Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
74 changes: 74 additions & 0 deletions .github/workflows/sec-qoriq.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,74 @@
name: NXP QorIQ SEC port

# START OF COMMON SECTION
on:
push:
branches: [ 'release/**' ]
pull_request:
types: [opened, synchronize, reopened, ready_for_review]
branches: [ '*' ]

concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

permissions:
contents: read
# END OF COMMON SECTION

# The simulated backend (--enable-sec-qoriq=sim) models the SEC job ring on
# the build host, so the driver's submission, timeout, reset-escalation and
# status-decoding logic plus AES/GCM/hash/RNG/modexp known answers run under
# make check with fault injection and no hardware. The cross jobs keep the
# real PowerPC backends compiling. A real-hardware smoke gate (T2080/T1040
# known-answer harness) remains outside CI; see the port README.
jobs:
sec_qoriq_sim:
name: simulated backend, autotools and cmake
if: ${{ (github.repository_owner == 'wolfssl') && (github.event_name != 'pull_request' || github.event.pull_request.draft == false) }}
runs-on: ubuntu-24.04
timeout-minutes: 20
steps:
- uses: actions/checkout@v4

# cmake first: it builds from the pristine checkout and relies on the
# in-tree wolfssl/version.h, which an autotools "make distclean" would
# have removed. cmake removes a stale in-tree wolfssl/options.h itself.
- name: cmake build and wolfCrypt test
run: |
cmake -B build-cmake -DWOLFSSL_SEC_QORIQ=sim -DWOLFSSL_EXAMPLES=no
cmake --build build-cmake -j
cd build-cmake && ./wolfcrypt/test/testwolfcrypt

- name: autotools build and check
run: |
./autogen.sh
./configure --enable-sec-qoriq=sim --enable-aesctr \
--enable-aesecb --enable-keygen
make -j
make check

sec_qoriq_cross:
name: PowerPC cross-compile, ${{ matrix.backend }} backend
if: ${{ (github.repository_owner == 'wolfssl') && (github.event_name != 'pull_request' || github.event.pull_request.draft == false) }}
runs-on: ubuntu-24.04
timeout-minutes: 15
strategy:
fail-fast: false
matrix:
backend: [ baremetal, linux ]
steps:
- uses: actions/checkout@v4

- name: install PowerPC toolchain
run: |
sudo apt-get update
sudo apt-get install -y gcc-powerpc-linux-gnu

- name: cross-compile the library
run: |
./autogen.sh
./configure --host=powerpc-linux-gnu CC=powerpc-linux-gnu-gcc \
--enable-sec-qoriq=${{ matrix.backend }} --disable-shared \
--disable-examples --disable-crypttests
make -j src/libwolfssl.la
4 changes: 4 additions & 0 deletions .wolfssl_known_macro_extras
Original file line number Diff line number Diff line change
Expand Up @@ -1129,6 +1129,10 @@ WOLFSSL_SE050_NO_RSA_VERIFY
WOLFSSL_SE050_NO_TRNG
WOLFSSL_SE050_SCP03_ROTATE
WOLFSSL_SECURE_RENEGOTIATION_ON_BY_DEFAULT
WOLFSSL_SEC_QORIQ_NO_CRYPTOCB
WOLFSSL_SEC_QORIQ_NO_PKHA
WOLFSSL_SEC_QORIQ_NO_RSA
WOLFSSL_SEC_QORIQ_SWAP_REGS
WOLFSSL_SERVER_EXAMPLE
WOLFSSL_SETTINGS_FILE
WOLFSSL_SGX_CPUID_AVX512_VAES
Expand Down
29 changes: 29 additions & 0 deletions CMakeLists.txt
Original file line number Diff line number Diff line change
Expand Up @@ -1660,6 +1660,10 @@ add_option("WOLFSSL_KEYGEN"
"Enable key generation (default: disabled)"
"no" "yes;no")

add_option("WOLFSSL_DH_GEN_PARAMS"
"Enable DH domain parameter generation with key generation -- protocols use the fixed FFDHE groups (default: enabled)"
"yes" "yes;no")

add_option("WOLFSSL_CERTGEN"
"Enable cert generation (default: disabled)"
"no" "yes;no")
Expand Down Expand Up @@ -3188,6 +3192,9 @@ endif()

if(WOLFSSL_KEYGEN)
list(APPEND WOLFSSL_DEFINITIONS "-DWOLFSSL_KEY_GEN")
if(NOT WOLFSSL_DH_GEN_PARAMS)
list(APPEND WOLFSSL_DEFINITIONS "-DWOLFSSL_NO_DH_GEN_PARAMS")
endif()
endif()
if(WOLFSSL_CERTGEN)
list(APPEND WOLFSSL_DEFINITIONS "-DWOLFSSL_CERT_GEN")
Expand Down Expand Up @@ -3268,6 +3275,28 @@ if (WOLFSSL_CAAM)
list(APPEND WOLFSSL_DEFINITIONS "-DWOLFSSL_CAAM")
endif()

# NXP QorIQ SEC (the PowerPC T-series security engine). The value selects
# the environment backend, mirroring --enable-sec-qoriq: "yes"/"baremetal"
# for a flat physically addressed target, "linux" for user space on a
# running kernel, "sim" for the host-runnable simulated backend the in-tree
# tests use.
add_option("WOLFSSL_SEC_QORIQ"
"Enable NXP QorIQ SEC engine, T1040/T2080 (default: disabled)"
"no" "yes;no;baremetal;linux;sim")
if (WOLFSSL_SEC_QORIQ AND NOT WOLFSSL_SEC_QORIQ STREQUAL "no")
list(APPEND WOLFSSL_DEFINITIONS "-DWOLFSSL_SEC_QORIQ")
if (WOLFSSL_SEC_QORIQ STREQUAL "linux")
set(WOLFSSL_SEC_QORIQ_LINUX "yes")
list(APPEND WOLFSSL_DEFINITIONS "-DWOLFSSL_SEC_QORIQ_LINUX")
elseif (WOLFSSL_SEC_QORIQ STREQUAL "sim")
set(WOLFSSL_SEC_QORIQ_SIM "yes")
list(APPEND WOLFSSL_DEFINITIONS "-DWOLFSSL_SEC_QORIQ_SIM")
else()
set(WOLFSSL_SEC_QORIQ_BAREMETAL "yes")
list(APPEND WOLFSSL_DEFINITIONS "-DWOLFSSL_SEC_QORIQ_BAREMETAL")
endif()
endif()

if (WOLFSSL_ARIA)
list(APPEND WOLFSSL_DEFINITIONS "-DHAVE_ARIA")
endif()
Expand Down
21 changes: 20 additions & 1 deletion cmake/functions.cmake
Original file line number Diff line number Diff line change
Expand Up @@ -359,7 +359,10 @@ function(generate_build_flags)
set(BUILD_MCAPI ${WOLFSSL_MCAPI} PARENT_SCOPE)
set(BUILD_ASYNCCRYPT ${WOLFSSL_ASYNCCRYPT} PARENT_SCOPE)
set(BUILD_WOLFEVENT ${WOLFSSL_ASYNCCRYPT} PARENT_SCOPE)
if(WOLFSSL_CRYPTOCB OR WOLFSSL_USER_SETTINGS)
if(WOLFSSL_CRYPTOCB OR WOLFSSL_USER_SETTINGS OR
(WOLFSSL_SEC_QORIQ AND NOT WOLFSSL_SEC_QORIQ STREQUAL "no"))
# settings.h forces WOLF_CRYPTO_CB on for the QorIQ SEC port, so the
# dispatcher source has to come along too.
set(BUILD_CRYPTOCB "yes" PARENT_SCOPE)
endif()
if(WOLFSSL_VAULTIC)
Expand Down Expand Up @@ -403,6 +406,9 @@ function(generate_build_flags)
if(WOLFSSL_CAAM)
set(BUILD_CAAM "yes" PARENT_SCOPE)
endif()
if(WOLFSSL_SEC_QORIQ AND NOT WOLFSSL_SEC_QORIQ STREQUAL "no")
set(BUILD_SEC_QORIQ "yes" PARENT_SCOPE)
endif()
if(WOLFSSL_HPKE OR WOLFSSL_USER_SETTINGS)
set(BUILD_HPKE "yes" PARENT_SCOPE)
endif()
Expand Down Expand Up @@ -1342,6 +1348,19 @@ function(generate_lib_src_list LIB_SOURCES)
list(APPEND LIB_SOURCES wolfcrypt/src/port/sealsq/vaultic.c)
endif()

if(BUILD_SEC_QORIQ)
list(APPEND LIB_SOURCES
wolfcrypt/src/port/nxp/sec_qoriq.c
wolfcrypt/src/port/nxp/sec_qoriq_cb.c
wolfcrypt/src/port/nxp/sec_qoriq_hash.c
wolfcrypt/src/port/nxp/sec_qoriq_aes.c
wolfcrypt/src/port/nxp/sec_qoriq_rng.c
wolfcrypt/src/port/nxp/sec_qoriq_pkha.c
wolfcrypt/src/port/nxp/sec_qoriq_baremetal.c
wolfcrypt/src/port/nxp/sec_qoriq_linux.c
wolfcrypt/src/port/nxp/sec_qoriq_sim.c)
endif()

if(BUILD_CAAM)
list(APPEND LIB_SOURCES
wolfcrypt/src/port/caam/wolfcaam_init.c
Expand Down
11 changes: 11 additions & 0 deletions cmake/options.h.in
Original file line number Diff line number Diff line change
Expand Up @@ -347,6 +347,9 @@ extern "C" {
#cmakedefine WOLFSSL_IP_ALT_NAME
#undef WOLFSSL_KEY_GEN
#cmakedefine WOLFSSL_KEY_GEN

#undef WOLFSSL_NO_DH_GEN_PARAMS
#cmakedefine WOLFSSL_NO_DH_GEN_PARAMS
#undef WOLFSSL_NO_ASM
#cmakedefine WOLFSSL_NO_ASM
#undef WOLFSSL_NO_SHAKE128
Expand All @@ -363,6 +366,14 @@ extern "C" {
#cmakedefine WOLFSSL_PUBLIC_MP
#undef WOLFSSL_QUIC
#cmakedefine WOLFSSL_QUIC
#undef WOLFSSL_SEC_QORIQ
#cmakedefine WOLFSSL_SEC_QORIQ
#undef WOLFSSL_SEC_QORIQ_BAREMETAL
#cmakedefine WOLFSSL_SEC_QORIQ_BAREMETAL
#undef WOLFSSL_SEC_QORIQ_LINUX
#cmakedefine WOLFSSL_SEC_QORIQ_LINUX
#undef WOLFSSL_SEC_QORIQ_SIM
#cmakedefine WOLFSSL_SEC_QORIQ_SIM
#undef WOLFSSL_SEND_HRR_COOKIE
#cmakedefine WOLFSSL_SEND_HRR_COOKIE
#undef WOLFSSL_SHA224
Expand Down
65 changes: 63 additions & 2 deletions configure.ac
Original file line number Diff line number Diff line change
Expand Up @@ -4977,6 +4977,40 @@ then
done
fi

# NXP QorIQ SEC (the PowerPC T-series security engine, a CAAM derivative).
# Takes a comma separated list selecting the environment backend, e.g.
# --enable-sec-qoriq=baremetal
# "sim" selects the host-runnable simulated backend used by the in-tree
# tests; it needs no hardware and runs on any architecture.
AC_ARG_ENABLE([sec-qoriq],
[AS_HELP_STRING([--enable-sec-qoriq],[Enable wolfSSL support for the NXP QorIQ SEC engine, T1040/T2080 (default: disabled)])],
[ ENABLED_SEC_QORIQ=$enableval ],
[ ENABLED_SEC_QORIQ=no ]
)

if test "$ENABLED_SEC_QORIQ" != "no"
then
AM_CFLAGS="$AM_CFLAGS -DWOLFSSL_SEC_QORIQ"

for v in `echo $ENABLED_SEC_QORIQ | tr "," " "`
do
case $v in
yes | baremetal)
AM_CFLAGS="$AM_CFLAGS -DWOLFSSL_SEC_QORIQ_BAREMETAL"
;;
linux)
AM_CFLAGS="$AM_CFLAGS -DWOLFSSL_SEC_QORIQ_LINUX"
;;
sim)
AM_CFLAGS="$AM_CFLAGS -DWOLFSSL_SEC_QORIQ_SIM"
;;
*)
AC_MSG_ERROR([Invalid choice for --enable-sec-qoriq: $v (want baremetal, linux or sim)])
;;
esac
done
fi

AC_ARG_ENABLE([caam],
[AS_HELP_STRING([--enable-caam],[Enable wolfSSL support for CAAM (default: disabled)])],
[ ENABLED_CAAM=$enableval ],
Expand Down Expand Up @@ -5804,11 +5838,36 @@ fi

# KEY GENERATION
AC_ARG_ENABLE([keygen],
[AS_HELP_STRING([--enable-keygen],[Enable key generation (only applies to RSA key generation) (default: disabled)])],
[AS_HELP_STRING([--enable-keygen],[Enable key generation. Takes yes, no, or a comma separated list of: all, no-dh-params (drop DH domain parameter generation, keeping DH key generation; protocols use the fixed FFDHE groups) (default: disabled)])],
[ ENABLED_KEYGEN=$enableval ],
[ ENABLED_KEYGEN=no ]
)

# Expand the list form of --enable-keygen into the individual sub-features.
ENABLED_DH_GEN_PARAMS=yes
if test "$ENABLED_KEYGEN" != "no" && test "$ENABLED_KEYGEN" != "yes"
then
for kg in `echo $ENABLED_KEYGEN | tr ',' ' '`
do
case $kg in
all)
;;
no-dh-params | nodhparams | nodhparamgen)
ENABLED_DH_GEN_PARAMS=no
;;
*)
AC_MSG_ERROR([Invalid choice for --enable-keygen: $kg. Use yes, no, all or no-dh-params.])
;;
esac
done
ENABLED_KEYGEN=yes
fi

if test "$ENABLED_DH_GEN_PARAMS" = "no"
then
AM_CFLAGS="$AM_CFLAGS -DWOLFSSL_NO_DH_GEN_PARAMS"
fi

if test "$ENABLED_BIND" = "yes" || test "$ENABLED_NTP" = "yes" || \
test "$ENABLED_LIBSSH2" = "yes" || test "$ENABLED_OPENRESTY" = "yes" || \
test "$ENABLED_NGINX" = "yes" || test "$ENABLED_WOLFENGINE" = "yes" || \
Expand Down Expand Up @@ -11995,7 +12054,7 @@ then
fi
fi

if test "x$ENABLED_PKCS11" = "xyes" || test "x$ENABLED_WOLFTPM" = "xyes" || test "$ENABLED_CAAM" != "no" || test "x$ENABLED_RTL8735B" != "xno" || test "x$ENABLED_SILABS_CRYPTOCB" != "xno" || test "x$ENABLED_VAULTIC" = "xyes"
if test "x$ENABLED_PKCS11" = "xyes" || test "x$ENABLED_WOLFTPM" = "xyes" || test "$ENABLED_CAAM" != "no" || test "$ENABLED_SEC_QORIQ" != "no" || test "x$ENABLED_RTL8735B" != "xno" || test "x$ENABLED_SILABS_CRYPTOCB" != "xno" || test "x$ENABLED_VAULTIC" = "xyes"
then
ENABLED_CRYPTOCB=yes
fi
Expand Down Expand Up @@ -14099,6 +14158,7 @@ AM_CONDITIONAL([BUILD_BENCHMARK],[test "$ENABLED_BENCHMARK" = "yes"])
AM_CONDITIONAL([BUILD_RC2],[test "x$ENABLED_RC2" = "xyes"])
AM_CONDITIONAL([BUILD_CUDA],[test "x$ENABLED_CUDA" = "xyes"])
AM_CONDITIONAL([BUILD_CAAM],[test "x$ENABLED_CAAM" != "xno"])
AM_CONDITIONAL([BUILD_SEC_QORIQ],[test "x$ENABLED_SEC_QORIQ" != "xno"])
AM_CONDITIONAL([BUILD_QNXCAAM],[test "x$ENABLED_CAAM_QNX" = "xyes"])
AM_CONDITIONAL([BUILD_CAAM_LINUX],[test "x$ENABLED_CAAM_LINUX" = "xyes"])
AM_CONDITIONAL([BUILD_IOTSAFE],[test "x$ENABLED_IOTSAFE" = "xyes"])
Expand Down Expand Up @@ -14525,6 +14585,7 @@ echo " * BLAKE2S: $ENABLED_BLAKE2S"
echo " * SipHash: $ENABLED_SIPHASH"
echo " * CMAC: $ENABLED_CMAC"
echo " * keygen: $ENABLED_KEYGEN"
echo " * DH parameter generation: $ENABLED_DH_GEN_PARAMS"
echo " * acert: $ENABLED_ACERT"
echo " * certgen: $ENABLED_CERTGEN"
echo " * certreq: $ENABLED_CERTREQ"
Expand Down
6 changes: 6 additions & 0 deletions src/pk.c
Original file line number Diff line number Diff line change
Expand Up @@ -4693,11 +4693,17 @@ int wolfSSL_DH_generate_parameters_ex(WOLFSSL_DH* dh, int prime_len,
}
}
if (ret == 1) {
#ifndef WOLFSSL_NO_DH_GEN_PARAMS
/* Generate parameters into internal DH key. */
if (wc_DhGenerateParams(rng, prime_len, key) != 0) {
WOLFSSL_ERROR_MSG("wc_DhGenerateParams error");
ret = 0;
}
#else
WOLFSSL_ERROR_MSG("DH parameter generation disabled in this build");
(void)prime_len;
ret = 0;
#endif
}

/* Free local random number generator if created. */
Expand Down
1 change: 1 addition & 0 deletions tests/api/test_dh.c
Original file line number Diff line number Diff line change
Expand Up @@ -1010,6 +1010,7 @@ int test_wc_DhGenerateParams_and_ExportRaw(void)
* generate-and-export flow below is only valid with the full SP math
* (WOLFSSL_SP_MATH_ALL), fastmath or heapmath backends. */
#if !defined(NO_DH) && defined(WOLFSSL_KEY_GEN) && !defined(WOLFSSL_SP_MATH) && \
!defined(WOLFSSL_NO_DH_GEN_PARAMS) && \
!defined(HAVE_SELFTEST) && !defined(HAVE_FIPS)
DhKey dh;
WC_RNG rng;
Expand Down
1 change: 1 addition & 0 deletions tests/api/test_evp_pkey.c
Original file line number Diff line number Diff line change
Expand Up @@ -1203,6 +1203,7 @@ int test_wolfSSL_EVP_PKEY_copy_parameters(void)
{
EXPECT_DECLS;
#if defined(OPENSSL_EXTRA) && !defined(NO_DH) && defined(WOLFSSL_KEY_GEN) && \
!defined(WOLFSSL_NO_DH_GEN_PARAMS) && \
!defined(HAVE_SELFTEST) && defined(WOLFSSL_DH_EXTRA) && \
(defined(OPENSSL_ALL) || defined(WOLFSSL_QT)) && !defined(NO_FILESYSTEM)
WOLFSSL_EVP_PKEY* params = NULL;
Expand Down
10 changes: 9 additions & 1 deletion tests/api/test_ossl_dh.c
Original file line number Diff line number Diff line change
Expand Up @@ -171,11 +171,19 @@ int test_wolfSSL_DH(void)
DH_free(dh);
dh = NULL;

#ifdef WOLFSSL_KEY_GEN
#if defined(WOLFSSL_KEY_GEN) && !defined(WOLFSSL_NO_DH_GEN_PARAMS)
ExpectNotNull(dh = DH_generate_parameters(2048, 2, NULL, NULL));
ExpectIntEQ(wolfSSL_DH_generate_parameters_ex(NULL, 2048, 2, NULL), 0);
DH_free(dh);
dh = NULL;
#elif defined(WOLFSSL_KEY_GEN)
/* Domain parameter generation is compiled out: the calls must fail
* cleanly on a valid DH object rather than generate. */
ExpectNull(dh = DH_generate_parameters(2048, 2, NULL, NULL));
ExpectNotNull(dh = wolfSSL_DH_new());
ExpectIntEQ(wolfSSL_DH_generate_parameters_ex(dh, 2048, 2, NULL), 0);
DH_free(dh);
dh = NULL;
#endif
#endif /* !HAVE_FIPS || (HAVE_FIPS_VERSION && HAVE_FIPS_VERSION > 2) */
#endif /* OPENSSL_ALL */
Expand Down
Loading
Loading