| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 1 | #!/usr/bin/env python3 | 
|  | 2 |  | 
| Andrzej Kurek | 629c412 | 2022-10-17 08:34:40 -0400 | [diff] [blame] | 3 | # Copyright (c) 2022, Arm Limited, All Rights Reserved. | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 4 | # SPDX-License-Identifier: Apache-2.0 | 
|  | 5 | # | 
|  | 6 | # Licensed under the Apache License, Version 2.0 (the "License"); you may | 
|  | 7 | # not use this file except in compliance with the License. | 
|  | 8 | # You may obtain a copy of the License at | 
|  | 9 | # | 
|  | 10 | # http://www.apache.org/licenses/LICENSE-2.0 | 
|  | 11 | # | 
|  | 12 | # Unless required by applicable law or agreed to in writing, software | 
|  | 13 | # distributed under the License is distributed on an "AS IS" BASIS, WITHOUT | 
|  | 14 | # WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. | 
|  | 15 | # See the License for the specific language governing permissions and | 
|  | 16 | # limitations under the License. | 
|  | 17 | # | 
|  | 18 | # This file is part of Mbed TLS (https://tls.mbed.org) | 
|  | 19 |  | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 20 | """ | 
| Andrzej Kurek | 01af84a | 2022-10-09 05:29:44 -0400 | [diff] [blame] | 21 | Test Mbed TLS with a subset of algorithms. | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 22 |  | 
| Andrzej Kurek | 01af84a | 2022-10-09 05:29:44 -0400 | [diff] [blame] | 23 | This script can be divided into several steps: | 
|  | 24 |  | 
|  | 25 | First, include/mbedtls/mbedtls_config.h or a different config file passed | 
|  | 26 | in the arguments is parsed to extract any configuration options (collect_config_symbols). | 
|  | 27 |  | 
|  | 28 | Then, test domains (groups of jobs, tests) are built based on predefined data | 
|  | 29 | collected in the DomainData class. Here, each domain has five major traits: | 
| Andrzej Kurek | 629c412 | 2022-10-17 08:34:40 -0400 | [diff] [blame] | 30 | - domain name, can be used to run only specific tests via command-line; | 
| Andrzej Kurek | 01af84a | 2022-10-09 05:29:44 -0400 | [diff] [blame] | 31 | - configuration building method, described in detail below; | 
|  | 32 | - list of symbols passed to the configuration building method; | 
|  | 33 | - commands to be run on each job (only build, build and test, or any other custom); | 
|  | 34 | - optional list of symbols to be excluded from testing. | 
|  | 35 |  | 
|  | 36 | The configuration building method can be one of the three following: | 
|  | 37 |  | 
|  | 38 | - ComplementaryDomain - build a job for each passed symbol by disabling a single | 
|  | 39 | symbol and its reverse dependencies (defined in REVERSE_DEPENDENCIES); | 
|  | 40 |  | 
|  | 41 | - ExclusiveDomain - build a job where, for each passed symbol, only this particular | 
|  | 42 | one is defined and other symbols from the list are unset. For each job look for | 
|  | 43 | any non-standard symbols to set/unset in EXCLUSIVE_GROUPS. These are usually not | 
|  | 44 | direct dependencies, but rather non-trivial results of other configs missing. Then | 
|  | 45 | look for any unset symbols and handle their reverse dependencies. | 
|  | 46 | Examples of EXCLUSIVE_GROUPS usage: | 
| Andrzej Kurek | 629c412 | 2022-10-17 08:34:40 -0400 | [diff] [blame] | 47 | - MBEDTLS_SHA256 job turns off all hashes except SHA256, however, when investigating | 
|  | 48 | reverse dependencies, SHA224 is found to depend on SHA256, so it is disabled, | 
|  | 49 | and then SHA256 is found to depend on SHA224, so it is also disabled. To handle | 
|  | 50 | this, there's a field in EXCLUSIVE_GROUPS that states that in a SHA256 test SHA224 | 
| Andrzej Kurek | 01af84a | 2022-10-09 05:29:44 -0400 | [diff] [blame] | 51 | should also be enabled before processing reverse dependencies: | 
| Andrzej Kurek | 629c412 | 2022-10-17 08:34:40 -0400 | [diff] [blame] | 52 | 'MBEDTLS_SHA256_C': ['+MBEDTLS_SHA224_C'] | 
| Andrzej Kurek | 01af84a | 2022-10-09 05:29:44 -0400 | [diff] [blame] | 53 | - MBEDTLS_SHA512_C job turns off all hashes except SHA512. MBEDTLS_SSL_COOKIE_C | 
|  | 54 | requires either SHA256 or SHA384 to work, so it also has to be disabled. | 
|  | 55 | This is not a dependency on SHA512_C, but a result of an exclusive domain | 
|  | 56 | config building method. Relevant field: | 
| Andrzej Kurek | 629c412 | 2022-10-17 08:34:40 -0400 | [diff] [blame] | 57 | 'MBEDTLS_SHA512_C': ['-MBEDTLS_SSL_COOKIE_C'], | 
| Andrzej Kurek | 01af84a | 2022-10-09 05:29:44 -0400 | [diff] [blame] | 58 |  | 
|  | 59 | - DualDomain - combination of the two above - both complementary and exclusive domain | 
|  | 60 | job generation code will be run. Currently only used for hashes. | 
|  | 61 |  | 
|  | 62 | Lastly, the collected jobs are executed and (optionally) tested, with | 
|  | 63 | error reporting and coloring as configured in options. Each test starts with | 
|  | 64 | a full config without a couple of slowing down or unnecessary options | 
|  | 65 | (see set_reference_config), then the specific job config is derived. | 
|  | 66 | """ | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 67 | import argparse | 
|  | 68 | import os | 
|  | 69 | import re | 
|  | 70 | import shutil | 
|  | 71 | import subprocess | 
|  | 72 | import sys | 
|  | 73 | import traceback | 
|  | 74 |  | 
| Andrzej Kurek | 3322c22 | 2022-10-04 15:02:41 -0400 | [diff] [blame] | 75 | class Colors: # pylint: disable=too-few-public-methods | 
| Gilles Peskine | 0fa7cbe | 2019-01-29 18:48:48 +0100 | [diff] [blame] | 76 | """Minimalistic support for colored output. | 
|  | 77 | Each field of an object of this class is either None if colored output | 
|  | 78 | is not possible or not desired, or a pair of strings (start, stop) such | 
|  | 79 | that outputting start switches the text color to the desired color and | 
|  | 80 | stop switches the text color back to the default.""" | 
|  | 81 | red = None | 
|  | 82 | green = None | 
|  | 83 | bold_red = None | 
|  | 84 | bold_green = None | 
|  | 85 | def __init__(self, options=None): | 
| Andrzej Kurek | 3322c22 | 2022-10-04 15:02:41 -0400 | [diff] [blame] | 86 | """Initialize color profile according to passed options.""" | 
| Gilles Peskine | 0fa7cbe | 2019-01-29 18:48:48 +0100 | [diff] [blame] | 87 | if not options or options.color in ['no', 'never']: | 
|  | 88 | want_color = False | 
|  | 89 | elif options.color in ['yes', 'always']: | 
|  | 90 | want_color = True | 
|  | 91 | else: | 
|  | 92 | want_color = sys.stderr.isatty() | 
|  | 93 | if want_color: | 
|  | 94 | # Assume ANSI compatible terminal | 
|  | 95 | normal = '\033[0m' | 
|  | 96 | self.red = ('\033[31m', normal) | 
|  | 97 | self.green = ('\033[32m', normal) | 
|  | 98 | self.bold_red = ('\033[1;31m', normal) | 
|  | 99 | self.bold_green = ('\033[1;32m', normal) | 
|  | 100 | NO_COLORS = Colors(None) | 
|  | 101 |  | 
|  | 102 | def log_line(text, prefix='depends.py:', suffix='', color=None): | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 103 | """Print a status message.""" | 
| Andrzej Kurek | 3322c22 | 2022-10-04 15:02:41 -0400 | [diff] [blame] | 104 | if color is not None: | 
| Gilles Peskine | 0fa7cbe | 2019-01-29 18:48:48 +0100 | [diff] [blame] | 105 | prefix = color[0] + prefix | 
|  | 106 | suffix = suffix + color[1] | 
|  | 107 | sys.stderr.write(prefix + ' ' + text + suffix + '\n') | 
| Gilles Peskine | 46c8256 | 2019-01-29 18:42:55 +0100 | [diff] [blame] | 108 | sys.stderr.flush() | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 109 |  | 
| Gilles Peskine | 54aa5c6 | 2019-01-29 18:46:34 +0100 | [diff] [blame] | 110 | def log_command(cmd): | 
|  | 111 | """Print a trace of the specified command. | 
|  | 112 | cmd is a list of strings: a command name and its arguments.""" | 
|  | 113 | log_line(' '.join(cmd), prefix='+') | 
|  | 114 |  | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 115 | def backup_config(options): | 
| Andrzej Kurek | e05b17f | 2022-09-28 03:17:56 -0400 | [diff] [blame] | 116 | """Back up the library configuration file (mbedtls_config.h). | 
| Gilles Peskine | bf7537d | 2019-01-29 18:52:16 +0100 | [diff] [blame] | 117 | If the backup file already exists, it is presumed to be the desired backup, | 
|  | 118 | so don't make another backup.""" | 
|  | 119 | if os.path.exists(options.config_backup): | 
|  | 120 | options.own_backup = False | 
|  | 121 | else: | 
|  | 122 | options.own_backup = True | 
|  | 123 | shutil.copy(options.config, options.config_backup) | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 124 |  | 
| Gilles Peskine | bf7537d | 2019-01-29 18:52:16 +0100 | [diff] [blame] | 125 | def restore_config(options): | 
| Andrzej Kurek | e05b17f | 2022-09-28 03:17:56 -0400 | [diff] [blame] | 126 | """Restore the library configuration file (mbedtls_config.h). | 
| Gilles Peskine | bf7537d | 2019-01-29 18:52:16 +0100 | [diff] [blame] | 127 | Remove the backup file if it was saved earlier.""" | 
|  | 128 | if options.own_backup: | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 129 | shutil.move(options.config_backup, options.config) | 
|  | 130 | else: | 
|  | 131 | shutil.copy(options.config_backup, options.config) | 
| Gilles Peskine | bf7537d | 2019-01-29 18:52:16 +0100 | [diff] [blame] | 132 |  | 
| Andrzej Kurek | a44c5bc | 2022-10-16 12:52:20 -0400 | [diff] [blame] | 133 | def run_config_py(options, args): | 
| Andrzej Kurek | 3322c22 | 2022-10-04 15:02:41 -0400 | [diff] [blame] | 134 | """Run scripts/config.py with the specified arguments.""" | 
|  | 135 | cmd = ['scripts/config.py'] | 
| Andrzej Kurek | e05b17f | 2022-09-28 03:17:56 -0400 | [diff] [blame] | 136 | if options.config != 'include/mbedtls/mbedtls_config.h': | 
| Gilles Peskine | 54aa5c6 | 2019-01-29 18:46:34 +0100 | [diff] [blame] | 137 | cmd += ['--file', options.config] | 
|  | 138 | cmd += args | 
|  | 139 | log_command(cmd) | 
|  | 140 | subprocess.check_call(cmd) | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 141 |  | 
| Andrzej Kurek | 3322c22 | 2022-10-04 15:02:41 -0400 | [diff] [blame] | 142 | def set_reference_config(options): | 
|  | 143 | """Change the library configuration file (mbedtls_config.h) to the reference state. | 
|  | 144 | The reference state is the one from which the tested configurations are | 
|  | 145 | derived.""" | 
| Andrzej Kurek | a0cb4fa | 2022-10-14 07:06:43 -0400 | [diff] [blame] | 146 | # Turn off options that are not relevant to the tests and slow them down. | 
| Andrzej Kurek | a44c5bc | 2022-10-16 12:52:20 -0400 | [diff] [blame] | 147 | run_config_py(options, ['full']) | 
| Andrzej Kurek | a44c5bc | 2022-10-16 12:52:20 -0400 | [diff] [blame] | 148 | run_config_py(options, ['unset', 'MBEDTLS_TEST_HOOKS']) | 
| Andrzej Kurek | 3322c22 | 2022-10-04 15:02:41 -0400 | [diff] [blame] | 149 |  | 
|  | 150 | def collect_config_symbols(options): | 
|  | 151 | """Read the list of settings from mbedtls_config.h. | 
|  | 152 | Return them in a generator.""" | 
|  | 153 | with open(options.config, encoding="utf-8") as config_file: | 
|  | 154 | rx = re.compile(r'\s*(?://\s*)?#define\s+(\w+)\s*(?:$|/[/*])') | 
|  | 155 | for line in config_file: | 
|  | 156 | m = re.match(rx, line) | 
|  | 157 | if m: | 
|  | 158 | yield m.group(1) | 
|  | 159 |  | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 160 | class Job: | 
|  | 161 | """A job builds the library in a specific configuration and runs some tests.""" | 
|  | 162 | def __init__(self, name, config_settings, commands): | 
|  | 163 | """Build a job object. | 
|  | 164 | The job uses the configuration described by config_settings. This is a | 
|  | 165 | dictionary where the keys are preprocessor symbols and the values are | 
|  | 166 | booleans or strings. A boolean indicates whether or not to #define the | 
|  | 167 | symbol. With a string, the symbol is #define'd to that value. | 
|  | 168 | After setting the configuration, the job runs the programs specified by | 
|  | 169 | commands. This is a list of lists of strings; each list of string is a | 
|  | 170 | command name and its arguments and is passed to subprocess.call with | 
|  | 171 | shell=False.""" | 
|  | 172 | self.name = name | 
|  | 173 | self.config_settings = config_settings | 
|  | 174 | self.commands = commands | 
|  | 175 |  | 
| Gilles Peskine | 0fa7cbe | 2019-01-29 18:48:48 +0100 | [diff] [blame] | 176 | def announce(self, colors, what): | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 177 | '''Announce the start or completion of a job. | 
|  | 178 | If what is None, announce the start of the job. | 
|  | 179 | If what is True, announce that the job has passed. | 
|  | 180 | If what is False, announce that the job has failed.''' | 
|  | 181 | if what is True: | 
| Gilles Peskine | 0fa7cbe | 2019-01-29 18:48:48 +0100 | [diff] [blame] | 182 | log_line(self.name + ' PASSED', color=colors.green) | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 183 | elif what is False: | 
| Gilles Peskine | 0fa7cbe | 2019-01-29 18:48:48 +0100 | [diff] [blame] | 184 | log_line(self.name + ' FAILED', color=colors.red) | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 185 | else: | 
|  | 186 | log_line('starting ' + self.name) | 
|  | 187 |  | 
| Gilles Peskine | 54aa5c6 | 2019-01-29 18:46:34 +0100 | [diff] [blame] | 188 | def configure(self, options): | 
| Andrzej Kurek | a0cb4fa | 2022-10-14 07:06:43 -0400 | [diff] [blame] | 189 | '''Set library configuration options as required for the job.''' | 
| Andrzej Kurek | 3322c22 | 2022-10-04 15:02:41 -0400 | [diff] [blame] | 190 | set_reference_config(options) | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 191 | for key, value in sorted(self.config_settings.items()): | 
|  | 192 | if value is True: | 
|  | 193 | args = ['set', key] | 
|  | 194 | elif value is False: | 
|  | 195 | args = ['unset', key] | 
|  | 196 | else: | 
|  | 197 | args = ['set', key, value] | 
| Andrzej Kurek | a44c5bc | 2022-10-16 12:52:20 -0400 | [diff] [blame] | 198 | run_config_py(options, args) | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 199 |  | 
|  | 200 | def test(self, options): | 
|  | 201 | '''Run the job's build and test commands. | 
|  | 202 | Return True if all the commands succeed and False otherwise. | 
|  | 203 | If options.keep_going is false, stop as soon as one command fails. Otherwise | 
|  | 204 | run all the commands, except that if the first command fails, none of the | 
|  | 205 | other commands are run (typically, the first command is a build command | 
|  | 206 | and subsequent commands are tests that cannot run if the build failed).''' | 
|  | 207 | built = False | 
|  | 208 | success = True | 
|  | 209 | for command in self.commands: | 
| Gilles Peskine | 54aa5c6 | 2019-01-29 18:46:34 +0100 | [diff] [blame] | 210 | log_command(command) | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 211 | ret = subprocess.call(command) | 
|  | 212 | if ret != 0: | 
|  | 213 | if command[0] not in ['make', options.make_command]: | 
|  | 214 | log_line('*** [{}] Error {}'.format(' '.join(command), ret)) | 
|  | 215 | if not options.keep_going or not built: | 
|  | 216 | return False | 
|  | 217 | success = False | 
|  | 218 | built = True | 
|  | 219 | return success | 
|  | 220 |  | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 221 | # If the configuration option A requires B, make sure that | 
| Andrzej Kurek | 202932f | 2022-10-04 16:22:22 -0400 | [diff] [blame] | 222 | # B in REVERSE_DEPENDENCIES[A]. | 
| Gilles Peskine | 584c24a | 2019-01-29 19:30:40 +0100 | [diff] [blame] | 223 | # All the information here should be contained in check_config.h. This | 
|  | 224 | # file includes a copy because it changes rarely and it would be a pain | 
|  | 225 | # to extract automatically. | 
| Andrzej Kurek | 202932f | 2022-10-04 16:22:22 -0400 | [diff] [blame] | 226 | REVERSE_DEPENDENCIES = { | 
| Gilles Peskine | 34a1557 | 2019-01-29 23:12:28 +0100 | [diff] [blame] | 227 | 'MBEDTLS_AES_C': ['MBEDTLS_CTR_DRBG_C', | 
| Andrzej Kurek | e05b17f | 2022-09-28 03:17:56 -0400 | [diff] [blame] | 228 | 'MBEDTLS_NIST_KW_C'], | 
| Gilles Peskine | 34a1557 | 2019-01-29 23:12:28 +0100 | [diff] [blame] | 229 | 'MBEDTLS_CHACHA20_C': ['MBEDTLS_CHACHAPOLY_C'], | 
| Andrzej Kurek | e05b17f | 2022-09-28 03:17:56 -0400 | [diff] [blame] | 230 | 'MBEDTLS_ECDSA_C': ['MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED', | 
|  | 231 | 'MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA_ENABLED'], | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 232 | 'MBEDTLS_ECP_C': ['MBEDTLS_ECDSA_C', | 
|  | 233 | 'MBEDTLS_ECDH_C', | 
|  | 234 | 'MBEDTLS_ECJPAKE_C', | 
|  | 235 | 'MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA_ENABLED', | 
|  | 236 | 'MBEDTLS_KEY_EXCHANGE_ECDH_RSA_ENABLED', | 
|  | 237 | 'MBEDTLS_KEY_EXCHANGE_ECDHE_PSK_ENABLED', | 
|  | 238 | 'MBEDTLS_KEY_EXCHANGE_ECDHE_RSA_ENABLED', | 
| Andrzej Kurek | e05b17f | 2022-09-28 03:17:56 -0400 | [diff] [blame] | 239 | 'MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED', | 
| Ronald Cron | d8d2ea5 | 2022-10-04 15:48:06 +0200 | [diff] [blame] | 240 | 'MBEDTLS_KEY_EXCHANGE_ECJPAKE_ENABLED', | 
|  | 241 | 'MBEDTLS_SSL_TLS1_3_KEY_EXCHANGE_MODE_EPHEMERAL_ENABLED', | 
|  | 242 | 'MBEDTLS_SSL_TLS1_3_KEY_EXCHANGE_MODE_PSK_EPHEMERAL_ENABLED'], | 
| Gilles Peskine | 584c24a | 2019-01-29 19:30:40 +0100 | [diff] [blame] | 243 | 'MBEDTLS_ECP_DP_SECP256R1_ENABLED': ['MBEDTLS_KEY_EXCHANGE_ECJPAKE_ENABLED'], | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 244 | 'MBEDTLS_PKCS1_V21': ['MBEDTLS_X509_RSASSA_PSS_SUPPORT'], | 
|  | 245 | 'MBEDTLS_PKCS1_V15': ['MBEDTLS_KEY_EXCHANGE_DHE_RSA_ENABLED', | 
|  | 246 | 'MBEDTLS_KEY_EXCHANGE_ECDHE_RSA_ENABLED', | 
|  | 247 | 'MBEDTLS_KEY_EXCHANGE_RSA_PSK_ENABLED', | 
|  | 248 | 'MBEDTLS_KEY_EXCHANGE_RSA_ENABLED'], | 
|  | 249 | 'MBEDTLS_RSA_C': ['MBEDTLS_X509_RSASSA_PSS_SUPPORT', | 
|  | 250 | 'MBEDTLS_KEY_EXCHANGE_DHE_RSA_ENABLED', | 
|  | 251 | 'MBEDTLS_KEY_EXCHANGE_ECDHE_RSA_ENABLED', | 
|  | 252 | 'MBEDTLS_KEY_EXCHANGE_RSA_PSK_ENABLED', | 
| Andrzej Kurek | e05b17f | 2022-09-28 03:17:56 -0400 | [diff] [blame] | 253 | 'MBEDTLS_KEY_EXCHANGE_RSA_ENABLED', | 
|  | 254 | 'MBEDTLS_KEY_EXCHANGE_ECDH_RSA_ENABLED'], | 
| Gilles Peskine | 584c24a | 2019-01-29 19:30:40 +0100 | [diff] [blame] | 255 | 'MBEDTLS_SHA256_C': ['MBEDTLS_KEY_EXCHANGE_ECJPAKE_ENABLED', | 
| Andrzej Kurek | e05b17f | 2022-09-28 03:17:56 -0400 | [diff] [blame] | 256 | 'MBEDTLS_ENTROPY_FORCE_SHA256', | 
|  | 257 | 'MBEDTLS_SHA224_C', | 
|  | 258 | 'MBEDTLS_SHA256_USE_A64_CRYPTO_IF_PRESENT', | 
| Andrzej Kurek | 22b959d | 2022-10-16 12:51:41 -0400 | [diff] [blame] | 259 | 'MBEDTLS_SHA256_USE_A64_CRYPTO_ONLY', | 
|  | 260 | 'MBEDTLS_LMS_C', | 
|  | 261 | 'MBEDTLS_LMS_PRIVATE'], | 
| Andrzej Kurek | e05b17f | 2022-09-28 03:17:56 -0400 | [diff] [blame] | 262 | 'MBEDTLS_SHA512_C': ['MBEDTLS_SHA384_C', | 
|  | 263 | 'MBEDTLS_SHA512_USE_A64_CRYPTO_IF_PRESENT', | 
|  | 264 | 'MBEDTLS_SHA512_USE_A64_CRYPTO_ONLY'], | 
|  | 265 | 'MBEDTLS_SHA224_C': ['MBEDTLS_KEY_EXCHANGE_ECJPAKE_ENABLED', | 
|  | 266 | 'MBEDTLS_ENTROPY_FORCE_SHA256', | 
|  | 267 | 'MBEDTLS_SHA256_C', | 
|  | 268 | 'MBEDTLS_SHA256_USE_A64_CRYPTO_IF_PRESENT', | 
|  | 269 | 'MBEDTLS_SHA256_USE_A64_CRYPTO_ONLY'], | 
| Andrzej Kurek | e05b17f | 2022-09-28 03:17:56 -0400 | [diff] [blame] | 270 | 'MBEDTLS_X509_RSASSA_PSS_SUPPORT': [] | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 271 | } | 
|  | 272 |  | 
| Andrzej Kurek | e05b17f | 2022-09-28 03:17:56 -0400 | [diff] [blame] | 273 | # If an option is tested in an exclusive test, alter the following defines. | 
| Andrzej Kurek | 01af84a | 2022-10-09 05:29:44 -0400 | [diff] [blame] | 274 | # These are not necessarily dependencies, but just minimal required changes | 
| Andrzej Kurek | e05b17f | 2022-09-28 03:17:56 -0400 | [diff] [blame] | 275 | # if a given define is the only one enabled from an exclusive group. | 
| Andrzej Kurek | 202932f | 2022-10-04 16:22:22 -0400 | [diff] [blame] | 276 | EXCLUSIVE_GROUPS = { | 
| Andrzej Kurek | 65b2ac1 | 2022-10-14 08:09:16 -0400 | [diff] [blame] | 277 | 'MBEDTLS_SHA256_C': ['+MBEDTLS_SHA224_C'], | 
|  | 278 | 'MBEDTLS_SHA384_C': ['+MBEDTLS_SHA512_C'], | 
|  | 279 | 'MBEDTLS_SHA512_C': ['-MBEDTLS_SSL_COOKIE_C', | 
|  | 280 | '-MBEDTLS_SSL_PROTO_TLS1_3'], | 
|  | 281 | 'MBEDTLS_ECP_DP_CURVE448_ENABLED': ['-MBEDTLS_ECDSA_C', | 
|  | 282 | '-MBEDTLS_ECDSA_DETERMINISTIC', | 
|  | 283 | '-MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED', | 
|  | 284 | '-MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA_ENABLED', | 
|  | 285 | '-MBEDTLS_ECJPAKE_C', | 
|  | 286 | '-MBEDTLS_KEY_EXCHANGE_ECJPAKE_ENABLED'], | 
|  | 287 | 'MBEDTLS_ECP_DP_CURVE25519_ENABLED': ['-MBEDTLS_ECDSA_C', | 
|  | 288 | '-MBEDTLS_ECDSA_DETERMINISTIC', | 
|  | 289 | '-MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED', | 
|  | 290 | '-MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA_ENABLED', | 
|  | 291 | '-MBEDTLS_ECJPAKE_C', | 
|  | 292 | '-MBEDTLS_KEY_EXCHANGE_ECJPAKE_ENABLED'], | 
|  | 293 | 'MBEDTLS_ARIA_C': ['-MBEDTLS_CMAC_C'], | 
|  | 294 | 'MBEDTLS_CAMELLIA_C': ['-MBEDTLS_CMAC_C'], | 
|  | 295 | 'MBEDTLS_CHACHA20_C': ['-MBEDTLS_CMAC_C', '-MBEDTLS_CCM_C', '-MBEDTLS_GCM_C'], | 
|  | 296 | 'MBEDTLS_DES_C': ['-MBEDTLS_CCM_C', | 
|  | 297 | '-MBEDTLS_GCM_C', | 
|  | 298 | '-MBEDTLS_SSL_TICKET_C', | 
|  | 299 | '-MBEDTLS_SSL_CONTEXT_SERIALIZATION'], | 
| Andrzej Kurek | e05b17f | 2022-09-28 03:17:56 -0400 | [diff] [blame] | 300 | } | 
|  | 301 | def handle_exclusive_groups(config_settings, symbol): | 
|  | 302 | """For every symbol tested in an exclusive group check if there are other | 
|  | 303 | defines to be altered. """ | 
| Andrzej Kurek | 202932f | 2022-10-04 16:22:22 -0400 | [diff] [blame] | 304 | for dep in EXCLUSIVE_GROUPS.get(symbol, []): | 
| Andrzej Kurek | 65b2ac1 | 2022-10-14 08:09:16 -0400 | [diff] [blame] | 305 | unset = dep.startswith('-') | 
|  | 306 | dep = dep[1:] | 
| Andrzej Kurek | e05b17f | 2022-09-28 03:17:56 -0400 | [diff] [blame] | 307 | config_settings[dep] = not unset | 
|  | 308 |  | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 309 | def turn_off_dependencies(config_settings): | 
|  | 310 | """For every option turned off config_settings, also turn off what depends on it. | 
|  | 311 | An option O is turned off if config_settings[O] is False.""" | 
|  | 312 | for key, value in sorted(config_settings.items()): | 
|  | 313 | if value is not False: | 
|  | 314 | continue | 
| Andrzej Kurek | 202932f | 2022-10-04 16:22:22 -0400 | [diff] [blame] | 315 | for dep in REVERSE_DEPENDENCIES.get(key, []): | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 316 | config_settings[dep] = False | 
|  | 317 |  | 
| Andrzej Kurek | 228b12c | 2022-10-06 18:52:44 -0400 | [diff] [blame] | 318 | class BaseDomain: # pylint: disable=too-few-public-methods, unused-argument | 
|  | 319 | """A base class for all domains.""" | 
|  | 320 | def __init__(self, symbols, commands, exclude): | 
|  | 321 | """Initialize the jobs container""" | 
|  | 322 | self.jobs = [] | 
|  | 323 |  | 
|  | 324 | class ExclusiveDomain(BaseDomain): # pylint: disable=too-few-public-methods | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 325 | """A domain consisting of a set of conceptually-equivalent settings. | 
|  | 326 | Establish a list of configuration symbols. For each symbol, run a test job | 
| Andrzej Kurek | fe46949 | 2022-10-06 16:57:38 -0400 | [diff] [blame] | 327 | with this symbol set and the others unset.""" | 
| Gilles Peskine | b1284cf | 2019-01-29 18:56:03 +0100 | [diff] [blame] | 328 | def __init__(self, symbols, commands, exclude=None): | 
|  | 329 | """Build a domain for the specified list of configuration symbols. | 
| Andrzej Kurek | fe46949 | 2022-10-06 16:57:38 -0400 | [diff] [blame] | 330 | The domain contains a set of jobs that enable one of the elements | 
|  | 331 | of symbols and disable the others. | 
| Gilles Peskine | b1284cf | 2019-01-29 18:56:03 +0100 | [diff] [blame] | 332 | Each job runs the specified commands. | 
|  | 333 | If exclude is a regular expression, skip generated jobs whose description | 
|  | 334 | would match this regular expression.""" | 
| Andrzej Kurek | 228b12c | 2022-10-06 18:52:44 -0400 | [diff] [blame] | 335 | super().__init__(symbols, commands, exclude) | 
| Andrzej Kurek | fe46949 | 2022-10-06 16:57:38 -0400 | [diff] [blame] | 336 | base_config_settings = {} | 
|  | 337 | for symbol in symbols: | 
|  | 338 | base_config_settings[symbol] = False | 
|  | 339 | for symbol in symbols: | 
|  | 340 | description = symbol | 
|  | 341 | if exclude and re.match(exclude, description): | 
|  | 342 | continue | 
|  | 343 | config_settings = base_config_settings.copy() | 
|  | 344 | config_settings[symbol] = True | 
|  | 345 | handle_exclusive_groups(config_settings, symbol) | 
|  | 346 | turn_off_dependencies(config_settings) | 
|  | 347 | job = Job(description, config_settings, commands) | 
|  | 348 | self.jobs.append(job) | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 349 |  | 
| Andrzej Kurek | 228b12c | 2022-10-06 18:52:44 -0400 | [diff] [blame] | 350 | class ComplementaryDomain(BaseDomain): # pylint: disable=too-few-public-methods | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 351 | """A domain consisting of a set of loosely-related settings. | 
|  | 352 | Establish a list of configuration symbols. For each symbol, run a test job | 
| Andrzej Kurek | a0cb4fa | 2022-10-14 07:06:43 -0400 | [diff] [blame] | 353 | with this symbol unset. | 
|  | 354 | If exclude is a regular expression, skip generated jobs whose description | 
|  | 355 | would match this regular expression.""" | 
| Andrzej Kurek | 228b12c | 2022-10-06 18:52:44 -0400 | [diff] [blame] | 356 | def __init__(self, symbols, commands, exclude=None): | 
| Gilles Peskine | b1284cf | 2019-01-29 18:56:03 +0100 | [diff] [blame] | 357 | """Build a domain for the specified list of configuration symbols. | 
|  | 358 | Each job in the domain disables one of the specified symbols. | 
|  | 359 | Each job runs the specified commands.""" | 
| Andrzej Kurek | 228b12c | 2022-10-06 18:52:44 -0400 | [diff] [blame] | 360 | super().__init__(symbols, commands, exclude) | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 361 | for symbol in symbols: | 
|  | 362 | description = '!' + symbol | 
| Andrzej Kurek | 228b12c | 2022-10-06 18:52:44 -0400 | [diff] [blame] | 363 | if exclude and re.match(exclude, description): | 
|  | 364 | continue | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 365 | config_settings = {symbol: False} | 
|  | 366 | turn_off_dependencies(config_settings) | 
|  | 367 | job = Job(description, config_settings, commands) | 
|  | 368 | self.jobs.append(job) | 
|  | 369 |  | 
| Andrzej Kurek | 228b12c | 2022-10-06 18:52:44 -0400 | [diff] [blame] | 370 | class DualDomain(ExclusiveDomain, ComplementaryDomain): # pylint: disable=too-few-public-methods | 
| Andrzej Kurek | a0cb4fa | 2022-10-14 07:06:43 -0400 | [diff] [blame] | 371 | """A domain that contains both the ExclusiveDomain and BaseDomain tests. | 
| Andrzej Kurek | f4b1867 | 2022-10-14 07:57:00 -0400 | [diff] [blame] | 372 | Both parent class __init__ calls are performed in any order and | 
| Andrzej Kurek | a0cb4fa | 2022-10-14 07:06:43 -0400 | [diff] [blame] | 373 | each call adds respective jobs. The job array initialization is done once in | 
|  | 374 | BaseDomain, before the parent __init__ calls.""" | 
| Andrzej Kurek | 228b12c | 2022-10-06 18:52:44 -0400 | [diff] [blame] | 375 |  | 
| Andrzej Kurek | 3322c22 | 2022-10-04 15:02:41 -0400 | [diff] [blame] | 376 | class CipherInfo: # pylint: disable=too-few-public-methods | 
| Gilles Peskine | 34a1557 | 2019-01-29 23:12:28 +0100 | [diff] [blame] | 377 | """Collect data about cipher.h.""" | 
| Andrzej Kurek | 3322c22 | 2022-10-04 15:02:41 -0400 | [diff] [blame] | 378 | def __init__(self): | 
| Gilles Peskine | 34a1557 | 2019-01-29 23:12:28 +0100 | [diff] [blame] | 379 | self.base_symbols = set() | 
| Andrzej Kurek | 3322c22 | 2022-10-04 15:02:41 -0400 | [diff] [blame] | 380 | with open('include/mbedtls/cipher.h', encoding="utf-8") as fh: | 
| Gilles Peskine | 34a1557 | 2019-01-29 23:12:28 +0100 | [diff] [blame] | 381 | for line in fh: | 
|  | 382 | m = re.match(r' *MBEDTLS_CIPHER_ID_(\w+),', line) | 
|  | 383 | if m and m.group(1) not in ['NONE', 'NULL', '3DES']: | 
|  | 384 | self.base_symbols.add('MBEDTLS_' + m.group(1) + '_C') | 
|  | 385 |  | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 386 | class DomainData: | 
| Andrzej Kurek | 3322c22 | 2022-10-04 15:02:41 -0400 | [diff] [blame] | 387 | """A container for domains and jobs, used to structurize testing.""" | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 388 | def config_symbols_matching(self, regexp): | 
| Andrzej Kurek | e05b17f | 2022-09-28 03:17:56 -0400 | [diff] [blame] | 389 | """List the mbedtls_config.h settings matching regexp.""" | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 390 | return [symbol for symbol in self.all_config_symbols | 
|  | 391 | if re.match(regexp, symbol)] | 
|  | 392 |  | 
|  | 393 | def __init__(self, options): | 
|  | 394 | """Gather data about the library and establish a list of domains to test.""" | 
|  | 395 | build_command = [options.make_command, 'CFLAGS=-Werror'] | 
|  | 396 | build_and_test = [build_command, [options.make_command, 'test']] | 
| Andrzej Kurek | 3322c22 | 2022-10-04 15:02:41 -0400 | [diff] [blame] | 397 | self.all_config_symbols = set(collect_config_symbols(options)) | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 398 | # Find hash modules by name. | 
|  | 399 | hash_symbols = self.config_symbols_matching(r'MBEDTLS_(MD|RIPEMD|SHA)[0-9]+_C\Z') | 
|  | 400 | # Find elliptic curve enabling macros by name. | 
|  | 401 | curve_symbols = self.config_symbols_matching(r'MBEDTLS_ECP_DP_\w+_ENABLED\Z') | 
|  | 402 | # Find key exchange enabling macros by name. | 
|  | 403 | key_exchange_symbols = self.config_symbols_matching(r'MBEDTLS_KEY_EXCHANGE_\w+_ENABLED\Z') | 
| Gilles Peskine | 34a1557 | 2019-01-29 23:12:28 +0100 | [diff] [blame] | 404 | # Find cipher IDs (block permutations and stream ciphers --- chaining | 
|  | 405 | # and padding modes are exercised separately) information by parsing | 
| Andrzej Kurek | e05b17f | 2022-09-28 03:17:56 -0400 | [diff] [blame] | 406 | # cipher.h, as the information is not readily available in mbedtls_config.h. | 
| Andrzej Kurek | 3322c22 | 2022-10-04 15:02:41 -0400 | [diff] [blame] | 407 | cipher_info = CipherInfo() | 
| Gilles Peskine | 34a1557 | 2019-01-29 23:12:28 +0100 | [diff] [blame] | 408 | # Find block cipher chaining and padding mode enabling macros by name. | 
|  | 409 | cipher_chaining_symbols = self.config_symbols_matching(r'MBEDTLS_CIPHER_MODE_\w+\Z') | 
|  | 410 | cipher_padding_symbols = self.config_symbols_matching(r'MBEDTLS_CIPHER_PADDING_\w+\Z') | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 411 | self.domains = { | 
| Gilles Peskine | 34a1557 | 2019-01-29 23:12:28 +0100 | [diff] [blame] | 412 | # Cipher IDs, chaining modes and padding modes. Run the test suites. | 
|  | 413 | 'cipher_id': ExclusiveDomain(cipher_info.base_symbols, | 
|  | 414 | build_and_test), | 
|  | 415 | 'cipher_chaining': ExclusiveDomain(cipher_chaining_symbols, | 
|  | 416 | build_and_test), | 
|  | 417 | 'cipher_padding': ExclusiveDomain(cipher_padding_symbols, | 
|  | 418 | build_and_test), | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 419 | # Elliptic curves. Run the test suites. | 
|  | 420 | 'curves': ExclusiveDomain(curve_symbols, build_and_test), | 
| Andrzej Kurek | a0cb4fa | 2022-10-14 07:06:43 -0400 | [diff] [blame] | 421 | # Hash algorithms. Exclude three groups: | 
|  | 422 | # - Exclusive domain of MD, RIPEMD, SHA1 (obsolete); | 
|  | 423 | # - Exclusive domain of SHA224 (tested with and depends on SHA256); | 
|  | 424 | # - Complementary domain of SHA224 and SHA384 - tested with and depend | 
|  | 425 | #       on SHA256 and SHA512, respectively. | 
| Andrzej Kurek | 228b12c | 2022-10-06 18:52:44 -0400 | [diff] [blame] | 426 | 'hashes': DualDomain(hash_symbols, build_and_test, | 
| Andrzej Kurek | a0cb4fa | 2022-10-14 07:06:43 -0400 | [diff] [blame] | 427 | exclude=r'MBEDTLS_(MD|RIPEMD|SHA1_)' \ | 
|  | 428 | '|MBEDTLS_SHA224_'\ | 
|  | 429 | '|!MBEDTLS_(SHA224_|SHA384_)'), | 
| Gilles Peskine | c3b4dee | 2019-01-29 19:33:05 +0100 | [diff] [blame] | 430 | # Key exchange types. Only build the library and the sample | 
|  | 431 | # programs. | 
|  | 432 | 'kex': ExclusiveDomain(key_exchange_symbols, | 
|  | 433 | [build_command + ['lib'], | 
|  | 434 | build_command + ['-C', 'programs']]), | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 435 | 'pkalgs': ComplementaryDomain(['MBEDTLS_ECDSA_C', | 
|  | 436 | 'MBEDTLS_ECP_C', | 
|  | 437 | 'MBEDTLS_PKCS1_V21', | 
|  | 438 | 'MBEDTLS_PKCS1_V15', | 
|  | 439 | 'MBEDTLS_RSA_C', | 
|  | 440 | 'MBEDTLS_X509_RSASSA_PSS_SUPPORT'], | 
|  | 441 | build_and_test), | 
|  | 442 | } | 
|  | 443 | self.jobs = {} | 
|  | 444 | for domain in self.domains.values(): | 
|  | 445 | for job in domain.jobs: | 
|  | 446 | self.jobs[job.name] = job | 
|  | 447 |  | 
|  | 448 | def get_jobs(self, name): | 
|  | 449 | """Return the list of jobs identified by the given name. | 
|  | 450 | A name can either be the name of a domain or the name of one specific job.""" | 
|  | 451 | if name in self.domains: | 
|  | 452 | return sorted(self.domains[name].jobs, key=lambda job: job.name) | 
|  | 453 | else: | 
|  | 454 | return [self.jobs[name]] | 
|  | 455 |  | 
| Gilles Peskine | 0fa7cbe | 2019-01-29 18:48:48 +0100 | [diff] [blame] | 456 | def run(options, job, colors=NO_COLORS): | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 457 | """Run the specified job (a Job instance).""" | 
|  | 458 | subprocess.check_call([options.make_command, 'clean']) | 
| Gilles Peskine | 0fa7cbe | 2019-01-29 18:48:48 +0100 | [diff] [blame] | 459 | job.announce(colors, None) | 
| Gilles Peskine | 54aa5c6 | 2019-01-29 18:46:34 +0100 | [diff] [blame] | 460 | job.configure(options) | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 461 | success = job.test(options) | 
| Gilles Peskine | 0fa7cbe | 2019-01-29 18:48:48 +0100 | [diff] [blame] | 462 | job.announce(colors, success) | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 463 | return success | 
|  | 464 |  | 
| Andrzej Kurek | 3322c22 | 2022-10-04 15:02:41 -0400 | [diff] [blame] | 465 | def run_tests(options, domain_data): | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 466 | """Run the desired jobs. | 
|  | 467 | domain_data should be a DomainData instance that describes the available | 
|  | 468 | domains and jobs. | 
| Andrzej Kurek | b8a97e7 | 2022-10-17 08:39:09 -0400 | [diff] [blame] | 469 | Run the jobs listed in options.tasks.""" | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 470 | if not hasattr(options, 'config_backup'): | 
|  | 471 | options.config_backup = options.config + '.bak' | 
| Gilles Peskine | 0fa7cbe | 2019-01-29 18:48:48 +0100 | [diff] [blame] | 472 | colors = Colors(options) | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 473 | jobs = [] | 
|  | 474 | failures = [] | 
|  | 475 | successes = [] | 
| Andrzej Kurek | b8a97e7 | 2022-10-17 08:39:09 -0400 | [diff] [blame] | 476 | for name in options.tasks: | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 477 | jobs += domain_data.get_jobs(name) | 
|  | 478 | backup_config(options) | 
|  | 479 | try: | 
|  | 480 | for job in jobs: | 
| Gilles Peskine | 0fa7cbe | 2019-01-29 18:48:48 +0100 | [diff] [blame] | 481 | success = run(options, job, colors=colors) | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 482 | if not success: | 
|  | 483 | if options.keep_going: | 
|  | 484 | failures.append(job.name) | 
|  | 485 | else: | 
|  | 486 | return False | 
|  | 487 | else: | 
|  | 488 | successes.append(job.name) | 
| Gilles Peskine | bf7537d | 2019-01-29 18:52:16 +0100 | [diff] [blame] | 489 | restore_config(options) | 
|  | 490 | except: | 
|  | 491 | # Restore the configuration, except in stop-on-error mode if there | 
|  | 492 | # was an error, where we leave the failing configuration up for | 
|  | 493 | # developer convenience. | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 494 | if options.keep_going: | 
| Gilles Peskine | bf7537d | 2019-01-29 18:52:16 +0100 | [diff] [blame] | 495 | restore_config(options) | 
|  | 496 | raise | 
| Gilles Peskine | e85163b | 2019-01-29 18:50:03 +0100 | [diff] [blame] | 497 | if successes: | 
|  | 498 | log_line('{} passed'.format(' '.join(successes)), color=colors.bold_green) | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 499 | if failures: | 
| Gilles Peskine | e85163b | 2019-01-29 18:50:03 +0100 | [diff] [blame] | 500 | log_line('{} FAILED'.format(' '.join(failures)), color=colors.bold_red) | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 501 | return False | 
|  | 502 | else: | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 503 | return True | 
|  | 504 |  | 
| Andrzej Kurek | 3322c22 | 2022-10-04 15:02:41 -0400 | [diff] [blame] | 505 | def main(): | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 506 | try: | 
| Andrzej Kurek | 01af84a | 2022-10-09 05:29:44 -0400 | [diff] [blame] | 507 | parser = argparse.ArgumentParser( | 
|  | 508 | formatter_class=argparse.RawDescriptionHelpFormatter, | 
|  | 509 | description= | 
|  | 510 | "Test Mbed TLS with a subset of algorithms.\n\n" | 
|  | 511 | "Example usage:\n" | 
| Andrzej Kurek | 629c412 | 2022-10-17 08:34:40 -0400 | [diff] [blame] | 512 | r"./tests/scripts/depends.py \!MBEDTLS_SHA1_C MBEDTLS_SHA256_C""\n" | 
| Andrzej Kurek | 01af84a | 2022-10-09 05:29:44 -0400 | [diff] [blame] | 513 | "./tests/scripts/depends.py MBEDTLS_AES_C hashes\n" | 
|  | 514 | "./tests/scripts/depends.py cipher_id cipher_chaining\n") | 
| Gilles Peskine | 0fa7cbe | 2019-01-29 18:48:48 +0100 | [diff] [blame] | 515 | parser.add_argument('--color', metavar='WHEN', | 
|  | 516 | help='Colorize the output (always/auto/never)', | 
|  | 517 | choices=['always', 'auto', 'never'], default='auto') | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 518 | parser.add_argument('-c', '--config', metavar='FILE', | 
|  | 519 | help='Configuration file to modify', | 
| Andrzej Kurek | e05b17f | 2022-09-28 03:17:56 -0400 | [diff] [blame] | 520 | default='include/mbedtls/mbedtls_config.h') | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 521 | parser.add_argument('-C', '--directory', metavar='DIR', | 
|  | 522 | help='Change to this directory before anything else', | 
|  | 523 | default='.') | 
|  | 524 | parser.add_argument('-k', '--keep-going', | 
|  | 525 | help='Try all configurations even if some fail (default)', | 
|  | 526 | action='store_true', dest='keep_going', default=True) | 
|  | 527 | parser.add_argument('-e', '--no-keep-going', | 
|  | 528 | help='Stop as soon as a configuration fails', | 
|  | 529 | action='store_false', dest='keep_going') | 
|  | 530 | parser.add_argument('--list-jobs', | 
|  | 531 | help='List supported jobs and exit', | 
|  | 532 | action='append_const', dest='list', const='jobs') | 
|  | 533 | parser.add_argument('--list-domains', | 
|  | 534 | help='List supported domains and exit', | 
|  | 535 | action='append_const', dest='list', const='domains') | 
|  | 536 | parser.add_argument('--make-command', metavar='CMD', | 
|  | 537 | help='Command to run instead of make (e.g. gmake)', | 
|  | 538 | action='store', default='make') | 
| Andrzej Kurek | b8a97e7 | 2022-10-17 08:39:09 -0400 | [diff] [blame] | 539 | parser.add_argument('tasks', metavar='TASKS', nargs='*', | 
|  | 540 | help='The domain(s) or job(s) to test (default: all).', | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 541 | default=True) | 
|  | 542 | options = parser.parse_args() | 
|  | 543 | os.chdir(options.directory) | 
|  | 544 | domain_data = DomainData(options) | 
| Andrzej Kurek | b8a97e7 | 2022-10-17 08:39:09 -0400 | [diff] [blame] | 545 | if options.tasks is True: | 
|  | 546 | options.tasks = sorted(domain_data.domains.keys()) | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 547 | if options.list: | 
| Andrzej Kurek | 3322c22 | 2022-10-04 15:02:41 -0400 | [diff] [blame] | 548 | for arg in options.list: | 
|  | 549 | for domain_name in sorted(getattr(domain_data, arg).keys()): | 
|  | 550 | print(domain_name) | 
|  | 551 | sys.exit(0) | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 552 | else: | 
| Andrzej Kurek | 3322c22 | 2022-10-04 15:02:41 -0400 | [diff] [blame] | 553 | sys.exit(0 if run_tests(options, domain_data) else 1) | 
|  | 554 | except Exception: # pylint: disable=broad-except | 
| Gilles Peskine | b39e3ec | 2019-01-29 08:50:20 +0100 | [diff] [blame] | 555 | traceback.print_exc() | 
| Andrzej Kurek | 3322c22 | 2022-10-04 15:02:41 -0400 | [diff] [blame] | 556 | sys.exit(3) | 
|  | 557 |  | 
|  | 558 | if __name__ == '__main__': | 
|  | 559 | main() |