Repository navigation
Conversation
|
Requires wolfSSL PR: |
There was a problem hiding this comment.
🟡 Changes recommended
The review found security, cryptographic error-handling, protocol-validation, and test-coverage defects.
8 open findings
Freshness counter wraparound reopens replayed frames · New TLS validation does not verify the gateway identity · New AUTOSAR fallback skips fail the unsupported-configuration check · New CI omits the unauthorized routing-activation test · New Diagnostic ACK validation ignores payload length and status · New Server reports PASS after application I/O failure · New Freeing an uninitialized SHA-256 context · New Tamper check ignores cryptographic errors · New
What changed in this PR
Adds comprehensive AUTOSAR CSM, DoIP, and ISO 15118-20 examples, documentation, and CI manifest integration.
Changes:
- Adds nine AUTOSAR examples plus a standalone ECU-style build.
- Adds TLS 1.3 DoIP gateway/tester and ISO 15118 SECC/EVCC workflows.
- Adds certificate generation, checks, documentation, and CI profiles.
| File | Description |
|---|---|
README.md |
Documents the new example directories. |
.gitignore |
Ignores generated binaries, logs, and certificates. |
.github/examples-manifest.yml |
Adds build profiles and CI entries. |
autosar/README.md |
Documents AUTOSAR examples and configuration. |
autosar/Makefile |
Builds and checks AUTOSAR examples. |
autosar/csm-basic.c |
Demonstrates core CSM operations. |
autosar/csm-key-redirection.c |
Demonstrates keystore redirection. |
autosar/csm-jobs.c |
Exercises streaming job lifecycle. |
autosar/csm-errors.c |
Covers CSM failure paths. |
autosar/csm-secoc.c |
Implements the SecOC demonstration. |
autosar/csm-stream.c |
Demonstrates block streaming over CAN-sized frames. |
autosar/csm-threads.c |
Exercises concurrent CSM use. |
autosar/csm-she-provision.c |
Demonstrates SHE provisioning. |
autosar/csm-cryptocb.c |
Demonstrates crypto callbacks. |
autosar/user_settings/README.md |
Documents the standalone ECU build. |
autosar/user_settings/Makefile |
Builds wolfCrypt sources directly. |
autosar/user_settings/user_settings.h |
Defines the embedded configuration. |
autosar/user_settings/ecu-seed.c |
Supplies host entropy. |
autosar/user_settings/ecu-app.c |
Validates the configured features. |
doip/README.md |
Documents the DoIP workflow. |
doip/Makefile |
Builds and checks DoIP examples. |
doip/doip.h |
Defines DoIP constants and APIs. |
doip/doip.c |
Implements generic DoIP framing. |
doip/doip-gateway.c |
Implements the TLS gateway. |
doip/doip-tester.c |
Implements the TLS tester. |
iso15118/README.md |
Documents the Plug & Charge examples. |
iso15118/Makefile |
Builds and checks ISO 15118 examples. |
iso15118/generate_v2g_certs.sh |
Generates the V2G certificate hierarchy. |
iso15118/secc-server.c |
Implements the charging-station endpoint. |
iso15118/evcc-client.c |
Implements the vehicle endpoint. |
iso15118/v2g-signature.c |
Demonstrates V2G ECDSA signing. |
iso15118/contract-install.c |
Demonstrates contract-key wrapping. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
d0223dc to
b72d0c0
Compare
There was a problem hiding this comment.
🟡 Changes recommended
Several checks can report success without validating the intended authentication, MAC, provisioning, or protocol behavior.
8 open findings
Pass full 128-bit CMAC length to verification · New Validate ciphertext against both known vectors · New Use matching counters to isolate authorization key changes · New Require fatal alert level for peer refusal detection · New Validate malformed-header NACK reason code · New Require complete 17-byte VIN response · New Reject only fatal alerts as SECC refusal · New Correct MAC length documentation from bytes to bits · New
8 resolved since last review
TLS validation does not verify the gateway identity Freshness counter wraparound reopens replayed frames Tamper check ignores cryptographic errors Freeing an uninitialized SHA-256 context Server reports PASS after application I/O failure Diagnostic ACK validation ignores payload length and status CI omits the unauthorized routing-activation test AUTOSAR fallback skips fail the unsupported-configuration check
🧠 Review effort: Balanced
b72d0c0 to
5d5fc2a
Compare
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #641
Scan targets checked: wolfssl-examples-src, wolfssl-examples-bugs
Coverage: 4 of 20 in-scope changed file(s) opened by the reviewer; not opened: autosar/csm-basic.c, autosar/csm-cryptocb.c, autosar/csm-errors.c, autosar/csm-jobs.c, autosar/csm-key-redirection.c, autosar/csm-secoc.c, autosar/user_settings/ecu-app.c, autosar/user_settings/ecu-seed.c, autosar/user_settings/user_settings.h, doip/doip-gateway.c and 6 more
Fenrir result: Approved ✅
No new issues found in the changed files.
Advisory only — this automated result does not count as a GitHub approval.
Review tier: Lite
There was a problem hiding this comment.
🟡 Changes recommended
The provisioning example exposes derived secrets, and the DoIP authorization test can pass for an incorrect refusal code.
2 open findings
8 resolved since last review
Pass full 128-bit CMAC length to verification Reject only fatal alerts as SECC refusal Require complete 17-byte VIN response Validate malformed-header NACK reason code Require fatal alert level for peer refusal detection Use matching counters to isolate authorization key changes Validate ciphertext against both known vectors Correct MAC length documentation from bytes to bits
🧠 Review effort: Balanced
d9e31ae to
6e4100f
Compare
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #641
Scan targets checked: wolfssl-examples-src, wolfssl-examples-bugs
Coverage: 1 of 1 in-scope changed file(s) opened by the reviewer
Fenrir result: Approved ✅
No new issues found in the changed files.
Advisory only — this automated result does not count as a GitHub approval.
Review tier: Lite
There was a problem hiding this comment.
🟡 Changes recommended
Protocol validation, deterministic concurrency coverage, HSM key-handling guidance, and the unconfirmed ISO KDF input must be corrected.
8 open findings
Concurrency test lacks synchronization and may not exercise races · New TLS test accepts any fatal alert instead of certificate-required · New Accepts truncated routing-activation responses as successful · New Does not require the expected certificate-required TLS alert · New Unconfirmed SharedInfo encoding risks non-interoperable ISO 15118 output · New Callback devId does not keep key material out of software storage · New Incorrectly claims devId registration keeps keys in the HSM · New DevId does not prevent private-key material from residing in RAM · New
2 resolved since last review
🧠 Review effort: Balanced
6e4100f to
e33d222
Compare
There was a problem hiding this comment.
🟡 Changes recommended
Protocol validation, refusal assertions, streaming cleanup, and concurrency coverage remain incomplete.
2 open findings
8 resolved since last review
Unconfirmed SharedInfo encoding risks non-interoperable ISO 15118 output Does not require the expected certificate-required TLS alert Accepts truncated routing-activation responses as successful TLS test accepts any fatal alert instead of certificate-required Concurrency test lacks synchronization and may not exercise races DevId does not prevent private-key material from residing in RAM Incorrectly claims devId registration keeps keys in the HSM Callback devId does not keep key material out of software storage
🧠 Review effort: Balanced
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #641
Scan targets checked: wolfssl-examples-src, wolfssl-examples-bugs
Coverage: 0 of 3 in-scope changed file(s) opened by the reviewer; not opened: doip/doip-gateway.c, iso15118/evcc-client.c, iso15118/secc-server.c
Fenrir result: Approved ✅
No new issues found in the changed files.
Advisory only — this automated result does not count as a GitHub approval.
Review tier: Lite
autosar/ -- nine examples for the AUTOSAR Classic CSM port:
csm-basic Csm_Init/GetVersionInfo/RandomGenerate/KeyElementSet
and AES-CBC, single-call and streamed
csm-key-redirection how the driver picks a keystore slot, and how
compile-time redirection pins a job to one
csm-jobs two jobs streaming interleaved, and MAX_JOBS
exhaustion and recovery
csm-errors every E_NOT_OK path, and the one failure that is not
an E_NOT_OK
csm-secoc Secure Onboard Communication over classic CAN:
truncated CMAC plus a freshness value, with a
SocketCAN front-end and the attacks each half stops
csm-stream a payload larger than a CAN frame encrypted a block
at a time, and what one lost frame does to CBC
csm-threads several SW-Cs using the CSM concurrently; doubles as
a regression test for the driver's locking
csm-she-provision SHE key update, pinned against the specification's
memory update vector, then handed to the CSM
csm-cryptocb backing the Crypto driver with hardware: which
operations reach the callback and how to accept,
decline or fail them
user_settings/ the same port built with no autotools or CMake, the
way an ECU builds it, with a verified minimal source
list and an entropy hook
doip/ -- ISO 13400-2 diagnostics over TLS 1.3. A gateway and tester doing
routing activation and a UDS ReadDataByIdentifier over loopback, showing both
gates that protect a diagnostic session: client authentication in the
handshake, and the routing activation response code. Also shows that under
TLS 1.3 a rejected tester sees wolfSSL_connect() succeed and learns of the
refusal on the first read, unlike TLS 1.2.
iso15118/ -- the TLS layer of ISO 15118-20 Plug & Charge. An SECC and EVCC
authenticating each other over TLS 1.3 against a realistic V2G hierarchy
(three branches, four tiers each, one trust anchor), the ECDSA operation an
XML signature wraps, and contract certificate installation with the key
wrapping that keeps the vehicle's charging key off the wire. No -2 variant:
its mandated suite is static ECDH.
Examples whose feature is not built report SKIP and exit 0, so make check
passes on any configuration rather than failing on what was not enabled.
CI: entries for all three directories in examples-manifest.yml. doip and
iso15118 run their check targets, iso15118 under --enable-x963kdf. The three
autosar entries are mode: skip, because the directory needs AUTOSAR port
changes that are not on wolfSSL's master ref yet: csm-cryptocb sets
Csm_ConfigType.devId, which released Csm.h does not declare, so the dir does
not compile under a crypto-callback profile; csm-errors expects FINISH on a
job that was never started to return E_NOT_OK; csm-threads asserts the
keystore copy-out and the job-table mutex. Also still pending:
-DREDIRECTION_CONFIG and --enable-autosar-cmac. All nine were verified by hand
against the port branch; the entries name their profiles again as soon as it
lands.
e33d222 to
13e6894
Compare
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #641
Scan targets checked: wolfssl-examples-src, wolfssl-examples-bugs
Coverage: 0 of 2 in-scope changed file(s) opened by the reviewer; not opened: autosar/csm-stream.c, doip/doip-tester.c
Fenrir result: Approved ✅
No new issues found in the changed files.
Advisory only — this automated result does not count as a GitHub approval.
Review tier: Lite
| if (wolfSSL_CTX_load_verify_locations(ctx, CA_FILE, NULL) | ||
| != WOLFSSL_SUCCESS) { | ||
| fprintf(stderr, "could not load %s\n", CA_FILE); | ||
| goto cleanup; | ||
| } |



autosar/ -- nine examples for the AUTOSAR Classic CSM port:
csm-basic Csm_Init/GetVersionInfo/RandomGenerate/KeyElementSet
and AES-CBC, single-call and streamed
csm-key-redirection how the driver picks a keystore slot, and how
compile-time redirection pins a job to one
csm-jobs two jobs streaming interleaved, and MAX_JOBS
exhaustion and recovery
csm-errors every E_NOT_OK path, and the one failure that is not
an E_NOT_OK
csm-secoc Secure Onboard Communication over classic CAN:
truncated CMAC plus a freshness value, with a
SocketCAN front-end and the attacks each half stops
csm-stream a payload larger than a CAN frame encrypted a block
at a time, and what one lost frame does to CBC
csm-threads several SW-Cs using the CSM concurrently; doubles as
a regression test for the driver's locking
csm-she-provision SHE key update, pinned against the specification's
memory update vector, then handed to the CSM
csm-cryptocb backing the Crypto driver with hardware: which
operations reach the callback and how to accept,
decline or fail them
user_settings/ the same port built with no autotools or CMake, the
way an ECU builds it, with a verified minimal source
list and an entropy hook
doip/ -- ISO 13400-2 diagnostics over TLS 1.3. A gateway and tester doing routing activation and a UDS ReadDataByIdentifier over loopback, showing both gates that protect a diagnostic session: client authentication in the handshake, and the routing activation response code. Also shows that under TLS 1.3 a rejected tester sees wolfSSL_connect() succeed and learns of the refusal on the first read, unlike TLS 1.2.
iso15118/ -- the TLS layer of ISO 15118-20 Plug & Charge. An SECC and EVCC authenticating each other over TLS 1.3 against a realistic V2G hierarchy (three branches, four tiers each, one trust anchor), the ECDSA operation an XML signature wraps, and contract certificate installation with the key wrapping that keeps the vehicle's charging key off the wire. No -2 variant: its mandated suite is static ECDH.
Examples whose feature is not built report SKIP and exit 0, so make check passes on any configuration rather than failing on what was not enabled.
CI: entries for all three directories in examples-manifest.yml. doip and iso15118 run their check targets, iso15118 under --enable-x963kdf. The three autosar entries are mode: skip, because the directory needs AUTOSAR port changes that are not on wolfSSL's master ref yet: csm-cryptocb sets Csm_ConfigType.devId, which released Csm.h does not declare, so the dir does not compile under a crypto-callback profile; csm-errors expects FINISH on a job that was never started to return E_NOT_OK; csm-threads asserts the keystore copy-out and the job-table mutex. Also still pending: -DREDIRECTION_CONFIG and --enable-autosar-cmac. All nine were verified by hand against the port branch; the entries name their profiles again as soon as it lands.