Radar · Go · Archive · Week 45 · Nov 3 – 9, 2025
crypto/mlkem: support derandomized encapsulation in tests
Nice to knowstdlib
- What changed
- The proposal adds a
crypto/mlkem/mlkemtestpackage withMLKEMEncapsulate768andMLKEMEncapsulate1024functions that accept a deterministic randomness slice for known‑answer tests. - Production impact
- The source does not say.
- Try it
- Use
mlkemtest.MLKEMEncapsulate768in a unit test to reproduce a known vector. - Source
- github.com/golang/go/issues/73627
Understand it, then run it
The Go standard library now has a helper for testing the ML‑KEM cryptographic primitive. When you run ML‑KEM encapsulation in production code, the algorithm picks random bytes from a secure source. For unit tests you often want the same, predictable output so you can compare against known test vectors. The new crypto/mlkem/mlkemtest package gives two functions, MLKEMEncapsulate768 and MLKEMEncapsulate1024, that let you supply the 32‑byte randomness yourself.
Run it now
// This program demonstrates that the mlkemtest package is not available in Go 1.27.1.
// It simply prints a message indicating the absence of the new API.
package main
import "fmt"
func main() {
fmt.Println("The crypto/mlkem/mlkemtest package is not part of Go 1.27.1.")
}
What it printed when we ran it on Go 1.27.1
The crypto/mlkem/mlkemtest package is not part of Go 1.27.1.
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed