Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
Show all changes
17 commits
Select commit Hold shift + click to select a range
6b32b0c
feat(wasi_crypto): implement ECDSA public key verification (#4932)
parthdagia05 Jun 11, 2026
d0c2922
fix(plugin/zlib): rename shadowed z_stream locals in zlib plugin
hydai Jun 12, 2026
efb882d
fix(plugin/wasm_bpf): rename shadowed loop variables in wasm_bpf test
hydai Jun 12, 2026
ea67fef
fix(test/opencvmini): suppress shadow warnings on the opencvmini test…
hydai Jun 12, 2026
cceb933
chore(plugin/llmc): deprecate wasmedge-llmc plugin (#4964)
hydai Jun 16, 2026
4424d2f
fix(test/plugins/wasi_nn): remove concrete types to fix devirtualizat…
pranjalkole Jun 17, 2026
59da64f
fix(test/plugins/wasm_bpf): remove concrete types to fix devirtualiza…
hydai Jun 17, 2026
034adc0
fix(test/plugins/wasmedge_process): remove concrete types to fix devi…
hydai Jun 17, 2026
84da82d
fix(test/plugins/wasmedge_stablediffusion): remove concrete types to …
hydai Jun 17, 2026
df6a8d9
fix(test/plugins/wasi_logging): remove concrete types to fix devirtua…
hydai Jun 17, 2026
2142e62
fix(plugin/wasi-logging): validate full string extent in Log::body (#…
Yashika0724 Jun 17, 2026
59f6362
fix(test/plugins/wasmedge_ffmpeg): remove concrete types to fix devir…
hydai Jun 17, 2026
df3bfd9
test(plugins): use ASSERT for host-function guards before getHostFunc()
hydai Jun 17, 2026
f8e7223
docs(test/plugins/wasm_bpf): correct copied comment to wasm_bpf_map_o…
hydai Jun 17, 2026
cf526fa
test(plugins): assert host-call outputs to preserve devirtualized bin…
hydai Jun 18, 2026
2d3f51f
fix(test/plugins/wasmedge_ffmpeg): expect AV_NOPTS_VALUE for unprobed…
hydai Jun 18, 2026
38d7801
test(plugins/wasmedge_ffmpeg): assert exact getter values to keep bin…
hydai Jun 18, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Next Next commit
feat(wasi_crypto): implement ECDSA public key verification (#4932)
Implement Ecdsa::PublicKey::verify() using EVP_PKEY_public_check. Part of #2669.

Signed-off-by: Parth Dagia <parth.24bcs10414@sst.scaler.com>
  • Loading branch information
parthdagia05 authored and 0yi0 committed Jun 11, 2026
commit 6b32b0c71c7cdf9207cfea35d6065423f71e732c
9 changes: 8 additions & 1 deletion plugins/wasi_crypto/asymmetric_common/ecdsa.h
Original file line number Diff line number Diff line change
Expand Up @@ -82,7 +82,14 @@ class Ecdsa {
}

WasiCryptoExpect<void> verify() const noexcept {
return WasiCryptoUnexpect(__WASI_CRYPTO_ERRNO_NOT_IMPLEMENTED);
EvpPkeyCtxPtr CheckCtx{EVP_PKEY_CTX_new(Ctx.get(), nullptr)};
ensureOrReturn(CheckCtx, __WASI_CRYPTO_ERRNO_ALGORITHM_FAILURE);
// EVP_PKEY_public_check() returns 1 for a valid key and 0 for an invalid
// one. A negative value means the check is unsupported for this key type
// (e.g. on OpenSSL 1.1.1), so only an explicit 0 is treated as invalid.
ensureOrReturn(EVP_PKEY_public_check(CheckCtx.get()) != 0,
__WASI_CRYPTO_ERRNO_INVALID_KEY);
return {};
}

protected:
Expand Down
18 changes: 18 additions & 0 deletions test/plugins/wasi_crypto/signatures.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -62,6 +62,9 @@ TEST_F(WasiCryptoTest, Signatures) {
WASI_CRYPTO_EXPECT_TRUE(publickeyVerify(PkHandle));
};
PublicKeyVerifyTest(__WASI_ALGORITHM_TYPE_SIGNATURES, "Ed25519"sv);
PublicKeyVerifyTest(__WASI_ALGORITHM_TYPE_SIGNATURES, "ECDSA_P256_SHA256"sv);
PublicKeyVerifyTest(__WASI_ALGORITHM_TYPE_SIGNATURES, "ECDSA_K256_SHA256"sv);
PublicKeyVerifyTest(__WASI_ALGORITHM_TYPE_SIGNATURES, "ECDSA_P384_SHA384"sv);

// A raw public key with an invalid length is rejected on import.
auto PublicKeyImportInvalidTest = [this](__wasi_algorithm_type_e_t AlgType,
Expand All @@ -73,6 +76,21 @@ TEST_F(WasiCryptoTest, Signatures) {
};
PublicKeyImportInvalidTest(__WASI_ALGORITHM_TYPE_SIGNATURES, "Ed25519"sv);

// A SEC1 public key whose point is not on the curve is rejected on import.
auto PublicKeyImportInvalidSecTest = [this](__wasi_algorithm_type_e_t AlgType,
std::string_view Alg) {
SCOPED_TRACE(Alg);
WASI_CRYPTO_EXPECT_FAILURE(
publickeyImport(
AlgType, Alg,
"04ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff"
"ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff"_u8v,
__WASI_PUBLICKEY_ENCODING_SEC),
__WASI_CRYPTO_ERRNO_INVALID_KEY);
};
PublicKeyImportInvalidSecTest(__WASI_ALGORITHM_TYPE_SIGNATURES,
"ECDSA_P256_SHA256"sv);

auto SigEncodingTest =
[this](
std::string_view Alg,
Expand Down