTPM2_EncryptSecret_ECC()and theTPM_ALG_ECCcase inwolfTPM2_EncryptSecret()were compiled out without the macro, so a session salted with an ECC key, or an import under an ECC parent, returnedNOT_COMPILED_IN. The guard is back toHAVE_ECC,!WC_NO_RNGandWOLFSSL_PUBLIC_MP. The RNG is still attached to both keys when timing resistance is available.2. Private-only ECC key import
wolfTPM2_EccMakePubBlinded()returnedNOT_COMPILED_INwithout the macro. It now falls back towc_ecc_make_pub(). The blindedwc_ecc_make_pub_ex()path is unchanged in hardened builds.3. SPDM requester key auto-generation
wolfTPM2_SpdmConnectNuvoton()andwolfTPM2_SpdmConnectNations()returnedNOT_COMPILED_INwhen no requester key was supplied. The ephemeral P-384 key generation is enabled for anyHAVE_ECCbuild again.Whether wolfCrypt's ECC is timing resistant is a wolfSSL build choice, and wolfSSL already warns at build time when it is off. wolfTPM should not turn that choice into a runtime failure.
Testing
Adds an ECC case to
test_wolfTPM2_EncryptSecret, a private-only import test forwolfTPM2_CreateEccKeyBlob, and ano-hardenCI job that builds wolfSSL with--disable-hardenand runsmake checkandrun_examples.sh. Run against wolfSSL 5.9.4 built with and without--disable-harden, on the fwTPM and on ibmswtpm2. The SPDM paths are compile-tested only.