34763 Commits

Author SHA1 Message Date
David Horstmann
9d76b2ee09
Merge pull request #10810 from davidhorstmann-arm/2026-07-update-python-dependencies
Update Python docs dependencies
2026-09-09 17:14:40 +00:00
David Horstmann
3d98a17142 Update Python packages for docs
Signed-off-by: David Horstmann <david.horstmann@arm.com>
2026-09-09 14:48:03 +01:00
Gilles Peskine
00d8124533
Merge pull request #10949 from gilles-peskine-arm/update-submodule-20261008-dev
Update framework with check-python-files fix
2026-09-09 14:37:30 +02:00
Gilles Peskine
07779d4137 Update framework with check-python-files fix
Signed-off-by: Gilles Peskine <Gilles.Peskine@arm.com>
2026-09-09 11:26:14 +02:00
David Horstmann
e3d5ae00cc
Merge pull request #10942 from ronald-cron-arm/cve_id_issue_1618
Add CVE-2026-73096 ID in ChangeLog
2026-09-03 11:02:29 +00:00
David Horstmann
f06454cd7b
Merge pull request #10927 from HelloOO7/development
Restore __cplusplus guard absent from oid.h
2026-09-03 10:30:12 +00:00
minosgalanakis
023aca8620
Merge pull request #10860 from yiwu0b11/cmake-config
Cmake custom compile-time config support
2026-09-02 15:16:33 +00:00
Ronald Cron
5cb95431c4 Add CVE ID
Signed-off-by: Ronald Cron <ronald.cron@arm.com>
2026-09-02 09:38:55 +02:00
Gilles Peskine
a5a368690e
Merge pull request #10394 from gilles-peskine-arm/threading-1.0-alt-build-mbedtls
Remove unused test headers
2026-09-01 11:00:04 +02:00
Valerio Setti
33f79f8ab0
Merge pull request #10493 from gilles-peskine-arm/all.sh-silence-support-failures-4.0
Silence support failures in all.sh
2026-08-31 14:36:46 +00:00
Yi Wu
9992b3d08e Update tf-psa-crypto with CMake config improvements
Signed-off-by: Yi Wu <yi.wu2@arm.com>
Signed-off-by: Gilles Peskine <Gilles.Peskine@arm.com>
2026-08-27 21:08:50 +02:00
HelloOO7
7145c949f0 Add missing __cplusplus guard to oid.h
Signed-off-by: HelloOO7 <cendarehor@gmail.com>
2026-08-22 00:36:34 +02:00
Yi Wu
8a7fdf2600 improve test coverage
Signed-off-by: Yi Wu <yi.wu2@arm.com>
2026-08-21 15:17:07 +01:00
Yi Wu
ebbe61a192 CMake: restore FILEPATH from STING for base
Signed-off-by: Yi Wu <yi.wu2@arm.com>
2026-08-21 12:13:28 +01:00
Yi Wu
d18007682d CMake: combine Mbed TLS and PSA transformations
Signed-off-by: Yi Wu <yi.wu2@arm.com>
2026-08-20 17:03:11 +01:00
Yi Wu
5c906f7fa0 compatible with PSA configs and test improvements
Signed-off-by: Yi Wu <yi.wu2@arm.com>
2026-08-19 15:57:00 +01:00
Gilles Peskine
522e2e4651
Merge pull request #10925 from gilles-peskine-arm/libtestdriver1-copy-pqcp-headers
Make installable pqcp headers available to the libtestdriver1 build
2026-08-18 16:33:48 +00:00
Gilles Peskine
50c40957c3 Make installable pqcp headers available to the libtestdriver1 build
Signed-off-by: Gilles Peskine <Gilles.Peskine@arm.com>
2026-08-18 16:07:13 +02:00
Yi Wu
c734d57590 test fixes: CMake 3.10 not support cmake -S -B
Signed-off-by: Yi Wu <yi.wu2@arm.com>
2026-08-14 17:23:24 +01:00
Yi Wu
166c69a921 CMake: make generated configs relocatable
Signed-off-by: Yi Wu <yi.wu2@arm.com>
2026-08-14 16:20:27 +01:00
Yi Wu
030f872a9b tests: cmake coverage improve
Signed-off-by: Yi Wu <yi.wu2@arm.com>
2026-08-14 15:28:29 +01:00
Yi Wu
1b5aabb7ff CMake: separate base config
Signed-off-by: Yi Wu <yi.wu2@arm.com>
2026-08-14 15:08:42 +01:00
Valerio Setti
0544d27cbc
Merge pull request #10628 from yiwu0b11/strcmp_for_md_programs_example
Replace mbedtls_md_info_from_string() with strcmp()
2026-08-14 10:19:01 +00:00
Valerio Setti
a6b469a5f5
Merge pull request #10848 from valeriosetti/issue10694
tests: scripts: remove _reference test components
2026-08-13 14:53:27 +00:00
Valerio Setti
88ae2c66c8
Merge pull request #10620 from mpg/ref-for-drivers
Check test dependencies against crypto internal macros
2026-08-13 09:56:09 +00:00
Yi Wu
efe8ab6518 fix guards and keep SHA
Signed-off-by: Yi Wu <yi.wu2@arm.com>
2026-08-13 09:35:50 +01:00
Yi Wu
3cf6109ccb Replace mbedtls_md_info_from_string() with strcmp()
Signed-off-by: Yi Wu <yi.wu2@arm.com>
2026-08-13 09:35:50 +01:00
Valerio Setti
67050ecbf1 tests: remove duplicate component_test_psa_crypto_config_accel_hash
Following recent removal for '_reference' and '_use_psa' functions we
ended up having 2 very similar test components named
'component_test_psa_crypto_config_accel_hash', one using 'default'
configuration and the other one using the 'full' one.

Let's keep the 'full' configuration version and get rid of the 'default'
case.

Signed-off-by: Valerio Setti <valerio.setti@nordicsemi.no>
2026-08-11 16:59:39 +02:00
Yi Wu
346ece94cc CMake: support custom base configurations
Signed-off-by: Yi Wu <yi.wu2@arm.com>
2026-08-06 16:21:07 +01:00
Valerio Setti
8a97676cb7 tests: configuration-crypto: remove ssl-opt.sh and compat.sh testing from accel components
'ssl-opt.sh' and 'compat.sh' in accel components were mostly useful back
when the accelerated components were to be compared against the reference
ones to ensure proper test coverage. Now that the reference components
have been removed it doesn't make sense to keep 'ssl-opt.sh' and
'compat.sh' around because they take a lot of simulation time for almost
no benefit. From TLS point of view we can rely on normal 'test_suite_'
testing to be sure that the crypto mechanism works as expected.

Signed-off-by: Valerio Setti <valerio.setti@nordicsemi.no>
2026-08-06 14:36:08 +02:00
Valerio Setti
73c48eb654 tests: configuration-crypto: remove mentions to USE_PSA_CRYPTO
Nowadays USE_PSA_CRYPTO is always enabled and there is no way to disable
it. It doesn't give more information to know that we're setting that
build symbol. Remove that.

While at this remove also '_use_psa' from some test component still using
it in the name for the same reason.

Signed-off-by: Valerio Setti <valerio.setti@nordicsemi.no>
2026-08-06 14:27:54 +02:00
Valerio Setti
6eda95fec1 tests: configuration-crypto: fix comments still referencing reference components
Signed-off-by: Valerio Setti <valerio.setti@nordicsemi.no>
2026-08-06 14:01:41 +02:00
Yi Wu
bf92cc769c add component test
Signed-off-by: Yi Wu <yi.wu2@arm.com>
2026-08-06 10:45:17 +01:00
Yi Wu
160096a0a3 Cmake: add support for config options
Signed-off-by: Yi Wu <yi.wu2@arm.com>
2026-08-06 09:46:32 +01:00
Gilles Peskine
ce0384b999
Merge pull request #10814 from valeriosetti/remove-ecp-deps
Reduce dependencies on private `ecp.h` header
2026-08-04 13:43:26 +00:00
Valerio Setti
795e7e6fd4
Merge pull request #10791 from nvxbug/tls12-session-id-bounds
Reject out-of-bounds session ID length in ssl_tls12_session_load
2026-08-03 14:24:15 +00:00
Valerio Setti
92cd477ffd tests: scripts: remove _reference test components
These were useful in the 3.6 days when 'analyze_outcomes.py' was used to
check that driver acceleration was providing the same coverage as the
reference legacy modules. Since this check has recently been removed
from 'analyze_outcomes.py' all the '_reference' component can be
removed as they are just wasting CI time.

Signed-off-by: Valerio Setti <valerio.setti@nordicsemi.no>
2026-07-30 15:27:46 +02:00
Valerio Setti
c824263361 library: ssl_tls: replace wrong usage of mbedtls_pk_get_type with mbedtls_pk_get_key_type
The intent on these lines was to get 'psa_key_type_t' for which
'mbedtls_pk_get_key_type' should clearly be used, not
'mbedtls_pk_get_type'.

Signed-off-by: Valerio Setti <valerio.setti@nordicsemi.no>
2026-07-30 10:23:02 +02:00
David Horstmann
3bb3738679
Merge pull request #10820 from minosgalanakis/tools/fix-auto-generated-files
Fix generate_errors.pl
2026-07-20 09:55:59 +00:00
David Horstmann
12556bc2a2
Merge pull request #10804 from valeriosetti/improve-rsa-pubkey-import-err-code
pk: improve error code failure reporting when RSA public key parsing fails (1/2)
2026-07-15 11:09:33 +00:00
Valerio Setti
41dd79e72c library: ssl: remove usage of MBEDTLS_ECP_DP_MAX
MBEDTLS_ECP_DP_MAX is defined in 'ecp.h' which is a tf-psa-crypto private
header. Instead of relying on that value define a new function named
'mbedtls_ssl_get_supported_tls_id_count' which returns the number of
entries in 'tls_id_match_table'.
Rationale: it does not have too much sense to allocate an array for TLS
IDs which is larger than the list of supported TLS IDs in the current
build.

Signed-off-by: Valerio Setti <valerio.setti@nordicsemi.no>
2026-07-10 12:14:20 +02:00
Valerio Setti
b1c673471f tests: ssl_helpers: update TEST_AVAILABLE_ECC and TEST_UNAVAILABLE_ECC
Align to recent changes in TLS group ID related functions:
- 'mbedtls_ssl_get_ecp_group_id_from_tls_id' renamed to
  'mbedtls_ssl_is_tls_id_supported'.
- 'mbedtls_ssl_get_tls_id_from_ecp_group_id' renamed to
  'mbedtls_ssl_get_tls_id_from_ecp_group_id'.

Signed-off-by: Valerio Setti <valerio.setti@nordicsemi.no>
2026-07-10 12:14:20 +02:00
Valerio Setti
d19ebc8c18 library: ssl: remove mbedtls_ecp_group_id field from mbedtls_ecp_group_id
This field is now completely useless.

Signed-off-by: Valerio Setti <valerio.setti@nordicsemi.no>
2026-07-10 12:14:20 +02:00
Valerio Setti
f9dbbec325 library: ssl: remove mbedtls_ssl_check_curve
Its main functionality was to get a TLS ID from 'mbedtls_ecp_group_id' and
then call 'mbedtls_ssl_check_curve_tls_id'. The same can be achieved
with public PK functions and 'mbedtls_ssl_get_tls_id_from_curve_info',
then calling into 'mbedtls_ssl_check_curve_tls_id' as before.

Signed-off-by: Valerio Setti <valerio.setti@nordicsemi.no>
2026-07-10 12:14:20 +02:00
Valerio Setti
8a23cf2f14 library: replace mbedtls_ssl_get_tls_id_from_ecp_group_id
Instead of retrieving the TLS ID using 'mbedtls_ecp_group_id', which
creates a dependency on the (now tf-psa-crypto private) 'ecp.h' header,
use PSA info to get the same result. Therefore rename the function as
'mbedtls_ssl_get_tls_id_from_curve_info'.

This new function has basically the opposite behavior than
'mbedtls_ssl_get_psa_curve_info_from_tls_id'.

Signed-off-by: Valerio Setti <valerio.setti@nordicsemi.no>
2026-07-10 12:14:20 +02:00
Valerio Setti
cac52a43c9 library: replace mbedtls_ssl_get_ecp_group_id_from_tls_id
All the usages of 'mbedtls_ssl_get_ecp_group_id_from_tls_id' basically
reduce to checking if a specific TLS ID is supported or not. Therefore
the function is replaced with 'mbedtls_ssl_is_tls_id_supported'.

Signed-off-by: Valerio Setti <valerio.setti@nordicsemi.no>
2026-07-10 12:14:19 +02:00
Minos Galanakis
32ae7d92d6 Fix generate_errors.pl
Signed-off-by: Minos Galanakis <minos.galanakis@arm.com>
2026-07-09 15:20:32 +01:00
Naveed
852c6bee29 Force sentinel session ID length in serialized-load test
Signed-off-by: Naveed <naveed@bugqore.com>
2026-07-09 13:16:14 +05:30
Naveed
c099994dca Reject out-of-bounds session ID length in ssl_tls12_session_load
Signed-off-by: Naveed <naveed@bugqore.com>
2026-07-09 13:07:44 +05:30
Ronald Cron
9e9eb069d6
Merge pull request #10817 from Mbed-TLS/mbedtls-4.2.0_mergeback
Mbedtls 4.2.0 mergeback
2026-07-08 13:16:51 +00:00