LICENSE

                                 Apache License
                           Version 2.0, January 2004
                        http://www.apache.org/licenses/

   TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION

   1. Definitions.

      "License" shall mean the terms and conditions for use, reproduction,
      and distribution as defined by Sections 1 through 9 of this document.

      "Licensor" shall mean the copyright owner or entity authorized by
      the copyright owner that is granting the License.

      "Legal Entity" shall mean the union of the acting entity and all
      other entities that control, are controlled by, or are under common
      control with that entity. For the purposes of this definition,
      "control" means (i) the power, direct or indirect, to cause the
      direction or management of such entity, whether by contract or
      otherwise, or (ii) ownership of fifty percent (50%) or more of the
      outstanding shares, or (iii) beneficial ownership of such entity.

      "You" (or "Your") shall mean an individual or Legal Entity
      exercising permissions granted by this License.

      "Source" form shall mean the preferred form for making modifications,
      including but not limited to software source code, documentation
      source, and configuration files.

      "Object" form shall mean any form resulting from mechanical
      transformation or translation of a Source form, including but
      not limited to compiled object code, generated documentation,
      and conversions to other media types.

      "Work" shall mean the work of authorship, whether in Source or
      Object form, made available under the License, as indicated by a
      copyright notice that is included in or attached to the work
      (an example is provided in the Appendix below).

      "Derivative Works" shall mean any work, whether in Source or Object
      form, that is based on (or derived from) the Work and for which the
      editorial revisions, annotations, elaborations, or other modifications
      represent, as a whole, an original work of authorship. For the purposes
      of this License, Derivative Works shall not include works that remain
      separable from, or merely link (or bind by name) to the interfaces of,
      the Work and Derivative Works thereof.

      "Contribution" shall mean any work of authorship, including
      the original version of the Work and any modifications or additions
      to that Work or Derivative Works thereof, that is intentionally
      submitted to Licensor for inclusion in the Work by the copyright owner
      or by an individual or Legal Entity authorized to submit on behalf of
      the copyright owner. For the purposes of this definition, "submitted"
      means any form of electronic, verbal, or written communication sent
      to the Licensor or its representatives, including but not limited to
      communication on electronic mailing lists, source code control systems,
      and issue tracking systems that are managed by, or on behalf of, the
      Licensor for the purpose of discussing and improving the Work, but
      excluding communication that is conspicuously marked or otherwise
      designated in writing by the copyright owner as "Not a Contribution."

      "Contributor" shall mean Licensor and any individual or Legal Entity
      on behalf of whom a Contribution has been received by the Licensor and
      subsequently incorporated within the Work.

   2. Grant of Copyright License. Subject to the terms and conditions of
      this License, each Contributor hereby grants to You a perpetual,
      worldwide, non-exclusive, no-charge, royalty-free, irrevocable
      copyright license to reproduce, prepare Derivative Works of,
      publicly display, publicly perform, sublicense, and distribute the
      Work and such Derivative Works in Source or Object form.

   3. Grant of Patent License. Subject to the terms and conditions of
      this License, each Contributor hereby grants to You a perpetual,
      worldwide, non-exclusive, no-charge, royalty-free, irrevocable
      (except as stated in this section) patent license to make, have made,
      use, offer to sell, sell, import, and otherwise transfer the Work,
      where such license applies only to those patent claims licensable
      by such Contributor that are necessarily infringed by their
      Contribution(s) alone or by combination of their Contribution(s)
      with the Work to which such Contribution(s) was submitted. If You
      institute patent litigation against any entity (including a
      cross-claim or countercounter claim in a lawsuit) alleging that the Work
      or a Contribution incorporated within the Work constitutes direct
      or contributory patent infringement, then any patent licenses
      granted to You under this License for that Work shall terminate
      as of the date such litigation is filed.

   4. Redistribution. You may reproduce and distribute copies of the
      Work or Derivative Works thereof in any medium, with or without
      modifications, and in Source or Object form, provided that You
      meet the following conditions:

      (a) You must give any other recipients of the Work or
          Derivative Works a copy of this License; and

      (b) You must cause any modified files to carry prominent notices
          stating that You changed the files; and

      (c) You must retain, in the Source form of any Derivative Works
          that You distribute, all copyright, patent, trademark, and
          attribution notices from the Source form of the Work,
          excluding those notices that do not pertain to any part of
          the Derivative Works; and

      (d) If the Work includes a "NOTICE" text file as part of its
          distribution, then any Derivative Works that You distribute must
          include a readable copy of the attribution notices contained
          within such NOTICE file, excluding those notices that do not
          pertain to any part of the Derivative Works, in at least one
          of the following places: within a NOTICE text file distributed
          as part of the Derivative Works; within the Source form or
          documentation, if provided along with the Derivative Works; or,
          within a display generated by the Derivative Works, if and
          wherever such third-party notices normally appear. The contents
          of the NOTICE file are for informational purposes only and
          do not modify the License. You may add Your own attribution
          notices within Derivative Works that You distribute, alongside
          or as an addendum to the NOTICE text from the Work, provided
          that such additional attribution notices cannot be construed
          as modifying the License.

      You may add Your own copyright statement to Your modifications and
      may provide additional or different license terms and conditions
      for use, reproduction, or distribution of Your modifications, or
      for any such Derivative Works as a whole, provided Your use,
      reproduction, and distribution of the Work otherwise complies with
      the conditions stated in this License.

   5. Submission of Contributions. Unless You explicitly state otherwise,
      any Contribution intentionally submitted for inclusion in the Work
      by You to the Licensor shall be under the terms and conditions of
      this License, without any additional terms or conditions.
      Notwithstanding the above, nothing herein shall supersede or modify
      the terms of any separate license agreement you may have executed
      with Licensor regarding such Contributions.

   6. Trademarks. This License does not grant permission to use the trade
      names, trademarks, service marks, or product names of the Licensor,
      except as required for reasonable and customary use in describing the
      origin of the Work and reproducing the content of the NOTICE file.

   7. Disclaimer of Warranty. Unless required by applicable law or
      agreed to in writing, Licensor provides the Work (and each
      Contributor provides its Contributions) on an "AS IS" BASIS,
      WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
      implied, including, without limitation, any warranties or conditions
      of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
      PARTICULAR PURPOSE. You are solely responsible for determining the
      appropriateness of using or redistributing the Work and assume any
      risks associated with Your Exercise of permissions under this License.

   8. Limitation of Liability. In no event and under no legal theory,
      whether in tort (including negligence), contract, or otherwise,
      unless required by applicable law (such as deliberate and grossly
      negligent acts) or agreed to in writing, shall any Contributor be
      liable to You for damages, including any direct, indirect, special,
      incidental, or consequential damages of any character arising as a
      result of this License or out of the use or inability to use the
      Work (including but not limited to damages for loss of goodwill,
      work stoppage, computer failure or malfunction, or any and all
      other commercial damages or losses), even if such Contributor
      has been advised of the possibility of such damages.

   9. Accepting Warranty or Additional Liability. While redistributing
      the Work or Derivative Works thereof, You may choose to offer,
      and charge a fee for, acceptance of support, warranty, indemnity,
      or other liability obligations and/or rights consistent with this
      License. However, in accepting such obligations, You may act only
      on your own behalf and on Your sole responsibility, not on behalf
      of any other Contributor, and only if You agree to indemnify,
      defend, and hold each Contributor harmless for any liability
      incurred by, or claims asserted against, such Contributor by reason
      of your accepting any such warranty or additional liability.

   END OF TERMS AND CONDITIONS

NOTICE

@awacloud/fw-wasm-crypto
Copyright (c) 2026 AwaCloud SAS
Author: Matthieu Bouilloux

Licensed under Apache-2.0; see the LICENSE file.
SPDX-License-Identifier: Apache-2.0

AWACLOUD and AWA are trademarks of Towards Conseil, used under licence.

Third-party components:
- mlkem-native v1.2.0 — Copyright (c) The mlkem-native project authors — Apache-2.0 AND MIT AND ISC AND CC0-1.0 — licence text: vendor/NOTICE-mlkem-native
- PQClean (commit 202a8f9, ML-DSA clean subset + FIPS-202/SHA-2 helpers) — The PQClean contributors — CC0-1.0 — licence text: vendor/NOTICE-pqclean
- OpenSSL SLH-DSA (FIPS-205) core — Copyright 2024-2025 The OpenSSL Project Authors. All Rights Reserved. — Apache-2.0 — licence text: vendor/NOTICE-openssl-slh-dsa
- BearSSL v0.6 — Copyright (c) 2016 Thomas Pornin <pornin@bolet.org> — MIT — licence text: vendor/NOTICE-bearssl
- fiat-crypto v0.1.6 — Copyright (c) 2015-2020 the fiat-crypto authors — MIT AND BSD-1-Clause AND Apache-2.0 — licence text: vendor/NOTICE-fiat-crypto
- libsodium 1.0.22 — Copyright (c) 2013-2024 Frank Denis and contributors — ISC — licence text: vendor/NOTICE-libsodium

vendor/NOTICE

@awacloud/fw-wasm-crypto — THIRD-PARTY NOTICES

This package vendors third-party crypto C sources under packages/front/
fw-wasm-crypto/vendor/. Provenance (url/ref/sha256/license) is locked in
vendor/PROVENANCE.json. This NOTICE aggregates the per-tree attribution.

================================================================================
mlkem-native — Apache-2.0 AND MIT AND ISC AND CC0-1.0
Upstream: https://github.com/pq-code-package/mlkem-native/archive/refs/tags/v1.2.0.tar.gz  (ref v1.2.0)
sha256:   377f0960ebab767ab2e4ad4bdb10d615dfcd530d575feeb572feb83e4aecbd33
--------------------------------------------------------------------------------
mlkem-native v1.2.0
Source: https://github.com/pq-code-package/mlkem-native/archive/refs/tags/v1.2.0.tar.gz
PQ Code Package / PQCA

mlkem-native is a fork of the public domain Kyber reference
implementation, available on https://github.com/pq-crystals/kyber.

All source code in mlkem/* and dev/* is licensed under your choice
of the Apache-2.0 license OR the ISC license OR the MIT license.
These licenses are reproduced below.
The copyright holders are indicated at the top of each file.

Only the freestanding ref (portable C) subset is vendored here:
  mlkem/mlkem_native.{c,h,_config.h}
  mlkem/src/*.{c,h,inc}
  mlkem/src/fips202/*.{c,h}
Native backends (AVX2/Neon/aarch64/riscv64/ppc64le), assembly (.S),
tests, benchmarks, CI, proofs, and examples are excluded.

---

MIT license (for mlkem-native project authors)

Copyright (c) The mlkem-native project authors
Copyright (c) 2020 Dougall Johnson
Copyright (c) 2022 Arm Limited
SPDX-License-Identifier: MIT

Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in
all copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.

---

ISC license

Copyright (c) The mlkem-native project authors

Permission to use, copy, modify, and/or distribute this software for any purpose
with or without fee is hereby granted, provided that the above copyright notice
and this permission notice appear in all copies.

THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH
REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY AND
FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,
INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS
OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR OTHER
TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF
THIS SOFTWARE.

---

Apache-2.0 license

                                 Apache License
                           Version 2.0, January 2004
                        http://www.apache.org/licenses/

   TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION

   1. Definitions.

      "License" shall mean the terms and conditions for use, reproduction,
      and distribution as defined by Sections 1 through 9 of this document.

      "Licensor" shall mean the copyright owner or entity authorized by
      the copyright owner that is granting the License.

      "Legal Entity" shall mean the union of the acting entity and all
      other entities that control, are controlled by, or are under common
      control with that entity. For the purposes of this definition,
      "control" means (i) the power, direct or indirect, to cause the
      direction or management of such entity, whether by contract or
      otherwise, or (ii) ownership of fifty percent (50%) or more of the
      outstanding shares, or (iii) beneficial ownership of such entity.

      "You" (or "Your") shall mean an individual or Legal Entity
      exercising permissions granted by this License.

      "Source" form shall mean the preferred form for making modifications,
      including but not limited to software source code, documentation
      source, and configuration files.

      "Object" form shall mean any form resulting from mechanical
      transformation or translation of a Source form, including but
      not limited to compiled object code, generated documentation,
      and conversions to other media types.

      "Work" shall mean the work of authorship, whether in Source or
      Object form, made available under the License, as indicated by a
      copyright notice that is included in or attached to the work
      (an example is provided in the Appendix below).

      "Derivative Works" shall mean any work, whether in Source or Object
      form, that is based on (or derived from) the Work and for which the
      editorial revisions, annotations, elaborations, or other modifications
      represent, as a whole, an original work of authorship. For the purposes
      of this License, Derivative Works shall not include works that remain
      separable from, or merely link (or bind by name) to the interfaces of,
      the Work and Derivative Works thereof.

      "Contribution" shall mean any work of authorship, including
      the original version of the Work and any modifications or additions
      to that Work or Derivative Works thereof, that is intentionally
      submitted to Licensor for inclusion in the Work by the copyright owner
      or by an individual or Legal Entity authorized to submit on behalf of
      the copyright owner. For the purposes of this definition, "submitted"
      means any form of electronic, verbal, or written communication sent
      to the Licensor or its representatives, including but not limited to
      communication on electronic mailing lists, source code control systems,
      and issue tracking systems that are managed by, or on behalf of, the
      Licensor for the purpose of discussing and improving the Work, but
      excluding communication that is conspicuously marked or otherwise
      designated in writing by the copyright owner as "Not a Contribution."

      "Contributor" shall mean Licensor and any individual or Legal Entity
      on behalf of whom a Contribution has been received by the Licensor and
      subsequently incorporated within the Work.

   2. Grant of Copyright License. Subject to the terms and conditions of
      this License, each Contributor hereby grants to You a perpetual,
      worldwide, non-exclusive, no-charge, royalty-free, irrevocable
      copyright license to reproduce, prepare Derivative Works of,
      publicly display, publicly perform, sublicense, and distribute the
      Work and such Derivative Works in Source or Object form.

   3. Grant of Patent License. Subject to the terms and conditions of
      this License, each Contributor hereby grants to You a perpetual,
      worldwide, non-exclusive, no-charge, royalty-free, irrevocable
      (except as stated in this section) patent license to make, have made,
      use, offer to sell, sell, import, and otherwise transfer the Work,
      where such license applies only to those patent claims licensable
      by such Contributor that are necessarily infringed by their
      Contribution(s) alone or by combination of their Contribution(s)
      with the Work to which such Contribution(s) was submitted. If You
      institute patent litigation against any entity (including a
      cross-claim or countercounter claim in a lawsuit) alleging that the Work
      or a Contribution incorporated within the Work constitutes direct
      or contributory patent infringement, then any patent licenses
      granted to You under this License for that Work shall terminate
      as of the date such litigation is filed.

   4. Redistribution. You may reproduce and distribute copies of the
      Work or Derivative Works thereof in any medium, with or without
      modifications, and in Source or Object form, provided that You
      meet the following conditions:

      (a) You must give any other recipients of the Work or
          Derivative Works a copy of this License; and

      (b) You must cause any modified files to carry prominent notices
          stating that You changed the files; and

      (c) You must retain, in the Source form of any Derivative Works
          that You distribute, all copyright, patent, trademark, and
          attribution notices from the Source form of the Work,
          excluding those notices that do not pertain to any part of
          the Derivative Works; and

      (d) If the Work includes a "NOTICE" text file as part of its
          distribution, then any Derivative Works that You distribute must
          include a readable copy of the attribution notices contained
          within such NOTICE file, excluding those notices that do not
          pertain to any part of the Derivative Works, in at least one
          of the following places: within a NOTICE text file distributed
          as part of the Derivative Works; within the Source form or
          documentation, if provided along with the Derivative Works; or,
          within a display generated by the Derivative Works, if and
          wherever such third-party notices normally appear. The contents
          of the NOTICE file are for informational purposes only and
          do not modify the License. You may add Your own attribution
          notices within Derivative Works that You distribute, alongside
          or as an addendum to the NOTICE text from the Work, provided
          that such additional attribution notices cannot be construed
          as modifying the License.

      You may add Your own copyright statement to Your modifications and
      may provide additional or different license terms and conditions
      for use, reproduction, or distribution of Your modifications, or
      for any such Derivative Works as a whole, provided Your use,
      reproduction, and distribution of the Work otherwise complies with
      the conditions stated in this License.

   5. Submission of Contributions. Unless You explicitly state otherwise,
      any Contribution intentionally submitted for inclusion in the Work
      by You to the Licensor shall be under the terms and conditions of
      this License, without any additional terms or conditions.
      Notwithstanding the above, nothing herein shall supersede or modify
      the terms of any separate license agreement you may have executed
      with Licensor regarding such Contributions.

   6. Trademarks. This License does not grant permission to use the trade
      names, trademarks, service marks, or product names of the Licensor,
      except as required for reasonable and customary use in describing the
      origin of the Work and reproducing the content of the NOTICE file.

   7. Disclaimer of Warranty. Unless required by applicable law or
      agreed to in writing, Licensor provides the Work (and each
      Contributor provides its Contributions) on an "AS IS" BASIS,
      WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
      implied, including, without limitation, any warranties or conditions
      of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
      PARTICULAR PURPOSE. You are solely responsible for determining the
      appropriateness of using or redistributing the Work and assume any
      risks associated with Your Exercise of permissions under this License.

   8. Limitation of Liability. In no event and under no legal theory,
      whether in tort (including negligence), contract, or otherwise,
      unless required by applicable law (such as deliberate and grossly
      negligent acts) or agreed to in writing, shall any Contributor be
      liable to You for damages, including any direct, indirect, special,
      incidental, or consequential damages of any character arising as a
      result of this License or out of the use or inability to use the
      Work (including but not limited to damages for loss of goodwill,
      work stoppage, computer failure or malfunction, or any and all
      other commercial damages or losses), even if such Contributor
      has been advised of the possibility of such damages.

   9. Accepting Warranty or Additional Liability. While redistributing
      the Work or Derivative Works thereof, You may choose to offer,
      and charge a fee for, acceptance of support, warranty, indemnity,
      or other liability obligations and/or rights consistent with this
      License. However, in accepting such obligations, You may act only
      on your own behalf and on Your sole responsibility, not on behalf
      of any other Contributor, and only if You agree to indemnify,
      defend, and hold each Contributor harmless for any liability
      incurred by, or claims asserted against, such Contributor by reason
      of your accepting any such warranty or additional liability.

   END OF TERMS AND CONDITIONS

================================================================================
pqclean — CC0-1.0
Upstream: https://github.com/PQClean/PQClean  (ref 202a8f96315f9ed219387a50f7e40d04af037ea8)
sha256:   517bffa8694b3e50f9ce5a68c316b6a24c4e1067a543c03083e77190b038b2c0
--------------------------------------------------------------------------------
NOTICE — vendored PQClean subset
=================================

Source:   https://github.com/PQClean/PQClean
Commit:   202a8f96315f9ed219387a50f7e40d04af037ea8
Vendored: packages/front/fw-wasm-crypto/vendor/pqclean/

Schemes vendored
----------------
  FIPS-204 (ML-DSA):
    crypto_sign/ml-dsa-44/clean/
    crypto_sign/ml-dsa-65/clean/
    crypto_sign/ml-dsa-87/clean/

  NOTE: the round-3 SPHINCS+ sets first vendored here were removed once SLH-DSA
  was re-sourced from OpenSSL's FIPS-205 implementation (see
  vendor/NOTICE-openssl-slh-dsa). This tree no longer vendors any sphincs set.

  Shared (FIPS-202 and SHA-2 helpers):
    common/fips202.c  — public domain (SUPERCOP/Keccak by Ronny Van Keer,
                        TweetFips202 authors; see file header); used by ml-dsa
                        and the OpenSSL SLH-DSA freestanding hash adapter
    common/fips202.h
    common/sha2.c     — public domain (SUPERCOP by D. J. Bernstein; see
                        file header); used by the OpenSSL SLH-DSA hash adapter
    common/sha2.h
    common/compat.h   — no explicit copyright; compiler-compatibility shims
    common/randombytes.h — declaration only; definition is the package RNG seam
                        (NOT PQClean's randombytes.c; MIT, omitted)

Files NOT vendored (out of scope)
----------------------------------
  common/randombytes.c  — MIT, Daan Sprenkels; not vendored, the definition is supplied by the package
  common/sp800-185.{c,h}, common/aes.{c,h}, common/nistseedexpander.{c,h},
  common/crypto_declassify.h — not referenced by any vendored scheme
  AVX2 backends, aarch64 backends, test harnesses, CI, other schemes

SPDX license expressions
-------------------------
  crypto_sign/ml-dsa-*/clean/   :  CC0-1.0 (see each clean/LICENSE)
  common/fips202.{c,h}          :  Public domain (see file headers)
  common/sha2.{c,h}             :  Public domain (see file headers)
  common/compat.h               :  (no license notice; header-only compat shims)
  common/randombytes.h          :  (no license notice; declaration only)

Aggregate SPDX expression: CC0-1.0

CC0 carries no NOTICE obligation, but this file is recorded per the
project's provenance policy for the audit trail.

================================================================================
openssl-slh-dsa — Apache-2.0
Upstream: https://github.com/openssl/openssl/archive/refs/tags/openssl-3.5.0.tar.gz  (ref openssl-3.5.0)
sha256:   20a5f860014d4008b95084cb40c5df85c5e6694dbef89ac755136be5396ef7a0
--------------------------------------------------------------------------------
OpenSSL SLH-DSA (FIPS-205) core — vendored source notice
=========================================================

Origin
------
Upstream: OpenSSL (https://github.com/openssl/openssl)
Tag:      openssl-3.5.0
Commit:   02192e014a72972a398eee3106f0ec369eabc1f1 (annotated tag object)
Path:     crypto/slh_dsa/** and include/crypto/slh_dsa.h
License:  Apache License 2.0

Only the PORTABLE FIPS-205 SLH-DSA algorithm core is vendored here (FORS, WOTS+,
XMSS, hypertree, address encoding, parameter sets, and the sign/verify driver).
The EVP/provider-coupled translation units (slh_hash.c, slh_dsa_key.c,
slh_dsa_hash_ctx.c) are NOT vendored: they are replaced by a freestanding
adapter under csrc/slhdsa/** that implements the OSSL_SLH_HASHFUNC_* vtable on
top of vendor/pqclean/common/{fips202,sha2}.c and provides a minimal
freestanding key/context and OpenSSL-infra compatibility layer.

slh_dsa_pub.h is the upstream include/crypto/slh_dsa.h, vendored next to the core
under the name slh_dsa_pub.h; the freestanding compat header tree maps
#include "crypto/slh_dsa.h" onto it.

Vendored files (13):
  slh_adrs.c slh_adrs.h slh_dsa.c slh_dsa_key.h slh_dsa_local.h slh_dsa_pub.h
  slh_fors.c slh_hash.h slh_hypertree.c slh_params.c slh_params.h slh_wots.c
  slh_xmss.c

Committed-tree SHA-256 (sorted POSIX paths, single running SHA-256 over
"<relpath>\0<bytes>" per file):
  20a5f860014d4008b95084cb40c5df85c5e6694dbef89ac755136be5396ef7a0


Apache License 2.0 obligation
-----------------------------
Copyright 2024-2025 The OpenSSL Project Authors. All Rights Reserved.

Licensed under the Apache License, Version 2.0 (the "License"); you may not use
these files except in compliance with the License. You may obtain a copy of the
License at

    http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software distributed
under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR
CONDITIONS OF ANY KIND, either express or implied. See the License for the
specific language governing permissions and limitations under the License.

The per-file headers in the vendored sources carry the upstream SPDX/copyright
notice verbatim and are preserved unchanged.

================================================================================
bearssl — MIT
Upstream: https://bearssl.org/bearssl-0.6.tar.gz  (ref v0.6)
sha256:   759d09cd1e850657301e60d6179fba4b1d11d743f7f34de821a5f6dffbb82a1f
--------------------------------------------------------------------------------
NOTICE — vendored BearSSL v0.6 subset
======================================

Source:   https://bearssl.org/bearssl-0.6.tar.gz
Version:  v0.6 (beta, August 2018)
Author:   Thomas Pornin <pornin@bolet.org>
Vendored: packages/front/fw-wasm-crypto/vendor/bearssl/

Security note: BearSSL v0.6 is a beta release and has never received a formal
cryptographic audit. This is accepted debt per the plan (risk 2).

Files vendored
--------------
  inc/bearssl*.h             — public API headers (all)
  src/inner.h                — internal API header
  src/config.h               — build configuration header
  src/aead/gcm.c             — GCM authenticated encryption
  src/ec/ec_keygen.c         — EC key generation
  src/ec/ec_prime_i31.c      — EC prime-field I31 arithmetic core
  src/ec/ec_pubkey.c         — EC public key ops
  src/ec/ec_secp256r1.c      — P-256 curve parameters
  src/ec/ec_secp384r1.c      — P-384 curve parameters
  src/ec/ec_secp521r1.c      — P-521 curve parameters
  src/ec/ecdsa_i31_sign_raw.c  — ECDSA I31 sign (raw)
  src/ec/ecdsa_i31_vrfy_raw.c  — ECDSA I31 verify (raw)
  src/hash/ghash_ctmul64.c   — GHASH constant-time 64-bit multiply
  src/hash/sha2big.c         — SHA-384 / SHA-512
  src/hash/sha2small.c       — SHA-224 / SHA-256
  src/int/i31_*.c            — I31 big-integer primitives (16 files)
  src/kdf/hkdf.c             — HKDF key derivation
  src/mac/hmac.c             — HMAC
  src/mac/hmac_ct.c          — HMAC constant-time variant
  src/rand/hmac_drbg.c       — HMAC-DRBG
  src/rsa/rsa_i31_keygen.c         — RSA I31 key generation (dispatcher)
  src/rsa/rsa_i31_keygen_inner.c   — RSA I31 key generation (core)
  src/rsa/rsa_i31_modulus.c        — RSA I31 modulus ops
  src/rsa/rsa_i31_oaep_decrypt.c   — RSA OAEP decrypt (I31)
  src/rsa/rsa_i31_pkcs1_sign.c     — RSA PKCS1 sign (I31)
  src/rsa/rsa_i31_pkcs1_vrfy.c     — RSA PKCS1 verify (I31)
  src/rsa/rsa_i31_priv.c           — RSA I31 private key ops
  src/rsa/rsa_i31_privexp.c        — RSA I31 private exponent
  src/rsa/rsa_i31_pub.c            — RSA I31 public key ops
  src/rsa/rsa_i31_pubexp.c         — RSA I31 public exponent
  src/rsa/rsa_oaep_pad.c           — RSA OAEP padding (generic)
  src/symcipher/aes_ct.c           — AES constant-time base
  src/symcipher/aes_ct64.c         — AES constant-time 64-bit
  src/symcipher/aes_ct64_cbcdec.c  — AES-CT64 CBC decrypt
  src/symcipher/aes_ct64_cbcenc.c  — AES-CT64 CBC encrypt
  src/symcipher/aes_ct64_ctr.c     — AES-CT64 CTR mode

Files NOT vendored (out of scope)
-----------------------------------
  T0/                    — T0 TLS codegen (not needed)
  test/                  — upstream test harness
  tools/                 — upstream build tools
  samples/               — example code
  src/ssl/               — TLS/SSL layer (unused)
  src/x509/              — X.509 layer (unused)
  src/codec/             — PEM/DER codecs (unused)
  src/ec/ec_*i15*.c      — I15 EC variants (unused)
  src/ec/ecdsa_*i15*.c   — I15 ECDSA variants (unused)
  src/ec/ec_c25519*.c    — Curve25519 (vendored via libsodium instead)
  src/symcipher/aes_big*.c, aes_small*.c, aes_x86ni*.c — non-CT or x86-specific
  src/rsa/rsa_i15_*.c, rsa_i32_*.c, rsa_i62_*.c — non-I31 RSA variants
  src/int/i15_*.c, i32_*.c, i62_*.c — non-I31 big-integer files
  T0Comp.exe             — Windows binary (not committed)

License
-------
MIT

Copyright (c) 2016 Thomas Pornin <pornin@bolet.org>

Permission is hereby granted, free of charge, to any person obtaining
a copy of this software and associated documentation files (the
"Software"), to deal in the Software without restriction, including
without limitation the rights to use, copy, modify, merge, publish,
distribute, sublicense, and/or sell copies of the Software, and to
permit persons to whom the Software is furnished to do so, subject to
the following conditions:

The above copyright notice and this permission notice shall be
included in all copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS
BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN
ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.

================================================================================
fiat-crypto — MIT AND BSD-1-Clause AND Apache-2.0
Upstream: https://github.com/mit-plv/fiat-crypto/archive/refs/tags/v0.1.6.tar.gz  (ref v0.1.6)
sha256:   b6a4a6ce5563b5b86ba1161801e0bbba60dd0c689b5b06abde36d91ab84b979a
--------------------------------------------------------------------------------
NOTICE — vendored fiat-crypto v0.1.6 subset
============================================

Source:   https://github.com/mit-plv/fiat-crypto/archive/refs/tags/v0.1.6.tar.gz
Version:  v0.1.6
Authors:  The fiat-crypto authors (see AUTHORS)
Vendored: packages/front/fw-wasm-crypto/vendor/fiat-crypto/

fiat-crypto generates machine-verified correct-by-construction field-arithmetic
code for prime-field curves (P-256, P-384, P-521, Curve25519, etc.) from
formal proofs in Coq/Bedrock2. The generated C files are the sole compilation
output — no proofs or Coq toolchain are needed at build time.

Files vendored
--------------
  fiat-c/src/p256_64.c         — P-256 field arithmetic (64-bit)
  fiat-c/src/p256_32.c         — P-256 field arithmetic (32-bit)
  fiat-c/src/p256_scalar_64.c  — P-256 scalar arithmetic (64-bit)
  fiat-c/src/p256_scalar_32.c  — P-256 scalar arithmetic (32-bit)
  fiat-c/src/p384_64.c         — P-384 field arithmetic (64-bit)
  fiat-c/src/p384_32.c         — P-384 field arithmetic (32-bit)
  fiat-c/src/p384_scalar_64.c  — P-384 scalar arithmetic (64-bit)
  fiat-c/src/p384_scalar_32.c  — P-384 scalar arithmetic (32-bit)
  fiat-c/src/p521_64.c         — P-521 field arithmetic (64-bit)
  fiat-c/src/p521_32.c         — P-521 field arithmetic (32-bit)
  fiat-c/src/curve25519_64.c   — X25519 / Ed25519 field arith (64-bit)
  fiat-c/src/curve25519_32.c   — X25519 / Ed25519 field arith (32-bit)
  (and all other fiat-c/src/*.c field-arithmetic files)
  AUTHORS, LICENSE-MIT, LICENSE-BSD-1, LICENSE-APACHE

Files NOT vendored (out of scope)
-----------------------------------
  fiat-amd64/, fiat-bedrock2/, fiat-go/, fiat-java/, fiat-rust/, fiat-zig/
  fiat-html/, fiat-json/   — other language targets
  src/                     — Coq proof sources
  inversion/, output-tests/, etc/ — proof tooling
  Makefile*, _CoqProject*, *.in, *.local  — build/proof infra
  README.md, *.md          — project documentation

License (triple — any one may be used)
---------------------------------------
  MIT: Copyright (c) 2015-2020 the fiat-crypto authors
  Apache-2.0: Copyright 2015-2020 the fiat-crypto authors
  BSD-1-Clause: Copyright (c) 2015-2020 the fiat-crypto authors

SPDX-License-Identifier: MIT AND Apache-2.0 AND BSD-1-Clause

The MIT License (MIT)

Copyright (c) 2015-2020 the fiat-crypto authors (see the AUTHORS file).

Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.

================================================================================
libsodium — ISC
Upstream: https://github.com/jedisct1/libsodium/archive/refs/tags/1.0.22-RELEASE.tar.gz  (ref 1.0.22-RELEASE)
sha256:   acb6837051b26fd4cb80405d9a2a9d96b25184c3e65ac04bc4894008e6554688
--------------------------------------------------------------------------------
libsodium — ISC License
=======================

Vendored subset: ed25519 + curve25519 ref10 link-closure (20 files).
Upstream: https://github.com/jedisct1/libsodium
Release: 1.0.22-RELEASE

Copyright (c) 2013-2024
Frank Denis and contributors

ISC License

Permission to use, copy, modify, and/or distribute this software for any
purpose with or without fee is hereby granted, provided that the above
copyright notice and this permission notice appear in all copies.

THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.

---

Vendored path: vendor/libsodium/
Field path: fe_25_5 (32-bit limb, wasm32-safe; fe_51 headers vendored
as include-closure but not compiled — HAVE_TI_MODE not defined).
SHA-512 / randombytes / sodium-utils seamed to the package's own
csrc/sha2 / csrc/rng / csrc/libsodium-compat (no libsodium SHA-512 TU
or sodium utils code vendored).