blob: ed36befeef9ca1df741133f98a340d4dfac733c5 [file] [log] [blame]
Bence Szépkúti80b31c52021-10-19 15:05:36 +02001#!/usr/bin/env python3
Shaun Case8b0ecbc2021-12-20 21:14:10 -08002"""Run the PSA Crypto API compliance test suite.
Bence Szépkúti449781f2021-11-02 13:41:14 +01003Clone the repo and check out the commit specified by PSA_ARCH_TEST_REPO and PSA_ARCH_TEST_REF,
David Horstmann3b8984a2023-08-29 10:32:26 +01004then compile and run the test suite. The clone is stored at <repository root>/psa-arch-tests.
Ronald Cron070e8652023-10-09 10:25:45 +02005Known defects in either the test suite or mbedtls / TF-PSA-Crypto - identified by their test
David Horstmann3b8984a2023-08-29 10:32:26 +01006number - are ignored, while unexpected failures AND successes are reported as errors, to help
7keep the list of known defects as up to date as possible.
Bence Szépkúti449781f2021-11-02 13:41:14 +01008"""
Bence Szépkúti67fb3142021-11-02 14:01:08 +01009
10# Copyright The Mbed TLS Contributors
Dave Rodgman16799db2023-11-02 19:47:20 +000011# SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
Bence Szépkúti67fb3142021-11-02 14:01:08 +010012
David Horstmann4dcddcf2023-08-17 18:08:24 +010013import argparse
Bence Szépkúti80b31c52021-10-19 15:05:36 +020014import os
15import re
16import shutil
17import subprocess
18import sys
David Horstmann9cc6b2f2023-08-29 17:36:35 +010019from typing import List
Bence Szépkúti80b31c52021-10-19 15:05:36 +020020
David Horstmanne31014a2023-07-19 11:43:27 +010021#pylint: disable=unused-import
David Horstmann1d091842023-07-18 17:39:35 +010022import scripts_path
23from mbedtls_dev import build_tree
24
Ronald Cron070e8652023-10-09 10:25:45 +020025# PSA Compliance tests we expect to fail due to known defects in Mbed TLS /
26# TF-PSA-Crypto (or the test suite).
Bence Szépkúticb288712021-11-09 21:30:43 +010027# The test numbers correspond to the numbers used by the console output of the test suite.
28# Test number 2xx corresponds to the files in the folder
29# psa-arch-tests/api-tests/dev_apis/crypto/test_c0xx
Bence Szépkúti80b31c52021-10-19 15:05:36 +020030EXPECTED_FAILURES = {
Bence Szépkúticb288712021-11-09 21:30:43 +010031 # psa_hash_suspend() and psa_hash_resume() are not supported.
32 # - Tracked in issue #3274
Valerio Setti41f8f732024-01-29 11:44:40 +010033 262, 263,
34 # PSA standard format for RSA public keys is a sequence of just n (modulus)
35 # and e (public exponent). However following tests rely on a format which
36 # also includes some metadata to identify the key as an RSA key, but this
37 # is not compliant with PSA standard.
38 239, 240, 241, 242, 250, 251,
Bence Szépkúti80b31c52021-10-19 15:05:36 +020039}
Bence Szépkútie2855c32021-11-09 17:33:57 +010040
41# We currently use a fork of ARM-software/psa-arch-tests, with a couple of downstream patches
Thomas Daubney540324c2023-10-06 17:07:24 +010042# that allow it to build with Mbed TLS 3, and fixes a couple of issues in the compliance test suite.
Bence Szépkútie2855c32021-11-09 17:33:57 +010043# These fixes allow the tests numbered 216, 248 and 249 to complete successfully.
44#
45# Once all the fixes are upstreamed, this fork should be replaced with an upstream commit/tag.
Bence Szépkútib376eac2021-11-09 22:13:46 +010046# - Tracked in issue #5145
Bence Szépkútie2855c32021-11-09 17:33:57 +010047#
48# Web URL: https://github.com/bensze01/psa-arch-tests/tree/fixes-for-mbedtls-3
49PSA_ARCH_TESTS_REPO = 'https://github.com/bensze01/psa-arch-tests.git'
Gilles Peskine42ed9632022-05-17 17:23:09 +020050PSA_ARCH_TESTS_REF = 'fix-pr-5736'
Bence Szépkúti80b31c52021-10-19 15:05:36 +020051
David Horstmanne31014a2023-07-19 11:43:27 +010052#pylint: disable=too-many-branches,too-many-statements,too-many-locals
David Horstmann4dcddcf2023-08-17 18:08:24 +010053def main(library_build_dir: str):
David Horstmannf7570692023-08-29 10:27:13 +010054 root_dir = os.getcwd()
Bence Szépkúti80b31c52021-10-19 15:05:36 +020055
Thomas Daubneye8f37892023-11-24 11:41:23 +000056 in_tf_psa_crypto_repo = build_tree.looks_like_tf_psa_crypto_root(root_dir)
57
Thomas Daubney08c6dc42023-11-30 13:56:09 +000058 crypto_name = build_tree.crypto_library_filename(root_dir)
Thomas Daubney10769bc2023-12-01 23:47:59 +000059 library_subdir = build_tree.crypto_core_directory(root_dir, relative=True)
David Horstmannbeaee262023-08-29 13:56:17 +010060
61 crypto_lib_filename = (library_build_dir + '/' +
62 library_subdir + '/' +
63 'lib' + crypto_name + '.a')
David Horstmann98af1982023-08-29 10:25:26 +010064
65 if not os.path.exists(crypto_lib_filename):
David Horstmann2ba89be2023-08-29 10:37:29 +010066 #pylint: disable=bad-continuation
David Horstmann4dcddcf2023-08-17 18:08:24 +010067 subprocess.check_call([
68 'cmake', '.',
69 '-GUnix Makefiles',
David Horstmann41c316d2023-08-29 14:57:23 +010070 '-B' + library_build_dir
David Horstmann4dcddcf2023-08-17 18:08:24 +010071 ])
David Horstmannbeaee262023-08-29 13:56:17 +010072 subprocess.check_call(['cmake', '--build', library_build_dir,
David Horstmann8f3ec8e2023-08-30 09:46:20 +010073 '--target', crypto_name])
Bence Szépkúti80b31c52021-10-19 15:05:36 +020074
75 psa_arch_tests_dir = 'psa-arch-tests'
Bence Szépkútic63d1602021-11-02 14:06:40 +010076 os.makedirs(psa_arch_tests_dir, exist_ok=True)
Bence Szépkúti80b31c52021-10-19 15:05:36 +020077 try:
Bence Szépkúti34b5f562021-11-02 13:48:39 +010078 os.chdir(psa_arch_tests_dir)
Bence Szépkúti80b31c52021-10-19 15:05:36 +020079
Bence Szépkútib3818412021-11-03 11:32:51 +010080 # Reuse existing local clone
Bence Szépkúti34b5f562021-11-02 13:48:39 +010081 subprocess.check_call(['git', 'init'])
82 subprocess.check_call(['git', 'fetch', PSA_ARCH_TESTS_REPO, PSA_ARCH_TESTS_REF])
83 subprocess.check_call(['git', 'checkout', 'FETCH_HEAD'])
Bence Szépkúti80b31c52021-10-19 15:05:36 +020084
Bence Szépkúti34b5f562021-11-02 13:48:39 +010085 build_dir = 'api-tests/build'
86 try:
87 shutil.rmtree(build_dir)
88 except FileNotFoundError:
89 pass
90 os.mkdir(build_dir)
91 os.chdir(build_dir)
Bence Szépkúti80b31c52021-10-19 15:05:36 +020092
David Horstmannf7570692023-08-29 10:27:13 +010093 extra_includes = (';{}/drivers/builtin/include'.format(root_dir)
Ronald Cron070e8652023-10-09 10:25:45 +020094 if in_tf_psa_crypto_repo else '')
David Horstmann1d091842023-07-18 17:39:35 +010095
Bence Szépkúti34b5f562021-11-02 13:48:39 +010096 #pylint: disable=bad-continuation
97 subprocess.check_call([
98 'cmake', '..',
99 '-GUnix Makefiles',
100 '-DTARGET=tgt_dev_apis_stdc',
101 '-DTOOLCHAIN=HOST_GCC',
102 '-DSUITE=CRYPTO',
David Horstmannf7570692023-08-29 10:27:13 +0100103 '-DPSA_CRYPTO_LIB_FILENAME={}/{}'.format(root_dir,
David Horstmann7f93d222023-08-23 16:21:40 +0100104 crypto_lib_filename),
David Horstmannf7570692023-08-29 10:27:13 +0100105 ('-DPSA_INCLUDE_PATHS={}/include' + extra_includes).format(root_dir)
Bence Szépkúti34b5f562021-11-02 13:48:39 +0100106 ])
107 subprocess.check_call(['cmake', '--build', '.'])
Bence Szépkúti80b31c52021-10-19 15:05:36 +0200108
Bence Szépkúti34b5f562021-11-02 13:48:39 +0100109 proc = subprocess.Popen(['./psa-arch-tests-crypto'],
110 bufsize=1, stdout=subprocess.PIPE, universal_newlines=True)
111
112 test_re = re.compile(
113 '^TEST: (?P<test_num>[0-9]*)|'
114 '^TEST RESULT: (?P<test_result>FAILED|PASSED)'
115 )
116 test = -1
117 unexpected_successes = set(EXPECTED_FAILURES)
David Horstmannfd9264e2023-08-29 16:21:15 +0100118 expected_failures = [] # type: List[int]
119 unexpected_failures = [] # type: List[int]
120 if proc.stdout is None:
121 return 1
122
Bence Szépkúti34b5f562021-11-02 13:48:39 +0100123 for line in proc.stdout:
124 print(line, end='')
125 match = test_re.match(line)
126 if match is not None:
127 groupdict = match.groupdict()
128 test_num = groupdict['test_num']
129 if test_num is not None:
130 test = int(test_num)
131 elif groupdict['test_result'] == 'FAILED':
132 try:
133 unexpected_successes.remove(test)
134 expected_failures.append(test)
135 print('Expected failure, ignoring')
136 except KeyError:
137 unexpected_failures.append(test)
138 print('ERROR: Unexpected failure')
139 elif test in unexpected_successes:
140 print('ERROR: Unexpected success')
141 proc.wait()
142
143 print()
144 print('***** test_psa_compliance.py report ******')
145 print()
146 print('Expected failures:', ', '.join(str(i) for i in expected_failures))
147 print('Unexpected failures:', ', '.join(str(i) for i in unexpected_failures))
148 print('Unexpected successes:', ', '.join(str(i) for i in sorted(unexpected_successes)))
149 print()
150 if unexpected_successes or unexpected_failures:
151 if unexpected_successes:
152 print('Unexpected successes encountered.')
153 print('Please remove the corresponding tests from '
154 'EXPECTED_FAILURES in tests/scripts/compliance_test.py')
155 print()
156 print('FAILED')
157 return 1
158 else:
Bence Szépkúti34b5f562021-11-02 13:48:39 +0100159 print('SUCCESS')
160 return 0
161 finally:
David Horstmannf7570692023-08-29 10:27:13 +0100162 os.chdir(root_dir)
Bence Szépkúti80b31c52021-10-19 15:05:36 +0200163
164if __name__ == '__main__':
David Horstmannb48822c2023-08-29 14:12:53 +0100165 BUILD_DIR = 'out_of_source_build'
David Horstmann4dcddcf2023-08-17 18:08:24 +0100166
David Horstmann3ed18712023-08-29 18:20:01 +0100167 # pylint: disable=invalid-name
David Horstmann4dcddcf2023-08-17 18:08:24 +0100168 parser = argparse.ArgumentParser()
169 parser.add_argument('--build-dir', nargs=1,
Ronald Cron070e8652023-10-09 10:25:45 +0200170 help='path to Mbed TLS / TF-PSA-Crypto build directory')
David Horstmann4dcddcf2023-08-17 18:08:24 +0100171 args = parser.parse_args()
172
173 if args.build_dir is not None:
David Horstmannb48822c2023-08-29 14:12:53 +0100174 BUILD_DIR = args.build_dir[0]
David Horstmann4dcddcf2023-08-17 18:08:24 +0100175
David Horstmannb48822c2023-08-29 14:12:53 +0100176 sys.exit(main(BUILD_DIR))