Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
100 changes: 100 additions & 0 deletions .github/examples-manifest.yml
Original file line number Diff line number Diff line change
Expand Up @@ -228,6 +228,33 @@ profiles:
--enable-static --enable-shared
cflags: "-DWOLFSSL_PUBLIC_MP"

autosar:
# Kept although the autosar entries are mode: skip for now -- they name
# these profiles again as soon as the port lands. See those entries.
# autosar/README: the AUTOSAR Csm/CryIf/Crypto shim is off by default and is
# not part of --enable-all, so it needs a profile of its own.
flags: "--enable-autosar --enable-static --enable-shared"

autosar-she:
# csm-she-provision needs wolfSSL's SHE support, which --enable-autosar does
# not pull in. Unlike the redirection and autosar-cmac paths this option is
# already upstream, so this profile can exist now.
flags: "--enable-autosar --enable-she=standard --enable-static --enable-shared"

iso15118:
# iso15118/contract-install needs the X9.63 KDF for the session key the
# contract private key is wrapped under; --enable-x963kdf is upstream, so
# this profile can exist now. Everything else in the dir needs only the
# defaults.
flags: "--enable-x963kdf --enable-static --enable-shared"

autosar-cryptocb:
# csm-cryptocb needs the crypto callback machinery to register a device at
# all. Also upstream already, so this one can run now too.
flags: >-
--enable-autosar --enable-cryptocb
--enable-static --enable-shared

examples:
# ---------------------------------------------------------------- host: run
# cmake.yml, not here: add_subdirectory(wolfssl) needs a wolfSSL source tree
Expand Down Expand Up @@ -344,12 +371,73 @@ examples:
profile: opensslextra
mode: check

- id: doip
path: doip
profile: default
# asserts via doip/Makefile's check target, which runs the gateway and
# tester on loopback: once authenticated (reads the VIN) and once without
# a client certificate (refused).
mode: check

- id: iso15118
path: iso15118
profile: iso15118
# The check target generates the V2G hierarchy first, then runs the
# signature example and the SECC/EVCC pair both ways. Needs openssl(1) for
# the certificate generation, which the runners have.
#
# NOT run against a -DMAX_CHAIN_DEPTH=4 library, which is what the dir's
# README tells users to build: that is a wolfSSL build option and this
# harness shares one library per profile. Verified by hand instead.
#
# The profile adds --enable-x963kdf so contract-install actually runs
# rather than reporting SKIP.
mode: check

- id: ecc
path: ecc
profile: ecc
# asserts via ecc/Makefile's check target
mode: check

- id: autosar-cryptocb
path: autosar
profile: autosar-cryptocb
# Same dir against a crypto-callback wolfSSL, so csm-cryptocb registers a
# device and asserts the cipher, MAC and RNG work reaches it instead of
# reporting SKIP.
mode: skip
reason: &autosar_port_pending >-
Needs the AUTOSAR port changes that are not on wolfSSL's master ref yet.
csm-cryptocb sets Csm_ConfigType.devId, which released Csm.h does not
declare, so the dir does not even compile under a crypto-callback
profile; csm-errors expects CRYPTO_OPERATIONMODE_FINISH on a job that was
never started to return E_NOT_OK, where the released driver frees the
slot and returns E_OK; and csm-threads asserts the keystore copy-out and
the job-table mutex. Also still waiting on it: -DREDIRECTION_CONFIG,
which did not compile before the GetKey fix, and --enable-autosar-cmac
for the MAC cases in csm-errors and for csm-secoc. Verified by hand
against the port branch -- all nine examples pass, with csm-secoc,
csm-she-provision and csm-cryptocb exercising SecOC, SHE and the crypto
callback rather than reporting SKIP. Turn these three entries back to
`mode: check` once the port lands; see autosar/README.md.

- id: autosar-she
path: autosar
profile: autosar-she
# Same dir, built against a SHE-enabled wolfSSL so csm-she-provision runs
# its known-answer checks instead of reporting SKIP. The other examples in
# the dir run here too, which is harmless duplication.
mode: skip
reason: *autosar_port_pending

- id: autosar
path: autosar
profile: autosar
# all nine examples assert via autosar/Makefile's check target
mode: skip
reason: *autosar_port_pending

- id: hash
path: hash
profile: crypto
Expand Down Expand Up @@ -1678,6 +1766,18 @@ examples:
default, BOARD ?= native) via fetch:, then `make pkg-prepare` in fetch: so
RIOT downloads its packages before the run enters the netns.

- id: autosar-user-settings
path: autosar/user_settings
mode: skip
reason: >-
Compiles the wolfSSL sources directly with -DWOLFSSL_USER_SETTINGS rather
than linking an installed libwolfssl, so it needs a wolfSSL SOURCE tree
and a profile install is no use to it. setup-wolfssl does clone one to
/tmp/wolfssl, but only on a cache miss, so pointing WOLFSSL_ROOT there
would pass or fail depending on the cache -- do not "fix" this that way.
Verified by hand against a local checkout; the dir's own `make check`
asserts the round trips. See autosar/user_settings/README.md.

- id: lwip
path: lwip
mode: skip
Expand Down
25 changes: 25 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -462,3 +462,28 @@ pk/hpke/hpke_context
pk/mikey-sakke/mikey-sakke
pk/srp/srp_sha256
pq/slh_dsa/slh_dsa_test
# autosar
autosar/csm-basic
autosar/csm-cryptocb
autosar/csm-errors
autosar/csm-jobs
autosar/csm-key-redirection
autosar/csm-secoc
autosar/csm-she-provision
autosar/csm-stream
autosar/csm-threads
autosar/user_settings/ecu-app
autosar/user_settings/*.o

# doip
doip/doip-gateway
doip/doip-tester
doip/*.log

# iso15118 -- certs/ is generated by generate_v2g_certs.sh
iso15118/secc-server
iso15118/evcc-client
iso15118/v2g-signature
iso15118/contract-install
iso15118/certs/
iso15118/*.log
40 changes: 40 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,22 @@ details.

<br />

#### autosar (AUTOSAR Classic CSM)

This directory contains examples using the wolfSSL AUTOSAR Classic Platform
port, which plugs wolfCrypt in under the standard Csm / CryIf / Crypto driver
chain. Covers AES-CBC, DRBG and AES-CMAC through the `Csm_*` API, keystore slot
selection, job lifecycle, error handling, concurrent use from several SW-Cs,
streaming a payload larger than a CAN frame, Secure Onboard Communication
(SecOC) over classic CAN, SHE key provisioning, backing the Crypto driver with
an HSM through a crypto callback, and a `user_settings.h` build of the kind an
ECU uses.

Please see the [autosar/README.md](autosar/README.md) for further usage and
details.

<br />

#### BTLE

This directory contains examples for securing a Bluetooth Low Energy Link (BTLE).
Expand Down Expand Up @@ -130,6 +146,17 @@ make
Please see the [dtls/README.md](dtls/README.md) for further usage and details.


<br />

#### doip (Diagnostics over IP)

This directory contains an ISO 13400-2 DoIP entity and tester carried over
TLS 1.3, doing routing activation and a UDS request over loopback. Shows the
two gates that protect a diagnostic session: client authentication in the
handshake, and the routing activation response code.

Please see the [doip/README.md](doip/README.md) for further usage and details.

<br />

#### ecc (Elliptic Curve Cryptography)
Expand Down Expand Up @@ -169,6 +196,19 @@ wolfCrypt.
Please see the [hash/README.md](hash/README.md) for further usage and details.


<br />

#### iso15118 (Plug & Charge, ISO 15118-20)

This directory contains the TLS layer of ISO 15118-20: a charging station
(SECC) and a vehicle (EVCC) authenticating each other over TLS 1.3 with a
realistic four-tier V2G certificate hierarchy, the contract certificate
installation step that wraps the vehicle's charging key to its OEM provisioning
key, and the ECDSA operation an ISO 15118 XML signature wraps.

Please see the [iso15118/README.md](iso15118/README.md) for further usage and
details.

<br />

#### java (wolfJSSE Examples)
Expand Down
79 changes: 79 additions & 0 deletions autosar/Makefile
Original file line number Diff line number Diff line change
@@ -0,0 +1,79 @@
# AUTOSAR CSM Examples Makefile
#
# Requires wolfSSL built and installed with --enable-autosar.
#
# make build every example
# make check build and run every example
# make REDIRECT=1 build against a libwolfssl that was itself configured
# with the key redirection macros (see README.md --
# the macros go into the library, not the application)
# make WOLFSSL_INSTALL_DIR=/opt/wolfssl
#
# The user_settings/ subdirectory is a separate build that compiles the wolfSSL
# sources directly instead of linking an installed library; see its README.
#
# The MAC cases in csm-errors compile in automatically when libwolfssl was built
# with --enable-autosar-cmac; nothing extra is needed here. csm-secoc needs that
# option outright and reports SKIP without it, and csm-she-provision likewise
# needs --enable-she=standard. csm-cryptocb needs --enable-cryptocb.
#
CC = gcc
WOLFSSL_INSTALL_DIR = /usr/local
CFLAGS = -Wall -I$(WOLFSSL_INSTALL_DIR)/include
LIBS = -L$(WOLFSSL_INSTALL_DIR)/lib -lwolfssl

# option variables
STATIC_LIB = $(WOLFSSL_INSTALL_DIR)/lib/libwolfssl.a
DEBUG_FLAGS = -g -DDEBUG
OPTIMIZE = -Os

CFLAGS+=$(OPTIMIZE)

# Key input redirection is a compile-time property of the wolfSSL library.
# These must match the macros libwolfssl was configured with, or the example
# will report that the wrong keystore slot was used.
ifdef REDIRECT
CFLAGS += -DREDIRECTION_CONFIG=0x03 \
-DREDIRECTION_IN1_KEYID=1 -DREDIRECTION_IN1_KEYELMID=0x01 \
-DREDIRECTION_IN2_KEYID=4 -DREDIRECTION_IN2_KEYELMID=0x05
endif

TARGETS = csm-basic csm-key-redirection csm-jobs csm-errors csm-secoc \
csm-threads csm-stream csm-she-provision csm-cryptocb

.PHONY: all debug clean check

all: $(TARGETS)

debug: CFLAGS+=$(DEBUG_FLAGS)
debug: all

# only csm-threads needs it; harmless elsewhere but kept target-specific
csm-threads: EXTRA_LIBS = -lpthread

%: %.c
$(CC) -o $@ $< $(CFLAGS) $(LIBS) $(EXTRA_LIBS)

clean:
rm -f $(TARGETS) *.o

check: $(TARGETS)
out=$$(./csm-basic) && \
printf '%s' "$$out" | grep -qE 'csm-basic: (PASS|SKIP)'
out=$$(./csm-key-redirection) && \
printf '%s' "$$out" | grep -qE 'csm-key-redirection: (PASS|SKIP)'
out=$$(./csm-jobs) && \
printf '%s' "$$out" | grep -qE 'csm-jobs: (PASS|SKIP)'
out=$$(./csm-errors) && \
printf '%s' "$$out" | grep -qE 'csm-errors: (PASS|SKIP)'
out=$$(./csm-secoc) && \
printf '%s' "$$out" | grep -qE 'csm-secoc: (PASS|SKIP)'
out=$$(./csm-threads) && \
printf '%s' "$$out" | grep -qE 'csm-threads: (PASS|SKIP)'
out=$$(./csm-stream) && \
printf '%s' "$$out" | grep -qE 'csm-stream: (PASS|SKIP)'
out=$$(./csm-she-provision) && \
printf '%s' "$$out" | grep -qE 'csm-she-provision: (PASS|SKIP)'
out=$$(./csm-cryptocb) && \
printf '%s' "$$out" | grep -qE 'csm-cryptocb: (PASS|SKIP)'
@echo "PASS: autosar checks"
Loading
Loading