Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 2 additions & 9 deletions .github/workflows/zephyr.yml
Original file line number Diff line number Diff line change
Expand Up @@ -25,8 +25,6 @@ env:
WOLFSSL_REF: master
ZEPHYR_REF: v4.4.2
ZEPHYR_SDK: 1.0.1
# PRs and pushes skip the slow suites; the nightly and manual runs include them.
FULL_RUN: ${{ github.event_name != 'pull_request' && github.event_name != 'push' }}

jobs:
qemu-x86:
Expand Down Expand Up @@ -56,14 +54,9 @@ jobs:
- name: Unit tests
run: |
cd "$HOME/zephyrproject"
if [ "$FULL_RUN" = true ]; then
slow=; slow_suites=wolfcert.unit.scep_msg
else
slow="-e slow"; slow_suites=
fi
# The EST suite and the sample need the host server
"$HOME/zephyr-venv/bin/python" zephyr/scripts/twister \
-T "${{ github.workspace }}/zephyr/tests" -e est $slow \
-T "${{ github.workspace }}/zephyr/tests" -e est \
-p qemu_x86 \
-x=EXTRA_ZEPHYR_MODULES=${{ github.workspace }} \
--outdir "$HOME/twister-unit" -vv
Expand All @@ -74,7 +67,7 @@ jobs:
"$HOME/twister-unit/twister.json" \
wolfcert.unit.smoke wolfcert.unit.keygen wolfcert.unit.csr \
wolfcert.unit.csr_attrs wolfcert.unit.store \
wolfcert.unit.parse_negative $slow_suites \
wolfcert.unit.parse_negative wolfcert.unit.scep_msg \
--built-only wolfcert.build.no_builtin_transport \
wolfcert.build.rsa_only wolfcert.build.scep_only_rsa \
wolfcert.build.ed448_mldsa
Expand Down
2 changes: 1 addition & 1 deletion docs/CI.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ set skips the wolfSSL build entirely.
| `nightly.yml` | schedule + dispatch | Re-runs the wolfSSL-variant build matrix against fresh wolfSSL `master`, the macOS extras, and the full negative-config set. Also **reseeds the wolfSSL prefix caches** so the next day's PRs restore instead of build. The feature/config gating itself now runs per-PR (see `pr.yml`). |
| `sanitizers.yml` | schedule + dispatch | ASan+UBSan over the full test suite, ThreadSanitizer over the threaded integration roundtrips (against a TSAN-instrumented wolfSSL), and valgrind over a representative subset. |
| `interop.yml` | schedule + dispatch | Third-party EST/SCEP interop (openssl, micromdm/scep, globalsign/est, cisco/libest, smallstep/step-ca). Best-effort: a dependency that fails to install makes its script exit 77, which is treated as a neutral skip; a real interop regression fails. |
| `zephyr.yml` | PR + push, schedule + dispatch | Two jobs sharing the west workspace setup (`.github/actions/zephyr-workspace`). The `qemu_x86` job runs the Zephyr module on `qemu_x86`: the unit suites, build-only rows for off-default Kconfig combinations, and an EST enrollment gate plus the sample against a host `wolfcert-server`, including a build of the sample with a custom trust anchor. The `mcxn` job builds the EST sample for `frdm_mcxn947/mcxn947/cpu0` with the SDK's `arm-zephyr-eabi` toolchain; [`zephyr/README.md`](../zephyr/README.md#est-client-sample) lists what CI covers per board. `scripts/ci/twister-assert-ran.py` checks that each step's suites actually ran. The slow `scep_msg` suite runs only on the nightly and on manual dispatch. |
| `zephyr.yml` | PR + push, schedule + dispatch | Two jobs sharing the west workspace setup (`.github/actions/zephyr-workspace`). The `qemu_x86` job runs the Zephyr module on `qemu_x86`: the unit suites, build-only rows for off-default Kconfig combinations, and an EST enrollment gate plus the sample against a host `wolfcert-server`, including a build of the sample with a custom trust anchor. The `mcxn` job builds the EST sample for `frdm_mcxn947/mcxn947/cpu0` with the SDK's `arm-zephyr-eabi` toolchain; [`zephyr/README.md`](../zephyr/README.md#est-client-sample) lists what CI covers per board. `scripts/ci/twister-assert-ran.py` checks that each step's suites actually ran. |

## wolfSSL configurations

Expand Down
3 changes: 3 additions & 0 deletions tests/integration/test_est_async_roundtrip.c
Original file line number Diff line number Diff line change
Expand Up @@ -141,6 +141,7 @@ int main(void)
.protocol = WOLFCERT_PROTO_EST,
.bind_host = "127.0.0.1",
.bind_port = 0,
.ca_store = test_ca_store(),
.tls_cert_pem = tls_cert, .tls_cert_pem_len = tls_cert_len,
.tls_key_pem = tls_key, .tls_key_pem_len = tls_key_len,
.tls_client_ca_pem = cli_cert, .tls_client_ca_pem_len = cli_cert_len,
Expand Down Expand Up @@ -200,6 +201,7 @@ int main(void)
.protocol = WOLFCERT_PROTO_EST,
.bind_host = "127.0.0.1",
.bind_port = 0,
.ca_store = test_ca_store(),
.http_basic_user = "alice",
.http_basic_pass = "hunter2",
.tls_cert_pem = tls_cert, .tls_cert_pem_len = tls_cert_len,
Expand Down Expand Up @@ -272,6 +274,7 @@ int main(void)
free(tls_key);
free(cli_cert);
free(cli_key);
test_ca_store_close();
wolfcert_cleanup();
if (pha_skipped)
return 77;
Expand Down
3 changes: 3 additions & 0 deletions tests/integration/test_est_chunked_robustness.c
Original file line number Diff line number Diff line change
Expand Up @@ -398,6 +398,7 @@ static int no_sigpipe_on_response(void)
WolfCertServerCfgSrv cfg = {
.protocol = WOLFCERT_PROTO_EST,
.bind_host = "127.0.0.1", .bind_port = 0,
.ca_store = test_ca_store(),
.est_allow_anonymous_enroll = 1,
};
WolfCertServer* srv = NULL;
Expand Down Expand Up @@ -459,6 +460,7 @@ int main(void)
WolfCertServerCfgSrv cfg = {
.protocol = WOLFCERT_PROTO_EST,
.bind_host = "127.0.0.1", .bind_port = 0,
.ca_store = test_ca_store(),
.tls_cert_pem = g_tls_cert, .tls_cert_pem_len = g_tls_cert_len,
.tls_key_pem = tls_key, .tls_key_pem_len = tls_key_len,
.est_allow_anonymous_enroll = 1,
Expand Down Expand Up @@ -498,6 +500,7 @@ int main(void)
if (rc != 0)
return rc;

test_ca_store_close();
wolfcert_cleanup();
printf("OK\n");
return 0;
Expand Down
2 changes: 2 additions & 0 deletions tests/integration/test_est_csr_attrs_apply_roundtrip.c
Original file line number Diff line number Diff line change
Expand Up @@ -246,6 +246,7 @@ int main(void)
WolfCertServerCfgSrv cfg = {
.protocol = WOLFCERT_PROTO_EST,
.bind_host = "127.0.0.1", .bind_port = 0,
.ca_store = test_ca_store(),
.csr_attributes_der = policy.data,
.csr_attributes_len = policy.len,
.tls_cert_pem = tls_cert, .tls_cert_pem_len = tls_cert_len,
Expand Down Expand Up @@ -278,6 +279,7 @@ int main(void)
if (rc != 0)
return rc;

test_ca_store_close();
wolfcert_cleanup();
printf("OK\n");
return 0;
Expand Down
5 changes: 5 additions & 0 deletions tests/integration/test_est_csr_attrs_enforce.c
Original file line number Diff line number Diff line change
Expand Up @@ -367,6 +367,7 @@ int main(void)
WolfCertServerCfgSrv cfg = {
.protocol = WOLFCERT_PROTO_EST,
.bind_host = "127.0.0.1", .bind_port = 0,
.ca_store = test_ca_store(),
.csr_attributes_der = policy.data,
.csr_attributes_len = policy.len,
.est_require_csr_attributes = 1,
Expand Down Expand Up @@ -395,6 +396,7 @@ int main(void)
WolfCertServerCfgSrv cfg2 = {
.protocol = WOLFCERT_PROTO_EST,
.bind_host = "127.0.0.1", .bind_port = 0,
.ca_store = test_ca_store(),
.csr_attributes_der = policy2.data,
.csr_attributes_len = policy2.len,
.est_require_csr_attributes = 1,
Expand Down Expand Up @@ -422,6 +424,7 @@ int main(void)
WolfCertServerCfgSrv cfg_raw = {
.protocol = WOLFCERT_PROTO_EST,
.bind_host = "127.0.0.1", .bind_port = 0,
.ca_store = test_ca_store(),
.csr_attributes_der = policy_raw.data,
.csr_attributes_len = policy_raw.len,
.est_require_csr_attributes = 1,
Expand Down Expand Up @@ -449,6 +452,7 @@ int main(void)
WolfCertServerCfgSrv cfg_bare = {
.protocol = WOLFCERT_PROTO_EST,
.bind_host = "127.0.0.1", .bind_port = 0,
.ca_store = test_ca_store(),
.http_basic_user = "alice", .http_basic_pass = "secret",
.tls_cert_pem = tls_cert, .tls_cert_pem_len = tls_cert_len,
.tls_key_pem = tls_key, .tls_key_pem_len = tls_key_len,
Expand All @@ -468,6 +472,7 @@ int main(void)
if (rc != 0)
return rc;

test_ca_store_close();
wolfcert_cleanup();
printf("OK\n");
return 0;
Expand Down
3 changes: 3 additions & 0 deletions tests/integration/test_est_csr_attrs_roundtrip.c
Original file line number Diff line number Diff line change
Expand Up @@ -93,6 +93,7 @@ int main(void)
.protocol = WOLFCERT_PROTO_EST,
.bind_host = "127.0.0.1",
.bind_port = 0,
.ca_store = test_ca_store(),
.csr_attributes_der = blob.data,
.csr_attributes_len = blob.len,
.tls_cert_pem = tls_cert, .tls_cert_pem_len = tls_cert_len,
Expand Down Expand Up @@ -152,6 +153,7 @@ int main(void)
WolfCertServerCfgSrv cfg2 = {
.protocol = WOLFCERT_PROTO_EST,
.bind_host = "127.0.0.1", .bind_port = 0,
.ca_store = test_ca_store(),
.tls_cert_pem = tls_cert, .tls_cert_pem_len = tls_cert_len,
.tls_key_pem = tls_key, .tls_key_pem_len = tls_key_len,
.est_allow_anonymous_enroll = 1,
Expand Down Expand Up @@ -197,6 +199,7 @@ int main(void)
wolfcert_buffer_free(&blob);
free(tls_cert);
free(tls_key);
test_ca_store_close();
wolfcert_cleanup();
printf("OK\n");
return 0;
Expand Down
2 changes: 2 additions & 0 deletions tests/integration/test_est_mldsa_roundtrip.c
Original file line number Diff line number Diff line change
Expand Up @@ -114,6 +114,7 @@ int main(void)
.protocol = WOLFCERT_PROTO_EST,
.bind_host = "127.0.0.1",
.bind_port = 0,
.ca_store = test_ca_store(),
.http_basic_user = "alice",
.http_basic_pass = "hunter2",
.tls_cert_pem = tls_cert, .tls_cert_pem_len = tls_cert_len,
Expand Down Expand Up @@ -156,6 +157,7 @@ int main(void)
wolfcert_buffer_free(&ca_pem);
free(tls_cert);
free(tls_key);
test_ca_store_close();
wolfcert_cleanup();

if (rc == 0)
Expand Down
3 changes: 3 additions & 0 deletions tests/integration/test_est_mtls_roundtrip.c
Original file line number Diff line number Diff line change
Expand Up @@ -409,6 +409,7 @@ static int test_reenroll_mismatch_not_parked(const uint8_t* tls_cert, size_t tls
.protocol = WOLFCERT_PROTO_EST,
.bind_host = "127.0.0.1",
.bind_port = 0,
.ca_store = test_ca_store(),
.tls_cert_pem = tls_cert, .tls_cert_pem_len = tls_cert_len,
.tls_key_pem = tls_key, .tls_key_pem_len = tls_key_len,
.tls_client_ca_pem = cli_cert, .tls_client_ca_pem_len = cli_cert_len,
Expand Down Expand Up @@ -521,6 +522,7 @@ int main(void)
.protocol = WOLFCERT_PROTO_EST,
.bind_host = "127.0.0.1",
.bind_port = 0,
.ca_store = test_ca_store(),
.tls_cert_pem = tls_cert, .tls_cert_pem_len = tls_cert_len,
.tls_key_pem = tls_key, .tls_key_pem_len = tls_key_len,
.tls_client_ca_pem = cli_cert, .tls_client_ca_pem_len = cli_cert_len,
Expand Down Expand Up @@ -623,6 +625,7 @@ int main(void)
free(tls_key);
free(cli_cert);
free(cli_key);
test_ca_store_close();
wolfcert_cleanup();
printf("OK\n");
return 0;
Expand Down
2 changes: 2 additions & 0 deletions tests/integration/test_est_pending_roundtrip.c
Original file line number Diff line number Diff line change
Expand Up @@ -507,6 +507,7 @@ int main(void)
WolfCertServerCfgSrv cfg = {
.protocol = WOLFCERT_PROTO_EST,
.bind_host = "127.0.0.1", .bind_port = 0,
.ca_store = test_ca_store(),
.est_require_approval = 1,
.est_retry_after_sec = 1,
.tls_cert_pem = tls_cert, .tls_cert_pem_len = tls_cert_len,
Expand All @@ -524,6 +525,7 @@ int main(void)

free(tls_cert);
free(tls_key);
test_ca_store_close();
wolfcert_cleanup();
if (rc != 0)
return rc;
Expand Down
3 changes: 3 additions & 0 deletions tests/integration/test_est_pha_roundtrip.c
Original file line number Diff line number Diff line change
Expand Up @@ -167,6 +167,7 @@ int main(void)
.protocol = WOLFCERT_PROTO_EST,
.bind_host = "127.0.0.1",
.bind_port = 0,
.ca_store = test_ca_store(),
.tls_cert_pem = tls_cert,
.tls_cert_pem_len = tls_cert_len,
.tls_key_pem = tls_key,
Expand Down Expand Up @@ -197,6 +198,7 @@ int main(void)
free(tls_key);
free(cli_cert);
free(cli_key);
test_ca_store_close();
wolfcert_cleanup();
return 77;
}
Expand Down Expand Up @@ -354,6 +356,7 @@ int main(void)
free(tls_key);
free(cli_cert);
free(cli_key);
test_ca_store_close();
wolfcert_cleanup();
printf("OK\n");
return 0;
Expand Down
3 changes: 3 additions & 0 deletions tests/integration/test_est_roundtrip.c
Original file line number Diff line number Diff line change
Expand Up @@ -238,6 +238,7 @@ int main(void)
.protocol = WOLFCERT_PROTO_EST,
.bind_host = "127.0.0.1",
.bind_port = 0,
.ca_store = test_ca_store(),
.http_basic_user = "alice",
.http_basic_pass = "hunter2",
.tls_cert_pem = tls_cert, .tls_cert_pem_len = tls_cert_len,
Expand Down Expand Up @@ -350,6 +351,7 @@ int main(void)
WolfCertServerCfgSrv acfg = {
.protocol = WOLFCERT_PROTO_EST,
.bind_host = "127.0.0.1", .bind_port = 0,
.ca_store = test_ca_store(),
.http_basic_user = "alice", .http_basic_pass = "hunter",
.tls_cert_pem = tls_cert, .tls_cert_pem_len = tls_cert_len,
.tls_key_pem = tls_key, .tls_key_pem_len = tls_key_len,
Expand Down Expand Up @@ -402,6 +404,7 @@ int main(void)
wolfcert_buffer_free(&ca_pem);
free(tls_cert);
free(tls_key);
test_ca_store_close();
wolfcert_cleanup();
printf("OK (%d transport connects)\n", g_connect_calls);
return 0;
Expand Down
4 changes: 4 additions & 0 deletions tests/integration/test_est_tls_roundtrip.c
Original file line number Diff line number Diff line change
Expand Up @@ -139,6 +139,7 @@ static int test_client_reenroll_keeps_identity(const uint8_t* tls_cert,
.protocol = WOLFCERT_PROTO_EST,
.bind_host = "127.0.0.1",
.bind_port = 0,
.ca_store = test_ca_store(),
.tls_cert_pem = tls_cert, .tls_cert_pem_len = tls_cert_len,
.tls_key_pem = tls_key, .tls_key_pem_len = tls_key_len,
};
Expand Down Expand Up @@ -299,6 +300,7 @@ int main(void)
.protocol = WOLFCERT_PROTO_EST,
.bind_host = "127.0.0.1",
.bind_port = 0,
.ca_store = test_ca_store(),
.tls_cert_pem = tls_cert, .tls_cert_pem_len = tls_cert_len,
.tls_key_pem = tls_key, .tls_key_pem_len = tls_key_len,
};
Expand Down Expand Up @@ -336,6 +338,7 @@ int main(void)
.protocol = WOLFCERT_PROTO_EST,
.bind_host = "127.0.0.1",
.bind_port = 0,
.ca_store = test_ca_store(),
.tls_cert_pem = tls_cert, .tls_cert_pem_len = tls_cert_len,
.tls_key_pem = tls_key, .tls_key_pem_len = tls_key_len,
.est_allow_anonymous_enroll = 1,
Expand Down Expand Up @@ -408,6 +411,7 @@ int main(void)
wolfcert_key_free(dk);
free(tls_cert);
free(tls_key);
test_ca_store_close();
wolfcert_cleanup();
printf("OK\n");
return 0;
Expand Down
Loading
Loading