Commit Graph

627 Commits (fc511714d37e8052a089e602ddaaf6b8c4af5ce7)

Author SHA1 Message Date
aidan garske ad08b88d6e Add fine-grained PQC build macros to trim v1.85 ML-DSA/ML-KEM by algorithm and operation 2026-06-15 15:49:34 -07:00
David Garske ba6563edac
Merge pull request #520 from aidangarske/pqc-tpm-fixes
Fix PQC minor leak, capability-gate tests, add negative examples, add PQC benchmarks
2026-06-09 15:13:08 -07:00
aidan garske 367aa04bfb examples: propagate test failures, fix handle range check, free PEM buffer 2026-06-09 12:22:03 -07:00
Aidan Garske 557aae6d03 wolfTPM v1.85 PQC: leak fix, capability-gated tests, negative examples, benchmark 2026-06-08 23:08:27 +01:00
David Garske 519e76098a
Merge pull request #518 from aidangarske/fenrir-fixes-14
fwTPM/wolfTPM testing and hardening
2026-06-03 12:42:14 -07:00
aidan garske 61f7fec929 F-5835, F-5100 - Validate firmware data-size bound and NV reserved attribute bits 2026-06-03 10:37:09 -07:00
aidan garske 0f157679f2 F-5653 F-5644 - Bounds-check NV key read and propagate NV load errors 2026-06-03 10:37:08 -07:00
Aidan Garske eb21c17a7a Add fwtpm SPDM support 2026-06-03 10:28:54 -07:00
aidan garske 90866dd3f4 F-4622 — Reject odd-length -digest= argument before hexToByte 2026-05-26 13:41:17 -07:00
aidan garske bcb3f57979 F-4623 — Reject st33_fw_update blob_len > 2048 before XMEMCPY 2026-05-26 12:13:58 -07:00
aidan garske 5477be2125 F-4622 — Pass full hex length to hexToByte in policy.c -digest= 2026-05-26 12:13:37 -07:00
aidan garske fa616ac090 F-4157 — Fix native_test hash check using && instead of || 2026-05-26 12:13:11 -07:00
Tobias Frauenschläger 77e31c0ebb ML-DSA renaming 2026-05-20 13:09:26 -07:00
aidan garske 1e6393938b Fix empty brace scope scan findings 2026-05-14 17:50:08 -07:00
Aidan Garske f30ce7fadc F-3927 - Hoist mid-block declarations in keyimport and seal_nv examples 2026-05-11 21:50:49 -07:00
Aidan Garske 27386cdb3f F-3922 - Use sizeof(auth.buffer) for -auth length check in keygen 2026-05-11 21:50:49 -07:00
Aidan Garske ca93d9281f F-3709 - Zero-init dev in external_import before alloc-fail goto exit 2026-05-11 21:50:26 -07:00
Aidan Garske 3828deed27 F-3711 - Use WOLFSSL_FATAL_ERROR not WOLFSSL_FAILURE in tls_client_notpm 2026-05-11 21:50:26 -07:00
Aidan Garske e4ac3db7a4 F-3709 - Scope NULL guards to heap build in external_import 2026-05-11 21:17:22 -07:00
Aidan Garske 5f6988d794 F-3918 - Use element-count form for pcrArray bounds check 2026-05-11 20:57:55 -07:00
Aidan Garske 31b8121482 F-3930 - Bound check offsets in ifx_fw_extract extractFW 2026-05-11 20:32:54 -07:00
Aidan Garske c13dc57879 F-3927 - Clamp -password length in keyimport example 2026-05-11 20:18:26 -07:00
Aidan Garske 4e16a160f4 F-3926 - Clamp -ownerauth length in seal_nv example 2026-05-11 20:17:56 -07:00
Aidan Garske 069dd33772 F-3922 - Clamp -auth length in keygen example 2026-05-11 20:17:45 -07:00
Aidan Garske 6d90662cfa F-3921 - Restore goto exit on TPM2_ObjectChangeAuth failure in native_test 2026-05-11 20:16:37 -07:00
Aidan Garske 65e0daa9b6 F-3918 - Bounds check pcrArray writes in secret_unseal and policy_sign 2026-05-11 20:13:17 -07:00
Aidan Garske e9d4f583f8 F-3711 - Set rc on cert/key buffer load failure in tls_client_notpm 2026-05-11 20:12:26 -07:00
Aidan Garske 25ccf1c9da F-3710 - Use goto exit on TPM2_LoadExternal failure in make_credential 2026-05-11 20:11:08 -07:00
Aidan Garske fc87b4b752 F-3709 - NULL check wolfTPM2_NewKeyBlob in external_import 2026-05-11 20:09:57 -07:00
David Garske 3bd3f0a8d1 Add capabilities to properly show FIPS 140-3 2026-05-11 11:35:01 -07:00
Aidan Garske d518bffe97 fwTPM v185: final skoll reivew pass 2026-04-29 10:29:51 -07:00
Aidan Garske 960ba43de1 fwTPM v185: CI fixes for non-PQC builds + Tier 5 server lifetime 2026-04-29 10:29:51 -07:00
Aidan Garske 484df3cdf3 fwTPM v185: Skoll review-cycle fixes (TCG + multi-scan) 2026-04-29 10:29:51 -07:00
Aidan Garske 9ce41885e0 fwTPM v185: PR review fixes + TCG/security hardening
Build / portability:
  - Drop #pragma message in fwtpm_crypto.c (MSVC-incompatible)
  - Replace non-ASCII section sign with Sec. across all sources/docs

  Configure:
  - Add --enable-pqc alias for --enable-v185 (same WOLFTPM_V185 macro)
  - Auto-detect: when --enable-fwtpm + wolfCrypt has dilithium.h+mlkem.h
    and neither flag is set, configure auto-enables PQC; --disable-pqc
    opts out
  - Both flags probe the wolfSSL PQC headers and fail at configure time
    with a clear hint when missing

  Spec / security hardening:
  - VerifySequenceComplete now emits TPM_ST_DIGEST_VERIFIED (with hashAlg
    metadata) for Hash-ML-DSA tickets, MESSAGE_VERIFIED for Pure ML-DSA
    (was mis-tagging digests as messages, breaking PolicyTicket consumers)
  - Sign/VerifySequenceComplete: free the slot on TPM_RC_SIGN_CONTEXT_KEY
    too, so wrong-key Complete cannot exhaust FWTPM_MAX_SIGN_SEQ slots
    (CWE-772 DoS)
  - TestParms PQC arms return TPM_RC_PARMS (spec-correct) instead of
    TPM_RC_VALUE; reject MLDSA/MLKEM parameter sets not actually compiled
    in; parse TPMS_MLKEM_PARMS.symmetric via TPM2_Packet_ParseSymmetric
  - GetCapability TPMA_ML_PARAMETER_SETS gates each MLDSA/MLKEM bit on the
    per-set wolfCrypt availability macro (subset builds advertise truth)
  - TPM2_VerifySignature client parser now defensive: only consume the
    v1.85 metaAlg when tag==DIGEST_VERIFIED && hierarchy!=RH_NULL
  - VerifyDigestSignature: hard-fail on keyName overflow instead of
    silently emitting a ticket missing the name binding
  - TPM_GENERATED_VALUE prefix check guarded with rc==0
  - Drop dead (void)cmdSize casts in Sign/VerifySequenceStart
  - wolfTPM2_EncryptSecret_MLKEM: track wc_InitRng_ex/wc_MlKemKey_Init
    success flags so Free is only called on initialized state
  - UBSan-v185 sanitizer cflags: explicitly disable signed-integer-overflow
    and shift checks (matches the comment about wolfSSL Hash_df 440<<24)

  Embedded RAM:
  - FWTPM_NV_PUBAREA_EST derives from FWTPM_MAX_MLDSA_PUB_SIZE /
    FWTPM_MAX_MLKEM_PUB_SIZE auto-shrink macros (subset builds save NV)
  - tpm2_types.h MAX_MLDSA_*/MAX_MLKEM_* stay at worst-case (ABI floor
    for TPM2B wire buffers) with comment

  Tests:
  - Negative test for Hash-MLDSA VerifySeqComplete ticket tag
  - Negative test exposing sign-seq slot leak on TPM_RC_SIGN_CONTEXT_KEY
  - Roundtrip test for wolfTPM2_SignDigest + VerifyDigestSignature

  Documentation:
  - README, FWTPM.md, fwtpm/README.md, examples/pqc/README.md mention
    both --enable-pqc and --enable-v185 + auto-detect
  - README wolfSSL line: --enable-pkcallbacks + WC_RSA_NO_PADDING
  - fwtpm/README.md: drop FWTPM_SPEC_* labels (macros never existed),
    remove v1.85 Additions table (all 8 commands implemented), update
    coverage table to 137/113/24 (82%); note remaining gaps are
    inherited v1.59/v1.84 commands, not PQC
  - fwtpm_nv.h:52: clarify 2592 vs 2720 math (PQC pub key + header slack)
2026-04-29 10:29:51 -07:00
Aidan Garske f568e048bd fwTPM v185: TCG/security review fixes + embedded RAM auto-shrink
Code quality / defensive fixes:
  - TPM2_Encap/Decap: drop bare scope braces, hoist wireSize locals
  - FwCmd_SequenceUpdate: clarify Pure ML-DSA sign accumulation comment
  - FwAllocSignSeq: _Static_assert transient slot range stays valid
  - keygen: drop unused hashMldsaHash local, pass TPM_ALG_SHA256 directly
  - FwCmd_Encapsulate: skip auth area when cmdTag == TPM_ST_SESSIONS
  - writeKeyBlob: restore no-op TPM_RC_SUCCESS in NO_FILESYSTEM build
  - FwCmd_SignDigest restricted-key ticket compare: TPM2_ConstantCompare
  - FwCmd_VerifySequenceComplete: hard-fail if ticket data binding lost
    (no silent fallback that emits a weakened ticket)
  - wolfTPM2_VerifySequenceComplete: validate sigSz before SequenceUpdate
    so BUFFER_E does not leak the TPM-side sequence handle
  - FwCmd_VerifySequenceComplete: heap-allocate ~1KB ticketData via
    FWTPM_DECLARE_BUF / FWTPM_ALLOC_BUF (matches sibling buffers)

  v1.85 capability + scope:
  - GetCapability: report TPM_PT_FIRMWARE_SVN/MAX_SVN = 0
  - Allow Pure ML-DSA streaming via SequenceUpdate per FIPS 204 (SHAKE256
    absorbing is incremental); SignSequenceComplete concatenates msgBuf
    with the trailing complete-time buffer and signs the full message
  - Document v1.85 scope: Encap/Decap is ML-KEM only; Sign/VerifySequence
    and SignDigest/VerifyDigestSignature are ML-DSA / Hash-ML-DSA only
    (classical schemes still go via TPM2_Sign / TPM2_VerifySignature)

  TCG ticket wire-format fixes (security):
  - TPMT_TK_HASHCHECK: SignDigest now validates tag = TPM_ST_HASHCHECK
    unconditionally (TPM_RC_TAG); wolfTPM2_SignDigest wrapper synthesizes
    the NULL Hashcheck instead of sending tag=0/hierarchy=0 from XMEMSET
  - NULL Verified Tickets: FwAppendTicket no longer appends metadata
    bytes when hierarchy == TPM_RH_NULL; client parser conditions
    metaAlg consumption on hierarchy != TPM_RH_NULL (Part 2 §10.6.5)

  Embedded RAM auto-shrink (v1.85):
  - New FWTPM_MAX_MLDSA_{SIG,PUB}_SIZE / FWTPM_MAX_MLKEM_{CT,PUB}_SIZE
    resolve to the largest enabled parameter set via wolfCrypt's
    WOLFSSL_NO_ML_DSA_{44,65,87} / WOLFSSL_NO_KYBER{512,768,1024} gates
  - FWTPM_MAX_DER_SIG_BUF, FWTPM_MAX_PUB_BUF, FWTPM_MAX_KEM_CT_BUF
    derive from those (no per-board override needed)
  - FWTPM_MAX_COMMAND_SIZE / FWTPM_TIS_FIFO_SIZE only lift to 8192 when
    MLDSA-65 or MLDSA-87 is enabled; MLDSA-44-only and MLKEM-only
    v1.85 builds stay at 4096
  - docs/FWTPM.md: per-build size table + override + small-stack notes

  Test coverage:
  - examples/run_examples.sh: invoke pqc/mldsa_sign and pqc/mlkem_encap
    inside the v1.85 block
  - tests/fwtpm_unit_tests.c:
    * SignDigest with malformed HASHCHECK tag rejected (TPM_RC_TAG)
    * FwAppendTicket NULL DIGEST_VERIFIED emits no metadata
    * SignSeqComplete Pure-MLDSA streaming (FIPS 204 §6) — replaces
      obsolete one-shot rejection assertion
  - tests/unit_tests.c:
    * Hash-ML-DSA SignSeqUpdate streaming end-to-end + arg validation
    * TPMT_SIGNATURE round-trip for ML-DSA / Hash-ML-DSA arms
    * TPM2B_PUBLIC round-trip for ML-DSA / Hash-ML-DSA / ML-KEM arms
2026-04-29 10:28:44 -07:00
Aidan Garske 3f7db58943 fix keyload ecc 159 in CI: writeKeyBlob silent write failure 2026-04-29 10:28:44 -07:00
Aidan Garske 8a9be3edff fwTPM v185: MSan-detected uninit reads (4 real bugs) + CI debug 2026-04-29 10:28:44 -07:00
Aidan Garske abe08f56cf fwTPM v1.85: CI fixes + MSan uninit-read in FwCmd_Create
Fixes 5 v1.85 PR CI/build issues:

  1. src/tpm2_wrap.c: add #include <wolfssl/wolfcrypt/mlkem.h> inside the
     v185 MLKEM guard. Builds with --disable-fwtpm against wolfSSL with
     --enable-mlkem failed because the MLKEM symbol declarations were
     only pulled in transitively by src/fwtpm/fwtpm_crypto.c.

  2. src/fwtpm/fwtpm_command.c: switch FWTPM_ALLOC_BUF(privKeyDer) to
     FWTPM_CALLOC_BUF in 4 sites (Create, Load, LoadExternal, Import,
     CreateLoaded). MSan-v185 flagged uninit-value reads in SocketSend
     originating from FwCmd_Create's keyedHash branch — when caller
     supplies undersized inSensitive material, FwComputeUniqueHash hashed
     beyond what was written. Zero-initialising the buffer eliminates the
     class of issue.

  3. examples/keygen/keygen.c: pass allowExternalMu=NO for MLDSA. The
     v1.85 EXT_MU enforcement now correctly rejects allowExternalMu=YES
     at object creation per Part 2 §12.2.3.6.

  4. .github/workflows/make-test-swtpm.yml: convert v185-pqc-swtpm lane
     to build-only. swtpm has no v1.85 PQC, so unit.test PQC blocks fail
     on TPM_RC_SIZE; runtime PQC coverage stays in the fwtpm-v185 lane.

  5. .github/workflows/sanitizer.yml: UBSan-v185 now uses the same
     sanitizer flags as the classical UBSan lane (drops ).
     Pre-existing wolfSSL UB at misc.c:117 (440<<24 in Hash_df) only
     surfaces under -fsanitize=integer.
2026-04-29 10:28:44 -07:00
Aidan Garske d9143e3084 fwTPM v1.85: TCG + Skoll review fixes (round 2)
Closes 13 findings across two reviews of the v1.85 PQC paths.

   Tickets (TPMT_TK_VERIFIED / TPMT_TK_HASHCHECK / TPMT_TK_CREATION):
   - FwAppendTicket binds tag (always) and metadata (DIGEST_VERIFIED only)
     into the HMAC per Part 2 §10.6.5 Eq (5). Streamed via chunked
     wc_HmacUpdate, no temp buffer. All 5 callers updated; the hand-rolled
     VerifyDigestSignature path collapses into FwAppendTicket.
   - FWTPM_Object gains a hierarchy field, captured at every load/create
     site (CreatePrimary, Load, LoadExternal, CreateLoaded). Replaces
     hardcoded TPM_RH_OWNER in VerifySignature, VerifySequenceComplete,
     VerifyDigestSignature, ContextSave, and Create's creation ticket.
   - VerifySequenceComplete snapshots the verified digest before
     wc_HashFinal so Hash-ML-DSA tickets bind (digest || keyName) rather
     than just keyName — pre-fix, two distinct verified digests on the
     same key produced byte-identical tickets (universal reuse).

   Authorization:
   - Sign/VerifySequenceStart split TPM_RC_KEY (non-signing key, e.g.
     ML-KEM) from TPM_RC_SCHEME (signing key, scheme unsupported) using
     TPMA_OBJECT_sign per Part 3 §17.5.1 / §17.6.1.
   - SignDigest restricted-key path validates TPMT_TK_HASHCHECK HMAC
     per Part 3 §20.7.1 instead of blanket-rejecting; x509sign keeps
     the TPM_RC_ATTRIBUTES short-circuit.
   - Decapsulate, SignDigest, SignSequenceComplete reject NO_SESSIONS
     with TPM_RC_AUTH_MISSING (Auth Role: USER, Tables 62/124/126).

   Restricted-key TPM_GENERATED_VALUE check:
   - FWTPM_SignSeq.firstBytes[4] populated by SequenceUpdate covers the
     Hash-ML-DSA path where bytes are otherwise consumed by hashCtx;
     topped-up from the Complete trailing buffer for Pure-MLDSA one-shot.
     Closes the Update-then-empty-Complete bypass.

   Client-side (src/tpm2.c):
   - TPM2_VerifySequenceComplete defensively dispatches on validation.tag
     for TPMU_TK_VERIFIED_META, mirroring TPM2_VerifyDigestSignature.

   Other:
   - TPM2_Packet_AppendSensitive caps mldsa/mlkem .size to buffer length.
   - pqc_mssim_e2e.c zeroizes ss1/ss2 on cleanup.
   - Untrack examples/pqc/pqc_mssim_e2e (libtool wrapper with hardcoded
     /home/aidangarske path; .gitignore already covered it).
   - #pragma message at WOLFTPM_V185 build-time flagging that the PQC
     primary-key KDFa labels are interpretation pending TCG Part 4 v1.85;
     suppressible via -DWOLFTPM_V185_LABELS_ACK.

   Tests: 11 new fixtures in tests/fwtpm_unit_tests.c, 4 existing tests
   updated to assert new spec-mandated RCs. fwtpm_unit.test reports 105
   passing, zero failures.
2026-04-29 10:28:44 -07:00
Aidan Garske 1b909655bf Add Sign + verify examples 2026-04-29 10:28:44 -07:00
Aidan Garske 8311223bee docs: add v1.85 PQC build + usage section to main README and examples
Main README:
   - New ## Post-Quantum Cryptography (v1.85) section between fwTPM and
     TPM 2.0 Overview. Covers supported algorithms (ML-DSA-44/65/87,
     Hash-ML-DSA, ML-KEM-512/768/1024), exact wolfSSL + wolfTPM build
     config (--enable-dilithium --enable-mlkem --enable-experimental ...
     for wolfSSL; --enable-fwtpm --enable-v185 for wolfTPM), and a
     make check pointer.
   - Existing feature-list bullet at line 41 now points to the new
     section instead of directly to docs/FWTPM.md.

   examples/pqc/README.md:
   - Rewrite around three audience splits: (1) build steps, (2) run
     everything with make check, (3) per-example details.
   - New sections for mlkem_encap and the -mldsa/-hash_mldsa/-mlkem
     options on examples/keygen/keygen.
   - Drop stale --enable-swtpm reference (wrong flag; caused reviewer
     confusion).
   - Point users at the existing tests/fwtpm_check.sh and
     tests/pqc_mssim_e2e.sh for targeted reruns without the full classical
     suite.

   Documentation split (no duplication):
   - Top-level README - build + I just want to run it
   - examples/pqc/README.md per-example usage
   - docs/FWTPM.md#tpm-20-v185-post-quantum-support -> server internals
     (commands, primary-key derivation, buffer constants, spec
     interpretation decisions)
2026-04-29 10:28:44 -07:00
Aidan Garske 4491c20caa Add PQC options to examples/keygen + ML-KEM encap example
examples/keygen/keygen:
  - New -mldsa[=44|65|87], -hash_mldsa[=44|65|87], -mlkem[=512|768|1024]
    options alongside existing -rsa/-ecc/-sym/-keyedhash. Dispatches to
    wolfTPM2_GetKeyTemplate_{MLDSA,HASH_MLDSA,MLKEM}, then CreateKey under
    the SRK parent. AIK template path correctly rejects PQC (AIKs are
    RSA/ECC only per TCG).
  - Param-set parser defaults: MLDSA-65, MLKEM-768, SHA-256 pre-hash for
    Hash-ML-DSA.

  examples/pqc/mlkem_encap (new):
  - CreatePrimary MLKEM (512/768/1024) then Encapsulate + Decapsulate,
    asserting the two shared secrets match byte-for-byte. Companion to
    pqc_mssim_e2e but focused on the KEM wrappers alone.

  examples/run_examples.sh:
  - Detects WOLFTPM_V185 from config.h, runs keygen+keyload round-trip
    for all 9 PQC variants (same pattern used by RSA/ECC blocks above).
    All 9 pass against fwtpm_server.
2026-04-29 10:27:50 -07:00
Aidan Garske 4ead816713 fwTPM PQC: finish v1.85 protocol wiring for Sign/Verify over mssim
Server-side handler fixes:
   - FwCmd_SignSequenceStart / VerifySequenceStart: call FwSkipAuthArea when
     cmdTag == TPM_ST_SESSIONS. Without it, the 4-byte authAreaSize prefix
     was mis-parsed as the auth / context TPM2B size fields, producing
     mis-aligned context bytes (ctxSz=9 on sign, 0 on verify) so the μ fed
     into FIPS 204 differed between the two handlers — verify always failed.
   - FwCmd_SignSequenceStart / VerifySequenceStart: emit the output
     sequenceHandle before FwRspParamsBegin, matching TPM 2.0 response
     framing (handles precede the SESSIONS paramSize).
   - FwCmd_CreatePrimary: add MLDSA / HASH_MLDSA / MLKEM arms to the
     hashUnique switch so the unique template actually binds into KDFa
     derivation.
   - FwCmd_TestParms: accept PQC algs (MLKEM / MLDSA / HASH_MLDSA).

   Client-side wrapper fixes:
   - wolfTPM2_CopyPubT: add MLDSA / HASH_MLDSA / MLKEM cases. Previous
     switch fell through, leaving unique.mlkem / .mldsa as zero-filled
     buffers after a successful CreatePrimary (Jay's reported bug).
   - GetKeyTemplateSize: add PQC parameter-set-aware sizes.
   - wolfTPM2_SetKeyTemplate_Unique: add PQC arms.
   - TPM2_SignSequenceComplete: add CMD_FLAG_AUTH_USER2 (Table 124 requires
     USER auth on both @seq and @key handles).
   - TPM2_VerifySequenceComplete: remove extra buffer field (Table 118 has
     no buffer parameter); add CMD_FLAG_AUTH_USER1.

   examples/pqc/pqc_mssim_e2e.c: tighten validation — check_pub_populated
   catches CopyPubT-class regressions, MLKEM-768 Encap/Decap secrets must
   match, HashMLDSA-65 SignDigest emits a DIGEST_VERIFIED ticket.
2026-04-29 10:27:50 -07:00
Aidan Garske 552032d357 fwTPM PQC: mssim E2E test + output formatting
Cross-process PQC validation: new examples/pqc/pqc_mssim_e2e exercises
  wolfTPM2_* client wrappers against a running fwtpm_server over the
  mssim (SWTPM) socket transport. Two round-trips in one binary:

  - MLKEM-768 Encap/Decap: asserts ciphertext = 1088 bytes and the two
    derived shared secrets are byte-identical.
  - HashMLDSA-65 SignDigest/Verify: asserts signature = 3309 bytes and
    the validation ticket carries TPM_ST_DIGEST_VERIFIED.

  tests/pqc_mssim_e2e.sh spawns fwtpm_server, waits for TCP readiness,
  runs the client, and cleans up. Proves client marshaling + mssim
  framing + fwtpm_server unmarshaling + PQC handler dispatch agree over
  a real socket between two separately-compiled processes — orthogonal
  to the in-process fwtpm_unit.test suite.

  Infrastructure:
  - configure.ac: new AM_CONDITIONAL BUILD_V185 so the example only
    builds when --enable-v185 is passed (matches the pattern of
    BUILD_SWTPM, BUILD_DEVTPM, etc.).
  - examples/include.am, examples/pqc/include.am: register the example.

  Output polish: replaced 85 inconsistent calls with a
  fwtpm_pass(name, is_pqc) helper that produces aligned
  columns. PQC tests are tagged [PQC] so they're visually distinct
  from the classical suite at a glance. All 86 existing tests still pass.
2026-04-29 10:27:50 -07:00
Aidan e2d1c344ad F-3507 - https://fenrir.wolfssl.com/finding/3507 - examples/attestation/activate_credential: zero-init tpmSession so early-failure cleanup is safe 2026-04-28 10:58:56 -07:00
Aidan 5e50cff6f5 F-3506 - https://fenrir.wolfssl.com/finding/3506 - examples/keygen/keyload: guard primary unload against NULL on early init failure 2026-04-28 10:42:57 -07:00
Aidan d2dc2f726d F-3505 - https://fenrir.wolfssl.com/finding/3505 - examples/attestation/activate_credential: guard primary unload against NULL on early init failure 2026-04-28 10:40:39 -07:00
Aidan e7202aac6c F-3495 - https://fenrir.wolfssl.com/finding/3495 - examples/keygen: guard primary unload against NULL on early init failure 2026-04-28 10:05:48 -07:00
Aidan 1c2c809751 F-3494 - https://fenrir.wolfssl.com/finding/3494 - examples/pkcs7: reset offset and fix loop continuation so detached PKCS7 body actually gets written 2026-04-28 09:14:43 -07:00
Aidan 4437bef244 F-3493 - https://fenrir.wolfssl.com/finding/3493 - examples/management/flush: fix copy-paste so HMAC sessions loop walks 0x02000000-0x02000003 2026-04-28 09:10:08 -07:00