Skip to content

v0.45.0 (2026-10-04)

Latest

Choose a tag to compare

@emmansun emmansun released this 04 Oct 02:52
4328ff9

Massive RISC-V 64 vector-extension support across the library, a Go 1.26 baseline upgrade, and several security and correctness fixes.

Highlights

  • RISC-V 64 (RVV 1.0 + Zvk) vector acceleration for ML-KEM, ML-DSA, SM4 (GCM/CTR/XTS), SM3, ZUC, GCM-SIV, SM2/SM9/BN256
  • Go 1.26 baseline (riscv64 vector crypto paths require Go 1.27+)
  • smx509 upgraded to the Go 1.26 stdlib baseline, with Go 1.27 PKIX name formatting support
  • Security and correctness fixes: pkcs7 out-of-bounds read on truncated BER, SM9 key-wrap ciphertext length checks, multiple XTS fixes

What's Changed

RISC-V 64 vector implementations

ML-KEM (mlkem)

  • Full RVV optimization: NTT / inverse NTT (incl. mulAcc / keygen paths), ring compress & encode (1/4/5/10/11-bit), decodeAndDecompress, samplePolyCBD, rejUniform, polynomial add/sub, with benchmarks (d0c786dd, ec56802c, 95134421, 51c4c2e7, baf78858, 12a28366, 6d644b2b, e288343b, e4be80cf, ...)
  • Keccak-x4 integration and VLEN>128 (M1 layout) support (2be6cccf, 979c2bb4)

ML-DSA (mldsa)

  • RVV optimization: NTT, nttMatRowVecMul, hint make/use & decompose, infinity norm, bit pack/unpack (encode/decode), with benchmarks (2eb3546f, b96c65b5, 320bfdca, 30d9971e, 8df409e6, 262b1f29, ...)

SM4 (internal/sm4)

  • GCM with Zvbc carry-less multiply and Zvkg GHASH paths, including gcm init/data/finish rework and tail optimizations (362eedf1, a2378679, dd1cc459, 27f39363, ...)
  • CTR mode via Zvksed (33934a6b, fba89f6b, ...)
  • XTS mode via Zvksed (ea482c59), incl. VLEN>128 fix (a179e573)

SM3 (internal/sm3)

  • Zvksh vector path using word instructions for go1.27 compatibility (fdaca36f, e7f02778, 63015b2a)

ZUC (internal/zuc)

  • riscv64 EEA / EIA-256 using Zvkned & Zvbb/Zvbc (d9da06a9, b652bbd6, 0cefb3f7, 12f0066b, ...)

GCM-SIV (internal/cipher/gcmsiv)

  • riscv64 Zvkg/Zvbc POLYVAL & mulX_GHASH (fe1ebc48, a9cd77a1, ...)

XTS (internal/cipher/xts)

  • riscv64 mul2Asm / doubleTweaksAsm incl. GB variant (41e6dcef, 22534839, f9ce8029, ...)

Other primitives

  • internal/sm2ec: RVV select primitives with scalar health-check fallback (9bf4fac3, ecb4b776, 96d172c5, 95fc884b)
  • internal/sm9, bn256: RVV select & memory copy, optimized MOVCOND64 (852890f8, e4834d3b)
  • internal/keccakx4: riscv64 support, M1 for VLEN>128 (4d555840, 979c2bb4)
  • internal/deps/cpu: detect RISC-V VLENB and Zvbb/Zvkb/Zvbc/Zvkg/Zvksed/Zvksh features (bc08516d, e97e7a68, 201a3fc4)

Other platforms

  • internal/sm3: LoongArch LASX/LSX optimizations — matrix transpose, VEXTRINSW in LSX schedule (0bc79ed9, ea9e7849, d9958439)
  • mldsa, mlkem: loong64 native XVPERMIQ/XVSHUFB instructions (fdc2e074)
  • smx509: upgrade to Go 1.26 baseline (#629), support Go 1.27 PKIX name formatting (24224d0d)

Performance

  • SM4 XTS: deferred tweak doubling for the GB variant (780202e1); CTS 16-byte stack swap buffer eliminated on amd64/arm64 (baea2085); riscv64 XTS optimizations

Bug fixes

  • pkcs7: fix ber2der reading past end of input on truncated BER (2a92bad7); add fuzz test (59207b18)
  • sm9: enhance PKE wrap/unwrap key with ECB/CBC ciphertext length checks (5c1252f9)
  • cipher: enforce XTS concurrent batch size (fe5e24c8); preserve XTS CTS block in concurrent decrypt (87878be5); arm64 XTS fix (c48fb3c6)
  • slhdsa: fix wrong key type (d0e46dcd, #622)
  • internal/bigmod: fix extendedGCD implementation mismatch (e84396f9)
  • tls13: fix compatibility issue with Golang (ea96268a)
  • smx509: stabilize patch generation (942b28d7); restore Go 1.26 root env tests (4b5fd79a)

Others

  • Upgrade Golang from 1.25 to 1.26 (825f11d2); riscv64 vector paths require go1.27+
  • CI: riscv64 VLEN test matrix (b5ad7b29), QEMU coverage, codecov/codeql/harden-runner/dependabot bumps
  • Dependencies: golang.org/x/crypto 0.54.0 → 0.55.0
  • Docs: README updates for riscv64 SM3/SM4/ML-KEM/ML-DSA; CONTRIBUTORS.md refreshed

🌟 Welcome New Contributors