Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 8 additions & 1 deletion .github/configs/os-check-linux.json
Original file line number Diff line number Diff line change
Expand Up @@ -533,5 +533,12 @@
"--disable-oldtls", "--disable-examples", "CPPFLAGS=-DWOLFSSL_NO_TLS12"]},
{"name": "tls13-sha512-runtime", "minutes": 1.6,
"comment": "--enable-tls13-sha512 with TLS 1.2 left in, so the examples and unit tests build and run with WOLFSSL_HS_HASH_SHA512 set. No cipher suite sets mac_algorithm to sha512_mac, so the sha512_mac arms in src/tls13.c stay unreached; what this entry proves is that the option does not break an otherwise ordinary build, which the two compile-only entries above cannot show.",
"configure": ["--enable-tls13", "--enable-tls13-sha512", "--enable-sha512"]}
"configure": ["--enable-tls13", "--enable-tls13-sha512", "--enable-sha512"]},
{"name": "cryptonly-sha3-keyid", "minutes": 0.8,
"comment": "SHA3 as the only hash family that can derive key identifiers: no SHA-1 and no SHA-256, so HashIdAlg()/CalcHashId_ex() must pick SHA3-256 and KEYID_SIZE must follow it. SHA-512 is kept only because the Hash DRBG needs it. The CERT KEYID subtest checks the SKID/AKID sizes the generator writes against CTC_MAX_SKID_SIZE.",
"configure": ["--enable-cryptonly", "--enable-ecc", "--enable-certgen",
"--enable-certreq", "--enable-certext", "--enable-sha3", "--enable-sha512",
"--disable-sha", "--disable-sha256", "--disable-sha224", "--disable-rsa",
"--disable-dh",
"CPPFLAGS=-DWOLFSSL_DRBG_SHA512 -DUSE_CERT_BUFFERS_256"]}
]
61 changes: 61 additions & 0 deletions .github/workflows/cmake.yml
Original file line number Diff line number Diff line change
Expand Up @@ -111,6 +111,67 @@ jobs:
cd ..
rm -rf build

# Option plumbing: a declared option must reach both the library and
# options.h, and a -D that is not an option must reach neither.
- name: Check option to options.h plumbing
run: |
mkdir build
cd build
cmake -DWOLFSSL_CRYPT_ONLY=yes .. 2>&1 | tee cfg.log
grep -q '^#define WOLFCRYPT_ONLY$' wolfssl/options.h
grep -q '^#define NO_TLS$' wolfssl/options.h
# TLS-layer options default off, as with --enable-cryptonly, but the
# TLS 1.3 KDFs stay.
! grep -q '^#define HAVE_SNI$' wolfssl/options.h
! grep -q '^#define WOLFSSL_DTLS$' wolfssl/options.h
grep -q '^#define WOLFSSL_TLS13$' wolfssl/options.h
! grep -q 'is not a wolfSSL build option' cfg.log
cmake --build .

cd ..
rm -rf build
mkdir build
cd build
# Adding cryptonly to a directory configured without it must take the
# TLS layer out too, not leave the previous defaults cached.
cmake .. > /dev/null
grep -q '^#define HAVE_SNI$' wolfssl/options.h
cmake -DWOLFSSL_CRYPT_ONLY=yes .. > /dev/null
! grep -q '^#define HAVE_SNI$' wolfssl/options.h
grep -q '^#define NO_TLS$' wolfssl/options.h

cd ..
rm -rf build
mkdir build
cd build
# Cryptonly wins over a TLS-layer option asked for alongside it.
cmake -DWOLFSSL_CRYPT_ONLY=yes -DWOLFSSL_DTLS=yes .. > /dev/null
! grep -q '^#define WOLFSSL_DTLS$' wolfssl/options.h

cd ..
rm -rf build
mkdir build
cd build
# An option declared with a raw CACHE entry rather than add_option must
# survive the stray-define guard, including across a reconfigure.
cmake -DWOLFSSL_HARDEN_TLS=128 .. 2>&1 | tee cfg.log
grep -q '^#define WOLFSSL_HARDEN_TLS 128$' wolfssl/options.h
! grep -q 'is not a wolfSSL build option' cfg.log
cmake . > /dev/null
grep -q '^#define WOLFSSL_HARDEN_TLS 128$' wolfssl/options.h

cd ..
rm -rf build
mkdir build
cd build
# WOLFSSL_STATICMEMORY is the option; this spelling is not one.
cmake -DWOLFSSL_STATIC_MEMORY=yes .. 2>&1 | tee cfg.log
grep -q 'WOLFSSL_STATIC_MEMORY is not a wolfSSL build option' cfg.log
! grep -q '^#define WOLFSSL_STATIC_MEMORY$' wolfssl/options.h

cd ..
rm -rf build

# CMake build with user_settings.h
- name: Build wolfssl with user_settings.h
run: |
Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/no-malloc.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,3 @@
name: No Malloc Tests

# START OF COMMON SECTION
Expand Down Expand Up @@ -99,7 +99,8 @@
"run": [["./wolfcrypt/test/testwolfcrypt"]]},
{"name": "no-heap-cert", "minutes": 0.8,
"configure": ["--enable-rsa", "--enable-keygen", "--enable-ecc",
"--enable-acert", "--disable-dh", "--disable-filesystem",
"--enable-acert", "--enable-certgen", "--enable-certreq",
"--enable-certext", "--disable-dh", "--disable-filesystem",
"CFLAGS=-DWOLFSSL_NO_MALLOC -DNO_WOLFSSL_MEMORY -DRSA_MIN_SIZE=1024 -DWOLFSSL_TEST_CERT -DUSE_CERT_BUFFERS_2048 -DUSE_CERT_BUFFERS_256 -pedantic -Wdeclaration-after-statement -Wnull-dereference -DTEST_LIBWOLFSSL_SOURCES_INCLUSION_SEQUENCE"],
"check": false,
"run": [["./wolfcrypt/test/testwolfcrypt"]]}
Expand Down
74 changes: 74 additions & 0 deletions CMakeLists.txt
Original file line number Diff line number Diff line change
Expand Up @@ -632,6 +632,35 @@ if(WOLFSSL_DEBUG)
endif()


# wolfCrypt only (no TLS). Declared ahead of the TLS-layer options so the
# forces below land before their add_option() calls.
add_option("WOLFSSL_CRYPT_ONLY"
"Enable wolfCrypt Only build (default: disabled)"
"no" "yes;no")

if(WOLFSSL_CRYPT_ONLY)
list(APPEND WOLFSSL_DEFINITIONS "-DWOLFCRYPT_ONLY")
# Mirror --enable-cryptonly: turn the TLS-layer options off so options.h
# describes the library that was built. These are forced rather than
# defaulted, because a cache entry cannot be told apart from an explicit
# setting on a reconfigure, and a header claiming a TLS feature that has
# no TLS layer behind it is the failure this is here to prevent.
# WOLFSSL_TLS carries -DNO_TLS itself, and the TLS-version checks read it
# to know a cryptonly build has no handshake. TLS 1.2 and 1.3 stay
# enabled -- their KDFs are wolfCrypt-layer code a cryptonly build wants.
foreach(_o WOLFSSL_TLS
WOLFSSL_ALPN WOLFSSL_CRL_MONITOR WOLFSSL_DTLS WOLFSSL_DTLS13
WOLFSSL_DTLS_CH_FRAG WOLFSSL_DTLS_CID WOLFSSL_DTLS_MTU
WOLFSSL_EARLYDATA WOLFSSL_ECH WOLFSSL_MCAST WOLFSSL_OCSP
WOLFSSL_OCSPSTAPLING WOLFSSL_OCSPSTAPLING_V2
WOLFSSL_PKCALLBACKS WOLFSSL_QUIC
WOLFSSL_RENEGOTIATION_INDICATION WOLFSSL_SECURE_RENEGOTIATION
WOLFSSL_SNI WOLFSSL_SRTP WOLFSSL_TLSX)
force_option(${_o} "no")
endforeach()
message(STATUS "WOLFSSL_CRYPT_ONLY: TLS layer off, including its options")
endif()

# Single threaded
add_option("WOLFSSL_SINGLE_THREADED"
"Enable wolfSSL single threaded (default: disabled)"
Expand Down Expand Up @@ -4547,6 +4576,51 @@ endforeach()
# both emitting the same feature define).
list(REMOVE_DUPLICATES WOLFSSL_DEFINITIONS)

# A -D the user passed that is not a build option still satisfies the
# matching #cmakedefine below, yielding an options.h that claims features the
# library was not compiled with -- the classic case being WOLFSSL_STATIC_MEMORY
# for the WOLFSSL_STATICMEMORY option. Drop those before the header is
# generated.
get_property(WOLFSSL_DECLARED_OPTIONS GLOBAL PROPERTY WOLFSSL_DECLARED_OPTIONS)
get_cmake_property(WOLFSSL_CACHE_VARS CACHE_VARIABLES)
file(STRINGS "${CMAKE_CURRENT_SOURCE_DIR}/cmake/options.h.in" OPTIONS_H_LINES
REGEX "^#cmakedefine[ \t]+[A-Za-z_]")
foreach(LINE IN LISTS OPTIONS_H_LINES)
string(REGEX REPLACE "^#cmakedefine[ \t]+([A-Za-z_][A-Za-z0-9_]*).*$" "\\1"
MACRO_NAME "${LINE}")
# Only wolfSSL's own namespace: everything else in options.h.in is a
# system probe (HAVE_LIMITS_H and friends) that the project sets itself.
if(NOT MACRO_NAME MATCHES "^WOLF")
continue()
endif()
if(MACRO_NAME IN_LIST WOLFSSL_DECLARED_OPTIONS)
continue()
endif()
if(NOT MACRO_NAME IN_LIST WOLFSSL_CACHE_VARS)
continue()
endif()
# Already compiled into the library, so it is a real option however its
# cache entry was made (WOLFSSL_HARDEN_TLS uses a raw CACHE STRING to keep
# an out-of-range value for validation).
set(MACRO_IN_DEFS FALSE)
foreach(DEF IN LISTS WOLFSSL_DEFINITIONS)
if(DEF MATCHES "^-D${MACRO_NAME}(=.*)?$")
set(MACRO_IN_DEFS TRUE)
break()
endif()
endforeach()
if(MACRO_IN_DEFS)
continue()
endif()
if(${MACRO_NAME})
message(WARNING "${MACRO_NAME} is not a wolfSSL build option; ignoring "
"it so that wolfssl/options.h matches the library. Run "
"`cmake -LH` for the option list.")
unset(${MACRO_NAME})
unset(${MACRO_NAME} CACHE)
endif()
endforeach()

foreach(DEF IN LISTS WOLFSSL_DEFINITIONS)
string(REGEX MATCH "^(-D)?([^=]+)(=(.*))?$" DEF_MATCH ${DEF})
if (NOT "${CMAKE_MATCH_4}" STREQUAL "")
Expand Down
3 changes: 3 additions & 0 deletions IDE/GCC-ARM/Header/user_settings.h
Original file line number Diff line number Diff line change
Expand Up @@ -537,6 +537,9 @@ extern unsigned int my_rng_seed_gen(void);
#define XSTRNCASECMP(s1,s2,n) strncasecmp((s1),(s2),(n))

#define XSNPRINTF snprintf

#include <stdlib.h>
#define XATOI(s) atoi((s))
#endif


Expand Down
3 changes: 3 additions & 0 deletions IDE/SimplicityStudio/user_settings.h
Original file line number Diff line number Diff line change
Expand Up @@ -454,6 +454,9 @@ extern "C" {
#define XSTRNCASECMP(s1,s2,n) strncasecmp((s1),(s2),(n))

#define XSNPRINTF snprintf

#include <stdlib.h>
#define XATOI(s) atoi((s))
#endif


Expand Down
3 changes: 3 additions & 0 deletions IDE/WICED-STUDIO/user_settings.h
Original file line number Diff line number Diff line change
Expand Up @@ -531,6 +531,9 @@ extern unsigned int my_rng_seed_gen(void);
#define XSTRNCASECMP(s1,s2,n) strncasecmp((s1),(s2),(n))

#define XSNPRINTF snprintf

#include <stdlib.h>
#define XATOI(s) atoi((s))
#endif


Expand Down
3 changes: 3 additions & 0 deletions IDE/WINCE/user_settings.h
Original file line number Diff line number Diff line change
Expand Up @@ -662,6 +662,9 @@ C149F3285397DFBD0C6720E14818475C3A50B10880EF9619463173A6D5ED15E7
#define XSTRNCASECMP(s1,s2,n) strncasecmp((s1),(s2),(n))

#define XSNPRINTF snprintf

#include <stdlib.h>
#define XATOI(s) atoi((s))
#endif


Expand Down
3 changes: 3 additions & 0 deletions IDE/XCODE-FIPSv2/macOS-C++/Intel/user_settings.h
Original file line number Diff line number Diff line change
Expand Up @@ -528,6 +528,9 @@ extern "C" {
#define XSTRNCASECMP(s1,s2,n) strncasecmp((s1),(s2),(n))

#define XSNPRINTF snprintf

#include <stdlib.h>
#define XATOI(s) atoi((s))
#endif


Expand Down
3 changes: 3 additions & 0 deletions IDE/XCODE-FIPSv2/macOS-C++/M1/user_settings.h
Original file line number Diff line number Diff line change
Expand Up @@ -539,6 +539,9 @@ extern "C" {
#define XSTRNCASECMP(s1,s2,n) strncasecmp((s1),(s2),(n))

#define XSNPRINTF snprintf

#include <stdlib.h>
#define XATOI(s) atoi((s))
#endif


Expand Down
3 changes: 3 additions & 0 deletions IDE/XCODE-FIPSv2/user_settings.h
Original file line number Diff line number Diff line change
Expand Up @@ -540,6 +540,9 @@ extern "C" {
#define XSTRNCASECMP(s1,s2,n) strncasecmp((s1),(s2),(n))

#define XSNPRINTF snprintf

#include <stdlib.h>
#define XATOI(s) atoi((s))
#endif


Expand Down
3 changes: 3 additions & 0 deletions IDE/XCODE-FIPSv5/user_settings.h
Original file line number Diff line number Diff line change
Expand Up @@ -621,6 +621,9 @@ extern "C" {
#define XSTRNCASECMP(s1,s2,n) strncasecmp((s1),(s2),(n))

#define XSNPRINTF snprintf

#include <stdlib.h>
#define XATOI(s) atoi((s))
#endif


Expand Down
3 changes: 3 additions & 0 deletions IDE/XCODE-FIPSv6/user_settings.h
Original file line number Diff line number Diff line change
Expand Up @@ -681,6 +681,9 @@ extern "C" {
#define XSTRNCASECMP(s1,s2,n) strncasecmp((s1),(s2),(n))

#define XSNPRINTF snprintf

#include <stdlib.h>
#define XATOI(s) atoi((s))
#endif


Expand Down
4 changes: 4 additions & 0 deletions cmake/functions.cmake
Original file line number Diff line number Diff line change
Expand Up @@ -39,6 +39,10 @@ function(wolfssl_warn_unconsumed_forces)
endfunction()

function(add_option NAME HELP_STRING DEFAULT VALUES)
# Record the name so a -D that is not a build option can be told apart
# from one that is. See the options.h.in guard in CMakeLists.txt.
set_property(GLOBAL APPEND PROPERTY WOLFSSL_DECLARED_OPTIONS "${NAME}")

if(VALUES STREQUAL "yes;no")
# Set the default value for the option.
set(${NAME} ${DEFAULT} CACHE BOOL ${HELP_STRING})
Expand Down
2 changes: 2 additions & 0 deletions cmake/options.h.in
Original file line number Diff line number Diff line change
Expand Up @@ -696,6 +696,8 @@ extern "C" {
#cmakedefine WOLFSSL_STATIC_MEMORY_LEAN
#undef WOLFSSL_STATIC_MEMORY_DEBUG_CALLBACK
#cmakedefine WOLFSSL_STATIC_MEMORY_DEBUG_CALLBACK
#undef WOLFCRYPT_ONLY
#cmakedefine WOLFCRYPT_ONLY
#undef NO_TLS
#cmakedefine NO_TLS
#undef NO_SHA256
Expand Down
3 changes: 3 additions & 0 deletions examples/configs/user_settings_template.h
Original file line number Diff line number Diff line change
Expand Up @@ -487,6 +487,9 @@ extern "C" {
#define XSTRNCASECMP(s1,s2,n) strncasecmp((s1),(s2),(n))

#define XSNPRINTF snprintf

#include <stdlib.h>
#define XATOI(s) atoi((s))
#endif


Expand Down
Loading
Loading