All of lore.kernel.org
 help / color / mirror / Atom feed
From: Philippe Reynes <philippe.reynes@softathome.com>
To: marko.makela@iki.fi, jonny.green@keytechinc.com,
	raymondmaoca@gmail.com, trini@konsulko.com,
	simon.glass@canonical.com
Cc: u-boot@lists.u-boot-project.org,
	Philippe Reynes <philippe.reynes@softathome.com>
Subject: [PATCH v9 06/15] test: dm: ecdsa.c: clean this test as software ecdsa is now implemented
Date: Thu,  3 Sep 2026 10:16:56 +0200	[thread overview]
Message-ID: <20260903081705.12894-7-philippe.reynes@softathome.com> (raw)
In-Reply-To: <20260903081705.12894-1-philippe.reynes@softathome.com>

The test ecdsa was done when ecdsa was only supported by hardware.
So it wasn't possible to test ecdsa on sandbox, and there is a test
to check that ecdsa is not supported on sandbox.
Now, there is a software implementation of ecdsa. So we add a test
to verify that ecdsa_verify may be used on sandbox.

Signed-off-by: Philippe Reynes <philippe.reynes@softathome.com>
---
v2:
- initial version
v3:
- no change
v4:
- add a test that use ecdsa_verify
v5:
- change secp256r1 to ecdsa256
- check that checksum and crypto are not null
v6:
- update commit message
- remove fdt_strerror in macro CHECK
- return ENOMEM when malloc fails
- add a define FDT_MAX_SIZE to avoid hardcoded value
v7:
- change uint8_t to u8
- set required_keynode to -1
v8:
- remove macro CHECK with a goto inside
- use lowercase for hex data
- code cleanup
v9:
- no change

 test/dm/ecdsa.c | 107 +++++++++++++++++++++++++++++++++++++++++++-----
 1 file changed, 97 insertions(+), 10 deletions(-)

diff --git a/test/dm/ecdsa.c b/test/dm/ecdsa.c
index d7eac7115f7..261ca3f9f73 100644
--- a/test/dm/ecdsa.c
+++ b/test/dm/ecdsa.c
@@ -3,36 +3,123 @@
 #include <crypto/ecdsa-uclass.h>
 #include <dm.h>
 #include <dm/test.h>
+#include <malloc.h>
 #include <test/ut.h>
 #include <u-boot/ecdsa.h>
 
+#define FDT_MAX_SIZE		512
+
+static int set_fdt_ecdsa_point(char *fdt, const char *name, const char *data)
+{
+	char *value = NULL;
+	size_t len;
+	int ret = 0;
+
+	if (!fdt || !name || !data) {
+		ret = -EINVAL;
+		goto out;
+	}
+
+	len = strlen(data) / 2;
+	if (!len) {
+		ret = -EINVAL;
+		goto out;
+	}
+
+	value = malloc(len);
+	if (!value) {
+		ret = -ENOMEM;
+		goto out;
+	}
+
+	ret = hex2bin(value, data, len);
+	if (ret)
+		goto out;
+
+	ret = fdt_property(fdt, name, value, len);
+	if (ret)
+		goto out;
+
+out:
+	free(value);
+	return ret;
+}
+
+static int create_fdt_with_ecdsa_key(struct unit_test_state *uts,
+				     char *fdt, size_t size,
+				     const char *name, const char *curve,
+				     const char *x, const char *y)
+{
+	ut_assertok(fdt_create(fdt, size));
+	ut_assertok(fdt_finish_reservemap(fdt));
+	ut_assertok(fdt_begin_node(fdt, ""));
+	ut_assertok(fdt_begin_node(fdt, "signature"));
+	ut_assertok(fdt_begin_node(fdt, name));
+	ut_assertok(fdt_property_string(fdt, "algo", "sha256,ecdsa256"));
+	ut_assertok(set_fdt_ecdsa_point(fdt, "ecdsa,y-point", y));
+	ut_assertok(set_fdt_ecdsa_point(fdt, "ecdsa,x-point", x));
+	ut_assertok(fdt_property_string(fdt, "ecdsa,curve", curve));
+	ut_assertok(fdt_property_string(fdt, "key-name-hint", name));
+	ut_assertok(fdt_end_node(fdt)); /* name */
+	ut_assertok(fdt_end_node(fdt)); /* "signature" */
+	ut_assertok(fdt_end_node(fdt)); /* "" */
+	ut_assertok(fdt_finish(fdt));
+	ut_assertok(fdt_pack(fdt));
+
+	return 0;
+}
+
 /*
  * Basic test of the ECDSA uclass and ecdsa_verify()
  *
- * ECDSA implementations in u-boot are hardware-dependent. Until we have a
- * software implementation that can be compiled into the sandbox, all we can
- * test is the uclass support.
+ * ECDSA software implementation is tested in another test,
+ * so we only check that the UCLASS_ECDSA uclass may be used.
  *
- * The uclass_get() test is redundant since ecdsa_verify() would also fail. We
- * run both functions in order to isolate the cause more clearly. i.e. is
- * ecdsa_verify() failing because the UCLASS is absent/broken?
+ * The data used in this test come from RFC6979 and use the
+ * sample with curve NIST P-256, hash sha256 and text "sample".
  */
 static int dm_test_ecdsa_verify(struct unit_test_state *uts)
 {
 	struct uclass *ucp;
+	const char *full_name = "sha256,ecdsa256";
+	const char *name = "key-ecdsa-256";
+	const char *curve = "prime256v1";
+	const char *x = "60fed4ba255a9d31c961eb74c6356d68c049b8923b61fa6ce669622e60f29fb6";
+	const char *y = "7903fe1008b8bc99a41ae9e95628bc64f2f1b20c2d7e9f5177a3c294d4462299";
+	const char *r = "efd48b2aacb6a8fd1140dd9cd45e81d69d2c877b56aaf991c34d0ea84eaf3716";
+	const char *s = "f7cb1c942d657c41d436c7a1b6e29f65f3e900dbb9aff4064dc4ab2f843acda8";
+	u8 sig[64];
+	char fdt[FDT_MAX_SIZE];
 
-	struct checksum_algo algo = {
-		.checksum_len = 256,
+	struct image_region region[] = {
+		{
+			.data = "sample",
+			.size = strlen("sample"),
+		},
 	};
 
 	struct image_sign_info info = {
-		.checksum = &algo,
+		.checksum = image_get_checksum_algo(full_name),
+		.crypto = image_get_crypto_algo(full_name),
+		.required_keynode = -1,
+		.fdt_blob = fdt,
 	};
 
+	ut_assertnonnull(info.checksum);
+	ut_assertnonnull(info.crypto);
+
+	/* create a fdt with the public key */
+	ut_assertok(create_fdt_with_ecdsa_key(uts, fdt, sizeof(fdt), name, curve, x, y));
+
+	/* prepare the signature */
+	ut_assertok(hex2bin(sig + 0, r, strlen(r) / 2));
+	ut_assertok(hex2bin(sig + 32, s, strlen(s) / 2));
+
 	ut_assertok(uclass_get(UCLASS_ECDSA, &ucp));
 	ut_assertnonnull(ucp);
-	ut_asserteq(-ENODEV, ecdsa_verify(&info, NULL, 0, NULL, 0));
+	ut_assertok(ecdsa_verify(&info, region, 1, sig, sizeof(sig)));
 
 	return 0;
 }
+
 DM_TEST(dm_test_ecdsa_verify, UTF_SCAN_PDATA | UTF_SCAN_FDT);
-- 
2.43.0


  parent reply	other threads:[~2026-09-03  8:17 UTC|newest]

Thread overview: 36+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-03  8:16 [PATCH v9 00/15] add software ecdsa support Philippe Reynes
2026-09-03  8:16 ` [PATCH v9 01/15] ecdsa: fix support of secp521r1 Philippe Reynes
2026-09-03 14:30   ` Raymond Mao
2026-09-03  8:16 ` [PATCH v9 02/15] mbedtls: enable support of ecc Philippe Reynes
2026-09-03 14:31   ` Raymond Mao
2026-09-03  8:16 ` [PATCH v9 03/15] ecdsa: initial support of ecdsa using mbedtls Philippe Reynes
2026-09-03 14:31   ` Raymond Mao
2026-09-03  8:16 ` [PATCH v9 04/15] test: lib: ecdsa: add initial test Philippe Reynes
2026-09-03 14:32   ` Raymond Mao
2026-09-03  8:16 ` [PATCH v9 05/15] drivers: crypto: add software ecdsa support Philippe Reynes
2026-09-03 14:32   ` Raymond Mao
2026-09-03 15:33     ` Raymond Mao
2026-09-03 18:33       ` Tom Rini
2026-09-03  8:16 ` Philippe Reynes [this message]
2026-09-03 14:33   ` [PATCH v9 06/15] test: dm: ecdsa.c: clean this test as software ecdsa is now implemented Raymond Mao
2026-09-03  8:16 ` [PATCH v9 07/15] test: py: vboot: prepare integration test for ecdsa Philippe Reynes
2026-09-03 15:42   ` Raymond Mao
2026-09-03  8:16 ` [PATCH v9 08/15] test: vboot: add " Philippe Reynes
2026-09-03 15:43   ` Raymond Mao
2026-09-03  8:16 ` [PATCH v9 09/15] tools: fit_image_setup_sig: set required_keynode to -1 Philippe Reynes
2026-09-03 14:34   ` Raymond Mao
2026-09-03  8:17 ` [PATCH v9 10/15] tools: mkimage: pre-load: add support of ecdsa Philippe Reynes
2026-09-03 14:36   ` Raymond Mao
2026-09-03  8:17 ` [PATCH v9 11/15] tools: binman: " Philippe Reynes
2026-09-03 14:37   ` Raymond Mao
2026-09-03  8:17 ` [PATCH v9 12/15] boot: " Philippe Reynes
2026-09-03 14:38   ` Raymond Mao
2026-09-03  8:17 ` [PATCH v9 13/15] tools: preload_check_sign: " Philippe Reynes
2026-09-03 14:39   ` Raymond Mao
2026-09-03  8:17 ` [PATCH v9 14/15] test: py: vboot: prepare test for global signature with ecdsa Philippe Reynes
2026-09-03 14:40   ` Raymond Mao
2026-09-03  8:17 ` [PATCH v9 15/15] test: py: vboot: add " Philippe Reynes
2026-09-03 14:41   ` Raymond Mao
2026-09-03 18:35 ` [PATCH v9 00/15] add software ecdsa support Tom Rini
2026-09-04  8:10   ` Philippe Reynes
2026-09-04 14:32     ` Tom Rini

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260903081705.12894-7-philippe.reynes@softathome.com \
    --to=philippe.reynes@softathome.com \
    --cc=jonny.green@keytechinc.com \
    --cc=marko.makela@iki.fi \
    --cc=raymondmaoca@gmail.com \
    --cc=simon.glass@canonical.com \
    --cc=trini@konsulko.com \
    --cc=u-boot@lists.u-boot-project.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.