From 177dc9dcf4f87d74cb47f2733af8975a2929b864 Mon Sep 17 00:00:00 2001 From: Aidan Garske Date: Wed, 30 Sep 2026 16:22:18 -0700 Subject: [PATCH 1/2] Restore the upstream wolfHSM pin and initialize guest sessions --- .github/workflows/auto-pin-dependencies.yml | 2 +- .gitmodules | 2 +- docs/Building.md | 4 ++++ docs/Crypto-Engines.md | 4 ++++ lib/wolfHSM | 2 +- .../wolfhsm-client/src/wolfhsm_client_glue.c | 10 ++++++++++ tests/host/wolfhsm_relay/main.c | 15 +++++++++++++++ 7 files changed, 36 insertions(+), 3 deletions(-) diff --git a/.github/workflows/auto-pin-dependencies.yml b/.github/workflows/auto-pin-dependencies.yml index 35c5ed1c..b2c82f98 100644 --- a/.github/workflows/auto-pin-dependencies.yml +++ b/.github/workflows/auto-pin-dependencies.yml @@ -38,7 +38,7 @@ jobs: # fork-only runtime-devId/device-ID changes. specs=( "lib/wolfSSL|https://github.com/wolfSSL/wolfSSL.git|v*-stable|51975e27a5439668733976a584d417dfd7776026" - "lib/wolfHSM|https://github.com/wolfSSL/wolfHSM.git|wolfHSM-v*|97dbbd72ad2bf757279d7dc5101580290525c647" + "lib/wolfHSM|https://github.com/wolfSSL/wolfHSM.git|wolfHSM-v*|66e2482333ff175a14d10a25c501367362212a38" "lib/wolfIP|https://github.com/wolfSSL/wolfIP.git|v*|" ) diff --git a/.gitmodules b/.gitmodules index 9578e24c..1ac32c54 100644 --- a/.gitmodules +++ b/.gitmodules @@ -1,6 +1,6 @@ [submodule "lib/wolfHSM"] path = lib/wolfHSM - url = https://github.com/aidangarske/wolfHSM.git + url = https://github.com/wolfSSL/wolfHSM.git [submodule "lib/wolfSSL"] path = lib/wolfSSL url = git@github.com:wolfSSL/wolfSSL.git diff --git a/docs/Building.md b/docs/Building.md index b7ed8f2e..4d546cad 100644 --- a/docs/Building.md +++ b/docs/Building.md @@ -20,6 +20,10 @@ equivalent Git URL rewrite before initializing them. git submodule update --init --recursive ``` +The wolfHSM pin is on upstream `main` and includes the 128-bit flash programming +support merged in wolfHSM PR #524. Automatic release bumps require that merge +commit so an older release cannot drop the STM32H563 flash support. + The Zephyr guest build additionally uses a Python virtual environment, CMake, Ninja, and network access to create its v4.2.0 workspace. The FreeRTOS guest build uses the Arm cross-toolchain and network access; its default source diff --git a/docs/Crypto-Engines.md b/docs/Crypto-Engines.md index 9444dc91..2053a857 100644 --- a/docs/Crypto-Engines.md +++ b/docs/Crypto-Engines.md @@ -151,6 +151,10 @@ size difference lives. ## wolfHSM engine +Guest initialization completes wolfHSM's `COMM INIT` handshake before enabling +crypto requests. A failed handshake releases the client transport. Transient +connection failures use the existing initialization retry. + The wolfHSM engine links the wolfHSM client/server protocol and creates one Secure server context for each configured guest. Guest wolfPSA calls use wolfCrypt's crypto-callback path, the wolfHSM client serializes the request, diff --git a/lib/wolfHSM b/lib/wolfHSM index 97dbbd72..66e24823 160000 --- a/lib/wolfHSM +++ b/lib/wolfHSM @@ -1 +1 @@ -Subproject commit 97dbbd72ad2bf757279d7dc5101580290525c647 +Subproject commit 66e2482333ff175a14d10a25c501367362212a38 diff --git a/tests/firmware/zephyr-stm32h5/module/wolfhsm-client/src/wolfhsm_client_glue.c b/tests/firmware/zephyr-stm32h5/module/wolfhsm-client/src/wolfhsm_client_glue.c index 1d6e9fe5..8180d55c 100644 --- a/tests/firmware/zephyr-stm32h5/module/wolfhsm-client/src/wolfhsm_client_glue.c +++ b/tests/firmware/zephyr-stm32h5/module/wolfhsm-client/src/wolfhsm_client_glue.c @@ -82,6 +82,16 @@ static int wolfhsm_guest_connect(void) return rc; } + /* Bind the client namespace before the server accepts crypto requests. */ + rc = wh_Client_CommInitRequest(&g_client_ctx); + if (rc == WH_ERROR_OK) { + rc = wh_Client_CommInitResponse(&g_client_ctx, NULL, NULL); + } + if (rc != WH_ERROR_OK) { + (void)wh_Client_Cleanup(&g_client_ctx); + return rc; + } + g_client_ready = 1; if (g_retry_crypto_initialized != 0) { (void)wolfCrypt_Cleanup(); diff --git a/tests/host/wolfhsm_relay/main.c b/tests/host/wolfhsm_relay/main.c index fc9062bb..cbcc6515 100644 --- a/tests/host/wolfhsm_relay/main.c +++ b/tests/host/wolfhsm_relay/main.c @@ -61,6 +61,7 @@ static int g_failures; static int32_t g_connect_error; static unsigned int g_connect_count; +static unsigned int g_close_count; extern int (*test_wolfhsm_sys_init)(void); int wolfhsm_guest_init(void); @@ -152,6 +153,7 @@ int32_t WolfTrust_FFM_Connect(uint32_t sid, uint32_t version) void WolfTrust_FFM_Close(int32_t handle) { + g_close_count++; (void)wt_ffm_close(&g_runtime, TEST_NS_CLIENT, handle); } @@ -314,6 +316,7 @@ static void test_guest_init_retry(void) WC_RNG rng; uint8_t output[32]; unsigned int connected_count; + unsigned int closed_count; (void)memset(&rng, 0, sizeof(rng)); rng.devId = WH_DEV_ID; @@ -338,6 +341,18 @@ static void test_guest_init_retry(void) check(wc_CryptoCb_RandomBlock(&rng, output, sizeof(output)) == 0, "successful guest SYS_INIT serves crypto operations"); (void)wh_Client_Cleanup(wolfhsm_guest_client()); + + wt_hsm_relay_set_submit(NULL, NULL); + closed_count = g_close_count; + check(wolfhsm_guest_init() == WH_ERROR_ABORTED && + g_close_count == closed_count + 1U && + wc_CryptoCb_IsDeviceRegistered(WH_DEV_ID) == 0, + "WT-FFM-0054 failed COMM INIT closes the client connection"); + wt_hsm_relay_set_submit(test_relay_submit, NULL); + check(wolfhsm_guest_init() == WH_ERROR_OK && + wc_CryptoCb_RandomBlock(&rng, output, sizeof(output)) == 0, + "WT-FFM-0054 guest init recovers after failed COMM INIT"); + (void)wh_Client_Cleanup(wolfhsm_guest_client()); } int main(void) From c279a2b98fc960d6855c4c9cb388ea4994b7dfe7 Mon Sep 17 00:00:00 2001 From: Aidan Garske Date: Thu, 1 Oct 2026 09:08:06 -0700 Subject: [PATCH 2/2] Preserve startup retry after wolfHSM handshake failures --- docs/Crypto-Engines.md | 4 +++- .../module/wolfhsm-client/src/wolfhsm_client_glue.c | 3 +++ tests/host/wolfhsm_relay/main.c | 12 ++++++++++++ 3 files changed, 18 insertions(+), 1 deletion(-) diff --git a/docs/Crypto-Engines.md b/docs/Crypto-Engines.md index 2053a857..c677aa3c 100644 --- a/docs/Crypto-Engines.md +++ b/docs/Crypto-Engines.md @@ -153,7 +153,9 @@ size difference lives. Guest initialization completes wolfHSM's `COMM INIT` handshake before enabling crypto requests. A failed handshake releases the client transport. Transient -connection failures use the existing initialization retry. +connection failures use the existing initialization retry. When that retry is +active, a failed handshake restores its callback so the next crypto request +can retry without an explicit guest initialization call. The wolfHSM engine links the wolfHSM client/server protocol and creates one Secure server context for each configured guest. Guest wolfPSA calls use diff --git a/tests/firmware/zephyr-stm32h5/module/wolfhsm-client/src/wolfhsm_client_glue.c b/tests/firmware/zephyr-stm32h5/module/wolfhsm-client/src/wolfhsm_client_glue.c index 8180d55c..e25e113e 100644 --- a/tests/firmware/zephyr-stm32h5/module/wolfhsm-client/src/wolfhsm_client_glue.c +++ b/tests/firmware/zephyr-stm32h5/module/wolfhsm-client/src/wolfhsm_client_glue.c @@ -89,6 +89,9 @@ static int wolfhsm_guest_connect(void) } if (rc != WH_ERROR_OK) { (void)wh_Client_Cleanup(&g_client_ctx); + if (g_retry_crypto_initialized != 0) { + (void)wolfhsm_guest_register_retry(); + } return rc; } diff --git a/tests/host/wolfhsm_relay/main.c b/tests/host/wolfhsm_relay/main.c index cbcc6515..24a9ef96 100644 --- a/tests/host/wolfhsm_relay/main.c +++ b/tests/host/wolfhsm_relay/main.c @@ -327,6 +327,18 @@ static void test_guest_init_retry(void) check(wc_CryptoCb_RandomBlock(&rng, output, sizeof(output)) == WC_HW_E, "HSM callback remains retryable after repeated failures"); g_connect_error = PSA_SUCCESS; + wt_hsm_relay_set_submit(NULL, NULL); + closed_count = g_close_count; + check(wc_CryptoCb_RandomBlock(&rng, output, sizeof(output)) == WC_HW_E, + "WT-FFM-0054 failed retry handshake fails closed"); + check(g_close_count == closed_count + 1U, + "failed retry handshake closes the client connection"); + check(wc_CryptoCb_IsDeviceRegistered(WH_DEV_ID) != 0, + "failed retry handshake restores the retry callback"); + check(wc_CryptoCb_RandomBlock(&rng, output, sizeof(output)) == WC_HW_E && + wc_CryptoCb_IsDeviceRegistered(WH_DEV_ID) != 0, + "repeated handshake failures preserve automatic retry"); + wt_hsm_relay_set_submit(test_relay_submit, NULL); (void)memset(output, 0, sizeof(output)); check(wc_CryptoCb_RandomBlock(&rng, output, sizeof(output)) == 0 && buf_is_zero(output, sizeof(output)) == 0,