* Refactor meta-wolfssl: modularize feature enablement and centralize helpers in bbclass
Refactored layer.conf to unconditionally include all recipes, moved feature-specific configuration into modular .inc files, created wolfssl-helper.bbclass with reusable do_wolfssl_autogen and do_wolfssl_check_package tasks, updated all recipes to use the new pattern, and standardized commercial license variables to be recipe-specific.
Use a virtual wolfssl to make library switching easier for fips vs non fips or other wolfSSL packages
Set wolfssl libraries as the deafualt weak Preferred_Provider option for packages
* Merged refactor and new test changes
* Combine refactor changes and add replace default and fips modes
* Add working and tested fips, replace default, non-fips, non-replace-default work
* Add FIPS replace default to layers and test all options
* Refactor bbappends to be more yocto like
* Add overide to openssl configure
* Address comment concerns
* Only do neccesary simlinks
* Only do neccesary simlinks
* Convert wolfprovider test bbappend to inc file
* Add Image minimals for all wolfprovider modes
* Fully tested images
* Get conf files from source
* Fix FIPS package issues
* Fixes 7z extraction issues, mostly around using password when the
password has already been stripped out
* Fixes autoreconf and configure issues with the FIPS package
* Fixes wolfcrypttest and wolfcryptbenchmark not being isntalled with
FIPS when they are selected
* Fix unstable meta data for fips package
* Fix the execution command for QEMU
The execution of QEMU to get the hash would fail when cross-compiling to
a different CPU target. This fixes it.
* gnutls-wolfssl layers
Added 3 layers
- gnutls: gnutls fork patched to use wolfssl as cryptographic
provider
- wolfssl: wolfssl configured to work against gnutls
- wolfssl-gnutls-wrapper: shim layer that gets called by gnutls
applications when linked against gnutls-wolfssl
- gnutls-wolfssl-tests: tests from the wolfssl-gnutls-wrapper folder
installed under /usr/lib/wolfssl-gnutls-wrapper/
Everything gets installed under /usr ovverriding the system installed
recipes, the wrapper is symlinked in /opt.
Fips currently not supported.
* fips support
* Removed hmac generation and installation since this step is already
happening on the base recipe
* gnutls layers (from https://github.com/wolfSSL/meta-wolfssl/pull/111/)
rebased against the new staging branch (refactor-meta-wolfssl)
* - added gnutls-image-minimal;
- update layer.conf to conditionally include gnutls-image-minimal if
included in the WOLFSSL_DEMOS;
- minor update to inc/gnutls/gnutls-enable-wolfssl.inc to by pass the
fuzzing binaries from the base recipes;
* added do_configure[network] = "1" to the inc file (fixes networking issues on
some builds)
* Add support for GCP and tarballs
The commercial package can now be retrieved from GCP and can be a
tarball without password protection.
* fix stamp.h in append rather than main .bb
* Update wolfprovider include files with local changes
* Add messages for debug files
* Follow Debian convention for provider config in openssl.cnf
- Install provider*.conf files to /etc/ssl/openssl.cnf.d/ instead of /opt
- Remove OPENSSL_CONF environment variable approach
- Add .include directive to openssl.cnf automatically in explicit load mode
- This allows OpenSSL to automatically load the provider configuration
- Update script output to reflect the new approach
* Append conf fil
* Don't use fixed version for FIPS
User can use any FIPS wolfSSL package
* Fix naming for new fips rename
* Add final wolfprovider refactor changes
* Benchmark and GPG Error Patch to resolve build issues and disable benchmarking due to length of time it takes to run AES GCM in current port
* Fixes for when GNUPG is needed
* Update wolfProvider images to match other demo images,
add to bbclass to ensure configurations are not added
to reciepes automatically.
* Fips Image for reference
* Fix openssl target detection
This was not working properly on an ARM64 build.
* Add symlink in ossl-modules, install provider.conf from main module
* Remove debug for wolfprovider
* Add fix for loading conf in wolfproviderenv
* linuxkm: add non-FIPS kernel module recipe and initramfs integration class
This introduces support for building the wolfSSL Linux kernel module (linuxkm)
in non-FIPS configurations and adds a generic bbclass for including the module
in any initramfs image.
Key additions:
- New recipe: wolfssl-linuxkm.bb (non-FIPS)
* Builds linuxkm against the target kernel
* Installs libwolfssl.ko into /lib/modules/.../extra
* Adds auto-load entry under /etc/modules-load.d/
* Tracks upstream wolfSSL master at commit 3062d1524
- New class: wolfssl-initramfs.bbclass
* Allows any initramfs image to include the linuxkm module
* Intended to be inherited from BSP/distro override layers
This prepares the layer for future FIPS/non-FIPS split support and provides
a clean mechanism for systems that need early-boot availability of the
wolfSSL kernel module.
Signed-off-by: Sameeh Jubran <sameeh@wolfssl.com>
* Add openssl ptest patch
* Fix openssl patch
* linuxkm: update to latest commit to include randomness changes for Tegra kernel
Signed-off-by: Sameeh Jubran <sameeh@wolfssl.com>
* Add wolfssl-kernel-random.bbclass for kernel randomness patches
Bbclass to apply wolfSSL DRBG callback hooks to Linux kernel.
Fetches patches from wolfSSL GitHub, works with any kernel flavor.
Usage in kernel bbappend:
inherit wolfssl-kernel-random
WOLFSSL_KERNEL_RANDOM_PATCH = "5.17-ubuntu-jammy-tegra"
Signed-off-by: Sameeh Jubran <sameeh@wolfssl.com>
* Add curl ptest patch
* Make RD and FIPS detection more robust
* Refactor to handle all cases
* Wrong file location for curl .inc
* - Updated gnutls to point to the 3.8.11 branch to get the 3.8.11 version
of gnutls-wolfssl (https://github.com/wolfSSL/gnutls/tree/gnutls-wolfssl-3.8.11);
- added nettle 3.10 recipe, gnutls depends on nettle to be >= 3.10;
- removed conditional bbappends in favor of the demo image and
recipes-core + inc configuration setup;
* Add fix for wolfProvider curl FIPS
* Add openssh ptest patch for wolfprovider
* Fix location of openSSH patch to point to upstream osp
* linuxkm-fips: add Yocto recipe
Add commercial FIPS LinuxKM recipe.
Signed-off-by: Sameeh Jubran <sameeh@wolfssl.com>
Signed-off-by: Zackery Backman <zackery@wolfssl.com>
* Wolfprovider patch fix and other cleanup
* Add librelp ptest patch for FIPS
* Add support for wolfProvider RD unit test
* Add replace default method for fips image
* Update rev for wolfProvider
* Update wolfProvider ref
* Update ref version for pr 347
* fixing compatability and file layout for .incs porting
* fix pathing for gcrypt patch file
* FIPS-off gnutls recipes + minimal fips-off image.
* Update ref version for cmd test specific commit to pr 347
* fix buggy paths in meta-wolfssl
* Fix issue with missing config script and also add gcs to linuxkm recipe
* Move commercial bundle evaluation outside of recipes and into bbclass
* Cleanup to readmes
* remove the need for the librelp patch
* Update emails to point at support email
* add Gnutls images to the main readme
* Fix typo in example for wolfprovider meta-data and update licensing to point to 2024/correct md5sum
---------
Signed-off-by: Sameeh Jubran <sameeh@wolfssl.com>
Signed-off-by: Zackery Backman <zackery@wolfssl.com>
Co-authored-by: Aidan Garske <aidan@wolfssl.com>
Co-authored-by: Andrew Hutchings <andrew@linuxjedi.co.uk>
Co-authored-by: Reda Chouk <reda@wolfssl.com>
Co-authored-by: Paul Adelsbach <paul.adelsbach@wolfssl.com>
Co-authored-by: Sameeh Jubran <sameeh@wolfssl.com>
Co-authored-by: Andrew Hutchings <andrew@wolfssl.com>
- bind
- socat
- rsyslog
- net-snmp
- libssh2
- strongswan (supports wolfSSL upstream)
- tcpdump
These BitBake files come from some customer work we did making their Yocto image
FIPS-compliant.
Additionally, I've adjusted the OpenSSH 8.5p1 patch to reflect the latest in our
OSP repo.
- Add a wolfssl_%.bbappend for curl.
- Add curl_7.82.0.bbappend.
- Add support for OpenSSH 8.5p1.
- Improve documentation in README.md around building open source projects with
wolfSSL.
- Clean up long lines and other minor things in README.md.
- Add support for Yocto gatesgarth.