Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/copilot-instructions.md
Original file line number Diff line number Diff line change
Expand Up @@ -70,7 +70,7 @@ noise rather than safety.
- Raw libc calls (`memcpy`, `memset`, `strlen`, ...) in the core library: these
are caught deterministically by the Semgrep gate and should use the
`XMEMCPY`/`XMEMSET`/`XSTRLEN` wrappers. Do not duplicate that as a review
comment. (The vendored `src/spdm/` and `src/fwtpm/` trees are exempt.)
comment. (The vendored `lib/wolfSPDM/`, `src/spdm/` and `src/fwtpm/` trees are exempt.)
- C++ idioms or constructs outside C89/C99. wolfTPM targets C89/C99 and must
compile across its many feature configurations.
- `TPM2_ForceZero` replaced by `memset`/`XMEMSET` (the project deliberately uses
Expand Down
5 changes: 4 additions & 1 deletion .github/semgrep-rules.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
#
# Style/maintainability is intentionally out of scope (owned by codespell,
# Coverity, and the CodeQL security suite). These rules only enforce security
# invariants. The vendored src/spdm/ and src/fwtpm/ trees, the HAL platform
# invariants. The vendored lib/wolfSPDM/, src/spdm/ and src/fwtpm/ trees, the HAL platform
# drivers, and the swtpm socket transport carry their own platform libc usage
# and are excluded where noted.

Expand All @@ -24,6 +24,7 @@ rules:
- src/
- hal/
- wolftpm/
- lib/wolfSPDM/src/
pattern-either:
- pattern: gets(...)
- pattern: strcpy(...)
Expand All @@ -43,6 +44,7 @@ rules:
- src/
- hal/
- wolftpm/
- lib/wolfSPDM/src/
pattern-either:
- pattern: system(...)
- pattern: popen(...)
Expand Down Expand Up @@ -72,6 +74,7 @@ rules:
- src/
exclude:
- src/spdm/
- lib/wolfSPDM/
- src/fwtpm/
- src/tpm2_swtpm.c
pattern-either:
Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/cmake-build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -138,6 +138,8 @@ jobs:
steps:
#pull wolfTPM
- uses: actions/checkout@master
with:
submodules: true

# Install cmake (matrix includes a Windows leg, so this job stays on the host
# runner; apt is made resilient instead of moving into the Linux CI image)
Expand Down Expand Up @@ -227,6 +229,8 @@ jobs:
password: ${{ secrets.GITHUB_TOKEN }}
steps:
- uses: actions/checkout@master
with:
submodules: true

# Same wolfSSL config as the matrix build above, so it shares that cache
# entry (key includes only OS + commit, not the wolfTPM options).
Expand Down
2 changes: 2 additions & 0 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -27,6 +27,8 @@ jobs:
steps:
- name: Checkout wolfTPM
uses: actions/checkout@v4
with:
submodules: true

# CodeQL's action is fiddly inside a custom container, so keep this job
# on the host runner and just make apt resilient to mirror timeouts.
Expand Down
2 changes: 2 additions & 0 deletions .github/workflows/codespell.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,8 @@ jobs:
steps:
- name: Checkout wolfTPM
uses: actions/checkout@v4
with:
submodules: true

- name: Run codespell
uses: codespell-project/actions-codespell@v2
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/coverity-scan-fixes.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,7 @@ jobs:
steps:
- uses: actions/checkout@v4
with:
submodules: true
ref: master

# Cache the built wolfSSL tree keyed on the resolved upstream commit so it
Expand Down
2 changes: 2 additions & 0 deletions .github/workflows/freestanding-build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,8 @@ jobs:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
submodules: true

- name: Write freestanding user_settings.h (types + mem/str, no libc)
run: |
Expand Down
2 changes: 2 additions & 0 deletions .github/workflows/fuzz.yml
Original file line number Diff line number Diff line change
Expand Up @@ -51,6 +51,8 @@ jobs:
steps:
- name: Checkout wolfTPM
uses: actions/checkout@v4
with:
submodules: true

- name: ASLR workaround
run: sudo sysctl vm.mmap_rnd_bits=28
Expand Down
12 changes: 12 additions & 0 deletions .github/workflows/fwtpm-test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -282,6 +282,8 @@ jobs:
steps:
- name: Checkout wolfTPM
uses: actions/checkout@v4
with:
submodules: true

# Matrix includes a macOS leg, so this job stays on the host runner;
# apt is made resilient rather than moving into the Linux CI image.
Expand Down Expand Up @@ -461,6 +463,8 @@ jobs:
steps:
- name: Checkout wolfTPM
uses: actions/checkout@v4
with:
submodules: true

- name: Setup wolfSSL
uses: ./.github/actions/setup-wolfssl
Expand Down Expand Up @@ -491,6 +495,8 @@ jobs:
steps:
- name: Checkout wolfTPM
uses: actions/checkout@v4
with:
submodules: true

- name: Setup wolfSSL
uses: ./.github/actions/setup-wolfssl
Expand Down Expand Up @@ -528,6 +534,8 @@ jobs:
# (where it passes) and just make apt resilient to mirror timeouts.
steps:
- uses: actions/checkout@master
with:
submodules: true

- name: Install tpm2-tools
uses: ./.github/actions/apt-retry
Expand Down Expand Up @@ -565,6 +573,8 @@ jobs:
steps:
- name: Checkout wolfTPM
uses: actions/checkout@v4
with:
submodules: true

- name: Checkout wolfSSL
uses: actions/checkout@v4
Expand Down Expand Up @@ -663,6 +673,8 @@ jobs:
steps:
- name: Checkout wolfTPM
uses: actions/checkout@v4
with:
submodules: true

- name: Setup wolfSSL
uses: ./.github/actions/setup-wolfssl
Expand Down
2 changes: 2 additions & 0 deletions .github/workflows/make-test-swtpm.yml
Original file line number Diff line number Diff line change
Expand Up @@ -380,6 +380,8 @@ jobs:
steps:
- name: Checkout wolfTPM
uses: actions/checkout@master
with:
submodules: true

# Build (or restore from cache) + install wolfSSL. The action caches the
# built ./wolfssl tree keyed on the resolved wolfSSL commit + this config,
Expand Down
2 changes: 2 additions & 0 deletions .github/workflows/multi-compiler.yml
Original file line number Diff line number Diff line change
Expand Up @@ -94,6 +94,8 @@ jobs:
# Checkout first so the local apt-retry composite action is on disk.
- name: Checkout wolfTPM
uses: actions/checkout@v4
with:
submodules: true

# Version-specific compilers are not baked into the CI image; keep this
# job on the host runner and just make apt resilient to mirror timeouts.
Expand Down
6 changes: 6 additions & 0 deletions .github/workflows/pqc-build-matrix.yml
Original file line number Diff line number Diff line change
Expand Up @@ -109,6 +109,8 @@ jobs:
steps:
- name: Checkout wolfTPM
uses: actions/checkout@v4
with:
submodules: true

- name: Setup wolfSSL with PQC
uses: ./.github/actions/setup-wolfssl
Expand Down Expand Up @@ -160,6 +162,8 @@ jobs:
steps:
- name: Checkout wolfTPM
uses: actions/checkout@v4
with:
submodules: true

- name: Build wolfTPM standalone (${{ matrix.name }})
run: |
Expand Down Expand Up @@ -188,6 +192,8 @@ jobs:
steps:
- name: Checkout wolfTPM
uses: actions/checkout@v4
with:
submodules: true
- name: Setup wolfSSL with PQC
uses: ./.github/actions/setup-wolfssl
with:
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/pqc-examples.yml
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,8 @@ jobs:
steps:
- name: Checkout wolfTPM
uses: actions/checkout@v4
with:
submodules: true

- name: Install tpm2-tools
uses: ./.github/actions/apt-retry
Expand Down Expand Up @@ -199,6 +201,7 @@ jobs:
- name: Checkout wolfTPM
uses: actions/checkout@v4
with:
submodules: true
persist-credentials: false

- name: Setup wolfSSL with PQC TLS
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/publish-ci-image.yml
Original file line number Diff line number Diff line change
Expand Up @@ -48,6 +48,7 @@ jobs:
steps:
- uses: actions/checkout@v4
with:
submodules: true
fetch-depth: 1

- name: Compute lowercase owner
Expand Down
6 changes: 6 additions & 0 deletions .github/workflows/release-checks.yml
Original file line number Diff line number Diff line change
Expand Up @@ -78,6 +78,8 @@ jobs:
steps:
- name: Checkout wolfTPM
uses: actions/checkout@v4
with:
submodules: true

- name: Download wolfSSL
uses: actions/download-artifact@v4
Expand Down Expand Up @@ -122,6 +124,8 @@ jobs:
steps:
- name: Checkout wolfTPM
uses: actions/checkout@v4
with:
submodules: true

- name: Download wolfSSL
uses: actions/download-artifact@v4
Expand Down Expand Up @@ -165,6 +169,8 @@ jobs:
steps:
- name: Checkout wolfTPM
uses: actions/checkout@v4
with:
submodules: true

# PQC-enabled wolfSSL is a superset of what fwTPM and SPDM need, so one
# install covers the maximal rebuild below.
Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/rust-test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -37,6 +37,8 @@ jobs:
steps:
- name: Checkout wolfTPM
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
with:
submodules: true

# Build + install wolfSSL with the crypto-callback support the wrapper
# (and the TPM-backed TLS bridge) needs; installs to /usr/local so
Expand Down Expand Up @@ -112,6 +114,8 @@ jobs:
steps:
- name: Checkout wolfTPM
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
with:
submodules: true
- name: Setup wolfSSL
uses: ./.github/actions/setup-wolfssl
with:
Expand Down
2 changes: 2 additions & 0 deletions .github/workflows/sanitizer.yml
Original file line number Diff line number Diff line change
Expand Up @@ -103,6 +103,8 @@ jobs:

- name: Checkout wolfTPM
uses: actions/checkout@v4
with:
submodules: true

- name: Install tpm2-tools
uses: ./.github/actions/apt-retry
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/sbom.yml
Original file line number Diff line number Diff line change
Expand Up @@ -28,6 +28,7 @@ jobs:
- name: Checkout wolftpm
uses: actions/checkout@v4
with:
submodules: true
path: wolftpm

# wolfTPM links wolfSSL/wolfCrypt, so its SBOM records wolfSSL as a
Expand Down Expand Up @@ -155,6 +156,8 @@ jobs:

steps:
- uses: actions/checkout@v4
with:
submodules: true

- name: Read the pinned wolfGlass revision
id: pin
Expand Down
2 changes: 2 additions & 0 deletions .github/workflows/seal-test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -34,6 +34,8 @@ jobs:
steps:
- name: Checkout wolfTPM
uses: actions/checkout@v4
with:
submodules: true

- name: Setup wolfSSL
uses: ./.github/actions/setup-wolfssl
Expand Down
2 changes: 2 additions & 0 deletions .github/workflows/semgrep.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,8 @@ jobs:
timeout-minutes: 10
steps:
- uses: actions/checkout@v4
with:
submodules: true

- uses: actions/setup-python@v5
with:
Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/smoke-test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -31,6 +31,8 @@ jobs:
steps:
- name: Checkout wolfTPM
uses: actions/checkout@v4
with:
submodules: true

- name: Check for bare C scope blocks
run: python3 scripts/check-empty-brace-scopes.py
Expand All @@ -54,6 +56,8 @@ jobs:
steps:
- name: Checkout wolfTPM
uses: actions/checkout@v4
with:
submodules: true

- name: Setup wolfSSL
uses: ./.github/actions/setup-wolfssl
Expand Down
18 changes: 18 additions & 0 deletions .github/workflows/spdm-test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,8 @@ on:
branches: [master]
paths:
- 'src/spdm/**'
- 'lib/wolfSPDM'
- '.gitmodules'
- 'wolftpm/spdm/**'
- 'src/fwtpm/**'
- 'wolftpm/fwtpm/**'
Expand Down Expand Up @@ -64,6 +66,7 @@ jobs:
- name: Checkout wolfTPM
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5
with:
submodules: true
persist-credentials: false

- name: Setup wolfSSL
Expand All @@ -80,6 +83,20 @@ jobs:
--with-wolfcrypt=$HOME/wolfssl-install
make -j"$(nproc)"

- name: Compile against the installed headers (${{ matrix.name }})
run: |
set -e
make install DESTDIR="$PWD/inst" >/dev/null
printf '%s\n' '#include <wolftpm/tpm2_wrap.h>' \
'#include <wolftpm/spdm/spdm.h>' '#include <wolfspdm/spdm.h>' \
'int main(void) { return 0; }' > consumer.c
cc -c consumer.c -o consumer.o -I"$PWD/inst/usr/local/include" \
-I"$HOME/wolfssl-install/include"
printf '%s\n' '#include <wolfspdm/spdm.h>' \
'int main(void) { return 0; }' > consumer2.c
cc -c consumer2.c -o consumer2.o -I"$PWD/inst/usr/local/include" \
-I"$HOME/wolfssl-install/include"

- name: Test unavailable vendor rejection (${{ matrix.name }})
if: matrix.name == 'spdm-nuvoton' || matrix.name == 'spdm-nations'
run: |
Expand Down Expand Up @@ -124,6 +141,7 @@ jobs:
- name: Checkout wolfTPM
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5
with:
submodules: true
persist-credentials: false

- name: Setup wolfSSL
Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/wolfhal-build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,8 @@ jobs:
steps:
- name: Checkout wolfTPM
uses: actions/checkout@v4
with:
submodules: true

- name: Install ARM toolchain
uses: ./.github/actions/apt-retry
Expand Down Expand Up @@ -125,6 +127,8 @@ jobs:
steps:
- name: Checkout wolfTPM
uses: actions/checkout@v4
with:
submodules: true

- name: Setup wolfSSL
uses: ./.github/actions/setup-wolfssl
Expand Down
Loading
Loading