Commit Graph

51 Commits (ef8181959e9312bc05ce59f07598a6e8be43aed1)

Author SHA1 Message Date
Aidan Keefe f5c6e02ba6 new injection mechanic in CI/CD and github review fixes 2026-08-07 19:14:40 -06:00
Aidan Keefe 5c56a1ce91 removed useless sig corruption 2026-07-30 10:52:54 -06:00
Aidan Keefe 213cb5646f revised slh_dsa 2026-07-29 13:00:17 -06:00
Anthony dbf6e9ad49 Add SLH-DSA (FIPS 205) example
Key generation, signing and verification for all SHAKE and SHA2
parameter sets, with corrupted-signature rejection.
2026-07-29 13:38:02 -04:00
Aidan Garske b41d12c0b8
Add CI that builds and runs every example (#598)
* Regenerate the CRL that expired in September 2025

* Refresh the expired certificates embedded in certloadverifybuffer

* Return 0 from tls servers that returned a wolfSSL_write byte count

* Send a client certificate from client-tls and client-tls13-resume

* Return 0 from certverify instead of WOLFSSL_SUCCESS

* Give the XTS demo key two different halves

* Exit success after ml_dsa prints its parameter table

* Report failure from the custom io file client and server

* Latch failures across every ecc-params curve lookup

* Ignore SIGPIPE in the btle fifo transport

* Fix the dtls rw-threads certificate paths

* Make runall.sh fail when an example fails

* Make openssl-verify.sh actually verify and actually fail

* Raise the generate_ssl.sh common name length limit

* Port the PQ examples to the current wolfSSL API

* Return 0 from csr_w_ed25519_example and rsa-public-decrypt-app

* Build the x509_acert openssl example against the right headers

* Give the examples Makefiles a consistent wolfSSL prefix

* Fix the double free and NULL derefs in the custom io cleanup paths

* Stop forcing the ESP32 examples to include a developer private config

* Add the missing WiFi Kconfig to the DTLS13 station examples

* Use XSTRLCPY in client-dtls13 since wolfSSL has no XSTRCPY

* Make the DTLS13 example ctx static so it stops colliding with libnet80211

* Set SO_REUSEADDR on the tls servers that lacked it

* Give puf the wolfSSL sources and stop building the IDF 4.4 only ENC28J60 examples

* Set SO_REUSEADDR on server-tcp as well

* Exit the can-bus client on EOF and give it real input in CI

* Re-arm the select timeout each pass in the nonblocking dtls server

* Keep the shared memory BIOs alive until both sides are done

* Port the ebpf tracers to the libbpf 1.0 perf_buffer__new signature

* Clone wolfSSL before make builds its graph so uefi-static builds from a clean tree

* Raise wolfcryptjni compileSdk to 32 for the BigInteger API its submodule uses

* Link wolfentropy.o and keep wc_port socket helpers out of the UEFI build

* Track the wolfSSL dilithium.c to wc_mldsa.c rename and drop a stale java import

* Move uefi-library to the wc_MlDsa API after the wolfSSL dilithium rename

* Declare the launcher activity exported, required from API 31

* Configure wolfSSL before make in the fullstack setup script

* Track the wolfSSL io.c to wolfio.c rename in the ndk sample

* Keep glibc headers out of the freestanding uefi-library build

* Track the wolfSSL mlkem.h rename and give RT1060 the SDK name it selects on

* Track the wolfIP struct ll rename and pin wolfIP to its v1.0 release

* Use getaddrinfo in the ndk sample since bionic does not declare gethostbyname

* Cross compile RT1060 with arm-none-eabi and document the SDK value the Makefile matches

* Enable wolfIP HTTP so its httpd.h actually declares the API the example calls

* Define HAVE_NETDB_H so wolfio.c includes the header its getaddrinfo path needs

* Link pkcs12.o, which RT1060 enables by default and wolfcrypt test calls

* Port the ENC28J60 examples to the ESP-IDF 5.x ethernet API

* Compile dtls.c in the ndk sample, which enables WOLFSSL_DTLS

* Define the PHY identifier registers the removed IDF header supplied

* Compile kdf.c in the ndk sample for the TLS PRF

* Give RT1060 a current_time so the benchmark stops needing clock_gettime

* Port the ENC28J60 PHY to the IDF 5.x autonego_ctrl vtable

* Remove the ENC28J60 server's duplicate driver copy that main already builds

* Return the DTLS server to accept on close_notify so a resume is heard

* Run the C# pq client/server pair under mono

* Define WOLFSSL_CERT_REQ so the ndk-gradle app links wolfssljni's X509_REQ calls

* Refresh the expired client ECC DER certificate

* Add CI that builds and runs every example against wolfSSL master and stable

* Sign OCSP staples with a responder intermediate1 actually delegated

* Report a failing PKCS#11 example instead of always exiting 0

* Link the PSA library the README's PSA_LIB_PATH names

* Widen the mynewt pointer prints so they build on a 64 bit native BSP

* Test RSA under UEFI with a 2048 bit key so it clears wolfSSL's minimum

* Left pad the ECDSA r and s so a leading zero cannot shift the signature

* Document the smime and indef flags the pkcs7 examples need

* Fail ecc-verify when the signature does not verify

* Fail ecc-sign when a round produces an invalid signature

* Fail aesgcm-file-encrypt when its sanity test does not pass

* Check that ML-KEM derives the same shared secret on both sides

* Fail ecdh_gen_secret when the two sides derive different secrets

* Return the DH key agreement error instead of always exiting 0

* Retry the fullstack HTTPS probe so a slow sim start does not fail it

* Confirm the custom-io file transfer succeeded so CI can assert it

* Print a success line from the silent file-encrypt and ecc-export examples

* Add device-sims job running ATECC608 STSAFE and TROPIC01 sim wolfcrypt tests

* Extend device-sims to STM32 and PIC32MZ for the full sim fleet

* Mount wolfSSL for the STM32 and PIC32MZ sim wolfcrypt runs

* Accept the zero success return from wolfSSL_CTX_set_max_early_data

* Read the earlydata reply so the client processes the session ticket before resuming

* Read the earlydata reply in the DTLS client so it processes the session ticket

* Run the tls13 and dtls13 earlydata pairs now that the clients process the ticket

* Let expect_fail clear on refs that carry the fix via a fixed_on marker

* Retry the PSA TLS 1.3 handshake so an intermittent ECC reject does not fail CI

* Retry network fetches across CI so a transient blip does not fail a job

* Normalize do_ecc and do_25519 exit codes like do_448 so an error is never masked to 0

* Build and run the merged-in hsm dtls_client example in CI via a dedicated hsm.yml job

* Add a make check target to each applicable example

* Run only the example and lint smoke set on draft PRs

* Only run a per-target workflow when its own example dir changes

* Assert the real se050 wolfcrypt result instead of an early sub-test line

* Size the RSA 2048 key export buffers so the UEFI test does not fail on BUFFER_E

* Call the always-present MLDSA context API from the UEFI driver

* Cross uefi-static and uefi-library with both wolfSSL refs in the matrix

* Give each tpm matrix leg a ref-unique results file and artifact

* Add a codespell spellcheck pass to the lint job

* Run push CI on master only so a PR branch does not double-trigger

* Select valgrind by caller_run_id since event_name is the caller under workflow_call

* Make example check targets catch real failures with pipefail exit checks and inputs

* Wire the harness to run make check for mode check examples starting with ecc

* Migrate the single-entry exec examples to mode check and fold their inputs into the check targets

* Fix four make check assertions that misfired under pipefail

* Give the tpm manifest entry a run step so it asserts output

* Skip uefi-static in the lint make -n loop so it does not clone

* Assert the actual verify result in the pkcs7 and rsa-nb checks

* Return nonzero from pkcs12-create-example on a failed create so the check is not a false pass

* Return nonzero from rsa-kg on any key generate or write failure

* Assert the static memory checks by exit code instead of a pipefail grep that BSD make lacks

* Run pkcs7 signedData stream through make check so it asserts the real verify result

* Check DER certificates and CRLs in the expiry canary too

* Feed the wolfHSM client its stdin so run_client actually exchanges data

* Assert every make check by exit code and captured output instead of a pipefail grep so they hold under BSD make
2026-07-23 10:07:06 -06:00
Paul Adelsbach 69eb6003bd Update LMS and XMSS example to latest 2026-07-16 11:54:51 -07:00
Emma Stensland 8f0f1af04a F-1298 F-1302 F-1307 F-1712 F-1713 F-1719 F-1720 F-1721 F-1722 F-2093 F-3466 F-3472 F-3477 F-4131 F-4132 F-4600 F-5612 F-6286 F-6289 F-6536: Fix error handling in crypto and signature examples 2026-07-14 15:06:41 -06:00
Emma Stensland f38780093c F-1300 F-2099 F-2100 F-2101 F-2113 F-2116 F-3474 F-3475 F-3476 F-3692 F-3694 F-3695 F-3892 F-3893 F-3894 F-4126: fix key/RNG leaks and zeroize private key buffers in certgen, ecc, and PQ examples 2026-07-14 14:32:22 -06:00
Emma Stensland 717e52d02b F-1305 F-1306 F-1714 F-2111 F-2905 F-2906 F-2909 F-3897 F-4125 F-4608 F-6288: fix NULL-deref, fd-leak, unaligned-access, and buffer-overflow bugs across CAN, PKCS7, embedded, and PEM-printing examples 2026-07-14 13:33:25 -06:00
Emma Stensland ac4b7b574e F-1698 F-1699 F-2094 F-2097 F-3222 F-3465 F-3900 F-4130 F-4599 F-5611 F-6285: fix logic and conditional bugs 2026-07-10 16:56:42 -06:00
Sean Parkinson 6ba3b3b7ef PQC proxy
Proxies that sit in front of a client and server that don't support PQC crypto algorithms.
2026-06-25 20:48:22 +10:00
Anthony Hu 785001fa82 An example of how to use ML-KEM. 2025-10-23 16:20:43 -04:00
Dario Pighin 3b12b80f17 Replace WOLFSSL_HAVE_KYBER with WOLFSSL_HAVE_MLKEM in wolfssl-examples/pq/tls/client-pq-tls13.c and wolfssl-examples/pq/tls/server-pq-tls13.c 2025-09-28 01:36:53 +02:00
Anthony Hu 376953752e Rename ML-KEM hybrids to match IETF Draft. 2025-07-31 16:32:56 -04:00
Anthony Hu 358e4a2a04 PQ update. Prepare for OQS deprecation. 2025-02-06 14:46:24 -05:00
jordan e5fdf2e1ee tiny cleanup to ml_dsa makefile. 2024-11-01 13:49:36 -05:00
jordan 986bd428d1 small readme cleanup. 2024-11-01 13:42:18 -05:00
jordan dca01c7293 pq: ML-DSA example. 2024-11-01 13:37:40 -05:00
jordan 1252dd6a34 Add missing wc_LmsKey_Init call. 2024-05-09 15:31:11 -05:00
jordan 64aedb43d0 Small readme cleanup. 2024-05-09 15:12:26 -05:00
jordan 946e6f3e7e Update LMS and XMSS examples. 2024-05-09 15:08:29 -05:00
Sean Parkinson 2326995fb0
Merge pull request #435 from bandi13/ConsolidateNaming
Several fixes in various tests across the repository
2024-05-02 10:42:57 +10:00
Anthony Hu d9fcb0e62c
Merge pull request #433 from philljj/fix_lms_example
Check privSz after GetPrivLen.
2024-04-25 11:10:30 -04:00
jordan c47e7a8bb7 Check privSz after GetPrivLen. 2024-04-25 10:05:02 -05:00
Andras Fekete 4c2f96ff64 Clean up wolfSSL path variable name 2024-04-04 13:28:23 -04:00
jordan 277a2dd3ba Update xmss example. 2024-01-26 17:35:27 -06:00
philljj ae6318e797 xmss_example: tiny cleanup to match g++ warning fix. 2023-10-13 18:18:25 -05:00
philljj 37aad60e25 Example for xmss hooks support: include an addendum patch readme. 2023-10-13 13:41:02 -05:00
philljj 61571b3c80 Example for xmss hooks support: little more patch cleanup. 2023-10-11 15:07:08 -05:00
philljj 87df7747da Example for xmss hooks support: update patch and build. 2023-10-09 11:45:34 -05:00
philljj 5b401de7d2 Example for xmss hooks support. 2023-10-05 08:45:57 -05:00
philljj 284e405b77
Add LMS/HSS example. (#390) 2023-07-14 16:38:41 -04:00
Anthony Hu 43882bdf69 Better instructions 2022-11-25 14:00:59 -05:00
Anthony Hu a1938fdf0f Update IOC file. 2022-11-25 13:27:33 -05:00
Anthony Hu 3b138a86b4 wrong variable. 2022-11-25 12:13:28 -05:00
Anthony Hu cf2c577177 Update PQM4 kyber setup script.
Until now there was a bug in the PQM4 library that did not allow us to turn on
optimizations. That bug has been resolved. So, now we use the current head as
of today.
2022-11-25 09:15:31 -05:00
Anthony Hu b06e00e123 Properly deallocate resources in sphincs_sign_verify.c 2022-11-03 10:12:30 -04:00
Anthony Hu 2f610aba1d Use wolfSSL API functions; not private ones. 2022-11-02 17:35:27 -04:00
Anthony Hu ac7336fe4a Add SPHINCS+ cert gen script and sample app. 2022-09-02 11:55:03 -04:00
Anthony Hu fd7ad770c2 Add a script for generating dilithium cert chains. 2022-07-19 13:14:37 -04:00
Anthony Hu 17ed483f41 Add the post-quantum TLS 1.3 STM32CubeIDE example project 2022-04-04 13:30:16 -04:00
David Garske d0a152744b Peer review feedback fixes. 2022-02-22 13:45:10 -08:00
Anthony Hu 6105a7c406
Merge pull request #290 from kojo1/examples-pq 2022-02-15 08:56:23 -05:00
Takashi Kojo fed26fcc7c Add command args for cert file 2022-02-12 09:18:38 +09:00
Anthony Hu 7599da2674 TLS 1.3 over uart for PQ.
...also some minor fixes in the original UART examples.
2022-02-11 15:17:50 -05:00
Anthony Hu 4b95514c36 Better certificate configurations to make the curl/httpd demo work. 2021-11-23 11:18:13 -05:00
Anthony Hu 7f2b379d0e Use the correct certificate file name. 2021-11-04 12:23:45 -04:00
Anthony Hu 6edb15d7e7 Reference github PR 2021-11-02 13:32:54 -04:00
Anthony Hu a534f9140a Macro guards and quickstart in README.md 2021-11-02 13:09:11 -04:00
Anthony Hu 02662f720d Stuff caught by dgarske 2021-11-01 19:06:33 -04:00