Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/auto-pin-dependencies.yml
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,7 @@ jobs:
# fork-only runtime-devId/device-ID changes.
specs=(
"lib/wolfSSL|https://github.com/wolfSSL/wolfSSL.git|v*-stable|51975e27a5439668733976a584d417dfd7776026"
"lib/wolfHSM|https://github.com/wolfSSL/wolfHSM.git|wolfHSM-v*|97dbbd72ad2bf757279d7dc5101580290525c647"
"lib/wolfHSM|https://github.com/wolfSSL/wolfHSM.git|wolfHSM-v*|66e2482333ff175a14d10a25c501367362212a38"
"lib/wolfIP|https://github.com/wolfSSL/wolfIP.git|v*|"
)

Expand Down
2 changes: 1 addition & 1 deletion .gitmodules
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
[submodule "lib/wolfHSM"]
path = lib/wolfHSM
url = https://github.com/aidangarske/wolfHSM.git
url = https://github.com/wolfSSL/wolfHSM.git
[submodule "lib/wolfSSL"]
path = lib/wolfSSL
url = git@github.com:wolfSSL/wolfSSL.git
Expand Down
4 changes: 4 additions & 0 deletions docs/Building.md
Original file line number Diff line number Diff line change
Expand Up @@ -20,6 +20,10 @@ equivalent Git URL rewrite before initializing them.
git submodule update --init --recursive
```

The wolfHSM pin is on upstream `main` and includes the 128-bit flash programming
support merged in wolfHSM PR #524. Automatic release bumps require that merge
commit so an older release cannot drop the STM32H563 flash support.

The Zephyr guest build additionally uses a Python virtual environment, CMake,
Ninja, and network access to create its v4.2.0 workspace. The FreeRTOS guest
build uses the Arm cross-toolchain and network access; its default source
Expand Down
6 changes: 6 additions & 0 deletions docs/Crypto-Engines.md
Original file line number Diff line number Diff line change
Expand Up @@ -151,6 +151,12 @@ size difference lives.

## wolfHSM engine

Guest initialization completes wolfHSM's `COMM INIT` handshake before enabling
crypto requests. A failed handshake releases the client transport. Transient
connection failures use the existing initialization retry. When that retry is
active, a failed handshake restores its callback so the next crypto request
can retry without an explicit guest initialization call.

The wolfHSM engine links the wolfHSM client/server protocol and creates one
Secure server context for each configured guest. Guest wolfPSA calls use
wolfCrypt's crypto-callback path, the wolfHSM client serializes the request,
Expand Down
2 changes: 1 addition & 1 deletion lib/wolfHSM
Submodule wolfHSM updated 68 files
+6 −4 .github/workflows/build-and-test-clientonly.yml
+13 −0 .github/workflows/build-and-test-refactor.yml
+1 −1 .github/workflows/build-and-test-stress.yml
+10 −0 .github/workflows/build-and-test-whnvmtool.yml
+8 −0 .github/workflows/build-and-test.yml
+0 −8 docs/draft/README.md
+0 −218 docs/draft/THREADSAFE.md
+0 −773 docs/draft/async-crypto.md
+0 −516 docs/draft/auth.md
+0 −635 docs/draft/certificates.md
+0 −96 docs/draft/crypto_affinity.md
+0 −67 docs/draft/posix-shm.md
+0 −122 docs/draft/timeout.md
+1 −1 docs/src/3-Quickstart.md
+42 −8 docs/src/5-Features.md
+2 −0 docs/src/6-Utilities.md
+1 −1 docs/src/8-Integration.md
+2 −0 docs/src/9-Configuration.md
+1 −1 examples/posix/wh_posix_server/wolfhsm_cfg.h
+86 −15 src/wh_client_she.c
+40 −0 src/wh_keyid.c
+50 −1 src/wh_message_she.c
+212 −93 src/wh_nvm_flash.c
+162 −21 src/wh_server.c
+97 −17 src/wh_server_cert.c
+51 −19 src/wh_server_counter.c
+182 −37 src/wh_server_nvm.c
+316 −148 src/wh_server_she.c
+1 −1 test-refactor/client-server/wh_test_crypto_lms.c
+1 −1 test-refactor/client-server/wh_test_crypto_xmss.c
+24 −12 test-refactor/client-server/wh_test_keywrap.c
+41 −106 test-refactor/client-server/wh_test_she.c
+7 −1 test-refactor/config/wolfhsm_cfg.h
+1,079 −39 test-refactor/misc/wh_test_multiclient.c
+111 −27 test-refactor/misc/wh_test_she_keywrap.c
+3 −0 test-refactor/misc/wh_test_she_uid_cb.c
+14 −0 test-refactor/posix/Makefile
+10 −0 test-refactor/posix/wh_test_keygen_unique_id.c
+10 −0 test-refactor/posix/wh_test_keyread_race.c
+212 −7 test-refactor/posix/wh_test_nvm_flash.c
+18 −0 test-refactor/posix/wh_test_posix_main.c
+180 −19 test-refactor/server/wh_test_cert.c
+22 −10 test-refactor/server/wh_test_cert_readtrusted.c
+110 −2 test-refactor/server/wh_test_she_server.c
+6 −0 test-refactor/wh_test_list.c
+10 −0 test/Makefile
+7 −2 test/config/wolfhsm_cfg.h
+210 −21 test/wh_test_cert.c
+2 −6 test/wh_test_clientserver.c
+2 −6 test/wh_test_crypto.c
+27 −15 test/wh_test_keywrap.c
+1,084 −39 test/wh_test_multiclient.c
+80 −10 test/wh_test_nvm_flash.c
+689 −230 test/wh_test_posix_threadsafe_stress.c
+321 −47 test/wh_test_she.c
+3 −0 tools/whnvmtool/README.md
+25 −0 tools/whnvmtool/test/test_whnvmtool.c
+48 −2 wolfhsm/wh_client.h
+28 −21 wolfhsm/wh_client_she.h
+32 −23 wolfhsm/wh_flash_unit.h
+45 −8 wolfhsm/wh_keyid.h
+2 −0 wolfhsm/wh_message.h
+3 −2 wolfhsm/wh_message_keystore.h
+49 −0 wolfhsm/wh_message_she.h
+0 −4 wolfhsm/wh_nvm_flash_log.h
+0 −4 wolfhsm/wh_server_cert_cache.h
+17 −0 wolfhsm/wh_server_she.h
+60 −2 wolfhsm/wh_settings.h
Original file line number Diff line number Diff line change
Expand Up @@ -82,6 +82,19 @@ static int wolfhsm_guest_connect(void)
return rc;
}

/* Bind the client namespace before the server accepts crypto requests. */
rc = wh_Client_CommInitRequest(&g_client_ctx);
if (rc == WH_ERROR_OK) {
rc = wh_Client_CommInitResponse(&g_client_ctx, NULL, NULL);
}
if (rc != WH_ERROR_OK) {
(void)wh_Client_Cleanup(&g_client_ctx);
if (g_retry_crypto_initialized != 0) {
(void)wolfhsm_guest_register_retry();
}
return rc;
}

g_client_ready = 1;
if (g_retry_crypto_initialized != 0) {
(void)wolfCrypt_Cleanup();
Expand Down
27 changes: 27 additions & 0 deletions tests/host/wolfhsm_relay/main.c
Original file line number Diff line number Diff line change
Expand Up @@ -61,6 +61,7 @@
static int g_failures;
static int32_t g_connect_error;
static unsigned int g_connect_count;
static unsigned int g_close_count;

extern int (*test_wolfhsm_sys_init)(void);
int wolfhsm_guest_init(void);
Expand Down Expand Up @@ -152,6 +153,7 @@ int32_t WolfTrust_FFM_Connect(uint32_t sid, uint32_t version)

void WolfTrust_FFM_Close(int32_t handle)
{
g_close_count++;
(void)wt_ffm_close(&g_runtime, TEST_NS_CLIENT, handle);
}

Expand Down Expand Up @@ -314,6 +316,7 @@ static void test_guest_init_retry(void)
WC_RNG rng;
uint8_t output[32];
unsigned int connected_count;
unsigned int closed_count;

(void)memset(&rng, 0, sizeof(rng));
rng.devId = WH_DEV_ID;
Expand All @@ -324,6 +327,18 @@ static void test_guest_init_retry(void)
check(wc_CryptoCb_RandomBlock(&rng, output, sizeof(output)) == WC_HW_E,
"HSM callback remains retryable after repeated failures");
g_connect_error = PSA_SUCCESS;
wt_hsm_relay_set_submit(NULL, NULL);
closed_count = g_close_count;
check(wc_CryptoCb_RandomBlock(&rng, output, sizeof(output)) == WC_HW_E,
"WT-FFM-0054 failed retry handshake fails closed");
check(g_close_count == closed_count + 1U,
"failed retry handshake closes the client connection");
check(wc_CryptoCb_IsDeviceRegistered(WH_DEV_ID) != 0,
"failed retry handshake restores the retry callback");
check(wc_CryptoCb_RandomBlock(&rng, output, sizeof(output)) == WC_HW_E &&
wc_CryptoCb_IsDeviceRegistered(WH_DEV_ID) != 0,
"repeated handshake failures preserve automatic retry");
wt_hsm_relay_set_submit(test_relay_submit, NULL);
(void)memset(output, 0, sizeof(output));
check(wc_CryptoCb_RandomBlock(&rng, output, sizeof(output)) == 0 &&
buf_is_zero(output, sizeof(output)) == 0,
Expand All @@ -338,6 +353,18 @@ static void test_guest_init_retry(void)
check(wc_CryptoCb_RandomBlock(&rng, output, sizeof(output)) == 0,
"successful guest SYS_INIT serves crypto operations");
(void)wh_Client_Cleanup(wolfhsm_guest_client());

wt_hsm_relay_set_submit(NULL, NULL);
closed_count = g_close_count;
check(wolfhsm_guest_init() == WH_ERROR_ABORTED &&
g_close_count == closed_count + 1U &&
wc_CryptoCb_IsDeviceRegistered(WH_DEV_ID) == 0,
"WT-FFM-0054 failed COMM INIT closes the client connection");
wt_hsm_relay_set_submit(test_relay_submit, NULL);
check(wolfhsm_guest_init() == WH_ERROR_OK &&
wc_CryptoCb_RandomBlock(&rng, output, sizeof(output)) == 0,
"WT-FFM-0054 guest init recovers after failed COMM INIT");
(void)wh_Client_Cleanup(wolfhsm_guest_client());
}

int main(void)
Expand Down
Loading