Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .github/workflows/build-test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,9 @@ name: Build and Test

on:
push:
branches: [ main, master, develop ]
branches: [ 'master', 'main', 'release/**' ]
pull_request:
branches: [ main, master, develop ]
branches: [ '*' ]

jobs:
build:
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,9 @@ name: CodeQL Security

on:
push:
branches: [ main, master, develop ]
branches: [ 'master', 'main', 'release/**' ]
pull_request:
branches: [ main, master, develop ]
branches: [ '*' ]
schedule:
- cron: '0 6 * * 1'

Expand Down
46 changes: 46 additions & 0 deletions .github/workflows/codespell.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,46 @@
# Codespell test

name: Codespell test

# START OF COMMON SECTION
on:
push:
branches: [ 'master', 'main', 'release/**' ]
pull_request:
branches: [ '*' ]

concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
# END OF COMMON SECTION

jobs:
codespell:
name: Check for spelling errors
runs-on: ubuntu-22.04
timeout-minutes: 5
steps:
- name: Checkout wolfSPDM
uses: actions/checkout@v4

- name: Create exclude file if needed
run: |
if [ ! -f .codespellexcludelines ]; then
touch .codespellexcludelines
fi

- name: Run codespell
uses: codespell-project/actions-codespell@v2.1
with:
check_filenames: true
check_hidden: true
ignore_words_list: adin,aNULL,cLen,dout,haveA,inOut,inout,parm,parms,ser,siz,te,Te
exclude_file: '.codespellexcludelines'
skip: '*.der,*.pem,.git,*.txt'

- name: Print errors
if: ${{ failure() }}
run: |
if [ -f test-suite.log ] ; then
cat test-suite.log
fi
14 changes: 6 additions & 8 deletions .github/workflows/compiler-warnings.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,9 @@ name: Compiler Warnings

on:
push:
branches: [ main, master, develop ]
branches: [ 'master', 'main', 'release/**' ]
pull_request:
branches: [ main, master, develop ]
branches: [ '*' ]

jobs:
gcc-strict:
Expand Down Expand Up @@ -42,9 +42,8 @@ jobs:
- name: Build with strict warnings
run: |
./autogen.sh
./configure --with-wolfssl=$HOME/wolfssl-install --enable-nuvoton \
CFLAGS="-Wall -Wextra -Wpedantic -Werror -Wconversion -Wshadow"
make -j$(nproc)
./configure --with-wolfssl=$HOME/wolfssl-install --enable-nuvoton
make -j$(nproc) CFLAGS="-Wall -Wextra -Wpedantic -Werror -Wconversion -Wshadow"

clang:
name: Clang Build
Expand Down Expand Up @@ -81,9 +80,8 @@ jobs:
- name: Build with clang
run: |
./autogen.sh
CC=clang ./configure --with-wolfssl=$HOME/wolfssl-install --enable-nuvoton \
CFLAGS="-Wall -Wextra -Werror"
make -j$(nproc)
CC=clang ./configure --with-wolfssl=$HOME/wolfssl-install --enable-nuvoton
make -j$(nproc) CFLAGS="-Wall -Wextra -Werror"

- name: Run unit tests
run: make check
Expand Down
5 changes: 3 additions & 2 deletions .github/workflows/memory-check.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,9 @@ name: Memory Check

on:
push:
branches: [ main, master, develop ]
branches: [ 'master', 'main', 'release/**' ]
pull_request:
branches: [ main, master, develop ]
branches: [ '*' ]

jobs:
valgrind:
Expand Down Expand Up @@ -44,6 +44,7 @@ jobs:
./autogen.sh
./configure --with-wolfssl=$HOME/wolfssl-install --enable-debug
make -j$(nproc)
make -j$(nproc) check TESTS=

- name: Run valgrind
run: |
Expand Down
6 changes: 4 additions & 2 deletions .github/workflows/static-analysis.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,9 @@ name: Static Analysis

on:
push:
branches: [ main, master, develop ]
branches: [ 'master', 'main', 'release/**' ]
pull_request:
branches: [ main, master, develop ]
branches: [ '*' ]

jobs:
cppcheck:
Expand Down Expand Up @@ -45,6 +45,8 @@ jobs:
cppcheck --enable=warning,style,performance,portability \
--error-exitcode=1 \
--suppress=missingIncludeSystem \
--suppress=constParameterPointer \
--suppress=knownConditionTrueFalse \
--inline-suppr \
-I wolfspdm -I src -I $HOME/wolfssl-install/include \
src/ test/
Expand Down
2 changes: 2 additions & 0 deletions src/spdm_context.c
Original file line number Diff line number Diff line change
Expand Up @@ -267,6 +267,7 @@ byte wolfSPDM_GetVersion_Negotiated(WOLFSPDM_CTX* ctx)
return ctx->spdmVersion;
}

#ifdef WOLFSPDM_NUVOTON
word32 wolfSPDM_GetConnectionHandle(WOLFSPDM_CTX* ctx)
{
if (ctx == NULL) {
Expand All @@ -282,6 +283,7 @@ word16 wolfSPDM_GetFipsIndicator(WOLFSPDM_CTX* ctx)
}
return ctx->fipsIndicator;
}
#endif

/* ==========================================================================
* Session Establishment - Connect (Full Handshake)
Expand Down
14 changes: 1 addition & 13 deletions src/spdm_kdf.c
Original file line number Diff line number Diff line change
Expand Up @@ -71,25 +71,13 @@ int wolfSPDM_HkdfExpandLabel(byte spdmVersion, const byte* secret, word32 secret
infoLen += SPDM_BIN_CONCAT_PREFIX_LEN;

XMEMCPY(info + infoLen, label, XSTRLEN(label));
infoLen += XSTRLEN(label);
infoLen += (word32)XSTRLEN(label);

if (context != NULL && contextSz > 0) {
XMEMCPY(info + infoLen, context, contextSz);
infoLen += contextSz;
}

/* Debug: print HKDF info parameter */
{
word32 i;
printf("[wolfSPDM] HKDF Label: \"%s\" outSz=%u\n", label, outSz);
printf("[wolfSPDM] HKDF info (%u bytes): ", infoLen);
for (i = 0; i < infoLen && i < 32; i++) {
printf("%02x ", info[i]);
}
if (infoLen > 32) printf("...");
printf("\n");
}

rc = wc_HKDF_Expand(WC_SHA384, secret, secretSz, info, infoLen, out, outSz);

return (rc == 0) ? WOLFSPDM_SUCCESS : WOLFSPDM_E_CRYPTO_FAIL;
Expand Down
13 changes: 7 additions & 6 deletions src/spdm_msg.c
Original file line number Diff line number Diff line change
Expand Up @@ -486,7 +486,8 @@ int wolfSPDM_ParseCapabilities(WOLFSPDM_CTX* ctx, const byte* buf, word32 bufSz)
return WOLFSPDM_E_CAPS_MISMATCH;
}

ctx->rspCaps = buf[8] | (buf[9] << 8) | (buf[10] << 16) | (buf[11] << 24);
ctx->rspCaps = (word32)buf[8] | ((word32)buf[9] << 8) |
((word32)buf[10] << 16) | ((word32)buf[11] << 24);
ctx->state = WOLFSPDM_STATE_CAPS;

wolfSPDM_DebugPrint(ctx, "Responder caps: 0x%08x\n", ctx->rspCaps);
Expand Down Expand Up @@ -545,8 +546,8 @@ int wolfSPDM_ParseCertificate(WOLFSPDM_CTX* ctx, const byte* buf, word32 bufSz,
return WOLFSPDM_E_CERT_FAIL;
}

*portionLen = buf[4] | (buf[5] << 8);
*remainderLen = buf[6] | (buf[7] << 8);
*portionLen = (word16)(buf[4] | (buf[5] << 8));
*remainderLen = (word16)(buf[6] | (buf[7] << 8));

/* Add certificate chain data (starting at offset 8) */
if (*portionLen > 0 && bufSz >= (word32)(8 + *portionLen)) {
Expand Down Expand Up @@ -590,8 +591,8 @@ int wolfSPDM_ParseKeyExchangeRsp(WOLFSPDM_CTX* ctx, const byte* buf, word32 bufS
return WOLFSPDM_E_KEY_EXCHANGE;
}

ctx->rspSessionId = buf[4] | (buf[5] << 8);
ctx->sessionId = ctx->reqSessionId | (ctx->rspSessionId << 16);
ctx->rspSessionId = (word16)(buf[4] | (buf[5] << 8));
ctx->sessionId = (word32)ctx->reqSessionId | ((word32)ctx->rspSessionId << 16);

wolfSPDM_DebugPrint(ctx, "RspSessionID: 0x%04x, SessionID: 0x%08x\n",
ctx->rspSessionId, ctx->sessionId);
Expand All @@ -601,7 +602,7 @@ int wolfSPDM_ParseKeyExchangeRsp(WOLFSPDM_CTX* ctx, const byte* buf, word32 bufS
XMEMCPY(peerPubKeyY, &buf[88], WOLFSPDM_ECC_KEY_SIZE);

/* OpaqueLen at offset 136 */
opaqueLen = buf[136] | (buf[137] << 8);
opaqueLen = (word16)(buf[136] | (buf[137] << 8));
sigOffset = 138 + opaqueLen;
keRspPartialLen = sigOffset;

Expand Down
1 change: 0 additions & 1 deletion src/spdm_nuvoton.c
Original file line number Diff line number Diff line change
Expand Up @@ -349,7 +349,6 @@ int wolfSPDM_ParseTcgSecuredMessage(
#define SPDM_VERSION_1_3 0x13
#define SPDM_VENDOR_DEFINED_REQUEST 0xFE
#define SPDM_VENDOR_DEFINED_RESPONSE 0x7E
#define SPDM_ERROR 0x7F

int wolfSPDM_BuildVendorDefined(
const char* vdCode,
Expand Down
30 changes: 16 additions & 14 deletions src/spdm_secured.c
Original file line number Diff line number Diff line change
Expand Up @@ -67,9 +67,9 @@ int wolfSPDM_EncryptInternal(WOLFSPDM_CTX* ctx,
* IV XOR: Rightmost 8 bytes (bytes 4-11) with 8-byte sequence number
*/
word16 appDataLen = (word16)plainSz;
word16 unpadded = 2 + appDataLen; /* AppDataLength + SPDM msg */
word16 padLen = (16 - (unpadded % 16)) % 16; /* Pad to 16-byte boundary */
word16 encPayloadSz = unpadded + padLen;
word16 unpadded = (word16)(2 + appDataLen); /* AppDataLength + SPDM msg */
word16 padLen = (word16)((16 - (unpadded % 16)) % 16); /* Pad to 16-byte boundary */
word16 encPayloadSz = (word16)(unpadded + padLen);

plainBufSz = encPayloadSz;
/* Length field = ciphertext + MAC (per Nuvoton spec page 25: Length=160=144+16) */
Expand Down Expand Up @@ -127,8 +127,8 @@ int wolfSPDM_EncryptInternal(WOLFSPDM_CTX* ctx,
* Header: SessionID(4 LE) + SeqNum(2 LE) + Length(2 LE) = 8 bytes
* AAD = Header
*/
word16 appDataLen = 1 + plainSz;
word16 encDataLen = 2 + appDataLen;
word16 appDataLen = (word16)(1 + plainSz);
word16 encDataLen = (word16)(2 + appDataLen);

plainBufSz = encDataLen;
recordLen = (word16)(encDataLen + WOLFSPDM_AEAD_TAG_SIZE);
Expand Down Expand Up @@ -280,12 +280,13 @@ int wolfSPDM_DecryptInternal(WOLFSPDM_CTX* ctx,
}

/* Parse header: SessionID(4) + SeqNum(8) + Length(2) */
rspSessionId = enc[0] | (enc[1] << 8) | (enc[2] << 16) | (enc[3] << 24);
rspSessionId = (word32)enc[0] | ((word32)enc[1] << 8) |
((word32)enc[2] << 16) | ((word32)enc[3] << 24);
rspSeqNum64 = (word64)enc[4] | ((word64)enc[5] << 8) |
((word64)enc[6] << 16) | ((word64)enc[7] << 24) |
((word64)enc[8] << 32) | ((word64)enc[9] << 40) |
((word64)enc[10] << 48) | ((word64)enc[11] << 56);
rspLen = enc[12] | (enc[13] << 8);
rspLen = (word16)(enc[12] | (enc[13] << 8));
rspSeqNum = (word16)(rspSeqNum64 & 0xFFFF); /* For debug output */

if (rspSessionId != ctx->sessionId) {
Expand All @@ -299,7 +300,7 @@ int wolfSPDM_DecryptInternal(WOLFSPDM_CTX* ctx,
return WOLFSPDM_E_BUFFER_SMALL;
}

cipherLen = rspLen - WOLFSPDM_AEAD_TAG_SIZE;
cipherLen = (word16)(rspLen - WOLFSPDM_AEAD_TAG_SIZE);
ciphertext = enc + hdrSz;
tag = enc + hdrSz + cipherLen;

Expand Down Expand Up @@ -335,7 +336,7 @@ int wolfSPDM_DecryptInternal(WOLFSPDM_CTX* ctx,
}

/* Parse decrypted: AppDataLen (2 LE) || SPDM message || RandomData */
appDataLen = decrypted[0] | (decrypted[1] << 8);
appDataLen = (word16)(decrypted[0] | (decrypted[1] << 8));

wolfSPDM_DebugPrint(ctx, "Decrypted appDataLen: %u\n", appDataLen);
wolfSPDM_DebugHex(ctx, "Decrypted data (first 32)", decrypted,
Expand Down Expand Up @@ -365,9 +366,10 @@ int wolfSPDM_DecryptInternal(WOLFSPDM_CTX* ctx,
}

/* Parse header */
rspSessionId = enc[0] | (enc[1] << 8) | (enc[2] << 16) | (enc[3] << 24);
rspSeqNum = enc[4] | (enc[5] << 8);
rspLen = enc[6] | (enc[7] << 8);
rspSessionId = (word32)enc[0] | ((word32)enc[1] << 8) |
((word32)enc[2] << 16) | ((word32)enc[3] << 24);
rspSeqNum = (word16)(enc[4] | (enc[5] << 8));
rspLen = (word16)(enc[6] | (enc[7] << 8));

if (rspSessionId != ctx->sessionId) {
wolfSPDM_DebugPrint(ctx, "Session ID mismatch: 0x%08x != 0x%08x\n",
Expand All @@ -379,7 +381,7 @@ int wolfSPDM_DecryptInternal(WOLFSPDM_CTX* ctx,
return WOLFSPDM_E_BUFFER_SMALL;
}

cipherLen = rspLen - WOLFSPDM_AEAD_TAG_SIZE;
cipherLen = (word16)(rspLen - WOLFSPDM_AEAD_TAG_SIZE);
ciphertext = enc + hdrSz;
tag = enc + hdrSz + cipherLen;

Expand All @@ -403,7 +405,7 @@ int wolfSPDM_DecryptInternal(WOLFSPDM_CTX* ctx,
}

/* Parse decrypted: AppDataLen (2) || MCTP (1) || SPDM msg */
appDataLen = decrypted[0] | (decrypted[1] << 8);
appDataLen = (word16)(decrypted[0] | (decrypted[1] << 8));

if (appDataLen < 1 || cipherLen < (word32)(2 + appDataLen)) {
return WOLFSPDM_E_BUFFER_SMALL;
Expand Down
Loading
Loading