Skip to content

Add Composite ML-KEM base APIs - #132440

Merged
PranavSenthilnathan merged 2 commits into
mainfrom
ps-composite-ml-kem-base
Aug 19, 2026
Merged

PranavSenthilnathan merged 2 commits into
mainfrom
ps-composite-ml-kem-base

Conversation

@PranavSenthilnathan

@PranavSenthilnathan PranavSenthilnathan commented Aug 18, 2026 •

Copy link
Copy Markdown
Member

Adds the approved Composite ML-KEM base APIs, algorithm identifiers, import/export support, and contract tests. Platform implementations will follow.

Note

GitHub Copilot helped create this PR.

Contributes to #129633

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 5676db47-d54b-4946-97ec-7fc0a7392c30
Copilot AI lite review requested due to automatic review settings August 18, 2026 00:33
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).
13 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @bartonjs, @vcsjones, @dotnet/area-system-security
See info in area-owners.md if you want to be subscribed.

@PranavSenthilnathan PranavSenthilnathan added this to the 11.0.0 milestone Aug 18, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds the initial (base) public API surface for Composite ML-KEM to System.Security.Cryptography, including algorithm identifiers, OID wiring, and a comprehensive set of contract/factory tests using a mock implementation. The implementation is currently NotSupported everywhere, with platform-specific implementations intended to follow.

Changes:

  • Introduces new public types CompositeMLKem and CompositeMLKemAlgorithm (ref + implementation) plus algorithm OIDs.
  • Adds CompositeMLKemImplementation scaffolding (including NotSupported) and import/export plumbing (SPKI/PKCS#8/PEM) in the base class.
  • Adds contract tests and algorithm identifier tests, wired into both System.Security.Cryptography and Microsoft.Bcl.Cryptography test projects.

Reviewed changes

Copilot reviewed 17 out of 17 changed files in this pull request and generated 2 comments.

Show a summary per file
File Description
src/libraries/System.Security.Cryptography/tests/System.Security.Cryptography.Tests.csproj Links new Composite ML-KEM common tests into the SSC test project.
src/libraries/System.Security.Cryptography/src/System.Security.Cryptography.csproj Includes new Composite ML-KEM common sources and NotSupported plumbing for platforms.
src/libraries/System.Security.Cryptography/ref/System.Security.Cryptography.cs Adds new public ref surface for CompositeMLKem and CompositeMLKemAlgorithm.
src/libraries/Microsoft.Bcl.Cryptography/tests/Microsoft.Bcl.Cryptography.Tests.csproj Links new Composite ML-KEM common tests into the BCL test project.
src/libraries/Microsoft.Bcl.Cryptography/src/Microsoft.Bcl.Cryptography.Forwards.cs Type-forwards Composite ML-KEM types when NET11_0_OR_GREATER.
src/libraries/Microsoft.Bcl.Cryptography/src/Microsoft.Bcl.Cryptography.csproj Conditions inclusion of Composite ML-KEM sources for the BCL package build.
src/libraries/Common/tests/System/Security/Cryptography/CompositeMLKemAlgorithmTests.cs Validates algorithm identifiers, sizes, equality semantics, and naming.
src/libraries/Common/tests/System/Security/Cryptography/AlgorithmImplementations/CompositeMLKem/CompositeMLKemContractTests.cs Contract tests for base-class behavior (validation, export/import, disposal, misbehavior handling).
src/libraries/Common/tests/System/Security/Cryptography/AlgorithmImplementations/CompositeMLKem/CompositeMLKemFactoryTests.cs Factory/import behavior tests (including “unsupported” behavior until implementations land).
src/libraries/Common/tests/System/Security/Cryptography/AlgorithmImplementations/CompositeMLKem/CompositeMLKemMockImplementation.cs Mock derived implementation used by contract tests.
src/libraries/Common/tests/System/Security/Cryptography/AlgorithmImplementations/CompositeMLKem/CompositeMLKemTestData.cs Test vectors/bounds helpers for component sizing.
src/libraries/Common/tests/System/Security/Cryptography/AlgorithmImplementations/CompositeMLKem/CompositeMLKemTestHelpers.cs Shared helpers for PEM/SPKI/PKCS#8 scaffolding and export/import assertions.
src/libraries/Common/src/System/Security/Cryptography/Oids.cs Adds Composite ML-KEM OID constants.
src/libraries/Common/src/System/Security/Cryptography/CompositeMLKemImplementation.cs Declares partial platform hooks for generating/importing keys.
src/libraries/Common/src/System/Security/Cryptography/CompositeMLKemImplementation.NotSupported.cs Provides the current NotSupported implementation stub for all platforms.
src/libraries/Common/src/System/Security/Cryptography/CompositeMLKemAlgorithm.cs Implements algorithm identifiers, name/OID mapping, and size bounds.
src/libraries/Common/src/System/Security/Cryptography/CompositeMLKem.cs Implements the base class API surface (encap/decap, import/export, PEM/PKCS#8/SPKI plumbing).

Comment thread src/libraries/Common/src/System/Security/Cryptography/CompositeMLKem.cs Outdated
Comment thread src/libraries/Common/src/System/Security/Cryptography/CompositeMLKem.cs Outdated
Comment thread src/libraries/Common/src/System/Security/Cryptography/CompositeMLKem.cs Outdated
Comment thread src/libraries/Common/src/System/Security/Cryptography/CompositeMLKem.cs Outdated
Comment thread src/libraries/Common/src/System/Security/Cryptography/CompositeMLKem.cs Outdated
Comment thread src/libraries/Common/src/System/Security/Cryptography/CompositeMLKemAlgorithm.cs Outdated
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 17bb5da2-badb-480f-a196-71dc1e23dc7b
Copilot AI review requested due to automatic review settings August 19, 2026 10:15

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 17 out of 17 changed files in this pull request and generated no new comments.

Suppressed comments (2)

src/libraries/System.Security.Cryptography/ref/System.Security.Cryptography.cs:723

  • The api-approved issue (#129633) approval comment includes CompositeMLKemCng : CompositeMLKem in System.Security.Cryptography (and in Microsoft.Bcl.Cryptography via type forwarding). This PR adds the base CompositeMLKem/CompositeMLKemAlgorithm surface but does not add CompositeMLKemCng (or the related forwards/project wiring), so the ref contract does not match the approved API shape.
    [System.Diagnostics.CodeAnalysis.ExperimentalAttribute("SYSLIB5006", UrlFormat="https://aka.ms/dotnet-warnings/{0}")]
    public sealed partial class CompositeMLKemAlgorithm : System.IEquatable<System.Security.Cryptography.CompositeMLKemAlgorithm>
    {
        internal CompositeMLKemAlgorithm() { }
        public int CiphertextSizeInBytes { get { throw null; } }
        public static System.Security.Cryptography.CompositeMLKemAlgorithm MLKem1024WithECDiffieHellmanBrainpoolP384r1 { get { throw null; } }

src/libraries/Common/src/System/Security/Cryptography/CompositeMLKemAlgorithm.cs:60

  • The decapsulation-size invariant assert compares against the encapsulation max, which makes the debug check incorrect and could hide real mistakes during development. It should compare minDecapsulationKeySizeInBytes against maxDecapsulationKeySizeInBytes.
            Debug.Assert(minEncapsulationKeySizeInBytes <= maxEncapsulationKeySizeInBytes);
            Debug.Assert(minDecapsulationKeySizeInBytes <= maxDecapsulationKeySizeInBytes);

@PranavSenthilnathan
PranavSenthilnathan merged commit 1595d60 into main Aug 19, 2026
77 of 79 checks passed
@PranavSenthilnathan
PranavSenthilnathan deleted the ps-composite-ml-kem-base branch August 19, 2026 22:36
@dotnet-milestone-bot dotnet-milestone-bot Bot modified the milestones: 11.0.0, 12.0-preview1 Aug 21, 2026
@bartonjs bartonjs added the cryptographic-docs-impact Issues impacting cryptographic docs. Cleared and reused after documentation is updated each release. label Sep 11, 2026
artl93 pushed a commit that referenced this pull request Sep 19, 2026
Adds the approved Composite ML-KEM base APIs, algorithm identifiers,
import/export support, and contract tests. Platform implementations will
follow.

> [!NOTE]
> GitHub Copilot helped create this PR.

Contributes to #129633

---------

Copilot-Session: 5676db47-d54b-4946-97ec-7fc0a7392c30
Copilot-Session: 17bb5da2-badb-480f-a196-71dc1e23dc7b
(cherry picked from commit 1595d60)
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
artl93 pushed a commit that referenced this pull request Sep 19, 2026
main PR: #132440

# Description

Add the experimental Composite ML-KEM base APIs, algorithm identifiers,
and key import/export support. Straight backport; no additional code
changes. Stack layer 2/4, based on #134162, targeting RC2.

# Customer Impact

Provides the new hybrid PQC API surface. Requires the implementation
layers #134164 and #134165.

# Regression

No. New APIs.

# Testing

Includes the original contract and import/export tests. Cherry-pick
equivalence verified; no local builds or tests run for this layer.

# Risk

Low. Adds new experimental APIs without changing existing API behavior.
Ships together with the implementation layers.

> [!NOTE]
> This PR description was generated with GitHub Copilot.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 5676db47-d54b-4946-97ec-7fc0a7392c30
Copilot-Session: 17bb5da2-badb-480f-a196-71dc1e23dc7b
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-System.Security cryptographic-docs-impact Issues impacting cryptographic docs. Cleared and reused after documentation is updated each release.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants