Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
61 commits
Select commit Hold shift + click to select a range
a95a4fa
F-8673 - Lock the cached empty user PIN state
aidangarske Oct 6, 2026
09bc036
F-8662 - Clear the derived key and decoded objects on failed login
aidangarske Oct 6, 2026
7976f1c
F-5080 - Keep the PIN lockout armed when failed logins race
aidangarske Oct 6, 2026
33fa0d8
F-4962 - Apply the SO login lockout to C_SetPIN
aidangarske Oct 6, 2026
d0bc59a
F-6495 - Apply the user login lockout to C_SetPIN
aidangarske Oct 6, 2026
f0084eb
F-13244 - Decide and log out on last session close under one lock
aidangarske Oct 6, 2026
4f84455
F-5253 - Hold the token lock while walking session objects in find
aidangarske Oct 6, 2026
a433096
F-8663 - Protect every token object on logout despite a failure
aidangarske Oct 6, 2026
03b7f2e
F-8642 - Stop token reset when token initialization fails
aidangarske Oct 6, 2026
fb34434
F-4958 - Read login state under the slot lock when finding objects
aidangarske Oct 6, 2026
f286ea1
F-4267 - Read object flags under the token lock in object lookup
aidangarske Oct 6, 2026
12f06a5
F-11509 - Invalidate private session objects on logout
aidangarske Oct 6, 2026
77cc056
F-4262 - Reject negative stored array lengths when loading token objects
aidangarske Oct 6, 2026
2ed90d3
F-5078 - Grow stored array buffers only as data is read
aidangarske Oct 6, 2026
6725f11
F-13814 - Set data object lengths only after a successful storage read
aidangarske Oct 6, 2026
d45a080
F-4264 - Reject stored private key records shorter than the tag
aidangarske Oct 6, 2026
c6de882
F-4733 - Bound stored DH public key length to the key buffer
aidangarske Oct 6, 2026
fbbe1e8
F-3641 - Reject stored trust records that are not the trust size
aidangarske Oct 6, 2026
340cc37
F-3404 - Write the encoded TPM key into the caller's buffer
aidangarske Oct 6, 2026
b800037
F-8643 - Keep key buffer allocation errors in TPM RSA and ECC encoders
aidangarske Oct 6, 2026
3ba23ff
F-13813 - Release DH and symmetric key data when encoding fails
aidangarske Oct 6, 2026
90210fe
F-3017 - Zeroize encoded private keys when RSA, ECC or ML-DSA encodin…
aidangarske Oct 6, 2026
b1b9fe5
F-3413 - Zeroize decrypted private key buffers on every decode path
aidangarske Oct 6, 2026
d154ded
F-8667 - Scrub symmetric and DH key buffers after a failed decrypt
aidangarske Oct 6, 2026
9bd0d5c
F-10400 - Authenticate stored object policy with the key encryption
aidangarske Oct 7, 2026
af26c4c
F-5763 - Release the replaced operation when a new one is initialized
aidangarske Oct 6, 2026
259e67c
F-8664 - Release operation state on terminating error paths
aidangarske Oct 6, 2026
2cd7e9a
F-11514 - Free buffered AES-GCM data when GCM parameters are reset
aidangarske Oct 6, 2026
907ac56
F-11506 - Free AES and HMAC contexts when key setup fails
aidangarske Oct 6, 2026
7bd40a4
F-12480 - Drop the session reference to a destroyed AES key read at o…
aidangarske Oct 6, 2026
bbe87e4
F-4071 - Scrub accumulated MAC input before growing or freeing it
aidangarske Oct 6, 2026
38c005e
F-8660 - Release accumulated MAC input when the session operation ends
aidangarske Oct 6, 2026
f37f753
F-8641 - Require an active digest before saving operation state
aidangarske Oct 6, 2026
1180d43
F-5871 - Release the active operation before restoring saved state
aidangarske Oct 6, 2026
9ad23fa
F-11510 - Validate saved operation state before changing the session
aidangarske Oct 6, 2026
913a2e6
F-5870 - Reject key handles when restoring a keyless operation state
aidangarske Oct 6, 2026
02662a2
F-10394 - Cancel the active operation when Init is called with a NULL…
aidangarske Oct 6, 2026
e679458
F-2769 - Blank pad fixed-length info fields
aidangarske Oct 7, 2026
718aee1
F-6230 - Report the token clock only when a valid UTC time is available
aidangarske Oct 7, 2026
ff6ac8e
F-6053 - Advertise wrap and unwrap only for mechanisms C_WrapKey supp…
aidangarske Oct 7, 2026
955d785
F-12477 - Report generic secret key generation sizes in bits
aidangarske Oct 7, 2026
cfe9def
F-13248 - Advertise PBKDF2 and PKCS#12 PBE key generation only with HMAC
aidangarske Oct 7, 2026
00854e7
F-8634 - Report C_OpenSession failures instead of returning CKR_OK
aidangarske Oct 7, 2026
e96c802
F-10370 - Document how C_Initialize uses pInitArgs
aidangarske Oct 7, 2026
e91ec4b
F-10371 - Remove the wrong NULL pulCount return from C_GetMechanismLi…
aidangarske Oct 7, 2026
75da0eb
F-10372 - Document CKR_PIN_LEN_RANGE for C_InitToken PIN length
aidangarske Oct 7, 2026
2ab8f0c
F-10373 - Document CKR_PIN_LEN_RANGE for C_InitPIN PIN length
aidangarske Oct 7, 2026
5fcc280
F-10374 - Document CKR_PIN_LEN_RANGE for the C_SetPIN new PIN length
aidangarske Oct 7, 2026
ab24e28
F-9413 - Correct the WP11_Slot_UserLogin return code docs
aidangarske Oct 7, 2026
260edee
F-10378 - Fix file store path lookup build with WOLFPKCS11_NO_ENV
aidangarske Oct 6, 2026
b3b3607
F-10379 - Keep token object count intact when an object store fails
aidangarske Oct 6, 2026
6ca778e
F-10386 - Report token store commit failures to the caller
aidangarske Oct 6, 2026
d03529f
F-10384 - Keep the stored token record until the new one is committed
aidangarske Oct 6, 2026
4fd257e
F-11505 - Report token store failures from C_Finalize
aidangarske Oct 6, 2026
e1d073d
F-8645 - Undo partial library initialization on failure
aidangarske Oct 6, 2026
26b4e77
F-10385 - Handle a failed object allocation without freeing NULL
aidangarske Oct 6, 2026
39cccd1
F-13243 - Report token object unstore failures from object destroy
aidangarske Oct 6, 2026
25a9415
F-2791 - Zeroize token state with wc_ForceZero on finalize
aidangarske Oct 6, 2026
ea58fe1
F-11502 - Propagate token flag read errors during token load
aidangarske Oct 6, 2026
6b08c14
F-10386 - Stage TPM store records in memory until commit
aidangarske Oct 6, 2026
eb5cd91
F-10380 - Size and index post-quantum key records in the TPM store
aidangarske Oct 6, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 10 additions & 0 deletions .github/workflows/unit-test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,11 @@ jobs:
with:
config: --enable-singlethreaded --enable-wolftpm --disable-dh C_EXTRA_FLAGS="-DWOLFPKCS11_TPM_STORE"
check: ./tests/pkcs11str && ./tests/pkcs11test && ./tests/rsa_session_persistence_test
tpm_debug:
uses: ./.github/workflows/build-workflow.yml
with:
config: --enable-singlethreaded --enable-wolftpm --disable-dh --enable-debug C_EXTRA_FLAGS="-DWOLFPKCS11_TPM_STORE"
check: ./tests/token_store_test

no_rsa:
uses: ./.github/workflows/build-workflow.yml
Expand Down Expand Up @@ -50,6 +55,11 @@ jobs:
uses: ./.github/workflows/build-workflow.yml
with:
config: CFLAGS="-DWOLFPKCS11_NO_STORE"
no_env:
uses: ./.github/workflows/build-workflow.yml
with:
config: C_EXTRA_FLAGS="-DWOLFPKCS11_NO_ENV -DWOLFPKCS11_DEFAULT_TOKEN_PATH=./store/default"
check: mkdir -p store && ./tests/pkcs11test
no_aesgcm:
uses: ./.github/workflows/build-workflow.yml
with:
Expand Down
3 changes: 1 addition & 2 deletions CMakeLists.txt
Original file line number Diff line number Diff line change
Expand Up @@ -158,8 +158,7 @@ if(NOT WOLFPKCS11_SINGLE_THREADED)
"-D_POSIX_THREADS")
endif()
else()
set(SINGLE_THREADED 1)
list(APPEND WOLFPKCS11_DEFINITIONS "-DSINGLE_THREADED")
list(APPEND WOLFPKCS11_DEFINITIONS "-DWOLFPKCS11_SINGLE_THREADED")
endif()


Expand Down
4 changes: 2 additions & 2 deletions cmake/options.h.in
Original file line number Diff line number Diff line change
Expand Up @@ -38,8 +38,8 @@ extern "C" {
#endif
#undef DEBUG_WOLFPKCS11
#cmakedefine DEBUG_WOLFPKCS11
#undef SINGLE_THREADED
#cmakedefine SINGLE_THREADED
#undef WOLFPKCS11_SINGLE_THREADED
#cmakedefine WOLFPKCS11_SINGLE_THREADED
#undef NO_RSA
#cmakedefine NO_RSA
#undef WC_NO_RSA_OAEP
Expand Down
2 changes: 1 addition & 1 deletion configure.ac
Original file line number Diff line number Diff line change
Expand Up @@ -127,7 +127,7 @@ AS_IF([ test "x$ENABLED_SINGLETHREADED" = "xno" ],[
])
])

AS_IF([ test "x$ENABLED_SINGLETHREADED" = "xyes" ],[ AM_CFLAGS="-DSINGLE_THREADED $AM_CFLAGS" ])
AS_IF([ test "x$ENABLED_SINGLETHREADED" = "xyes" ],[ AM_CFLAGS="-DWOLFPKCS11_SINGLE_THREADED $AM_CFLAGS" ])

HAVE_PTHREAD=0
AS_IF([test "x$ax_pthread_ok" = "xyes"],[HAVE_PTHREAD=1])
Expand Down
Loading
Loading