Skip to content

port: add a wolfCert transport over wolfIP sockets - #171

Open
yosuke-wolfssl wants to merge 1 commit into
wolfSSL:masterfrom
yosuke-wolfssl:feat/wolfCert
Open

yosuke-wolfssl wants to merge 1 commit into
wolfSSL:masterfrom
yosuke-wolfssl:feat/wolfCert

Conversation

@yosuke-wolfssl

@yosuke-wolfssl yosuke-wolfssl commented Sep 10, 2026 •

Copy link
Copy Markdown
Contributor

Background

wolfCert's WolfCertTransport vtable lets a target without BSD sockets supply
its own transport, but wolfIP had no implementation of it. EST/SCEP enrolment
on wolfIP was therefore impossible: wolfCert's built-in transport calls
close()/send()/recv() on a POSIX fd, while a wolfIP descriptor is an
index into wolfIP's own table — on a hosted build those calls hit an
unrelated file descriptor.

Changes (src/port/wolfcert_io.c)

One glue file implementing the four callbacks over wolfIP_sock_*, joining
wolfssl_io.c, wolfssh_io.c and wolfmqtt_io.c. It carries no TLS code —
wolfCert bridges wolfSSL's CBIO onto the same read/write, so EST over
HTTPS, SCEP over HTTPS and SCEP over plain HTTP all ride one transport.

  • connect resolves a dotted quad locally or via nslookup(), then calls
    wolfIP_sock_connect() after each wolfIP_poll() until it returns 0. It
    builds the handle after the first call and checks it after every poll, so a
    refused connection fails at once with WOLFCERT_ERR_CONN_CLOSED and a slot
    reset or handed to another socket is neither driven nor closed.
  • The connection handle packs the slot index, the local port and an 8-bit
    fold of the peer address. read, write and disconnect check it against
    the live socket first, so a slot that was reset or handed to another socket
    is never read, written or closed: read/write return WOLFCERT_ERR_IO,
    disconnect returns WOLFCERT_ERR_CONN_CLOSED.
  • read/write carry the blocking mode in timeout_ms, clamp len to
    INT_MAX, never return 0, and check the deadline before each poll.
  • disconnect calls wolfIP_sock_close() once, and wolfIP_sock_abort()
    when the FIN could not be queued.
wolfIP return Mapped to
> 0 byte count (short transfers passed through)
0 (receive only) WOLFCERT_ERR_CONN_CLOSED
-1 WOLFCERT_ERR_CONN_CLOSED
-WOLFIP_EAGAIN WANT_READ/WANT_WRITE, or pump and retry
-WOLFIP_EINVAL WOLFCERT_ERR_BAD_ARG
other WOLFCERT_ERR_IO

wolfip.h declares both entry points under WOLFCERT_WOLFIP, and
docs/wolfcert_howto.md documents the integration.

Tests

37 cases in a wolfCert-IO tcase. Mock wolfcert/ headers keep make unit
free of any wolfCert dependency, and the unit build defines WOLFCERT_WOLFIP,
so every CI job that builds the unit suite compiles the wolfip.h prototypes
against the glue.

Verification

  • Unit: 1672/1672 under ASan + UBSan. The only report is the
    existing deliberate out-of-bounds pointer in unit_tests_misc_edges.c:286,
    which this PR does not touch.
  • Compiles against wolfCert main (f61b0b0) headers under -Werror -Wextra -Wdeclaration-after-statement, and on i386 with the pointer/integer cast
    warnings; the object imports only wolfIP symbols.
  • Handle check against the real stack, 64-bit and i386: an orderly close still
    matches; a reset, and a slot reused for the same server, do not.
  • End to end over a utun link against wolfcert-server: plain HTTP GET,
    HTTPS GET, EST simpleenroll over HTTPS and SCEP GetCACaps all pass.

Depends on

  • TIME_WAIT is never freed in wolfIP, so each connection the client closes
    first (wolfCert's keep-alive session mode) keeps its slot. Filed separately.

Known limits

  • The handle cannot tell our connection from a new one to the same server
    that drew the same local port
    (about 1 in 64k per reuse): all four
    addresses match, so no address-based check can. Closing it needs a
    generation counter in wolfIP's descriptors, filed separately.
  • disconnect spots an unqueued FIN by wolfIP_sock_can_write() reading 0
    after close. That misses a FIN carrying SACK options, which needs up to 40
    option bytes while can_write reserves 12, so a close in that narrow window
    still leaves the socket open. Fixing it needs close to report the unqueued
    FIN itself, filed separately with the FIN issue.

Not in this PR

The top-level build target and CI step follow separately. DNS lookups can't be
cancelled and carry no per-lookup context, so a failed resolution spends the
connect budget.

@yosuke-wolfssl yosuke-wolfssl self-assigned this Sep 10, 2026
Copilot AI lite review requested due to automatic review settings September 10, 2026 02:08

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Warning

Copilot couldn't run its full agentic review because it didn't start before the timeout. Make sure your repository has a runner available, or add a copilot-code-review.yml file specifying one with the runs-on attribute. See the docs for more details.

Pull request overview

Adds a wolfCert WolfCertTransport implementation backed by wolfIP sockets to enable EST/SCEP enrollment on wolfIP targets without BSD sockets.

Changes:

  • Introduces src/port/wolfcert_io.c implementing connect/read/write/disconnect over wolfIP_sock_* plus DNS resolution via nslookup().
  • Exposes init/cleanup entry points in wolfip.h under WOLFCERT_WOLFIP.
  • Adds a dedicated wolfCert-IO unit-test tcase with mocks to exercise the transport glue.

Reviewed changes

Copilot reviewed 8 out of 8 changed files in this pull request and generated 6 comments.

Show a summary per file
File Description
wolfip.h Declares wolfCert transport init/cleanup APIs when WOLFCERT_WOLFIP is enabled.
src/port/wolfcert_io.c Implements wolfCert transport callbacks over wolfIP sockets, including DNS polling loops and timeout handling.
src/test/unit/unit_tests_wolfcert.c Adds extensive unit coverage for connect/DNS/read/write/disconnect behaviors.
src/test/unit/unit_shared.c Adds wolfCert IO mocks and includes the port glue to test internal static state.
src/test/unit/unit.c Registers the new wolfCert-IO test case with the unit test suite.
src/test/unit/mocks/wolfcert/types.h Adds minimal mock for WolfCertTransport to keep unit builds free of wolfCert dependency.
src/test/unit/mocks/wolfcert/errors.h Adds minimal mock error codes used by the glue layer.
Makefile Adds wolfCert unit test source(s) (but currently also adds src/port/wolfcert_io.c).
Suppressed comments (1)

Makefile:1

  • src/test/unit/unit_shared.c includes ../../port/wolfcert_io.c directly (to access internal static state like io_ctxs). Adding src/port/wolfcert_io.c to UNIT_TEST_SRCS compiles the same translation unit twice, which will cause multiple-definition linker errors for wolfCert_Init_wolfIP / wolfCert_Cleanup_wolfIP.
CC?=gcc

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/port/wolfcert_io.c
Comment thread src/port/wolfcert_io.c Outdated
Comment thread src/port/wolfcert_io.c
Comment thread src/port/wolfcert_io.c
Comment thread src/test/unit/unit_tests_wolfcert.c Outdated
Comment thread src/test/unit/unit_shared.c Outdated

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #171

Scan targets checked: wolfip-src, wolfip-bugs

Findings: 4
4 finding(s) posted as inline comments (see file-level comments below)

This review was generated automatically by Fenrir. Reported findings require changes before merge.

Comment thread src/port/wolfcert_io.c Outdated
Comment thread src/port/wolfcert_io.c Outdated
Comment thread src/port/wolfcert_io.c
Comment thread src/port/wolfcert_io.c Outdated
Comment thread src/port/wolfcert_io.c Outdated
Comment thread src/port/wolfcert_io.c Outdated
Comment thread src/port/wolfcert_io.c Outdated
Comment thread src/port/wolfcert_io.c

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #171

Scan targets checked: wolfip-src, wolfip-bugs

Findings: 2
2 finding(s) posted as inline comments (see file-level comments below)

This review was generated automatically by Fenrir. Reported findings require changes before merge.

Comment thread src/port/wolfcert_io.c
Comment thread src/port/wolfcert_io.c Outdated

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #171

Fenrir already completed a review of this PR at commit 0b65f53782d3 (run 2411); its findings are the review threads on the PR. Push new commits to get a re-review of what changed, or comment @wolfSSL-Fenrir-bot review force to run the full review again at this commit.

@yosuke-wolfssl
yosuke-wolfssl force-pushed the feat/wolfCert branch 2 times, most recently from dd01157 to c2c3fc7 Compare September 24, 2026 04:32
danielinux
danielinux previously approved these changes Sep 29, 2026

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #171

Scan targets checked: wolfip-src, wolfip-bugs
Coverage: 1 of 1 in-scope changed file(s) opened by the reviewer

Findings: 1
1 finding(s) posted as inline comments (see file-level comments below)

This review was generated automatically by Fenrir. Reported findings require changes before merge.

Review tier: Lite

Comment thread src/port/wolfcert_io.c Outdated
@yosuke-wolfssl
yosuke-wolfssl force-pushed the feat/wolfCert branch 2 times, most recently from a63a2a8 to 193de81 Compare September 30, 2026 23:03
@yosuke-wolfssl

Copy link
Copy Markdown
Contributor Author

@wolfSSL-Fenrir-bot review with balanced

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #171

Scan targets checked: wolfip-src, wolfip-bugs
Coverage: 1 of 1 in-scope changed file(s) opened by the reviewer

Fenrir result: Approved ✅

No new issues found in the changed files.

Advisory only — this automated result does not count as a GitHub approval.

Review tier: Lite

@wolfSSL-Fenrir-bot
wolfSSL-Fenrir-bot dismissed stale reviews from themself September 30, 2026 23:21

Fenrir's latest completed scan found no issues; clearing the prior automated change request.

- src/port/wolfcert_io.c implements WolfCertTransport over
  wolfIP_sock_*, with wolfCert_Init_wolfIP() and
  wolfCert_Cleanup_wolfIP() managing a static context pool.
- connect() resolves a dotted quad or via nslookup(), then calls
  wolfIP_sock_connect() after each wolfIP_poll() until it returns 0.
  It builds the handle after the first call, packing the slot, the
  local port and an 8-bit fold of the peer address, and returns
  CONN_CLOSED once the socket no longer matches it.
- read(), write() and disconnect() first check that the socket still
  matches the handle; read() and write() return ERR_IO and
  disconnect() CONN_CLOSED when it does not.
- read() and write() map -WOLFIP_EAGAIN to WANT_READ/WANT_WRITE or
  pump within a budget checked before each poll, and -1 to
  CONN_CLOSED; read() maps 0 to CONN_CLOSED.
- disconnect() closes once, and calls wolfIP_sock_abort() when the
  socket is still unwritable after close returns -WOLFIP_EAGAIN.
- wolfip.h declares the entry points under WOLFCERT_WOLFIP.
- unit_tests_wolfcert.c adds 37 tests on mocks in unit_shared.c and
  mocks/wolfcert headers, built by the Makefile's unit target, which
  defines WOLFCERT_WOLFIP.
- docs/wolfcert_howto.md documents the integration, linked from
  docs/API.md and README.md.
@yosuke-wolfssl

Copy link
Copy Markdown
Contributor Author

Hello @danielinux ,
I reworked on it. Could you please review it again ?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants