blob: 6c05b8937721a68ccb31afe0f8b256b8e8da3337 [file] [log] [blame]
Gilles Peskine09940492021-01-26 22:16:30 +01001#!/usr/bin/env python3
2"""Generate test data for PSA cryptographic mechanisms.
Gilles Peskine0298bda2021-03-10 02:34:37 +01003
4With no arguments, generate all test data. With non-option arguments,
5generate only the specified files.
Gilles Peskine09940492021-01-26 22:16:30 +01006"""
7
8# Copyright The Mbed TLS Contributors
9# SPDX-License-Identifier: Apache-2.0
10#
11# Licensed under the Apache License, Version 2.0 (the "License"); you may
12# not use this file except in compliance with the License.
13# You may obtain a copy of the License at
14#
15# http://www.apache.org/licenses/LICENSE-2.0
16#
17# Unless required by applicable law or agreed to in writing, software
18# distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
19# WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
20# See the License for the specific language governing permissions and
21# limitations under the License.
22
23import argparse
Gilles Peskinecba28a72022-03-15 17:26:33 +010024import enum
Gilles Peskine14e428f2021-01-26 22:19:21 +010025import os
Bence Szépkúti9e84ec72021-05-07 11:49:17 +020026import posixpath
Gilles Peskine14e428f2021-01-26 22:19:21 +010027import re
Gilles Peskine09940492021-01-26 22:16:30 +010028import sys
Gilles Peskine3d778392021-02-17 15:11:05 +010029from typing import Callable, Dict, FrozenSet, Iterable, Iterator, List, Optional, TypeVar
Gilles Peskine09940492021-01-26 22:16:30 +010030
31import scripts_path # pylint: disable=unused-import
Gilles Peskinec86f20a2021-04-22 00:20:47 +020032from mbedtls_dev import build_tree
Gilles Peskine14e428f2021-01-26 22:19:21 +010033from mbedtls_dev import crypto_knowledge
Gilles Peskine09940492021-01-26 22:16:30 +010034from mbedtls_dev import macro_collector
Gilles Peskine897dff92021-03-10 15:03:44 +010035from mbedtls_dev import psa_storage
Gilles Peskine14e428f2021-01-26 22:19:21 +010036from mbedtls_dev import test_case
Gilles Peskine09940492021-01-26 22:16:30 +010037
38T = TypeVar('T') #pylint: disable=invalid-name
39
Gilles Peskine14e428f2021-01-26 22:19:21 +010040
Gilles Peskine7f756872021-02-16 12:13:12 +010041def psa_want_symbol(name: str) -> str:
Gilles Peskineaf172842021-01-27 18:24:48 +010042 """Return the PSA_WANT_xxx symbol associated with a PSA crypto feature."""
43 if name.startswith('PSA_'):
44 return name[:4] + 'WANT_' + name[4:]
45 else:
46 raise ValueError('Unable to determine the PSA_WANT_ symbol for ' + name)
47
Gilles Peskine7f756872021-02-16 12:13:12 +010048def finish_family_dependency(dep: str, bits: int) -> str:
49 """Finish dep if it's a family dependency symbol prefix.
50
51 A family dependency symbol prefix is a PSA_WANT_ symbol that needs to be
52 qualified by the key size. If dep is such a symbol, finish it by adjusting
53 the prefix and appending the key size. Other symbols are left unchanged.
54 """
55 return re.sub(r'_FAMILY_(.*)', r'_\1_' + str(bits), dep)
56
57def finish_family_dependencies(dependencies: List[str], bits: int) -> List[str]:
58 """Finish any family dependency symbol prefixes.
59
60 Apply `finish_family_dependency` to each element of `dependencies`.
61 """
62 return [finish_family_dependency(dep, bits) for dep in dependencies]
Gilles Peskineaf172842021-01-27 18:24:48 +010063
Gilles Peskinec5d086f2021-04-20 23:23:45 +020064SYMBOLS_WITHOUT_DEPENDENCY = frozenset([
65 'PSA_ALG_AEAD_WITH_AT_LEAST_THIS_LENGTH_TAG', # modifier, only in policies
66 'PSA_ALG_AEAD_WITH_SHORTENED_TAG', # modifier
67 'PSA_ALG_ANY_HASH', # only in policies
68 'PSA_ALG_AT_LEAST_THIS_LENGTH_MAC', # modifier, only in policies
69 'PSA_ALG_KEY_AGREEMENT', # chaining
70 'PSA_ALG_TRUNCATED_MAC', # modifier
71])
Gilles Peskinef8223ab2021-03-10 15:07:16 +010072def automatic_dependencies(*expressions: str) -> List[str]:
73 """Infer dependencies of a test case by looking for PSA_xxx symbols.
74
75 The arguments are strings which should be C expressions. Do not use
76 string literals or comments as this function is not smart enough to
77 skip them.
78 """
79 used = set()
80 for expr in expressions:
81 used.update(re.findall(r'PSA_(?:ALG|ECC_FAMILY|KEY_TYPE)_\w+', expr))
Gilles Peskinec5d086f2021-04-20 23:23:45 +020082 used.difference_update(SYMBOLS_WITHOUT_DEPENDENCY)
Gilles Peskinef8223ab2021-03-10 15:07:16 +010083 return sorted(psa_want_symbol(name) for name in used)
84
Gilles Peskined169d602021-02-16 14:16:25 +010085# A temporary hack: at the time of writing, not all dependency symbols
86# are implemented yet. Skip test cases for which the dependency symbols are
87# not available. Once all dependency symbols are available, this hack must
88# be removed so that a bug in the dependency symbols proprely leads to a test
89# failure.
90def read_implemented_dependencies(filename: str) -> FrozenSet[str]:
91 return frozenset(symbol
92 for line in open(filename)
93 for symbol in re.findall(r'\bPSA_WANT_\w+\b', line))
Gilles Peskinec86f20a2021-04-22 00:20:47 +020094_implemented_dependencies = None #type: Optional[FrozenSet[str]] #pylint: disable=invalid-name
Gilles Peskined169d602021-02-16 14:16:25 +010095def hack_dependencies_not_implemented(dependencies: List[str]) -> None:
Gilles Peskinec86f20a2021-04-22 00:20:47 +020096 global _implemented_dependencies #pylint: disable=global-statement,invalid-name
97 if _implemented_dependencies is None:
98 _implemented_dependencies = \
99 read_implemented_dependencies('include/psa/crypto_config.h')
Przemyslaw Stekielba20fc92021-10-22 10:39:56 +0200100 if not all((dep.lstrip('!') in _implemented_dependencies or 'PSA_WANT' not in dep)
Gilles Peskined169d602021-02-16 14:16:25 +0100101 for dep in dependencies):
102 dependencies.append('DEPENDENCY_NOT_IMPLEMENTED_YET')
103
Gilles Peskine14e428f2021-01-26 22:19:21 +0100104
Gilles Peskineb94ea512021-03-10 02:12:08 +0100105class Information:
106 """Gather information about PSA constructors."""
Gilles Peskine09940492021-01-26 22:16:30 +0100107
Gilles Peskineb94ea512021-03-10 02:12:08 +0100108 def __init__(self) -> None:
Gilles Peskine09940492021-01-26 22:16:30 +0100109 self.constructors = self.read_psa_interface()
110
111 @staticmethod
Gilles Peskine09940492021-01-26 22:16:30 +0100112 def remove_unwanted_macros(
Gilles Peskine537d5fa2021-04-19 13:50:25 +0200113 constructors: macro_collector.PSAMacroEnumerator
Gilles Peskine09940492021-01-26 22:16:30 +0100114 ) -> None:
Gilles Peskine537d5fa2021-04-19 13:50:25 +0200115 # Mbed TLS doesn't support finite-field DH yet and will not support
116 # finite-field DSA. Don't attempt to generate any related test case.
117 constructors.key_types.discard('PSA_KEY_TYPE_DH_KEY_PAIR')
118 constructors.key_types.discard('PSA_KEY_TYPE_DH_PUBLIC_KEY')
Gilles Peskine09940492021-01-26 22:16:30 +0100119 constructors.key_types.discard('PSA_KEY_TYPE_DSA_KEY_PAIR')
120 constructors.key_types.discard('PSA_KEY_TYPE_DSA_PUBLIC_KEY')
Gilles Peskine09940492021-01-26 22:16:30 +0100121
Gilles Peskine537d5fa2021-04-19 13:50:25 +0200122 def read_psa_interface(self) -> macro_collector.PSAMacroEnumerator:
Gilles Peskine09940492021-01-26 22:16:30 +0100123 """Return the list of known key types, algorithms, etc."""
Gilles Peskine3d404b82021-03-30 21:46:35 +0200124 constructors = macro_collector.InputsForTest()
Gilles Peskine09940492021-01-26 22:16:30 +0100125 header_file_names = ['include/psa/crypto_values.h',
126 'include/psa/crypto_extra.h']
Gilles Peskine537d5fa2021-04-19 13:50:25 +0200127 test_suites = ['tests/suites/test_suite_psa_crypto_metadata.data']
Gilles Peskine09940492021-01-26 22:16:30 +0100128 for header_file_name in header_file_names:
Gilles Peskine537d5fa2021-04-19 13:50:25 +0200129 constructors.parse_header(header_file_name)
130 for test_cases in test_suites:
131 constructors.parse_test_cases(test_cases)
Gilles Peskine09940492021-01-26 22:16:30 +0100132 self.remove_unwanted_macros(constructors)
Gilles Peskine3d404b82021-03-30 21:46:35 +0200133 constructors.gather_arguments()
Gilles Peskine09940492021-01-26 22:16:30 +0100134 return constructors
135
Gilles Peskine14e428f2021-01-26 22:19:21 +0100136
Przemyslaw Stekielb576c7b2021-10-11 10:15:25 +0200137def test_case_for_key_type_not_supported(
Gilles Peskineb94ea512021-03-10 02:12:08 +0100138 verb: str, key_type: str, bits: int,
139 dependencies: List[str],
140 *args: str,
141 param_descr: str = ''
142) -> test_case.TestCase:
143 """Return one test case exercising a key creation method
144 for an unsupported key type or size.
145 """
146 hack_dependencies_not_implemented(dependencies)
147 tc = test_case.TestCase()
148 short_key_type = re.sub(r'PSA_(KEY_TYPE|ECC_FAMILY)_', r'', key_type)
149 adverb = 'not' if dependencies else 'never'
150 if param_descr:
151 adverb = param_descr + ' ' + adverb
Przemyslaw Stekielb576c7b2021-10-11 10:15:25 +0200152 tc.set_description('PSA {} {} {}-bit {} supported'
153 .format(verb, short_key_type, bits, adverb))
154 tc.set_dependencies(dependencies)
155 tc.set_function(verb + '_not_supported')
156 tc.set_arguments([key_type] + list(args))
157 return tc
158
Gilles Peskineb94ea512021-03-10 02:12:08 +0100159class NotSupported:
Przemyslaw Stekiel8d468e42021-10-18 14:58:20 +0200160 """Generate test cases for when something is not supported."""
Gilles Peskineb94ea512021-03-10 02:12:08 +0100161
162 def __init__(self, info: Information) -> None:
163 self.constructors = info.constructors
Gilles Peskine14e428f2021-01-26 22:19:21 +0100164
Gilles Peskine60b29fe2021-02-16 14:06:50 +0100165 ALWAYS_SUPPORTED = frozenset([
166 'PSA_KEY_TYPE_DERIVE',
167 'PSA_KEY_TYPE_RAW_DATA',
168 ])
Gilles Peskine14e428f2021-01-26 22:19:21 +0100169 def test_cases_for_key_type_not_supported(
Gilles Peskine60b29fe2021-02-16 14:06:50 +0100170 self,
Gilles Peskineaf172842021-01-27 18:24:48 +0100171 kt: crypto_knowledge.KeyType,
172 param: Optional[int] = None,
173 param_descr: str = '',
Gilles Peskine3d778392021-02-17 15:11:05 +0100174 ) -> Iterator[test_case.TestCase]:
Przemyslaw Stekiel8d468e42021-10-18 14:58:20 +0200175 """Return test cases exercising key creation when the given type is unsupported.
Gilles Peskineaf172842021-01-27 18:24:48 +0100176
177 If param is present and not None, emit test cases conditioned on this
178 parameter not being supported. If it is absent or None, emit test cases
Przemyslaw Stekiel8d468e42021-10-18 14:58:20 +0200179 conditioned on the base type not being supported.
Gilles Peskineaf172842021-01-27 18:24:48 +0100180 """
Gilles Peskine60b29fe2021-02-16 14:06:50 +0100181 if kt.name in self.ALWAYS_SUPPORTED:
182 # Don't generate test cases for key types that are always supported.
183 # They would be skipped in all configurations, which is noise.
Gilles Peskine3d778392021-02-17 15:11:05 +0100184 return
Gilles Peskineaf172842021-01-27 18:24:48 +0100185 import_dependencies = [('!' if param is None else '') +
186 psa_want_symbol(kt.name)]
187 if kt.params is not None:
188 import_dependencies += [('!' if param == i else '') +
189 psa_want_symbol(sym)
190 for i, sym in enumerate(kt.params)]
Gilles Peskine14e428f2021-01-26 22:19:21 +0100191 if kt.name.endswith('_PUBLIC_KEY'):
192 generate_dependencies = []
193 else:
194 generate_dependencies = import_dependencies
Gilles Peskine14e428f2021-01-26 22:19:21 +0100195 for bits in kt.sizes_to_test():
Przemyslaw Stekielb576c7b2021-10-11 10:15:25 +0200196 yield test_case_for_key_type_not_supported(
Gilles Peskine7f756872021-02-16 12:13:12 +0100197 'import', kt.expression, bits,
198 finish_family_dependencies(import_dependencies, bits),
Gilles Peskineaf172842021-01-27 18:24:48 +0100199 test_case.hex_string(kt.key_material(bits)),
200 param_descr=param_descr,
Gilles Peskine3d778392021-02-17 15:11:05 +0100201 )
Gilles Peskineaf172842021-01-27 18:24:48 +0100202 if not generate_dependencies and param is not None:
203 # If generation is impossible for this key type, rather than
204 # supported or not depending on implementation capabilities,
205 # only generate the test case once.
206 continue
Przemyslaw Stekiel7bc26b82021-11-02 10:50:44 +0100207 # For public key we expect that key generation fails with
208 # INVALID_ARGUMENT. It is handled by KeyGenerate class.
Przemyslaw Stekiel8d468e42021-10-18 14:58:20 +0200209 if not kt.name.endswith('_PUBLIC_KEY'):
Przemyslaw Stekielb576c7b2021-10-11 10:15:25 +0200210 yield test_case_for_key_type_not_supported(
211 'generate', kt.expression, bits,
212 finish_family_dependencies(generate_dependencies, bits),
213 str(bits),
214 param_descr=param_descr,
215 )
Gilles Peskine14e428f2021-01-26 22:19:21 +0100216 # To be added: derive
Gilles Peskine14e428f2021-01-26 22:19:21 +0100217
Gilles Peskine537d5fa2021-04-19 13:50:25 +0200218 ECC_KEY_TYPES = ('PSA_KEY_TYPE_ECC_KEY_PAIR',
219 'PSA_KEY_TYPE_ECC_PUBLIC_KEY')
220
Gilles Peskine3d778392021-02-17 15:11:05 +0100221 def test_cases_for_not_supported(self) -> Iterator[test_case.TestCase]:
Gilles Peskine14e428f2021-01-26 22:19:21 +0100222 """Generate test cases that exercise the creation of keys of unsupported types."""
Gilles Peskine14e428f2021-01-26 22:19:21 +0100223 for key_type in sorted(self.constructors.key_types):
Gilles Peskine537d5fa2021-04-19 13:50:25 +0200224 if key_type in self.ECC_KEY_TYPES:
225 continue
Gilles Peskine14e428f2021-01-26 22:19:21 +0100226 kt = crypto_knowledge.KeyType(key_type)
Gilles Peskine3d778392021-02-17 15:11:05 +0100227 yield from self.test_cases_for_key_type_not_supported(kt)
Gilles Peskineaf172842021-01-27 18:24:48 +0100228 for curve_family in sorted(self.constructors.ecc_curves):
Gilles Peskine537d5fa2021-04-19 13:50:25 +0200229 for constr in self.ECC_KEY_TYPES:
Gilles Peskineaf172842021-01-27 18:24:48 +0100230 kt = crypto_knowledge.KeyType(constr, [curve_family])
Gilles Peskine3d778392021-02-17 15:11:05 +0100231 yield from self.test_cases_for_key_type_not_supported(
Gilles Peskineaf172842021-01-27 18:24:48 +0100232 kt, param_descr='type')
Gilles Peskine3d778392021-02-17 15:11:05 +0100233 yield from self.test_cases_for_key_type_not_supported(
Gilles Peskineaf172842021-01-27 18:24:48 +0100234 kt, 0, param_descr='curve')
Gilles Peskineb94ea512021-03-10 02:12:08 +0100235
Przemyslaw Stekiel1b0978b2021-10-15 15:21:51 +0200236def test_case_for_key_generation(
237 key_type: str, bits: int,
238 dependencies: List[str],
239 *args: str,
Przemyslaw Stekiel437da192021-10-20 11:59:50 +0200240 result: str = ''
Przemyslaw Stekiel1b0978b2021-10-15 15:21:51 +0200241) -> test_case.TestCase:
242 """Return one test case exercising a key generation.
243 """
244 hack_dependencies_not_implemented(dependencies)
245 tc = test_case.TestCase()
246 short_key_type = re.sub(r'PSA_(KEY_TYPE|ECC_FAMILY)_', r'', key_type)
247 tc.set_description('PSA {} {}-bit'
Przemyslaw Stekiel437da192021-10-20 11:59:50 +0200248 .format(short_key_type, bits))
Przemyslaw Stekiel1b0978b2021-10-15 15:21:51 +0200249 tc.set_dependencies(dependencies)
250 tc.set_function('generate_key')
Przemyslaw Stekiel7bc26b82021-11-02 10:50:44 +0100251 tc.set_arguments([key_type] + list(args) + [result])
Przemyslaw Stekiel1b0978b2021-10-15 15:21:51 +0200252
253 return tc
254
255class KeyGenerate:
256 """Generate positive and negative (invalid argument) test cases for key generation."""
257
258 def __init__(self, info: Information) -> None:
259 self.constructors = info.constructors
260
Przemyslaw Stekiel437da192021-10-20 11:59:50 +0200261 ECC_KEY_TYPES = ('PSA_KEY_TYPE_ECC_KEY_PAIR',
262 'PSA_KEY_TYPE_ECC_PUBLIC_KEY')
263
Przemyslaw Stekiel7bc26b82021-11-02 10:50:44 +0100264 @staticmethod
Przemyslaw Stekiel1b0978b2021-10-15 15:21:51 +0200265 def test_cases_for_key_type_key_generation(
Przemyslaw Stekiel437da192021-10-20 11:59:50 +0200266 kt: crypto_knowledge.KeyType
Przemyslaw Stekiel1b0978b2021-10-15 15:21:51 +0200267 ) -> Iterator[test_case.TestCase]:
268 """Return test cases exercising key generation.
269
270 All key types can be generated except for public keys. For public key
271 PSA_ERROR_INVALID_ARGUMENT status is expected.
272 """
273 result = 'PSA_SUCCESS'
274
275 import_dependencies = [psa_want_symbol(kt.name)]
276 if kt.params is not None:
277 import_dependencies += [psa_want_symbol(sym)
278 for i, sym in enumerate(kt.params)]
279 if kt.name.endswith('_PUBLIC_KEY'):
Przemyslaw Stekiel7bc26b82021-11-02 10:50:44 +0100280 # The library checks whether the key type is a public key generically,
281 # before it reaches a point where it needs support for the specific key
282 # type, so it returns INVALID_ARGUMENT for unsupported public key types.
Przemyslaw Stekiel1b0978b2021-10-15 15:21:51 +0200283 generate_dependencies = []
284 result = 'PSA_ERROR_INVALID_ARGUMENT'
285 else:
286 generate_dependencies = import_dependencies
Przemyslaw Stekiel7bc26b82021-11-02 10:50:44 +0100287 if kt.name == 'PSA_KEY_TYPE_RSA_KEY_PAIR':
Przemyslaw Stekielba20fc92021-10-22 10:39:56 +0200288 generate_dependencies.append("MBEDTLS_GENPRIME")
Przemyslaw Stekiel1b0978b2021-10-15 15:21:51 +0200289 for bits in kt.sizes_to_test():
290 yield test_case_for_key_generation(
291 kt.expression, bits,
292 finish_family_dependencies(generate_dependencies, bits),
293 str(bits),
Przemyslaw Stekiel437da192021-10-20 11:59:50 +0200294 result
Przemyslaw Stekiel1b0978b2021-10-15 15:21:51 +0200295 )
296
Przemyslaw Stekiel1b0978b2021-10-15 15:21:51 +0200297 def test_cases_for_key_generation(self) -> Iterator[test_case.TestCase]:
298 """Generate test cases that exercise the generation of keys."""
299 for key_type in sorted(self.constructors.key_types):
300 if key_type in self.ECC_KEY_TYPES:
301 continue
302 kt = crypto_knowledge.KeyType(key_type)
303 yield from self.test_cases_for_key_type_key_generation(kt)
304 for curve_family in sorted(self.constructors.ecc_curves):
305 for constr in self.ECC_KEY_TYPES:
306 kt = crypto_knowledge.KeyType(constr, [curve_family])
Przemyslaw Stekiel437da192021-10-20 11:59:50 +0200307 yield from self.test_cases_for_key_type_key_generation(kt)
Przemyslaw Stekiel1b0978b2021-10-15 15:21:51 +0200308
Gilles Peskinec7e1ea02021-04-27 20:40:10 +0200309class OpFail:
310 """Generate test cases for operations that must fail."""
311 #pylint: disable=too-few-public-methods
312
Gilles Peskinecba28a72022-03-15 17:26:33 +0100313 class Reason(enum.Enum):
314 NOT_SUPPORTED = 0
315 INVALID = 1
316 INCOMPATIBLE = 2
317
Gilles Peskinec7e1ea02021-04-27 20:40:10 +0200318 def __init__(self, info: Information) -> None:
319 self.constructors = info.constructors
Gilles Peskinecba28a72022-03-15 17:26:33 +0100320 key_type_expressions = self.constructors.generate_expressions(
321 sorted(self.constructors.key_types)
322 )
323 self.key_types = [crypto_knowledge.KeyType(kt_expr)
324 for kt_expr in key_type_expressions]
Gilles Peskinec7e1ea02021-04-27 20:40:10 +0200325
Gilles Peskinecba28a72022-03-15 17:26:33 +0100326 def make_test_case(
327 self,
328 alg: crypto_knowledge.Algorithm,
329 category: crypto_knowledge.AlgorithmCategory,
330 reason: 'Reason',
331 kt: Optional[crypto_knowledge.KeyType] = None,
332 not_deps: FrozenSet[str] = frozenset(),
333 ) -> test_case.TestCase:
334 """Construct a failure test case for a one-key or keyless operation."""
335 #pylint: disable=too-many-arguments,too-many-locals
Gilles Peskine8b4a3812021-04-27 21:03:43 +0200336 tc = test_case.TestCase()
Gilles Peskinecba28a72022-03-15 17:26:33 +0100337 pretty_alg = re.sub(r'PSA_ALG_', r'', alg.expression)
Gilles Peskined79e3b92021-04-29 21:35:03 +0200338 if reason == self.Reason.NOT_SUPPORTED:
339 short_deps = [re.sub(r'PSA_WANT_ALG_', r'', dep)
340 for dep in not_deps]
341 pretty_reason = '!' + '&'.join(sorted(short_deps))
342 else:
343 pretty_reason = reason.name.lower()
Gilles Peskinecba28a72022-03-15 17:26:33 +0100344 if kt:
345 key_type = kt.expression
346 pretty_type = re.sub(r'PSA_KEY_TYPE_', r'', key_type)
Gilles Peskine8b4a3812021-04-27 21:03:43 +0200347 else:
Gilles Peskinecba28a72022-03-15 17:26:33 +0100348 key_type = ''
349 pretty_type = ''
350 tc.set_description('PSA {} {}: {}{}'
351 .format(category.name.lower(),
352 pretty_alg,
353 pretty_reason,
354 ' with ' + pretty_type if pretty_type else ''))
355 dependencies = automatic_dependencies(alg.base_expression, key_type)
356 for i, dep in enumerate(dependencies):
357 if dep in not_deps:
358 dependencies[i] = '!' + dep
Gilles Peskine8b4a3812021-04-27 21:03:43 +0200359 tc.set_dependencies(dependencies)
Gilles Peskinecba28a72022-03-15 17:26:33 +0100360 tc.set_function(category.name.lower() + '_fail')
361 arguments = []
362 if kt:
363 key_material = kt.key_material(kt.sizes_to_test()[0])
364 arguments += [key_type, test_case.hex_string(key_material)]
365 arguments.append(alg.expression)
366 error = ('NOT_SUPPORTED' if reason == self.Reason.NOT_SUPPORTED else
367 'INVALID_ARGUMENT')
368 arguments.append('PSA_ERROR_' + error)
369 tc.set_arguments(arguments)
370 return tc
Gilles Peskine8b4a3812021-04-27 21:03:43 +0200371
Gilles Peskinecba28a72022-03-15 17:26:33 +0100372 def no_key_test_cases(
373 self,
374 alg: crypto_knowledge.Algorithm,
375 category: crypto_knowledge.AlgorithmCategory,
376 ) -> Iterator[test_case.TestCase]:
377 """Generate failure test cases for keyless operations with the specified algorithm."""
378 if category == alg.category:
379 # Compatible operation, unsupported algorithm
380 for dep in automatic_dependencies(alg.base_expression):
381 yield self.make_test_case(alg, category,
382 self.Reason.NOT_SUPPORTED,
383 not_deps=frozenset([dep]))
384 else:
385 # Incompatible operation, supported algorithm
386 yield self.make_test_case(alg, category, self.Reason.INVALID)
387
388 def one_key_test_cases(
389 self,
390 alg: crypto_knowledge.Algorithm,
391 category: crypto_knowledge.AlgorithmCategory,
392 ) -> Iterator[test_case.TestCase]:
393 """Generate failure test cases for one-key operations with the specified algorithm."""
394 for kt in self.key_types:
395 key_is_compatible = kt.can_do(alg)
396 # To do: public key for a private key operation
397 if key_is_compatible and category == alg.category:
398 # Compatible key and operation, unsupported algorithm
399 for dep in automatic_dependencies(alg.base_expression):
400 yield self.make_test_case(alg, category,
401 self.Reason.NOT_SUPPORTED,
402 kt=kt, not_deps=frozenset([dep]))
403 elif key_is_compatible:
404 # Compatible key, incompatible operation, supported algorithm
405 yield self.make_test_case(alg, category,
406 self.Reason.INVALID,
407 kt=kt)
408 elif category == alg.category:
409 # Incompatible key, compatible operation, supported algorithm
410 yield self.make_test_case(alg, category,
411 self.Reason.INCOMPATIBLE,
412 kt=kt)
413 else:
414 # Incompatible key and operation. Don't test cases where
415 # multiple things are wrong, to keep the number of test
416 # cases reasonable.
417 pass
418
419 def test_cases_for_algorithm(
420 self,
421 alg: crypto_knowledge.Algorithm,
422 ) -> Iterator[test_case.TestCase]:
Gilles Peskine8b4a3812021-04-27 21:03:43 +0200423 """Generate operation failure test cases for the specified algorithm."""
Gilles Peskinecba28a72022-03-15 17:26:33 +0100424 for category in crypto_knowledge.AlgorithmCategory:
425 if category == crypto_knowledge.AlgorithmCategory.PAKE:
426 # PAKE operations are not implemented yet
427 pass
428 elif category.requires_key():
429 yield from self.one_key_test_cases(alg, category)
430 else:
431 yield from self.no_key_test_cases(alg, category)
Gilles Peskine8b4a3812021-04-27 21:03:43 +0200432
Gilles Peskinec7e1ea02021-04-27 20:40:10 +0200433 def all_test_cases(self) -> Iterator[test_case.TestCase]:
434 """Generate all test cases for operations that must fail."""
Gilles Peskine8b4a3812021-04-27 21:03:43 +0200435 algorithms = sorted(self.constructors.algorithms)
Gilles Peskinecba28a72022-03-15 17:26:33 +0100436 for expr in self.constructors.generate_expressions(algorithms):
437 alg = crypto_knowledge.Algorithm(expr)
Gilles Peskine8b4a3812021-04-27 21:03:43 +0200438 yield from self.test_cases_for_algorithm(alg)
Gilles Peskinec7e1ea02021-04-27 20:40:10 +0200439
440
Gilles Peskine897dff92021-03-10 15:03:44 +0100441class StorageKey(psa_storage.Key):
442 """Representation of a key for storage format testing."""
443
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200444 IMPLICIT_USAGE_FLAGS = {
445 'PSA_KEY_USAGE_SIGN_HASH': 'PSA_KEY_USAGE_SIGN_MESSAGE',
446 'PSA_KEY_USAGE_VERIFY_HASH': 'PSA_KEY_USAGE_VERIFY_MESSAGE'
447 } #type: Dict[str, str]
448 """Mapping of usage flags to the flags that they imply."""
449
450 def __init__(
451 self,
452 usage: str,
453 without_implicit_usage: Optional[bool] = False,
454 **kwargs
455 ) -> None:
456 """Prepare to generate a key.
457
458 * `usage` : The usage flags used for the key.
459 * `without_implicit_usage`: Flag to defide to apply the usage extension
460 """
gabor-mezei-arm2c9e54a2021-06-29 17:21:21 +0200461 super().__init__(usage=usage, **kwargs)
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200462
463 if not without_implicit_usage:
464 for flag, implicit in self.IMPLICIT_USAGE_FLAGS.items():
465 if self.usage.value() & psa_storage.Expr(flag).value() and \
466 self.usage.value() & psa_storage.Expr(implicit).value() == 0:
467 self.usage = psa_storage.Expr(self.usage.string + ' | ' + implicit)
468
469class StorageTestData(StorageKey):
470 """Representation of test case data for storage format testing."""
471
gabor-mezei-arm672e3762021-06-24 10:16:44 +0200472 def __init__(
473 self,
474 description: str,
475 expected_usage: Optional[str] = None,
476 **kwargs
477 ) -> None:
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200478 """Prepare to generate test data
gabor-mezei-arm672e3762021-06-24 10:16:44 +0200479
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200480 * `description` : used for the the test case names
481 * `expected_usage`: the usage flags generated as the expected usage flags
482 in the test cases. CAn differ from the usage flags
483 stored in the keys because of the usage flags extension.
gabor-mezei-arm672e3762021-06-24 10:16:44 +0200484 """
Gilles Peskine897dff92021-03-10 15:03:44 +0100485 super().__init__(**kwargs)
486 self.description = description #type: str
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200487 self.expected_usage = expected_usage if expected_usage else self.usage.string #type: str
gabor-mezei-arm7748b6f2021-06-24 10:04:38 +0200488
Gilles Peskine897dff92021-03-10 15:03:44 +0100489class StorageFormat:
490 """Storage format stability test cases."""
491
492 def __init__(self, info: Information, version: int, forward: bool) -> None:
493 """Prepare to generate test cases for storage format stability.
494
495 * `info`: information about the API. See the `Information` class.
496 * `version`: the storage format version to generate test cases for.
497 * `forward`: if true, generate forward compatibility test cases which
498 save a key and check that its representation is as intended. Otherwise
499 generate backward compatibility test cases which inject a key
500 representation and check that it can be read and used.
501 """
gabor-mezei-arm7b5c4e22021-06-23 17:01:44 +0200502 self.constructors = info.constructors #type: macro_collector.PSAMacroEnumerator
503 self.version = version #type: int
504 self.forward = forward #type: bool
Gilles Peskine897dff92021-03-10 15:03:44 +0100505
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200506 def make_test_case(self, key: StorageTestData) -> test_case.TestCase:
Gilles Peskine897dff92021-03-10 15:03:44 +0100507 """Construct a storage format test case for the given key.
508
509 If ``forward`` is true, generate a forward compatibility test case:
510 create a key and validate that it has the expected representation.
511 Otherwise generate a backward compatibility test case: inject the
512 key representation into storage and validate that it can be read
513 correctly.
514 """
515 verb = 'save' if self.forward else 'read'
516 tc = test_case.TestCase()
517 tc.set_description('PSA storage {}: {}'.format(verb, key.description))
Gilles Peskinef8223ab2021-03-10 15:07:16 +0100518 dependencies = automatic_dependencies(
519 key.lifetime.string, key.type.string,
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200520 key.expected_usage, key.alg.string, key.alg2.string,
Gilles Peskinef8223ab2021-03-10 15:07:16 +0100521 )
522 dependencies = finish_family_dependencies(dependencies, key.bits)
523 tc.set_dependencies(dependencies)
Gilles Peskine897dff92021-03-10 15:03:44 +0100524 tc.set_function('key_storage_' + verb)
525 if self.forward:
526 extra_arguments = []
527 else:
Gilles Peskine45f1cd72021-04-21 20:11:33 +0200528 flags = []
Gilles Peskine897dff92021-03-10 15:03:44 +0100529 # Some test keys have the RAW_DATA type and attributes that don't
530 # necessarily make sense. We do this to validate numerical
531 # encodings of the attributes.
532 # Raw data keys have no useful exercise anyway so there is no
533 # loss of test coverage.
Gilles Peskine45f1cd72021-04-21 20:11:33 +0200534 if key.type.string != 'PSA_KEY_TYPE_RAW_DATA':
535 flags.append('TEST_FLAG_EXERCISE')
536 if 'READ_ONLY' in key.lifetime.string:
537 flags.append('TEST_FLAG_READ_ONLY')
538 extra_arguments = [' | '.join(flags) if flags else '0']
Gilles Peskine897dff92021-03-10 15:03:44 +0100539 tc.set_arguments([key.lifetime.string,
540 key.type.string, str(key.bits),
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200541 key.expected_usage, key.alg.string, key.alg2.string,
Gilles Peskine897dff92021-03-10 15:03:44 +0100542 '"' + key.material.hex() + '"',
543 '"' + key.hex() + '"',
544 *extra_arguments])
545 return tc
546
Gilles Peskineeb7bdaa2021-04-21 22:05:34 +0200547 def key_for_lifetime(
548 self,
549 lifetime: str,
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200550 ) -> StorageTestData:
Gilles Peskineeb7bdaa2021-04-21 22:05:34 +0200551 """Construct a test key for the given lifetime."""
552 short = lifetime
553 short = re.sub(r'PSA_KEY_LIFETIME_FROM_PERSISTENCE_AND_LOCATION',
554 r'', short)
555 short = re.sub(r'PSA_KEY_[A-Z]+_', r'', short)
556 description = 'lifetime: ' + short
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200557 key = StorageTestData(version=self.version,
558 id=1, lifetime=lifetime,
559 type='PSA_KEY_TYPE_RAW_DATA', bits=8,
560 usage='PSA_KEY_USAGE_EXPORT', alg=0, alg2=0,
561 material=b'L',
562 description=description)
563 return key
Gilles Peskineeb7bdaa2021-04-21 22:05:34 +0200564
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200565 def all_keys_for_lifetimes(self) -> Iterator[StorageTestData]:
Gilles Peskineeb7bdaa2021-04-21 22:05:34 +0200566 """Generate test keys covering lifetimes."""
567 lifetimes = sorted(self.constructors.lifetimes)
568 expressions = self.constructors.generate_expressions(lifetimes)
569 for lifetime in expressions:
570 # Don't attempt to create or load a volatile key in storage
571 if 'VOLATILE' in lifetime:
572 continue
573 # Don't attempt to create a read-only key in storage,
574 # but do attempt to load one.
575 if 'READ_ONLY' in lifetime and self.forward:
576 continue
gabor-mezei-arm340fbf32021-06-28 19:26:55 +0200577 yield self.key_for_lifetime(lifetime)
Gilles Peskineeb7bdaa2021-04-21 22:05:34 +0200578
Gilles Peskinef7614272022-02-24 18:58:08 +0100579 def key_for_usage_flags(
Gilles Peskine897dff92021-03-10 15:03:44 +0100580 self,
581 usage_flags: List[str],
gabor-mezei-arm6ee72532021-06-24 09:42:02 +0200582 short: Optional[str] = None,
Gilles Peskinef7614272022-02-24 18:58:08 +0100583 test_implicit_usage: Optional[bool] = True
584 ) -> StorageTestData:
Gilles Peskine897dff92021-03-10 15:03:44 +0100585 """Construct a test key for the given key usage."""
586 usage = ' | '.join(usage_flags) if usage_flags else '0'
587 if short is None:
588 short = re.sub(r'\bPSA_KEY_USAGE_', r'', usage)
Gilles Peskinef7614272022-02-24 18:58:08 +0100589 extra_desc = ' without implication' if test_implicit_usage else ''
gabor-mezei-arm6ee72532021-06-24 09:42:02 +0200590 description = 'usage' + extra_desc + ': ' + short
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200591 key1 = StorageTestData(version=self.version,
592 id=1, lifetime=0x00000001,
593 type='PSA_KEY_TYPE_RAW_DATA', bits=8,
594 expected_usage=usage,
Gilles Peskinef7614272022-02-24 18:58:08 +0100595 without_implicit_usage=not test_implicit_usage,
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200596 usage=usage, alg=0, alg2=0,
597 material=b'K',
598 description=description)
Gilles Peskinef7614272022-02-24 18:58:08 +0100599 return key1
Gilles Peskine897dff92021-03-10 15:03:44 +0100600
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200601 def generate_keys_for_usage_flags(self, **kwargs) -> Iterator[StorageTestData]:
Gilles Peskine897dff92021-03-10 15:03:44 +0100602 """Generate test keys covering usage flags."""
603 known_flags = sorted(self.constructors.key_usage_flags)
Gilles Peskinef7614272022-02-24 18:58:08 +0100604 yield self.key_for_usage_flags(['0'], **kwargs)
gabor-mezei-arm340fbf32021-06-28 19:26:55 +0200605 for usage_flag in known_flags:
Gilles Peskinef7614272022-02-24 18:58:08 +0100606 yield self.key_for_usage_flags([usage_flag], **kwargs)
gabor-mezei-arm340fbf32021-06-28 19:26:55 +0200607 for flag1, flag2 in zip(known_flags,
608 known_flags[1:] + [known_flags[0]]):
Gilles Peskinef7614272022-02-24 18:58:08 +0100609 yield self.key_for_usage_flags([flag1, flag2], **kwargs)
gabor-mezei-arm49d6ea92021-06-24 14:38:51 +0200610
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200611 def generate_key_for_all_usage_flags(self) -> Iterator[StorageTestData]:
gabor-mezei-arm49d6ea92021-06-24 14:38:51 +0200612 known_flags = sorted(self.constructors.key_usage_flags)
Gilles Peskinef7614272022-02-24 18:58:08 +0100613 yield self.key_for_usage_flags(known_flags, short='all known')
gabor-mezei-arm49d6ea92021-06-24 14:38:51 +0200614
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200615 def all_keys_for_usage_flags(self) -> Iterator[StorageTestData]:
gabor-mezei-arm340fbf32021-06-28 19:26:55 +0200616 yield from self.generate_keys_for_usage_flags()
617 yield from self.generate_key_for_all_usage_flags()
Gilles Peskine897dff92021-03-10 15:03:44 +0100618
Gilles Peskinef8223ab2021-03-10 15:07:16 +0100619 def keys_for_type(
620 self,
621 key_type: str,
622 params: Optional[Iterable[str]] = None
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200623 ) -> Iterator[StorageTestData]:
Gilles Peskinef8223ab2021-03-10 15:07:16 +0100624 """Generate test keys for the given key type.
625
626 For key types that depend on a parameter (e.g. elliptic curve family),
627 `param` is the parameter to pass to the constructor. Only a single
628 parameter is supported.
629 """
630 kt = crypto_knowledge.KeyType(key_type, params)
631 for bits in kt.sizes_to_test():
632 usage_flags = 'PSA_KEY_USAGE_EXPORT'
633 alg = 0
634 alg2 = 0
635 key_material = kt.key_material(bits)
636 short_expression = re.sub(r'\bPSA_(?:KEY_TYPE|ECC_FAMILY)_',
637 r'',
638 kt.expression)
639 description = 'type: {} {}-bit'.format(short_expression, bits)
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200640 key = StorageTestData(version=self.version,
641 id=1, lifetime=0x00000001,
642 type=kt.expression, bits=bits,
643 usage=usage_flags, alg=alg, alg2=alg2,
644 material=key_material,
645 description=description)
646 yield key
Gilles Peskinef8223ab2021-03-10 15:07:16 +0100647
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200648 def all_keys_for_types(self) -> Iterator[StorageTestData]:
Gilles Peskinef8223ab2021-03-10 15:07:16 +0100649 """Generate test keys covering key types and their representations."""
Gilles Peskine537d5fa2021-04-19 13:50:25 +0200650 key_types = sorted(self.constructors.key_types)
gabor-mezei-arm340fbf32021-06-28 19:26:55 +0200651 for key_type in self.constructors.generate_expressions(key_types):
652 yield from self.keys_for_type(key_type)
Gilles Peskinef8223ab2021-03-10 15:07:16 +0100653
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200654 def keys_for_algorithm(self, alg: str) -> Iterator[StorageTestData]:
Gilles Peskined86bc522021-03-10 15:08:57 +0100655 """Generate test keys for the specified algorithm."""
656 # For now, we don't have information on the compatibility of key
657 # types and algorithms. So we just test the encoding of algorithms,
658 # and not that operations can be performed with them.
Gilles Peskine20f55f62021-04-21 10:18:19 +0200659 descr = re.sub(r'PSA_ALG_', r'', alg)
660 descr = re.sub(r',', r', ', re.sub(r' +', r'', descr))
Gilles Peskined86bc522021-03-10 15:08:57 +0100661 usage = 'PSA_KEY_USAGE_EXPORT'
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200662 key1 = StorageTestData(version=self.version,
663 id=1, lifetime=0x00000001,
664 type='PSA_KEY_TYPE_RAW_DATA', bits=8,
665 usage=usage, alg=alg, alg2=0,
666 material=b'K',
667 description='alg: ' + descr)
668 yield key1
669 key2 = StorageTestData(version=self.version,
670 id=1, lifetime=0x00000001,
671 type='PSA_KEY_TYPE_RAW_DATA', bits=8,
672 usage=usage, alg=0, alg2=alg,
673 material=b'L',
674 description='alg2: ' + descr)
675 yield key2
Gilles Peskined86bc522021-03-10 15:08:57 +0100676
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200677 def all_keys_for_algorithms(self) -> Iterator[StorageTestData]:
Gilles Peskined86bc522021-03-10 15:08:57 +0100678 """Generate test keys covering algorithm encodings."""
Gilles Peskine537d5fa2021-04-19 13:50:25 +0200679 algorithms = sorted(self.constructors.algorithms)
gabor-mezei-arm340fbf32021-06-28 19:26:55 +0200680 for alg in self.constructors.generate_expressions(algorithms):
681 yield from self.keys_for_algorithm(alg)
Gilles Peskined86bc522021-03-10 15:08:57 +0100682
gabor-mezei-arm0c24edd2021-06-29 15:42:57 +0200683 def generate_all_keys(self) -> Iterator[StorageTestData]:
gabor-mezei-arm780cf9d2021-06-24 09:49:50 +0200684 """Generate all keys for the test cases."""
gabor-mezei-arm0c24edd2021-06-29 15:42:57 +0200685 yield from self.all_keys_for_lifetimes()
686 yield from self.all_keys_for_usage_flags()
687 yield from self.all_keys_for_types()
688 yield from self.all_keys_for_algorithms()
gabor-mezei-arm780cf9d2021-06-24 09:49:50 +0200689
gabor-mezei-arm340fbf32021-06-28 19:26:55 +0200690 def all_test_cases(self) -> Iterator[test_case.TestCase]:
Gilles Peskine897dff92021-03-10 15:03:44 +0100691 """Generate all storage format test cases."""
Gilles Peskine3c9d4232021-04-12 14:43:05 +0200692 # First build a list of all keys, then construct all the corresponding
693 # test cases. This allows all required information to be obtained in
694 # one go, which is a significant performance gain as the information
695 # includes numerical values obtained by compiling a C program.
Gilles Peskine45f2a402021-07-06 21:05:52 +0200696 all_keys = list(self.generate_all_keys())
697 for key in all_keys:
gabor-mezei-arm340fbf32021-06-28 19:26:55 +0200698 if key.location_value() != 0:
699 # Skip keys with a non-default location, because they
700 # require a driver and we currently have no mechanism to
701 # determine whether a driver is available.
702 continue
703 yield self.make_test_case(key)
Gilles Peskine897dff92021-03-10 15:03:44 +0100704
gabor-mezei-arma4102cb2021-06-24 09:53:26 +0200705class StorageFormatForward(StorageFormat):
706 """Storage format stability test cases for forward compatibility."""
707
708 def __init__(self, info: Information, version: int) -> None:
709 super().__init__(info, version, True)
710
711class StorageFormatV0(StorageFormat):
712 """Storage format stability test cases for version 0 compatibility."""
713
714 def __init__(self, info: Information) -> None:
715 super().__init__(info, 0, False)
Gilles Peskine897dff92021-03-10 15:03:44 +0100716
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200717 def all_keys_for_usage_flags(self) -> Iterator[StorageTestData]:
gabor-mezei-arm7748b6f2021-06-24 10:04:38 +0200718 """Generate test keys covering usage flags."""
Gilles Peskinef7614272022-02-24 18:58:08 +0100719 yield from super().all_keys_for_usage_flags()
720 yield from self.generate_keys_for_usage_flags(test_implicit_usage=False)
gabor-mezei-arm7748b6f2021-06-24 10:04:38 +0200721
gabor-mezei-arm5df1dee2021-06-28 17:40:32 +0200722 def keys_for_implicit_usage(
gabor-mezei-arm672e3762021-06-24 10:16:44 +0200723 self,
gabor-mezei-arm2710bb12021-06-28 16:54:11 +0200724 implyer_usage: str,
gabor-mezei-arm672e3762021-06-24 10:16:44 +0200725 alg: str,
gabor-mezei-arm2784bfe2021-06-28 20:02:11 +0200726 key_type: crypto_knowledge.KeyType
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200727 ) -> StorageTestData:
gabor-mezei-arm0f8136a2021-06-24 14:38:25 +0200728 # pylint: disable=too-many-locals
gabor-mezei-arm8f405102021-06-28 16:27:29 +0200729 """Generate test keys for the specified implicit usage flag,
gabor-mezei-arm672e3762021-06-24 10:16:44 +0200730 algorithm and key type combination.
731 """
gabor-mezei-arm2784bfe2021-06-28 20:02:11 +0200732 bits = key_type.sizes_to_test()[0]
gabor-mezei-arm2710bb12021-06-28 16:54:11 +0200733 implicit_usage = StorageKey.IMPLICIT_USAGE_FLAGS[implyer_usage]
gabor-mezei-armd9050a52021-06-28 16:35:48 +0200734 usage_flags = 'PSA_KEY_USAGE_EXPORT'
gabor-mezei-arm2710bb12021-06-28 16:54:11 +0200735 material_usage_flags = usage_flags + ' | ' + implyer_usage
736 expected_usage_flags = material_usage_flags + ' | ' + implicit_usage
gabor-mezei-armd9050a52021-06-28 16:35:48 +0200737 alg2 = 0
gabor-mezei-arm2784bfe2021-06-28 20:02:11 +0200738 key_material = key_type.key_material(bits)
gabor-mezei-arm2710bb12021-06-28 16:54:11 +0200739 usage_expression = re.sub(r'PSA_KEY_USAGE_', r'', implyer_usage)
gabor-mezei-armd9050a52021-06-28 16:35:48 +0200740 alg_expression = re.sub(r'PSA_ALG_', r'', alg)
741 alg_expression = re.sub(r',', r', ', re.sub(r' +', r'', alg_expression))
742 key_type_expression = re.sub(r'\bPSA_(?:KEY_TYPE|ECC_FAMILY)_',
743 r'',
gabor-mezei-arm2784bfe2021-06-28 20:02:11 +0200744 key_type.expression)
gabor-mezei-arm5df1dee2021-06-28 17:40:32 +0200745 description = 'implied by {}: {} {} {}-bit'.format(
gabor-mezei-armd9050a52021-06-28 16:35:48 +0200746 usage_expression, alg_expression, key_type_expression, bits)
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200747 key = StorageTestData(version=self.version,
748 id=1, lifetime=0x00000001,
749 type=key_type.expression, bits=bits,
750 usage=material_usage_flags,
751 expected_usage=expected_usage_flags,
752 without_implicit_usage=True,
753 alg=alg, alg2=alg2,
754 material=key_material,
755 description=description)
756 return key
gabor-mezei-arm672e3762021-06-24 10:16:44 +0200757
758 def gather_key_types_for_sign_alg(self) -> Dict[str, List[str]]:
gabor-mezei-arm0f8136a2021-06-24 14:38:25 +0200759 # pylint: disable=too-many-locals
gabor-mezei-arm672e3762021-06-24 10:16:44 +0200760 """Match possible key types for sign algorithms."""
761 # To create a valid combinaton both the algorithms and key types
762 # must be filtered. Pair them with keywords created from its names.
763 incompatible_alg_keyword = frozenset(['RAW', 'ANY', 'PURE'])
764 incompatible_key_type_keywords = frozenset(['MONTGOMERY'])
765 keyword_translation = {
766 'ECDSA': 'ECC',
767 'ED[0-9]*.*' : 'EDWARDS'
768 }
769 exclusive_keywords = {
770 'EDWARDS': 'ECC'
771 }
gabor-mezei-arm0f8136a2021-06-24 14:38:25 +0200772 key_types = set(self.constructors.generate_expressions(self.constructors.key_types))
773 algorithms = set(self.constructors.generate_expressions(self.constructors.sign_algorithms))
gabor-mezei-arm672e3762021-06-24 10:16:44 +0200774 alg_with_keys = {} #type: Dict[str, List[str]]
775 translation_table = str.maketrans('(', '_', ')')
776 for alg in algorithms:
777 # Generate keywords from the name of the algorithm
778 alg_keywords = set(alg.partition('(')[0].split(sep='_')[2:])
779 # Translate keywords for better matching with the key types
780 for keyword in alg_keywords.copy():
781 for pattern, replace in keyword_translation.items():
782 if re.match(pattern, keyword):
783 alg_keywords.remove(keyword)
784 alg_keywords.add(replace)
785 # Filter out incompatible algortihms
786 if not alg_keywords.isdisjoint(incompatible_alg_keyword):
787 continue
788
789 for key_type in key_types:
790 # Generate keywords from the of the key type
791 key_type_keywords = set(key_type.translate(translation_table).split(sep='_')[3:])
792
793 # Remove ambigious keywords
794 for keyword1, keyword2 in exclusive_keywords.items():
795 if keyword1 in key_type_keywords:
796 key_type_keywords.remove(keyword2)
797
798 if key_type_keywords.isdisjoint(incompatible_key_type_keywords) and\
799 not key_type_keywords.isdisjoint(alg_keywords):
800 if alg in alg_with_keys:
801 alg_with_keys[alg].append(key_type)
802 else:
803 alg_with_keys[alg] = [key_type]
804 return alg_with_keys
805
gabor-mezei-arm2a499c02021-06-29 15:29:24 +0200806 def all_keys_for_implicit_usage(self) -> Iterator[StorageTestData]:
gabor-mezei-arm672e3762021-06-24 10:16:44 +0200807 """Generate test keys for usage flag extensions."""
808 # Generate a key type and algorithm pair for each extendable usage
809 # flag to generate a valid key for exercising. The key is generated
810 # without usage extension to check the extension compatiblity.
gabor-mezei-arm672e3762021-06-24 10:16:44 +0200811 alg_with_keys = self.gather_key_types_for_sign_alg()
gabor-mezei-arm11e48382021-06-24 16:35:01 +0200812
gabor-mezei-arm340fbf32021-06-28 19:26:55 +0200813 for usage in sorted(StorageKey.IMPLICIT_USAGE_FLAGS, key=str):
814 for alg in sorted(alg_with_keys):
815 for key_type in sorted(alg_with_keys[alg]):
816 # The key types must be filtered to fit the specific usage flag.
gabor-mezei-arm2784bfe2021-06-28 20:02:11 +0200817 kt = crypto_knowledge.KeyType(key_type)
818 if kt.is_valid_for_signature(usage):
819 yield self.keys_for_implicit_usage(usage, alg, kt)
gabor-mezei-arm672e3762021-06-24 10:16:44 +0200820
gabor-mezei-arm0c24edd2021-06-29 15:42:57 +0200821 def generate_all_keys(self) -> Iterator[StorageTestData]:
822 yield from super().generate_all_keys()
823 yield from self.all_keys_for_implicit_usage()
gabor-mezei-arm7748b6f2021-06-24 10:04:38 +0200824
Gilles Peskineb94ea512021-03-10 02:12:08 +0100825class TestGenerator:
826 """Generate test data."""
827
828 def __init__(self, options) -> None:
829 self.test_suite_directory = self.get_option(options, 'directory',
830 'tests/suites')
831 self.info = Information()
832
833 @staticmethod
834 def get_option(options, name: str, default: T) -> T:
835 value = getattr(options, name, None)
836 return default if value is None else value
837
Gilles Peskine0298bda2021-03-10 02:34:37 +0100838 def filename_for(self, basename: str) -> str:
839 """The location of the data file with the specified base name."""
Bence Szépkúti9e84ec72021-05-07 11:49:17 +0200840 return posixpath.join(self.test_suite_directory, basename + '.data')
Gilles Peskine0298bda2021-03-10 02:34:37 +0100841
Gilles Peskineb94ea512021-03-10 02:12:08 +0100842 def write_test_data_file(self, basename: str,
843 test_cases: Iterable[test_case.TestCase]) -> None:
844 """Write the test cases to a .data file.
845
846 The output file is ``basename + '.data'`` in the test suite directory.
847 """
Gilles Peskine0298bda2021-03-10 02:34:37 +0100848 filename = self.filename_for(basename)
Gilles Peskineb94ea512021-03-10 02:12:08 +0100849 test_case.write_data_file(filename, test_cases)
850
Gilles Peskine92165362021-04-23 16:37:12 +0200851 # Note that targets whose name containns 'test_format' have their content
852 # validated by `abi_check.py`.
Gilles Peskine0298bda2021-03-10 02:34:37 +0100853 TARGETS = {
Przemyslaw Stekiel1b0978b2021-10-15 15:21:51 +0200854 'test_suite_psa_crypto_generate_key.generated':
855 lambda info: KeyGenerate(info).test_cases_for_key_generation(),
Gilles Peskine0298bda2021-03-10 02:34:37 +0100856 'test_suite_psa_crypto_not_supported.generated':
Gilles Peskine3d778392021-02-17 15:11:05 +0100857 lambda info: NotSupported(info).test_cases_for_not_supported(),
Gilles Peskinec7e1ea02021-04-27 20:40:10 +0200858 'test_suite_psa_crypto_op_fail.generated':
859 lambda info: OpFail(info).all_test_cases(),
Gilles Peskine897dff92021-03-10 15:03:44 +0100860 'test_suite_psa_crypto_storage_format.current':
gabor-mezei-arma4102cb2021-06-24 09:53:26 +0200861 lambda info: StorageFormatForward(info, 0).all_test_cases(),
Gilles Peskine897dff92021-03-10 15:03:44 +0100862 'test_suite_psa_crypto_storage_format.v0':
gabor-mezei-arma4102cb2021-06-24 09:53:26 +0200863 lambda info: StorageFormatV0(info).all_test_cases(),
Gilles Peskine0298bda2021-03-10 02:34:37 +0100864 } #type: Dict[str, Callable[[Information], Iterable[test_case.TestCase]]]
865
866 def generate_target(self, name: str) -> None:
867 test_cases = self.TARGETS[name](self.info)
868 self.write_test_data_file(name, test_cases)
Gilles Peskine14e428f2021-01-26 22:19:21 +0100869
Gilles Peskine09940492021-01-26 22:16:30 +0100870def main(args):
871 """Command line entry point."""
872 parser = argparse.ArgumentParser(description=__doc__)
Gilles Peskine0298bda2021-03-10 02:34:37 +0100873 parser.add_argument('--list', action='store_true',
874 help='List available targets and exit')
David Horstmanne12e7f42021-10-15 19:10:15 +0100875 parser.add_argument('--list-for-cmake', action='store_true',
876 help='Print \';\'-separated list of available targets and exit')
Manuel Pégourié-Gonnarda9cb8942021-05-14 11:37:09 +0200877 parser.add_argument('--directory', metavar='DIR',
878 help='Output directory (default: tests/suites)')
Gilles Peskine0298bda2021-03-10 02:34:37 +0100879 parser.add_argument('targets', nargs='*', metavar='TARGET',
880 help='Target file to generate (default: all; "-": none)')
Gilles Peskine09940492021-01-26 22:16:30 +0100881 options = parser.parse_args(args)
Gilles Peskinec86f20a2021-04-22 00:20:47 +0200882 build_tree.chdir_to_root()
Gilles Peskine09940492021-01-26 22:16:30 +0100883 generator = TestGenerator(options)
Gilles Peskine0298bda2021-03-10 02:34:37 +0100884 if options.list:
885 for name in sorted(generator.TARGETS):
886 print(generator.filename_for(name))
887 return
David Horstmanne12e7f42021-10-15 19:10:15 +0100888 # List in a cmake list format (i.e. ';'-separated)
889 if options.list_for_cmake:
David Horstmann65d8c692021-10-21 16:09:51 +0100890 print(';'.join(generator.filename_for(name)
891 for name in sorted(generator.TARGETS)), end='')
David Horstmanne12e7f42021-10-15 19:10:15 +0100892 return
Gilles Peskine0298bda2021-03-10 02:34:37 +0100893 if options.targets:
894 # Allow "-" as a special case so you can run
895 # ``generate_psa_tests.py - $targets`` and it works uniformly whether
896 # ``$targets`` is empty or not.
897 options.targets = [os.path.basename(re.sub(r'\.data\Z', r'', target))
898 for target in options.targets
899 if target != '-']
900 else:
901 options.targets = sorted(generator.TARGETS)
902 for target in options.targets:
903 generator.generate_target(target)
Gilles Peskine09940492021-01-26 22:16:30 +0100904
905if __name__ == '__main__':
906 main(sys.argv[1:])