Skip to content

wolfCrypt: support zero-malloc cert encoding and clean up CMake/platform defines - #11625

Open
dgarske wants to merge 4 commits into
wolfSSL:masterfrom
dgarske:cryptonly_nomalloc
Open

dgarske wants to merge 4 commits into
wolfSSL:masterfrom
dgarske:cryptonly_nomalloc

Conversation

@dgarske

@dgarske dgarske commented Oct 1, 2026

Copy link
Copy Markdown
Member

Description

Four independent CMake and wolfCrypt fixes for WOLFSSL_NO_MALLOC bare-metal builds.

Changes

  • CMake: Add WOLFCRYPT_ONLY option & filter stray cache defines
    • Declared WOLFCRYPT_ONLY CMake option emitting -DWOLFCRYPT_ONLY and -DNO_TLS (matching --enable-cryptonly).
    • Filtered undeclared/stray WOLF* CMake cache variables to prevent macro pollution in options.h (e.g., -DWOLFSSL_STATIC_MEMORY=yes).
  • ASN: Zero-allocation CSR/cert encoding (WOLFSSL_NO_MALLOC)
    • Updated wc_MakeCertReq_ex(), wc_MakeCert(), and SetKeyIdFromPublicKey() to use stack-based arrays bounded by WC_ASN_MAX_NAME_ENTRIES and MAX_PUBLIC_KEY_SZ.
  • ASN: Dynamic SKID/AKID buffer sizing & hash selection
    • Unified hash selection (asn_public.h) for key IDs across SHA-1, SHA-256, and SHA-3.
    • Sized CTC_MAX_SKID_SIZE and CTC_MAX_AKID_SIZE based on active hash family (32-byte minimum) and fixed wc_Sha256Hash compile failures when SHA-256 is disabled.
  • Types: Define XATOI under STRING_USER and platform templates
    • Ensured XATOI fallback is available under STRING_USER and added explicit definitions to platform templates (IDE/WICED-STUDIO, etc.) to prevent missing macro errors during OID parsing.

Testing

  • Added cryptonly-sha3-keyid and certreq_no_malloc_test() to CI; verified zero-alloc P-256 CSR generation and parsing.
  • Verified CMake WOLFCRYPT_ONLY defaults, macro output against ./configure, and warning behavior on stray cache variables.
  • Tested no-heap-cert CI configuration and platform template compilation with STRING_USER.

@dgarske dgarske self-assigned this Oct 1, 2026
Copilot AI balanced review requested due to automatic review settings October 1, 2026 20:21

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Crypt-only CMake state and extended-key-usage encoding remain incorrect for supported configurations.

Review effort: Balanced
Findings: 3 Medium severity

Open (3)
What changed in this PR

Adds no-heap certificate encoding support, configurable key-ID hashing, CMake crypt-only handling, and XATOI platform fallbacks.

Changes:

  • Uses bounded stack buffers for certificate names and key identifiers.
  • Adds SHA-3 key-ID support and dynamic SKID/AKID sizing.
  • Adds CMake crypt-only plumbing, cache filtering, platform macros, and CI coverage.
File Description
wolfssl/​wolfcrypt/​types.h Adds XATOI fallback for STRING_USER.
wolfssl/​wolfcrypt/​asn.h Uses configured key-ID size.
wolfssl/​wolfcrypt/​asn_public.h Selects key-ID hash and buffer sizes.
wolfcrypt/​src/​asn.c Adds stack-based certificate encoding paths.
wolfcrypt/​test/​test.c Tests no-heap CSR and key IDs.
IDE/​XCODE-FIPSv6/​user_settings.h Defines XATOI.
IDE/​XCODE-FIPSv5/​user_settings.h Defines XATOI.
IDE/​XCODE-FIPSv2/​user_settings.h Defines XATOI.
IDE/​XCODE-FIPSv2/​macOS-C++/​M1/​user_settings.h Defines XATOI.
IDE/​XCODE-FIPSv2/​macOS-C++/​Intel/​user_settings.h Defines XATOI.
IDE/​WINCE/​user_settings.h Defines XATOI.
IDE/​WICED-STUDIO/​user_settings.h Defines XATOI.
IDE/​SimplicityStudio/​user_settings.h Defines XATOI.
IDE/​GCC-ARM/​Header/​user_settings.h Defines XATOI.
examples/​configs/​user_settings_template.h Documents the platform fallback.
CMakeLists.txt Adds crypt-only and cache filtering logic.
cmake/​options.h.in Emits crypt-only macros.
cmake/​functions.cmake Tracks declared CMake options.
.github/​workflows/​no-malloc.yml Expands no-heap certificate coverage.
.github/​workflows/​cmake.yml Tests CMake option plumbing.
.github/​configs/​os-check-linux.json Adds SHA-3 key-ID coverage.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread CMakeLists.txt Outdated
Comment thread CMakeLists.txt Outdated
Comment thread wolfcrypt/src/asn.c

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Crypt-only multicast forcing is ineffective, and SHA3-only OCSP hashing remains inconsistent.

Review effort: Balanced
Findings: 2 Medium severity

Open (2)
Resolved since last review (3)

Comment thread CMakeLists.txt
foreach(_o WOLFSSL_TLS
WOLFSSL_ALPN WOLFSSL_CRL_MONITOR WOLFSSL_DTLS WOLFSSL_DTLS13
WOLFSSL_DTLS_CH_FRAG WOLFSSL_DTLS_CID WOLFSSL_DTLS_MTU
WOLFSSL_EARLYDATA WOLFSSL_ECH WOLFSSL_MCAST WOLFSSL_OCSP
Comment on lines +141 to +143
#elif defined(WOLFSSL_SHA3) && !defined(WOLFSSL_NOSHA3_256)
#define WC_ASN_KEYID_HASH_SHA3_256
#define WC_ASN_KEYID_SZ 32 /* WC_SHA3_256_DIGEST_SIZE */
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants