blob: f0f09f198e57e3a49f5cb0e4efd8a03746bee783 [file] [log] [blame]
Gilles Peskineb39e3ec2019-01-29 08:50:20 +01001#!/usr/bin/env python3
2
3# Copyright (c) 2018, Arm Limited, All Rights Reserved.
4# SPDX-License-Identifier: Apache-2.0
5#
6# Licensed under the Apache License, Version 2.0 (the "License"); you may
7# not use this file except in compliance with the License.
8# You may obtain a copy of the License at
9#
10# http://www.apache.org/licenses/LICENSE-2.0
11#
12# Unless required by applicable law or agreed to in writing, software
13# distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
14# WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
15# See the License for the specific language governing permissions and
16# limitations under the License.
17#
18# This file is part of Mbed TLS (https://tls.mbed.org)
19
20"""Test Mbed TLS with a subset of algorithms.
21"""
22
23import argparse
24import os
25import re
26import shutil
27import subprocess
28import sys
29import traceback
30
Gilles Peskine0fa7cbe2019-01-29 18:48:48 +010031class Colors:
32 """Minimalistic support for colored output.
33Each field of an object of this class is either None if colored output
34is not possible or not desired, or a pair of strings (start, stop) such
35that outputting start switches the text color to the desired color and
36stop switches the text color back to the default."""
37 red = None
38 green = None
39 bold_red = None
40 bold_green = None
41 def __init__(self, options=None):
42 if not options or options.color in ['no', 'never']:
43 want_color = False
44 elif options.color in ['yes', 'always']:
45 want_color = True
46 else:
47 want_color = sys.stderr.isatty()
48 if want_color:
49 # Assume ANSI compatible terminal
50 normal = '\033[0m'
51 self.red = ('\033[31m', normal)
52 self.green = ('\033[32m', normal)
53 self.bold_red = ('\033[1;31m', normal)
54 self.bold_green = ('\033[1;32m', normal)
55NO_COLORS = Colors(None)
56
57def log_line(text, prefix='depends.py:', suffix='', color=None):
Gilles Peskineb39e3ec2019-01-29 08:50:20 +010058 """Print a status message."""
Gilles Peskine0fa7cbe2019-01-29 18:48:48 +010059 if color != None:
60 prefix = color[0] + prefix
61 suffix = suffix + color[1]
62 sys.stderr.write(prefix + ' ' + text + suffix + '\n')
Gilles Peskine46c82562019-01-29 18:42:55 +010063 sys.stderr.flush()
Gilles Peskineb39e3ec2019-01-29 08:50:20 +010064
Gilles Peskine54aa5c62019-01-29 18:46:34 +010065def log_command(cmd):
66 """Print a trace of the specified command.
67cmd is a list of strings: a command name and its arguments."""
68 log_line(' '.join(cmd), prefix='+')
69
Gilles Peskineb39e3ec2019-01-29 08:50:20 +010070def backup_config(options):
Gilles Peskinebf7537d2019-01-29 18:52:16 +010071 """Back up the library configuration file (config.h).
72If the backup file already exists, it is presumed to be the desired backup,
73so don't make another backup."""
74 if os.path.exists(options.config_backup):
75 options.own_backup = False
76 else:
77 options.own_backup = True
78 shutil.copy(options.config, options.config_backup)
Gilles Peskineb39e3ec2019-01-29 08:50:20 +010079
Gilles Peskinebf7537d2019-01-29 18:52:16 +010080def restore_config(options):
Gilles Peskineb39e3ec2019-01-29 08:50:20 +010081 """Restore the library configuration file (config.h).
Gilles Peskinebf7537d2019-01-29 18:52:16 +010082Remove the backup file if it was saved earlier."""
83 if options.own_backup:
Gilles Peskineb39e3ec2019-01-29 08:50:20 +010084 shutil.move(options.config_backup, options.config)
85 else:
86 shutil.copy(options.config_backup, options.config)
Gilles Peskinebf7537d2019-01-29 18:52:16 +010087
Gilles Peskine54aa5c62019-01-29 18:46:34 +010088def run_config_pl(options, args):
89 """Run scripts/config.pl with the specified arguments."""
90 cmd = ['scripts/config.pl']
91 if options.config != 'include/mbedtls/config.h':
92 cmd += ['--file', options.config]
93 cmd += args
94 log_command(cmd)
95 subprocess.check_call(cmd)
Gilles Peskineb39e3ec2019-01-29 08:50:20 +010096
97class Job:
98 """A job builds the library in a specific configuration and runs some tests."""
99 def __init__(self, name, config_settings, commands):
100 """Build a job object.
101The job uses the configuration described by config_settings. This is a
102dictionary where the keys are preprocessor symbols and the values are
103booleans or strings. A boolean indicates whether or not to #define the
104symbol. With a string, the symbol is #define'd to that value.
105After setting the configuration, the job runs the programs specified by
106commands. This is a list of lists of strings; each list of string is a
107command name and its arguments and is passed to subprocess.call with
108shell=False."""
109 self.name = name
110 self.config_settings = config_settings
111 self.commands = commands
112
Gilles Peskine0fa7cbe2019-01-29 18:48:48 +0100113 def announce(self, colors, what):
Gilles Peskineb39e3ec2019-01-29 08:50:20 +0100114 '''Announce the start or completion of a job.
115If what is None, announce the start of the job.
116If what is True, announce that the job has passed.
117If what is False, announce that the job has failed.'''
118 if what is True:
Gilles Peskine0fa7cbe2019-01-29 18:48:48 +0100119 log_line(self.name + ' PASSED', color=colors.green)
Gilles Peskineb39e3ec2019-01-29 08:50:20 +0100120 elif what is False:
Gilles Peskine0fa7cbe2019-01-29 18:48:48 +0100121 log_line(self.name + ' FAILED', color=colors.red)
Gilles Peskineb39e3ec2019-01-29 08:50:20 +0100122 else:
123 log_line('starting ' + self.name)
124
Gilles Peskinebf7537d2019-01-29 18:52:16 +0100125 def set_reference_config(self, options):
126 """Change the library configuration file (config.h) to the reference state.
127 The reference state is the one from which the tested configurations are
128 derived."""
129 # Turn off memory management options that are not relevant to
130 # the tests and slow them down.
131 run_config_pl(options, ['full'])
132 run_config_pl(options, ['unset', 'MBEDTLS_MEMORY_BACKTRACE'])
133 run_config_pl(options, ['unset', 'MBEDTLS_MEMORY_BUFFER_ALLOC_C'])
134 run_config_pl(options, ['unset', 'MBEDTLS_MEMORY_DEBUG'])
Gilles Peskineb39e3ec2019-01-29 08:50:20 +0100135
Gilles Peskine54aa5c62019-01-29 18:46:34 +0100136 def configure(self, options):
Gilles Peskineb39e3ec2019-01-29 08:50:20 +0100137 '''Set library configuration options as required for the job.
138config_file_name indicates which file to modify.'''
Gilles Peskinebf7537d2019-01-29 18:52:16 +0100139 self.set_reference_config(options)
Gilles Peskineb39e3ec2019-01-29 08:50:20 +0100140 for key, value in sorted(self.config_settings.items()):
141 if value is True:
142 args = ['set', key]
143 elif value is False:
144 args = ['unset', key]
145 else:
146 args = ['set', key, value]
Gilles Peskine54aa5c62019-01-29 18:46:34 +0100147 run_config_pl(options, args)
Gilles Peskineb39e3ec2019-01-29 08:50:20 +0100148
149 def test(self, options):
150 '''Run the job's build and test commands.
151Return True if all the commands succeed and False otherwise.
152If options.keep_going is false, stop as soon as one command fails. Otherwise
153run all the commands, except that if the first command fails, none of the
154other commands are run (typically, the first command is a build command
155and subsequent commands are tests that cannot run if the build failed).'''
156 built = False
157 success = True
158 for command in self.commands:
Gilles Peskine54aa5c62019-01-29 18:46:34 +0100159 log_command(command)
Gilles Peskineb39e3ec2019-01-29 08:50:20 +0100160 ret = subprocess.call(command)
161 if ret != 0:
162 if command[0] not in ['make', options.make_command]:
163 log_line('*** [{}] Error {}'.format(' '.join(command), ret))
164 if not options.keep_going or not built:
165 return False
166 success = False
167 built = True
168 return success
169
170# SSL/TLS versions up to 1.1 and corresponding options. These require
171# both MD5 and SHA-1.
172ssl_pre_1_2_dependencies = ['MBEDTLS_SSL_CBC_RECORD_SPLITTING',
173 'MBEDTLS_SSL_PROTO_SSL3',
174 'MBEDTLS_SSL_PROTO_TLS1',
175 'MBEDTLS_SSL_PROTO_TLS1_1']
176
177# If the configuration option A requires B, make sure that
178# B in reverse_dependencies[A].
179reverse_dependencies = {
180 'MBEDTLS_ECDSA_C': ['MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED'],
181 'MBEDTLS_ECP_C': ['MBEDTLS_ECDSA_C',
182 'MBEDTLS_ECDH_C',
183 'MBEDTLS_ECJPAKE_C',
184 'MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA_ENABLED',
185 'MBEDTLS_KEY_EXCHANGE_ECDH_RSA_ENABLED',
186 'MBEDTLS_KEY_EXCHANGE_ECDHE_PSK_ENABLED',
187 'MBEDTLS_KEY_EXCHANGE_ECDHE_RSA_ENABLED',
188 'MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED'],
189 'MBEDTLS_MD5_C': ssl_pre_1_2_dependencies,
190 'MBEDTLS_PKCS1_V21': ['MBEDTLS_X509_RSASSA_PSS_SUPPORT'],
191 'MBEDTLS_PKCS1_V15': ['MBEDTLS_KEY_EXCHANGE_DHE_RSA_ENABLED',
192 'MBEDTLS_KEY_EXCHANGE_ECDHE_RSA_ENABLED',
193 'MBEDTLS_KEY_EXCHANGE_RSA_PSK_ENABLED',
194 'MBEDTLS_KEY_EXCHANGE_RSA_ENABLED'],
195 'MBEDTLS_RSA_C': ['MBEDTLS_X509_RSASSA_PSS_SUPPORT',
196 'MBEDTLS_KEY_EXCHANGE_DHE_RSA_ENABLED',
197 'MBEDTLS_KEY_EXCHANGE_ECDHE_RSA_ENABLED',
198 'MBEDTLS_KEY_EXCHANGE_RSA_PSK_ENABLED',
199 'MBEDTLS_KEY_EXCHANGE_RSA_ENABLED'],
200 'MBEDTLS_SHA1_C': ssl_pre_1_2_dependencies,
201 'MBEDTLS_X509_RSASSA_PSS_SUPPORT': [],
202}
203
204def turn_off_dependencies(config_settings):
205 """For every option turned off config_settings, also turn off what depends on it.
206An option O is turned off if config_settings[O] is False."""
207 for key, value in sorted(config_settings.items()):
208 if value is not False:
209 continue
210 for dep in reverse_dependencies.get(key, []):
211 config_settings[dep] = False
212
213class Domain:
214 """A domain is a set of jobs that all relate to a particular configuration aspect."""
215 pass
216
217class ExclusiveDomain(Domain):
218 """A domain consisting of a set of conceptually-equivalent settings.
219Establish a list of configuration symbols. For each symbol, run a test job
220with this symbol set and the others unset, and a test job with this symbol
221unset and the others set."""
Gilles Peskineb1284cf2019-01-29 18:56:03 +0100222 def __init__(self, symbols, commands, exclude=None):
223 """Build a domain for the specified list of configuration symbols.
224The domain contains two sets of jobs: jobs that enable one of the elements
225of symbols and disable the others, and jobs that disable one of the elements
226of symbols and enable the others.
227Each job runs the specified commands.
228If exclude is a regular expression, skip generated jobs whose description
229would match this regular expression."""
Gilles Peskineb39e3ec2019-01-29 08:50:20 +0100230 self.jobs = []
231 for invert in [False, True]:
232 base_config_settings = {}
233 for symbol in symbols:
234 base_config_settings[symbol] = invert
235 for symbol in symbols:
236 description = '!' + symbol if invert else symbol
Gilles Peskineb1284cf2019-01-29 18:56:03 +0100237 if exclude and re.match(exclude, description):
238 continue
Gilles Peskineb39e3ec2019-01-29 08:50:20 +0100239 config_settings = base_config_settings.copy()
240 config_settings[symbol] = not invert
241 turn_off_dependencies(config_settings)
242 job = Job(description, config_settings, commands)
243 self.jobs.append(job)
244
245class ComplementaryDomain:
246 """A domain consisting of a set of loosely-related settings.
247Establish a list of configuration symbols. For each symbol, run a test job
248with this symbol unset."""
249 def __init__(self, symbols, commands):
Gilles Peskineb1284cf2019-01-29 18:56:03 +0100250 """Build a domain for the specified list of configuration symbols.
251Each job in the domain disables one of the specified symbols.
252Each job runs the specified commands."""
Gilles Peskineb39e3ec2019-01-29 08:50:20 +0100253 self.jobs = []
254 for symbol in symbols:
255 description = '!' + symbol
256 config_settings = {symbol: False}
257 turn_off_dependencies(config_settings)
258 job = Job(description, config_settings, commands)
259 self.jobs.append(job)
260
261class DomainData:
262 """Collect data about the library."""
263 def collect_config_symbols(self, options):
264 """Read the list of settings from config.h.
265Return them in a generator."""
266 with open(options.config) as config_file:
267 rx = re.compile(r'\s*(?://\s*)?#define\s+(\w+)\s*(?:$|/[/*])')
268 for line in config_file:
269 m = re.match(rx, line)
270 if m:
271 yield m.group(1)
272
273 def config_symbols_matching(self, regexp):
274 """List the config.h settings matching regexp."""
275 return [symbol for symbol in self.all_config_symbols
276 if re.match(regexp, symbol)]
277
278 def __init__(self, options):
279 """Gather data about the library and establish a list of domains to test."""
280 build_command = [options.make_command, 'CFLAGS=-Werror']
281 build_and_test = [build_command, [options.make_command, 'test']]
282 self.all_config_symbols = set(self.collect_config_symbols(options))
283 # Find hash modules by name.
284 hash_symbols = self.config_symbols_matching(r'MBEDTLS_(MD|RIPEMD|SHA)[0-9]+_C\Z')
285 # Find elliptic curve enabling macros by name.
286 curve_symbols = self.config_symbols_matching(r'MBEDTLS_ECP_DP_\w+_ENABLED\Z')
287 # Find key exchange enabling macros by name.
288 key_exchange_symbols = self.config_symbols_matching(r'MBEDTLS_KEY_EXCHANGE_\w+_ENABLED\Z')
289 self.domains = {
290 # Elliptic curves. Run the test suites.
291 'curves': ExclusiveDomain(curve_symbols, build_and_test),
292 # Hash algorithms. Exclude configurations with only one
293 # hash which is obsolete. Run the test suites.
Gilles Peskineb1284cf2019-01-29 18:56:03 +0100294 'hashes': ExclusiveDomain(hash_symbols, build_and_test,
295 exclude=r'MBEDTLS_(MD|RIPEMD|SHA1_)'),
Gilles Peskineb39e3ec2019-01-29 08:50:20 +0100296 # Key exchange types. Just check the build.
297 'kex': ExclusiveDomain(key_exchange_symbols, [build_command]),
298 # Public-key algorithms. Run the test suites.
299 'pkalgs': ComplementaryDomain(['MBEDTLS_ECDSA_C',
300 'MBEDTLS_ECP_C',
301 'MBEDTLS_PKCS1_V21',
302 'MBEDTLS_PKCS1_V15',
303 'MBEDTLS_RSA_C',
304 'MBEDTLS_X509_RSASSA_PSS_SUPPORT'],
305 build_and_test),
306 }
307 self.jobs = {}
308 for domain in self.domains.values():
309 for job in domain.jobs:
310 self.jobs[job.name] = job
311
312 def get_jobs(self, name):
313 """Return the list of jobs identified by the given name.
314A name can either be the name of a domain or the name of one specific job."""
315 if name in self.domains:
316 return sorted(self.domains[name].jobs, key=lambda job: job.name)
317 else:
318 return [self.jobs[name]]
319
Gilles Peskine0fa7cbe2019-01-29 18:48:48 +0100320def run(options, job, colors=NO_COLORS):
Gilles Peskineb39e3ec2019-01-29 08:50:20 +0100321 """Run the specified job (a Job instance)."""
322 subprocess.check_call([options.make_command, 'clean'])
Gilles Peskine0fa7cbe2019-01-29 18:48:48 +0100323 job.announce(colors, None)
Gilles Peskine54aa5c62019-01-29 18:46:34 +0100324 job.configure(options)
Gilles Peskineb39e3ec2019-01-29 08:50:20 +0100325 success = job.test(options)
Gilles Peskine0fa7cbe2019-01-29 18:48:48 +0100326 job.announce(colors, success)
Gilles Peskineb39e3ec2019-01-29 08:50:20 +0100327 return success
328
329def main(options, domain_data):
330 """Run the desired jobs.
331domain_data should be a DomainData instance that describes the available
332domains and jobs.
333Run the jobs listed in options.domains."""
334 if not hasattr(options, 'config_backup'):
335 options.config_backup = options.config + '.bak'
Gilles Peskine0fa7cbe2019-01-29 18:48:48 +0100336 colors = Colors(options)
Gilles Peskineb39e3ec2019-01-29 08:50:20 +0100337 jobs = []
338 failures = []
339 successes = []
340 for name in options.domains:
341 jobs += domain_data.get_jobs(name)
342 backup_config(options)
343 try:
344 for job in jobs:
Gilles Peskine0fa7cbe2019-01-29 18:48:48 +0100345 success = run(options, job, colors=colors)
Gilles Peskineb39e3ec2019-01-29 08:50:20 +0100346 if not success:
347 if options.keep_going:
348 failures.append(job.name)
349 else:
350 return False
351 else:
352 successes.append(job.name)
Gilles Peskinebf7537d2019-01-29 18:52:16 +0100353 restore_config(options)
354 except:
355 # Restore the configuration, except in stop-on-error mode if there
356 # was an error, where we leave the failing configuration up for
357 # developer convenience.
Gilles Peskineb39e3ec2019-01-29 08:50:20 +0100358 if options.keep_going:
Gilles Peskinebf7537d2019-01-29 18:52:16 +0100359 restore_config(options)
360 raise
Gilles Peskinee85163b2019-01-29 18:50:03 +0100361 if successes:
362 log_line('{} passed'.format(' '.join(successes)), color=colors.bold_green)
Gilles Peskineb39e3ec2019-01-29 08:50:20 +0100363 if failures:
Gilles Peskinee85163b2019-01-29 18:50:03 +0100364 log_line('{} FAILED'.format(' '.join(failures)), color=colors.bold_red)
Gilles Peskineb39e3ec2019-01-29 08:50:20 +0100365 return False
366 else:
Gilles Peskineb39e3ec2019-01-29 08:50:20 +0100367 return True
368
369
370if __name__ == '__main__':
371 try:
372 parser = argparse.ArgumentParser(description=__doc__)
Gilles Peskine0fa7cbe2019-01-29 18:48:48 +0100373 parser.add_argument('--color', metavar='WHEN',
374 help='Colorize the output (always/auto/never)',
375 choices=['always', 'auto', 'never'], default='auto')
Gilles Peskineb39e3ec2019-01-29 08:50:20 +0100376 parser.add_argument('-c', '--config', metavar='FILE',
377 help='Configuration file to modify',
378 default='include/mbedtls/config.h')
379 parser.add_argument('-C', '--directory', metavar='DIR',
380 help='Change to this directory before anything else',
381 default='.')
382 parser.add_argument('-k', '--keep-going',
383 help='Try all configurations even if some fail (default)',
384 action='store_true', dest='keep_going', default=True)
385 parser.add_argument('-e', '--no-keep-going',
386 help='Stop as soon as a configuration fails',
387 action='store_false', dest='keep_going')
388 parser.add_argument('--list-jobs',
389 help='List supported jobs and exit',
390 action='append_const', dest='list', const='jobs')
391 parser.add_argument('--list-domains',
392 help='List supported domains and exit',
393 action='append_const', dest='list', const='domains')
394 parser.add_argument('--make-command', metavar='CMD',
395 help='Command to run instead of make (e.g. gmake)',
396 action='store', default='make')
397 parser.add_argument('domains', metavar='DOMAIN', nargs='*',
398 help='The domain(s) to test (default: all)',
399 default=True)
400 options = parser.parse_args()
401 os.chdir(options.directory)
402 domain_data = DomainData(options)
403 if options.domains == True:
404 options.domains = sorted(domain_data.domains.keys())
405 if options.list:
406 for what in options.list:
407 for key in sorted(getattr(domain_data, what).keys()):
408 print(key)
409 exit(0)
410 else:
411 sys.exit(0 if main(options, domain_data) else 1)
412 except SystemExit:
413 raise
414 except:
415 traceback.print_exc()
416 exit(3)