Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions VERSION
Original file line number Diff line number Diff line change
@@ -1,2 +1,2 @@
go1.27.0
time 2026-08-18T21:24:23Z
go1.27.1
time 2026-08-28T16:20:06Z
17 changes: 16 additions & 1 deletion src/cmd/compile/internal/noder/reader.go
Original file line number Diff line number Diff line change
Expand Up @@ -3081,7 +3081,22 @@ func shapedMethodExpr(pos src.XPos, obj *ir.Name, sym *types.Sym) ir.Node {
lsym := obj.Linksym().Name
// Since the method is generic, we know the method name must be followed by a bracket.
// TODO(mark): It's not ideal to rely on string naming here. Find a more robust solution.
msym := sym.Pkg.Lookup(lsym[strings.LastIndex(lsym, sym.Name+"["):])
idx := func() int { // Find the index of the bracket following the method name.
depth, i := 0, len(lsym)-1
for {
switch lsym[i] {
case ']':
depth++
case '[':
depth--
}
if depth == 0 {
return i
}
i--
}
}()
msym := sym.Pkg.Lookup(lsym[idx-len(sym.Name):])

// Note that the field name here includes the type arguments; while also not ideal, the
// types package does not seem to complain.
Expand Down
2 changes: 1 addition & 1 deletion src/cmd/compile/internal/noder/writer.go
Original file line number Diff line number Diff line change
Expand Up @@ -1088,7 +1088,7 @@ func (w *writer) qualifiedIdent(obj types2.Object) {
if isGenericMethod(obj.Type()) {
recv := obj.Type().(*types2.Signature).Recv().Type()
fstr := "%s.%s"
if _, ok := recv.(*types2.Pointer); ok {
if _, ok := types2.Unalias(recv).(*types2.Pointer); ok {
fstr = "(*%s).%s"
}
name = fmt.Sprintf(fstr, types2.Unalias(deref2(recv)).(*types2.Named).Obj().Name(), name)
Expand Down
4 changes: 3 additions & 1 deletion src/cmd/compile/internal/ssagen/ssa.go
Original file line number Diff line number Diff line change
Expand Up @@ -4275,10 +4275,12 @@ func (s *state) minMax(n *ir.CallExpr) *ssa.Value {
if typ.IsFloat() {
hasIntrinsic := false
switch Arch.LinkArch.Family {
case sys.AMD64, sys.ARM64, sys.Loong64, sys.RISCV64, sys.S390X:
case sys.AMD64, sys.ARM64, sys.Loong64, sys.RISCV64:
hasIntrinsic = true
case sys.PPC64:
hasIntrinsic = buildcfg.GOPPC64 >= 9
case sys.S390X:
// FIXME: add check once GOS390X exists
}

if hasIntrinsic {
Expand Down
2 changes: 1 addition & 1 deletion src/cmd/go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ require (
golang.org/x/sys v0.45.0
golang.org/x/telemetry v0.0.0-20260519152614-eab6ae52b5e2
golang.org/x/term v0.43.0
golang.org/x/tools v0.45.1-0.20260730185712-faf6fa7c2f89
golang.org/x/tools v0.45.1-0.20260826175739-e1f45aa8aed5
)

require (
Expand Down
4 changes: 2 additions & 2 deletions src/cmd/go.sum
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ golang.org/x/term v0.43.0 h1:S4RLU2sB31O/NCl+zFN9Aru9A/Cq2aqKpTZJ6B+DwT4=
golang.org/x/term v0.43.0/go.mod h1:lrhlHNdQJHO+1qVYiHfFKVuVioJIheAc3fBSMFYEIsk=
golang.org/x/text v0.37.0 h1:Cqjiwd9eSg8e0QAkyCaQTNHFIIzWtidPahFWR83rTrc=
golang.org/x/text v0.37.0/go.mod h1:a5sjxXGs9hsn/AJVwuElvCAo9v8QYLzvavO5z2PiM38=
golang.org/x/tools v0.45.1-0.20260730185712-faf6fa7c2f89 h1:xFO+JWdpoTIFkUDzLfZrX4+NSAU3FZ8zc3wzsP7+aWQ=
golang.org/x/tools v0.45.1-0.20260730185712-faf6fa7c2f89/go.mod h1:LuUGqqaXcXMEFEruIVJVm5mgDD8vww/z/SR1gQ4uE/0=
golang.org/x/tools v0.45.1-0.20260826175739-e1f45aa8aed5 h1:vnaehVTejSNXKBvdx1mZMwNt7N3hxwIMC9CMJbf/iLI=
golang.org/x/tools v0.45.1-0.20260826175739-e1f45aa8aed5/go.mod h1:LuUGqqaXcXMEFEruIVJVm5mgDD8vww/z/SR1gQ4uE/0=
rsc.io/markdown v0.0.0-20240306144322-0bf8f97ee8ef h1:mqLYrXCXYEZOop9/Dbo6RPX11539nwiCNBb1icVPmw8=
rsc.io/markdown v0.0.0-20240306144322-0bf8f97ee8ef/go.mod h1:8xcPgWmwlZONN1D9bjxtHEjrUtSEa3fakVF8iaewYKQ=

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion src/cmd/vendor/modules.txt
Original file line number Diff line number Diff line change
Expand Up @@ -73,7 +73,7 @@ golang.org/x/text/internal/tag
golang.org/x/text/language
golang.org/x/text/transform
golang.org/x/text/unicode/norm
# golang.org/x/tools v0.45.1-0.20260730185712-faf6fa7c2f89
# golang.org/x/tools v0.45.1-0.20260826175739-e1f45aa8aed5
## explicit; go 1.25.0
golang.org/x/tools/cmd/bisect
golang.org/x/tools/cover
Expand Down
4 changes: 3 additions & 1 deletion src/crypto/internal/fips140/mldsa/mldsa_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -346,7 +346,9 @@ func TestCASTRejectionPaths(t *testing.T) {
testingOnlyRejectionReason = nil
})

fips140CAST()
if err := fips140CAST(); err != nil {
t.Fatal(err)
}

for reason, hit := range reached {
if !hit {
Expand Down
102 changes: 66 additions & 36 deletions src/crypto/internal/fips140/mlkem/cast.go
Original file line number Diff line number Diff line change
Expand Up @@ -8,45 +8,75 @@ import (
"bytes"
"crypto/internal/fips140"
_ "crypto/internal/fips140/check"
"crypto/internal/fips140/sha256"
"errors"
"sync"
)

var fipsSelfTest = sync.OnceFunc(func() {
fips140.CAST("ML-KEM-768", func() error {
var d = &[32]byte{
0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08,
0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f, 0x10,
0x11, 0x12, 0x13, 0x14, 0x15, 0x16, 0x17, 0x18,
0x19, 0x1a, 0x1b, 0x1c, 0x1d, 0x1e, 0x1f, 0x20,
}
var z = &[32]byte{
0x21, 0x22, 0x23, 0x24, 0x25, 0x26, 0x27, 0x28,
0x29, 0x2a, 0x2b, 0x2c, 0x2d, 0x2e, 0x2f, 0x30,
0x31, 0x32, 0x33, 0x34, 0x35, 0x36, 0x37, 0x38,
0x39, 0x3a, 0x3b, 0x3c, 0x3d, 0x3e, 0x3f, 0x40,
}
var m = &[32]byte{
0x41, 0x42, 0x43, 0x44, 0x45, 0x46, 0x47, 0x48,
0x49, 0x4a, 0x4b, 0x4c, 0x4d, 0x4e, 0x4f, 0x50,
0x51, 0x52, 0x53, 0x54, 0x55, 0x56, 0x57, 0x58,
0x59, 0x5a, 0x5b, 0x5c, 0x5d, 0x5e, 0x5f, 0x60,
}
var K = []byte{
0x55, 0x01, 0xfc, 0x52, 0x3b, 0x74, 0x5f, 0x41,
0x76, 0x2a, 0x18, 0x8d, 0xe4, 0x4a, 0x59, 0xb9,
0x20, 0xf4, 0x30, 0x14, 0x62, 0x04, 0xee, 0x4e,
0x79, 0x37, 0x32, 0x39, 0x6d, 0xf7, 0xaa, 0x48,
}
dk := &DecapsulationKey768{}
kemKeyGen(dk, d, z)
ek := dk.EncapsulationKey()
var cc [CiphertextSize768]byte
Ke, _ := kemEncaps(&cc, ek, m)
Kd := kemDecaps(dk, &cc)
if !bytes.Equal(Ke, K) || !bytes.Equal(Kd, K) {
return errors.New("unexpected result")
}
return nil
})
fips140.CAST("ML-KEM-768", fips140CAST)
})

// fips140CAST covers both the successful and the implicit rejection paths, as
// required by IG 10.3.A, Resolution 14, and as tested by TestCASTRejectionPath.
// It tests only one parameter set as allowed by Note22. It compares dk and not
// ek, because ek is part of dk, as allowed by the same Resolution. It compares
// dk with an expected hash to avoid embedding several kilobytes of test vectors
// in every binary, as allowed by GeneralNote7.
func fips140CAST() error {
var d = &[32]byte{
0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08,
0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f, 0x10,
0x11, 0x12, 0x13, 0x14, 0x15, 0x16, 0x17, 0x18,
0x19, 0x1a, 0x1b, 0x1c, 0x1d, 0x1e, 0x1f, 0x20,
}
var z = &[32]byte{
0x21, 0x22, 0x23, 0x24, 0x25, 0x26, 0x27, 0x28,
0x29, 0x2a, 0x2b, 0x2c, 0x2d, 0x2e, 0x2f, 0x30,
0x31, 0x32, 0x33, 0x34, 0x35, 0x36, 0x37, 0x38,
0x39, 0x3a, 0x3b, 0x3c, 0x3d, 0x3e, 0x3f, 0x40,
}
var dkHash = []byte{
0xa1, 0x32, 0x4a, 0x71, 0xf5, 0x7e, 0x26, 0x85,
0x37, 0x7e, 0x4f, 0x7d, 0xe2, 0xd1, 0xf0, 0x58,
0x53, 0x8e, 0x08, 0x7e, 0xe3, 0x9b, 0x48, 0x2b,
0x3d, 0xbf, 0x96, 0xf9, 0xf7, 0x69, 0xc7, 0x85,
}
var m = &[32]byte{
0x41, 0x42, 0x43, 0x44, 0x45, 0x46, 0x47, 0x48,
0x49, 0x4a, 0x4b, 0x4c, 0x4d, 0x4e, 0x4f, 0x50,
0x51, 0x52, 0x53, 0x54, 0x55, 0x56, 0x57, 0x58,
0x59, 0x5a, 0x5b, 0x5c, 0x5d, 0x5e, 0x5f, 0x60,
}
var K = []byte{
0x55, 0x01, 0xfc, 0x52, 0x3b, 0x74, 0x5f, 0x41,
0x76, 0x2a, 0x18, 0x8d, 0xe4, 0x4a, 0x59, 0xb9,
0x20, 0xf4, 0x30, 0x14, 0x62, 0x04, 0xee, 0x4e,
0x79, 0x37, 0x32, 0x39, 0x6d, 0xf7, 0xaa, 0x48,
}
var Kr = []byte{
0x01, 0xa1, 0x03, 0x3a, 0x2e, 0x68, 0x33, 0x80,
0x7f, 0xd3, 0x91, 0x80, 0xbe, 0x3b, 0x4f, 0x0a,
0x1f, 0x6f, 0x50, 0x51, 0x67, 0x56, 0x9d, 0x0e,
0x5e, 0x5e, 0x1f, 0xdb, 0x52, 0xa9, 0x10, 0xec,
}
dk := &DecapsulationKey768{}
kemKeyGen(dk, d, z)
ek := dk.EncapsulationKey()
H := sha256.New()
H.Write(TestingOnlyExpandedBytes768(dk))
if !bytes.Equal(H.Sum(nil), dkHash) {
return errors.New("unexpected private key hash")
}
var cc [CiphertextSize768]byte
Kd := kemDecaps(dk, &cc)
if !bytes.Equal(Kd, Kr) {
return errors.New("unexpected rejection result")
}
Ke, _ := kemEncaps(&cc, ek, m)
Kd = kemDecaps(dk, &cc)
if !bytes.Equal(Ke, K) || !bytes.Equal(Kd, K) {
return errors.New("unexpected result")
}
return nil
}
Loading
Loading