Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
57 commits
Select commit Hold shift + click to select a range
48a2ab3
wolfcrypt: give the keywrap _ex test an Aes with the type's alignment
danielinux Aug 20, 2026
b46ff7a
tests: drive the crafted SP vectors on the three qemu-user ARM lanes
danielinux Aug 20, 2026
861512d
wolfcrypt: dsa.c key/parameter generation cleared mp_ints a failed mp…
danielinux Aug 20, 2026
fc23316
tests: add a white-box MC/DC supplement for src/tls13.c
danielinux Aug 20, 2026
0cf4dd8
tests: reach the tls13.c key schedule, cookie and message-ordering gu…
danielinux Aug 20, 2026
57cad5f
tests: xmss white-box drives the forged-BDS and unsupported-idx_len M…
danielinux Aug 20, 2026
ebb85b7
tests: lms MC/DC white-box for BDS auth-path state and the post-keyge…
danielinux Aug 20, 2026
276ad66
tests/unit-mcdc: add test_tfm_fault_whitebox.c closing 7 tfm.c MC/DC …
danielinux Aug 20, 2026
40ceeed
tests: white-box supplements for sp_cortexm.c on the m33mu lane
danielinux Aug 20, 2026
ada9250
tests: add white-box MC/DC supplements for srp.c and wolfmath.c
danielinux Aug 20, 2026
292c575
tests: drive the curve25519 blinding-rz and wolfentropy startup-noise…
danielinux Aug 20, 2026
5032dce
tests: white-box for puf.c's GF(2^7) multiply zero-operand guard
danielinux Aug 20, 2026
802b31c
wolfcrypt: xmss exhausted-key index marker wrapped and re-enabled sig…
danielinux Aug 20, 2026
5240ede
tests: complete the argument-guard vectors for the TLS 1.3-only publi…
danielinux Aug 20, 2026
b454a5b
tests: close the last MC/DC conditions in dsa.c, eccsi.c and sakke.c …
danielinux Aug 20, 2026
da2e4b4
wolfssl: keep the PEM no-start-line reason code out of the error trac…
danielinux Aug 20, 2026
490c679
wolfssl: include chacha20_poly1305.h whenever the ChaCha20-Poly1305 s…
danielinux Aug 20, 2026
f14d4f2
tests: pin the flaky lms treehash_update ret operands with a computed…
danielinux Aug 20, 2026
77b1c9d
tests: pair tsp.c TspResponse_Verify cert!=NULL with a wrong-trusted-…
danielinux Aug 20, 2026
cbb22d3
tests: close sp_int.c randomised Miller-Rabin err operand with a pinn…
danielinux Aug 20, 2026
a0daf9a
tests: record the xmss white-box exclusions and re-anchor its line re…
danielinux Aug 20, 2026
93dacda
tests: record the falcon depth-1 Babai clamp re-analysis in the white…
danielinux Aug 20, 2026
c29d3af
tests: drive wc_MlDsaKey_CheckKey s1/s2 range rows with a mutated pri…
danielinux Aug 20, 2026
aa5f472
tests: close ten pkcs7.c MC/DC conditions and make the seeded RNG hea…
danielinux Aug 20, 2026
a209619
tests: add test_puf_gf_whitebox.c to EXTRA_DIST
danielinux Aug 20, 2026
de0f578
tests: asn.c MC/DC vectors for the extension, key and revocation deco…
danielinux Aug 20, 2026
e4f36b6
tests: close eight tls13.c legacy-version MC/DC conditions with mutat…
danielinux Aug 20, 2026
e6c30b8
tests: close pkcs7.c MC/DC :12036 cond 0 and :8237 cond 0 with seeded…
danielinux Aug 20, 2026
2f9e695
tests: drive tls13.c certificate fragment resume with an interrupted …
danielinux Aug 20, 2026
152eb44
tests: close thirteen asn.c MC/DC conditions across five white-boxes
danielinux Aug 20, 2026
302542c
tests: add tls13 ECH handshakes and two version-negotiation vectors
danielinux Aug 20, 2026
7df01a6
tests: mutually authenticated tls13 handshakes for ecdsa, ed25519, ed…
danielinux Aug 20, 2026
b16cde4
tests: white-box the tls13.c pointer-presence guards
danielinux Aug 20, 2026
af04bae
tests: drive the sizeOnly arm of BuildTls13Message's argument guard
danielinux Aug 20, 2026
4d5c2fd
tests: close thirty-two tls13.c feature-flag MC/DC conditions with ne…
danielinux Aug 20, 2026
8e90e6a
tests: drop external tooling references from MC/DC test comments
danielinux Aug 20, 2026
b844d33
tests: fix tls13 test guard scope and register the new files with cmake
danielinux Aug 20, 2026
0545aca
tests: guard the ech round's session-ticket assertion on HAVE_SESSION…
danielinux Aug 20, 2026
1e8d00b
tests: add three tls extension test files to the tls group
danielinux Aug 20, 2026
fa088cb
tests: close tls.c argument-guard, CSR/CSR2 and TLS 1.2 MAC MC/DC con…
danielinux Aug 20, 2026
1dbb5d7
tests: cover the tls extension per-message-type gates in TLSX_Parse
danielinux Aug 20, 2026
eaac75d
tests: add TLSX extension parser tests for tls.c
danielinux Aug 20, 2026
2d51e22
tests: cover SNI, pre-shared-key, cookie and trusted-CA parsing in tls.c
danielinux Aug 20, 2026
3e047f1
tests: cover supported groups and key-share negotiation in tls.c
danielinux Aug 20, 2026
55150d0
tests: cover OCSP stapling, extension population and msgType dispatch…
danielinux Aug 20, 2026
aad6589
tests: define tls bounds tests unconditionally and fix link visibility
danielinux Aug 20, 2026
af6393b
tests: mark the tls bounds helpers as possibly unused
danielinux Aug 20, 2026
ce67d87
tests: skip the oversize psk key case where the library does not reje…
danielinux Aug 20, 2026
07aa9d1
tests: expect the ffdhe group when the build supports it
danielinux Aug 20, 2026
506c546
tests: guard the tls extension tests on the features they actually use
danielinux Aug 21, 2026
63c0381
tests: guard the tls extension tests on server side and auth availabi…
danielinux Aug 21, 2026
438c673
tests: mark the tls parse server-context helper as possibly unused
danielinux Aug 21, 2026
9874fa7
tests: define the tls parse unused marker outside the dh guard
danielinux Aug 21, 2026
3911d99
tests: guard the tls extension tests on extension and tls 1.2 availab…
danielinux Aug 21, 2026
e298803
tests: mark every static helper in the tls extension tests as possibl…
danielinux Aug 21, 2026
67c3983
tests: load an ecc server certificate when rsa is unavailable
danielinux Aug 21, 2026
fbfbdc6
tests: guard two ssl dereferences that run after a failed allocation
danielinux Aug 21, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions CMakeLists.txt
Original file line number Diff line number Diff line change
Expand Up @@ -4510,6 +4510,9 @@ if(WOLFSSL_EXAMPLES)
tests/api/test_evp.c
tests/api/test_tls_ext.c
tests/api/test_tls.c
tests/api/test_tls_bounds.c
tests/api/test_tls_msgtype.c
tests/api/test_tls_parse.c
tests/api/test_session.c
tests/api/test_x509.c
tests/api/test_asn.c
Expand Down Expand Up @@ -4550,6 +4553,8 @@ if(WOLFSSL_EXAMPLES)
tests/api/test_evp_pkey.c
tests/api/test_certman.c
tests/api/test_tls13.c
tests/api/test_tls13_bounds.c
tests/api/test_tls13_features.c
tests/srp.c
tests/suites.c
tests/w64wrapper.c
Expand Down
10 changes: 10 additions & 0 deletions tests/api.c
Original file line number Diff line number Diff line change
Expand Up @@ -268,6 +268,9 @@
#include <tests/api/test_evp.h>
#include <tests/api/test_tls_ext.h>
#include <tests/api/test_tls.h>
#include <tests/api/test_tls_bounds.h>
#include <tests/api/test_tls_msgtype.h>
#include <tests/api/test_tls_parse.h>
#include <tests/api/test_session.h>
#include <tests/api/test_x509.h>
#include <tests/api/test_asn.h>
Expand Down Expand Up @@ -309,6 +312,8 @@
#include <tests/api/test_evp_pkey.h>
#include <tests/api/test_certman.h>
#include <tests/api/test_tls13.h>
#include <tests/api/test_tls13_bounds.h>
#include <tests/api/test_tls13_features.h>
#if !defined(NO_CERTS) && defined(WOLFSSL_ASN_TEMPLATE) && defined(HAVE_ECC)
#include <tests/api/test_x500_unique_id_certs.h>
#endif
Expand Down Expand Up @@ -40276,6 +40281,8 @@ TEST_CASE testCases[] = {
TEST_DECL(test_wolfSSL_set_options),

TEST_TLS13_DECLS,
TEST_TLS13_BOUNDS_DECLS,
TEST_TLS13_FEATURES_DECLS,

TEST_DECL(test_wolfSSL_tmp_dh),
TEST_DECL(test_wolfSSL_tmp_dh_regression),
Expand Down Expand Up @@ -40678,6 +40685,9 @@ TEST_CASE testCases[] = {
TEST_DECL(test_ocsp_responder),
TEST_DECL(test_wolfIO_DecodeUrl_crlf_reject),
TEST_TLS_DECLS,
TEST_TLS_BOUNDS_DECLS,
TEST_TLS_MSGTYPE_DECLS,
TEST_TLS_PARSE_DECLS,
TEST_SESSION_DECLS,
TEST_DECL(test_wc_DhSetNamedKey),
TEST_DECL(test_DhAgree_rejects_p_minus_1),
Expand Down
10 changes: 10 additions & 0 deletions tests/api/include.am
Original file line number Diff line number Diff line change
Expand Up @@ -81,6 +81,9 @@ tests_unit_test_SOURCES += tests/api/test_ocsp.c
tests_unit_test_SOURCES += tests/api/test_evp.c
tests_unit_test_SOURCES += tests/api/test_tls_ext.c
tests_unit_test_SOURCES += tests/api/test_tls.c
tests_unit_test_SOURCES += tests/api/test_tls_bounds.c
tests_unit_test_SOURCES += tests/api/test_tls_msgtype.c
tests_unit_test_SOURCES += tests/api/test_tls_parse.c
tests_unit_test_SOURCES += tests/api/test_session.c
# Certs
tests_unit_test_SOURCES += tests/api/test_x509.c
Expand Down Expand Up @@ -138,6 +141,8 @@ tests_unit_test_SOURCES += tests/api/test_evp_pkey.c
tests_unit_test_SOURCES += tests/api/test_certman.c
# TLS 1.3 specific
tests_unit_test_SOURCES += tests/api/test_tls13.c
tests_unit_test_SOURCES += tests/api/test_tls13_bounds.c
tests_unit_test_SOURCES += tests/api/test_tls13_features.c
endif

EXTRA_DIST += tests/api/api.h
Expand Down Expand Up @@ -216,6 +221,9 @@ EXTRA_DIST += tests/api/create_x500_unique_id_certs.py
EXTRA_DIST += tests/api/test_evp.h
EXTRA_DIST += tests/api/test_tls_ext.h
EXTRA_DIST += tests/api/test_tls.h
EXTRA_DIST += tests/api/test_tls_bounds.h
EXTRA_DIST += tests/api/test_tls_msgtype.h
EXTRA_DIST += tests/api/test_tls_parse.h
EXTRA_DIST += tests/api/test_session.h
EXTRA_DIST += tests/api/test_x509.h
EXTRA_DIST += tests/api/test_asn.h
Expand Down Expand Up @@ -256,4 +264,6 @@ EXTRA_DIST += tests/api/test_evp_cipher.h
EXTRA_DIST += tests/api/test_evp_pkey.h
EXTRA_DIST += tests/api/test_certman.h
EXTRA_DIST += tests/api/test_tls13.h
EXTRA_DIST += tests/api/test_tls13_bounds.h
EXTRA_DIST += tests/api/test_tls13_features.h

2 changes: 1 addition & 1 deletion tests/api/test_aes.c
Original file line number Diff line number Diff line change
Expand Up @@ -8520,7 +8520,7 @@ int test_wc_AesFeatureCoverage(void)
* GCM/GMAC block works on all of them, so it only excludes HAVE_SELFTEST; the
* CCM block additionally excludes old FIPS (its AAD-only case diverges there,
* see the per-block note); the key-wrap block excludes all FIPS + self-test.
* The open MC/DC campaign builds are unaffected. */
* The open MC/DC builds are unaffected. */
#if !defined(NO_AES) && defined(HAVE_AESGCM) && !defined(HAVE_SELFTEST)
/* ---- AES-GCM streaming API: multi-chunk AAD and data ---- */
/* Uses a hardcoded 256-bit key, so requires AES-256. */
Expand Down
2 changes: 1 addition & 1 deletion tests/api/test_chacha.c
Original file line number Diff line number Diff line change
Expand Up @@ -73,7 +73,7 @@ int test_wc_Chacha_SetKey(void)

/* misaligned key pointer: exercises the (wc_ptr_t)key % 4 realignment
* decision in wc_Chacha_SetKey when XSTREAM_ALIGN is forced on (the
* xstream_align campaign variant). settings.h compiles XSTREAM_ALIGN out
* xstream_align variant). settings.h compiles XSTREAM_ALIGN out
* by default on x86_64/i386/ia64 (NO_XSTREAM_ALIGN), so this call is a
* harmless no-op realignment-free copy on every other build. */
{
Expand Down
2 changes: 1 addition & 1 deletion tests/api/test_dh.c
Original file line number Diff line number Diff line change
Expand Up @@ -39,7 +39,7 @@
* DH_MAX_SIZE expands to WC_BITS_FULL_BYTES(SP_INT_BITS), and
* WC_BITS_FULL_BYTES(x) is defined as (WC_BITS_TO_BYTES(x) << 3) - i.e. it
* returns SP_INT_BITS itself (rounded up to a byte multiple), NOT
* SP_INT_BITS/8 as its name suggests. With this campaign's SP_INT_BITS 4096,
* SP_INT_BITS/8 as its name suggests. With this suite's SP_INT_BITS 4096,
* DH_MAX_SIZE is therefore 4096 (bytes!), not the 512 a caller would
* reasonably expect. Passing that value as *privSz (a requested private-key
* size, not just a buffer capacity) to wc_DhGenerateKeyPair overflows the
Expand Down
64 changes: 32 additions & 32 deletions tests/api/test_ecc.c
Original file line number Diff line number Diff line change
Expand Up @@ -2712,12 +2712,12 @@ int test_wc_EccPrivateKeyToDer(void)
/*
* MC/DC wave 1 - decision-targeted negative/edge paths for wolfcrypt/src/
* ecc.c that the existing (already extensive) API tests above do not drive.
* Each block cites the GAPS.md line:col:cond it targets. No library source
* Each block cites the the uncovered-condition report line:col:cond it targets. No library source
* is changed; every case is reached through the public wc_ecc_* API.
*
* Split into several functions (test_wc_EccDecisionCoverage{,2,3,4}) rather
* than one large one: a single function covering this many independent
* decisions produced a stack-corrupting crash under this campaign's
* decisions produced a stack-corrupting crash under this suite's
* -fcoverage-mcdc + -O0 combination (reproduced with gdb: a plain on-stack
* mp_int's used/size fields were already garbage immediately after its own
* mp_init(), and clearing it then walked off the end of its dp[] array and
Expand Down Expand Up @@ -2747,7 +2747,7 @@ int test_wc_EccDecisionCoverage(void)
#endif
ExpectIntEQ(ret, 0);

/* ---- wc_ecc_set_curve: GAPS.md 1927 ----
/* ---- wc_ecc_set_curve: the uncovered-condition report 1927 ----
* if (key == NULL || (keysize <= 0 && curve_id < 0))
* key==NULL true side is already exercised elsewhere (BAD_FUNC_ARG on a
* NULL key is a common pattern); complete the compound's other operand
Expand All @@ -2763,7 +2763,7 @@ int test_wc_EccDecisionCoverage(void)
ExpectIntEQ(wc_ecc_set_curve(&key, KEY32, -1), 0);
#endif

/* ---- wc_ecc_get_curve_id: GAPS.md 4317 ----
/* ---- wc_ecc_get_curve_id: the uncovered-condition report 4317 ----
* if (wc_ecc_is_valid_idx(curve_idx) && curve_idx >= 0)
* curve_idx == -1 makes wc_ecc_is_valid_idx() true (ECC_CUSTOM_IDX is
* a valid "user-supplied params" index) but curve_idx>=0 false: the
Expand All @@ -2774,14 +2774,14 @@ int test_wc_EccDecisionCoverage(void)
ExpectIntEQ(wc_ecc_get_curve_id(key.idx), ECC_SECP256R1);
#endif

/* ---- wc_ecc_get_curve_params: GAPS.md 4654 ----
/* ---- wc_ecc_get_curve_params: the uncovered-condition report 4654 ----
* if (curve_idx >= 0 && curve_idx < (int)ECC_SET_COUNT)
* both boundary violations (negative, and >= COUNT) plus a valid idx. */
ExpectNull(wc_ecc_get_curve_params(-1));
ExpectNull(wc_ecc_get_curve_params(1000000));
ExpectNotNull(wc_ecc_get_curve_params(key.idx));

/* ---- wc_ecc_point_is_at_infinity: GAPS.md 5320 ----
/* ---- wc_ecc_point_is_at_infinity: the uncovered-condition report 5320 ----
* if (mp_iszero(p->x) && mp_iszero(p->y))
* Unique-cause MC/DC for a 2-operand AND needs THREE vectors within
* this same binary: (T,T), (F,T), (T,F) (the existing pointFns test's
Expand All @@ -2805,7 +2805,7 @@ int test_wc_EccDecisionCoverage(void)
wc_ecc_del_point(inf);
}

/* ---- wc_ecc_gen_k: GAPS.md 5335 ----
/* ---- wc_ecc_gen_k: the uncovered-condition report 5335 ----
* if (rng==NULL || size<0 || size+8>ECC_MAXSIZE_GEN || k==NULL ||
* order==NULL)
* Exercise each operand's TRUE side individually against an otherwise
Expand All @@ -2832,7 +2832,7 @@ int test_wc_EccDecisionCoverage(void)
}
#endif

/* ---- wc_ecc_init_id: GAPS.md 6479, 6483 ----
/* ---- wc_ecc_init_id: the uncovered-condition report 6479, 6483 ----
* if (ret == 0 && (len < 0 || len > ECC_MAX_ID_LEN)) -> BUFFER_E
* if (ret == 0 && id != NULL && len != 0) -> copy branch
* Exercise: len<0, len>MAX, id==NULL (len!=0 skipped), len==0 (id!=NULL
Expand All @@ -2855,7 +2855,7 @@ int test_wc_EccDecisionCoverage(void)
XMEMSET(&idKey, 0, sizeof(idKey));
ExpectIntEQ(wc_ecc_init_id(&idKey, NULL, 0, NULL, INVALID_DEVID), 0);
wc_ecc_free(&idKey);
/* id != NULL, len == 0: GAPS.md 6483's 3rd operand (len != 0)
/* id != NULL, len == 0: the uncovered-condition report 6483's 3rd operand (len != 0)
* independence pair -- id!=NULL fixed TRUE across this call and
* the all-true "copy" call below, len toggled 0 vs nonzero. */
XMEMSET(&idKey, 0, sizeof(idKey));
Expand All @@ -2868,7 +2868,7 @@ int test_wc_EccDecisionCoverage(void)
}
#endif

/* ---- wc_ecc_init_label: GAPS.md 6503, 6507 ----
/* ---- wc_ecc_init_label: the uncovered-condition report 6503, 6507 ----
* if (key == NULL || label == NULL)
* if (labelLen == 0 || labelLen > ECC_MAX_LABEL_LEN) */
#ifdef WOLF_PRIVATE_KEY_ID
Expand Down Expand Up @@ -2898,7 +2898,7 @@ int test_wc_EccDecisionCoverage(void)
#endif

#if defined(HAVE_ECC_SIGN) && !defined(NO_ASN)
/* ---- wc_ecc_sign_hash / wc_ecc_sign_hash_ex: GAPS.md 6909, 7443 ----
/* ---- wc_ecc_sign_hash / wc_ecc_sign_hash_ex: the uncovered-condition report 6909, 7443 ----
* if ((inlen > WC_MAX_DIGEST_SIZE) || (inlen < WC_MIN_DIGEST_SIZE_FOR_SIGN))
* The signVerify_hash test above already shows the ">MAX" true side;
* complete the other operand with a too-short digest. */
Expand All @@ -2919,7 +2919,7 @@ int test_wc_EccDecisionCoverage(void)
#endif
/* wc_ecc_sign_hash() has its OWN copy of this length check (it does
* not delegate to wc_ecc_sign_hash_ex() before running it), so
* GAPS.md 7443 (wc_ecc_sign_hash_ex's identical check) needs a
* the uncovered-condition report 7443 (wc_ecc_sign_hash_ex's identical check) needs a
* direct call in the SAME test binary to independently show its own
* MC/DC pair -- llvm-cov computes independence per-binary, so
* showing the FALSE side via signVerify_hash's normal-length call
Expand Down Expand Up @@ -2947,7 +2947,7 @@ int test_wc_EccDecisionCoverage(void)
#endif /* HAVE_ECC_SIGN && !NO_ASN */

#if defined(HAVE_ECC_VERIFY) && defined(WOLFSSL_PUBLIC_MP)
/* ---- wc_ecc_verify_hash_ex: GAPS.md 9476 ----
/* ---- wc_ecc_verify_hash_ex: the uncovered-condition report 9476 ----
* Same reasoning as wc_ecc_sign_hash_ex above: wc_ecc_verify_hash()
* does not delegate through this check, so it needs its own direct
* short-hash call in this binary. */
Expand All @@ -2970,7 +2970,7 @@ int test_wc_EccDecisionCoverage(void)
}
#endif

/* ---- wc_ecc_free: GAPS.md 8209 ----
/* ---- wc_ecc_free: the uncovered-condition report 8209 ----
* if (key->deallocSet && key->dp != NULL)
* Exercise the "deallocSet but dp already NULL" and "dp set but
* deallocSet false" independence halves via wc_ecc_set_custom_curve
Expand Down Expand Up @@ -3025,7 +3025,7 @@ int test_wc_EccDecisionCoverage2(void)

#if defined(HAVE_ECC_VERIFY) && !defined(WOLFSSL_SP_MATH) && \
defined(WOLFSSL_PUBLIC_MP)
/* ---- wc_ecc_check_r_s_range (via wc_ecc_verify_hash_ex): GAPS.md
/* ---- wc_ecc_check_r_s_range (via wc_ecc_verify_hash_ex): the uncovered-condition report
* 8939, 8942 ----
* if ((err == 0) && (mp_cmp(r, curve->order) != MP_LT)) -> r >= order
* if ((err == 0) && (mp_cmp(s, curve->order) != MP_LT)) -> s >= order
Expand Down Expand Up @@ -3056,7 +3056,7 @@ int test_wc_EccDecisionCoverage2(void)
#endif

/* ---- wc_ecc_import_point_der_ex / wc_ecc_export_point_der{,_compressed}:
* GAPS.md 9710, 9964, 9970, 9975, 9984, 10030, 10037, 10042 ---- */
* the uncovered-condition report 9710, 9964, 9970, 9975, 9984, 10030, 10037, 10042 ---- */
#if defined(HAVE_ECC_KEY_EXPORT) && defined(HAVE_ECC_KEY_IMPORT)
{
ecc_point* point = NULL;
Expand Down Expand Up @@ -3102,10 +3102,10 @@ int test_wc_EccDecisionCoverage2(void)
{
/* wc_ecc_export_point_der_compressed is WOLFSSL_LOCAL (hidden in a
* shared library), so it is not linkable from the shared-library
* unit test; its own decision coverage is driven by the campaign's
* unit test; its own decision coverage is driven by the
* ecc white-box (which includes ecc.c directly). The public
* compressed export path wc_ecc_export_x963_ex(..., 1) is exercised
* here (GAPS.md 16058, the static wc_ecc_export_x963_compressed
* here (the uncovered-condition report 16058, the static wc_ecc_export_x963_compressed
* helper). */
#ifdef HAVE_ECC_KEY_EXPORT
{
Expand All @@ -3124,7 +3124,7 @@ int test_wc_EccDecisionCoverage2(void)
}
#endif /* HAVE_ECC_KEY_EXPORT && HAVE_ECC_KEY_IMPORT */

/* ---- wc_ecc_is_point: GAPS.md 10304, 10329, 10332, 10390, 10396,
/* ---- wc_ecc_is_point: the uncovered-condition report 10304, 10329, 10332, 10390, 10396,
* 10403 ----
* Direct call (rather than through wc_ecc_point_is_on_curve) with a
* point that is genuinely ON the curve (the generator) and the
Expand Down Expand Up @@ -3191,7 +3191,7 @@ int test_wc_EccDecisionCoverage3(void)
ExpectIntEQ(ret, 0);

/* ---- wc_ecc_export_public_raw / wc_ecc_export_private_raw:
* GAPS.md 11477, 11484, 11538, 11548 ---- */
* the uncovered-condition report 11477, 11484, 11538, 11548 ---- */
#if defined(HAVE_ECC_KEY_EXPORT)
{
byte qx[MAX_ECC_BYTES], qy[MAX_ECC_BYTES], d[MAX_ECC_BYTES];
Expand All @@ -3207,12 +3207,12 @@ int test_wc_EccDecisionCoverage3(void)
&qyLen), WC_NO_ERR_TRACE(ECC_BAD_ARG_E));
wc_ecc_free(&noDpKey);

/* d != NULL but dLen == NULL: GAPS.md 11484 first operand. */
/* d != NULL but dLen == NULL: the uncovered-condition report 11484 first operand. */
qxLen = sizeof(qx); qyLen = sizeof(qy);
ExpectIntEQ(wc_ecc_export_private_raw(&key, qx, &qxLen, qy, &qyLen,
d, NULL), WC_NO_ERR_TRACE(BAD_FUNC_ARG));

/* d != NULL, dLen != NULL, but key type is public-only: GAPS.md
/* d != NULL, dLen != NULL, but key type is public-only: the uncovered-condition report
* 11484 second operand. */
{
ecc_key pubOnly;
Expand All @@ -3229,13 +3229,13 @@ int test_wc_EccDecisionCoverage3(void)
ExpectIntEQ(wc_ecc_export_private_raw(&pubOnly, NULL, NULL,
NULL, NULL, d, &dLen), WC_NO_ERR_TRACE(BAD_FUNC_ARG));

/* qx != NULL, qxLen == NULL: GAPS.md 11538 first operand. */
/* qx != NULL, qxLen == NULL: the uncovered-condition report 11538 first operand. */
ExpectIntEQ(wc_ecc_export_private_raw(&key, qx, NULL, NULL,
NULL, NULL, NULL), WC_NO_ERR_TRACE(BAD_FUNC_ARG));
/* qy != NULL, qyLen == NULL: GAPS.md 11548 first operand. */
/* qy != NULL, qyLen == NULL: the uncovered-condition report 11548 first operand. */
ExpectIntEQ(wc_ecc_export_private_raw(&key, NULL, NULL, qy,
NULL, NULL, NULL), WC_NO_ERR_TRACE(BAD_FUNC_ARG));
/* qx != NULL against a PRIVATEKEY_ONLY key: GAPS.md 11538
/* qx != NULL against a PRIVATEKEY_ONLY key: the uncovered-condition report 11538
* second operand (type == ECC_PRIVATEKEY_ONLY). */
pubOnly.type = ECC_PRIVATEKEY_ONLY;
qxbLen = sizeof(qxb);
Expand All @@ -3250,7 +3250,7 @@ int test_wc_EccDecisionCoverage3(void)
}
#endif /* HAVE_ECC_KEY_EXPORT */

/* ---- wc_ecc_rs_raw_to_sig: GAPS.md 12015 ---- */
/* ---- wc_ecc_rs_raw_to_sig: the uncovered-condition report 12015 ---- */
{
byte r[KEY32], s[KEY32], sig[ECC_MAX_SIG_SIZE];
word32 sigLen = sizeof(sig);
Expand All @@ -3269,7 +3269,7 @@ int test_wc_EccDecisionCoverage3(void)
NULL), WC_NO_ERR_TRACE(ECC_BAD_ARG_E));
}

/* ---- wc_ecc_import_private_key_ex: GAPS.md 11671 (_ecc_import_
/* ---- wc_ecc_import_private_key_ex: the uncovered-condition report 11671 (_ecc_import_
* private_key_ex key==NULL||priv==NULL, reached via the public
* wrapper's own identical pre-check, same independence pair) ---- */
#if defined(HAVE_ECC_KEY_IMPORT)
Expand Down Expand Up @@ -3313,7 +3313,7 @@ int test_wc_EccDecisionCoverage4(void)
#endif
ExpectIntEQ(ret, 0);

/* ---- ecc_mul2add argument guard: GAPS.md 8446 ----
/* ---- ecc_mul2add argument guard: the uncovered-condition report 8446 ----
* NOT closeable by any current variant, API or white-box: both bodies
* of ecc_mul2add() (the argument-checked "normal" one at line ~8417 and
* the Shamir/fixed-point-cache one at line ~13909 that supersedes it
Expand All @@ -3324,13 +3324,13 @@ int test_wc_EccDecisionCoverage4(void)
* exercises the unchecked Shamir body under the name ecc_mul2add) or
* turns BOTH ECC_SHAMIR and FP_ECC OFF together (no_fp_shamir, per its
* config_base's philosophy of flipping the FALSE side of both feature
* guards at once -- see modules.json's ecc notes), which compiles
* guards at once -- see the module registry's ecc notes), which compiles
* *neither* body, making ecc_mul2add an undefined symbol there (link
* failure, confirmed empirically). Reaching this decision needs a new,
* not-yet-scaffolded variant: ECC_SHAMIR on + FP_ECC off. Classified as
* a needs-variant residual; see RESIDUALS.md. */

/* ---- wc_ecc_ctx_set_kdf_salt: GAPS.md 14607 ----
/* ---- wc_ecc_ctx_set_kdf_salt: the uncovered-condition report 14607 ----
* if (ctx == NULL || (salt == NULL && sz != 0))
* ctx==NULL already the common BAD_FUNC_ARG idiom shown elsewhere; add
* the salt==NULL/sz!=0 half here with a live ctx. */
Expand All @@ -3347,7 +3347,7 @@ int test_wc_EccDecisionCoverage4(void)
}
#endif

/* ---- wc_ecc_set_custom_curve: GAPS.md 16181 ---- */
/* ---- wc_ecc_set_custom_curve: the uncovered-condition report 16181 ---- */
#if defined(WOLFSSL_CUSTOM_CURVES)
{
ecc_key ccKey2;
Expand All @@ -3361,7 +3361,7 @@ int test_wc_EccDecisionCoverage4(void)
}
#endif

/* ---- wc_X963_KDF: GAPS.md 16217, 16221 ---- */
/* ---- wc_X963_KDF: the uncovered-condition report 16217, 16221 ---- */
#ifdef HAVE_X963_KDF
{
byte secret[16];
Expand Down
2 changes: 1 addition & 1 deletion tests/api/test_hash.c
Original file line number Diff line number Diff line change
Expand Up @@ -999,7 +999,7 @@ int test_wc_HashDecisionCoverage(void)
* these types, so hash->type is never one of them and the debug check
* always intercepts here, making the arm unreachable in DEBUG builds
* (non-DEBUG builds cover it). Not a value workaround -- the arm's
* coverage simply comes from non-DEBUG variants in the campaign union. */
* coverage simply comes from non-DEBUG variants in the harness union. */
#ifndef DEBUG_WOLFSSL
ExpectIntEQ(wc_HashUpdate(&hash, WC_HASH_TYPE_MD5_SHA, (byte*)"a", 1),
WC_NO_ERR_TRACE(HASH_TYPE_E));
Expand Down
Loading
Loading