| Fredrik Hesse | cc207bc | 2021-09-28 21:06:08 +0200 | [diff] [blame] | 1 | # Mbed TLS driver interface test strategy | 
| Gilles Peskine | b26c8d8 | 2019-09-04 19:26:17 +0200 | [diff] [blame] | 2 |  | 
| Fredrik Hesse | cc207bc | 2021-09-28 21:06:08 +0200 | [diff] [blame] | 3 | This document describes the test strategy for the driver interfaces in Mbed TLS. Mbed TLS has interfaces for secure element drivers, accelerator drivers and entropy drivers. This document is about testing Mbed TLS itself; testing drivers is out of scope. | 
| Gilles Peskine | b26c8d8 | 2019-09-04 19:26:17 +0200 | [diff] [blame] | 4 |  | 
|  | 5 | The driver interfaces are standardized through PSA Cryptography functional specifications. | 
|  | 6 |  | 
| Gilles Peskine | f0e2853 | 2020-11-30 17:51:14 +0100 | [diff] [blame] | 7 | ## Secure element driver interface testing | 
| Gilles Peskine | b26c8d8 | 2019-09-04 19:26:17 +0200 | [diff] [blame] | 8 |  | 
| Gilles Peskine | f0e2853 | 2020-11-30 17:51:14 +0100 | [diff] [blame] | 9 | ### Secure element driver interfaces | 
|  | 10 |  | 
|  | 11 | #### Opaque driver interface | 
|  | 12 |  | 
|  | 13 | The [unified driver interface](../../proposed/psa-driver-interface.md) supports both transparent drivers (for accelerators) and opaque drivers (for secure elements). | 
|  | 14 |  | 
|  | 15 | Drivers exposing this interface need to be registered at compile time by declaring their JSON description file. | 
|  | 16 |  | 
|  | 17 | #### Dynamic secure element driver interface | 
|  | 18 |  | 
| Emmanuel Ferdman | 5c0c515 | 2024-11-17 02:34:52 -0800 | [diff] [blame] | 19 | The dynamic secure element driver interface (SE interface for short) is defined by [`psa/crypto_se_driver.h`](../../../tf-psa-crypto/include/psa/crypto_se_driver.h). This is an interface between Mbed TLS and one or more third-party drivers. | 
| Gilles Peskine | b26c8d8 | 2019-09-04 19:26:17 +0200 | [diff] [blame] | 20 |  | 
| Fredrik Hesse | cc207bc | 2021-09-28 21:06:08 +0200 | [diff] [blame] | 21 | The SE interface consists of one function provided by Mbed TLS (`psa_register_se_driver`) and many functions that drivers must implement. To make a driver usable by Mbed TLS, the initialization code must call `psa_register_se_driver` with a structure that describes the driver. The structure mostly contains function pointers, pointing to the driver's methods. All calls to a driver function are triggered by a call to a PSA crypto API function. | 
| Gilles Peskine | b26c8d8 | 2019-09-04 19:26:17 +0200 | [diff] [blame] | 22 |  | 
| Gilles Peskine | 92bcfdb | 2019-09-04 19:26:50 +0200 | [diff] [blame] | 23 | ### SE driver interface unit tests | 
|  | 24 |  | 
|  | 25 | This section describes unit tests that must be implemented to validate the secure element driver interface. Note that a test case may cover multiple requirements; for example a “good case” test can validate that the proper function is called, that it receives the expected inputs and that it produces the expected outputs. | 
|  | 26 |  | 
|  | 27 | Many SE driver interface unit tests could be covered by running the existing API tests with a key in a secure element. | 
|  | 28 |  | 
|  | 29 | #### SE driver registration | 
|  | 30 |  | 
| Gilles Peskine | f0e2853 | 2020-11-30 17:51:14 +0100 | [diff] [blame] | 31 | This applies to dynamic drivers only. | 
|  | 32 |  | 
| Gilles Peskine | 92bcfdb | 2019-09-04 19:26:50 +0200 | [diff] [blame] | 33 | * Test `psa_register_se_driver` with valid and with invalid arguments. | 
|  | 34 | * Make at least one failing call to `psa_register_se_driver` followed by a successful call. | 
|  | 35 | * Make at least one test that successfully registers the maximum number of drivers and fails to register one more. | 
|  | 36 |  | 
|  | 37 | #### Dispatch to SE driver | 
|  | 38 |  | 
|  | 39 | For each API function that can lead to a driver call (more precisely, for each driver method call site, but this is practically equivalent): | 
|  | 40 |  | 
|  | 41 | * Make at least one test with a key in a secure element that checks that the driver method is called. A few API functions involve multiple driver methods; these should validate that all the expected driver methods are called. | 
|  | 42 | * Make at least one test with a key that is not in a secure element that checks that the driver method is not called. | 
|  | 43 | * Make at least one test with a key in a secure element with a driver that does not have the requisite method (i.e. the method pointer is `NULL`) but has the substructure containing that method, and check that the return value is `PSA_ERROR_NOT_SUPPORTED`. | 
|  | 44 | * Make at least one test with a key in a secure element with a driver that does not have the substructure containing that method (i.e. the pointer to the substructure is `NULL`), and check that the return value is `PSA_ERROR_NOT_SUPPORTED`. | 
|  | 45 | * At least one test should register multiple drivers with a key in each driver and check that the expected driver is called. This does not need to be done for all operations (use a white-box approach to determine if operations may use different code paths to choose the driver). | 
|  | 46 | * At least one test should register the same driver structure with multiple lifetime values and check that the driver receives the expected lifetime value. | 
|  | 47 |  | 
|  | 48 | Some methods only make sense as a group (for example a driver that provides the MAC methods must provide all or none). In those cases, test with all of them null and none of them null. | 
|  | 49 |  | 
|  | 50 | #### SE driver inputs | 
|  | 51 |  | 
|  | 52 | For each API function that can lead to a driver call (more precisely, for each driver method call site, but this is practically equivalent): | 
|  | 53 |  | 
|  | 54 | * Wherever the specification guarantees parameters that satisfy certain preconditions, check these preconditions whenever practical. | 
|  | 55 | * If the API function can take parameters that are invalid and must not reach the driver, call the API function with such parameters and verify that the driver method is not called. | 
| Gilles Peskine | 8b193c1 | 2019-09-05 17:58:13 +0200 | [diff] [blame] | 56 | * Check that the expected inputs reach the driver. This may be implicit in a test that checks the outputs if the only realistic way to obtain the correct outputs is to start from the expected inputs (as is often the case for cryptographic material, but not for metadata). | 
| Gilles Peskine | 92bcfdb | 2019-09-04 19:26:50 +0200 | [diff] [blame] | 57 |  | 
|  | 58 | #### SE driver outputs | 
|  | 59 |  | 
| Fredrik Hesse | cc207bc | 2021-09-28 21:06:08 +0200 | [diff] [blame] | 60 | For each API function that leads to a driver call, call it with parameters that cause a driver to be invoked and check how Mbed TLS handles the outputs. | 
| Gilles Peskine | 92bcfdb | 2019-09-04 19:26:50 +0200 | [diff] [blame] | 61 |  | 
|  | 62 | * Correct outputs. | 
|  | 63 | * Incorrect outputs such as an invalid output length. | 
|  | 64 | * Expected errors (e.g. `PSA_ERROR_INVALID_SIGNATURE` from a signature verification method). | 
|  | 65 | * Unexpected errors. At least test that if the driver returns `PSA_ERROR_GENERIC_ERROR`, this is propagated correctly. | 
|  | 66 |  | 
|  | 67 | Key creation functions invoke multiple methods and need more complex error handling: | 
|  | 68 |  | 
|  | 69 | * Check the consequence of errors detected at each stage (slot number allocation or validation, key creation method, storage accesses). | 
|  | 70 | * Check that the storage ends up in the expected state. At least make sure that no intermediate file remains after a failure. | 
|  | 71 |  | 
|  | 72 | #### Persistence of SE keys | 
|  | 73 |  | 
|  | 74 | The following tests must be performed at least one for each key creation method (import, generate, ...). | 
|  | 75 |  | 
|  | 76 | * Test that keys in a secure element survive `psa_close_key(); psa_open_key()`. | 
|  | 77 | * Test that keys in a secure element survive `mbedtls_psa_crypto_free(); psa_crypto_init()`. | 
|  | 78 | * Test that the driver's persistent data survives `mbedtls_psa_crypto_free(); psa_crypto_init()`. | 
|  | 79 | * Test that `psa_destroy_key()` does not leave any trace of the key. | 
|  | 80 |  | 
|  | 81 | #### Resilience for SE drivers | 
|  | 82 |  | 
|  | 83 | Creating or removing a key in a secure element involves multiple storage modifications (M<sub>1</sub>, ..., M<sub>n</sub>). If the operation is interrupted by a reset at any point, it must be either rolled back or completed. | 
|  | 84 |  | 
|  | 85 | * For each potential interruption point (before M<sub>1</sub>, between M<sub>1</sub> and M<sub>2</sub>, ..., after M<sub>n</sub>), call `mbedtls_psa_crypto_free(); psa_crypto_init()` at that point and check that this either rolls back or completes the operation that was started. | 
|  | 86 | * This must be done for each key creation method and for key destruction. | 
|  | 87 | * This must be done for each possible flow, including error cases (e.g. a key creation that fails midway due to `OUT_OF_MEMORY`). | 
|  | 88 | * The recovery during `psa_crypto_init` can itself be interrupted. Test those interruptions too. | 
|  | 89 | * Two things need to be tested: the key that is being created or destroyed, and the driver's persistent storage. | 
| bootstrap-prime | 6dbbf44 | 2022-05-17 19:30:44 -0400 | [diff] [blame] | 90 | * Check both that the storage has the expected content (this can be done by e.g. using a key that is supposed to be present) and does not have any unexpected content (for keys, this can be done by checking that `psa_open_key` fails with `PSA_ERROR_DOES_NOT_EXIST`). | 
| Gilles Peskine | 92bcfdb | 2019-09-04 19:26:50 +0200 | [diff] [blame] | 91 |  | 
|  | 92 | This requires instrumenting the storage implementation, either to force it to fail at each point or to record successive storage states and replay each of them. Each `psa_its_xxx` function call is assumed to be atomic. | 
|  | 93 |  | 
|  | 94 | ### SE driver system tests | 
|  | 95 |  | 
|  | 96 | #### Real-world use case | 
|  | 97 |  | 
|  | 98 | We must have at least one driver that is close to real-world conditions: | 
|  | 99 |  | 
|  | 100 | * With its own source tree. | 
|  | 101 | * Running on actual hardware. | 
|  | 102 | * Run the full driver validation test suite (which does not yet exist). | 
|  | 103 | * Run at least one test application (e.g. the Mbed OS TLS example). | 
|  | 104 |  | 
| Gilles Peskine | 545c28b | 2019-09-04 19:41:16 +0200 | [diff] [blame] | 105 | This requirement shall be fulfilled by the [Microchip ATECC508A driver](https://github.com/ARMmbed/mbed-os-atecc608a/). | 
| Gilles Peskine | 92bcfdb | 2019-09-04 19:26:50 +0200 | [diff] [blame] | 106 |  | 
|  | 107 | #### Complete driver | 
|  | 108 |  | 
|  | 109 | We should have at least one driver that covers the whole interface: | 
|  | 110 |  | 
|  | 111 | * With its own source tree. | 
|  | 112 | * Implementing all the methods. | 
|  | 113 | * Run the full driver validation test suite (which does not yet exist). | 
|  | 114 |  | 
|  | 115 | A PKCS#11 driver would be a good candidate. It would be useful as part of our product offering. | 
| Gilles Peskine | 24cebf6 | 2020-11-30 17:51:53 +0100 | [diff] [blame] | 116 |  | 
| Manuel Pégourié-Gonnard | 1a827a3 | 2023-11-13 10:01:21 +0100 | [diff] [blame] | 117 | ## Unified driver interface testing | 
| Gilles Peskine | 24cebf6 | 2020-11-30 17:51:53 +0100 | [diff] [blame] | 118 |  | 
|  | 119 | The [unified driver interface](../../proposed/psa-driver-interface.md) defines interfaces for accelerators. | 
|  | 120 |  | 
|  | 121 | ### Test requirements | 
|  | 122 |  | 
|  | 123 | #### Requirements for transparent driver testing | 
|  | 124 |  | 
|  | 125 | Every cryptographic mechanism for which a transparent driver interface exists (key creation, cryptographic operations, …) must be exercised in at least one build. The test must verify that the driver code is called. | 
|  | 126 |  | 
|  | 127 | #### Requirements for fallback | 
|  | 128 |  | 
|  | 129 | The driver interface includes a fallback mechanism so that a driver can reject a request at runtime and let another driver handle the request. For each entry point, there must be at least three test runs with two or more drivers available with driver A configured to fall back to driver B, with one run where A returns `PSA_SUCCESS`, one where A returns `PSA_ERROR_NOT_SUPPORTED` and B is invoked, and one where A returns a different error and B is not invoked. | 
|  | 130 |  | 
| Manuel Pégourié-Gonnard | b66f9db | 2023-11-13 11:32:37 +0100 | [diff] [blame] | 131 | ### Test drivers | 
| Manuel Pégourié-Gonnard | 1a827a3 | 2023-11-13 10:01:21 +0100 | [diff] [blame] | 132 |  | 
|  | 133 | We have test drivers that are enabled by `PSA_CRYPTO_DRIVER_TEST` (not present | 
|  | 134 | in the usual config files, must be defined on the command line or in a custom | 
| David Horstmann | 5b93d97 | 2024-10-31 15:36:05 +0000 | [diff] [blame] | 135 | config file). Those test drivers are implemented in `framework/tests/src/drivers/*.c` | 
|  | 136 | and their API is declared in `framework/tests/include/test/drivers/*.h`. | 
| Manuel Pégourié-Gonnard | 1a827a3 | 2023-11-13 10:01:21 +0100 | [diff] [blame] | 137 |  | 
|  | 138 | We have two test driver registered: `mbedtls_test_opaque_driver` and | 
|  | 139 | `mbedtls_test_transparent_driver`. These are described in | 
|  | 140 | `scripts/data_files/driver_jsons/mbedtls_test_xxx_driver.json` (as much as our | 
|  | 141 | JSON support currently allows). Each of the drivers can potentially implement | 
|  | 142 | support for several mechanism; conversely, each of the file mentioned in the | 
|  | 143 | previous paragraph can potentially contribute to both the opaque and the | 
|  | 144 | transparent test driver. | 
|  | 145 |  | 
|  | 146 | Each entry point is instrumented to record the number of hits for each part of | 
|  | 147 | the driver (same division as the files) and the status of the last call. It is | 
| Manuel Pégourié-Gonnard | b66f9db | 2023-11-13 11:32:37 +0100 | [diff] [blame] | 148 | also possible to force the next call to return a specified status, and | 
|  | 149 | sometimes more things can be forced: see the various | 
| Manuel Pégourié-Gonnard | 4575d23 | 2024-04-15 10:54:49 +0200 | [diff] [blame] | 150 | `mbedtls_test_driver_XXX_hooks_t` structures declared by each driver (and | 
|  | 151 | subsections below). | 
| Manuel Pégourié-Gonnard | 1a827a3 | 2023-11-13 10:01:21 +0100 | [diff] [blame] | 152 |  | 
|  | 153 | The drivers can use one of two back-ends: | 
|  | 154 | - internal: this requires the built-in implementation to be present. | 
|  | 155 | - libtestdriver1: this allows the built-in implementation to be omitted from | 
|  | 156 | the build. | 
|  | 157 |  | 
|  | 158 | Historical note: internal was initially the only back-end; then support for | 
| Manuel Pégourié-Gonnard | 0ca2fd0 | 2024-04-12 10:14:17 +0200 | [diff] [blame] | 159 | libtestdriver1 was added gradually. Support for libtestdriver1 is now complete | 
|  | 160 | (see following sub-sections), so we could remove internal now. Note it's | 
|  | 161 | useful to have builds with both a driver and the built-in, in order to test | 
|  | 162 | fallback to built-in, which is currently done only with internal, but this can | 
|  | 163 | be achieved with libtestdriver1 just as well. | 
| Manuel Pégourié-Gonnard | 1a827a3 | 2023-11-13 10:01:21 +0100 | [diff] [blame] | 164 |  | 
| Manuel Pégourié-Gonnard | 4575d23 | 2024-04-15 10:54:49 +0200 | [diff] [blame] | 165 | Note on instrumentation: originally, when only the internal backend was | 
|  | 166 | available, hits were how we knew that the driver was called, as opposed to | 
|  | 167 | directly calling the built-in code. With libtestdriver1, we can check that by | 
|  | 168 | ensuring that the built-in code is not present, so if the operation gives the | 
|  | 169 | correct result, only a driver call can have calculated that result. So, | 
|  | 170 | nowadays there is low value in checking the hit count. There is still some | 
|  | 171 | value for hit counts, e.g. checking that we don't call a multipart entry point | 
|  | 172 | when we intended to call the one-shot entry point, but it's limited. | 
|  | 173 |  | 
| Manuel Pégourié-Gonnard | b18bc80 | 2023-11-24 11:59:25 +0100 | [diff] [blame] | 174 | Note: our test drivers tend to provide all possible entry points (with a few | 
|  | 175 | exceptions that may not be intentional, see the next sections). However, in | 
|  | 176 | some cases, when an entry point is not available, the core is supposed to | 
|  | 177 | implement it using other entry points, for example: | 
|  | 178 | - `mac_verify` may use `mac_compute` if the driver does no provide verify; | 
|  | 179 | - for things that have both one-shot and multi-part API, the driver can | 
|  | 180 | provide only the multi-part entry points, and the core is supposed to | 
|  | 181 | implement one-shot on top of it (but still call the one-shot entry points when | 
|  | 182 | they're available); | 
|  | 183 | - `sign/verify_message` can be implemented on top of `sign/verify_hash` for | 
|  | 184 | some algorithms; | 
|  | 185 | - (not sure if the list is exhaustive). | 
|  | 186 |  | 
|  | 187 | Ideally, we'd want build options for the test drivers so that we can test with | 
|  | 188 | different combinations of entry points present, and make sure the core behaves | 
|  | 189 | appropriately when some entry points are absent but other entry points allow | 
| Manuel Pégourié-Gonnard | ae22f04 | 2024-04-12 10:18:27 +0200 | [diff] [blame] | 190 | implementing the operation. This will remain hard to test until we have proper | 
|  | 191 | support for JSON-defined drivers with auto-generation of dispatch code. | 
|  | 192 | (The `MBEDTLS_PSA_ACCEL_xxx` macros we currently use are not expressive enough | 
| Manuel Pégourié-Gonnard | 4575d23 | 2024-04-15 10:54:49 +0200 | [diff] [blame] | 193 | to specify which entry points are supported for a given mechanism.) | 
| Manuel Pégourié-Gonnard | b18bc80 | 2023-11-24 11:59:25 +0100 | [diff] [blame] | 194 |  | 
| Manuel Pégourié-Gonnard | 1a827a3 | 2023-11-13 10:01:21 +0100 | [diff] [blame] | 195 | Our implementation of PSA Crypto is structured in a way that the built-in | 
|  | 196 | implementation of each operation follows the driver API, see | 
|  | 197 | [`../architecture/psa-crypto-implementation-structure.md`](../architecture/psa-crypto-implementation-structure.html). | 
|  | 198 | This makes implementing the test drivers very easy: each entry point has a | 
|  | 199 | corresponding `mbedtls_psa_xxx()` function that it can call as its | 
|  | 200 | implementation - with the `libtestdriver1` back-end the function is called | 
|  | 201 | `libtestdriver1_mbedtls_psa_xxx()` instead. | 
|  | 202 |  | 
| Manuel Pégourié-Gonnard | b66f9db | 2023-11-13 11:32:37 +0100 | [diff] [blame] | 203 | A nice consequence of that strategy is that when an entry point has | 
|  | 204 | test-driver support, most of the time, it automatically works for all | 
|  | 205 | algorithms and key types supported by the library. (The exception being when | 
|  | 206 | the driver needs to call a different function for different key types, as is | 
| Manuel Pégourié-Gonnard | 432e3b4 | 2024-04-12 10:25:25 +0200 | [diff] [blame] | 207 | the case with some asymmetric key management operations.) (Note: it's still | 
|  | 208 | useful to test drivers in configurations with partial algorithm support, and | 
|  | 209 | that can still be done by configuring libtestdriver1 and the main library as | 
|  | 210 | desired.) | 
| Manuel Pégourié-Gonnard | b66f9db | 2023-11-13 11:32:37 +0100 | [diff] [blame] | 211 |  | 
| Manuel Pégourié-Gonnard | 1a827a3 | 2023-11-13 10:01:21 +0100 | [diff] [blame] | 212 | The renaming process for `libtestdriver1` is implemented as a few Perl regexes | 
|  | 213 | applied to a copy of the library code, see the `libtestdriver1.a` target in | 
|  | 214 | `tests/Makefile`. Another modification that's done to this copy is appending | 
| Ronald Cron | e0ebf55 | 2024-11-19 14:59:09 +0100 | [diff] [blame] | 215 | `tests/configs/crypto_config_test_driver_extension.h` to `psa/crypto_config.h`. | 
|  | 216 | This file reverses the `ACCEL`/`BUILTIN` macros so that `libtestdriver1` | 
|  | 217 | includes as built-in what the main `libmbedcrypto.a` will have accelerated; | 
|  | 218 | see that file's initial comment for details. See also `helper_libtestdriver1_` | 
|  | 219 | functions and the preceding comment in `all.sh` for how libtestdriver is used | 
|  | 220 | in practice. | 
| Manuel Pégourié-Gonnard | 1a827a3 | 2023-11-13 10:01:21 +0100 | [diff] [blame] | 221 |  | 
|  | 222 | This general framework needs specific code for each family of operations. At a | 
|  | 223 | given point in time, not all operations have the same level of support. The | 
|  | 224 | following sub-sections describe the status of the test driver support, mostly | 
|  | 225 | following the structure and order of sections 9.6 and 10.2 to 10.10 of the | 
|  | 226 | [PSA Crypto standard](https://arm-software.github.io/psa-api/crypto/1.1/) as | 
|  | 227 | that is also a natural division for implementing test drivers (that's how the | 
| Manuel Pégourié-Gonnard | b66f9db | 2023-11-13 11:32:37 +0100 | [diff] [blame] | 228 | code is divided into files). | 
| Manuel Pégourié-Gonnard | 1a827a3 | 2023-11-13 10:01:21 +0100 | [diff] [blame] | 229 |  | 
|  | 230 | #### Key management | 
|  | 231 |  | 
| Manuel Pégourié-Gonnard | b66f9db | 2023-11-13 11:32:37 +0100 | [diff] [blame] | 232 | The following entry points are declared in `test/drivers/key_management.h`: | 
|  | 233 |  | 
|  | 234 | - `"init"` (transparent and opaque) | 
|  | 235 | - `"generate_key"` (transparent and opaque) | 
|  | 236 | - `"export_public_key"` (transparent and opaque) | 
|  | 237 | - `"import_key"` (transparent and opaque) | 
|  | 238 | - `"export_key"` (opaque only) | 
|  | 239 | - `"get_builtin_key"` (opaque only) | 
|  | 240 | - `"copy_key"` (opaque only) | 
|  | 241 |  | 
|  | 242 | The transparent driver fully implements the declared entry points, and can use | 
|  | 243 | any backend: internal or libtestdriver1. | 
|  | 244 |  | 
|  | 245 | The opaque's driver implementation status is as follows: | 
|  | 246 | - `"generate_key"`: not implemented, always returns `NOT_SUPPORTED`. | 
|  | 247 | - `"export_public_key"`: implemented only for ECC and RSA keys, both backends. | 
|  | 248 | - `"import_key"`: implemented except for DH keys, both backends. | 
|  | 249 | - `"export_key"`: implemented for built-in keys (ECC and AES), and for | 
|  | 250 | non-builtin keys except DH keys. (Backend not relevant.) | 
|  | 251 | - `"get_builtin_key"`: implemented - provisioned keys: AES-128 and ECC | 
|  | 252 | secp2456r1. (Backend not relevant.) | 
|  | 253 | - `"copy_key"`: implemented - emulates a SE without storage. (Backend not | 
|  | 254 | relevant.) | 
|  | 255 |  | 
|  | 256 | Note: the `"init"` entry point is not part of the "key management" family, but | 
|  | 257 | listed here as it's declared and implemented in the same file. With the | 
|  | 258 | transparent driver and the libtestdriver1 backend, it calls | 
|  | 259 | `libtestdriver1_psa_crypto_init()`, which partially but not fully ensures | 
|  | 260 | that this entry point is called before other entry points in the test drivers. | 
|  | 261 | With the opaque driver, this entry point just does nothing an returns success. | 
|  | 262 |  | 
|  | 263 | The following entry points are defined by the driver interface but missing | 
|  | 264 | from our test drivers: | 
|  | 265 | - `"allocate_key"`, `"destroy_key"`: this is for opaque drivers that store the | 
|  | 266 | key material internally. | 
|  | 267 |  | 
|  | 268 | Note: the instrumentation also allows forcing the output and its length. | 
| Manuel Pégourié-Gonnard | 1a827a3 | 2023-11-13 10:01:21 +0100 | [diff] [blame] | 269 |  | 
|  | 270 | #### Message digests (Hashes) | 
|  | 271 |  | 
| Manuel Pégourié-Gonnard | b66f9db | 2023-11-13 11:32:37 +0100 | [diff] [blame] | 272 | The following entry points are declared (transparent only): | 
|  | 273 | - `"hash_compute"` | 
|  | 274 | - `"hash_setup"` | 
|  | 275 | - `"hash_clone"` | 
|  | 276 | - `"hash_update"` | 
|  | 277 | - `"hash_finish"` | 
|  | 278 | - `"hash_abort"` | 
|  | 279 |  | 
|  | 280 | The transparent driver fully implements the declared entry points, and can use | 
|  | 281 | any backend: internal or libtestdriver1. | 
|  | 282 |  | 
| Emmanuel Ferdman | 5c0c515 | 2024-11-17 02:34:52 -0800 | [diff] [blame] | 283 | This family is not part of the opaque driver as it doesn't use keys. | 
| Manuel Pégourié-Gonnard | 1a827a3 | 2023-11-13 10:01:21 +0100 | [diff] [blame] | 284 |  | 
|  | 285 | #### Message authentication codes (MAC) | 
|  | 286 |  | 
| Manuel Pégourié-Gonnard | b66f9db | 2023-11-13 11:32:37 +0100 | [diff] [blame] | 287 | The following entry points are declared (transparent and opaque): | 
|  | 288 | - `"mac_compute"` | 
|  | 289 | - `"mac_sign_setup"` | 
|  | 290 | - `"mac_verify_setup"` | 
|  | 291 | - `"mac_update"` | 
|  | 292 | - `"mac_sign_finish"` | 
|  | 293 | - `"mac_verify_finish"` | 
|  | 294 | - `"mac_abort"` | 
|  | 295 |  | 
|  | 296 | The transparent driver fully implements the declared entry points, and can use | 
|  | 297 | any backend: internal or libtestdriver1. | 
|  | 298 |  | 
|  | 299 | The opaque driver only implements the instrumentation but not the actual | 
|  | 300 | operations: entry points will always return `NOT_SUPPORTED`, unless another | 
|  | 301 | status is forced. | 
|  | 302 |  | 
|  | 303 | The following entry points are not implemented: | 
| Manuel Pégourié-Gonnard | b18bc80 | 2023-11-24 11:59:25 +0100 | [diff] [blame] | 304 | - `mac_verify`: this mostly makes sense for opaque drivers; the core will fall | 
| Manuel Pégourié-Gonnard | b66f9db | 2023-11-13 11:32:37 +0100 | [diff] [blame] | 305 | back to using `"mac_compute"` if this is not implemented. So, perhaps | 
|  | 306 | ideally we should test both with `"mac_verify"` implemented and with it not | 
|  | 307 | implemented? Anyway, we have a test gap here. | 
| Manuel Pégourié-Gonnard | 1a827a3 | 2023-11-13 10:01:21 +0100 | [diff] [blame] | 308 |  | 
|  | 309 | #### Unauthenticated ciphers | 
|  | 310 |  | 
| Manuel Pégourié-Gonnard | b66f9db | 2023-11-13 11:32:37 +0100 | [diff] [blame] | 311 | The following entry points are declared (transparent and opaque): | 
|  | 312 | - `"cipher_encrypt"` | 
|  | 313 | - `"cipher_decrypt"` | 
|  | 314 | - `"cipher_encrypt_setup"` | 
|  | 315 | - `"cipher_decrypt_setup"` | 
|  | 316 | - `"cipher_set_iv"` | 
|  | 317 | - `"cipher_update"` | 
|  | 318 | - `"cipher_finish"` | 
|  | 319 | - `"cipher_abort"` | 
|  | 320 |  | 
|  | 321 | The transparent driver fully implements the declared entry points, and can use | 
|  | 322 | any backend: internal or libtestdriver1. | 
|  | 323 |  | 
|  | 324 | The opaque driver is not implemented at all, neither instumentation nor the | 
|  | 325 | operation: entry points always return `NOT_SUPPORTED`. | 
|  | 326 |  | 
|  | 327 | Note: the instrumentation also allows forcing a specific output and output | 
|  | 328 | length. | 
| Manuel Pégourié-Gonnard | 1a827a3 | 2023-11-13 10:01:21 +0100 | [diff] [blame] | 329 |  | 
|  | 330 | #### Authenticated encryption with associated data (AEAD) | 
|  | 331 |  | 
| Manuel Pégourié-Gonnard | b66f9db | 2023-11-13 11:32:37 +0100 | [diff] [blame] | 332 | The following entry points are declared (transparent only): | 
|  | 333 | - `"aead_encrypt"` | 
|  | 334 | - `"aead_decrypt"` | 
|  | 335 | - `"aead_encrypt_setup"` | 
|  | 336 | - `"aead_decrypt_setup"` | 
|  | 337 | - `"aead_set_nonce"` | 
|  | 338 | - `"aead_set_lengths"` | 
|  | 339 | - `"aead_update_ad"` | 
|  | 340 | - `"aead_update"` | 
|  | 341 | - `"aead_finish"` | 
|  | 342 | - `"aead_verify"` | 
|  | 343 | - `"aead_abort"` | 
|  | 344 |  | 
|  | 345 | The transparent driver fully implements the declared entry points, and can use | 
|  | 346 | any backend: internal or libtestdriver1. | 
|  | 347 |  | 
|  | 348 | The opaque driver does not implement or even declare entry points for this | 
|  | 349 | family. | 
|  | 350 |  | 
|  | 351 | Note: the instrumentation records the number of hits per entry point, not just | 
|  | 352 | the total number of hits for this family. | 
| Manuel Pégourié-Gonnard | 1a827a3 | 2023-11-13 10:01:21 +0100 | [diff] [blame] | 353 |  | 
|  | 354 | #### Key derivation | 
|  | 355 |  | 
| Manuel Pégourié-Gonnard | b66f9db | 2023-11-13 11:32:37 +0100 | [diff] [blame] | 356 | Not covered at all by the test drivers. | 
|  | 357 |  | 
| Manuel Pégourié-Gonnard | a47a3c4e | 2024-04-12 10:21:42 +0200 | [diff] [blame] | 358 | That's a test gap which reflects a feature gap: the driver interface does | 
|  | 359 | define a key derivation family of entry points, but we don't currently | 
|  | 360 | implement that part of the driver interface, see #5488 and related issues. | 
| Manuel Pégourié-Gonnard | 1a827a3 | 2023-11-13 10:01:21 +0100 | [diff] [blame] | 361 |  | 
|  | 362 | #### Asymmetric signature | 
|  | 363 |  | 
| Manuel Pégourié-Gonnard | b66f9db | 2023-11-13 11:32:37 +0100 | [diff] [blame] | 364 | The following entry points are declared (transparent and opaque): | 
|  | 365 |  | 
|  | 366 | - `"sign_message"` | 
|  | 367 | - `"verify_message"` | 
|  | 368 | - `"sign_hash"` | 
|  | 369 | - `"verify_hash"` | 
|  | 370 |  | 
|  | 371 | The transparent driver fully implements the declared entry points, and can use | 
|  | 372 | any backend: internal or libtestdriver1. | 
|  | 373 |  | 
|  | 374 | The opaque driver is not implemented at all, neither instumentation nor the | 
|  | 375 | operation: entry points always return `NOT_SUPPORTED`. | 
|  | 376 |  | 
|  | 377 | Note: the instrumentation also allows forcing a specific output and output | 
|  | 378 | length, and has two instance of the hooks structure: one for sign, the other | 
|  | 379 | for verify. | 
|  | 380 |  | 
|  | 381 | Note: when a driver implements only the `"xxx_hash"` entry points, the core is | 
|  | 382 | supposed to implement the `psa_xxx_message()` functions by computing the hash | 
|  | 383 | itself before calling the `"xxx_hash"` entry point. Since the test driver does | 
|  | 384 | implement the `"xxx_message"` entry point, it's not exercising that part of | 
|  | 385 | the core's expected behaviour. | 
| Manuel Pégourié-Gonnard | 1a827a3 | 2023-11-13 10:01:21 +0100 | [diff] [blame] | 386 |  | 
|  | 387 | #### Asymmetric encryption | 
|  | 388 |  | 
| Manuel Pégourié-Gonnard | b66f9db | 2023-11-13 11:32:37 +0100 | [diff] [blame] | 389 | The following entry points are declared (transparent and opaque): | 
|  | 390 |  | 
|  | 391 | - `"asymmetric_encrypt"` | 
|  | 392 | - `"asymmetric_decrypt"` | 
|  | 393 |  | 
|  | 394 | The transparent driver fully implements the declared entry points, and can use | 
|  | 395 | any backend: internal or libtestdriver1. | 
|  | 396 |  | 
| Manuel Pégourié-Gonnard | dde1abd | 2024-04-09 12:12:48 +0200 | [diff] [blame] | 397 | The opaque driver implements the declared entry points, and can use any | 
|  | 398 | backend: internal or libtestdriver1. However it does not implement the | 
|  | 399 | instrumentation (hits, forced output/status), as this [was not an immediate | 
|  | 400 | priority](https://github.com/Mbed-TLS/mbedtls/pull/8700#issuecomment-1892466159). | 
| Manuel Pégourié-Gonnard | b66f9db | 2023-11-13 11:32:37 +0100 | [diff] [blame] | 401 |  | 
|  | 402 | Note: the instrumentation also allows forcing a specific output and output | 
|  | 403 | length. | 
| Manuel Pégourié-Gonnard | 1a827a3 | 2023-11-13 10:01:21 +0100 | [diff] [blame] | 404 |  | 
|  | 405 | #### Key agreement | 
|  | 406 |  | 
| Manuel Pégourié-Gonnard | b66f9db | 2023-11-13 11:32:37 +0100 | [diff] [blame] | 407 | The following entry points are declared (transparent and opaque): | 
|  | 408 |  | 
|  | 409 | - `"key_agreement"` | 
|  | 410 |  | 
|  | 411 | The transparent driver fully implements the declared entry points, and can use | 
|  | 412 | any backend: internal or libtestdriver1. | 
|  | 413 |  | 
|  | 414 | The opaque driver is not implemented at all, neither instumentation nor the | 
|  | 415 | operation: entry points always return `NOT_SUPPORTED`. | 
|  | 416 |  | 
|  | 417 | Note: the instrumentation also allows forcing a specific output and output | 
|  | 418 | length. | 
| Manuel Pégourié-Gonnard | 1a827a3 | 2023-11-13 10:01:21 +0100 | [diff] [blame] | 419 |  | 
|  | 420 | #### Other cryptographic services (Random number generation) | 
| Gilles Peskine | 24cebf6 | 2020-11-30 17:51:53 +0100 | [diff] [blame] | 421 |  | 
| Manuel Pégourié-Gonnard | b66f9db | 2023-11-13 11:32:37 +0100 | [diff] [blame] | 422 | Not covered at all by the test drivers. | 
|  | 423 |  | 
|  | 424 | The driver interface defines a `"get_entropy"` entry point, as well as a | 
|  | 425 | "Random generation" family of entry points. None of those are currently | 
|  | 426 | implemented in the library. Part of it will be planned for 4.0, see #8150. | 
|  | 427 |  | 
|  | 428 | #### PAKE extension | 
|  | 429 |  | 
|  | 430 | The following entry points are declared (transparent only): | 
|  | 431 | - `"pake_setup"` | 
|  | 432 | - `"pake_output"` | 
|  | 433 | - `"pake_input"` | 
|  | 434 | - `"pake_get_implicit_key"` | 
|  | 435 | - `"pake_abort"` | 
|  | 436 |  | 
|  | 437 | Note: the instrumentation records hits per entry point and allows forcing the | 
|  | 438 | output and its length, as well as forcing the status of setup independently | 
|  | 439 | from the others. | 
|  | 440 |  | 
|  | 441 | The transparent driver fully implements the declared entry points, and can use | 
|  | 442 | any backend: internal or libtestdriver1. | 
|  | 443 |  | 
|  | 444 | The opaque driver does not implement or even declare entry points for this | 
|  | 445 | family. | 
| Manuel Pégourié-Gonnard | 6a96f42 | 2023-11-16 13:01:22 +0100 | [diff] [blame] | 446 |  | 
|  | 447 | ### Driver wrapper test suite | 
|  | 448 |  | 
|  | 449 | We have a test suite dedicated to driver dispatch, which takes advantage of the | 
|  | 450 | instrumentation in the test drivers described in the previous section, in | 
|  | 451 | order to check that drivers are called when they're supposed to, and that the | 
|  | 452 | core behaves as expected when they return errors (in particular, that we fall | 
| Manuel Pégourié-Gonnard | 432e3b4 | 2024-04-12 10:25:25 +0200 | [diff] [blame] | 453 | back to the built-in implementation when the driver returns `NOT_SUPPORTED`). | 
| Manuel Pégourié-Gonnard | 6a96f42 | 2023-11-16 13:01:22 +0100 | [diff] [blame] | 454 |  | 
|  | 455 | This is `test_suite_psa_crypto_driver_wrappers`, which is maintained manually | 
|  | 456 | (that is, the test cases in the `.data` files are not auto-generated). The | 
|  | 457 | entire test suite depends on the test drivers being enabled | 
|  | 458 | (`PSA_CRYPTO_DRIVER_TEST`), which is not the case in the default or full | 
|  | 459 | config. | 
|  | 460 |  | 
| Manuel Pégourié-Gonnard | 432e3b4 | 2024-04-12 10:25:25 +0200 | [diff] [blame] | 461 | The test suite is focused on driver usage (mostly by checking the expected | 
|  | 462 | number of hits) but also does some validation of the results: for | 
|  | 463 | deterministic algorithms, known-answers tests are used, and for the rest, some | 
| Emmanuel Ferdman | 5c0c515 | 2024-11-17 02:34:52 -0800 | [diff] [blame] | 464 | consistency checks are done (more or less detailed depending on the algorithm | 
| Manuel Pégourié-Gonnard | 432e3b4 | 2024-04-12 10:25:25 +0200 | [diff] [blame] | 465 | and build configuration). | 
|  | 466 |  | 
| Manuel Pégourié-Gonnard | 6a96f42 | 2023-11-16 13:01:22 +0100 | [diff] [blame] | 467 | #### Configurations coverage | 
|  | 468 |  | 
|  | 469 | The driver wrappers test suite has cases that expect both the driver and the | 
|  | 470 | built-in to be present, and also cases that expect the driver to be present | 
|  | 471 | but not the built-in. As such, it's impossible for a single configuration to | 
|  | 472 | run all test cases, and we need at least two: driver+built-in, and | 
|  | 473 | driver-only. | 
|  | 474 |  | 
|  | 475 | - The driver+built-in case is covered by `test_psa_crypto_drivers` in `all.sh`. | 
|  | 476 | This covers all areas (key types and algs) at once. | 
|  | 477 | - The driver-only case is split into multiple `all.sh` components whose names | 
|  | 478 | start with `test_psa_crypto_config_accel`; we have one or more component per | 
|  | 479 | area, see below. | 
|  | 480 |  | 
|  | 481 | Here's a summary of driver-only coverage, grouped by families of key types. | 
|  | 482 |  | 
|  | 483 | Hash (key types: none) | 
|  | 484 | - `test_psa_crypto_config_accel_hash`: all algs, default config, no parity | 
|  | 485 | testing. | 
|  | 486 | - `test_psa_crypto_config_accel_hash_use_psa`: all algs, full config, with | 
|  | 487 | parity testing. | 
|  | 488 |  | 
|  | 489 | HMAC (key type: HMAC) | 
| Manuel Pégourié-Gonnard | 6c45361 | 2024-03-18 10:12:49 +0100 | [diff] [blame] | 490 | - `test_psa_crypto_config_accel_hmac`: all algs, full config except a few | 
|  | 491 | exclusions (PKCS5, PKCS7, HMAC-DRBG, legacy HKDF, deterministic ECDSA), with | 
|  | 492 | parity testing. | 
| Manuel Pégourié-Gonnard | 6a96f42 | 2023-11-16 13:01:22 +0100 | [diff] [blame] | 493 |  | 
|  | 494 | Cipher, AEAD and CMAC (key types: DES, AES, ARIA, CHACHA20, CAMELLIA): | 
| Manuel Pégourié-Gonnard | 98f8da1 | 2024-01-10 12:53:58 +0100 | [diff] [blame] | 495 | - `test_psa_crypto_config_accel_cipher_aead_cmac`: all key types and algs, full | 
|  | 496 | config with a few exclusions (NIST-KW), with parity testing. | 
|  | 497 | - `test_psa_crypto_config_accel_des`: only DES (with all algs), full | 
| Manuel Pégourié-Gonnard | 6a96f42 | 2023-11-16 13:01:22 +0100 | [diff] [blame] | 498 | config, no parity testing. | 
|  | 499 | - `test_psa_crypto_config_accel_aead`: only AEAD algs (with all relevant key | 
|  | 500 | types), full config, no parity testing. | 
|  | 501 |  | 
|  | 502 | Key derivation (key types: `DERIVE`, `RAW_DATA`, `PASSWORD`, `PEPPER`, | 
|  | 503 | `PASSWORD_HASH`): | 
| Manuel Pégourié-Gonnard | a47a3c4e | 2024-04-12 10:21:42 +0200 | [diff] [blame] | 504 | - No testing as we don't have driver support yet (see previous section). | 
| Manuel Pégourié-Gonnard | 6a96f42 | 2023-11-16 13:01:22 +0100 | [diff] [blame] | 505 |  | 
|  | 506 | RSA (key types: `RSA_KEY_PAIR_xxx`, `RSA_PUBLIC_KEY`): | 
| Manuel Pégourié-Gonnard | f2089da | 2023-12-18 11:36:26 +0100 | [diff] [blame] | 507 | - `test_psa_crypto_config_accel_rsa_crypto`: all 4 algs (encryption & | 
|  | 508 | signature, v1.5 & v2.1), config `crypto_full`, with parity testing excluding | 
|  | 509 | PK. | 
| Manuel Pégourié-Gonnard | 6a96f42 | 2023-11-16 13:01:22 +0100 | [diff] [blame] | 510 |  | 
|  | 511 | DH (key types: `DH_KEY_PAIR_xxx`, `DH_PUBLIC_KEY`): | 
|  | 512 | - `test_psa_crypto_config_accel_ffdh`: all key types and algs, full config, | 
|  | 513 | with parity testing. | 
|  | 514 | - `test_psa_crypto_config_accel_ecc_ffdh_no_bignum`: with also bignum removed. | 
|  | 515 |  | 
|  | 516 | ECC (key types: `ECC_KEY_PAIR_xxx`, `ECC_PUBLIC_KEY`): | 
|  | 517 | - Single algorithm accelerated (both key types, all curves): | 
|  | 518 | - `test_psa_crypto_config_accel_ecdh`: default config, no parity testing. | 
|  | 519 | - `test_psa_crypto_config_accel_ecdsa`: default config, no parity testing. | 
|  | 520 | - `test_psa_crypto_config_accel_pake`: full config, no parity testing. | 
|  | 521 | - All key types, algs and curves accelerated (full config with exceptions, | 
|  | 522 | with parity testing): | 
|  | 523 | - `test_psa_crypto_config_accel_ecc_ecp_light_only`: `ECP_C` mostly disabled | 
|  | 524 | - `test_psa_crypto_config_accel_ecc_no_ecp_at_all`: `ECP_C` fully disabled | 
|  | 525 | - `test_psa_crypto_config_accel_ecc_no_bignum`: `BIGNUM_C` disabled (DH disabled) | 
|  | 526 | - `test_psa_crypto_config_accel_ecc_ffdh_no_bignum`: `BIGNUM_C` disabled (DH accelerated) | 
|  | 527 | - Other - all algs accelerated but only some algs/curves (full config with | 
|  | 528 | exceptions, no parity testing): | 
|  | 529 | - `test_psa_crypto_config_accel_ecc_some_key_types` | 
|  | 530 | - `test_psa_crypto_config_accel_ecc_non_weierstrass_curves` | 
|  | 531 | - `test_psa_crypto_config_accel_ecc_weierstrass_curves` | 
|  | 532 |  | 
|  | 533 | Note: `analyze_outcomes.py` provides a list of test cases that are not | 
| Manuel Pégourié-Gonnard | f2089da | 2023-12-18 11:36:26 +0100 | [diff] [blame] | 534 | executed in any configuration tested on the CI. We're missing driver-only HMAC | 
|  | 535 | testing, but no test is flagged as never executed there; this reveals we don't | 
|  | 536 | have "fallback not available" cases for MAC, see #8565. | 
| Manuel Pégourié-Gonnard | 6a96f42 | 2023-11-16 13:01:22 +0100 | [diff] [blame] | 537 |  | 
|  | 538 | #### Test case coverage | 
|  | 539 |  | 
|  | 540 | Since `test_suite_psa_crypto_driver_wrappers.data` is maintained manually, | 
| Manuel Pégourié-Gonnard | 432e3b4 | 2024-04-12 10:25:25 +0200 | [diff] [blame] | 541 | we need to make sure it exercises all the cases that need to be tested. In the | 
|  | 542 | future, this file should be generated in order to ensure exhaustiveness. | 
| Manuel Pégourié-Gonnard | 6a96f42 | 2023-11-16 13:01:22 +0100 | [diff] [blame] | 543 |  | 
| Manuel Pégourié-Gonnard | 432e3b4 | 2024-04-12 10:25:25 +0200 | [diff] [blame] | 544 | In the meantime, one way to observe (lack of) completeness is to look at line | 
| Emmanuel Ferdman | 5c0c515 | 2024-11-17 02:34:52 -0800 | [diff] [blame] | 545 | coverage in test driver implementations - this doesn't reveal all gaps, but it | 
| Manuel Pégourié-Gonnard | 432e3b4 | 2024-04-12 10:25:25 +0200 | [diff] [blame] | 546 | does reveal cases where we thought about something when writing the test | 
|  | 547 | driver, but not when writing test functions/data. | 
| Manuel Pégourié-Gonnard | 6a96f42 | 2023-11-16 13:01:22 +0100 | [diff] [blame] | 548 |  | 
|  | 549 | Key management: | 
| Manuel Pégourié-Gonnard | 6a96f42 | 2023-11-16 13:01:22 +0100 | [diff] [blame] | 550 | - `mbedtls_test_transparent_generate_key()` is not tested with RSA keys. | 
|  | 551 | - `mbedtls_test_transparent_import_key()` is not tested with DH keys. | 
|  | 552 | - `mbedtls_test_opaque_import_key()` is not tested with unstructured keys nor | 
|  | 553 | with RSA keys (nor DH keys since that's not implemented). | 
|  | 554 | - `mbedtls_test_opaque_export_key()` is not tested with non-built-in keys. | 
|  | 555 | - `mbedtls_test_transparent_export_public_key()` is not tested with RSA or DH keys. | 
|  | 556 | - `mbedtls_test_opaque_export_public_key()` is not tested with non-built-in keys. | 
|  | 557 | - `mbedtls_test_opaque_copy_key()` is not tested at all. | 
|  | 558 |  | 
|  | 559 | Hash: | 
|  | 560 | - `mbedtls_test_transparent_hash_finish()` is not tested with a forced status. | 
|  | 561 |  | 
|  | 562 | MAC: | 
|  | 563 | - The following are not tested with a forced status: | 
|  | 564 | - `mbedtls_test_transparent_mac_sign_setup()` | 
|  | 565 | - `mbedtls_test_transparent_mac_verify_setup()` | 
|  | 566 | - `mbedtls_test_transparent_mac_update()` | 
|  | 567 | - `mbedtls_test_transparent_mac_verify_finish()` | 
|  | 568 | - `mbedtls_test_transparent_mac_abort()` | 
|  | 569 | - No opaque entry point is tested (they're not implemented either). | 
|  | 570 |  | 
|  | 571 | Cipher: | 
|  | 572 | - The following are not tested with a forced status nor with a forced output: | 
|  | 573 | - `mbedtls_test_transparent_cipher_encrypt()` | 
|  | 574 | - `mbedtls_test_transparent_cipher_finish()` | 
|  | 575 | - No opaque entry point is tested (they're not implemented either). | 
|  | 576 |  | 
|  | 577 | AEAD: | 
|  | 578 | - The following are not tested with a forced status: | 
|  | 579 | - `mbedtls_test_transparent_aead_set_nonce()` | 
|  | 580 | - `mbedtls_test_transparent_aead_set_lengths()` | 
|  | 581 | - `mbedtls_test_transparent_aead_update_ad()` | 
|  | 582 | - `mbedtls_test_transparent_aead_update()` | 
|  | 583 | - `mbedtls_test_transparent_aead_finish()` | 
|  | 584 | - `mbedtls_test_transparent_aead_verify()` | 
|  | 585 | - `mbedtls_test_transparent_aead_verify()` is not tested with an invalid tag | 
|  | 586 | (though it might be in another test suite). | 
|  | 587 |  | 
|  | 588 | Signature: | 
|  | 589 | - `sign_hash()` is not tested with RSA-PSS | 
|  | 590 | - No opaque entry point is tested (they're not implemented either). | 
|  | 591 |  | 
| Manuel Pégourié-Gonnard | 6a96f42 | 2023-11-16 13:01:22 +0100 | [diff] [blame] | 592 | Key agreement: | 
|  | 593 | - `mbedtls_test_transparent_key_agreement()` is not tested with FFDH. | 
|  | 594 | - No opaque entry point is tested (they're not implemented either). | 
|  | 595 |  | 
|  | 596 | PAKE: | 
|  | 597 | - All lines are covered. |