Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
73 commits
Select commit Hold shift + click to select a range
1d31334
wolfcrypt: give the keywrap _ex test an Aes with the type's alignment
danielinux Aug 20, 2026
d1f2cdb
tests: drive the crafted SP vectors on the three qemu-user ARM lanes
danielinux Aug 20, 2026
e313930
wolfcrypt: dsa.c key/parameter generation cleared mp_ints a failed mp…
danielinux Aug 20, 2026
3e1c01a
tests: add a white-box MC/DC supplement for src/tls13.c
danielinux Aug 20, 2026
6cf91c7
tests: reach the tls13.c key schedule, cookie and message-ordering gu…
danielinux Aug 20, 2026
1338d08
tests: xmss white-box drives the forged-BDS and unsupported-idx_len M…
danielinux Aug 20, 2026
cce76fa
tests: lms MC/DC white-box for BDS auth-path state and the post-keyge…
danielinux Aug 20, 2026
147d096
tests/unit-mcdc: add test_tfm_fault_whitebox.c closing 7 tfm.c MC/DC …
danielinux Aug 20, 2026
aee870d
tests: white-box supplements for sp_cortexm.c on the m33mu lane
danielinux Aug 20, 2026
9462443
tests: add white-box MC/DC supplements for srp.c and wolfmath.c
danielinux Aug 20, 2026
623e9b4
tests: drive the curve25519 blinding-rz and wolfentropy startup-noise…
danielinux Aug 20, 2026
8895b38
tests: white-box for puf.c's GF(2^7) multiply zero-operand guard
danielinux Aug 20, 2026
dd4bceb
wolfcrypt: xmss exhausted-key index marker wrapped and re-enabled sig…
danielinux Aug 20, 2026
c10bb07
tests: complete the argument-guard vectors for the TLS 1.3-only publi…
danielinux Aug 20, 2026
3d79645
tests: close the last MC/DC conditions in dsa.c, eccsi.c and sakke.c …
danielinux Aug 20, 2026
3ba0d81
wolfssl: keep the PEM no-start-line reason code out of the error trac…
danielinux Aug 20, 2026
6f31721
wolfssl: include chacha20_poly1305.h whenever the ChaCha20-Poly1305 s…
danielinux Aug 20, 2026
a6a3364
tests: pin the flaky lms treehash_update ret operands with a computed…
danielinux Aug 20, 2026
985efe5
tests: pair tsp.c TspResponse_Verify cert!=NULL with a wrong-trusted-…
danielinux Aug 20, 2026
e503124
tests: close sp_int.c randomised Miller-Rabin err operand with a pinn…
danielinux Aug 20, 2026
eb37ddb
tests: record the xmss white-box exclusions and re-anchor its line re…
danielinux Aug 20, 2026
84877cf
tests: record the falcon depth-1 Babai clamp re-analysis in the white…
danielinux Aug 20, 2026
07dfd4d
tests: drive wc_MlDsaKey_CheckKey s1/s2 range rows with a mutated pri…
danielinux Aug 20, 2026
7861c74
tests: close ten pkcs7.c MC/DC conditions and make the seeded RNG hea…
danielinux Aug 20, 2026
3de2c96
tests: add test_puf_gf_whitebox.c to EXTRA_DIST
danielinux Aug 20, 2026
6aad92e
tests: asn.c MC/DC vectors for the extension, key and revocation deco…
danielinux Aug 20, 2026
05d1987
tests: close eight tls13.c legacy-version MC/DC conditions with mutat…
danielinux Aug 20, 2026
b331ba3
tests: close pkcs7.c MC/DC :12036 cond 0 and :8237 cond 0 with seeded…
danielinux Aug 20, 2026
4764818
tests: drive tls13.c certificate fragment resume with an interrupted …
danielinux Aug 20, 2026
597ef0d
tests: close thirteen asn.c MC/DC conditions across five white-boxes
danielinux Aug 20, 2026
2217ce5
tests: add tls13 ECH handshakes and two version-negotiation vectors
danielinux Aug 20, 2026
01b2961
tests: mutually authenticated tls13 handshakes for ecdsa, ed25519, ed…
danielinux Aug 20, 2026
819bfaa
tests: white-box the tls13.c pointer-presence guards
danielinux Aug 20, 2026
492ce4d
tests: drive the sizeOnly arm of BuildTls13Message's argument guard
danielinux Aug 20, 2026
41520b0
tests: close thirty-two tls13.c feature-flag MC/DC conditions with ne…
danielinux Aug 20, 2026
3558e9c
tests: drop external tooling references from MC/DC test comments
danielinux Aug 20, 2026
3d3a8fa
tests: fix tls13 test guard scope and register the new files with cmake
danielinux Aug 20, 2026
8912bfc
tests: guard the ech round's session-ticket assertion on HAVE_SESSION…
danielinux Aug 20, 2026
803951f
tests: add three tls extension test files to the tls group
danielinux Aug 20, 2026
55cc159
tests: close tls.c argument-guard, CSR/CSR2 and TLS 1.2 MAC MC/DC con…
danielinux Aug 20, 2026
f9631aa
tests: cover the tls extension per-message-type gates in TLSX_Parse
danielinux Aug 20, 2026
9fb742d
tests: add TLSX extension parser tests for tls.c
danielinux Aug 20, 2026
2265da5
tests: cover SNI, pre-shared-key, cookie and trusted-CA parsing in tls.c
danielinux Aug 20, 2026
5890c9d
tests: cover supported groups and key-share negotiation in tls.c
danielinux Aug 20, 2026
b1639e8
tests: cover OCSP stapling, extension population and msgType dispatch…
danielinux Aug 20, 2026
d62365e
tests: define tls bounds tests unconditionally and fix link visibility
danielinux Aug 20, 2026
ba92d25
tests: mark the tls bounds helpers as possibly unused
danielinux Aug 20, 2026
6ae2afd
tests: skip the oversize psk key case where the library does not reje…
danielinux Aug 20, 2026
ee4042e
tests: expect the ffdhe group when the build supports it
danielinux Aug 20, 2026
6570a7e
tests: guard the tls extension tests on the features they actually use
danielinux Aug 21, 2026
c0443c5
tests: guard the tls extension tests on server side and auth availabi…
danielinux Aug 21, 2026
c5bea47
tests: mark the tls parse server-context helper as possibly unused
danielinux Aug 21, 2026
1571108
tests: define the tls parse unused marker outside the dh guard
danielinux Aug 21, 2026
154c552
tests: guard the tls extension tests on extension and tls 1.2 availab…
danielinux Aug 21, 2026
620b8ed
tests: mark every static helper in the tls extension tests as possibl…
danielinux Aug 21, 2026
40b0fa2
tests: load an ecc server certificate when rsa is unavailable
danielinux Aug 21, 2026
e31a1eb
tests: guard two ssl dereferences that run after a failed allocation
danielinux Aug 21, 2026
f167009
tests: guard the client half of the sni parse test on NO_WOLFSSL_CLIENT
danielinux Aug 25, 2026
8ba7029
tests: mark the psk clienthello body as possibly unused
danielinux Aug 25, 2026
956d9c3
tests: initialise pointers assigned only through an expectation macro
danielinux Aug 25, 2026
0cddea3
tests: guard the tls extension tests on the allocator, ticket and ffd…
danielinux Aug 25, 2026
e560238
tests: add a white-box smoke job
danielinux Aug 25, 2026
334863b
tests: exercise the curve448 crypto callback dispatch guards
danielinux Aug 26, 2026
6cbfdcd
tests: widen the directoryName name matching cases
danielinux Aug 26, 2026
a117761
tests: send an rsassa-pss signed ca in the tls 1.3 certificate chain
danielinux Aug 26, 2026
4bf8a80
tests: drive the tls 1.3 sha-1 chain rule from the white-box
danielinux Aug 26, 2026
586d3e9
wolfcrypt: fix a comment typo in the test harness
danielinux Aug 26, 2026
83c48a0
wolfcrypt: allocate the keywrap test aes instead of placing it on the…
danielinux Aug 26, 2026
036d12f
wolfcrypt: give the keywrap caller-Aes test its own frame
danielinux Aug 27, 2026
dc5b25a
wolfcrypt: allocate the keywrap test aes with explicit alignment
danielinux Aug 27, 2026
af7b770
wolfcrypt: cap requested data alignment at the allocator guarantee on…
danielinux Aug 27, 2026
454d477
Revert "wolfcrypt: cap requested data alignment at the allocator guar…
danielinux Aug 27, 2026
87b41fa
tests: guard the allocator-override tests on the callback signature
danielinux Aug 28, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
60 changes: 60 additions & 0 deletions .github/workflows/whitebox-smoke.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,60 @@
name: White-box Smoke

# The tests/unit-mcdc/*_whitebox.c translation units each #include one library
# source and exercise its file-static functions directly - code the public API
# cannot reach. They are not part of tests/unit.test, so nothing else in CI
# builds or runs them: a change to a library source can break one and every
# other job still passes.
#
# This builds --enable-all once and runs the subset that works against that
# configuration (see tests/unit-mcdc/run-whitebox-smoke.sh). It is a smoke
# gate, not a coverage measurement - no instrumentation, no llvm tooling, and
# the cost does not depend on which files the pull request touches.
#
# Scope note: the TUs that need a narrower configuration are reported as skips
# rather than run here, so a green result means "nothing that worked before is
# broken", not "every white-box passed".

on:
push:
branches: [ master, main ]
pull_request:
types: [opened, synchronize, reopened, ready_for_review]
branches: [ master, main ]

concurrency:
group: whitebox-smoke-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

permissions:
contents: read

jobs:
whitebox-smoke:
name: White-box smoke
runs-on: ubuntu-24.04
timeout-minutes: 20
steps:
- uses: actions/checkout@v4

- name: Install build dependencies
run: |
sudo apt-get update
sudo apt-get install -y autoconf automake libtool

- name: Configure and build
# --enable-static is required: each white-box relinks against
# libwolfssl.a with the object it replaces removed.
run: |
./autogen.sh
./configure --enable-all --enable-static --disable-shared \
CPPFLAGS=-DWOLFSSL_TEST_STATIC_BUILD
make -j"$(nproc)"

- name: Run white-box smoke
# smoke-expected.txt is generated with gcc; six TUs build under clang
# and not gcc, so the compiler has to match or the run reports false
# regressions.
env:
CC: gcc
run: ./tests/unit-mcdc/run-whitebox-smoke.sh .
5 changes: 5 additions & 0 deletions CMakeLists.txt
Original file line number Diff line number Diff line change
Expand Up @@ -4551,6 +4551,9 @@ if(WOLFSSL_EXAMPLES)
tests/api/test_evp.c
tests/api/test_tls_ext.c
tests/api/test_tls.c
tests/api/test_tls_bounds.c
tests/api/test_tls_msgtype.c
tests/api/test_tls_parse.c
tests/api/test_session.c
tests/api/test_x509.c
tests/api/test_asn.c
Expand Down Expand Up @@ -4591,6 +4594,8 @@ if(WOLFSSL_EXAMPLES)
tests/api/test_evp_pkey.c
tests/api/test_certman.c
tests/api/test_tls13.c
tests/api/test_tls13_bounds.c
tests/api/test_tls13_features.c
tests/srp.c
tests/suites.c
tests/w64wrapper.c
Expand Down
10 changes: 10 additions & 0 deletions tests/api.c
Original file line number Diff line number Diff line change
Expand Up @@ -268,6 +268,9 @@
#include <tests/api/test_evp.h>
#include <tests/api/test_tls_ext.h>
#include <tests/api/test_tls.h>
#include <tests/api/test_tls_bounds.h>
#include <tests/api/test_tls_msgtype.h>
#include <tests/api/test_tls_parse.h>
#include <tests/api/test_session.h>
#include <tests/api/test_x509.h>
#include <tests/api/test_asn.h>
Expand Down Expand Up @@ -309,6 +312,8 @@
#include <tests/api/test_evp_pkey.h>
#include <tests/api/test_certman.h>
#include <tests/api/test_tls13.h>
#include <tests/api/test_tls13_bounds.h>
#include <tests/api/test_tls13_features.h>
#if !defined(NO_CERTS) && defined(WOLFSSL_ASN_TEMPLATE) && defined(HAVE_ECC)
#include <tests/api/test_x500_unique_id_certs.h>
#endif
Expand Down Expand Up @@ -40356,6 +40361,8 @@ TEST_CASE testCases[] = {
TEST_DECL(test_wolfSSL_set_options),

TEST_TLS13_DECLS,
TEST_TLS13_BOUNDS_DECLS,
TEST_TLS13_FEATURES_DECLS,

TEST_DECL(test_wolfSSL_tmp_dh),
TEST_DECL(test_wolfSSL_tmp_dh_regression),
Expand Down Expand Up @@ -40759,6 +40766,9 @@ TEST_CASE testCases[] = {
TEST_DECL(test_ocsp_responder),
TEST_DECL(test_wolfIO_DecodeUrl_crlf_reject),
TEST_TLS_DECLS,
TEST_TLS_BOUNDS_DECLS,
TEST_TLS_MSGTYPE_DECLS,
TEST_TLS_PARSE_DECLS,
TEST_SESSION_DECLS,
TEST_DECL(test_wc_DhSetNamedKey),
TEST_DECL(test_DhAgree_rejects_p_minus_1),
Expand Down
10 changes: 10 additions & 0 deletions tests/api/include.am
Original file line number Diff line number Diff line change
Expand Up @@ -81,6 +81,9 @@ tests_unit_test_SOURCES += tests/api/test_ocsp.c
tests_unit_test_SOURCES += tests/api/test_evp.c
tests_unit_test_SOURCES += tests/api/test_tls_ext.c
tests_unit_test_SOURCES += tests/api/test_tls.c
tests_unit_test_SOURCES += tests/api/test_tls_bounds.c
tests_unit_test_SOURCES += tests/api/test_tls_msgtype.c
tests_unit_test_SOURCES += tests/api/test_tls_parse.c
tests_unit_test_SOURCES += tests/api/test_session.c
# Certs
tests_unit_test_SOURCES += tests/api/test_x509.c
Expand Down Expand Up @@ -138,6 +141,8 @@ tests_unit_test_SOURCES += tests/api/test_evp_pkey.c
tests_unit_test_SOURCES += tests/api/test_certman.c
# TLS 1.3 specific
tests_unit_test_SOURCES += tests/api/test_tls13.c
tests_unit_test_SOURCES += tests/api/test_tls13_bounds.c
tests_unit_test_SOURCES += tests/api/test_tls13_features.c
endif

EXTRA_DIST += tests/api/api.h
Expand Down Expand Up @@ -216,6 +221,9 @@ EXTRA_DIST += tests/api/create_x500_unique_id_certs.py
EXTRA_DIST += tests/api/test_evp.h
EXTRA_DIST += tests/api/test_tls_ext.h
EXTRA_DIST += tests/api/test_tls.h
EXTRA_DIST += tests/api/test_tls_bounds.h
EXTRA_DIST += tests/api/test_tls_msgtype.h
EXTRA_DIST += tests/api/test_tls_parse.h
EXTRA_DIST += tests/api/test_session.h
EXTRA_DIST += tests/api/test_x509.h
EXTRA_DIST += tests/api/test_asn.h
Expand Down Expand Up @@ -256,4 +264,6 @@ EXTRA_DIST += tests/api/test_evp_cipher.h
EXTRA_DIST += tests/api/test_evp_pkey.h
EXTRA_DIST += tests/api/test_certman.h
EXTRA_DIST += tests/api/test_tls13.h
EXTRA_DIST += tests/api/test_tls13_bounds.h
EXTRA_DIST += tests/api/test_tls13_features.h

2 changes: 1 addition & 1 deletion tests/api/test_aes.c
Original file line number Diff line number Diff line change
Expand Up @@ -8520,7 +8520,7 @@ int test_wc_AesFeatureCoverage(void)
* GCM/GMAC block works on all of them, so it only excludes HAVE_SELFTEST; the
* CCM block additionally excludes old FIPS (its AAD-only case diverges there,
* see the per-block note); the key-wrap block excludes all FIPS + self-test.
* The open MC/DC campaign builds are unaffected. */
* The open MC/DC builds are unaffected. */
#if !defined(NO_AES) && defined(HAVE_AESGCM) && !defined(HAVE_SELFTEST)
/* ---- AES-GCM streaming API: multi-chunk AAD and data ---- */
/* Uses a hardcoded 256-bit key, so requires AES-256. */
Expand Down
172 changes: 171 additions & 1 deletion tests/api/test_asn.c
Original file line number Diff line number Diff line change
Expand Up @@ -901,6 +901,43 @@ static int dirNameEnc(byte* out, word32 outSz, const DirTestAttr* attrs,
return (int)idx;
}

/* Encode "Forbid" <cp> "den" as a UTF8String value, i.e. one code point in
* the middle of a name that is otherwise "Forbidden". A code point RFC 4518
* Sec. 2.2 maps to nothing drops out and leaves "Forbidden"; any other one
* stays and makes it a different name. Returns the encoded length. */
static word32 dirUtf8Probe(byte* out, word32 cp)
{
static const byte head[] = { 'F','o','r','b','i','d' };
static const byte tail[] = { 'd','e','n' };
word32 idx = (word32)sizeof(head);

XMEMCPY(out, head, sizeof(head));

if (cp < 0x80U) {
out[idx++] = (byte)cp;
}
else if (cp < 0x800U) {
out[idx++] = (byte)(0xC0U | (cp >> 6));
out[idx++] = (byte)(0x80U | (cp & 0x3FU));
}
else if (cp < 0x10000U) {
out[idx++] = (byte)(0xE0U | (cp >> 12));
out[idx++] = (byte)(0x80U | ((cp >> 6) & 0x3FU));
out[idx++] = (byte)(0x80U | (cp & 0x3FU));
}
else {
out[idx++] = (byte)(0xF0U | (cp >> 18));
out[idx++] = (byte)(0x80U | ((cp >> 12) & 0x3FU));
out[idx++] = (byte)(0x80U | ((cp >> 6) & 0x3FU));
out[idx++] = (byte)(0x80U | (cp & 0x3FU));
}

XMEMCPY(out + idx, tail, sizeof(tail));
idx += (word32)sizeof(tail);

return idx;
}

/* Encode both names and run them through the directoryName matcher. */
static int dirMatch(const DirTestAttr* nm, int nmCnt, const DirTestAttr* bs,
int bsCnt)
Expand Down Expand Up @@ -1315,6 +1352,131 @@ int test_wolfssl_local_MatchBaseName(void)
ExpectIntEQ(dirMatch(nm, 1, bForBid, 1),
WC_NO_ERR_TRACE(ASN_PARSE_E));
}

/* EN SPACE, one of the EN QUAD (U+2000) to HAIR SPACE (U+200A)
* block that Sec. 2.2 gives as a range rather than one by one. */
{
static const byte forEnSpBid[] =
{ 'F','o','r', 0xe2,0x80,0x82, 'b','i','d' };
const DirTestAttr nm[] = {
{ DIR_OID_O, ASN_UTF8STRING, forEnSpBid,
sizeof(forEnSpBid) }
};
ExpectIntEQ(dirMatch(nm, 1, bForBid, 1), 1);
}

/* The code points Sec. 2.2 maps to nothing, given there as
* ranges. Each range is probed just inside and just outside
* both of its bounds: inside, the code point drops out of the
* name and what is left is "Forbidden"; outside, it stays and
* the name is a different one. A range left unmapped would let
* a certificate carrying one of its code points inside a name
* pass an excluded subtree. */
{
static const struct {
word32 cp; /* Code point placed inside the name. */
int drops; /* 1 when Sec. 2.2 maps it to nothing. */
} probes[] = {
/* Below CHARACTER TABULATION, and the C0 controls above
* CARRIAGE RETURN. */
{ 0x00001, 1 }, { 0x00010, 1 },
/* DELETE through U+0084, and the C1 controls above NEXT
* LINE; U+0100 is past both. */
{ 0x00080, 1 }, { 0x00090, 1 }, { 0x00100, 0 },
/* The MONGOLIAN FREE VARIATION SELECTORs. */
{ 0x0180B, 1 }, { 0x01900, 0 },
/* ZERO WIDTH NON-JOINER through RIGHT-TO-LEFT MARK. */
{ 0x0200C, 1 }, { 0x02010, 0 },
/* The bidirectional formatting characters. */
{ 0x0202A, 1 }, { 0x02030, 0 },
/* WORD JOINER and the invisible operators. */
{ 0x02060, 1 }, { 0x02064, 0 },
/* INHIBIT SYMMETRIC SWAPPING through NOMINAL DIGIT
* SHAPES. */
{ 0x0206A, 1 }, { 0x02100, 0 },
/* The VARIATION SELECTORs. */
{ 0x0FE00, 1 }, { 0x0FE10, 0 },
/* The interlinear annotation characters. */
{ 0x0FFF9, 1 }, { 0x0FFFD, 0 },
/* The musical symbol combining stems. */
{ 0x1D173, 1 }, { 0x1D180, 0 },
/* The deprecated tag characters. */
{ 0xE0020, 1 }, { 0xE0080, 0 }
};
byte probe[32];
int p;

for (p = 0; p < (int)(sizeof(probes) / sizeof(probes[0]));
p++) {
DirTestAttr nm[1];

nm[0].oid = DIR_OID_O;
nm[0].tag = ASN_UTF8STRING;
nm[0].val = probe;
nm[0].valSz = dirUtf8Probe(probe, probes[p].cp);
ExpectIntEQ(dirMatch(nm, 1, bForbidden, 1),
probes[p].drops);
}
}
}

/* A UTF-16 surrogate pair in a BMPString is one code point, and is
* the same character as the one the UTF-8 spelling holds. */
{
/* U+10000 as a surrogate pair and as UTF-8. */
static const byte astralBmp[] = { 0xd8, 0x00, 0xdc, 0x00 };
static const byte astralUtf8[] = { 0xf0, 0x90, 0x80, 0x80 };
const DirTestAttr nm[] = {
{ DIR_OID_O, ASN_BMPSTRING, astralBmp, sizeof(astralBmp) }
};
const DirTestAttr bs[] = {
{ DIR_OID_O, ASN_UTF8STRING, astralUtf8, sizeof(astralUtf8) }
};
ExpectIntEQ(dirMatch(nm, 1, bs, 1), 1);
}
/* A code unit just above the surrogate block is an ordinary
* character in both of the wide string types. */
{
/* U+E000, the first Private Use character. */
static const byte puaBmp[] = { 0xe0, 0x00 };
static const byte puaUcs[] = { 0x00, 0x00, 0xe0, 0x00 };
const DirTestAttr nmBmp[] = {
{ DIR_OID_O, ASN_BMPSTRING, puaBmp, sizeof(puaBmp) }
};
const DirTestAttr nmUcs[] = {
{ DIR_OID_O, ASN_UNIVERSALSTRING, puaUcs, sizeof(puaUcs) }
};
ExpectIntEQ(dirMatch(nmBmp, 1, bForbidden, 1), 0);
ExpectIntEQ(dirMatch(nmUcs, 1, bForbidden, 1), 0);
}
/* Case folding covers the ASCII letters and leaves everything below
* them alone. */
{
static const byte forbid1[] = { 'F','o','r','b','i','d','1' };
static const byte forbid1Up[] = { 'F','O','R','B','I','D','1' };
const DirTestAttr nm[] = {
{ DIR_OID_O, ASN_UTF8STRING, forbid1Up, sizeof(forbid1Up) }
};
const DirTestAttr bs[] = {
{ DIR_OID_O, ASN_UTF8STRING, forbid1, sizeof(forbid1) }
};
ExpectIntEQ(dirMatch(nm, 1, bs, 1), 1);
}
/* A value that is not a character string type is compared octet for
* octet: the same octets under a different tag are a different
* value, and the string rules are not applied to either side. */
{
const DirTestAttr nm[] = {
{ DIR_OID_O, ASN_OCTET_STRING, forbidden, sizeof(forbidden) }
};
const DirTestAttr up[] = {
{ DIR_OID_O, ASN_OCTET_STRING, forbiddenUp,
sizeof(forbiddenUp) }
};
ExpectIntEQ(dirMatch(nm, 1, bForbidden, 1), 0);
ExpectIntEQ(dirMatch(bForbidden, 1, nm, 1), 0);
ExpectIntEQ(dirMatch(nm, 1, nm, 1), 1);
ExpectIntEQ(dirMatch(nm, 1, up, 1), 0);
}

/* Negative tests - should NOT match */
Expand Down Expand Up @@ -1470,10 +1632,16 @@ int test_wolfssl_local_MatchBaseName(void)
static const byte loneHiBmp[] = { 0xd8, 0x00, 0x00, 'F' };
/* BMPString low surrogate with no high surrogate before it. */
static const byte loneLoBmp[] = { 0xdc, 0x00, 0x00, 'F' };
/* BMPString high surrogate followed by a code unit that is not
* a low surrogate. */
static const byte hiThenPua[] = { 0xd8, 0x00, 0xe0, 0x00 };
/* UniversalString with a length that is not a multiple of 4. */
static const byte shortUcs[] = { 0x00, 0x00, 0x00 };
/* UniversalString code point past the end of Unicode. */
static const byte bigUcs[] = { 0x00, 0x11, 0x00, 0x00 };
/* UniversalString holding a surrogate code point, which is not
* a character. */
static const byte surrUcs[] = { 0x00, 0x00, 0xd8, 0x00 };
static const struct {
byte tag;
const byte* val;
Expand All @@ -1485,8 +1653,10 @@ int test_wolfssl_local_MatchBaseName(void)
{ ASN_BMPSTRING, oddBmp, sizeof(oddBmp) },
{ ASN_BMPSTRING, loneHiBmp, sizeof(loneHiBmp) },
{ ASN_BMPSTRING, loneLoBmp, sizeof(loneLoBmp) },
{ ASN_BMPSTRING, hiThenPua, sizeof(hiThenPua) },
{ ASN_UNIVERSALSTRING, shortUcs, sizeof(shortUcs) },
{ ASN_UNIVERSALSTRING, bigUcs, sizeof(bigUcs) }
{ ASN_UNIVERSALSTRING, bigUcs, sizeof(bigUcs) },
{ ASN_UNIVERSALSTRING, surrUcs, sizeof(surrUcs) }
};
int i;

Expand Down
2 changes: 1 addition & 1 deletion tests/api/test_chacha.c
Original file line number Diff line number Diff line change
Expand Up @@ -73,7 +73,7 @@ int test_wc_Chacha_SetKey(void)

/* misaligned key pointer: exercises the (wc_ptr_t)key % 4 realignment
* decision in wc_Chacha_SetKey when XSTREAM_ALIGN is forced on (the
* xstream_align campaign variant). settings.h compiles XSTREAM_ALIGN out
* xstream_align variant). settings.h compiles XSTREAM_ALIGN out
* by default on x86_64/i386/ia64 (NO_XSTREAM_ALIGN), so this call is a
* harmless no-op realignment-free copy on every other build. */
{
Expand Down
2 changes: 1 addition & 1 deletion tests/api/test_dh.c
Original file line number Diff line number Diff line change
Expand Up @@ -39,7 +39,7 @@
* DH_MAX_SIZE expands to WC_BITS_FULL_BYTES(SP_INT_BITS), and
* WC_BITS_FULL_BYTES(x) is defined as (WC_BITS_TO_BYTES(x) << 3) - i.e. it
* returns SP_INT_BITS itself (rounded up to a byte multiple), NOT
* SP_INT_BITS/8 as its name suggests. With this campaign's SP_INT_BITS 4096,
* SP_INT_BITS/8 as its name suggests. With this suite's SP_INT_BITS 4096,
* DH_MAX_SIZE is therefore 4096 (bytes!), not the 512 a caller would
* reasonably expect. Passing that value as *privSz (a requested private-key
* size, not just a buffer capacity) to wc_DhGenerateKeyPair overflows the
Expand Down
Loading
Loading