Commit b41d12c
authored
Add CI that builds and runs every example (#598)
* Regenerate the CRL that expired in September 2025
* Refresh the expired certificates embedded in certloadverifybuffer
* Return 0 from tls servers that returned a wolfSSL_write byte count
* Send a client certificate from client-tls and client-tls13-resume
* Return 0 from certverify instead of WOLFSSL_SUCCESS
* Give the XTS demo key two different halves
* Exit success after ml_dsa prints its parameter table
* Report failure from the custom io file client and server
* Latch failures across every ecc-params curve lookup
* Ignore SIGPIPE in the btle fifo transport
* Fix the dtls rw-threads certificate paths
* Make runall.sh fail when an example fails
* Make openssl-verify.sh actually verify and actually fail
* Raise the generate_ssl.sh common name length limit
* Port the PQ examples to the current wolfSSL API
* Return 0 from csr_w_ed25519_example and rsa-public-decrypt-app
* Build the x509_acert openssl example against the right headers
* Give the examples Makefiles a consistent wolfSSL prefix
* Fix the double free and NULL derefs in the custom io cleanup paths
* Stop forcing the ESP32 examples to include a developer private config
* Add the missing WiFi Kconfig to the DTLS13 station examples
* Use XSTRLCPY in client-dtls13 since wolfSSL has no XSTRCPY
* Make the DTLS13 example ctx static so it stops colliding with libnet80211
* Set SO_REUSEADDR on the tls servers that lacked it
* Give puf the wolfSSL sources and stop building the IDF 4.4 only ENC28J60 examples
* Set SO_REUSEADDR on server-tcp as well
* Exit the can-bus client on EOF and give it real input in CI
* Re-arm the select timeout each pass in the nonblocking dtls server
* Keep the shared memory BIOs alive until both sides are done
* Port the ebpf tracers to the libbpf 1.0 perf_buffer__new signature
* Clone wolfSSL before make builds its graph so uefi-static builds from a clean tree
* Raise wolfcryptjni compileSdk to 32 for the BigInteger API its submodule uses
* Link wolfentropy.o and keep wc_port socket helpers out of the UEFI build
* Track the wolfSSL dilithium.c to wc_mldsa.c rename and drop a stale java import
* Move uefi-library to the wc_MlDsa API after the wolfSSL dilithium rename
* Declare the launcher activity exported, required from API 31
* Configure wolfSSL before make in the fullstack setup script
* Track the wolfSSL io.c to wolfio.c rename in the ndk sample
* Keep glibc headers out of the freestanding uefi-library build
* Track the wolfSSL mlkem.h rename and give RT1060 the SDK name it selects on
* Track the wolfIP struct ll rename and pin wolfIP to its v1.0 release
* Use getaddrinfo in the ndk sample since bionic does not declare gethostbyname
* Cross compile RT1060 with arm-none-eabi and document the SDK value the Makefile matches
* Enable wolfIP HTTP so its httpd.h actually declares the API the example calls
* Define HAVE_NETDB_H so wolfio.c includes the header its getaddrinfo path needs
* Link pkcs12.o, which RT1060 enables by default and wolfcrypt test calls
* Port the ENC28J60 examples to the ESP-IDF 5.x ethernet API
* Compile dtls.c in the ndk sample, which enables WOLFSSL_DTLS
* Define the PHY identifier registers the removed IDF header supplied
* Compile kdf.c in the ndk sample for the TLS PRF
* Give RT1060 a current_time so the benchmark stops needing clock_gettime
* Port the ENC28J60 PHY to the IDF 5.x autonego_ctrl vtable
* Remove the ENC28J60 server's duplicate driver copy that main already builds
* Return the DTLS server to accept on close_notify so a resume is heard
* Run the C# pq client/server pair under mono
* Define WOLFSSL_CERT_REQ so the ndk-gradle app links wolfssljni's X509_REQ calls
* Refresh the expired client ECC DER certificate
* Add CI that builds and runs every example against wolfSSL master and stable
* Sign OCSP staples with a responder intermediate1 actually delegated
* Report a failing PKCS#11 example instead of always exiting 0
* Link the PSA library the README's PSA_LIB_PATH names
* Widen the mynewt pointer prints so they build on a 64 bit native BSP
* Test RSA under UEFI with a 2048 bit key so it clears wolfSSL's minimum
* Left pad the ECDSA r and s so a leading zero cannot shift the signature
* Document the smime and indef flags the pkcs7 examples need
* Fail ecc-verify when the signature does not verify
* Fail ecc-sign when a round produces an invalid signature
* Fail aesgcm-file-encrypt when its sanity test does not pass
* Check that ML-KEM derives the same shared secret on both sides
* Fail ecdh_gen_secret when the two sides derive different secrets
* Return the DH key agreement error instead of always exiting 0
* Retry the fullstack HTTPS probe so a slow sim start does not fail it
* Confirm the custom-io file transfer succeeded so CI can assert it
* Print a success line from the silent file-encrypt and ecc-export examples
* Add device-sims job running ATECC608 STSAFE and TROPIC01 sim wolfcrypt tests
* Extend device-sims to STM32 and PIC32MZ for the full sim fleet
* Mount wolfSSL for the STM32 and PIC32MZ sim wolfcrypt runs
* Accept the zero success return from wolfSSL_CTX_set_max_early_data
* Read the earlydata reply so the client processes the session ticket before resuming
* Read the earlydata reply in the DTLS client so it processes the session ticket
* Run the tls13 and dtls13 earlydata pairs now that the clients process the ticket
* Let expect_fail clear on refs that carry the fix via a fixed_on marker
* Retry the PSA TLS 1.3 handshake so an intermittent ECC reject does not fail CI
* Retry network fetches across CI so a transient blip does not fail a job
* Normalize do_ecc and do_25519 exit codes like do_448 so an error is never masked to 0
* Build and run the merged-in hsm dtls_client example in CI via a dedicated hsm.yml job
* Add a make check target to each applicable example
* Run only the example and lint smoke set on draft PRs
* Only run a per-target workflow when its own example dir changes
* Assert the real se050 wolfcrypt result instead of an early sub-test line
* Size the RSA 2048 key export buffers so the UEFI test does not fail on BUFFER_E
* Call the always-present MLDSA context API from the UEFI driver
* Cross uefi-static and uefi-library with both wolfSSL refs in the matrix
* Give each tpm matrix leg a ref-unique results file and artifact
* Add a codespell spellcheck pass to the lint job
* Run push CI on master only so a PR branch does not double-trigger
* Select valgrind by caller_run_id since event_name is the caller under workflow_call
* Make example check targets catch real failures with pipefail exit checks and inputs
* Wire the harness to run make check for mode check examples starting with ecc
* Migrate the single-entry exec examples to mode check and fold their inputs into the check targets
* Fix four make check assertions that misfired under pipefail
* Give the tpm manifest entry a run step so it asserts output
* Skip uefi-static in the lint make -n loop so it does not clone
* Assert the actual verify result in the pkcs7 and rsa-nb checks
* Return nonzero from pkcs12-create-example on a failed create so the check is not a false pass
* Return nonzero from rsa-kg on any key generate or write failure
* Assert the static memory checks by exit code instead of a pipefail grep that BSD make lacks
* Run pkcs7 signedData stream through make check so it asserts the real verify result
* Check DER certificates and CRLs in the expiry canary too
* Feed the wolfHSM client its stdin so run_client actually exchanges data
* Assert every make check by exit code and captured output instead of a pipefail grep so they hold under BSD make1 parent c586428 commit b41d12c
215 files changed
Lines changed: 9790 additions & 2994 deletions
File tree
- .github
- actions
- apt-update
- setup-wolfssl
- scripts
- workflows
- CSharp
- ESP32
- DTLS13-wifi-station-client/main
- include
- DTLS13-wifi-station-server/main
- include
- TLS13-ENC28J60-client/main
- TLS13-ENC28J60-server
- components/eth_enc28j60
- main
- TLS13-wifi_station-client/main
- TLS13-wifi_station-server/main
- RT1060
- SE050/wolfssl/wolfcrypt_test
- SGX_Linux
- X9.146
- android
- wolfcryptjni-ndk-gradle/app
- src/main
- wolfssljni-ndk-gradle/app
- wolfssljni-ndk-sample/jni
- btle/common
- can-bus
- certfields
- all-fields
- extendedKeyUsage
- extract-pubkey-from-certfile
- keyUsage
- certgen
- certmanager
- certstore
- certs
- crl
- certvfy
- crypto
- 3des
- aes-modes
- aes
- rdseed
- ascon
- camellia
- keywrap
- pkcs12
- custom-io-callbacks
- file-client
- file-server
- dtls
- ebpf
- syscall-write-trace
- tls-uprobe-trace
- ecc
- embedded
- fullstack/freertos-wolfip-wolfssl-https
- src
- hash
- java/https-url
- mynewt
- ocsp
- responder
- stapling
- client-certs
- responder-certs
- server-certs
- pkcs11
- pkcs7
- scripts
- pk
- curve25519
- dh-pg
- ecc
- ecdh_generate_secret
- ed25519_gen
- ed25519
- ed448
- enc-through-sign-rsa
- hpke
- rsa-kg
- rsa-pss
- rsa
- srp
- test_cert_and_private_keypair
- pq
- ml_dsa
- ml_kem
- stateful_hash_sig
- psa
- scripts
- signature
- ecc-sign-verify
- rsa_buffer
- rsa_vfy_only
- sigtest
- staticmemory
- memory-bucket-optimizer
- optimizer
- tester
- tls
- uefi-library
- src
- uefi-static
- x509_acert
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
0 commit comments