summaryrefslogtreecommitdiff
path: root/CryptoPkg/Test/UnitTest/Library/BaseCryptLib/TestBaseCryptLib.h
AgeCommit message (Collapse)AuthorFilesLines
2026-08-28CryptoPkg: Add Pkcs7Decrypt APIDoug Cook1-0/+3
Add support for a Pkcs7Decrypt API, mirroring the Pkcs7Encrypt API. I expect that the primary use of Pkcs7Decrypt would be for testing the Pkcs7Encrypt API, but maybe somebody will need it for real work someday. Signed-off-by: Doug Cook <dcook@microsoft.com> Committed-by: Doug Flick <dougflick@microsoft.com>
2026-08-28CryptoPkg: Add Pkcs7Encrypt smoke testsDoug Flick1-0/+3
These don't actually decrypt anything, so calling them "unit tests" was a stretch. They're smoke tests: build an envelopedData ContentInfo for a recipient cert, then walk the DER and check the shape looks right (id-envelopedData, CMSVersion, the right number of RecipientInfo entries, the expected content-encryption OID). Covered: * AES-128/192/256-CBC happy paths. * Two recipients, just to confirm the SET grows. * The parameter-validation contract from BaseCryptLib.h (NULL stack/InData/output pointers, bogus CipherNid, bogus Flags). The DER walker is hand-rolled in the test file so we don't have to pull OpenSSL or mbedtls headers into a unit test that has to compile against both. It catches obvious shape regressions but won't notice if the CEK, IV, or PKCS#7 padding are wrong - a real round-trip needs a Pkcs7Decrypt API we don't have yet. Signed-off-by: Doug Flick <dougflick@microsoft.com>
2026-07-21CryptoPkg/BaseCryptLib: Add SLH-DSA SupportMichael G.A. Holland1-0/+3
Created SLH-DSA API functions to configure public and private keys for SLH-DSA algorithm. This will allow users to sign and verify with SLH-DSA. Unit tests were added to confirm operation of the API. Signed-off-by: Michael G.A. Holland <michael.holland@intel.com>
2026-07-14CryptoPkg/BaseCryptLib: Add ML-DSA SupportMichael G.A. Holland1-0/+3
Created ML-DSA API functions to configure public and private keys for ML-DSA algorithm. This will allow users to sign and verify with ML-DSA. Unit tests were add to confirm operation of the API. Signed-off-by: Michael G.A. Holland <michael.holland@intel.com>
2026-07-01CryptoPkg/BaseCryptLib: Add ED448 verification and signature fcnsMichael G.A. Holland1-0/+3
Implemented signature and verification functions for ED448; Updated documentation and unit tests to cover new verification functions Signed-off-by: Michael G.A. Holland <michael.holland@intel.com>
2026-02-24CryptoPkg: Replace include guards with #pragma onceMichael Kubacki1-4/+1
Replace traditional `#ifndef`/`#define`/`#endif` include guards with `#pragma` once. `#pragma once` is a widely supported preprocessor directive that prevents header files from being included multiple times. It is supported by all toolchains used to build edk2: GCC, Clang/LLVM, and MSVC. Does not include updates to OpenSSL generated header files checked into the repo. Those in `CryptoPkg\Library\OpensslLib\OpensslGen\`. Compared to macro-based include guards, `#pragma once`: - Eliminates the risk of macro name collisions or copy/paste errors where two headers inadvertently use the same guard macro. - Eliminate inconsistency in the way include guard macros are named (e.g., some files use `__FILE_H__`, others use `FILE_H_`, etc.). - Reduces boilerplate (three lines replaced by one). - Avoids polluting the macro namespace with guard symbols. - Can improve build times as the preprocessor can skip re-opening the file entirely, rather than re-reading it to find the matching `#endif` ("multiple-include optimization"). - Note that some compilers may already optimize traditional include guards, by recognzining the idiomatic pattern. This change is made acknowledging that overall portability of the code will technically be reduced, as `#pragma once` is not part of the C/C++ standards. However, this is considered acceptable given: 1. edk2 already defines a subset of supported compilers in BaseTools/Conf/tools_def.template, all of which have supported `#pragma once` for over two decades. 2. There have been concerns raised to the project about inconsistent include guard naming and potential macro collisions. Approximate compiler support dates: - MSVC: Supported since Visual C++ 4.2 (1996) - GCC: Supported since 3.4 (2004) (http://gnu.ist.utl.pt/software/gcc/gcc-3.4/changes.html) - Clang (LLVM based): Since initial release in 2007 Signed-off-by: Michael Kubacki <michael.kubacki@microsoft.com>
2025-11-24CryptoPkg/BaseCryptLibUnitTest: Separate MbedTls UnitTest Library.Longhaox Lee1-0/+18
Separate Unit test functions for MbedTls. BaseCryptLibMbedTls does not support all Crypto services So deprecate below function for MbedTls Unit test: TestVerifyEKUsWith3CertsInSignature() TestVerifyEKUsWith2CertsInSignature() TestNoEKUsInSignature() TestVerifyRsaCertPkcs1SignVerify TestVerifyPkcs7SignVerifyNonSelfIssued() TestVerifyDhGenerateKey() Pkcs1v2Decrypt Pkcs1v2EncryptDecrypt RsaOaepEncrypt (Interface) RsaOaepEncrypt (NoSeed) RsaOaepEncrypt (Seeded) RsaOaepDecrypt RsaOaepEncryptDecrypt RsaOaepEncryptPkcs1v2Decrypt Pkcs1v2EncryptRsaOaepDecrypt RsaOaepEncrypt (MdDefaultMgf1Default) RsaOaepDecrypt (MdDefaultMgf1Default) RsaOaepEncryptDecrypt (MdDefaultMgf1Default) RsaOaepEncrypt (MdSha1Bgf1Sha1 RsaOaepDecrypt (MdSha1Bgf1Sha1) RsaOaepEncryptDecrypt (MdSha1Bgf1Sha1) RsaOaepEncrypt (MdSha256Bgf1Sha256) RsaOaepDecrypt (MdSha256Bgf1Sha256) RsaOaepEncryptDecrypt (MdSha256Bgf1Sha256) TestVerifyBn() TestVerifyEcKey() TestPkcs7Attached() TestPkcs7Detached() TestVerifyPkcs7ContentData() REF: https://github.com/tianocore/edk2/issues/11605 Signed-off-by: Longhaox Lee <longhaox.lee@intel.com>
2025-11-24CryptoPkg: Unit test for Pkcs7GetAttachedContent()Longhaox Lee1-0/+3
MbebTls no support signature with content data. test would be fail in below test case: TestPkcs7Attached TestPkcs7Detached TestVerifyPkcs7ContentData REF: https://github.com/tianocore/edk2/issues/11605 Signed-off-by: Longhaox Lee <longhaox.lee@intel.com>
2025-03-07CryptoPkg/Library/OpensslLib: Fix CLANG compatibility issuesMichael D Kinney1-0/+14
Update the CryptoPkg to support CLANGPDB and CLANGDWARF from both Windows and Linux host environments. * Add PcdOpensslLibAssemblySourceStyleNasm to select the correct optimized assembly source style for OpensslLib for IA32/X64. NASM style is for MSFT and CLANGPDB. GAS style is for GCC. Use this PCD in OpensslLibAccel.inf and OpensslLibFullAccel.inf to select between .nasm and .S files. * Add intrinsic functions required by CLANG IA32/X64 builds. * __ashlti3 * __lshrdi3 * Disable warning -Wno-error=unused-function for CLANG build compatibility * Set -D OPENSSL_NO_INLINE_ASM for CLANG build compatibility * Update TestBaseCryptLib to split out the implementation of main() into its own C file that is only use for host-based unit tests. This is due to CLANGPDB for host environments injecting a __main() call that can only be resolved in host based builds that link against host libraries. * Update Configure.py to update IA32/X64 [Sources] sections with feature flag expressions using the new PCD PcdOpensslLibAssemblySourceStyleNasm. Signed-off-by: Michael D Kinney <michael.d.kinney@intel.com>
2022-10-12CryptoPkg: add Unit Test for X509 new function.Qi Zhang1-0/+4
REF: https://bugzilla.tianocore.org/show_bug.cgi?id=4082 Cc: Jiewen Yao <jiewen.yao@intel.com> Cc: Jian J Wang <jian.j.wang@intel.com> Cc: Xiaoyu Lu <xiaoyu1.lu@intel.com> Cc: Guomin Jiang <guomin.jiang@intel.com> Signed-off-by: Qi Zhang <qi1.zhang@intel.com> Reviewed-by: Jiewen Yao <jiewen.yao@intel.com>
2022-09-26CryptoPkg/Test: Add unit test for CryptoEcYi Li1-0/+2
Add unit test for CryptoEc. Cc: Jiewen Yao <jiewen.yao@intel.com> Cc: Jian J Wang <jian.j.wang@intel.com> Cc: Xiaoyu Lu <xiaoyu1.lu@intel.com> Cc: Guomin Jiang <guomin.jiang@intel.com> Signed-off-by: Yi Li <yi1.li@intel.com> Reviewed-by: Jiewen Yao <jiewen.yao@intel.com>
2022-09-23CryptoPkg/Test: Add unit test for CryptoBnYi Li1-0/+3
Add unit test for CryptoBn. Cc: Jiewen Yao <jiewen.yao@intel.com> Cc: Jian J Wang <jian.j.wang@intel.com> Cc: Xiaoyu Lu <xiaoyu1.lu@intel.com> Cc: Guomin Jiang <guomin.jiang@intel.com> Signed-off-by: Yi Li <yi1.li@intel.com> Reviewed-by: Jiewen Yao <jiewen.yao@intel.com>
2022-09-23CryptoPkg: add UnitTest for AeadAesGcm.Qi Zhang1-0/+3
REF: https://bugzilla.tianocore.org/show_bug.cgi?id=4036 Signed-off-by: Qi Zhang <qi1.zhang@intel.com> Cc: Jiewen Yao <jiewen.yao@intel.com> Cc: Jian J Wang <jian.j.wang@intel.com> Cc: Xiaoyu Lu <xiaoyu1.lu@intel.com> Cc: Guomin Jiang <guomin.jiang@intel.com> Reviewed-by: Jiewen Yao <jiewen.yao@intel.com>
2022-09-23CryptoPkg: add Hkdf UnitTest.Qi Zhang1-0/+3
REF: https://bugzilla.tianocore.org/show_bug.cgi?id=4033 Signed-off-by: Qi Zhang <qi1.zhang@intel.com> Cc: Jiewen Yao <jiewen.yao@intel.com> Cc: Jian J Wang <jian.j.wang@intel.com> Cc: Xiaoyu Lu <xiaoyu1.lu@intel.com> Cc: Guomin Jiang <guomin.jiang@intel.com> Reviewed-by: Jiewen Yao <jiewen.yao@intel.com>
2021-12-07CryptoPkg: Apply uncrustify changesMichael Kubacki1-50/+48
REF: https://bugzilla.tianocore.org/show_bug.cgi?id=3737 Apply uncrustify changes to .c/.h files in the CryptoPkg package Cc: Andrew Fish <afish@apple.com> Cc: Leif Lindholm <leif@nuviainc.com> Cc: Michael D Kinney <michael.d.kinney@intel.com> Signed-off-by: Michael Kubacki <michael.kubacki@microsoft.com> Reviewed-by: Jian J Wang <jian.j.wang@intel.com>
2021-05-14CryptoPkg: BaseCryptLib: Add RSA PSS verify supportSachin Agrawal1-0/+3
REF: https://bugzilla.tianocore.org/show_bug.cgi?id=3314 This patch uses Openssl's EVP API's to perform RSASSA-PSS verification of a binary blob. Cc: Jiewen Yao <jiewen.yao@intel.com> Cc: Jian J Wang <jian.j.wang@intel.com> Cc: Xiaoyu Lu <xiaoyux.lu@intel.com> Cc: Guomin Jiang <guomin.jiang@intel.com> Signed-off-by: Sachin Agrawal <sachin.agrawal@intel.com> Reviewed-by: Jiewen Yao <jiewen.yao@intel.com>
2020-10-18CryptoPkg: BaseCryptLib: Add unit tests (Host and Shell based)Matthew Carlson1-0/+121
This adds a new INF for BaseCryptLib suitable for host based environments. It adds a host based unit test for BaseCryptLib that can also be built as a shell based Unit Test. In addition, this also adds a UnitTestHostCrtWrapper.c file, which provides some of the functionality not provided by the default host based unit test system that OpenSSL expects. This is used by UnitTestHostBaseCryptLib, a version of the BaseCryptLib meant specifically for host based unit testing. Cc: Jian J Wang <jian.j.wang@intel.com> Cc: Xiaoyu Lu <xiaoyux.lu@intel.com> Cc: Jiewen Yao <jiewen.yao@intel.com> Cc: Guomin Jiang <guomin.jiang@intel.com> Signed-off-by: Matthew Carlson <matthewfcarlson@gmail.com> Reviewed-by: Jiewen Yao <jiewen.yao@intel.com>