Skip to content

kem/schemes: run Wycheproof ML-KEM test vectors - #704

Open
KurathSec wants to merge 1 commit into
cloudflare:mainfrom
KurathSec:wycheproof-mlkem
Open

KurathSec wants to merge 1 commit into
cloudflare:mainfrom
KurathSec:wycheproof-mlkem

Conversation

@KurathSec

@KurathSec KurathSec commented Sep 23, 2026 •

Copy link
Copy Markdown

sign/schemes runs the Wycheproof ML-DSA vectors; this does the same for ML-KEM. It adds the twelve mlkem_{512,768,1024}_* files from C2SP/wycheproof testvectors_v1 at 3fa63dd, gzipped under kem/schemes/testdata/wycheproof/ like the ML-DSA ones, and kem/schemes/wycheproof_test.go:

group type check
MLKEMTest derive from seed, compare ek, decapsulate c (a wrong-length c must be rejected), compare K; a wrong-length seed counts as rejected, since DeriveKeyPair panics on it
MLKEMEncapsTest import ek (unreduced and wrong-length keys must be rejected), encapsulate with m, compare c and K
MLKEMDecapsValidationTest import the expanded dk (wrong length or bad hash must be rejected), compare its ek, decapsulate c (wrong length must be rejected)
MLKEMKeyGen derive from seed, compare ek and dk

An invalid case passes only if the scheme returns an error. Wrong outputs are reported separately, so a mismatch never counts as the expected rejection.

All 1,725 cases pass on main, also under GOOS=js GOARCH=wasm. golangci-lint (v2.12.2) and the shadow check are clean.


Devin Review

Adds the ML-KEM files from C2SP/wycheproof testvectors_v1 at 3fa63dd.
Copilot AI lite review requested due to automatic review settings September 23, 2026 06:58

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved review comments remain, and the supplied assessments support approval.

Review effort: Lite
Findings: None

What changed in this PR

Adds Wycheproof ML-KEM coverage for ML-KEM-512, ML-KEM-768, and ML-KEM-1024.

Changes:

  • Adds a reusable test runner for key generation, encapsulation, decapsulation, and malformed inputs.
  • Adds twelve compressed ML-KEM test-vector files.
File Summary
kem/​schemes/​wycheproof_test.go Implements ML-KEM Wycheproof vector execution and rejection checks.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Devin Review: No Issues Found

Devin Review analyzed this PR and found no bugs or issues to report.

Devin Review

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants