-
Notifications
You must be signed in to change notification settings - Fork 1k
Add wolfCrypt port for the Nuvoton NuMicro M2354 #11445
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
dgarske
wants to merge
1
commit into
wolfSSL:master
Choose a base branch
from
dgarske:nuvoton_m2354_cryptocb
base: master
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
+5,799
−30
Open
Changes from all commits
Commits
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,241 @@ | ||
| name: "Nuvoton M2354 port" | ||
|
|
||
| # Keeps the Nuvoton NuMicro M2354 crypto callback port compiling against the | ||
| # real vendor BSP. The port has no autotools option and is not built by any | ||
| # other job: an application compiles wolfcrypt/src/port/nuvoton/*.c into its own | ||
| # project, the same way wolfcrypt/src/port/st/stm32.c is carried. Without this | ||
| # guard a header rename in the BSP, or a refactor in aes.c, ecc.c or cryptocb.h, | ||
| # would break the port silently until someone next built for the board. | ||
| # | ||
| # Nothing is faked. arm-none-eabi-gcc is a plain apt package and the BSP is a | ||
| # public GitHub repository, so both legs compile against the genuine Nuvoton | ||
| # StdDriver headers at a pinned commit. | ||
| # | ||
| # secure WOLFSSL_NUVOTON_SECURE, the whole port including nuvoton_hw.c | ||
| # nonsecure WOLFSSL_NUVOTON_NSC, where nuvoton_hw.c compiles to nothing | ||
| # and the cmse_nonsecure_entry veneers supply the symbols | ||
| # | ||
| # The runnable example, including those veneers, lives in wolfssl-examples | ||
| # under embedded/nuvoton_m2354. Functional correctness is validated on a | ||
| # NuMaker-M2354, not here; see wolfcrypt/src/port/nuvoton/README.md. | ||
|
|
||
| # START OF COMMON SECTION | ||
| on: | ||
| push: | ||
| branches: [ 'master', 'main', 'release/**' ] | ||
| # Same set as the pull_request filter below: a refactor in aes.c, ecc.c or | ||
| # cryptocb.h breaks this port just as a change under port/nuvoton does, so | ||
| # the post-merge guard has to watch the same tree the PR guard does. | ||
| paths: | ||
| - 'wolfcrypt/src/**' | ||
| - 'wolfssl/wolfcrypt/**' | ||
| - '.github/workflows/nuvoton-m2354-compile.yml' | ||
| pull_request: | ||
| types: [opened, synchronize, reopened, ready_for_review] | ||
| branches: [ '**' ] | ||
| paths: | ||
| - 'wolfcrypt/src/**' | ||
| - 'wolfssl/wolfcrypt/**' | ||
| - '.github/workflows/nuvoton-m2354-compile.yml' | ||
| workflow_dispatch: | ||
|
|
||
| concurrency: | ||
| group: ${{ github.workflow }}-${{ github.ref }} | ||
| cancel-in-progress: true | ||
|
|
||
| permissions: | ||
| contents: read | ||
| # END OF COMMON SECTION | ||
|
|
||
| env: | ||
| # Pinned so a BSP change cannot break a PR that did not touch the port. Bump | ||
| # it deliberately. | ||
| BSP_REF: 3d423be763edabe1d8b3f27dea363b69e787f8f9 | ||
|
|
||
| jobs: | ||
| compile: | ||
| name: ${{ matrix.leg }} (Cortex-M23) | ||
| if: ${{ github.event_name != 'pull_request' || github.event.pull_request.draft == false }} | ||
| runs-on: ubuntu-24.04 | ||
| timeout-minutes: 20 | ||
| strategy: | ||
| fail-fast: false | ||
| matrix: | ||
| include: | ||
| - leg: secure | ||
| world: WOLFSSL_NUVOTON_SECURE | ||
| - leg: nonsecure | ||
| world: WOLFSSL_NUVOTON_NSC | ||
| steps: | ||
| - uses: actions/checkout@v4 | ||
| name: Checkout wolfSSL | ||
|
|
||
| - name: Install the toolchain | ||
| run: | | ||
| sudo apt-get update | ||
| sudo apt-get install -y gcc-arm-none-eabi | ||
|
|
||
| - name: Checkout the Nuvoton M2354 BSP | ||
| run: | | ||
| set -e | ||
| # The full repository is around 256 MB and almost none of it is | ||
| # needed, so take one commit and only the driver tree. | ||
| git clone --filter=blob:none --no-checkout --sparse \ | ||
| https://github.com/OpenNuvoton/M2354BSP "$GITHUB_WORKSPACE/M2354BSP" | ||
| cd "$GITHUB_WORKSPACE/M2354BSP" | ||
| git sparse-checkout set \ | ||
| Library/StdDriver/inc Library/Device Library/CMSIS | ||
| git fetch --depth 1 origin "$BSP_REF" | ||
| git checkout "$BSP_REF" | ||
|
|
||
| - name: Compile the port | ||
| run: | | ||
| set -e | ||
| BSP="$GITHUB_WORKSPACE/M2354BSP" | ||
| mkdir -p "$GITHUB_WORKSPACE/cfg" | ||
|
|
||
| # Minimal configuration: enough to reach every engine in the port. | ||
| # The example in wolfssl-examples carries a realistic one. | ||
| cat > "$GITHUB_WORKSPACE/cfg/user_settings.h" <<'EOF' | ||
| #ifndef CI_USER_SETTINGS_H | ||
| #define CI_USER_SETTINGS_H | ||
| #define WOLFSSL_NUVOTON_M2354 | ||
| #define SINGLE_THREADED | ||
| #define NO_FILESYSTEM | ||
| #define WOLFSSL_SMALL_STACK | ||
| #define WOLFSSL_SHA224 | ||
| #define WOLFSSL_SHA384 | ||
| #define WOLFSSL_SHA512 | ||
| #define HAVE_HASHDRBG | ||
| #define HAVE_AES_CBC | ||
| #define HAVE_AES_ECB | ||
| #define WOLFSSL_AES_DIRECT | ||
| #define WOLFSSL_AES_COUNTER | ||
| #define HAVE_AESGCM | ||
| #define HAVE_ECC | ||
| #define HAVE_ECC_DHE | ||
| #define HAVE_ECC_SIGN | ||
| #define HAVE_ECC_VERIFY | ||
| #define HAVE_ECC384 | ||
| #define WOLFSSL_KEY_GEN | ||
| #define TFM_TIMING_RESISTANT | ||
| #define ECC_TIMING_RESISTANT | ||
| #define WC_RSA_BLINDING | ||
| #endif | ||
| EOF | ||
|
|
||
| CFLAGS="-mcpu=cortex-m23 -mthumb -Os -Wall -Wextra -Werror -c" | ||
| CFLAGS="$CFLAGS -I. -I$GITHUB_WORKSPACE/cfg -DWOLFSSL_USER_SETTINGS" | ||
| CFLAGS="$CFLAGS -D${{ matrix.world }}" | ||
| CFLAGS="$CFLAGS -I$BSP/Library/StdDriver/inc" | ||
| CFLAGS="$CFLAGS -I$BSP/Library/Device/Nuvoton/M2354/Include" | ||
| CFLAGS="$CFLAGS -I$BSP/Library/CMSIS/Include" | ||
|
|
||
| for f in wolfcrypt/src/port/nuvoton/*.c wolfcrypt/src/random.c; do | ||
| echo " $f" | ||
| # shellcheck disable=SC2086 | ||
| arm-none-eabi-gcc $CFLAGS -o /dev/null "$f" | ||
| done | ||
|
|
||
| - name: Compile reduced configurations | ||
| if: ${{ matrix.leg == 'secure' }} | ||
| run: | | ||
| set -e | ||
| # The two full legs above pin one fully-enabled user_settings.h and | ||
| # cannot catch a conditional-compilation break. These reduced builds | ||
| # exercise the feature guards: verify-only ECC, an RSA-only build | ||
| # (mp_tohex gating), the AES-GCM / Key Store opt-outs, and an ECC | ||
| # build with every sub-feature off, where the hex and curve-id | ||
| # helpers have no caller. | ||
| BSP="$GITHUB_WORKSPACE/M2354BSP" | ||
| CF="-mcpu=cortex-m23 -mthumb -Os -Wall -Wextra -Wunused-function -Werror -c" | ||
| CF="$CF -I. -I$GITHUB_WORKSPACE/rcfg -DWOLFSSL_USER_SETTINGS" | ||
| CF="$CF -DWOLFSSL_NUVOTON_SECURE" | ||
| CF="$CF -I$BSP/Library/StdDriver/inc" | ||
| CF="$CF -I$BSP/Library/Device/Nuvoton/M2354/Include" | ||
| CF="$CF -I$BSP/Library/CMSIS/Include" | ||
| mkdir -p "$GITHUB_WORKSPACE/rcfg" | ||
|
|
||
| build() { | ||
| echo "== reduced: $1 ==" | ||
| for f in wolfcrypt/src/port/nuvoton/*.c wolfcrypt/src/random.c; do | ||
| # shellcheck disable=SC2086 | ||
| arm-none-eabi-gcc $CF -o /dev/null "$f" | ||
| done | ||
| } | ||
|
|
||
| cat > "$GITHUB_WORKSPACE/rcfg/user_settings.h" <<'EOF' | ||
| #ifndef RCFG_H | ||
| #define RCFG_H | ||
| #define WOLFSSL_NUVOTON_M2354 | ||
| #define SINGLE_THREADED | ||
| #define NO_FILESYSTEM | ||
| #define HAVE_HASHDRBG | ||
| #define WOLFSSL_SHA256 | ||
| #define HAVE_AES_CBC | ||
| #define WOLFSSL_AES_COUNTER | ||
| #define HAVE_AESGCM | ||
| #define HAVE_ECC | ||
| #define HAVE_ECC_DHE | ||
| #define HAVE_ECC_VERIFY | ||
| #define NO_ECC_SIGN | ||
| #define ECC_TIMING_RESISTANT | ||
| #define WC_RSA_BLINDING | ||
| #endif | ||
| EOF | ||
| build "verify-only ECC (NO_ECC_SIGN)" | ||
|
|
||
| cat > "$GITHUB_WORKSPACE/rcfg/user_settings.h" <<'EOF' | ||
| #ifndef RCFG_H | ||
| #define RCFG_H | ||
| #define WOLFSSL_NUVOTON_M2354 | ||
| #define SINGLE_THREADED | ||
| #define NO_FILESYSTEM | ||
| #define HAVE_HASHDRBG | ||
| #define WOLFSSL_SHA256 | ||
| #define NO_ECC | ||
| #define WC_RSA_BLINDING | ||
| #define WOLFSSL_NUVOTON_RSA | ||
| #endif | ||
| EOF | ||
| build "RSA-only (mp_tohex gating)" | ||
|
|
||
| cat > "$GITHUB_WORKSPACE/rcfg/user_settings.h" <<'EOF' | ||
| #ifndef RCFG_H | ||
| #define RCFG_H | ||
| #define WOLFSSL_NUVOTON_M2354 | ||
| #define SINGLE_THREADED | ||
| #define NO_FILESYSTEM | ||
| #define HAVE_HASHDRBG | ||
| #define WOLFSSL_SHA256 | ||
| #define HAVE_ECC | ||
| #define ECC_TIMING_RESISTANT | ||
| #define NO_ECC_SIGN | ||
| #define NO_ECC_VERIFY | ||
| #define NO_ECC_DHE | ||
| #define WC_RSA_BLINDING | ||
| #endif | ||
| EOF | ||
| build "ECC with no sign, verify or DHE" | ||
|
|
||
| cat > "$GITHUB_WORKSPACE/rcfg/user_settings.h" <<'EOF' | ||
| #ifndef RCFG_H | ||
| #define RCFG_H | ||
| #define WOLFSSL_NUVOTON_M2354 | ||
| #define SINGLE_THREADED | ||
| #define NO_FILESYSTEM | ||
| #define HAVE_HASHDRBG | ||
| #define WOLFSSL_SHA256 | ||
| #define HAVE_AES_CBC | ||
| #define WOLFSSL_AES_COUNTER | ||
| #define HAVE_ECC | ||
| #define HAVE_ECC_DHE | ||
| #define HAVE_ECC_SIGN | ||
| #define HAVE_ECC_VERIFY | ||
| #define ECC_TIMING_RESISTANT | ||
| #define WC_RSA_BLINDING | ||
| #define WOLFSSL_NUVOTON_NO_AESGCM | ||
| #define WOLFSSL_NUVOTON_NO_KS | ||
| #endif | ||
| EOF | ||
| build "no-GCM, no-KS opt-outs" | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.