Skip to content

Faster RSA tests - #52

Open
Frauschi wants to merge 2 commits into
wolfSSL:mainfrom
Frauschi:faster-rsa-tests
Open

Frauschi wants to merge 2 commits into
wolfSSL:mainfrom
Frauschi:faster-rsa-tests

Conversation

@Frauschi

@Frauschi Frauschi commented Oct 9, 2026 •

Copy link
Copy Markdown
Member

Remove the number of new RSA keys are generated in tests and instead reuse existing ones:

  • test_scep_msg decodes the six RSA-2048 keys from wolfSSL's certs_test.h instead of generating 36 keys per run; each test draws distinct keys and fails past six. Host: 3.2 s to 0.8 s. Zephyr on qemu_x86: 820 s to 26 s, so the suite drops its slow tag and runs on every PR instead of nightly.
  • The integration test servers share one CA per process through a memory store, instead of generating a fresh RSA-2048 CA on every start (58 generations per run before). The two tests that read the CA back from their own store keep it. A failed store open stops the test, and each test closes the shared store before wolfcert_cleanup().

Test-only, no library changes.

test_scep_msg generated 36 RSA-2048 keys per run, one for every
make_ca and make_signed_cert call plus a few direct ones. It now
decodes them in turn from the six RSA-2048 keys in wolfSSL's
certs_test.h, and the two tests that only need some wolfCert key load
one with wolfcert_key_from_pem. Each test starts from the first key and
fails if it draws more than six, so no test reuses a key, which the
signer checks need: with a single shared key the RepSigner check fails.

The test drops from 3.2 s to 0.8 s on the host, and the Zephyr suite
on qemu_x86 from 820 s to 26 s.

The Zephyr suite is now as fast as the others, so it loses its slow
tag and 900 s timeout, and the Zephyr workflow runs it on every PR and
push instead of only on the nightly.
@Frauschi Frauschi self-assigned this Oct 9, 2026
Copilot AI balanced review requested due to automatic review settings October 9, 2026 14:04

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The shared CA fixture must validate allocation and release its memory before test-process cleanup.

1 open finding
What changed in this PR

Optimizes RSA-heavy tests by reusing existing keys and process-wide test CAs.

Changes:

  • Reuses six wolfSSL RSA test keys in SCEP unit tests.
  • Shares one in-memory CA store per integration-test process.
  • Enables the faster Zephyr SCEP suite on every PR.
File Description
.github/​workflows/​zephyr.yml Runs SCEP tests on every invocation.
docs/​CI.md Updates Zephyr CI documentation.
zephyr/​tests/​wolfcert_unit_scep_msg/​testcase.yaml Removes slow tag and lowers timeout.
tests/​unit/​test_scep_msg.c Replaces RSA generation with predefined keys.
tests/​integration/​tls_test_util.h Adds shared CA-store helper.
tests/​integration/​test_server_stop_idle.c Reuses CA across server scenarios.
tests/​integration/​test_scep_roundtrip.c Reuses CA across SCEP scenarios.
tests/​integration/​test_scep_poll_roundtrip.c Reuses CA across polling scenarios.
tests/​integration/​test_scep_get_cert.c Reuses CA across GetCert scenarios.
tests/​integration/​test_scep_async_roundtrip.c Reuses CA across asynchronous scenarios.
tests/​integration/​test_est_tls_roundtrip.c Reuses CA across TLS scenarios.
tests/​integration/​test_est_roundtrip.c Reuses CA across EST scenarios.
tests/​integration/​test_est_pha_roundtrip.c Reuses CA for PHA testing.
tests/​integration/​test_est_pending_roundtrip.c Reuses CA for pending enrollment.
tests/​integration/​test_est_mtls_roundtrip.c Reuses CA across mTLS scenarios.
tests/​integration/​test_est_mldsa_roundtrip.c Reuses CA for ML-DSA enrollment.
tests/​integration/​test_est_csr_attrs_roundtrip.c Reuses CA across CSR-attribute scenarios.
tests/​integration/​test_est_csr_attrs_enforce.c Reuses CA across enforcement scenarios.
tests/​integration/​test_est_csr_attrs_apply_roundtrip.c Reuses CA for attribute application.
tests/​integration/​test_est_chunked_robustness.c Reuses CA across robustness scenarios.
tests/​integration/​test_est_async_roundtrip.c Reuses CA across asynchronous EST scenarios.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread tests/integration/tls_test_util.h Outdated
A test server with no ca_store generates a fresh RSA-2048 CA on every
start, which cost the integration tests 58 key generations per run,
ten of them in scep_async_roundtrip alone. tls_test_util.h now hands
out one memory store per process, and the integration test servers use
it, so only the first start generates a CA and the later ones load it.
No test depends on its servers having distinct CAs.

A failed store open exits the test instead of passing NULL, which the
server would take as no persistence. Each test closes the store with
test_ca_store_close() before wolfcert_cleanup().

test_server_ca_store and test_reenroll_server_issued keep their own
stores, since they read the CA back from the store they started with.
@Frauschi

Frauschi commented Oct 9, 2026

Copy link
Copy Markdown
Member Author

@wolfSSL-Fenrir-bot review balanced

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #52

Scan targets checked: wolfcert-bugs
Coverage: 17 of 17 in-scope changed file(s) opened by the reviewer

Fenrir result: Approved ✅

No new issues found in the changed files.

Advisory only — this automated result does not count as a GitHub approval.

Review tier: Balanced

@Frauschi Frauschi assigned wolfSSL-Bot and unassigned Frauschi Oct 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants