初始提交:terminalX 可运行态(M0/M1/M1.5 已真机验证)
- M0: libghostty SSH 终端(渲染/输入/连接)+ 白屏修复(OutputGate) + 会话状态机/自动重连 - M1: tsnet 用户态组网 + SSH-over-tsnet(fd 桥),shell 级真机验证;R5(Go+gvisor+C+++Swift 同进程) retire - M1.5: tmux -CC 原生 tab(MVP) - 结构: packages/(TXCore·TXTransport), apps/TerminalX, vendor/(libghostty-spm/libssh2/mbedtls/tsnet-bridge), artifacts/ - 文档: CLAUDE.md + docs/HANDOFF.md(新会话入口) - 环境: 认证代理→依赖 vendor 本地化;Go 在 ~/.local/go;仅模拟器/未签名 - 待续: M2 mosh, tmux 多 pane, M4 安全(host key/SE) Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
3
vendor/mbedtls/framework/scripts/mbedtls_framework/__init__.py
vendored
Normal file
3
vendor/mbedtls/framework/scripts/mbedtls_framework/__init__.py
vendored
Normal file
@@ -0,0 +1,3 @@
|
||||
# This file needs to exist to make mbedtls_framework a package.
|
||||
# Among other things, this allows modules in this directory to make
|
||||
# relative imports.
|
||||
325
vendor/mbedtls/framework/scripts/mbedtls_framework/asymmetric_key_data.py
vendored
Normal file
325
vendor/mbedtls/framework/scripts/mbedtls_framework/asymmetric_key_data.py
vendored
Normal file
File diff suppressed because one or more lines are too long
416
vendor/mbedtls/framework/scripts/mbedtls_framework/bignum_common.py
vendored
Normal file
416
vendor/mbedtls/framework/scripts/mbedtls_framework/bignum_common.py
vendored
Normal file
@@ -0,0 +1,416 @@
|
||||
"""Common features for bignum in test generation framework."""
|
||||
# Copyright The Mbed TLS Contributors
|
||||
# SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
#
|
||||
|
||||
from abc import abstractmethod
|
||||
import enum
|
||||
from typing import Iterator, List, Tuple, TypeVar, Any
|
||||
from copy import deepcopy
|
||||
from itertools import chain
|
||||
from math import ceil
|
||||
|
||||
from . import test_case
|
||||
from . import test_data_generation
|
||||
from .bignum_data import INPUTS_DEFAULT, MODULI_DEFAULT
|
||||
|
||||
T = TypeVar('T') #pylint: disable=invalid-name
|
||||
|
||||
def invmod(a: int, n: int) -> int:
|
||||
"""Return inverse of a to modulo n.
|
||||
|
||||
Warning: the output might be negative! See invmod_positive().
|
||||
"""
|
||||
b, c = 1, 0
|
||||
while n:
|
||||
q, r = divmod(a, n)
|
||||
a, b, c, n = n, c, b - q*c, r
|
||||
# at this point a is the gcd of the original inputs
|
||||
if a == 1:
|
||||
return b
|
||||
raise ValueError("Not invertible")
|
||||
|
||||
def invmod_positive(a: int, n: int) -> int:
|
||||
"""Return a non-negative inverse of a to modulo n.
|
||||
|
||||
Equivalent to pow(a, -1, n) in Python 3.8+.
|
||||
"""
|
||||
inv = invmod(a, n)
|
||||
return inv if inv >= 0 else inv + n
|
||||
|
||||
def hex_to_int(val: str) -> int:
|
||||
"""Implement the syntax accepted by mbedtls_test_read_mpi().
|
||||
|
||||
This is a superset of what is accepted by mbedtls_test_read_mpi_core().
|
||||
"""
|
||||
if val in ['', '-']:
|
||||
return 0
|
||||
return int(val, 16)
|
||||
|
||||
def quote_str(val: str) -> str:
|
||||
return "\"{}\"".format(val)
|
||||
|
||||
def bound_mpi(val: int, bits_in_limb: int) -> int:
|
||||
"""First number exceeding number of limbs needed for given input value."""
|
||||
return bound_mpi_limbs(limbs_mpi(val, bits_in_limb), bits_in_limb)
|
||||
|
||||
def bound_mpi_limbs(limbs: int, bits_in_limb: int) -> int:
|
||||
"""First number exceeding maximum of given number of limbs."""
|
||||
bits = bits_in_limb * limbs
|
||||
return 1 << bits
|
||||
|
||||
def limbs_mpi(val: int, bits_in_limb: int) -> int:
|
||||
"""Return the number of limbs required to store value."""
|
||||
bit_length = max(val.bit_length(), 1)
|
||||
return (bit_length + bits_in_limb - 1) // bits_in_limb
|
||||
|
||||
def combination_pairs(values: List[T]) -> List[Tuple[T, T]]:
|
||||
"""Return all pair combinations from input values."""
|
||||
return [(x, y) for x in values for y in values]
|
||||
|
||||
def combination_two_lists(first_vals: List[T], second_vals: List[T]) -> List[Tuple[T, T]]:
|
||||
"""Return all pair combinations from two input lists"""
|
||||
return [(x, y) for x in first_vals for y in second_vals]
|
||||
|
||||
def expand_list_negative(values: List[str]) -> List[str]:
|
||||
"""Adds the negative of every element in the list to the list"""
|
||||
return values + [f"-{value}" for value in values]
|
||||
|
||||
def bits_to_limbs(bits: int, bits_in_limb: int) -> int:
|
||||
""" Return the appropriate ammount of limbs needed to store
|
||||
a number contained in input bits"""
|
||||
return ceil(bits / bits_in_limb)
|
||||
|
||||
def hex_digits_for_limb(limbs: int, bits_in_limb: int) -> int:
|
||||
""" Return the hex digits need for a number of limbs. """
|
||||
return 2 * ((limbs * bits_in_limb) // 8)
|
||||
|
||||
def hex_digits_max_int(val: str, bits_in_limb: int) -> int:
|
||||
""" Return the first number exceeding maximum the limb space
|
||||
required to store the input hex-string value. This method
|
||||
weights on the input str_len rather than numerical value
|
||||
and works with zero-padded inputs"""
|
||||
n = ((1 << (len(val) * 4)) - 1)
|
||||
l = limbs_mpi(n, bits_in_limb)
|
||||
return bound_mpi_limbs(l, bits_in_limb)
|
||||
|
||||
def zfill_match(reference: str, target: str) -> str:
|
||||
""" Zero pad target hex-string to match the limb size of
|
||||
the reference input """
|
||||
lt = len(target)
|
||||
lr = len(reference)
|
||||
target_len = lr if lt < lr else lt
|
||||
return "{:x}".format(int(target, 16)).zfill(target_len)
|
||||
|
||||
class OperationCommon(test_data_generation.BaseTest):
|
||||
"""Common features for bignum binary operations.
|
||||
|
||||
This adds functionality common in binary operation tests.
|
||||
|
||||
Attributes:
|
||||
symbol: Symbol to use for the operation in case description.
|
||||
input_values: List of values to use as test case inputs. These are
|
||||
combined to produce pairs of values.
|
||||
input_cases: List of tuples containing pairs of test case inputs. This
|
||||
can be used to implement specific pairs of inputs.
|
||||
unique_combinations_only: Boolean to select if test case combinations
|
||||
must be unique. If True, only A,B or B,A would be included as a test
|
||||
case. If False, both A,B and B,A would be included.
|
||||
input_style: Controls the way how test data is passed to the functions
|
||||
in the generated test cases. "variable" passes them as they are
|
||||
defined in the python source. "arch_split" pads the values with
|
||||
zeroes depending on the architecture/limb size. If this is set,
|
||||
test cases are generated for all architectures.
|
||||
arity: the number of operands for the operation. Currently supported
|
||||
values are 1 and 2.
|
||||
"""
|
||||
symbol = ""
|
||||
input_values = INPUTS_DEFAULT # type: List[str]
|
||||
input_cases = [] # type: List[Any]
|
||||
dependencies = [] # type: List[Any]
|
||||
unique_combinations_only = False
|
||||
input_styles = ["variable", "fixed", "arch_split"] # type: List[str]
|
||||
input_style = "variable" # type: str
|
||||
limb_sizes = [32, 64] # type: List[int]
|
||||
arities = [1, 2]
|
||||
arity = 2
|
||||
suffix = False # for arity = 1, symbol can be prefix (default) or suffix
|
||||
|
||||
def __init__(self, val_a: str, val_b: str = "0", bits_in_limb: int = 32) -> None:
|
||||
self.val_a = val_a
|
||||
self.val_b = val_b
|
||||
# Setting the int versions here as opposed to making them @properties
|
||||
# provides earlier/more robust input validation.
|
||||
self.int_a = hex_to_int(val_a)
|
||||
self.int_b = hex_to_int(val_b)
|
||||
self.dependencies = deepcopy(self.dependencies)
|
||||
if bits_in_limb not in self.limb_sizes:
|
||||
raise ValueError("Invalid number of bits in limb!")
|
||||
if self.input_style == "arch_split":
|
||||
self.dependencies.append("MBEDTLS_HAVE_INT{:d}".format(bits_in_limb))
|
||||
self.bits_in_limb = bits_in_limb
|
||||
|
||||
@property
|
||||
def boundary(self) -> int:
|
||||
if self.arity == 1:
|
||||
return self.int_a
|
||||
elif self.arity == 2:
|
||||
return max(self.int_a, self.int_b)
|
||||
raise ValueError("Unsupported number of operands!")
|
||||
|
||||
@property
|
||||
def limb_boundary(self) -> int:
|
||||
return bound_mpi(self.boundary, self.bits_in_limb)
|
||||
|
||||
@property
|
||||
def limbs(self) -> int:
|
||||
return limbs_mpi(self.boundary, self.bits_in_limb)
|
||||
|
||||
@property
|
||||
def hex_digits(self) -> int:
|
||||
return hex_digits_for_limb(self.limbs, self.bits_in_limb)
|
||||
|
||||
def format_arg(self, val: str) -> str:
|
||||
if self.input_style not in self.input_styles:
|
||||
raise ValueError("Unknown input style!")
|
||||
if self.input_style == "variable":
|
||||
return val
|
||||
else:
|
||||
return val.zfill(self.hex_digits)
|
||||
|
||||
def format_result(self, res: int) -> str:
|
||||
res_str = '{:x}'.format(res)
|
||||
return quote_str(self.format_arg(res_str))
|
||||
|
||||
@property
|
||||
def arg_a(self) -> str:
|
||||
return self.format_arg(self.val_a)
|
||||
|
||||
@property
|
||||
def arg_b(self) -> str:
|
||||
if self.arity == 1:
|
||||
raise AttributeError("Operation is unary and doesn't have arg_b!")
|
||||
return self.format_arg(self.val_b)
|
||||
|
||||
def arguments(self) -> List[str]:
|
||||
args = [quote_str(self.arg_a)]
|
||||
if self.arity == 2:
|
||||
args.append(quote_str(self.arg_b))
|
||||
return args + self.result()
|
||||
|
||||
def description(self) -> str:
|
||||
"""Generate a description for the test case.
|
||||
|
||||
If not set, case_description uses the form A `symbol` B, where symbol
|
||||
is used to represent the operation. Descriptions of each value are
|
||||
generated to provide some context to the test case.
|
||||
"""
|
||||
if not self.case_description:
|
||||
if self.arity == 1:
|
||||
format_string = "{1:x} {0}" if self.suffix else "{0} {1:x}"
|
||||
self.case_description = format_string.format(
|
||||
self.symbol, self.int_a
|
||||
)
|
||||
elif self.arity == 2:
|
||||
self.case_description = "{:x} {} {:x}".format(
|
||||
self.int_a, self.symbol, self.int_b
|
||||
)
|
||||
return super().description()
|
||||
|
||||
@property
|
||||
def is_valid(self) -> bool:
|
||||
return True
|
||||
|
||||
@abstractmethod
|
||||
def result(self) -> List[str]:
|
||||
"""Get the result of the operation.
|
||||
|
||||
This could be calculated during initialization and stored as `_result`
|
||||
and then returned, or calculated when the method is called.
|
||||
"""
|
||||
raise NotImplementedError
|
||||
|
||||
@classmethod
|
||||
def get_value_pairs(cls) -> Iterator[Tuple[str, str]]:
|
||||
"""Generator to yield pairs of inputs.
|
||||
|
||||
Combinations are first generated from all input values, and then
|
||||
specific cases provided.
|
||||
"""
|
||||
if cls.arity == 1:
|
||||
yield from ((a, "0") for a in cls.input_values)
|
||||
elif cls.arity == 2:
|
||||
if cls.unique_combinations_only:
|
||||
yield from combination_pairs(cls.input_values)
|
||||
else:
|
||||
yield from (
|
||||
(a, b)
|
||||
for a in cls.input_values
|
||||
for b in cls.input_values
|
||||
)
|
||||
else:
|
||||
raise ValueError("Unsupported number of operands!")
|
||||
|
||||
@classmethod
|
||||
def generate_function_tests(cls) -> Iterator[test_case.TestCase]:
|
||||
if cls.input_style not in cls.input_styles:
|
||||
raise ValueError("Unknown input style!")
|
||||
if cls.arity not in cls.arities:
|
||||
raise ValueError("Unsupported number of operands!")
|
||||
if cls.input_style == "arch_split":
|
||||
test_objects = (cls(a, b, bits_in_limb=bil)
|
||||
for a, b in cls.get_value_pairs()
|
||||
for bil in cls.limb_sizes)
|
||||
special_cases = (cls(*args, bits_in_limb=bil) # type: ignore
|
||||
for args in cls.input_cases
|
||||
for bil in cls.limb_sizes)
|
||||
else:
|
||||
test_objects = (cls(a, b)
|
||||
for a, b in cls.get_value_pairs())
|
||||
special_cases = (cls(*args) for args in cls.input_cases)
|
||||
yield from (valid_test_object.create_test_case()
|
||||
for valid_test_object in filter(
|
||||
lambda test_object: test_object.is_valid,
|
||||
chain(test_objects, special_cases)
|
||||
)
|
||||
)
|
||||
|
||||
|
||||
class ModulusRepresentation(enum.Enum):
|
||||
"""Representation selector of a modulus."""
|
||||
# Numerical values aligned with the type mbedtls_mpi_mod_rep_selector
|
||||
INVALID = 0
|
||||
MONTGOMERY = 2
|
||||
OPT_RED = 3
|
||||
|
||||
def symbol(self) -> str:
|
||||
"""The C symbol for this representation selector."""
|
||||
return 'MBEDTLS_MPI_MOD_REP_' + self.name
|
||||
|
||||
@classmethod
|
||||
def supported_representations(cls) -> List['ModulusRepresentation']:
|
||||
"""Return all representations that are supported in positive test cases."""
|
||||
return [cls.MONTGOMERY, cls.OPT_RED]
|
||||
|
||||
|
||||
class ModOperationCommon(OperationCommon):
|
||||
#pylint: disable=abstract-method
|
||||
"""Target for bignum mod_raw test case generation."""
|
||||
moduli = MODULI_DEFAULT # type: List[str]
|
||||
montgomery_form_a = False
|
||||
disallow_zero_a = False
|
||||
|
||||
def __init__(self, val_n: str, val_a: str, val_b: str = "0",
|
||||
bits_in_limb: int = 64) -> None:
|
||||
super().__init__(val_a=val_a, val_b=val_b, bits_in_limb=bits_in_limb)
|
||||
self.val_n = val_n
|
||||
# Setting the int versions here as opposed to making them @properties
|
||||
# provides earlier/more robust input validation.
|
||||
self.int_n = hex_to_int(val_n)
|
||||
|
||||
def to_montgomery(self, val: int) -> int:
|
||||
return (val * self.r) % self.int_n
|
||||
|
||||
def from_montgomery(self, val: int) -> int:
|
||||
return (val * self.r_inv) % self.int_n
|
||||
|
||||
def convert_from_canonical(self, canonical: int,
|
||||
rep: ModulusRepresentation) -> int:
|
||||
"""Convert values from canonical representation to the given representation."""
|
||||
if rep is ModulusRepresentation.MONTGOMERY:
|
||||
return self.to_montgomery(canonical)
|
||||
elif rep is ModulusRepresentation.OPT_RED:
|
||||
return canonical
|
||||
else:
|
||||
raise ValueError('Modulus representation not supported: {}'
|
||||
.format(rep.name))
|
||||
|
||||
@property
|
||||
def boundary(self) -> int:
|
||||
return self.int_n
|
||||
|
||||
@property
|
||||
def arg_a(self) -> str:
|
||||
if self.montgomery_form_a:
|
||||
value_a = self.to_montgomery(self.int_a)
|
||||
else:
|
||||
value_a = self.int_a
|
||||
return self.format_arg('{:x}'.format(value_a))
|
||||
|
||||
@property
|
||||
def arg_n(self) -> str:
|
||||
return self.format_arg(self.val_n)
|
||||
|
||||
def format_arg(self, val: str) -> str:
|
||||
return super().format_arg(val).zfill(self.hex_digits)
|
||||
|
||||
def arguments(self) -> List[str]:
|
||||
return [quote_str(self.arg_n)] + super().arguments()
|
||||
|
||||
@property
|
||||
def r(self) -> int: # pylint: disable=invalid-name
|
||||
l = limbs_mpi(self.int_n, self.bits_in_limb)
|
||||
return bound_mpi_limbs(l, self.bits_in_limb)
|
||||
|
||||
@property
|
||||
def r_inv(self) -> int:
|
||||
return invmod(self.r, self.int_n)
|
||||
|
||||
@property
|
||||
def r2(self) -> int: # pylint: disable=invalid-name
|
||||
return pow(self.r, 2)
|
||||
|
||||
@property
|
||||
def is_valid(self) -> bool:
|
||||
if self.int_a >= self.int_n:
|
||||
return False
|
||||
if self.disallow_zero_a and self.int_a == 0:
|
||||
return False
|
||||
if self.arity == 2 and self.int_b >= self.int_n:
|
||||
return False
|
||||
return True
|
||||
|
||||
def description(self) -> str:
|
||||
"""Generate a description for the test case.
|
||||
|
||||
It uses the form A `symbol` B mod N, where symbol is used to represent
|
||||
the operation.
|
||||
"""
|
||||
|
||||
if not self.case_description:
|
||||
return super().description() + " mod {:x}".format(self.int_n)
|
||||
return super().description()
|
||||
|
||||
@classmethod
|
||||
def input_cases_args(cls) -> Iterator[Tuple[Any, Any, Any]]:
|
||||
if cls.arity == 1:
|
||||
yield from ((n, a, "0") for a, n in cls.input_cases)
|
||||
elif cls.arity == 2:
|
||||
yield from ((n, a, b) for a, b, n in cls.input_cases)
|
||||
else:
|
||||
raise ValueError("Unsupported number of operands!")
|
||||
|
||||
@classmethod
|
||||
def generate_function_tests(cls) -> Iterator[test_case.TestCase]:
|
||||
if cls.input_style not in cls.input_styles:
|
||||
raise ValueError("Unknown input style!")
|
||||
if cls.arity not in cls.arities:
|
||||
raise ValueError("Unsupported number of operands!")
|
||||
if cls.input_style == "arch_split":
|
||||
test_objects = (cls(n, a, b, bits_in_limb=bil)
|
||||
for n in cls.moduli
|
||||
for a, b in cls.get_value_pairs()
|
||||
for bil in cls.limb_sizes)
|
||||
special_cases = (cls(*args, bits_in_limb=bil)
|
||||
for args in cls.input_cases_args()
|
||||
for bil in cls.limb_sizes)
|
||||
else:
|
||||
test_objects = (cls(n, a, b)
|
||||
for n in cls.moduli
|
||||
for a, b in cls.get_value_pairs())
|
||||
special_cases = (cls(*args) for args in cls.input_cases_args())
|
||||
yield from (valid_test_object.create_test_case()
|
||||
for valid_test_object in filter(
|
||||
lambda test_object: test_object.is_valid,
|
||||
chain(test_objects, special_cases)
|
||||
))
|
||||
972
vendor/mbedtls/framework/scripts/mbedtls_framework/bignum_core.py
vendored
Normal file
972
vendor/mbedtls/framework/scripts/mbedtls_framework/bignum_core.py
vendored
Normal file
@@ -0,0 +1,972 @@
|
||||
"""Framework classes for generation of bignum core test cases."""
|
||||
# Copyright The Mbed TLS Contributors
|
||||
# SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
#
|
||||
|
||||
import math
|
||||
import random
|
||||
|
||||
from typing import Dict, Iterator, List, Tuple
|
||||
|
||||
from . import test_case
|
||||
from . import test_data_generation
|
||||
from . import bignum_common
|
||||
from . import bignum_data
|
||||
|
||||
class BignumCoreTarget(test_data_generation.BaseTarget):
|
||||
#pylint: disable=abstract-method, too-few-public-methods
|
||||
"""Target for bignum core test case generation."""
|
||||
target_basename = 'test_suite_bignum_core.generated'
|
||||
|
||||
|
||||
class BignumCoreShiftR(BignumCoreTarget, test_data_generation.BaseTest):
|
||||
"""Test cases for mbedtls_bignum_core_shift_r()."""
|
||||
count = 0
|
||||
test_function = "mpi_core_shift_r"
|
||||
test_name = "Core shift right"
|
||||
|
||||
DATA = [
|
||||
('00', '0', [0, 1, 8]),
|
||||
('01', '1', [0, 1, 2, 8, 64]),
|
||||
('dee5ca1a7ef10a75', '64-bit',
|
||||
list(range(11)) + [31, 32, 33, 63, 64, 65, 71, 72]),
|
||||
('002e7ab0070ad57001', '[leading 0 limb]',
|
||||
[0, 1, 8, 63, 64]),
|
||||
('a1055eb0bb1efa1150ff', '80-bit',
|
||||
[0, 1, 8, 63, 64, 65, 72, 79, 80, 81, 88, 128, 129, 136]),
|
||||
('020100000000000000001011121314151617', '138-bit',
|
||||
[0, 1, 8, 9, 16, 72, 73, 136, 137, 138, 144]),
|
||||
]
|
||||
|
||||
def __init__(self, input_hex: str, descr: str, count: int) -> None:
|
||||
self.input_hex = input_hex
|
||||
self.number_description = descr
|
||||
self.shift_count = count
|
||||
self.result = bignum_common.hex_to_int(input_hex) >> count
|
||||
|
||||
def arguments(self) -> List[str]:
|
||||
return ['"{}"'.format(self.input_hex),
|
||||
str(self.shift_count),
|
||||
'"{:0{}x}"'.format(self.result, len(self.input_hex))]
|
||||
|
||||
def description(self) -> str:
|
||||
return 'Core shift {} >> {}'.format(self.number_description,
|
||||
self.shift_count)
|
||||
|
||||
@classmethod
|
||||
def generate_function_tests(cls) -> Iterator[test_case.TestCase]:
|
||||
for input_hex, descr, counts in cls.DATA:
|
||||
for count in counts:
|
||||
yield cls(input_hex, descr, count).create_test_case()
|
||||
|
||||
|
||||
class BignumCoreShiftL(BignumCoreTarget, bignum_common.ModOperationCommon):
|
||||
"""Test cases for mbedtls_bignum_core_shift_l()."""
|
||||
|
||||
BIT_SHIFT_VALUES = ['0', '1', '2', '3', '4', '5', '6', '7', '8', '9', 'a',
|
||||
'1f', '20', '21', '3f', '40', '41', '47', '48', '4f',
|
||||
'50', '51', '58', '80', '81', '88']
|
||||
DATA = ["0", "1", "40", "dee5ca1a7ef10a75", "a1055eb0bb1efa1150ff",
|
||||
"002e7ab0070ad57001", "020100000000000000001011121314151617",
|
||||
"1946e2958a85d8863ae21f4904fcc49478412534ed53eaf321f63f2a222" +
|
||||
"7a3c63acbf50b6305595f90cfa8327f6db80d986fe96080bcbb5df1bdbe" +
|
||||
"9b74fb8dedf2bddb3f8215b54dffd66409323bcc473e45a8fe9d08e77a51" +
|
||||
"1698b5dad0416305db7fcf"]
|
||||
arity = 1
|
||||
test_function = "mpi_core_shift_l"
|
||||
test_name = "Core shift(L)"
|
||||
input_style = "arch_split"
|
||||
symbol = "<<"
|
||||
input_values = BIT_SHIFT_VALUES
|
||||
moduli = DATA
|
||||
|
||||
@property
|
||||
def val_n_max_limbs(self) -> int:
|
||||
""" Return the limb count required to store the maximum number that can
|
||||
fit in a the number of digits used by val_n """
|
||||
m = bignum_common.hex_digits_max_int(self.val_n, self.bits_in_limb) - 1
|
||||
return bignum_common.limbs_mpi(m, self.bits_in_limb)
|
||||
|
||||
def arguments(self) -> List[str]:
|
||||
return [bignum_common.quote_str(self.val_n),
|
||||
str(self.int_a)
|
||||
] + self.result()
|
||||
|
||||
def description(self) -> str:
|
||||
""" Format the output as:
|
||||
#{count} {hex input} ({input bits} {limbs capacity}) << {bit shift} """
|
||||
bits = "({} bits in {} limbs)".format(self.int_n.bit_length(), self.val_n_max_limbs)
|
||||
return "{} #{} {} {} {} {}".format(self.test_name,
|
||||
self.count,
|
||||
self.val_n,
|
||||
bits,
|
||||
self.symbol,
|
||||
self.int_a)
|
||||
|
||||
def format_result(self, res: int) -> str:
|
||||
# Override to match zero-pading for leading digits between the output and input.
|
||||
res_str = bignum_common.zfill_match(self.val_n, "{:x}".format(res))
|
||||
return bignum_common.quote_str(res_str)
|
||||
|
||||
def result(self) -> List[str]:
|
||||
result = (self.int_n << self.int_a)
|
||||
# Calculate if there is space for shifting to the left(leading zero limbs)
|
||||
mx = bignum_common.hex_digits_max_int(self.val_n, self.bits_in_limb)
|
||||
# If there are empty limbs ahead, adjust the bitmask accordingly
|
||||
result = result & (mx - 1)
|
||||
return [self.format_result(result)]
|
||||
|
||||
@property
|
||||
def is_valid(self) -> bool:
|
||||
return True
|
||||
|
||||
|
||||
class BignumCoreCTLookup(BignumCoreTarget, test_data_generation.BaseTest):
|
||||
"""Test cases for mbedtls_mpi_core_ct_uint_table_lookup()."""
|
||||
test_function = "mpi_core_ct_uint_table_lookup"
|
||||
test_name = "Constant time MPI table lookup"
|
||||
|
||||
bitsizes = [
|
||||
(32, "One limb"),
|
||||
(192, "Smallest curve sized"),
|
||||
(512, "Largest curve sized"),
|
||||
(2048, "Small FF/RSA sized"),
|
||||
(4096, "Large FF/RSA sized"),
|
||||
]
|
||||
|
||||
window_sizes = [0, 1, 2, 3, 4, 5, 6]
|
||||
|
||||
def __init__(self,
|
||||
bitsize: int, descr: str, window_size: int) -> None:
|
||||
self.bitsize = bitsize
|
||||
self.bitsize_description = descr
|
||||
self.window_size = window_size
|
||||
|
||||
def arguments(self) -> List[str]:
|
||||
return [str(self.bitsize), str(self.window_size)]
|
||||
|
||||
def description(self) -> str:
|
||||
return '{} - {} MPI with {} bit window'.format(
|
||||
BignumCoreCTLookup.test_name,
|
||||
self.bitsize_description,
|
||||
self.window_size
|
||||
)
|
||||
|
||||
@classmethod
|
||||
def generate_function_tests(cls) -> Iterator[test_case.TestCase]:
|
||||
for bitsize, bitsize_description in cls.bitsizes:
|
||||
for window_size in cls.window_sizes:
|
||||
yield (cls(bitsize, bitsize_description, window_size)
|
||||
.create_test_case())
|
||||
|
||||
|
||||
class BignumCoreAddAndAddIf(BignumCoreTarget, bignum_common.OperationCommon):
|
||||
"""Test cases for bignum core add and add-if."""
|
||||
count = 0
|
||||
symbol = "+"
|
||||
test_function = "mpi_core_add_and_add_if"
|
||||
test_name = "mpi_core_add_and_add_if"
|
||||
input_style = "arch_split"
|
||||
input_values = bignum_data.ADD_SUB_DATA
|
||||
unique_combinations_only = True
|
||||
|
||||
def result(self) -> List[str]:
|
||||
result = self.int_a + self.int_b
|
||||
|
||||
carry, result = divmod(result, self.limb_boundary)
|
||||
|
||||
return [
|
||||
self.format_result(result),
|
||||
str(carry)
|
||||
]
|
||||
|
||||
|
||||
class BignumCoreSub(BignumCoreTarget, bignum_common.OperationCommon):
|
||||
"""Test cases for bignum core sub."""
|
||||
count = 0
|
||||
input_style = "arch_split"
|
||||
symbol = "-"
|
||||
test_function = "mpi_core_sub"
|
||||
test_name = "mbedtls_mpi_core_sub"
|
||||
input_values = bignum_data.ADD_SUB_DATA
|
||||
|
||||
def result(self) -> List[str]:
|
||||
if self.int_a >= self.int_b:
|
||||
result = self.int_a - self.int_b
|
||||
carry = 0
|
||||
else:
|
||||
result = self.limb_boundary + self.int_a - self.int_b
|
||||
carry = 1
|
||||
return [
|
||||
self.format_result(result),
|
||||
str(carry)
|
||||
]
|
||||
|
||||
|
||||
class BignumCoreMLA(BignumCoreTarget, bignum_common.OperationCommon):
|
||||
"""Test cases for fixed-size multiply accumulate."""
|
||||
count = 0
|
||||
test_function = "mpi_core_mla"
|
||||
test_name = "mbedtls_mpi_core_mla"
|
||||
|
||||
input_values = [
|
||||
"0", "1", "fffe", "ffffffff", "100000000", "20000000000000",
|
||||
"ffffffffffffffff", "10000000000000000", "1234567890abcdef0",
|
||||
"fffffffffffffffffefefefefefefefe",
|
||||
"100000000000000000000000000000000",
|
||||
"1234567890abcdef01234567890abcdef0",
|
||||
"ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff",
|
||||
"1234567890abcdef01234567890abcdef01234567890abcdef01234567890abcdef0",
|
||||
(
|
||||
"4df72d07b4b71c8dacb6cffa954f8d88254b6277099308baf003fab73227f" +
|
||||
"34029643b5a263f66e0d3c3fa297ef71755efd53b8fb6cb812c6bbf7bcf17" +
|
||||
"9298bd9947c4c8b14324140a2c0f5fad7958a69050a987a6096e9f055fb38" +
|
||||
"edf0c5889eca4a0cfa99b45fbdeee4c696b328ddceae4723945901ec02507" +
|
||||
"6b12b"
|
||||
)
|
||||
] # type: List[str]
|
||||
input_scalars = [
|
||||
"0", "3", "fe", "ff", "ffff", "10000", "ffffffff", "100000000",
|
||||
"7f7f7f7f7f7f7f7f", "8000000000000000", "fffffffffffffffe"
|
||||
] # type: List[str]
|
||||
|
||||
def __init__(self, val_a: str, val_b: str, val_s: str) -> None:
|
||||
super().__init__(val_a, val_b)
|
||||
self.arg_scalar = val_s
|
||||
self.int_scalar = bignum_common.hex_to_int(val_s)
|
||||
if bignum_common.limbs_mpi(self.int_scalar, 32) > 1:
|
||||
self.dependencies = ["MBEDTLS_HAVE_INT64"]
|
||||
|
||||
def arguments(self) -> List[str]:
|
||||
return [
|
||||
bignum_common.quote_str(self.arg_a),
|
||||
bignum_common.quote_str(self.arg_b),
|
||||
bignum_common.quote_str(self.arg_scalar)
|
||||
] + self.result()
|
||||
|
||||
def description(self) -> str:
|
||||
"""Override and add the additional scalar."""
|
||||
if not self.case_description:
|
||||
self.case_description = "0x{} + 0x{} * 0x{}".format(
|
||||
self.arg_a, self.arg_b, self.arg_scalar
|
||||
)
|
||||
return super().description()
|
||||
|
||||
def result(self) -> List[str]:
|
||||
result = self.int_a + (self.int_b * self.int_scalar)
|
||||
bound_val = max(self.int_a, self.int_b)
|
||||
bound_4 = bignum_common.bound_mpi(bound_val, 32)
|
||||
bound_8 = bignum_common.bound_mpi(bound_val, 64)
|
||||
carry_4, remainder_4 = divmod(result, bound_4)
|
||||
carry_8, remainder_8 = divmod(result, bound_8)
|
||||
return [
|
||||
"\"{:x}\"".format(remainder_4),
|
||||
"\"{:x}\"".format(carry_4),
|
||||
"\"{:x}\"".format(remainder_8),
|
||||
"\"{:x}\"".format(carry_8)
|
||||
]
|
||||
|
||||
@classmethod
|
||||
def get_value_pairs(cls) -> Iterator[Tuple[str, str]]:
|
||||
"""Generator to yield pairs of inputs.
|
||||
|
||||
Combinations are first generated from all input values, and then
|
||||
specific cases provided.
|
||||
"""
|
||||
yield from super().get_value_pairs()
|
||||
yield from cls.input_cases
|
||||
|
||||
@classmethod
|
||||
def generate_function_tests(cls) -> Iterator[test_case.TestCase]:
|
||||
"""Override for additional scalar input."""
|
||||
for a_value, b_value in cls.get_value_pairs():
|
||||
for s_value in cls.input_scalars:
|
||||
cur_op = cls(a_value, b_value, s_value)
|
||||
yield cur_op.create_test_case()
|
||||
|
||||
|
||||
class BignumCoreMul(BignumCoreTarget, bignum_common.OperationCommon):
|
||||
"""Test cases for bignum core multiplication."""
|
||||
count = 0
|
||||
input_style = "arch_split"
|
||||
symbol = "*"
|
||||
test_function = "mpi_core_mul"
|
||||
test_name = "mbedtls_mpi_core_mul"
|
||||
arity = 2
|
||||
unique_combinations_only = True
|
||||
|
||||
def format_arg(self, val: str) -> str:
|
||||
return val
|
||||
|
||||
def format_result(self, res: int) -> str:
|
||||
res_str = '{:x}'.format(res)
|
||||
a_limbs = bignum_common.limbs_mpi(self.int_a, self.bits_in_limb)
|
||||
b_limbs = bignum_common.limbs_mpi(self.int_b, self.bits_in_limb)
|
||||
hex_digits = bignum_common.hex_digits_for_limb(a_limbs + b_limbs, self.bits_in_limb)
|
||||
return bignum_common.quote_str(self.format_arg(res_str).zfill(hex_digits))
|
||||
|
||||
def result(self) -> List[str]:
|
||||
result = self.int_a * self.int_b
|
||||
return [self.format_result(result)]
|
||||
|
||||
|
||||
class BignumCoreMontmul(BignumCoreTarget, test_data_generation.BaseTest):
|
||||
"""Test cases for Montgomery multiplication."""
|
||||
count = 0
|
||||
test_function = "mpi_core_montmul"
|
||||
test_name = "mbedtls_mpi_core_montmul"
|
||||
|
||||
start_2_mpi4 = False
|
||||
start_2_mpi8 = False
|
||||
|
||||
replay_test_cases = [
|
||||
(2, 1, 1, 1, "19", "1", "1D"), (2, 1, 1, 1, "7", "1", "9"),
|
||||
(2, 1, 1, 1, "4", "1", "9"),
|
||||
(
|
||||
12, 1, 6, 1, (
|
||||
"3C246D0E059A93A266288A7718419EC741661B474C58C032C5EDAF92709402" +
|
||||
"B07CC8C7CE0B781C641A1EA8DB2F4343"
|
||||
), "1", (
|
||||
"66A198186C18C10B2F5ED9B522752A9830B69916E535C8F047518A889A43A5" +
|
||||
"94B6BED27A168D31D4A52F88925AA8F5"
|
||||
)
|
||||
), (
|
||||
8, 1, 4, 1,
|
||||
"1E442976B0E63D64FCCE74B999E470CA9888165CB75BFA1F340E918CE03C6211",
|
||||
"1", "B3A119602EE213CDE28581ECD892E0F592A338655DCE4CA88054B3D124D0E561"
|
||||
), (
|
||||
22, 1, 11, 1, (
|
||||
"7CF5AC97304E0B63C65413F57249F59994B0FED1D2A8D3D83ED5FA38560FFB" +
|
||||
"82392870D6D08F87D711917FD7537E13B7E125BE407E74157776839B0AC9DB" +
|
||||
"23CBDFC696104353E4D2780B2B4968F8D8542306BCA7A2366E"
|
||||
), "1", (
|
||||
"284139EA19C139EBE09A8111926AAA39A2C2BE12ED487A809D3CB5BC558547" +
|
||||
"25B4CDCB5734C58F90B2F60D99CC1950CDBC8D651793E93C9C6F0EAD752500" +
|
||||
"A32C56C62082912B66132B2A6AA42ADA923E1AD22CEB7BA0123"
|
||||
)
|
||||
)
|
||||
] # type: List[Tuple[int, int, int, int, str, str, str]]
|
||||
|
||||
random_test_cases = [
|
||||
("2", "2", "3", ""), ("1", "2", "3", ""), ("2", "1", "3", ""),
|
||||
("6", "5", "7", ""), ("3", "4", "7", ""), ("1", "6", "7", ""), ("5", "6", "7", ""),
|
||||
("3", "4", "B", ""), ("7", "4", "B", ""), ("9", "7", "B", ""), ("2", "a", "B", ""),
|
||||
("25", "16", "29", "(0x29 is prime)"), ("8", "28", "29", ""),
|
||||
("18", "21", "29", ""), ("15", "f", "29", ""),
|
||||
("e2", "ea", "FF", ""), ("43", "72", "FF", ""),
|
||||
("d8", "70", "FF", ""), ("3c", "7c", "FF", ""),
|
||||
("99", "b9", "101", "(0x101 is prime)"), ("65", "b2", "101", ""),
|
||||
("81", "32", "101", ""), ("51", "dd", "101", ""),
|
||||
("d5", "143", "38B", "(0x38B is prime)"), ("3d", "387", "38B", ""),
|
||||
("160", "2e5", "38B", ""), ("10f", "137", "38B", ""),
|
||||
("7dac", "25a", "8003", "(0x8003 is prime)"), ("6f1c", "3286", "8003", ""),
|
||||
("59ed", "2f3f", "8003", ""), ("6893", "736d", "8003", ""),
|
||||
("d199", "2832", "10001", "(0x10001 is prime)"), ("c3b2", "3e5b", "10001", ""),
|
||||
("abe4", "214e", "10001", ""), ("4360", "a05d", "10001", ""),
|
||||
("3f5a1", "165b2", "7F7F7", ""), ("3bd29", "37863", "7F7F7", ""),
|
||||
("60c47", "64819", "7F7F7", ""), ("16584", "12c49", "7F7F7", ""),
|
||||
("1ff03f", "610347", "800009", "(0x800009 is prime)"), ("340fd5", "19812e", "800009", ""),
|
||||
("3fe2e8", "4d0dc7", "800009", ""), ("40356", "e6392", "800009", ""),
|
||||
("dd8a1d", "266c0e", "100002B", "(0x100002B is prime)"),
|
||||
("3fa1cb", "847fd6", "100002B", ""), ("5f439d", "5c3196", "100002B", ""),
|
||||
("18d645", "f72dc6", "100002B", ""),
|
||||
("20051ad", "37def6e", "37EEE9D", "(0x37EEE9D is prime)"),
|
||||
("2ec140b", "3580dbf", "37EEE9D", ""), ("1d91b46", "190d4fc", "37EEE9D", ""),
|
||||
("34e488d", "1224d24", "37EEE9D", ""),
|
||||
("2a4fe2cb", "263466a9", "8000000B", "(0x8000000B is prime)"),
|
||||
("5643fe94", "29a1aefa", "8000000B", ""), ("29633513", "7b007ac4", "8000000B", ""),
|
||||
("2439cef5", "5c9d5a47", "8000000B", ""),
|
||||
("4de3cfaa", "50dea178", "8CD626B9", "(0x8CD626B9 is prime)"),
|
||||
("b8b8563", "10dbbbac", "8CD626B9", ""), ("4e8a6151", "5574ec19", "8CD626B9", ""),
|
||||
("69224878", "309cfc23", "8CD626B9", ""),
|
||||
("fb6f7fb6", "afb05423", "10000000F", "(0x10000000F is prime)"),
|
||||
("8391a243", "26034dcd", "10000000F", ""), ("d26b98c", "14b2d6aa", "10000000F", ""),
|
||||
("6b9f1371", "a21daf1d", "10000000F", ""),
|
||||
(
|
||||
"9f49435ad", "c8264ade8", "174876E7E9",
|
||||
"0x174876E7E9 is prime (dec) 99999999977"
|
||||
),
|
||||
("c402da434", "1fb427acf", "174876E7E9", ""),
|
||||
("f6ebc2bb1", "1096d39f2a", "174876E7E9", ""),
|
||||
("153b7f7b6b", "878fda8ff", "174876E7E9", ""),
|
||||
("2c1adbb8d6", "4384d2d3c6", "8000000017", "(0x8000000017 is prime)"),
|
||||
("2e4f9cf5fb", "794f3443d9", "8000000017", ""),
|
||||
("149e495582", "3802b8f7b7", "8000000017", ""),
|
||||
("7b9d49df82", "69c68a442a", "8000000017", ""),
|
||||
("683a134600", "6dd80ea9f6", "864CB9076D", "(0x864CB9076D is prime)"),
|
||||
("13a870ff0d", "59b099694a", "864CB9076D", ""),
|
||||
("37d06b0e63", "4d2147e46f", "864CB9076D", ""),
|
||||
("661714f8f4", "22e55df507", "864CB9076D", ""),
|
||||
("2f0a96363", "52693307b4", "F7F7F7F7F7", ""),
|
||||
("3c85078e64", "f2275ecb6d", "F7F7F7F7F7", ""),
|
||||
("352dae68d1", "707775b4c6", "F7F7F7F7F7", ""),
|
||||
("37ae0f3e0b", "912113040f", "F7F7F7F7F7", ""),
|
||||
("6dada15e31", "f58ed9eff7", "1000000000F", "(0x1000000000F is prime)"),
|
||||
("69627a7c89", "cfb5ebd13d", "1000000000F", ""),
|
||||
("a5e1ad239b", "afc030c731", "1000000000F", ""),
|
||||
("f1cc45f4c5", "c64ad607c8", "1000000000F", ""),
|
||||
("2ebad87d2e31", "4c72d90bca78", "800000000005", "(0x800000000005 is prime)"),
|
||||
("a30b3cc50d", "29ac4fe59490", "800000000005", ""),
|
||||
("33674e9647b4", "5ec7ee7e72d3", "800000000005", ""),
|
||||
("3d956f474f61", "74070040257d", "800000000005", ""),
|
||||
("48348e3717d6", "43fcb4399571", "800795D9BA47", "(0x800795D9BA47 is prime)"),
|
||||
("5234c03cc99b", "2f3cccb87803", "800795D9BA47", ""),
|
||||
("3ed13db194ab", "44b8f4ba7030", "800795D9BA47", ""),
|
||||
("1c11e843bfdb", "95bd1b47b08", "800795D9BA47", ""),
|
||||
("a81d11cb81fd", "1e5753a3f33d", "1000000000015", "(0x1000000000015 is prime)"),
|
||||
("688c4db99232", "36fc0cf7ed", "1000000000015", ""),
|
||||
("f0720cc07e07", "fc76140ed903", "1000000000015", ""),
|
||||
("2ec61f8d17d1", "d270c85e36d2", "1000000000015", ""),
|
||||
(
|
||||
"6a24cd3ab63820", "ed4aad55e5e348", "100000000000051",
|
||||
"(0x100000000000051 is prime)"
|
||||
),
|
||||
("e680c160d3b248", "31e0d8840ed510", "100000000000051", ""),
|
||||
("a80637e9aebc38", "bb81decc4e1738", "100000000000051", ""),
|
||||
("9afa5a59e9d630", "be9e65a6d42938", "100000000000051", ""),
|
||||
("ab5e104eeb71c000", "2cffbd639e9fea00", "ABCDEF0123456789", ""),
|
||||
("197b867547f68a00", "44b796cf94654800", "ABCDEF0123456789", ""),
|
||||
("329f9483a04f2c00", "9892f76961d0f000", "ABCDEF0123456789", ""),
|
||||
("4a2e12dfb4545000", "1aa3e89a69794500", "ABCDEF0123456789", ""),
|
||||
(
|
||||
"8b9acdf013d140f000", "12e4ceaefabdf2b2f00", "25A55A46E5DA99C71C7",
|
||||
"0x25A55A46E5DA99C71C7 is the 3rd repunit prime(dec) 11111111111111111111111"
|
||||
),
|
||||
("1b8d960ea277e3f5500", "14418aa980e37dd000", "25A55A46E5DA99C71C7", ""),
|
||||
("7314524977e8075980", "8172fa45618ccd0d80", "25A55A46E5DA99C71C7", ""),
|
||||
("ca14f031769be63580", "147a2f3cf2964ca9400", "25A55A46E5DA99C71C7", ""),
|
||||
(
|
||||
"18532ba119d5cd0cf39735c0000", "25f9838e31634844924733000000",
|
||||
"314DC643FB763F2B8C0E2DE00879",
|
||||
"0x314DC643FB763F2B8C0E2DE00879 is (dec)99999999977^3"
|
||||
),
|
||||
(
|
||||
"a56e2d2517519e3970e70c40000", "ec27428d4bb380458588fa80000",
|
||||
"314DC643FB763F2B8C0E2DE00879", ""
|
||||
),
|
||||
(
|
||||
"1cb5e8257710e8653fff33a00000", "15fdd42fe440fd3a1d121380000",
|
||||
"314DC643FB763F2B8C0E2DE00879", ""
|
||||
),
|
||||
(
|
||||
"e50d07a65fc6f93e538ce040000", "1f4b059ca609f3ce597f61240000",
|
||||
"314DC643FB763F2B8C0E2DE00879", ""
|
||||
),
|
||||
(
|
||||
"1ea3ade786a095d978d387f30df9f20000000",
|
||||
"127c448575f04af5a367a7be06c7da0000000",
|
||||
"47BF19662275FA2F6845C74942ED1D852E521",
|
||||
"0x47BF19662275FA2F6845C74942ED1D852E521 is (dec) 99999999977^4"
|
||||
),
|
||||
(
|
||||
"16e15b0ca82764e72e38357b1f10a20000000",
|
||||
"43e2355d8514bbe22b0838fdc3983a0000000",
|
||||
"47BF19662275FA2F6845C74942ED1D852E521", ""
|
||||
),
|
||||
(
|
||||
"be39332529d93f25c3d116c004c620000000",
|
||||
"5cccec42370a0a2c89c6772da801a0000000",
|
||||
"47BF19662275FA2F6845C74942ED1D852E521", ""
|
||||
),
|
||||
(
|
||||
"ecaa468d90de0eeda474d39b3e1fc0000000",
|
||||
"1e714554018de6dc0fe576bfd3b5660000000",
|
||||
"47BF19662275FA2F6845C74942ED1D852E521", ""
|
||||
),
|
||||
(
|
||||
"32298816711c5dce46f9ba06e775c4bedfc770e6700000000000000",
|
||||
"8ee751fd5fb24f0b4a653cb3a0c8b7d9e724574d168000000000000",
|
||||
"97EDD86E4B5C4592C6D32064AC55C888A7245F07CA3CC455E07C931",
|
||||
(
|
||||
"0x97EDD86E4B5C4592C6D32064AC55C888A7245F07CA3CC455E07C931" +
|
||||
" is (dec) 99999999977^6"
|
||||
)
|
||||
),
|
||||
(
|
||||
"29213b9df3cfd15f4b428645b67b677c29d1378d810000000000000",
|
||||
"6cbb732c65e10a28872394dfdd1936d5171c3c3aac0000000000000",
|
||||
"97EDD86E4B5C4592C6D32064AC55C888A7245F07CA3CC455E07C931", ""
|
||||
),
|
||||
(
|
||||
"6f18db06ad4abc52c0c50643dd13098abccd4a232f0000000000000",
|
||||
"7e6bf41f2a86098ad51f98dfc10490ba3e8081bc830000000000000",
|
||||
"97EDD86E4B5C4592C6D32064AC55C888A7245F07CA3CC455E07C931", ""
|
||||
),
|
||||
(
|
||||
"62d3286cd706ad9d73caff63f1722775d7e8c731208000000000000",
|
||||
"530f7ba02ae2b04c2fe3e3d27ec095925631a6c2528000000000000",
|
||||
"97EDD86E4B5C4592C6D32064AC55C888A7245F07CA3CC455E07C931", ""
|
||||
),
|
||||
(
|
||||
"a6c6503e3c031fdbf6009a89ed60582b7233c5a85de28b16000000000000000",
|
||||
"75c8ed18270b583f16d442a467d32bf95c5e491e9b8523798000000000000000",
|
||||
"DD15FE80B731872AC104DB37832F7E75A244AA2631BC87885B861E8F20375499",
|
||||
(
|
||||
"0xDD15FE80B731872AC104DB37832F7E75A244AA2631BC87885B861E8F20375499" +
|
||||
" is (dec) 99999999977^7"
|
||||
)
|
||||
),
|
||||
(
|
||||
"bf84d1f85cf6b51e04d2c8f4ffd03532d852053cf99b387d4000000000000000",
|
||||
"397ba5a743c349f4f28bc583ecd5f06e0a25f9c6d98f09134000000000000000",
|
||||
"DD15FE80B731872AC104DB37832F7E75A244AA2631BC87885B861E8F20375499", ""
|
||||
),
|
||||
(
|
||||
"6db11c3a4152ed1a2aa6fa34b0903ec82ea1b88908dcb482000000000000000",
|
||||
"ac8ac576a74ad6ca48f201bf89f77350ce86e821358d85920000000000000000",
|
||||
"DD15FE80B731872AC104DB37832F7E75A244AA2631BC87885B861E8F20375499", ""
|
||||
),
|
||||
(
|
||||
"3001d96d7fe8b733f33687646fc3017e3ac417eb32e0ec708000000000000000",
|
||||
"925ddbdac4174e8321a48a32f79640e8cf7ec6f46ea235a80000000000000000",
|
||||
"DD15FE80B731872AC104DB37832F7E75A244AA2631BC87885B861E8F20375499", ""
|
||||
),
|
||||
(
|
||||
"1029048755f2e60dd98c8de6d9989226b6bb4f0db8e46bd1939de560000000000000000000",
|
||||
"51bb7270b2e25cec0301a03e8275213bb6c2f6e6ec93d4d46d36ca0000000000000000000",
|
||||
"141B8EBD9009F84C241879A1F680FACCED355DA36C498F73E96E880CF78EA5F96146380E41",
|
||||
(
|
||||
"0x141B8EBD9009F84C241879A1F680FACCED355DA36C498F73E96E880CF78EA5F96146" +
|
||||
"380E41 is 99999999977^8"
|
||||
)
|
||||
),
|
||||
(
|
||||
"1c5337ff982b3ad6611257dbff5bbd7a9920ba2d4f5838a0cc681ce000000000000000000",
|
||||
"520c5d049ca4702031ba728591b665c4d4ccd3b2b86864d4c160fd2000000000000000000",
|
||||
"141B8EBD9009F84C241879A1F680FACCED355DA36C498F73E96E880CF78EA5F96146380E41",
|
||||
""
|
||||
),
|
||||
(
|
||||
"57074dfa00e42f6555bae624b7f0209f218adf57f73ed34ab0ff90c000000000000000000",
|
||||
"41eb14b6c07bfd3d1fe4f4a610c17cc44fcfcda695db040e011065000000000000000000",
|
||||
"141B8EBD9009F84C241879A1F680FACCED355DA36C498F73E96E880CF78EA5F96146380E41",
|
||||
""
|
||||
),
|
||||
(
|
||||
"d8ed7feed2fe855e6997ad6397f776158573d425031bf085a615784000000000000000000",
|
||||
"6f121dcd18c578ab5e229881006007bb6d319b179f11015fe958b9c000000000000000000",
|
||||
"141B8EBD9009F84C241879A1F680FACCED355DA36C498F73E96E880CF78EA5F96146380E41",
|
||||
""
|
||||
),
|
||||
(
|
||||
(
|
||||
"2a462b156180ea5fe550d3758c764e06fae54e626b5f503265a09df76edbdfbf" +
|
||||
"a1e6000000000000000000000000"
|
||||
), (
|
||||
"1136f41d1879fd4fb9e49e0943a46b6704d77c068ee237c3121f9071cfd3e6a0" +
|
||||
"0315800000000000000000000000"
|
||||
), (
|
||||
"2A94608DE88B6D5E9F8920F5ABB06B24CC35AE1FBACC87D075C621C3E2833EC90" +
|
||||
"2713E40F51E3B3C214EDFABC451"
|
||||
), (
|
||||
"0x2A94608DE88B6D5E9F8920F5ABB06B24CC35AE1FBACC87D075C621C3E2833EC" +
|
||||
"902713E40F51E3B3C214EDFABC451 is (dec) 99999999977^10"
|
||||
)
|
||||
),
|
||||
(
|
||||
(
|
||||
"c1ac3800dfb3c6954dea391d206200cf3c47f795bf4a5603b4cb88ae7e574de47" +
|
||||
"40800000000000000000000000"
|
||||
), (
|
||||
"c0d16eda0549ede42fa0deb4635f7b7ce061fadea02ee4d85cba4c4f709603419" +
|
||||
"3c800000000000000000000000"
|
||||
), (
|
||||
"2A94608DE88B6D5E9F8920F5ABB06B24CC35AE1FBACC87D075C621C3E2833EC90" +
|
||||
"2713E40F51E3B3C214EDFABC451"
|
||||
), ""
|
||||
),
|
||||
(
|
||||
(
|
||||
"19e45bb7633094d272588ad2e43bcb3ee341991c6731b6fa9d47c4018d7ce7bba" +
|
||||
"5ee800000000000000000000000"
|
||||
), (
|
||||
"1e4f83166ae59f6b9cc8fd3e7677ed8bfc01bb99c98bd3eb084246b64c1e18c33" +
|
||||
"65b800000000000000000000000"
|
||||
), (
|
||||
"2A94608DE88B6D5E9F8920F5ABB06B24CC35AE1FBACC87D075C621C3E2833EC90" +
|
||||
"2713E40F51E3B3C214EDFABC451"
|
||||
), ""
|
||||
),
|
||||
(
|
||||
(
|
||||
"1aa93395fad5f9b7f20b8f9028a054c0bb7c11bb8520e6a95e5a34f06cb70bcdd" +
|
||||
"01a800000000000000000000000"
|
||||
), (
|
||||
"54b45afa5d4310192f8d224634242dd7dcfb342318df3d9bd37b4c614788ba13b" +
|
||||
"8b000000000000000000000000"
|
||||
), (
|
||||
"2A94608DE88B6D5E9F8920F5ABB06B24CC35AE1FBACC87D075C621C3E2833EC90" +
|
||||
"2713E40F51E3B3C214EDFABC451"
|
||||
), ""
|
||||
),
|
||||
(
|
||||
(
|
||||
"544f2628a28cfb5ce0a1b7180ee66b49716f1d9476c466c57f0c4b23089917843" +
|
||||
"06d48f78686115ee19e25400000000000000000000000000000000"
|
||||
), (
|
||||
"677eb31ef8d66c120fa872a60cd47f6e10cbfdf94f90501bd7883cba03d185be0" +
|
||||
"a0148d1625745e9c4c827300000000000000000000000000000000"
|
||||
), (
|
||||
"8335616AED761F1F7F44E6BD49E807B82E3BF2BF11BFA6AF813C808DBF33DBFA1" +
|
||||
"1DABD6E6144BEF37C6800000000000000000000000000000000051"
|
||||
), (
|
||||
"0x8335616AED761F1F7F44E6BD49E807B82E3BF2BF11BFA6AF813C808DBF33DBF" +
|
||||
"A11DABD6E6144BEF37C6800000000000000000000000000000000051 is prime," +
|
||||
" (dec) 10^143 + 3^4"
|
||||
)
|
||||
),
|
||||
(
|
||||
(
|
||||
"76bb3470985174915e9993522aec989666908f9e8cf5cb9f037bf4aee33d8865c" +
|
||||
"b6464174795d07e30015b80000000000000000000000000000000"
|
||||
), (
|
||||
"6aaaf60d5784dcef612d133613b179a317532ecca0eed40b8ad0c01e6d4a6d8c7" +
|
||||
"9a52af190abd51739009a900000000000000000000000000000000"
|
||||
), (
|
||||
"8335616AED761F1F7F44E6BD49E807B82E3BF2BF11BFA6AF813C808DBF33DBFA1" +
|
||||
"1DABD6E6144BEF37C6800000000000000000000000000000000051"
|
||||
), ""
|
||||
),
|
||||
(
|
||||
(
|
||||
"6cfdd6e60912e441d2d1fc88f421b533f0103a5322ccd3f4db84861643ad63fd6" +
|
||||
"3d1d8cfbc1d498162786ba00000000000000000000000000000000"
|
||||
), (
|
||||
"1177246ec5e93814816465e7f8f248b350d954439d35b2b5d75d917218e7fd5fb" +
|
||||
"4c2f6d0667f9467fdcf33400000000000000000000000000000000"
|
||||
), (
|
||||
"8335616AED761F1F7F44E6BD49E807B82E3BF2BF11BFA6AF813C808DBF33DBFA1" +
|
||||
"1DABD6E6144BEF37C6800000000000000000000000000000000051"
|
||||
), ""
|
||||
),
|
||||
(
|
||||
(
|
||||
"7a09a0b0f8bbf8057116fb0277a9bdf3a91b5eaa8830d448081510d8973888be5" +
|
||||
"a9f0ad04facb69aa3715f00000000000000000000000000000000"
|
||||
), (
|
||||
"764dec6c05a1c0d87b649efa5fd94c91ea28bffb4725d4ab4b33f1a3e8e3b314d" +
|
||||
"799020e244a835a145ec9800000000000000000000000000000000"
|
||||
), (
|
||||
"8335616AED761F1F7F44E6BD49E807B82E3BF2BF11BFA6AF813C808DBF33DBFA1" +
|
||||
"1DABD6E6144BEF37C6800000000000000000000000000000000051"
|
||||
), ""
|
||||
)
|
||||
] # type: List[Tuple[str, str, str, str]]
|
||||
|
||||
def __init__(
|
||||
self, val_a: str, val_b: str, val_n: str, case_description: str = ""
|
||||
):
|
||||
self.case_description = case_description
|
||||
self.arg_a = val_a
|
||||
self.int_a = bignum_common.hex_to_int(val_a)
|
||||
self.arg_b = val_b
|
||||
self.int_b = bignum_common.hex_to_int(val_b)
|
||||
self.arg_n = val_n
|
||||
self.int_n = bignum_common.hex_to_int(val_n)
|
||||
|
||||
limbs_a4 = bignum_common.limbs_mpi(self.int_a, 32)
|
||||
limbs_a8 = bignum_common.limbs_mpi(self.int_a, 64)
|
||||
self.limbs_b4 = bignum_common.limbs_mpi(self.int_b, 32)
|
||||
self.limbs_b8 = bignum_common.limbs_mpi(self.int_b, 64)
|
||||
self.limbs_an4 = bignum_common.limbs_mpi(self.int_n, 32)
|
||||
self.limbs_an8 = bignum_common.limbs_mpi(self.int_n, 64)
|
||||
|
||||
if limbs_a4 > self.limbs_an4 or limbs_a8 > self.limbs_an8:
|
||||
raise Exception("Limbs of input A ({}) exceeds N ({})".format(
|
||||
self.arg_a, self.arg_n
|
||||
))
|
||||
|
||||
def arguments(self) -> List[str]:
|
||||
return [
|
||||
str(self.limbs_an4), str(self.limbs_b4),
|
||||
str(self.limbs_an8), str(self.limbs_b8),
|
||||
bignum_common.quote_str(self.arg_a),
|
||||
bignum_common.quote_str(self.arg_b),
|
||||
bignum_common.quote_str(self.arg_n)
|
||||
] + self.result()
|
||||
|
||||
def description(self) -> str:
|
||||
if self.case_description != "replay":
|
||||
if not self.start_2_mpi4 and self.limbs_an4 > 1:
|
||||
tmp = "(start of 2-MPI 4-byte bignums) "
|
||||
self.__class__.start_2_mpi4 = True
|
||||
elif not self.start_2_mpi8 and self.limbs_an8 > 1:
|
||||
tmp = "(start of 2-MPI 8-byte bignums) "
|
||||
self.__class__.start_2_mpi8 = True
|
||||
else:
|
||||
tmp = "(gen) "
|
||||
self.case_description = tmp + self.case_description
|
||||
return super().description()
|
||||
|
||||
def result(self) -> List[str]:
|
||||
"""Get the result of the operation."""
|
||||
r4 = bignum_common.bound_mpi_limbs(self.limbs_an4, 32)
|
||||
i4 = bignum_common.invmod(r4, self.int_n)
|
||||
x4 = self.int_a * self.int_b * i4
|
||||
x4 = x4 % self.int_n
|
||||
|
||||
r8 = bignum_common.bound_mpi_limbs(self.limbs_an8, 64)
|
||||
i8 = bignum_common.invmod(r8, self.int_n)
|
||||
x8 = self.int_a * self.int_b * i8
|
||||
x8 = x8 % self.int_n
|
||||
return [
|
||||
"\"{:x}\"".format(x4),
|
||||
"\"{:x}\"".format(x8)
|
||||
]
|
||||
|
||||
def set_limbs(
|
||||
self, limbs_an4: int, limbs_b4: int, limbs_an8: int, limbs_b8: int
|
||||
) -> None:
|
||||
"""Set number of limbs for each input.
|
||||
|
||||
Replaces default values set during initialization.
|
||||
"""
|
||||
self.limbs_an4 = limbs_an4
|
||||
self.limbs_b4 = limbs_b4
|
||||
self.limbs_an8 = limbs_an8
|
||||
self.limbs_b8 = limbs_b8
|
||||
|
||||
@classmethod
|
||||
def generate_function_tests(cls) -> Iterator[test_case.TestCase]:
|
||||
"""Generate replay and randomly generated test cases."""
|
||||
# Test cases which replay captured invocations during unit test runs.
|
||||
for limbs_an4, limbs_b4, limbs_an8, limbs_b8, a, b, n in cls.replay_test_cases:
|
||||
cur_op = cls(a, b, n, case_description="replay")
|
||||
cur_op.set_limbs(limbs_an4, limbs_b4, limbs_an8, limbs_b8)
|
||||
yield cur_op.create_test_case()
|
||||
# Random test cases can be generated using mpi_modmul_case_generate()
|
||||
# Uses a mixture of primes and odd numbers as N, with four randomly
|
||||
# generated cases for each N.
|
||||
for a, b, n, description in cls.random_test_cases:
|
||||
cur_op = cls(a, b, n, case_description=description)
|
||||
yield cur_op.create_test_case()
|
||||
|
||||
|
||||
def mpi_modmul_case_generate() -> None:
|
||||
"""Generate valid inputs for montmul tests using moduli.
|
||||
|
||||
For each modulus, generates random values for A and B and simple descriptions
|
||||
for the test case.
|
||||
"""
|
||||
moduli = [
|
||||
("3", ""), ("7", ""), ("B", ""), ("29", ""), ("FF", ""),
|
||||
("101", ""), ("38B", ""), ("8003", ""), ("10001", ""),
|
||||
("7F7F7", ""), ("800009", ""), ("100002B", ""), ("37EEE9D", ""),
|
||||
("8000000B", ""), ("8CD626B9", ""), ("10000000F", ""),
|
||||
("174876E7E9", "is prime (dec) 99999999977"),
|
||||
("8000000017", ""), ("864CB9076D", ""), ("F7F7F7F7F7", ""),
|
||||
("1000000000F", ""), ("800000000005", ""), ("800795D9BA47", ""),
|
||||
("1000000000015", ""), ("100000000000051", ""), ("ABCDEF0123456789", ""),
|
||||
(
|
||||
"25A55A46E5DA99C71C7",
|
||||
"is the 3rd repunit prime (dec) 11111111111111111111111"
|
||||
),
|
||||
("314DC643FB763F2B8C0E2DE00879", "is (dec)99999999977^3"),
|
||||
("47BF19662275FA2F6845C74942ED1D852E521", "is (dec) 99999999977^4"),
|
||||
(
|
||||
"97EDD86E4B5C4592C6D32064AC55C888A7245F07CA3CC455E07C931",
|
||||
"is (dec) 99999999977^6"
|
||||
),
|
||||
(
|
||||
"DD15FE80B731872AC104DB37832F7E75A244AA2631BC87885B861E8F20375499",
|
||||
"is (dec) 99999999977^7"
|
||||
),
|
||||
(
|
||||
"141B8EBD9009F84C241879A1F680FACCED355DA36C498F73E96E880CF78EA5F96146380E41",
|
||||
"is (dec) 99999999977^8"
|
||||
),
|
||||
(
|
||||
(
|
||||
"2A94608DE88B6D5E9F8920F5ABB06B24CC35AE1FBACC87D075C621C3E283" +
|
||||
"3EC902713E40F51E3B3C214EDFABC451"
|
||||
),
|
||||
"is (dec) 99999999977^10"
|
||||
),
|
||||
(
|
||||
"8335616AED761F1F7F44E6BD49E807B82E3BF2BF11BFA6AF813C808DBF33DBFA11" +
|
||||
"DABD6E6144BEF37C6800000000000000000000000000000000051",
|
||||
"is prime, (dec) 10^143 + 3^4"
|
||||
)
|
||||
] # type: List[Tuple[str, str]]
|
||||
primes = [
|
||||
"3", "7", "B", "29", "101", "38B", "8003", "10001", "800009",
|
||||
"100002B", "37EEE9D", "8000000B", "8CD626B9",
|
||||
# From here they require > 1 4-byte MPI
|
||||
"10000000F", "174876E7E9", "8000000017", "864CB9076D", "1000000000F",
|
||||
"800000000005", "800795D9BA47", "1000000000015", "100000000000051",
|
||||
# From here they require > 1 8-byte MPI
|
||||
"25A55A46E5DA99C71C7", # this is 11111111111111111111111 decimal
|
||||
# 10^143 + 3^4: (which is prime)
|
||||
# 100000000000000000000000000000000000000000000000000000000000000000000000000000
|
||||
# 000000000000000000000000000000000000000000000000000000000000000081
|
||||
(
|
||||
"8335616AED761F1F7F44E6BD49E807B82E3BF2BF11BFA6AF813C808DBF33DBFA11" +
|
||||
"DABD6E6144BEF37C6800000000000000000000000000000000051"
|
||||
)
|
||||
] # type: List[str]
|
||||
generated_inputs = []
|
||||
for mod, description in moduli:
|
||||
n = bignum_common.hex_to_int(mod)
|
||||
mod_read = "{:x}".format(n)
|
||||
case_count = 3 if n < 5 else 4
|
||||
cases = {} # type: Dict[int, int]
|
||||
i = 0
|
||||
while i < case_count:
|
||||
a = random.randint(1, n)
|
||||
b = random.randint(1, n)
|
||||
if cases.get(a) == b:
|
||||
continue
|
||||
cases[a] = b
|
||||
if description:
|
||||
out_description = "0x{} {}".format(mod_read, description)
|
||||
elif i == 0 and len(mod) > 1 and mod in primes:
|
||||
out_description = "(0x{} is prime)"
|
||||
else:
|
||||
out_description = ""
|
||||
generated_inputs.append(
|
||||
("{:x}".format(a), "{:x}".format(b), mod, out_description)
|
||||
)
|
||||
i += 1
|
||||
print(generated_inputs)
|
||||
|
||||
|
||||
class BignumCoreExpMod(BignumCoreTarget, bignum_common.ModOperationCommon):
|
||||
"""Test cases for bignum core exponentiation."""
|
||||
symbol = "^"
|
||||
test_function = "mpi_core_exp_mod"
|
||||
test_name = "Core modular exponentiation (Mongtomery form only)"
|
||||
input_style = "fixed"
|
||||
montgomery_form_a = True
|
||||
|
||||
def result(self) -> List[str]:
|
||||
# Result has to be given in Montgomery form too
|
||||
result = pow(self.int_a, self.int_b, self.int_n)
|
||||
mont_result = self.to_montgomery(result)
|
||||
return [self.format_result(mont_result)]
|
||||
|
||||
@property
|
||||
def is_valid(self) -> bool:
|
||||
# The base needs to be canonical, but the exponent can be larger than
|
||||
# the modulus (see for example exponent blinding)
|
||||
return bool(self.int_a < self.int_n)
|
||||
|
||||
|
||||
class BignumCoreSubInt(BignumCoreTarget, bignum_common.OperationCommon):
|
||||
"""Test cases for bignum core sub int."""
|
||||
count = 0
|
||||
symbol = "-"
|
||||
test_function = "mpi_core_sub_int"
|
||||
test_name = "mpi_core_sub_int"
|
||||
input_style = "arch_split"
|
||||
|
||||
@property
|
||||
def is_valid(self) -> bool:
|
||||
# This is "sub int", so b is only one limb
|
||||
if bignum_common.limbs_mpi(self.int_b, self.bits_in_limb) > 1:
|
||||
return False
|
||||
return True
|
||||
|
||||
# Overriding because we don't want leading zeros on b
|
||||
@property
|
||||
def arg_b(self) -> str:
|
||||
return self.val_b
|
||||
|
||||
def result(self) -> List[str]:
|
||||
result = self.int_a - self.int_b
|
||||
|
||||
borrow, result = divmod(result, self.limb_boundary)
|
||||
|
||||
# Borrow will be -1 if non-zero, but we want it to be 1 in the test data
|
||||
return [
|
||||
self.format_result(result),
|
||||
str(-borrow)
|
||||
]
|
||||
|
||||
class BignumCoreZeroCheckCT(BignumCoreTarget, bignum_common.OperationCommon):
|
||||
"""Test cases for bignum core zero check (constant flow)."""
|
||||
count = 0
|
||||
symbol = "== 0"
|
||||
test_function = "mpi_core_check_zero_ct"
|
||||
test_name = "mpi_core_check_zero_ct"
|
||||
input_style = "variable"
|
||||
arity = 1
|
||||
suffix = True
|
||||
|
||||
def result(self) -> List[str]:
|
||||
result = 1 if self.int_a == 0 else 0
|
||||
return [str(result)]
|
||||
|
||||
class BignumCoreGcdModinvOdd(BignumCoreTarget, test_data_generation.BaseTest):
|
||||
"""Test cases for bignum core GCD+modinv (odd modulus)"""
|
||||
|
||||
test_function = "mpi_core_gcd_modinv_odd"
|
||||
test_name = "mpi_core_gcd_modinv_odd"
|
||||
|
||||
# - All small integers because that naturally covers a lot of cases.
|
||||
# - (Close to) powers of 2 because that looks like interesting values.
|
||||
# Also covers the cases where N, N+1 or N-1 is a multiple of A (with
|
||||
# multiple limbs).
|
||||
# - X * 2, X * 3 is so that we get GCD(X*2, X*3) = X where the GCD has a
|
||||
# the same order of magnitude as the inputs.
|
||||
# - Random values of cryptographic size for good measure.
|
||||
DATA = (
|
||||
("0", 0),
|
||||
("1", 1),
|
||||
("2", 2),
|
||||
("3", 3),
|
||||
("4", 4),
|
||||
("5", 5),
|
||||
("6", 6),
|
||||
("7", 7),
|
||||
("2^64 - 1", 2**64 - 1),
|
||||
("2^64", 2**64),
|
||||
("2^64 + 1", 2**64 + 1),
|
||||
("2^128 - 1", 2**128 - 1),
|
||||
("2^128", 2**128),
|
||||
("2^128 + 1", 2**128 + 1),
|
||||
("prime192[1]", int(bignum_data.SAFE_PRIME_192_BIT_SEED_1, 16)),
|
||||
("prime192[1] * 2", int(bignum_data.SAFE_PRIME_192_BIT_SEED_1, 16) * 2),
|
||||
("prime192[1] * 3", int(bignum_data.SAFE_PRIME_192_BIT_SEED_1, 16) * 3),
|
||||
("rand192[2.1]", int(bignum_data.RANDOM_192_BIT_SEED_2_NO1, 16)),
|
||||
("rand192[2.2]", int(bignum_data.RANDOM_192_BIT_SEED_2_NO2, 16)),
|
||||
("rand192[2.3]", int(bignum_data.RANDOM_192_BIT_SEED_2_NO3, 16)),
|
||||
("rand192[2.4]", int(bignum_data.RANDOM_192_BIT_SEED_2_NO4, 16)),
|
||||
("rand192[2.9]", int(bignum_data.RANDOM_192_BIT_SEED_2_NO9, 16)),
|
||||
("prime1024[3]", int(bignum_data.SAFE_PRIME_1024_BIT_SEED_3, 16)),
|
||||
("rand1024[4.1]", int(bignum_data.RANDOM_1024_BIT_SEED_4_NO1, 16)),
|
||||
("rand1024[4.2]", int(bignum_data.RANDOM_1024_BIT_SEED_4_NO2, 16)),
|
||||
("rand1024[4.3]", int(bignum_data.RANDOM_1024_BIT_SEED_4_NO3, 16)),
|
||||
("rand1024[4.4]", int(bignum_data.RANDOM_1024_BIT_SEED_4_NO4, 16)),
|
||||
("rand1024[4.5]", int(bignum_data.RANDOM_1024_BIT_SEED_4_NO5, 16)),
|
||||
("rand1024[4.5] * 2", int(bignum_data.RANDOM_1024_BIT_SEED_4_NO5, 16) * 2),
|
||||
("rand1024[4.5] * 3", int(bignum_data.RANDOM_1024_BIT_SEED_4_NO5, 16) * 3),
|
||||
)
|
||||
|
||||
def __init__(self, a: int, a_desc: str, n: int, n_desc: str) -> None:
|
||||
self.a_val = a
|
||||
self.a_desc = a_desc
|
||||
self.n_val = n
|
||||
self.n_desc = n_desc
|
||||
self.g_val = math.gcd(a, n)
|
||||
test_i = self.g_val == 1 and self.n_val != 1
|
||||
self.i_val = bignum_common.invmod_positive(a, n) if test_i else None
|
||||
|
||||
def arguments(self) -> List[str]:
|
||||
a_str = f"{self.a_val:x}"
|
||||
n_str = f"{self.n_val:x}"
|
||||
g_str = f"{self.g_val:x}"
|
||||
i_str = f"{self.i_val:x}" if self.i_val is not None else ""
|
||||
return [bignum_common.quote_str(s) for s in (a_str, n_str, g_str, i_str)]
|
||||
|
||||
def description(self) -> str:
|
||||
return f"GCD-modinv, A = {self.a_desc}, N = {self.n_desc}"
|
||||
|
||||
@classmethod
|
||||
def generate_function_tests(cls) -> Iterator[test_case.TestCase]:
|
||||
for n_desc, n in cls.DATA:
|
||||
if n % 2 == 0:
|
||||
continue
|
||||
for a_desc, a in cls.DATA:
|
||||
if a > n:
|
||||
continue
|
||||
yield cls(a, a_desc, n, n_desc).create_test_case()
|
||||
159
vendor/mbedtls/framework/scripts/mbedtls_framework/bignum_data.py
vendored
Normal file
159
vendor/mbedtls/framework/scripts/mbedtls_framework/bignum_data.py
vendored
Normal file
@@ -0,0 +1,159 @@
|
||||
"""Base values and datasets for bignum generated tests and helper functions that
|
||||
produced them."""
|
||||
# Copyright The Mbed TLS Contributors
|
||||
# SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
#
|
||||
|
||||
import random
|
||||
|
||||
# Functions calling these were used to produce test data and are here only for
|
||||
# reproducibility, they are not used by the test generation framework/classes
|
||||
try:
|
||||
from Cryptodome.Util.number import isPrime, getPrime #type: ignore #pylint: disable=import-error
|
||||
except ImportError:
|
||||
pass
|
||||
|
||||
# Generated by bignum_common.gen_safe_prime(192,1)
|
||||
SAFE_PRIME_192_BIT_SEED_1 = "d1c127a667786703830500038ebaef20e5a3e2dc378fb75b"
|
||||
|
||||
# First number generated by random.getrandbits(192) - seed(2,2), not a prime
|
||||
RANDOM_192_BIT_SEED_2_NO1 = "177219d30e7a269fd95bafc8f2a4d27bdcf4bb99f4bea973"
|
||||
|
||||
# Second number generated by random.getrandbits(192) - seed(2,2), not a prime
|
||||
RANDOM_192_BIT_SEED_2_NO2 = "cf1822ffbc6887782b491044d5e341245c6e433715ba2bdd"
|
||||
|
||||
# Third number generated by random.getrandbits(192) - seed(2,2), not a prime
|
||||
RANDOM_192_BIT_SEED_2_NO3 = "3653f8dd9b1f282e4067c3584ee207f8da94e3e8ab73738f"
|
||||
|
||||
# Fourth number generated by random.getrandbits(192) - seed(2,2), not a prime
|
||||
RANDOM_192_BIT_SEED_2_NO4 = "ffed9235288bc781ae66267594c9c9500925e4749b575bd1"
|
||||
|
||||
# Ninth number generated by random.getrandbits(192) - seed(2,2), not a prime
|
||||
RANDOM_192_BIT_SEED_2_NO9 = "2a1be9cd8697bbd0e2520e33e44c50556c71c4a66148a86f"
|
||||
|
||||
# Generated by bignum_common.gen_safe_prime(1024,3)
|
||||
SAFE_PRIME_1024_BIT_SEED_3 = ("c93ba7ec74d96f411ba008bdb78e63ff11bb5df46a51e16b"
|
||||
"2c9d156f8e4e18abf5e052cb01f47d0d1925a77f60991577"
|
||||
"e128fb6f52f34a27950a594baadd3d8057abeb222cf3cca9"
|
||||
"62db16abf79f2ada5bd29ab2f51244bf295eff9f6aaba130"
|
||||
"2efc449b128be75eeaca04bc3c1a155d11d14e8be32a2c82"
|
||||
"87b3996cf6ad5223")
|
||||
|
||||
# First number generated by random.getrandbits(1024) - seed(4,2), not a prime
|
||||
RANDOM_1024_BIT_SEED_4_NO1 = ("6905269ed6f0b09f165c8ce36e2f24b43000de01b2ed40ed"
|
||||
"3addccb2c33be0ac79d679346d4ac7a5c3902b38963dc6e8"
|
||||
"534f45738d048ec0f1099c6c3e1b258fd724452ccea71ff4"
|
||||
"a14876aeaff1a098ca5996666ceab360512bd13110722311"
|
||||
"710cf5327ac435a7a97c643656412a9b8a1abcd1a6916c74"
|
||||
"da4f9fc3c6da5d7")
|
||||
|
||||
# Second number generated by random.getrandbits(1024) - seed(4,2), not a prime
|
||||
RANDOM_1024_BIT_SEED_4_NO2 = ("f1cfd99216df648647adec26793d0e453f5082492d83a823"
|
||||
"3fb62d2c81862fc9634f806fabf4a07c566002249b191bf4"
|
||||
"d8441b5616332aca5f552773e14b0190d93936e1daca3c06"
|
||||
"f5ff0c03bb5d7385de08caa1a08179104a25e4664f5253a0"
|
||||
"2a3187853184ff27459142deccea264542a00403ce80c4b0"
|
||||
"a4042bb3d4341aad")
|
||||
|
||||
# Third number generated by random.getrandbits(1024) - seed(4,2), not a prime
|
||||
RANDOM_1024_BIT_SEED_4_NO3 = ("14c15c910b11ad28cc21ce88d0060cc54278c2614e1bcb38"
|
||||
"3bb4a570294c4ea3738d243a6e58d5ca49c7b59b995253fd"
|
||||
"6c79a3de69f85e3131f3b9238224b122c3e4a892d9196ada"
|
||||
"4fcfa583e1df8af9b474c7e89286a1754abcb06ae8abb93f"
|
||||
"01d89a024cdce7a6d7288ff68c320f89f1347e0cdd905ecf"
|
||||
"d160c5d0ef412ed6")
|
||||
|
||||
# Fourth number generated by random.getrandbits(1024) - seed(4,2), not a prime
|
||||
RANDOM_1024_BIT_SEED_4_NO4 = ("32decd6b8efbc170a26a25c852175b7a96b98b5fbf37a2be"
|
||||
"6f98bca35b17b9662f0733c846bbe9e870ef55b1a1f65507"
|
||||
"a2909cb633e238b4e9dd38b869ace91311021c9e32111ac1"
|
||||
"ac7cc4a4ff4dab102522d53857c49391b36cc9aa78a330a1"
|
||||
"a5e333cb88dcf94384d4cd1f47ca7883ff5a52f1a05885ac"
|
||||
"7671863c0bdbc23a")
|
||||
|
||||
# Fifth number generated by random.getrandbits(1024) - seed(4,2), not a prime
|
||||
RANDOM_1024_BIT_SEED_4_NO5 = ("53be4721f5b9e1f5acdac615bc20f6264922b9ccf469aef8"
|
||||
"f6e7d078e55b85dd1525f363b281b8885b69dc230af5ac87"
|
||||
"0692b534758240df4a7a03052d733dcdef40af2e54c0ce68"
|
||||
"1f44ebd13cc75f3edcb285f89d8cf4d4950b16ffc3e1ac3b"
|
||||
"4708d9893a973000b54a23020fc5b043d6e4a51519d9c9cc"
|
||||
"52d32377e78131c1")
|
||||
|
||||
# Adding 192 bit and 1024 bit numbers because these are the shortest required
|
||||
# for ECC and RSA respectively.
|
||||
INPUTS_DEFAULT = [
|
||||
"0", "1", # corner cases
|
||||
"2", "3", # small primes
|
||||
"4", # non-prime even
|
||||
"38", # small random
|
||||
SAFE_PRIME_192_BIT_SEED_1, # prime
|
||||
RANDOM_192_BIT_SEED_2_NO1, # not a prime
|
||||
RANDOM_192_BIT_SEED_2_NO2, # not a prime
|
||||
SAFE_PRIME_1024_BIT_SEED_3, # prime
|
||||
RANDOM_1024_BIT_SEED_4_NO1, # not a prime
|
||||
RANDOM_1024_BIT_SEED_4_NO3, # not a prime
|
||||
RANDOM_1024_BIT_SEED_4_NO2, # largest (not a prime)
|
||||
]
|
||||
|
||||
ADD_SUB_DATA = [
|
||||
"0", "1", "3", "f", "fe", "ff", "100", "ff00",
|
||||
"fffe", "ffff", "10000", # 2^16 - 1, 2^16, 2^16 + 1
|
||||
"fffffffe", "ffffffff", "100000000", # 2^32 - 1, 2^32, 2^32 + 1
|
||||
"1f7f7f7f7f7f7f",
|
||||
"8000000000000000", "fefefefefefefefe",
|
||||
"fffffffffffffffe", "ffffffffffffffff", "10000000000000000", # 2^64 - 1, 2^64, 2^64 + 1
|
||||
"1234567890abcdef0",
|
||||
"fffffffffffffffffffffffe",
|
||||
"ffffffffffffffffffffffff",
|
||||
"1000000000000000000000000",
|
||||
"fffffffffffffffffefefefefefefefe",
|
||||
"fffffffffffffffffffffffffffffffe",
|
||||
"ffffffffffffffffffffffffffffffff",
|
||||
"100000000000000000000000000000000",
|
||||
"1234567890abcdef01234567890abcdef0",
|
||||
"fffffffffffffffffffffffffffffffffffffffffffffffffefefefefefefefe",
|
||||
"fffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffe",
|
||||
"ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff",
|
||||
"10000000000000000000000000000000000000000000000000000000000000000",
|
||||
"1234567890abcdef01234567890abcdef01234567890abcdef01234567890abcdef0",
|
||||
]
|
||||
|
||||
# Only odd moduli are present as in the new bignum code only odd moduli are
|
||||
# supported for now.
|
||||
MODULI_DEFAULT = [
|
||||
"53", # safe prime
|
||||
"45", # non-prime
|
||||
SAFE_PRIME_192_BIT_SEED_1, # safe prime
|
||||
RANDOM_192_BIT_SEED_2_NO4, # not a prime
|
||||
SAFE_PRIME_1024_BIT_SEED_3, # safe prime
|
||||
RANDOM_1024_BIT_SEED_4_NO5, # not a prime
|
||||
]
|
||||
|
||||
# Some functions, e.g. mbedtls_mpi_mod_raw_inv_prime(), only support prime moduli.
|
||||
ONLY_PRIME_MODULI = [
|
||||
"53", # safe prime
|
||||
"8ac72304057392b5", # 9999999997777777333 (longer, not safe, prime)
|
||||
# The next prime has a different R in Montgomery form depending on
|
||||
# whether 32- or 64-bit MPIs are used.
|
||||
"152d02c7e14af67fe0bf", # 99999999999999999991999
|
||||
SAFE_PRIME_192_BIT_SEED_1, # safe prime
|
||||
SAFE_PRIME_1024_BIT_SEED_3, # safe prime
|
||||
]
|
||||
|
||||
def __gen_safe_prime(bits, seed):
|
||||
'''
|
||||
Generate a safe prime.
|
||||
|
||||
This function is intended for generating constants offline and shouldn't be
|
||||
used in test generation classes.
|
||||
|
||||
Requires pycryptodomex for getPrime and isPrime and python 3.9 or later for
|
||||
randbytes.
|
||||
'''
|
||||
rng = random.Random()
|
||||
# We want reproducibility across python versions
|
||||
rng.seed(seed, version=2)
|
||||
while True:
|
||||
prime = 2*getPrime(bits-1, rng.randbytes)+1 #pylint: disable=no-member
|
||||
if isPrime(prime, 1e-30):
|
||||
return prime
|
||||
102
vendor/mbedtls/framework/scripts/mbedtls_framework/bignum_mod.py
vendored
Normal file
102
vendor/mbedtls/framework/scripts/mbedtls_framework/bignum_mod.py
vendored
Normal file
@@ -0,0 +1,102 @@
|
||||
"""Framework classes for generation of bignum mod test cases."""
|
||||
# Copyright The Mbed TLS Contributors
|
||||
# SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
#
|
||||
|
||||
from typing import List
|
||||
|
||||
from . import test_data_generation
|
||||
from . import bignum_common
|
||||
from .bignum_data import ONLY_PRIME_MODULI
|
||||
|
||||
class BignumModTarget(test_data_generation.BaseTarget):
|
||||
#pylint: disable=abstract-method, too-few-public-methods
|
||||
"""Target for bignum mod test case generation."""
|
||||
target_basename = 'test_suite_bignum_mod.generated'
|
||||
|
||||
|
||||
class BignumModMul(bignum_common.ModOperationCommon,
|
||||
BignumModTarget):
|
||||
# pylint:disable=duplicate-code
|
||||
"""Test cases for bignum mpi_mod_mul()."""
|
||||
symbol = "*"
|
||||
test_function = "mpi_mod_mul"
|
||||
test_name = "mbedtls_mpi_mod_mul"
|
||||
input_style = "arch_split"
|
||||
arity = 2
|
||||
|
||||
def arguments(self) -> List[str]:
|
||||
return [self.format_result(self.to_montgomery(self.int_a)),
|
||||
self.format_result(self.to_montgomery(self.int_b)),
|
||||
bignum_common.quote_str(self.arg_n)
|
||||
] + self.result()
|
||||
|
||||
def result(self) -> List[str]:
|
||||
result = (self.int_a * self.int_b) % self.int_n
|
||||
return [self.format_result(self.to_montgomery(result))]
|
||||
|
||||
|
||||
class BignumModSub(bignum_common.ModOperationCommon, BignumModTarget):
|
||||
"""Test cases for bignum mpi_mod_sub()."""
|
||||
symbol = "-"
|
||||
test_function = "mpi_mod_sub"
|
||||
test_name = "mbedtls_mpi_mod_sub"
|
||||
input_style = "fixed"
|
||||
arity = 2
|
||||
|
||||
def result(self) -> List[str]:
|
||||
result = (self.int_a - self.int_b) % self.int_n
|
||||
# To make negative tests easier, append 0 for success to the
|
||||
# generated cases
|
||||
return [self.format_result(result), "0"]
|
||||
|
||||
class BignumModInvNonMont(bignum_common.ModOperationCommon, BignumModTarget):
|
||||
"""Test cases for bignum mpi_mod_inv() - not in Montgomery form."""
|
||||
moduli = ONLY_PRIME_MODULI # for now only prime moduli supported
|
||||
symbol = "^ -1"
|
||||
test_function = "mpi_mod_inv_non_mont"
|
||||
test_name = "mbedtls_mpi_mod_inv non-Mont. form"
|
||||
input_style = "fixed"
|
||||
arity = 1
|
||||
suffix = True
|
||||
disallow_zero_a = True
|
||||
|
||||
def result(self) -> List[str]:
|
||||
result = bignum_common.invmod_positive(self.int_a, self.int_n)
|
||||
# To make negative tests easier, append 0 for success to the
|
||||
# generated cases
|
||||
return [self.format_result(result), "0"]
|
||||
|
||||
class BignumModInvMont(bignum_common.ModOperationCommon, BignumModTarget):
|
||||
"""Test cases for bignum mpi_mod_inv() - Montgomery form."""
|
||||
moduli = ONLY_PRIME_MODULI # for now only prime moduli supported
|
||||
symbol = "^ -1"
|
||||
test_function = "mpi_mod_inv_mont"
|
||||
test_name = "mbedtls_mpi_mod_inv Mont. form"
|
||||
input_style = "arch_split" # Mont. form requires arch_split
|
||||
arity = 1
|
||||
suffix = True
|
||||
disallow_zero_a = True
|
||||
montgomery_form_a = True
|
||||
|
||||
def result(self) -> List[str]:
|
||||
result = bignum_common.invmod_positive(self.int_a, self.int_n)
|
||||
mont_result = self.to_montgomery(result)
|
||||
# To make negative tests easier, append 0 for success to the
|
||||
# generated cases
|
||||
return [self.format_result(mont_result), "0"]
|
||||
|
||||
|
||||
class BignumModAdd(bignum_common.ModOperationCommon, BignumModTarget):
|
||||
"""Test cases for bignum mpi_mod_add()."""
|
||||
count = 0
|
||||
symbol = "+"
|
||||
test_function = "mpi_mod_add"
|
||||
test_name = "mbedtls_mpi_mod_add"
|
||||
input_style = "fixed"
|
||||
|
||||
def result(self) -> List[str]:
|
||||
result = (self.int_a + self.int_b) % self.int_n
|
||||
# To make negative tests easier, append "0" for success to the
|
||||
# generated cases
|
||||
return [self.format_result(result), "0"]
|
||||
242
vendor/mbedtls/framework/scripts/mbedtls_framework/bignum_mod_raw.py
vendored
Normal file
242
vendor/mbedtls/framework/scripts/mbedtls_framework/bignum_mod_raw.py
vendored
Normal file
@@ -0,0 +1,242 @@
|
||||
"""Framework classes for generation of bignum mod_raw test cases."""
|
||||
# Copyright The Mbed TLS Contributors
|
||||
# SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
#
|
||||
|
||||
from typing import Iterator, List
|
||||
|
||||
from . import test_case
|
||||
from . import test_data_generation
|
||||
from . import bignum_common
|
||||
from .bignum_data import ONLY_PRIME_MODULI
|
||||
|
||||
class BignumModRawTarget(test_data_generation.BaseTarget):
|
||||
#pylint: disable=abstract-method, too-few-public-methods
|
||||
"""Target for bignum mod_raw test case generation."""
|
||||
target_basename = 'test_suite_bignum_mod_raw.generated'
|
||||
|
||||
|
||||
class BignumModRawSub(bignum_common.ModOperationCommon,
|
||||
BignumModRawTarget):
|
||||
"""Test cases for bignum mpi_mod_raw_sub()."""
|
||||
symbol = "-"
|
||||
test_function = "mpi_mod_raw_sub"
|
||||
test_name = "mbedtls_mpi_mod_raw_sub"
|
||||
input_style = "fixed"
|
||||
arity = 2
|
||||
|
||||
def arguments(self) -> List[str]:
|
||||
return [bignum_common.quote_str(n) for n in [self.arg_a,
|
||||
self.arg_b,
|
||||
self.arg_n]
|
||||
] + self.result()
|
||||
|
||||
def result(self) -> List[str]:
|
||||
result = (self.int_a - self.int_b) % self.int_n
|
||||
return [self.format_result(result)]
|
||||
|
||||
class BignumModRawFixQuasiReduction(bignum_common.ModOperationCommon,
|
||||
BignumModRawTarget):
|
||||
"""Test cases for ecp quasi_reduction()."""
|
||||
symbol = "-"
|
||||
test_function = "mpi_mod_raw_fix_quasi_reduction"
|
||||
test_name = "fix_quasi_reduction"
|
||||
input_style = "fixed"
|
||||
arity = 1
|
||||
|
||||
# Extend the default values with n < x < 2n
|
||||
input_values = bignum_common.ModOperationCommon.input_values + [
|
||||
"73",
|
||||
|
||||
# First number generated by random.getrandbits(1024) - seed(3,2)
|
||||
"ea7b5bf55eb561a4216363698b529b4a97b750923ceb3ffd",
|
||||
|
||||
# First number generated by random.getrandbits(1024) - seed(1,2)
|
||||
("cd447e35b8b6d8fe442e3d437204e52db2221a58008a05a6c4647159c324c985" +
|
||||
"9b810e766ec9d28663ca828dd5f4b3b2e4b06ce60741c7a87ce42c8218072e8c" +
|
||||
"35bf992dc9e9c616612e7696a6cecc1b78e510617311d8a3c2ce6f447ed4d57b" +
|
||||
"1e2feb89414c343c1027c4d1c386bbc4cd613e30d8f16adf91b7584a2265b1f5")
|
||||
] # type: List[str]
|
||||
|
||||
def result(self) -> List[str]:
|
||||
result = self.int_a % self.int_n
|
||||
return [self.format_result(result)]
|
||||
|
||||
@property
|
||||
def is_valid(self) -> bool:
|
||||
return bool(self.int_a < 2 * self.int_n)
|
||||
|
||||
class BignumModRawMul(bignum_common.ModOperationCommon,
|
||||
BignumModRawTarget):
|
||||
"""Test cases for bignum mpi_mod_raw_mul()."""
|
||||
symbol = "*"
|
||||
test_function = "mpi_mod_raw_mul"
|
||||
test_name = "mbedtls_mpi_mod_raw_mul"
|
||||
input_style = "arch_split"
|
||||
arity = 2
|
||||
|
||||
def arguments(self) -> List[str]:
|
||||
return [self.format_result(self.to_montgomery(self.int_a)),
|
||||
self.format_result(self.to_montgomery(self.int_b)),
|
||||
bignum_common.quote_str(self.arg_n)
|
||||
] + self.result()
|
||||
|
||||
def result(self) -> List[str]:
|
||||
result = (self.int_a * self.int_b) % self.int_n
|
||||
return [self.format_result(self.to_montgomery(result))]
|
||||
|
||||
|
||||
class BignumModRawInvPrime(bignum_common.ModOperationCommon,
|
||||
BignumModRawTarget):
|
||||
"""Test cases for bignum mpi_mod_raw_inv_prime()."""
|
||||
moduli = ONLY_PRIME_MODULI
|
||||
symbol = "^ -1"
|
||||
test_function = "mpi_mod_raw_inv_prime"
|
||||
test_name = "mbedtls_mpi_mod_raw_inv_prime (Montgomery form only)"
|
||||
input_style = "arch_split"
|
||||
arity = 1
|
||||
suffix = True
|
||||
montgomery_form_a = True
|
||||
disallow_zero_a = True
|
||||
|
||||
def result(self) -> List[str]:
|
||||
result = bignum_common.invmod_positive(self.int_a, self.int_n)
|
||||
mont_result = self.to_montgomery(result)
|
||||
return [self.format_result(mont_result)]
|
||||
|
||||
|
||||
class BignumModRawAdd(bignum_common.ModOperationCommon,
|
||||
BignumModRawTarget):
|
||||
"""Test cases for bignum mpi_mod_raw_add()."""
|
||||
symbol = "+"
|
||||
test_function = "mpi_mod_raw_add"
|
||||
test_name = "mbedtls_mpi_mod_raw_add"
|
||||
input_style = "fixed"
|
||||
arity = 2
|
||||
|
||||
def result(self) -> List[str]:
|
||||
result = (self.int_a + self.int_b) % self.int_n
|
||||
return [self.format_result(result)]
|
||||
|
||||
|
||||
class BignumModRawConvertRep(bignum_common.ModOperationCommon,
|
||||
BignumModRawTarget):
|
||||
# This is an abstract class, it's ok to have unimplemented methods.
|
||||
#pylint: disable=abstract-method
|
||||
"""Test cases for representation conversion."""
|
||||
symbol = ""
|
||||
input_style = "arch_split"
|
||||
arity = 1
|
||||
rep = bignum_common.ModulusRepresentation.INVALID
|
||||
|
||||
def set_representation(self, r: bignum_common.ModulusRepresentation) -> None:
|
||||
self.rep = r
|
||||
|
||||
def arguments(self) -> List[str]:
|
||||
return ([bignum_common.quote_str(self.arg_n), self.rep.symbol(),
|
||||
bignum_common.quote_str(self.arg_a)] +
|
||||
self.result())
|
||||
|
||||
def description(self) -> str:
|
||||
base = super().description()
|
||||
mod_with_rep = 'mod({})'.format(self.rep.name)
|
||||
return base.replace('mod', mod_with_rep, 1)
|
||||
|
||||
@classmethod
|
||||
def test_cases_for_values(cls, rep: bignum_common.ModulusRepresentation,
|
||||
n: str, a: str) -> Iterator[test_case.TestCase]:
|
||||
"""Emit test cases for the given values (if any).
|
||||
|
||||
This may emit no test cases if a isn't valid for the modulus n,
|
||||
or multiple test cases if rep requires different data depending
|
||||
on the limb size.
|
||||
"""
|
||||
for bil in cls.limb_sizes:
|
||||
test_object = cls(n, a, bits_in_limb=bil)
|
||||
test_object.set_representation(rep)
|
||||
# The class is set to having separate test cases for each limb
|
||||
# size, because the Montgomery representation requires it.
|
||||
# But other representations don't require it. So for other
|
||||
# representations, emit a single test case with no dependency
|
||||
# on the limb size.
|
||||
if rep is not bignum_common.ModulusRepresentation.MONTGOMERY:
|
||||
test_object.dependencies = \
|
||||
[dep for dep in test_object.dependencies
|
||||
if not dep.startswith('MBEDTLS_HAVE_INT')]
|
||||
if test_object.is_valid:
|
||||
yield test_object.create_test_case()
|
||||
if rep is not bignum_common.ModulusRepresentation.MONTGOMERY:
|
||||
# A single test case (emitted, or skipped due to invalidity)
|
||||
# is enough, since this test case doesn't depend on the
|
||||
# limb size.
|
||||
break
|
||||
|
||||
# The parent class doesn't support non-bignum parameters. So we override
|
||||
# test generation, in order to have the representation as a parameter.
|
||||
@classmethod
|
||||
def generate_function_tests(cls) -> Iterator[test_case.TestCase]:
|
||||
|
||||
for rep in bignum_common.ModulusRepresentation.supported_representations():
|
||||
for n in cls.moduli:
|
||||
for a in cls.input_values:
|
||||
yield from cls.test_cases_for_values(rep, n, a)
|
||||
|
||||
class BignumModRawCanonicalToModulusRep(BignumModRawConvertRep):
|
||||
"""Test cases for mpi_mod_raw_canonical_to_modulus_rep."""
|
||||
test_function = "mpi_mod_raw_canonical_to_modulus_rep"
|
||||
test_name = "Rep canon->mod"
|
||||
|
||||
def result(self) -> List[str]:
|
||||
return [self.format_result(self.convert_from_canonical(self.int_a, self.rep))]
|
||||
|
||||
class BignumModRawModulusToCanonicalRep(BignumModRawConvertRep):
|
||||
"""Test cases for mpi_mod_raw_modulus_to_canonical_rep."""
|
||||
test_function = "mpi_mod_raw_modulus_to_canonical_rep"
|
||||
test_name = "Rep mod->canon"
|
||||
|
||||
@property
|
||||
def arg_a(self) -> str:
|
||||
return self.format_arg("{:x}".format(self.convert_from_canonical(self.int_a, self.rep)))
|
||||
|
||||
def result(self) -> List[str]:
|
||||
return [self.format_result(self.int_a)]
|
||||
|
||||
|
||||
class BignumModRawConvertToMont(bignum_common.ModOperationCommon,
|
||||
BignumModRawTarget):
|
||||
""" Test cases for mpi_mod_raw_to_mont_rep(). """
|
||||
test_function = "mpi_mod_raw_to_mont_rep"
|
||||
test_name = "Convert into Mont: "
|
||||
symbol = "R *"
|
||||
input_style = "arch_split"
|
||||
arity = 1
|
||||
|
||||
def result(self) -> List[str]:
|
||||
result = self.to_montgomery(self.int_a)
|
||||
return [self.format_result(result)]
|
||||
|
||||
class BignumModRawConvertFromMont(bignum_common.ModOperationCommon,
|
||||
BignumModRawTarget):
|
||||
""" Test cases for mpi_mod_raw_from_mont_rep(). """
|
||||
test_function = "mpi_mod_raw_from_mont_rep"
|
||||
test_name = "Convert from Mont: "
|
||||
symbol = "1/R *"
|
||||
input_style = "arch_split"
|
||||
arity = 1
|
||||
|
||||
def result(self) -> List[str]:
|
||||
result = self.from_montgomery(self.int_a)
|
||||
return [self.format_result(result)]
|
||||
|
||||
class BignumModRawModNegate(bignum_common.ModOperationCommon,
|
||||
BignumModRawTarget):
|
||||
""" Test cases for mpi_mod_raw_neg(). """
|
||||
test_function = "mpi_mod_raw_neg"
|
||||
test_name = "Modular negation: "
|
||||
symbol = "-"
|
||||
input_style = "arch_split"
|
||||
arity = 1
|
||||
|
||||
def result(self) -> List[str]:
|
||||
result = (self.int_n - self.int_a) % self.int_n
|
||||
return [self.format_result(result)]
|
||||
150
vendor/mbedtls/framework/scripts/mbedtls_framework/build_tree.py
vendored
Normal file
150
vendor/mbedtls/framework/scripts/mbedtls_framework/build_tree.py
vendored
Normal file
@@ -0,0 +1,150 @@
|
||||
"""Mbed TLS build tree information and manipulation.
|
||||
"""
|
||||
|
||||
# Copyright The Mbed TLS Contributors
|
||||
# SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
#
|
||||
|
||||
import os
|
||||
import inspect
|
||||
import re
|
||||
from typing import Optional
|
||||
|
||||
def looks_like_tf_psa_crypto_root(path: str) -> bool:
|
||||
"""Whether the given directory looks like the root of the PSA Crypto source tree."""
|
||||
try:
|
||||
with open(os.path.join(path, 'scripts', 'project_name.txt'), 'r') as f:
|
||||
return f.read() == "TF-PSA-Crypto\n"
|
||||
except FileNotFoundError:
|
||||
return False
|
||||
|
||||
def looks_like_mbedtls_root(path: str) -> bool:
|
||||
"""Whether the given directory looks like the root of the Mbed TLS source tree."""
|
||||
try:
|
||||
with open(os.path.join(path, 'scripts', 'project_name.txt'), 'r') as f:
|
||||
return f.read() == "Mbed TLS\n"
|
||||
except FileNotFoundError:
|
||||
return False
|
||||
|
||||
def looks_like_root(path: str) -> bool:
|
||||
return looks_like_tf_psa_crypto_root(path) or looks_like_mbedtls_root(path)
|
||||
|
||||
def crypto_core_directory(root: Optional[str] = None, relative: Optional[bool] = False) -> str:
|
||||
"""
|
||||
Return the path of the directory containing the PSA crypto core
|
||||
for either TF-PSA-Crypto or Mbed TLS.
|
||||
|
||||
Returns either the full path or relative path depending on the
|
||||
"relative" boolean argument.
|
||||
"""
|
||||
if root is None:
|
||||
root = guess_project_root()
|
||||
if looks_like_tf_psa_crypto_root(root):
|
||||
if relative:
|
||||
return "core"
|
||||
return os.path.join(root, "core")
|
||||
elif looks_like_mbedtls_root(root):
|
||||
if is_mbedtls_3_6():
|
||||
path = "library"
|
||||
else:
|
||||
path = "tf-psa-crypto/core"
|
||||
if relative:
|
||||
return path
|
||||
return os.path.join(root, path)
|
||||
else:
|
||||
raise Exception('Neither Mbed TLS nor TF-PSA-Crypto source tree found')
|
||||
|
||||
def crypto_library_filename(root: Optional[str] = None) -> str:
|
||||
"""Return the crypto library filename for either TF-PSA-Crypto or Mbed TLS."""
|
||||
if root is None:
|
||||
root = guess_project_root()
|
||||
if looks_like_tf_psa_crypto_root(root):
|
||||
return "tfpsacrypto"
|
||||
elif looks_like_mbedtls_root(root):
|
||||
return "mbedcrypto"
|
||||
else:
|
||||
raise Exception('Neither Mbed TLS nor TF-PSA-Crypto source tree found')
|
||||
|
||||
def check_repo_path():
|
||||
"""Check that the current working directory is the project root, and throw
|
||||
an exception if not.
|
||||
"""
|
||||
if not all(os.path.isdir(d) for d in ["include", "library", "tests"]):
|
||||
raise Exception("This script must be run from Mbed TLS root")
|
||||
|
||||
def chdir_to_root() -> None:
|
||||
"""Detect the root of the Mbed TLS or TF-PSA-Crypto source tree and change to it.
|
||||
|
||||
The current directory must be up to two levels deep inside an Mbed TLS or
|
||||
TF-PSA-Crypto source tree.
|
||||
"""
|
||||
for d in [os.path.curdir,
|
||||
os.path.pardir,
|
||||
os.path.join(os.path.pardir, os.path.pardir)]:
|
||||
if looks_like_root(d):
|
||||
os.chdir(d)
|
||||
return
|
||||
raise Exception('Mbed TLS or TF-PSA-Crypto source tree not found')
|
||||
|
||||
def guess_project_root():
|
||||
"""Guess project source code directory.
|
||||
|
||||
Return the first possible project root directory.
|
||||
"""
|
||||
dirs = set({})
|
||||
for frame in inspect.stack():
|
||||
path = os.path.dirname(frame.filename)
|
||||
for d in ['.', os.path.pardir] \
|
||||
+ [os.path.join(*([os.path.pardir]*i)) for i in range(2, 10)]:
|
||||
d = os.path.abspath(os.path.join(path, d))
|
||||
if d in dirs:
|
||||
continue
|
||||
dirs.add(d)
|
||||
if looks_like_root(d):
|
||||
return d
|
||||
raise Exception('Neither Mbed TLS nor TF-PSA-Crypto source tree found')
|
||||
|
||||
def guess_mbedtls_root(root: Optional[str] = None) -> str:
|
||||
"""Guess Mbed TLS source code directory.
|
||||
|
||||
Return the first possible Mbed TLS root directory.
|
||||
Raise an exception if we are not in Mbed TLS.
|
||||
"""
|
||||
if root is None:
|
||||
root = guess_project_root()
|
||||
if looks_like_mbedtls_root(root):
|
||||
return root
|
||||
else:
|
||||
raise Exception('Mbed TLS source tree not found')
|
||||
|
||||
def guess_tf_psa_crypto_root(root: Optional[str] = None) -> str:
|
||||
"""Guess TF-PSA-Crypto source code directory.
|
||||
|
||||
Return the first possible TF-PSA-Crypto root directory.
|
||||
Raise an exception if we are not in TF-PSA-Crypto.
|
||||
"""
|
||||
if root is None:
|
||||
root = guess_project_root()
|
||||
if looks_like_tf_psa_crypto_root(root):
|
||||
return root
|
||||
else:
|
||||
raise Exception('TF-PSA-Crypto source tree not found')
|
||||
|
||||
def framework_root(root: Optional[str] = None) -> str:
|
||||
"""Return the path to the framework directory for this project."""
|
||||
if root is None:
|
||||
root = guess_project_root()
|
||||
return os.path.join(root, 'framework')
|
||||
|
||||
def is_mbedtls_3_6() -> bool:
|
||||
"""Whether the working tree is an Mbed TLS 3.6 one or not
|
||||
|
||||
Return false if we are in TF-PSA-Crypto or in Mbed TLS but with a version
|
||||
different from 3.6.x.
|
||||
Raise an exception if we are neither in Mbed TLS nor in TF-PSA-Crypto.
|
||||
"""
|
||||
root = guess_project_root()
|
||||
if not looks_like_mbedtls_root(root):
|
||||
return False
|
||||
with open(os.path.join(root, 'include', 'mbedtls', 'build_info.h'), 'r') as f:
|
||||
return re.search(r"#define MBEDTLS_VERSION_NUMBER.*0x0306", f.read()) is not None
|
||||
176
vendor/mbedtls/framework/scripts/mbedtls_framework/c_build_helper.py
vendored
Normal file
176
vendor/mbedtls/framework/scripts/mbedtls_framework/c_build_helper.py
vendored
Normal file
@@ -0,0 +1,176 @@
|
||||
"""Generate and run C code.
|
||||
"""
|
||||
|
||||
# Copyright The Mbed TLS Contributors
|
||||
# SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
#
|
||||
|
||||
import os
|
||||
import platform
|
||||
import subprocess
|
||||
import sys
|
||||
import tempfile
|
||||
|
||||
class CompileError(Exception):
|
||||
"""Exception to represent an error during the compilation."""
|
||||
|
||||
def __init__(self, message):
|
||||
"""Save the error massage"""
|
||||
super().__init__(message)
|
||||
self.message = message
|
||||
|
||||
def remove_file_if_exists(filename):
|
||||
"""Remove the specified file, ignoring errors."""
|
||||
if not filename:
|
||||
return
|
||||
try:
|
||||
os.remove(filename)
|
||||
except OSError:
|
||||
pass
|
||||
|
||||
def create_c_file(file_label):
|
||||
"""Create a temporary C file.
|
||||
|
||||
* ``file_label``: a string that will be included in the file name.
|
||||
|
||||
Return ```(c_file, c_name, exe_name)``` where ``c_file`` is a Python
|
||||
stream open for writing to the file, ``c_name`` is the name of the file
|
||||
and ``exe_name`` is the name of the executable that will be produced
|
||||
by compiling the file.
|
||||
"""
|
||||
c_fd, c_name = tempfile.mkstemp(prefix='tmp-{}-'.format(file_label),
|
||||
suffix='.c')
|
||||
exe_suffix = '.exe' if platform.system() == 'Windows' else ''
|
||||
exe_name = c_name[:-2] + exe_suffix
|
||||
remove_file_if_exists(exe_name)
|
||||
c_file = os.fdopen(c_fd, 'w', encoding='ascii')
|
||||
return c_file, c_name, exe_name
|
||||
|
||||
def generate_c_printf_expressions(c_file, cast_to, printf_format, expressions):
|
||||
"""Generate C instructions to print the value of ``expressions``.
|
||||
|
||||
Write the code with ``c_file``'s ``write`` method.
|
||||
|
||||
Each expression is cast to the type ``cast_to`` and printed with the
|
||||
printf format ``printf_format``.
|
||||
"""
|
||||
for expr in expressions:
|
||||
c_file.write(' printf("{}\\n", ({}) {});\n'
|
||||
.format(printf_format, cast_to, expr))
|
||||
|
||||
def generate_c_file(c_file,
|
||||
caller, header,
|
||||
main_generator):
|
||||
"""Generate a temporary C source file.
|
||||
|
||||
* ``c_file`` is an open stream on the C source file.
|
||||
* ``caller``: an informational string written in a comment at the top
|
||||
of the file.
|
||||
* ``header``: extra code to insert before any function in the generated
|
||||
C file.
|
||||
* ``main_generator``: a function called with ``c_file`` as its sole argument
|
||||
to generate the body of the ``main()`` function.
|
||||
"""
|
||||
c_file.write('/* Generated by {} */'
|
||||
.format(caller))
|
||||
c_file.write('''
|
||||
#include <stdio.h>
|
||||
''')
|
||||
c_file.write(header)
|
||||
c_file.write('''
|
||||
int main(void)
|
||||
{
|
||||
''')
|
||||
main_generator(c_file)
|
||||
c_file.write(''' return 0;
|
||||
}
|
||||
''')
|
||||
|
||||
def compile_c_file(c_filename, exe_filename, include_dirs):
|
||||
"""Compile a C source file with the host compiler.
|
||||
|
||||
* ``c_filename``: the name of the source file to compile.
|
||||
* ``exe_filename``: the name for the executable to be created.
|
||||
* ``include_dirs``: a list of paths to include directories to be passed
|
||||
with the -I switch.
|
||||
"""
|
||||
# Respect $HOSTCC if it is set
|
||||
cc = os.getenv('HOSTCC', None)
|
||||
if cc is None:
|
||||
cc = os.getenv('CC', 'cc')
|
||||
cmd = [cc]
|
||||
|
||||
proc = subprocess.Popen(cmd,
|
||||
stdout=subprocess.DEVNULL,
|
||||
stderr=subprocess.PIPE,
|
||||
universal_newlines=True)
|
||||
cc_is_msvc = 'Microsoft (R) C/C++' in proc.communicate()[1]
|
||||
|
||||
cmd += ['-I' + dir for dir in include_dirs]
|
||||
if cc_is_msvc:
|
||||
# MSVC has deprecated using -o to specify the output file,
|
||||
# and produces an object file in the working directory by default.
|
||||
obj_filename = exe_filename[:-4] + '.obj'
|
||||
cmd += ['-Fe' + exe_filename, '-Fo' + obj_filename]
|
||||
else:
|
||||
cmd += ['-o' + exe_filename]
|
||||
|
||||
try:
|
||||
subprocess.check_output(cmd + [c_filename],
|
||||
stderr=subprocess.PIPE,
|
||||
universal_newlines=True)
|
||||
|
||||
except subprocess.CalledProcessError as e:
|
||||
raise CompileError(e.stderr) from e
|
||||
|
||||
def get_c_expression_values(
|
||||
cast_to, printf_format,
|
||||
expressions,
|
||||
caller=__name__, file_label='',
|
||||
header='', include_path=None,
|
||||
keep_c=False,
|
||||
): # pylint: disable=too-many-arguments, too-many-locals
|
||||
"""Generate and run a program to print out numerical values for expressions.
|
||||
|
||||
* ``cast_to``: a C type.
|
||||
* ``printf_format``: a printf format suitable for the type ``cast_to``.
|
||||
* ``header``: extra code to insert before any function in the generated
|
||||
C file.
|
||||
* ``expressions``: a list of C language expressions that have the type
|
||||
``cast_to``.
|
||||
* ``include_path``: a list of directories containing header files.
|
||||
* ``keep_c``: if true, keep the temporary C file (presumably for debugging
|
||||
purposes).
|
||||
|
||||
Use the C compiler specified by the ``CC`` environment variable, defaulting
|
||||
to ``cc``. If ``CC`` looks like MSVC, use its command line syntax,
|
||||
otherwise assume the compiler supports Unix traditional ``-I`` and ``-o``.
|
||||
|
||||
Return the list of values of the ``expressions``.
|
||||
"""
|
||||
if include_path is None:
|
||||
include_path = []
|
||||
c_name = None
|
||||
exe_name = None
|
||||
obj_name = None
|
||||
try:
|
||||
c_file, c_name, exe_name = create_c_file(file_label)
|
||||
generate_c_file(
|
||||
c_file, caller, header,
|
||||
lambda c_file: generate_c_printf_expressions(c_file,
|
||||
cast_to, printf_format,
|
||||
expressions)
|
||||
)
|
||||
c_file.close()
|
||||
|
||||
compile_c_file(c_name, exe_name, include_path)
|
||||
if keep_c:
|
||||
sys.stderr.write('List of {} tests kept at {}\n'
|
||||
.format(caller, c_name))
|
||||
else:
|
||||
os.remove(c_name)
|
||||
output = subprocess.check_output([exe_name])
|
||||
return output.decode('ascii').strip().split('\n')
|
||||
finally:
|
||||
remove_file_if_exists(exe_name)
|
||||
remove_file_if_exists(obj_name)
|
||||
168
vendor/mbedtls/framework/scripts/mbedtls_framework/c_parsing_helper.py
vendored
Normal file
168
vendor/mbedtls/framework/scripts/mbedtls_framework/c_parsing_helper.py
vendored
Normal file
@@ -0,0 +1,168 @@
|
||||
"""Helper functions to parse C code in heavily constrained scenarios.
|
||||
|
||||
Currently supported functionality:
|
||||
|
||||
* read_function_declarations: read function declarations from a header file.
|
||||
"""
|
||||
|
||||
# Copyright The Mbed TLS Contributors
|
||||
# SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
|
||||
### WARNING: the code in this file has not been extensively reviewed yet.
|
||||
### We do not think it is harmful, but it may be below our normal standards
|
||||
### for robustness and maintainability.
|
||||
|
||||
import re
|
||||
from typing import Dict, Iterable, Iterator, List, Optional, Tuple
|
||||
|
||||
|
||||
class ArgumentInfo:
|
||||
"""Information about an argument to an API function."""
|
||||
#pylint: disable=too-few-public-methods
|
||||
|
||||
_KEYWORDS = [
|
||||
'const', 'register', 'restrict',
|
||||
'int', 'long', 'short', 'signed', 'unsigned',
|
||||
]
|
||||
_DECLARATION_RE = re.compile(
|
||||
r'(?P<type>\w[\w\s*]*?)\s*' +
|
||||
r'(?!(?:' + r'|'.join(_KEYWORDS) + r'))(?P<name>\b\w+\b)?' +
|
||||
r'\s*(?P<suffix>\[[^][]*\])?\Z',
|
||||
re.A | re.S)
|
||||
|
||||
@classmethod
|
||||
def normalize_type(cls, typ: str) -> str:
|
||||
"""Normalize whitespace in a type."""
|
||||
typ = re.sub(r'\s+', r' ', typ)
|
||||
typ = re.sub(r'\s*\*', r' *', typ)
|
||||
return typ
|
||||
|
||||
def __init__(self, decl: str) -> None:
|
||||
self.decl = decl.strip()
|
||||
m = self._DECLARATION_RE.match(self.decl)
|
||||
if not m:
|
||||
raise ValueError(self.decl)
|
||||
self.type = self.normalize_type(m.group('type')) #type: str
|
||||
self.name = m.group('name') #type: Optional[str]
|
||||
self.suffix = m.group('suffix') if m.group('suffix') else '' #type: str
|
||||
|
||||
def __str__(self) -> str:
|
||||
return self.decl
|
||||
|
||||
class FunctionInfo:
|
||||
"""Information about an API function."""
|
||||
#pylint: disable=too-few-public-methods
|
||||
|
||||
# Regex matching the declaration of a function that returns void.
|
||||
VOID_RE = re.compile(r'\s*\bvoid\s*\Z', re.A)
|
||||
|
||||
def __init__(self, #pylint: disable=too-many-arguments
|
||||
filename: str,
|
||||
line_number: int,
|
||||
qualifiers: Iterable[str],
|
||||
return_type: str,
|
||||
name: str,
|
||||
arguments: List[str],
|
||||
doc: str = "") -> None:
|
||||
|
||||
self.filename = filename
|
||||
self.line_number = line_number
|
||||
self.qualifiers = frozenset(qualifiers)
|
||||
self.return_type = return_type
|
||||
self.name = name
|
||||
self.arguments = [ArgumentInfo(arg) for arg in arguments]
|
||||
self.doc = doc
|
||||
|
||||
def returns_void(self) -> bool:
|
||||
"""Whether the function returns void."""
|
||||
return bool(self.VOID_RE.search(self.return_type))
|
||||
|
||||
def __str__(self) -> str:
|
||||
str_args = [str(a) for a in self.arguments]
|
||||
str_text = "{} {} {}({})".format(" ".join(self.qualifiers),
|
||||
self.return_type, self.name,
|
||||
", ".join(str_args)).strip()
|
||||
str_text = self._c_wrap_(str_text)
|
||||
return self.doc + "\n" + str_text
|
||||
|
||||
@staticmethod
|
||||
def _c_wrap_(in_str: str, line_len: int = 80) -> str:
|
||||
"""Auto-idents function declaration args using opening parenthesis."""
|
||||
if len(in_str) >= line_len:
|
||||
p_idx = in_str.index("(")
|
||||
ident = " " * p_idx
|
||||
padded_comma = ",\n" + ident
|
||||
in_str = in_str.replace(",", padded_comma)
|
||||
return in_str
|
||||
|
||||
# Match one C comment.
|
||||
# Note that we match both comment types, so things like // in a /*...*/
|
||||
# comment are handled correctly.
|
||||
_C_COMMENT_RE = re.compile(r'//(?:[^\n]|\\\n)*|/\*.*?\*/', re.S)
|
||||
_NOT_NEWLINES_RE = re.compile(r'[^\n]+')
|
||||
|
||||
def read_logical_lines(filename: str) -> Iterator[Tuple[int, str]]:
|
||||
"""Read logical lines from a file.
|
||||
|
||||
Logical lines are one or more physical line, with balanced parentheses.
|
||||
"""
|
||||
with open(filename, encoding='utf-8') as inp:
|
||||
content = inp.read()
|
||||
# Strip comments, but keep newlines for line numbering
|
||||
content = re.sub(_C_COMMENT_RE,
|
||||
lambda m: re.sub(_NOT_NEWLINES_RE, "", m.group(0)),
|
||||
content)
|
||||
lines = enumerate(content.splitlines(), 1)
|
||||
for line_number, line in lines:
|
||||
# Read a logical line, containing balanced parentheses.
|
||||
# We assume that parentheses are balanced (this should be ok
|
||||
# since comments have been stripped), otherwise there will be
|
||||
# a gigantic logical line at the end.
|
||||
paren_level = line.count('(') - line.count(')')
|
||||
while paren_level > 0:
|
||||
_, more = next(lines) #pylint: disable=stop-iteration-return
|
||||
paren_level += more.count('(') - more.count(')')
|
||||
line += '\n' + more
|
||||
yield line_number, line
|
||||
|
||||
_C_FUNCTION_DECLARATION_RE = re.compile(
|
||||
r'(?P<qualifiers>(?:(?:extern|inline|static)\b\s*)*)'
|
||||
r'(?P<return_type>\w[\w\s*]*?)\s*' +
|
||||
r'\b(?P<name>\w+)' +
|
||||
r'\s*\((?P<arguments>.*)\)\s*;',
|
||||
re.A | re.S)
|
||||
|
||||
def read_function_declarations(functions: Dict[str, FunctionInfo],
|
||||
filename: str) -> None:
|
||||
|
||||
"""Collect function declarations from a C header file."""
|
||||
for line_number, line in read_logical_lines(filename):
|
||||
m = _C_FUNCTION_DECLARATION_RE.match(line)
|
||||
if not m:
|
||||
continue
|
||||
qualifiers = m.group('qualifiers').split()
|
||||
return_type = m.group('return_type')
|
||||
name = m.group('name')
|
||||
arguments = m.group('arguments').split(',')
|
||||
if len(arguments) == 1 and re.match(FunctionInfo.VOID_RE, arguments[0]):
|
||||
arguments = []
|
||||
# Note: we replace any existing declaration for the same name.
|
||||
functions[name] = FunctionInfo(filename, line_number,
|
||||
qualifiers,
|
||||
return_type,
|
||||
name,
|
||||
arguments)
|
||||
|
||||
_C_TYPEDEF_DECLARATION_RE = re.compile(r'typedef (?:struct )?(?P<type>\w+) (?P<name>\w+)')
|
||||
|
||||
def read_typedefs(filename: str) -> Dict[str, str]:
|
||||
""" Extract type definitions in a {typedef aliased name: original type} dictionary.
|
||||
Multi-line typedef struct are not captured. """
|
||||
|
||||
type_decl = {}
|
||||
|
||||
for _, line in read_logical_lines(filename):
|
||||
m = _C_TYPEDEF_DECLARATION_RE.match(line)
|
||||
if m:
|
||||
type_decl[m.group("name")] = m.group("type")
|
||||
return type_decl
|
||||
511
vendor/mbedtls/framework/scripts/mbedtls_framework/c_wrapper_generator.py
vendored
Normal file
511
vendor/mbedtls/framework/scripts/mbedtls_framework/c_wrapper_generator.py
vendored
Normal file
@@ -0,0 +1,511 @@
|
||||
"""Generate C wrapper functions.
|
||||
"""
|
||||
|
||||
# Copyright The Mbed TLS Contributors
|
||||
# SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
|
||||
### WARNING: the code in this file has not been extensively reviewed yet.
|
||||
### We do not think it is harmful, but it may be below our normal standards
|
||||
### for robustness and maintainability.
|
||||
|
||||
import os
|
||||
import re
|
||||
import sys
|
||||
from typing import Dict, NamedTuple, List, Optional, Tuple
|
||||
|
||||
from .c_parsing_helper import ArgumentInfo, FunctionInfo
|
||||
from . import typing_util
|
||||
|
||||
|
||||
def c_declare(prefix: str, name: str, suffix: str) -> str:
|
||||
"""Format a declaration of name with the given type prefix and suffix."""
|
||||
if not prefix.endswith('*'):
|
||||
prefix += ' '
|
||||
return prefix + name + suffix
|
||||
|
||||
|
||||
WrapperInfo = NamedTuple('WrapperInfo', [
|
||||
('argument_names', List[str]),
|
||||
('guard', Optional[str]),
|
||||
('wrapper_name', str),
|
||||
])
|
||||
|
||||
def strip_indentation(in_str: str, new_lines: int = 1, indent_lv: int = 0) -> str:
|
||||
"""Return a whitespace stripped str, with configurable whitespace in output.
|
||||
|
||||
The method will remove space-character indentation from input string.
|
||||
It will also remove all new-lines around the text-block as well as
|
||||
trailing whitespace.
|
||||
The output indentation can be configured by indent_lv, and will use blocks
|
||||
of 4 spaces.
|
||||
At the end of the string a `new_lines` amount of empty lines will be added.
|
||||
"""
|
||||
|
||||
_ret_string = in_str.lstrip('\n').rstrip()
|
||||
# Count empty spaces in beggining of each line. The smallest non-zero entry
|
||||
# will be used to clean up input indentation.
|
||||
indents = [len(n)-1 for n in re.findall(r'(?m)^ +\S', in_str)]
|
||||
|
||||
if indents:
|
||||
_ret_string = re.sub(r'(?m)^ {{{indent}}}'.format(indent=min(indents)),
|
||||
'', _ret_string)
|
||||
if indent_lv:
|
||||
_ret_string = '\n'.join([' ' * indent_lv * 4 + s
|
||||
for s in _ret_string.splitlines()])
|
||||
return _ret_string + ('\n' * (new_lines + 1))
|
||||
|
||||
class Base:
|
||||
"""Generate a C source file containing wrapper functions."""
|
||||
|
||||
# This class is designed to have many methods potentially overloaded.
|
||||
# Tell pylint not to complain about methods that have unused arguments:
|
||||
# child classes are likely to override those methods and need the
|
||||
# arguments in question.
|
||||
#pylint: disable=no-self-use,unused-argument
|
||||
|
||||
# Prefix prepended to the function's name to form the wrapper name.
|
||||
_WRAPPER_NAME_PREFIX = ''
|
||||
# Suffix appended to the function's name to form the wrapper name.
|
||||
_WRAPPER_NAME_SUFFIX = '_wrap'
|
||||
|
||||
_INCLUDES = ['<mbedtls/build_info.h>']
|
||||
|
||||
# Functions with one of these qualifiers are skipped.
|
||||
_SKIP_FUNCTION_WITH_QUALIFIERS = frozenset(['inline', 'static'])
|
||||
|
||||
def __init__(self):
|
||||
"""Construct a wrapper generator object.
|
||||
"""
|
||||
self.program_name = os.path.basename(sys.argv[0])
|
||||
# To be populated in a derived class
|
||||
self.functions = {} #type: Dict[str, FunctionInfo]
|
||||
self._function_guards = {} #type: Dict[str, str]
|
||||
# Preprocessor symbol used as a guard against multiple inclusion in the
|
||||
# header. Must be set before writing output to a header.
|
||||
# Not used when writing .c output.
|
||||
self.header_guard = None #type: Optional[str]
|
||||
|
||||
def _write_prologue(self, out: typing_util.Writable, header: bool) -> None:
|
||||
"""Write the prologue of a C file.
|
||||
|
||||
This includes a description comment and some include directives.
|
||||
"""
|
||||
prologue = strip_indentation(f'''
|
||||
/* Automatically generated by {self.program_name}, do not edit! */
|
||||
|
||||
/* Copyright The Mbed TLS Contributors
|
||||
* SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
*/
|
||||
|
||||
''')
|
||||
|
||||
if header:
|
||||
prologue += strip_indentation(f'''
|
||||
#ifndef {self.header_guard}
|
||||
#define {self.header_guard}
|
||||
|
||||
#ifdef __cplusplus
|
||||
extern "C" {{
|
||||
#endif
|
||||
|
||||
''')
|
||||
|
||||
if not header:
|
||||
# On Mingw-w64, force the use of a C99-compliant printf() and friends.
|
||||
# This is necessary on older versions of Mingw and/or Windows runtimes
|
||||
# where snprintf does not always zero-terminate the buffer, and does
|
||||
# not support formats such as "%zu" for size_t and "%lld" for long long.
|
||||
prologue += strip_indentation(f'''
|
||||
#if !defined(__USE_MINGW_ANSI_STDIO)
|
||||
#define __USE_MINGW_ANSI_STDIO 1
|
||||
#endif
|
||||
''')
|
||||
|
||||
for include in self._INCLUDES:
|
||||
prologue += "#include {}\n".format(include)
|
||||
|
||||
# Make certain there is an empty line at the end of this section.
|
||||
prologue += '\n' if self._INCLUDES else '\n\n'
|
||||
|
||||
out.write(prologue)
|
||||
|
||||
def _write_epilogue(self, out: typing_util.Writable, header: bool) -> None:
|
||||
"""Write the epilogue of a C file."""
|
||||
epilogue = ""
|
||||
if header:
|
||||
epilogue += strip_indentation(f'''
|
||||
#ifdef __cplusplus
|
||||
}}
|
||||
#endif
|
||||
|
||||
#endif /* {self.header_guard} */
|
||||
|
||||
''')
|
||||
|
||||
epilogue += ('/* End of automatically generated file. */\n')
|
||||
out.write(epilogue)
|
||||
|
||||
def _wrapper_function_name(self, original_name: str) -> str:
|
||||
"""The name of the wrapper function.
|
||||
|
||||
By default, this adds a suffix.
|
||||
"""
|
||||
return (self._WRAPPER_NAME_PREFIX +
|
||||
original_name +
|
||||
self._WRAPPER_NAME_SUFFIX)
|
||||
|
||||
def _wrapper_declaration_start(self,
|
||||
function: FunctionInfo,
|
||||
wrapper_name: str) -> str:
|
||||
"""The beginning of the wrapper function declaration.
|
||||
|
||||
This ends just before the opening parenthesis of the argument list.
|
||||
|
||||
This is a string containing at least the return type and the
|
||||
function name. It may start with additional qualifiers or attributes
|
||||
such as `static`, `__attribute__((...))`, etc.
|
||||
"""
|
||||
return c_declare(function.return_type, wrapper_name, '')
|
||||
|
||||
def _argument_name(self,
|
||||
function_name: str,
|
||||
num: int,
|
||||
arg: ArgumentInfo) -> str:
|
||||
"""Name to use for the given argument in the wrapper function.
|
||||
|
||||
Argument numbers count from 0.
|
||||
"""
|
||||
name = 'arg' + str(num)
|
||||
if arg.name:
|
||||
name += '_' + arg.name
|
||||
return name
|
||||
|
||||
def _wrapper_declaration_argument(self,
|
||||
function_name: str,
|
||||
num: int, name: str,
|
||||
arg: ArgumentInfo) -> str:
|
||||
"""One argument definition in the wrapper function declaration.
|
||||
|
||||
Argument numbers count from 0.
|
||||
"""
|
||||
return c_declare(arg.type, name, arg.suffix)
|
||||
|
||||
def _underlying_function_name(self, function: FunctionInfo) -> str:
|
||||
"""The name of the underlying function.
|
||||
|
||||
By default, this is the name of the wrapped function.
|
||||
"""
|
||||
return function.name
|
||||
|
||||
def _return_variable_name(self, function: FunctionInfo) -> str:
|
||||
"""The name of the variable that will contain the return value."""
|
||||
return 'retval'
|
||||
|
||||
def _write_function_call(self, out: typing_util.Writable,
|
||||
function: FunctionInfo,
|
||||
argument_names: List[str]) -> None:
|
||||
"""Write the call to the underlying function.
|
||||
"""
|
||||
# Note that the function name is in parentheses, to avoid calling
|
||||
# a function-like macro with the same name, since in typical usage
|
||||
# there is a function-like macro with the same name which is the
|
||||
# wrapper.
|
||||
call = '({})({})'.format(self._underlying_function_name(function),
|
||||
', '.join(argument_names))
|
||||
if function.returns_void():
|
||||
out.write(' {};\n'.format(call))
|
||||
else:
|
||||
ret_name = self._return_variable_name(function)
|
||||
ret_decl = c_declare(function.return_type, ret_name, '')
|
||||
out.write(' {} = {};\n'.format(ret_decl, call))
|
||||
|
||||
def _write_function_return(self, out: typing_util.Writable,
|
||||
function: FunctionInfo,
|
||||
if_void: bool = False) -> None:
|
||||
"""Write a return statement.
|
||||
|
||||
If the function returns void, only write a statement if if_void is true.
|
||||
"""
|
||||
if function.returns_void():
|
||||
if if_void:
|
||||
out.write(' return;\n')
|
||||
else:
|
||||
ret_name = self._return_variable_name(function)
|
||||
out.write(' return {};\n'.format(ret_name))
|
||||
|
||||
def _write_function_body(self, out: typing_util.Writable,
|
||||
function: FunctionInfo,
|
||||
argument_names: List[str]) -> None:
|
||||
"""Write the body of the wrapper code for the specified function.
|
||||
"""
|
||||
self._write_function_call(out, function, argument_names)
|
||||
self._write_function_return(out, function)
|
||||
|
||||
def _skip_function(self, function: FunctionInfo) -> bool:
|
||||
"""Whether to skip this function.
|
||||
|
||||
By default, static or inline functions are skipped.
|
||||
"""
|
||||
if not self._SKIP_FUNCTION_WITH_QUALIFIERS.isdisjoint(function.qualifiers):
|
||||
return True
|
||||
return False
|
||||
|
||||
def _function_guard(self, function: FunctionInfo) -> Optional[str]:
|
||||
"""A preprocessor condition for this function.
|
||||
|
||||
The wrapper will be guarded with `#if` on this condition, if not None.
|
||||
"""
|
||||
return self._function_guards.get(function.name)
|
||||
|
||||
def _wrapper_info(self, function: FunctionInfo) -> Optional[WrapperInfo]:
|
||||
"""Information about the wrapper for one function.
|
||||
|
||||
Return None if the function should be skipped.
|
||||
"""
|
||||
if self._skip_function(function):
|
||||
return None
|
||||
argument_names = [self._argument_name(function.name, num, arg)
|
||||
for num, arg in enumerate(function.arguments)]
|
||||
return WrapperInfo(
|
||||
argument_names=argument_names,
|
||||
guard=self._function_guard(function),
|
||||
wrapper_name=self._wrapper_function_name(function.name),
|
||||
)
|
||||
|
||||
def _write_function_prototype(self, out: typing_util.Writable,
|
||||
function: FunctionInfo,
|
||||
wrapper: WrapperInfo,
|
||||
header: bool) -> None:
|
||||
"""Write the prototype of a wrapper function.
|
||||
|
||||
If header is true, write a function declaration, with a semicolon at
|
||||
the end. Otherwise just write the prototype, intended to be followed
|
||||
by the function's body.
|
||||
"""
|
||||
declaration_start = self._wrapper_declaration_start(function,
|
||||
wrapper.wrapper_name)
|
||||
arg_indent = ' '
|
||||
terminator = ';\n' if header else '\n'
|
||||
if function.arguments:
|
||||
out.write(declaration_start + '(\n')
|
||||
for num in range(len(function.arguments)):
|
||||
arg_def = self._wrapper_declaration_argument(
|
||||
function.name,
|
||||
num, wrapper.argument_names[num], function.arguments[num])
|
||||
arg_terminator = \
|
||||
(')' + terminator if num == len(function.arguments) - 1 else
|
||||
',\n')
|
||||
out.write(arg_indent + arg_def + arg_terminator)
|
||||
else:
|
||||
out.write(declaration_start + '(void)' + terminator)
|
||||
|
||||
def _write_c_function(self, out: typing_util.Writable,
|
||||
function: FunctionInfo) -> None:
|
||||
"""Write wrapper code for one function.
|
||||
|
||||
Do nothing if the function is skipped.
|
||||
"""
|
||||
wrapper = self._wrapper_info(function)
|
||||
if wrapper is None:
|
||||
return
|
||||
out.write('/* Wrapper for {} */\n'.format(function.name))
|
||||
|
||||
if wrapper.guard is not None:
|
||||
out.write('#if {}\n'.format(wrapper.guard))
|
||||
self._write_function_prototype(out, function, wrapper, False)
|
||||
out.write('{\n')
|
||||
self._write_function_body(out, function, wrapper.argument_names)
|
||||
out.write('}\n')
|
||||
if wrapper.guard is not None:
|
||||
out.write('#endif /* {} */\n'.format(wrapper.guard))
|
||||
out.write('\n')
|
||||
|
||||
def _write_h_function_declaration(self, out: typing_util.Writable,
|
||||
function: FunctionInfo,
|
||||
wrapper: WrapperInfo) -> None:
|
||||
"""Write the declaration of one wrapper function.
|
||||
"""
|
||||
self._write_function_prototype(out, function, wrapper, True)
|
||||
|
||||
def _write_h_macro_definition(self, out: typing_util.Writable,
|
||||
function: FunctionInfo,
|
||||
wrapper: WrapperInfo) -> None:
|
||||
"""Write the macro definition for one wrapper.
|
||||
"""
|
||||
arg_list = ', '.join(wrapper.argument_names)
|
||||
out.write('#define {function_name}({args}) \\\n {wrapper_name}({args})\n'
|
||||
.format(function_name=function.name,
|
||||
wrapper_name=wrapper.wrapper_name,
|
||||
args=arg_list))
|
||||
|
||||
def _write_h_function(self, out: typing_util.Writable,
|
||||
function: FunctionInfo) -> None:
|
||||
"""Write the complete header content for one wrapper.
|
||||
|
||||
This is the declaration of the wrapper function, and the
|
||||
definition of a function-like macro that calls the wrapper function.
|
||||
|
||||
Do nothing if the function is skipped.
|
||||
"""
|
||||
wrapper = self._wrapper_info(function)
|
||||
if wrapper is None:
|
||||
return
|
||||
if wrapper.guard is not None:
|
||||
out.write('#if {}\n'.format(wrapper.guard))
|
||||
self._write_h_function_declaration(out, function, wrapper)
|
||||
self._write_h_macro_definition(out, function, wrapper)
|
||||
if wrapper.guard is not None:
|
||||
out.write('#endif /* {} */\n'.format(wrapper.guard))
|
||||
out.write('\n')
|
||||
|
||||
def write_c_file(self, filename: str) -> None:
|
||||
"""Output a whole C file containing function wrapper definitions."""
|
||||
with open(filename, 'w', encoding='utf-8') as out:
|
||||
self._write_prologue(out, False)
|
||||
for name in sorted(self.functions):
|
||||
self._write_c_function(out, self.functions[name])
|
||||
self._write_epilogue(out, False)
|
||||
|
||||
def _header_guard_from_file_name(self, filename: str) -> str:
|
||||
"""Preprocessor symbol used as a guard against multiple inclusion."""
|
||||
# Heuristic to strip irrelevant leading directories
|
||||
filename = re.sub(r'.*include[\\/]', r'', filename)
|
||||
return re.sub(r'[^0-9A-Za-z]', r'_', filename, flags=re.A).upper()
|
||||
|
||||
def write_h_file(self, filename: str) -> None:
|
||||
"""Output a header file with function wrapper declarations and macro definitions."""
|
||||
self.header_guard = self._header_guard_from_file_name(filename)
|
||||
with open(filename, 'w', encoding='utf-8') as out:
|
||||
self._write_prologue(out, True)
|
||||
for name in sorted(self.functions):
|
||||
self._write_h_function(out, self.functions[name])
|
||||
self._write_epilogue(out, True)
|
||||
|
||||
|
||||
class UnknownTypeForPrintf(Exception):
|
||||
"""Exception raised when attempting to generate code that logs a value of an unknown type."""
|
||||
|
||||
def __init__(self, typ: str) -> None:
|
||||
super().__init__("Unknown type for printf format generation: " + typ)
|
||||
|
||||
|
||||
class Logging(Base):
|
||||
"""Generate wrapper functions that log the inputs and outputs."""
|
||||
|
||||
def __init__(self) -> None:
|
||||
"""Construct a wrapper generator including logging of inputs and outputs.
|
||||
|
||||
Log to stdout by default. Call `set_stream` to change this.
|
||||
"""
|
||||
super().__init__()
|
||||
self.stream = 'stdout'
|
||||
|
||||
def set_stream(self, stream: str) -> None:
|
||||
"""Set the stdio stream to log to.
|
||||
|
||||
Call this method before calling `write_c_output` or `write_h_output`.
|
||||
"""
|
||||
self.stream = stream
|
||||
|
||||
def _write_prologue(self, out: typing_util.Writable, header: bool) -> None:
|
||||
super()._write_prologue(out, header)
|
||||
if not header:
|
||||
out.write("""
|
||||
#if defined(MBEDTLS_FS_IO) && defined(MBEDTLS_TEST_HOOKS)
|
||||
#include <stdio.h>
|
||||
#include <inttypes.h>
|
||||
#include <mbedtls/platform.h> // for mbedtls_fprintf
|
||||
#endif /* defined(MBEDTLS_FS_IO) && defined(MBEDTLS_TEST_HOOKS) */
|
||||
""")
|
||||
|
||||
_PRINTF_SIMPLE_FORMAT = {
|
||||
'int': '%d',
|
||||
'long': '%ld',
|
||||
'long long': '%lld',
|
||||
'size_t': '%zu',
|
||||
'unsigned': '0x%08x',
|
||||
'unsigned int': '0x%08x',
|
||||
'unsigned long': '0x%08lx',
|
||||
'unsigned long long': '0x%016llx',
|
||||
}
|
||||
|
||||
def _printf_simple_format(self, typ: str) -> Optional[str]:
|
||||
"""Use this printf format for a value of typ.
|
||||
|
||||
Return None if values of typ need more complex handling.
|
||||
"""
|
||||
return self._PRINTF_SIMPLE_FORMAT.get(typ)
|
||||
|
||||
_PRINTF_TYPE_CAST = {
|
||||
'int32_t': 'int',
|
||||
'uint32_t': 'unsigned',
|
||||
'uint64_t': 'unsigned long long',
|
||||
} #type: Dict[str, str]
|
||||
|
||||
def _printf_type_cast(self, typ: str) -> Optional[str]:
|
||||
"""Cast values of typ to this type before passing them to printf.
|
||||
|
||||
Return None if values of the given type do not need a cast.
|
||||
"""
|
||||
return self._PRINTF_TYPE_CAST.get(typ)
|
||||
|
||||
_POINTER_TYPE_RE = re.compile(r'\s*\*\Z')
|
||||
|
||||
def _printf_parameters(self, typ: str, var: str) -> Tuple[str, List[str]]:
|
||||
"""The printf format and arguments for a value of type typ stored in var.
|
||||
"""
|
||||
expr = var
|
||||
base_type = typ
|
||||
# For outputs via a pointer, get the value that has been written.
|
||||
# Note: we don't support pointers to pointers here.
|
||||
pointer_match = self._POINTER_TYPE_RE.search(base_type)
|
||||
if pointer_match:
|
||||
base_type = base_type[:pointer_match.start(0)]
|
||||
expr = '*({})'.format(expr)
|
||||
# Maybe cast the value to a standard type.
|
||||
cast_to = self._printf_type_cast(base_type)
|
||||
if cast_to is not None:
|
||||
expr = '({}) {}'.format(cast_to, expr)
|
||||
base_type = cast_to
|
||||
# Try standard types.
|
||||
fmt = self._printf_simple_format(base_type)
|
||||
if fmt is not None:
|
||||
return '{}={}'.format(var, fmt), [expr]
|
||||
raise UnknownTypeForPrintf(typ)
|
||||
|
||||
def _write_function_logging(self, out: typing_util.Writable,
|
||||
function: FunctionInfo,
|
||||
argument_names: List[str]) -> None:
|
||||
"""Write code to log the function's inputs and outputs."""
|
||||
formats, values = '%s', ['"' + function.name + '"']
|
||||
for arg_info, arg_name in zip(function.arguments, argument_names):
|
||||
fmt, vals = self._printf_parameters(arg_info.type, arg_name)
|
||||
if fmt:
|
||||
formats += ' ' + fmt
|
||||
values += vals
|
||||
if not function.returns_void():
|
||||
ret_name = self._return_variable_name(function)
|
||||
fmt, vals = self._printf_parameters(function.return_type, ret_name)
|
||||
if fmt:
|
||||
formats += ' ' + fmt
|
||||
values += vals
|
||||
out.write("""\
|
||||
#if defined(MBEDTLS_FS_IO) && defined(MBEDTLS_TEST_HOOKS)
|
||||
if ({stream}) {{
|
||||
mbedtls_fprintf({stream}, "{formats}\\n",
|
||||
{values});
|
||||
}}
|
||||
#endif /* defined(MBEDTLS_FS_IO) && defined(MBEDTLS_TEST_HOOKS) */
|
||||
"""
|
||||
.format(stream=self.stream,
|
||||
formats=formats,
|
||||
values=', '.join(values)))
|
||||
|
||||
def _write_function_body(self, out: typing_util.Writable,
|
||||
function: FunctionInfo,
|
||||
argument_names: List[str]) -> None:
|
||||
"""Write the body of the wrapper code for the specified function.
|
||||
"""
|
||||
self._write_function_call(out, function, argument_names)
|
||||
self._write_function_logging(out, function, argument_names)
|
||||
self._write_function_return(out, function)
|
||||
0
vendor/mbedtls/framework/scripts/mbedtls_framework/code_wrapper/__init__.py
vendored
Normal file
0
vendor/mbedtls/framework/scripts/mbedtls_framework/code_wrapper/__init__.py
vendored
Normal file
25
vendor/mbedtls/framework/scripts/mbedtls_framework/code_wrapper/psa_buffer.py
vendored
Normal file
25
vendor/mbedtls/framework/scripts/mbedtls_framework/code_wrapper/psa_buffer.py
vendored
Normal file
@@ -0,0 +1,25 @@
|
||||
""" PSA Buffer utility data-class.
|
||||
"""
|
||||
|
||||
# Copyright The Mbed TLS Contributors
|
||||
# SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
|
||||
class BufferParameter:
|
||||
"""Description of an input or output buffer parameter sequence to a PSA function."""
|
||||
#pylint: disable=too-few-public-methods
|
||||
|
||||
def __init__(self, i: int, is_output: bool,
|
||||
buffer_name: str, size_name: str) -> None:
|
||||
"""Initialize the parameter information.
|
||||
|
||||
i is the index of the function argument that is the pointer to the buffer.
|
||||
The size is argument i+1. For a variable-size output, the actual length
|
||||
goes in argument i+2.
|
||||
|
||||
buffer_name and size_names are the names of arguments i and i+1.
|
||||
This class does not yet help with the output length.
|
||||
"""
|
||||
self.index = i
|
||||
self.buffer_name = buffer_name
|
||||
self.size_name = size_name
|
||||
self.is_output = is_output
|
||||
27
vendor/mbedtls/framework/scripts/mbedtls_framework/code_wrapper/psa_test_wrapper.py
vendored
Normal file
27
vendor/mbedtls/framework/scripts/mbedtls_framework/code_wrapper/psa_test_wrapper.py
vendored
Normal file
@@ -0,0 +1,27 @@
|
||||
"""Generate wrapper functions for PSA function calls.
|
||||
"""
|
||||
|
||||
# Copyright The Mbed TLS Contributors
|
||||
# SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
|
||||
from typing import List, Optional
|
||||
|
||||
from .psa_wrapper import PSAWrapper, PSALoggingWrapper
|
||||
|
||||
class PSATestWrapper(PSAWrapper):
|
||||
"""Generate a C source file containing wrapper functions for PSA Crypto API calls."""
|
||||
|
||||
_WRAPPER_NAME_PREFIX = 'mbedtls_test_wrap_'
|
||||
_WRAPPER_NAME_SUFFIX = ''
|
||||
|
||||
_PSA_WRAPPER_INCLUDES = ['<psa/crypto.h>',
|
||||
'<test/memory.h>',
|
||||
'<test/psa_crypto_helpers.h>',
|
||||
'<test/psa_test_wrappers.h>']
|
||||
|
||||
class PSALoggingTestWrapper(PSATestWrapper, PSALoggingWrapper):
|
||||
"""Generate a C source file containing wrapper functions that log PSA Crypto API calls."""
|
||||
|
||||
def __init__(self, out_h_f: str, out_c_f: str, stream: str,
|
||||
in_headers: Optional[List[str]] = None) -> None:
|
||||
super().__init__(out_h_f, out_c_f, stream, in_headers)
|
||||
287
vendor/mbedtls/framework/scripts/mbedtls_framework/code_wrapper/psa_wrapper.py
vendored
Normal file
287
vendor/mbedtls/framework/scripts/mbedtls_framework/code_wrapper/psa_wrapper.py
vendored
Normal file
@@ -0,0 +1,287 @@
|
||||
"""Generate wrapper functions for PSA function calls.
|
||||
"""
|
||||
|
||||
# Copyright The Mbed TLS Contributors
|
||||
# SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
|
||||
import itertools
|
||||
import os
|
||||
from typing import Iterable, Iterator, List, Optional, Tuple
|
||||
|
||||
from .. import build_tree
|
||||
from .. import c_parsing_helper
|
||||
from .. import c_wrapper_generator
|
||||
from .. import typing_util
|
||||
|
||||
from .psa_buffer import BufferParameter
|
||||
|
||||
class PSAWrapperConfiguration:
|
||||
"""Configuration data class for PSA Wrapper."""
|
||||
#pylint: disable=too-few-public-methods
|
||||
|
||||
def __init__(self) -> None:
|
||||
self.cpp_guards = [
|
||||
"MBEDTLS_PSA_CRYPTO_C",
|
||||
"MBEDTLS_TEST_HOOKS",
|
||||
"!RECORD_PSA_STATUS_COVERAGE_LOG",
|
||||
]
|
||||
|
||||
self.skipped_functions = frozenset([
|
||||
'mbedtls_psa_external_get_random', # not a library function
|
||||
'psa_get_key_domain_parameters', # client-side function
|
||||
'psa_get_key_slot_number', # client-side function
|
||||
'psa_key_derivation_verify_bytes', # not implemented yet
|
||||
'psa_key_derivation_verify_key', # not implemented yet
|
||||
'psa_set_key_domain_parameters', # client-side function
|
||||
])
|
||||
|
||||
self.skipped_argument_types = frozenset([
|
||||
# PAKE stuff: not implemented yet
|
||||
'psa_crypto_driver_pake_inputs_t *',
|
||||
'psa_pake_cipher_suite_t *',
|
||||
])
|
||||
|
||||
self.function_guards = {
|
||||
'mbedtls_psa_register_se_key': 'defined(MBEDTLS_PSA_CRYPTO_SE_C)',
|
||||
'mbedtls_psa_inject_entropy': 'defined(MBEDTLS_PSA_INJECT_ENTROPY)',
|
||||
'mbedtls_psa_external_get_random': 'defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG)',
|
||||
'mbedtls_psa_platform_get_builtin_key': 'defined(MBEDTLS_PSA_CRYPTO_BUILTIN_KEYS)',
|
||||
'psa_crypto_driver_pake_get_cipher_suite' : 'defined(PSA_WANT_ALG_SOME_PAKE)',
|
||||
'psa_crypto_driver_pake_get_password' : 'defined(PSA_WANT_ALG_SOME_PAKE)',
|
||||
'psa_crypto_driver_pake_get_password_len' : 'defined(PSA_WANT_ALG_SOME_PAKE)',
|
||||
'psa_crypto_driver_pake_get_peer' : 'defined(PSA_WANT_ALG_SOME_PAKE)',
|
||||
'psa_crypto_driver_pake_get_peer_len' : 'defined(PSA_WANT_ALG_SOME_PAKE)',
|
||||
'psa_crypto_driver_pake_get_user' : 'defined(PSA_WANT_ALG_SOME_PAKE)',
|
||||
'psa_crypto_driver_pake_get_user_len' : 'defined(PSA_WANT_ALG_SOME_PAKE)',
|
||||
'psa_pake_abort' : 'defined(PSA_WANT_ALG_SOME_PAKE)',
|
||||
'psa_pake_get_implicit_key' : 'defined(PSA_WANT_ALG_SOME_PAKE)',
|
||||
'psa_pake_input' : 'defined(PSA_WANT_ALG_SOME_PAKE)',
|
||||
'psa_pake_output' : 'defined(PSA_WANT_ALG_SOME_PAKE)',
|
||||
'psa_pake_set_password_key' : 'defined(PSA_WANT_ALG_SOME_PAKE)',
|
||||
'psa_pake_set_peer' : 'defined(PSA_WANT_ALG_SOME_PAKE)',
|
||||
'psa_pake_set_role' : 'defined(PSA_WANT_ALG_SOME_PAKE)',
|
||||
'psa_pake_set_user' : 'defined(PSA_WANT_ALG_SOME_PAKE)',
|
||||
'psa_pake_setup' : 'defined(PSA_WANT_ALG_SOME_PAKE)',
|
||||
}
|
||||
|
||||
class PSAWrapper(c_wrapper_generator.Base):
|
||||
"""Generate a C source file containing wrapper functions for PSA Crypto API calls."""
|
||||
|
||||
_WRAPPER_NAME_PREFIX = 'mbedtls_test_wrap_'
|
||||
_WRAPPER_NAME_SUFFIX = ''
|
||||
|
||||
_PSA_WRAPPER_INCLUDES = ['<psa/crypto.h>']
|
||||
_DEFAULT_IN_HEADERS = ['crypto.h', 'crypto_extra.h']
|
||||
|
||||
def __init__(self,
|
||||
out_h_f: str,
|
||||
out_c_f: str,
|
||||
in_headers: Optional[List[str]] = None,
|
||||
config: PSAWrapperConfiguration = PSAWrapperConfiguration()) -> None:
|
||||
|
||||
super().__init__()
|
||||
self.out_c_f = out_c_f
|
||||
self.out_h_f = out_h_f
|
||||
|
||||
self.project_root = build_tree.guess_project_root()
|
||||
self.read_config(config)
|
||||
self.read_headers(in_headers)
|
||||
|
||||
def read_config(self, cfg: PSAWrapperConfiguration)-> None:
|
||||
"""Configure instance's parameters from a user provided config."""
|
||||
|
||||
self._cpp_guards = PSAWrapper.parse_def_guards(cfg.cpp_guards)
|
||||
self._skip_functions = cfg.skipped_functions
|
||||
self._function_guards.update(cfg.function_guards)
|
||||
self._not_implemented = cfg.skipped_argument_types
|
||||
|
||||
def read_headers(self, headers: Optional[List[str]]) -> None:
|
||||
"""Reads functions to be wrapped from source header files into self.functions."""
|
||||
self.in_headers = self._DEFAULT_IN_HEADERS if headers is None else headers
|
||||
for header_name in self.in_headers:
|
||||
header_path = self.rel_path(header_name)
|
||||
c_parsing_helper.read_function_declarations(self.functions, header_path)
|
||||
|
||||
def rel_path(self, filename: str, path_list: Optional[List[str]] = None) -> str:
|
||||
"""Return the estimated path in relationship to the project_root.
|
||||
|
||||
The method allows overriding the targetted sub-directory.
|
||||
Currently the default is set to project_root/include/psa."""
|
||||
if path_list is None:
|
||||
path_list = ['include', 'psa']
|
||||
return os.path.join(self.project_root, *path_list, filename)
|
||||
|
||||
# Utility Methods
|
||||
@staticmethod
|
||||
def parse_def_guards(def_list: Iterable[str])-> str:
|
||||
""" Create define guards.
|
||||
|
||||
Convert an input list of into a C preprocessor
|
||||
expression of defined() && !defined() syntax string."""
|
||||
|
||||
output = ""
|
||||
dl = [("defined({})".format(n) if n[0] != "!" else
|
||||
"!defined({})".format(n[1:]))
|
||||
for n in def_list]
|
||||
|
||||
# Split the list in chunks of 2 and add new lines
|
||||
for i in range(0, len(dl), 2):
|
||||
output += "{} && {} && \\".format(dl[i], dl[i+1]) + "\n "\
|
||||
if i+2 <= len(dl) else dl[i]
|
||||
return output
|
||||
|
||||
@staticmethod
|
||||
def _detect_buffer_parameters(arguments: List[c_parsing_helper.ArgumentInfo],
|
||||
argument_names: List[str]) -> Iterator[BufferParameter]:
|
||||
"""Detect function arguments that are buffers (pointer, size [,length])."""
|
||||
types = ['' if arg.suffix else arg.type for arg in arguments]
|
||||
# pairs = list of (type_of_arg_N, type_of_arg_N+1)
|
||||
# where each type_of_arg_X is the empty string if the type is an array
|
||||
# or there is no argument X.
|
||||
pairs = enumerate(itertools.zip_longest(types, types[1:], fillvalue=''))
|
||||
for i, t01 in pairs:
|
||||
if (t01[0] == 'const uint8_t *' or t01[0] == 'uint8_t *') and \
|
||||
t01[1] == 'size_t':
|
||||
yield BufferParameter(i, not t01[0].startswith('const '),
|
||||
argument_names[i], argument_names[i+1])
|
||||
|
||||
@staticmethod
|
||||
def _parameter_should_be_copied(function_name: str,
|
||||
_buffer_name: Optional[str]) -> bool:
|
||||
"""Whether the specified buffer argument to a PSA function should be copied.
|
||||
"""
|
||||
# False-positives that do not need buffer copying
|
||||
if function_name in ('mbedtls_psa_inject_entropy',
|
||||
'psa_crypto_driver_pake_get_password',
|
||||
'psa_crypto_driver_pake_get_user',
|
||||
'psa_crypto_driver_pake_get_peer'):
|
||||
return False
|
||||
|
||||
return True
|
||||
|
||||
@staticmethod
|
||||
def _poison_wrap(param: BufferParameter, poison: bool,
|
||||
ident_lv: int = 1) -> str:
|
||||
"""Returns a call to MBEDTLS_TEST_MEMORY_[UN]POISON.
|
||||
|
||||
The output is prefixed with MBEDTLS_TEST_MEMORY_ followed by POISON/UNPOISON
|
||||
and the input parameter arguments (name, length)
|
||||
"""
|
||||
return "{}MBEDTLS_TEST_MEMORY_{}({}, {});\n".format(
|
||||
(ident_lv * 4) * ' ',
|
||||
'POISON' if poison else 'UNPOISON',
|
||||
param.buffer_name, param.size_name)
|
||||
|
||||
def _poison_multi_write(self,
|
||||
out: typing_util.Writable,
|
||||
buffer_parameters: List['BufferParameter'],
|
||||
poison: bool) -> None:
|
||||
"""Write poisoning or unpoisoning code for the buffer parameters.
|
||||
|
||||
Write poisoning code if poison is true, unpoisoning code otherwise.
|
||||
"""
|
||||
|
||||
if not buffer_parameters:
|
||||
return
|
||||
out.write('#if !defined(MBEDTLS_PSA_ASSUME_EXCLUSIVE_BUFFERS)\n')
|
||||
for param in buffer_parameters:
|
||||
out.write(self._poison_wrap(param, poison))
|
||||
out.write('#endif /* !defined(MBEDTLS_PSA_ASSUME_EXCLUSIVE_BUFFERS) */\n')
|
||||
|
||||
# Override parent's methods
|
||||
def _write_function_call(self, out: typing_util.Writable,
|
||||
function: c_wrapper_generator.FunctionInfo,
|
||||
argument_names: List[str]) -> None:
|
||||
buffer_parameters = list(
|
||||
param
|
||||
for param in self._detect_buffer_parameters(function.arguments,
|
||||
argument_names)
|
||||
if self._parameter_should_be_copied(function.name,
|
||||
function.arguments[param.index].name))
|
||||
|
||||
self._poison_multi_write(out, buffer_parameters, True)
|
||||
super()._write_function_call(out, function, argument_names)
|
||||
self._poison_multi_write(out, buffer_parameters, False)
|
||||
|
||||
def _skip_function(self, function: c_wrapper_generator.FunctionInfo) -> bool:
|
||||
if function.return_type != 'psa_status_t':
|
||||
return True
|
||||
if function.name in self._skip_functions:
|
||||
return True
|
||||
return False
|
||||
|
||||
def _return_variable_name(self,
|
||||
function: c_wrapper_generator.FunctionInfo) -> str:
|
||||
"""The name of the variable that will contain the return value."""
|
||||
|
||||
if function.return_type == 'psa_status_t':
|
||||
return 'status'
|
||||
return super()._return_variable_name(function)
|
||||
|
||||
def _write_prologue(self, out: typing_util.Writable, header: bool) -> None:
|
||||
super()._write_prologue(out, header)
|
||||
|
||||
prologue = []
|
||||
if self._cpp_guards:
|
||||
prologue.append("#if {}".format(self._cpp_guards))
|
||||
prologue.append('')
|
||||
|
||||
for include in self._PSA_WRAPPER_INCLUDES:
|
||||
prologue.append("#include {}".format(include))
|
||||
|
||||
# Make certain there is an empty line at the end of this section.
|
||||
for i in [-1, -2]:
|
||||
if prologue[i] != '':
|
||||
prologue.append('')
|
||||
|
||||
out.write("\n".join(prologue))
|
||||
|
||||
def _write_epilogue(self, out: typing_util.Writable, header: bool) -> None:
|
||||
if self._cpp_guards:
|
||||
out.write("#endif /* {} */\n\n".format(self._cpp_guards))
|
||||
super()._write_epilogue(out, header)
|
||||
|
||||
class PSALoggingWrapper(PSAWrapper, c_wrapper_generator.Logging):
|
||||
"""Generate a C source file containing wrapper functions that log PSA Crypto API calls."""
|
||||
|
||||
def __init__(self, #pylint: disable=too-many-arguments
|
||||
stream: str,
|
||||
out_h_f: str,
|
||||
out_c_f: str,
|
||||
in_headers: Optional[List[str]] = None,
|
||||
config: PSAWrapperConfiguration = PSAWrapperConfiguration()) -> None:
|
||||
|
||||
super().__init__(out_h_f, out_c_f, in_headers, config)
|
||||
self.set_stream(stream)
|
||||
|
||||
_PRINTF_TYPE_CAST = c_wrapper_generator.Logging._PRINTF_TYPE_CAST.copy()
|
||||
_PRINTF_TYPE_CAST.update({
|
||||
'mbedtls_svc_key_id_t': 'unsigned',
|
||||
'psa_algorithm_t': 'unsigned',
|
||||
'psa_drv_slot_number_t': 'unsigned long long',
|
||||
'psa_key_derivation_step_t': 'int',
|
||||
'psa_key_id_t': 'unsigned',
|
||||
'psa_key_slot_number_t': 'unsigned long long',
|
||||
'psa_key_lifetime_t': 'unsigned',
|
||||
'psa_key_type_t': 'unsigned',
|
||||
'psa_key_usage_flags_t': 'unsigned',
|
||||
'psa_pake_role_t': 'int',
|
||||
'psa_pake_step_t': 'int',
|
||||
'psa_status_t': 'int',
|
||||
})
|
||||
|
||||
def _printf_parameters(self, typ: str, var: str) -> Tuple[str, List[str]]:
|
||||
if typ.startswith('const '):
|
||||
typ = typ[6:]
|
||||
if typ == 'uint8_t *':
|
||||
# Skip buffers
|
||||
return '', []
|
||||
if typ.endswith('operation_t *'):
|
||||
return '', []
|
||||
if typ in self._not_implemented:
|
||||
return '', []
|
||||
if typ == 'psa_key_attributes_t *':
|
||||
return (var + '={id=%u, lifetime=0x%08x, type=0x%08x, bits=%u, alg=%08x, usage=%08x}',
|
||||
['(unsigned) psa_get_key_{}({})'.format(field, var)
|
||||
for field in ['id', 'lifetime', 'type', 'bits', 'algorithm', 'usage_flags']])
|
||||
return super()._printf_parameters(typ, var)
|
||||
170
vendor/mbedtls/framework/scripts/mbedtls_framework/collect_test_cases.py
vendored
Normal file
170
vendor/mbedtls/framework/scripts/mbedtls_framework/collect_test_cases.py
vendored
Normal file
@@ -0,0 +1,170 @@
|
||||
"""Discover all the test cases (unit tests and SSL tests)."""
|
||||
|
||||
# Copyright The Mbed TLS Contributors
|
||||
# SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
|
||||
import glob
|
||||
import os
|
||||
import re
|
||||
import subprocess
|
||||
import sys
|
||||
|
||||
from . import build_tree
|
||||
|
||||
|
||||
class ScriptOutputError(ValueError):
|
||||
"""A kind of ValueError that indicates we found
|
||||
the script doesn't list test cases in an expected
|
||||
pattern.
|
||||
"""
|
||||
|
||||
@property
|
||||
def script_name(self):
|
||||
return super().args[0]
|
||||
|
||||
@property
|
||||
def idx(self):
|
||||
return super().args[1]
|
||||
|
||||
@property
|
||||
def line(self):
|
||||
return super().args[2]
|
||||
|
||||
class Results:
|
||||
"""Store file and line information about errors or warnings in test suites."""
|
||||
|
||||
def __init__(self, options):
|
||||
self.errors = 0
|
||||
self.warnings = 0
|
||||
self.ignore_warnings = options.quiet
|
||||
|
||||
def error(self, file_name, line_number, fmt, *args):
|
||||
sys.stderr.write(('{}:{}:ERROR:' + fmt + '\n').
|
||||
format(file_name, line_number, *args))
|
||||
self.errors += 1
|
||||
|
||||
def warning(self, file_name, line_number, fmt, *args):
|
||||
if not self.ignore_warnings:
|
||||
sys.stderr.write(('{}:{}:Warning:' + fmt + '\n')
|
||||
.format(file_name, line_number, *args))
|
||||
self.warnings += 1
|
||||
|
||||
class TestDescriptionExplorer:
|
||||
"""An iterator over test cases with descriptions.
|
||||
|
||||
The test cases that have descriptions are:
|
||||
* Individual unit tests (entries in a .data file) in test suites.
|
||||
* Individual test cases in ssl-opt.sh.
|
||||
|
||||
This is an abstract class. To use it, derive a class that implements
|
||||
the process_test_case method, and call walk_all().
|
||||
"""
|
||||
|
||||
def process_test_case(self, per_file_state,
|
||||
file_name, line_number, description):
|
||||
"""Process a test case.
|
||||
|
||||
per_file_state: an object created by new_per_file_state() at the beginning
|
||||
of each file.
|
||||
file_name: a relative path to the file containing the test case.
|
||||
line_number: the line number in the given file.
|
||||
description: the test case description as a byte string.
|
||||
"""
|
||||
raise NotImplementedError
|
||||
|
||||
def new_per_file_state(self):
|
||||
"""Return a new per-file state object.
|
||||
|
||||
The default per-file state object is None. Child classes that require per-file
|
||||
state may override this method.
|
||||
"""
|
||||
#pylint: disable=no-self-use
|
||||
return None
|
||||
|
||||
def walk_test_suite(self, data_file_name):
|
||||
"""Iterate over the test cases in the given unit test data file."""
|
||||
in_paragraph = False
|
||||
descriptions = self.new_per_file_state() # pylint: disable=assignment-from-none
|
||||
with open(data_file_name, 'rb') as data_file:
|
||||
for line_number, line in enumerate(data_file, 1):
|
||||
line = line.rstrip(b'\r\n')
|
||||
if not line:
|
||||
in_paragraph = False
|
||||
continue
|
||||
if line.startswith(b'#'):
|
||||
continue
|
||||
if not in_paragraph:
|
||||
# This is a test case description line.
|
||||
self.process_test_case(descriptions,
|
||||
data_file_name, line_number, line)
|
||||
in_paragraph = True
|
||||
|
||||
def collect_from_script(self, script_name):
|
||||
"""Collect the test cases in a script by calling its listing test cases
|
||||
option"""
|
||||
descriptions = self.new_per_file_state() # pylint: disable=assignment-from-none
|
||||
listed = subprocess.check_output(['sh', script_name, '--list-test-cases'])
|
||||
# Assume test file is responsible for printing identical format of
|
||||
# test case description between --list-test-cases and its OUTCOME.CSV
|
||||
#
|
||||
# idx indicates the number of test case since there is no line number
|
||||
# in the script for each test case.
|
||||
for idx, line in enumerate(listed.splitlines()):
|
||||
# We are expecting the script to list the test cases in
|
||||
# `<suite_name>;<description>` pattern.
|
||||
script_outputs = line.split(b';', 1)
|
||||
if len(script_outputs) == 2:
|
||||
suite_name, description = script_outputs
|
||||
else:
|
||||
raise ScriptOutputError(script_name, idx, line.decode("utf-8"))
|
||||
|
||||
self.process_test_case(descriptions,
|
||||
suite_name.decode('utf-8'),
|
||||
idx,
|
||||
description.rstrip())
|
||||
|
||||
@staticmethod
|
||||
def collect_test_directories():
|
||||
"""Get the relative path for the TLS and Crypto test directories."""
|
||||
project_root = build_tree.guess_project_root()
|
||||
if build_tree.looks_like_mbedtls_root(project_root) and not build_tree.is_mbedtls_3_6():
|
||||
directories = [os.path.join(project_root, 'tests'),
|
||||
os.path.join(project_root, 'tf-psa-crypto', 'tests')]
|
||||
else:
|
||||
directories = [os.path.join(project_root, 'tests')]
|
||||
|
||||
directories = [os.path.relpath(p) for p in directories]
|
||||
return directories
|
||||
|
||||
def walk_all(self):
|
||||
"""Iterate over all named test cases."""
|
||||
test_directories = self.collect_test_directories()
|
||||
for directory in test_directories:
|
||||
for data_file_name in glob.glob(os.path.join(directory, 'suites',
|
||||
'*.data')):
|
||||
self.walk_test_suite(data_file_name)
|
||||
|
||||
for sh_file in ['ssl-opt.sh', 'compat.sh']:
|
||||
sh_file = os.path.join(directory, sh_file)
|
||||
if os.path.isfile(sh_file):
|
||||
self.collect_from_script(sh_file)
|
||||
|
||||
class TestDescriptions(TestDescriptionExplorer):
|
||||
"""Collect the available test cases."""
|
||||
|
||||
def __init__(self):
|
||||
super().__init__()
|
||||
self.descriptions = set()
|
||||
|
||||
def process_test_case(self, _per_file_state,
|
||||
file_name, _line_number, description):
|
||||
"""Record an available test case."""
|
||||
base_name = re.sub(r'\.[^.]*$', '', re.sub(r'.*/', '', file_name))
|
||||
key = ';'.join([base_name, description.decode('utf-8')])
|
||||
self.descriptions.add(key)
|
||||
|
||||
def collect_available_test_cases():
|
||||
"""Collect the available test cases."""
|
||||
explorer = TestDescriptions()
|
||||
explorer.walk_all()
|
||||
return sorted(explorer.descriptions)
|
||||
297
vendor/mbedtls/framework/scripts/mbedtls_framework/config_checks_generator.py
vendored
Normal file
297
vendor/mbedtls/framework/scripts/mbedtls_framework/config_checks_generator.py
vendored
Normal file
@@ -0,0 +1,297 @@
|
||||
"""Generate C preprocessor code to check for bad configurations.
|
||||
|
||||
The headers are meant to be included in a specific way in PROJECT_config.c.
|
||||
See framework/docs/architecture/config-check-framework.md for information.
|
||||
"""
|
||||
|
||||
## Copyright The Mbed TLS Contributors
|
||||
## SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
|
||||
import argparse
|
||||
import enum
|
||||
import os
|
||||
import posixpath
|
||||
import re
|
||||
import sys
|
||||
import textwrap
|
||||
import typing
|
||||
from typing import Iterator, List, Optional
|
||||
|
||||
from . import build_tree
|
||||
from . import typing_util
|
||||
|
||||
|
||||
class Position(enum.Enum):
|
||||
BEFORE = 0 # Before build_info.h
|
||||
USER = 1 # Just after reading PROJECT_CONFIG_FILE (*config.h) and PROJECT_USER_CONFIG_FILE
|
||||
FINAL = 2 # After *adjust*.h and the rest of build_info.h
|
||||
|
||||
|
||||
class Checker:
|
||||
"""Description of checks for one option.
|
||||
|
||||
By default, this class triggers an error if the option is set after
|
||||
reading the user configuration. To change the behavior, override
|
||||
the methods `before`, `user` and `final` as needed.
|
||||
"""
|
||||
|
||||
def __init__(self, name: str, suggestion: str = '') -> None:
|
||||
"""Construct a checker for the given preprocessor macro name.
|
||||
|
||||
If suggestion is given, it is appended to the error message.
|
||||
It should be a short sentence intended for human readers.
|
||||
This sentence follows a sentence like "<macro_name> is not
|
||||
a valid configuration option".
|
||||
"""
|
||||
self.name = name
|
||||
self.suggestion = suggestion
|
||||
|
||||
def _basic_message(self) -> str:
|
||||
"""The first sentence of the message to display on error.
|
||||
|
||||
It should end with a full stop or other sentence-ending punctuation.
|
||||
"""
|
||||
return f'{self.name} is not a valid configuration option.'
|
||||
|
||||
def message(self) -> str:
|
||||
"""The message to display on error."""
|
||||
message = self._basic_message()
|
||||
if self.suggestion:
|
||||
message += ' Suggestion: ' + self.suggestion
|
||||
return message
|
||||
|
||||
def _quoted_message(self) -> str:
|
||||
"""Quote message() in double quotes. Useful for #error directives."""
|
||||
return ('"' +
|
||||
str.replace(str.replace(self.message(),
|
||||
'\\', '\\\\'),
|
||||
'"', '\\"') +
|
||||
'"')
|
||||
|
||||
def before(self, _prefix: str) -> str:
|
||||
"""C code to inject before including the config."""
|
||||
#pylint: disable=no-self-use
|
||||
# Derived classes will add content where needed.
|
||||
return ''
|
||||
|
||||
def user(self, _prefix: str) -> str:
|
||||
"""C code to inject immediately after including the user config."""
|
||||
return f'''
|
||||
#if defined({self.name})
|
||||
# error {self._quoted_message()}
|
||||
#endif
|
||||
'''
|
||||
|
||||
def final(self, _prefix: str) -> str:
|
||||
"""C code to inject after finalizing the config."""
|
||||
#pylint: disable=no-self-use
|
||||
# Derived classes will add content where needed.
|
||||
return ''
|
||||
|
||||
def code(self, position: Position, prefix: str) -> str:
|
||||
"""C code to inject at the given position.
|
||||
|
||||
Use the given prefix for auxiliary macro names.
|
||||
"""
|
||||
methods = {
|
||||
Position.BEFORE: self.before,
|
||||
Position.USER: self.user,
|
||||
Position.FINAL: self.final,
|
||||
}
|
||||
method = methods[position]
|
||||
snippet = method(prefix)
|
||||
return textwrap.dedent(snippet)
|
||||
|
||||
|
||||
class Internal(Checker):
|
||||
"""Checker for an internal-only option."""
|
||||
|
||||
|
||||
class SubprojectInternal(Checker):
|
||||
"""Checker for an internal macro of a subproject."""
|
||||
|
||||
# must be overridden in child classes
|
||||
SUBPROJECT = None #type: Optional[str]
|
||||
|
||||
def __init__(self, name: str, suggestion: str = '') -> None:
|
||||
super().__init__(name, suggestion)
|
||||
if self.SUBPROJECT is None:
|
||||
raise ValueError('No subproject specified for ' + name)
|
||||
self.subproject = self.SUBPROJECT #type: str
|
||||
|
||||
def _basic_message(self) -> str:
|
||||
return f'{self.name} is an internal macro of {self.subproject} and may not be configured.'
|
||||
|
||||
def before(self, prefix: str) -> str:
|
||||
return f'''
|
||||
#if defined({self.name})
|
||||
# define {prefix}_WASSET_{self.name} 1
|
||||
#else
|
||||
# define {prefix}_WASSET_{self.name} 0
|
||||
#endif
|
||||
#undef {self.name}
|
||||
'''
|
||||
|
||||
def user(self, prefix: str) -> str:
|
||||
return f'''
|
||||
#if defined({self.name})
|
||||
# error {self._quoted_message()}
|
||||
#endif
|
||||
#if {prefix}_WASSET_{self.name}
|
||||
# define {self.name}
|
||||
#endif
|
||||
#undef {prefix}_WASSET_{self.name}
|
||||
'''
|
||||
|
||||
|
||||
class SubprojectOption(SubprojectInternal):
|
||||
"""Checker for a configuration option of a subproject."""
|
||||
|
||||
def _basic_message(self) -> str:
|
||||
return f'{self.name} must be configured in {self.subproject}.'
|
||||
|
||||
def user(self, prefix: str) -> str:
|
||||
return f'''
|
||||
#if defined({self.name}) && !{prefix}_WASSET_{self.name}
|
||||
# error {self._quoted_message()}
|
||||
#endif
|
||||
#if {prefix}_WASSET_{self.name}
|
||||
# define {self.name}
|
||||
#endif
|
||||
#undef {prefix}_WASSET_{self.name}
|
||||
'''
|
||||
|
||||
|
||||
class Removed(Checker):
|
||||
"""Checker for an option that has been removed."""
|
||||
|
||||
def __init__(self, name: str, version: str, suggestion: str = '') -> None:
|
||||
super().__init__(name, suggestion)
|
||||
self.version = version
|
||||
|
||||
def _basic_message(self) -> str:
|
||||
"""The first sentence of the message to display on error.
|
||||
|
||||
It should end with a full stop or other sentence-ending punctuation.
|
||||
"""
|
||||
return f'{self.name} was removed in {self.version}.'
|
||||
|
||||
def user(self, prefix: str) -> str:
|
||||
"""C code to inject immediately after including the user config."""
|
||||
# A removed option is forbidden, just like an internal option.
|
||||
# But since we're checking a macro that is not defined anywhere,
|
||||
# we need to tell check_names.py that this is a false positive.
|
||||
code = super().user(prefix)
|
||||
return re.sub(rf'^ *# *\w+.*\b{self.name}\b.*$',
|
||||
lambda m: m.group(0) + ' //no-check-names',
|
||||
code, flags=re.M)
|
||||
|
||||
|
||||
class BranchData(typing.NamedTuple):
|
||||
"""The relevant aspects of the configuration on a branch."""
|
||||
|
||||
# Subdirectory where the generated headers will be located.
|
||||
header_directory: str
|
||||
|
||||
# Prefix used for the generated headers' basename.
|
||||
header_prefix: str
|
||||
|
||||
# Prefix used for C preprocessor macros.
|
||||
project_cpp_prefix: str
|
||||
|
||||
# Options to check
|
||||
checkers: List[Checker]
|
||||
|
||||
|
||||
class HeaderGenerator:
|
||||
"""Generate a header to include before or after the user config."""
|
||||
|
||||
def __init__(self, branch_data: BranchData, position: Position) -> None:
|
||||
self.branch_data = branch_data
|
||||
self.position = position
|
||||
self.prefix = branch_data.project_cpp_prefix + '_CONFIG_CHECK'
|
||||
self.bypass_checks = self.prefix + '_BYPASS'
|
||||
|
||||
def write_stanza(self, out: typing_util.Writable, checker: Checker) -> None:
|
||||
"""Write the part of the output corresponding to one config option."""
|
||||
code = checker.code(self.position, self.prefix)
|
||||
out.write(code)
|
||||
|
||||
def write_content(self, out: typing_util.Writable) -> None:
|
||||
"""Write the output for all config options to be processed."""
|
||||
for checker in self.branch_data.checkers:
|
||||
self.write_stanza(out, checker)
|
||||
|
||||
def output_file_name(self) -> str:
|
||||
"""The base name of the output file."""
|
||||
return ''.join([self.branch_data.header_prefix,
|
||||
'config_check_',
|
||||
self.position.name.lower(),
|
||||
'.h'])
|
||||
|
||||
def write(self, directory: str) -> None:
|
||||
"""Write the whole output file."""
|
||||
basename = self.output_file_name()
|
||||
with open(os.path.join(directory, basename), 'w') as out:
|
||||
out.write(f'''\
|
||||
/* {basename} (generated part of {self.branch_data.header_prefix}config.c). */
|
||||
/* Automatically generated by {os.path.basename(sys.argv[0])}. Do not edit! */
|
||||
|
||||
#if !defined({self.bypass_checks}) //no-check-names
|
||||
|
||||
/* *INDENT-OFF* */
|
||||
''')
|
||||
self.write_content(out)
|
||||
out.write(f'''
|
||||
/* *INDENT-ON* */
|
||||
|
||||
#endif /* !defined({self.bypass_checks}) */ //no-check-names
|
||||
|
||||
/* End of automatically generated {basename} */
|
||||
''')
|
||||
|
||||
|
||||
def generate_header_files(branch_data: BranchData,
|
||||
directory: str,
|
||||
list_only: bool = False) -> Iterator[str]:
|
||||
"""Generate the header files to include before and after *config.h."""
|
||||
for position in Position:
|
||||
generator = HeaderGenerator(branch_data, position)
|
||||
# Make sure to output a path with / even on Windows, so that
|
||||
# it can be consumed by tools such as CMake.
|
||||
yield posixpath.join(directory, generator.output_file_name())
|
||||
if not list_only:
|
||||
generator.write(directory)
|
||||
|
||||
|
||||
def main(branch_data: BranchData) -> None:
|
||||
root = build_tree.guess_project_root()
|
||||
# Is root the current directory? The safe default is no, so compare
|
||||
# the paths, rather than calling `os.samefile()` which can have false
|
||||
# positives and can fail in edge cases.
|
||||
if root == os.getcwd():
|
||||
# Be nice and use a relative path when it's simple to do so.
|
||||
# (build_tree.guess_project_root() should probably do this, actually.)
|
||||
# This is not only nice to humans, but also necessary for
|
||||
# `make_generated_files.py --root DIR --check`: it calls
|
||||
# this script with `--list` and expects a path that is relative
|
||||
# to DIR, not an absolute path that is under the project root.
|
||||
root = os.curdir
|
||||
parser = argparse.ArgumentParser(description=__doc__)
|
||||
parser.add_argument('--list', action='store_true',
|
||||
help='List generated files and exit')
|
||||
parser.add_argument('--list-for-cmake', action='store_true',
|
||||
help='List generated files in CMake-friendly format and exit')
|
||||
parser.add_argument('output_directory', metavar='DIR', nargs='?',
|
||||
default=posixpath.join(root, branch_data.header_directory),
|
||||
help='output file location (default: %(default)s)')
|
||||
options = parser.parse_args()
|
||||
list_only = options.list or options.list_for_cmake
|
||||
output_files = list(generate_header_files(branch_data,
|
||||
options.output_directory,
|
||||
list_only=list_only))
|
||||
if options.list_for_cmake:
|
||||
sys.stdout.write(';'.join(output_files))
|
||||
elif options.list:
|
||||
for filename in output_files:
|
||||
print(filename)
|
||||
507
vendor/mbedtls/framework/scripts/mbedtls_framework/config_common.py
vendored
Normal file
507
vendor/mbedtls/framework/scripts/mbedtls_framework/config_common.py
vendored
Normal file
@@ -0,0 +1,507 @@
|
||||
"""Mbed TLS and PSA configuration file manipulation library
|
||||
"""
|
||||
|
||||
## Copyright The Mbed TLS Contributors
|
||||
## SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
##
|
||||
|
||||
import argparse
|
||||
import os
|
||||
import re
|
||||
import shutil
|
||||
import sys
|
||||
|
||||
from abc import ABCMeta
|
||||
|
||||
|
||||
class Setting:
|
||||
"""Representation of one Mbed TLS mbedtls_config.h or PSA crypto_config.h setting.
|
||||
|
||||
Fields:
|
||||
* name: the symbol name ('MBEDTLS_xxx').
|
||||
* value: the value of the macro. The empty string for a plain #define
|
||||
with no value.
|
||||
* active: True if name is defined, False if a #define for name is
|
||||
present in mbedtls_config.h but commented out.
|
||||
* section: the name of the section that contains this symbol.
|
||||
* configfile: the representation of the configuration file where the setting is defined
|
||||
"""
|
||||
# pylint: disable=too-few-public-methods, too-many-arguments
|
||||
def __init__(self, configfile, active, name, value='', section=None):
|
||||
self.active = active
|
||||
self.name = name
|
||||
self.value = value
|
||||
self.section = section
|
||||
self.configfile = configfile
|
||||
|
||||
|
||||
class Config:
|
||||
"""Representation of the Mbed TLS and PSA configuration.
|
||||
|
||||
In the documentation of this class, a symbol is said to be *active*
|
||||
if there is a #define for it that is not commented out, and *known*
|
||||
if there is a #define for it whether commented out or not.
|
||||
|
||||
This class supports the following protocols:
|
||||
* `name in config` is `True` if the symbol `name` is active, `False`
|
||||
otherwise (whether `name` is inactive or not known).
|
||||
* `config[name]` is the value of the macro `name`. If `name` is inactive,
|
||||
raise `KeyError` (even if `name` is known).
|
||||
* `config[name] = value` sets the value associated to `name`. `name`
|
||||
must be known, but does not need to be set. This does not cause
|
||||
name to become set.
|
||||
"""
|
||||
|
||||
def __init__(self):
|
||||
self.settings = {}
|
||||
self.configfiles = []
|
||||
|
||||
def __contains__(self, name):
|
||||
"""True if the given symbol is active (i.e. set).
|
||||
|
||||
False if the given symbol is not set, even if a definition
|
||||
is present but commented out.
|
||||
"""
|
||||
return name in self.settings and self.settings[name].active
|
||||
|
||||
def all(self, *names):
|
||||
"""True if all the elements of names are active (i.e. set)."""
|
||||
return all(name in self for name in names)
|
||||
|
||||
def any(self, *names):
|
||||
"""True if at least one symbol in names are active (i.e. set)."""
|
||||
return any(name in self for name in names)
|
||||
|
||||
def known(self, name):
|
||||
"""True if a #define for name is present, whether it's commented out or not."""
|
||||
return name in self.settings
|
||||
|
||||
def __getitem__(self, name):
|
||||
"""Get the value of name, i.e. what the preprocessor symbol expands to.
|
||||
|
||||
If name is not known, raise KeyError. name does not need to be active.
|
||||
"""
|
||||
return self.settings[name].value
|
||||
|
||||
def get(self, name, default=None):
|
||||
"""Get the value of name. If name is inactive (not set), return default.
|
||||
|
||||
If a #define for name is present and not commented out, return
|
||||
its expansion, even if this is the empty string.
|
||||
|
||||
If a #define for name is present but commented out, return default.
|
||||
"""
|
||||
if name in self:
|
||||
return self.settings[name].value
|
||||
else:
|
||||
return default
|
||||
|
||||
def get_matching(self, regexs, only_enabled):
|
||||
"""Get all symbols matching one of the regexs."""
|
||||
if not regexs:
|
||||
return
|
||||
regex = re.compile('|'.join(regexs))
|
||||
for setting in self.settings.values():
|
||||
if regex.search(setting.name):
|
||||
if setting.active or not only_enabled:
|
||||
yield setting.name
|
||||
|
||||
def __setitem__(self, name, value):
|
||||
"""If name is known, set its value.
|
||||
|
||||
If name is not known, raise KeyError.
|
||||
"""
|
||||
setting = self.settings[name]
|
||||
if setting.value != value:
|
||||
setting.configfile.modified = True
|
||||
|
||||
setting.value = value
|
||||
|
||||
def set(self, name, value=None):
|
||||
"""Set name to the given value and make it active.
|
||||
|
||||
If value is None and name is already known, don't change its value.
|
||||
If value is None and name is not known, set its value.
|
||||
"""
|
||||
if name in self.settings:
|
||||
setting = self.settings[name]
|
||||
if (value is not None and setting.value != value) or not setting.active:
|
||||
setting.configfile.modified = True
|
||||
if value is not None:
|
||||
setting.value = value
|
||||
setting.active = True
|
||||
else:
|
||||
configfile = self._get_configfile(name)
|
||||
self.settings[name] = Setting(configfile, True, name, value=value)
|
||||
configfile.modified = True
|
||||
|
||||
def unset(self, name):
|
||||
"""Make name unset (inactive).
|
||||
|
||||
name remains known if it was known before.
|
||||
"""
|
||||
if name not in self.settings:
|
||||
return
|
||||
|
||||
setting = self.settings[name]
|
||||
# Check if modifying the config file
|
||||
if setting.active:
|
||||
setting.configfile.modified = True
|
||||
|
||||
setting.active = False
|
||||
|
||||
def adapt(self, adapter):
|
||||
"""Run adapter on each known symbol and (de)activate it accordingly.
|
||||
|
||||
`adapter` must be a function that returns a boolean. It is called as
|
||||
`adapter(name, value, active)` for each setting, where
|
||||
`value` is the macro's expansion (possibly empty), and `active` is
|
||||
`True` if `name` is set and `False` if `name` is known but unset.
|
||||
If `adapter` returns `True`, then set `name` (i.e. make it active),
|
||||
otherwise unset `name` (i.e. make it known but inactive).
|
||||
"""
|
||||
for setting in self.settings.values():
|
||||
is_active = setting.active
|
||||
setting.active = adapter(setting.name, setting.value,
|
||||
setting.active)
|
||||
# Check if modifying the config file
|
||||
if setting.active != is_active:
|
||||
setting.configfile.modified = True
|
||||
|
||||
def change_matching(self, regexs, enable):
|
||||
"""Change all symbols matching one of the regexs to the desired state."""
|
||||
if not regexs:
|
||||
return
|
||||
regex = re.compile('|'.join(regexs))
|
||||
for setting in self.settings.values():
|
||||
if regex.search(setting.name):
|
||||
# Check if modifying the config file
|
||||
if setting.active != enable:
|
||||
setting.configfile.modified = True
|
||||
setting.active = enable
|
||||
|
||||
def _get_configfile(self, name=None):
|
||||
"""Get the representation of the configuration file name belongs to
|
||||
|
||||
If the configuration is spread among several configuration files, this
|
||||
function may need to be overridden for the case of an unknown setting.
|
||||
"""
|
||||
|
||||
if name and name in self.settings:
|
||||
return self.settings[name].configfile
|
||||
return self.configfiles[0]
|
||||
|
||||
def write(self, filename=None):
|
||||
"""Write the whole configuration to the file(s) it was read from.
|
||||
|
||||
If filename is specified, write to this file(s) instead.
|
||||
"""
|
||||
|
||||
for configfile in self.configfiles:
|
||||
configfile.write(self.settings, filename)
|
||||
|
||||
def filename(self, name=None):
|
||||
"""Get the name of the config file where the setting name is defined."""
|
||||
|
||||
return self._get_configfile(name).filename
|
||||
|
||||
def backup(self, suffix='.bak'):
|
||||
"""Back up the configuration file."""
|
||||
|
||||
for configfile in self.configfiles:
|
||||
configfile.backup(suffix)
|
||||
|
||||
def restore(self):
|
||||
"""Restore the configuration file."""
|
||||
|
||||
for configfile in self.configfiles:
|
||||
configfile.restore()
|
||||
|
||||
|
||||
class ConfigFile(metaclass=ABCMeta):
|
||||
"""Representation of a configuration file."""
|
||||
|
||||
def __init__(self, default_path, name, filename=None):
|
||||
"""Check if the config file exists."""
|
||||
if filename is None:
|
||||
for candidate in default_path:
|
||||
if os.path.lexists(candidate):
|
||||
filename = candidate
|
||||
break
|
||||
|
||||
if not os.path.lexists(filename):
|
||||
raise FileNotFoundError(f'{name} configuration file not found: '
|
||||
f'{filename if filename else default_path}')
|
||||
|
||||
self.filename = filename
|
||||
self.templates = []
|
||||
self.current_section = None
|
||||
self.inclusion_guard = None
|
||||
self.modified = False
|
||||
self._backupname = None
|
||||
self._own_backup = False
|
||||
|
||||
_define_line_regexp = (r'(?P<indentation>\s*)' +
|
||||
r'(?P<commented_out>(//\s*)?)' +
|
||||
r'(?P<define>#\s*define\s+)' +
|
||||
r'(?P<name>\w+)' +
|
||||
r'(?P<arguments>(?:\((?:\w|\s|,)*\))?)' +
|
||||
r'(?P<separator>\s*)' +
|
||||
r'(?P<value>.*)')
|
||||
_ifndef_line_regexp = r'#ifndef (?P<inclusion_guard>\w+)'
|
||||
_section_line_regexp = (r'\s*/?\*+\s*[\\@]name\s+SECTION:\s*' +
|
||||
r'(?P<section>.*)[ */]*')
|
||||
_config_line_regexp = re.compile(r'|'.join([_define_line_regexp,
|
||||
_ifndef_line_regexp,
|
||||
_section_line_regexp]))
|
||||
def _parse_line(self, line):
|
||||
"""Parse a line in the config file, save the templates representing the lines
|
||||
and return the corresponding setting element.
|
||||
"""
|
||||
|
||||
line = line.rstrip('\r\n')
|
||||
m = re.match(self._config_line_regexp, line)
|
||||
if m is None:
|
||||
self.templates.append(line)
|
||||
return None
|
||||
elif m.group('section'):
|
||||
self.current_section = m.group('section')
|
||||
self.templates.append(line)
|
||||
return None
|
||||
elif m.group('inclusion_guard') and self.inclusion_guard is None:
|
||||
self.inclusion_guard = m.group('inclusion_guard')
|
||||
self.templates.append(line)
|
||||
return None
|
||||
else:
|
||||
active = not m.group('commented_out')
|
||||
name = m.group('name')
|
||||
value = m.group('value')
|
||||
if name == self.inclusion_guard and value == '':
|
||||
# The file double-inclusion guard is not an option.
|
||||
self.templates.append(line)
|
||||
return None
|
||||
template = (name,
|
||||
m.group('indentation'),
|
||||
m.group('define') + name +
|
||||
m.group('arguments') + m.group('separator'))
|
||||
self.templates.append(template)
|
||||
|
||||
return (active, name, value, self.current_section)
|
||||
|
||||
def parse_file(self):
|
||||
"""Parse the whole file and return the settings."""
|
||||
|
||||
with open(self.filename, 'r', encoding='utf-8') as file:
|
||||
for line in file:
|
||||
setting = self._parse_line(line)
|
||||
if setting is not None:
|
||||
yield setting
|
||||
self.current_section = None
|
||||
|
||||
#pylint: disable=no-self-use
|
||||
def _format_template(self, setting, indent, middle):
|
||||
"""Build a line for the config file for the given setting.
|
||||
|
||||
The line has the form "<indent>#define <name> <value>"
|
||||
where <middle> is "#define <name> ".
|
||||
"""
|
||||
|
||||
value = setting.value
|
||||
if value is None:
|
||||
value = ''
|
||||
# Normally the whitespace to separate the symbol name from the
|
||||
# value is part of middle, and there's no whitespace for a symbol
|
||||
# with no value. But if a symbol has been changed from having a
|
||||
# value to not having one, the whitespace is wrong, so fix it.
|
||||
if value:
|
||||
if middle[-1] not in '\t ':
|
||||
middle += ' '
|
||||
else:
|
||||
middle = middle.rstrip()
|
||||
return ''.join([indent,
|
||||
'' if setting.active else '//',
|
||||
middle,
|
||||
value]).rstrip()
|
||||
|
||||
def write_to_stream(self, settings, output):
|
||||
"""Write the whole configuration to output."""
|
||||
|
||||
for template in self.templates:
|
||||
if isinstance(template, str):
|
||||
line = template
|
||||
else:
|
||||
name, indent, middle = template
|
||||
line = self._format_template(settings[name], indent, middle)
|
||||
output.write(line + '\n')
|
||||
|
||||
def write(self, settings, filename=None):
|
||||
"""Write the whole configuration to the file it was read from.
|
||||
|
||||
If filename is specified, write to this file instead.
|
||||
"""
|
||||
|
||||
if filename is None:
|
||||
filename = self.filename
|
||||
|
||||
# Not modified so no need to write to the file
|
||||
if not self.modified and filename == self.filename:
|
||||
return
|
||||
|
||||
with open(filename, 'w', encoding='utf-8') as output:
|
||||
self.write_to_stream(settings, output)
|
||||
|
||||
def backup(self, suffix='.bak'):
|
||||
"""Back up the configuration file.
|
||||
|
||||
If the backup file already exists, it is presumed to be the desired backup,
|
||||
so don't make another backup.
|
||||
"""
|
||||
if self._backupname:
|
||||
return
|
||||
|
||||
self._backupname = self.filename + suffix
|
||||
if os.path.exists(self._backupname):
|
||||
self._own_backup = False
|
||||
else:
|
||||
self._own_backup = True
|
||||
shutil.copy(self.filename, self._backupname)
|
||||
|
||||
def restore(self):
|
||||
"""Restore the configuration file.
|
||||
|
||||
Only delete the backup file if it was created earlier.
|
||||
"""
|
||||
if not self._backupname:
|
||||
return
|
||||
|
||||
if self._own_backup:
|
||||
shutil.move(self._backupname, self.filename)
|
||||
else:
|
||||
shutil.copy(self._backupname, self.filename)
|
||||
|
||||
self._backupname = None
|
||||
|
||||
|
||||
class ConfigTool(metaclass=ABCMeta):
|
||||
"""Command line config manipulation tool.
|
||||
|
||||
Custom parser options can be added by overriding 'custom_parser_options'.
|
||||
"""
|
||||
|
||||
def __init__(self, default_file_path):
|
||||
"""Create parser for config manipulation tool.
|
||||
|
||||
:param default_file_path: Default configuration file path
|
||||
"""
|
||||
|
||||
self.parser = argparse.ArgumentParser(description="""
|
||||
Configuration file manipulation tool.""")
|
||||
self.subparsers = self.parser.add_subparsers(dest='command',
|
||||
title='Commands')
|
||||
self._common_parser_options(default_file_path)
|
||||
self.custom_parser_options()
|
||||
self.args = self.parser.parse_args()
|
||||
self.config = Config() # Make the pylint happy
|
||||
|
||||
def add_adapter(self, name, function, description):
|
||||
"""Creates a command in the tool for a configuration adapter."""
|
||||
|
||||
subparser = self.subparsers.add_parser(name, help=description)
|
||||
subparser.set_defaults(adapter=function)
|
||||
|
||||
def _common_parser_options(self, default_file_path):
|
||||
# pylint: disable=too-many-branches
|
||||
"""Common parser options for config manipulation tool."""
|
||||
|
||||
self.parser.add_argument(
|
||||
'--file', '-f',
|
||||
help="""File to read (and modify if requested). Default: {}.
|
||||
""".format(default_file_path))
|
||||
self.parser.add_argument(
|
||||
'--force', '-o',
|
||||
action='store_true',
|
||||
help="""For the set command, if SYMBOL is not present, add a definition for it.""")
|
||||
self.parser.add_argument(
|
||||
'--write', '-w',
|
||||
metavar='FILE',
|
||||
help="""File to write to instead of the input file.""")
|
||||
|
||||
parser_get = self.subparsers.add_parser(
|
||||
'get',
|
||||
help="""Find the value of SYMBOL and print it. Exit with
|
||||
status 0 if a #define for SYMBOL is found, 1 otherwise.""")
|
||||
parser_get.add_argument('symbol', metavar='SYMBOL')
|
||||
parser_set = self.subparsers.add_parser(
|
||||
'set',
|
||||
help="""Set SYMBOL to VALUE. If VALUE is omitted, just uncomment
|
||||
the #define for SYMBOL. Error out of a line defining
|
||||
SYMBOL (commented or not) is not found, unless --force is passed. """)
|
||||
parser_set.add_argument('symbol', metavar='SYMBOL')
|
||||
parser_set.add_argument('value', metavar='VALUE', nargs='?', default='')
|
||||
parser_set_all = self.subparsers.add_parser(
|
||||
'set-all',
|
||||
help="""Uncomment all #define whose name contains a match for REGEX.""")
|
||||
parser_set_all.add_argument('regexs', metavar='REGEX', nargs='*')
|
||||
parser_unset = self.subparsers.add_parser(
|
||||
'unset',
|
||||
help="""Comment out the #define for SYMBOL. Do nothing if none is present.""")
|
||||
parser_unset.add_argument('symbol', metavar='SYMBOL')
|
||||
parser_unset_all = self.subparsers.add_parser(
|
||||
'unset-all',
|
||||
help="""Comment out all #define whose name contains a match for REGEX.""")
|
||||
parser_unset_all.add_argument('regexs', metavar='REGEX', nargs='*')
|
||||
parser_get_all = self.subparsers.add_parser(
|
||||
'get-all',
|
||||
help="""Get all #define whose name contains a match for REGEX.""")
|
||||
parser_get_all.add_argument('regexs', metavar='REGEX', nargs='*')
|
||||
parser_get_all_enabled = self.subparsers.add_parser(
|
||||
'get-all-enabled',
|
||||
help="""Get all enabled #define whose name contains a match for REGEX.""")
|
||||
parser_get_all_enabled.add_argument('regexs', metavar='REGEX', nargs='*')
|
||||
|
||||
|
||||
def custom_parser_options(self):
|
||||
"""Adds custom options for the parser. Designed for overridden by descendant."""
|
||||
pass
|
||||
|
||||
def main(self):
|
||||
# pylint: disable=too-many-branches
|
||||
"""Common main fuction for config manipulation tool."""
|
||||
|
||||
args = self.args
|
||||
config = self.config
|
||||
|
||||
if args.command is None:
|
||||
self.parser.print_help()
|
||||
return 1
|
||||
if args.command == 'get':
|
||||
if args.symbol in config:
|
||||
value = config[args.symbol]
|
||||
if value:
|
||||
sys.stdout.write(value + '\n')
|
||||
return 0 if args.symbol in config else 1
|
||||
elif args.command == 'get-all':
|
||||
match_list = config.get_matching(args.regexs, False)
|
||||
sys.stdout.write("\n".join(match_list))
|
||||
elif args.command == 'get-all-enabled':
|
||||
match_list = config.get_matching(args.regexs, True)
|
||||
sys.stdout.write("\n".join(match_list))
|
||||
elif args.command == 'set':
|
||||
if not args.force and args.symbol not in config.settings:
|
||||
sys.stderr.write(
|
||||
"A #define for the symbol {} was not found in {}\n"
|
||||
.format(args.symbol,
|
||||
config.filename(args.symbol)))
|
||||
return 1
|
||||
config.set(args.symbol, value=args.value)
|
||||
elif args.command == 'set-all':
|
||||
config.change_matching(args.regexs, True)
|
||||
elif args.command == 'unset':
|
||||
config.unset(args.symbol)
|
||||
elif args.command == 'unset-all':
|
||||
config.change_matching(args.regexs, False)
|
||||
else:
|
||||
config.adapt(args.adapter)
|
||||
config.write(args.write)
|
||||
|
||||
return 0
|
||||
59
vendor/mbedtls/framework/scripts/mbedtls_framework/config_history.py
vendored
Normal file
59
vendor/mbedtls/framework/scripts/mbedtls_framework/config_history.py
vendored
Normal file
@@ -0,0 +1,59 @@
|
||||
"""Historical information about the library configuration.
|
||||
|
||||
Note: this module is deprecated. Use config_macros.py instead.
|
||||
"""
|
||||
|
||||
## Copyright The Mbed TLS Contributors
|
||||
## SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
|
||||
import glob
|
||||
import os
|
||||
import re
|
||||
from typing import Dict, FrozenSet
|
||||
|
||||
from . import build_tree
|
||||
|
||||
class ConfigHistory:
|
||||
"""Historical information about the library configuration.
|
||||
"""
|
||||
|
||||
@staticmethod
|
||||
def load_options(filename: str) -> FrozenSet[str]:
|
||||
"""Load the options from the given file.
|
||||
|
||||
The file must contain one option name per line, with no whitespace.
|
||||
"""
|
||||
with open(filename) as inp:
|
||||
return frozenset(inp.read().splitlines())
|
||||
|
||||
def load_history_files(self,
|
||||
variety: str,
|
||||
exclude_dict: Dict[str, Dict[str, FrozenSet[str]]]
|
||||
) -> Dict[str, Dict[str, FrozenSet[str]]]:
|
||||
"""Load all files containing macro lists of the given variety"""
|
||||
data = {} #type: Dict[str, Dict[str, FrozenSet[str]]]
|
||||
glob_pattern = os.path.join(self._history_dir,
|
||||
f'config-{variety}-*-*.txt')
|
||||
for filename in sorted(glob.glob(glob_pattern)):
|
||||
basename = os.path.splitext(os.path.basename(filename))[0]
|
||||
m = re.match(r'config-\w+-(.*?)-(.*)', basename)
|
||||
assert m is not None
|
||||
(product, version) = m.groups()
|
||||
options = self.load_options(filename)
|
||||
exclude = exclude_dict.get(product, {}).get(version, frozenset())
|
||||
data.setdefault(product, {})[version] = options - exclude
|
||||
return data
|
||||
|
||||
def __init__(self) -> None:
|
||||
"""Load all files containing historical option lists."""
|
||||
self._history_dir = os.path.join(build_tree.framework_root(), 'history')
|
||||
self._options = self.load_history_files('options', {})
|
||||
self._internal = self.load_history_files('adjust', self._options)
|
||||
|
||||
def options(self, product: str, version: str) -> FrozenSet[str]:
|
||||
"""The set of options in the given product version."""
|
||||
return self._options[product][version]
|
||||
|
||||
def internal(self, product: str, version: str) -> FrozenSet[str]:
|
||||
"""The set of internal option-like macros in the given product version."""
|
||||
return self._internal[product][version]
|
||||
180
vendor/mbedtls/framework/scripts/mbedtls_framework/config_macros.py
vendored
Normal file
180
vendor/mbedtls/framework/scripts/mbedtls_framework/config_macros.py
vendored
Normal file
@@ -0,0 +1,180 @@
|
||||
"""Information about configuration macros and derived macros."""
|
||||
|
||||
## Copyright The Mbed TLS Contributors
|
||||
## SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
|
||||
import glob
|
||||
import os
|
||||
import re
|
||||
from typing import FrozenSet, Iterable, Iterator, List
|
||||
|
||||
from . import build_tree
|
||||
from . import generate_files_helper
|
||||
|
||||
|
||||
class ConfigMacros:
|
||||
"""Information about configuration macros and derived macros."""
|
||||
|
||||
def __init__(self, public: FrozenSet[str], adjusted: FrozenSet[str]) -> None:
|
||||
self._public = public
|
||||
self._internal = adjusted - public
|
||||
|
||||
def options(self) -> FrozenSet[str]:
|
||||
"""The set of configuration options in this product."""
|
||||
return self._public
|
||||
|
||||
def internal(self) -> FrozenSet[str]:
|
||||
"""The set of internal option-like macros in this product."""
|
||||
return self._internal
|
||||
|
||||
@staticmethod
|
||||
def _load_file(filename: str) -> FrozenSet[str]:
|
||||
"""Load macro names from the given file."""
|
||||
with open(filename, encoding='ascii') as input_:
|
||||
return frozenset(line.strip()
|
||||
for line in input_)
|
||||
|
||||
|
||||
class Current(ConfigMacros, generate_files_helper.Generator):
|
||||
"""Information about config-like macros parsed from the source code."""
|
||||
|
||||
_SHADOW_FILE = 'scripts/data_files/config-options-current.txt'
|
||||
|
||||
_PUBLIC_CONFIG_HEADERS = [
|
||||
'include/mbedtls/mbedtls_config.h',
|
||||
'include/psa/crypto_config.h',
|
||||
]
|
||||
|
||||
_ADJUST_CONFIG_HEADERS = [
|
||||
'include/**/*adjust*.h',
|
||||
'drivers/*/include/**/*adjust*.h',
|
||||
]
|
||||
|
||||
_DEFINE_RE = re.compile(r'[/ ]*# *define *([A-Z_a-z][0-9A-Z_a-z]*)')
|
||||
|
||||
def _list_files(self, patterns: Iterable[str]) -> Iterator[str]:
|
||||
"""Yield files matching the given glob patterns."""
|
||||
for pattern in patterns:
|
||||
yield from glob.glob(os.path.join(self._root, self._submodule,
|
||||
pattern),
|
||||
recursive=True)
|
||||
|
||||
def _search_file(self, filename: str) -> Iterator[str]:
|
||||
"""Yield macros defined in the given file."""
|
||||
with open(filename, encoding='utf-8') as input_:
|
||||
for line in input_:
|
||||
m = self._DEFINE_RE.match(line)
|
||||
if m:
|
||||
yield m.group(1)
|
||||
|
||||
def _search_files(self, patterns: Iterable[str]) -> FrozenSet[str]:
|
||||
"""Yield macros defined in files matching the given glob patterns."""
|
||||
return frozenset(element
|
||||
for filename in self._list_files(patterns)
|
||||
for element in self._search_file(filename))
|
||||
|
||||
def shadow_file_path(self) -> str:
|
||||
"""The path to the option list shadow file."""
|
||||
return os.path.join(self._root, self._submodule, self._SHADOW_FILE)
|
||||
|
||||
def __init__(self, submodule: str = '',
|
||||
shadow_missing_ok: bool = False) -> None:
|
||||
"""Look for macros defined in the given submodule's source tree.
|
||||
|
||||
If submodule is omitted or empty, look in the root module.
|
||||
|
||||
If shadow_missing_ok is true, treat a missing shadow file as
|
||||
if it was empty. This is intended for use only when regenerating
|
||||
the shadow file.
|
||||
"""
|
||||
self._root = build_tree.guess_project_root()
|
||||
self._submodule = submodule
|
||||
shadow_file = self.shadow_file_path()
|
||||
try:
|
||||
public = self._load_file(shadow_file)
|
||||
except FileNotFoundError:
|
||||
if not shadow_missing_ok:
|
||||
raise
|
||||
public = frozenset()
|
||||
adjusted = self._search_files(self._ADJUST_CONFIG_HEADERS)
|
||||
super().__init__(public, adjusted)
|
||||
|
||||
def live_config_options(self) -> FrozenSet[str]:
|
||||
"""Return config options from the config file (as opposed to the shadow file)."""
|
||||
return self._search_files(self._PUBLIC_CONFIG_HEADERS)
|
||||
|
||||
def is_shadow_file_up_to_date(self) -> bool:
|
||||
"""Whether the config options shadow file is up to date."""
|
||||
live = self.live_config_options()
|
||||
return live == self._public
|
||||
|
||||
def compare_shadow_file(self) -> str:
|
||||
"""Compare the option list shadow file with the live config file.
|
||||
|
||||
Return a string containing the names that are only found in one of
|
||||
them, in a diff-like format: a line prefixed by ``+`` if the name
|
||||
is missing from the shadow file, or by ``-`` if the name is only
|
||||
in the shadow file.
|
||||
"""
|
||||
live = self.live_config_options()
|
||||
diff = []
|
||||
for x in sorted(live | self._public):
|
||||
if x not in live:
|
||||
diff.append('+' + x + '\n')
|
||||
elif x not in self._public:
|
||||
diff.append('-' + x + '\n')
|
||||
return ''.join(diff)
|
||||
|
||||
def update_shadow_file(self, always_update: bool) -> None:
|
||||
"""Update the shadow file from the live config file.
|
||||
|
||||
If always_update is false and the shadow file already has the desired
|
||||
content, don't touch it.
|
||||
"""
|
||||
if not always_update and self.is_shadow_file_up_to_date():
|
||||
return
|
||||
with open(self.shadow_file_path(), 'w') as out:
|
||||
for name in sorted(self.live_config_options()):
|
||||
out.write(name + '\n')
|
||||
|
||||
# Implement the generate_files_helper.Generator interface
|
||||
def generator_name(self) -> str:
|
||||
"""Name as a generate_files_helper.Generator."""
|
||||
return 'options'
|
||||
|
||||
def target_files(self) -> List[str]:
|
||||
"""List the (single) generated file name."""
|
||||
return [os.path.join(self._submodule, self._SHADOW_FILE)]
|
||||
|
||||
def outdated_files(self) -> List[str]:
|
||||
"""List the (single) generated file name if it is out of date."""
|
||||
if self.is_shadow_file_up_to_date():
|
||||
return []
|
||||
else:
|
||||
return self.target_files()
|
||||
|
||||
def update(self, always: bool) -> None:
|
||||
"""Update the shadow file from the live config file."""
|
||||
self.update_shadow_file(always)
|
||||
|
||||
|
||||
class History(ConfigMacros):
|
||||
"""Information about config-like macros in a previous version.
|
||||
|
||||
Load files created by ``framework/scripts/save_config_history.sh``.
|
||||
"""
|
||||
|
||||
def _load_history_file(self, basename: str) -> FrozenSet[str]:
|
||||
"""Load macro names from the given file in the history directory."""
|
||||
filename = os.path.join(self._history_dir, basename)
|
||||
return self._load_file(filename)
|
||||
|
||||
def __init__(self, project: str, version: str) -> None:
|
||||
"""Read information about the given project at the given version.
|
||||
|
||||
The information must be present in history files in the framework.
|
||||
"""
|
||||
self._history_dir = os.path.join(build_tree.framework_root(), 'history')
|
||||
public = self._load_history_file(f'config-options-{project}-{version}.txt')
|
||||
adjusted = self._load_history_file(f'config-adjust-{project}-{version}.txt')
|
||||
super().__init__(public, adjusted)
|
||||
106
vendor/mbedtls/framework/scripts/mbedtls_framework/crypto_data_tests.py
vendored
Normal file
106
vendor/mbedtls/framework/scripts/mbedtls_framework/crypto_data_tests.py
vendored
Normal file
@@ -0,0 +1,106 @@
|
||||
"""Generate test data for cryptographic mechanisms.
|
||||
|
||||
This module is a work in progress, only implementing a few cases for now.
|
||||
"""
|
||||
|
||||
# Copyright The Mbed TLS Contributors
|
||||
# SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
#
|
||||
|
||||
import hashlib
|
||||
from typing import Callable, Dict, Iterator, List, Optional #pylint: disable=unused-import
|
||||
|
||||
from . import crypto_knowledge
|
||||
from . import psa_information
|
||||
from . import psa_test_case
|
||||
from . import test_case
|
||||
|
||||
|
||||
class HashPSALowLevel:
|
||||
"""Generate test cases for the PSA low-level hash interface."""
|
||||
|
||||
def __init__(self, info: psa_information.Information) -> None:
|
||||
self.info = info
|
||||
base_algorithms = sorted(info.constructors.algorithms)
|
||||
all_algorithms = \
|
||||
[crypto_knowledge.Algorithm(expr)
|
||||
for expr in info.constructors.generate_expressions(base_algorithms)]
|
||||
self.algorithms = \
|
||||
[alg
|
||||
for alg in all_algorithms
|
||||
if (not alg.is_wildcard and
|
||||
alg.can_do(crypto_knowledge.AlgorithmCategory.HASH))]
|
||||
|
||||
# CALCULATE[alg] = function to return the hash of its argument in hex
|
||||
# TO-DO: implement the None entries with a third-party library, because
|
||||
# hashlib might not have everything, depending on the Python version and
|
||||
# the underlying OpenSSL. On Ubuntu 16.04, truncated sha512 and sha3/shake
|
||||
# are not available. On Ubuntu 22.04, md2, md4 and ripemd160 are not
|
||||
# available. As of Python 3.14, Ascon is not available.
|
||||
CALCULATE = {
|
||||
'PSA_ALG_MD5': lambda data: hashlib.md5(data).hexdigest(),
|
||||
'PSA_ALG_RIPEMD160': None, #lambda data: hashlib.new('ripdemd160').hexdigest()
|
||||
'PSA_ALG_SHA_1': lambda data: hashlib.sha1(data).hexdigest(),
|
||||
'PSA_ALG_SHA_224': lambda data: hashlib.sha224(data).hexdigest(),
|
||||
'PSA_ALG_SHA_256': lambda data: hashlib.sha256(data).hexdigest(),
|
||||
'PSA_ALG_SHA_256_192': None, #lambda data: hashlib.new('sha256').hexdigest()[:48]
|
||||
'PSA_ALG_SHA_384': lambda data: hashlib.sha384(data).hexdigest(),
|
||||
'PSA_ALG_SHA_512': lambda data: hashlib.sha512(data).hexdigest(),
|
||||
'PSA_ALG_SHA_512_224': None, #lambda data: hashlib.new('sha512_224').hexdigest()
|
||||
'PSA_ALG_SHA_512_256': None, #lambda data: hashlib.new('sha512_256').hexdigest()
|
||||
'PSA_ALG_SHA3_224': None, #lambda data: hashlib.sha3_224(data).hexdigest(),
|
||||
'PSA_ALG_SHA3_256': None, #lambda data: hashlib.sha3_256(data).hexdigest(),
|
||||
'PSA_ALG_SHA3_384': None, #lambda data: hashlib.sha3_384(data).hexdigest(),
|
||||
'PSA_ALG_SHA3_512': None, #lambda data: hashlib.sha3_512(data).hexdigest(),
|
||||
'PSA_ALG_SHAKE128_192': None, #lambda data: hashlib.shake_128(data).hexdigest(24),
|
||||
'PSA_ALG_SHAKE128_256': None, #lambda data: hashlib.shake_128(data).hexdigest(32),
|
||||
'PSA_ALG_SHAKE256_256': None, #lambda data: hashlib.shake_256(data).hexdigest(32),
|
||||
'PSA_ALG_SHAKE256_512': None, #lambda data: hashlib.shake_256(data).hexdigest(64),
|
||||
'PSA_ALG_ASCON_HASH256': None, #lambda data: ascon.ascon_hash(data),
|
||||
} #type: Dict[str, Optional[Callable[[bytes], str]]]
|
||||
|
||||
@staticmethod
|
||||
def one_test_case(alg: crypto_knowledge.Algorithm,
|
||||
function: str, note: str,
|
||||
arguments: List[str]) -> test_case.TestCase:
|
||||
"""Construct one test case involving a hash."""
|
||||
tc = psa_test_case.TestCase(dependency_prefix='MBEDTLS_PSA_BUILTIN_')
|
||||
tc.set_description('{}{} {}'
|
||||
.format(function,
|
||||
' ' + note if note else '',
|
||||
alg.short_expression()))
|
||||
tc.set_function(function)
|
||||
tc.set_arguments([alg.expression] +
|
||||
['"{}"'.format(arg) for arg in arguments])
|
||||
return tc
|
||||
|
||||
def test_cases_for_hash(self,
|
||||
alg: crypto_knowledge.Algorithm
|
||||
) -> Iterator[test_case.TestCase]:
|
||||
"""Enumerate all test cases for one hash algorithm."""
|
||||
calc = self.CALCULATE[alg.expression]
|
||||
if calc is None:
|
||||
return # not implemented yet
|
||||
|
||||
short = b'abc'
|
||||
hash_short = calc(short)
|
||||
long = (b'Hello, world. Here are 16 unprintable bytes: ['
|
||||
b'\x00\x01\x02\x03\x04\x05\x06\x07\x08\x09\x0a'
|
||||
b'\x80\x81\x82\x83\xfe\xff]. '
|
||||
b' This message was brought to you by a natural intelligence. '
|
||||
b' If you can read this, good luck with your debugging!')
|
||||
hash_long = calc(long)
|
||||
|
||||
yield self.one_test_case(alg, 'hash_empty', '', [calc(b'')])
|
||||
yield self.one_test_case(alg, 'hash_valid_one_shot', '',
|
||||
[short.hex(), hash_short])
|
||||
for n in [0, 1, 64, len(long) - 1, len(long)]:
|
||||
yield self.one_test_case(alg, 'hash_valid_multipart',
|
||||
'{} + {}'.format(n, len(long) - n),
|
||||
[long[:n].hex(), calc(long[:n]),
|
||||
long[n:].hex(), hash_long])
|
||||
|
||||
def all_test_cases(self) -> Iterator[test_case.TestCase]:
|
||||
"""Enumerate all test cases for all hash algorithms."""
|
||||
for alg in self.algorithms:
|
||||
yield from self.test_cases_for_hash(alg)
|
||||
610
vendor/mbedtls/framework/scripts/mbedtls_framework/crypto_knowledge.py
vendored
Normal file
610
vendor/mbedtls/framework/scripts/mbedtls_framework/crypto_knowledge.py
vendored
Normal file
@@ -0,0 +1,610 @@
|
||||
"""Knowledge about cryptographic mechanisms implemented in Mbed TLS.
|
||||
|
||||
This module is entirely based on the PSA API.
|
||||
"""
|
||||
|
||||
# Copyright The Mbed TLS Contributors
|
||||
# SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
#
|
||||
|
||||
import enum
|
||||
import re
|
||||
from typing import FrozenSet, Iterable, List, Optional, Tuple, Dict
|
||||
|
||||
from .asymmetric_key_data import ASYMMETRIC_KEY_DATA
|
||||
|
||||
|
||||
def short_expression(original: str, level: int = 0) -> str:
|
||||
"""Abbreviate the expression, keeping it human-readable.
|
||||
|
||||
If `level` is 0, just remove parts that are implicit from context,
|
||||
such as a leading ``PSA_KEY_TYPE_``.
|
||||
For larger values of `level`, also abbreviate some names in an
|
||||
unambiguous, but ad hoc way.
|
||||
"""
|
||||
short = original
|
||||
short = re.sub(r'\bPSA_(?:ALG|DH_FAMILY|ECC_FAMILY|KEY_[A-Z]+)_', r'', short)
|
||||
short = re.sub(r' +', r'', short)
|
||||
if level >= 1:
|
||||
short = re.sub(r'PUBLIC_KEY\b', r'PUB', short)
|
||||
short = re.sub(r'KEY_PAIR\b', r'PAIR', short)
|
||||
short = re.sub(r'\bBRAINPOOL_P', r'BP', short)
|
||||
short = re.sub(r'\bMONTGOMERY\b', r'MGM', short)
|
||||
short = re.sub(r'AEAD_WITH_SHORTENED_TAG\b', r'AEAD_SHORT', short)
|
||||
short = re.sub(r'\bDETERMINISTIC_', r'DET_', short)
|
||||
short = re.sub(r'\bKEY_AGREEMENT\b', r'KA', short)
|
||||
short = re.sub(r'_PSK_TO_MS\b', r'_PSK2MS', short)
|
||||
return short
|
||||
|
||||
|
||||
BLOCK_CIPHERS = frozenset(['AES', 'ARIA', 'CAMELLIA', 'DES'])
|
||||
BLOCK_MAC_MODES = frozenset(['CBC_MAC', 'CMAC'])
|
||||
BLOCK_CIPHER_MODES = frozenset([
|
||||
'CTR', 'CFB', 'OFB', 'XTS', 'CCM_STAR_NO_TAG',
|
||||
'ECB_NO_PADDING', 'CBC_NO_PADDING', 'CBC_PKCS7',
|
||||
])
|
||||
BLOCK_AEAD_MODES = frozenset(['CCM', 'GCM'])
|
||||
|
||||
class EllipticCurveCategory(enum.Enum):
|
||||
"""Categorization of elliptic curve families.
|
||||
|
||||
The category of a curve determines what algorithms are defined over it.
|
||||
"""
|
||||
|
||||
SHORT_WEIERSTRASS = 0
|
||||
MONTGOMERY = 1
|
||||
TWISTED_EDWARDS = 2
|
||||
|
||||
@staticmethod
|
||||
def from_family(family: str) -> 'EllipticCurveCategory':
|
||||
if family == 'PSA_ECC_FAMILY_MONTGOMERY':
|
||||
return EllipticCurveCategory.MONTGOMERY
|
||||
if family == 'PSA_ECC_FAMILY_TWISTED_EDWARDS':
|
||||
return EllipticCurveCategory.TWISTED_EDWARDS
|
||||
# Default to SW, which most curves belong to.
|
||||
return EllipticCurveCategory.SHORT_WEIERSTRASS
|
||||
|
||||
|
||||
class KeyType:
|
||||
"""Knowledge about a PSA key type."""
|
||||
|
||||
def __init__(self, name: str, params: Optional[Iterable[str]] = None) -> None:
|
||||
"""Analyze a key type.
|
||||
|
||||
The key type must be specified in PSA syntax. In its simplest form,
|
||||
`name` is a string 'PSA_KEY_TYPE_xxx' which is the name of a PSA key
|
||||
type macro. For key types that take arguments, the arguments can
|
||||
be passed either through the optional argument `params` or by
|
||||
passing an expression of the form 'PSA_KEY_TYPE_xxx(param1, ...)'
|
||||
in `name` as a string.
|
||||
"""
|
||||
|
||||
self.name = name.strip()
|
||||
"""The key type macro name (``PSA_KEY_TYPE_xxx``).
|
||||
|
||||
For key types constructed from a macro with arguments, this is the
|
||||
name of the macro, and the arguments are in `self.params`.
|
||||
"""
|
||||
if params is None:
|
||||
if '(' in self.name:
|
||||
m = re.match(r'(\w+)\s*\((.*)\)\Z', self.name)
|
||||
assert m is not None
|
||||
self.name = m.group(1)
|
||||
params = m.group(2).split(',')
|
||||
self.params = (None if params is None else
|
||||
[param.strip() for param in params])
|
||||
"""The parameters of the key type, if there are any.
|
||||
|
||||
None if the key type is a macro without arguments.
|
||||
"""
|
||||
assert re.match(r'PSA_KEY_TYPE_\w+\Z', self.name)
|
||||
|
||||
self.expression = self.name
|
||||
"""A C expression whose value is the key type encoding."""
|
||||
if self.params is not None:
|
||||
self.expression += '(' + ', '.join(self.params) + ')'
|
||||
|
||||
m = re.match(r'PSA_KEY_TYPE_(\w+)', self.name)
|
||||
assert m
|
||||
self.head = re.sub(r'_(?:PUBLIC_KEY|KEY_PAIR)\Z', r'', m.group(1))
|
||||
"""The key type macro name, with common prefixes and suffixes stripped."""
|
||||
|
||||
self.private_type = re.sub(r'_PUBLIC_KEY\Z', r'_KEY_PAIR', self.name)
|
||||
"""The key type macro name for the corresponding key pair type.
|
||||
|
||||
For everything other than a public key type, this is the same as
|
||||
`self.name`.
|
||||
"""
|
||||
|
||||
def short_expression(self, level: int = 0) -> str:
|
||||
"""Abbreviate the expression, keeping it human-readable.
|
||||
|
||||
See `crypto_knowledge.short_expression`.
|
||||
"""
|
||||
return short_expression(self.expression, level=level)
|
||||
|
||||
def is_public(self) -> bool:
|
||||
"""Whether the key type is for public keys."""
|
||||
return self.name.endswith('_PUBLIC_KEY')
|
||||
|
||||
DH_KEY_SIZES = {
|
||||
'PSA_DH_FAMILY_RFC3526': (1536, 2048, 3072, 4096, 6144, 8192),
|
||||
'PSA_DH_FAMILY_RFC7919': (2048, 3072, 4096, 6144, 8192),
|
||||
} # type: Dict[str, Tuple[int, ...]]
|
||||
ECC_KEY_SIZES = {
|
||||
'PSA_ECC_FAMILY_SECP_K1': (192, 225, 256),
|
||||
'PSA_ECC_FAMILY_SECP_R1': (224, 256, 384, 521),
|
||||
'PSA_ECC_FAMILY_SECP_R2': (160,),
|
||||
'PSA_ECC_FAMILY_SECT_K1': (163, 233, 239, 283, 409, 571),
|
||||
'PSA_ECC_FAMILY_SECT_R1': (163, 233, 283, 409, 571),
|
||||
'PSA_ECC_FAMILY_SECT_R2': (163,),
|
||||
'PSA_ECC_FAMILY_BRAINPOOL_P_R1': (160, 192, 224, 256, 320, 384, 512),
|
||||
'PSA_ECC_FAMILY_FRP': (256,),
|
||||
'PSA_ECC_FAMILY_MONTGOMERY': (255, 448),
|
||||
'PSA_ECC_FAMILY_TWISTED_EDWARDS': (255, 448),
|
||||
} # type: Dict[str, Tuple[int, ...]]
|
||||
KEY_TYPE_SIZES = {
|
||||
'PSA_KEY_TYPE_AES': (128, 192, 256), # exhaustive
|
||||
'PSA_KEY_TYPE_ARC4': (8, 128, 2048), # extremes + sensible
|
||||
'PSA_KEY_TYPE_ARIA': (128, 192, 256), # exhaustive
|
||||
'PSA_KEY_TYPE_ASCON': (128, 256), # exhaustive
|
||||
'PSA_KEY_TYPE_CAMELLIA': (128, 192, 256), # exhaustive
|
||||
'PSA_KEY_TYPE_CHACHA20': (256,), # exhaustive
|
||||
'PSA_KEY_TYPE_DERIVE': (120, 128), # sample
|
||||
'PSA_KEY_TYPE_DES': (64, 128, 192), # exhaustive
|
||||
'PSA_KEY_TYPE_HMAC': (128, 160, 224, 256, 384, 512), # standard size for each supported hash
|
||||
'PSA_KEY_TYPE_PASSWORD': (48, 168, 336), # sample
|
||||
'PSA_KEY_TYPE_PASSWORD_HASH': (128, 256), # sample
|
||||
'PSA_KEY_TYPE_PEPPER': (128, 256), # sample
|
||||
'PSA_KEY_TYPE_RAW_DATA': (8, 40, 128), # sample
|
||||
'PSA_KEY_TYPE_RSA_KEY_PAIR': (1024, 1536), # small sample
|
||||
'PSA_KEY_TYPE_SM4': (128,), # exhaustive
|
||||
'PSA_KEY_TYPE_XCHACHA20': (256,), # exhaustive
|
||||
} # type: Dict[str, Tuple[int, ...]]
|
||||
def sizes_to_test(self) -> Tuple[int, ...]:
|
||||
"""Return a tuple of key sizes to test.
|
||||
|
||||
For key types that only allow a single size, or only a small set of
|
||||
sizes, these are all the possible sizes. For key types that allow a
|
||||
wide range of sizes, these are a representative sample of sizes,
|
||||
excluding large sizes for which a typical resource-constrained platform
|
||||
may run out of memory.
|
||||
"""
|
||||
if self.private_type == 'PSA_KEY_TYPE_ECC_KEY_PAIR':
|
||||
assert self.params is not None
|
||||
return self.ECC_KEY_SIZES[self.params[0]]
|
||||
if self.private_type == 'PSA_KEY_TYPE_DH_KEY_PAIR':
|
||||
assert self.params is not None
|
||||
return self.DH_KEY_SIZES[self.params[0]]
|
||||
return self.KEY_TYPE_SIZES[self.private_type]
|
||||
|
||||
# "48657265006973206b6579a064617461"
|
||||
DATA_BLOCK = b'Here\000is key\240data'
|
||||
def key_material(self, bits: int) -> bytes:
|
||||
"""Return a byte string containing suitable key material with the given bit length.
|
||||
|
||||
Use the PSA export representation. The resulting byte string is one that
|
||||
can be obtained with the following code:
|
||||
```
|
||||
psa_set_key_type(&attributes, `self.expression`);
|
||||
psa_set_key_bits(&attributes, `bits`);
|
||||
psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_EXPORT);
|
||||
psa_generate_key(&attributes, &id);
|
||||
psa_export_key(id, `material`, ...);
|
||||
```
|
||||
"""
|
||||
if self.expression in ASYMMETRIC_KEY_DATA:
|
||||
if bits not in ASYMMETRIC_KEY_DATA[self.expression]:
|
||||
raise ValueError('No key data for {}-bit {}'
|
||||
.format(bits, self.expression))
|
||||
return ASYMMETRIC_KEY_DATA[self.expression][bits]
|
||||
if bits % 8 != 0:
|
||||
raise ValueError('Non-integer number of bytes: {} bits for {}'
|
||||
.format(bits, self.expression))
|
||||
length = bits // 8
|
||||
if self.name == 'PSA_KEY_TYPE_DES':
|
||||
# "644573206b457901644573206b457902644573206b457904"
|
||||
des3 = b'dEs kEy\001dEs kEy\002dEs kEy\004'
|
||||
return des3[:length]
|
||||
return b''.join([self.DATA_BLOCK] * (length // len(self.DATA_BLOCK)) +
|
||||
[self.DATA_BLOCK[:length % len(self.DATA_BLOCK)]])
|
||||
|
||||
def can_do(self, alg: 'Algorithm') -> bool:
|
||||
"""Whether this key type can be used for operations with the given algorithm.
|
||||
|
||||
This function does not currently handle key derivation or PAKE.
|
||||
"""
|
||||
#pylint: disable=too-many-branches,too-many-return-statements
|
||||
if not alg.is_valid_for_operation():
|
||||
return False
|
||||
if self.head == 'HMAC' and alg.head == 'HMAC':
|
||||
return True
|
||||
if self.head == 'DES':
|
||||
# 64-bit block ciphers only allow a reduced set of modes.
|
||||
return alg.head in [
|
||||
'CBC_NO_PADDING', 'CBC_PKCS7',
|
||||
'ECB_NO_PADDING',
|
||||
]
|
||||
if self.head in BLOCK_CIPHERS and \
|
||||
alg.head in frozenset.union(BLOCK_MAC_MODES,
|
||||
BLOCK_CIPHER_MODES,
|
||||
BLOCK_AEAD_MODES):
|
||||
if alg.head in ['CMAC', 'OFB'] and \
|
||||
self.head in ['ARIA', 'CAMELLIA']:
|
||||
return False # not implemented in Mbed TLS
|
||||
if alg.head == 'XTS' and self.head != 'AES':
|
||||
return False # not implemented in Mbed TLS
|
||||
return True
|
||||
if self.head == 'CHACHA20' and alg.head == 'CHACHA20_POLY1305':
|
||||
return True
|
||||
if self.head in {'ARC4', 'CHACHA20'} and \
|
||||
alg.head == 'STREAM_CIPHER':
|
||||
return True
|
||||
if self.head == 'RSA' and alg.head.startswith('RSA_'):
|
||||
return True
|
||||
if alg.category == AlgorithmCategory.KEY_AGREEMENT and \
|
||||
self.is_public():
|
||||
# The PSA API does not use public key objects in key agreement
|
||||
# operations: it imports the public key as a formatted byte string.
|
||||
# So a public key object with a key agreement algorithm is not
|
||||
# a valid combination.
|
||||
return False
|
||||
if alg.is_invalid_key_agreement_with_derivation():
|
||||
return False
|
||||
if self.head == 'ECC':
|
||||
assert self.params is not None
|
||||
eccc = EllipticCurveCategory.from_family(self.params[0])
|
||||
if alg.head == 'ECDH' and \
|
||||
eccc in {EllipticCurveCategory.SHORT_WEIERSTRASS,
|
||||
EllipticCurveCategory.MONTGOMERY}:
|
||||
return True
|
||||
if alg.head == 'ECDSA' and \
|
||||
eccc == EllipticCurveCategory.SHORT_WEIERSTRASS:
|
||||
return True
|
||||
if alg.head in {'PURE_EDDSA', 'EDDSA_PREHASH'} and \
|
||||
eccc == EllipticCurveCategory.TWISTED_EDWARDS:
|
||||
return True
|
||||
if self.head == 'DH' and alg.head == 'FFDH':
|
||||
return True
|
||||
return False
|
||||
|
||||
|
||||
class AlgorithmCategory(enum.Enum):
|
||||
"""PSA algorithm categories."""
|
||||
# The numbers are aligned with the category bits in numerical values of
|
||||
# algorithms. The names match the `PSA_ALG_IS_xxx` macros.
|
||||
HASH = 2
|
||||
MAC = 3
|
||||
CIPHER = 4
|
||||
AEAD = 5
|
||||
SIGN = 6
|
||||
ASYMMETRIC_ENCRYPTION = 7
|
||||
KEY_DERIVATION = 8
|
||||
KEY_AGREEMENT = 9
|
||||
PAKE = 10
|
||||
KEY_WRAP = 11
|
||||
KEY_ENCAPSULATION = 12
|
||||
XOF = 13
|
||||
|
||||
def requires_key(self) -> bool:
|
||||
"""Whether operations in this category are set up with a key."""
|
||||
return self not in {
|
||||
self.HASH,
|
||||
self.XOF,
|
||||
self.KEY_DERIVATION, # key passed separately from setup
|
||||
}
|
||||
|
||||
def is_asymmetric(self) -> bool:
|
||||
"""Whether operations in this category involve asymmetric keys."""
|
||||
return self in {
|
||||
self.SIGN,
|
||||
self.ASYMMETRIC_ENCRYPTION,
|
||||
self.KEY_AGREEMENT,
|
||||
self.KEY_ENCAPSULATION,
|
||||
}
|
||||
|
||||
|
||||
class AlgorithmNotRecognized(Exception):
|
||||
def __init__(self, expr: str) -> None:
|
||||
super().__init__('Algorithm not recognized: ' + expr)
|
||||
self.expr = expr
|
||||
|
||||
|
||||
class Algorithm:
|
||||
"""Knowledge about a PSA algorithm."""
|
||||
|
||||
@staticmethod
|
||||
def determine_base(expr: str) -> str:
|
||||
"""Return an expression for the "base" of the algorithm.
|
||||
|
||||
This strips off variants of algorithms such as MAC truncation.
|
||||
|
||||
This function does not attempt to detect invalid inputs.
|
||||
"""
|
||||
m = re.match(r'PSA_ALG_(?:'
|
||||
r'(?:TRUNCATED|AT_LEAST_THIS_LENGTH)_MAC|'
|
||||
r'AEAD_WITH_(?:SHORTENED|AT_LEAST_THIS_LENGTH)_TAG'
|
||||
r')\((.*),[^,]+\)\Z', expr)
|
||||
if m:
|
||||
expr = m.group(1)
|
||||
return expr
|
||||
|
||||
@staticmethod
|
||||
def determine_head(expr: str) -> str:
|
||||
"""Return the head of an algorithm expression.
|
||||
|
||||
The head is the first (outermost) constructor, without its PSA_ALG_
|
||||
prefix, and with some normalization of similar algorithms.
|
||||
"""
|
||||
m = re.match(r'PSA_ALG_(?:DETERMINISTIC_)?(\w+)', expr)
|
||||
if not m:
|
||||
raise AlgorithmNotRecognized(expr)
|
||||
head = m.group(1)
|
||||
if head == 'KEY_AGREEMENT':
|
||||
m = re.match(r'PSA_ALG_KEY_AGREEMENT\s*\(\s*PSA_ALG_(\w+)', expr)
|
||||
if not m:
|
||||
raise AlgorithmNotRecognized(expr)
|
||||
head = m.group(1)
|
||||
head = re.sub(r'_ANY\Z', r'', head)
|
||||
if re.match(r'ED[0-9]+PH\Z', head):
|
||||
head = 'EDDSA_PREHASH'
|
||||
return head
|
||||
|
||||
CATEGORY_FROM_HEAD = {
|
||||
'AES_MMO_ZIGBEE': AlgorithmCategory.HASH,
|
||||
'ASCON_HASH': AlgorithmCategory.HASH,
|
||||
'SHA': AlgorithmCategory.HASH,
|
||||
'SHAKE256_512': AlgorithmCategory.HASH,
|
||||
'MD': AlgorithmCategory.HASH,
|
||||
'RIPEMD': AlgorithmCategory.HASH,
|
||||
'SM3': AlgorithmCategory.HASH,
|
||||
'ANY_HASH': AlgorithmCategory.HASH,
|
||||
'HMAC': AlgorithmCategory.MAC,
|
||||
'STREAM_CIPHER': AlgorithmCategory.CIPHER,
|
||||
'ASCON_AEAD': AlgorithmCategory.AEAD,
|
||||
'CHACHA20_POLY1305': AlgorithmCategory.AEAD,
|
||||
'XCHACHA20_POLY1305': AlgorithmCategory.AEAD,
|
||||
'DSA': AlgorithmCategory.SIGN,
|
||||
'ECDSA': AlgorithmCategory.SIGN,
|
||||
'EDDSA': AlgorithmCategory.SIGN,
|
||||
'HASH_ML_DSA': AlgorithmCategory.SIGN,
|
||||
'HASH_SLH_DSA': AlgorithmCategory.SIGN,
|
||||
'HSS': AlgorithmCategory.SIGN,
|
||||
'LMS': AlgorithmCategory.SIGN,
|
||||
'ML_DSA': AlgorithmCategory.SIGN,
|
||||
'PURE_EDDSA': AlgorithmCategory.SIGN,
|
||||
'SLH_DSA': AlgorithmCategory.SIGN,
|
||||
'RSA_PSS': AlgorithmCategory.SIGN,
|
||||
'RSA_PKCS1V15_SIGN': AlgorithmCategory.SIGN,
|
||||
'XMMS': AlgorithmCategory.SIGN,
|
||||
'XMMS_MT': AlgorithmCategory.SIGN,
|
||||
'RSA_PKCS1V15_CRYPT': AlgorithmCategory.ASYMMETRIC_ENCRYPTION,
|
||||
'RSA_OAEP': AlgorithmCategory.ASYMMETRIC_ENCRYPTION,
|
||||
'HKDF': AlgorithmCategory.KEY_DERIVATION,
|
||||
'TLS12_PRF': AlgorithmCategory.KEY_DERIVATION,
|
||||
'TLS12_PSK_TO_MS': AlgorithmCategory.KEY_DERIVATION,
|
||||
'TLS12_ECJPAKE_TO_PMS': AlgorithmCategory.KEY_DERIVATION,
|
||||
'SP800_108': AlgorithmCategory.KEY_DERIVATION,
|
||||
'PBKDF': AlgorithmCategory.KEY_DERIVATION,
|
||||
'ECDH': AlgorithmCategory.KEY_AGREEMENT,
|
||||
'FFDH': AlgorithmCategory.KEY_AGREEMENT,
|
||||
# KEY_AGREEMENT(...) is a key derivation with a key agreement component
|
||||
'KEY_AGREEMENT': AlgorithmCategory.KEY_DERIVATION,
|
||||
'JPAKE': AlgorithmCategory.PAKE,
|
||||
'SPAKE2P': AlgorithmCategory.PAKE,
|
||||
'KW': AlgorithmCategory.KEY_WRAP,
|
||||
'KWP': AlgorithmCategory.KEY_WRAP,
|
||||
'ECIES_SEC1': AlgorithmCategory.KEY_ENCAPSULATION,
|
||||
'ML_KEM': AlgorithmCategory.KEY_ENCAPSULATION,
|
||||
'ASCON_CXOF': AlgorithmCategory.XOF,
|
||||
'ASCON_XOF': AlgorithmCategory.XOF,
|
||||
'SHAKE': AlgorithmCategory.XOF,
|
||||
}
|
||||
for x in BLOCK_MAC_MODES:
|
||||
CATEGORY_FROM_HEAD[x] = AlgorithmCategory.MAC
|
||||
for x in BLOCK_CIPHER_MODES:
|
||||
CATEGORY_FROM_HEAD[x] = AlgorithmCategory.CIPHER
|
||||
for x in BLOCK_AEAD_MODES:
|
||||
CATEGORY_FROM_HEAD[x] = AlgorithmCategory.AEAD
|
||||
|
||||
def determine_category(self, expr: str, head: str) -> AlgorithmCategory:
|
||||
"""Return the category of the given algorithm expression.
|
||||
|
||||
This function does not attempt to detect invalid inputs.
|
||||
"""
|
||||
prefix = head
|
||||
while prefix:
|
||||
if prefix in self.CATEGORY_FROM_HEAD:
|
||||
return self.CATEGORY_FROM_HEAD[prefix]
|
||||
if re.match(r'.*[0-9]\Z', prefix):
|
||||
prefix = re.sub(r'_*[0-9]+\Z', r'', prefix)
|
||||
else:
|
||||
prefix = re.sub(r'_*[^_]*\Z', r'', prefix)
|
||||
raise AlgorithmNotRecognized(expr)
|
||||
|
||||
@staticmethod
|
||||
def determine_wildcard(expr) -> bool:
|
||||
"""Whether the given algorithm expression is a wildcard.
|
||||
|
||||
This function does not attempt to detect invalid inputs.
|
||||
"""
|
||||
if re.search(r'\bPSA_ALG_ANY_HASH\b', expr):
|
||||
return True
|
||||
if re.search(r'_AT_LEAST_', expr):
|
||||
return True
|
||||
return False
|
||||
|
||||
def __init__(self, expr: str) -> None:
|
||||
"""Analyze an algorithm value.
|
||||
|
||||
The algorithm must be expressed as a C expression containing only
|
||||
calls to PSA algorithm constructor macros and numeric literals.
|
||||
|
||||
This class is only programmed to handle valid expressions. Invalid
|
||||
expressions may result in exceptions or in nonsensical results.
|
||||
"""
|
||||
self.expression = re.sub(r'\s+', r'', expr)
|
||||
self.base_expression = self.determine_base(self.expression)
|
||||
self.head = self.determine_head(self.base_expression)
|
||||
self.category = self.determine_category(self.base_expression, self.head)
|
||||
self.is_wildcard = self.determine_wildcard(self.expression)
|
||||
|
||||
def get_key_agreement_derivation(self) -> Optional[str]:
|
||||
"""For a combined key agreement and key derivation algorithm, get the derivation part.
|
||||
|
||||
For anything else, return None.
|
||||
"""
|
||||
if self.category != AlgorithmCategory.KEY_AGREEMENT:
|
||||
return None
|
||||
m = re.match(r'PSA_ALG_KEY_AGREEMENT\(\w+,\s*(.*)\)\Z', self.expression)
|
||||
if not m:
|
||||
return None
|
||||
kdf_alg = m.group(1)
|
||||
# Assume kdf_alg is either a valid KDF or 0.
|
||||
if re.match(r'(?:0[Xx])?0+\s*\Z', kdf_alg):
|
||||
return None
|
||||
return kdf_alg
|
||||
|
||||
KEY_DERIVATIONS_INCOMPATIBLE_WITH_AGREEMENT = frozenset([
|
||||
'PSA_ALG_TLS12_ECJPAKE_TO_PMS', # secret input in specific format
|
||||
])
|
||||
def is_valid_key_agreement_with_derivation(self) -> bool:
|
||||
"""Whether this is a valid combined key agreement and key derivation algorithm."""
|
||||
kdf_alg = self.get_key_agreement_derivation()
|
||||
if kdf_alg is None:
|
||||
return False
|
||||
return kdf_alg not in self.KEY_DERIVATIONS_INCOMPATIBLE_WITH_AGREEMENT
|
||||
|
||||
def is_invalid_key_agreement_with_derivation(self) -> bool:
|
||||
"""Whether this is an invalid combined key agreement and key derivation algorithm."""
|
||||
kdf_alg = self.get_key_agreement_derivation()
|
||||
if kdf_alg is None:
|
||||
return False
|
||||
return kdf_alg in self.KEY_DERIVATIONS_INCOMPATIBLE_WITH_AGREEMENT
|
||||
|
||||
def short_expression(self, level: int = 0) -> str:
|
||||
"""Abbreviate the expression, keeping it human-readable.
|
||||
|
||||
See `crypto_knowledge.short_expression`.
|
||||
"""
|
||||
return short_expression(self.expression, level=level)
|
||||
|
||||
HASH_LENGTH_BYTES = {
|
||||
'PSA_ALG_AES_MMO_ZIGBEE': 16,
|
||||
'PSA_ALG_MD2': 16,
|
||||
'PSA_ALG_MD4': 16,
|
||||
'PSA_ALG_MD5': 16,
|
||||
'PSA_ALG_SHA_1': 20,
|
||||
'PSA_ALG_SM3': 32,
|
||||
}
|
||||
HASH_LENGTH_BITS_RE = re.compile(r'([0-9]+)\Z')
|
||||
@classmethod
|
||||
def hash_length(cls, alg: str) -> int:
|
||||
"""The length of the given hash algorithm, in bytes."""
|
||||
if alg in cls.HASH_LENGTH_BYTES:
|
||||
return cls.HASH_LENGTH_BYTES[alg]
|
||||
m = cls.HASH_LENGTH_BITS_RE.search(alg)
|
||||
if m:
|
||||
return int(m.group(1)) // 8
|
||||
raise ValueError('Unknown hash length for ' + alg)
|
||||
|
||||
PERMITTED_TAG_LENGTHS = {
|
||||
'PSA_ALG_CCM': frozenset([4, 6, 8, 10, 12, 14, 16]),
|
||||
'PSA_ALG_CHACHA20_POLY1305': frozenset([16]),
|
||||
'PSA_ALG_GCM': frozenset([4, 8, 12, 13, 14, 15, 16]),
|
||||
}
|
||||
MAC_LENGTH = {
|
||||
'PSA_ALG_CBC_MAC': 16, # actually the block cipher length
|
||||
'PSA_ALG_CMAC': 16, # actually the block cipher length
|
||||
}
|
||||
HMAC_RE = re.compile(r'PSA_ALG_HMAC\((.*)\)\Z')
|
||||
@classmethod
|
||||
def permitted_truncations(cls, base: str) -> FrozenSet[int]:
|
||||
"""Permitted output lengths for the given MAC or AEAD base algorithm.
|
||||
|
||||
For a MAC algorithm, this is the set of truncation lengths that
|
||||
Mbed TLS supports.
|
||||
For an AEAD algorithm, this is the set of truncation lengths that
|
||||
are permitted by the algorithm specification.
|
||||
"""
|
||||
if base in cls.PERMITTED_TAG_LENGTHS:
|
||||
return cls.PERMITTED_TAG_LENGTHS[base]
|
||||
max_length = cls.MAC_LENGTH.get(base, None)
|
||||
if max_length is None:
|
||||
m = cls.HMAC_RE.match(base)
|
||||
if m:
|
||||
max_length = cls.hash_length(m.group(1))
|
||||
if max_length is None:
|
||||
raise ValueError('Unknown permitted lengths for ' + base)
|
||||
return frozenset(range(4, max_length + 1))
|
||||
|
||||
TRUNCATED_ALG_RE = re.compile(
|
||||
r'(?P<face>PSA_ALG_(?:AEAD_WITH_SHORTENED_TAG|TRUNCATED_MAC))'
|
||||
r'\((?P<base>.*),'
|
||||
r'(?P<length>0[Xx][0-9A-Fa-f]+|[1-9][0-9]*|0[0-7]*)[LUlu]*\)\Z')
|
||||
def is_invalid_truncation(self) -> bool:
|
||||
"""False for a MAC or AEAD algorithm truncated to an invalid length.
|
||||
|
||||
True for a MAC or AEAD algorithm truncated to a valid length or to
|
||||
a length that cannot be determined. True for anything other than
|
||||
a truncated MAC or AEAD.
|
||||
"""
|
||||
m = self.TRUNCATED_ALG_RE.match(self.expression)
|
||||
if m:
|
||||
base = m.group('base')
|
||||
to_length = int(m.group('length'), 0)
|
||||
permitted_lengths = self.permitted_truncations(base)
|
||||
if to_length not in permitted_lengths:
|
||||
return True
|
||||
return False
|
||||
|
||||
def is_valid_for_operation(self) -> bool:
|
||||
"""Whether this algorithm construction is valid for an operation.
|
||||
|
||||
This function assumes that the algorithm is constructed in a
|
||||
"grammatically" correct way, and only rejects semantically invalid
|
||||
combinations.
|
||||
"""
|
||||
if self.is_wildcard:
|
||||
return False
|
||||
if self.is_invalid_truncation():
|
||||
return False
|
||||
return True
|
||||
|
||||
def can_do(self, category: AlgorithmCategory) -> bool:
|
||||
"""Whether this algorithm can perform operations in the given category.
|
||||
"""
|
||||
if category == self.category:
|
||||
return True
|
||||
if category == AlgorithmCategory.KEY_DERIVATION and \
|
||||
self.is_valid_key_agreement_with_derivation():
|
||||
return True
|
||||
return False
|
||||
|
||||
def usage_flags(self, public: bool = False) -> List[str]:
|
||||
"""The list of usage flags describing operations that can perform this algorithm.
|
||||
|
||||
If public is true, only return public-key operations, not private-key operations.
|
||||
"""
|
||||
if self.category == AlgorithmCategory.HASH:
|
||||
flags = []
|
||||
elif self.category == AlgorithmCategory.MAC:
|
||||
flags = ['SIGN_HASH', 'SIGN_MESSAGE',
|
||||
'VERIFY_HASH', 'VERIFY_MESSAGE']
|
||||
elif self.category == AlgorithmCategory.CIPHER or \
|
||||
self.category == AlgorithmCategory.AEAD:
|
||||
flags = ['DECRYPT', 'ENCRYPT']
|
||||
elif self.category == AlgorithmCategory.SIGN:
|
||||
flags = ['VERIFY_HASH', 'VERIFY_MESSAGE']
|
||||
if not public:
|
||||
flags += ['SIGN_HASH', 'SIGN_MESSAGE']
|
||||
elif self.category == AlgorithmCategory.ASYMMETRIC_ENCRYPTION:
|
||||
flags = ['ENCRYPT']
|
||||
if not public:
|
||||
flags += ['DECRYPT']
|
||||
elif self.category == AlgorithmCategory.KEY_DERIVATION or \
|
||||
self.category == AlgorithmCategory.KEY_AGREEMENT:
|
||||
flags = ['DERIVE']
|
||||
else:
|
||||
raise AlgorithmNotRecognized(self.expression)
|
||||
return ['PSA_KEY_USAGE_' + flag for flag in flags]
|
||||
884
vendor/mbedtls/framework/scripts/mbedtls_framework/ecp.py
vendored
Normal file
884
vendor/mbedtls/framework/scripts/mbedtls_framework/ecp.py
vendored
Normal file
@@ -0,0 +1,884 @@
|
||||
"""Framework classes for generation of ecp test cases."""
|
||||
# Copyright The Mbed TLS Contributors
|
||||
# SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
#
|
||||
|
||||
from typing import List
|
||||
|
||||
from . import test_data_generation
|
||||
from . import bignum_common
|
||||
from . import build_tree
|
||||
|
||||
|
||||
class EcpTarget(test_data_generation.BaseTarget):
|
||||
#pylint: disable=abstract-method, too-few-public-methods
|
||||
"""Target for ecp test case generation."""
|
||||
target_basename = 'test_suite_ecp.generated'
|
||||
|
||||
|
||||
class EcpP192R1Raw(bignum_common.ModOperationCommon,
|
||||
EcpTarget):
|
||||
"""Test cases for ECP P192 fast reduction."""
|
||||
symbol = "-"
|
||||
test_function = "ecp_mod_p_generic_raw"
|
||||
test_name = "ecp_mod_p192_raw"
|
||||
input_style = "fixed"
|
||||
arity = 1
|
||||
dependencies = ["MBEDTLS_ECP_DP_SECP192R1_ENABLED",
|
||||
"MBEDTLS_ECP_NIST_OPTIM"]
|
||||
|
||||
moduli = ["fffffffffffffffffffffffffffffffeffffffffffffffff"] # type: List[str]
|
||||
|
||||
input_values = [
|
||||
"0", "1",
|
||||
|
||||
# Modulus - 1
|
||||
"fffffffffffffffffffffffffffffffefffffffffffffffe",
|
||||
|
||||
# Modulus + 1
|
||||
"ffffffffffffffffffffffffffffffff0000000000000000",
|
||||
|
||||
# 2^192 - 1
|
||||
"ffffffffffffffffffffffffffffffffffffffffffffffff",
|
||||
|
||||
# Maximum canonical P192 multiplication result
|
||||
("fffffffffffffffffffffffffffffffdfffffffffffffffc" +
|
||||
"000000000000000100000000000000040000000000000004"),
|
||||
|
||||
# Generate an overflow during reduction
|
||||
("00000000000000000000000000000001ffffffffffffffff" +
|
||||
"ffffffffffffffffffffffffffffffff0000000000000000"),
|
||||
|
||||
# Generate an overflow during carry reduction
|
||||
("ffffffffffffffff00000000000000010000000000000000" +
|
||||
"fffffffffffffffeffffffffffffffff0000000000000000"),
|
||||
|
||||
# First 8 number generated by random.getrandbits(384) - seed(2,2)
|
||||
("cf1822ffbc6887782b491044d5e341245c6e433715ba2bdd" +
|
||||
"177219d30e7a269fd95bafc8f2a4d27bdcf4bb99f4bea973"),
|
||||
("ffed9235288bc781ae66267594c9c9500925e4749b575bd1" +
|
||||
"3653f8dd9b1f282e4067c3584ee207f8da94e3e8ab73738f"),
|
||||
("ef8acd128b4f2fc15f3f57ebf30b94fa82523e86feac7eb7" +
|
||||
"dc38f519b91751dacdbd47d364be8049a372db8f6e405d93"),
|
||||
("e8624fab5186ee32ee8d7ee9770348a05d300cb90706a045" +
|
||||
"defc044a09325626e6b58de744ab6cce80877b6f71e1f6d2"),
|
||||
("2d3d854e061b90303b08c6e33c7295782d6c797f8f7d9b78" +
|
||||
"2a1be9cd8697bbd0e2520e33e44c50556c71c4a66148a86f"),
|
||||
("fec3f6b32e8d4b8a8f54f8ceacaab39e83844b40ffa9b9f1" +
|
||||
"5c14bc4a829e07b0829a48d422fe99a22c70501e533c9135"),
|
||||
("97eeab64ca2ce6bc5d3fd983c34c769fe89204e2e8168561" +
|
||||
"867e5e15bc01bfce6a27e0dfcbf8754472154e76e4c11ab2"),
|
||||
("bd143fa9b714210c665d7435c1066932f4767f26294365b2" +
|
||||
"721dea3bf63f23d0dbe53fcafb2147df5ca495fa5a91c89b"),
|
||||
|
||||
# Next 2 number generated by random.getrandbits(192)
|
||||
"47733e847d718d733ff98ff387c56473a7a83ee0761ebfd2",
|
||||
"cbd4d3e2d4dec9ef83f0be4e80371eb97f81375eecc1cb63"
|
||||
]
|
||||
|
||||
@property
|
||||
def arg_a(self) -> str:
|
||||
return super().format_arg('{:x}'.format(self.int_a)).zfill(2 * self.hex_digits)
|
||||
|
||||
def result(self) -> List[str]:
|
||||
result = self.int_a % self.int_n
|
||||
return [self.format_result(result)]
|
||||
|
||||
@property
|
||||
def is_valid(self) -> bool:
|
||||
# secp192r1 support has been removed from development, but it's stil
|
||||
# available in 3.6 branch.
|
||||
return build_tree.is_mbedtls_3_6()
|
||||
|
||||
def arguments(self)-> List[str]:
|
||||
args = super().arguments()
|
||||
return ["MBEDTLS_ECP_DP_SECP192R1"] + args
|
||||
|
||||
|
||||
class EcpP224R1Raw(bignum_common.ModOperationCommon,
|
||||
EcpTarget):
|
||||
"""Test cases for ECP P224 fast reduction."""
|
||||
symbol = "-"
|
||||
test_function = "ecp_mod_p_generic_raw"
|
||||
test_name = "ecp_mod_p224_raw"
|
||||
input_style = "arch_split"
|
||||
arity = 1
|
||||
dependencies = ["MBEDTLS_ECP_DP_SECP224R1_ENABLED",
|
||||
"MBEDTLS_ECP_NIST_OPTIM"]
|
||||
|
||||
moduli = ["ffffffffffffffffffffffffffffffff000000000000000000000001"] # type: List[str]
|
||||
|
||||
input_values = [
|
||||
"0", "1",
|
||||
|
||||
# Modulus - 1
|
||||
"ffffffffffffffffffffffffffffffff000000000000000000000000",
|
||||
|
||||
# Modulus + 1
|
||||
"ffffffffffffffffffffffffffffffff000000000000000000000002",
|
||||
|
||||
# 2^224 - 1
|
||||
"ffffffffffffffffffffffffffffffffffffffffffffffffffffffff",
|
||||
|
||||
# Maximum canonical P224 multiplication result
|
||||
("fffffffffffffffffffffffffffffffe000000000000000000000000" +
|
||||
"00000001000000000000000000000000000000000000000000000000"),
|
||||
|
||||
# Generate an overflow during reduction
|
||||
("00000000000000000000000000010000000070000000002000001000" +
|
||||
"ffffffffffff9fffffffffe00000efff000070000000002000001003"),
|
||||
|
||||
# Generate an underflow during reduction
|
||||
("00000001000000000000000000000000000000000000000000000000" +
|
||||
"00000000000dc0000000000000000001000000010000000100000003"),
|
||||
|
||||
# First 8 number generated by random.getrandbits(448) - seed(2,2)
|
||||
("da94e3e8ab73738fcf1822ffbc6887782b491044d5e341245c6e4337" +
|
||||
"15ba2bdd177219d30e7a269fd95bafc8f2a4d27bdcf4bb99f4bea973"),
|
||||
("cdbd47d364be8049a372db8f6e405d93ffed9235288bc781ae662675" +
|
||||
"94c9c9500925e4749b575bd13653f8dd9b1f282e4067c3584ee207f8"),
|
||||
("defc044a09325626e6b58de744ab6cce80877b6f71e1f6d2ef8acd12" +
|
||||
"8b4f2fc15f3f57ebf30b94fa82523e86feac7eb7dc38f519b91751da"),
|
||||
("2d6c797f8f7d9b782a1be9cd8697bbd0e2520e33e44c50556c71c4a6" +
|
||||
"6148a86fe8624fab5186ee32ee8d7ee9770348a05d300cb90706a045"),
|
||||
("8f54f8ceacaab39e83844b40ffa9b9f15c14bc4a829e07b0829a48d4" +
|
||||
"22fe99a22c70501e533c91352d3d854e061b90303b08c6e33c729578"),
|
||||
("97eeab64ca2ce6bc5d3fd983c34c769fe89204e2e8168561867e5e15" +
|
||||
"bc01bfce6a27e0dfcbf8754472154e76e4c11ab2fec3f6b32e8d4b8a"),
|
||||
("a7a83ee0761ebfd2bd143fa9b714210c665d7435c1066932f4767f26" +
|
||||
"294365b2721dea3bf63f23d0dbe53fcafb2147df5ca495fa5a91c89b"),
|
||||
("74667bffe202849da9643a295a9ac6decbd4d3e2d4dec9ef83f0be4e" +
|
||||
"80371eb97f81375eecc1cb6347733e847d718d733ff98ff387c56473"),
|
||||
|
||||
# Next 2 number generated by random.getrandbits(224)
|
||||
"eb9ac688b9d39cca91551e8259cc60b17604e4b4e73695c3e652c71a",
|
||||
"f0caeef038c89b38a8acb5137c9260dc74e088a9b9492f258ebdbfe3"
|
||||
]
|
||||
|
||||
@property
|
||||
def arg_a(self) -> str:
|
||||
limbs = 2 * bignum_common.bits_to_limbs(224, self.bits_in_limb)
|
||||
hex_digits = bignum_common.hex_digits_for_limb(limbs, self.bits_in_limb)
|
||||
return super().format_arg('{:x}'.format(self.int_a)).zfill(hex_digits)
|
||||
|
||||
def result(self) -> List[str]:
|
||||
result = self.int_a % self.int_n
|
||||
return [self.format_result(result)]
|
||||
|
||||
@property
|
||||
def is_valid(self) -> bool:
|
||||
# secp224r1 support has been removed from development, but it's stil
|
||||
# available in 3.6 branch.
|
||||
return build_tree.is_mbedtls_3_6()
|
||||
|
||||
def arguments(self)-> List[str]:
|
||||
args = super().arguments()
|
||||
return ["MBEDTLS_ECP_DP_SECP224R1"] + args
|
||||
|
||||
|
||||
class EcpP256R1Raw(bignum_common.ModOperationCommon,
|
||||
EcpTarget):
|
||||
"""Test cases for ECP P256 fast reduction."""
|
||||
symbol = "-"
|
||||
test_function = "ecp_mod_p_generic_raw"
|
||||
test_name = "ecp_mod_p256_raw"
|
||||
input_style = "fixed"
|
||||
arity = 1
|
||||
dependencies = ["MBEDTLS_ECP_DP_SECP256R1_ENABLED",
|
||||
"MBEDTLS_ECP_NIST_OPTIM"]
|
||||
|
||||
moduli = ["ffffffff00000001000000000000000000000000ffffffffffffffffffffffff"] # type: List[str]
|
||||
|
||||
input_values = [
|
||||
"0", "1",
|
||||
|
||||
# Modulus - 1
|
||||
"ffffffff00000001000000000000000000000000fffffffffffffffffffffffe",
|
||||
|
||||
# Modulus + 1
|
||||
"ffffffff00000001000000000000000000000001000000000000000000000000",
|
||||
|
||||
# 2^256 - 1
|
||||
"ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff",
|
||||
|
||||
# Maximum canonical P256 multiplication result
|
||||
("fffffffe00000002fffffffe0000000100000001fffffffe00000001fffffffc" +
|
||||
"00000003fffffffcfffffffffffffffffffffffc000000000000000000000004"),
|
||||
|
||||
# Generate an overflow during reduction
|
||||
("0000000000000000000000010000000000000000000000000000000000000000" +
|
||||
"00000000000000000000000000000000000000000000000000000000ffffffff"),
|
||||
|
||||
# Generate an underflow during reduction
|
||||
("0000000000000000000000000000000000000000000000000000000000000010" +
|
||||
"ffffffff00000000000000000000000000000000000000000000000000000000"),
|
||||
|
||||
# Generate an overflow during carry reduction
|
||||
("aaaaaaaa00000000000000000000000000000000000000000000000000000000" +
|
||||
"00000000000000000000000000000000aaaaaaacaaaaaaaaaaaaaaaa00000000"),
|
||||
|
||||
# Generate an underflow during carry reduction
|
||||
("000000000000000000000001ffffffff00000000000000000000000000000000" +
|
||||
"0000000000000000000000000000000000000002000000020000000100000002"),
|
||||
|
||||
# First 8 number generated by random.getrandbits(512) - seed(2,2)
|
||||
("4067c3584ee207f8da94e3e8ab73738fcf1822ffbc6887782b491044d5e34124" +
|
||||
"5c6e433715ba2bdd177219d30e7a269fd95bafc8f2a4d27bdcf4bb99f4bea973"),
|
||||
("82523e86feac7eb7dc38f519b91751dacdbd47d364be8049a372db8f6e405d93" +
|
||||
"ffed9235288bc781ae66267594c9c9500925e4749b575bd13653f8dd9b1f282e"),
|
||||
("e8624fab5186ee32ee8d7ee9770348a05d300cb90706a045defc044a09325626" +
|
||||
"e6b58de744ab6cce80877b6f71e1f6d2ef8acd128b4f2fc15f3f57ebf30b94fa"),
|
||||
("829a48d422fe99a22c70501e533c91352d3d854e061b90303b08c6e33c729578" +
|
||||
"2d6c797f8f7d9b782a1be9cd8697bbd0e2520e33e44c50556c71c4a66148a86f"),
|
||||
("e89204e2e8168561867e5e15bc01bfce6a27e0dfcbf8754472154e76e4c11ab2" +
|
||||
"fec3f6b32e8d4b8a8f54f8ceacaab39e83844b40ffa9b9f15c14bc4a829e07b0"),
|
||||
("bd143fa9b714210c665d7435c1066932f4767f26294365b2721dea3bf63f23d0" +
|
||||
"dbe53fcafb2147df5ca495fa5a91c89b97eeab64ca2ce6bc5d3fd983c34c769f"),
|
||||
("74667bffe202849da9643a295a9ac6decbd4d3e2d4dec9ef83f0be4e80371eb9" +
|
||||
"7f81375eecc1cb6347733e847d718d733ff98ff387c56473a7a83ee0761ebfd2"),
|
||||
("d08f1bb2531d6460f0caeef038c89b38a8acb5137c9260dc74e088a9b9492f25" +
|
||||
"8ebdbfe3eb9ac688b9d39cca91551e8259cc60b17604e4b4e73695c3e652c71a"),
|
||||
|
||||
# Next 2 number generated by random.getrandbits(256)
|
||||
"c5e2486c44a4a8f69dc8db48e86ec9c6e06f291b2a838af8d5c44a4eb3172062",
|
||||
"d4c0dca8b4c9e755cc9c3adcf515a8234da4daeb4f3f87777ad1f45ae9500ec9"
|
||||
]
|
||||
|
||||
@property
|
||||
def arg_a(self) -> str:
|
||||
return super().format_arg('{:x}'.format(self.int_a)).zfill(2 * self.hex_digits)
|
||||
|
||||
def result(self) -> List[str]:
|
||||
result = self.int_a % self.int_n
|
||||
return [self.format_result(result)]
|
||||
|
||||
@property
|
||||
def is_valid(self) -> bool:
|
||||
return True
|
||||
|
||||
def arguments(self)-> List[str]:
|
||||
args = super().arguments()
|
||||
return ["MBEDTLS_ECP_DP_SECP256R1"] + args
|
||||
|
||||
|
||||
class EcpP384R1Raw(bignum_common.ModOperationCommon,
|
||||
EcpTarget):
|
||||
"""Test cases for ECP P384 fast reduction."""
|
||||
test_function = "ecp_mod_p_generic_raw"
|
||||
test_name = "ecp_mod_p384_raw"
|
||||
input_style = "fixed"
|
||||
arity = 1
|
||||
dependencies = ["MBEDTLS_ECP_DP_SECP384R1_ENABLED",
|
||||
"MBEDTLS_ECP_NIST_OPTIM"]
|
||||
|
||||
moduli = [("ffffffffffffffffffffffffffffffffffffffffffffffff" +
|
||||
"fffffffffffffffeffffffff0000000000000000ffffffff")
|
||||
] # type: List[str]
|
||||
|
||||
input_values = [
|
||||
"0", "1",
|
||||
|
||||
# Modulus - 1
|
||||
("ffffffffffffffffffffffffffffffffffffffffffffffff" +
|
||||
"fffffffffffffffeffffffff0000000000000000fffffffe"),
|
||||
|
||||
# Modulus + 1
|
||||
("ffffffffffffffffffffffffffffffffffffffffffffffff" +
|
||||
"fffffffffffffffeffffffff000000000000000100000000"),
|
||||
|
||||
# 2^384 - 1
|
||||
("ffffffffffffffffffffffffffffffffffffffffffffffff" +
|
||||
"ffffffffffffffffffffffffffffffffffffffffffffffff"),
|
||||
|
||||
# Maximum canonical P384 multiplication result
|
||||
("ffffffffffffffffffffffffffffffffffffffffffffffff" +
|
||||
"fffffffffffffffdfffffffe0000000000000001fffffffc" +
|
||||
"000000000000000000000000000000010000000200000000" +
|
||||
"fffffffe000000020000000400000000fffffffc00000004"),
|
||||
|
||||
# Testing with overflow in A(12) + A(21) + A(20);
|
||||
("497811378624857a2c2af60d70583376545484cfae5c812f" +
|
||||
"e2999fc1abb51d18b559e8ca3b50aaf263fdf8f24bdfb98f" +
|
||||
"ffffffff20e65bf9099e4e73a5e8b517cf4fbeb8fd1750fd" +
|
||||
"ae6d43f2e53f82d5ffffffffffffffffcc6f1e06111c62e0"),
|
||||
|
||||
# Testing with underflow in A(13) + A(22) + A(23) - A(12) - A(20);
|
||||
("dfdd25e96777406b3c04b8c7b406f5fcf287e1e576003a09" +
|
||||
"2852a6fbe517f2712b68abef41dbd35183a0614fb7222606" +
|
||||
"ffffffff84396eee542f18a9189d94396c784059c17a9f18" +
|
||||
"f807214ef32f2f10ffffffff8a77fac20000000000000000"),
|
||||
|
||||
# Testing with overflow in A(23) + A(20) + A(19) - A(22);
|
||||
("783753f8a5afba6c1862eead1deb2fcdd907272be3ffd185" +
|
||||
"42b24a71ee8b26cab0aa33513610ff973042bbe1637cc9fc" +
|
||||
"99ad36c7f703514572cf4f5c3044469a8f5be6312c19e5d3" +
|
||||
"f8fc1ac6ffffffffffffffff8c86252400000000ffffffff"),
|
||||
|
||||
# Testing with underflow in A(23) + A(20) + A(19) - A(22);
|
||||
("65e1d2362fce922663b7fd517586e88842a9b4bd092e93e6" +
|
||||
"251c9c69f278cbf8285d99ae3b53da5ba36e56701e2b17c2" +
|
||||
"25f1239556c5f00117fa140218b46ebd8e34f50d0018701f" +
|
||||
"a8a0a5cc00000000000000004410bcb4ffffffff00000000"),
|
||||
|
||||
# Testing the second round of carry reduction
|
||||
("000000000000000000000000ffffffffffffffffffffffff" +
|
||||
"ffffffffffffffffffffffffffffffff0000000000000000" +
|
||||
"0000000000000000ffffffff000000000000000000000001" +
|
||||
"00000000000000000000000000000000ffffffff00000001"),
|
||||
|
||||
# First 8 number generated by random.getrandbits(768) - seed(2,2)
|
||||
("ffed9235288bc781ae66267594c9c9500925e4749b575bd1" +
|
||||
"3653f8dd9b1f282e4067c3584ee207f8da94e3e8ab73738f" +
|
||||
"cf1822ffbc6887782b491044d5e341245c6e433715ba2bdd" +
|
||||
"177219d30e7a269fd95bafc8f2a4d27bdcf4bb99f4bea973"),
|
||||
("e8624fab5186ee32ee8d7ee9770348a05d300cb90706a045" +
|
||||
"defc044a09325626e6b58de744ab6cce80877b6f71e1f6d2" +
|
||||
"ef8acd128b4f2fc15f3f57ebf30b94fa82523e86feac7eb7" +
|
||||
"dc38f519b91751dacdbd47d364be8049a372db8f6e405d93"),
|
||||
("fec3f6b32e8d4b8a8f54f8ceacaab39e83844b40ffa9b9f1" +
|
||||
"5c14bc4a829e07b0829a48d422fe99a22c70501e533c9135" +
|
||||
"2d3d854e061b90303b08c6e33c7295782d6c797f8f7d9b78" +
|
||||
"2a1be9cd8697bbd0e2520e33e44c50556c71c4a66148a86f"),
|
||||
("bd143fa9b714210c665d7435c1066932f4767f26294365b2" +
|
||||
"721dea3bf63f23d0dbe53fcafb2147df5ca495fa5a91c89b" +
|
||||
"97eeab64ca2ce6bc5d3fd983c34c769fe89204e2e8168561" +
|
||||
"867e5e15bc01bfce6a27e0dfcbf8754472154e76e4c11ab2"),
|
||||
("8ebdbfe3eb9ac688b9d39cca91551e8259cc60b17604e4b4" +
|
||||
"e73695c3e652c71a74667bffe202849da9643a295a9ac6de" +
|
||||
"cbd4d3e2d4dec9ef83f0be4e80371eb97f81375eecc1cb63" +
|
||||
"47733e847d718d733ff98ff387c56473a7a83ee0761ebfd2"),
|
||||
("d4c0dca8b4c9e755cc9c3adcf515a8234da4daeb4f3f8777" +
|
||||
"7ad1f45ae9500ec9c5e2486c44a4a8f69dc8db48e86ec9c6" +
|
||||
"e06f291b2a838af8d5c44a4eb3172062d08f1bb2531d6460" +
|
||||
"f0caeef038c89b38a8acb5137c9260dc74e088a9b9492f25"),
|
||||
("0227eeb7b9d7d01f5769da05d205bbfcc8c69069134bccd3" +
|
||||
"e1cf4f589f8e4ce0af29d115ef24bd625dd961e6830b54fa" +
|
||||
"7d28f93435339774bb1e386c4fd5079e681b8f5896838b76" +
|
||||
"9da59b74a6c3181c81e220df848b1df78feb994a81167346"),
|
||||
("d322a7353ead4efe440e2b4fda9c025a22f1a83185b98f5f" +
|
||||
"c11e60de1b343f52ea748db9e020307aaeb6db2c3a038a70" +
|
||||
"9779ac1f45e9dd320c855fdfa7251af0930cdbd30f0ad2a8" +
|
||||
"1b2d19a2beaa14a7ff3fe32a30ffc4eed0a7bd04e85bfcdd"),
|
||||
|
||||
# Next 2 number generated by random.getrandbits(384)
|
||||
("5c3747465cc36c270e8a35b10828d569c268a20eb78ac332" +
|
||||
"e5e138e26c4454b90f756132e16dce72f18e859835e1f291"),
|
||||
("eb2b5693babb7fbb0a76c196067cfdcb11457d9cf45e2fa0" +
|
||||
"1d7f4275153924800600571fac3a5b263fdf57cd2c006497")
|
||||
]
|
||||
|
||||
@property
|
||||
def arg_a(self) -> str:
|
||||
return super().format_arg('{:x}'.format(self.int_a)).zfill(2 * self.hex_digits)
|
||||
|
||||
def result(self) -> List[str]:
|
||||
result = self.int_a % self.int_n
|
||||
return [self.format_result(result)]
|
||||
|
||||
@property
|
||||
def is_valid(self) -> bool:
|
||||
return True
|
||||
|
||||
def arguments(self)-> List[str]:
|
||||
args = super().arguments()
|
||||
return ["MBEDTLS_ECP_DP_SECP384R1"] + args
|
||||
|
||||
|
||||
class EcpP521R1Raw(bignum_common.ModOperationCommon,
|
||||
EcpTarget):
|
||||
"""Test cases for ECP P521 fast reduction."""
|
||||
test_function = "ecp_mod_p_generic_raw"
|
||||
test_name = "ecp_mod_p521_raw"
|
||||
input_style = "arch_split"
|
||||
arity = 1
|
||||
dependencies = ["MBEDTLS_ECP_DP_SECP521R1_ENABLED",
|
||||
"MBEDTLS_ECP_NIST_OPTIM"]
|
||||
|
||||
moduli = [("01ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff" +
|
||||
"ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff")
|
||||
] # type: List[str]
|
||||
|
||||
input_values = [
|
||||
"0", "1",
|
||||
|
||||
# Modulus - 1
|
||||
("01ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff" +
|
||||
"fffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffe"),
|
||||
|
||||
# Modulus + 1
|
||||
("020000000000000000000000000000000000000000000000000000000000000000" +
|
||||
"000000000000000000000000000000000000000000000000000000000000000000"),
|
||||
|
||||
# Maximum canonical P521 multiplication result
|
||||
("0003ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff" +
|
||||
"ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff" +
|
||||
"fffff800" +
|
||||
"0000000000000000000000000000000000000000000000000000000000000000" +
|
||||
"0000000000000000000000000000000000000000000000000000000000000004"),
|
||||
|
||||
# Test case for overflow during addition
|
||||
("0001efffffffffffffffffffffffffffffffffffffffffffffffffffffffffff" +
|
||||
"ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff" +
|
||||
"000001ef" +
|
||||
"0000000000000000000000000000000000000000000000000000000000000000" +
|
||||
"000000000000000000000000000000000000000000000000000000000f000000"),
|
||||
|
||||
# First 8 number generated by random.getrandbits(1042) - seed(2,2)
|
||||
("0003cc2e82523e86feac7eb7dc38f519b91751dacdbd47d364be8049a372db8f" +
|
||||
"6e405d93ffed9235288bc781ae66267594c9c9500925e4749b575bd13653f8dd" +
|
||||
"9b1f282e" +
|
||||
"4067c3584ee207f8da94e3e8ab73738fcf1822ffbc6887782b491044d5e34124" +
|
||||
"5c6e433715ba2bdd177219d30e7a269fd95bafc8f2a4d27bdcf4bb99f4bea973"),
|
||||
("00017052829e07b0829a48d422fe99a22c70501e533c91352d3d854e061b9030" +
|
||||
"3b08c6e33c7295782d6c797f8f7d9b782a1be9cd8697bbd0e2520e33e44c5055" +
|
||||
"6c71c4a6" +
|
||||
"6148a86fe8624fab5186ee32ee8d7ee9770348a05d300cb90706a045defc044a" +
|
||||
"09325626e6b58de744ab6cce80877b6f71e1f6d2ef8acd128b4f2fc15f3f57eb"),
|
||||
("00021f15a7a83ee0761ebfd2bd143fa9b714210c665d7435c1066932f4767f26" +
|
||||
"294365b2721dea3bf63f23d0dbe53fcafb2147df5ca495fa5a91c89b97eeab64" +
|
||||
"ca2ce6bc" +
|
||||
"5d3fd983c34c769fe89204e2e8168561867e5e15bc01bfce6a27e0dfcbf87544" +
|
||||
"72154e76e4c11ab2fec3f6b32e8d4b8a8f54f8ceacaab39e83844b40ffa9b9f1"),
|
||||
("000381bc2a838af8d5c44a4eb3172062d08f1bb2531d6460f0caeef038c89b38" +
|
||||
"a8acb5137c9260dc74e088a9b9492f258ebdbfe3eb9ac688b9d39cca91551e82" +
|
||||
"59cc60b1" +
|
||||
"7604e4b4e73695c3e652c71a74667bffe202849da9643a295a9ac6decbd4d3e2" +
|
||||
"d4dec9ef83f0be4e80371eb97f81375eecc1cb6347733e847d718d733ff98ff3"),
|
||||
("00034816c8c69069134bccd3e1cf4f589f8e4ce0af29d115ef24bd625dd961e6" +
|
||||
"830b54fa7d28f93435339774bb1e386c4fd5079e681b8f5896838b769da59b74" +
|
||||
"a6c3181c" +
|
||||
"81e220df848b1df78feb994a81167346d4c0dca8b4c9e755cc9c3adcf515a823" +
|
||||
"4da4daeb4f3f87777ad1f45ae9500ec9c5e2486c44a4a8f69dc8db48e86ec9c6"),
|
||||
("000397846c4454b90f756132e16dce72f18e859835e1f291d322a7353ead4efe" +
|
||||
"440e2b4fda9c025a22f1a83185b98f5fc11e60de1b343f52ea748db9e020307a" +
|
||||
"aeb6db2c" +
|
||||
"3a038a709779ac1f45e9dd320c855fdfa7251af0930cdbd30f0ad2a81b2d19a2" +
|
||||
"beaa14a7ff3fe32a30ffc4eed0a7bd04e85bfcdd0227eeb7b9d7d01f5769da05"),
|
||||
("00002c3296e6bc4d62b47204007ee4fab105d83e85e951862f0981aebc1b00d9" +
|
||||
"2838e766ef9b6bf2d037fe2e20b6a8464174e75a5f834da70569c018eb2b5693" +
|
||||
"babb7fbb" +
|
||||
"0a76c196067cfdcb11457d9cf45e2fa01d7f4275153924800600571fac3a5b26" +
|
||||
"3fdf57cd2c0064975c3747465cc36c270e8a35b10828d569c268a20eb78ac332"),
|
||||
("00009d23b4917fc09f20dbb0dcc93f0e66dfe717c17313394391b6e2e6eacb0f" +
|
||||
"0bb7be72bd6d25009aeb7fa0c4169b148d2f527e72daf0a54ef25c0707e33868" +
|
||||
"7d1f7157" +
|
||||
"5653a45c49390aa51cf5192bbf67da14be11d56ba0b4a2969d8055a9f03f2d71" +
|
||||
"581d8e830112ff0f0948eccaf8877acf26c377c13f719726fd70bddacb4deeec"),
|
||||
|
||||
# Next 2 number generated by random.getrandbits(521)
|
||||
("12b84ae65e920a63ac1f2b64df6dff07870c9d531ae72a47403063238da1a1fe" +
|
||||
"3f9d6a179fa50f96cd4aff9261aa92c0e6f17ec940639bc2ccdf572df00790813e3"),
|
||||
("166049dd332a73fa0b26b75196cf87eb8a09b27ec714307c68c425424a1574f1" +
|
||||
"eedf5b0f16cdfdb839424d201e653f53d6883ca1c107ca6e706649889c0c7f38608")
|
||||
]
|
||||
|
||||
@property
|
||||
def arg_a(self) -> str:
|
||||
# Number of limbs: 2 * N
|
||||
return super().format_arg('{:x}'.format(self.int_a)).zfill(2 * self.hex_digits)
|
||||
|
||||
def result(self) -> List[str]:
|
||||
result = self.int_a % self.int_n
|
||||
return [self.format_result(result)]
|
||||
|
||||
@property
|
||||
def is_valid(self) -> bool:
|
||||
return True
|
||||
|
||||
def arguments(self)-> List[str]:
|
||||
args = super().arguments()
|
||||
return ["MBEDTLS_ECP_DP_SECP521R1"] + args
|
||||
|
||||
|
||||
class EcpP192K1Raw(bignum_common.ModOperationCommon,
|
||||
EcpTarget):
|
||||
"""Test cases for ECP P192K1 fast reduction."""
|
||||
symbol = "-"
|
||||
test_function = "ecp_mod_p_generic_raw"
|
||||
test_name = "ecp_mod_p192k1_raw"
|
||||
input_style = "fixed"
|
||||
arity = 1
|
||||
dependencies = ["MBEDTLS_ECP_DP_SECP192K1_ENABLED"]
|
||||
|
||||
moduli = ["fffffffffffffffffffffffffffffffffffffffeffffee37"] # type: List[str]
|
||||
|
||||
input_values = [
|
||||
"0", "1",
|
||||
|
||||
# Modulus - 1
|
||||
"fffffffffffffffffffffffffffffffffffffffeffffee36",
|
||||
|
||||
# Modulus + 1
|
||||
"fffffffffffffffffffffffffffffffffffffffeffffee38",
|
||||
|
||||
# 2^192 - 1
|
||||
"ffffffffffffffffffffffffffffffffffffffffffffffff",
|
||||
|
||||
# Maximum canonical P192K1 multiplication result
|
||||
("fffffffffffffffffffffffffffffffffffffffdffffdc6c" +
|
||||
"0000000000000000000000000000000100002394013c7364"),
|
||||
|
||||
# Test case for overflow during addition
|
||||
("00000007ffff71b809e27dd832cfd5e04d9d2dbb9f8da217" +
|
||||
"0000000000000000000000000000000000000000520834f0"),
|
||||
|
||||
# First 8 number generated by random.getrandbits(384) - seed(2,2)
|
||||
("cf1822ffbc6887782b491044d5e341245c6e433715ba2bdd" +
|
||||
"177219d30e7a269fd95bafc8f2a4d27bdcf4bb99f4bea973"),
|
||||
("ffed9235288bc781ae66267594c9c9500925e4749b575bd1" +
|
||||
"3653f8dd9b1f282e4067c3584ee207f8da94e3e8ab73738f"),
|
||||
("ef8acd128b4f2fc15f3f57ebf30b94fa82523e86feac7eb7" +
|
||||
"dc38f519b91751dacdbd47d364be8049a372db8f6e405d93"),
|
||||
("e8624fab5186ee32ee8d7ee9770348a05d300cb90706a045" +
|
||||
"defc044a09325626e6b58de744ab6cce80877b6f71e1f6d2"),
|
||||
("2d3d854e061b90303b08c6e33c7295782d6c797f8f7d9b78" +
|
||||
"2a1be9cd8697bbd0e2520e33e44c50556c71c4a66148a86f"),
|
||||
("fec3f6b32e8d4b8a8f54f8ceacaab39e83844b40ffa9b9f1" +
|
||||
"5c14bc4a829e07b0829a48d422fe99a22c70501e533c9135"),
|
||||
("97eeab64ca2ce6bc5d3fd983c34c769fe89204e2e8168561" +
|
||||
"867e5e15bc01bfce6a27e0dfcbf8754472154e76e4c11ab2"),
|
||||
("bd143fa9b714210c665d7435c1066932f4767f26294365b2" +
|
||||
"721dea3bf63f23d0dbe53fcafb2147df5ca495fa5a91c89b"),
|
||||
|
||||
# Next 2 number generated by random.getrandbits(192)
|
||||
"47733e847d718d733ff98ff387c56473a7a83ee0761ebfd2",
|
||||
"cbd4d3e2d4dec9ef83f0be4e80371eb97f81375eecc1cb63"
|
||||
]
|
||||
|
||||
@property
|
||||
def arg_a(self) -> str:
|
||||
return super().format_arg('{:x}'.format(self.int_a)).zfill(2 * self.hex_digits)
|
||||
|
||||
def result(self) -> List[str]:
|
||||
result = self.int_a % self.int_n
|
||||
return [self.format_result(result)]
|
||||
|
||||
@property
|
||||
def is_valid(self) -> bool:
|
||||
# secp192k1 support has been removed from development, but it's stil
|
||||
# available in 3.6 branch.
|
||||
return build_tree.is_mbedtls_3_6()
|
||||
|
||||
def arguments(self):
|
||||
args = super().arguments()
|
||||
return ["MBEDTLS_ECP_DP_SECP192K1"] + args
|
||||
|
||||
|
||||
class EcpP224K1Raw(bignum_common.ModOperationCommon,
|
||||
EcpTarget):
|
||||
"""Test cases for ECP P224 fast reduction."""
|
||||
symbol = "-"
|
||||
test_function = "ecp_mod_p_generic_raw"
|
||||
test_name = "ecp_mod_p224k1_raw"
|
||||
input_style = "arch_split"
|
||||
arity = 1
|
||||
dependencies = ["MBEDTLS_ECP_DP_SECP224K1_ENABLED"]
|
||||
|
||||
moduli = ["fffffffffffffffffffffffffffffffffffffffffffffffeffffe56d"] # type: List[str]
|
||||
|
||||
input_values = [
|
||||
"0", "1",
|
||||
|
||||
# Modulus - 1
|
||||
"fffffffffffffffffffffffffffffffffffffffffffffffeffffe56c",
|
||||
|
||||
# Modulus + 1
|
||||
"fffffffffffffffffffffffffffffffffffffffffffffffeffffe56e",
|
||||
|
||||
# 2^224 - 1
|
||||
"ffffffffffffffffffffffffffffffffffffffffffffffffffffffff",
|
||||
|
||||
# Maximum canonical P224K1 multiplication result
|
||||
("fffffffffffffffffffffffffffffffffffffffffffffffdffffcad8" +
|
||||
"00000000000000000000000000000000000000010000352802c26590"),
|
||||
|
||||
# Test case for overflow during addition
|
||||
("0000007ffff2b68161180fd8cd92e1a109be158a19a99b1809db8032" +
|
||||
"0000000000000000000000000000000000000000000000000bf04f49"),
|
||||
|
||||
# First 8 number generated by random.getrandbits(448) - seed(2,2)
|
||||
("da94e3e8ab73738fcf1822ffbc6887782b491044d5e341245c6e4337" +
|
||||
"15ba2bdd177219d30e7a269fd95bafc8f2a4d27bdcf4bb99f4bea973"),
|
||||
("cdbd47d364be8049a372db8f6e405d93ffed9235288bc781ae662675" +
|
||||
"94c9c9500925e4749b575bd13653f8dd9b1f282e4067c3584ee207f8"),
|
||||
("defc044a09325626e6b58de744ab6cce80877b6f71e1f6d2ef8acd12" +
|
||||
"8b4f2fc15f3f57ebf30b94fa82523e86feac7eb7dc38f519b91751da"),
|
||||
("2d6c797f8f7d9b782a1be9cd8697bbd0e2520e33e44c50556c71c4a6" +
|
||||
"6148a86fe8624fab5186ee32ee8d7ee9770348a05d300cb90706a045"),
|
||||
("8f54f8ceacaab39e83844b40ffa9b9f15c14bc4a829e07b0829a48d4" +
|
||||
"22fe99a22c70501e533c91352d3d854e061b90303b08c6e33c729578"),
|
||||
("97eeab64ca2ce6bc5d3fd983c34c769fe89204e2e8168561867e5e15" +
|
||||
"bc01bfce6a27e0dfcbf8754472154e76e4c11ab2fec3f6b32e8d4b8a"),
|
||||
("a7a83ee0761ebfd2bd143fa9b714210c665d7435c1066932f4767f26" +
|
||||
"294365b2721dea3bf63f23d0dbe53fcafb2147df5ca495fa5a91c89b"),
|
||||
("74667bffe202849da9643a295a9ac6decbd4d3e2d4dec9ef83f0be4e" +
|
||||
"80371eb97f81375eecc1cb6347733e847d718d733ff98ff387c56473"),
|
||||
|
||||
# Next 2 number generated by random.getrandbits(224)
|
||||
("eb9ac688b9d39cca91551e8259cc60b17604e4b4e73695c3e652c71a"),
|
||||
("f0caeef038c89b38a8acb5137c9260dc74e088a9b9492f258ebdbfe3"),
|
||||
]
|
||||
|
||||
@property
|
||||
def arg_a(self) -> str:
|
||||
limbs = 2 * bignum_common.bits_to_limbs(224, self.bits_in_limb)
|
||||
hex_digits = bignum_common.hex_digits_for_limb(limbs, self.bits_in_limb)
|
||||
return super().format_arg('{:x}'.format(self.int_a)).zfill(hex_digits)
|
||||
|
||||
def result(self) -> List[str]:
|
||||
result = self.int_a % self.int_n
|
||||
return [self.format_result(result)]
|
||||
|
||||
@property
|
||||
def is_valid(self) -> bool:
|
||||
# secp224k1 support has been removed from development, but it's stil
|
||||
# available in 3.6 branch.
|
||||
return build_tree.is_mbedtls_3_6()
|
||||
|
||||
def arguments(self):
|
||||
args = super().arguments()
|
||||
return ["MBEDTLS_ECP_DP_SECP224K1"] + args
|
||||
|
||||
|
||||
class EcpP256K1Raw(bignum_common.ModOperationCommon,
|
||||
EcpTarget):
|
||||
"""Test cases for ECP P256 fast reduction."""
|
||||
symbol = "-"
|
||||
test_function = "ecp_mod_p_generic_raw"
|
||||
test_name = "ecp_mod_p256k1_raw"
|
||||
input_style = "fixed"
|
||||
arity = 1
|
||||
dependencies = ["MBEDTLS_ECP_DP_SECP256K1_ENABLED"]
|
||||
|
||||
moduli = ["fffffffffffffffffffffffffffffffffffffffffffffffffffffffefffffc2f"] # type: List[str]
|
||||
|
||||
input_values = [
|
||||
"0", "1",
|
||||
|
||||
# Modulus - 1
|
||||
"fffffffffffffffffffffffffffffffffffffffffffffffffffffffefffffc2e",
|
||||
|
||||
# Modulus + 1
|
||||
"fffffffffffffffffffffffffffffffffffffffffffffffffffffffefffffc30",
|
||||
|
||||
# 2^256 - 1
|
||||
"ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff",
|
||||
|
||||
# Maximum canonical P256K1 multiplication result
|
||||
("fffffffffffffffffffffffffffffffffffffffffffffffffffffffdfffff85c" +
|
||||
"000000000000000000000000000000000000000000000001000007a4000e9844"),
|
||||
|
||||
# Test case for overflow during addition
|
||||
("0000fffffc2f000e90a0c86a0a63234e5ba641f43a7e4aecc4040e67ec850562" +
|
||||
"00000000000000000000000000000000000000000000000000000000585674fd"),
|
||||
|
||||
# Test case for overflow during addition
|
||||
("0000fffffc2f000e90a0c86a0a63234e5ba641f43a7e4aecc4040e67ec850562" +
|
||||
"00000000000000000000000000000000000000000000000000000000585674fd"),
|
||||
|
||||
# First 8 number generated by random.getrandbits(512) - seed(2,2)
|
||||
("4067c3584ee207f8da94e3e8ab73738fcf1822ffbc6887782b491044d5e34124" +
|
||||
"5c6e433715ba2bdd177219d30e7a269fd95bafc8f2a4d27bdcf4bb99f4bea973"),
|
||||
("82523e86feac7eb7dc38f519b91751dacdbd47d364be8049a372db8f6e405d93" +
|
||||
"ffed9235288bc781ae66267594c9c9500925e4749b575bd13653f8dd9b1f282e"),
|
||||
("e8624fab5186ee32ee8d7ee9770348a05d300cb90706a045defc044a09325626" +
|
||||
"e6b58de744ab6cce80877b6f71e1f6d2ef8acd128b4f2fc15f3f57ebf30b94fa"),
|
||||
("829a48d422fe99a22c70501e533c91352d3d854e061b90303b08c6e33c729578" +
|
||||
"2d6c797f8f7d9b782a1be9cd8697bbd0e2520e33e44c50556c71c4a66148a86f"),
|
||||
("e89204e2e8168561867e5e15bc01bfce6a27e0dfcbf8754472154e76e4c11ab2" +
|
||||
"fec3f6b32e8d4b8a8f54f8ceacaab39e83844b40ffa9b9f15c14bc4a829e07b0"),
|
||||
("bd143fa9b714210c665d7435c1066932f4767f26294365b2721dea3bf63f23d0" +
|
||||
"dbe53fcafb2147df5ca495fa5a91c89b97eeab64ca2ce6bc5d3fd983c34c769f"),
|
||||
("74667bffe202849da9643a295a9ac6decbd4d3e2d4dec9ef83f0be4e80371eb9" +
|
||||
"7f81375eecc1cb6347733e847d718d733ff98ff387c56473a7a83ee0761ebfd2"),
|
||||
("d08f1bb2531d6460f0caeef038c89b38a8acb5137c9260dc74e088a9b9492f25" +
|
||||
"8ebdbfe3eb9ac688b9d39cca91551e8259cc60b17604e4b4e73695c3e652c71a"),
|
||||
|
||||
# Next 2 number generated by random.getrandbits(256)
|
||||
("c5e2486c44a4a8f69dc8db48e86ec9c6e06f291b2a838af8d5c44a4eb3172062"),
|
||||
("d4c0dca8b4c9e755cc9c3adcf515a8234da4daeb4f3f87777ad1f45ae9500ec9"),
|
||||
]
|
||||
|
||||
@property
|
||||
def arg_a(self) -> str:
|
||||
return super().format_arg('{:x}'.format(self.int_a)).zfill(2 * self.hex_digits)
|
||||
|
||||
def result(self) -> List[str]:
|
||||
result = self.int_a % self.int_n
|
||||
return [self.format_result(result)]
|
||||
|
||||
@property
|
||||
def is_valid(self) -> bool:
|
||||
return True
|
||||
|
||||
def arguments(self):
|
||||
args = super().arguments()
|
||||
return ["MBEDTLS_ECP_DP_SECP256K1"] + args
|
||||
|
||||
|
||||
class EcpP255Raw(bignum_common.ModOperationCommon,
|
||||
EcpTarget):
|
||||
"""Test cases for ECP 25519 fast reduction."""
|
||||
symbol = "-"
|
||||
test_function = "ecp_mod_p_generic_raw"
|
||||
test_name = "mbedtls_ecp_mod_p255_raw"
|
||||
input_style = "fixed"
|
||||
arity = 1
|
||||
dependencies = ["MBEDTLS_ECP_DP_CURVE25519_ENABLED"]
|
||||
|
||||
moduli = [("7fffffffffffffffffffffffffffffffffffffffffffffffff" +
|
||||
"ffffffffffffed")] # type: List[str]
|
||||
|
||||
input_values = [
|
||||
"0", "1",
|
||||
|
||||
# Modulus - 1
|
||||
("7fffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffec"),
|
||||
|
||||
# Modulus + 1
|
||||
("7fffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffee"),
|
||||
|
||||
# 2^255 - 1
|
||||
("7fffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff"),
|
||||
|
||||
# Maximum canonical P255 multiplication result
|
||||
("3fffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffec" +
|
||||
"0000000000000000000000000000000000000000000000000000000000000190"),
|
||||
|
||||
# First 8 number generated by random.getrandbits(510) - seed(2,2)
|
||||
("1019f0d64ee207f8da94e3e8ab73738fcf1822ffbc6887782b491044d5e34124" +
|
||||
"5c6e433715ba2bdd177219d30e7a269fd95bafc8f2a4d27bdcf4bb99f4bea973"),
|
||||
("20948fa1feac7eb7dc38f519b91751dacdbd47d364be8049a372db8f6e405d93" +
|
||||
"ffed9235288bc781ae66267594c9c9500925e4749b575bd13653f8dd9b1f282e"),
|
||||
("3a1893ea5186ee32ee8d7ee9770348a05d300cb90706a045defc044a09325626" +
|
||||
"e6b58de744ab6cce80877b6f71e1f6d2ef8acd128b4f2fc15f3f57ebf30b94fa"),
|
||||
("20a6923522fe99a22c70501e533c91352d3d854e061b90303b08c6e33c729578" +
|
||||
"2d6c797f8f7d9b782a1be9cd8697bbd0e2520e33e44c50556c71c4a66148a86f"),
|
||||
("3a248138e8168561867e5e15bc01bfce6a27e0dfcbf8754472154e76e4c11ab2" +
|
||||
"fec3f6b32e8d4b8a8f54f8ceacaab39e83844b40ffa9b9f15c14bc4a829e07b0"),
|
||||
("2f450feab714210c665d7435c1066932f4767f26294365b2721dea3bf63f23d0" +
|
||||
"dbe53fcafb2147df5ca495fa5a91c89b97eeab64ca2ce6bc5d3fd983c34c769f"),
|
||||
("1d199effe202849da9643a295a9ac6decbd4d3e2d4dec9ef83f0be4e80371eb9" +
|
||||
"7f81375eecc1cb6347733e847d718d733ff98ff387c56473a7a83ee0761ebfd2"),
|
||||
("3423c6ec531d6460f0caeef038c89b38a8acb5137c9260dc74e088a9b9492f25" +
|
||||
"8ebdbfe3eb9ac688b9d39cca91551e8259cc60b17604e4b4e73695c3e652c71a"),
|
||||
|
||||
# Next 2 number generated by random.getrandbits(255)
|
||||
("62f1243644a4a8f69dc8db48e86ec9c6e06f291b2a838af8d5c44a4eb3172062"),
|
||||
("6a606e54b4c9e755cc9c3adcf515a8234da4daeb4f3f87777ad1f45ae9500ec9"),
|
||||
]
|
||||
|
||||
@property
|
||||
def arg_a(self) -> str:
|
||||
return super().format_arg('{:x}'.format(self.int_a)).zfill(2 * self.hex_digits)
|
||||
|
||||
def result(self) -> List[str]:
|
||||
result = self.int_a % self.int_n
|
||||
return [self.format_result(result)]
|
||||
|
||||
@property
|
||||
def is_valid(self) -> bool:
|
||||
return True
|
||||
|
||||
def arguments(self)-> List[str]:
|
||||
args = super().arguments()
|
||||
return ["MBEDTLS_ECP_DP_CURVE25519"] + args
|
||||
|
||||
|
||||
class EcpP448Raw(bignum_common.ModOperationCommon,
|
||||
EcpTarget):
|
||||
"""Test cases for ECP P448 fast reduction."""
|
||||
symbol = "-"
|
||||
test_function = "ecp_mod_p_generic_raw"
|
||||
test_name = "ecp_mod_p448_raw"
|
||||
input_style = "fixed"
|
||||
arity = 1
|
||||
dependencies = ["MBEDTLS_ECP_DP_CURVE448_ENABLED"]
|
||||
|
||||
moduli = [("fffffffffffffffffffffffffffffffffffffffffffffffffffffffe" +
|
||||
"ffffffffffffffffffffffffffffffffffffffffffffffffffffffff")] # type: List[str]
|
||||
|
||||
input_values = [
|
||||
"0", "1",
|
||||
|
||||
# Modulus - 1
|
||||
("fffffffffffffffffffffffffffffffffffffffffffffffffffffffe" +
|
||||
"fffffffffffffffffffffffffffffffffffffffffffffffffffffffe"),
|
||||
|
||||
# Modulus + 1
|
||||
("ffffffffffffffffffffffffffffffffffffffffffffffffffffffff" +
|
||||
"00000000000000000000000000000000000000000000000000000000"),
|
||||
|
||||
# 2^448 - 1
|
||||
("ffffffffffffffffffffffffffffffffffffffffffffffffffffffff" +
|
||||
"ffffffffffffffffffffffffffffffffffffffffffffffffffffffff"),
|
||||
|
||||
# Maximum canonical P448 multiplication result
|
||||
("fffffffffffffffffffffffffffffffffffffffffffffffffffffffd" +
|
||||
"fffffffffffffffffffffffffffffffffffffffffffffffffffffffd" +
|
||||
"00000000000000000000000000000000000000000000000000000004" +
|
||||
"00000000000000000000000000000000000000000000000000000004"),
|
||||
|
||||
# First 8 number generated by random.getrandbits(896) - seed(2,2)
|
||||
("74667bffe202849da9643a295a9ac6decbd4d3e2d4dec9ef83f0be4e" +
|
||||
"80371eb97f81375eecc1cb6347733e847d718d733ff98ff387c56473" +
|
||||
"a7a83ee0761ebfd2bd143fa9b714210c665d7435c1066932f4767f26" +
|
||||
"294365b2721dea3bf63f23d0dbe53fcafb2147df5ca495fa5a91c89b"),
|
||||
("4da4daeb4f3f87777ad1f45ae9500ec9c5e2486c44a4a8f69dc8db48" +
|
||||
"e86ec9c6e06f291b2a838af8d5c44a4eb3172062d08f1bb2531d6460" +
|
||||
"f0caeef038c89b38a8acb5137c9260dc74e088a9b9492f258ebdbfe3" +
|
||||
"eb9ac688b9d39cca91551e8259cc60b17604e4b4e73695c3e652c71a"),
|
||||
("bc1b00d92838e766ef9b6bf2d037fe2e20b6a8464174e75a5f834da7" +
|
||||
"0569c018eb2b5693babb7fbb0a76c196067cfdcb11457d9cf45e2fa0" +
|
||||
"1d7f4275153924800600571fac3a5b263fdf57cd2c0064975c374746" +
|
||||
"5cc36c270e8a35b10828d569c268a20eb78ac332e5e138e26c4454b9"),
|
||||
("8d2f527e72daf0a54ef25c0707e338687d1f71575653a45c49390aa5" +
|
||||
"1cf5192bbf67da14be11d56ba0b4a2969d8055a9f03f2d71581d8e83" +
|
||||
"0112ff0f0948eccaf8877acf26c377c13f719726fd70bddacb4deeec" +
|
||||
"0b0c995e96e6bc4d62b47204007ee4fab105d83e85e951862f0981ae"),
|
||||
("84ae65e920a63ac1f2b64df6dff07870c9d531ae72a47403063238da" +
|
||||
"1a1fe3f9d6a179fa50f96cd4aff9261aa92c0e6f17ec940639bc2ccd" +
|
||||
"f572df00790813e32748dd1db4917fc09f20dbb0dcc93f0e66dfe717" +
|
||||
"c17313394391b6e2e6eacb0f0bb7be72bd6d25009aeb7fa0c4169b14"),
|
||||
("2bb3b36f29421c4021b7379f0897246a40c270b00e893302aba9e7b8" +
|
||||
"23fc5ad2f58105748ed5d1b7b310b730049dd332a73fa0b26b75196c" +
|
||||
"f87eb8a09b27ec714307c68c425424a1574f1eedf5b0f16cdfdb8394" +
|
||||
"24d201e653f53d6883ca1c107ca6e706649889c0c7f3860895bfa813"),
|
||||
("af3f5d7841b1256d5c1dc12fb5a1ae519fb8883accda6559caa538a0" +
|
||||
"9fc9370d3a6b86a7975b54a31497024640332b0612d4050771d7b14e" +
|
||||
"b6c004cc3b8367dc3f2bb31efe9934ad0809eae3ef232a32b5459d83" +
|
||||
"fbc46f1aea990e94821d46063b4dbf2ca294523d74115c86188b1044"),
|
||||
("7430051376e31f5aab63ad02854efa600641b4fa37a47ce41aeffafc" +
|
||||
"3b45402ac02659fe2e87d4150511baeb198ababb1a16daff3da95cd2" +
|
||||
"167b75dfb948f82a8317cba01c75f67e290535d868a24b7f627f2855" +
|
||||
"09167d4126af8090013c3273c02c6b9586b4625b475b51096c4ad652"),
|
||||
|
||||
# Corner case which causes maximum overflow
|
||||
("f4ae65e920a63ac1f2b64df6dff07870c9d531ae72a47403063238da1" +
|
||||
"a1fe3f9d6a179fa50f96cd4aff9261aa92c0e6f17ec940639bc2ccd0B" +
|
||||
"519A16DF59C53E0D49B209200F878F362ACE518D5B8BFCF9CDC725E5E" +
|
||||
"01C06295E8605AF06932B5006D9E556D3F190E8136BF9C643D332"),
|
||||
|
||||
# Next 2 number generated by random.getrandbits(448)
|
||||
("8f54f8ceacaab39e83844b40ffa9b9f15c14bc4a829e07b0829a48d4" +
|
||||
"22fe99a22c70501e533c91352d3d854e061b90303b08c6e33c729578"),
|
||||
("97eeab64ca2ce6bc5d3fd983c34c769fe89204e2e8168561867e5e15" +
|
||||
"bc01bfce6a27e0dfcbf8754472154e76e4c11ab2fec3f6b32e8d4b8a"),
|
||||
|
||||
]
|
||||
|
||||
@property
|
||||
def arg_a(self) -> str:
|
||||
return super().format_arg('{:x}'.format(self.int_a)).zfill(2 * self.hex_digits)
|
||||
|
||||
def result(self) -> List[str]:
|
||||
result = self.int_a % self.int_n
|
||||
return [self.format_result(result)]
|
||||
|
||||
@property
|
||||
def is_valid(self) -> bool:
|
||||
return True
|
||||
|
||||
def arguments(self):
|
||||
args = super().arguments()
|
||||
return ["MBEDTLS_ECP_DP_CURVE448"] + args
|
||||
182
vendor/mbedtls/framework/scripts/mbedtls_framework/generate_files_helper.py
vendored
Normal file
182
vendor/mbedtls/framework/scripts/mbedtls_framework/generate_files_helper.py
vendored
Normal file
@@ -0,0 +1,182 @@
|
||||
"""Utilities for intermediate files that are generated, but platform-independent
|
||||
and configuration-independent.
|
||||
"""
|
||||
|
||||
# Copyright The Mbed TLS Contributors
|
||||
# SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
|
||||
import argparse
|
||||
import os
|
||||
import subprocess
|
||||
import sys
|
||||
from typing import Dict, Iterable, List, Sequence, Set
|
||||
|
||||
|
||||
class Generator:
|
||||
"""An abstract base class for generators of intermediate files."""
|
||||
|
||||
def generator_name(self) -> str:
|
||||
"""A name for this generator.
|
||||
|
||||
Generator names must be unique and should not be identical to
|
||||
the name of any target.
|
||||
"""
|
||||
raise NotImplementedError
|
||||
|
||||
def target_files(self) -> List[str]:
|
||||
"""The list of files targeted by this generator.
|
||||
|
||||
File names are relative to the project root.
|
||||
"""
|
||||
raise NotImplementedError
|
||||
|
||||
def outdated_files(self) -> Iterable[str]:
|
||||
"""Return the list of targets that are out of date.
|
||||
|
||||
This is empty after running update().
|
||||
Missing targets are considered out of date.
|
||||
"""
|
||||
raise NotImplementedError
|
||||
|
||||
def update(self, always: bool) -> None:
|
||||
"""Update the target(s) of this generator.
|
||||
|
||||
If always is false, avoid changing the output file if it already has
|
||||
the desired content. If always is true, make sure to update the
|
||||
time stamp on the output file even if it already has the desired content.
|
||||
"""
|
||||
raise NotImplementedError
|
||||
|
||||
|
||||
class TestDataGenerator(Generator):
|
||||
"""A test data generator script.
|
||||
|
||||
Even though the test data generator scripts are written in Python, we
|
||||
run them as a separate process, because their output depends on the
|
||||
program name (they write sys.argv[0] in a comment in the .data file).
|
||||
"""
|
||||
|
||||
def __init__(self, script: str) -> None:
|
||||
"""Run the specified test generator to generate files.
|
||||
|
||||
Assume that the script is written in Python and has the command line
|
||||
interface of test_data_generation.py.
|
||||
"""
|
||||
self.script = script
|
||||
|
||||
def generator_name(self) -> str:
|
||||
return os.path.basename(self.script)
|
||||
|
||||
def target_files(self) -> List[str]:
|
||||
output = subprocess.check_output([sys.executable, self.script, '--list'],
|
||||
encoding='utf-8')
|
||||
return output.splitlines()
|
||||
|
||||
def outdated_files(self) -> List[str]:
|
||||
output = subprocess.check_output([sys.executable, self.script, '--list-outdated'],
|
||||
encoding='utf-8')
|
||||
return output.splitlines()
|
||||
|
||||
def update(self, _always) -> None:
|
||||
subprocess.check_call([sys.executable, self.script])
|
||||
|
||||
|
||||
def assemble(available: Iterable[Generator]) -> Dict[str, Generator]:
|
||||
"""Assemble the generators into a dictionary with both names and targets as keys."""
|
||||
by_ident = {} #type: Dict[str, Generator]
|
||||
for generator in available:
|
||||
ident = generator.generator_name()
|
||||
if ident in by_ident:
|
||||
raise Exception(f'Generator conflict: name "{ident}" of {generator} '
|
||||
f'already recorded for {by_ident[ident]}')
|
||||
by_ident[ident] = generator
|
||||
for ident in generator.target_files():
|
||||
if ident in by_ident:
|
||||
raise Exception(f'Generator conflict: target "{ident}" of {generator} '
|
||||
f'already recorded for {by_ident[ident]}')
|
||||
by_ident[ident] = generator
|
||||
return by_ident
|
||||
|
||||
def list_names(available: Iterable[Generator]) -> List[str]:
|
||||
"""Return the list of generator names."""
|
||||
return sorted(generator.generator_name() for generator in available)
|
||||
|
||||
def list_targets(available: Iterable[Generator]) -> List[str]:
|
||||
"""Return the list of generator targets."""
|
||||
return sorted(target
|
||||
for generator in available
|
||||
for target in generator.target_files())
|
||||
|
||||
def select(available: Dict[str, Generator],
|
||||
wanted: Iterable[str]) -> List[Generator]:
|
||||
"""Select generators by name or target."""
|
||||
wanted_names = set() #type: Set[str]
|
||||
for ident in wanted:
|
||||
if ident not in available:
|
||||
raise Exception(f'No generator found for {ident}')
|
||||
wanted_names.add(ident)
|
||||
return [available[name] for name in sorted(wanted_names)]
|
||||
|
||||
def main(generators: Sequence[Generator],
|
||||
description: str) -> None:
|
||||
#pylint: disable=too-many-branches
|
||||
"""Command line entry point.
|
||||
"""
|
||||
parser = argparse.ArgumentParser(description=description)
|
||||
parser.add_argument('--always-update', '-U',
|
||||
action='store_true',
|
||||
help=('Update target files unconditionally '
|
||||
'(overrides --update)'))
|
||||
parser.add_argument('--list',
|
||||
action='store_true',
|
||||
help='List generator names and targets and exit')
|
||||
parser.add_argument('--list-names',
|
||||
action='store_true',
|
||||
help='List generator names and exit')
|
||||
parser.add_argument('--list-targets',
|
||||
action='store_true',
|
||||
help='List generator targets and exit')
|
||||
parser.add_argument('--update', '-u',
|
||||
action='store_true',
|
||||
help='Update target files if needed')
|
||||
parser.add_argument('--verbose', '-v',
|
||||
action='store_true',
|
||||
help='Be more verbose')
|
||||
parser.add_argument('idents', nargs='*', metavar='NAME|TARGET',
|
||||
help='List of generator names or targets (all targets if empty)')
|
||||
args = parser.parse_args()
|
||||
|
||||
if args.list:
|
||||
args.list_names = True
|
||||
args.list_targets = True
|
||||
if args.list_names:
|
||||
for name in list_names(generators):
|
||||
print(name)
|
||||
if args.list_targets:
|
||||
for target in list_targets(generators):
|
||||
print(target)
|
||||
if args.list_names or args.list_targets:
|
||||
return
|
||||
|
||||
if args.idents:
|
||||
available = assemble(generators)
|
||||
wanted = select(available, args.idents) #type: Sequence[Generator]
|
||||
else:
|
||||
wanted = generators
|
||||
if args.update or args.always_update:
|
||||
for generator in wanted:
|
||||
if args.verbose:
|
||||
sys.stderr.write(f'Running generator {generator.generator_name()}...\n')
|
||||
generator.update(args.always_update)
|
||||
else:
|
||||
outdated = [] #type: List[str]
|
||||
for generator in wanted:
|
||||
if args.verbose:
|
||||
sys.stderr.write(f'Checking targets of generator {generator.generator_name()}...\n')
|
||||
outdated += generator.outdated_files()
|
||||
if outdated:
|
||||
sys.stderr.write(f'Some targets are missing or out of date.\n')
|
||||
for target in outdated:
|
||||
print(target)
|
||||
sys.stderr.write(f'Run {sys.argv[0]} -u and commit the result.')
|
||||
sys.exit(1)
|
||||
167
vendor/mbedtls/framework/scripts/mbedtls_framework/generated_files.py
vendored
Normal file
167
vendor/mbedtls/framework/scripts/mbedtls_framework/generated_files.py
vendored
Normal file
@@ -0,0 +1,167 @@
|
||||
"""Generic code to generate, check and list the generated files
|
||||
"""
|
||||
|
||||
# Copyright The Mbed TLS Contributors
|
||||
# SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
|
||||
import argparse
|
||||
import filecmp
|
||||
import shutil
|
||||
import subprocess
|
||||
import sys
|
||||
|
||||
from pathlib import Path
|
||||
from typing import List, Optional
|
||||
|
||||
class GenerationScript:
|
||||
"""
|
||||
Representation of a script generating a configuration independent file.
|
||||
"""
|
||||
# pylint: disable=too-few-public-methods,too-many-arguments
|
||||
def __init__(self, script: Path, files: List[Path],
|
||||
output_dir_option: Optional[str] = None,
|
||||
output_file_option: Optional[str] = None,
|
||||
optional: bool = False) -> None:
|
||||
# Path from the root of Mbed TLS or TF-PSA-Crypto of the generation script
|
||||
self.script = script
|
||||
|
||||
# Executable to run the script, needed for Windows
|
||||
if script.suffix == ".py":
|
||||
self.exe = sys.executable
|
||||
elif script.suffix == ".pl":
|
||||
self.exe = "perl"
|
||||
|
||||
# List of the default paths from the Mbed TLS or TF-PSA-Crypto root of the
|
||||
# files the script generates.
|
||||
self.files = files
|
||||
|
||||
# Output directory script argument. Can be an empty string in case it is a
|
||||
# positional argument.
|
||||
self.output_dir_option = output_dir_option
|
||||
|
||||
# Output file script argument. Can be an empty string in case it is a
|
||||
# positional argument.
|
||||
self.output_file_option = output_file_option
|
||||
|
||||
# Optional files are skipped in --check mode if they don't exist.
|
||||
# This normally shouldn't happen, but it can happen during transition
|
||||
# periods where we're adding a new script or a new file, and a
|
||||
# consuming repository hasn't been updated yet.
|
||||
self.optional = optional
|
||||
|
||||
def get_generation_script_files(generation_script: str) -> List[Path]:
|
||||
"""
|
||||
Get the list of the default paths of the files that a given script
|
||||
generates. It is assumed that the script supports the "--list" option.
|
||||
"""
|
||||
files = []
|
||||
if generation_script.endswith(".py"):
|
||||
cmd = [sys.executable]
|
||||
elif generation_script.endswith(".pl"):
|
||||
cmd = ["perl"]
|
||||
cmd += [generation_script, "--list"]
|
||||
|
||||
output = subprocess.check_output(cmd, universal_newlines=True)
|
||||
for line in output.splitlines():
|
||||
files.append(Path(line))
|
||||
|
||||
return files
|
||||
|
||||
def get_generated_files(generation_scripts: List[GenerationScript]) -> List[Path]:
|
||||
"""
|
||||
List the generated files in Mbed TLS or TF-PSA-Crypto. The path from root
|
||||
is returned for each generated files.
|
||||
"""
|
||||
files = []
|
||||
for generation_script in generation_scripts:
|
||||
files += generation_script.files
|
||||
|
||||
return files
|
||||
|
||||
def make_generated_files(generation_scripts: List[GenerationScript]) -> None:
|
||||
"""
|
||||
Generate the configuration independent files in their default location in
|
||||
the Mbed TLS or TF-PSA-Crypto tree.
|
||||
"""
|
||||
for generation_script in generation_scripts:
|
||||
subprocess.run([generation_script.exe, str(generation_script.script)], check=True)
|
||||
|
||||
def check_generated_files(generation_scripts: List[GenerationScript],
|
||||
root: Path) -> bool:
|
||||
"""
|
||||
Check that the given root directory contains the generated files as expected/
|
||||
generated by this script.
|
||||
"""
|
||||
ok = True
|
||||
for generation_script in generation_scripts:
|
||||
for file in generation_script.files:
|
||||
file = root / file
|
||||
if not file.exists():
|
||||
# If the script is just being added, allow its files not
|
||||
# to exist. This can happen, at least, when adding a new
|
||||
# generation script in crypto: until mbedtls is updated,
|
||||
# the files from that script won't be present when
|
||||
# the updated crypto is built from mbedtls development.
|
||||
if generation_script.optional:
|
||||
continue
|
||||
raise Exception(f"Expected generated file does not exist: {file}")
|
||||
bak_file = file.with_name(file.name + ".bak")
|
||||
if bak_file.exists():
|
||||
bak_file.unlink()
|
||||
file.rename(bak_file)
|
||||
|
||||
command = [generation_script.exe, str(generation_script.script)]
|
||||
if generation_script.output_dir_option is not None:
|
||||
command += [generation_script.output_dir_option,
|
||||
str(root / Path(generation_script.files[0].parent))]
|
||||
elif generation_script.output_file_option is not None:
|
||||
command += generation_script.output_file_option.split()
|
||||
command += [str(root / Path(generation_script.files[0]))]
|
||||
subprocess.run([item for item in command if item.strip()], check=True)
|
||||
|
||||
for file in generation_script.files:
|
||||
file = root / file
|
||||
bak_file = file.with_name(file.name + ".bak")
|
||||
if generation_script.optional and not bak_file.exists():
|
||||
# This file is optional and didn't exist before, so
|
||||
# there's nothing to compare to, or clean up.
|
||||
continue
|
||||
if not filecmp.cmp(file, bak_file):
|
||||
ok = False
|
||||
ref_file = file.with_name(file.name + ".ref")
|
||||
ref_file = root / ref_file
|
||||
if ref_file.exists():
|
||||
ref_file.unlink()
|
||||
shutil.copy(file, ref_file)
|
||||
print(f"Generated file {file} not identical to the reference one {ref_file}.")
|
||||
file.unlink()
|
||||
bak_file.rename(file)
|
||||
return ok
|
||||
|
||||
def main(generation_scripts: List[GenerationScript]) -> int:
|
||||
"""
|
||||
Main function of this program
|
||||
"""
|
||||
parser = argparse.ArgumentParser()
|
||||
|
||||
parser.add_argument('--list', action='store_true',
|
||||
default=False, help='List generated files.')
|
||||
parser.add_argument('--root', metavar='DIR',
|
||||
help='Root of the tree containing the generated files \
|
||||
to check (default: Mbed TLS or TF-PSA-Cryto root.)')
|
||||
parser.add_argument('--check', action='store_true',
|
||||
default=False, help='Check the generated files in root')
|
||||
|
||||
args = parser.parse_args()
|
||||
|
||||
if args.list:
|
||||
files = get_generated_files(generation_scripts)
|
||||
for file in files:
|
||||
print(str(file))
|
||||
return 0
|
||||
elif args.check:
|
||||
ok = check_generated_files(generation_scripts, Path(args.root or "."))
|
||||
return 0 if ok else 1
|
||||
else:
|
||||
make_generated_files(generation_scripts)
|
||||
return 0 # Any error causes an exception
|
||||
679
vendor/mbedtls/framework/scripts/mbedtls_framework/interface_checks.py
vendored
Normal file
679
vendor/mbedtls/framework/scripts/mbedtls_framework/interface_checks.py
vendored
Normal file
@@ -0,0 +1,679 @@
|
||||
"""This script compares the interfaces of two versions of Mbed TLS, looking
|
||||
for backward incompatibilities between two different Git revisions within
|
||||
an Mbed TLS repository. It must be run from the root of a Git working tree.
|
||||
|
||||
### How the script works ###
|
||||
|
||||
For the source (API) and runtime (ABI) interface compatibility, this script
|
||||
is a small wrapper around the abi-compliance-checker and abi-dumper tools,
|
||||
applying them to compare the header and library files.
|
||||
|
||||
For the storage format, this script compares the automatically generated
|
||||
storage tests and the manual read tests, and complains if there is a
|
||||
reduction in coverage. A change in test data will be signaled as a
|
||||
coverage reduction since the old test data is no longer present. A change in
|
||||
how test data is presented will be signaled as well; this would be a false
|
||||
positive.
|
||||
|
||||
The results of the API/ABI comparison are either formatted as HTML and stored
|
||||
at a configurable location, or are given as a brief list of problems.
|
||||
Returns 0 on success, 1 on non-compliance, and 2 if there is an error
|
||||
while running the script.
|
||||
|
||||
### How to interpret non-compliance ###
|
||||
|
||||
This script has relatively common false positives. In many scenarios, it only
|
||||
reports a pass if there is a strict textual match between the old version and
|
||||
the new version, and it reports problems where there is a sufficient semantic
|
||||
match but not a textual match. This section lists some common false positives.
|
||||
This is not an exhaustive list: in the end what matters is whether we are
|
||||
breaking a backward compatibility goal.
|
||||
|
||||
**API**: the goal is that if an application works with the old version of the
|
||||
library, it can be recompiled against the new version and will still work.
|
||||
This is normally validated by comparing the declarations in `include/*/*.h`.
|
||||
A failure is a declaration that has disappeared or that now has a different
|
||||
type.
|
||||
|
||||
* It's ok to change or remove macros and functions that are documented as
|
||||
for internal use only or as experimental.
|
||||
* It's ok to rename function or macro parameters as long as the semantics
|
||||
has not changed.
|
||||
* It's ok to change or remove structure fields that are documented as
|
||||
private.
|
||||
* It's ok to add fields to a structure that already had private fields
|
||||
or was documented as extensible.
|
||||
|
||||
**ABI**: the goal is that if an application was built against the old version
|
||||
of the library, the same binary will work when linked against the new version.
|
||||
This is normally validated by comparing the symbols exported by `libmbed*.so`.
|
||||
A failure is a symbol that is no longer exported by the same library or that
|
||||
now has a different type.
|
||||
|
||||
* All ABI changes are acceptable if the library version is bumped
|
||||
(see `scripts/bump_version.sh`).
|
||||
* ABI changes that concern functions which are declared only inside the
|
||||
library directory, and not in `include/*/*.h`, are acceptable only if
|
||||
the function was only ever used inside the same library (libmbedcrypto,
|
||||
libmbedx509, libmbedtls). As a counter example, if the old version
|
||||
of libmbedtls calls mbedtls_foo() from libmbedcrypto, and the new version
|
||||
of libmbedcrypto no longer has a compatible mbedtls_foo(), this does
|
||||
require a version bump for libmbedcrypto.
|
||||
|
||||
**Storage format**: the goal is to check that persistent keys stored by the
|
||||
old version can be read by the new version. This is normally validated by
|
||||
comparing the `*read*` test cases in `test_suite*storage_format*.data`.
|
||||
A failure is a storage read test case that is no longer present with the same
|
||||
function name and parameter list.
|
||||
|
||||
* It's ok if the same test data is present, but its presentation has changed,
|
||||
for example if a test function is renamed or has different parameters.
|
||||
* It's ok if redundant tests are removed.
|
||||
|
||||
**Generated test coverage**: the goal is to check that automatically
|
||||
generated tests have as much coverage as before. This is normally validated
|
||||
by comparing the test cases that are automatically generated by a script.
|
||||
A failure is a generated test case that is no longer present with the same
|
||||
function name and parameter list.
|
||||
|
||||
* It's ok if the same test data is present, but its presentation has changed,
|
||||
for example if a test function is renamed or has different parameters.
|
||||
* It's ok if redundant tests are removed.
|
||||
|
||||
"""
|
||||
|
||||
# Copyright The Mbed TLS Contributors
|
||||
# SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
|
||||
import glob
|
||||
import os
|
||||
import re
|
||||
import sys
|
||||
import traceback
|
||||
import shutil
|
||||
import subprocess
|
||||
import argparse
|
||||
import logging
|
||||
import tempfile
|
||||
import filecmp
|
||||
import fnmatch
|
||||
from types import SimpleNamespace
|
||||
|
||||
import xml.etree.ElementTree as ET
|
||||
|
||||
from . import build_tree
|
||||
|
||||
|
||||
class AbiChecker:
|
||||
"""API and ABI checker."""
|
||||
|
||||
def __init__(self, old_version, new_version, configuration):
|
||||
"""Instantiate the API/ABI checker.
|
||||
|
||||
old_version: RepoVersion containing details to compare against
|
||||
new_version: RepoVersion containing details to check
|
||||
configuration.report_dir: directory for output files
|
||||
configuration.keep_all_reports: if false, delete old reports
|
||||
configuration.brief: if true, output shorter report to stdout
|
||||
configuration.check_abi: if true, compare ABIs
|
||||
configuration.check_api: if true, compare APIs
|
||||
configuration.check_storage: if true, compare storage format tests
|
||||
configuration.skip_file: path to file containing symbols and types to skip
|
||||
"""
|
||||
self.repo_path = build_tree.guess_project_root()
|
||||
self.log = None
|
||||
self.verbose = configuration.verbose
|
||||
self._setup_logger()
|
||||
self.report_dir = os.path.abspath(configuration.report_dir)
|
||||
self.keep_all_reports = configuration.keep_all_reports
|
||||
self.can_remove_report_dir = not (os.path.exists(self.report_dir) or
|
||||
self.keep_all_reports)
|
||||
self.old_version = old_version
|
||||
self.new_version = new_version
|
||||
self.skip_file = configuration.skip_file
|
||||
self.check_abi = configuration.check_abi
|
||||
self.check_api = configuration.check_api
|
||||
if self.check_abi != self.check_api:
|
||||
raise Exception('Checking API without ABI or vice versa is not supported')
|
||||
self.check_storage_tests = configuration.check_storage
|
||||
self.brief = configuration.brief
|
||||
self.git_command = "git"
|
||||
self.cmake_command = "cmake"
|
||||
|
||||
def _setup_logger(self):
|
||||
self.log = logging.getLogger()
|
||||
if self.verbose:
|
||||
self.log.setLevel(logging.DEBUG)
|
||||
else:
|
||||
self.log.setLevel(logging.INFO)
|
||||
self.log.addHandler(logging.StreamHandler())
|
||||
|
||||
@staticmethod
|
||||
def check_abi_tools_are_installed():
|
||||
for command in ["abi-dumper", "abi-compliance-checker"]:
|
||||
if not shutil.which(command):
|
||||
raise Exception("{} not installed, aborting".format(command))
|
||||
|
||||
def _get_clean_worktree_for_git_revision(self, version):
|
||||
"""Make a separate worktree with version.revision checked out.
|
||||
Do not modify the current worktree."""
|
||||
git_worktree_path = tempfile.mkdtemp()
|
||||
if version.repository:
|
||||
self.log.debug(
|
||||
"Checking out git worktree for revision {} from {}".format(
|
||||
version.revision, version.repository
|
||||
)
|
||||
)
|
||||
fetch_output = subprocess.check_output(
|
||||
[self.git_command, "fetch",
|
||||
version.repository, version.revision],
|
||||
cwd=self.repo_path,
|
||||
stderr=subprocess.STDOUT
|
||||
)
|
||||
self.log.debug(fetch_output.decode("utf-8"))
|
||||
worktree_rev = "FETCH_HEAD"
|
||||
else:
|
||||
self.log.debug("Checking out git worktree for revision {}".format(
|
||||
version.revision
|
||||
))
|
||||
worktree_rev = version.revision
|
||||
worktree_output = subprocess.check_output(
|
||||
[self.git_command, "worktree", "add", "--detach",
|
||||
git_worktree_path, worktree_rev],
|
||||
cwd=self.repo_path,
|
||||
stderr=subprocess.STDOUT
|
||||
)
|
||||
self.log.debug(worktree_output.decode("utf-8"))
|
||||
version.commit = subprocess.check_output(
|
||||
[self.git_command, "rev-parse", "HEAD"],
|
||||
cwd=git_worktree_path,
|
||||
stderr=subprocess.STDOUT
|
||||
).decode("ascii").rstrip()
|
||||
self.log.debug("Commit is {}".format(version.commit))
|
||||
return git_worktree_path
|
||||
|
||||
def _update_git_submodules(self, git_worktree_path):
|
||||
"""Recursively checkout all submodules at the revision recorded in their
|
||||
parent module"""
|
||||
submodule_output = subprocess.check_output(
|
||||
[self.git_command, "submodule", "foreach", "--recursive",
|
||||
f'git worktree add --detach "{git_worktree_path}/$displaypath" HEAD'],
|
||||
cwd=self.repo_path,
|
||||
stderr=subprocess.STDOUT
|
||||
)
|
||||
self.log.debug(submodule_output.decode("utf-8"))
|
||||
|
||||
try:
|
||||
# Try to update the submodules using local commits
|
||||
# (Git will sometimes insist on fetching the remote without --no-fetch
|
||||
# if the submodules are shallow clones)
|
||||
update_output = subprocess.check_output(
|
||||
[self.git_command, "submodule", "update", "--init", '--recursive', '--no-fetch'],
|
||||
cwd=git_worktree_path,
|
||||
stderr=subprocess.STDOUT
|
||||
)
|
||||
except subprocess.CalledProcessError as err:
|
||||
self.log.debug(err.stdout.decode("utf-8"))
|
||||
|
||||
# Checkout with --no-fetch failed, falling back to fetching from origin
|
||||
update_output = subprocess.check_output(
|
||||
[self.git_command, "submodule", "update", "--init", '--recursive'],
|
||||
cwd=git_worktree_path,
|
||||
stderr=subprocess.STDOUT
|
||||
)
|
||||
self.log.debug(update_output.decode("utf-8"))
|
||||
|
||||
def _build_shared_libraries(self, git_worktree_path, version):
|
||||
"""Build the shared libraries in the specified worktree."""
|
||||
build_dir = os.path.join(git_worktree_path, "build")
|
||||
os.mkdir(build_dir)
|
||||
configure_output = subprocess.check_output(
|
||||
[
|
||||
self.cmake_command, "..",
|
||||
"-DCMAKE_BUILD_TYPE=Debug",
|
||||
"-DENABLE_TESTING=OFF",
|
||||
"-DENABLE_PROGRAMS=OFF",
|
||||
"-DUSE_SHARED_MBEDTLS_LIBRARY=ON",
|
||||
"-DUSE_STATIC_MBEDTLS_LIBRARY=OFF",
|
||||
"-DUSE_SHARED_TF_PSA_CRYPTO_LIBRARY=ON",
|
||||
"-DUSE_STATIC_TF_PSA_CRYPTO_LIBRARY=OFF",
|
||||
],
|
||||
cwd=build_dir,
|
||||
stderr=subprocess.STDOUT
|
||||
)
|
||||
self.log.debug(configure_output.decode("utf-8"))
|
||||
|
||||
build_output = subprocess.check_output(
|
||||
[self.cmake_command, "--build", build_dir],
|
||||
stderr=subprocess.STDOUT
|
||||
)
|
||||
self.log.debug(build_output.decode("utf-8"))
|
||||
for root, _dirs, files in os.walk(build_dir):
|
||||
for file in fnmatch.filter(files, "*.so"):
|
||||
basename = os.path.splitext(file)[0]
|
||||
path = os.path.join(root, file)
|
||||
if basename in version.modules:
|
||||
if not filecmp.cmp(version.modules[basename], path):
|
||||
raise Exception(
|
||||
"The following libraries differ, but have the same name:\n"
|
||||
f"{version.modules[basename]}\n"
|
||||
f"{path}"
|
||||
)
|
||||
else:
|
||||
version.modules[basename] = path
|
||||
|
||||
@staticmethod
|
||||
def _pretty_revision(version):
|
||||
if version.revision == version.commit:
|
||||
return version.revision
|
||||
else:
|
||||
return "{} ({})".format(version.revision, version.commit)
|
||||
|
||||
def _get_abi_dumps_from_shared_libraries(self, version):
|
||||
"""Generate the ABI dumps for the specified git revision.
|
||||
The shared libraries must have been built and the module paths
|
||||
present in version.modules."""
|
||||
for mbed_module, module_path in version.modules.items():
|
||||
output_path = os.path.join(
|
||||
self.report_dir, "{}-{}-{}.dump".format(
|
||||
mbed_module, version.revision, version.version
|
||||
)
|
||||
)
|
||||
abi_dump_command = [
|
||||
"abi-dumper",
|
||||
module_path,
|
||||
"-o", output_path,
|
||||
"-lver", self._pretty_revision(version),
|
||||
]
|
||||
abi_dump_output = subprocess.check_output(
|
||||
abi_dump_command,
|
||||
stderr=subprocess.STDOUT
|
||||
)
|
||||
self.log.debug(abi_dump_output.decode("utf-8"))
|
||||
version.abi_dumps[mbed_module] = output_path
|
||||
|
||||
@staticmethod
|
||||
def _normalize_storage_test_case_data(line):
|
||||
"""Eliminate cosmetic or irrelevant details in storage format test cases."""
|
||||
line = re.sub(r'\s+', r'', line)
|
||||
return line
|
||||
|
||||
def _read_storage_tests(self,
|
||||
directory,
|
||||
filename,
|
||||
is_generated,
|
||||
storage_tests):
|
||||
"""Record storage tests from the given file.
|
||||
|
||||
Populate the storage_tests dictionary with test cases read from
|
||||
filename under directory.
|
||||
"""
|
||||
at_paragraph_start = True
|
||||
description = None
|
||||
full_path = os.path.join(directory, filename)
|
||||
with open(full_path) as fd:
|
||||
for line_number, line in enumerate(fd, 1):
|
||||
line = line.strip()
|
||||
if not line:
|
||||
at_paragraph_start = True
|
||||
continue
|
||||
if line.startswith('#'):
|
||||
continue
|
||||
if at_paragraph_start:
|
||||
description = line.strip()
|
||||
at_paragraph_start = False
|
||||
continue
|
||||
if line.startswith('depends_on:'):
|
||||
continue
|
||||
# We've reached a test case data line
|
||||
test_case_data = self._normalize_storage_test_case_data(line)
|
||||
if not is_generated:
|
||||
# In manual test data, only look at read tests.
|
||||
function_name = test_case_data.split(':', 1)[0]
|
||||
if 'read' not in function_name.split('_'):
|
||||
continue
|
||||
metadata = SimpleNamespace(
|
||||
filename=filename,
|
||||
line_number=line_number,
|
||||
description=description
|
||||
)
|
||||
storage_tests[test_case_data] = metadata
|
||||
|
||||
@staticmethod
|
||||
def _list_generated_test_data_files(git_worktree_path):
|
||||
"""List the generated test data files."""
|
||||
generate_psa_tests = 'framework/scripts/generate_psa_tests.py'
|
||||
if not os.path.isfile(git_worktree_path + '/' + generate_psa_tests):
|
||||
# The checked-out revision is from before generate_psa_tests.py
|
||||
# was moved to the framework submodule. Use the old location.
|
||||
generate_psa_tests = 'tests/scripts/generate_psa_tests.py'
|
||||
|
||||
output = subprocess.check_output(
|
||||
[generate_psa_tests, '--list'],
|
||||
cwd=git_worktree_path,
|
||||
).decode('ascii')
|
||||
return [line for line in output.split('\n') if line]
|
||||
|
||||
def _get_storage_format_tests(self, version, git_worktree_path):
|
||||
"""Record the storage format tests for the specified git version.
|
||||
|
||||
The storage format tests are the test suite data files whose name
|
||||
contains "storage_format".
|
||||
|
||||
The version must be checked out at git_worktree_path.
|
||||
|
||||
This function creates or updates the generated data files.
|
||||
"""
|
||||
# Existing test data files. This may be missing some automatically
|
||||
# generated files if they haven't been generated yet.
|
||||
if os.path.isdir(os.path.join(git_worktree_path, 'tf-psa-crypto',
|
||||
'tests', 'suites')):
|
||||
storage_data_files = set(glob.glob(
|
||||
'tf-psa-crypto/tests/suites/test_suite_*storage_format*.data'
|
||||
))
|
||||
else:
|
||||
storage_data_files = set(glob.glob(
|
||||
'tests/suites/test_suite_*storage_format*.data'
|
||||
))
|
||||
# Discover and (re)generate automatically generated data files.
|
||||
to_be_generated = set()
|
||||
for filename in self._list_generated_test_data_files(git_worktree_path):
|
||||
if 'storage_format' in filename:
|
||||
storage_data_files.add(filename)
|
||||
to_be_generated.add(filename)
|
||||
|
||||
generate_psa_tests = 'framework/scripts/generate_psa_tests.py'
|
||||
if not os.path.isfile(git_worktree_path + '/' + generate_psa_tests):
|
||||
# The checked-out revision is from before generate_psa_tests.py
|
||||
# was moved to the framework submodule. Use the old location.
|
||||
generate_psa_tests = 'tests/scripts/generate_psa_tests.py'
|
||||
subprocess.check_call(
|
||||
[generate_psa_tests] + sorted(to_be_generated),
|
||||
cwd=git_worktree_path,
|
||||
)
|
||||
for test_file in sorted(storage_data_files):
|
||||
self._read_storage_tests(git_worktree_path,
|
||||
test_file,
|
||||
test_file in to_be_generated,
|
||||
version.storage_tests)
|
||||
|
||||
def _cleanup_worktree(self, git_worktree_path):
|
||||
"""Remove the specified git worktree."""
|
||||
shutil.rmtree(git_worktree_path)
|
||||
submodule_output = subprocess.check_output(
|
||||
[self.git_command, "submodule", "foreach", "--recursive",
|
||||
f'git worktree remove "{git_worktree_path}/$displaypath"'],
|
||||
cwd=self.repo_path,
|
||||
stderr=subprocess.STDOUT
|
||||
)
|
||||
self.log.debug(submodule_output.decode("utf-8"))
|
||||
worktree_output = subprocess.check_output(
|
||||
[self.git_command, "worktree", "remove", git_worktree_path],
|
||||
cwd=self.repo_path,
|
||||
stderr=subprocess.STDOUT
|
||||
)
|
||||
self.log.debug(worktree_output.decode("utf-8"))
|
||||
|
||||
def _get_abi_dump_for_ref(self, version):
|
||||
"""Generate the interface information for the specified git revision."""
|
||||
git_worktree_path = self._get_clean_worktree_for_git_revision(version)
|
||||
self._update_git_submodules(git_worktree_path)
|
||||
if self.check_abi:
|
||||
self._build_shared_libraries(git_worktree_path, version)
|
||||
self._get_abi_dumps_from_shared_libraries(version)
|
||||
if self.check_storage_tests:
|
||||
self._get_storage_format_tests(version, git_worktree_path)
|
||||
self._cleanup_worktree(git_worktree_path)
|
||||
|
||||
def _remove_children_with_tag(self, parent, tag):
|
||||
children = parent.getchildren()
|
||||
for child in children:
|
||||
if child.tag == tag:
|
||||
parent.remove(child)
|
||||
else:
|
||||
self._remove_children_with_tag(child, tag)
|
||||
|
||||
def _remove_extra_detail_from_report(self, report_root):
|
||||
for tag in ['test_info', 'test_results', 'problem_summary',
|
||||
'added_symbols', 'affected']:
|
||||
self._remove_children_with_tag(report_root, tag)
|
||||
|
||||
for report in report_root:
|
||||
for problems in report.getchildren()[:]:
|
||||
if not problems.getchildren():
|
||||
report.remove(problems)
|
||||
|
||||
def _abi_compliance_command(self, mbed_module, output_path):
|
||||
"""Build the command to run to analyze the library mbed_module.
|
||||
The report will be placed in output_path."""
|
||||
abi_compliance_command = [
|
||||
"abi-compliance-checker",
|
||||
"-l", mbed_module,
|
||||
"-old", self.old_version.abi_dumps[mbed_module],
|
||||
"-new", self.new_version.abi_dumps[mbed_module],
|
||||
"-strict",
|
||||
"-report-path", output_path,
|
||||
]
|
||||
if self.skip_file:
|
||||
abi_compliance_command += ["-skip-symbols", self.skip_file,
|
||||
"-skip-types", self.skip_file]
|
||||
if self.brief:
|
||||
abi_compliance_command += ["-report-format", "xml",
|
||||
"-stdout"]
|
||||
return abi_compliance_command
|
||||
|
||||
def _is_library_compatible(self, mbed_module, compatibility_report):
|
||||
"""Test if the library mbed_module has remained compatible.
|
||||
Append a message regarding compatibility to compatibility_report."""
|
||||
output_path = os.path.join(
|
||||
self.report_dir, "{}-{}-{}.html".format(
|
||||
mbed_module, self.old_version.revision,
|
||||
self.new_version.revision
|
||||
)
|
||||
)
|
||||
try:
|
||||
subprocess.check_output(
|
||||
self._abi_compliance_command(mbed_module, output_path),
|
||||
stderr=subprocess.STDOUT
|
||||
)
|
||||
except subprocess.CalledProcessError as err:
|
||||
if err.returncode != 1:
|
||||
raise err
|
||||
if self.brief:
|
||||
self.log.info(
|
||||
"Compatibility issues found for {}".format(mbed_module)
|
||||
)
|
||||
report_root = ET.fromstring(err.output.decode("utf-8"))
|
||||
self._remove_extra_detail_from_report(report_root)
|
||||
self.log.info(ET.tostring(report_root).decode("utf-8"))
|
||||
else:
|
||||
self.can_remove_report_dir = False
|
||||
compatibility_report.append(
|
||||
"Compatibility issues found for {}, "
|
||||
"for details see {}".format(mbed_module, output_path)
|
||||
)
|
||||
return False
|
||||
compatibility_report.append(
|
||||
"No compatibility issues for {}".format(mbed_module)
|
||||
)
|
||||
if not (self.keep_all_reports or self.brief):
|
||||
os.remove(output_path)
|
||||
return True
|
||||
|
||||
@staticmethod
|
||||
def _is_storage_format_compatible(old_tests, new_tests,
|
||||
compatibility_report):
|
||||
"""Check whether all tests present in old_tests are also in new_tests.
|
||||
|
||||
Append a message regarding compatibility to compatibility_report.
|
||||
"""
|
||||
missing = frozenset(old_tests.keys()).difference(new_tests.keys())
|
||||
for test_data in sorted(missing):
|
||||
metadata = old_tests[test_data]
|
||||
compatibility_report.append(
|
||||
'Test case from {} line {} "{}" has disappeared: {}'.format(
|
||||
metadata.filename, metadata.line_number,
|
||||
metadata.description, test_data
|
||||
)
|
||||
)
|
||||
compatibility_report.append(
|
||||
'FAIL: {}/{} storage format test cases have changed or disappeared.'.format(
|
||||
len(missing), len(old_tests)
|
||||
) if missing else
|
||||
'PASS: All {} storage format test cases are preserved.'.format(
|
||||
len(old_tests)
|
||||
)
|
||||
)
|
||||
compatibility_report.append(
|
||||
'Info: number of storage format tests cases: {} -> {}.'.format(
|
||||
len(old_tests), len(new_tests)
|
||||
)
|
||||
)
|
||||
return not missing
|
||||
|
||||
def get_abi_compatibility_report(self):
|
||||
"""Generate a report of the differences between the reference ABI
|
||||
and the new ABI. ABI dumps from self.old_version and self.new_version
|
||||
must be available."""
|
||||
compatibility_report = ["Checking evolution from {} to {}".format(
|
||||
self._pretty_revision(self.old_version),
|
||||
self._pretty_revision(self.new_version)
|
||||
)]
|
||||
compliance_return_code = 0
|
||||
|
||||
if self.check_abi:
|
||||
shared_modules = list(set(self.old_version.modules.keys()) &
|
||||
set(self.new_version.modules.keys()))
|
||||
for mbed_module in shared_modules:
|
||||
if not self._is_library_compatible(mbed_module,
|
||||
compatibility_report):
|
||||
compliance_return_code = 1
|
||||
|
||||
if self.check_storage_tests:
|
||||
if not self._is_storage_format_compatible(
|
||||
self.old_version.storage_tests,
|
||||
self.new_version.storage_tests,
|
||||
compatibility_report):
|
||||
compliance_return_code = 1
|
||||
|
||||
for version in [self.old_version, self.new_version]:
|
||||
for mbed_module, mbed_module_dump in version.abi_dumps.items():
|
||||
os.remove(mbed_module_dump)
|
||||
if self.can_remove_report_dir:
|
||||
os.rmdir(self.report_dir)
|
||||
self.log.info("\n".join(compatibility_report))
|
||||
return compliance_return_code
|
||||
|
||||
def check_for_abi_changes(self):
|
||||
"""Generate a report of ABI differences
|
||||
between self.old_rev and self.new_rev."""
|
||||
try:
|
||||
if self.check_api or self.check_abi:
|
||||
self.check_abi_tools_are_installed()
|
||||
self._get_abi_dump_for_ref(self.old_version)
|
||||
self._get_abi_dump_for_ref(self.new_version)
|
||||
return self.get_abi_compatibility_report()
|
||||
except subprocess.CalledProcessError as err:
|
||||
self.log.error(err.stdout.decode("utf-8"))
|
||||
raise err
|
||||
|
||||
|
||||
def run_main():
|
||||
try:
|
||||
parser = argparse.ArgumentParser(
|
||||
description=__doc__,
|
||||
formatter_class=argparse.RawDescriptionHelpFormatter
|
||||
)
|
||||
parser.add_argument(
|
||||
"-v", "--verbose", action="store_true",
|
||||
help="set verbosity level",
|
||||
)
|
||||
parser.add_argument(
|
||||
"-r", "--report-dir", type=str, default="reports",
|
||||
help="directory where reports are stored, default is reports",
|
||||
)
|
||||
parser.add_argument(
|
||||
"-k", "--keep-all-reports", action="store_true",
|
||||
help="keep all reports, even if there are no compatibility issues",
|
||||
)
|
||||
parser.add_argument(
|
||||
"-o", "--old-rev", type=str, help="revision for old version.",
|
||||
required=True,
|
||||
)
|
||||
parser.add_argument(
|
||||
"-or", "--old-repo", type=str, help="repository for old version."
|
||||
)
|
||||
parser.add_argument(
|
||||
"-n", "--new-rev", type=str, help="revision for new version",
|
||||
required=True,
|
||||
)
|
||||
parser.add_argument(
|
||||
"-nr", "--new-repo", type=str, help="repository for new version."
|
||||
)
|
||||
parser.add_argument(
|
||||
"-s", "--skip-file", type=str,
|
||||
help=("path to file containing symbols and types to skip "
|
||||
"(typically \"-s identifiers\" after running "
|
||||
"\"tests/scripts/list-identifiers.sh --internal\")")
|
||||
)
|
||||
parser.add_argument(
|
||||
"--check-abi",
|
||||
action='store_true', default=True,
|
||||
help="Perform ABI comparison (default: yes)"
|
||||
)
|
||||
parser.add_argument("--no-check-abi", action='store_false', dest='check_abi')
|
||||
parser.add_argument(
|
||||
"--check-api",
|
||||
action='store_true', default=True,
|
||||
help="Perform API comparison (default: yes)"
|
||||
)
|
||||
parser.add_argument("--no-check-api", action='store_false', dest='check_api')
|
||||
parser.add_argument(
|
||||
"--check-storage",
|
||||
action='store_true', default=True,
|
||||
help="Perform storage tests comparison (default: yes)"
|
||||
)
|
||||
parser.add_argument("--no-check-storage", action='store_false', dest='check_storage')
|
||||
parser.add_argument(
|
||||
"-b", "--brief", action="store_true",
|
||||
help="output only the list of issues to stdout, instead of a full report",
|
||||
)
|
||||
abi_args = parser.parse_args()
|
||||
if os.path.isfile(abi_args.report_dir):
|
||||
parser.error("{} is not a directory".format(abi_args.report_dir))
|
||||
old_version = SimpleNamespace(
|
||||
version="old",
|
||||
repository=abi_args.old_repo,
|
||||
revision=abi_args.old_rev,
|
||||
commit=None,
|
||||
abi_dumps={},
|
||||
storage_tests={},
|
||||
modules={}
|
||||
)
|
||||
new_version = SimpleNamespace(
|
||||
version="new",
|
||||
repository=abi_args.new_repo,
|
||||
revision=abi_args.new_rev,
|
||||
commit=None,
|
||||
abi_dumps={},
|
||||
storage_tests={},
|
||||
modules={}
|
||||
)
|
||||
configuration = SimpleNamespace(
|
||||
verbose=abi_args.verbose,
|
||||
report_dir=abi_args.report_dir,
|
||||
keep_all_reports=abi_args.keep_all_reports,
|
||||
brief=abi_args.brief,
|
||||
check_abi=abi_args.check_abi,
|
||||
check_api=abi_args.check_api,
|
||||
check_storage=abi_args.check_storage,
|
||||
skip_file=abi_args.skip_file
|
||||
)
|
||||
abi_check = AbiChecker(old_version, new_version, configuration)
|
||||
return_code = abi_check.check_for_abi_changes()
|
||||
sys.exit(return_code)
|
||||
except Exception: # pylint: disable=broad-except
|
||||
# Print the backtrace and exit explicitly so as to exit with
|
||||
# status 2, not 1.
|
||||
traceback.print_exc()
|
||||
sys.exit(2)
|
||||
46
vendor/mbedtls/framework/scripts/mbedtls_framework/logging_util.py
vendored
Normal file
46
vendor/mbedtls/framework/scripts/mbedtls_framework/logging_util.py
vendored
Normal file
@@ -0,0 +1,46 @@
|
||||
"""Auxiliary functions used for logging module.
|
||||
"""
|
||||
|
||||
# Copyright The Mbed TLS Contributors
|
||||
# SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
#
|
||||
|
||||
import logging
|
||||
import sys
|
||||
|
||||
def configure_logger(
|
||||
logger: logging.Logger,
|
||||
log_format="[%(levelname)s]: %(message)s",
|
||||
split_level=logging.WARNING
|
||||
) -> None:
|
||||
"""
|
||||
Configure the logging.Logger instance so that:
|
||||
- Format is set to any log_format.
|
||||
Default: "[%(levelname)s]: %(message)s"
|
||||
- loglevel >= split_level are printed to stderr.
|
||||
- loglevel < split_level are printed to stdout.
|
||||
Default: logging.WARNING
|
||||
"""
|
||||
class MaxLevelFilter(logging.Filter):
|
||||
# pylint: disable=too-few-public-methods
|
||||
def __init__(self, max_level, name=''):
|
||||
super().__init__(name)
|
||||
self.max_level = max_level
|
||||
|
||||
def filter(self, record: logging.LogRecord) -> bool:
|
||||
return record.levelno <= self.max_level
|
||||
|
||||
log_formatter = logging.Formatter(log_format)
|
||||
|
||||
# set loglevel >= split_level to be printed to stderr
|
||||
stderr_hdlr = logging.StreamHandler(sys.stderr)
|
||||
stderr_hdlr.setLevel(split_level)
|
||||
stderr_hdlr.setFormatter(log_formatter)
|
||||
|
||||
# set loglevel < split_level to be printed to stdout
|
||||
stdout_hdlr = logging.StreamHandler(sys.stdout)
|
||||
stdout_hdlr.addFilter(MaxLevelFilter(split_level - 1))
|
||||
stdout_hdlr.setFormatter(log_formatter)
|
||||
|
||||
logger.addHandler(stderr_hdlr)
|
||||
logger.addHandler(stdout_hdlr)
|
||||
572
vendor/mbedtls/framework/scripts/mbedtls_framework/macro_collector.py
vendored
Normal file
572
vendor/mbedtls/framework/scripts/mbedtls_framework/macro_collector.py
vendored
Normal file
@@ -0,0 +1,572 @@
|
||||
"""Collect macro definitions from header files.
|
||||
"""
|
||||
|
||||
# Copyright The Mbed TLS Contributors
|
||||
# SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
#
|
||||
|
||||
import itertools
|
||||
import re
|
||||
from typing import Dict, IO, Iterable, Iterator, List, Optional, Pattern, Set, Tuple, Union
|
||||
|
||||
|
||||
class ReadFileLineException(Exception):
|
||||
def __init__(self, filename: str, line_number: Union[int, str]) -> None:
|
||||
message = 'in {} at {}'.format(filename, line_number)
|
||||
super(ReadFileLineException, self).__init__(message)
|
||||
self.filename = filename
|
||||
self.line_number = line_number
|
||||
|
||||
|
||||
class read_file_lines:
|
||||
# Dear Pylint, conventionally, a context manager class name is lowercase.
|
||||
# pylint: disable=invalid-name,too-few-public-methods
|
||||
"""Context manager to read a text file line by line.
|
||||
|
||||
```
|
||||
with read_file_lines(filename) as lines:
|
||||
for line in lines:
|
||||
process(line)
|
||||
```
|
||||
is equivalent to
|
||||
```
|
||||
with open(filename, 'r') as input_file:
|
||||
for line in input_file:
|
||||
process(line)
|
||||
```
|
||||
except that if process(line) raises an exception, then the read_file_lines
|
||||
snippet annotates the exception with the file name and line number.
|
||||
"""
|
||||
def __init__(self, filename: str) -> None:
|
||||
self.filename = filename
|
||||
self.file = None #type: Optional[IO[str]]
|
||||
self.line_number = 'entry' #type: Union[int, str]
|
||||
self.generator = None #type: Optional[Iterable[Tuple[int, str]]]
|
||||
def __enter__(self) -> 'read_file_lines':
|
||||
self.file = open(self.filename)
|
||||
self.generator = enumerate(self.file)
|
||||
return self
|
||||
def __iter__(self) -> Iterator[str]:
|
||||
assert self.generator is not None
|
||||
for line_number, content in self.generator:
|
||||
self.line_number = line_number
|
||||
yield content
|
||||
self.line_number = 'exit'
|
||||
def __exit__(self, exc_type, exc_value, exc_traceback) -> None:
|
||||
if self.file is not None:
|
||||
self.file.close()
|
||||
if exc_type is not None:
|
||||
raise ReadFileLineException(self.filename, self.line_number) \
|
||||
from exc_value
|
||||
|
||||
|
||||
class PSAMacroEnumerator:
|
||||
"""Information about constructors of various PSA Crypto types.
|
||||
|
||||
This includes macro names as well as information about their arguments
|
||||
when applicable.
|
||||
|
||||
This class only provides ways to enumerate expressions that evaluate to
|
||||
values of the covered types. Derived classes are expected to populate
|
||||
the set of known constructors of each kind, as well as populate
|
||||
`self.arguments_for` for arguments that are not of a kind that is
|
||||
enumerated here.
|
||||
"""
|
||||
#pylint: disable=too-many-instance-attributes
|
||||
|
||||
def __init__(self) -> None:
|
||||
"""Set up an empty set of known constructor macros.
|
||||
"""
|
||||
self.statuses = set() #type: Set[str]
|
||||
self.lifetimes = set() #type: Set[str]
|
||||
self.locations = set() #type: Set[str]
|
||||
self.persistence_levels = set() #type: Set[str]
|
||||
self.algorithms = set() #type: Set[str]
|
||||
self.ecc_curves = set() #type: Set[str]
|
||||
self.dh_groups = set() #type: Set[str]
|
||||
self.key_types = set() #type: Set[str]
|
||||
self.key_usage_flags = set() #type: Set[str]
|
||||
self.hash_algorithms = set() #type: Set[str]
|
||||
self.mac_algorithms = set() #type: Set[str]
|
||||
self.key_agreement_algorithms = set() #type: Set[str]
|
||||
self.key_derivation_algorithms = set() #type: Set[str]
|
||||
self.pake_algorithms = set() #type: Set[str]
|
||||
self.aead_algorithms = set() #type: Set[str]
|
||||
self.sign_algorithms = set() #type: Set[str]
|
||||
# macro name -> list of argument names
|
||||
self.argspecs = {} #type: Dict[str, List[str]]
|
||||
# argument name -> list of values
|
||||
self.arguments_for = {
|
||||
'mac_length': [],
|
||||
'min_mac_length': [],
|
||||
'tag_length': [],
|
||||
'min_tag_length': [],
|
||||
} #type: Dict[str, List[str]]
|
||||
# Whether to include intermediate macros in enumerations. Intermediate
|
||||
# macros serve as category headers and are not valid values of their
|
||||
# type. See `is_internal_name`.
|
||||
# Always false in this class, may be set to true in derived classes.
|
||||
self.include_intermediate = False
|
||||
# Deprecated backward compatibility alias for generate_psa_constants.py.
|
||||
self.ka_algorithms = self.key_agreement_algorithms
|
||||
|
||||
def is_internal_name(self, name: str) -> bool:
|
||||
"""Whether this is an internal macro. Internal macros will be skipped."""
|
||||
if not self.include_intermediate:
|
||||
if name.endswith('_BASE') or name.endswith('_NONE'):
|
||||
return True
|
||||
if '_CATEGORY_' in name:
|
||||
return True
|
||||
return name.endswith('_FLAG') or name.endswith('_MASK')
|
||||
|
||||
def gather_arguments(self) -> None:
|
||||
"""Populate the list of values for macro arguments.
|
||||
|
||||
Call this after parsing all the inputs.
|
||||
"""
|
||||
self.arguments_for['hash_alg'] = sorted(self.hash_algorithms)
|
||||
self.arguments_for['mac_alg'] = sorted(self.mac_algorithms)
|
||||
self.arguments_for['ka_alg'] = sorted(self.key_agreement_algorithms)
|
||||
self.arguments_for['kdf_alg'] = sorted(self.key_derivation_algorithms)
|
||||
self.arguments_for['aead_alg'] = sorted(self.aead_algorithms)
|
||||
self.arguments_for['sign_alg'] = sorted(self.sign_algorithms)
|
||||
self.arguments_for['curve'] = sorted(self.ecc_curves)
|
||||
self.arguments_for['group'] = sorted(self.dh_groups)
|
||||
self.arguments_for['persistence'] = sorted(self.persistence_levels)
|
||||
self.arguments_for['location'] = sorted(self.locations)
|
||||
self.arguments_for['lifetime'] = sorted(self.lifetimes)
|
||||
|
||||
@staticmethod
|
||||
def _format_arguments(name: str, arguments: Iterable[str]) -> str:
|
||||
"""Format a macro call with arguments.
|
||||
|
||||
The resulting format is consistent with
|
||||
`InputsForTest.normalize_argument`.
|
||||
"""
|
||||
return name + '(' + ', '.join(arguments) + ')'
|
||||
|
||||
_argument_split_re = re.compile(r' *, *')
|
||||
@classmethod
|
||||
def _argument_split(cls, arguments: str) -> List[str]:
|
||||
return re.split(cls._argument_split_re, arguments)
|
||||
|
||||
def distribute_arguments(self, name: str) -> Iterator[str]:
|
||||
"""Generate macro calls with each tested argument set.
|
||||
|
||||
If name is a macro without arguments, just yield "name".
|
||||
If name is a macro with arguments, yield a series of
|
||||
"name(arg1,...,argN)" where each argument takes each possible
|
||||
value at least once.
|
||||
"""
|
||||
try:
|
||||
if name not in self.argspecs:
|
||||
yield name
|
||||
return
|
||||
argspec = self.argspecs[name]
|
||||
if argspec == []:
|
||||
yield name + '()'
|
||||
return
|
||||
argument_lists = [self.arguments_for[arg] for arg in argspec]
|
||||
arguments = [values[0] for values in argument_lists]
|
||||
yield self._format_arguments(name, arguments)
|
||||
# Dear Pylint, enumerate won't work here since we're modifying
|
||||
# the array.
|
||||
# pylint: disable=consider-using-enumerate
|
||||
for i in range(len(arguments)):
|
||||
for value in argument_lists[i][1:]:
|
||||
arguments[i] = value
|
||||
yield self._format_arguments(name, arguments)
|
||||
arguments[i] = argument_lists[i][0]
|
||||
except BaseException as e:
|
||||
raise Exception('distribute_arguments({})'.format(name)) from e
|
||||
|
||||
def distribute_arguments_without_duplicates(
|
||||
self, seen: Set[str], name: str
|
||||
) -> Iterator[str]:
|
||||
"""Same as `distribute_arguments`, but don't repeat seen results."""
|
||||
for result in self.distribute_arguments(name):
|
||||
if result not in seen:
|
||||
seen.add(result)
|
||||
yield result
|
||||
|
||||
def generate_expressions(self, names: Iterable[str]) -> Iterator[str]:
|
||||
"""Generate expressions covering values constructed from the given names.
|
||||
|
||||
`names` can be any iterable collection of macro names.
|
||||
|
||||
For example:
|
||||
* ``generate_expressions(['PSA_ALG_CMAC', 'PSA_ALG_HMAC'])``
|
||||
generates ``'PSA_ALG_CMAC'`` as well as ``'PSA_ALG_HMAC(h)'`` for
|
||||
every known hash algorithm ``h``.
|
||||
* ``macros.generate_expressions(macros.key_types)`` generates all
|
||||
key types.
|
||||
"""
|
||||
seen = set() #type: Set[str]
|
||||
return itertools.chain(*(
|
||||
self.distribute_arguments_without_duplicates(seen, name)
|
||||
for name in names
|
||||
))
|
||||
|
||||
|
||||
class PSAMacroCollector(PSAMacroEnumerator):
|
||||
"""Collect PSA crypto macro definitions from C header files.
|
||||
"""
|
||||
|
||||
def __init__(self, include_intermediate: bool = False) -> None:
|
||||
"""Set up an object to collect PSA macro definitions.
|
||||
|
||||
Call the read_file method of the constructed object on each header file.
|
||||
|
||||
* include_intermediate: if true, include intermediate macros such as
|
||||
PSA_XXX_BASE that do not designate semantic values.
|
||||
"""
|
||||
super().__init__()
|
||||
self.include_intermediate = include_intermediate
|
||||
self.key_types_from_curve = {} #type: Dict[str, str]
|
||||
self.key_types_from_group = {} #type: Dict[str, str]
|
||||
self.algorithms_from_hash = {} #type: Dict[str, str]
|
||||
|
||||
@staticmethod
|
||||
def algorithm_tester(name: str) -> str:
|
||||
"""The predicate for whether an algorithm is built from the given constructor.
|
||||
|
||||
The given name must be the name of an algorithm constructor of the
|
||||
form ``PSA_ALG_xxx`` which is used as ``PSA_ALG_xxx(yyy)`` to build
|
||||
an algorithm value. Return the corresponding predicate macro which
|
||||
is used as ``predicate(alg)`` to test whether ``alg`` can be built
|
||||
as ``PSA_ALG_xxx(yyy)``. The predicate is usually called
|
||||
``PSA_ALG_IS_xxx``.
|
||||
"""
|
||||
prefix = 'PSA_ALG_'
|
||||
assert name.startswith(prefix)
|
||||
midfix = 'IS_'
|
||||
suffix = name[len(prefix):]
|
||||
if suffix in ['DSA', 'ECDSA']:
|
||||
midfix += 'RANDOMIZED_'
|
||||
elif suffix == 'RSA_PSS':
|
||||
suffix += '_STANDARD_SALT'
|
||||
return prefix + midfix + suffix
|
||||
|
||||
def record_algorithm_subtype(self, name: str, expansion: str) -> None:
|
||||
"""Record the subtype of an algorithm constructor.
|
||||
|
||||
Given a ``PSA_ALG_xxx`` macro name and its expansion, if the algorithm
|
||||
is of a subtype that is tracked in its own set, add it to the relevant
|
||||
set.
|
||||
"""
|
||||
# This code is very ad hoc and fragile. It should be replaced by
|
||||
# something more robust.
|
||||
if re.match(r'MAC(?:_|\Z)', name):
|
||||
self.mac_algorithms.add(name)
|
||||
elif re.match(r'KDF(?:_|\Z)', name):
|
||||
self.key_derivation_algorithms.add(name)
|
||||
elif re.search(r'0x020000[0-9A-Fa-f]{2}', expansion):
|
||||
self.hash_algorithms.add(name)
|
||||
elif re.search(r'0x03[0-9A-Fa-f]{6}', expansion):
|
||||
self.mac_algorithms.add(name)
|
||||
elif re.search(r'0x05[0-9A-Fa-f]{6}', expansion):
|
||||
self.aead_algorithms.add(name)
|
||||
elif re.search(r'0x09[0-9A-Fa-f]{2}0000', expansion):
|
||||
self.key_agreement_algorithms.add(name)
|
||||
elif re.search(r'0x08[0-9A-Fa-f]{6}', expansion):
|
||||
self.key_derivation_algorithms.add(name)
|
||||
|
||||
# "#define" followed by a macro name with either no parameters
|
||||
# or a single parameter and a non-empty expansion.
|
||||
# Grab the macro name in group 1, the parameter name if any in group 2
|
||||
# and the expansion in group 3.
|
||||
_define_directive_re = re.compile(r'\s*#\s*define\s+(\w+)' +
|
||||
r'(?:\s+|\((\w+)\)\s*)' +
|
||||
r'(.+)')
|
||||
_deprecated_definition_re = re.compile(r'\s*MBEDTLS_DEPRECATED')
|
||||
|
||||
# Macro that is a destructor, not a constructor (i.e. takes a thing as
|
||||
# an argument and analyzes it, rather than constructing a thing).
|
||||
_destructor_name_re = re.compile('|'.join([
|
||||
r'.*(?:_GET_|_HAS_|_IS_)',
|
||||
r'.*_LENGTH\Z',
|
||||
r'PSA_ALG_SIGN_SUPPORTS_CONTEXT\Z',
|
||||
]))
|
||||
|
||||
# Macro that converts between things, rather than building a thing from
|
||||
# scratch.
|
||||
_conversion_macro_names = frozenset([
|
||||
'PSA_KEY_TYPE_KEY_PAIR_OF_PUBLIC_KEY',
|
||||
'PSA_KEY_TYPE_PUBLIC_KEY_OF_KEY_PAIR',
|
||||
'PSA_ALG_FULL_LENGTH_MAC',
|
||||
'PSA_ALG_AEAD_WITH_DEFAULT_LENGTH_TAG',
|
||||
'PSA_JPAKE_EXPECTED_INPUTS',
|
||||
'PSA_JPAKE_EXPECTED_OUTPUTS',
|
||||
])
|
||||
|
||||
def read_line(self, line):
|
||||
"""Parse a C header line and record the PSA identifier it defines if any.
|
||||
This function analyzes lines that start with "#define PSA_"
|
||||
(up to non-significant whitespace) and skips all non-matching lines.
|
||||
"""
|
||||
# pylint: disable=too-many-branches,too-many-return-statements
|
||||
m = re.match(self._define_directive_re, line)
|
||||
if not m:
|
||||
return
|
||||
name, parameter, expansion = m.groups()
|
||||
expansion = re.sub(r'/\*.*?\*/|//.*', r' ', expansion)
|
||||
if parameter:
|
||||
self.argspecs[name] = [parameter]
|
||||
if re.match(self._deprecated_definition_re, expansion):
|
||||
# Skip deprecated values, which are assumed to be
|
||||
# backward compatibility aliases that share
|
||||
# numerical values with non-deprecated values.
|
||||
return
|
||||
if re.match(self._destructor_name_re, name):
|
||||
# Not a constructor
|
||||
return
|
||||
if name in self._conversion_macro_names:
|
||||
# Not a constructor
|
||||
return
|
||||
if self.is_internal_name(name):
|
||||
# Macro only to build actual values
|
||||
return
|
||||
elif (name.startswith('PSA_ERROR_') or name == 'PSA_SUCCESS') \
|
||||
and not parameter:
|
||||
self.statuses.add(name)
|
||||
elif name.startswith('PSA_KEY_TYPE_') and not parameter:
|
||||
self.key_types.add(name)
|
||||
elif name.startswith('PSA_KEY_TYPE_') and parameter == 'curve':
|
||||
self.key_types_from_curve[name] = name[:13] + 'IS_' + name[13:]
|
||||
elif name.startswith('PSA_KEY_TYPE_') and parameter == 'group':
|
||||
self.key_types_from_group[name] = name[:13] + 'IS_' + name[13:]
|
||||
elif name.startswith('PSA_ECC_FAMILY_') and not parameter:
|
||||
self.ecc_curves.add(name)
|
||||
elif name.startswith('PSA_DH_FAMILY_') and not parameter:
|
||||
self.dh_groups.add(name)
|
||||
elif name.startswith('PSA_ALG_') and not parameter:
|
||||
if name in ['PSA_ALG_ECDSA_BASE',
|
||||
'PSA_ALG_RSA_PKCS1V15_SIGN_BASE']:
|
||||
# Ad hoc skipping of duplicate names for some numerical values
|
||||
return
|
||||
self.algorithms.add(name)
|
||||
self.record_algorithm_subtype(name, expansion)
|
||||
elif name.startswith('PSA_ALG_') and parameter == 'hash_alg':
|
||||
self.algorithms_from_hash[name] = self.algorithm_tester(name)
|
||||
elif name.startswith('PSA_KEY_USAGE_') and not parameter:
|
||||
self.key_usage_flags.add(name)
|
||||
elif parameter is None:
|
||||
# Macro with no parameter, whose name does not start with one
|
||||
# of the prefixes we look for. Just ignore it.
|
||||
return
|
||||
else:
|
||||
raise Exception("Unsupported macro and parameter name: {}({})"
|
||||
.format(name, parameter))
|
||||
|
||||
_nonascii_re = re.compile(rb'[^\x00-\x7f]+')
|
||||
_continued_line_re = re.compile(rb'\\\r?\n\Z')
|
||||
def read_file(self, header_file):
|
||||
for line in header_file:
|
||||
m = re.search(self._continued_line_re, line)
|
||||
while m:
|
||||
cont = next(header_file)
|
||||
line = line[:m.start(0)] + cont
|
||||
m = re.search(self._continued_line_re, line)
|
||||
line = re.sub(self._nonascii_re, rb'', line).decode('ascii')
|
||||
self.read_line(line)
|
||||
|
||||
|
||||
class InputsForTest(PSAMacroEnumerator):
|
||||
# pylint: disable=too-many-instance-attributes
|
||||
"""Accumulate information about macros to test.
|
||||
enumerate
|
||||
This includes macro names as well as information about their arguments
|
||||
when applicable.
|
||||
"""
|
||||
|
||||
def __init__(self) -> None:
|
||||
super().__init__()
|
||||
self.all_declared = set() #type: Set[str]
|
||||
# Identifier prefixes
|
||||
self.table_by_prefix = {
|
||||
'ERROR': self.statuses,
|
||||
'ALG': self.algorithms,
|
||||
'ECC_CURVE': self.ecc_curves,
|
||||
'DH_GROUP': self.dh_groups,
|
||||
'KEY_LIFETIME': self.lifetimes,
|
||||
'KEY_LOCATION': self.locations,
|
||||
'KEY_PERSISTENCE': self.persistence_levels,
|
||||
'KEY_TYPE': self.key_types,
|
||||
'KEY_USAGE': self.key_usage_flags,
|
||||
} #type: Dict[str, Set[str]]
|
||||
# Test functions
|
||||
self.table_by_test_function = {
|
||||
# Any function ending in _algorithm also gets added to
|
||||
# self.algorithms.
|
||||
'key_type': [self.key_types],
|
||||
'block_cipher_key_type': [self.key_types],
|
||||
'stream_cipher_key_type': [self.key_types],
|
||||
'ecc_key_family': [self.ecc_curves],
|
||||
'ecc_key_types': [self.ecc_curves],
|
||||
'dh_key_family': [self.dh_groups],
|
||||
'dh_key_types': [self.dh_groups],
|
||||
'hash_algorithm': [self.hash_algorithms],
|
||||
'mac_algorithm': [self.mac_algorithms],
|
||||
'cipher_algorithm': [],
|
||||
'hmac_algorithm': [self.mac_algorithms, self.sign_algorithms],
|
||||
'aead_algorithm': [self.aead_algorithms],
|
||||
'key_derivation_algorithm': [self.key_derivation_algorithms],
|
||||
'key_agreement_algorithm': [self.key_agreement_algorithms],
|
||||
'asymmetric_signature_algorithm': [self.sign_algorithms],
|
||||
'asymmetric_signature_wildcard': [self.algorithms],
|
||||
'asymmetric_encryption_algorithm': [],
|
||||
'pake_algorithm': [self.pake_algorithms],
|
||||
'key_wrap_algorithm': [],
|
||||
'key_encapsulation_algorithm': [],
|
||||
'xof_algorithm': [],
|
||||
'other_algorithm': [],
|
||||
'lifetime': [self.lifetimes],
|
||||
} #type: Dict[str, List[Set[str]]]
|
||||
mac_lengths = [str(n) for n in [
|
||||
1, # minimum expressible
|
||||
4, # minimum allowed by policy
|
||||
13, # an odd size in a plausible range
|
||||
14, # an even non-power-of-two size in a plausible range
|
||||
16, # same as full size for at least one algorithm
|
||||
63, # maximum expressible
|
||||
]]
|
||||
self.arguments_for['mac_length'] += mac_lengths
|
||||
self.arguments_for['min_mac_length'] += mac_lengths
|
||||
aead_lengths = [str(n) for n in [
|
||||
1, # minimum expressible
|
||||
4, # minimum allowed by policy
|
||||
13, # an odd size in a plausible range
|
||||
14, # an even non-power-of-two size in a plausible range
|
||||
16, # same as full size for at least one algorithm
|
||||
63, # maximum expressible
|
||||
]]
|
||||
self.arguments_for['tag_length'] += aead_lengths
|
||||
self.arguments_for['min_tag_length'] += aead_lengths
|
||||
|
||||
def add_numerical_values(self) -> None:
|
||||
"""Add numerical values that are not supported to the known identifiers."""
|
||||
# Sets of names per type
|
||||
self.algorithms.add('0xffffffff')
|
||||
self.ecc_curves.add('0xff')
|
||||
self.dh_groups.add('0xff')
|
||||
self.key_types.add('0xffff')
|
||||
self.key_usage_flags.add('0x80000000')
|
||||
|
||||
# Hard-coded values for unknown algorithms
|
||||
#
|
||||
# These have to have values that are correct for their respective
|
||||
# PSA_ALG_IS_xxx macros, but are also not currently assigned and are
|
||||
# not likely to be assigned in the near future.
|
||||
self.hash_algorithms.add('0x020000fe') # 0x020000ff is PSA_ALG_ANY_HASH
|
||||
self.mac_algorithms.add('0x03007fff')
|
||||
self.key_agreement_algorithms.add('0x09fc0000')
|
||||
self.key_derivation_algorithms.add('0x080000ff')
|
||||
self.pake_algorithms.add('0x0a0000ff')
|
||||
# For AEAD algorithms, the only variability is over the tag length,
|
||||
# and this only applies to known algorithms, so don't test an
|
||||
# unknown algorithm.
|
||||
|
||||
def get_names(self, type_word: str) -> Set[str]:
|
||||
"""Return the set of known names of values of the given type."""
|
||||
return {
|
||||
'status': self.statuses,
|
||||
'algorithm': self.algorithms,
|
||||
'ecc_curve': self.ecc_curves,
|
||||
'dh_group': self.dh_groups,
|
||||
'key_type': self.key_types,
|
||||
'key_usage': self.key_usage_flags,
|
||||
}[type_word]
|
||||
|
||||
# Regex for interesting header lines.
|
||||
# Groups: 1=macro name, 2=type, 3=argument list (optional).
|
||||
_header_line_re = \
|
||||
re.compile(r'#define +' +
|
||||
r'(PSA_((?:(?:DH|ECC|KEY)_)?[A-Z]+)_\w+)' +
|
||||
r'(?:\(([^\n()]*)\))?')
|
||||
# Regex of macro names to exclude.
|
||||
_excluded_name_re = re.compile(r'_(?:GET|HAS|IS|OF)_|_(?:BASE|FLAG|MASK)\Z')
|
||||
# Additional excluded macros.
|
||||
_excluded_names = set([
|
||||
# Macros that provide an alternative way to build the same
|
||||
# algorithm as another macro.
|
||||
'PSA_ALG_AEAD_WITH_DEFAULT_LENGTH_TAG',
|
||||
'PSA_ALG_FULL_LENGTH_MAC',
|
||||
# Auxiliary macro whose name doesn't fit the usual patterns for
|
||||
# auxiliary macros.
|
||||
'PSA_ALG_AEAD_WITH_DEFAULT_LENGTH_TAG_CASE',
|
||||
])
|
||||
def parse_header_line(self, line: str) -> None:
|
||||
"""Parse a C header line, looking for "#define PSA_xxx"."""
|
||||
m = re.match(self._header_line_re, line)
|
||||
if not m:
|
||||
return
|
||||
name = m.group(1)
|
||||
self.all_declared.add(name)
|
||||
if re.search(self._excluded_name_re, name) or \
|
||||
name in self._excluded_names or \
|
||||
self.is_internal_name(name):
|
||||
return
|
||||
dest = self.table_by_prefix.get(m.group(2))
|
||||
if dest is None:
|
||||
return
|
||||
dest.add(name)
|
||||
if m.group(3):
|
||||
self.argspecs[name] = self._argument_split(m.group(3))
|
||||
|
||||
_nonascii_re = re.compile(rb'[^\x00-\x7f]+') #type: Pattern
|
||||
def parse_header(self, filename: str) -> None:
|
||||
"""Parse a C header file, looking for "#define PSA_xxx"."""
|
||||
with open(filename, 'rb') as input_:
|
||||
for line in input_:
|
||||
line = re.sub(self._nonascii_re, rb'', line)
|
||||
self.parse_header_line(line.decode('ascii'))
|
||||
|
||||
_macro_identifier_re = re.compile(r'[A-Z]\w+')
|
||||
def generate_undeclared_names(self, expr: str) -> Iterable[str]:
|
||||
for name in re.findall(self._macro_identifier_re, expr):
|
||||
if name not in self.all_declared:
|
||||
yield name
|
||||
|
||||
def accept_test_case_line(self, function: str, argument: str) -> bool:
|
||||
#pylint: disable=unused-argument
|
||||
undeclared = list(self.generate_undeclared_names(argument))
|
||||
if undeclared:
|
||||
raise Exception('Undeclared names in test case', undeclared)
|
||||
return True
|
||||
|
||||
@staticmethod
|
||||
def normalize_argument(argument: str) -> str:
|
||||
"""Normalize whitespace in the given C expression.
|
||||
|
||||
The result uses the same whitespace as
|
||||
` PSAMacroEnumerator.distribute_arguments`.
|
||||
"""
|
||||
return re.sub(r',', r', ', re.sub(r' +', r'', argument))
|
||||
|
||||
def add_test_case_line(self, function: str, argument: str) -> None:
|
||||
"""Parse a test case data line, looking for algorithm metadata tests."""
|
||||
sets = []
|
||||
if function.endswith('_algorithm'):
|
||||
sets.append(self.algorithms)
|
||||
if function == 'key_agreement_algorithm' and \
|
||||
argument.startswith('PSA_ALG_KEY_AGREEMENT('):
|
||||
# We only want *raw* key agreement algorithms as such, so
|
||||
# exclude ones that are already chained with a KDF.
|
||||
# Keep the expression as one to test as an algorithm.
|
||||
function = 'other_algorithm'
|
||||
sets += self.table_by_test_function[function]
|
||||
if self.accept_test_case_line(function, argument):
|
||||
for s in sets:
|
||||
s.add(self.normalize_argument(argument))
|
||||
|
||||
# Regex matching a *.data line containing a test function call and
|
||||
# its arguments. The actual definition is partly positional, but this
|
||||
# regex is good enough in practice.
|
||||
_test_case_line_re = re.compile(r'(?!depends_on:)(\w+):([^\n :][^:\n]*)')
|
||||
def parse_test_cases(self, filename: str) -> None:
|
||||
"""Parse a test case file (*.data), looking for algorithm metadata tests."""
|
||||
with read_file_lines(filename) as lines:
|
||||
for line in lines:
|
||||
m = re.match(self._test_case_line_re, line)
|
||||
if m:
|
||||
self.add_test_case_line(m.group(1), m.group(2))
|
||||
122
vendor/mbedtls/framework/scripts/mbedtls_framework/min_requirements.py
vendored
Normal file
122
vendor/mbedtls/framework/scripts/mbedtls_framework/min_requirements.py
vendored
Normal file
@@ -0,0 +1,122 @@
|
||||
"""Install all the required Python packages, with the minimum Python version.
|
||||
"""
|
||||
|
||||
# Copyright The Mbed TLS Contributors
|
||||
# SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
|
||||
import argparse
|
||||
import os
|
||||
import re
|
||||
import subprocess
|
||||
import sys
|
||||
import tempfile
|
||||
import typing
|
||||
|
||||
from typing import List, Optional
|
||||
|
||||
import framework_scripts_path # pylint: disable=unused-import
|
||||
from mbedtls_framework import typing_util
|
||||
|
||||
def pylint_doesn_t_notice_that_certain_types_are_used_in_annotations(
|
||||
_list: List[typing.Any],
|
||||
) -> None:
|
||||
pass
|
||||
|
||||
|
||||
class Requirements:
|
||||
"""Collect and massage Python requirements."""
|
||||
|
||||
def __init__(self) -> None:
|
||||
self.requirements = [] #type: List[str]
|
||||
|
||||
def adjust_requirement(self, req: str) -> str:
|
||||
"""Adjust a requirement to the minimum specified version."""
|
||||
# allow inheritance #pylint: disable=no-self-use
|
||||
# If a requirement specifies a minimum version, impose that version.
|
||||
split_req = req.split(';', 1)
|
||||
split_req[0] = re.sub(r'>=|~=', r'==', split_req[0])
|
||||
return ';'.join(split_req)
|
||||
|
||||
def add_file(self, filename: str) -> None:
|
||||
"""Add requirements from the specified file.
|
||||
|
||||
This method supports a subset of pip's requirement file syntax:
|
||||
* One requirement specifier per line, which is passed to
|
||||
`adjust_requirement`.
|
||||
* Comments (``#`` at the beginning of the line or after whitespace).
|
||||
* ``-r FILENAME`` to include another file.
|
||||
"""
|
||||
for line in open(filename):
|
||||
line = line.strip()
|
||||
line = re.sub(r'(\A|\s+)#.*', r'', line)
|
||||
if not line:
|
||||
continue
|
||||
m = re.match(r'-r\s+', line)
|
||||
if m:
|
||||
nested_file = os.path.join(os.path.dirname(filename),
|
||||
line[m.end(0):])
|
||||
self.add_file(nested_file)
|
||||
continue
|
||||
self.requirements.append(self.adjust_requirement(line))
|
||||
|
||||
def write(self, out: typing_util.Writable) -> None:
|
||||
"""List the gathered requirements."""
|
||||
for req in self.requirements:
|
||||
out.write(req + '\n')
|
||||
|
||||
def install(
|
||||
self,
|
||||
pip_general_options: Optional[List[str]] = None,
|
||||
pip_install_options: Optional[List[str]] = None,
|
||||
) -> None:
|
||||
"""Call pip to install the requirements."""
|
||||
if pip_general_options is None:
|
||||
pip_general_options = []
|
||||
if pip_install_options is None:
|
||||
pip_install_options = []
|
||||
with tempfile.TemporaryDirectory() as temp_dir:
|
||||
# This is more complicated than it needs to be for the sake
|
||||
# of Windows. Use a temporary file rather than the command line
|
||||
# to avoid quoting issues. Use a temporary directory rather
|
||||
# than NamedTemporaryFile because with a NamedTemporaryFile on
|
||||
# Windows, the subprocess can't open the file because this process
|
||||
# has an exclusive lock on it.
|
||||
req_file_name = os.path.join(temp_dir, 'requirements.txt')
|
||||
with open(req_file_name, 'w') as req_file:
|
||||
self.write(req_file)
|
||||
subprocess.check_call([sys.executable, '-m', 'pip'] +
|
||||
pip_general_options +
|
||||
['install'] + pip_install_options +
|
||||
['-r', req_file_name])
|
||||
|
||||
def main(default_requirement_file: str) -> None:
|
||||
"""Command line entry point."""
|
||||
parser = argparse.ArgumentParser(description=__doc__)
|
||||
parser.add_argument('--no-act', '-n',
|
||||
action='store_true',
|
||||
help="Don't act, just print what will be done")
|
||||
parser.add_argument('--pip-install-option',
|
||||
action='append', dest='pip_install_options',
|
||||
help="Pass this option to pip install")
|
||||
parser.add_argument('--pip-option',
|
||||
action='append', dest='pip_general_options',
|
||||
help="Pass this general option to pip")
|
||||
parser.add_argument('--user',
|
||||
action='append_const', dest='pip_install_options',
|
||||
const='--user',
|
||||
help="Install to the Python user install directory"
|
||||
" (short for --pip-install-option --user)")
|
||||
parser.add_argument('files', nargs='*', metavar='FILE',
|
||||
help="Requirement files"
|
||||
" (default: {})" \
|
||||
.format(default_requirement_file))
|
||||
options = parser.parse_args()
|
||||
if not options.files:
|
||||
options.files = [default_requirement_file]
|
||||
reqs = Requirements()
|
||||
for filename in options.files:
|
||||
reqs.add_file(filename)
|
||||
reqs.write(sys.stdout)
|
||||
if not options.no_act:
|
||||
reqs.install(pip_general_options=options.pip_general_options,
|
||||
pip_install_options=options.pip_install_options)
|
||||
463
vendor/mbedtls/framework/scripts/mbedtls_framework/outcome_analysis.py
vendored
Normal file
463
vendor/mbedtls/framework/scripts/mbedtls_framework/outcome_analysis.py
vendored
Normal file
@@ -0,0 +1,463 @@
|
||||
"""Outcome file analysis code.
|
||||
|
||||
This module is the bulk of the code of tests/scripts/analyze_outcomes.py
|
||||
in each consuming branch. The consuming script is expected to derive
|
||||
the classes with branch-specific customizations such as ignore lists.
|
||||
"""
|
||||
|
||||
# Copyright The Mbed TLS Contributors
|
||||
# SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
|
||||
import argparse
|
||||
import gzip
|
||||
import lzma
|
||||
import sys
|
||||
import traceback
|
||||
import re
|
||||
import subprocess
|
||||
import os
|
||||
import typing
|
||||
|
||||
from . import collect_test_cases
|
||||
|
||||
|
||||
# `ComponentOutcomes` is a named tuple which is defined as:
|
||||
# ComponentOutcomes(
|
||||
# successes = {
|
||||
# "<suite_case>",
|
||||
# ...
|
||||
# },
|
||||
# failures = {
|
||||
# "<suite_case>",
|
||||
# ...
|
||||
# }
|
||||
# )
|
||||
# suite_case = "<suite>;<case>"
|
||||
ComponentOutcomes = typing.NamedTuple('ComponentOutcomes',
|
||||
[('successes', typing.Set[str]),
|
||||
('failures', typing.Set[str])])
|
||||
|
||||
# `Outcomes` is a representation of the outcomes file,
|
||||
# which defined as:
|
||||
# Outcomes = {
|
||||
# "<component>": ComponentOutcomes,
|
||||
# ...
|
||||
# }
|
||||
Outcomes = typing.Dict[str, ComponentOutcomes]
|
||||
|
||||
|
||||
class Results:
|
||||
"""Process analysis results."""
|
||||
|
||||
def __init__(self,
|
||||
stderr: bool = True,
|
||||
log_file: str = '') -> None:
|
||||
"""Log and count errors.
|
||||
|
||||
Log to stderr if stderr is true.
|
||||
Log to log_file if specified and non-empty.
|
||||
"""
|
||||
self.error_count = 0
|
||||
self.warning_count = 0
|
||||
self.stderr = stderr
|
||||
self.log_file = None
|
||||
if log_file:
|
||||
self.log_file = open(log_file, 'w', encoding='utf-8')
|
||||
|
||||
def new_section(self, fmt, *args, **kwargs):
|
||||
self._print_line('\n*** ' + fmt + ' ***\n', *args, **kwargs)
|
||||
|
||||
def info(self, fmt, *args, **kwargs):
|
||||
self._print_line('Info: ' + fmt, *args, **kwargs)
|
||||
|
||||
def error(self, fmt, *args, **kwargs):
|
||||
self.error_count += 1
|
||||
self._print_line('Error: ' + fmt, *args, **kwargs)
|
||||
|
||||
def warning(self, fmt, *args, **kwargs):
|
||||
self.warning_count += 1
|
||||
self._print_line('Warning: ' + fmt, *args, **kwargs)
|
||||
|
||||
def _print_line(self, fmt, *args, **kwargs):
|
||||
line = (fmt + '\n').format(*args, **kwargs)
|
||||
if self.stderr:
|
||||
sys.stderr.write(line)
|
||||
if self.log_file:
|
||||
self.log_file.write(line)
|
||||
|
||||
def execute_reference_driver_tests(results: Results, ref_component: str, driver_component: str, \
|
||||
outcome_file: str) -> None:
|
||||
"""Run the tests specified in ref_component and driver_component. Results
|
||||
are stored in the output_file and they will be used for the following
|
||||
coverage analysis"""
|
||||
results.new_section("Test {} and {}", ref_component, driver_component)
|
||||
|
||||
shell_command = "tests/scripts/all.sh --outcome-file " + outcome_file + \
|
||||
" " + ref_component + " " + driver_component
|
||||
results.info("Running: {}", shell_command)
|
||||
ret_val = subprocess.run(shell_command.split(), check=False).returncode
|
||||
|
||||
if ret_val != 0:
|
||||
results.error("failed to run reference/driver components")
|
||||
|
||||
|
||||
TestCaseMatcher = typing.Union[str, typing.Pattern]
|
||||
|
||||
# Map test suite names (with the test_suite prefix) to a list of ignored
|
||||
# test cases. Each element in the list can be either a string or a
|
||||
# compiled regex (Pattern). Strings only match themselves. Regexes must
|
||||
# match the full test case description (not just a prefix or other
|
||||
# substring).
|
||||
TestCaseSetDescription = typing.Mapping[str, typing.Sequence[TestCaseMatcher]]
|
||||
|
||||
class TestCaseSet:
|
||||
"""A set of test cases, indexed by their test suite."""
|
||||
#pylint: disable=too-few-public-methods
|
||||
|
||||
def __init__(self, description: TestCaseSetDescription) -> None:
|
||||
"""Construct a set of test cases from a list of matches for each test suite.
|
||||
"""
|
||||
# Construct new mutable objects, to avoid mutating the parameter,
|
||||
# which could be confusing.
|
||||
self.matchers = {key: list(entries)
|
||||
for key, entries in description.items()}
|
||||
|
||||
def extend(self, description: TestCaseSetDescription) -> None:
|
||||
"""Add more matchers to this test case set."""
|
||||
for key, entries in description.items():
|
||||
self.matchers.setdefault(key, [])
|
||||
self.matchers[key] += entries
|
||||
|
||||
@staticmethod
|
||||
def _name_matches_pattern(name: str, str_or_re: TestCaseMatcher) -> bool:
|
||||
"""Check if name matches a pattern, that may be a string or regex.
|
||||
- If the pattern is a string, name must be equal to match.
|
||||
- If the pattern is a regex, name must fully match.
|
||||
"""
|
||||
# The CI's python is too old for re.Pattern
|
||||
#if isinstance(str_or_re, re.Pattern):
|
||||
if not isinstance(str_or_re, str):
|
||||
return str_or_re.fullmatch(name) is not None
|
||||
else:
|
||||
return str_or_re == name
|
||||
|
||||
def _suite_matchers(self, test_suite: str) -> typing.Iterator[TestCaseMatcher]:
|
||||
"""Generate the matcher list for the specified test suite."""
|
||||
if test_suite in self.matchers:
|
||||
yield from self.matchers[test_suite]
|
||||
pos = test_suite.find('.')
|
||||
if pos != -1:
|
||||
base_test_suite = test_suite[:pos]
|
||||
if base_test_suite in self.matchers:
|
||||
yield from self.matchers[base_test_suite]
|
||||
|
||||
def contains(self, test_suite: str, test_string: str) -> bool:
|
||||
"""Check if the specified test case is in the set."""
|
||||
for str_or_re in self._suite_matchers(test_suite):
|
||||
if self._name_matches_pattern(test_string, str_or_re):
|
||||
return True
|
||||
return False
|
||||
|
||||
|
||||
def open_outcome_file(outcome_file: str) -> typing.TextIO:
|
||||
if outcome_file.endswith('.gz'):
|
||||
return gzip.open(outcome_file, 'rt', encoding='utf-8')
|
||||
elif outcome_file.endswith('.xz'):
|
||||
return lzma.open(outcome_file, 'rt', encoding='utf-8')
|
||||
else:
|
||||
return open(outcome_file, 'rt', encoding='utf-8')
|
||||
|
||||
def read_outcome_file(outcome_file: str) -> Outcomes:
|
||||
"""Parse an outcome file and return an outcome collection.
|
||||
"""
|
||||
outcomes = {}
|
||||
with open_outcome_file(outcome_file) as input_file:
|
||||
for line in input_file:
|
||||
(_platform, component, suite, case, result, _cause) = line.split(';')
|
||||
# Note that `component` is not unique. If a test case passes on Linux
|
||||
# and fails on FreeBSD, it'll end up in both the successes set and
|
||||
# the failures set.
|
||||
suite_case = ';'.join([suite, case])
|
||||
if component not in outcomes:
|
||||
outcomes[component] = ComponentOutcomes(set(), set())
|
||||
if result == 'PASS':
|
||||
outcomes[component].successes.add(suite_case)
|
||||
elif result == 'FAIL':
|
||||
outcomes[component].failures.add(suite_case)
|
||||
|
||||
return outcomes
|
||||
|
||||
|
||||
class Task:
|
||||
"""Base class for outcome analysis tasks."""
|
||||
|
||||
@staticmethod
|
||||
def _has_word_re(words: typing.Iterable[str],
|
||||
exclude: typing.Optional[str] = None) -> typing.Pattern:
|
||||
"""Construct a regex that matches if any of the words appears.
|
||||
|
||||
The occurrence must start and end at a word boundary.
|
||||
|
||||
If exclude is specified, strings containing a match for that
|
||||
regular expression will not match the returned pattern.
|
||||
"""
|
||||
exclude_clause = r''
|
||||
if exclude:
|
||||
exclude_clause = r'(?!.*' + exclude + ')'
|
||||
return re.compile(exclude_clause +
|
||||
r'.*\b(?:' + r'|'.join(words) + r')\b.*',
|
||||
re.DOTALL)
|
||||
|
||||
def __init__(self, options) -> None:
|
||||
"""Pass command line options to the tasks.
|
||||
|
||||
Each task decides which command line options it cares about.
|
||||
"""
|
||||
pass
|
||||
|
||||
def section_name(self) -> str:
|
||||
"""The section name to use in results."""
|
||||
raise NotImplementedError
|
||||
|
||||
def run(self, results: Results, outcomes: Outcomes):
|
||||
"""Run the analysis on the specified outcomes.
|
||||
|
||||
Signal errors via the results objects
|
||||
"""
|
||||
raise NotImplementedError
|
||||
|
||||
|
||||
class CoverageTask(Task):
|
||||
"""Analyze test coverage."""
|
||||
|
||||
# Test cases whose suite and description are matched by an entry in
|
||||
# UNCOVERED_TESTS are expected to be never executed.
|
||||
# Tests matched by IGNORED_TESTS are ignored entirely.
|
||||
# All other test cases are expected to be executed at least once.
|
||||
|
||||
UNCOVERED_TESTS: TestCaseSetDescription = {}
|
||||
IGNORED_TESTS: TestCaseSetDescription = {}
|
||||
|
||||
def __init__(self, options) -> None:
|
||||
super().__init__(options)
|
||||
self.full_coverage = options.full_coverage #type: bool
|
||||
self.uncovered_tests = TestCaseSet(self.UNCOVERED_TESTS)
|
||||
self.ignored_tests = TestCaseSet(self.IGNORED_TESTS)
|
||||
|
||||
@staticmethod
|
||||
def section_name() -> str:
|
||||
return "Analyze coverage"
|
||||
|
||||
def note_ignored_test(self, results: Results,
|
||||
test_suite: str, test_description: str) -> None:
|
||||
# pylint: disable=no-self-use # derived classes may need self
|
||||
"""This method runs for each test case that's available and ignored."""
|
||||
results.info('Test case was ignored: {};{}',
|
||||
test_suite, test_description)
|
||||
|
||||
def run(self, results: Results, outcomes: Outcomes) -> None:
|
||||
"""Check that all available test cases are executed at least once."""
|
||||
# Make sure that the generated data files are present (and up-to-date).
|
||||
# This allows analyze_outcomes.py to run correctly on a fresh Git
|
||||
# checkout.
|
||||
cp = subprocess.run(['make', 'generated_files'],
|
||||
cwd='tests',
|
||||
stdout=subprocess.PIPE, stderr=subprocess.STDOUT,
|
||||
check=False)
|
||||
if cp.returncode != 0:
|
||||
sys.stderr.write(cp.stdout.decode('utf-8'))
|
||||
results.error("Failed \"make generated_files\" in tests. "
|
||||
"Coverage analysis may be incorrect.")
|
||||
available = collect_test_cases.collect_available_test_cases()
|
||||
for suite_case in available:
|
||||
hit = any(suite_case in comp_outcomes.successes or
|
||||
suite_case in comp_outcomes.failures
|
||||
for comp_outcomes in outcomes.values())
|
||||
(test_suite, test_description) = suite_case.split(';')
|
||||
ignored = self.ignored_tests.contains(test_suite, test_description)
|
||||
if ignored:
|
||||
self.note_ignored_test(results, test_suite, test_description)
|
||||
continue
|
||||
|
||||
uncovered = self.uncovered_tests.contains(test_suite, test_description)
|
||||
if not hit and not uncovered:
|
||||
if self.full_coverage:
|
||||
results.error('Test case not executed: {}', suite_case)
|
||||
else:
|
||||
results.warning('Test case not executed: {}', suite_case)
|
||||
elif hit and uncovered:
|
||||
# If a test case is no longer always skipped, we should remove
|
||||
# it from the ignore list.
|
||||
if self.full_coverage:
|
||||
results.error(
|
||||
'Test case was executed but marked as uncovered for coverage: {}',
|
||||
suite_case)
|
||||
else:
|
||||
results.warning(
|
||||
'Test case was executed but marked as uncovered for coverage: {}',
|
||||
suite_case)
|
||||
|
||||
|
||||
class DriverVSReference(Task):
|
||||
"""Compare outcomes from testing with and without a driver.
|
||||
|
||||
There are 2 options to use analyze_driver_vs_reference_xxx locally:
|
||||
1. Run tests and then analysis:
|
||||
- tests/scripts/all.sh --outcome-file "$PWD/out.csv" <component_ref> <component_driver>
|
||||
- tests/scripts/analyze_outcomes.py out.csv analyze_driver_vs_reference_xxx
|
||||
2. Let this script run both automatically:
|
||||
- tests/scripts/analyze_outcomes.py out.csv analyze_driver_vs_reference_xxx
|
||||
"""
|
||||
|
||||
# Override the following in child classes.
|
||||
# Configuration name (all.sh component) used as the reference.
|
||||
REFERENCE = ''
|
||||
# Configuration name (all.sh component) used as the driver.
|
||||
DRIVER = ''
|
||||
# Ignored test suites (without the test_suite_ prefix).
|
||||
IGNORED_SUITES = [] #type: typing.Sequence[str]
|
||||
# Ignored test cases. Despite the name, these test cases are not
|
||||
# completely ignored: they must be skipped by driver tests. If they
|
||||
# are not skipped, this indicates a spurious entry and the analysis will
|
||||
# complain.
|
||||
IGNORED_TESTS: TestCaseSetDescription = {}
|
||||
|
||||
def __init__(self, options) -> None:
|
||||
super().__init__(options)
|
||||
self.ignored_suites = frozenset('test_suite_' + x
|
||||
for x in self.IGNORED_SUITES)
|
||||
self.ignored_tests = TestCaseSet(self.IGNORED_TESTS)
|
||||
|
||||
def section_name(self) -> str:
|
||||
return f"Analyze driver {self.DRIVER} vs reference {self.REFERENCE}"
|
||||
|
||||
def run(self, results: Results, outcomes: Outcomes) -> None:
|
||||
"""Check that all tests passing in the driver component are also
|
||||
passing in the corresponding reference component.
|
||||
Skip:
|
||||
- full test suites provided in ignored_suites list
|
||||
- only some specific test inside a test suite, for which the corresponding
|
||||
output string is provided
|
||||
"""
|
||||
ref_outcomes = outcomes.get("component_" + self.REFERENCE)
|
||||
driver_outcomes = outcomes.get("component_" + self.DRIVER)
|
||||
|
||||
if ref_outcomes is None or driver_outcomes is None:
|
||||
results.error("required components are missing: bad outcome file?")
|
||||
return
|
||||
|
||||
if not ref_outcomes.successes:
|
||||
results.error("no passing test in reference component: bad outcome file?")
|
||||
return
|
||||
|
||||
for suite_case in ref_outcomes.successes:
|
||||
# suite_case is like "test_suite_foo.bar;Description of test case"
|
||||
(full_test_suite, test_string) = suite_case.split(';')
|
||||
test_suite = full_test_suite.split('.')[0] # retrieve main part of test suite name
|
||||
|
||||
# Immediately skip fully-ignored test suites
|
||||
if test_suite in self.ignored_suites or \
|
||||
full_test_suite in self.ignored_suites:
|
||||
continue
|
||||
|
||||
# For ignored test cases inside test suites, just remember and:
|
||||
# don't issue an error if they're skipped with drivers,
|
||||
# but issue an error if they're not (means we have a bad entry).
|
||||
ignored = self.ignored_tests.contains(full_test_suite, test_string)
|
||||
|
||||
if not ignored and not suite_case in driver_outcomes.successes:
|
||||
results.error("SKIP/FAIL -> PASS: {}", suite_case)
|
||||
if ignored and suite_case in driver_outcomes.successes:
|
||||
results.error("uselessly ignored: {}", suite_case)
|
||||
|
||||
|
||||
# Set this to False if a consuming branch can't achieve full test coverage
|
||||
# in its default CI run.
|
||||
FULL_COVERAGE_BY_DEFAULT = True
|
||||
|
||||
def main(known_tasks: typing.Dict[str, typing.Type[Task]]) -> None:
|
||||
try:
|
||||
parser = argparse.ArgumentParser(description=__doc__)
|
||||
parser.add_argument('outcomes', metavar='OUTCOMES.CSV',
|
||||
help='Outcome file to analyze (can be .gz or .xz)')
|
||||
parser.add_argument('specified_tasks', default='all', nargs='?',
|
||||
help='Analysis to be done. By default, run all tasks. '
|
||||
'With one or more TASK, run only those. '
|
||||
'TASK can be the name of a single task or '
|
||||
'comma/space-separated list of tasks. ')
|
||||
parser.add_argument('--allow-partial-coverage', action='store_false',
|
||||
dest='full_coverage', default=FULL_COVERAGE_BY_DEFAULT,
|
||||
help=("Only warn if a test case is skipped in all components" +
|
||||
(" (default)" if not FULL_COVERAGE_BY_DEFAULT else "") +
|
||||
". Only used by the 'analyze_coverage' task."))
|
||||
parser.add_argument('--list', action='store_true',
|
||||
help='List all available tasks and exit.')
|
||||
parser.add_argument('--log-file',
|
||||
default='tests/analyze_outcomes.log',
|
||||
help='Log file (default: tests/analyze_outcomes.log;'
|
||||
' empty means no log file)')
|
||||
parser.add_argument('--require-full-coverage', action='store_true',
|
||||
dest='full_coverage', default=FULL_COVERAGE_BY_DEFAULT,
|
||||
help=("Require all available test cases to be executed" +
|
||||
(" (default)" if FULL_COVERAGE_BY_DEFAULT else "") +
|
||||
". Only used by the 'analyze_coverage' task."))
|
||||
options = parser.parse_args()
|
||||
|
||||
if options.list:
|
||||
for task_name in known_tasks:
|
||||
print(task_name)
|
||||
sys.exit(0)
|
||||
|
||||
main_results = Results(log_file=options.log_file)
|
||||
|
||||
if options.specified_tasks == 'all':
|
||||
tasks_list = list(known_tasks.keys())
|
||||
else:
|
||||
tasks_list = re.split(r'[, ]+', options.specified_tasks)
|
||||
for task_name in tasks_list:
|
||||
if task_name not in known_tasks:
|
||||
sys.stderr.write('invalid task: {}\n'.format(task_name))
|
||||
sys.exit(2)
|
||||
|
||||
# If the outcome file exists, parse it once and share the result
|
||||
# among tasks to improve performance.
|
||||
# Otherwise, it will be generated by execute_reference_driver_tests.
|
||||
if not os.path.exists(options.outcomes):
|
||||
if len(tasks_list) > 1:
|
||||
sys.stderr.write("mutiple tasks found, please provide a valid outcomes file.\n")
|
||||
sys.exit(2)
|
||||
|
||||
task_name = tasks_list[0]
|
||||
task_class = known_tasks[task_name]
|
||||
if not issubclass(task_class, DriverVSReference):
|
||||
sys.stderr.write("please provide valid outcomes file for {}.\n".format(task_name))
|
||||
sys.exit(2)
|
||||
# mypy isn't smart enough to know that REFERENCE and DRIVER
|
||||
# are *class* attributes of all classes derived from
|
||||
# DriverVSReference. (It would be smart enough if we had an
|
||||
# instance of task_class, but we can't construct an instance
|
||||
# until we have the outcome data, so at this point we only
|
||||
# have the class.) So we use indirection to access the class
|
||||
# attributes.
|
||||
execute_reference_driver_tests(main_results,
|
||||
getattr(task_class, 'REFERENCE'),
|
||||
getattr(task_class, 'DRIVER'),
|
||||
options.outcomes)
|
||||
|
||||
outcomes = read_outcome_file(options.outcomes)
|
||||
|
||||
for task_name in tasks_list:
|
||||
task_constructor = known_tasks[task_name]
|
||||
task_instance = task_constructor(options)
|
||||
main_results.new_section(task_instance.section_name())
|
||||
task_instance.run(main_results, outcomes)
|
||||
|
||||
main_results.info("Overall results: {} warnings and {} errors",
|
||||
main_results.warning_count, main_results.error_count)
|
||||
|
||||
sys.exit(0 if (main_results.error_count == 0) else 1)
|
||||
|
||||
except Exception: # pylint: disable=broad-except
|
||||
# Print the backtrace and exit explicitly with our chosen status.
|
||||
traceback.print_exc()
|
||||
sys.exit(120)
|
||||
189
vendor/mbedtls/framework/scripts/mbedtls_framework/psa_compliance.py
vendored
Normal file
189
vendor/mbedtls/framework/scripts/mbedtls_framework/psa_compliance.py
vendored
Normal file
@@ -0,0 +1,189 @@
|
||||
"""Run the PSA Crypto API compliance test suite.
|
||||
Clone the repo and check out the commit specified by PSA_ARCH_TEST_REPO and PSA_ARCH_TEST_REF,
|
||||
then compile and run the test suite. The clone is stored at <repository root>/psa-arch-tests.
|
||||
Known defects in either the test suite or mbedtls / TF-PSA-Crypto - identified by their test
|
||||
number - are ignored, while unexpected failures AND successes are reported as errors, to help
|
||||
keep the list of known defects as up to date as possible.
|
||||
"""
|
||||
|
||||
# Copyright The Mbed TLS Contributors
|
||||
# SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
|
||||
import argparse
|
||||
import glob
|
||||
import os
|
||||
import re
|
||||
import shutil
|
||||
import subprocess
|
||||
import sys
|
||||
from typing import List, Optional
|
||||
from pathlib import Path
|
||||
|
||||
from . import build_tree
|
||||
|
||||
PSA_ARCH_TESTS_REPO = 'https://github.com/ARM-software/psa-arch-tests.git'
|
||||
|
||||
#pylint: disable=too-many-branches,too-many-statements,too-many-locals
|
||||
def test_compliance(library_build_dir: str,
|
||||
psa_arch_tests_ref: str,
|
||||
patch_files: List[str],
|
||||
expected_failures: List[int]) -> int:
|
||||
"""Check out and run compliance tests.
|
||||
|
||||
library_build_dir: path where our library will be built.
|
||||
psa_arch_tests_ref: tag or sha to use for the arch-tests.
|
||||
patch: patch to apply to the arch-tests with ``patch -p1``.
|
||||
expected_failures: default list of expected failures.
|
||||
"""
|
||||
root_dir = os.getcwd()
|
||||
install_dir = Path(library_build_dir + "/install_dir").resolve()
|
||||
tmp_env = os.environ
|
||||
tmp_env['CC'] = 'gcc'
|
||||
subprocess.check_call(['cmake', '.', '-GUnix Makefiles',
|
||||
'-B' + library_build_dir,
|
||||
'-DCMAKE_INSTALL_PREFIX=' + str(install_dir)],
|
||||
env=tmp_env)
|
||||
subprocess.check_call(['cmake', '--build', library_build_dir, '--target', 'install'])
|
||||
|
||||
if build_tree.is_mbedtls_3_6():
|
||||
crypto_library_path = install_dir.joinpath("lib/libmbedcrypto.a")
|
||||
else:
|
||||
crypto_library_path = install_dir.joinpath("lib/libtfpsacrypto.a")
|
||||
|
||||
psa_arch_tests_dir = 'psa-arch-tests'
|
||||
os.makedirs(psa_arch_tests_dir, exist_ok=True)
|
||||
try:
|
||||
os.chdir(psa_arch_tests_dir)
|
||||
|
||||
# Reuse existing local clone
|
||||
subprocess.check_call(['git', 'init'])
|
||||
subprocess.check_call(['git', 'fetch', PSA_ARCH_TESTS_REPO, psa_arch_tests_ref])
|
||||
subprocess.check_call(['git', 'checkout', '--force', 'FETCH_HEAD'])
|
||||
|
||||
if patch_files:
|
||||
subprocess.check_call(['git', 'reset', '--hard'])
|
||||
for patch_file in patch_files:
|
||||
with open(os.path.join(root_dir, patch_file), 'rb') as patch:
|
||||
subprocess.check_call(['patch', '-p1'],
|
||||
stdin=patch)
|
||||
|
||||
build_dir = 'api-tests/build'
|
||||
try:
|
||||
shutil.rmtree(build_dir)
|
||||
except FileNotFoundError:
|
||||
pass
|
||||
os.mkdir(build_dir)
|
||||
os.chdir(build_dir)
|
||||
|
||||
#pylint: disable=bad-continuation
|
||||
subprocess.check_call([
|
||||
'cmake', '..',
|
||||
'-GUnix Makefiles',
|
||||
'-DTARGET=tgt_dev_apis_stdc',
|
||||
'-DTOOLCHAIN=HOST_GCC',
|
||||
'-DSUITE=CRYPTO',
|
||||
'-DPSA_CRYPTO_LIB_FILENAME={}'.format(str(crypto_library_path)),
|
||||
'-DPSA_INCLUDE_PATHS=' + str(install_dir.joinpath("include"))
|
||||
])
|
||||
|
||||
subprocess.check_call(['cmake', '--build', '.'])
|
||||
|
||||
proc = subprocess.Popen(['./psa-arch-tests-crypto'],
|
||||
bufsize=1, stdout=subprocess.PIPE, universal_newlines=True)
|
||||
|
||||
test_re = re.compile(
|
||||
'^TEST: (?P<test_num>[0-9]*)|'
|
||||
'^TEST RESULT: (?P<test_result>FAILED|PASSED)'
|
||||
)
|
||||
test = -1
|
||||
unexpected_successes = expected_failures.copy()
|
||||
expected_failures.clear()
|
||||
unexpected_failures = [] # type: List[int]
|
||||
if proc.stdout is None:
|
||||
return 1
|
||||
|
||||
for line in proc.stdout:
|
||||
print(line, end='')
|
||||
match = test_re.match(line)
|
||||
if match is not None:
|
||||
groupdict = match.groupdict()
|
||||
test_num = groupdict['test_num']
|
||||
if test_num is not None:
|
||||
test = int(test_num)
|
||||
elif groupdict['test_result'] == 'FAILED':
|
||||
try:
|
||||
unexpected_successes.remove(test)
|
||||
expected_failures.append(test)
|
||||
print('Expected failure, ignoring')
|
||||
except KeyError:
|
||||
unexpected_failures.append(test)
|
||||
print('ERROR: Unexpected failure')
|
||||
elif test in unexpected_successes:
|
||||
print('ERROR: Unexpected success')
|
||||
proc.wait()
|
||||
|
||||
print()
|
||||
print('***** test_psa_compliance.py report ******')
|
||||
print()
|
||||
print('Expected failures:', ', '.join(str(i) for i in expected_failures))
|
||||
print('Unexpected failures:', ', '.join(str(i) for i in unexpected_failures))
|
||||
print('Unexpected successes:', ', '.join(str(i) for i in sorted(unexpected_successes)))
|
||||
print()
|
||||
if unexpected_successes or unexpected_failures:
|
||||
if unexpected_successes:
|
||||
print('Unexpected successes encountered.')
|
||||
print('Please remove the corresponding tests from '
|
||||
'EXPECTED_FAILURES in tests/scripts/compliance_test.py')
|
||||
print()
|
||||
print('FAILED')
|
||||
return 1
|
||||
else:
|
||||
print('SUCCESS')
|
||||
return 0
|
||||
finally:
|
||||
os.chdir(root_dir)
|
||||
|
||||
def main(psa_arch_tests_ref: str,
|
||||
expected_failures: Optional[List[int]] = None) -> None:
|
||||
"""Command line entry point.
|
||||
|
||||
psa_arch_tests_ref: tag or sha to use for the arch-tests.
|
||||
expected_failures: default list of expected failures.
|
||||
"""
|
||||
build_dir = 'out_of_source_build'
|
||||
default_patch_directory = os.path.join(build_tree.guess_project_root(),
|
||||
'scripts/data_files/psa-arch-tests')
|
||||
|
||||
# pylint: disable=invalid-name
|
||||
parser = argparse.ArgumentParser()
|
||||
parser.add_argument('--build-dir', nargs=1,
|
||||
help='path to Mbed TLS / TF-PSA-Crypto build directory')
|
||||
parser.add_argument('--expected-failures', nargs='+',
|
||||
help='''set the list of test codes which are expected to fail
|
||||
from the command line. If omitted the list given by
|
||||
EXPECTED_FAILURES (inside the script) is used.''')
|
||||
parser.add_argument('--patch-directory', nargs=1,
|
||||
default=default_patch_directory,
|
||||
help='Directory containing patches (*.patch) to apply to psa-arch-tests')
|
||||
args = parser.parse_args()
|
||||
|
||||
if args.build_dir is not None:
|
||||
build_dir = args.build_dir[0]
|
||||
|
||||
if expected_failures is None:
|
||||
expected_failures = []
|
||||
if args.expected_failures is not None:
|
||||
expected_failures_list = [int(i) for i in args.expected_failures]
|
||||
else:
|
||||
expected_failures_list = expected_failures
|
||||
|
||||
if args.patch_directory:
|
||||
patch_file_glob = os.path.join(args.patch_directory, '*.patch')
|
||||
patch_files = sorted(glob.glob(patch_file_glob))
|
||||
else:
|
||||
patch_files = []
|
||||
|
||||
sys.exit(test_compliance(build_dir,
|
||||
psa_arch_tests_ref,
|
||||
patch_files,
|
||||
expected_failures_list))
|
||||
162
vendor/mbedtls/framework/scripts/mbedtls_framework/psa_information.py
vendored
Normal file
162
vendor/mbedtls/framework/scripts/mbedtls_framework/psa_information.py
vendored
Normal file
@@ -0,0 +1,162 @@
|
||||
"""Collect information about PSA cryptographic mechanisms.
|
||||
"""
|
||||
|
||||
# Copyright The Mbed TLS Contributors
|
||||
# SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
#
|
||||
|
||||
import re
|
||||
from collections import OrderedDict
|
||||
from typing import List, Optional
|
||||
|
||||
from . import build_tree
|
||||
from . import macro_collector
|
||||
|
||||
|
||||
class Information:
|
||||
"""Gather information about PSA constructors."""
|
||||
|
||||
def __init__(self) -> None:
|
||||
self.constructors = self.read_psa_interface()
|
||||
|
||||
@staticmethod
|
||||
def remove_unwanted_macros(
|
||||
constructors: macro_collector.PSAMacroEnumerator
|
||||
) -> None:
|
||||
"""Remove constructors that should be exckuded from systematic testing."""
|
||||
# Mbed TLS does not support finite-field DSA, but 3.6 defines DSA
|
||||
# identifiers for historical reasons.
|
||||
# Mbed TLS and TF-PSA-Crypto 1.0 do not support SPAKE2+, although
|
||||
# TF-PSA-Crypto 1.0 defines SPAKE2+ identifiers to be able to build
|
||||
# the psa-arch-tests compliance test suite.
|
||||
#
|
||||
# Don't attempt to generate any related test case.
|
||||
# The corresponding test cases would be commented out anyway,
|
||||
# but for these types, we don't have enough support in the test scripts
|
||||
# to generate these test cases.
|
||||
constructors.key_types.discard('PSA_KEY_TYPE_DSA_KEY_PAIR')
|
||||
constructors.key_types.discard('PSA_KEY_TYPE_DSA_PUBLIC_KEY')
|
||||
constructors.key_types.discard('PSA_KEY_TYPE_SPAKE2P_KEY_PAIR')
|
||||
constructors.key_types.discard('PSA_KEY_TYPE_SPAKE2P_PUBLIC_KEY')
|
||||
|
||||
def read_psa_interface(self) -> macro_collector.PSAMacroEnumerator:
|
||||
"""Return the list of known key types, algorithms, etc."""
|
||||
constructors = macro_collector.InputsForTest()
|
||||
|
||||
if build_tree.looks_like_root('.'):
|
||||
if build_tree.looks_like_mbedtls_root('.') and \
|
||||
(not build_tree.is_mbedtls_3_6()):
|
||||
header_file_names = ['tf-psa-crypto/include/psa/crypto_values.h',
|
||||
'tf-psa-crypto/include/psa/crypto_extra.h']
|
||||
test_suites = ['tf-psa-crypto/tests/suites/test_suite_psa_crypto_metadata.data']
|
||||
else:
|
||||
header_file_names = ['include/psa/crypto_values.h',
|
||||
'include/psa/crypto_extra.h']
|
||||
test_suites = ['tests/suites/test_suite_psa_crypto_metadata.data']
|
||||
|
||||
for header_file_name in header_file_names:
|
||||
constructors.parse_header(header_file_name)
|
||||
for test_cases in test_suites:
|
||||
constructors.parse_test_cases(test_cases)
|
||||
self.remove_unwanted_macros(constructors)
|
||||
constructors.gather_arguments()
|
||||
return constructors
|
||||
|
||||
|
||||
def psa_want_symbol(name: str, prefix: Optional[str] = None) -> str:
|
||||
"""Return the PSA_WANT_xxx symbol associated with a PSA crypto feature.
|
||||
|
||||
You can use an altenative `prefix`, e.g. 'MBEDTLS_PSA_BUILTIN_'
|
||||
when specifically testing builtin implementations.
|
||||
"""
|
||||
if prefix is None:
|
||||
prefix = 'PSA_WANT_'
|
||||
if name.startswith('PSA_'):
|
||||
return prefix + name[4:]
|
||||
else:
|
||||
raise ValueError('Unable to determine the PSA_WANT_ symbol for ' + name)
|
||||
|
||||
def finish_family_dependency(dep: str, bits: int) -> str:
|
||||
"""Finish dep if it's a family dependency symbol prefix.
|
||||
|
||||
A family dependency symbol prefix is a PSA_WANT_ symbol that needs to be
|
||||
qualified by the key size. If dep is such a symbol, finish it by adjusting
|
||||
the prefix and appending the key size. Other symbols are left unchanged.
|
||||
"""
|
||||
return re.sub(r'_FAMILY_(.*)', r'_\1_' + str(bits), dep)
|
||||
|
||||
def finish_family_dependencies(dependencies: List[str], bits: int) -> List[str]:
|
||||
"""Finish any family dependency symbol prefixes.
|
||||
|
||||
Apply `finish_family_dependency` to each element of `dependencies`.
|
||||
"""
|
||||
return [finish_family_dependency(dep, bits) for dep in dependencies]
|
||||
|
||||
SYMBOLS_WITHOUT_DEPENDENCY = frozenset([
|
||||
'PSA_ALG_AEAD_WITH_AT_LEAST_THIS_LENGTH_TAG', # modifier, only in policies
|
||||
'PSA_ALG_AEAD_WITH_SHORTENED_TAG', # modifier
|
||||
'PSA_ALG_ANY_HASH', # only in policies
|
||||
'PSA_ALG_AT_LEAST_THIS_LENGTH_MAC', # modifier, only in policies
|
||||
'PSA_ALG_KEY_AGREEMENT', # chaining
|
||||
'PSA_ALG_TRUNCATED_MAC', # modifier
|
||||
])
|
||||
def automatic_dependencies(*expressions: str,
|
||||
prefix: Optional[str] = None) -> List[str]:
|
||||
"""Infer dependencies of a test case by looking for PSA_xxx symbols.
|
||||
|
||||
The arguments are strings which should be C expressions. Do not use
|
||||
string literals or comments as this function is not smart enough to
|
||||
skip them.
|
||||
|
||||
`prefix`: prefix to use in dependencies. Defaults to ``'PSA_WANT_'``.
|
||||
Use ``'MBEDTLS_PSA_BUILTIN_'`` when specifically testing
|
||||
builtin implementations.
|
||||
"""
|
||||
used = set()
|
||||
for expr in expressions:
|
||||
used.update(re.findall(r'PSA_(?:ALG|ECC_FAMILY|DH_FAMILY|KEY_TYPE)_\w+', expr))
|
||||
used.difference_update(SYMBOLS_WITHOUT_DEPENDENCY)
|
||||
return sorted(psa_want_symbol(name, prefix=prefix) for name in used)
|
||||
|
||||
# Define set of regular expressions and dependencies to optionally append
|
||||
# extra dependencies for test case based on key description.
|
||||
|
||||
# Skip AES test cases which require 192- or 256-bit key
|
||||
# if MBEDTLS_AES_ONLY_128_BIT_KEY_LENGTH defined
|
||||
AES_128BIT_ONLY_DEP_REGEX = re.compile(r'AES\s(192|256)')
|
||||
AES_128BIT_ONLY_DEP = ['!MBEDTLS_AES_ONLY_128_BIT_KEY_LENGTH']
|
||||
# Skip AES/ARIA/CAMELLIA test cases which require decrypt operation in ECB mode
|
||||
# if MBEDTLS_BLOCK_CIPHER_NO_DECRYPT enabled.
|
||||
ECB_NO_PADDING_DEP_REGEX = re.compile(r'(AES|ARIA|CAMELLIA).*ECB_NO_PADDING')
|
||||
ECB_NO_PADDING_DEP = ['!MBEDTLS_BLOCK_CIPHER_NO_DECRYPT']
|
||||
|
||||
DEPENDENCY_FROM_DESCRIPTION = OrderedDict()
|
||||
DEPENDENCY_FROM_DESCRIPTION[AES_128BIT_ONLY_DEP_REGEX] = AES_128BIT_ONLY_DEP
|
||||
DEPENDENCY_FROM_DESCRIPTION[ECB_NO_PADDING_DEP_REGEX] = ECB_NO_PADDING_DEP
|
||||
def generate_deps_from_description(
|
||||
description: str
|
||||
) -> List[str]:
|
||||
"""Return additional dependencies based on test case description and REGEX.
|
||||
"""
|
||||
dep_list = []
|
||||
for regex, deps in DEPENDENCY_FROM_DESCRIPTION.items():
|
||||
if re.search(regex, description):
|
||||
dep_list += deps
|
||||
|
||||
return dep_list
|
||||
|
||||
def tweak_key_pair_dependency(dep: str, usages: List[str]) -> List[str]:
|
||||
"""
|
||||
This helper function add the proper suffix to PSA_WANT_KEY_TYPE_xxx_KEY_PAIR
|
||||
symbols according to the required usage.
|
||||
"""
|
||||
if dep.endswith('KEY_PAIR'):
|
||||
return [dep + '_' + usage for usage in usages]
|
||||
return [dep]
|
||||
|
||||
def fix_key_pair_dependencies(dep_list: List[str], usages: List[str]) -> List[str]:
|
||||
new_list = [new_deps
|
||||
for dep in dep_list
|
||||
for new_deps in tweak_key_pair_dependency(dep, usages)]
|
||||
|
||||
return new_list
|
||||
221
vendor/mbedtls/framework/scripts/mbedtls_framework/psa_storage.py
vendored
Normal file
221
vendor/mbedtls/framework/scripts/mbedtls_framework/psa_storage.py
vendored
Normal file
@@ -0,0 +1,221 @@
|
||||
"""Knowledge about the PSA key store as implemented in Mbed TLS.
|
||||
|
||||
Note that if you need to make a change that affects how keys are
|
||||
stored, this may indicate that the key store is changing in a
|
||||
backward-incompatible way! Think carefully about backward compatibility
|
||||
before changing how test data is constructed or validated.
|
||||
"""
|
||||
|
||||
# Copyright The Mbed TLS Contributors
|
||||
# SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
#
|
||||
|
||||
import re
|
||||
import struct
|
||||
from typing import Dict, List, Optional, Set, Union
|
||||
import unittest
|
||||
|
||||
from . import c_build_helper
|
||||
from . import build_tree
|
||||
|
||||
|
||||
class Expr:
|
||||
"""Representation of a C expression with a known or knowable numerical value."""
|
||||
|
||||
def __init__(self, content: Union[int, str]):
|
||||
if isinstance(content, int):
|
||||
digits = 8 if content > 0xffff else 4
|
||||
self.string = '{0:#0{1}x}'.format(content, digits + 2)
|
||||
self.value_if_known = content #type: Optional[int]
|
||||
else:
|
||||
self.string = content
|
||||
self.unknown_values.add(self.normalize(content))
|
||||
self.value_if_known = None
|
||||
|
||||
value_cache = {} #type: Dict[str, int]
|
||||
"""Cache of known values of expressions."""
|
||||
|
||||
unknown_values = set() #type: Set[str]
|
||||
"""Expressions whose values are not present in `value_cache` yet."""
|
||||
|
||||
def update_cache(self) -> None:
|
||||
"""Update `value_cache` for expressions registered in `unknown_values`."""
|
||||
expressions = sorted(self.unknown_values)
|
||||
# Temporary, while Mbed TLS does not just rely on the TF-PSA-Crypto
|
||||
# build system to build its crypto library. When it does, the first
|
||||
# case can just be removed.
|
||||
|
||||
if build_tree.looks_like_root('.'):
|
||||
includes = ['include']
|
||||
if build_tree.looks_like_tf_psa_crypto_root('.'):
|
||||
includes.append('drivers/builtin/include')
|
||||
includes.append('drivers/everest/include')
|
||||
includes.append('drivers/everest/include/tf-psa-crypto/private/')
|
||||
includes.append('drivers/pqcp/include')
|
||||
elif not build_tree.is_mbedtls_3_6():
|
||||
includes.append('tf-psa-crypto/include')
|
||||
includes.append('tf-psa-crypto/drivers/builtin/include')
|
||||
includes.append('tf-psa-crypto/drivers/everest/include')
|
||||
includes.append('tf-psa-crypto/drivers/everest/include/tf-psa-crypto/private/')
|
||||
includes.append('tf-psa-crypto/drivers/pqcp/include')
|
||||
|
||||
values = c_build_helper.get_c_expression_values(
|
||||
'unsigned long', '%lu',
|
||||
expressions,
|
||||
header="""
|
||||
#include <psa/crypto.h>
|
||||
""",
|
||||
include_path=includes) #type: List[str]
|
||||
for e, v in zip(expressions, values):
|
||||
self.value_cache[e] = int(v, 0)
|
||||
self.unknown_values.clear()
|
||||
|
||||
@staticmethod
|
||||
def normalize(string: str) -> str:
|
||||
"""Put the given C expression in a canonical form.
|
||||
|
||||
This function is only intended to give correct results for the
|
||||
relatively simple kind of C expression typically used with this
|
||||
module.
|
||||
"""
|
||||
return re.sub(r'\s+', r'', string)
|
||||
|
||||
def value(self) -> int:
|
||||
"""Return the numerical value of the expression."""
|
||||
if self.value_if_known is None:
|
||||
if re.match(r'([0-9]+|0x[0-9a-f]+)\Z', self.string, re.I):
|
||||
return int(self.string, 0)
|
||||
normalized = self.normalize(self.string)
|
||||
if normalized not in self.value_cache:
|
||||
self.update_cache()
|
||||
self.value_if_known = self.value_cache[normalized]
|
||||
return self.value_if_known
|
||||
|
||||
Exprable = Union[str, int, Expr]
|
||||
"""Something that can be converted to a C expression with a known numerical value."""
|
||||
|
||||
def as_expr(thing: Exprable) -> Expr:
|
||||
"""Return an `Expr` object for `thing`.
|
||||
|
||||
If `thing` is already an `Expr` object, return it. Otherwise build a new
|
||||
`Expr` object from `thing`. `thing` can be an integer or a string that
|
||||
contains a C expression.
|
||||
"""
|
||||
if isinstance(thing, Expr):
|
||||
return thing
|
||||
else:
|
||||
return Expr(thing)
|
||||
|
||||
|
||||
class Key:
|
||||
"""Representation of a PSA crypto key object and its storage encoding.
|
||||
"""
|
||||
|
||||
LATEST_VERSION = 0
|
||||
"""The latest version of the storage format."""
|
||||
|
||||
def __init__(self, *,
|
||||
version: Optional[int] = None,
|
||||
id: Optional[int] = None, #pylint: disable=redefined-builtin
|
||||
lifetime: Exprable = 'PSA_KEY_LIFETIME_PERSISTENT',
|
||||
type: Exprable, #pylint: disable=redefined-builtin
|
||||
bits: int,
|
||||
usage: Exprable, alg: Exprable, alg2: Exprable,
|
||||
material: bytes #pylint: disable=used-before-assignment
|
||||
) -> None:
|
||||
self.version = self.LATEST_VERSION if version is None else version
|
||||
self.id = id #pylint: disable=invalid-name #type: Optional[int]
|
||||
self.lifetime = as_expr(lifetime) #type: Expr
|
||||
self.type = as_expr(type) #type: Expr
|
||||
self.bits = bits #type: int
|
||||
self.usage = as_expr(usage) #type: Expr
|
||||
self.alg = as_expr(alg) #type: Expr
|
||||
self.alg2 = as_expr(alg2) #type: Expr
|
||||
self.material = material #type: bytes
|
||||
|
||||
MAGIC = b'PSA\000KEY\000'
|
||||
|
||||
@staticmethod
|
||||
def pack(
|
||||
fmt: str,
|
||||
*args: Union[int, Expr]
|
||||
) -> bytes: #pylint: disable=used-before-assignment
|
||||
"""Pack the given arguments into a byte string according to the given format.
|
||||
|
||||
This function is similar to `struct.pack`, but with the following differences:
|
||||
* All integer values are encoded with standard sizes and in
|
||||
little-endian representation. `fmt` must not include an endianness
|
||||
prefix.
|
||||
* Arguments can be `Expr` objects instead of integers.
|
||||
* Only integer-valued elements are supported.
|
||||
"""
|
||||
return struct.pack('<' + fmt, # little-endian, standard sizes
|
||||
*[arg.value() if isinstance(arg, Expr) else arg
|
||||
for arg in args])
|
||||
|
||||
def bytes(self) -> bytes:
|
||||
"""Return the representation of the key in storage as a byte array.
|
||||
|
||||
This is the content of the PSA storage file. When PSA storage is
|
||||
implemented over stdio files, this does not include any wrapping made
|
||||
by the PSA-storage-over-stdio-file implementation.
|
||||
|
||||
Note that if you need to make a change in this function,
|
||||
this may indicate that the key store is changing in a
|
||||
backward-incompatible way! Think carefully about backward
|
||||
compatibility before making any change here.
|
||||
"""
|
||||
header = self.MAGIC + self.pack('L', self.version)
|
||||
if self.version == 0:
|
||||
attributes = self.pack('LHHLLL',
|
||||
self.lifetime, self.type, self.bits,
|
||||
self.usage, self.alg, self.alg2)
|
||||
material = self.pack('L', len(self.material)) + self.material
|
||||
else:
|
||||
raise NotImplementedError
|
||||
return header + attributes + material
|
||||
|
||||
def hex(self) -> str:
|
||||
"""Return the representation of the key as a hexadecimal string.
|
||||
|
||||
This is the hexadecimal representation of `self.bytes`.
|
||||
"""
|
||||
return self.bytes().hex()
|
||||
|
||||
def location_value(self) -> int:
|
||||
"""The numerical value of the location encoded in the key's lifetime."""
|
||||
return self.lifetime.value() >> 8
|
||||
|
||||
|
||||
class TestKey(unittest.TestCase):
|
||||
# pylint: disable=line-too-long
|
||||
"""A few smoke tests for the functionality of the `Key` class."""
|
||||
|
||||
def test_numerical(self):
|
||||
key = Key(version=0,
|
||||
id=1, lifetime=0x00000001,
|
||||
type=0x2400, bits=128,
|
||||
usage=0x00000300, alg=0x05500200, alg2=0x04c01000,
|
||||
material=b'@ABCDEFGHIJKLMNO')
|
||||
expected_hex = '505341004b45590000000000010000000024800000030000000250050010c00410000000404142434445464748494a4b4c4d4e4f'
|
||||
self.assertEqual(key.bytes(), bytes.fromhex(expected_hex))
|
||||
self.assertEqual(key.hex(), expected_hex)
|
||||
|
||||
def test_names(self):
|
||||
length = 0xfff8 // 8 # PSA_MAX_KEY_BITS in bytes
|
||||
key = Key(version=0,
|
||||
id=1, lifetime='PSA_KEY_LIFETIME_PERSISTENT',
|
||||
type='PSA_KEY_TYPE_RAW_DATA', bits=length*8,
|
||||
usage=0, alg=0, alg2=0,
|
||||
material=b'\x00' * length)
|
||||
expected_hex = '505341004b45590000000000010000000110f8ff000000000000000000000000ff1f0000' + '00' * length
|
||||
self.assertEqual(key.bytes(), bytes.fromhex(expected_hex))
|
||||
self.assertEqual(key.hex(), expected_hex)
|
||||
|
||||
def test_defaults(self):
|
||||
key = Key(type=0x1001, bits=8,
|
||||
usage=0, alg=0, alg2=0,
|
||||
material=b'\x2a')
|
||||
expected_hex = '505341004b455900000000000100000001100800000000000000000000000000010000002a'
|
||||
self.assertEqual(key.bytes(), bytes.fromhex(expected_hex))
|
||||
self.assertEqual(key.hex(), expected_hex)
|
||||
205
vendor/mbedtls/framework/scripts/mbedtls_framework/psa_test_case.py
vendored
Normal file
205
vendor/mbedtls/framework/scripts/mbedtls_framework/psa_test_case.py
vendored
Normal file
@@ -0,0 +1,205 @@
|
||||
"""Generate test cases for PSA API calls, with automatic dependencies.
|
||||
"""
|
||||
|
||||
# Copyright The Mbed TLS Contributors
|
||||
# SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
#
|
||||
|
||||
import os
|
||||
import re
|
||||
from typing import FrozenSet, List, Optional, Set
|
||||
|
||||
from . import build_tree
|
||||
from . import psa_information
|
||||
from . import test_case
|
||||
|
||||
|
||||
# Skip test cases for which the dependency symbols are not defined.
|
||||
# We assume that this means that a required mechanism is not implemented.
|
||||
# Note that if we erroneously skip generating test cases for
|
||||
# mechanisms that are not implemented, this should be caught
|
||||
# by the NOT_SUPPORTED test cases generated by generate_psa_tests.py
|
||||
# in test_suite_psa_crypto_not_supported and test_suite_psa_crypto_op_fail:
|
||||
# those emit tests with negative dependencies, which will not be skipped here.
|
||||
|
||||
def read_implemented_dependencies(acc: Set[str], filename: str) -> None:
|
||||
with open(filename) as input_stream:
|
||||
for line in input_stream:
|
||||
for symbol in re.findall(r'\bPSA_WANT_\w+\b', line):
|
||||
acc.add(symbol)
|
||||
|
||||
_implemented_dependencies = None #type: Optional[FrozenSet[str]] #pylint: disable=invalid-name
|
||||
|
||||
def find_dependencies_not_implemented(dependencies: List[str]) -> List[str]:
|
||||
"""List the dependencies that are not implemented."""
|
||||
global _implemented_dependencies #pylint: disable=global-statement,invalid-name
|
||||
if _implemented_dependencies is None:
|
||||
# Temporary, while Mbed TLS does not just rely on the TF-PSA-Crypto
|
||||
# build system to build its crypto library. When it does, the first
|
||||
# case can just be removed.
|
||||
|
||||
if build_tree.looks_like_root('.'):
|
||||
if build_tree.looks_like_mbedtls_root('.') and \
|
||||
(not build_tree.is_mbedtls_3_6()):
|
||||
include_dir = 'tf-psa-crypto/include'
|
||||
else:
|
||||
include_dir = 'include'
|
||||
|
||||
acc = set() #type: Set[str]
|
||||
for filename in [
|
||||
'psa/crypto_config.h',
|
||||
'psa/crypto_adjust_config_synonyms.h',
|
||||
'tf-psa-crypto/private/crypto_adjust_config_synonyms.h',
|
||||
]:
|
||||
path = os.path.join(build_tree.guess_project_root(),
|
||||
include_dir,
|
||||
filename)
|
||||
if os.path.exists(path):
|
||||
read_implemented_dependencies(acc, path)
|
||||
_implemented_dependencies = frozenset(acc)
|
||||
return [dep
|
||||
for dep in dependencies
|
||||
if (dep not in _implemented_dependencies and
|
||||
dep.startswith('PSA_WANT'))]
|
||||
|
||||
|
||||
class TestCase(test_case.TestCase):
|
||||
"""A PSA test case with automatically inferred dependencies.
|
||||
|
||||
For mechanisms like ECC curves where the support status includes
|
||||
the key bit-size, this class assumes that only one bit-size is
|
||||
involved in a given test case.
|
||||
"""
|
||||
|
||||
def __init__(self, dependency_prefix: Optional[str] = None) -> None:
|
||||
"""Construct a test case for a PSA Crypto API call.
|
||||
|
||||
`dependency_prefix`: prefix to use in dependencies. Defaults to
|
||||
``'PSA_WANT_'``. Use ``'MBEDTLS_PSA_BUILTIN_'``
|
||||
when specifically testing builtin implementations.
|
||||
"""
|
||||
super().__init__()
|
||||
del self.dependencies
|
||||
self.manual_dependencies = [] #type: List[str]
|
||||
self.automatic_dependencies = set() #type: Set[str]
|
||||
self.dependency_prefix = dependency_prefix #type: Optional[str]
|
||||
self.negated_dependencies = set() #type: Set[str]
|
||||
self.key_bits = None #type: Optional[int]
|
||||
self.key_pair_usage = None #type: Optional[List[str]]
|
||||
|
||||
def set_key_bits(self, key_bits: Optional[int]) -> None:
|
||||
"""Use the given key size for automatic dependency generation.
|
||||
|
||||
Call this function before set_arguments() if relevant.
|
||||
|
||||
This is only relevant for ECC and DH keys. For other key types,
|
||||
this information is ignored.
|
||||
"""
|
||||
self.key_bits = key_bits
|
||||
|
||||
def set_key_pair_usage(self, key_pair_usage: Optional[List[str]]) -> None:
|
||||
"""Use the given suffixes for key pair dependencies.
|
||||
|
||||
Call this function before set_arguments() if relevant.
|
||||
|
||||
This is only relevant for key pair types. For other key types,
|
||||
this information is ignored.
|
||||
"""
|
||||
self.key_pair_usage = key_pair_usage
|
||||
|
||||
def infer_dependencies(self, arguments: List[str]) -> List[str]:
|
||||
"""Infer dependencies based on the test case arguments."""
|
||||
dependencies = psa_information.automatic_dependencies(*arguments,
|
||||
prefix=self.dependency_prefix)
|
||||
if self.key_bits is not None:
|
||||
dependencies = psa_information.finish_family_dependencies(dependencies,
|
||||
self.key_bits)
|
||||
if self.key_pair_usage is not None:
|
||||
dependencies = psa_information.fix_key_pair_dependencies(dependencies,
|
||||
self.key_pair_usage)
|
||||
if 'PSA_WANT_KEY_TYPE_RSA_KEY_PAIR_GENERATE' in dependencies and \
|
||||
'PSA_WANT_KEY_TYPE_RSA_KEY_PAIR_GENERATE' not in self.negated_dependencies and \
|
||||
self.key_bits is not None:
|
||||
size_dependency = ('PSA_VENDOR_RSA_GENERATE_MIN_KEY_BITS <= ' +
|
||||
str(self.key_bits))
|
||||
dependencies.append(size_dependency)
|
||||
return dependencies
|
||||
|
||||
def assumes_not_supported(self, name: str) -> None:
|
||||
"""Negate the given mechanism for automatic dependency generation.
|
||||
|
||||
`name` can be either a dependency symbol (``PSA_WANT_xxx``) or
|
||||
a mechanism name (``PSA_KEY_TYPE_xxx``, etc.).
|
||||
|
||||
Call this function before set_arguments() for a test case that should
|
||||
run if the given mechanism is not supported.
|
||||
|
||||
Call modifiers such as set_key_bits() and set_key_pair_usage() before
|
||||
calling this method, if applicable.
|
||||
|
||||
A mechanism is a PSA_XXX symbol, e.g. PSA_KEY_TYPE_AES, PSA_ALG_HMAC,
|
||||
etc. For mechanisms like ECC curves where the support status includes
|
||||
the key bit-size, this class assumes that only one bit-size is
|
||||
involved in a given test case.
|
||||
"""
|
||||
if name.startswith('PSA_WANT_'):
|
||||
self.negated_dependencies.add(name)
|
||||
return
|
||||
if name == 'PSA_KEY_TYPE_RSA_KEY_PAIR' and \
|
||||
self.key_bits is not None and \
|
||||
self.key_pair_usage == ['GENERATE']:
|
||||
# When RSA key pair generation is not supported, it could be
|
||||
# due to the specific key size is out of range, or because
|
||||
# RSA key pair generation itself is not supported. Assume the
|
||||
# latter.
|
||||
dep = psa_information.psa_want_symbol(name, prefix=self.dependency_prefix)
|
||||
|
||||
self.negated_dependencies.add(dep + '_GENERATE')
|
||||
return
|
||||
dependencies = self.infer_dependencies([name])
|
||||
# * If we have more than one dependency to negate, the result would
|
||||
# say that all of the dependencies are disabled, which is not
|
||||
# a desirable outcome: the negation of (A and B) is (!A or !B),
|
||||
# not (!A and !B).
|
||||
# * If we have no dependency to negate, the result wouldn't be a
|
||||
# not-supported case.
|
||||
# Assert that we don't reach either such case.
|
||||
assert len(dependencies) == 1
|
||||
self.negated_dependencies.add(dependencies[0])
|
||||
|
||||
def set_arguments(self, arguments: List[str]) -> None:
|
||||
"""Set test case arguments and automatically infer dependencies."""
|
||||
super().set_arguments(arguments)
|
||||
dependencies = self.infer_dependencies(arguments)
|
||||
for i in range(len(dependencies)): #pylint: disable=consider-using-enumerate
|
||||
if dependencies[i] in self.negated_dependencies:
|
||||
dependencies[i] = '!' + dependencies[i]
|
||||
self.skip_if_any_not_implemented(dependencies)
|
||||
self.automatic_dependencies.update(dependencies)
|
||||
|
||||
def set_dependencies(self, dependencies: List[str]) -> None:
|
||||
"""Override any previously added automatic or manual dependencies.
|
||||
|
||||
Also override any previous instruction to skip the test case.
|
||||
"""
|
||||
self.manual_dependencies = dependencies
|
||||
self.automatic_dependencies.clear()
|
||||
self.skip_reasons = []
|
||||
|
||||
def add_dependencies(self, dependencies: List[str]) -> None:
|
||||
"""Add manual dependencies."""
|
||||
self.manual_dependencies += dependencies
|
||||
|
||||
def get_dependencies(self) -> List[str]:
|
||||
# Make the output independent of the order in which the dependencies
|
||||
# are calculated by the script. Also avoid duplicates. This makes
|
||||
# the output robust with respect to refactoring of the scripts.
|
||||
dependencies = set(self.manual_dependencies)
|
||||
dependencies.update(self.automatic_dependencies)
|
||||
return sorted(dependencies)
|
||||
|
||||
def skip_if_any_not_implemented(self, dependencies: List[str]) -> None:
|
||||
"""Skip the test case if any of the given dependencies is not implemented."""
|
||||
not_implemented = find_dependencies_not_implemented(dependencies)
|
||||
for dep in not_implemented:
|
||||
self.skip_because('not implemented: ' + dep)
|
||||
352
vendor/mbedtls/framework/scripts/mbedtls_framework/ssl_session_reset_check.py
vendored
Normal file
352
vendor/mbedtls/framework/scripts/mbedtls_framework/ssl_session_reset_check.py
vendored
Normal file
@@ -0,0 +1,352 @@
|
||||
"""Common code for generating the test code to validate mbedtls_ssl_session_reset().
|
||||
"""
|
||||
|
||||
# Copyright The Mbed TLS Contributors
|
||||
# SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
|
||||
import enum
|
||||
import os
|
||||
import re
|
||||
import sys
|
||||
import typing
|
||||
import argparse
|
||||
from typing import Dict, Iterator, List, Tuple, FrozenSet
|
||||
|
||||
from . import c_parsing_helper
|
||||
from . import typing_util
|
||||
from . import build_tree
|
||||
|
||||
class ResetBehavior(enum.Enum):
|
||||
KEEP = 0 # Kept unchanged before/after the reset
|
||||
RESET = 1 # Returned to the initial state (which is not necessarily 0)
|
||||
REALLOCATE = 2 # Pointer that gets reallocated
|
||||
IGNORE = 3 # Ignored field
|
||||
SPECIAL = 4
|
||||
|
||||
class ElementType(enum.Enum):
|
||||
SCALAR = 0
|
||||
POINTER = 1
|
||||
ARRAY = 2
|
||||
NAMED_STRUCTURE = 3
|
||||
IGNORE = 4
|
||||
SPECIAL = 5
|
||||
|
||||
class FieldsInfo(typing.NamedTuple):
|
||||
"""Expected reset behavior for the fields of the structure."""
|
||||
rules: Dict[str, ResetBehavior]
|
||||
special: Dict[str, List[str]]
|
||||
# The script isn't capable to identify named structures (ex: dtls_srtp_info)
|
||||
# so we keep an explicit list of them.
|
||||
named_structures: FrozenSet[str]
|
||||
|
||||
class CField():
|
||||
# pylint: disable=too-few-public-methods
|
||||
"""Information about one field of a C struct."""
|
||||
name: str
|
||||
conditional: List[str]
|
||||
element_type: ElementType
|
||||
|
||||
def __init__(self, name: str, conditionals: List[str], element_type: ElementType):
|
||||
self.name = name
|
||||
self.conditionals = conditionals.copy()
|
||||
self.element_type = element_type
|
||||
|
||||
def check_value(self) -> List[str]:
|
||||
raise Exception(f'Class {self.__class__.__name__} cannot handle entries'
|
||||
f'of type {self.element_type}')
|
||||
|
||||
class CFieldIgnore(CField):
|
||||
# pylint: disable=too-few-public-methods
|
||||
"""Explicitly ignored field."""
|
||||
def check_value(self) -> List[str]:
|
||||
return [f'/* {self.name} is ignored */']
|
||||
|
||||
class CFieldKeep(CField):
|
||||
# pylint: disable=too-few-public-methods
|
||||
"""Field kept unchanged."""
|
||||
def check_value(self) -> List[str]:
|
||||
if self.element_type == ElementType.SCALAR:
|
||||
return [f'TEST_EQUAL(before->{self.name}, after->{self.name});']
|
||||
elif self.element_type == ElementType.POINTER:
|
||||
return [f'TEST_ASSERT(before->{self.name} == after->{self.name});']
|
||||
elif self.element_type == ElementType.ARRAY:
|
||||
return [f'TEST_MEMORY_COMPARE(before->{self.name}, '
|
||||
f'sizeof(before->{self.name}), after->{self.name}, '
|
||||
f'sizeof(after->{self.name}));']
|
||||
elif self.element_type == ElementType.NAMED_STRUCTURE:
|
||||
return [f'TEST_MEMORY_COMPARE(&(before->{self.name}), '
|
||||
f'sizeof(before->{self.name}), &(after->{self.name}), '
|
||||
f'sizeof(after->{self.name}));']
|
||||
return super().check_value()
|
||||
|
||||
class CFieldReset(CField):
|
||||
# pylint: disable=too-few-public-methods
|
||||
"""Field returned to the intial state."""
|
||||
def check_value(self) -> List[str]:
|
||||
if (self.element_type == ElementType.SCALAR) or (self.element_type == ElementType.POINTER):
|
||||
return [f'TEST_ASSERT(after->{self.name} == initial.{self.name});']
|
||||
elif self.element_type == ElementType.ARRAY:
|
||||
return [f'TEST_MEMORY_COMPARE(after->{self.name}, '
|
||||
f'sizeof(after->{self.name}), initial.{self.name}, '
|
||||
f'sizeof(initial.{self.name}));']
|
||||
elif self.element_type == ElementType.NAMED_STRUCTURE:
|
||||
return [f'TEST_MEMORY_COMPARE(&(after->{self.name}), '
|
||||
f'sizeof(after->{self.name}), &(initial.{self.name}), '
|
||||
f'sizeof(initial.{self.name}));']
|
||||
return super().check_value()
|
||||
|
||||
class CFieldReallocate(CField):
|
||||
# pylint: disable=too-few-public-methods
|
||||
"""Pointer (might be) reallocated during reset."""
|
||||
def check_value(self) -> List[str]:
|
||||
if self.element_type == ElementType.POINTER:
|
||||
return [f'TEST_ASSERT(after->{self.name} != NULL);']
|
||||
return super().check_value()
|
||||
|
||||
class CFieldSpecial(CField):
|
||||
# pylint: disable=too-few-public-methods
|
||||
"""Field with a custom check."""
|
||||
custom_behavior: List[str]
|
||||
|
||||
def __init__(self, name: str, conditional: List[str], element_type: ElementType,
|
||||
custom_behavior: List[str]):
|
||||
self.custom_behavior = custom_behavior
|
||||
super().__init__(name, conditional, element_type)
|
||||
|
||||
def check_value(self) -> List[str]:
|
||||
return self.custom_behavior
|
||||
|
||||
class CStruct:
|
||||
# pylint: disable=too-few-public-methods
|
||||
"""Information about the fields of a C struct."""
|
||||
|
||||
_PREPROCESSOR_RE = re.compile(r'\s*#\s*(\w+)\s*(.*)')
|
||||
_STRUCT_RE = re.compile(r'struct\s+(\w+)\s*{')
|
||||
_FIELD_RE = re.compile(r'\s*([^;]+);')
|
||||
_PRIVATE_FIELD_RE = re.compile(r'MBEDTLS_PRIVATE\((\w+)\)')
|
||||
_BARE_FIELD_RE = re.compile(r'[\t *](\w+)\Z')
|
||||
_NON_BLANK_RE = re.compile(r'.*\S')
|
||||
|
||||
def _get_element_type(self, name: str, declaration: str) -> ElementType:
|
||||
"""Return structure field type based on either its name or the fact
|
||||
that it belongs to the list of special symbols/named structures"""
|
||||
# Check for fields with custom check rules
|
||||
if name in self.fields_info.special:
|
||||
return ElementType.SPECIAL
|
||||
# Check for named structures
|
||||
if name in self.fields_info.named_structures:
|
||||
return ElementType.NAMED_STRUCTURE
|
||||
# Check for pointer
|
||||
if '*' in declaration:
|
||||
return ElementType.POINTER
|
||||
# Check for array
|
||||
if '[' in declaration:
|
||||
return ElementType.ARRAY
|
||||
# If we get here then the field is a scalar
|
||||
return ElementType.SCALAR
|
||||
|
||||
def _parse_field(self, declaration: str, conditionals: List[str]) -> CField:
|
||||
"""Return the CField object describing the given field declaration."""
|
||||
# Note that this simplistic parsing finds fields in inline
|
||||
# sub-structs, unions and enums.
|
||||
m = self._PRIVATE_FIELD_RE.search(declaration)
|
||||
if not m:
|
||||
m = self._BARE_FIELD_RE.search(declaration)
|
||||
if not m:
|
||||
raise Exception(f'Field name not found in "{declaration}"')
|
||||
name = m.group(1)
|
||||
# Get the expected behavior on reset
|
||||
if name not in self.fields_info.rules:
|
||||
raise Exception(f'Field {name} does not have an associated behavior')
|
||||
behavior = self.fields_info.rules[name]
|
||||
element_type = self._get_element_type(name, declaration)
|
||||
if behavior == ResetBehavior.SPECIAL:
|
||||
return CFieldSpecial(name, conditionals, element_type,
|
||||
self.fields_info.special[name])
|
||||
elif behavior == ResetBehavior.KEEP:
|
||||
return CFieldKeep(name, conditionals, element_type)
|
||||
elif behavior == ResetBehavior.REALLOCATE:
|
||||
return CFieldReallocate(name, conditionals, element_type)
|
||||
elif behavior == ResetBehavior.IGNORE:
|
||||
return CFieldIgnore(name, conditionals, element_type)
|
||||
elif behavior == ResetBehavior.RESET:
|
||||
return CFieldReset(name, conditionals, element_type)
|
||||
else:
|
||||
raise Exception(f'Unhandled behavior {behavior}')
|
||||
|
||||
@staticmethod
|
||||
def _continue_parsing_preprocessor(arguments: str,
|
||||
lines: Iterator[Tuple[int, str]]) -> str:
|
||||
"""Append continuation lines of preprocesssor directive."""
|
||||
while True:
|
||||
try:
|
||||
line_content = next(lines)[1]
|
||||
arguments = arguments + '\n' + line_content
|
||||
except StopIteration:
|
||||
raise Exception('Unexpected end of file reached while '
|
||||
' parsing a C preprocessor directive')
|
||||
if not line_content.endswith('\\'):
|
||||
break
|
||||
return arguments
|
||||
|
||||
def _structure_fields(self,
|
||||
lines: Iterator[Tuple[int, str]],
|
||||
struct_name: str) -> Iterator[CField]:
|
||||
"""Yield a CField object for each field of the given structure."""
|
||||
# pylint: disable=too-many-branches
|
||||
found_start = False
|
||||
for num, line in lines:
|
||||
m = self._STRUCT_RE.match(line)
|
||||
if m and m.group(1) == struct_name:
|
||||
found_start = True
|
||||
break
|
||||
if not found_start:
|
||||
raise Exception(f'Definition of struct {struct_name} not found')
|
||||
conditionals: List[str] = []
|
||||
for num, line in lines:
|
||||
if line.startswith('}'):
|
||||
return
|
||||
m = self._PREPROCESSOR_RE.match(line)
|
||||
if m:
|
||||
# If the preprocessor directives are included in parentheses (ex:
|
||||
# "(defined(AAA) && defined(BBB))") then 'line' contains the full directive
|
||||
# including new lines (if present) so we can just copy that.
|
||||
# If instead outer parentheses are missing, ex: "defined(AAA) && defined(BBB)"
|
||||
# then parsing stops at the end of the line so we need to keep parsing
|
||||
# manually if there is a "\" at the end of the line.
|
||||
if line.endswith('\\'):
|
||||
arguments = m.group(2)
|
||||
arguments = self._continue_parsing_preprocessor(arguments, lines)
|
||||
one_conditional = '#if ' + arguments
|
||||
else:
|
||||
one_conditional = line
|
||||
one_conditional = one_conditional + '\n'
|
||||
directive = m.group(1)
|
||||
if directive == 'if':
|
||||
conditionals.append(one_conditional)
|
||||
elif directive == 'endif':
|
||||
del conditionals[-1]
|
||||
else:
|
||||
raise Exception(f'Unsupported directive #{directive} at line {num}')
|
||||
continue
|
||||
m = self._FIELD_RE.match(line)
|
||||
if m:
|
||||
yield self._parse_field(m.group(1), conditionals)
|
||||
continue
|
||||
m = self._NON_BLANK_RE.match(line)
|
||||
if m:
|
||||
raise Exception(f'Failed to parse non-empty line {num}. Content is: {line}')
|
||||
raise Exception(f'End of definition of struct {struct_name} not found')
|
||||
|
||||
def _check_special_fields(self):
|
||||
"""Ensure that all the entries FieldsInfo.rules that are given a SPECIAL
|
||||
behavior also have the corresponding entry in FieldsInfo.special
|
||||
(and viceversa)"""
|
||||
in_rules = frozenset(name for name in self.fields_info.rules
|
||||
if self.fields_info.rules[name] == ResetBehavior.SPECIAL)
|
||||
in_special = frozenset(self.fields_info.special)
|
||||
if in_rules != in_special:
|
||||
raise Exception(f'Fields with SPECIAL rule in FieldsInfo.rules but '
|
||||
f'not listed in FieldsInfo.special: {in_rules - in_special}. '
|
||||
f'Fields listed FieldsInfo.special, but not given a'
|
||||
f'SPECIAL rule in FieldsInfo.rules: {in_special - in_rules}.')
|
||||
|
||||
def _check_rules_struct_fields_matching(self):
|
||||
"""Ensure that for each field of the given FieldsInfo.rules there is
|
||||
an entry in the parsed C structure and viceversa"""
|
||||
given = frozenset(name for name in self.fields_info.rules)
|
||||
parsed = frozenset(field.name for field in self.fields)
|
||||
if given != parsed:
|
||||
raise Exception(f'Fields found in the C struct but not given a '
|
||||
f'reset behavior: {parsed - given}. '
|
||||
f'Fields given a reset behavior but not found in '
|
||||
f'the C struct: {given - parsed}')
|
||||
|
||||
def __init__(self, file_name: str, struct_name: str,
|
||||
fields_info: FieldsInfo) -> None:
|
||||
"""Parse a structure definition in a C source file."""
|
||||
self.fields_info = fields_info
|
||||
self._check_special_fields()
|
||||
lines = c_parsing_helper.read_logical_lines(file_name)
|
||||
self.fields = list(self._structure_fields(lines, struct_name))
|
||||
self._check_rules_struct_fields_matching()
|
||||
|
||||
|
||||
class SSLContextStruct(CStruct):
|
||||
# pylint: disable=too-few-public-methods
|
||||
"""Information about the fields of struct mbedtls_ssl_context."""
|
||||
|
||||
def __init__(self, fields_info: FieldsInfo) -> None:
|
||||
super().__init__('include/mbedtls/ssl.h', 'mbedtls_ssl_context',
|
||||
fields_info)
|
||||
|
||||
def write_check_function(self, out: typing_util.Writable) -> None:
|
||||
"""Write the generated context-checking function to the output."""
|
||||
out.write(f"""\
|
||||
/*
|
||||
* Copyright The Mbed TLS Contributors
|
||||
* SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
*/
|
||||
|
||||
/*
|
||||
* The following function was automatically generated through the script
|
||||
* {sys.argv[0]}.
|
||||
*/
|
||||
|
||||
#include <test/ssl_helpers.h>
|
||||
#include <test/ssl_helpers_internal.h>
|
||||
#include "mbedtls/psa_util.h"
|
||||
#include <test/macros.h>
|
||||
|
||||
#include <limits.h>
|
||||
|
||||
#if defined(MBEDTLS_SSL_TLS_C)
|
||||
|
||||
int mbedtls_test_ssl_check_context_after_session_reset(const mbedtls_ssl_context *before,
|
||||
const mbedtls_ssl_context *after)
|
||||
{{
|
||||
mbedtls_ssl_context initial;
|
||||
int ret = -1;
|
||||
|
||||
/* Create a freshly initialized SSL context*/
|
||||
memset(&initial, 0, sizeof(initial));
|
||||
mbedtls_ssl_init(&initial);
|
||||
TEST_EQUAL(mbedtls_ssl_setup(&initial, after->conf), 0);
|
||||
|
||||
/* *INDENT-OFF* */
|
||||
""")
|
||||
for field in self.fields:
|
||||
if len(field.conditionals) > 0:
|
||||
out.write('\n'.join(field.conditionals))
|
||||
for check_line in field.check_value():
|
||||
out.write(f' {check_line}\n')
|
||||
if len(field.conditionals) > 0:
|
||||
out.write('#endif\n' * len(field.conditionals))
|
||||
out.write(f"""\
|
||||
/* *INDENT-ON* */
|
||||
|
||||
ret = 0;
|
||||
|
||||
exit:
|
||||
mbedtls_ssl_free(&initial);
|
||||
|
||||
return ret;
|
||||
}}
|
||||
|
||||
#endif /* MBEDTLS_SSL_TLS_C */
|
||||
""")
|
||||
|
||||
|
||||
def main(fields_info: FieldsInfo):
|
||||
if not build_tree.looks_like_mbedtls_root(os.curdir):
|
||||
raise Exception("The script must be launched from the root path of Mbed TLS")
|
||||
arg_parser = argparse.ArgumentParser()
|
||||
arg_parser.add_argument('-o', dest='output_file',
|
||||
help='Generated output file',
|
||||
default='tests/src/ssl_context_reset_verifier.c')
|
||||
parsed_args = arg_parser.parse_args()
|
||||
|
||||
output_file = parsed_args.output_file
|
||||
with open(output_file, 'wt') as out:
|
||||
ssl_context = SSLContextStruct(fields_info)
|
||||
ssl_context.write_check_function(out)
|
||||
175
vendor/mbedtls/framework/scripts/mbedtls_framework/test_case.py
vendored
Normal file
175
vendor/mbedtls/framework/scripts/mbedtls_framework/test_case.py
vendored
Normal file
@@ -0,0 +1,175 @@
|
||||
"""Library for constructing an Mbed TLS test case.
|
||||
"""
|
||||
|
||||
# Copyright The Mbed TLS Contributors
|
||||
# SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
#
|
||||
|
||||
import binascii
|
||||
import os
|
||||
import sys
|
||||
from typing import Iterable, List, Optional
|
||||
from enum import Enum
|
||||
|
||||
from . import build_tree
|
||||
from . import psa_information
|
||||
from . import typing_util
|
||||
|
||||
HASHES_3_6 = {
|
||||
"PSA_ALG_MD5" : "MBEDTLS_MD_CAN_MD5",
|
||||
"PSA_ALG_RIPEMD160" : "MBEDTLS_MD_CAN_RIPEMD160",
|
||||
"PSA_ALG_SHA_1" : "MBEDTLS_MD_CAN_SHA1",
|
||||
"PSA_ALG_SHA_224" : "MBEDTLS_MD_CAN_SHA224",
|
||||
"PSA_ALG_SHA_256" : "MBEDTLS_MD_CAN_SHA256",
|
||||
"PSA_ALG_SHA_384" : "MBEDTLS_MD_CAN_SHA384",
|
||||
"PSA_ALG_SHA_512" : "MBEDTLS_MD_CAN_SHA512",
|
||||
"PSA_ALG_SHA3_224" : "MBEDTLS_MD_CAN_SHA3_224",
|
||||
"PSA_ALG_SHA3_256" : "MBEDTLS_MD_CAN_SHA3_256",
|
||||
"PSA_ALG_SHA3_384" : "MBEDTLS_MD_CAN_SHA3_384",
|
||||
"PSA_ALG_SHA3_512" : "MBEDTLS_MD_CAN_SHA3_512"
|
||||
}
|
||||
|
||||
PK_MACROS_3_6 = {
|
||||
"PSA_KEY_TYPE_ECC_PUBLIC_KEY" : "MBEDTLS_PK_HAVE_ECC_KEYS"
|
||||
}
|
||||
|
||||
class Domain36(Enum):
|
||||
PSA = 1
|
||||
TLS_1_3_ONLY = 2
|
||||
USE_PSA = 3
|
||||
LEGACY = 4
|
||||
|
||||
def hex_string(data: bytes) -> str:
|
||||
return '"' + binascii.hexlify(data).decode('ascii') + '"'
|
||||
|
||||
class MissingDescription(Exception):
|
||||
pass
|
||||
|
||||
class MissingFunction(Exception):
|
||||
pass
|
||||
|
||||
class TestCase:
|
||||
"""An Mbed TLS test case."""
|
||||
|
||||
def __init__(self, description: Optional[str] = None):
|
||||
self.comments = [] #type: List[str]
|
||||
self.description = description #type: Optional[str]
|
||||
self.dependencies = [] #type: List[str]
|
||||
self.function = None #type: Optional[str]
|
||||
self.arguments = [] #type: List[str]
|
||||
self.skip_reasons = [] #type: List[str]
|
||||
|
||||
def add_comment(self, *lines: str) -> None:
|
||||
self.comments += lines
|
||||
|
||||
def set_description(self, description: str) -> None:
|
||||
self.description = description
|
||||
|
||||
def get_dependencies(self) -> List[str]:
|
||||
return self.dependencies
|
||||
|
||||
def set_dependencies(self, dependencies: List[str]) -> None:
|
||||
self.dependencies = dependencies
|
||||
|
||||
def set_function(self, function: str) -> None:
|
||||
self.function = function
|
||||
|
||||
def set_arguments(self, arguments: List[str]) -> None:
|
||||
self.arguments = arguments
|
||||
|
||||
def skip_because(self, reason: str) -> None:
|
||||
"""Skip this test case.
|
||||
|
||||
It will be included in the output, but commented out.
|
||||
|
||||
This is intended for test cases that are obtained from a
|
||||
systematic enumeration, but that have dependencies that cannot
|
||||
be fulfilled. Since we don't want to have test cases that are
|
||||
never executed, we arrange not to have actual test cases. But
|
||||
we do include comments to make it easier to understand the output
|
||||
of test case generation.
|
||||
|
||||
reason must be a non-empty string explaining to humans why this
|
||||
test case is skipped.
|
||||
"""
|
||||
self.skip_reasons.append(reason)
|
||||
|
||||
def check_completeness(self) -> None:
|
||||
if self.description is None:
|
||||
raise MissingDescription
|
||||
if self.function is None:
|
||||
raise MissingFunction
|
||||
|
||||
def write(self, out: typing_util.Writable) -> None:
|
||||
"""Write the .data file paragraph for this test case.
|
||||
|
||||
The output starts and ends with a single newline character. If the
|
||||
surrounding code writes lines (consisting of non-newline characters
|
||||
and a final newline), you will end up with a blank line before, but
|
||||
not after the test case.
|
||||
"""
|
||||
self.check_completeness()
|
||||
assert self.description is not None # guide mypy
|
||||
assert self.function is not None # guide mypy
|
||||
out.write('\n')
|
||||
for line in self.comments:
|
||||
out.write('# ' + line + '\n')
|
||||
prefix = ''
|
||||
if self.skip_reasons:
|
||||
prefix = '## '
|
||||
for reason in self.skip_reasons:
|
||||
out.write('## # skipped because: ' + reason + '\n')
|
||||
out.write(prefix + self.description + '\n')
|
||||
dependencies = self.get_dependencies()
|
||||
if dependencies:
|
||||
out.write(prefix + 'depends_on:' +
|
||||
':'.join(dependencies) + '\n')
|
||||
out.write(prefix + self.function + ':' +
|
||||
':'.join(self.arguments) + '\n')
|
||||
|
||||
def write_data_stream(out,
|
||||
test_cases: Iterable[TestCase],
|
||||
caller: Optional[str] = None) -> None:
|
||||
"""Write the test cases to the specified output stream."""
|
||||
if caller is None:
|
||||
caller = os.path.basename(sys.argv[0])
|
||||
out.write('# Automatically generated by {}. Do not edit!\n'
|
||||
.format(caller))
|
||||
for tc in test_cases:
|
||||
tc.write(out)
|
||||
out.write('\n# End of automatically generated file.\n')
|
||||
|
||||
def write_data_file(filename: str,
|
||||
test_cases: Iterable[TestCase],
|
||||
caller: Optional[str] = None) -> None:
|
||||
"""Write the test cases to the specified file.
|
||||
|
||||
If the file already exists, it is overwritten.
|
||||
"""
|
||||
tempfile = filename + '.new'
|
||||
with open(tempfile, 'w') as out:
|
||||
write_data_stream(out, test_cases, caller)
|
||||
os.replace(tempfile, filename)
|
||||
|
||||
def psa_or_3_6_feature_macro(psa_name: str,
|
||||
domain_3_6: Domain36) -> str:
|
||||
"""Determine the dependency symbol for a given psa_name based on
|
||||
the domain and Mbed TLS version. For more information about the domains,
|
||||
and MBEDTLS_MD_CAN_ prefixed symbols, see transition-guards.md.
|
||||
This function currently works with hashes and some PK symbols only.
|
||||
It accepts PSA_ALG_xxx or PSA_KEY_TYPE_xxx as inputs for psa_name.
|
||||
"""
|
||||
|
||||
if domain_3_6 == Domain36.PSA or domain_3_6 == Domain36.TLS_1_3_ONLY or \
|
||||
not build_tree.is_mbedtls_3_6():
|
||||
if psa_name in PK_MACROS_3_6 or psa_name in HASHES_3_6:
|
||||
return psa_information.psa_want_symbol(psa_name)
|
||||
|
||||
if domain_3_6 == Domain36.USE_PSA:
|
||||
if psa_name in PK_MACROS_3_6:
|
||||
return PK_MACROS_3_6[psa_name]
|
||||
|
||||
if psa_name in HASHES_3_6:
|
||||
return HASHES_3_6[psa_name]
|
||||
|
||||
raise ValueError(f'Unable to determine dependency symbol for {psa_name} in {domain_3_6}')
|
||||
249
vendor/mbedtls/framework/scripts/mbedtls_framework/test_data_generation.py
vendored
Normal file
249
vendor/mbedtls/framework/scripts/mbedtls_framework/test_data_generation.py
vendored
Normal file
@@ -0,0 +1,249 @@
|
||||
"""Common code for test data generation.
|
||||
|
||||
This module defines classes that are of general use to automatically
|
||||
generate .data files for unit tests, as well as a main function.
|
||||
|
||||
These are used both by generate_psa_tests.py and generate_bignum_tests.py.
|
||||
"""
|
||||
|
||||
# Copyright The Mbed TLS Contributors
|
||||
# SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
#
|
||||
|
||||
import argparse
|
||||
import io
|
||||
import os
|
||||
import posixpath
|
||||
import re
|
||||
import inspect
|
||||
|
||||
from abc import ABCMeta, abstractmethod
|
||||
from typing import Callable, Dict, Iterable, Iterator, List, Type, TypeVar
|
||||
|
||||
from . import build_tree
|
||||
from . import test_case
|
||||
|
||||
T = TypeVar('T') #pylint: disable=invalid-name
|
||||
|
||||
|
||||
class BaseTest(metaclass=ABCMeta):
|
||||
"""Base class for test case generation.
|
||||
|
||||
Attributes:
|
||||
count: Counter for test cases from this class.
|
||||
case_description: Short description of the test case. This may be
|
||||
automatically generated using the class, or manually set.
|
||||
dependencies: A list of dependencies required for the test case.
|
||||
show_test_count: Toggle for inclusion of `count` in the test description.
|
||||
test_function: Test function which the class generates cases for.
|
||||
test_name: A common name or description of the test function. This can
|
||||
be `test_function`, a clearer equivalent, or a short summary of the
|
||||
test function's purpose.
|
||||
"""
|
||||
count = 0
|
||||
case_description = ""
|
||||
dependencies = [] # type: List[str]
|
||||
show_test_count = True
|
||||
test_function = ""
|
||||
test_name = ""
|
||||
|
||||
def __new__(cls, *args, **kwargs):
|
||||
# pylint: disable=unused-argument
|
||||
cls.count += 1
|
||||
return super().__new__(cls)
|
||||
|
||||
@abstractmethod
|
||||
def arguments(self) -> List[str]:
|
||||
"""Get the list of arguments for the test case.
|
||||
|
||||
Override this method to provide the list of arguments required for
|
||||
the `test_function`.
|
||||
|
||||
Returns:
|
||||
List of arguments required for the test function.
|
||||
"""
|
||||
raise NotImplementedError
|
||||
|
||||
def description(self) -> str:
|
||||
"""Create a test case description.
|
||||
|
||||
Creates a description of the test case, including a name for the test
|
||||
function, an optional case count, and a description of the specific
|
||||
test case. This should inform a reader what is being tested, and
|
||||
provide context for the test case.
|
||||
|
||||
Returns:
|
||||
Description for the test case.
|
||||
"""
|
||||
if self.show_test_count:
|
||||
return "{} #{} {}".format(
|
||||
self.test_name, self.count, self.case_description
|
||||
).strip()
|
||||
else:
|
||||
return "{} {}".format(self.test_name, self.case_description).strip()
|
||||
|
||||
|
||||
def create_test_case(self) -> test_case.TestCase:
|
||||
"""Generate TestCase from the instance."""
|
||||
tc = test_case.TestCase()
|
||||
tc.set_description(self.description())
|
||||
tc.set_function(self.test_function)
|
||||
tc.set_arguments(self.arguments())
|
||||
tc.set_dependencies(self.dependencies)
|
||||
|
||||
return tc
|
||||
|
||||
@classmethod
|
||||
@abstractmethod
|
||||
def generate_function_tests(cls) -> Iterator[test_case.TestCase]:
|
||||
"""Generate test cases for the class test function.
|
||||
|
||||
This will be called in classes where `test_function` is set.
|
||||
Implementations should yield TestCase objects, by creating instances
|
||||
of the class with appropriate input data, and then calling
|
||||
`create_test_case()` on each.
|
||||
"""
|
||||
raise NotImplementedError
|
||||
|
||||
|
||||
class BaseTarget:
|
||||
#pylint: disable=too-few-public-methods
|
||||
"""Base target for test case generation.
|
||||
|
||||
Child classes of this class represent an output file, and can be referred
|
||||
to as file targets. These indicate where test cases will be written to for
|
||||
all subclasses of the file target, which is set by `target_basename`.
|
||||
|
||||
Attributes:
|
||||
target_basename: Basename of file to write generated tests to. This
|
||||
should be specified in a child class of BaseTarget.
|
||||
"""
|
||||
target_basename = ""
|
||||
|
||||
@classmethod
|
||||
def generate_tests(cls) -> Iterator[test_case.TestCase]:
|
||||
"""Generate test cases for the class and its subclasses.
|
||||
|
||||
In classes with `test_function` set, `generate_function_tests()` is
|
||||
called to generate test cases first.
|
||||
|
||||
In all classes, this method will iterate over its subclasses, and
|
||||
yield from `generate_tests()` in each. Calling this method on a class X
|
||||
will yield test cases from all classes derived from X.
|
||||
"""
|
||||
if issubclass(cls, BaseTest) and not inspect.isabstract(cls):
|
||||
#pylint: disable=no-member
|
||||
yield from cls.generate_function_tests()
|
||||
for subclass in sorted(cls.__subclasses__(), key=lambda c: c.__name__):
|
||||
yield from subclass.generate_tests()
|
||||
|
||||
|
||||
class TestGenerator:
|
||||
"""Generate test cases and write to data files."""
|
||||
|
||||
# Note that targets whose names contain 'test_format' have their content
|
||||
# validated by `abi_check.py`.
|
||||
targets = {} # type: Dict[str, Callable[..., Iterable[test_case.TestCase]]]
|
||||
|
||||
def __init__(self, options) -> None:
|
||||
self.test_suite_directory = options.directory
|
||||
# Update `targets` with an entry for each child class of BaseTarget.
|
||||
# Each entry represents a file generated by the BaseTarget framework,
|
||||
# and enables generating the .data files using the CLI.
|
||||
self.targets.update({
|
||||
subclass.target_basename: subclass.generate_tests
|
||||
for subclass in BaseTarget.__subclasses__()
|
||||
if subclass.target_basename
|
||||
})
|
||||
|
||||
def filename_for(self, basename: str) -> str:
|
||||
"""The location of the data file with the specified base name."""
|
||||
return posixpath.join(self.test_suite_directory, basename + '.data')
|
||||
|
||||
def write_test_data_file(self, basename: str,
|
||||
test_cases: Iterable[test_case.TestCase]) -> None:
|
||||
"""Write the test cases to a .data file.
|
||||
|
||||
The output file is ``basename + '.data'`` in the test suite directory.
|
||||
"""
|
||||
filename = self.filename_for(basename)
|
||||
test_case.write_data_file(filename, test_cases)
|
||||
|
||||
def generate_target(self, name: str, *target_args) -> None:
|
||||
"""Generate cases and write to data file for a target.
|
||||
|
||||
For target callables which require arguments, override this function
|
||||
and pass these arguments using super() (see PSATestGenerator).
|
||||
"""
|
||||
test_cases = self.targets[name](*target_args)
|
||||
self.write_test_data_file(name, test_cases)
|
||||
|
||||
def is_up_to_date(self, target) -> bool:
|
||||
"""Check if the given target already has the expected content."""
|
||||
filename = self.filename_for(target)
|
||||
if not os.path.exists(filename):
|
||||
return False
|
||||
test_cases = self.targets[target]()
|
||||
out = io.StringIO()
|
||||
test_case.write_data_stream(out, test_cases)
|
||||
out.seek(0)
|
||||
new_content = out.read()
|
||||
out.close()
|
||||
with open(filename) as current_file:
|
||||
old_content = current_file.read()
|
||||
return new_content == old_content
|
||||
|
||||
|
||||
def main(args, description: str, generator_class: Type[TestGenerator] = TestGenerator):
|
||||
"""Command line entry point."""
|
||||
parser = argparse.ArgumentParser(description=description)
|
||||
parser.add_argument('--list', action='store_true',
|
||||
help='List available targets and exit')
|
||||
parser.add_argument('--list-for-cmake', action='store_true',
|
||||
help='Print \';\'-separated list of available targets and exit')
|
||||
parser.add_argument('--list-outdated', action='store_true',
|
||||
help=('List outdated targets and exit '
|
||||
'(succeeds even if there are outdated or missing targets)'))
|
||||
# If specified explicitly, this option may be a path relative to the
|
||||
# current directory when the script is invoked. The default value
|
||||
# is relative to the mbedtls root, which we don't know yet. So we
|
||||
# can't set a string as the default value here.
|
||||
parser.add_argument('--directory', metavar='DIR',
|
||||
help='Output directory (default: tests/suites)')
|
||||
parser.add_argument('targets', nargs='*', metavar='TARGET',
|
||||
help='Target file to generate (default: all; "-": none)')
|
||||
options = parser.parse_args(args)
|
||||
|
||||
# Change to the mbedtls root, to keep things simple. But first, adjust
|
||||
# command line options that might be relative paths.
|
||||
if options.directory is None:
|
||||
options.directory = 'tests/suites'
|
||||
else:
|
||||
options.directory = os.path.abspath(options.directory)
|
||||
build_tree.chdir_to_root()
|
||||
|
||||
generator = generator_class(options)
|
||||
if options.list:
|
||||
for name in sorted(generator.targets):
|
||||
print(generator.filename_for(name))
|
||||
return
|
||||
# List in a cmake list format (i.e. ';'-separated)
|
||||
if options.list_for_cmake:
|
||||
print(';'.join(generator.filename_for(name)
|
||||
for name in sorted(generator.targets)), end='')
|
||||
return
|
||||
if options.targets:
|
||||
# Allow "-" as a special case so you can run
|
||||
# ``generate_xxx_tests.py - $targets`` and it works uniformly whether
|
||||
# ``$targets`` is empty or not.
|
||||
options.targets = [os.path.basename(re.sub(r'\.data\Z', r'', target))
|
||||
for target in options.targets
|
||||
if target != '-']
|
||||
else:
|
||||
options.targets = sorted(generator.targets)
|
||||
for target in options.targets:
|
||||
if options.list_outdated:
|
||||
if not generator.is_up_to_date(target):
|
||||
print(generator.filename_for(target))
|
||||
else:
|
||||
generator.generate_target(target)
|
||||
341
vendor/mbedtls/framework/scripts/mbedtls_framework/test_driver.py
vendored
Normal file
341
vendor/mbedtls/framework/scripts/mbedtls_framework/test_driver.py
vendored
Normal file
@@ -0,0 +1,341 @@
|
||||
"""Library for building a TF-PSA-Crypto test driver from the built-in driver
|
||||
"""
|
||||
|
||||
# Copyright The Mbed TLS Contributors
|
||||
# SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
#
|
||||
|
||||
import argparse
|
||||
import re
|
||||
import shutil
|
||||
import subprocess
|
||||
|
||||
from fnmatch import fnmatch
|
||||
from pathlib import Path
|
||||
from typing import Iterable, List, Match, Optional, Set
|
||||
|
||||
def get_parsearg_base() -> argparse.ArgumentParser:
|
||||
""" Get base arguments for scripts generating a TF-PSA-Crypto test driver """
|
||||
parser = argparse.ArgumentParser(description="""\
|
||||
Clone the built-in driver tree, rewrite header inclusions and prefix
|
||||
exposed C identifiers.
|
||||
""")
|
||||
|
||||
parser.add_argument("dst_dir", metavar="DST_DIR",
|
||||
help="Destination directory (relative to repository root)")
|
||||
parser.add_argument("--driver", default="libtestdriver1", metavar="DRIVER",
|
||||
help="Test driver name (default: %(default)s).")
|
||||
parser.add_argument('--list-vars-for-cmake', nargs="?", \
|
||||
const="__AUTO__", metavar="FILE",
|
||||
help="""
|
||||
Generate a file to be included from a CMakeLists.txt and exit. The file
|
||||
defines CMake list variables with the script's inputs/outputs files. If
|
||||
FILE is omitted, the output name defaults to '<DRIVER>-list-vars.cmake'.
|
||||
""")
|
||||
return parser
|
||||
|
||||
class TestDriverGenerator:
|
||||
"""A TF-PSA-Crypto test driver generator"""
|
||||
def __init__(self, src_dir: Path, dst_dir: Path, driver: str, \
|
||||
exclude_files: Optional[Iterable[str]] = None) -> None:
|
||||
"""
|
||||
Initialize a test driver generator.
|
||||
|
||||
Args:
|
||||
src_dir (Path):
|
||||
Path to the source directory that contains the built-in driver.
|
||||
If this path is relative, it should be relative to the repository
|
||||
root so that the source paths returned by `write_list_vars_for_cmake`
|
||||
are correct.
|
||||
|
||||
The source directory is expected to contain:
|
||||
- an `include` directory
|
||||
- an `src` directory
|
||||
|
||||
dst_dir (Path):
|
||||
Path to the destination directory where the rewritten tree will
|
||||
be created. If the directory already exists, only the `include`
|
||||
and `src` subdirectories are modified.
|
||||
|
||||
driver (str):
|
||||
Name of the driver. This is used as a prefix when rewritting
|
||||
the tree.
|
||||
|
||||
exclude_files (Optional[Iterable[str]]):
|
||||
Glob patterns for the basename of the files to be excluded from
|
||||
the source directory.
|
||||
"""
|
||||
self.src_dir = src_dir
|
||||
self.dst_dir = dst_dir
|
||||
self.driver = driver
|
||||
self.exclude_files = [] if exclude_files is None else list(exclude_files)
|
||||
|
||||
if not (src_dir / "include").is_dir():
|
||||
raise RuntimeError(f'"include" directory in {src_dir} not found')
|
||||
|
||||
if not (src_dir / "src").is_dir():
|
||||
raise RuntimeError(f'"src" directory in {src_dir} not found')
|
||||
|
||||
def write_list_vars_for_cmake(self, fname: str) -> None:
|
||||
src_relpaths = self.__get_src_code_files()
|
||||
with open(self.dst_dir / fname, "w") as f:
|
||||
f.write(f"set({self.driver}_input_files\n " + \
|
||||
"\n ".join(f'"{path}"' for path in src_relpaths) + "\n)\n\n")
|
||||
f.write(f"set({self.driver}_files\n " + \
|
||||
"\n ".join(f'"{self.__get_dst_relpath(path.relative_to(self.src_dir))}"' \
|
||||
for path in src_relpaths) + "\n)\n\n")
|
||||
f.write(f"set({self.driver}_src_files\n " + \
|
||||
"\n ".join(f'"{self.__get_dst_relpath(path.relative_to(self.src_dir))}"' \
|
||||
for path in src_relpaths if path.suffix == ".c") + "\n)\n")
|
||||
|
||||
def get_identifiers_to_prefix(self, prefixes: Set[str]) -> Set[str]:
|
||||
"""
|
||||
Get the set of identifiers that will be prefixed in the test driver code.
|
||||
|
||||
This method is intended to be amended by subclasses in consuming branches.
|
||||
|
||||
The default implementation returns the complete set of identifiers from
|
||||
the built-in driver whose names begin with any of the `prefixes`. These
|
||||
are the identifiers that could be renamed in the test driver before
|
||||
adaptation.
|
||||
|
||||
Subclasses need to filter, transform, or otherwise adjust the set of
|
||||
identifiers that should be renamed when generating the test driver.
|
||||
|
||||
Args:
|
||||
prefixes (Set[str]):
|
||||
The set of identifier prefixes used by the built-in driver
|
||||
for the symbols it exposes to the other parts of the crypto
|
||||
library. All identifiers beginning with any of these
|
||||
prefixes are candidates for renaming in the test driver to
|
||||
avoid symbol clashes.
|
||||
|
||||
Returns:
|
||||
Set[str]: The default set of identifiers to rename.
|
||||
"""
|
||||
identifiers = set()
|
||||
for file in self.__get_src_code_files():
|
||||
identifiers.update(self.get_c_identifiers(file))
|
||||
|
||||
identifiers_with_prefixes = set()
|
||||
for identifier in identifiers:
|
||||
if any(identifier.startswith(prefix) for prefix in prefixes):
|
||||
identifiers_with_prefixes.add(identifier)
|
||||
return identifiers_with_prefixes
|
||||
|
||||
def create_test_driver_tree(self, prefixes: Set[str]) -> None:
|
||||
"""
|
||||
Create a test driver tree from `self.src_dir` into `self.dst_dir`.
|
||||
|
||||
Only the `include/` and `src/` subdirectories of the source tree are
|
||||
used, and their internal directory structure is preserved.
|
||||
|
||||
Only "*.h" and "*.c" files are copied. Files whose basenames match any
|
||||
of the glob patterns in `self.exclude_files` are excluded.
|
||||
|
||||
The basename of all files is prefixed with `{self.driver}-`. The
|
||||
header inclusions referencing the renamed headers are rewritten
|
||||
accordingly.
|
||||
|
||||
Symbol identifiers exposed by the built-in driver are renamed by
|
||||
prefixing them with `{self.driver}_` to avoid collisions when linking the
|
||||
built-in driver and the test driver together in the crypto library.
|
||||
|
||||
Args:
|
||||
prefixes (Set[str]):
|
||||
The set of identifier prefixes used by the built-in driver
|
||||
for the symbols it exposes to the other parts of the crypto
|
||||
library. All identifiers beginning with any of these
|
||||
prefixes are candidates for renaming in the test driver to
|
||||
avoid symbol clashes.
|
||||
"""
|
||||
if (self.dst_dir / "include").exists():
|
||||
shutil.rmtree(self.dst_dir / "include")
|
||||
|
||||
if (self.dst_dir / "src").exists():
|
||||
shutil.rmtree(self.dst_dir / "src")
|
||||
|
||||
headers = {
|
||||
f.name \
|
||||
for f in self.__get_src_code_files() if f.suffix == ".h"
|
||||
}
|
||||
identifiers_to_prefix = self.get_identifiers_to_prefix(prefixes)
|
||||
|
||||
# Create the test driver tree
|
||||
for file in self.__get_src_code_files():
|
||||
dst = self.dst_dir / \
|
||||
self.__get_dst_relpath(file.relative_to(self.src_dir))
|
||||
dst.parent.mkdir(parents=True, exist_ok=True)
|
||||
self.__write_test_driver_file(file, dst, headers,\
|
||||
identifiers_to_prefix)
|
||||
|
||||
@staticmethod
|
||||
def __get_code_files(root: Path) -> List[Path]:
|
||||
"""
|
||||
Return all "*.c" and "*.h" files found recursively under the
|
||||
`include` and `src` subdirectories of `root`.
|
||||
"""
|
||||
return sorted(path
|
||||
for directory in ('include', 'src')
|
||||
for path in (root / directory).rglob('*.[hc]'))
|
||||
|
||||
def __get_src_code_files(self) -> List[Path]:
|
||||
"""
|
||||
Return all "*.c" and "*.h" files found recursively under the
|
||||
`include` and `src` subdirectories of the source directory `self.src_dir`
|
||||
excluding the files whose basename match any of the patterns in
|
||||
`self.exclude_files`.
|
||||
"""
|
||||
out = []
|
||||
for file in self.__get_code_files(self.src_dir):
|
||||
if not any(fnmatch(file.name, pattern) for pattern in self.exclude_files):
|
||||
out.append(file)
|
||||
return out
|
||||
|
||||
def __get_dst_relpath(self, src_relpath: Path) -> Path:
|
||||
"""
|
||||
Return the path relative to `dst_dir` of the file that corresponds to the
|
||||
file with relative path `src_relpath` in the source tree.
|
||||
|
||||
Same as `src_relpath` but the basename prefixed with `self.driver`
|
||||
"""
|
||||
assert not src_relpath.is_absolute(), "src_relpath must be relative"
|
||||
|
||||
return src_relpath.parent / (self.driver + '-' + src_relpath.name)
|
||||
|
||||
@staticmethod
|
||||
def get_c_identifiers(file: Path) -> Set[str]:
|
||||
"""
|
||||
Extract the C identifiers present in `file` using `ctags -x`
|
||||
|
||||
The following C symbol kinds are included (with their `--c-kinds`
|
||||
flags in parentheses):
|
||||
|
||||
- macro definitions (d)
|
||||
- enum values (e)
|
||||
- functions (f)
|
||||
- enum tags (g)
|
||||
- function prototypes (p)
|
||||
- struct tags (s)
|
||||
- typedefs (t)
|
||||
- union tags (u)
|
||||
- global variables (v)
|
||||
|
||||
Compatibility
|
||||
-------------
|
||||
The command used here has been validated with the following `ctags`
|
||||
implementations:
|
||||
- Exuberant Ctags 5.8
|
||||
- Exuberant Ctags 5.9~svn20110310 (default on Ubuntu 16.04–24.04)
|
||||
- Universal Ctags 5.9.0 (Ubuntu 24.04)
|
||||
- Universal Ctags 6.2.0 (Ubuntu 26.04)
|
||||
|
||||
All of these versions support the options `-x`, `--language-force=C`,
|
||||
and ``--c-kinds=defgpstuv`` sufficiently for the use case here.
|
||||
|
||||
Returns:
|
||||
Set[str]: The set of identifiers found in `file`.
|
||||
"""
|
||||
output = subprocess.check_output(
|
||||
["ctags", "-x", "--language-force=C", "--c-kinds=defgpstuv", str(file)],
|
||||
stderr=subprocess.STDOUT,
|
||||
universal_newlines=True,
|
||||
)
|
||||
identifiers = set()
|
||||
for line in output.splitlines():
|
||||
identifiers.add(line.split()[0])
|
||||
|
||||
return identifiers
|
||||
|
||||
def __write_test_driver_file(self, src: Path, dst: Path,
|
||||
headers: Set[str],
|
||||
identifiers_to_prefix: Set[str]) -> None:
|
||||
"""
|
||||
Write a test driver file to `dst` based on the contents of `src` with
|
||||
two transformations: rewriting of `#include` directives and identifier
|
||||
renaming.
|
||||
|
||||
1. Rewrite header inclusions
|
||||
Any `#include` directive whose header basename matches an entry of
|
||||
`headers` is rewritten so that the basename is prefixed with
|
||||
`{self.driver}-`. Directory components (if any) are preserved.
|
||||
|
||||
Example:
|
||||
#include "mbedtls/private/aes.h"
|
||||
becomes
|
||||
#include "mbedtls/private/libtestdriver1-aes.h"
|
||||
|
||||
LIMITATION:
|
||||
The current implementation does not correctly handle the case
|
||||
where a built-in header and a non–built-in header share the same
|
||||
basename. In principle, only inclusions of built-in headers
|
||||
should be rewritten, while inclusions of non–built-in headers
|
||||
should be left unchanged. However, the current logic only matches
|
||||
on the basename, so both are rewritten.
|
||||
|
||||
For example, if both `include/psa/foo.h` (non–built-in) and
|
||||
`drivers/builtin/include/mbedtls/foo.h` (built-in) exist, then
|
||||
in the test driver:
|
||||
|
||||
- `#include <psa/foo.h>` should not be rewritten
|
||||
- `#include <mbedtls/foo.h>` should be rewritten to
|
||||
`#include <mbedtls/libtestdriver1-foo.h>`
|
||||
|
||||
With the current basename-only matching, both inclusions are
|
||||
rewritten, which is incorrect. No practical implications
|
||||
currently, such same header basename case does not occur in the
|
||||
code base.
|
||||
|
||||
2. Rename selected identifiers
|
||||
Each identifier in `identifiers_to_prefix` is prefixed with
|
||||
`self.driver`. Case is preserved: if the identifier is all-uppercase,
|
||||
then the uppercase form of `driver` is used, the lowercase form
|
||||
otherwise.
|
||||
|
||||
Examples:
|
||||
`MBEDTLS_AES_C` becomes `LIBTESTDRIVER1_MBEDTLS_AES_C`
|
||||
`mbedtls_sha256_init` becomes `libtestdriver1_mbedtls_sha256_init`
|
||||
|
||||
Args:
|
||||
src (Path):
|
||||
The source file to read.
|
||||
|
||||
dst (Path):
|
||||
The destination file where the rewritten version is written.
|
||||
|
||||
headers (Set[str]):
|
||||
Basenames of headers whose includes should be rewritten.
|
||||
|
||||
identifiers_to_prefix (Set[str]):
|
||||
Identifiers that must be renamed by prefixing with `self.driver`
|
||||
(using uppercase or lowercase depending on the identifier's casing).
|
||||
"""
|
||||
text = src.read_text(encoding="utf-8")
|
||||
|
||||
include_line_re = re.compile(
|
||||
fr'^(\s*#\s*include\s*[<"])([^>"]+)([>"])',
|
||||
re.MULTILINE
|
||||
)
|
||||
def repl_header_inclusion(m: Match) -> str:
|
||||
parts = m.group(2).split("/")
|
||||
if parts[-1] in headers:
|
||||
path = "/".join(parts[:-1] + [self.driver + "-" + parts[-1]])
|
||||
return f'{m.group(1)}{path}{m.group(3)}'
|
||||
return m.group(0)
|
||||
intermediate_text = include_line_re.sub(repl_header_inclusion, text)
|
||||
|
||||
c_identifier_re = re.compile(r"\b[A-Za-z_][A-Za-z0-9_]*\b")
|
||||
prefix_uppercased = self.driver.upper()
|
||||
prefix_lowercased = self.driver.lower()
|
||||
|
||||
def repl(m: Match) -> str:
|
||||
identifier = m.group(0)
|
||||
if identifier in identifiers_to_prefix:
|
||||
if identifier[0].isupper():
|
||||
return f"{prefix_uppercased}_{identifier}"
|
||||
else:
|
||||
return f"{prefix_lowercased}_{identifier}"
|
||||
return identifier
|
||||
|
||||
new_text = c_identifier_re.sub(repl, intermediate_text)
|
||||
dst.write_text(new_text, encoding="utf-8")
|
||||
228
vendor/mbedtls/framework/scripts/mbedtls_framework/tls_handshake_tests.py
vendored
Normal file
228
vendor/mbedtls/framework/scripts/mbedtls_framework/tls_handshake_tests.py
vendored
Normal file
@@ -0,0 +1,228 @@
|
||||
"""
|
||||
Generate miscellaneous TLS test cases relating to the handshake.
|
||||
"""
|
||||
|
||||
# Copyright The Mbed TLS Contributors
|
||||
# SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
|
||||
import argparse
|
||||
import os
|
||||
import sys
|
||||
from typing import Optional
|
||||
|
||||
from mbedtls_framework import tls_test_case
|
||||
from mbedtls_framework import typing_util
|
||||
from mbedtls_framework.tls_test_case import Side, Version
|
||||
import translate_ciphers
|
||||
|
||||
|
||||
# Assume that a TLS 1.2 ClientHello used in these tests will be at most
|
||||
# this many bytes long.
|
||||
TLS12_CLIENT_HELLO_ASSUMED_MAX_LENGTH = 255
|
||||
|
||||
# Minimum handshake fragment length that Mbed TLS supports.
|
||||
TLS_HANDSHAKE_FRAGMENT_MIN_LENGTH = 4
|
||||
|
||||
def write_tls_handshake_defragmentation_test(
|
||||
#pylint: disable=too-many-arguments
|
||||
out: typing_util.Writable,
|
||||
side: Side,
|
||||
length: Optional[int],
|
||||
version: Optional[Version] = None,
|
||||
cipher: Optional[str] = None,
|
||||
etm: Optional[bool] = None, #encrypt-then-mac (only relevant for CBC)
|
||||
tls12_client_hello_defragmentation: Optional[bool] = True,
|
||||
variant: str = ''
|
||||
) -> None:
|
||||
"""Generate one TLS handshake defragmentation test.
|
||||
|
||||
:param out: file to write to.
|
||||
:param side: which side is Mbed TLS.
|
||||
:param length: fragment length, or None to not fragment.
|
||||
:param version: protocol version, if forced.
|
||||
"""
|
||||
#pylint: disable=chained-comparison,too-many-branches,too-many-statements
|
||||
|
||||
our_args = ''
|
||||
their_args = ''
|
||||
|
||||
if length is None:
|
||||
description = 'no fragmentation, for reference'
|
||||
else:
|
||||
description = 'len=' + str(length)
|
||||
if version is not None:
|
||||
description += ', TLS 1.' + str(version.value)
|
||||
description = f'Handshake defragmentation on {side.name.lower()}: {description}'
|
||||
tc = tls_test_case.TestCase(description)
|
||||
|
||||
if version is not None:
|
||||
their_args += ' ' + version.openssl_option()
|
||||
# Emit a version requirement, because we're forcing the version via
|
||||
# OpenSSL, not via Mbed TLS, and the automatic depdendencies in
|
||||
# ssl-opt.sh only handle forcing the version via Mbed TLS.
|
||||
tc.requirements.append(version.requires_command())
|
||||
if side == Side.SERVER and version == Version.TLS12 and \
|
||||
length is not None and \
|
||||
length <= TLS12_CLIENT_HELLO_ASSUMED_MAX_LENGTH and \
|
||||
not tls12_client_hello_defragmentation:
|
||||
# If Server-side ClientHello defragmentation is only supported in
|
||||
# the TLS 1.3 message parser, not in the TLS 1.2 message parser,
|
||||
# a TLS 1.2 fragmented ClientHello is handled properly only if it
|
||||
# is first reassembled by the TLS 1.3 parser before to be passed to
|
||||
# the TLS 1.2 ClientHello parser in a TLS 1.3 or TLS 1.2 version
|
||||
# negotiation scenario.
|
||||
# When TLS 1.3 support is disabled in the server (at compile-time
|
||||
# or at runtime), the TLS 1.2 ClientHello parser only sees
|
||||
# the first fragment of a fragmented ClientHello.
|
||||
tc.requirements.append('requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3')
|
||||
tc.description += ' with 1.3 support'
|
||||
|
||||
# To guarantee that the handhake messages are large enough and need to be
|
||||
# split into fragments, the tests require certificate authentication.
|
||||
# The party in control of the fragmentation operations is OpenSSL and
|
||||
# will always use server5.crt (548 Bytes).
|
||||
if length is not None and \
|
||||
length >= TLS_HANDSHAKE_FRAGMENT_MIN_LENGTH:
|
||||
tc.requirements.append('requires_certificate_authentication')
|
||||
if version == Version.TLS12 and side == Side.CLIENT:
|
||||
#The server uses an ECDSA cert, so make sure we have a compatible key exchange
|
||||
tc.requirements.append(
|
||||
'requires_config_enabled MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED')
|
||||
else:
|
||||
# This test case may run in a pure-PSK configuration. OpenSSL doesn't
|
||||
# allow this by default with TLS 1.3.
|
||||
their_args += ' -allow_no_dhe_kex'
|
||||
|
||||
if length is None:
|
||||
forbidden_patterns = [
|
||||
'waiting for more fragments',
|
||||
]
|
||||
wanted_patterns = []
|
||||
elif length < TLS_HANDSHAKE_FRAGMENT_MIN_LENGTH:
|
||||
their_args += ' -split_send_frag ' + str(length)
|
||||
tc.exit_code = 1
|
||||
forbidden_patterns = []
|
||||
wanted_patterns = [
|
||||
'handshake message too short: ' + str(length),
|
||||
'SSL - An invalid SSL record was received',
|
||||
]
|
||||
if side == Side.SERVER:
|
||||
wanted_patterns[0:0] = ['=> parse client hello']
|
||||
elif version == Version.TLS13:
|
||||
wanted_patterns[0:0] = ['=> ssl_tls13_process_server_hello']
|
||||
else:
|
||||
their_args += ' -split_send_frag ' + str(length)
|
||||
forbidden_patterns = []
|
||||
wanted_patterns = [
|
||||
'reassembled record',
|
||||
fr'initial handshake fragment: {length}, 0\.\.{length} of [0-9]\+',
|
||||
fr'subsequent handshake fragment: [0-9]\+, {length}\.\.',
|
||||
fr'Prepare: waiting for more handshake fragments {length}/',
|
||||
fr'Consume: waiting for more handshake fragments {length}/',
|
||||
]
|
||||
|
||||
if cipher is not None:
|
||||
mbedtls_cipher = translate_ciphers.translate_mbedtls(cipher)
|
||||
if side == Side.CLIENT:
|
||||
our_args += ' force_ciphersuite=' + mbedtls_cipher
|
||||
if 'NULL' in cipher:
|
||||
their_args += ' -cipher ALL@SECLEVEL=0:COMPLEMENTOFALL@SECLEVEL=0'
|
||||
else:
|
||||
# For TLS 1.2, when Mbed TLS is the server, we must force the
|
||||
# cipher suite on the client side, because passing
|
||||
# force_ciphersuite to ssl_server2 would force a TLS-1.2-only
|
||||
# server, which does not support a fragmented ClientHello.
|
||||
tc.requirements.append('requires_ciphersuite_enabled ' + mbedtls_cipher)
|
||||
their_args += ' -cipher ' + translate_ciphers.translate_ossl(cipher)
|
||||
if 'NULL' in cipher:
|
||||
their_args += '@SECLEVEL=0'
|
||||
|
||||
if etm is not None:
|
||||
if etm:
|
||||
tc.requirements.append('requires_config_enabled MBEDTLS_SSL_ENCRYPT_THEN_MAC')
|
||||
our_args += ' etm=' + str(int(etm))
|
||||
(wanted_patterns if etm else forbidden_patterns)[0:0] = [
|
||||
'using encrypt then mac',
|
||||
]
|
||||
|
||||
tc.description += variant
|
||||
|
||||
if side == Side.CLIENT:
|
||||
tc.client = '$P_CLI debug_level=4' + our_args
|
||||
tc.server = '$O_NEXT_SRV' + their_args
|
||||
tc.wanted_client_patterns = wanted_patterns
|
||||
tc.forbidden_client_patterns = forbidden_patterns
|
||||
else:
|
||||
their_args += ' -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key'
|
||||
our_args += ' auth_mode=required'
|
||||
tc.client = '$O_NEXT_CLI' + their_args
|
||||
tc.server = '$P_SRV debug_level=4' + our_args
|
||||
tc.wanted_server_patterns = wanted_patterns
|
||||
tc.forbidden_server_patterns = forbidden_patterns
|
||||
tc.write(out)
|
||||
|
||||
|
||||
CIPHERS_FOR_TLS12_HANDSHAKE_DEFRAGMENTATION = [
|
||||
(None, 'default', None),
|
||||
('TLS_ECDHE_ECDSA_WITH_NULL_SHA', 'null', None),
|
||||
('TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256', 'ChachaPoly', None),
|
||||
('TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256', 'GCM', None),
|
||||
('TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256', 'CBC, etm=n', False),
|
||||
('TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256', 'CBC, etm=y', True),
|
||||
]
|
||||
|
||||
def write_tls_handshake_defragmentation_tests(args, out: typing_util.Writable) -> None:
|
||||
"""Generate TLS handshake defragmentation tests."""
|
||||
for side in Side.CLIENT, Side.SERVER:
|
||||
write_tls_handshake_defragmentation_test(out, side, None)
|
||||
for length in [512, 513, 256, 128, 64, 36, 32, 16, 13, 5, 4, 3]:
|
||||
write_tls_handshake_defragmentation_test(out, side, length,
|
||||
Version.TLS13)
|
||||
if length == 4:
|
||||
for (cipher_suite, nickname, etm) in \
|
||||
CIPHERS_FOR_TLS12_HANDSHAKE_DEFRAGMENTATION:
|
||||
write_tls_handshake_defragmentation_test(
|
||||
out, side, length, Version.TLS12,
|
||||
cipher=cipher_suite, etm=etm,
|
||||
variant=', '+nickname,
|
||||
tls12_client_hello_defragmentation= \
|
||||
args.tls12_client_hello_defragmentation)
|
||||
else:
|
||||
write_tls_handshake_defragmentation_test(
|
||||
out, side, length, Version.TLS12,
|
||||
tls12_client_hello_defragmentation=
|
||||
args.tls12_client_hello_defragmentation)
|
||||
|
||||
|
||||
def write_handshake_tests(args, out: typing_util.Writable) -> None:
|
||||
"""Generate handshake tests."""
|
||||
out.write(f"""\
|
||||
# Miscellaneous tests related to the TLS handshake layer.
|
||||
#
|
||||
# Automatically generated by {os.path.basename(sys.argv[0])}. Do not edit!
|
||||
|
||||
# Copyright The Mbed TLS Contributors
|
||||
# SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
|
||||
""")
|
||||
write_tls_handshake_defragmentation_tests(args, out)
|
||||
out.write("""\
|
||||
# End of automatically generated file.
|
||||
""")
|
||||
|
||||
def main() -> None:
|
||||
"""Command line entry point."""
|
||||
parser = argparse.ArgumentParser()
|
||||
parser = argparse.ArgumentParser(description=__doc__)
|
||||
parser.add_argument('-o', '--output',
|
||||
default='tests/opt-testcases/handshake-generated.sh',
|
||||
help='Output file (default: tests/opt-testcases/handshake-generated.sh)')
|
||||
parser.add_argument('--no-tls12-client-hello-defragmentation-support',
|
||||
action="store_false",
|
||||
dest="tls12_client_hello_defragmentation",
|
||||
help="Whether the TLS 1.2 ClientHello defragmentation is "
|
||||
"fully supported or not (default: True)")
|
||||
args = parser.parse_args()
|
||||
|
||||
with open(args.output, 'w') as out:
|
||||
write_handshake_tests(args, out)
|
||||
101
vendor/mbedtls/framework/scripts/mbedtls_framework/tls_test_case.py
vendored
Normal file
101
vendor/mbedtls/framework/scripts/mbedtls_framework/tls_test_case.py
vendored
Normal file
@@ -0,0 +1,101 @@
|
||||
"""Library for constructing an Mbed TLS ssl-opt test case.
|
||||
"""
|
||||
|
||||
# Copyright The Mbed TLS Contributors
|
||||
# SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
|
||||
import enum
|
||||
import re
|
||||
from typing import List
|
||||
|
||||
from . import typing_util
|
||||
|
||||
|
||||
class TestCase:
|
||||
"""Data about an ssl-opt test case."""
|
||||
#pylint: disable=too-few-public-methods
|
||||
|
||||
def __init__(self, description: str) -> None:
|
||||
# List of shell snippets to call before run_test, typically
|
||||
# calls to requires_xxx functions.
|
||||
self.requirements = [] #type: List[str]
|
||||
# Test case description (first argument to run_test).
|
||||
self.description = description
|
||||
# Client command line.
|
||||
# This will be placed directly inside double quotes in the shell script.
|
||||
self.client = '$P_CLI'
|
||||
# Server command line.
|
||||
# This will be placed directly inside double quotes in the shell script.
|
||||
self.server = '$P_SRV'
|
||||
# Expected client exit code.
|
||||
self.exit_code = 0
|
||||
|
||||
# Note that all patterns matched in the logs are in BRE
|
||||
# (Basic Regular Expression) syntax, more precisely in the BRE
|
||||
# dialect that is the default for GNU grep. The main difference
|
||||
# with Python regular expressions is that the operators for
|
||||
# grouping `\(...\)`, alternation `x\|y`, option `x\?`,
|
||||
# one-or-more `x\+` and repetition ranges `x\{M,N\}` must be
|
||||
# preceded by a backslash. The characters `()|?+{}` stand for
|
||||
# themselves.
|
||||
|
||||
# BRE for text that must be present in the client log (run_test -c).
|
||||
self.wanted_client_patterns = [] #type: List[str]
|
||||
# BRE for text that must be present in the server log (run_test -s).
|
||||
self.wanted_server_patterns = [] #type: List[str]
|
||||
# BRE for text that must not be present in the client log (run_test -C).
|
||||
self.forbidden_client_patterns = [] #type: List[str]
|
||||
# BRE for text that must not be present in the server log (run_test -S).
|
||||
self.forbidden_server_patterns = [] #type: List[str]
|
||||
|
||||
@staticmethod
|
||||
def _quote(raw: str) -> str:
|
||||
"""Quote the given string for sh.
|
||||
|
||||
Use double quotes, because that's currently the norm in ssl-opt.sh.
|
||||
"""
|
||||
return '"' + re.sub(r'([$"\\`])', r'\\\1', raw) + '"'
|
||||
|
||||
def write(self, out: typing_util.Writable) -> None:
|
||||
"""Write the test case to the specified file."""
|
||||
for req in self.requirements:
|
||||
out.write(req + '\n')
|
||||
out.write(f'run_test {self._quote(self.description)} \\\n')
|
||||
out.write(f' "{self.server}" \\\n')
|
||||
out.write(f' "{self.client}" \\\n')
|
||||
out.write(f' {self.exit_code}')
|
||||
for pat in self.wanted_server_patterns:
|
||||
out.write(' \\\n -s ' + self._quote(pat))
|
||||
for pat in self.forbidden_server_patterns:
|
||||
out.write(' \\\n -S ' + self._quote(pat))
|
||||
for pat in self.wanted_client_patterns:
|
||||
out.write(' \\\n -c ' + self._quote(pat))
|
||||
for pat in self.forbidden_client_patterns:
|
||||
out.write(' \\\n -C ' + self._quote(pat))
|
||||
out.write('\n\n')
|
||||
|
||||
|
||||
class Side(enum.Enum):
|
||||
CLIENT = 0
|
||||
SERVER = 1
|
||||
|
||||
class Version(enum.Enum):
|
||||
"""TLS protocol version.
|
||||
|
||||
This class doesn't know about DTLS yet.
|
||||
"""
|
||||
|
||||
TLS12 = 2
|
||||
TLS13 = 3
|
||||
|
||||
def force_version(self) -> str:
|
||||
"""Argument to pass to ssl_client2 or ssl_server2 to force this version."""
|
||||
return f'force_version=tls1{self.value}'
|
||||
|
||||
def openssl_option(self) -> str:
|
||||
"""Option to pass to openssl s_client or openssl s_server to select this version."""
|
||||
return f'-tls1_{self.value}'
|
||||
|
||||
def requires_command(self) -> str:
|
||||
"""Command to require this protocol version in an ssl-opt.sh test case."""
|
||||
return 'requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_' + str(self.value)
|
||||
28
vendor/mbedtls/framework/scripts/mbedtls_framework/typing_util.py
vendored
Normal file
28
vendor/mbedtls/framework/scripts/mbedtls_framework/typing_util.py
vendored
Normal file
@@ -0,0 +1,28 @@
|
||||
"""Auxiliary definitions used in type annotations.
|
||||
"""
|
||||
|
||||
# Copyright The Mbed TLS Contributors
|
||||
# SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
#
|
||||
|
||||
from typing import Any
|
||||
|
||||
# The typing_extensions module is necessary for type annotations that are
|
||||
# checked with mypy. It is only used for type annotations or to define
|
||||
# things that are themselves only used for type annotations. It is not
|
||||
# available on a default Python installation. Therefore, try loading
|
||||
# what we need from it for the sake of mypy (which depends on, or comes
|
||||
# with, typing_extensions), and if not define substitutes that lack the
|
||||
# static type information but are good enough at runtime.
|
||||
try:
|
||||
from typing_extensions import Protocol #pylint: disable=import-error
|
||||
except ImportError:
|
||||
class Protocol: #type: ignore
|
||||
#pylint: disable=too-few-public-methods
|
||||
pass
|
||||
|
||||
class Writable(Protocol):
|
||||
"""Abstract class for typing hints."""
|
||||
# pylint: disable=no-self-use,too-few-public-methods,unused-argument
|
||||
def write(self, text: str) -> Any:
|
||||
...
|
||||
195
vendor/mbedtls/framework/scripts/mbedtls_framework/unittest_config_checks.py
vendored
Normal file
195
vendor/mbedtls/framework/scripts/mbedtls_framework/unittest_config_checks.py
vendored
Normal file
@@ -0,0 +1,195 @@
|
||||
"""Test the configuration checks that reject some bad compile-time configs.
|
||||
|
||||
This tests the output of ``generate_config_checks.py``.
|
||||
This can also let us verify what we enforce in the manually written
|
||||
checks in ``<PROJECT>_check_config.h`` and ``<PROJECT>_config.c``.
|
||||
"""
|
||||
|
||||
## Copyright The Mbed TLS Contributors
|
||||
## SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
|
||||
|
||||
import os
|
||||
import subprocess
|
||||
import sys
|
||||
import unittest
|
||||
from typing import List, Optional, Pattern, Union
|
||||
|
||||
|
||||
class TestConfigChecks(unittest.TestCase):
|
||||
"""Unit tests for checks performed via ``<PROJECT>_config.c``.
|
||||
|
||||
This can test the code generated by `config_checks_generator`,
|
||||
as well as manually written checks in `check_config.h`.
|
||||
"""
|
||||
|
||||
# Set this to the path to the source file containing the config checks.
|
||||
PROJECT_CONFIG_C = None #type: Optional[str]
|
||||
|
||||
# Project-specific include directories (in addition to /include)
|
||||
PROJECT_SPECIFIC_INCLUDE_DIRECTORIES = [] #type: List[str]
|
||||
|
||||
# Increase the length of strings that assertion failures are willing to
|
||||
# print. This is useful for failures where the compiler has a lot
|
||||
# to say.
|
||||
maxDiff = 9999
|
||||
|
||||
def setUp(self) -> None:
|
||||
self.cc_output = None #type: Optional[str]
|
||||
|
||||
def tearDown(self) -> None:
|
||||
"""Log the compiler output to a file, if available and desired.
|
||||
|
||||
This is intended for debugging. It only happens if the environment
|
||||
variable UNITTEST_CONFIG_CHECKS_DEBUG is non-empty.
|
||||
"""
|
||||
if os.getenv('UNITTEST_CONFIG_CHECKS_DEBUG'):
|
||||
# We set self.cc_output to the compiler output before
|
||||
# asserting, and set it to None if all the assertions pass.
|
||||
if self.cc_output is not None:
|
||||
basename = os.path.splitext(os.path.basename(sys.argv[0]))[0]
|
||||
filename = f'{basename}.{self._testMethodName}.out.txt'
|
||||
with open(filename, 'w') as out:
|
||||
out.write(self.cc_output)
|
||||
|
||||
def user_config_file_name(self, variant: str) -> str:
|
||||
"""Construct a unique temporary file name for a user config header."""
|
||||
name = os.path.splitext(os.path.basename(sys.argv[0]))[0]
|
||||
pid = str(os.getpid())
|
||||
oid = str(id(self))
|
||||
return f'tmp-user_config_{variant}-{name}-{pid}-{oid}.h'
|
||||
|
||||
def write_user_config(self, variant: str, content: Optional[str]) -> Optional[str]:
|
||||
"""Write a user configuration file with the given content.
|
||||
|
||||
If content is None, ensure the file does not exist.
|
||||
|
||||
Return None if content is none, otherwise return the file name.
|
||||
"""
|
||||
file_name = self.user_config_file_name(variant)
|
||||
if content is None:
|
||||
if os.path.exists(file_name):
|
||||
os.remove(file_name)
|
||||
return None
|
||||
if content and not content.endswith('\n'):
|
||||
content += '\n'
|
||||
with open(file_name, 'w', encoding='utf-8') as out:
|
||||
out.write(content)
|
||||
return file_name
|
||||
|
||||
def run_with_config_files(self,
|
||||
crypto_user_config_file: Optional[str],
|
||||
mbedtls_user_config_file: Optional[str],
|
||||
extra_options: List[str],
|
||||
) -> subprocess.CompletedProcess:
|
||||
"""Run cc with the given user configuration files.
|
||||
|
||||
Return the CompletedProcess object capturing the return code,
|
||||
stdout and stderr.
|
||||
"""
|
||||
cmd = [os.getenv('CC', 'cc')]
|
||||
if os.getenv('UNITTEST_CONFIG_CHECKS_DEBUG'):
|
||||
cmd += ['-dD']
|
||||
if crypto_user_config_file is not None:
|
||||
cmd.append(f'-DTF_PSA_CRYPTO_USER_CONFIG_FILE="{crypto_user_config_file}"')
|
||||
if mbedtls_user_config_file is not None:
|
||||
cmd.append(f'-DMBEDTLS_USER_CONFIG_FILE="{mbedtls_user_config_file}"')
|
||||
cmd += extra_options
|
||||
assert self.PROJECT_CONFIG_C is not None
|
||||
cmd += ['-I' + dir for dir in self.PROJECT_SPECIFIC_INCLUDE_DIRECTORIES]
|
||||
cmd += ['-Iinclude',
|
||||
'-I.',
|
||||
'-I' + os.path.dirname(self.PROJECT_CONFIG_C)]
|
||||
cmd += ['-o', os.devnull, '-c', self.PROJECT_CONFIG_C]
|
||||
return subprocess.run(cmd,
|
||||
check=False,
|
||||
encoding='utf-8',
|
||||
stdout=subprocess.PIPE,
|
||||
stderr=subprocess.PIPE)
|
||||
|
||||
def run_with_config(self,
|
||||
crypto_user_config: Optional[str],
|
||||
mbedtls_user_config: Optional[str] = None,
|
||||
extra_options: Optional[List[str]] = None,
|
||||
) -> subprocess.CompletedProcess:
|
||||
"""Run cc with the given content for user configuration files.
|
||||
|
||||
Return the CompletedProcess object capturing the return code,
|
||||
stdout and stderr.
|
||||
"""
|
||||
if extra_options is None:
|
||||
extra_options = []
|
||||
crypto_user_config_file = None
|
||||
mbedtls_user_config_file = None
|
||||
try:
|
||||
# Create temporary files without using tempfile because:
|
||||
# 1. Before Python 3.12, tempfile.NamedTemporaryFile does
|
||||
# not have good support for allowing an external program
|
||||
# to access the file on Windows.
|
||||
# 2. With a tempfile-provided context, it's awkward to not
|
||||
# create a file optionally (we only do it when xxx_user_config
|
||||
# is not None).
|
||||
crypto_user_config_file = \
|
||||
self.write_user_config('crypto', crypto_user_config)
|
||||
mbedtls_user_config_file = \
|
||||
self.write_user_config('mbedtls', mbedtls_user_config)
|
||||
cp = self.run_with_config_files(crypto_user_config_file,
|
||||
mbedtls_user_config_file,
|
||||
extra_options)
|
||||
return cp
|
||||
finally:
|
||||
if crypto_user_config_file is not None and \
|
||||
os.path.exists(crypto_user_config_file):
|
||||
os.remove(crypto_user_config_file)
|
||||
if mbedtls_user_config_file is not None and \
|
||||
os.path.exists(mbedtls_user_config_file):
|
||||
os.remove(mbedtls_user_config_file)
|
||||
|
||||
def good_case(self,
|
||||
crypto_user_config: Optional[str],
|
||||
mbedtls_user_config: Optional[str] = None,
|
||||
extra_options: Optional[List[str]] = None,
|
||||
) -> None:
|
||||
"""Run cc with the given user config(s). Expect no error.
|
||||
|
||||
Pass extra_options on the command line of cc.
|
||||
"""
|
||||
cp = self.run_with_config(crypto_user_config, mbedtls_user_config,
|
||||
extra_options=extra_options)
|
||||
# Assert the error text before the status. That way, if it fails,
|
||||
# we see the unexpected error messages in the test log.
|
||||
self.cc_output = cp.stdout
|
||||
self.assertEqual(cp.stderr, '')
|
||||
self.assertEqual(cp.returncode, 0)
|
||||
self.cc_output = None
|
||||
|
||||
def bad_case(self,
|
||||
crypto_user_config: Optional[str],
|
||||
mbedtls_user_config: Optional[str] = None,
|
||||
error: Optional[Union[str, Pattern]] = None,
|
||||
extra_options: Optional[List[str]] = None,
|
||||
) -> None:
|
||||
"""Run cc with the given user config(s). Expect errors.
|
||||
|
||||
Pass extra_options on the command line of cc.
|
||||
|
||||
If error is given, the standard error from cc must match this regex.
|
||||
"""
|
||||
cp = self.run_with_config(crypto_user_config, mbedtls_user_config,
|
||||
extra_options=extra_options)
|
||||
self.cc_output = cp.stdout
|
||||
if error is not None:
|
||||
# Assert the error text before the status. That way, if it fails,
|
||||
# we see the unexpected error messages in the test log.
|
||||
self.assertRegex(cp.stderr, error)
|
||||
self.assertGreater(cp.returncode, 0)
|
||||
self.assertLess(cp.returncode, 126)
|
||||
self.cc_output = None
|
||||
|
||||
# Nominal case, run first
|
||||
def test_01_nominal(self) -> None:
|
||||
self.good_case(None)
|
||||
|
||||
# Trivial error case, run second
|
||||
def test_02_error(self) -> None:
|
||||
self.bad_case('#error "Bad crypto configuration"',
|
||||
error='"Bad crypto configuration"')
|
||||
Reference in New Issue
Block a user