Build SPDM from the wolfSPDM submodule - #617
aidangarske wants to merge 4 commits into
Conversation
There was a problem hiding this comment.
Warning
Copilot couldn't run its full agentic review because it didn't start before the timeout. Make sure your repository has a runner available, or add a copilot-code-review.yml file specifying one with the runs-on attribute. See the docs for more details.
Copilot review overview
Review effort: Lite
Findings: None
What changed in this PR
This PR migrates wolfTPM’s SPDM implementation to the lib/wolfSPDM git submodule, removing duplicated SPDM sources and building against the consolidated wolfSPDM library while preserving existing wolfTPM include paths via forwarding headers.
Changes:
- Replaced in-tree SPDM sources with submodule sources in
lib/wolfSPDM/srcand updated Automake source lists accordingly. - Converted
wolftpm/spdm/*.hto forwarding headers that include wolfSPDM headers whenWOLFTPM_SPDMis enabled, while retaining Nations-specific TPM constants locally. - Updated configure + CI/workflows to require/checkout the submodule and validated installed-header consumption via consumer compile steps.
| File | Description |
|---|---|
| wolftpm/spdm/spdm.h | Forwarding header to <wolfspdm/spdm.h> gated by WOLFTPM_SPDM. |
| wolftpm/spdm/spdm_types.h | Forwarding header to <wolfspdm/spdm_types.h> gated by WOLFTPM_SPDM. |
| wolftpm/spdm/spdm_error.h | Forwarding header to <wolfspdm/spdm_error.h> gated by WOLFTPM_SPDM. |
| wolftpm/spdm/spdm_tcg.h | Forwarding header to <wolfspdm/spdm_tcg.h> gated by WOLFTPM_SPDM. |
| wolftpm/spdm/spdm_psk.h | Forwarding header to <wolfspdm/spdm_psk.h> gated by WOLFTPM_SPDM. |
| wolftpm/spdm/spdm_responder.h | Forwarding header to <wolfspdm/spdm_responder.h> gated by WOLFTPM_SPDM. |
| wolftpm/spdm/spdm_nuvoton.h | Forwarding header to <wolfspdm/spdm_nuvoton.h> gated by WOLFTPM_SPDM. |
| wolftpm/spdm/spdm_nations.h | Forwarding to <wolfspdm/spdm_nations.h> and retains Nations TPM constants under WOLFSPDM_NATIONS. |
| wolftpm/include.am | Installs wolfSPDM public headers and wolfspdm/options.h when BUILD_SPDM is enabled. |
| src/spdm/wolfspdm/options.h | Adds an installed wolfspdm/options.h that includes <wolftpm/options.h>. |
| src/spdm/include.am | Builds SPDM from lib/wolfSPDM/src and ships needed submodule files in dist. |
| src/fwtpm/include.am | Switches fwTPM SPDM build inputs to lib/wolfSPDM/src. |
| configure.ac | Fails early if submodule isn’t checked out and adds wolfSPDM include paths. |
| .gitmodules | Adds lib/wolfSPDM submodule configuration. |
| src/spdm/README.md | Documents the submodule-based SPDM arrangement and clone/update instructions. |
| .github/workflows/*.yml | Ensures CI checkouts include submodules; expands SPDM workflow triggers and adds consumer header compile checks. |
| .github/semgrep-rules.yml | Expands Semgrep scanning to cover lib/wolfSPDM/src appropriately. |
| .github/copilot-instructions.md | Updates vendored-tree exemptions to include lib/wolfSPDM/. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #617
Scan targets checked: wolftpm-src, wolftpm-bugs
Coverage: 5 of 8 in-scope changed file(s) opened by the reviewer; not opened: wolftpm/spdm/spdm.h, wolftpm/spdm/spdm_error.h, wolftpm/spdm/spdm_nuvoton.h
Fenrir result: Approved ✅
No new issues found in the changed files.
Advisory only — this automated result does not count as a GitHub approval.
Review tier: Lite
Summary
wolfTPM's SPDM code (
src/spdm/*.c,spdm_internal.h) now lives in the wolfSPDM library, and this PR consumes it as thelib/wolfSPDMgit submodule. This removes the duplicated SPDM stack, so SPDM fixes land once in wolfSPDM and both projects pick them up.--enable-spdmstill compiles the SPDM sources into libwolftpm. wolfSPDM builds in its TPM profile, forced byWOLFTPM_SPDM, which compiles out:libwolftpm exports no standard-requester symbols, and the SPDM context stays about 9.5 KB.
Paired with wolfSSL/wolfSPDM#34. The submodule is pinned to that branch; it moves to a wolfSPDM release tag once that PR merges.
Changes
.gitmodulesaddslib/wolfSPDMwithignore = dirty, because in-tree builds write objects there.--enable-spdmfails with a clear message when the submodule isn't checked out, and addslib/wolfSPDMandlib/wolfSPDM/srcto the include path.src/spdm/include.amandsrc/fwtpm/include.amcompile fromlib/wolfSPDM/src. The configure switches and their gating are unchanged.wolftpm/spdm/*.hare now forwarding headers to<wolfspdm/*.h>, so existing includes keep working.TPM_CC/TPM_PTconstants stay inwolftpm/spdm/spdm_nations.h.<wolftpm/tpm2_types.h>first, so it picks up wolfTPM's options, and forwards only whenWOLFTPM_SPDMis set.make installalso installswolfspdm/*.h, plus awolfspdm/options.hthat includes<wolftpm/options.h>, so<wolfspdm/spdm.h>works as a first include.WOLFTPM_SPDM_TCG/WOLFTPM_SPDM_PSKfrom the vendor macros again, so user-settings builds that define onlyWOLFTPM_SPDMplus a vendor keep the TCG and PSK wrappers.src/spdm/unit_test.cstays in wolfTPM and runs against the submodule code.submodules: true. The SPDM build matrix installs each config and compiles consumers against only the installed headers, in both include orders.spdm-test.ymlalso triggers onlib/wolfSPDMand.gitmodules.lib/wolfSPDM/src/; the X-wrapper and copilot exemptions listlib/wolfSPDM/.src/spdm/README.mddocuments the submodule.What wolfSPDM brings to wolfTPM
These fixes come from reviewing the consolidated stack. The wolfTPM-side ones also apply to wolfTPM
mastertoday.Responder (fwTPM)
Requester
Upgrade notes
git submodule update --init. New clones should use--recursive.git archiveomits submodules. Build release tarballs withmake dist, which includes the wolfSPDM files.Testing
spdm-test.yml/make-test-swtpm.yml(base-only, tcg-only, both, nuvoton, nations, full-vendors, requester-only, debug, no-getenv, nuvoton/nations smallstack, nations-debug, nuvoton/nations autodisable)master; 0 standard-requester symbols exportedspdm_test.sh fwtpm-tcg)spdm_test.sh fwtpm-psk)make check(full build)tests/fwtpm_check.shfails exactly as onmasterin the same lab, because that wolfSSL build lacks salted-session support; it is unrelated to SPDM.make dist--enable-spdm --enable-nuvoton --enable-nationsspdm_test.sh nuvoton, identity key pinned)masteron the same board gives the identical 8/9. The one failure, in both, istests/unit_tests.ccallingwolfTPM2_GetCapability_SPDMSessionInfo, which this firmware rejects withTPM_RC_VALUE.Known issues seen on the bench (not changed here, same on
master)Tracked in wolfSSL/wolfSPDM #19, #20 and #21.
spdm_ctrl --get-pubkeyfails on Nuvoton. It sends GET_PUBK without GET_VERSION first, and the firmware replies with ERROR UnexpectedRequest. It also prints only the first 32 bytes of the TPMT_PUBLIC. To pin the key for the bench, I read it with GET_VERSION and then GET_PUBK.spdm_ctrlprints SPDM errors as "unknown error number". It formats wolfSPDM error codes withTPM2_GetRCString.Before merge
lib/wolfSPDMfromwolftpm-coreto the wolfSPDM release tag.