blob: c526f15ef6108943977f1ab151a77cb54bf1bcf5 [file] [log] [blame]
Darryl Green7c2dd582018-03-01 14:53:49 +00001#!/usr/bin/env python3
Gilles Peskine6100d3c2022-06-20 18:51:18 +02002"""This script compares the interfaces of two versions of Mbed TLS, looking
Gilles Peskine92165362021-04-23 16:37:12 +02003for backward incompatibilities between two different Git revisions within
4an Mbed TLS repository. It must be run from the root of a Git working tree.
5
Gilles Peskine228d99b2022-06-20 18:51:44 +02006### How the script works ###
7
Gilles Peskine92165362021-04-23 16:37:12 +02008For the source (API) and runtime (ABI) interface compatibility, this script
9is a small wrapper around the abi-compliance-checker and abi-dumper tools,
10applying them to compare the header and library files.
11
12For the storage format, this script compares the automatically generated
Gilles Peskineca586a52022-02-22 19:02:44 +010013storage tests and the manual read tests, and complains if there is a
Gilles Peskine4a9630a2022-03-04 19:59:55 +010014reduction in coverage. A change in test data will be signaled as a
Gilles Peskineca586a52022-02-22 19:02:44 +010015coverage reduction since the old test data is no longer present. A change in
Gilles Peskine4a9630a2022-03-04 19:59:55 +010016how test data is presented will be signaled as well; this would be a false
Gilles Peskineca586a52022-02-22 19:02:44 +010017positive.
Gilles Peskine92165362021-04-23 16:37:12 +020018
Gilles Peskineca586a52022-02-22 19:02:44 +010019The results of the API/ABI comparison are either formatted as HTML and stored
20at a configurable location, or are given as a brief list of problems.
21Returns 0 on success, 1 on non-compliance, and 2 if there is an error
Gilles Peskine92165362021-04-23 16:37:12 +020022while running the script.
Gilles Peskine644b3f62022-03-03 10:23:09 +010023
Gilles Peskine228d99b2022-06-20 18:51:44 +020024### How to interpret non-compliance ###
25
26This script has relatively common false positives. In many scenarios, it only
27reports a pass if there is a strict textual match between the old version and
28the new version, and it reports problems where there is a sufficient semantic
29match but not a textual match. This section lists some common false positives.
30This is not an exhaustive list: in the end what matters is whether we are
31breaking a backward compatibility goal.
32
33**API**: the goal is that if an application works with the old version of the
34library, it can be recompiled against the new version and will still work.
35This is normally validated by comparing the declarations in `include/*/*.h`.
36A failure is a declaration that has disappeared or that now has a different
37type.
38
39 * It's ok to change or remove macros and functions that are documented as
40 for internal use only or as experimental.
41 * It's ok to rename function or macro parameters as long as the semantics
42 has not changed.
43 * It's ok to change or remove structure fields that are documented as
44 private.
45 * It's ok to add fields to a structure that already had private fields
46 or was documented as extensible.
47
48**ABI**: the goal is that if an application was built against the old version
49of the library, the same binary will work when linked against the new version.
50This is normally validated by comparing the symbols exported by `libmbed*.so`.
51A failure is a symbol that is no longer exported by the same library or that
52now has a different type.
53
54 * All ABI changes are acceptable if the library version is bumped
55 (see `scripts/bump_version.sh`).
56 * ABI changes that concern functions which are declared only inside the
57 library directory, and not in `include/*/*.h`, are acceptable only if
58 the function was only ever used inside the same library (libmbedcrypto,
59 libmbedx509, libmbedtls). As a counter example, if the old version
60 of libmbedtls calls mbedtls_foo() from libmbedcrypto, and the new version
61 of libmbedcrypto no longer has a compatible mbedtls_foo(), this does
62 require a version bump for libmbedcrypto.
63
64**Storage format**: the goal is to check that persistent keys stored by the
65old version can be read by the new version. This is normally validated by
66comparing the `*read*` test cases in `test_suite*storage_format*.data`.
67A failure is a storage read test case that is no longer present with the same
68function name and parameter list.
69
70 * It's ok if the same test data is present, but its presentation has changed,
71 for example if a test function is renamed or has different parameters.
72 * It's ok if redundant tests are removed.
73
74**Generated test coverage**: the goal is to check that automatically
75generated tests have as much coverage as before. This is normally validated
76by comparing the test cases that are automatically generated by a script.
77A failure is a generated test case that is no longer present with the same
78function name and parameter list.
79
80 * It's ok if the same test data is present, but its presentation has changed,
81 for example if a test function is renamed or has different parameters.
82 * It's ok if redundant tests are removed.
83
Darryl Green78696802018-04-06 11:23:22 +010084"""
Darryl Green7c2dd582018-03-01 14:53:49 +000085
Bence Szépkúti1e148272020-08-07 13:07:28 +020086# Copyright The Mbed TLS Contributors
Dave Rodgman16799db2023-11-02 19:47:20 +000087# SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
Bence Szépkútic7da1fe2020-05-26 01:54:15 +020088
Gilles Peskineca586a52022-02-22 19:02:44 +010089import glob
Darryl Green7c2dd582018-03-01 14:53:49 +000090import os
Gilles Peskine92165362021-04-23 16:37:12 +020091import re
Darryl Green7c2dd582018-03-01 14:53:49 +000092import sys
93import traceback
94import shutil
95import subprocess
96import argparse
97import logging
98import tempfile
Darryl Green9f357d62019-02-25 11:35:05 +000099import fnmatch
Darryl Green0d1ca512019-04-09 09:14:17 +0100100from types import SimpleNamespace
Darryl Green7c2dd582018-03-01 14:53:49 +0000101
Darryl Greene62f9bb2019-02-21 13:09:26 +0000102import xml.etree.ElementTree as ET
103
David Horstmannecd6d012024-05-10 16:58:31 +0100104import framework_scripts_path # pylint: disable=unused-import
David Horstmanncd84bb22024-05-03 14:36:12 +0100105from mbedtls_framework import build_tree
Gilles Peskined9071e72022-09-18 21:17:09 +0200106
Darryl Green7c2dd582018-03-01 14:53:49 +0000107
Gilles Peskine184c0962020-03-24 18:25:17 +0100108class AbiChecker:
Gilles Peskine712afa72019-02-25 20:36:52 +0100109 """API and ABI checker."""
Darryl Green7c2dd582018-03-01 14:53:49 +0000110
Darryl Green0d1ca512019-04-09 09:14:17 +0100111 def __init__(self, old_version, new_version, configuration):
Gilles Peskine712afa72019-02-25 20:36:52 +0100112 """Instantiate the API/ABI checker.
113
Darryl Green7c1a7332019-03-05 16:25:38 +0000114 old_version: RepoVersion containing details to compare against
115 new_version: RepoVersion containing details to check
Darryl Greenf67e3492019-04-12 15:17:02 +0100116 configuration.report_dir: directory for output files
117 configuration.keep_all_reports: if false, delete old reports
118 configuration.brief: if true, output shorter report to stdout
Gilles Peskine4a9630a2022-03-04 19:59:55 +0100119 configuration.check_abi: if true, compare ABIs
Gilles Peskinec76ab852021-04-23 16:32:32 +0200120 configuration.check_api: if true, compare APIs
Gilles Peskine92165362021-04-23 16:37:12 +0200121 configuration.check_storage: if true, compare storage format tests
Darryl Greenf67e3492019-04-12 15:17:02 +0100122 configuration.skip_file: path to file containing symbols and types to skip
Gilles Peskine712afa72019-02-25 20:36:52 +0100123 """
Darryl Green7c2dd582018-03-01 14:53:49 +0000124 self.repo_path = "."
125 self.log = None
Darryl Green0d1ca512019-04-09 09:14:17 +0100126 self.verbose = configuration.verbose
Darryl Green3a5f6c82019-03-05 16:30:39 +0000127 self._setup_logger()
Darryl Green0d1ca512019-04-09 09:14:17 +0100128 self.report_dir = os.path.abspath(configuration.report_dir)
129 self.keep_all_reports = configuration.keep_all_reports
Darryl Green492bc402019-04-11 15:50:41 +0100130 self.can_remove_report_dir = not (os.path.exists(self.report_dir) or
Darryl Green0d1ca512019-04-09 09:14:17 +0100131 self.keep_all_reports)
Darryl Green7c1a7332019-03-05 16:25:38 +0000132 self.old_version = old_version
133 self.new_version = new_version
Darryl Green0d1ca512019-04-09 09:14:17 +0100134 self.skip_file = configuration.skip_file
Gilles Peskinec76ab852021-04-23 16:32:32 +0200135 self.check_abi = configuration.check_abi
136 self.check_api = configuration.check_api
137 if self.check_abi != self.check_api:
138 raise Exception('Checking API without ABI or vice versa is not supported')
Gilles Peskine92165362021-04-23 16:37:12 +0200139 self.check_storage_tests = configuration.check_storage
Darryl Green0d1ca512019-04-09 09:14:17 +0100140 self.brief = configuration.brief
Darryl Green7c2dd582018-03-01 14:53:49 +0000141 self.git_command = "git"
142 self.make_command = "make"
143
Darryl Green3a5f6c82019-03-05 16:30:39 +0000144 def _setup_logger(self):
Darryl Green7c2dd582018-03-01 14:53:49 +0000145 self.log = logging.getLogger()
Darryl Green3c3da792019-03-08 11:30:04 +0000146 if self.verbose:
147 self.log.setLevel(logging.DEBUG)
148 else:
149 self.log.setLevel(logging.INFO)
Darryl Green7c2dd582018-03-01 14:53:49 +0000150 self.log.addHandler(logging.StreamHandler())
151
Gilles Peskine712afa72019-02-25 20:36:52 +0100152 @staticmethod
153 def check_abi_tools_are_installed():
Darryl Green7c2dd582018-03-01 14:53:49 +0000154 for command in ["abi-dumper", "abi-compliance-checker"]:
155 if not shutil.which(command):
156 raise Exception("{} not installed, aborting".format(command))
157
Darryl Green3a5f6c82019-03-05 16:30:39 +0000158 def _get_clean_worktree_for_git_revision(self, version):
Darryl Green7c1a7332019-03-05 16:25:38 +0000159 """Make a separate worktree with version.revision checked out.
Gilles Peskine712afa72019-02-25 20:36:52 +0100160 Do not modify the current worktree."""
Darryl Green7c2dd582018-03-01 14:53:49 +0000161 git_worktree_path = tempfile.mkdtemp()
Darryl Green7c1a7332019-03-05 16:25:38 +0000162 if version.repository:
Darryl Green3c3da792019-03-08 11:30:04 +0000163 self.log.debug(
Darryl Greenda84e322019-02-19 16:59:33 +0000164 "Checking out git worktree for revision {} from {}".format(
Darryl Green7c1a7332019-03-05 16:25:38 +0000165 version.revision, version.repository
Darryl Greenda84e322019-02-19 16:59:33 +0000166 )
167 )
Darryl Greenb2ee0b82019-04-12 16:24:25 +0100168 fetch_output = subprocess.check_output(
Darryl Green7c1a7332019-03-05 16:25:38 +0000169 [self.git_command, "fetch",
170 version.repository, version.revision],
Darryl Greenda84e322019-02-19 16:59:33 +0000171 cwd=self.repo_path,
Darryl Greenda84e322019-02-19 16:59:33 +0000172 stderr=subprocess.STDOUT
173 )
Darryl Green3c3da792019-03-08 11:30:04 +0000174 self.log.debug(fetch_output.decode("utf-8"))
Darryl Greenda84e322019-02-19 16:59:33 +0000175 worktree_rev = "FETCH_HEAD"
176 else:
Darryl Green3c3da792019-03-08 11:30:04 +0000177 self.log.debug("Checking out git worktree for revision {}".format(
Darryl Green7c1a7332019-03-05 16:25:38 +0000178 version.revision
179 ))
180 worktree_rev = version.revision
Darryl Greenb2ee0b82019-04-12 16:24:25 +0100181 worktree_output = subprocess.check_output(
Darryl Greenda84e322019-02-19 16:59:33 +0000182 [self.git_command, "worktree", "add", "--detach",
183 git_worktree_path, worktree_rev],
Darryl Green7c2dd582018-03-01 14:53:49 +0000184 cwd=self.repo_path,
Darryl Green7c2dd582018-03-01 14:53:49 +0000185 stderr=subprocess.STDOUT
186 )
Darryl Green3c3da792019-03-08 11:30:04 +0000187 self.log.debug(worktree_output.decode("utf-8"))
Gilles Peskine3e2da4a2019-07-04 19:01:22 +0200188 version.commit = subprocess.check_output(
Darryl Green762351b2019-07-25 14:33:33 +0100189 [self.git_command, "rev-parse", "HEAD"],
Gilles Peskine3e2da4a2019-07-04 19:01:22 +0200190 cwd=git_worktree_path,
191 stderr=subprocess.STDOUT
192 ).decode("ascii").rstrip()
193 self.log.debug("Commit is {}".format(version.commit))
Darryl Green7c2dd582018-03-01 14:53:49 +0000194 return git_worktree_path
195
Darryl Green3a5f6c82019-03-05 16:30:39 +0000196 def _update_git_submodules(self, git_worktree_path, version):
Darryl Green8184df52019-04-05 17:06:17 +0100197 """If the crypto submodule is present, initialize it.
198 if version.crypto_revision exists, update it to that revision,
199 otherwise update it to the default revision"""
Bence Szépkútieffa5342025-09-25 15:51:07 +0200200 submodule_output = subprocess.check_output(
201 [self.git_command, "submodule", "foreach", "--recursive",
Bence Szépkútidc88f6e2025-09-26 15:37:42 +0200202 f'git worktree add --detach "{git_worktree_path}/$displaypath" HEAD'],
Bence Szépkútieffa5342025-09-25 15:51:07 +0200203 cwd=self.repo_path,
204 stderr=subprocess.STDOUT
205 )
206 self.log.debug(submodule_output.decode("utf-8"))
Darryl Greenb2ee0b82019-04-12 16:24:25 +0100207 update_output = subprocess.check_output(
Jaeden Ameroffeb1b82018-11-02 16:35:09 +0000208 [self.git_command, "submodule", "update", "--init", '--recursive'],
209 cwd=git_worktree_path,
Jaeden Ameroffeb1b82018-11-02 16:35:09 +0000210 stderr=subprocess.STDOUT
211 )
Darryl Greenb2ee0b82019-04-12 16:24:25 +0100212 self.log.debug(update_output.decode("utf-8"))
Darryl Greene29ce702019-03-05 15:23:25 +0000213 if not (os.path.exists(os.path.join(git_worktree_path, "crypto"))
Darryl Green7c1a7332019-03-05 16:25:38 +0000214 and version.crypto_revision):
Darryl Greene29ce702019-03-05 15:23:25 +0000215 return
216
Darryl Green7c1a7332019-03-05 16:25:38 +0000217 if version.crypto_repository:
Darryl Greenb2ee0b82019-04-12 16:24:25 +0100218 fetch_output = subprocess.check_output(
Darryl Green1d95c532019-03-08 11:12:19 +0000219 [self.git_command, "fetch", version.crypto_repository,
220 version.crypto_revision],
Darryl Greene29ce702019-03-05 15:23:25 +0000221 cwd=os.path.join(git_worktree_path, "crypto"),
Darryl Greene29ce702019-03-05 15:23:25 +0000222 stderr=subprocess.STDOUT
223 )
Darryl Green3c3da792019-03-08 11:30:04 +0000224 self.log.debug(fetch_output.decode("utf-8"))
Darryl Green1d95c532019-03-08 11:12:19 +0000225 crypto_rev = "FETCH_HEAD"
226 else:
227 crypto_rev = version.crypto_revision
228
Darryl Greenb2ee0b82019-04-12 16:24:25 +0100229 checkout_output = subprocess.check_output(
Darryl Green1d95c532019-03-08 11:12:19 +0000230 [self.git_command, "checkout", crypto_rev],
231 cwd=os.path.join(git_worktree_path, "crypto"),
Darryl Green1d95c532019-03-08 11:12:19 +0000232 stderr=subprocess.STDOUT
233 )
Darryl Green3c3da792019-03-08 11:30:04 +0000234 self.log.debug(checkout_output.decode("utf-8"))
Jaeden Ameroffeb1b82018-11-02 16:35:09 +0000235
Darryl Green3a5f6c82019-03-05 16:30:39 +0000236 def _build_shared_libraries(self, git_worktree_path, version):
Gilles Peskine712afa72019-02-25 20:36:52 +0100237 """Build the shared libraries in the specified worktree."""
Darryl Green7c2dd582018-03-01 14:53:49 +0000238 my_environment = os.environ.copy()
239 my_environment["CFLAGS"] = "-g -Og"
240 my_environment["SHARED"] = "1"
Darryl Greend2dba362019-05-09 13:03:05 +0100241 if os.path.exists(os.path.join(git_worktree_path, "crypto")):
242 my_environment["USE_CRYPTO_SUBMODULE"] = "1"
Ronald Cronbb02ec12025-08-28 14:43:59 +0200243
244 if os.path.exists(os.path.join(git_worktree_path, "scripts", "legacy.make")):
245 command = [self.make_command, "-f", "scripts/legacy.make", "lib"]
246 else:
247 command = [self.make_command, "lib"]
248
Darryl Greenb2ee0b82019-04-12 16:24:25 +0100249 make_output = subprocess.check_output(
Ronald Cronbb02ec12025-08-28 14:43:59 +0200250 command,
Darryl Green7c2dd582018-03-01 14:53:49 +0000251 env=my_environment,
252 cwd=git_worktree_path,
Darryl Green7c2dd582018-03-01 14:53:49 +0000253 stderr=subprocess.STDOUT
254 )
Darryl Green3c3da792019-03-08 11:30:04 +0000255 self.log.debug(make_output.decode("utf-8"))
Darryl Greenf025d532019-04-12 15:18:02 +0100256 for root, _dirs, files in os.walk(git_worktree_path):
Darryl Green9f357d62019-02-25 11:35:05 +0000257 for file in fnmatch.filter(files, "*.so"):
Darryl Green7c1a7332019-03-05 16:25:38 +0000258 version.modules[os.path.splitext(file)[0]] = (
Darryl Green3e7a9802019-02-27 16:53:40 +0000259 os.path.join(root, file)
Darryl Green9f357d62019-02-25 11:35:05 +0000260 )
Darryl Green7c2dd582018-03-01 14:53:49 +0000261
Gilles Peskine3e2da4a2019-07-04 19:01:22 +0200262 @staticmethod
263 def _pretty_revision(version):
264 if version.revision == version.commit:
265 return version.revision
266 else:
267 return "{} ({})".format(version.revision, version.commit)
268
Darryl Green8184df52019-04-05 17:06:17 +0100269 def _get_abi_dumps_from_shared_libraries(self, version):
Gilles Peskine712afa72019-02-25 20:36:52 +0100270 """Generate the ABI dumps for the specified git revision.
Darryl Green8184df52019-04-05 17:06:17 +0100271 The shared libraries must have been built and the module paths
272 present in version.modules."""
Darryl Green7c1a7332019-03-05 16:25:38 +0000273 for mbed_module, module_path in version.modules.items():
Darryl Green7c2dd582018-03-01 14:53:49 +0000274 output_path = os.path.join(
Darryl Greenfe9a6752019-04-04 14:39:33 +0100275 self.report_dir, "{}-{}-{}.dump".format(
276 mbed_module, version.revision, version.version
Darryl Green3e7a9802019-02-27 16:53:40 +0000277 )
Darryl Green7c2dd582018-03-01 14:53:49 +0000278 )
279 abi_dump_command = [
280 "abi-dumper",
Darryl Green9f357d62019-02-25 11:35:05 +0000281 module_path,
Darryl Green7c2dd582018-03-01 14:53:49 +0000282 "-o", output_path,
Gilles Peskine3e2da4a2019-07-04 19:01:22 +0200283 "-lver", self._pretty_revision(version),
Darryl Green7c2dd582018-03-01 14:53:49 +0000284 ]
Darryl Greenb2ee0b82019-04-12 16:24:25 +0100285 abi_dump_output = subprocess.check_output(
Darryl Green7c2dd582018-03-01 14:53:49 +0000286 abi_dump_command,
Darryl Green7c2dd582018-03-01 14:53:49 +0000287 stderr=subprocess.STDOUT
288 )
Darryl Green3c3da792019-03-08 11:30:04 +0000289 self.log.debug(abi_dump_output.decode("utf-8"))
Darryl Green7c1a7332019-03-05 16:25:38 +0000290 version.abi_dumps[mbed_module] = output_path
Darryl Green7c2dd582018-03-01 14:53:49 +0000291
Gilles Peskine92165362021-04-23 16:37:12 +0200292 @staticmethod
293 def _normalize_storage_test_case_data(line):
294 """Eliminate cosmetic or irrelevant details in storage format test cases."""
295 line = re.sub(r'\s+', r'', line)
296 return line
297
Gilles Peskineca586a52022-02-22 19:02:44 +0100298 def _read_storage_tests(self,
299 directory,
300 filename,
301 is_generated,
302 storage_tests):
Gilles Peskine92165362021-04-23 16:37:12 +0200303 """Record storage tests from the given file.
304
305 Populate the storage_tests dictionary with test cases read from
306 filename under directory.
307 """
308 at_paragraph_start = True
309 description = None
310 full_path = os.path.join(directory, filename)
Gilles Peskinedcf2ff52022-03-04 20:02:00 +0100311 with open(full_path) as fd:
312 for line_number, line in enumerate(fd, 1):
313 line = line.strip()
314 if not line:
315 at_paragraph_start = True
Gilles Peskineca586a52022-02-22 19:02:44 +0100316 continue
Gilles Peskinedcf2ff52022-03-04 20:02:00 +0100317 if line.startswith('#'):
318 continue
319 if at_paragraph_start:
320 description = line.strip()
321 at_paragraph_start = False
322 continue
323 if line.startswith('depends_on:'):
324 continue
325 # We've reached a test case data line
326 test_case_data = self._normalize_storage_test_case_data(line)
327 if not is_generated:
328 # In manual test data, only look at read tests.
329 function_name = test_case_data.split(':', 1)[0]
330 if 'read' not in function_name.split('_'):
331 continue
332 metadata = SimpleNamespace(
333 filename=filename,
334 line_number=line_number,
335 description=description
336 )
337 storage_tests[test_case_data] = metadata
Gilles Peskine92165362021-04-23 16:37:12 +0200338
Gilles Peskineca586a52022-02-22 19:02:44 +0100339 @staticmethod
340 def _list_generated_test_data_files(git_worktree_path):
341 """List the generated test data files."""
David Horstmannb8360cf2024-05-31 14:38:52 +0100342 generate_psa_tests = 'framework/scripts/generate_psa_tests.py'
343 if not os.path.isfile(git_worktree_path + '/' + generate_psa_tests):
344 # The checked-out revision is from before generate_psa_tests.py
345 # was moved to the framework submodule. Use the old location.
346 generate_psa_tests = 'tests/scripts/generate_psa_tests.py'
347
Gilles Peskineca586a52022-02-22 19:02:44 +0100348 output = subprocess.check_output(
David Horstmannb8360cf2024-05-31 14:38:52 +0100349 [generate_psa_tests, '--list'],
Gilles Peskine92165362021-04-23 16:37:12 +0200350 cwd=git_worktree_path,
351 ).decode('ascii')
Gilles Peskineca586a52022-02-22 19:02:44 +0100352 return [line for line in output.split('\n') if line]
353
354 def _get_storage_format_tests(self, version, git_worktree_path):
355 """Record the storage format tests for the specified git version.
356
357 The storage format tests are the test suite data files whose name
358 contains "storage_format".
359
360 The version must be checked out at git_worktree_path.
361
362 This function creates or updates the generated data files.
363 """
364 # Existing test data files. This may be missing some automatically
365 # generated files if they haven't been generated yet.
Ronald Cron5903be22024-07-11 19:50:54 +0200366 if os.path.isdir(os.path.join(git_worktree_path, 'tf-psa-crypto',
367 'tests', 'suites')):
368 storage_data_files = set(glob.glob(
369 'tf-psa-crypto/tests/suites/test_suite_*storage_format*.data'
370 ))
371 else:
372 storage_data_files = set(glob.glob(
373 'tests/suites/test_suite_*storage_format*.data'
374 ))
Gilles Peskineca586a52022-02-22 19:02:44 +0100375 # Discover and (re)generate automatically generated data files.
376 to_be_generated = set()
377 for filename in self._list_generated_test_data_files(git_worktree_path):
378 if 'storage_format' in filename:
379 storage_data_files.add(filename)
380 to_be_generated.add(filename)
David Horstmannb8360cf2024-05-31 14:38:52 +0100381
382 generate_psa_tests = 'framework/scripts/generate_psa_tests.py'
383 if not os.path.isfile(git_worktree_path + '/' + generate_psa_tests):
384 # The checked-out revision is from before generate_psa_tests.py
385 # was moved to the framework submodule. Use the old location.
386 generate_psa_tests = 'tests/scripts/generate_psa_tests.py'
Gilles Peskine92165362021-04-23 16:37:12 +0200387 subprocess.check_call(
David Horstmannb8360cf2024-05-31 14:38:52 +0100388 [generate_psa_tests] + sorted(to_be_generated),
Gilles Peskine92165362021-04-23 16:37:12 +0200389 cwd=git_worktree_path,
390 )
Gilles Peskineca586a52022-02-22 19:02:44 +0100391 for test_file in sorted(storage_data_files):
392 self._read_storage_tests(git_worktree_path,
393 test_file,
394 test_file in to_be_generated,
Gilles Peskine92165362021-04-23 16:37:12 +0200395 version.storage_tests)
396
Darryl Green3a5f6c82019-03-05 16:30:39 +0000397 def _cleanup_worktree(self, git_worktree_path):
Gilles Peskine712afa72019-02-25 20:36:52 +0100398 """Remove the specified git worktree."""
Darryl Green7c2dd582018-03-01 14:53:49 +0000399 shutil.rmtree(git_worktree_path)
Bence Szépkútieffa5342025-09-25 15:51:07 +0200400 submodule_output = subprocess.check_output(
Bence Szépkúti8d950622025-09-26 15:44:11 +0200401 [self.git_command, "submodule", "foreach", "--recursive",
402 f'git worktree remove "{git_worktree_path}/$displaypath"'],
Bence Szépkútieffa5342025-09-25 15:51:07 +0200403 cwd=self.repo_path,
404 stderr=subprocess.STDOUT
405 )
406 self.log.debug(submodule_output.decode("utf-8"))
Darryl Greenb2ee0b82019-04-12 16:24:25 +0100407 worktree_output = subprocess.check_output(
Bence Szépkúti8d950622025-09-26 15:44:11 +0200408 [self.git_command, "worktree", "remove", git_worktree_path],
Darryl Green7c2dd582018-03-01 14:53:49 +0000409 cwd=self.repo_path,
Darryl Green7c2dd582018-03-01 14:53:49 +0000410 stderr=subprocess.STDOUT
411 )
Darryl Green3c3da792019-03-08 11:30:04 +0000412 self.log.debug(worktree_output.decode("utf-8"))
Darryl Green7c2dd582018-03-01 14:53:49 +0000413
Darryl Green3a5f6c82019-03-05 16:30:39 +0000414 def _get_abi_dump_for_ref(self, version):
Gilles Peskine92165362021-04-23 16:37:12 +0200415 """Generate the interface information for the specified git revision."""
Darryl Green3a5f6c82019-03-05 16:30:39 +0000416 git_worktree_path = self._get_clean_worktree_for_git_revision(version)
417 self._update_git_submodules(git_worktree_path, version)
Gilles Peskinec76ab852021-04-23 16:32:32 +0200418 if self.check_abi:
419 self._build_shared_libraries(git_worktree_path, version)
420 self._get_abi_dumps_from_shared_libraries(version)
Gilles Peskine92165362021-04-23 16:37:12 +0200421 if self.check_storage_tests:
422 self._get_storage_format_tests(version, git_worktree_path)
Darryl Green3a5f6c82019-03-05 16:30:39 +0000423 self._cleanup_worktree(git_worktree_path)
Darryl Green7c2dd582018-03-01 14:53:49 +0000424
Darryl Green3a5f6c82019-03-05 16:30:39 +0000425 def _remove_children_with_tag(self, parent, tag):
Darryl Greene62f9bb2019-02-21 13:09:26 +0000426 children = parent.getchildren()
427 for child in children:
428 if child.tag == tag:
429 parent.remove(child)
430 else:
Darryl Green3a5f6c82019-03-05 16:30:39 +0000431 self._remove_children_with_tag(child, tag)
Darryl Greene62f9bb2019-02-21 13:09:26 +0000432
Darryl Green3a5f6c82019-03-05 16:30:39 +0000433 def _remove_extra_detail_from_report(self, report_root):
Darryl Greene62f9bb2019-02-21 13:09:26 +0000434 for tag in ['test_info', 'test_results', 'problem_summary',
Darryl Greenc6f874b2019-06-05 12:57:50 +0100435 'added_symbols', 'affected']:
Darryl Green3a5f6c82019-03-05 16:30:39 +0000436 self._remove_children_with_tag(report_root, tag)
Darryl Greene62f9bb2019-02-21 13:09:26 +0000437
438 for report in report_root:
439 for problems in report.getchildren()[:]:
440 if not problems.getchildren():
441 report.remove(problems)
442
Gilles Peskineada828f2019-07-04 19:17:40 +0200443 def _abi_compliance_command(self, mbed_module, output_path):
444 """Build the command to run to analyze the library mbed_module.
445 The report will be placed in output_path."""
446 abi_compliance_command = [
447 "abi-compliance-checker",
448 "-l", mbed_module,
449 "-old", self.old_version.abi_dumps[mbed_module],
450 "-new", self.new_version.abi_dumps[mbed_module],
451 "-strict",
452 "-report-path", output_path,
453 ]
454 if self.skip_file:
455 abi_compliance_command += ["-skip-symbols", self.skip_file,
456 "-skip-types", self.skip_file]
457 if self.brief:
458 abi_compliance_command += ["-report-format", "xml",
459 "-stdout"]
460 return abi_compliance_command
461
462 def _is_library_compatible(self, mbed_module, compatibility_report):
463 """Test if the library mbed_module has remained compatible.
464 Append a message regarding compatibility to compatibility_report."""
465 output_path = os.path.join(
466 self.report_dir, "{}-{}-{}.html".format(
467 mbed_module, self.old_version.revision,
468 self.new_version.revision
469 )
470 )
471 try:
472 subprocess.check_output(
473 self._abi_compliance_command(mbed_module, output_path),
474 stderr=subprocess.STDOUT
475 )
476 except subprocess.CalledProcessError as err:
477 if err.returncode != 1:
478 raise err
479 if self.brief:
480 self.log.info(
481 "Compatibility issues found for {}".format(mbed_module)
482 )
483 report_root = ET.fromstring(err.output.decode("utf-8"))
484 self._remove_extra_detail_from_report(report_root)
485 self.log.info(ET.tostring(report_root).decode("utf-8"))
486 else:
487 self.can_remove_report_dir = False
488 compatibility_report.append(
489 "Compatibility issues found for {}, "
490 "for details see {}".format(mbed_module, output_path)
491 )
492 return False
493 compatibility_report.append(
494 "No compatibility issues for {}".format(mbed_module)
495 )
496 if not (self.keep_all_reports or self.brief):
497 os.remove(output_path)
498 return True
499
Gilles Peskine92165362021-04-23 16:37:12 +0200500 @staticmethod
501 def _is_storage_format_compatible(old_tests, new_tests,
502 compatibility_report):
503 """Check whether all tests present in old_tests are also in new_tests.
504
505 Append a message regarding compatibility to compatibility_report.
506 """
507 missing = frozenset(old_tests.keys()).difference(new_tests.keys())
508 for test_data in sorted(missing):
509 metadata = old_tests[test_data]
510 compatibility_report.append(
511 'Test case from {} line {} "{}" has disappeared: {}'.format(
512 metadata.filename, metadata.line_number,
513 metadata.description, test_data
514 )
515 )
516 compatibility_report.append(
517 'FAIL: {}/{} storage format test cases have changed or disappeared.'.format(
518 len(missing), len(old_tests)
519 ) if missing else
520 'PASS: All {} storage format test cases are preserved.'.format(
521 len(old_tests)
522 )
523 )
524 compatibility_report.append(
525 'Info: number of storage format tests cases: {} -> {}.'.format(
526 len(old_tests), len(new_tests)
527 )
528 )
529 return not missing
530
Darryl Green7c2dd582018-03-01 14:53:49 +0000531 def get_abi_compatibility_report(self):
Gilles Peskine712afa72019-02-25 20:36:52 +0100532 """Generate a report of the differences between the reference ABI
Darryl Green8184df52019-04-05 17:06:17 +0100533 and the new ABI. ABI dumps from self.old_version and self.new_version
534 must be available."""
Gilles Peskineada828f2019-07-04 19:17:40 +0200535 compatibility_report = ["Checking evolution from {} to {}".format(
Gilles Peskine3e2da4a2019-07-04 19:01:22 +0200536 self._pretty_revision(self.old_version),
537 self._pretty_revision(self.new_version)
Gilles Peskineada828f2019-07-04 19:17:40 +0200538 )]
Darryl Green7c2dd582018-03-01 14:53:49 +0000539 compliance_return_code = 0
Gilles Peskine92165362021-04-23 16:37:12 +0200540
Gilles Peskinec76ab852021-04-23 16:32:32 +0200541 if self.check_abi:
542 shared_modules = list(set(self.old_version.modules.keys()) &
543 set(self.new_version.modules.keys()))
544 for mbed_module in shared_modules:
545 if not self._is_library_compatible(mbed_module,
546 compatibility_report):
547 compliance_return_code = 1
548
Gilles Peskine92165362021-04-23 16:37:12 +0200549 if self.check_storage_tests:
550 if not self._is_storage_format_compatible(
551 self.old_version.storage_tests,
552 self.new_version.storage_tests,
553 compatibility_report):
Gilles Peskineada828f2019-07-04 19:17:40 +0200554 compliance_return_code = 1
Gilles Peskine92165362021-04-23 16:37:12 +0200555
Darryl Greenf2688e22019-05-29 11:29:08 +0100556 for version in [self.old_version, self.new_version]:
557 for mbed_module, mbed_module_dump in version.abi_dumps.items():
558 os.remove(mbed_module_dump)
Darryl Green3d3d5522019-02-25 17:01:55 +0000559 if self.can_remove_report_dir:
Darryl Green7c2dd582018-03-01 14:53:49 +0000560 os.rmdir(self.report_dir)
Gilles Peskineada828f2019-07-04 19:17:40 +0200561 self.log.info("\n".join(compatibility_report))
Darryl Green7c2dd582018-03-01 14:53:49 +0000562 return compliance_return_code
563
564 def check_for_abi_changes(self):
Gilles Peskine712afa72019-02-25 20:36:52 +0100565 """Generate a report of ABI differences
566 between self.old_rev and self.new_rev."""
Gilles Peskined9071e72022-09-18 21:17:09 +0200567 build_tree.check_repo_path()
Gilles Peskine93c2a422022-03-03 10:22:36 +0100568 if self.check_api or self.check_abi:
569 self.check_abi_tools_are_installed()
Darryl Green3a5f6c82019-03-05 16:30:39 +0000570 self._get_abi_dump_for_ref(self.old_version)
571 self._get_abi_dump_for_ref(self.new_version)
Darryl Green7c2dd582018-03-01 14:53:49 +0000572 return self.get_abi_compatibility_report()
573
574
575def run_main():
576 try:
577 parser = argparse.ArgumentParser(
Gilles Peskine644b3f62022-03-03 10:23:09 +0100578 description=__doc__
Darryl Green7c2dd582018-03-01 14:53:49 +0000579 )
580 parser.add_argument(
Darryl Green3c3da792019-03-08 11:30:04 +0000581 "-v", "--verbose", action="store_true",
582 help="set verbosity level",
583 )
584 parser.add_argument(
Darryl Green418527b2018-04-16 12:02:29 +0100585 "-r", "--report-dir", type=str, default="reports",
Darryl Green7c2dd582018-03-01 14:53:49 +0000586 help="directory where reports are stored, default is reports",
587 )
588 parser.add_argument(
Darryl Green418527b2018-04-16 12:02:29 +0100589 "-k", "--keep-all-reports", action="store_true",
Darryl Green7c2dd582018-03-01 14:53:49 +0000590 help="keep all reports, even if there are no compatibility issues",
591 )
592 parser.add_argument(
Darryl Greenc5132ff2019-03-01 09:54:44 +0000593 "-o", "--old-rev", type=str, help="revision for old version.",
594 required=True,
Darryl Green7c2dd582018-03-01 14:53:49 +0000595 )
596 parser.add_argument(
Darryl Greenc5132ff2019-03-01 09:54:44 +0000597 "-or", "--old-repo", type=str, help="repository for old version."
Darryl Green9f357d62019-02-25 11:35:05 +0000598 )
599 parser.add_argument(
Darryl Greenc5132ff2019-03-01 09:54:44 +0000600 "-oc", "--old-crypto-rev", type=str,
601 help="revision for old crypto submodule."
Darryl Green7c2dd582018-03-01 14:53:49 +0000602 )
Darryl Greenc2883a22019-02-20 15:01:56 +0000603 parser.add_argument(
Darryl Greenc5132ff2019-03-01 09:54:44 +0000604 "-ocr", "--old-crypto-repo", type=str,
605 help="repository for old crypto submodule."
606 )
607 parser.add_argument(
608 "-n", "--new-rev", type=str, help="revision for new version",
609 required=True,
610 )
611 parser.add_argument(
612 "-nr", "--new-repo", type=str, help="repository for new version."
613 )
614 parser.add_argument(
615 "-nc", "--new-crypto-rev", type=str,
616 help="revision for new crypto version"
617 )
618 parser.add_argument(
619 "-ncr", "--new-crypto-repo", type=str,
620 help="repository for new crypto submodule."
Darryl Green9f357d62019-02-25 11:35:05 +0000621 )
622 parser.add_argument(
Darryl Greenc2883a22019-02-20 15:01:56 +0000623 "-s", "--skip-file", type=str,
Gilles Peskineb6ce2342019-07-04 19:00:31 +0200624 help=("path to file containing symbols and types to skip "
625 "(typically \"-s identifiers\" after running "
626 "\"tests/scripts/list-identifiers.sh --internal\")")
Darryl Greenc2883a22019-02-20 15:01:56 +0000627 )
Darryl Greene62f9bb2019-02-21 13:09:26 +0000628 parser.add_argument(
Gilles Peskinec76ab852021-04-23 16:32:32 +0200629 "--check-abi",
630 action='store_true', default=True,
631 help="Perform ABI comparison (default: yes)"
632 )
633 parser.add_argument("--no-check-abi", action='store_false', dest='check_abi')
634 parser.add_argument(
635 "--check-api",
636 action='store_true', default=True,
637 help="Perform API comparison (default: yes)"
638 )
639 parser.add_argument("--no-check-api", action='store_false', dest='check_api')
640 parser.add_argument(
Gilles Peskine92165362021-04-23 16:37:12 +0200641 "--check-storage",
642 action='store_true', default=True,
643 help="Perform storage tests comparison (default: yes)"
644 )
645 parser.add_argument("--no-check-storage", action='store_false', dest='check_storage')
646 parser.add_argument(
Darryl Greene62f9bb2019-02-21 13:09:26 +0000647 "-b", "--brief", action="store_true",
648 help="output only the list of issues to stdout, instead of a full report",
649 )
Darryl Green7c2dd582018-03-01 14:53:49 +0000650 abi_args = parser.parse_args()
Darryl Green492bc402019-04-11 15:50:41 +0100651 if os.path.isfile(abi_args.report_dir):
652 print("Error: {} is not a directory".format(abi_args.report_dir))
653 parser.exit()
Darryl Green0d1ca512019-04-09 09:14:17 +0100654 old_version = SimpleNamespace(
655 version="old",
656 repository=abi_args.old_repo,
657 revision=abi_args.old_rev,
Gilles Peskine3e2da4a2019-07-04 19:01:22 +0200658 commit=None,
Darryl Green0d1ca512019-04-09 09:14:17 +0100659 crypto_repository=abi_args.old_crypto_repo,
660 crypto_revision=abi_args.old_crypto_rev,
661 abi_dumps={},
Gilles Peskine92165362021-04-23 16:37:12 +0200662 storage_tests={},
Darryl Green0d1ca512019-04-09 09:14:17 +0100663 modules={}
Darryl Green8184df52019-04-05 17:06:17 +0100664 )
Darryl Green0d1ca512019-04-09 09:14:17 +0100665 new_version = SimpleNamespace(
666 version="new",
667 repository=abi_args.new_repo,
668 revision=abi_args.new_rev,
Gilles Peskine3e2da4a2019-07-04 19:01:22 +0200669 commit=None,
Darryl Green0d1ca512019-04-09 09:14:17 +0100670 crypto_repository=abi_args.new_crypto_repo,
671 crypto_revision=abi_args.new_crypto_rev,
672 abi_dumps={},
Gilles Peskine92165362021-04-23 16:37:12 +0200673 storage_tests={},
Darryl Green0d1ca512019-04-09 09:14:17 +0100674 modules={}
Darryl Green8184df52019-04-05 17:06:17 +0100675 )
Darryl Green0d1ca512019-04-09 09:14:17 +0100676 configuration = SimpleNamespace(
677 verbose=abi_args.verbose,
678 report_dir=abi_args.report_dir,
679 keep_all_reports=abi_args.keep_all_reports,
680 brief=abi_args.brief,
Gilles Peskinec76ab852021-04-23 16:32:32 +0200681 check_abi=abi_args.check_abi,
682 check_api=abi_args.check_api,
Gilles Peskine92165362021-04-23 16:37:12 +0200683 check_storage=abi_args.check_storage,
Darryl Green0d1ca512019-04-09 09:14:17 +0100684 skip_file=abi_args.skip_file
Darryl Green7c2dd582018-03-01 14:53:49 +0000685 )
Darryl Green0d1ca512019-04-09 09:14:17 +0100686 abi_check = AbiChecker(old_version, new_version, configuration)
Darryl Green7c2dd582018-03-01 14:53:49 +0000687 return_code = abi_check.check_for_abi_changes()
688 sys.exit(return_code)
Gilles Peskinee915d532019-02-25 21:39:42 +0100689 except Exception: # pylint: disable=broad-except
690 # Print the backtrace and exit explicitly so as to exit with
691 # status 2, not 1.
Darryl Greena6f430f2018-03-15 10:12:06 +0000692 traceback.print_exc()
Darryl Green7c2dd582018-03-01 14:53:49 +0000693 sys.exit(2)
694
695
696if __name__ == "__main__":
697 run_main()