Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
27 commits
Select commit Hold shift + click to select a range
cdd1221
Import SPDM core from wolfTPM 0f639565
aidangarske Sep 25, 2026
f6ebdcd
Select vendor KEY_EXCHANGE format at runtime and tighten response checks
aidangarske Sep 25, 2026
5dd2755
Add the standard certificate requester on the wolfTPM core
aidangarske Sep 25, 2026
29afc3f
Run wolfTPM's own SPDM unit tests in the downstream job
aidangarske Sep 25, 2026
2843d48
Add HEARTBEAT and KEY_UPDATE on the wolfTPM core
aidangarske Sep 25, 2026
8b36cfa
Add GET_MEASUREMENTS and CHALLENGE on the wolfTPM core
aidangarske Sep 25, 2026
9999208
Add CHUNK_SEND and CHUNK_GET large message chunking
aidangarske Sep 26, 2026
a8dece0
Compile out the TPM side in standalone builds and MCTP in pure TCG bu…
aidangarske Sep 26, 2026
66100f7
Run every CI workflow on wolftpm-core and fix what GCC and codespell …
aidangarske Sep 26, 2026
414326c
Suppress cppcheck on the wolfCrypt requirement guards
aidangarske Sep 26, 2026
8cc0b82
Add MCTP application data and secured message API on the wolfTPM core
aidangarske Sep 26, 2026
0d50ae9
Add ML-DSA and ML-KEM on the wolfTPM core and restore main's remainin…
aidangarske Sep 28, 2026
5b477e1
Update the README and wiki for the consolidated SPDM stack
aidangarske Sep 28, 2026
765d347
Port main's remaining unit test coverage onto the core
aidangarske Sep 28, 2026
def71ca
Fix the Skoll review findings in session handling, TCG transport and …
aidangarske Sep 28, 2026
7a7f0f6
Drop a dead store scan-build flags in chain validation
aidangarske Sep 28, 2026
4b2f0de
Fix the Codex review findings in key update, FINISH, PSK replacement …
aidangarske Sep 28, 2026
aa876cb
Reject a vendor-defined VdCode that is not exactly eight characters
aidangarske Sep 28, 2026
ee4e319
Restore the 4096-byte trusted CA default from main
aidangarske Sep 28, 2026
4629344
Accept --kex ecdhe without ML-KEM and tighten two unit tests
aidangarske Sep 28, 2026
66d9503
Check the vendor-defined VdCode without scanning past eight bytes
aidangarske Sep 28, 2026
9db7ab0
Drop the integration branch from the workflow push triggers
aidangarske Sep 28, 2026
ecc89ab
Support wolfTPM's lib/wolfSPDM submodule layout in the downstream job
aidangarske Sep 28, 2026
299cec8
Fix the Opus review findings in session gates, responder wipes and FI…
aidangarske Sep 29, 2026
3b92690
Load options.h for every consumer and keep a safe MEAS_NOT_VERIFIED s…
aidangarske Sep 29, 2026
bcb9e9b
Name the legacy MEAS_NOT_VERIFIED code in GetErrorString
aidangarske Sep 29, 2026
c0f0ce2
Check the exact legacy MEAS_NOT_VERIFIED error string
aidangarske Sep 29, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
62 changes: 50 additions & 12 deletions .github/workflows/build-test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -52,7 +52,7 @@ jobs:

- name: Configure
run: |
./configure --with-wolfssl=$HOME/wolfssl-install \
./configure --with-wolfssl=$HOME/wolfssl-install --enable-nuvoton --enable-nations --enable-responder \
${{ matrix.debug == 'yes' && '--enable-debug' || '' }} \
${{ matrix.dynamic-mem == 'yes' && '--enable-dynamic-mem' || '' }}

Expand All @@ -73,21 +73,49 @@ jobs:
test/*.log
config.log

chunk-config:
name: chunking / ${{ matrix.variant }}
feature-config:
name: features / ${{ matrix.variant }}
runs-on: ubuntu-latest
env:
# Standalone builds carry none of the TPM side, pure TCG builds none of
# the standard requester
TPM_SYMS: 'wolfSPDM_(TCG_.*|Nuvoton_.*|Nations_.*|Resp[A-Z].*|.*Psk.*|SetPSK|ConnectTCG|.*TcgClear.*|.*VendorDefined|SetRequesterKey.*|SignHash|GetConnectionHandle|GetFipsIndicator)'
STD_SYMS: 'wolfSPDM_(GetCapabilities|BuildGetCapabilities|ParseCapabilities|NegotiateAlgorithms|BuildNegotiateAlgorithms|ParseAlgorithms|GetDigests|ParseDigests|GetCertificate|ParseCertificate|ValidateCertChain|SetTrustedCAs|AllowUntrustedCerts|ConnectStandard|.*Measurement.*|.*Challenge.*|M1Start|M1Add|AttestFree|ChunkExchange|ClearExchange|SendData|ReceiveData|EncryptMessage|DecryptMessage|.*MlDsa.*|.*MlKem.*|SetKeyExchangePref)'
strategy:
fail-fast: false
matrix:
include:
- variant: default
- variant: core
configure: ''
- variant: disabled
forbid: tpm
- variant: tcg
configure: '--enable-tcg'
- variant: tcg-psk
configure: '--enable-tcg --enable-psk'
- variant: nuvoton
configure: '--enable-nuvoton'
- variant: nations
configure: '--enable-nations'
- variant: tcg-responder
configure: '--enable-tcg --enable-responder'
- variant: tcg-pure
configure: '--enable-nuvoton --enable-nations --enable-responder --disable-mctp'
forbid: std
- variant: no-session-ext
configure: '--disable-heartbeat --disable-key-update'
forbid: tpm
- variant: no-attest
configure: '--disable-meas --disable-challenge'
forbid: tpm
- variant: no-chunking
configure: '--disable-chunking'
- variant: no-secured
configure: 'CPPFLAGS=-DWOLFSPDM_CHUNK_NO_SECURED'
- variant: small-mtu
configure: 'CPPFLAGS=-DWOLFSPDM_CHUNK_BUF_SIZE=1024'
forbid: tpm
- variant: no-app-data
configure: '--disable-app-data'
forbid: tpm
- variant: lean
configure: '--disable-cert --disable-heartbeat --disable-key-update --disable-app-data'
forbid: tpm

steps:
- uses: actions/checkout@v4
Expand Down Expand Up @@ -123,9 +151,6 @@ jobs:
- name: Configure
run: ./configure --with-wolfssl=$HOME/wolfssl-install ${{ matrix.configure }}

- name: Verify chunking status
run: grep -E 'Chunking:' config.log || true

- name: Build
run: make -j$(nproc)

Expand All @@ -134,6 +159,19 @@ jobs:
env:
LD_LIBRARY_PATH: ${{ github.workspace }}/src/.libs:$HOME/wolfssl-install/lib

- name: Check the other side is compiled out
if: matrix.forbid != ''
run: |
case "${{ matrix.forbid }}" in
tpm) re="$TPM_SYMS" ;;
std) re="$STD_SYMS" ;;
esac
bad=$(nm --defined-only .libs/libwolfspdm.so | awk '{print $3}' |
grep -E "^${re}$" || true)
if [ -n "$bad" ]; then
echo "Unexpected symbols:"; echo "$bad"; exit 1
fi

- name: Upload test logs on failure
if: failure()
uses: actions/upload-artifact@v4
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -56,7 +56,7 @@ jobs:
- name: Build
run: |
./autogen.sh
./configure --with-wolfssl=$HOME/wolfssl-install
./configure --with-wolfssl=$HOME/wolfssl-install --enable-nuvoton --enable-nations --enable-responder
make -j$(nproc)

- name: Perform CodeQL Analysis
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/compiler-warnings.yml
Original file line number Diff line number Diff line change
Expand Up @@ -44,7 +44,7 @@ jobs:
- name: Build with strict warnings
run: |
./autogen.sh
./configure --with-wolfssl=$HOME/wolfssl-install
./configure --with-wolfssl=$HOME/wolfssl-install --enable-nuvoton --enable-nations --enable-responder
make -j$(nproc) CFLAGS="-Wall -Wextra -Wpedantic -Werror -Wconversion -Wshadow"

clang:
Expand Down Expand Up @@ -82,7 +82,7 @@ jobs:
- name: Build with clang
run: |
./autogen.sh
CC=clang ./configure --with-wolfssl=$HOME/wolfssl-install
CC=clang ./configure --with-wolfssl=$HOME/wolfssl-install --enable-nuvoton --enable-nations --enable-responder
make -j$(nproc) CFLAGS="-Wall -Wextra -Werror"

- name: Run unit tests
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/memory-check.yml
Original file line number Diff line number Diff line change
Expand Up @@ -48,7 +48,7 @@ jobs:
- name: Build with debug
run: |
./autogen.sh
./configure --with-wolfssl=$HOME/wolfssl-install --enable-debug \
./configure --with-wolfssl=$HOME/wolfssl-install --enable-nuvoton --enable-nations --enable-responder --enable-debug \
${{ matrix.dynamic-mem == 'yes' && '--enable-dynamic-mem' || '' }}
make -j$(nproc)
make -j$(nproc) check TESTS=
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/multi-compiler.yml
Original file line number Diff line number Diff line change
Expand Up @@ -59,7 +59,7 @@ jobs:
- name: Build wolfSPDM with ${{ matrix.cc }}
run: |
./autogen.sh
CC=${{ matrix.cc }} ./configure --with-wolfssl=$HOME/wolfssl-install
CC=${{ matrix.cc }} ./configure --with-wolfssl=$HOME/wolfssl-install --enable-nuvoton --enable-nations --enable-responder
make -j$(nproc) CFLAGS="-Wall -Wextra -Werror"

- name: Run unit tests
Expand Down
14 changes: 8 additions & 6 deletions .github/workflows/spdm-emu-pqc-test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -82,15 +82,14 @@ jobs:
# the combined build below does not. Cleaned up before the full build. ---
- name: Build + test wolfSPDM ML-KEM-only (--disable-mldsa --enable-mlkem)
run: |
export LD_LIBRARY_PATH="${{ github.workspace }}/.libs:${{ github.workspace }}/src/.libs:$HOME/wolfssl-install/lib"
./autogen.sh
./configure --with-wolfssl=$HOME/wolfssl-install \
--disable-mldsa --enable-mlkem \
${{ matrix.dynamic-mem == 'yes' && '--enable-dynamic-mem' || '' }}
make -j"$(nproc)"
make check
make distclean
env:
LD_LIBRARY_PATH: ${{ github.workspace }}/.libs:${{ github.workspace }}/src/.libs:${{ env.HOME }}/wolfssl-install/lib

# --- wolfSPDM with ML-DSA + ML-KEM asserted on, static or dynamic memory ---
- name: Build and install wolfSPDM (--enable-mldsa --enable-mlkem)
Expand All @@ -103,9 +102,9 @@ jobs:
make install

- name: Run unit tests (includes ML-DSA verify + ML-KEM decap)
run: make check
env:
LD_LIBRARY_PATH: ${{ github.workspace }}/.libs:${{ github.workspace }}/src/.libs:${{ env.HOME }}/wolfssl-install/lib
run: |
export LD_LIBRARY_PATH="${{ github.workspace }}/.libs:${{ github.workspace }}/src/.libs:$HOME/wolfssl-install/lib"
make check

# --- spdm-emu with OpenSSL backend (ML-DSA), cached per OS/arch ---
# Cache the whole build tree, not just build/bin: the OpenSSL-backed
Expand Down Expand Up @@ -285,7 +284,7 @@ jobs:
# message; ML-DSA-87 (sig 4627 B) + ciphertext c (1088 B) exceeds the
# DataTransferSize, so this case also exercises CHUNK_GET reassembly -
# ML-KEM + ML-DSA + chunking in a single handshake.
- name: Full PQ (ML-KEM-768 + ML-DSA 65/87) session + measurements + challenge
- name: Full PQ (ML-KEM-768 + ML-DSA 65/87) session, attestation, key update, app data
run: |
export LD_LIBRARY_PATH=$HOME/wolfspdm-install/lib:$HOME/wolfssl-install/lib
export SPDM_EMU_PATH=$HOME/spdm-emu/build/bin
Expand Down Expand Up @@ -344,6 +343,9 @@ jobs:
run_pq "$pqc" "$dir" session --emu
run_pq "$pqc" "$dir" meas --meas
run_pq "$pqc" "$dir" challenge --challenge
run_pq "$pqc" "$dir" heartbeat --heartbeat
run_pq "$pqc" "$dir" keyupdate --key-update
run_pq "$pqc" "$dir" appdata --app-data
done

if [ -n "$FAILURES" ]; then
Expand Down
126 changes: 102 additions & 24 deletions .github/workflows/spdm-emu-test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -79,9 +79,9 @@ jobs:
make install

- name: Run unit tests
run: make check
env:
LD_LIBRARY_PATH: ${{ github.workspace }}/.libs:${{ github.workspace }}/src/.libs:${{ env.HOME }}/wolfssl-install/lib
run: |
export LD_LIBRARY_PATH="${{ github.workspace }}/.libs:${{ github.workspace }}/src/.libs:$HOME/wolfssl-install/lib"
make check

# --- spdm-emu (cached) ---
- name: Cache spdm-emu
Expand Down Expand Up @@ -109,26 +109,8 @@ jobs:
export LD_LIBRARY_PATH=$HOME/wolfspdm-install/lib:$HOME/wolfssl-install/lib
./examples/spdm_demo --help 2>&1 | head -20 || true

# --- Legacy smoke test (test/test_spdm) — single session against emu ---
- name: test/test_spdm smoke (one session)
run: |
export LD_LIBRARY_PATH=$HOME/wolfspdm-install/lib:$HOME/wolfssl-install/lib
export SPDM_EMU_PATH=$HOME/spdm-emu/build/bin
# Start emulator in background, run the legacy smoke, then kill it
(cd "$SPDM_EMU_PATH" && ./spdm_responder_emu --ver 1.2 \
--hash SHA_384 --asym ECDSA_P384 \
--dhe SECP_384_R1 --aead AES_256_GCM \
>/tmp/test_spdm_emu.log 2>&1) &
EMU_PID=$!
sleep 2
./test/test_spdm
RC=$?
kill $EMU_PID 2>/dev/null || true
wait $EMU_PID 2>/dev/null || true
exit $RC

# --- Full integration matrix (18 tests: 6 scenarios x SPDM 1.2/1.3/1.4) ---
- name: Run SPDM emulator tests (18-test matrix)
# --- Integration matrix (scenarios x SPDM 1.2/1.3/1.4; unbuilt ones skip) ---
- name: Run SPDM emulator tests
run: |
export LD_LIBRARY_PATH=$HOME/wolfspdm-install/lib:$HOME/wolfssl-install/lib
export SPDM_EMU_PATH=$HOME/spdm-emu/build/bin
Expand All @@ -143,4 +125,100 @@ jobs:
config.log
test/*.log
/tmp/spdm_emu_*.log
/tmp/test_spdm_emu.log

# CHUNK_SEND / CHUNK_GET: a small DataTransferSize on either side
spdm-emu-chunk:
name: chunking / wolfSPDM ${{ matrix.lib }} vs spdm-emu ${{ matrix.emu }}
runs-on: ubuntu-24.04
strategy:
fail-fast: false
matrix:
include:
- lib: dts64
emu: stock
- lib: default
emu: dts42
- lib: dts64
emu: dts42
env:
EMU_CAPS: CACHE,CERT,CHAL,MEAS_SIG,MEAS_FRESH,ENCRYPT,MAC,MUT_AUTH,KEY_EX,PSK_WITH_CONTEXT,ENCAP,HBEAT,KEY_UPD,HANDSHAKE_IN_CLEAR,SET_CERT,CSR,MULTI_KEY_NEG,GET_KEY_PAIR_INFO,SET_KEY_PAIR_INFO,LARGE_RESP,CHUNK
steps:
- uses: actions/checkout@v4

- name: Install dependencies
run: |
sudo apt-get update
sudo apt-get install -y autoconf automake libtool cmake libmbedtls-dev

- name: Compute cache period
id: cache-period
run: echo "biweekly=$(( $(date +%s) / 1296000 ))" >> $GITHUB_OUTPUT

- name: Cache wolfSSL
id: cache-wolfssl
uses: actions/cache@v4
with:
path: ~/wolfssl-install
key: wolfssl-spdm-ubuntu-24.04-${{ steps.cache-period.outputs.biweekly }}

- name: Build wolfSSL
if: steps.cache-wolfssl.outputs.cache-hit != 'true'
run: |
cd ~
git clone --depth 1 https://github.com/wolfSSL/wolfssl.git
cd wolfssl
./autogen.sh
./configure --enable-wolftpm --enable-ecc --enable-sha384 \
--enable-aesgcm --enable-hkdf --enable-sp \
--prefix=$HOME/wolfssl-install
make -j$(nproc)
make install

- name: Build wolfSPDM
run: |
./autogen.sh
./configure --with-wolfssl=$HOME/wolfssl-install \
CFLAGS="-O2 ${{ matrix.lib == 'dts64' && '-DWOLFSPDM_DATA_TRANSFER_SIZE=64' || '' }}"
make -j$(nproc)

- name: Run unit tests
run: LD_LIBRARY_PATH=$HOME/wolfssl-install/lib make check

# The stock build shares the main job's cache; dts42 shrinks the
# responder's DataTransferSize to the 42-byte minimum
- name: Cache spdm-emu
id: cache-spdm-emu
uses: actions/cache@v4
with:
path: ~/${{ matrix.emu == 'dts42' && 'spdm-emu-dts42' || 'spdm-emu' }}/build/bin
key: ${{ matrix.emu == 'dts42' && 'spdm-emu-dts42' || 'spdm-emu' }}-ubuntu-24.04-${{ steps.cache-period.outputs.biweekly }}

- name: Build spdm-emu
if: steps.cache-spdm-emu.outputs.cache-hit != 'true'
run: |
cd ~
git clone --depth 1 --recursive https://github.com/DMTF/spdm-emu.git \
${{ matrix.emu == 'dts42' && 'spdm-emu-dts42' || 'spdm-emu' }}
cd ${{ matrix.emu == 'dts42' && 'spdm-emu-dts42' || 'spdm-emu' }}
mkdir build && cd build
cmake -DARCH=x64 -DTOOLCHAIN=GCC -DTARGET=Release -DCRYPTO=mbedtls \
-DCMAKE_C_FLAGS="${{ matrix.emu == 'dts42' && '-DLIBSPDM_RECEIVER_BUFFER_SIZE=170' || '' }}" ..
make copy_sample_key
make -j$(nproc)

- name: Run SPDM emulator tests with chunking
run: |
export LD_LIBRARY_PATH=$HOME/wolfssl-install/lib:${{ github.workspace }}/.libs
export SPDM_EMU_PATH=$HOME/${{ matrix.emu == 'dts42' && 'spdm-emu-dts42' || 'spdm-emu' }}/build/bin
export SPDM_EMU_ARGS="--cap $EMU_CAPS"
./examples/spdm_test.sh

- name: Upload logs on failure
if: failure()
uses: actions/upload-artifact@v4
with:
name: spdm-emu-chunk-${{ matrix.lib }}-${{ matrix.emu }}
path: |
config.log
test/*.log
/tmp/spdm_emu_*.log
3 changes: 2 additions & 1 deletion .github/workflows/static-analysis.yml
Original file line number Diff line number Diff line change
Expand Up @@ -48,6 +48,7 @@ jobs:
--error-exitcode=1 \
--suppress=missingIncludeSystem \
--suppress=constParameterPointer \
--suppress=constParameterCallback \
--suppress=knownConditionTrueFalse \
--inline-suppr \
-I wolfspdm -I src -I $HOME/wolfssl-install/include \
Expand Down Expand Up @@ -88,7 +89,7 @@ jobs:
- name: Configure
run: |
./autogen.sh
./configure --with-wolfssl=$HOME/wolfssl-install
./configure --with-wolfssl=$HOME/wolfssl-install --enable-nuvoton --enable-nations --enable-responder

- name: Run scan-build
run: scan-build --status-bugs -o scan-results make -j$(nproc)
Expand Down
16 changes: 8 additions & 8 deletions .github/workflows/wolfssl-versions.yml
Original file line number Diff line number Diff line change
Expand Up @@ -115,27 +115,27 @@ jobs:
MLDSA_FLAG=""
if [ "${{ matrix.pqc }}" = "true" ]; then MLDSA_FLAG="--enable-mldsa"; fi
./autogen.sh
./configure --with-wolfssl=$HOME/wolfssl-install $MLDSA_FLAG
./configure --with-wolfssl=$HOME/wolfssl-install --enable-nuvoton --enable-nations --enable-responder $MLDSA_FLAG
make -j"$(nproc)"

- name: Run unit tests
run: make check
env:
LD_LIBRARY_PATH: ${{ github.workspace }}/src/.libs:${{ env.HOME }}/wolfssl-install/lib
run: |
export LD_LIBRARY_PATH="${{ github.workspace }}/src/.libs:$HOME/wolfssl-install/lib"
make check

- name: Build with --enable-dynamic-mem
run: |
MLDSA_FLAG=""
if [ "${{ matrix.pqc }}" = "true" ]; then MLDSA_FLAG="--enable-mldsa"; fi
make distclean || true
./autogen.sh
./configure --with-wolfssl=$HOME/wolfssl-install --enable-dynamic-mem $MLDSA_FLAG
./configure --with-wolfssl=$HOME/wolfssl-install --enable-nuvoton --enable-nations --enable-responder --enable-dynamic-mem $MLDSA_FLAG
make -j"$(nproc)"

- name: Run unit tests (dynamic-mem)
run: make check
env:
LD_LIBRARY_PATH: ${{ github.workspace }}/src/.libs:${{ env.HOME }}/wolfssl-install/lib
run: |
export LD_LIBRARY_PATH="${{ github.workspace }}/src/.libs:$HOME/wolfssl-install/lib"
make check

- name: Upload failure logs
if: failure()
Expand Down
Loading
Loading