From ac7d996924b36668965c5e1237328f3180f04554 Mon Sep 17 00:00:00 2001 From: yuhan6665 <1588741+yuhan6665@users.noreply.github.com> Date: Tue, 8 Sep 2026 21:45:43 -0400 Subject: [PATCH] crypto: return an error if a hash function is not available Calling New otherwise panics, which is unnecessary, especially in crypto.SignMessage and especially if we add a new not-implemented hash value for ML-DSA external Mu. Change-Id: I9f8d29d01e126838d7d2585133e562536a6a6964 Reviewed-on: https://go-review.googlesource.com/c/go/+/745660 Reviewed-by: Roland Shoemaker Reviewed-by: Daniel McCarney Reviewed-by: Dmitri Shuralyov LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com Auto-Submit: Filippo Valsorda --- auth.go | 3 +++ cipher_suites.go | 1 + 2 files changed, 4 insertions(+) diff --git a/auth.go b/auth.go index a9c6a66..f7c27d5 100644 --- a/auth.go +++ b/auth.go @@ -21,6 +21,9 @@ import ( // verifyHandshakeSignature verifies a signature against unhashed handshake contents. func verifyHandshakeSignature(sigType uint8, pubkey crypto.PublicKey, hashFunc crypto.Hash, signed, sig []byte) error { if hashFunc != directSigning { + if !hashFunc.Available() { + return fmt.Errorf("hash function unavailable: %v", hashFunc) + } h := hashFunc.New() h.Write(signed) signed = h.Sum(nil) diff --git a/cipher_suites.go b/cipher_suites.go index 3cb9fa3..bc508fe 100644 --- a/cipher_suites.go +++ b/cipher_suites.go @@ -13,6 +13,7 @@ import ( "crypto/rc4" "crypto/sha1" "crypto/sha256" + _ "crypto/sha512" // for crypto.SHA384 "fmt" "hash" "runtime"