Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
26 changes: 25 additions & 1 deletion .github/configs/os-check-linux.json
Original file line number Diff line number Diff line change
Expand Up @@ -541,5 +541,29 @@
"--disable-oldtls", "--disable-examples", "CPPFLAGS=-DWOLFSSL_NO_TLS12"]},
{"name": "tls13-sha512-runtime", "minutes": 1.6,
"comment": "--enable-tls13-sha512 with TLS 1.2 left in, so the examples and unit tests build and run with WOLFSSL_HS_HASH_SHA512 set. No cipher suite sets mac_algorithm to sha512_mac, so the sha512_mac arms in src/tls13.c stay unreached; what this entry proves is that the option does not break an otherwise ordinary build, which the two compile-only entries above cannot show.",
"configure": ["--enable-tls13", "--enable-tls13-sha512", "--enable-sha512"]}
"configure": ["--enable-tls13", "--enable-tls13-sha512", "--enable-sha512"]},
{"name": "cryptonly-sha3-keyid", "minutes": 0.8,
"comment": "SHA3 as the only hash family that can derive key identifiers: no SHA-1 and no SHA-256, so HashIdAlg()/CalcHashId_ex() must pick SHA3-256 and KEYID_SIZE must follow it. SHA-512 is kept only because the Hash DRBG needs it. The CERT KEYID subtest checks the SKID/AKID sizes the generator writes against CTC_MAX_SKID_SIZE.",
"configure": ["--enable-cryptonly", "--enable-ecc", "--enable-certgen",
"--enable-certreq", "--enable-certext", "--enable-sha3", "--enable-sha512",
"--disable-sha", "--disable-sha256", "--disable-sha224", "--disable-rsa",
"--disable-dh",
"CPPFLAGS=-DWOLFSSL_DRBG_SHA512 -DUSE_CERT_BUFFERS_256"]},
{"name": "sha3-keyid-ocsp-crl", "minutes": 1.2,
"comment": "The SHA3-only key identifier hash of cryptonly-sha3-keyid, but with the TLS layer left in so src/ocsp.c and the Signer table compile. OCSP_DIGEST and OCSP_RESPONDER_ID_HASH_TYPE must name SHA3-256 and SIGNER_DIGEST_SIZE must match KEYID_SIZE, none of which a cryptonly build reaches. NO_SESSION_CACHE because HashObject() needs MD5, SHA-1 or SHA-256 and this build has none; no cipher suite survives either, so there is no handshake left to check.",
"configure": ["--enable-ocsp", "--enable-crl", "--enable-sha3",
"--enable-certgen", "--enable-certreq", "--enable-certext",
"--disable-sha", "--disable-sha256", "--disable-sha224",
"--disable-examples", "CPPFLAGS=-DNO_SESSION_CACHE"],
"check": false,
"run": [["./wolfcrypt/test/testwolfcrypt"]]},
{"name": "sha3-384-keyid", "minutes": 0.8,
"comment": "WOLFSSL_NOSHA3_256 on top of the SHA3-only key identifier hash, so the selection falls through to SHA3-384 and WC_ASN_KEYID_SZ becomes 48. This is the only entry where the key identifier is larger than the 32-byte floor, so it is what proves CTC_MAX_SKID_SIZE widens and the Cert SKID/AKID buffers still hold what CalcHashId_ex() writes. ML-KEM is off because wc_mlkem_poly.c calls wc_InitSha3_256() unconditionally.",
"configure": ["--enable-cryptonly", "--enable-ecc", "--enable-certgen",
"--enable-certreq", "--enable-certext", "--enable-sha3", "--enable-sha512",
"--disable-sha", "--disable-sha256", "--disable-sha224", "--disable-rsa",
"--disable-dh", "--disable-mlkem",
"CPPFLAGS=-DWOLFSSL_DRBG_SHA512 -DUSE_CERT_BUFFERS_256 -DWOLFSSL_NOSHA3_256"],
"check": false,
"run": [["./wolfcrypt/test/testwolfcrypt"]]}
]
61 changes: 61 additions & 0 deletions .github/workflows/cmake.yml
Original file line number Diff line number Diff line change
Expand Up @@ -111,6 +111,67 @@ jobs:
cd ..
rm -rf build

# Option plumbing: a declared option must reach both the library and
# options.h, and a -D that is not an option must reach neither.
- name: Check option to options.h plumbing
run: |
mkdir build
cd build
cmake -DWOLFSSL_CRYPT_ONLY=yes .. 2>&1 | tee cfg.log
grep -q '^#define WOLFCRYPT_ONLY$' wolfssl/options.h
grep -q '^#define NO_TLS$' wolfssl/options.h
# TLS-layer options default off, as with --enable-cryptonly, but the
# TLS 1.3 KDFs stay.
! grep -q '^#define HAVE_SNI$' wolfssl/options.h
! grep -q '^#define WOLFSSL_DTLS$' wolfssl/options.h
grep -q '^#define WOLFSSL_TLS13$' wolfssl/options.h
! grep -q 'is not a wolfSSL build option' cfg.log
cmake --build .

cd ..
rm -rf build
mkdir build
cd build
# Adding cryptonly to a directory configured without it must take the
# TLS layer out too, not leave the previous defaults cached.
cmake .. > /dev/null
grep -q '^#define HAVE_SNI$' wolfssl/options.h
cmake -DWOLFSSL_CRYPT_ONLY=yes .. > /dev/null
! grep -q '^#define HAVE_SNI$' wolfssl/options.h
grep -q '^#define NO_TLS$' wolfssl/options.h

cd ..
rm -rf build
mkdir build
cd build
# Cryptonly wins over a TLS-layer option asked for alongside it.
cmake -DWOLFSSL_CRYPT_ONLY=yes -DWOLFSSL_DTLS=yes .. > /dev/null
! grep -q '^#define WOLFSSL_DTLS$' wolfssl/options.h

cd ..
rm -rf build
mkdir build
cd build
# An option declared with a raw CACHE entry rather than add_option must
# survive the stray-define guard, including across a reconfigure.
cmake -DWOLFSSL_HARDEN_TLS=128 .. 2>&1 | tee cfg.log
grep -q '^#define WOLFSSL_HARDEN_TLS 128$' wolfssl/options.h
! grep -q 'is not a wolfSSL build option' cfg.log
cmake . > /dev/null
grep -q '^#define WOLFSSL_HARDEN_TLS 128$' wolfssl/options.h

cd ..
rm -rf build
mkdir build
cd build
# WOLFSSL_STATICMEMORY is the option; this spelling is not one.
cmake -DWOLFSSL_STATIC_MEMORY=yes .. 2>&1 | tee cfg.log
grep -q 'WOLFSSL_STATIC_MEMORY is not a wolfSSL build option' cfg.log
! grep -q '^#define WOLFSSL_STATIC_MEMORY$' wolfssl/options.h

cd ..
rm -rf build

# CMake build with user_settings.h
- name: Build wolfssl with user_settings.h
run: |
Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/no-malloc.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,3 @@
name: No Malloc Tests

# START OF COMMON SECTION
Expand Down Expand Up @@ -99,7 +99,8 @@
"run": [["./wolfcrypt/test/testwolfcrypt"]]},
{"name": "no-heap-cert", "minutes": 0.8,
"configure": ["--enable-rsa", "--enable-keygen", "--enable-ecc",
"--enable-acert", "--disable-dh", "--disable-filesystem",
"--enable-acert", "--enable-certgen", "--enable-certreq",
"--enable-certext", "--disable-dh", "--disable-filesystem",
"CFLAGS=-DWOLFSSL_NO_MALLOC -DNO_WOLFSSL_MEMORY -DRSA_MIN_SIZE=1024 -DWOLFSSL_TEST_CERT -DUSE_CERT_BUFFERS_2048 -DUSE_CERT_BUFFERS_256 -pedantic -Wdeclaration-after-statement -Wnull-dereference -DTEST_LIBWOLFSSL_SOURCES_INCLUSION_SEQUENCE"],
"check": false,
"run": [["./wolfcrypt/test/testwolfcrypt"]]}
Expand Down
93 changes: 85 additions & 8 deletions CMakeLists.txt
Original file line number Diff line number Diff line change
Expand Up @@ -500,14 +500,6 @@ if(WOLFSSL_SCEP)
list(APPEND WOLFSSL_DEFINITIONS "-DHAVE_AES_KEYWRAP" "-DHAVE_X963_KDF" "-DWOLFSSL_AES_DIRECT" "-DWOLFSSL_CERT_EXT" "-DWOLFSSL_CERT_GEN" "-DWOLFSSL_CERT_REQ" "-DWOLFSSL_HAVE_WOLFSCEP" "-DWOLFSSL_KEY_GEN")
endif()

add_option("WOLFSSL_MCAST" "Enable DTLS multicast support (default: disabled)" "no" "yes;no")
if(WOLFSSL_MCAST)
foreach(_o WOLFSSL_DTLS)
force_option(${_o} "yes")
endforeach()
list(APPEND WOLFSSL_DEFINITIONS "-DHAVE_NULL_CIPHER" "-DWOLFSSL_MULTICAST")
endif()

add_option("WOLFSSL_WPAS_DPP" "Enable wpa_supplicant DPP support (default: disabled)" "no" "yes;no")
if(WOLFSSL_WPAS_DPP)
foreach(_o WOLFSSL_AES WOLFSSL_ARC4 WOLFSSL_CRL WOLFSSL_DES3 WOLFSSL_DSA WOLFSSL_MD4 WOLFSSL_MD5 WOLFSSL_OCSP WOLFSSL_OCSPSTAPLING WOLFSSL_OCSPSTAPLING_V2 WOLFSSL_PKCS7)
Expand Down Expand Up @@ -632,6 +624,39 @@ if(WOLFSSL_DEBUG)
endif()


# wolfCrypt only (no TLS). Declared ahead of the TLS-layer options so the
# forces below land before their add_option() calls.
add_option("WOLFSSL_CRYPT_ONLY"
"Enable wolfCrypt Only build (default: disabled)"
"no" "yes;no")

if(WOLFSSL_CRYPT_ONLY)
list(APPEND WOLFSSL_DEFINITIONS "-DWOLFCRYPT_ONLY")
# Mirror --enable-cryptonly so options.h describes the library built.
# Forced, not defaulted: a reconfigure cannot tell a cache entry from an
# explicit setting. WOLFSSL_TLS carries -DNO_TLS and the TLS-version
# checks read it. TLS 1.2 and 1.3 stay on for their wolfCrypt-layer KDFs.
foreach(_o WOLFSSL_TLS
WOLFSSL_ALPN WOLFSSL_CRL_MONITOR WOLFSSL_DTLS WOLFSSL_DTLS13
WOLFSSL_DTLS_CH_FRAG WOLFSSL_DTLS_CID WOLFSSL_DTLS_MTU
WOLFSSL_EARLYDATA WOLFSSL_ECH WOLFSSL_MCAST WOLFSSL_OCSP
Comment thread
dgarske marked this conversation as resolved.
WOLFSSL_OCSPSTAPLING WOLFSSL_OCSPSTAPLING_V2
WOLFSSL_PKCALLBACKS WOLFSSL_QUIC
WOLFSSL_RENEGOTIATION_INDICATION WOLFSSL_SECURE_RENEGOTIATION
WOLFSSL_SNI WOLFSSL_SRTP WOLFSSL_TLSX)
Comment thread
dgarske marked this conversation as resolved.
force_option(${_o} "no")
endforeach()
message(STATUS "WOLFSSL_CRYPT_ONLY: TLS layer off, including its options")
endif()

add_option("WOLFSSL_MCAST" "Enable DTLS multicast support (default: disabled)" "no" "yes;no")
if(WOLFSSL_MCAST)
foreach(_o WOLFSSL_DTLS)
force_option(${_o} "yes")
endforeach()
list(APPEND WOLFSSL_DEFINITIONS "-DHAVE_NULL_CIPHER" "-DWOLFSSL_MULTICAST")
endif()

# Single threaded
add_option("WOLFSSL_SINGLE_THREADED"
"Enable wolfSSL single threaded (default: disabled)"
Expand Down Expand Up @@ -4576,6 +4601,58 @@ endforeach()
# both emitting the same feature define).
list(REMOVE_DUPLICATES WOLFSSL_DEFINITIONS)

# Matches configure.ac: cryptonly and opensslall are mutually incompatible.
# The application bundles (nginx, haproxy, ...) each append -DOPENSSL_ALL
# directly, which forcing their leaf options off does not retract, so test the
# definition list as well as the option.
if(WOLFSSL_CRYPT_ONLY)
if(WOLFSSL_OPENSSLALL OR "-DOPENSSL_ALL" IN_LIST WOLFSSL_DEFINITIONS)
message(FATAL_ERROR
"cryptonly and opensslall are mutually incompatible.")
endif()
endif()

# A -D that is not a build option still satisfies the matching #cmakedefine
# below, so options.h would claim features the library lacks (for example
# WOLFSSL_STATIC_MEMORY for the WOLFSSL_STATICMEMORY option). Drop those.
get_property(WOLFSSL_DECLARED_OPTIONS GLOBAL PROPERTY WOLFSSL_DECLARED_OPTIONS)
get_cmake_property(WOLFSSL_CACHE_VARS CACHE_VARIABLES)
file(STRINGS "${CMAKE_CURRENT_SOURCE_DIR}/cmake/options.h.in" OPTIONS_H_LINES
REGEX "^#cmakedefine[ \t]+[A-Za-z_]")
foreach(LINE IN LISTS OPTIONS_H_LINES)
string(REGEX REPLACE "^#cmakedefine[ \t]+([A-Za-z_][A-Za-z0-9_]*).*$" "\\1"
MACRO_NAME "${LINE}")
# wolfSSL's namespace only; the rest are system probes we set ourselves.
if(NOT MACRO_NAME MATCHES "^WOLF")
continue()
endif()
if(MACRO_NAME IN_LIST WOLFSSL_DECLARED_OPTIONS)
continue()
endif()
if(NOT MACRO_NAME IN_LIST WOLFSSL_CACHE_VARS)
continue()
endif()
# Already compiled in, so a real option however its cache entry was made
# (WOLFSSL_HARDEN_TLS uses a raw CACHE STRING to keep a bad value).
set(MACRO_IN_DEFS FALSE)
foreach(DEF IN LISTS WOLFSSL_DEFINITIONS)
if(DEF MATCHES "^-D${MACRO_NAME}(=.*)?$")
set(MACRO_IN_DEFS TRUE)
break()
endif()
endforeach()
if(MACRO_IN_DEFS)
continue()
endif()
if(${MACRO_NAME})
message(WARNING "${MACRO_NAME} is not a wolfSSL build option; ignoring "
"it so that wolfssl/options.h matches the library. Run "
"`cmake -LH` for the option list.")
unset(${MACRO_NAME})
unset(${MACRO_NAME} CACHE)
endif()
endforeach()

foreach(DEF IN LISTS WOLFSSL_DEFINITIONS)
string(REGEX MATCH "^(-D)?([^=]+)(=(.*))?$" DEF_MATCH ${DEF})
if (NOT "${CMAKE_MATCH_4}" STREQUAL "")
Expand Down
3 changes: 3 additions & 0 deletions IDE/GCC-ARM/Header/user_settings.h
Original file line number Diff line number Diff line change
Expand Up @@ -537,6 +537,9 @@ extern unsigned int my_rng_seed_gen(void);
#define XSTRNCASECMP(s1,s2,n) strncasecmp((s1),(s2),(n))

#define XSNPRINTF snprintf

#include <stdlib.h>
#define XATOI(s) atoi((s))
#endif


Expand Down
3 changes: 3 additions & 0 deletions IDE/SimplicityStudio/user_settings.h
Original file line number Diff line number Diff line change
Expand Up @@ -454,6 +454,9 @@ extern "C" {
#define XSTRNCASECMP(s1,s2,n) strncasecmp((s1),(s2),(n))

#define XSNPRINTF snprintf

#include <stdlib.h>
#define XATOI(s) atoi((s))
#endif


Expand Down
3 changes: 3 additions & 0 deletions IDE/WICED-STUDIO/user_settings.h
Original file line number Diff line number Diff line change
Expand Up @@ -531,6 +531,9 @@ extern unsigned int my_rng_seed_gen(void);
#define XSTRNCASECMP(s1,s2,n) strncasecmp((s1),(s2),(n))

#define XSNPRINTF snprintf

#include <stdlib.h>
#define XATOI(s) atoi((s))
#endif


Expand Down
3 changes: 3 additions & 0 deletions IDE/WINCE/user_settings.h
Original file line number Diff line number Diff line change
Expand Up @@ -662,6 +662,9 @@ C149F3285397DFBD0C6720E14818475C3A50B10880EF9619463173A6D5ED15E7
#define XSTRNCASECMP(s1,s2,n) strncasecmp((s1),(s2),(n))

#define XSNPRINTF snprintf

#include <stdlib.h>
#define XATOI(s) atoi((s))
#endif


Expand Down
3 changes: 3 additions & 0 deletions IDE/XCODE-FIPSv2/macOS-C++/Intel/user_settings.h
Original file line number Diff line number Diff line change
Expand Up @@ -528,6 +528,9 @@ extern "C" {
#define XSTRNCASECMP(s1,s2,n) strncasecmp((s1),(s2),(n))

#define XSNPRINTF snprintf

#include <stdlib.h>
#define XATOI(s) atoi((s))
#endif


Expand Down
3 changes: 3 additions & 0 deletions IDE/XCODE-FIPSv2/macOS-C++/M1/user_settings.h
Original file line number Diff line number Diff line change
Expand Up @@ -539,6 +539,9 @@ extern "C" {
#define XSTRNCASECMP(s1,s2,n) strncasecmp((s1),(s2),(n))

#define XSNPRINTF snprintf

#include <stdlib.h>
#define XATOI(s) atoi((s))
#endif


Expand Down
3 changes: 3 additions & 0 deletions IDE/XCODE-FIPSv2/user_settings.h
Original file line number Diff line number Diff line change
Expand Up @@ -540,6 +540,9 @@ extern "C" {
#define XSTRNCASECMP(s1,s2,n) strncasecmp((s1),(s2),(n))

#define XSNPRINTF snprintf

#include <stdlib.h>
#define XATOI(s) atoi((s))
#endif


Expand Down
3 changes: 3 additions & 0 deletions IDE/XCODE-FIPSv5/user_settings.h
Original file line number Diff line number Diff line change
Expand Up @@ -621,6 +621,9 @@ extern "C" {
#define XSTRNCASECMP(s1,s2,n) strncasecmp((s1),(s2),(n))

#define XSNPRINTF snprintf

#include <stdlib.h>
#define XATOI(s) atoi((s))
#endif


Expand Down
3 changes: 3 additions & 0 deletions IDE/XCODE-FIPSv6/user_settings.h
Original file line number Diff line number Diff line change
Expand Up @@ -681,6 +681,9 @@ extern "C" {
#define XSTRNCASECMP(s1,s2,n) strncasecmp((s1),(s2),(n))

#define XSNPRINTF snprintf

#include <stdlib.h>
#define XATOI(s) atoi((s))
#endif


Expand Down
14 changes: 7 additions & 7 deletions cmake/functions.cmake
Original file line number Diff line number Diff line change
Expand Up @@ -17,9 +17,8 @@ endfunction()
# explicit rather than relying on cross-file cache-precedence side effects.
function(force_option NAME VALUE)
set_property(GLOBAL PROPERTY "WOLFSSL_FORCE_${NAME}" "${VALUE}")
# Track pending forces so an unconsumed one (no matching add_option) can be
# reported by wolfssl_warn_unconsumed_forces() -- a force on an option that
# is not declared via add_option() would otherwise be silently ignored.
# Track pending forces so wolfssl_warn_unconsumed_forces() can report one
# with no matching add_option(), which would otherwise be ignored.
set_property(GLOBAL APPEND PROPERTY WOLFSSL_FORCE_PENDING "${NAME}")
endfunction()

Expand All @@ -39,6 +38,9 @@ function(wolfssl_warn_unconsumed_forces)
endfunction()

function(add_option NAME HELP_STRING DEFAULT VALUES)
# Record the name for the options.h.in guard in CMakeLists.txt.
set_property(GLOBAL APPEND PROPERTY WOLFSSL_DECLARED_OPTIONS "${NAME}")

if(VALUES STREQUAL "yes;no")
# Set the default value for the option.
set(${NAME} ${DEFAULT} CACHE BOOL ${HELP_STRING})
Expand All @@ -49,10 +51,8 @@ function(add_option NAME HELP_STRING DEFAULT VALUES)
set_property(CACHE ${NAME} PROPERTY STRINGS ${VALUES})
endif()

# Apply any dependency force recorded via force_option(). Done after the
# cache entry is created (so its BOOL/STRING type and help are preserved)
# and before the reduction below, so the forced value drives this option's
# own define/source emission just as an explicit setting would.
# Apply any force_option(), after the cache entry exists so its type and
# help survive, and before the reduction below.
get_property(_wolfssl_forced GLOBAL PROPERTY "WOLFSSL_FORCE_${NAME}" SET)
if(_wolfssl_forced)
get_property(_wolfssl_force_val GLOBAL PROPERTY "WOLFSSL_FORCE_${NAME}")
Expand Down
2 changes: 2 additions & 0 deletions cmake/options.h.in
Original file line number Diff line number Diff line change
Expand Up @@ -707,6 +707,8 @@ extern "C" {
#cmakedefine WOLFSSL_STATIC_MEMORY_LEAN
#undef WOLFSSL_STATIC_MEMORY_DEBUG_CALLBACK
#cmakedefine WOLFSSL_STATIC_MEMORY_DEBUG_CALLBACK
#undef WOLFCRYPT_ONLY
#cmakedefine WOLFCRYPT_ONLY
#undef NO_TLS
#cmakedefine NO_TLS
#undef NO_SHA256
Expand Down
3 changes: 3 additions & 0 deletions examples/configs/user_settings_template.h
Original file line number Diff line number Diff line change
Expand Up @@ -487,6 +487,9 @@ extern "C" {
#define XSTRNCASECMP(s1,s2,n) strncasecmp((s1),(s2),(n))

#define XSNPRINTF snprintf

#include <stdlib.h>
#define XATOI(s) atoi((s))
#endif


Expand Down
Loading
Loading