blob: f82a1e5b0f291f139c544ce3fcd161a15a03071a [file] [log] [blame]
Gilles Peskine09940492021-01-26 22:16:30 +01001#!/usr/bin/env python3
2"""Generate test data for PSA cryptographic mechanisms.
Gilles Peskine0298bda2021-03-10 02:34:37 +01003
4With no arguments, generate all test data. With non-option arguments,
5generate only the specified files.
Gilles Peskine09940492021-01-26 22:16:30 +01006"""
7
8# Copyright The Mbed TLS Contributors
9# SPDX-License-Identifier: Apache-2.0
10#
11# Licensed under the Apache License, Version 2.0 (the "License"); you may
12# not use this file except in compliance with the License.
13# You may obtain a copy of the License at
14#
15# http://www.apache.org/licenses/LICENSE-2.0
16#
17# Unless required by applicable law or agreed to in writing, software
18# distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
19# WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
20# See the License for the specific language governing permissions and
21# limitations under the License.
22
23import argparse
Gilles Peskinecba28a72022-03-15 17:26:33 +010024import enum
Gilles Peskine14e428f2021-01-26 22:19:21 +010025import os
Bence Szépkúti9e84ec72021-05-07 11:49:17 +020026import posixpath
Gilles Peskine14e428f2021-01-26 22:19:21 +010027import re
Gilles Peskine09940492021-01-26 22:16:30 +010028import sys
Gilles Peskine3d778392021-02-17 15:11:05 +010029from typing import Callable, Dict, FrozenSet, Iterable, Iterator, List, Optional, TypeVar
Gilles Peskine09940492021-01-26 22:16:30 +010030
31import scripts_path # pylint: disable=unused-import
Gilles Peskinec86f20a2021-04-22 00:20:47 +020032from mbedtls_dev import build_tree
Gilles Peskine14e428f2021-01-26 22:19:21 +010033from mbedtls_dev import crypto_knowledge
Gilles Peskine09940492021-01-26 22:16:30 +010034from mbedtls_dev import macro_collector
Gilles Peskine897dff92021-03-10 15:03:44 +010035from mbedtls_dev import psa_storage
Gilles Peskine14e428f2021-01-26 22:19:21 +010036from mbedtls_dev import test_case
Gilles Peskine09940492021-01-26 22:16:30 +010037
38T = TypeVar('T') #pylint: disable=invalid-name
39
Gilles Peskine14e428f2021-01-26 22:19:21 +010040
Gilles Peskine7f756872021-02-16 12:13:12 +010041def psa_want_symbol(name: str) -> str:
Gilles Peskineaf172842021-01-27 18:24:48 +010042 """Return the PSA_WANT_xxx symbol associated with a PSA crypto feature."""
43 if name.startswith('PSA_'):
44 return name[:4] + 'WANT_' + name[4:]
45 else:
46 raise ValueError('Unable to determine the PSA_WANT_ symbol for ' + name)
47
Gilles Peskine7f756872021-02-16 12:13:12 +010048def finish_family_dependency(dep: str, bits: int) -> str:
49 """Finish dep if it's a family dependency symbol prefix.
50
51 A family dependency symbol prefix is a PSA_WANT_ symbol that needs to be
52 qualified by the key size. If dep is such a symbol, finish it by adjusting
53 the prefix and appending the key size. Other symbols are left unchanged.
54 """
55 return re.sub(r'_FAMILY_(.*)', r'_\1_' + str(bits), dep)
56
57def finish_family_dependencies(dependencies: List[str], bits: int) -> List[str]:
58 """Finish any family dependency symbol prefixes.
59
60 Apply `finish_family_dependency` to each element of `dependencies`.
61 """
62 return [finish_family_dependency(dep, bits) for dep in dependencies]
Gilles Peskineaf172842021-01-27 18:24:48 +010063
Gilles Peskinec5d086f2021-04-20 23:23:45 +020064SYMBOLS_WITHOUT_DEPENDENCY = frozenset([
65 'PSA_ALG_AEAD_WITH_AT_LEAST_THIS_LENGTH_TAG', # modifier, only in policies
66 'PSA_ALG_AEAD_WITH_SHORTENED_TAG', # modifier
67 'PSA_ALG_ANY_HASH', # only in policies
68 'PSA_ALG_AT_LEAST_THIS_LENGTH_MAC', # modifier, only in policies
69 'PSA_ALG_KEY_AGREEMENT', # chaining
70 'PSA_ALG_TRUNCATED_MAC', # modifier
71])
Gilles Peskinef8223ab2021-03-10 15:07:16 +010072def automatic_dependencies(*expressions: str) -> List[str]:
73 """Infer dependencies of a test case by looking for PSA_xxx symbols.
74
75 The arguments are strings which should be C expressions. Do not use
76 string literals or comments as this function is not smart enough to
77 skip them.
78 """
79 used = set()
80 for expr in expressions:
81 used.update(re.findall(r'PSA_(?:ALG|ECC_FAMILY|KEY_TYPE)_\w+', expr))
Gilles Peskinec5d086f2021-04-20 23:23:45 +020082 used.difference_update(SYMBOLS_WITHOUT_DEPENDENCY)
Gilles Peskinef8223ab2021-03-10 15:07:16 +010083 return sorted(psa_want_symbol(name) for name in used)
84
Gilles Peskined169d602021-02-16 14:16:25 +010085# A temporary hack: at the time of writing, not all dependency symbols
86# are implemented yet. Skip test cases for which the dependency symbols are
87# not available. Once all dependency symbols are available, this hack must
88# be removed so that a bug in the dependency symbols proprely leads to a test
89# failure.
90def read_implemented_dependencies(filename: str) -> FrozenSet[str]:
91 return frozenset(symbol
92 for line in open(filename)
93 for symbol in re.findall(r'\bPSA_WANT_\w+\b', line))
Gilles Peskinec86f20a2021-04-22 00:20:47 +020094_implemented_dependencies = None #type: Optional[FrozenSet[str]] #pylint: disable=invalid-name
Gilles Peskined169d602021-02-16 14:16:25 +010095def hack_dependencies_not_implemented(dependencies: List[str]) -> None:
Gilles Peskinec86f20a2021-04-22 00:20:47 +020096 global _implemented_dependencies #pylint: disable=global-statement,invalid-name
97 if _implemented_dependencies is None:
98 _implemented_dependencies = \
99 read_implemented_dependencies('include/psa/crypto_config.h')
Przemyslaw Stekielba20fc92021-10-22 10:39:56 +0200100 if not all((dep.lstrip('!') in _implemented_dependencies or 'PSA_WANT' not in dep)
Gilles Peskined169d602021-02-16 14:16:25 +0100101 for dep in dependencies):
102 dependencies.append('DEPENDENCY_NOT_IMPLEMENTED_YET')
103
Gilles Peskine14e428f2021-01-26 22:19:21 +0100104
Gilles Peskineb94ea512021-03-10 02:12:08 +0100105class Information:
106 """Gather information about PSA constructors."""
Gilles Peskine09940492021-01-26 22:16:30 +0100107
Gilles Peskineb94ea512021-03-10 02:12:08 +0100108 def __init__(self) -> None:
Gilles Peskine09940492021-01-26 22:16:30 +0100109 self.constructors = self.read_psa_interface()
110
111 @staticmethod
Gilles Peskine09940492021-01-26 22:16:30 +0100112 def remove_unwanted_macros(
Gilles Peskine537d5fa2021-04-19 13:50:25 +0200113 constructors: macro_collector.PSAMacroEnumerator
Gilles Peskine09940492021-01-26 22:16:30 +0100114 ) -> None:
Gilles Peskine537d5fa2021-04-19 13:50:25 +0200115 # Mbed TLS doesn't support finite-field DH yet and will not support
116 # finite-field DSA. Don't attempt to generate any related test case.
117 constructors.key_types.discard('PSA_KEY_TYPE_DH_KEY_PAIR')
118 constructors.key_types.discard('PSA_KEY_TYPE_DH_PUBLIC_KEY')
Gilles Peskine09940492021-01-26 22:16:30 +0100119 constructors.key_types.discard('PSA_KEY_TYPE_DSA_KEY_PAIR')
120 constructors.key_types.discard('PSA_KEY_TYPE_DSA_PUBLIC_KEY')
Gilles Peskine09940492021-01-26 22:16:30 +0100121
Gilles Peskine537d5fa2021-04-19 13:50:25 +0200122 def read_psa_interface(self) -> macro_collector.PSAMacroEnumerator:
Gilles Peskine09940492021-01-26 22:16:30 +0100123 """Return the list of known key types, algorithms, etc."""
Gilles Peskine3d404b82021-03-30 21:46:35 +0200124 constructors = macro_collector.InputsForTest()
Gilles Peskine09940492021-01-26 22:16:30 +0100125 header_file_names = ['include/psa/crypto_values.h',
126 'include/psa/crypto_extra.h']
Gilles Peskine537d5fa2021-04-19 13:50:25 +0200127 test_suites = ['tests/suites/test_suite_psa_crypto_metadata.data']
Gilles Peskine09940492021-01-26 22:16:30 +0100128 for header_file_name in header_file_names:
Gilles Peskine537d5fa2021-04-19 13:50:25 +0200129 constructors.parse_header(header_file_name)
130 for test_cases in test_suites:
131 constructors.parse_test_cases(test_cases)
Gilles Peskine09940492021-01-26 22:16:30 +0100132 self.remove_unwanted_macros(constructors)
Gilles Peskine3d404b82021-03-30 21:46:35 +0200133 constructors.gather_arguments()
Gilles Peskine09940492021-01-26 22:16:30 +0100134 return constructors
135
Gilles Peskine14e428f2021-01-26 22:19:21 +0100136
Przemyslaw Stekielb576c7b2021-10-11 10:15:25 +0200137def test_case_for_key_type_not_supported(
Gilles Peskineb94ea512021-03-10 02:12:08 +0100138 verb: str, key_type: str, bits: int,
139 dependencies: List[str],
140 *args: str,
141 param_descr: str = ''
142) -> test_case.TestCase:
143 """Return one test case exercising a key creation method
144 for an unsupported key type or size.
145 """
146 hack_dependencies_not_implemented(dependencies)
147 tc = test_case.TestCase()
148 short_key_type = re.sub(r'PSA_(KEY_TYPE|ECC_FAMILY)_', r'', key_type)
149 adverb = 'not' if dependencies else 'never'
150 if param_descr:
151 adverb = param_descr + ' ' + adverb
Przemyslaw Stekielb576c7b2021-10-11 10:15:25 +0200152 tc.set_description('PSA {} {} {}-bit {} supported'
153 .format(verb, short_key_type, bits, adverb))
154 tc.set_dependencies(dependencies)
155 tc.set_function(verb + '_not_supported')
156 tc.set_arguments([key_type] + list(args))
157 return tc
158
Gilles Peskineb94ea512021-03-10 02:12:08 +0100159class NotSupported:
Przemyslaw Stekiel8d468e42021-10-18 14:58:20 +0200160 """Generate test cases for when something is not supported."""
Gilles Peskineb94ea512021-03-10 02:12:08 +0100161
162 def __init__(self, info: Information) -> None:
163 self.constructors = info.constructors
Gilles Peskine14e428f2021-01-26 22:19:21 +0100164
Gilles Peskine60b29fe2021-02-16 14:06:50 +0100165 ALWAYS_SUPPORTED = frozenset([
166 'PSA_KEY_TYPE_DERIVE',
167 'PSA_KEY_TYPE_RAW_DATA',
168 ])
Gilles Peskine14e428f2021-01-26 22:19:21 +0100169 def test_cases_for_key_type_not_supported(
Gilles Peskine60b29fe2021-02-16 14:06:50 +0100170 self,
Gilles Peskineaf172842021-01-27 18:24:48 +0100171 kt: crypto_knowledge.KeyType,
172 param: Optional[int] = None,
173 param_descr: str = '',
Gilles Peskine3d778392021-02-17 15:11:05 +0100174 ) -> Iterator[test_case.TestCase]:
Przemyslaw Stekiel8d468e42021-10-18 14:58:20 +0200175 """Return test cases exercising key creation when the given type is unsupported.
Gilles Peskineaf172842021-01-27 18:24:48 +0100176
177 If param is present and not None, emit test cases conditioned on this
178 parameter not being supported. If it is absent or None, emit test cases
Przemyslaw Stekiel8d468e42021-10-18 14:58:20 +0200179 conditioned on the base type not being supported.
Gilles Peskineaf172842021-01-27 18:24:48 +0100180 """
Gilles Peskine60b29fe2021-02-16 14:06:50 +0100181 if kt.name in self.ALWAYS_SUPPORTED:
182 # Don't generate test cases for key types that are always supported.
183 # They would be skipped in all configurations, which is noise.
Gilles Peskine3d778392021-02-17 15:11:05 +0100184 return
Gilles Peskineaf172842021-01-27 18:24:48 +0100185 import_dependencies = [('!' if param is None else '') +
186 psa_want_symbol(kt.name)]
187 if kt.params is not None:
188 import_dependencies += [('!' if param == i else '') +
189 psa_want_symbol(sym)
190 for i, sym in enumerate(kt.params)]
Gilles Peskine14e428f2021-01-26 22:19:21 +0100191 if kt.name.endswith('_PUBLIC_KEY'):
192 generate_dependencies = []
193 else:
194 generate_dependencies = import_dependencies
Gilles Peskine14e428f2021-01-26 22:19:21 +0100195 for bits in kt.sizes_to_test():
Przemyslaw Stekielb576c7b2021-10-11 10:15:25 +0200196 yield test_case_for_key_type_not_supported(
Gilles Peskine7f756872021-02-16 12:13:12 +0100197 'import', kt.expression, bits,
198 finish_family_dependencies(import_dependencies, bits),
Gilles Peskineaf172842021-01-27 18:24:48 +0100199 test_case.hex_string(kt.key_material(bits)),
200 param_descr=param_descr,
Gilles Peskine3d778392021-02-17 15:11:05 +0100201 )
Gilles Peskineaf172842021-01-27 18:24:48 +0100202 if not generate_dependencies and param is not None:
203 # If generation is impossible for this key type, rather than
204 # supported or not depending on implementation capabilities,
205 # only generate the test case once.
206 continue
Przemyslaw Stekiel7bc26b82021-11-02 10:50:44 +0100207 # For public key we expect that key generation fails with
208 # INVALID_ARGUMENT. It is handled by KeyGenerate class.
Przemyslaw Stekiel8d468e42021-10-18 14:58:20 +0200209 if not kt.name.endswith('_PUBLIC_KEY'):
Przemyslaw Stekielb576c7b2021-10-11 10:15:25 +0200210 yield test_case_for_key_type_not_supported(
211 'generate', kt.expression, bits,
212 finish_family_dependencies(generate_dependencies, bits),
213 str(bits),
214 param_descr=param_descr,
215 )
Gilles Peskine14e428f2021-01-26 22:19:21 +0100216 # To be added: derive
Gilles Peskine14e428f2021-01-26 22:19:21 +0100217
Gilles Peskine537d5fa2021-04-19 13:50:25 +0200218 ECC_KEY_TYPES = ('PSA_KEY_TYPE_ECC_KEY_PAIR',
219 'PSA_KEY_TYPE_ECC_PUBLIC_KEY')
220
Gilles Peskine3d778392021-02-17 15:11:05 +0100221 def test_cases_for_not_supported(self) -> Iterator[test_case.TestCase]:
Gilles Peskine14e428f2021-01-26 22:19:21 +0100222 """Generate test cases that exercise the creation of keys of unsupported types."""
Gilles Peskine14e428f2021-01-26 22:19:21 +0100223 for key_type in sorted(self.constructors.key_types):
Gilles Peskine537d5fa2021-04-19 13:50:25 +0200224 if key_type in self.ECC_KEY_TYPES:
225 continue
Gilles Peskine14e428f2021-01-26 22:19:21 +0100226 kt = crypto_knowledge.KeyType(key_type)
Gilles Peskine3d778392021-02-17 15:11:05 +0100227 yield from self.test_cases_for_key_type_not_supported(kt)
Gilles Peskineaf172842021-01-27 18:24:48 +0100228 for curve_family in sorted(self.constructors.ecc_curves):
Gilles Peskine537d5fa2021-04-19 13:50:25 +0200229 for constr in self.ECC_KEY_TYPES:
Gilles Peskineaf172842021-01-27 18:24:48 +0100230 kt = crypto_knowledge.KeyType(constr, [curve_family])
Gilles Peskine3d778392021-02-17 15:11:05 +0100231 yield from self.test_cases_for_key_type_not_supported(
Gilles Peskineaf172842021-01-27 18:24:48 +0100232 kt, param_descr='type')
Gilles Peskine3d778392021-02-17 15:11:05 +0100233 yield from self.test_cases_for_key_type_not_supported(
Gilles Peskineaf172842021-01-27 18:24:48 +0100234 kt, 0, param_descr='curve')
Gilles Peskineb94ea512021-03-10 02:12:08 +0100235
Przemyslaw Stekiel1b0978b2021-10-15 15:21:51 +0200236def test_case_for_key_generation(
237 key_type: str, bits: int,
238 dependencies: List[str],
239 *args: str,
Przemyslaw Stekiel437da192021-10-20 11:59:50 +0200240 result: str = ''
Przemyslaw Stekiel1b0978b2021-10-15 15:21:51 +0200241) -> test_case.TestCase:
242 """Return one test case exercising a key generation.
243 """
244 hack_dependencies_not_implemented(dependencies)
245 tc = test_case.TestCase()
246 short_key_type = re.sub(r'PSA_(KEY_TYPE|ECC_FAMILY)_', r'', key_type)
247 tc.set_description('PSA {} {}-bit'
Przemyslaw Stekiel437da192021-10-20 11:59:50 +0200248 .format(short_key_type, bits))
Przemyslaw Stekiel1b0978b2021-10-15 15:21:51 +0200249 tc.set_dependencies(dependencies)
250 tc.set_function('generate_key')
Przemyslaw Stekiel7bc26b82021-11-02 10:50:44 +0100251 tc.set_arguments([key_type] + list(args) + [result])
Przemyslaw Stekiel1b0978b2021-10-15 15:21:51 +0200252
253 return tc
254
255class KeyGenerate:
256 """Generate positive and negative (invalid argument) test cases for key generation."""
257
258 def __init__(self, info: Information) -> None:
259 self.constructors = info.constructors
260
Przemyslaw Stekiel437da192021-10-20 11:59:50 +0200261 ECC_KEY_TYPES = ('PSA_KEY_TYPE_ECC_KEY_PAIR',
262 'PSA_KEY_TYPE_ECC_PUBLIC_KEY')
263
Przemyslaw Stekiel7bc26b82021-11-02 10:50:44 +0100264 @staticmethod
Przemyslaw Stekiel1b0978b2021-10-15 15:21:51 +0200265 def test_cases_for_key_type_key_generation(
Przemyslaw Stekiel437da192021-10-20 11:59:50 +0200266 kt: crypto_knowledge.KeyType
Przemyslaw Stekiel1b0978b2021-10-15 15:21:51 +0200267 ) -> Iterator[test_case.TestCase]:
268 """Return test cases exercising key generation.
269
270 All key types can be generated except for public keys. For public key
271 PSA_ERROR_INVALID_ARGUMENT status is expected.
272 """
273 result = 'PSA_SUCCESS'
274
275 import_dependencies = [psa_want_symbol(kt.name)]
276 if kt.params is not None:
277 import_dependencies += [psa_want_symbol(sym)
278 for i, sym in enumerate(kt.params)]
279 if kt.name.endswith('_PUBLIC_KEY'):
Przemyslaw Stekiel7bc26b82021-11-02 10:50:44 +0100280 # The library checks whether the key type is a public key generically,
281 # before it reaches a point where it needs support for the specific key
282 # type, so it returns INVALID_ARGUMENT for unsupported public key types.
Przemyslaw Stekiel1b0978b2021-10-15 15:21:51 +0200283 generate_dependencies = []
284 result = 'PSA_ERROR_INVALID_ARGUMENT'
285 else:
286 generate_dependencies = import_dependencies
Przemyslaw Stekiel7bc26b82021-11-02 10:50:44 +0100287 if kt.name == 'PSA_KEY_TYPE_RSA_KEY_PAIR':
Przemyslaw Stekielba20fc92021-10-22 10:39:56 +0200288 generate_dependencies.append("MBEDTLS_GENPRIME")
Przemyslaw Stekiel1b0978b2021-10-15 15:21:51 +0200289 for bits in kt.sizes_to_test():
290 yield test_case_for_key_generation(
291 kt.expression, bits,
292 finish_family_dependencies(generate_dependencies, bits),
293 str(bits),
Przemyslaw Stekiel437da192021-10-20 11:59:50 +0200294 result
Przemyslaw Stekiel1b0978b2021-10-15 15:21:51 +0200295 )
296
Przemyslaw Stekiel1b0978b2021-10-15 15:21:51 +0200297 def test_cases_for_key_generation(self) -> Iterator[test_case.TestCase]:
298 """Generate test cases that exercise the generation of keys."""
299 for key_type in sorted(self.constructors.key_types):
300 if key_type in self.ECC_KEY_TYPES:
301 continue
302 kt = crypto_knowledge.KeyType(key_type)
303 yield from self.test_cases_for_key_type_key_generation(kt)
304 for curve_family in sorted(self.constructors.ecc_curves):
305 for constr in self.ECC_KEY_TYPES:
306 kt = crypto_knowledge.KeyType(constr, [curve_family])
Przemyslaw Stekiel437da192021-10-20 11:59:50 +0200307 yield from self.test_cases_for_key_type_key_generation(kt)
Przemyslaw Stekiel1b0978b2021-10-15 15:21:51 +0200308
Gilles Peskinec7e1ea02021-04-27 20:40:10 +0200309class OpFail:
310 """Generate test cases for operations that must fail."""
311 #pylint: disable=too-few-public-methods
312
Gilles Peskinecba28a72022-03-15 17:26:33 +0100313 class Reason(enum.Enum):
314 NOT_SUPPORTED = 0
315 INVALID = 1
316 INCOMPATIBLE = 2
317
Gilles Peskinec7e1ea02021-04-27 20:40:10 +0200318 def __init__(self, info: Information) -> None:
319 self.constructors = info.constructors
Gilles Peskinecba28a72022-03-15 17:26:33 +0100320 key_type_expressions = self.constructors.generate_expressions(
321 sorted(self.constructors.key_types)
322 )
323 self.key_types = [crypto_knowledge.KeyType(kt_expr)
324 for kt_expr in key_type_expressions]
Gilles Peskinec7e1ea02021-04-27 20:40:10 +0200325
Gilles Peskinecba28a72022-03-15 17:26:33 +0100326 def make_test_case(
327 self,
328 alg: crypto_knowledge.Algorithm,
329 category: crypto_knowledge.AlgorithmCategory,
330 reason: 'Reason',
331 kt: Optional[crypto_knowledge.KeyType] = None,
332 not_deps: FrozenSet[str] = frozenset(),
333 ) -> test_case.TestCase:
334 """Construct a failure test case for a one-key or keyless operation."""
335 #pylint: disable=too-many-arguments,too-many-locals
Gilles Peskine8b4a3812021-04-27 21:03:43 +0200336 tc = test_case.TestCase()
Gilles Peskinecba28a72022-03-15 17:26:33 +0100337 pretty_alg = re.sub(r'PSA_ALG_', r'', alg.expression)
338 pretty_reason = reason.name.lower()
339 if kt:
340 key_type = kt.expression
341 pretty_type = re.sub(r'PSA_KEY_TYPE_', r'', key_type)
Gilles Peskine8b4a3812021-04-27 21:03:43 +0200342 else:
Gilles Peskinecba28a72022-03-15 17:26:33 +0100343 key_type = ''
344 pretty_type = ''
345 tc.set_description('PSA {} {}: {}{}'
346 .format(category.name.lower(),
347 pretty_alg,
348 pretty_reason,
349 ' with ' + pretty_type if pretty_type else ''))
350 dependencies = automatic_dependencies(alg.base_expression, key_type)
351 for i, dep in enumerate(dependencies):
352 if dep in not_deps:
353 dependencies[i] = '!' + dep
Gilles Peskine8b4a3812021-04-27 21:03:43 +0200354 tc.set_dependencies(dependencies)
Gilles Peskinecba28a72022-03-15 17:26:33 +0100355 tc.set_function(category.name.lower() + '_fail')
356 arguments = []
357 if kt:
358 key_material = kt.key_material(kt.sizes_to_test()[0])
359 arguments += [key_type, test_case.hex_string(key_material)]
360 arguments.append(alg.expression)
361 error = ('NOT_SUPPORTED' if reason == self.Reason.NOT_SUPPORTED else
362 'INVALID_ARGUMENT')
363 arguments.append('PSA_ERROR_' + error)
364 tc.set_arguments(arguments)
365 return tc
Gilles Peskine8b4a3812021-04-27 21:03:43 +0200366
Gilles Peskinecba28a72022-03-15 17:26:33 +0100367 def no_key_test_cases(
368 self,
369 alg: crypto_knowledge.Algorithm,
370 category: crypto_knowledge.AlgorithmCategory,
371 ) -> Iterator[test_case.TestCase]:
372 """Generate failure test cases for keyless operations with the specified algorithm."""
373 if category == alg.category:
374 # Compatible operation, unsupported algorithm
375 for dep in automatic_dependencies(alg.base_expression):
376 yield self.make_test_case(alg, category,
377 self.Reason.NOT_SUPPORTED,
378 not_deps=frozenset([dep]))
379 else:
380 # Incompatible operation, supported algorithm
381 yield self.make_test_case(alg, category, self.Reason.INVALID)
382
383 def one_key_test_cases(
384 self,
385 alg: crypto_knowledge.Algorithm,
386 category: crypto_knowledge.AlgorithmCategory,
387 ) -> Iterator[test_case.TestCase]:
388 """Generate failure test cases for one-key operations with the specified algorithm."""
389 for kt in self.key_types:
390 key_is_compatible = kt.can_do(alg)
391 # To do: public key for a private key operation
392 if key_is_compatible and category == alg.category:
393 # Compatible key and operation, unsupported algorithm
394 for dep in automatic_dependencies(alg.base_expression):
395 yield self.make_test_case(alg, category,
396 self.Reason.NOT_SUPPORTED,
397 kt=kt, not_deps=frozenset([dep]))
398 elif key_is_compatible:
399 # Compatible key, incompatible operation, supported algorithm
400 yield self.make_test_case(alg, category,
401 self.Reason.INVALID,
402 kt=kt)
403 elif category == alg.category:
404 # Incompatible key, compatible operation, supported algorithm
405 yield self.make_test_case(alg, category,
406 self.Reason.INCOMPATIBLE,
407 kt=kt)
408 else:
409 # Incompatible key and operation. Don't test cases where
410 # multiple things are wrong, to keep the number of test
411 # cases reasonable.
412 pass
413
414 def test_cases_for_algorithm(
415 self,
416 alg: crypto_knowledge.Algorithm,
417 ) -> Iterator[test_case.TestCase]:
Gilles Peskine8b4a3812021-04-27 21:03:43 +0200418 """Generate operation failure test cases for the specified algorithm."""
Gilles Peskinecba28a72022-03-15 17:26:33 +0100419 for category in crypto_knowledge.AlgorithmCategory:
420 if category == crypto_knowledge.AlgorithmCategory.PAKE:
421 # PAKE operations are not implemented yet
422 pass
423 elif category.requires_key():
424 yield from self.one_key_test_cases(alg, category)
425 else:
426 yield from self.no_key_test_cases(alg, category)
Gilles Peskine8b4a3812021-04-27 21:03:43 +0200427
Gilles Peskinec7e1ea02021-04-27 20:40:10 +0200428 def all_test_cases(self) -> Iterator[test_case.TestCase]:
429 """Generate all test cases for operations that must fail."""
Gilles Peskine8b4a3812021-04-27 21:03:43 +0200430 algorithms = sorted(self.constructors.algorithms)
Gilles Peskinecba28a72022-03-15 17:26:33 +0100431 for expr in self.constructors.generate_expressions(algorithms):
432 alg = crypto_knowledge.Algorithm(expr)
Gilles Peskine8b4a3812021-04-27 21:03:43 +0200433 yield from self.test_cases_for_algorithm(alg)
Gilles Peskinec7e1ea02021-04-27 20:40:10 +0200434
435
Gilles Peskine897dff92021-03-10 15:03:44 +0100436class StorageKey(psa_storage.Key):
437 """Representation of a key for storage format testing."""
438
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200439 IMPLICIT_USAGE_FLAGS = {
440 'PSA_KEY_USAGE_SIGN_HASH': 'PSA_KEY_USAGE_SIGN_MESSAGE',
441 'PSA_KEY_USAGE_VERIFY_HASH': 'PSA_KEY_USAGE_VERIFY_MESSAGE'
442 } #type: Dict[str, str]
443 """Mapping of usage flags to the flags that they imply."""
444
445 def __init__(
446 self,
447 usage: str,
448 without_implicit_usage: Optional[bool] = False,
449 **kwargs
450 ) -> None:
451 """Prepare to generate a key.
452
453 * `usage` : The usage flags used for the key.
454 * `without_implicit_usage`: Flag to defide to apply the usage extension
455 """
gabor-mezei-arm2c9e54a2021-06-29 17:21:21 +0200456 super().__init__(usage=usage, **kwargs)
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200457
458 if not without_implicit_usage:
459 for flag, implicit in self.IMPLICIT_USAGE_FLAGS.items():
460 if self.usage.value() & psa_storage.Expr(flag).value() and \
461 self.usage.value() & psa_storage.Expr(implicit).value() == 0:
462 self.usage = psa_storage.Expr(self.usage.string + ' | ' + implicit)
463
464class StorageTestData(StorageKey):
465 """Representation of test case data for storage format testing."""
466
gabor-mezei-arm672e3762021-06-24 10:16:44 +0200467 def __init__(
468 self,
469 description: str,
470 expected_usage: Optional[str] = None,
471 **kwargs
472 ) -> None:
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200473 """Prepare to generate test data
gabor-mezei-arm672e3762021-06-24 10:16:44 +0200474
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200475 * `description` : used for the the test case names
476 * `expected_usage`: the usage flags generated as the expected usage flags
477 in the test cases. CAn differ from the usage flags
478 stored in the keys because of the usage flags extension.
gabor-mezei-arm672e3762021-06-24 10:16:44 +0200479 """
Gilles Peskine897dff92021-03-10 15:03:44 +0100480 super().__init__(**kwargs)
481 self.description = description #type: str
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200482 self.expected_usage = expected_usage if expected_usage else self.usage.string #type: str
gabor-mezei-arm7748b6f2021-06-24 10:04:38 +0200483
Gilles Peskine897dff92021-03-10 15:03:44 +0100484class StorageFormat:
485 """Storage format stability test cases."""
486
487 def __init__(self, info: Information, version: int, forward: bool) -> None:
488 """Prepare to generate test cases for storage format stability.
489
490 * `info`: information about the API. See the `Information` class.
491 * `version`: the storage format version to generate test cases for.
492 * `forward`: if true, generate forward compatibility test cases which
493 save a key and check that its representation is as intended. Otherwise
494 generate backward compatibility test cases which inject a key
495 representation and check that it can be read and used.
496 """
gabor-mezei-arm7b5c4e22021-06-23 17:01:44 +0200497 self.constructors = info.constructors #type: macro_collector.PSAMacroEnumerator
498 self.version = version #type: int
499 self.forward = forward #type: bool
Gilles Peskine897dff92021-03-10 15:03:44 +0100500
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200501 def make_test_case(self, key: StorageTestData) -> test_case.TestCase:
Gilles Peskine897dff92021-03-10 15:03:44 +0100502 """Construct a storage format test case for the given key.
503
504 If ``forward`` is true, generate a forward compatibility test case:
505 create a key and validate that it has the expected representation.
506 Otherwise generate a backward compatibility test case: inject the
507 key representation into storage and validate that it can be read
508 correctly.
509 """
510 verb = 'save' if self.forward else 'read'
511 tc = test_case.TestCase()
512 tc.set_description('PSA storage {}: {}'.format(verb, key.description))
Gilles Peskinef8223ab2021-03-10 15:07:16 +0100513 dependencies = automatic_dependencies(
514 key.lifetime.string, key.type.string,
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200515 key.expected_usage, key.alg.string, key.alg2.string,
Gilles Peskinef8223ab2021-03-10 15:07:16 +0100516 )
517 dependencies = finish_family_dependencies(dependencies, key.bits)
518 tc.set_dependencies(dependencies)
Gilles Peskine897dff92021-03-10 15:03:44 +0100519 tc.set_function('key_storage_' + verb)
520 if self.forward:
521 extra_arguments = []
522 else:
Gilles Peskine45f1cd72021-04-21 20:11:33 +0200523 flags = []
Gilles Peskine897dff92021-03-10 15:03:44 +0100524 # Some test keys have the RAW_DATA type and attributes that don't
525 # necessarily make sense. We do this to validate numerical
526 # encodings of the attributes.
527 # Raw data keys have no useful exercise anyway so there is no
528 # loss of test coverage.
Gilles Peskine45f1cd72021-04-21 20:11:33 +0200529 if key.type.string != 'PSA_KEY_TYPE_RAW_DATA':
530 flags.append('TEST_FLAG_EXERCISE')
531 if 'READ_ONLY' in key.lifetime.string:
532 flags.append('TEST_FLAG_READ_ONLY')
533 extra_arguments = [' | '.join(flags) if flags else '0']
Gilles Peskine897dff92021-03-10 15:03:44 +0100534 tc.set_arguments([key.lifetime.string,
535 key.type.string, str(key.bits),
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200536 key.expected_usage, key.alg.string, key.alg2.string,
Gilles Peskine897dff92021-03-10 15:03:44 +0100537 '"' + key.material.hex() + '"',
538 '"' + key.hex() + '"',
539 *extra_arguments])
540 return tc
541
Gilles Peskineeb7bdaa2021-04-21 22:05:34 +0200542 def key_for_lifetime(
543 self,
544 lifetime: str,
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200545 ) -> StorageTestData:
Gilles Peskineeb7bdaa2021-04-21 22:05:34 +0200546 """Construct a test key for the given lifetime."""
547 short = lifetime
548 short = re.sub(r'PSA_KEY_LIFETIME_FROM_PERSISTENCE_AND_LOCATION',
549 r'', short)
550 short = re.sub(r'PSA_KEY_[A-Z]+_', r'', short)
551 description = 'lifetime: ' + short
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200552 key = StorageTestData(version=self.version,
553 id=1, lifetime=lifetime,
554 type='PSA_KEY_TYPE_RAW_DATA', bits=8,
555 usage='PSA_KEY_USAGE_EXPORT', alg=0, alg2=0,
556 material=b'L',
557 description=description)
558 return key
Gilles Peskineeb7bdaa2021-04-21 22:05:34 +0200559
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200560 def all_keys_for_lifetimes(self) -> Iterator[StorageTestData]:
Gilles Peskineeb7bdaa2021-04-21 22:05:34 +0200561 """Generate test keys covering lifetimes."""
562 lifetimes = sorted(self.constructors.lifetimes)
563 expressions = self.constructors.generate_expressions(lifetimes)
564 for lifetime in expressions:
565 # Don't attempt to create or load a volatile key in storage
566 if 'VOLATILE' in lifetime:
567 continue
568 # Don't attempt to create a read-only key in storage,
569 # but do attempt to load one.
570 if 'READ_ONLY' in lifetime and self.forward:
571 continue
gabor-mezei-arm340fbf32021-06-28 19:26:55 +0200572 yield self.key_for_lifetime(lifetime)
Gilles Peskineeb7bdaa2021-04-21 22:05:34 +0200573
Gilles Peskinef7614272022-02-24 18:58:08 +0100574 def key_for_usage_flags(
Gilles Peskine897dff92021-03-10 15:03:44 +0100575 self,
576 usage_flags: List[str],
gabor-mezei-arm6ee72532021-06-24 09:42:02 +0200577 short: Optional[str] = None,
Gilles Peskinef7614272022-02-24 18:58:08 +0100578 test_implicit_usage: Optional[bool] = True
579 ) -> StorageTestData:
Gilles Peskine897dff92021-03-10 15:03:44 +0100580 """Construct a test key for the given key usage."""
581 usage = ' | '.join(usage_flags) if usage_flags else '0'
582 if short is None:
583 short = re.sub(r'\bPSA_KEY_USAGE_', r'', usage)
Gilles Peskinef7614272022-02-24 18:58:08 +0100584 extra_desc = ' without implication' if test_implicit_usage else ''
gabor-mezei-arm6ee72532021-06-24 09:42:02 +0200585 description = 'usage' + extra_desc + ': ' + short
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200586 key1 = StorageTestData(version=self.version,
587 id=1, lifetime=0x00000001,
588 type='PSA_KEY_TYPE_RAW_DATA', bits=8,
589 expected_usage=usage,
Gilles Peskinef7614272022-02-24 18:58:08 +0100590 without_implicit_usage=not test_implicit_usage,
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200591 usage=usage, alg=0, alg2=0,
592 material=b'K',
593 description=description)
Gilles Peskinef7614272022-02-24 18:58:08 +0100594 return key1
Gilles Peskine897dff92021-03-10 15:03:44 +0100595
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200596 def generate_keys_for_usage_flags(self, **kwargs) -> Iterator[StorageTestData]:
Gilles Peskine897dff92021-03-10 15:03:44 +0100597 """Generate test keys covering usage flags."""
598 known_flags = sorted(self.constructors.key_usage_flags)
Gilles Peskinef7614272022-02-24 18:58:08 +0100599 yield self.key_for_usage_flags(['0'], **kwargs)
gabor-mezei-arm340fbf32021-06-28 19:26:55 +0200600 for usage_flag in known_flags:
Gilles Peskinef7614272022-02-24 18:58:08 +0100601 yield self.key_for_usage_flags([usage_flag], **kwargs)
gabor-mezei-arm340fbf32021-06-28 19:26:55 +0200602 for flag1, flag2 in zip(known_flags,
603 known_flags[1:] + [known_flags[0]]):
Gilles Peskinef7614272022-02-24 18:58:08 +0100604 yield self.key_for_usage_flags([flag1, flag2], **kwargs)
gabor-mezei-arm49d6ea92021-06-24 14:38:51 +0200605
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200606 def generate_key_for_all_usage_flags(self) -> Iterator[StorageTestData]:
gabor-mezei-arm49d6ea92021-06-24 14:38:51 +0200607 known_flags = sorted(self.constructors.key_usage_flags)
Gilles Peskinef7614272022-02-24 18:58:08 +0100608 yield self.key_for_usage_flags(known_flags, short='all known')
gabor-mezei-arm49d6ea92021-06-24 14:38:51 +0200609
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200610 def all_keys_for_usage_flags(self) -> Iterator[StorageTestData]:
gabor-mezei-arm340fbf32021-06-28 19:26:55 +0200611 yield from self.generate_keys_for_usage_flags()
612 yield from self.generate_key_for_all_usage_flags()
Gilles Peskine897dff92021-03-10 15:03:44 +0100613
Gilles Peskinef8223ab2021-03-10 15:07:16 +0100614 def keys_for_type(
615 self,
616 key_type: str,
617 params: Optional[Iterable[str]] = None
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200618 ) -> Iterator[StorageTestData]:
Gilles Peskinef8223ab2021-03-10 15:07:16 +0100619 """Generate test keys for the given key type.
620
621 For key types that depend on a parameter (e.g. elliptic curve family),
622 `param` is the parameter to pass to the constructor. Only a single
623 parameter is supported.
624 """
625 kt = crypto_knowledge.KeyType(key_type, params)
626 for bits in kt.sizes_to_test():
627 usage_flags = 'PSA_KEY_USAGE_EXPORT'
628 alg = 0
629 alg2 = 0
630 key_material = kt.key_material(bits)
631 short_expression = re.sub(r'\bPSA_(?:KEY_TYPE|ECC_FAMILY)_',
632 r'',
633 kt.expression)
634 description = 'type: {} {}-bit'.format(short_expression, bits)
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200635 key = StorageTestData(version=self.version,
636 id=1, lifetime=0x00000001,
637 type=kt.expression, bits=bits,
638 usage=usage_flags, alg=alg, alg2=alg2,
639 material=key_material,
640 description=description)
641 yield key
Gilles Peskinef8223ab2021-03-10 15:07:16 +0100642
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200643 def all_keys_for_types(self) -> Iterator[StorageTestData]:
Gilles Peskinef8223ab2021-03-10 15:07:16 +0100644 """Generate test keys covering key types and their representations."""
Gilles Peskine537d5fa2021-04-19 13:50:25 +0200645 key_types = sorted(self.constructors.key_types)
gabor-mezei-arm340fbf32021-06-28 19:26:55 +0200646 for key_type in self.constructors.generate_expressions(key_types):
647 yield from self.keys_for_type(key_type)
Gilles Peskinef8223ab2021-03-10 15:07:16 +0100648
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200649 def keys_for_algorithm(self, alg: str) -> Iterator[StorageTestData]:
Gilles Peskined86bc522021-03-10 15:08:57 +0100650 """Generate test keys for the specified algorithm."""
651 # For now, we don't have information on the compatibility of key
652 # types and algorithms. So we just test the encoding of algorithms,
653 # and not that operations can be performed with them.
Gilles Peskine20f55f62021-04-21 10:18:19 +0200654 descr = re.sub(r'PSA_ALG_', r'', alg)
655 descr = re.sub(r',', r', ', re.sub(r' +', r'', descr))
Gilles Peskined86bc522021-03-10 15:08:57 +0100656 usage = 'PSA_KEY_USAGE_EXPORT'
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200657 key1 = StorageTestData(version=self.version,
658 id=1, lifetime=0x00000001,
659 type='PSA_KEY_TYPE_RAW_DATA', bits=8,
660 usage=usage, alg=alg, alg2=0,
661 material=b'K',
662 description='alg: ' + descr)
663 yield key1
664 key2 = StorageTestData(version=self.version,
665 id=1, lifetime=0x00000001,
666 type='PSA_KEY_TYPE_RAW_DATA', bits=8,
667 usage=usage, alg=0, alg2=alg,
668 material=b'L',
669 description='alg2: ' + descr)
670 yield key2
Gilles Peskined86bc522021-03-10 15:08:57 +0100671
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200672 def all_keys_for_algorithms(self) -> Iterator[StorageTestData]:
Gilles Peskined86bc522021-03-10 15:08:57 +0100673 """Generate test keys covering algorithm encodings."""
Gilles Peskine537d5fa2021-04-19 13:50:25 +0200674 algorithms = sorted(self.constructors.algorithms)
gabor-mezei-arm340fbf32021-06-28 19:26:55 +0200675 for alg in self.constructors.generate_expressions(algorithms):
676 yield from self.keys_for_algorithm(alg)
Gilles Peskined86bc522021-03-10 15:08:57 +0100677
gabor-mezei-arm0c24edd2021-06-29 15:42:57 +0200678 def generate_all_keys(self) -> Iterator[StorageTestData]:
gabor-mezei-arm780cf9d2021-06-24 09:49:50 +0200679 """Generate all keys for the test cases."""
gabor-mezei-arm0c24edd2021-06-29 15:42:57 +0200680 yield from self.all_keys_for_lifetimes()
681 yield from self.all_keys_for_usage_flags()
682 yield from self.all_keys_for_types()
683 yield from self.all_keys_for_algorithms()
gabor-mezei-arm780cf9d2021-06-24 09:49:50 +0200684
gabor-mezei-arm340fbf32021-06-28 19:26:55 +0200685 def all_test_cases(self) -> Iterator[test_case.TestCase]:
Gilles Peskine897dff92021-03-10 15:03:44 +0100686 """Generate all storage format test cases."""
Gilles Peskine3c9d4232021-04-12 14:43:05 +0200687 # First build a list of all keys, then construct all the corresponding
688 # test cases. This allows all required information to be obtained in
689 # one go, which is a significant performance gain as the information
690 # includes numerical values obtained by compiling a C program.
Gilles Peskine45f2a402021-07-06 21:05:52 +0200691 all_keys = list(self.generate_all_keys())
692 for key in all_keys:
gabor-mezei-arm340fbf32021-06-28 19:26:55 +0200693 if key.location_value() != 0:
694 # Skip keys with a non-default location, because they
695 # require a driver and we currently have no mechanism to
696 # determine whether a driver is available.
697 continue
698 yield self.make_test_case(key)
Gilles Peskine897dff92021-03-10 15:03:44 +0100699
gabor-mezei-arma4102cb2021-06-24 09:53:26 +0200700class StorageFormatForward(StorageFormat):
701 """Storage format stability test cases for forward compatibility."""
702
703 def __init__(self, info: Information, version: int) -> None:
704 super().__init__(info, version, True)
705
706class StorageFormatV0(StorageFormat):
707 """Storage format stability test cases for version 0 compatibility."""
708
709 def __init__(self, info: Information) -> None:
710 super().__init__(info, 0, False)
Gilles Peskine897dff92021-03-10 15:03:44 +0100711
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200712 def all_keys_for_usage_flags(self) -> Iterator[StorageTestData]:
gabor-mezei-arm7748b6f2021-06-24 10:04:38 +0200713 """Generate test keys covering usage flags."""
Gilles Peskinef7614272022-02-24 18:58:08 +0100714 yield from super().all_keys_for_usage_flags()
715 yield from self.generate_keys_for_usage_flags(test_implicit_usage=False)
gabor-mezei-arm7748b6f2021-06-24 10:04:38 +0200716
gabor-mezei-arm5df1dee2021-06-28 17:40:32 +0200717 def keys_for_implicit_usage(
gabor-mezei-arm672e3762021-06-24 10:16:44 +0200718 self,
gabor-mezei-arm2710bb12021-06-28 16:54:11 +0200719 implyer_usage: str,
gabor-mezei-arm672e3762021-06-24 10:16:44 +0200720 alg: str,
gabor-mezei-arm2784bfe2021-06-28 20:02:11 +0200721 key_type: crypto_knowledge.KeyType
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200722 ) -> StorageTestData:
gabor-mezei-arm0f8136a2021-06-24 14:38:25 +0200723 # pylint: disable=too-many-locals
gabor-mezei-arm8f405102021-06-28 16:27:29 +0200724 """Generate test keys for the specified implicit usage flag,
gabor-mezei-arm672e3762021-06-24 10:16:44 +0200725 algorithm and key type combination.
726 """
gabor-mezei-arm2784bfe2021-06-28 20:02:11 +0200727 bits = key_type.sizes_to_test()[0]
gabor-mezei-arm2710bb12021-06-28 16:54:11 +0200728 implicit_usage = StorageKey.IMPLICIT_USAGE_FLAGS[implyer_usage]
gabor-mezei-armd9050a52021-06-28 16:35:48 +0200729 usage_flags = 'PSA_KEY_USAGE_EXPORT'
gabor-mezei-arm2710bb12021-06-28 16:54:11 +0200730 material_usage_flags = usage_flags + ' | ' + implyer_usage
731 expected_usage_flags = material_usage_flags + ' | ' + implicit_usage
gabor-mezei-armd9050a52021-06-28 16:35:48 +0200732 alg2 = 0
gabor-mezei-arm2784bfe2021-06-28 20:02:11 +0200733 key_material = key_type.key_material(bits)
gabor-mezei-arm2710bb12021-06-28 16:54:11 +0200734 usage_expression = re.sub(r'PSA_KEY_USAGE_', r'', implyer_usage)
gabor-mezei-armd9050a52021-06-28 16:35:48 +0200735 alg_expression = re.sub(r'PSA_ALG_', r'', alg)
736 alg_expression = re.sub(r',', r', ', re.sub(r' +', r'', alg_expression))
737 key_type_expression = re.sub(r'\bPSA_(?:KEY_TYPE|ECC_FAMILY)_',
738 r'',
gabor-mezei-arm2784bfe2021-06-28 20:02:11 +0200739 key_type.expression)
gabor-mezei-arm5df1dee2021-06-28 17:40:32 +0200740 description = 'implied by {}: {} {} {}-bit'.format(
gabor-mezei-armd9050a52021-06-28 16:35:48 +0200741 usage_expression, alg_expression, key_type_expression, bits)
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200742 key = StorageTestData(version=self.version,
743 id=1, lifetime=0x00000001,
744 type=key_type.expression, bits=bits,
745 usage=material_usage_flags,
746 expected_usage=expected_usage_flags,
747 without_implicit_usage=True,
748 alg=alg, alg2=alg2,
749 material=key_material,
750 description=description)
751 return key
gabor-mezei-arm672e3762021-06-24 10:16:44 +0200752
753 def gather_key_types_for_sign_alg(self) -> Dict[str, List[str]]:
gabor-mezei-arm0f8136a2021-06-24 14:38:25 +0200754 # pylint: disable=too-many-locals
gabor-mezei-arm672e3762021-06-24 10:16:44 +0200755 """Match possible key types for sign algorithms."""
756 # To create a valid combinaton both the algorithms and key types
757 # must be filtered. Pair them with keywords created from its names.
758 incompatible_alg_keyword = frozenset(['RAW', 'ANY', 'PURE'])
759 incompatible_key_type_keywords = frozenset(['MONTGOMERY'])
760 keyword_translation = {
761 'ECDSA': 'ECC',
762 'ED[0-9]*.*' : 'EDWARDS'
763 }
764 exclusive_keywords = {
765 'EDWARDS': 'ECC'
766 }
gabor-mezei-arm0f8136a2021-06-24 14:38:25 +0200767 key_types = set(self.constructors.generate_expressions(self.constructors.key_types))
768 algorithms = set(self.constructors.generate_expressions(self.constructors.sign_algorithms))
gabor-mezei-arm672e3762021-06-24 10:16:44 +0200769 alg_with_keys = {} #type: Dict[str, List[str]]
770 translation_table = str.maketrans('(', '_', ')')
771 for alg in algorithms:
772 # Generate keywords from the name of the algorithm
773 alg_keywords = set(alg.partition('(')[0].split(sep='_')[2:])
774 # Translate keywords for better matching with the key types
775 for keyword in alg_keywords.copy():
776 for pattern, replace in keyword_translation.items():
777 if re.match(pattern, keyword):
778 alg_keywords.remove(keyword)
779 alg_keywords.add(replace)
780 # Filter out incompatible algortihms
781 if not alg_keywords.isdisjoint(incompatible_alg_keyword):
782 continue
783
784 for key_type in key_types:
785 # Generate keywords from the of the key type
786 key_type_keywords = set(key_type.translate(translation_table).split(sep='_')[3:])
787
788 # Remove ambigious keywords
789 for keyword1, keyword2 in exclusive_keywords.items():
790 if keyword1 in key_type_keywords:
791 key_type_keywords.remove(keyword2)
792
793 if key_type_keywords.isdisjoint(incompatible_key_type_keywords) and\
794 not key_type_keywords.isdisjoint(alg_keywords):
795 if alg in alg_with_keys:
796 alg_with_keys[alg].append(key_type)
797 else:
798 alg_with_keys[alg] = [key_type]
799 return alg_with_keys
800
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200801 def all_keys_for_implicit_usage(self) -> Iterator[StorageTestData]:
gabor-mezei-arm672e3762021-06-24 10:16:44 +0200802 """Generate test keys for usage flag extensions."""
803 # Generate a key type and algorithm pair for each extendable usage
804 # flag to generate a valid key for exercising. The key is generated
805 # without usage extension to check the extension compatiblity.
gabor-mezei-arm672e3762021-06-24 10:16:44 +0200806 alg_with_keys = self.gather_key_types_for_sign_alg()
gabor-mezei-arm11e48382021-06-24 16:35:01 +0200807
gabor-mezei-arm340fbf32021-06-28 19:26:55 +0200808 for usage in sorted(StorageKey.IMPLICIT_USAGE_FLAGS, key=str):
809 for alg in sorted(alg_with_keys):
810 for key_type in sorted(alg_with_keys[alg]):
811 # The key types must be filtered to fit the specific usage flag.
gabor-mezei-arm2784bfe2021-06-28 20:02:11 +0200812 kt = crypto_knowledge.KeyType(key_type)
813 if kt.is_valid_for_signature(usage):
814 yield self.keys_for_implicit_usage(usage, alg, kt)
gabor-mezei-arm672e3762021-06-24 10:16:44 +0200815
gabor-mezei-arm0c24edd2021-06-29 15:42:57 +0200816 def generate_all_keys(self) -> Iterator[StorageTestData]:
817 yield from super().generate_all_keys()
818 yield from self.all_keys_for_implicit_usage()
gabor-mezei-arm7748b6f2021-06-24 10:04:38 +0200819
Gilles Peskineb94ea512021-03-10 02:12:08 +0100820class TestGenerator:
821 """Generate test data."""
822
823 def __init__(self, options) -> None:
824 self.test_suite_directory = self.get_option(options, 'directory',
825 'tests/suites')
826 self.info = Information()
827
828 @staticmethod
829 def get_option(options, name: str, default: T) -> T:
830 value = getattr(options, name, None)
831 return default if value is None else value
832
Gilles Peskine0298bda2021-03-10 02:34:37 +0100833 def filename_for(self, basename: str) -> str:
834 """The location of the data file with the specified base name."""
Bence Szépkúti9e84ec72021-05-07 11:49:17 +0200835 return posixpath.join(self.test_suite_directory, basename + '.data')
Gilles Peskine0298bda2021-03-10 02:34:37 +0100836
Gilles Peskineb94ea512021-03-10 02:12:08 +0100837 def write_test_data_file(self, basename: str,
838 test_cases: Iterable[test_case.TestCase]) -> None:
839 """Write the test cases to a .data file.
840
841 The output file is ``basename + '.data'`` in the test suite directory.
842 """
Gilles Peskine0298bda2021-03-10 02:34:37 +0100843 filename = self.filename_for(basename)
Gilles Peskineb94ea512021-03-10 02:12:08 +0100844 test_case.write_data_file(filename, test_cases)
845
Gilles Peskine92165362021-04-23 16:37:12 +0200846 # Note that targets whose name containns 'test_format' have their content
847 # validated by `abi_check.py`.
Gilles Peskine0298bda2021-03-10 02:34:37 +0100848 TARGETS = {
Przemyslaw Stekiel1b0978b2021-10-15 15:21:51 +0200849 'test_suite_psa_crypto_generate_key.generated':
850 lambda info: KeyGenerate(info).test_cases_for_key_generation(),
Gilles Peskine0298bda2021-03-10 02:34:37 +0100851 'test_suite_psa_crypto_not_supported.generated':
Gilles Peskine3d778392021-02-17 15:11:05 +0100852 lambda info: NotSupported(info).test_cases_for_not_supported(),
Gilles Peskinec7e1ea02021-04-27 20:40:10 +0200853 'test_suite_psa_crypto_op_fail.generated':
854 lambda info: OpFail(info).all_test_cases(),
Gilles Peskine897dff92021-03-10 15:03:44 +0100855 'test_suite_psa_crypto_storage_format.current':
gabor-mezei-arma4102cb2021-06-24 09:53:26 +0200856 lambda info: StorageFormatForward(info, 0).all_test_cases(),
Gilles Peskine897dff92021-03-10 15:03:44 +0100857 'test_suite_psa_crypto_storage_format.v0':
gabor-mezei-arma4102cb2021-06-24 09:53:26 +0200858 lambda info: StorageFormatV0(info).all_test_cases(),
Gilles Peskine0298bda2021-03-10 02:34:37 +0100859 } #type: Dict[str, Callable[[Information], Iterable[test_case.TestCase]]]
860
861 def generate_target(self, name: str) -> None:
862 test_cases = self.TARGETS[name](self.info)
863 self.write_test_data_file(name, test_cases)
Gilles Peskine14e428f2021-01-26 22:19:21 +0100864
Gilles Peskine09940492021-01-26 22:16:30 +0100865def main(args):
866 """Command line entry point."""
867 parser = argparse.ArgumentParser(description=__doc__)
Gilles Peskine0298bda2021-03-10 02:34:37 +0100868 parser.add_argument('--list', action='store_true',
869 help='List available targets and exit')
David Horstmanne12e7f42021-10-15 19:10:15 +0100870 parser.add_argument('--list-for-cmake', action='store_true',
871 help='Print \';\'-separated list of available targets and exit')
Manuel Pégourié-Gonnarda9cb8942021-05-14 11:37:09 +0200872 parser.add_argument('--directory', metavar='DIR',
873 help='Output directory (default: tests/suites)')
Gilles Peskine0298bda2021-03-10 02:34:37 +0100874 parser.add_argument('targets', nargs='*', metavar='TARGET',
875 help='Target file to generate (default: all; "-": none)')
Gilles Peskine09940492021-01-26 22:16:30 +0100876 options = parser.parse_args(args)
Gilles Peskinec86f20a2021-04-22 00:20:47 +0200877 build_tree.chdir_to_root()
Gilles Peskine09940492021-01-26 22:16:30 +0100878 generator = TestGenerator(options)
Gilles Peskine0298bda2021-03-10 02:34:37 +0100879 if options.list:
880 for name in sorted(generator.TARGETS):
881 print(generator.filename_for(name))
882 return
David Horstmanne12e7f42021-10-15 19:10:15 +0100883 # List in a cmake list format (i.e. ';'-separated)
884 if options.list_for_cmake:
David Horstmann65d8c692021-10-21 16:09:51 +0100885 print(';'.join(generator.filename_for(name)
886 for name in sorted(generator.TARGETS)), end='')
David Horstmanne12e7f42021-10-15 19:10:15 +0100887 return
Gilles Peskine0298bda2021-03-10 02:34:37 +0100888 if options.targets:
889 # Allow "-" as a special case so you can run
890 # ``generate_psa_tests.py - $targets`` and it works uniformly whether
891 # ``$targets`` is empty or not.
892 options.targets = [os.path.basename(re.sub(r'\.data\Z', r'', target))
893 for target in options.targets
894 if target != '-']
895 else:
896 options.targets = sorted(generator.TARGETS)
897 for target in options.targets:
898 generator.generate_target(target)
Gilles Peskine09940492021-01-26 22:16:30 +0100899
900if __name__ == '__main__':
901 main(sys.argv[1:])