Commit Graph

1875 Commits (master)

Author SHA1 Message Date
Aidan Garske 7d9ed2c72e
Merge pull request #631 from padelsbach/freebsd-version-tolerance
Address nightly failure in BSD kernel workflow
2026-09-17 15:11:52 -07:00
Paul Adelsbach 82a19ba9b1 Address nightly failure in BSD kernel workflow 2026-09-17 10:32:07 -07:00
Aidan Garske fff9e1eac8
Merge pull request #629 from padelsbach/cert-regen-2026
Update certs to fix failing nightly
2026-09-16 09:42:05 -07:00
Paul Adelsbach 6ff9c5e966 Update certs to fix failing nightly 2026-09-14 14:25:28 -07:00
Aidan Garske e691776d7f
Merge pull request #627 from dgarske/efr32xg25_cryptocb
EFR32xG25 Secure Element example
2026-09-11 09:10:55 -07:00
Aidan Garske dfc84f3d13
Merge pull request #623 from dgarske/puf_interactive_uart
puf: fix transmit-only UART HAL and add an interactive INTERACTIVE=1 demo mode
2026-09-10 16:22:44 -07:00
David Garske 269816454e EFR32xG25 Secure Element example for wolfSSL PR 11267: wolfCrypt test, benchmark and TLS 1.3 2026-09-10 16:11:49 -07:00
David Garske ef8181959e puf: fix transmit-only UART HAL and add an interactive INTERACTIVE=1 demo mode 2026-09-10 08:49:58 -07:00
Sean Parkinson d421168ad8
Merge pull request #617 from dgarske/c2000_hw_aes
C2000 example: HWAES, entropy and probe
2026-09-07 20:43:52 +10:00
David Garske 7acd6b5c53 TI C2000 example: do not compile the ML-DSA-87 verify KAT into SECUREBOOT builds 2026-09-04 08:34:32 -07:00
David Garske 9046a9548f TI C2000: add PRECOMPA build using a flash-resident ML-DSA-87 matrix A 2026-09-02 14:34:30 -07:00
David Garske fd1f216859 TI C2000 example: SECUREBOOT=1 pure-mode ML-DSA verify of a packed image streamed from flash 2026-09-02 14:34:30 -07:00
David Garske 1238312e9c TI C2000 example: add FASTVERIFY=1 to trade RAM for ML-DSA verify speed 2026-09-02 14:34:30 -07:00
David Garske def00ad02d TI C2000 example: init the software AES context, honour ENTROPY_NUM_SRC, report per-window raw entropy 2026-09-02 14:34:30 -07:00
David Garske 104cab75a0 TI C2000 example: MLDSA=1 octet-boundary KATs for ML-DSA-44/65/87, pre-hash and packed input 2026-08-31 16:59:53 -07:00
Andrew Hutchings 05daee9e89
Merge pull request #618 from dgarske/optee_pkcs11
Add PKCS11 OP-TEE token support with a PKCS#11 token initialization example
2026-08-21 13:30:46 +01:00
David Garske 28a6f5b8b1 pkcs11: link -ldl for the token init example and only take a numeric slot arg 2026-08-21 05:25:59 -07:00
philljj 219ba675be
Merge pull request #616 from SparkiDev/pkcs11_test_c_fix
pkcs11_test.c: fix uninitialized
2026-08-20 16:29:42 -05:00
David Garske a4c09c7f40 TI C2000 example: real entropy source, probe image and validation KATs 2026-08-19 12:30:34 -07:00
David Garske 8fca85fa57 TI C2000 example: HWAES=1 AESA offload with HW-vs-SW cross-KATs 2026-08-19 12:30:34 -07:00
David Garske 803d9c8226 pkcs11: add OP-TEE token support with a token initialization example 2026-08-18 15:50:47 -07:00
Sean Parkinson 289b290a9b pkcs11_test.c: fix uninitialized
Some compilers believe that modSz and expSz may be uninitialized at use.
Initialize to 0 to stop warnings.
2026-08-17 16:01:06 +10:00
philljj cb4a3cb976
Merge pull request #612 from dgarske/aes_plain
rtl8735b: add plaintext-key AES-GCM device test alongside HUK, selected by devId
2026-08-14 14:16:30 -05:00
philljj c8e71603ae
Merge pull request #576 from dgarske/ti_c25
Add TI LAUNCHXL-F28P55X (C2000 C28x) bare-metal wolfCrypt example
2026-08-10 16:47:13 -05:00
David Garske 6f9c0fb19d Add TI LAUNCHXL-F28P55X (C2000 C28x, CHAR_BIT==16) bare-metal wolfCrypt example 2026-08-10 09:11:21 -07:00
David Garske 5301d436cd
Merge pull request #610 from aidankeefe2022/algo_examples
Algo examples
2026-08-08 10:58:43 -07:00
Aidan Keefe f5c6e02ba6 new injection mechanic in CI/CD and github review fixes 2026-08-07 19:14:40 -06:00
David Garske 31bc616dc8 Peer review fixes 2026-07-30 14:55:38 -07:00
Aidan Keefe 5c56a1ce91 removed useless sig corruption 2026-07-30 10:52:54 -06:00
David Garske 27f686821b rtl8735b: add plaintext-key AES-GCM device test alongside HUK, selected by devId 2026-07-30 09:09:06 -07:00
David Garske 1bd90e0738
Merge pull request #611 from aidangarske/nightly-latest-stable-only
Test only master and the latest stable tag in the nightly
2026-07-29 13:30:05 -07:00
Aidan Garske 4cce69703f Test only master and the latest stable tag in the nightly 2026-07-29 13:08:03 -07:00
Aidan Keefe 213cb5646f revised slh_dsa 2026-07-29 13:00:17 -06:00
Aidan Keefe 5626aa3a0b Mikey-sakke format fix 2026-07-29 13:00:17 -06:00
Aidan Keefe 23c020e186 sm2-ecdh revised 2026-07-29 13:00:17 -06:00
Aidan Keefe 6715f35753 hpke_context revised 2026-07-29 13:00:17 -06:00
Aidan Keefe edac0694db srp_sha256 revised 2026-07-29 13:00:17 -06:00
Aidan Keefe a6933bdb24 Mikey-Sakke example revised 2026-07-29 13:00:17 -06:00
Anthony fa32abf948 Register new algorithm examples in CI manifest
Add check entries for slh_dsa, blake2, siphash, kdf and mikey-sakke;
extend the crypto, pq and pk profiles with their configure flags.
crypto/sm is a documented skip: it needs the wolfsm overlay patched
into the wolfSSL tree before configure.
2026-07-29 13:40:02 -04:00
Anthony 0aeba02dce Add MIKEY-SAKKE (ECCSI + SAKKE) example
Identity-based key exchange per RFC 6507-6509: KMS provisions user key
material, ECCSI signs the SAKKE-encapsulated SSV, receiver verifies
and derives the shared secret.
2026-07-29 13:39:43 -04:00
Anthony 6398f4552f Add SRP-6a SHA-256 example
Full exchange (enrollment through mutual proof verification) using
SHA-256 and the RFC 5054 2048-bit group.
2026-07-29 13:39:36 -04:00
Anthony 96fb285077 Add HPKE seal/open context example
One KEM encapsulation protecting an ordered message sequence via
wc_HpkeInitSealContext()/wc_HpkeContextSealBase() and the open
equivalents, with out-of-order rejection.
2026-07-29 13:39:21 -04:00
Anthony f09fb7378f Add KDF examples
HKDF (RFC 5869), PBKDF2 (RFC 2898) and scrypt (RFC 7914), each
verified against its RFC known-answer test vector.
2026-07-29 13:39:15 -04:00
Anthony 9f751293e3 Add SipHash example
SipHash-2-4 one-shot 64/128-bit MACs and the incremental API, checked
against the reference implementation's test vector.
2026-07-29 13:39:03 -04:00
Anthony 73dde4a277 Add BLAKE2b/BLAKE2s examples
Incremental hashing checked against the RFC 7693 known-answer vectors,
plus BLAKE2b's native keyed mode used as a MAC.
2026-07-29 13:38:44 -04:00
Anthony eba0390017 Add SM2/SM3/SM4 examples
wolfCrypt-level ShangMi examples: SM3 hash (GB/T 32905 known answer),
SM4-GCM with tamper detection, SM2 sign/verify including the ZA digest
step, and SM2 ECDH. Requires the wolfSSL/wolfsm overlay.
2026-07-29 13:38:24 -04:00
Anthony dbf6e9ad49 Add SLH-DSA (FIPS 205) example
Key generation, signing and verification for all SHAKE and SHA2
parameter sets, with corrupted-signature rejection.
2026-07-29 13:38:02 -04:00
Aidan Garske b41d12c0b8
Add CI that builds and runs every example (#598)
* Regenerate the CRL that expired in September 2025

* Refresh the expired certificates embedded in certloadverifybuffer

* Return 0 from tls servers that returned a wolfSSL_write byte count

* Send a client certificate from client-tls and client-tls13-resume

* Return 0 from certverify instead of WOLFSSL_SUCCESS

* Give the XTS demo key two different halves

* Exit success after ml_dsa prints its parameter table

* Report failure from the custom io file client and server

* Latch failures across every ecc-params curve lookup

* Ignore SIGPIPE in the btle fifo transport

* Fix the dtls rw-threads certificate paths

* Make runall.sh fail when an example fails

* Make openssl-verify.sh actually verify and actually fail

* Raise the generate_ssl.sh common name length limit

* Port the PQ examples to the current wolfSSL API

* Return 0 from csr_w_ed25519_example and rsa-public-decrypt-app

* Build the x509_acert openssl example against the right headers

* Give the examples Makefiles a consistent wolfSSL prefix

* Fix the double free and NULL derefs in the custom io cleanup paths

* Stop forcing the ESP32 examples to include a developer private config

* Add the missing WiFi Kconfig to the DTLS13 station examples

* Use XSTRLCPY in client-dtls13 since wolfSSL has no XSTRCPY

* Make the DTLS13 example ctx static so it stops colliding with libnet80211

* Set SO_REUSEADDR on the tls servers that lacked it

* Give puf the wolfSSL sources and stop building the IDF 4.4 only ENC28J60 examples

* Set SO_REUSEADDR on server-tcp as well

* Exit the can-bus client on EOF and give it real input in CI

* Re-arm the select timeout each pass in the nonblocking dtls server

* Keep the shared memory BIOs alive until both sides are done

* Port the ebpf tracers to the libbpf 1.0 perf_buffer__new signature

* Clone wolfSSL before make builds its graph so uefi-static builds from a clean tree

* Raise wolfcryptjni compileSdk to 32 for the BigInteger API its submodule uses

* Link wolfentropy.o and keep wc_port socket helpers out of the UEFI build

* Track the wolfSSL dilithium.c to wc_mldsa.c rename and drop a stale java import

* Move uefi-library to the wc_MlDsa API after the wolfSSL dilithium rename

* Declare the launcher activity exported, required from API 31

* Configure wolfSSL before make in the fullstack setup script

* Track the wolfSSL io.c to wolfio.c rename in the ndk sample

* Keep glibc headers out of the freestanding uefi-library build

* Track the wolfSSL mlkem.h rename and give RT1060 the SDK name it selects on

* Track the wolfIP struct ll rename and pin wolfIP to its v1.0 release

* Use getaddrinfo in the ndk sample since bionic does not declare gethostbyname

* Cross compile RT1060 with arm-none-eabi and document the SDK value the Makefile matches

* Enable wolfIP HTTP so its httpd.h actually declares the API the example calls

* Define HAVE_NETDB_H so wolfio.c includes the header its getaddrinfo path needs

* Link pkcs12.o, which RT1060 enables by default and wolfcrypt test calls

* Port the ENC28J60 examples to the ESP-IDF 5.x ethernet API

* Compile dtls.c in the ndk sample, which enables WOLFSSL_DTLS

* Define the PHY identifier registers the removed IDF header supplied

* Compile kdf.c in the ndk sample for the TLS PRF

* Give RT1060 a current_time so the benchmark stops needing clock_gettime

* Port the ENC28J60 PHY to the IDF 5.x autonego_ctrl vtable

* Remove the ENC28J60 server's duplicate driver copy that main already builds

* Return the DTLS server to accept on close_notify so a resume is heard

* Run the C# pq client/server pair under mono

* Define WOLFSSL_CERT_REQ so the ndk-gradle app links wolfssljni's X509_REQ calls

* Refresh the expired client ECC DER certificate

* Add CI that builds and runs every example against wolfSSL master and stable

* Sign OCSP staples with a responder intermediate1 actually delegated

* Report a failing PKCS#11 example instead of always exiting 0

* Link the PSA library the README's PSA_LIB_PATH names

* Widen the mynewt pointer prints so they build on a 64 bit native BSP

* Test RSA under UEFI with a 2048 bit key so it clears wolfSSL's minimum

* Left pad the ECDSA r and s so a leading zero cannot shift the signature

* Document the smime and indef flags the pkcs7 examples need

* Fail ecc-verify when the signature does not verify

* Fail ecc-sign when a round produces an invalid signature

* Fail aesgcm-file-encrypt when its sanity test does not pass

* Check that ML-KEM derives the same shared secret on both sides

* Fail ecdh_gen_secret when the two sides derive different secrets

* Return the DH key agreement error instead of always exiting 0

* Retry the fullstack HTTPS probe so a slow sim start does not fail it

* Confirm the custom-io file transfer succeeded so CI can assert it

* Print a success line from the silent file-encrypt and ecc-export examples

* Add device-sims job running ATECC608 STSAFE and TROPIC01 sim wolfcrypt tests

* Extend device-sims to STM32 and PIC32MZ for the full sim fleet

* Mount wolfSSL for the STM32 and PIC32MZ sim wolfcrypt runs

* Accept the zero success return from wolfSSL_CTX_set_max_early_data

* Read the earlydata reply so the client processes the session ticket before resuming

* Read the earlydata reply in the DTLS client so it processes the session ticket

* Run the tls13 and dtls13 earlydata pairs now that the clients process the ticket

* Let expect_fail clear on refs that carry the fix via a fixed_on marker

* Retry the PSA TLS 1.3 handshake so an intermittent ECC reject does not fail CI

* Retry network fetches across CI so a transient blip does not fail a job

* Normalize do_ecc and do_25519 exit codes like do_448 so an error is never masked to 0

* Build and run the merged-in hsm dtls_client example in CI via a dedicated hsm.yml job

* Add a make check target to each applicable example

* Run only the example and lint smoke set on draft PRs

* Only run a per-target workflow when its own example dir changes

* Assert the real se050 wolfcrypt result instead of an early sub-test line

* Size the RSA 2048 key export buffers so the UEFI test does not fail on BUFFER_E

* Call the always-present MLDSA context API from the UEFI driver

* Cross uefi-static and uefi-library with both wolfSSL refs in the matrix

* Give each tpm matrix leg a ref-unique results file and artifact

* Add a codespell spellcheck pass to the lint job

* Run push CI on master only so a PR branch does not double-trigger

* Select valgrind by caller_run_id since event_name is the caller under workflow_call

* Make example check targets catch real failures with pipefail exit checks and inputs

* Wire the harness to run make check for mode check examples starting with ecc

* Migrate the single-entry exec examples to mode check and fold their inputs into the check targets

* Fix four make check assertions that misfired under pipefail

* Give the tpm manifest entry a run step so it asserts output

* Skip uefi-static in the lint make -n loop so it does not clone

* Assert the actual verify result in the pkcs7 and rsa-nb checks

* Return nonzero from pkcs12-create-example on a failed create so the check is not a false pass

* Return nonzero from rsa-kg on any key generate or write failure

* Assert the static memory checks by exit code instead of a pipefail grep that BSD make lacks

* Run pkcs7 signedData stream through make check so it asserts the real verify result

* Check DER certificates and CRLs in the expiry canary too

* Feed the wolfHSM client its stdin so run_client actually exchanges data

* Assert every make check by exit code and captured output instead of a pipefail grep so they hold under BSD make
2026-07-23 10:07:06 -06:00
Marco Oliverio c586428531
wolfHSM: add DTLS client example that uses HSM as cryptographic back end (#555)
* wolfHSM: add DTLS client that uses HSM as cryptographic backend

* address reviewer's comment

* dtls client improvements
2026-07-22 08:37:34 -06:00
Emma Stensland dc6a012c30
Merge pull request #606 from padelsbach/fix-ecc-verify
Minor fixes in ecc-verify example
2026-07-21 16:37:18 -06:00