mirror of
https://github.com/wolfSSL/wolfssl.git
synced 2026-08-04 03:14:13 +02:00
4ec80d309a
Add tooling to produce Software Bills of Materials and build provenance for wolfSSL, supporting EU Cyber Resilience Act (CRA) obligations. SBOM generation: - New `make sbom` target producing SPDX 2.3 output with NTIA minimum elements, urn:uuid document namespaces, and SPDX LicenseRef compliance. - Reproducible library discovery across autotools and CMake builds, with liboqs recorded as a linked artefact. - Standalone `scripts/gen-sbom` for embedded / RTOS / custom-builder flows that do not use the main build system, plus --srcs-file, --no-artifact-hash, and hash-source options. Build provenance (OmniBOR / bomsh): - End-to-end bomsh tracing of the built binaries with ArtifactID insertion, snapshotting the traced library before libtool relink and hashing the bomsh-traced binary. - `scripts/bomsh_verify.py` to validate provenance against the traced gitoid. Security advisories: - `scripts/gen-advisory` generating CSAF 2.0 and CycloneDX VEX, with a `make` target, VEX overlay schema/example, and CWE name data. Docs, tests, and CI: - doc/SBOM.md and doc/CRA.md, plus README/INSTALL updates. - Unit and regression tests for gen-sbom and gen-advisory. - New sbom.yml and advisory.yml workflows: SPDX validation via pyspdxtools, CSAF validation, bomsh provenance verification, SBOM artifact archiving, macOS coverage, and actions pinned to SHAs. Signed-off-by: Sameeh Jubran <sameeh@wolfssl.com>
208 lines
6.9 KiB
Plaintext
208 lines
6.9 KiB
Plaintext
# vim:ft=automake
|
|
# included from Top Level Makefile.am
|
|
# All paths should be given relative to the root
|
|
|
|
|
|
|
|
if BUILD_SNIFFTEST
|
|
dist_noinst_SCRIPTS+= scripts/sniffer-testsuite.test
|
|
endif
|
|
|
|
if BUILD_EXAMPLE_SERVERS
|
|
|
|
dist_noinst_SCRIPTS+= scripts/resume.test
|
|
|
|
# The CRL and OCSP tests use RSA certificates.
|
|
if BUILD_RSA
|
|
|
|
if BUILD_CRL
|
|
# make revoked test rely on completion of resume test
|
|
dist_noinst_SCRIPTS+= scripts/crl-revoked.test
|
|
dist_noinst_SCRIPTS+= scripts/crl-gen-openssl.test
|
|
scripts/crl-revoked.log: scripts/resume.log
|
|
scripts/crl-gen-openssl.log: scripts/crl-revoked.log
|
|
endif
|
|
|
|
# arrange to serialize ocsp.test, ocsp-stapling.test, ocsp-stapling-with-ca-as-responder.test, ocsp-stapling2.test, and testsuite,
|
|
# to help mitigate port conflicts among them.
|
|
# note that unit.test is gated on testsuite in Makefile.am, which is also helpful for these purposes.
|
|
|
|
if BUILD_OCSP_STAPLING
|
|
dist_noinst_SCRIPTS+= scripts/ocsp-stapling.test
|
|
if BUILD_OCSP_STAPLING_MULTI
|
|
dist_noinst_SCRIPTS+= scripts/ocsp-stapling_tls13multi.test
|
|
endif
|
|
if !BUILD_OCSP_STAPLING_V2
|
|
testsuite/testsuite.log: scripts/ocsp-stapling.log scripts/ocsp-stapling-with-ca-as-responder.log
|
|
endif
|
|
scripts/ocsp-stapling.log: scripts/ocsp.log
|
|
dist_noinst_SCRIPTS+= scripts/ocsp-stapling-with-ca-as-responder.test
|
|
scripts/ocsp-stapling-with-ca-as-responder.log: scripts/ocsp.log
|
|
scripts/ocsp-stapling-with-ca-as-responder.log: scripts/ocsp-stapling.log
|
|
if BUILD_OCSP_STAPLING_MULTI
|
|
scripts/ocsp-stapling_tls13multi.log: scripts/ocsp-stapling-with-ca-as-responder.log
|
|
endif
|
|
endif
|
|
|
|
if BUILD_OCSP_STAPLING_V2
|
|
dist_noinst_SCRIPTS+= scripts/ocsp-stapling2.test
|
|
|
|
if BUILD_OCSP_STAPLING
|
|
testsuite/testsuite.log: scripts/ocsp-stapling2.log
|
|
scripts/ocsp-stapling2.log: scripts/ocsp.log
|
|
scripts/ocsp-stapling2.log: scripts/ocsp-stapling.log
|
|
scripts/ocsp-stapling2.log: scripts/ocsp-stapling-with-ca-as-responder.log
|
|
else
|
|
scripts/ocsp-stapling2.log: scripts/ocsp.log
|
|
endif
|
|
|
|
endif
|
|
|
|
if BUILD_OCSP_RESPONDER
|
|
if BUILD_OCSP_STAPLING
|
|
dist_noinst_SCRIPTS+= scripts/ocsp-stapling-with-wolfssl-responder.test
|
|
scripts/ocsp-stapling-with-wolfssl-responder.log: scripts/ocsp-stapling-with-ca-as-responder.log
|
|
dist_noinst_SCRIPTS+= scripts/ocsp-responder-openssl-interop.test
|
|
scripts/ocsp-responder-openssl-interop.log: scripts/ocsp-stapling-with-wolfssl-responder.log
|
|
testsuite/testsuite.log: scripts/ocsp-responder-openssl-interop.log
|
|
else
|
|
dist_noinst_SCRIPTS+= scripts/ocsp-responder-openssl-interop.test
|
|
scripts/ocsp-responder-openssl-interop.log: scripts/ocsp.log
|
|
testsuite/testsuite.log: scripts/ocsp-responder-openssl-interop.log
|
|
endif
|
|
endif
|
|
|
|
endif
|
|
|
|
if BUILD_PSK
|
|
dist_noinst_SCRIPTS+= scripts/psk.test
|
|
endif
|
|
|
|
if BUILD_TRUST_PEER_CERT
|
|
dist_noinst_SCRIPTS+= scripts/trusted_peer.test
|
|
endif
|
|
|
|
if BUILD_PKCALLBACKS
|
|
dist_noinst_SCRIPTS+= scripts/pkcallbacks.test
|
|
scripts/pkcallbacks.log: scripts/resume.log
|
|
endif
|
|
|
|
if BUILD_TLS13
|
|
dist_noinst_SCRIPTS+= scripts/tls13.test
|
|
endif
|
|
|
|
endif # end of BUILD_EXAMPLE_SERVERS
|
|
|
|
if BUILD_EXAMPLE_CLIENTS
|
|
if !BUILD_IPV6
|
|
dist_noinst_SCRIPTS+= scripts/external.test
|
|
dist_noinst_SCRIPTS+= scripts/google.test
|
|
dist_noinst_SCRIPTS+= scripts/openssl.test
|
|
|
|
if BUILD_OCSP
|
|
dist_noinst_SCRIPTS+= scripts/ocsp.test
|
|
endif
|
|
|
|
dist_noinst_SCRIPTS+= scripts/unit.test
|
|
noinst_SCRIPTS+= scripts/unit.test.in
|
|
|
|
# multi-msg-record.test drives the wolfSSL example client against a
|
|
# Python (tlslite-ng) peer to verify parsing of TLS records that carry
|
|
# multiple handshake messages. The script probes the client binary
|
|
# at runtime for TLS 1.2, TLS 1.3 and secure-renegotiation support
|
|
# and skips phases that are not compiled in. The whole test exits 77
|
|
# (SKIP) if python3 or tlslite-ng is missing or if nothing is
|
|
# runnable.
|
|
dist_noinst_SCRIPTS+= scripts/multi-msg-record.test
|
|
|
|
endif
|
|
endif
|
|
|
|
# The Python half of multi-msg-record.test always ships in tarballs so
|
|
# the wrapper can find it on the installed side.
|
|
EXTRA_DIST+= scripts/multi-msg-record.py
|
|
|
|
dist_noinst_SCRIPTS+= scripts/pem.test
|
|
|
|
dist_noinst_SCRIPTS+= scripts/tsp.test
|
|
|
|
EXTRA_DIST += scripts/sniffer-static-rsa.pcap \
|
|
scripts/sniffer-ipv6.pcap \
|
|
scripts/sniffer-tls13-dh.pcap \
|
|
scripts/sniffer-tls13-dh-resume.pcap \
|
|
scripts/sniffer-tls13-ecc.pcap \
|
|
scripts/sniffer-tls13-ecc-resume.pcap \
|
|
scripts/sniffer-tls13-x25519.pcap \
|
|
scripts/sniffer-tls13-x25519-resume.pcap \
|
|
scripts/sniffer-tls13-hrr.pcap \
|
|
scripts/sniffer-gen.sh \
|
|
scripts/ping.test \
|
|
scripts/benchmark.test \
|
|
scripts/memtest.sh \
|
|
scripts/makedistsmall.sh \
|
|
scripts/openssl_srtp.test \
|
|
scripts/aria-cmake-build-test.sh \
|
|
scripts/asn1_oid_sum.pl
|
|
|
|
|
|
# leave openssl.test as extra until non bash works
|
|
EXTRA_DIST += scripts/openssl.test
|
|
EXTRA_DIST += scripts/rsapss.test
|
|
|
|
EXTRA_DIST += scripts/dertoc.pl
|
|
|
|
# for use with wolfssl-x.x.x-commercial-fips-stm32l4-v2
|
|
EXTRA_DIST += scripts/stm32l4-v4_0_1_build.sh
|
|
|
|
EXTRA_DIST += scripts/cleanup_testfiles.sh
|
|
|
|
EXTRA_DIST += scripts/dtls.test
|
|
|
|
if BUILD_DTLS13
|
|
EXTRA_DIST += scripts/dtlscid.test
|
|
endif
|
|
|
|
if BUILD_DTLS_CID
|
|
dist_noinst_SCRIPTS+= scripts/dtlscid.test
|
|
endif
|
|
|
|
EXTRA_DIST += scripts/bench/bench_functions.sh
|
|
EXTRA_DIST += scripts/benchmark_compare.sh
|
|
|
|
EXTRA_DIST += scripts/user_settings_asm.sh
|
|
|
|
# SBOM generator (invoked from `make sbom` in the top-level Makefile.am).
|
|
# Must be in the dist tarball, otherwise `make dist && cd <tarball> &&
|
|
# ./configure && make sbom` fails for downstream consumers.
|
|
EXTRA_DIST += scripts/gen-sbom
|
|
|
|
# SBOM generator unit tests. Shipped so downstream consumers building
|
|
# from a release tarball can re-run the regression suite.
|
|
EXTRA_DIST += scripts/test_gen_sbom.py
|
|
|
|
# Bomsh / OmniBOR provenance verifier (invoked from `.github/workflows/
|
|
# sbom.yml` and runnable by hand against any local `make bomsh` output;
|
|
# see doc/SBOM.md sec. 3.5). Must ship with the dist tarball so a
|
|
# downstream consumer / CRA reviewer who clones a release tarball can
|
|
# re-verify the OmniBOR graph against its enriched SPDX without going
|
|
# back to the git repo.
|
|
EXTRA_DIST += scripts/bomsh_verify.py
|
|
|
|
# Security advisory generator (invoked from `make advisory`), its canonical
|
|
# CWE-name catalogue, and the VEX overlay schema + example. Shipped so a
|
|
# downstream consumer building from a release tarball can run `make advisory`.
|
|
EXTRA_DIST += scripts/gen-advisory \
|
|
scripts/cwe-names.json \
|
|
scripts/advisory-vex-overlay.schema.json \
|
|
scripts/advisory-vex-overlay.example.json
|
|
|
|
# Advisory regression suite + CSAF 2.0 conformance gate, with the frozen CVE
|
|
# fixtures they run against. Shipped so a downstream consumer / CRA reviewer
|
|
# can re-run the advisory tests from a release tarball.
|
|
EXTRA_DIST += scripts/csaf_validate.mjs \
|
|
scripts/test_gen_advisory.py \
|
|
scripts/testdata/README.md \
|
|
scripts/testdata/CVE-2026-5501.json \
|
|
scripts/testdata/CVE-2026-5778.json \
|
|
scripts/testdata/CVE-2026-5999.json
|