wolfssl/tests/unit-mcdc
JacobBarthelmeh 87d41e2dd5
Merge pull request #11140 from holtrop-wolfssl/zd22282
Fix directoryName NameConstraints bypass
2026-08-20 09:21:47 -06:00
..
README.md
mcdc_der_edit.h tests: address the findings on the mcdc helpers and the CRL skip vector 2026-08-17 10:01:57 +02:00
mcdc_fault_alloc.h tests: drive the dsa crafted keys, ecc ECIES modes and rsa pad guards 2026-08-17 08:09:36 +02:00
mcdc_fault_hash.h tests: drive the slhdsa pre-hash, check-key and cross-family decode rows 2026-08-17 08:09:36 +02:00
mcdc_fault_mp.h tests: address the findings on the mcdc helpers and the CRL skip vector 2026-08-17 10:01:57 +02:00
mcdc_fault_mpint.h tests: add an mp_int lifecycle injector and drive the rsa keygen chains 2026-08-17 08:09:36 +02:00
mcdc_fault_mutex.h tests: drive the ecc argument-guard operands 2026-08-17 08:09:35 +02:00
mcdc_seed_rng.h tests: address the findings on the mcdc helpers and the CRL skip vector 2026-08-17 10:01:57 +02:00
test_aes_whitebox.c tests: pair the GHASH size operands in the aes white-box 2026-08-17 09:37:23 +02:00
test_asn_cert_whitebox.c tests: correct the asn white-box fixtures that asserted the wrong result 2026-08-17 08:09:36 +02:00
test_asn_certgen_whitebox.c tests: reject the acert general-name URIs and both nonRepudiation spellings 2026-08-17 08:09:37 +02:00
test_asn_ext_whitebox.c Merge pull request #11140 from holtrop-wolfssl/zd22282 2026-08-20 09:21:47 -06:00
test_asn_fault_whitebox.c tests: overflow the unknown-extension OID so the callback dispatch is skipped 2026-08-17 08:09:37 +02:00
test_asn_keys_whitebox.c tests: restore the asn path-length and specified-curve version rows 2026-08-17 08:09:37 +02:00
test_asn_revocation_whitebox.c tests: address the findings on the mcdc helpers and the CRL skip vector 2026-08-17 10:01:57 +02:00
test_asn_whitebox.c tests: record the asn unreachability arguments in the driver headers 2026-08-17 08:09:36 +02:00
test_blake2b_whitebox.c
test_blake2s_whitebox.c
test_chacha20_poly1305_whitebox.c tests: sweep the chacha20/poly1305 AVX-512 dispatch rows 2026-08-17 09:25:11 +02:00
test_chacha_whitebox.c tests: sweep the chacha20/poly1305 AVX-512 dispatch rows 2026-08-17 09:25:11 +02:00
test_cmac_whitebox.c
test_cryptocb_whitebox.c tests: drive the new cryptocb dispatch guards 2026-08-17 09:17:32 +02:00
test_curve25519_whitebox.c tests: cover the conditions master added under the campaign 2026-08-07 09:27:42 +02:00
test_dh_fault_whitebox.c tests: drive the dh public-value argument guard 2026-08-17 09:21:14 +02:00
test_dsa_fault_whitebox.c tests: drive the dsa crafted keys, ecc ECIES modes and rsa pad guards 2026-08-17 08:09:36 +02:00
test_ecc_fault_whitebox.c tests: forge invalid ecc keys and points for the validation guards 2026-08-17 08:09:36 +02:00
test_ecc_whitebox.c tests: mark the ecc mul2add scalar-width rows covered in the residual block 2026-08-17 08:09:37 +02:00
test_eccsi_fault_whitebox.c tests: bound the fault sweeps by vector count, not elapsed time 2026-08-17 08:09:36 +02:00
test_eccsi_whitebox.c tests: stage the eccsi rejection-sampling retry rows 2026-08-17 08:09:36 +02:00
test_ed448_hash_fault_whitebox.c tests: fault the ed25519 and ed448 hash chains and pair the ed448 argument guards 2026-08-17 08:09:36 +02:00
test_ed448_whitebox.c tests: fault the ed25519 and ed448 hash chains and pair the ed448 argument guards 2026-08-17 08:09:36 +02:00
test_ed25519_hash_fault_whitebox.c tests: fault the ed25519 and ed448 hash chains and pair the ed448 argument guards 2026-08-17 08:09:36 +02:00
test_ed25519_whitebox.c
test_falcon_whitebox.c tests: correct the falcon keygen coefficient-bound residual note 2026-08-17 08:09:36 +02:00
test_frodokem_cryptocb_whitebox.c tests: interpose the frodokem one-shot hash and add the XMSSMT-20/2 retired index 2026-08-17 08:09:36 +02:00
test_frodokem_fault_common.h tests: repair the white-boxes that stopped building 2026-08-07 09:27:42 +02:00
test_frodokem_fault_whitebox.c
test_frodokem_mat_fault_whitebox.c
test_frodokem_mat_hash_fault_whitebox.c tests: call the frodokem noise generator directly to reach its init guard 2026-08-17 08:09:36 +02:00
test_hpke_fault_whitebox.c
test_hpke_whitebox.c
test_integer_fault_whitebox.c tests: pair the integer comba thresholds and the gcd error rows 2026-08-17 08:09:36 +02:00
test_integer_whitebox.c tests: pair the integer comba thresholds and the gcd error rows 2026-08-17 08:09:36 +02:00
test_kdf_hash_fault_whitebox.c tests: fault the kdf hash and AES transforms for the ret==0 guards 2026-08-17 08:09:36 +02:00
test_kdf_whitebox.c tests: drive the kdf input-validation guards 2026-08-17 09:16:38 +02:00
test_lms_fault_whitebox.c tests: drive the argument-guard rows in the MC/DC white-boxes 2026-08-07 09:27:42 +02:00
test_lms_hash_fault_whitebox.c tests: record why the lms keygen is not seeded 2026-08-17 08:09:36 +02:00
test_logging_globalq_whitebox.c
test_logging_whitebox.c
test_memory_whitebox.c tests: drive the infra cryptocb devId, memory bucket and wc_port errno guards 2026-08-17 08:09:36 +02:00
test_mldsa_fault_whitebox.c tests: close the mlkem and mldsa sampler, dispatch and guard rows 2026-08-17 08:09:36 +02:00
test_mldsa_hash_fault_whitebox.c tests: record why an empty mldsa private key cannot reach the length else-ifs 2026-08-17 08:09:36 +02:00
test_mlkem_fault_whitebox.c
test_mlkem_poly_hash_fault_whitebox.c tests: fault the mlkem poly SHAKE chains and hash512 arguments 2026-08-17 08:09:36 +02:00
test_pkcs7_arg_whitebox.c tests: size the pkcs7 detached header/footer buffers to fit the encode 2026-08-17 08:09:36 +02:00
test_pkcs7_craft_whitebox.c tests: record the pkcs7 fourth-pass unreachability arguments 2026-08-17 08:09:37 +02:00
test_pkcs7_decode_whitebox.c tests: drive the PKCS7 signer-info, KARI and ORI decode paths 2026-08-17 08:09:36 +02:00
test_pkcs7_fault_whitebox.c tests: isolate the PKCS7 allocation guards and add the missing baselines 2026-08-17 08:09:36 +02:00
test_pkcs7_lever_whitebox.c tests: drive the pkcs7 KARI issuer-and-serial match arms 2026-08-17 08:09:37 +02:00
test_pkcs7_mutate_whitebox.c tests: pin the PKCS7 bundle generation to a fixed stream 2026-08-17 08:09:36 +02:00
test_pkcs7_whitebox.c tests: drive the PKCS7 argument chains and decode mutations 2026-08-17 08:09:36 +02:00
test_pkcs12_fault_whitebox.c tests: correct the pkcs12 unreachability arguments in the driver header 2026-08-17 08:09:36 +02:00
test_pkcs12_parse_whitebox.c
test_pkcs12_whitebox.c tests: wrap error-code operands and fix the test_compress include order 2026-08-07 09:27:42 +02:00
test_poly1305_whitebox.c tests: sweep the chacha20/poly1305 AVX-512 dispatch rows 2026-08-17 09:25:11 +02:00
test_puf_whitebox.c tests: cover the new puf argument guards 2026-08-17 08:09:35 +02:00
test_pwdbased_whitebox.c tests: fault the pwdbased KDF loop transforms 2026-08-17 08:09:36 +02:00
test_random_fault_whitebox.c tests: add the random entropy and Hash_df fault supplement 2026-08-17 08:09:36 +02:00
test_random_whitebox.c tests: add the random entropy and Hash_df fault supplement 2026-08-17 08:09:36 +02:00
test_rsa_fault_whitebox.c tests: close the rsa fault white-box header comment 2026-08-17 08:09:37 +02:00
test_rsa_whitebox.c tests: fault the mldsa SHAKE chains and forge retired xmss indices 2026-08-17 08:09:36 +02:00
test_sakke_fault_whitebox.c tests: stage the sakke zero-key retry and pairing error rows 2026-08-17 08:09:36 +02:00
test_sakke_whitebox.c
test_sha3_whitebox.c tests: fix codespell hits in the MC/DC test files 2026-08-07 09:27:42 +02:00
test_sha256_whitebox.c tests: drive the sha256 and sha512 length-guard error halves 2026-08-17 08:09:36 +02:00
test_sha512_whitebox.c tests: drive the sha256 and sha512 length-guard error halves 2026-08-17 08:09:36 +02:00
test_she_whitebox.c tests: fault the she AES transform loop 2026-08-17 08:09:36 +02:00
test_signature_whitebox.c tests: pair the signature plain_ptr cleanup guard 2026-08-17 08:09:36 +02:00
test_slhdsa_hash_fault_whitebox.c tests: drive the slhdsa pre-hash, check-key and cross-family decode rows 2026-08-17 08:09:36 +02:00
test_slhdsa_whitebox.c
test_sp_arm32_fault_whitebox.c tests: drive the SP ARM lane signature and inverse guards 2026-08-17 08:09:36 +02:00
test_sp_arm32_whitebox.c tests: drive the SP ARM lane signature and inverse guards 2026-08-17 08:09:36 +02:00
test_sp_arm64_fault_whitebox.c tests: drive the SP ARM lane signature and inverse guards 2026-08-17 08:09:36 +02:00
test_sp_arm64_whitebox.c tests: drive the SP ARM lane signature and inverse guards 2026-08-17 08:09:36 +02:00
test_sp_arm_fault_common.h tests: drive the SP ARM lane signature and inverse guards 2026-08-17 08:09:36 +02:00
test_sp_armthumb_fault_whitebox.c tests: drive the SP ARM lane signature and inverse guards 2026-08-17 08:09:36 +02:00
test_sp_armthumb_whitebox.c tests: drive the SP ARM lane signature and inverse guards 2026-08-17 08:09:36 +02:00
test_sp_c32_fault_whitebox.c tests: add heap-fault white-boxes for the SP backends and sp_int 2026-08-17 08:09:35 +02:00
test_sp_c32_whitebox.c tests: drive the SP host-backend crafted entry points 2026-08-17 08:09:36 +02:00
test_sp_c64_fault_whitebox.c tests: add heap-fault white-boxes for the SP backends and sp_int 2026-08-17 08:09:35 +02:00
test_sp_c64_whitebox.c tests: drive the SP host-backend crafted entry points 2026-08-17 08:09:36 +02:00
test_sp_cortexm_whitebox.c tests: drive the SP ARM lane signature and inverse guards 2026-08-17 08:09:36 +02:00
test_sp_crafted_common.h tests: close the sp_int prime-trial and exptmod reduction error rows 2026-08-17 08:09:36 +02:00
test_sp_fault_common.h tests: call the SP entry points directly under the fault sweep 2026-08-17 08:09:36 +02:00
test_sp_int_fault_whitebox.c tests: drive the sp_int and integer error chains and width guards 2026-08-17 08:09:36 +02:00
test_sp_int_whitebox.c tests: close the sp_int prime-trial and exptmod reduction error rows 2026-08-17 08:09:36 +02:00
test_sp_x86_64_fault_whitebox.c tests: add heap-fault white-boxes for the SP backends and sp_int 2026-08-17 08:09:35 +02:00
test_sp_x86_64_whitebox.c tests: drive the SP host-backend crafted entry points 2026-08-17 08:09:36 +02:00
test_tfm_whitebox.c tests: add hash and mp fault injectors, drive the stateful-hash error chains 2026-08-17 08:09:36 +02:00
test_tsp_fault_whitebox.c tests: mock the tsp clock formatting calls and the tsa name length guard 2026-08-17 08:09:36 +02:00
test_tsp_whitebox.c tests: record the audited rsa, ecc and tsp unreachability arguments 2026-08-17 08:09:36 +02:00
test_wc_encrypt_whitebox.c tests: pair the wc_encrypt password-length and PBE version guards 2026-08-17 08:09:36 +02:00
test_wc_lms_impl_whitebox.c tests: fix codespell hits in the MC/DC test files 2026-08-07 09:27:42 +02:00
test_wc_lms_impl_whitebox_gap.c
test_wc_mldsa_whitebox.c tests: close the mlkem and mldsa sampler, dispatch and guard rows 2026-08-17 08:09:36 +02:00
test_wc_mlkem_poly_whitebox.c tests: close the mlkem and mldsa sampler, dispatch and guard rows 2026-08-17 08:09:36 +02:00
test_wc_port_whitebox.c tests: drive the infra cryptocb devId, memory bucket and wc_port errno guards 2026-08-17 08:09:36 +02:00
test_wc_xmss_impl_whitebox.c tests: fault the xmss BDS state allocation beside the retired-index rows 2026-08-17 08:09:36 +02:00
test_wolfentropy_whitebox.c tests: close argument and allocation guards across the small modules 2026-08-17 08:09:36 +02:00
test_xmss_fault_whitebox.c tests: drive the argument-guard rows in the MC/DC white-boxes 2026-08-07 09:27:42 +02:00
test_xmss_hash_fault_whitebox.c tests: bound the fault sweeps by vector count, not elapsed time 2026-08-17 08:09:36 +02:00

README.md

tests/unit-mcdc - white-box MC/DC supplements

This directory holds small, standalone white-box programs that raise MC/DC (Modified Condition/Decision Coverage) on wolfcrypt/wolfssl source files by reaching decisions that are structurally unreachable from the public API.

These are not part of the wolfSSL build and are not registered in tests/api. They exist for the external ISO 26262 per-module coverage campaign in iso26262/mcdc-per-module/. Nothing here changes library behaviour.

Why a separate module

The tests/api suite drives each source file through its public API. A handful of decision conditions live in WOLFSSL_LOCAL (link-local) or file-static helpers whose "impossible" operand combinations every public caller rejects before the helper runs (e.g. a size != 0 argument paired with a NULL pointer, which every wc_* entry point turns into BAD_FUNC_ARG). Such a condition's MC/DC independence pair can never be demonstrated from the API without editing library source.

A white-box program compiles the .c file in directly (#include), so the static/local helpers are in scope, and calls them with both halves of each MC/DC independence pair in the same binary.

How coverage is combined

llvm-cov computes MC/DC independence per binary. The campaign's aggregate.sh unions the "independence shown" bit across binaries by source line:col. So each pair must be completed within the white-box binary itself - it does not lean on the API tests to supply the other half. The white-box result is unioned in as an extra "<variant>_wb" ledger row, one per build variant, exactly like any other variant.

Build contract (driven by run-mcdc.sh)

The campaign's run-mcdc.sh builds each file via #include with the exact compile flags the instrumented library used for that translation unit (captured from the real libtool command - struct layout and backend selection depend on -DHAVE___UINT128_T, user_settings.h, -DWOLFSSL_TEST_STATIC_BUILD, ...), then links against that variant's libwolfssl.a with the file's own object removed (the white-box TU supplies the single, instrumented definition). The binary is run, exported with llvm-cov export, and its aes.c MC/DC is unioned by line:col. Any failure in this path is best-effort: it logs a skip and never affects the API variant's own coverage row.

Files

file target source reaches
test_aes_whitebox.c wolfcrypt/src/aes.c GHASH / GHASH_UPDATE internal ptr != NULL guards (Class 1, 13 conds) and _AesNew_common cross-argument BAD_FUNC_ARG checks (Class 2, 6 conds)

test_aes_whitebox.c - what it deliberately does not cover

Four aes.c union residuals remain structurally uncoverable even here and stay justified in iso26262/mcdc-per-module/reports/aes/RESIDUALS.md:

  • 13386:5, 13836:5 - the two operands are exact logical complements of one parameter (ivSz==0/ivSz>0, ivFixed==NULL/!=NULL); unique-cause MC/DC is unsatisfiable by construction.
  • 14268:0 - roll_auth's ret==0 needs an internal AES op to fail mid-operation, not selectable without corrupting library state.
  • 15833:0 - a dead defensive branch on a loop index provably bounded to [0,7).

Adding a new white-box module

  1. Create test_<file>_whitebox.c that #includes the target .c and, in main(), calls each unreachable helper with both halves of every targeted MC/DC pair. Keep every call memory-safe (short-circuits protect NULL derefs); surface setup failures as printed skips and return 0 (a nonzero exit makes the campaign discard the variant).
  2. Point the campaign at it (a per-module white-box source path in db/modules.json); run-mcdc.sh's white-box step handles build/link/export.
  3. Re-run run-mcdc.sh <module> then aggregate.sh <module>; confirm the targeted line:col keys leave GAPS.md.