port: add a wolfCert transport over wolfIP sockets - #171
yosuke-wolfssl wants to merge 1 commit into
Conversation
There was a problem hiding this comment.
Warning
Copilot couldn't run its full agentic review because it didn't start before the timeout. Make sure your repository has a runner available, or add a copilot-code-review.yml file specifying one with the runs-on attribute. See the docs for more details.
Pull request overview
Adds a wolfCert WolfCertTransport implementation backed by wolfIP sockets to enable EST/SCEP enrollment on wolfIP targets without BSD sockets.
Changes:
- Introduces
src/port/wolfcert_io.cimplementingconnect/read/write/disconnectoverwolfIP_sock_*plus DNS resolution vianslookup(). - Exposes init/cleanup entry points in
wolfip.hunderWOLFCERT_WOLFIP. - Adds a dedicated
wolfCert-IOunit-test tcase with mocks to exercise the transport glue.
Reviewed changes
Copilot reviewed 8 out of 8 changed files in this pull request and generated 6 comments.
Show a summary per file
| File | Description |
|---|---|
| wolfip.h | Declares wolfCert transport init/cleanup APIs when WOLFCERT_WOLFIP is enabled. |
| src/port/wolfcert_io.c | Implements wolfCert transport callbacks over wolfIP sockets, including DNS polling loops and timeout handling. |
| src/test/unit/unit_tests_wolfcert.c | Adds extensive unit coverage for connect/DNS/read/write/disconnect behaviors. |
| src/test/unit/unit_shared.c | Adds wolfCert IO mocks and includes the port glue to test internal static state. |
| src/test/unit/unit.c | Registers the new wolfCert-IO test case with the unit test suite. |
| src/test/unit/mocks/wolfcert/types.h | Adds minimal mock for WolfCertTransport to keep unit builds free of wolfCert dependency. |
| src/test/unit/mocks/wolfcert/errors.h | Adds minimal mock error codes used by the glue layer. |
| Makefile | Adds wolfCert unit test source(s) (but currently also adds src/port/wolfcert_io.c). |
Suppressed comments (1)
Makefile:1
src/test/unit/unit_shared.cincludes../../port/wolfcert_io.cdirectly (to access internal static state likeio_ctxs). Addingsrc/port/wolfcert_io.ctoUNIT_TEST_SRCScompiles the same translation unit twice, which will cause multiple-definition linker errors forwolfCert_Init_wolfIP/wolfCert_Cleanup_wolfIP.
CC?=gcc
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
5d1c24a to
d5e391d
Compare
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #171
Scan targets checked: wolfip-src, wolfip-bugs
Findings: 4
4 finding(s) posted as inline comments (see file-level comments below)
This review was generated automatically by Fenrir. Reported findings require changes before merge.
d5e391d to
0b65f53
Compare
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #171
Scan targets checked: wolfip-src, wolfip-bugs
Findings: 2
2 finding(s) posted as inline comments (see file-level comments below)
This review was generated automatically by Fenrir. Reported findings require changes before merge.
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #171
Fenrir already completed a review of this PR at commit 0b65f53782d3 (run 2411); its findings are the review threads on the PR. Push new commits to get a re-review of what changed, or comment @wolfSSL-Fenrir-bot review force to run the full review again at this commit.
dd01157 to
c2c3fc7
Compare
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #171
Scan targets checked: wolfip-src, wolfip-bugs
Coverage: 1 of 1 in-scope changed file(s) opened by the reviewer
Findings: 1
1 finding(s) posted as inline comments (see file-level comments below)
This review was generated automatically by Fenrir. Reported findings require changes before merge.
Review tier: Lite
c2c3fc7 to
7c4d797
Compare
a63a2a8 to
193de81
Compare
|
@wolfSSL-Fenrir-bot review with balanced |
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #171
Scan targets checked: wolfip-src, wolfip-bugs
Coverage: 1 of 1 in-scope changed file(s) opened by the reviewer
Fenrir result: Approved ✅
No new issues found in the changed files.
Advisory only — this automated result does not count as a GitHub approval.
Review tier: Lite
Fenrir's latest completed scan found no issues; clearing the prior automated change request.
- src/port/wolfcert_io.c implements WolfCertTransport over wolfIP_sock_*, with wolfCert_Init_wolfIP() and wolfCert_Cleanup_wolfIP() managing a static context pool. - connect() resolves a dotted quad or via nslookup(), then calls wolfIP_sock_connect() after each wolfIP_poll() until it returns 0. It builds the handle after the first call, packing the slot, the local port and an 8-bit fold of the peer address, and returns CONN_CLOSED once the socket no longer matches it. - read(), write() and disconnect() first check that the socket still matches the handle; read() and write() return ERR_IO and disconnect() CONN_CLOSED when it does not. - read() and write() map -WOLFIP_EAGAIN to WANT_READ/WANT_WRITE or pump within a budget checked before each poll, and -1 to CONN_CLOSED; read() maps 0 to CONN_CLOSED. - disconnect() closes once, and calls wolfIP_sock_abort() when the socket is still unwritable after close returns -WOLFIP_EAGAIN. - wolfip.h declares the entry points under WOLFCERT_WOLFIP. - unit_tests_wolfcert.c adds 37 tests on mocks in unit_shared.c and mocks/wolfcert headers, built by the Makefile's unit target, which defines WOLFCERT_WOLFIP. - docs/wolfcert_howto.md documents the integration, linked from docs/API.md and README.md.
193de81 to
d943814
Compare
|
Hello @danielinux , |
Background
wolfCert's
WolfCertTransportvtable lets a target without BSD sockets supplyits own transport, but wolfIP had no implementation of it. EST/SCEP enrolment
on wolfIP was therefore impossible: wolfCert's built-in transport calls
close()/send()/recv()on a POSIX fd, while a wolfIP descriptor is anindex into wolfIP's own table — on a hosted build those calls hit an
unrelated file descriptor.
Changes (
src/port/wolfcert_io.c)One glue file implementing the four callbacks over
wolfIP_sock_*, joiningwolfssl_io.c,wolfssh_io.candwolfmqtt_io.c. It carries no TLS code —wolfCert bridges wolfSSL's CBIO onto the same
read/write, so EST overHTTPS, SCEP over HTTPS and SCEP over plain HTTP all ride one transport.
connectresolves a dotted quad locally or vianslookup(), then callswolfIP_sock_connect()after eachwolfIP_poll()until it returns 0. Itbuilds the handle after the first call and checks it after every poll, so a
refused connection fails at once with
WOLFCERT_ERR_CONN_CLOSEDand a slotreset or handed to another socket is neither driven nor closed.
fold of the peer address.
read,writeanddisconnectcheck it againstthe live socket first, so a slot that was reset or handed to another socket
is never read, written or closed:
read/writereturnWOLFCERT_ERR_IO,disconnectreturnsWOLFCERT_ERR_CONN_CLOSED.read/writecarry the blocking mode intimeout_ms, clamplentoINT_MAX, never return 0, and check the deadline before each poll.disconnectcallswolfIP_sock_close()once, andwolfIP_sock_abort()when the FIN could not be queued.
> 00(receive only)WOLFCERT_ERR_CONN_CLOSED-1WOLFCERT_ERR_CONN_CLOSED-WOLFIP_EAGAINWANT_READ/WANT_WRITE, or pump and retry-WOLFIP_EINVALWOLFCERT_ERR_BAD_ARGWOLFCERT_ERR_IOwolfip.hdeclares both entry points underWOLFCERT_WOLFIP, anddocs/wolfcert_howto.mddocuments the integration.Tests
37 cases in a
wolfCert-IOtcase. Mockwolfcert/headers keepmake unitfree of any wolfCert dependency, and the unit build defines
WOLFCERT_WOLFIP,so every CI job that builds the unit suite compiles the
wolfip.hprototypesagainst the glue.
Verification
existing deliberate out-of-bounds pointer in
unit_tests_misc_edges.c:286,which this PR does not touch.
main(f61b0b0) headers under-Werror -Wextra -Wdeclaration-after-statement, and on i386 with the pointer/integer castwarnings; the object imports only wolfIP symbols.
matches; a reset, and a slot reused for the same server, do not.
wolfcert-server: plain HTTP GET,HTTPS GET, EST
simpleenrollover HTTPS and SCEPGetCACapsall pass.Depends on
first (wolfCert's keep-alive session mode) keeps its slot. Filed separately.
Known limits
that drew the same local port (about 1 in 64k per reuse): all four
addresses match, so no address-based check can. Closing it needs a
generation counter in wolfIP's descriptors, filed separately.
disconnectspots an unqueued FIN bywolfIP_sock_can_write()reading 0after close. That misses a FIN carrying SACK options, which needs up to 40
option bytes while
can_writereserves 12, so a close in that narrow windowstill leaves the socket open. Fixing it needs
closeto report the unqueuedFIN itself, filed separately with the FIN issue.
Not in this PR
The top-level build target and CI step follow separately. DNS lookups can't be
cancelled and carry no per-lookup context, so a failed resolution spends the
connect budget.