Commit Graph
5015 Commits
Author SHA1 Message Date
Tobias Frauenschläger d7a5e85716 Add negative test for Ed448 signature S-range check
Ed448 verification rejects a non-canonical signature scalar S (S >= L)
per RFC 8032, and that range check is the only guard against a malleated
signature: because L times the base point is the identity, (R, S + L)
recomputes the same R and would otherwise verify. The check had no
negative coverage, so a deletion or boundary mutation passed the suite
while all canonical KAT signatures kept working.

Add a test that signs a message, then verifies crafted signatures whose
S half equals the order, exceeds it in a high or low byte, and equals
S + L, asserting BAD_FUNC_ARG, plus an in-range wrong S asserting
SIG_VERIFY_E.

Fixes F-6777.
2026-08-01 13:13:00 +02:00
Tobias Frauenschläger 4c05429fb0 Add negative tests for wc_ecc_check_key public-key checks
wc_ecc_check_key validates a public key's coordinate range, that the
point is on the curve, and its order, but the software path had no
negative coverage: the existing test only exercised a valid key and
NULL, and the off-curve case lived in the crypto-callback test, which
validates the device path rather than the software on-curve check. A
deletion of either the on-curve check or the coordinate-range checks
therefore passed the suite.

Add a test that imports secp256r1 public keys that are off the curve
and out of coordinate range, asserting IS_POINT_E and ECC_OUT_OF_RANGE_E
respectively, exercising the software validation path.

Fixes F-6620.
2026-08-01 13:13:00 +02:00
Tobias Frauenschläger fd13b11755 Use random-witness primality test for untrusted DH modulus
wc_DhSetKey_ex loads DH parameters as untrusted and validates that the
modulus is prime, but it passed no RNG, so the check fell back to a
Miller-Rabin test using the fixed small-prime bases 2 through 19. That
test is defeatable: a composite crafted as a strong pseudoprime to those
known bases passes as prime, letting an attacker supply a composite
modulus with a smooth factorization for small-subgroup recovery of the
private exponent and shared secret.

When no RNG is supplied on the untrusted path, create a temporary RNG so
mp_prime_is_prime_ex runs with random witnesses, which such crafted
composites cannot reliably pass. Named FFDHE primes still short-circuit
the check, and builds without an RNG keep the deterministic test.

Fixes F-6776.
2026-08-01 13:13:00 +02:00
Tobias Frauenschläger c508b402ca Reject identity-point ECDH shared secret
wc_ecc_shared_secret_gen_sync ran the scalar multiplication and then
copied the x-coordinate to the output without checking whether the
result was the point at infinity. Both math backends report success for
the identity: ecc_map_ex sets x, y to zero and z to one and returns
success, and the single precision generators serialize the identity as
an all-zero x-coordinate. Either way a shared secret that computed to
infinity was handed back as an all-zero secret with a success code,
where SP 800-56Ar3 5.7.1.2 requires an error and stop.

Check the mapped point on the software path, and detect the all-zero
output after the single precision generators, returning ECC_INF_E in
both cases. The scan accumulates over the whole buffer so it does not
branch on the secret.

A key whose private value is resident in an SE050 carries no software
scalar, so the software multiply legitimately yields the identity for
it. Skip the check for those keys specifically, rather than for a zero
scalar: on a prime-order curve a zero scalar is the one way the identity
can arise, so exempting it would disable the check for the case it
exists to catch.

Fixes F-6770.
2026-08-01 13:13:00 +02:00
Tobias Frauenschläger 3b663585ea Reject unset key in wc_Chacha_Process
wc_Chacha_Process validated only its pointer arguments and then produced
keystream directly from the context state. A zero-initialized ChaCha
context, common for static or global storage, that received a nonce via
wc_Chacha_SetIV but never had wc_Chacha_SetKey called would encrypt with
an all-zero, attacker-predictable key and still return success. This is
the same fail-open class already guarded against in wc_Arc4Process.

Add a keySet flag to the ChaCha struct, set it in wc_Chacha_SetKey, and
return MISSING_KEY from wc_Chacha_Process when the key was never set.

Fixes F-6893.
2026-08-01 13:11:52 +02:00
Daniele Lacamera c2ab98bba1 tests: re-enable ascon inSz=0 and rsa prime-check OOM cases (PR 10973)
Two MC/DC cases the campaign disclosed and PR 10973 fixed are now safe to
drive:

* ascon: wc_AsconAEAD128_DecryptUpdate(ctx, out, NULL, 0) demonstrates the
  inSz!=0 operand (the NULL-memcpy on inSz==0 is fixed) -> ascon.c 36/36.

* rsa: the wc_CompareDiffPQ / _CheckProbablePrime / wc_CheckProbablePrime_ex
  XMALLOC-chain later operands (idx1/idx2) are now faulted via arm(2)/arm(3)
  in test_rsa_fault_whitebox.c; they were blocked by the partial-OOM
  double-free the fix removed -> rsa.c 168 -> 172.
2026-07-31 13:16:41 +02:00
Daniele Lacamera 26ef275f82 tests: MC/DC coverage for the wolfEvent queue (wolfevent.c)
Add test_wc_WolfEventDecisionCoverage (group "wolfevent") driving the
wolfEvent / wolfEventQueue_* doubly-linked FIFO from the public API:
the queue==NULL || event==NULL guards (Push/Pop/Add/Remove, each operand
plus the all-false half), the Add first-element branch, the Remove
head/tail/sole cascade including the (event==head && event==tail) AND and
the defensive (next==NULL || prev==NULL) corruption guard, and the Poll
context-filter OR.

Guarded by HAVE_WOLF_EVENT (compiled empty otherwise). The queue core is
async-independent; it builds standalone (no WOLFSSL_ASYNC_CRYPT) now that
BUILD_WOLFEVENT is true under --enable-usersettings and wolfEvent_Poll no
longer warns on unused params in non-async builds.
2026-07-31 12:56:52 +02:00
Daniele Lacamera 1533d63699 tests: fix invented WOLFSSL_SP_256 guard in cortex-m SP white-box
test_sp_cortexm_whitebox.c gated on defined(WOLFSSL_SP_256), which is not a
real wolfSSL macro (256-bit SP is the default, disabled via WOLFSSL_SP_NO_256;
the sized macros are WOLFSSL_SP_384/521/1024). check-source-text flags it as
an unrecognized macro and the guard was always false (dead code). Use
!defined(WOLFSSL_SP_NO_256) so the P-256 Cortex-M SP path is actually built.
2026-07-31 12:56:52 +02:00
Daniele Lacamera 7487073591 tests: WC_NO_ERR_TRACE error-code operands + uppercase literal suffixes
Two check-source-text / clang-tidy fixes on the MC/DC test files:

* Wrap error-code comparison operands in WC_NO_ERR_TRACE() (check-source-text
  check I). Code comparisons (blake2b/blake2s/hpke white-boxes and the
  logging global-queue pull check) are wrapped; the pseudo-code in doc
  comments and the WB_CHECK message strings (mcdc_fault_alloc.h, dsa/mlkem
  fault white-boxes, logging white-box) are reworded so an error code is no
  longer adjacent to == / != .

* Uppercase the integer-literal suffixes in test_sakke.c (384u -> 384U, etc.)
  for clang-tidy readability-uppercase-literal-suffix.

No behavioral change.
2026-07-31 12:56:52 +02:00
Daniele Lacamera 7aee0419ea tests: skip single-DES NULL-arg MC/DC under FIPS/selftest (SIGSEGV)
test_wc_Des_CbcEncryptDecrypt drove the per-operand NULL guards of
wc_Des_CbcEncrypt/CbcDecrypt/EcbEncrypt/SetIV. The frozen FIPS/selftest
single-DES module predates those open-build NULL checks and dereferences a
NULL des/out/in directly, so the probes segfault (exit 139) in a FIPS build.
Gate the whole test on !HAVE_FIPS && !HAVE_SELFTEST -- this single-DES MC/DC
coverage is gathered in the open build; the frozen module is out of its scope.
2026-07-31 12:56:52 +02:00
Daniele Lacamera 6213cbf1cf tests: reword "statics" in MC/DC comments (codespell)
codespell reads "statics" as a misspelling of "statistics" and fails the
Codespell CI lane. Reword the whitebox doc comments/notes to "static
helpers" (falcon/frodokem/rsa fault white-boxes). Comment/string only.
2026-07-31 12:56:52 +02:00
Daniele Lacamera c3055aeed2 tests: avoid C++ // markers in MC/DC white-box doc comments
check-source-text (check E) rejects C++-style // comments in C files, and
its regex fires on the // used as inline annotations inside the /* */ doc
blocks of mcdc_fault_alloc.h (sweep-pattern pseudo-code) and
test_integer_fault_whitebox.c (the mp_div alloc-chain line:col:cond refs).
Nested /* */ can't be used inside a block comment, so switch those inline
markers to '--'. No code change.
2026-07-31 12:56:52 +02:00
Daniele Lacamera a32a2384f7 tests: MC/DC coverage for native Falcon (falcon.c)
Add test_wc_FalconDecisionCoverage to the falcon API group, covering the
public wc_falcon_* wrapper decisions (level checks, import/export and
sign/verify argument guards, init_id/init_label) with per-condition MC/DC
independence cases.

Add tests/unit-mcdc/test_falcon_whitebox.c, a standalone binary that
#includes falcon.c and drives its file-static encode/decode/zint/modp/
sampler/keygen-solver/sign guards -- including the small-mem
falcon_do_sign_dyn twin -- with both halves of each independence pair, plus
a real Falcon-512 make/sign/verify round-trip for the proceed halves.

Register the whitebox in EXTRA_DIST (test-only; it is not part of the
library build).
2026-07-31 12:56:52 +02:00
Daniele Lacamera 46376d3cb2 tests: fault-injection + ARM-lane MC/DC white-box supplements
Add the tests/unit-mcdc white-box drivers produced by the coverage campaign's
fault-injection and SP-ARM emulator-lane passes, and extend the EXTRA_DIST
listing to cover them (test-only; standalone main() + #include the target .c;
never built into libwolfssl or unit.test -- see the comment in tests/include.am).

Fault-injection (mcdc_fault_alloc.h: a fail-after-N wolfSSL_SetAllocators mock,
swept across allocation sites to drive the FALSE half of (err==MP_OKAY)&&step
success-chain guards): dsa, eccsi, sakke, hpke, mlkem, mldsa, integer, rsa,
frodokem (+ a shared frodokem fault header).

SP-ARM emulator lanes (drive the C-level decisions in the cross-only asm SP
backends under qemu-user / m33mu): sp_arm64, sp_arm32, sp_armthumb, sp_cortexm.
2026-07-31 12:56:52 +02:00
Daniele Lacamera 7de723d676 tests: list this branch's unit-mcdc white-boxes in EXTRA_DIST
The tests/unit-mcdc/*.c MC/DC white-box supplements this branch adds each
#include a wolfCrypt .c and carry their own main(); they are built standalone
by the per-module coverage campaign and are NOT compiled into libwolfssl or
unit.test (that would duplicate main()/symbols). They are test-only.

The source-completeness check (per-PR diff) requires every file a PR adds to
appear in an include.am. Since these cannot be tests_unit_test_SOURCES, list
them in EXTRA_DIST -- the same bucket tests/api/include.am uses for its
non-compiled files -- so they ship in the dist tarball without being built.
Scope: only the white-boxes this branch introduces.
2026-07-31 12:56:52 +02:00
Daniele Lacamera e799f180af tests: fix eccsi ValidateEccsiPair error code under WOLFSSL_SP_MATH
wc_ValidateEccsiPair() reports an off-curve PVT via wc_ecc_is_point(), whose
error code is backend-dependent: the mp-based check (classic / SP_MATH_ALL /
fast-math) returns IS_POINT_E, but the minimal WOLFSSL_SP_MATH backend routes
through sp_ecc_is_point_*(), which returns MP_VAL for a point not on the curve
(and eccsi.c only remaps -1 -> IS_POINT_E, not MP_VAL). Select the expected
code per backend so the all-pq-sp-math CI config (--enable-sp-math) passes.

Verified: full unit.test --api under --enable-all --enable-sp-math --enable-sp-asm
reports 0 failures.
2026-07-31 12:56:52 +02:00
Daniele Lacamera 95ce9ede23 tests: address Copilot review comments on MC/DC coverage tests
- test_wolfmath.c: limit the "digits > capacity" mp_rand rejection vector to
  the fixed-size backends. USE_INTEGER_HEAP_MATH grows the mp_int via
  mp_set_bit instead of rejecting, so the call would legally succeed (and
  force a large allocation), failing ExpectIntNE.

- test_memory_whitebox.c: guard the WOLFSSL_STATIC_MEMORY / WOLFSSL_MEM_FAIL_COUNT
  defines with #ifndef so a build that already provides them (user_settings.h /
  CFLAGS) does not hit a redefinition warning treated as error.

- test_sakke_whitebox.c: skip the sakke_mulmod_base_add() calls when
  wc_ecc_new_point() returns NULL. That function does not validate its result
  pointer and would dereference a NULL addResult under allocation pressure.
2026-07-31 12:56:52 +02:00
Daniele Lacamera 2ce3432a3b tests: fix CI failures in HPKE/SAKKE MC/DC coverage tests
- test_hpke.c: guard both test bodies on HAVE_HPKE. They were gated only on
  HAVE_CURVE25519 && !NO_SHA256 && WOLFSSL_AES_128, so configs with those but
  without HPKE (e.g. pk-mlkem) compiled the body against absent HPKE symbols
  and failed to build under -Werror.

- test_sakke.c: make the wc_GenerateSakkeRskTable / wc_GenerateSakkePointITable
  / wc_SetSakkePointITable checks SP-backend agnostic. The required table size
  is 0 on the small-stack SP path but non-zero on the full precomputation path
  (sizeof(sp_table_entry_1024) * 1167 / * 256), so the previous fixed
  "len == 0" and success-with-tiny-buffer assertions failed (and could write a
  full-size table into the small stack buffer) under --enable-all. Capture the
  queried length and branch: the Rsk table builds into a correctly-sized heap
  buffer; the PointI table's full-path build/store is left to the sakke_test
  KAT (it stores the pointer in the key).

- codespell: rename addRes -> addResult in test_sakke_whitebox.c and reword a
  comment in test_hpke.c ("statics").
2026-07-31 12:56:52 +02:00
Daniele Lacamera 45a98467e4 tests: MC/DC decision coverage for remaining wolfCrypt primitives
Add DecisionCoverage/FeatureCoverage tests and tests/unit-mcdc white-box
supplements for the remaining reachable wolfCrypt primitive sources in the
ISO 26262 per-module MC/DC campaign (excluding asn* and the EVP/OpenSSL
compat layer, which are out of the MC/DC boundary).

tests/api:
- legacy ciphers / digests: des3, camellia, ascon, blake2, siphash
- niche PK: srp, eccsi, sakke, hpke
- native PQC KEM: frodokem
- math: wolfmath

tests/unit-mcdc white-box drivers (#include the .c to reach file-static
helpers and impl-selected paths, standalone main()/WB_NOTE harness):
- blake2b, blake2s
- eccsi, sakke, hpke
- SP host backends: sp_x86_64, sp_c64, sp_c32
- infra: cryptocb (dev && dev->cb dispatch three-vector, 127/127),
  logging (per-thread + global error-queue impls, 19/19),
  memory (static-pool allocator, 46/48)

Registrations in tests/api.c, tests/api/include.am and CMakeLists.txt.
2026-07-31 12:56:51 +02:00
Tobias FrauenschlägerandGitHub b844cdcce0 Merge pull request #10421 from kojo1/pha
TLS 1.3 PHA with OCSP Stapling
2026-07-31 09:07:29 +02:00
Daniel PouzznerandGitHub 8ec8bd6876 Merge pull request #11015 from SparkiDev/asm_fixes_5
RISC-V 64-bit assembly: AES-GCM decrypt fix
2026-07-30 18:20:14 -05:00
David GarskeandGitHub 643d209dba Merge pull request #10961 from anhu/crl_unknown_ext
New API for CRL unknown extension callback
2026-07-30 09:00:23 -07:00
Sean Parkinson e9d411ed09 RISC-V 64-bit assembly: AES-GCM decrypt fix
Fix for when decrypting into the same buffer.

Also fixed test on PPC64/32.
2026-07-30 16:50:52 +10:00
Daniel PouzznerandGitHub f69903778f Merge pull request #11001 from SparkiDev/regression_fixes_28
Regression testing fixes
2026-07-29 22:02:19 -05:00
Sean Parkinson 119901c227 Regression testing fixes
wc_mlkem.h/test_mlkem.c: Respect WC_NO_CONSTRUCTORS guard.

settings.h, fe_operations.h: move WOLFSSL_CURVE25519_USE_ED25519 derivation into settings.h so the assembler sees it; fixes fe_cmov_table undefined on ARM32.

ge_448.c: shift the product instead of the byte in six sc448_* loops, dodging a GCC ARM32 NEON miscompile that produced wrong ed448 signatures; table shrunk [56]→[28].
2026-07-29 14:59:47 +10:00
Sean ParkinsonandGitHub 9c5436b853 Merge pull request #10968 from Frauschi/fenrir_tls
Fenrir fixes
2026-07-28 11:31:19 +10:00
Sean ParkinsonandGitHub 19c1d07beb Merge pull request #10944 from Frauschi/tls-read-ahead
Add TLS receive read-ahead support
2026-07-28 11:16:21 +10:00
Sean ParkinsonandGitHub 495296a739 Merge pull request #10625 from julek-wolfssl/client-custom-ext
Add SSL_CTX_add_client_custom_ext (OpenSSL-compat client custom extensions)
2026-07-28 09:22:47 +10:00
Daniel Pouzzner 1693b08b3e tests/api/test_kdf.c: fix NO_SHA in test_wc_KdfFeatureCoverage(). 2026-07-24 16:39:55 -05:00
Daniel Pouzzner 142109db24 test/:
* fixes for NO_DH;
* fixes in test_wc_ed448_import_public() and test_wc_Ed448DecisionCoverage() for FIPS v6;
* fixes in tests/api/test_sha3.c for KMAC keysize in FIPS builds.
2026-07-24 16:39:54 -05:00
JacobBarthelmehandGitHub acff4d62a1 Merge pull request #10883 from night1rider/Extend-ECIES
Add AES-GCM DEM, CryptoCb support, and devId threading to ECIES
2026-07-24 14:02:32 -06:00
Anthony Hu 73f1a7b665 More tests 2026-07-24 14:34:17 -04:00
night1rider 3062dea0b6 Use the existing KEY32 macro and a named fake overhead constant in the new ECIES tests 2026-07-24 10:21:20 -06:00
night1rider c00e7260be Add AES-GCM DEM, CryptoCb support, and devId threading to ECIES
Add AES-GCM (128/256) as an ECIES DEM next to the AES-CBC/CTR+HMAC modes. Only the encryption key comes from the KDF; the mac salt is bound as GCM AAD and the 16-byte tag replaces the HMAC. The GCM DEM honors all three IV build modes, and default fixed-nonce GCM is gated behind the new WOLFSSL_ECIES_STATIC_GCM_NONCE opt-in. Adds ECIES CryptoCb encrypt/decrypt, the WOLF_CRYPTO_CB ctx getters, devId/heap threading into the DEM primitives, and test/benchmark/CI coverage.
2026-07-24 10:19:40 -06:00
Tobias Frauenschläger f60002d137 Add TLS receive read-ahead support
Add WOLFSSL_TLS_READ_AHEAD (--enable-readahead), toggled at runtime via
wolfSSL_set_read_ahead(). When enabled, the record-header read pulls a
full record in one recv() so the body arrives without a second syscall.

The receive window is configurable with
wolfSSL_CTX/SSL_set_default_read_buffer_len() (OpenSSL-compatible):
0 keeps the one-record default, a larger value coalesces several records
per recv(), a smaller value caps the per-connection buffer footprint.
Records exceeding the window are still received correctly, the buffer
grows on demand and is reallocated back down to the window afterwards so
the retained footprint stays bounded.

Includes docs, API tests, and a benchmark toggle.
2026-07-24 08:17:41 +02:00
Sean ParkinsonandGitHub 674a77b5a1 Merge pull request #10953 from embhorn/zd22167
Bound CKS extension allocation in TLSX_CKS_Parse
2026-07-24 10:40:29 +10:00
Sean ParkinsonandGitHub 15afad7f8f Merge pull request #10902 from rlm2002/coverity
2020714 Coverity fixes
2026-07-24 10:38:13 +10:00
Sean ParkinsonandGitHub 2b90784463 Merge pull request #10952 from embhorn/zd22171
Fix off-by-one OOB NUL write in GetCertName (classic ASN parser)
2026-07-24 10:37:30 +10:00
Sean ParkinsonandGitHub f7571db708 Merge pull request #10896 from julek-wolfssl/julek-dev/openvpn-set0-crls
X509_STORE_CTX_set0_crls: implement for OpenVPN
2026-07-24 10:18:40 +10:00
Sean ParkinsonandGitHub 3254e75598 Merge pull request #10811 from kareem-wolfssl/gh10746
Correct alert type for missing supported_versions in HRR and avoid sending duplicate protocol_version alerts.
2026-07-24 09:45:14 +10:00
Sean ParkinsonandGitHub 98edc78599 Merge pull request #10769 from rizlik/dtls13_max_handshake_sz
dtls13: add check over handshake message length
2026-07-24 09:35:37 +10:00
Sean ParkinsonandGitHub 7b829b92b7 Merge pull request #10777 from gasbytes/rsa-pkcs-v1.5-negative-test
RSA pkcs#1 v1.5 negative tests
2026-07-24 08:56:24 +10:00
JacobBarthelmehandGitHub b3424c4df6 Merge pull request #10966 from ejohnstown/upd-ocsp
Reject CR/LF and obs-fold in OCSP requests
2026-07-23 15:07:44 -06:00
Anthony Hu 8b0e0b9683 New API for CRL unknown extension callback
Adds public entry points mirroring the existing X.509 unknown extension callback so callers can register a handler for unrecognized CRL extensions instead of failing with ASN_CRIT_EXT_E.
2026-07-23 15:30:16 -04:00
Sean ParkinsonandGitHub e6c3bb4403 Merge pull request #10827 from danielinux/falcon-native
Falcon: native implementation replacing liboqs, with crypto callbacks and ARM acceleration. Deprecate liboqs support.
2026-07-23 21:17:10 +10:00
John Safranek 6b78c5952b Reject CR/LF and obs-fold in OCSP requests
The OpenSSL compatibility APIs copied caller-supplied strings into the
outbound OCSP request verbatim, so an embedded newline split it into
attacker-chosen header lines, and a header name starting with SP or HTAB
folded into the preceding header's value. OpenSSL rejects these; the
library's own fetch path already rejects CR/LF via wolfIO_DecodeUrl().

* wolfSSL_OCSP_REQ_CTX_http(): reject CR/LF in op and path.
* wolfSSL_OCSP_REQ_CTX_add1_header(): reject CR/LF in name and value.
* wolfSSL_OCSP_REQ_CTX_add1_header(): reject a name starting with SP or
  HTAB, which RFC 7230 Section 3.2.4 treats as an obs-fold continuation
  of the previous header rather than a new header.
* wolfSSL_OCSP_parse_url(): reject CR/LF anywhere in the URL, the likely
  source of a tainted path via a certificate's AIA extension.
2026-07-22 20:47:06 -07:00
Brett NicholasandGitHub e6d86b4bbb Merge pull request #10832 from padelsbach/curve25519-cryptocb-only
Add crypto callback only mode for curve25519
2026-07-22 17:35:55 -06:00
Takashi Kojo 60817b08c6 Fix repeated TLS 1.3 PHA over write_dup 2026-07-23 07:46:13 +09:00
Takashi Kojo 6d0dca2950 Post handsake authentication with client end OCSP 2026-07-23 07:42:20 +09:00
David GarskeandGitHub 983e1090d7 Merge pull request #10922 from aidangarske/fenrir-asn-strict
Enforce RFC 5280 extension MUSTs under WOLFSSL_NO_ASN_STRICT and validate DTLS 1.3 legacy_session_id echo
2026-07-22 14:12:33 -07:00