Skip to content

wolfCrypt: support zero-malloc cert encoding and clean up CMake/platform defines - #11625

Open
dgarske wants to merge 4 commits into
wolfSSL:masterfrom
dgarske:cryptonly_nomalloc
Open

dgarske wants to merge 4 commits into
wolfSSL:masterfrom
dgarske:cryptonly_nomalloc

Conversation

@dgarske

@dgarske dgarske commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

Description

Four independent CMake and wolfCrypt fixes for WOLFSSL_NO_MALLOC bare-metal builds.

Changes

  • CMake: add a wolfCrypt-only option and stop stray cache defines reaching options.h
    • WOLFSSL_CRYPT_ONLY emits -DWOLFCRYPT_ONLY and -DNO_TLS, matching --enable-cryptonly, and forces the TLS-layer options off so options.h describes the library that was built.
    • Undeclared WOLF* cache variables are filtered out, and a dependency force with no matching option is reported rather than silently ignored.
    • WOLFSSL_MCAST is now declared after the crypt-only block so that force is consumed; a crypt-only build previously kept WOLFSSL_MULTICAST and HAVE_NULL_CIPHER.
  • ASN: encode certificates and CSRs without an allocator
    • wc_MakeCert(), wc_MakeCertReq_ex(), SetKeyIdFromPublicKey() and the name and extension encoders use stack arrays bounded by WC_ASN_MAX_NAME_ENTRIES and MAX_PUBLIC_KEY_SZ.
  • ASN: one key-identifier hash selection, applied everywhere
    • WC_ASN_KEYID_HASH_TYPE and WC_ASN_KEYID_SZ name the hash and its size once. KEYID_SIZE, SIGNER_DIGEST_SIZE, OCSP_DIGEST, OCSP_DIGEST_SIZE and OCSP_RESPONDER_ID_HASH_TYPE all derive from them instead of each re-deriving an answer from NO_SHA.
    • That closes a mismatch under WC_ASN_HASH_SHA256, where KEYID_SIZE followed the option but SIGNER_DIGEST_SIZE stayed at the SHA-1 size, so CalcHashId() wrote past the hash buffers in FindRevokedSerial() and GetCAByAKID(). An OCSP CertID now also carries the OID of the hash that produced the issuer hashes it contains.
    • SHA3-256 and SHA3-384 are selectable when neither SHA-1 nor SHA-256 is in the build, and CalcHashId_ex() dispatches on the algorithm the caller names, keeping the SHA-3 state on the stack so the no-allocator path is preserved.
  • Types: provide XATOI under STRING_USER and in the platform templates

Testing

  • make check on a default build and on --enable-all; wolfcrypt_test() across the cryptonly SHA3, SHA3-384, no-heap certificate, C89 and --disable-inline configurations.
  • New sha3-keyid-ocsp-crl and sha3-384-keyid entries compile the OCSP and Signer hash selectors in SHA3-only builds, which a cryptonly entry does not reach, and cover the key identifier larger than the 32-byte floor.
  • CMake crypt-only defaults and emitted options.h macros compared against the equivalent ./configure build.

@dgarske dgarske self-assigned this Oct 1, 2026
Copilot AI balanced review requested due to automatic review settings October 1, 2026 20:21

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Crypt-only CMake state and extended-key-usage encoding remain incorrect for supported configurations.

Review effort: Balanced
Findings: 3 Medium severity

Open (3)
What changed in this PR

Adds no-heap certificate encoding support, configurable key-ID hashing, CMake crypt-only handling, and XATOI platform fallbacks.

Changes:

  • Uses bounded stack buffers for certificate names and key identifiers.
  • Adds SHA-3 key-ID support and dynamic SKID/AKID sizing.
  • Adds CMake crypt-only plumbing, cache filtering, platform macros, and CI coverage.
File Description
wolfssl/​wolfcrypt/​types.h Adds XATOI fallback for STRING_USER.
wolfssl/​wolfcrypt/​asn.h Uses configured key-ID size.
wolfssl/​wolfcrypt/​asn_public.h Selects key-ID hash and buffer sizes.
wolfcrypt/​src/​asn.c Adds stack-based certificate encoding paths.
wolfcrypt/​test/​test.c Tests no-heap CSR and key IDs.
IDE/​XCODE-FIPSv6/​user_settings.h Defines XATOI.
IDE/​XCODE-FIPSv5/​user_settings.h Defines XATOI.
IDE/​XCODE-FIPSv2/​user_settings.h Defines XATOI.
IDE/​XCODE-FIPSv2/​macOS-C++/​M1/​user_settings.h Defines XATOI.
IDE/​XCODE-FIPSv2/​macOS-C++/​Intel/​user_settings.h Defines XATOI.
IDE/​WINCE/​user_settings.h Defines XATOI.
IDE/​WICED-STUDIO/​user_settings.h Defines XATOI.
IDE/​SimplicityStudio/​user_settings.h Defines XATOI.
IDE/​GCC-ARM/​Header/​user_settings.h Defines XATOI.
examples/​configs/​user_settings_template.h Documents the platform fallback.
CMakeLists.txt Adds crypt-only and cache filtering logic.
cmake/​options.h.in Emits crypt-only macros.
cmake/​functions.cmake Tracks declared CMake options.
.github/​workflows/​no-malloc.yml Expands no-heap certificate coverage.
.github/​workflows/​cmake.yml Tests CMake option plumbing.
.github/​configs/​os-check-linux.json Adds SHA-3 key-ID coverage.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread CMakeLists.txt Outdated
Comment thread CMakeLists.txt Outdated
Comment thread wolfcrypt/src/asn.c Outdated
@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

MemBrowse Memory Report

gcc-arm-cortex-m0plus

  • FLASH: .text +48 B (+0.1%, 69,195 B / 262,144 B, total: 26% used)

gcc-arm-cortex-m3

  • FLASH: .text +52 B (+0.0%, 129,185 B / 262,144 B, total: 49% used)

gcc-arm-cortex-m4

  • FLASH: .text +64 B (+0.0%, 207,916 B / 262,144 B, total: 79% used)

gcc-arm-cortex-m4-baremetal

  • FLASH: .text +64 B (+0.1%, 71,587 B / 262,144 B, total: 27% used)

gcc-arm-cortex-m4-crypto-only

  • FLASH: .text +64 B (+0.0%, 180,893 B / 262,144 B, total: 69% used)

gcc-arm-cortex-m4-dtls13

  • FLASH: .text +64 B (+0.0%, 192,324 B / 1,048,576 B, total: 18% used)

gcc-arm-cortex-m4-min-ecc

  • FLASH: .text +64 B (+0.1%, 66,373 B / 262,144 B, total: 25% used)

gcc-arm-cortex-m4-openssl-compat

  • FLASH: .text +192 B (+0.0%, 790,684 B / 1,048,576 B, total: 75% used)

gcc-arm-cortex-m4-pkcs7

  • FLASH: .text +192 B (+0.1%, 221,790 B / 262,144 B, total: 85% used)

gcc-arm-cortex-m4-pq

  • FLASH: .text +192 B (+0.1%, 308,464 B / 1,048,576 B, total: 29% used)

gcc-arm-cortex-m4-rsa-only

  • FLASH: .text +64 B (+0.0%, 338,608 B / 1,048,576 B, total: 32% used)

gcc-arm-cortex-m4-sp-math

  • FLASH: .text +64 B (+0.1%, 66,373 B / 262,144 B, total: 25% used)

gcc-arm-cortex-m4-tls12

  • FLASH: .text +64 B (+0.0%, 129,981 B / 262,144 B, total: 50% used)

gcc-arm-cortex-m4-tls13

  • FLASH: .text +64 B (+0.0%, 247,262 B / 262,144 B, total: 94% used)

gcc-arm-cortex-m7

  • FLASH: .text +64 B (+0.0%, 207,916 B / 262,144 B, total: 79% used)

gcc-arm-cortex-m7-pq

  • FLASH: .text +192 B (+0.1%, 309,360 B / 1,048,576 B, total: 30% used)

gcc-arm-cortex-m7-tls13

  • FLASH: .text +64 B (+0.0%, 247,262 B / 262,144 B, total: 94% used)

stm32-sim-stm32h753

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Crypt-only multicast forcing is ineffective, and SHA3-only OCSP hashing remains inconsistent.

Review effort: Balanced
Findings: 2 Medium severity

Open (2)
Resolved since last review (3)

Comment thread CMakeLists.txt
Comment thread wolfssl/wolfcrypt/asn_public.h

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

OCSP hash metadata, mixed SM3/SHA3 sizing, and crypt-only bundle handling remain incorrect.

Review effort: Balanced
Findings: 2 High severity · 1 Medium severity

Open (3)
Resolved since last review (2)

Comment thread wolfcrypt/src/asn.c
Comment thread wolfssl/wolfcrypt/asn.h Outdated
Comment thread CMakeLists.txt
@dgarske
dgarske force-pushed the cryptonly_nomalloc branch from f8aaec2 to 65f2058 Compare October 3, 2026 00:11
@dgarske
dgarske force-pushed the cryptonly_nomalloc branch from 65f2058 to dc854a6 Compare October 3, 2026 01:27

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

OCSP can mislabel hashes in mixed SM3 chains, and custom STRING_USER benchmark builds still lack XATOI.

Review effort: Balanced
Findings: 2 High severity

Open (2)
Resolved since last review (3)

Comment thread wolfcrypt/src/asn.c
Comment on lines +38191 to 38196
/* CertID.hashAlgorithm names the hash the issuer hashes were made
* with (RFC 6960 4.1.1), which is per certificate in an SM build. */
req->hashAlg = wc_HashGetOID(
wc_HashTypeConvert(HashIdAlg(cert->signatureOID)));
XMEMCPY(req->issuerHash, cert->issuerHash, KEYID_SIZE);
XMEMCPY(req->issuerKeyHash, cert->issuerKeyHash, KEYID_SIZE);
Comment thread wolfssl/wolfcrypt/types.h
Comment on lines +1324 to +1327
#if defined(STRING_USER) && !defined(XATOI) && \
(defined(WOLFSSL_CERT_EXT) || defined(HAVE_OCSP) || \
defined(HAVE_CRL_IO) || defined(HAVE_HTTP_CLIENT) || \
defined(OPENSSL_EXTRA))
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants