Skip to content

Add autosar, doip and iso15118 example directories - #641

Open
SparkiDev wants to merge 1 commit into
wolfSSL:masterfrom
SparkiDev:autosar_examples
Open

SparkiDev wants to merge 1 commit into
wolfSSL:masterfrom
SparkiDev:autosar_examples

Conversation

@SparkiDev

Copy link
Copy Markdown
Contributor

autosar/ -- nine examples for the AUTOSAR Classic CSM port:

csm-basic Csm_Init/GetVersionInfo/RandomGenerate/KeyElementSet
and AES-CBC, single-call and streamed
csm-key-redirection how the driver picks a keystore slot, and how
compile-time redirection pins a job to one
csm-jobs two jobs streaming interleaved, and MAX_JOBS
exhaustion and recovery
csm-errors every E_NOT_OK path, and the one failure that is not
an E_NOT_OK
csm-secoc Secure Onboard Communication over classic CAN:
truncated CMAC plus a freshness value, with a
SocketCAN front-end and the attacks each half stops
csm-stream a payload larger than a CAN frame encrypted a block
at a time, and what one lost frame does to CBC
csm-threads several SW-Cs using the CSM concurrently; doubles as
a regression test for the driver's locking
csm-she-provision SHE key update, pinned against the specification's
memory update vector, then handed to the CSM
csm-cryptocb backing the Crypto driver with hardware: which
operations reach the callback and how to accept,
decline or fail them
user_settings/ the same port built with no autotools or CMake, the
way an ECU builds it, with a verified minimal source
list and an entropy hook

doip/ -- ISO 13400-2 diagnostics over TLS 1.3. A gateway and tester doing routing activation and a UDS ReadDataByIdentifier over loopback, showing both gates that protect a diagnostic session: client authentication in the handshake, and the routing activation response code. Also shows that under TLS 1.3 a rejected tester sees wolfSSL_connect() succeed and learns of the refusal on the first read, unlike TLS 1.2.

iso15118/ -- the TLS layer of ISO 15118-20 Plug & Charge. An SECC and EVCC authenticating each other over TLS 1.3 against a realistic V2G hierarchy (three branches, four tiers each, one trust anchor), the ECDSA operation an XML signature wraps, and contract certificate installation with the key wrapping that keeps the vehicle's charging key off the wire. No -2 variant: its mandated suite is static ECDH.

Examples whose feature is not built report SKIP and exit 0, so make check passes on any configuration rather than failing on what was not enabled.

CI: entries for all three directories in examples-manifest.yml. doip and iso15118 run their check targets, iso15118 under --enable-x963kdf. The three autosar entries are mode: skip, because the directory needs AUTOSAR port changes that are not on wolfSSL's master ref yet: csm-cryptocb sets Csm_ConfigType.devId, which released Csm.h does not declare, so the dir does not compile under a crypto-callback profile; csm-errors expects FINISH on a job that was never started to return E_NOT_OK; csm-threads asserts the keystore copy-out and the job-table mutex. Also still pending: -DREDIRECTION_CONFIG and --enable-autosar-cmac. All nine were verified by hand against the port branch; the entries name their profiles again as soon as it lands.

@SparkiDev SparkiDev self-assigned this Oct 8, 2026
Copilot AI balanced review requested due to automatic review settings October 8, 2026 22:48
@SparkiDev

Copy link
Copy Markdown
Contributor Author

Requires wolfSSL PR:
wolfSSL/wolfssl#11695

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The review found security, cryptographic error-handling, protocol-validation, and test-coverage defects.

8 open findings
What changed in this PR

Adds comprehensive AUTOSAR CSM, DoIP, and ISO 15118-20 examples, documentation, and CI manifest integration.

Changes:

  • Adds nine AUTOSAR examples plus a standalone ECU-style build.
  • Adds TLS 1.3 DoIP gateway/tester and ISO 15118 SECC/EVCC workflows.
  • Adds certificate generation, checks, documentation, and CI profiles.
File Description
README.md Documents the new example directories.
.gitignore Ignores generated binaries, logs, and certificates.
.github/​examples-manifest.yml Adds build profiles and CI entries.
autosar/​README.md Documents AUTOSAR examples and configuration.
autosar/​Makefile Builds and checks AUTOSAR examples.
autosar/​csm-basic.c Demonstrates core CSM operations.
autosar/​csm-key-redirection.c Demonstrates keystore redirection.
autosar/​csm-jobs.c Exercises streaming job lifecycle.
autosar/​csm-errors.c Covers CSM failure paths.
autosar/​csm-secoc.c Implements the SecOC demonstration.
autosar/​csm-stream.c Demonstrates block streaming over CAN-sized frames.
autosar/​csm-threads.c Exercises concurrent CSM use.
autosar/​csm-she-provision.c Demonstrates SHE provisioning.
autosar/​csm-cryptocb.c Demonstrates crypto callbacks.
autosar/​user_settings/​README.md Documents the standalone ECU build.
autosar/​user_settings/​Makefile Builds wolfCrypt sources directly.
autosar/​user_settings/​user_settings.h Defines the embedded configuration.
autosar/​user_settings/​ecu-seed.c Supplies host entropy.
autosar/​user_settings/​ecu-app.c Validates the configured features.
doip/​README.md Documents the DoIP workflow.
doip/​Makefile Builds and checks DoIP examples.
doip/​doip.h Defines DoIP constants and APIs.
doip/​doip.c Implements generic DoIP framing.
doip/​doip-gateway.c Implements the TLS gateway.
doip/​doip-tester.c Implements the TLS tester.
iso15118/​README.md Documents the Plug & Charge examples.
iso15118/​Makefile Builds and checks ISO 15118 examples.
iso15118/​generate_v2g_certs.sh Generates the V2G certificate hierarchy.
iso15118/​secc-server.c Implements the charging-station endpoint.
iso15118/​evcc-client.c Implements the vehicle endpoint.
iso15118/​v2g-signature.c Demonstrates V2G ECDSA signing.
iso15118/​contract-install.c Demonstrates contract-key wrapping.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread autosar/csm-secoc.c Outdated
Comment thread doip/doip-tester.c
Comment thread autosar/README.md
Comment thread doip/Makefile Outdated
Comment thread doip/doip-tester.c
Comment thread iso15118/secc-server.c
Comment thread iso15118/v2g-signature.c Outdated
Comment thread iso15118/v2g-signature.c Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment thread autosar/user_settings/ecu-app.c Outdated
Comment thread autosar/csm-key-redirection.c Outdated
Comment thread autosar/csm-she-provision.c Outdated
Comment thread doip/doip-tester.c Outdated
Comment thread doip/doip-tester.c Outdated
Comment thread doip/doip-tester.c Outdated
Comment thread iso15118/evcc-client.c Outdated
Comment thread autosar/README.md Outdated

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #641

Scan targets checked: wolfssl-examples-src, wolfssl-examples-bugs
Coverage: 4 of 20 in-scope changed file(s) opened by the reviewer; not opened: autosar/csm-basic.c, autosar/csm-cryptocb.c, autosar/csm-errors.c, autosar/csm-jobs.c, autosar/csm-key-redirection.c, autosar/csm-secoc.c, autosar/user_settings/ecu-app.c, autosar/user_settings/ecu-seed.c, autosar/user_settings/user_settings.h, doip/doip-gateway.c and 6 more

Fenrir result: Approved ✅

No new issues found in the changed files.

Advisory only — this automated result does not count as a GitHub approval.

Review tier: Lite

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment thread iso15118/contract-install.c Outdated
Comment thread doip/Makefile Outdated
@SparkiDev
SparkiDev force-pushed the autosar_examples branch 2 times, most recently from d9e31ae to 6e4100f Compare October 9, 2026 05:28
@SparkiDev
SparkiDev requested review from wolfSSL-Fenrir-bot and a balanced review from Copilot October 9, 2026 05:31

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #641

Scan targets checked: wolfssl-examples-src, wolfssl-examples-bugs
Coverage: 1 of 1 in-scope changed file(s) opened by the reviewer

Fenrir result: Approved ✅

No new issues found in the changed files.

Advisory only — this automated result does not count as a GitHub approval.

Review tier: Lite

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment thread autosar/csm-threads.c
Comment thread doip/Makefile Outdated
Comment thread doip/doip-tester.c Outdated
Comment thread iso15118/Makefile Outdated
Comment thread iso15118/contract-install.c
Comment thread autosar/README.md
Comment thread autosar/csm-she-provision.c
Comment thread autosar/user_settings/README.md

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment thread doip/doip-tester.c Outdated
Comment thread autosar/csm-stream.c Outdated

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #641

Scan targets checked: wolfssl-examples-src, wolfssl-examples-bugs
Coverage: 0 of 3 in-scope changed file(s) opened by the reviewer; not opened: doip/doip-gateway.c, iso15118/evcc-client.c, iso15118/secc-server.c

Fenrir result: Approved ✅

No new issues found in the changed files.

Advisory only — this automated result does not count as a GitHub approval.

Review tier: Lite

autosar/ -- nine examples for the AUTOSAR Classic CSM port:

  csm-basic            Csm_Init/GetVersionInfo/RandomGenerate/KeyElementSet
                       and AES-CBC, single-call and streamed
  csm-key-redirection  how the driver picks a keystore slot, and how
                       compile-time redirection pins a job to one
  csm-jobs             two jobs streaming interleaved, and MAX_JOBS
                       exhaustion and recovery
  csm-errors           every E_NOT_OK path, and the one failure that is not
                       an E_NOT_OK
  csm-secoc            Secure Onboard Communication over classic CAN:
                       truncated CMAC plus a freshness value, with a
                       SocketCAN front-end and the attacks each half stops
  csm-stream           a payload larger than a CAN frame encrypted a block
                       at a time, and what one lost frame does to CBC
  csm-threads          several SW-Cs using the CSM concurrently; doubles as
                       a regression test for the driver's locking
  csm-she-provision    SHE key update, pinned against the specification's
                       memory update vector, then handed to the CSM
  csm-cryptocb         backing the Crypto driver with hardware: which
                       operations reach the callback and how to accept,
                       decline or fail them
  user_settings/       the same port built with no autotools or CMake, the
                       way an ECU builds it, with a verified minimal source
                       list and an entropy hook

doip/ -- ISO 13400-2 diagnostics over TLS 1.3. A gateway and tester doing
routing activation and a UDS ReadDataByIdentifier over loopback, showing both
gates that protect a diagnostic session: client authentication in the
handshake, and the routing activation response code. Also shows that under
TLS 1.3 a rejected tester sees wolfSSL_connect() succeed and learns of the
refusal on the first read, unlike TLS 1.2.

iso15118/ -- the TLS layer of ISO 15118-20 Plug & Charge. An SECC and EVCC
authenticating each other over TLS 1.3 against a realistic V2G hierarchy
(three branches, four tiers each, one trust anchor), the ECDSA operation an
XML signature wraps, and contract certificate installation with the key
wrapping that keeps the vehicle's charging key off the wire. No -2 variant:
its mandated suite is static ECDH.

Examples whose feature is not built report SKIP and exit 0, so make check
passes on any configuration rather than failing on what was not enabled.

CI: entries for all three directories in examples-manifest.yml. doip and
iso15118 run their check targets, iso15118 under --enable-x963kdf. The three
autosar entries are mode: skip, because the directory needs AUTOSAR port
changes that are not on wolfSSL's master ref yet: csm-cryptocb sets
Csm_ConfigType.devId, which released Csm.h does not declare, so the dir does
not compile under a crypto-callback profile; csm-errors expects FINISH on a
job that was never started to return E_NOT_OK; csm-threads asserts the
keystore copy-out and the job-table mutex. Also still pending:
-DREDIRECTION_CONFIG and --enable-autosar-cmac. All nine were verified by hand
against the port branch; the entries name their profiles again as soon as it
lands.

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #641

Scan targets checked: wolfssl-examples-src, wolfssl-examples-bugs
Coverage: 0 of 2 in-scope changed file(s) opened by the reviewer; not opened: autosar/csm-stream.c, doip/doip-tester.c

Fenrir result: Approved ✅

No new issues found in the changed files.

Advisory only — this automated result does not count as a GitHub approval.

Review tier: Lite

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Server verification is missing in the DoIP tester, and several key-protection and concurrency claims remain inaccurate or unverified.

1 open finding
2 resolved since last review

🧠 Review effort: Balanced

Comment thread doip/doip-tester.c
Comment on lines +303 to +307
if (wolfSSL_CTX_load_verify_locations(ctx, CA_FILE, NULL)
!= WOLFSSL_SUCCESS) {
fprintf(stderr, "could not load %s\n", CA_FILE);
goto cleanup;
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants