Compare commits
8
Commits
v1.14.1
...
v1.14.1-pqc
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
ad01fbcccb | ||
|
|
fa08792c78 | ||
|
|
1ead221c6a | ||
|
|
a6b0c58511 | ||
|
|
86c744897b | ||
|
|
d4568326af | ||
|
|
7cf826c6b6 | ||
|
|
c550fe0684 |
No files matched your search
@@ -31,14 +31,14 @@ jobs:
|
||||
- name: selftest
|
||||
run: |
|
||||
make selftest
|
||||
./zerotier-selftest
|
||||
./backone-selftest
|
||||
- name: 'Tar files' # keeps permissions (execute)
|
||||
run: tar -cvf zerotier-one.tar zerotier-one
|
||||
run: tar -cvf backone.tar backone
|
||||
- name: Archive production artifacts
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: zerotier-one-ubuntu-x64
|
||||
path: zerotier-one.tar
|
||||
name: backone-ubuntu-x64
|
||||
path: backone.tar
|
||||
retention-days: 7
|
||||
|
||||
build_macos:
|
||||
@@ -75,14 +75,14 @@ jobs:
|
||||
- name: selftest
|
||||
run: |
|
||||
make selftest
|
||||
./zerotier-selftest
|
||||
./backone-selftest
|
||||
- name: 'Tar files' # keeps permissions (execute)
|
||||
run: tar -cvf zerotier-one.tar zerotier-one
|
||||
run: tar -cvf backone.tar backone
|
||||
- name: Archive production artifacts
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: zerotier-one-mac
|
||||
path: zerotier-one.tar
|
||||
name: backone-mac
|
||||
path: backone.tar
|
||||
retention-days: 7
|
||||
|
||||
|
||||
@@ -118,6 +118,6 @@ jobs:
|
||||
- name: Archive production artifacts
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: zerotier-one-windows
|
||||
name: backone-windows
|
||||
path: windows/Build
|
||||
retention-days: 7
|
||||
@@ -0,0 +1,25 @@
|
||||
name: Lint
|
||||
|
||||
on:
|
||||
push:
|
||||
pull_request:
|
||||
|
||||
jobs:
|
||||
clang-format:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
with:
|
||||
fetch-depth: 0
|
||||
# Pin: format results differ across clang-format versions.
|
||||
- run: pip install --user clang-format==23.1.1 && echo "$HOME/.local/bin" >> "$GITHUB_PATH"
|
||||
- name: Check changed lines
|
||||
run: |
|
||||
if [ "${{ github.event_name }}" = "pull_request" ]; then
|
||||
BASE="${{ github.event.pull_request.base.sha }}"
|
||||
elif [ "${{ github.event.before }}" != "" ] && [ "${{ github.event.before }}" != "0000000000000000000000000000000000000000" ]; then
|
||||
BASE="${{ github.event.before }}"
|
||||
else
|
||||
BASE="$(git merge-base HEAD "origin/${{ github.event.repository.default_branch }}" || echo HEAD~1)"
|
||||
fi
|
||||
./tools/lint.sh "$BASE"
|
||||
@@ -38,9 +38,9 @@ test() {
|
||||
export NS1="ip netns exec ns1"
|
||||
export NS2="ip netns exec ns2"
|
||||
|
||||
export ZT1="$NS1 ./zerotier-cli -p9996 -D$(pwd)/node1"
|
||||
export ZT1="$NS1 ./backone-cli -p9996 -D$(pwd)/node1"
|
||||
# Specify custom port on one node to ensure that feature works
|
||||
export ZT2="$NS2 ./zerotier-cli -p9997 -D$(pwd)/node2"
|
||||
export ZT2="$NS2 ./backone-cli -p9997 -D$(pwd)/node2"
|
||||
|
||||
echo -e "\nSetting up network namespaces..."
|
||||
echo "Setting up ns1"
|
||||
@@ -102,13 +102,13 @@ test() {
|
||||
--xml=yes \
|
||||
--xml-file=$FILENAME_MEMORY_LOG \
|
||||
--leak-check=full \
|
||||
./zerotier-one node1 -p$ZT_PORT_NODE_1 -U >>node_1.log 2>&1 &
|
||||
./backone node1 -p$ZT_PORT_NODE_1 -U >>node_1.log 2>&1 &
|
||||
|
||||
# Second instance, not run in memory profiler
|
||||
# Don't set up internet access until _after_ zerotier is running
|
||||
# This has been a source of stuckness in the past.
|
||||
$NS2 ip addr del 192.168.1.2/24 dev veth3
|
||||
$NS2 sudo ./zerotier-one node2 -U -p$ZT_PORT_NODE_2 >>node_2.log 2>&1 &
|
||||
$NS2 sudo ./backone node2 -U -p$ZT_PORT_NODE_2 >>node_2.log 2>&1 &
|
||||
|
||||
sleep 10; # New HTTP control plane is a bit sluggish, so we delay here
|
||||
|
||||
@@ -170,9 +170,9 @@ test() {
|
||||
|
||||
echo -e "\n\nRunning ZeroTier processes:"
|
||||
echo -e "\nNode 1:\n"
|
||||
$NS1 ps aux | grep zerotier-one
|
||||
$NS1 ps aux | grep backone
|
||||
echo -e "\nNode 2:\n"
|
||||
$NS2 ps aux | grep zerotier-one
|
||||
$NS2 ps aux | grep backone
|
||||
|
||||
echo -e "\n\nStatus of each instance:"
|
||||
|
||||
@@ -319,10 +319,10 @@ exit_test_and_generate_report() {
|
||||
node2_id=$($ZT2 -j status | jq -r .address)
|
||||
|
||||
$ZT1 dump
|
||||
mv zerotier_dump.txt "$TEST_FILEPATH_PREFIX-node-dump-$node1_id.txt"
|
||||
mv backone_dump.txt "$TEST_FILEPATH_PREFIX-node-dump-$node1_id.txt"
|
||||
|
||||
$ZT2 dump
|
||||
mv zerotier_dump.txt "$TEST_FILEPATH_PREFIX-node-dump-$node2_id.txt"
|
||||
mv backone_dump.txt "$TEST_FILEPATH_PREFIX-node-dump-$node2_id.txt"
|
||||
|
||||
# Copy ZeroTier stdout/stderr logs
|
||||
|
||||
@@ -386,7 +386,7 @@ exit_test_and_generate_report() {
|
||||
"commit":"$ZTO_COMMIT",
|
||||
"arch_m":"$(uname -m)",
|
||||
"arch_a":"$(uname -a)",
|
||||
"binary_size":"$(stat -c %s zerotier-one)",
|
||||
"binary_size":"$(stat -c %s backone)",
|
||||
"time_length_test":$time_length_test,
|
||||
"time_to_both_nodes_online":$time_to_both_nodes_online,
|
||||
"num_possible_bytes_lost": $POSSIBLY_LOST,
|
||||
@@ -448,7 +448,7 @@ spam_cli() {
|
||||
check_exit_on_invalid_identity() {
|
||||
echo "Checking ZeroTier exits on invalid identity..."
|
||||
mkdir -p $(pwd)/exit_test
|
||||
ZT1="sudo ./zerotier-one -p9999 $(pwd)/exit_test"
|
||||
ZT1="sudo ./backone -p9999 $(pwd)/exit_test"
|
||||
echo "asdfasdfasdfasdf" > $(pwd)/exit_test/identity.secret
|
||||
echo "asdfasdfasdfasdf" > $(pwd)/exit_test/authtoken.secret
|
||||
|
||||
@@ -473,20 +473,20 @@ check_exit_on_invalid_identity() {
|
||||
check_bind_to_correct_ports() {
|
||||
PORT_NUMBER=$1
|
||||
echo "Checking bound ports:"
|
||||
sudo netstat -anp | grep "$PORT_NUMBER" | grep "zerotier"
|
||||
if [[ $(sudo netstat -anp | grep "$PORT_NUMBER" | grep "zerotier" | grep "tcp") ]];
|
||||
sudo netstat -anp | grep "$PORT_NUMBER" | grep "backone"
|
||||
if [[ $(sudo netstat -anp | grep "$PORT_NUMBER" | grep "backone" | grep "tcp") ]];
|
||||
then
|
||||
:
|
||||
else
|
||||
exit_test_and_generate_report $TEST_FAIL "ZeroTier did not bind to tcp/$1"
|
||||
fi
|
||||
if [[ $(sudo netstat -anp | grep "$PORT_NUMBER" | grep "zerotier" | grep "tcp6") ]];
|
||||
if [[ $(sudo netstat -anp | grep "$PORT_NUMBER" | grep "backone" | grep "tcp6") ]];
|
||||
then
|
||||
:
|
||||
else
|
||||
exit_test_and_generate_report $TEST_FAIL "ZeroTier did not bind to tcp6/$1"
|
||||
fi
|
||||
if [[ $(sudo netstat -anp | grep "$PORT_NUMBER" | grep "zerotier" | grep "udp") ]];
|
||||
if [[ $(sudo netstat -anp | grep "$PORT_NUMBER" | grep "backone" | grep "udp") ]];
|
||||
then
|
||||
:
|
||||
else
|
||||
|
||||
+9
-3
@@ -80,10 +80,12 @@ zt1-src.tar.gz
|
||||
node_modules
|
||||
zt1_update_*
|
||||
debian/files
|
||||
debian/zerotier-one
|
||||
debian/zerotier-one*.debhelper
|
||||
debian/backone
|
||||
debian/backone*.debhelper
|
||||
debian/*.log
|
||||
debian/zerotier-one.substvars
|
||||
debian/backone.substvars
|
||||
debian/.debhelper/
|
||||
debian/debhelper-build-stamp
|
||||
root-watcher/config.json
|
||||
|
||||
# Java/Android/JNI build droppings
|
||||
@@ -154,3 +156,7 @@ rustybits/
|
||||
backone
|
||||
backone-cli
|
||||
backone-idtool
|
||||
|
||||
/backone-selftest
|
||||
*.gcno
|
||||
*.gcda
|
||||
@@ -0,0 +1,124 @@
|
||||
# Repository Guidelines
|
||||
|
||||
## Project Overview
|
||||
|
||||
BackOne — fork of ZeroTier 1.14.1: peer-to-peer SDN daemon. Builds virtual Ethernet (TUN/TAP), tunnels L2 frames over encrypted UDP mesh, issues membership certs from an embedded controller. One fat binary `backone` doubles as CLI (`backone-cli`) and identity tool (`backone-idtool`) via `argv[0]` dispatch (`one.cpp:2140-2142`). Local JSON API on `127.0.0.1:9993`.
|
||||
|
||||
## Architecture & Data Flow
|
||||
|
||||
Four layers, top → bottom:
|
||||
|
||||
1. **Entry** — `one.cpp`: `main()` → `cli()` / `idtool()` / daemon → `OneService::newInstance()` + `run()`.
|
||||
2. **Service** — `service/OneService.cpp` (`OneServiceImpl`, line 776): owns sockets (`Phy<>`), httplib control plane, TAP devices, `Node`, `EmbeddedNetworkController`, main loop.
|
||||
3. **Core** — `node/`: OS-independent switch. Reached only through the C API (`ZT_Node_*` in `include/ZeroTierOne.h`, implemented at bottom of `node/Node.cpp`).
|
||||
4. **OS glue** — `osdep/`: `Phy` (select()-based reactor, the only event loop), `EthernetTap` (per-OS TUN/TAP), `OSUtils`, `ManagedRoute`, `Thread`, `BlockingQueue`.
|
||||
|
||||
**Core pattern = inversion of control.** `OneServiceImpl` fills `struct ZT_Node_Callbacks` (`service/OneService.cpp:1045-1054`) with `Snode*` static functions; `node/` never touches OS code, it calls back. Shared context is `RuntimeEnvironment` passed as `const RuntimeEnvironment *RR` to every `node/` function (`node/RuntimeEnvironment.hpp`).
|
||||
|
||||
Flows:
|
||||
|
||||
- **Wire → app:** `Phy::poll` → `phyOnDatagram` (`service/OneService.cpp:2940`) → `Node::processWirePacket` (`node/Node.cpp:206`) → `Switch::onRemotePacket` → verb dispatch `switch` (`node/IncomingPacket.cpp:94-151`) → peer/network/crypto. Heavy work offloaded to `PacketMultiplexer` worker threads.
|
||||
- **App → wire:** TAP handler → `tapFrameHandler` (`service/OneService.cpp:3776`) → `Node::processVirtualNetworkFrame` → `Switch::onLocalEthernet` → `Peer`/`Path` → `_phy.udpSend`.
|
||||
- **Controller:** `IncomingPacket::_doNETWORK_CONFIG_REQUEST` → `EmbeddedNetworkController::request` posts `_RQEntry*` to `BlockingQueue` → `hardware_concurrency()` workers → `DBMirrorSet`/`DB` → signed cert back via `NetworkController::Sender`.
|
||||
- **Main loop** (`OneServiceImpl::run`, `service/OneService.cpp:~1150-1310`): single-threaded, time-sliced; refresh binds → `processBackgroundTasks` when due → `_phy.poll(delay)`. `Phy::whack()` (self-pipe) is the only cross-thread-safe Phy call.
|
||||
|
||||
## Key Directories
|
||||
|
||||
| Path | Purpose |
|
||||
|---|---|
|
||||
| `one.cpp` | Daemon/CLI/idtool entry; privilege drop, daemonize, signals |
|
||||
| `node/` | Overlay engine: `Switch`, `Topology`, `Peer`, `IncomingPacket`, `Identity`, `Bond`, `Metrics` — OS-independent by rule |
|
||||
| `service/` | `OneService` (whole runtime), `SoftwareUpdater` |
|
||||
| `controller/` | `EmbeddedNetworkController` + `DB` backends (FileDB default, LFDB, PostgreSQL, Redis) |
|
||||
| `osdep/` | All OS-dependent code: `Phy`, `EthernetTap*`, `Binder`, `ManagedRoute`, netlink/DNS helpers |
|
||||
| `include/` | Public C API (`ZeroTierOne.h`, 57KB) — changes ripple to Java/libzt/SDK |
|
||||
| `ext/` | Vendored: nlohmann/json, cpp-httplib, prometheus-cpp-lite, libpqxx, redis++, miniupnpc, ASM crypto |
|
||||
| `rustybits/` | Cargo workspace: `zeroidc` (SSO FFI), `smeeclient` (PostgreSQL workflow client) |
|
||||
| `java/` | JNI wrapper (`java/jni/…Node.cpp`, ant build) |
|
||||
| `tcp-proxy/` | Standalone TCP fallback relay; own Makefile (C++11) |
|
||||
| `rule-compiler/` | JS network-rules compiler (`node cli.js <rules>`), npm |
|
||||
| `pkg/`, `debian/`, `windows/` | Packaging (snap/QNAP/Synology/ASUSTOR/WD, RPM `backone.spec`, MSVC sln) |
|
||||
|
||||
## Development Commands
|
||||
|
||||
```sh
|
||||
make # = make one → ./backone + backone-cli/backone-idtool symlinks
|
||||
make -j$(nproc) one
|
||||
make core # libbackonecore.a
|
||||
make selftest && ./backone-selftest
|
||||
make debug # ZT_DEBUG=1 (adds -g, forces ZT_TRACE=1)
|
||||
make ZT_SANITIZE=1 one # ASan
|
||||
make central-controller # ZT_CONTROLLER=1 (needs ext/ libpqxx + hiredis + redis++)
|
||||
make install DESTDIR=/tmp/root
|
||||
make debian | make redhat # debuild / rpmbuild
|
||||
make manpages # cd doc && ./build.sh (needs ronn or node marked-man)
|
||||
cd rustybits && cargo build # zeroidc/smeeclient (also auto via `make zeroidc`)
|
||||
cd java && ant build_java | build_android | build_jar
|
||||
cd tcp-proxy && make
|
||||
```
|
||||
|
||||
`Makefile` is a uname dispatcher → `make-linux.mk` / `make-mac.mk` / `make-bsd.mk` / `make-netbsd.mk`. Windows: `MSBuild windows/ZeroTierOne.sln /property:Configuration=Release`. Top-level `CMakeLists.txt` is a 323B stub — never `cmake .` as product build.
|
||||
|
||||
Env knobs (make vars): `ZT_DEBUG`, `ZT_TRACE`, `ZT_SANITIZE`, `ZT_STATIC`, `ZT_OFFICIAL`, `ZT_CONTROLLER`, `ZT_SSO_SUPPORTED` (0 on Linux default → no cargo needed), `ZT_VAULT_SUPPORT`, `ZT_IA32`.
|
||||
|
||||
**Build hygiene — no header dependency tracking.** The makefiles emit no `-MMD` `.d` files, so `.o` outputs never rebuild when a header changes. A tree that ships prebuilt objects (root `one.o`, `node/*.o`, `libbackonecore.a` — present in this checkout) plus any `.hpp` edit produces ABI-mismatched objects; symptom is an instant `SIGSEGV` at `Topology::Topology` during `./backone` startup with a null call target. `make clean` after touching any `.hpp`, and verify startup after every build:
|
||||
|
||||
```sh
|
||||
rm -rf /tmp/bohome && mkdir -p /tmp/bohome
|
||||
timeout 8 ./backone -p9999 -U /tmp/bohome # exit 124 (timeout) = healthy; 139 = crash
|
||||
```
|
||||
|
||||
## Code Conventions & Common Patterns
|
||||
|
||||
- **Standard: C++17** (`-std=c++17` in all makefiles; `tcp-proxy` is C++11). Ignore stale comments claiming otherwise (`node/README.md` "No C++11", `osdep/BlockingQueue.hpp:30`).
|
||||
- **Formatting**: `.clang-format` — LLVM base, **tabs always**, indent 4, Stroustrup braces, `BinPackArguments: false`, `PointerAlignment: Left`. Gate: `make lint` → `tools/lint.sh` (clang-format on lines changed vs base commit; `--all` checks whole files — whole repo has format debt, don't reformat untouched lines). No clang-tidy, no `-Werror`.
|
||||
- **Namespace**: everything in `namespace ZeroTier { … }`, close with `} // namespace ZeroTier`. File-local helpers in anonymous namespace or `static`.
|
||||
- **Naming**: classes `PascalCase`; methods `camelCase`; private members `_camelCase`; static C callbacks `S` + class (`SnodeWirePacketSendFunction`); macros/enums `ZT_UPPER_SNAKE`; include guards `ZT_<NAME>_HPP` (no `#pragma once`).
|
||||
- **Includes**: quoted relative (`"../node/Constants.hpp"` from subdirs, `"node/Constants.hpp"` from root). Third-party via angle brackets resolved by `-isystem ext`. `node/Constants.hpp` FIRST in `node/` files — canonicalizes `__LINUX__`/`__APPLE__`/`__UNIX_LIKE__`/`__WINDOWS__`; never test raw `__linux__`/`_WIN32`.
|
||||
- **Error handling**: three regimes — (1) C API boundary returns `ZT_ResultCode`, fatal = 100–999, checked via `ZT_ResultCode_isFatal`; (2) `node/` throws bare ints (`ZT_EXCEPTION_OUT_OF_BOUNDS`, `node/Constants.hpp:757+`), caught as `catch (int e)` in `OneServiceImpl::run`; (3) service/controller use `std::exception`/`catch (...)` at thread boundaries. **No exceptions across the C API.**
|
||||
- **Threading**: no global lock; per-object `ZeroTier::Mutex` scoped guard (`Mutex::Lock _l(_m);`) or `std::mutex` + `lock_guard`/`shared_lock` in controller. Cross-thread wake only via `Phy::whack()`; producer/consumer via `BlockingQueue<T>`. Threads: `std::thread`.
|
||||
- **Async**: single-threaded reactor (`Phy::poll` callbacks), not futures; no `std::async`/`future` in C++ paths (tokio only inside `rustybits/smeeclient`).
|
||||
- **Memory**: raw `new`/`delete` in service/controller; intrusive `SharedPtr<T>` (`node/SharedPtr.hpp` — class needs `friend class SharedPtr<X>` + `AtomicCounter __refCount`) for `Peer`/`Network`/`Path`; `std::shared_ptr` for `DB` backends. Zero secrets with `Utils::burn`.
|
||||
- **DI/state**: no framework. Two seams only: `ZT_Node_Callbacks` function-pointer struct (core ↔ OS) and `const RuntimeEnvironment *RR` as first param. Controller injected via `Node::setNetconfMaster`.
|
||||
- **JSON**: `nlohmann::json` + typed accessors `OSUtils::jsonString/jsonInt/jsonBool` (defaults); API is type-sensitive.
|
||||
- **Metrics**: `node/Metrics.hpp` namespace, increment inline (`Metrics::udp_recv += len;`).
|
||||
- **License header**: every new `.cpp/.hpp/.h` gets the 11-line BSL block verbatim (copy `node/Mutex.hpp:1-12`).
|
||||
- **Placement rule**: sockets/files/interfaces → `osdep/`; orchestration → `service/`; persistence → `controller/`; `node/` stays OS-independent. New compiled file must be added to `objects.mk` (`CORE_OBJS` or `ONE_OBJS`) or it won't link.
|
||||
|
||||
## Important Files
|
||||
|
||||
Read before editing:
|
||||
|
||||
1. `include/ZeroTierOne.h` — public contract (`ZT_Node_Callbacks:1733`, `ZT_ResultCode:375`); ripples to Java/SDK.
|
||||
2. `node/Constants.hpp` — platform macros, exception ints, constants; include first.
|
||||
3. `node/RuntimeEnvironment.hpp` — object graph every `node/` fn navigates.
|
||||
4. `service/OneService.cpp` lines 690–1100 (callback table) and 1150–1400 (`run()` loop) — the integration seam.
|
||||
5. `osdep/Phy.hpp` lines 55–160 — handler contract for any socket behavior.
|
||||
6. `objects.mk` + `make-linux.mk:12,62-73,370-457` — what compiles with which flags.
|
||||
7. Per-dir READMEs: `service/README.md` (local.conf schema + JSON API — primary ops doc), `controller/README.md`, `node/README.md`.
|
||||
|
||||
Module-specific: wire protocol → `node/IncomingPacket.cpp:94-151` + `node/Packet.hpp`; routing → `node/Switch.cpp`; DB backend → `controller/DB.hpp` + `EmbeddedNetworkController.cpp:465-580`; TAP → `osdep/EthernetTap.cpp`.
|
||||
|
||||
## Runtime/Tooling Preferences
|
||||
|
||||
- **Build**: GNU make (g++ or clang auto-detected, `make-linux.mk:3-10`); MSVC on Windows; ant + NDK for Java; cargo for `rustybits/`; npm for `rule-compiler/`.
|
||||
- **No package manager for C++** — deps vendored in `ext/` (do not add new ones casually).
|
||||
- **Daemon paths (Linux)**: home `/var/lib/backone` (macOS: `/Library/Application Support/BackOne`); port 9993; key files `identity.secret`, `authtoken.secret`, `networks.d/`, `local.conf`, `controller.db`. Unprivileged CLI: `cp authtoken.secret ~/.backOneOneAuthToken` (source: `one.cpp:283`).
|
||||
- **CLI**: `backone-cli info|listpeers|listnetworks|join <nwid>|leave <nwid>` (`-j` JSON, `-p<port>`, `-D<dir>`); `backone-idtool generate|validate|getpublic|sign|verify|mkcom`.
|
||||
- **Dangerous scripts**: `update_controllers.sh`, `cycle_controllers.sh` are live ZeroTier-Central kubectl ops — never run locally.
|
||||
- **Rebrand is partial**: build outputs, CI (`build.yml`, `validate-linux.sh`), `Dockerfile.ci`, `make-bsd.mk`/`make-netbsd.mk`, and debian units now use `backone*`. Still upstream-named: `pkg/snap/snapcraft.yaml` (builds `github.com/zerotier/zerotierone.git` → broken) and cosmetic strings (`/etc/zerotier-version` in `Dockerfile.ci`, `windows/zerotier-cli.bat`, `pkg/` vendor paths). Expect occasional `zerotier-*` names in docs/scripts.
|
||||
|
||||
## Testing & QA
|
||||
|
||||
No C++ unit framework. Practical loop:
|
||||
|
||||
```sh
|
||||
make selftest && ./backone-selftest # crypto KATs, identity, certs, packet codec, Phy loopback; non-zero exit on failure
|
||||
make debug # ZT_DEBUG=1 build of one + selftest
|
||||
```
|
||||
|
||||
- **Sections** in `selftest.cpp`: `testCrypto`, `testIdentity`, `testCertificate`, `testPacket`, `testOther`, `testPhy` (binds 127.0.0.1 UDP/TCP loopback; no root needed).
|
||||
- **CI** (`.github/workflows/`): `build.yml` = build smoke (`make`, `make selftest`); `validate.yml` = `make one ZT_COVERAGE=1 ZT_TRACE=1` then `.github/workflows/validate-linux.sh` (two-node netns + ping + iperf3 + valgrind) and `validate-report.sh` (fails on any definite leak or non-zero test exit — the only hard gate). `ZT_COVERAGE=1` adds `--coverage` flags (`make-linux.mk:322-326`); coverage recorded via gcovr, never thresholded.
|
||||
- **Lint/format**: `make lint` → `tools/lint.sh` (clang-format on changed lines vs base; CI: `.github/workflows/lint.yml`, clang-format pinned 23.1.1). No clang-tidy, no `-Werror`. Do not reformat untouched lines.
|
||||
- **Gaps**: no Rust tests, no Java tests (orphaned `java/test/` deleted), no `make test`/`check` target. Prefer extending `selftest.cpp` for regression coverage; `rule-compiler` has `npm test` (real, `rule-compiler/test.js`).
|
||||
- **Windows smoke** (`windows/README.md`): run exe `-p9994 -C <tmpdir>` then `zerotier-cli.bat -p9994 -D<tmpdir> info|join`.
|
||||
+6
-5
@@ -6,16 +6,17 @@ RUN apt-get update -qq && apt-get -qq install make clang
|
||||
COPY . .
|
||||
RUN /usr/bin/make
|
||||
RUN echo $PWD
|
||||
RUN cp zerotier-one /usr/sbin
|
||||
RUN cp backone /usr/sbin
|
||||
|
||||
FROM ubuntu:21.04
|
||||
|
||||
COPY --from=stage /zerotier-one /usr/sbin
|
||||
RUN ln -sf /usr/sbin/zerotier-one /usr/sbin/zerotier-idtool
|
||||
RUN ln -sf /usr/sbin/zerotier-one /usr/sbin/zerotier-cli
|
||||
COPY --from=stage /backone /usr/sbin
|
||||
RUN ln -sf /usr/sbin/backone /usr/sbin/backone-idtool
|
||||
RUN ln -sf /usr/sbin/backone /usr/sbin/backone-cli
|
||||
|
||||
RUN echo "${VERSION}" > /etc/zerotier-version
|
||||
RUN rm -rf /var/lib/zerotier-one
|
||||
RUN rm -rf /var/lib/backone
|
||||
ENV ZEROTIER_HOME=/var/lib/backone ZT_PID_FILE=backone.pid ZT_PORT_FILE=backone.port ZT_DAEMON=/usr/sbin/backone ZT_CLI=backone-cli
|
||||
|
||||
|
||||
RUN apt-get -qq update
|
||||
|
||||
@@ -27,6 +27,9 @@ ifeq ($(OSTYPE),NetBSD)
|
||||
include make-netbsd.mk
|
||||
endif
|
||||
|
||||
lint:
|
||||
@./tools/lint.sh
|
||||
|
||||
drone:
|
||||
@echo "rendering .drone.yaml from .drone.jsonnet"
|
||||
drone jsonnet --format --stream
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
# BackOne - (1.14.1)
|
||||
# BackOne - (2.0.0)
|
||||
---
|
||||
[BackOne](https://backone.cloud)
|
||||
|
||||
|
||||
@@ -1,6 +1,12 @@
|
||||
ZeroTier Release Notes
|
||||
======
|
||||
|
||||
# 2026-10-01 -- Version 2.0.0
|
||||
|
||||
* BackOne version diverges from zerotier-one from this point: version
|
||||
scheme starts at 2.0.0 to distinguish BackOne packages and binaries
|
||||
from upstream ZeroTier One 1.14.x.
|
||||
|
||||
# 2024-09-12 -- Version 1.14.1
|
||||
|
||||
* Multithreaded packet I/O support! Currently this is just for Linux and must
|
||||
|
||||
@@ -9,6 +9,7 @@ The following versions of ZeroTier One receive security updates
|
||||
|
||||
| Version | Supported |
|
||||
| -------- | ------------------ |
|
||||
| 2.0.x | :white_check_mark: |
|
||||
| 1.14.x | :white_check_mark: |
|
||||
| 1.12.x | :white_check_mark: |
|
||||
| < 1.12.0 | :x: |
|
||||
|
||||
@@ -0,0 +1,107 @@
|
||||
# SPEC — BackOne
|
||||
|
||||
## §G (goal)
|
||||
|
||||
Make BackOne quantum ready: phases 1-6 of `backone-quantum-fork-research.md` — liboqs + hybrid X25519+ML-KEM-768 / Ed25519+ML-DSA-65 handshake, identity/COM v2 double-sign, capability-bit negotiation. Phase 7 (AES-256-GCM) OUT.
|
||||
|
||||
## §C (constraints)
|
||||
|
||||
- C++17. GNU make = real build. Top `CMakeLists.txt` = stub, never product build.
|
||||
- Deps vendored in `ext/`. No new dep for few-liners.
|
||||
- Tabs always, `.clang-format` LLVM/Stroustrup, indent 4. No reformat of untouched lines.
|
||||
- New `.cpp/.hpp/.h` gets 11-line BSL header verbatim (`node/Mutex.hpp:1-12`).
|
||||
- `node/` stays OS-independent. Sockets/files → `osdep/`. Orchestration → `service/`. Persistence → `controller/`.
|
||||
- No exceptions across C API. Fatal `ZT_ResultCode` = 100–999.
|
||||
- One reactor thread (`Phy::poll`). Cross-thread wake only `Phy::whack()`.
|
||||
- New compiled file → register in `objects.mk` or no link.
|
||||
- Platforms: Linux (primary), macOS, BSD/NetBSD, Windows (msbuild).
|
||||
- Header edits: no `-MMD` dep tracking → `make clean` after touching `.h`.
|
||||
- PQC lock: liboqs static vendored `ext/`; hybrid key = KDF(classical ‖ pq); presets `hybrid` (ML-KEM-768/ML-DSA-65) + `pqconly` (intended ML-KEM-1024/ML-DSA-87 — not yet distinct, see T25)
|
||||
- wire/identity/COM use versioned v2 + capability-bit fallback to classic
|
||||
- `include/ZeroTierOne.h` changes additive-only (Java/libzt ripple)
|
||||
- OUT: AES-256-GCM swap, trusted-path skipCrypto, forward secrecy, protocol standardization, crypto audit, production release/signing
|
||||
- `?` address v2 derivation keeping 40-bit + PoW
|
||||
- `?` VL1 fragmentation capacity for +4KB identity (check `node/Packet.*`)
|
||||
- `?` liboqs version/tag + build flags for `ext/`
|
||||
- `?` measured ML-KEM/ML-DSA latency (doc estimates unverified)
|
||||
- `?` capability-bit placement in existing handshake
|
||||
|
||||
## §I (public surfaces)
|
||||
|
||||
| id | surface | detail |
|
||||
|---|---|---|
|
||||
| I.capi | C API | `include/ZeroTierOne.h`, `ZT_Node_*` (lines 1796-2258), `ZT_SDK_API`. Ripples to Java/libzt/SDK |
|
||||
| I.api | HTTP JSON API | `127.0.0.1:9993`, `/status /peer /network /member /controller /metrics /info`, auth `X-ZT1-Auth` header or `?auth=` from `authtoken.secret` |
|
||||
| I.cli | CLI | `backone-cli info\|listpeers\|listnetworks\|join\|leave` (`-j -p -D`), `backone-idtool generate\|validate\|getpublic\|sign\|verify\|mkcom` — symlink dispatch on `argv[0]` |
|
||||
| I.cfg | config | home `/var/lib/backone` (macOS `/Library/Application Support/BackOne`), `local.conf`, `identity.secret`, `networks.d/`, `controller.db`, `backone.port`, `backone.pid` |
|
||||
| I.build | build | `make`, `make one`, `make selftest`, `make core`, `make debug`, `make install`, `make debian/redhat`, `make central-controller`; env `ZT_*` knobs |
|
||||
| I.ffi | Rust FFI | `rustybits/zeroidc` (`zeroidc_new`…), `smeeclient` — C header `zeroidc.h`, link on `ZT_SSO_SUPPORTED=1`/`ZT_CONTROLLER=1` |
|
||||
| I.jni | Java SDK | `java/jni/…Node.cpp`, ant targets `build_java/build_android/build_jar` |
|
||||
| I.pqc.cfg | config | `local.conf` `settings.pqcMode` (off/hybrid/pqconly); **absent = off/classic (opt-in)**, unknown value = warn + classic. Per-algorithm `kem`/`sig` selection is *not* wired (research doc only, see T25) |
|
||||
| I.pqc.wire | wire | static-static hybrid, no ephemeral exchange: identity v2 (type byte 1) carries ML-KEM-768 pub + ML-DSA-65 pub; agree = KDF(X25519-identity-agree ‖ ML-KEM-encaps(peer static pub)) (`node/Identity.hpp:364-379` encaps / `:392+` decaps, driven from `node/Peer.cpp` `ensurePendingHybridCt`/`setHybridSessionKey`); capability via HELLO protocol-version bytes (`node/Packet.hpp:329-333`); `identity.secret`/`identity.public` v2 on disk |
|
||||
| I.pqc.com | credentials | COM double-sign/verify — controller + `node/CertificateOfMembership.*` |
|
||||
| I.rules | rules compiler | `node rule-compiler/cli.js <rules>` → rules/tags JSON |
|
||||
|
||||
## §V (invariants)
|
||||
|
||||
Derived from `selftest.cpp` + CI gates. `?` = code-derived, no test yet.
|
||||
|
||||
| id | invariant | evidence |
|
||||
|---|---|---|
|
||||
| V1 | Crypto KATs pass: Salsa20 vectors, C25519 agreement, Ed25519 sign/verify, SHA512, Poly1305 | `selftest.cpp:137` `testCrypto` |
|
||||
| V2 | Identity known-good accepted, known-bad rejected | `selftest.cpp:475` `testIdentity` |
|
||||
| V3 | CertificateOfMembership signs and `agreesWith` roundtrip | `selftest.cpp:577` `testCertificate` |
|
||||
| V4 | Packet encode/decode roundtrip exact | `selftest.cpp:641` `testPacket` |
|
||||
| V5 | Phy UDP+TCP loopback on 127.0.0.1 works, no root | `selftest.cpp:1002` `testPhy` |
|
||||
| V6 | Zero definite leaks under valgrind; test exit code 0 | `.github/workflows/validate-report.sh` |
|
||||
| V7 | `?` No exception crosses C API; `ZT_ResultCode_isFatal` only 100–999 | `include/ZeroTierOne.h:426` |
|
||||
| V8 | `?` `node/` contains no OS calls (sockets/files/interfaces) | `node/README.md` rule |
|
||||
| V9 | hybrid↔vanilla negotiates classic, link stays up | interop matrix |
|
||||
| V10 | identity v2 survives 1280B MTU tunnel intact; v2 = type byte 1 (wire `Identity.hpp:219`, string slot `Identity.cpp:173`); address derivation hashes X25519 material only → v1/v2 addresses bit-identical; v1 parser rejects type ≠ 0 cleanly | interop matrix |
|
||||
| V11 | ML-KEM/ML-DSA KATs + hybrid KDF vector + identity v2 roundtrip + COM double-sign verify pass | extended `selftest.cpp` |
|
||||
| V12 | `pqcMode` negotiation honors `local.conf` (`off` -> no v2 fields) | live daemon: bogus `settings.pqcMode` -> `WARNING` (`service/OneService.cpp:1478`), `hybrid` -> clean (2026-10-03); `selftest` has no `pqcMode` coverage |
|
||||
| V13 | hybrid agree = KDF(X25519-identity-agree ‖ ML-KEM static-static), no ephemeral exchange; hybrid↔hybrid agree + hybrid↔vanilla classic fallback pass | `node/Peer.cpp:105-117` (encaps) `node/IncomingPacket.cpp:534-542,697-703` (decaps) |
|
||||
| V14 | COM double-sign = type byte 1→2 appends ML-DSA sig alongside Ed25519; v1 verify path unchanged; v1 rejects type 2 cleanly | `node/CertificateOfMembership.hpp:222-296`, `node/CertificateOfMembership.cpp:97-162`, `selftest.cpp:717` |
|
||||
| V15 | handshake vs fragment loss measured: PQC identity in clear HELLO = 3273B → 3 frags (classic 137B → 1 frag, max 7 `Packet.hpp:235`); Monte Carlo 20k trials obs≈analytic at p∈{.01,.05,.10,.30}; fragment loss delays HELLO (retransmit), does not break handshake | `selftest.cpp:1713` benchmark |
|
||||
| V16 | hybrid handshake puts a 1088 B ML-KEM-768 ct on the wire and both sides derive the same hybrid `_key`; classic/off peers carry none and fall back | write `node/Peer.cpp:493-502`, parse `node/IncomingPacket.cpp:534-542`, OK echo `node/IncomingPacket.cpp:608-619,697-703`; E2E lab M1-M5 all pass `tools/pqc-lab.sh` (2026-10-02; M3 68 / M4 90 large PQ datagrams on wire) |
|
||||
|
||||
## §T (tasks)
|
||||
|
||||
| id | status | task | cites |
|
||||
|---|---|---|---|
|
||||
| T1 | x | Fix CI build smoke: `build.yml` runs `./zerotier-selftest`, build emits `backone-selftest` (also `tar zerotier-one` → `backone`) | I.build,V6 |
|
||||
| T2 | x | Fix `validate-linux.sh` binary names: invokes `./zerotier-one`, `./zerotier-cli` (lines 41-43,105,111,451), builds `backone*` | I.cli,V6 |
|
||||
| T3 | x | Wire `ZT_COVERAGE` into makefiles — consumed by none, gcovr likely reports zeros `?` | I.build |
|
||||
| T4 | x | `make install` manpage rule: expects `doc/backone.8`, `doc/backone-cli.1`, `doc/backone-idtool.1`; `doc/` only has `zerotier-*`, no rename rule | I.build |
|
||||
| T5 | x | `make redhat`: `backone.spec` %install copies missing `debian/backone.service` + `ext/installfiles/linux/backone.init.rhel6` (actual files `zerotier-*`) | I.build |
|
||||
| T6 | x | Rebrand `make-bsd.mk`/`make-netbsd.mk`: still emit/install `zerotier-one`, `/var/db/zerotier-one` vs code writing `backone.pid` | I.build |
|
||||
| T7 | x | `Dockerfile.ci`: copies `zerotier-one` from build → fails; binary is `backone` | I.build |
|
||||
| T8 | . | `pkg/snap/snapcraft.yaml`: builds upstream `github.com/zerotier/zerotierone.git`, expects `usr/sbin/zerotier-one` | I.build |
|
||||
| T9 | . | Wire orphaned `java/test/StringUtilsTest.java` (JUnit4) into `java/build.xml` target or delete | I.jni |
|
||||
| T10 | . | Replace `rule-compiler/package.json` `npm test` failing placeholder with real test of `rule-compiler.js` | I.rules |
|
||||
| T11 | . | `?` Add `#[test]` coverage for `rustybits/zeroidc` FFI parse/exchange paths | I.ffi,V7 |
|
||||
| T12 | x | Implement Redis config TODO (`service/OneService.cpp:1467` `// TODO: Redis config`) | I.cfg |
|
||||
| T13 | . | Implement `LFDB::eraseNetwork`/`eraseMember` TODOs (`controller/LFDB.cpp:383,388`) | I.cfg |
|
||||
| T14 | . | ~~Lint gate~~ done: `make lint` (`tools/lint.sh`, changed-lines clang-format) + `.github/workflows/lint.yml` | I.build |
|
||||
| T15 | . | Fix `-Wsign-compare` suppression FIXME (`node/Bond.cpp:23`, `node/Node.cpp:40`) | I.build |
|
||||
| T16 | x | Federation identity-collision payload FIXME (`node/IncomingPacket.cpp:211`) `?` scope | I.capi,V7 |
|
||||
| T17 | x | Phase 1: vendor liboqs static into `ext/`, wire `make-linux.mk` + `objects.mk`, pin version/tag + flags | I.build |
|
||||
| T18 | x | Phase 2: `node/PQHybrid.*` hybrid agree = KDF(X25519-identity-agree ‖ ML-KEM-768 encaps over peer static pub); phase-2 ephemeral-field mockup dropped | I.pqc.wire,V13 |
|
||||
| T19 | x | Phase 3: identity v2 type byte 1, append ML-KEM+ML-DSA pubs, address hash X25519-only, v1 clean reject type ≠ 0 | I.pqc.wire,V10 |
|
||||
| T20 | x | Phase 4: COM type byte 2 double-sign (Ed25519+ML-DSA-65), v1 rejects cleanly | I.pqc.com,V14 |
|
||||
| T21 | . | Phase 5: `local.conf` `settings.pqcMode` parse (off/hybrid/pqconly) + capability negotiation via HELLO protocol-version bytes, fallback classic. Mode now selects *whether* PQ material is used; *which* preset is still hardcoded (T24) | I.pqc.cfg,V12,V9 |
|
||||
| T22 | x | Phase 6: selftest extension — ML-KEM/ML-DSA KATs, hybrid KDF vector, identity v2 roundtrip + address stability, COM double-sign, interop hybrid↔vanilla matrix | I.build,V11,V10,V14 |
|
||||
| T23 | x | Phase 6: handshake-vs-fragment-loss benchmark for PQC HELLO; cap/segment if loss breaks handshake | V15 |
|
||||
| T24 | x | Plumb `settings.pqcMode` through the identity path: `Node(…,int pqcMode)` stores `_pqcMode`; `Identity::generate(bool pq,int pqcMode)` derives `pq` from the daemon mode; `OneService` reads `local.conf` before `new Node` — a fresh hybrid/pqconly node writes a type-1 identity, a classic one type-0. Fixes the G1 defect. | I.pqc.cfg,V12 |
|
||||
| T25 | . | Distinct PQ parameter sets: `node/PQHybrid.*` hardcodes ML-KEM-768/ML-DSA-65 (`PQHybrid.cpp` static_asserts `OQS_KEM_ml_kem_768`/`OQS_SIG_ml_dsa_65`), so `hybrid` and `pqconly` currently select identical material, while `SPEC` §C claims ML-KEM-1024/ML-DSA-87 for `pqconly`. Parameterize the preset (key sizes, ct len, `_pendingHybridCt` buffer, HELLO guard) or drop the `pqconly` claim. Note a `pqconly` HELLO with a PQ identity is 3273B → 3 frags, well under the 10024B cap, so no clean-fail path is reachable today | I.pqc.wire,I.pqc.cfg,V15 |
|
||||
|
||||
T1/T2 = prerequisites — CI must invoke `backone-selftest` before PQC gates mean anything. T1–T16 backlog (rebrand/CI/lint leftovers); T17–T25 = PQC phases 1–6 + the pqconly preset gap.
|
||||
|
||||
Not tracked (low value `?`): `one.cpp:256` port/token cleanup, `MacKextEthernetTap.cpp:480` iface status, VLAN TODOs in `NetBSDEthernetTap.cpp:468`/`MacKextEthernetTap.cpp:685`, `Phy.hpp:325` unix sock type comment.
|
||||
|
||||
## §B (bug log)
|
||||
|
||||
| id | date | cause | fix |
|
||||
|---|---|---|---|
|
||||
| B1 | 2026-10-02 | Phase 5 (T21) advertised PQC capability in HELLO but never consumed it: `Peer::_key` was derived classically in the constructor and the hybrid ciphertext had no place in the HELLO/OK(HELLO) layout, so `hybridEligible()` was dead. | Wire hybrid static-static KEM ct into HELLO (lowest-address side writes `[moon count][moons][flag(1B)][ct 1088B]`, crypted with the classical key) and echo it in OK(HELLO); parser order matches `Peer::sendHELLO`/`_doHELLO`; `Peer::ensurePendingHybridCt()` lazily encapsulates on first capability sighting so the handshake completes in one round trip; direction guard `sender == lowest address` on both parses. Refuse to start when the on-disk identity cannot satisfy `settings.pqcMode` (classic↔PQ migration changes the address). |
|
||||
| B2 | 2026-10-02 | `settings.pqcMode` absent (or unrecognized) resolved to HYBRID, and `Node`'s `pqcMode` default was HYBRID with no way to tell "unconfigured" from "configured hybrid". Every existing type-0 install would hit the B1 refusal guard at startup; the C API `ZT_Node_new` path would silently generate type-1 identities. | Absent/unknown `settings.pqcMode` now resolves to `ZT_PQC_MODE_CLASSIC` (PQC is opt-in, matching the research doc); `Node(…,int pqcMode = ZT_PQC_MODE_CLASSIC)`. Verified: classic identity + no config boots on 2.0.0 and stays 141 B; fresh node w/o config makes type-0; fresh node with `"hybrid"` makes type-1 (6415 B); classic + explicit `"off"` boots; classic + explicit `"hybrid"` still refuses; unknown value warns and runs classic. |
|
||||
+29
-23
@@ -82,35 +82,41 @@ int main(int argc,char **argv)
|
||||
|
||||
const uint64_t id = ZT_WORLD_ID_EARTH;
|
||||
const uint64_t ts = 1567191349589ULL; // August 30th, 2019
|
||||
//const uint64_t ts = 1778645159589ULL; // May 13th, 2026
|
||||
|
||||
// Los Angeles
|
||||
// MVNET server1.saltis.id
|
||||
roots.push_back(World::Root());
|
||||
roots.back().identity = Identity("3a46f1bf30:0:76e66fab33e28549a62ee2064d1843273c2c300ba45c3f20bef02dbad225723bb59a9bb4b13535730961aeecf5a163ace477cceb0727025b99ac14a5166a09a3");
|
||||
roots.back().stableEndpoints.push_back(InetAddress("185.180.13.82/9993"));
|
||||
roots.back().stableEndpoints.push_back(InetAddress("2a02:6ea0:c815::/9993"));
|
||||
roots.back().identity = Identity("41cff2b17b:0:1f62d405a755ed8522e903edee7e2166fa357658a6cac8e6739b9e463898107538f09419e5cf5c2d139468c04ad1e0a08b59680ee2f07b2e50e670f81fd1dc3d");
|
||||
roots.back().stableEndpoints.push_back(InetAddress("103.80.237.27/9993"));
|
||||
|
||||
// Miami
|
||||
// MVNET server2.saltis.id
|
||||
roots.push_back(World::Root());
|
||||
roots.back().identity = Identity("de8950a8b2:0:1b3ada8251b91b6b6fa6535b8c7e2460918f4f729abdec97d3c7f3796868fb02f0de0b0ee554b2d59fc3524743eebfcf5315e790ed6d92db5bd10c28c09b40ef");
|
||||
roots.back().stableEndpoints.push_back(InetAddress("207.246.73.245/443"));
|
||||
roots.back().stableEndpoints.push_back(InetAddress("2001:19f0:9002:5cb:ec4:7aff:fe8f:69d9/443"));
|
||||
roots.back().identity = Identity("e4bfc89a12:0:93f764c53030b11c4b9f824cdade6fb731d26b5150f326ca484dbb3acb33a065d5431524fe7ce517512b13c21c4ab5edb04a2e145cefa33ffdf39a855b966c21");
|
||||
roots.back().stableEndpoints.push_back(InetAddress("103.80.237.163/9993"));
|
||||
|
||||
// Tokyo
|
||||
roots.push_back(World::Root());
|
||||
roots.back().identity = Identity("34e0a5e174:0:93efb50934788f856d5cfb9ca5be88e85b40965586b75befac900df77352c145a1ba7007569d37c77bfe52c0999f3bdc67a47a4a6000b720a883ce47aa2fb7f8");
|
||||
roots.back().stableEndpoints.push_back(InetAddress("147.75.92.2/443"));
|
||||
roots.back().stableEndpoints.push_back(InetAddress("2604:1380:3000:7100::1/443"));
|
||||
|
||||
// Amsterdam
|
||||
roots.push_back(World::Root());
|
||||
roots.back().identity = Identity("992fcf1db7:0:206ed59350b31916f749a1f85dffb3a8787dcbf83b8c6e9448d4e3ea0e3369301be716c3609344a9d1533850fb4460c50af43322bcfc8e13d3301a1f1003ceb6");
|
||||
roots.back().stableEndpoints.push_back(InetAddress("195.181.173.159/443"));
|
||||
roots.back().stableEndpoints.push_back(InetAddress("2a02:6ea0:c024::/443"));
|
||||
|
||||
// Alice
|
||||
// IDC server1a.saltis.id
|
||||
//roots.push_back(World::Root());
|
||||
//roots.back().identity = Identity("9d219039f3:0:01f0922a98e3b34ebcbff333269dc265d7a020aab69d72be4d4acc9c8c9294785771256cd1d942a90d1bd1d2dca3ea84ef7d85afe6611fb43ff0b74126d90a6e");
|
||||
//roots.back().stableEndpoints.push_back(InetAddress("188.166.94.177/9993")); // Amsterdam
|
||||
//roots.back().identity = Identity("e620faa6a2:0:f450e2de69d0a70fa3183af50e881a96daac6a736fbb6004492cf97da774de0e003b060ec19e4c9b4288a60a99b4a60464b475ec2d1efb1b0c4a9b924b8f4bf1");
|
||||
//roots.back().stableEndpoints.push_back(InetAddress("103.185.47.53/9993"));
|
||||
|
||||
// IDC server2a.saltis.id
|
||||
roots.push_back(World::Root());
|
||||
roots.back().identity = Identity("35b7a18f36:0:e7d0dc4f655c0a2adb72aa9529e97d0fdf1e72bf12a6e753c6b366d88b388b645702edbd8dfeda21c3654f2d73c28fecc7c4713b335ffa61b09e322a7b93c18a");
|
||||
roots.back().stableEndpoints.push_back(InetAddress("103.185.47.52/9993"));
|
||||
|
||||
// GW-Bridge Metro Link
|
||||
//roots.push_back(World::Root());
|
||||
//roots.back().identity = Identity("117cd947d5:0:8b15bfe3798aa1529abf6def4d4d8eb3ff5cbd50c04ddaf7747adc00a55aef5b6666953ee30a2b6c3c852db7426c42760b7d26c63acdc6489fd11bb36690d966");
|
||||
//roots.back().stableEndpoints.push_back(InetAddress("103.87.149.147/9993")); // Amsterdam
|
||||
//roots.back().stableEndpoints.push_back(InetAddress("203.30.255.130/9993")); // Amsterdam
|
||||
//roots.back().stableEndpoints.push_back(InetAddress("192.168.80.5/9993")); // Amsterdam
|
||||
|
||||
// GW-Bridge Metro Link
|
||||
roots.push_back(World::Root());
|
||||
roots.back().identity = Identity("82ff7e0148:0:01a99aac0d7084a59c03831517cdcd9ced2af58bc61de92ab45e0ea2ea86e2692935c84e9923dafce9675f3cc5dd46846d52b5f31e0e6726cb94884b9b6c5518");
|
||||
roots.back().stableEndpoints.push_back(InetAddress("103.87.149.150/9993")); // Amsterdam
|
||||
roots.back().stableEndpoints.push_back(InetAddress("192.168.80.5/9993")); // Amsterdam
|
||||
|
||||
//roots.back().stableEndpoints.push_back(InetAddress("2a03:b0c0:2:d0::7d:1/9993")); // Amsterdam
|
||||
//roots.back().stableEndpoints.push_back(InetAddress("154.66.197.33/9993")); // Johannesburg
|
||||
//roots.back().stableEndpoints.push_back(InetAddress("2c0f:f850:154:197::33/9993")); // Johannesburg
|
||||
|
||||
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
@@ -0,0 +1,199 @@
|
||||
# Deep Research: Fork ZeroTier 1.14.1 dengan Enkripsi Quantum-Resistant
|
||||
|
||||
**Tanggal:** 29 September 2026
|
||||
**Target:** Fork ZeroTier One 1.14.1 (C++), tambahkan Post-Quantum Cryptography (PQC)
|
||||
|
||||
---
|
||||
|
||||
## 1. Ringkasan Eksekutif
|
||||
|
||||
ZeroTier 1.14.1 memakai kriptografi klasik: **Curve25519/Ed25519** (key agreement + signature), **Salsa20** (stream cipher), **Poly1305** (MAC). Semua ini **rusak oleh komputer kuantum** (Shor's algorithm untuk ECC, Grover untuk symmetric — Salsa20 256-bit masih aman dari Grover, tapi kunci yang bocor dari ECDH membuatnya ikut rusak).
|
||||
|
||||
Catatan penting: **ZeroTier, Inc. sudah merilis "ZeroTier Quantum"** (Maret 2026) — produk komersial terpisah berbasis **Rust**, dengan skema **ML-KEM-1024 (FIPS 203) + ML-DSA-87 (FIPS 204) + P-384 hybrid + AES-256-GCM**, sesuai **NSA CNSA 2.0**. Produk itu **bukan fork dari kode 1.14.1** dan tidak open-source di repo yang sama. Jadi fork 1.14.1 dengan PQC tetap pekerjaan yang valid — kita pakai prinsip desain yang sama (hybrid PQC) tapi di atas kode C++ yang ada.
|
||||
|
||||
**Rekomendasi inti: Hybrid PQC** — jalankan ML-KEM (Kyber) **paralel** dengan X25519, dan ML-DSA (Dilithium) **paralel** dengan Ed25519, lalu gabungkan output-nya. Keamanan tetap terjaga jika salah satu keluarga algoritma ternyata lemah.
|
||||
|
||||
---
|
||||
|
||||
## 2. Arsitektur Kriptografi ZeroTier 1.14.1 (Baseline)
|
||||
|
||||
Sumber: docs.zerotier.com/protocol, repo github.com/zerotier/ZeroTierOne
|
||||
|
||||
### 2.1 Titik-Titik Kriptografi di Kode
|
||||
|
||||
| Komponen | File | Fungsi |
|
||||
|---|---|---|
|
||||
| Identity (X25519/Ed25519 keypair) | `node/Identity.hpp/.cpp` | 40-bit ZT address diturunkan dari public key; PoW anti-collision |
|
||||
| ECDH key agreement | `node/C25519.*` | Ephemeral key exchange antar peer |
|
||||
| Signature (Ed25519) | `node/Salsa20.cpp` area / Ed25519 impl | Signing credential, certificate of membership |
|
||||
| Packet encryption | `node/Salsa20.*`, NaCl-style box | Salsa20 encrypt-then-MAC Poly1305 |
|
||||
| MAC | `node/Poly1305.*` | Autentikasi pesan |
|
||||
| Credential signing | `node/CertificateOfMembership.*`, controller | Controller sign membership pakai secret key |
|
||||
|
||||
### 2.2 Alur Koneksi Peer (yang perlu dimodifikasi)
|
||||
|
||||
1. Node A kirim **HELLO** berisi identity public key (X25519 + Ed25519) — 40-bit address diturunkan dari hash public key.
|
||||
2. Handshake **ECDH** menghasilkan shared secret → derive key Salsa20+Poly1305.
|
||||
3. Semua payload VL1 di-encrypt end-to-end dengan kunci tsb.
|
||||
4. Credential (certificate of membership, dll) ditandatangani Ed25519.
|
||||
|
||||
### 2.3 Batasan Penting
|
||||
|
||||
- **Tidak ada forward secrecy** (by design — lihat issue #204 GitHub).
|
||||
- Salsa20/Poly1305 komposisi = NaCl reference (`crypto_box`).
|
||||
- Trusted paths bisa skip enkripsi (jangan disentuh).
|
||||
|
||||
---
|
||||
|
||||
## 3. Standar Post-Quantum (NIST + NSA CNSA 2.0)
|
||||
|
||||
### 3.1 FIPS Final (Agustus 2024)
|
||||
|
||||
| Standar | Nama lama | Fungsi | Parameter relevan |
|
||||
|---|---|---|---|
|
||||
| **FIPS 203 — ML-KEM** | CRYSTALS-Kyber | Key Encapsulation (ganti ECDH) | ML-KEM-512/768/1024 |
|
||||
| **FIPS 204 — ML-DSA** | CRYSTALS-Dilithium | Digital signature (ganti Ed25519) | ML-DSA-44/65/87 |
|
||||
| **FIPS 205 — SLH-DSA** | SPHINCS+ | Signature hash-based (backup) | SLH-DSA-128s/192s/256s |
|
||||
|
||||
### 3.2 CNSA 2.0 (NSA) — target yang dipakai ZeroTier Quantum
|
||||
|
||||
- **Key exchange:** ML-KEM-1024
|
||||
- **Signature:** ML-DSA-87
|
||||
- **Symmetric:** AES-256-GCM, HMAC-SHA-512
|
||||
- **Classical hybrid:** P-384 (opsional tapi disarankan)
|
||||
- Timeline: transisi wajib sampai **2033**; untuk data "harvest now, decrypt later" **mulai sekarang**.
|
||||
|
||||
### 3.3 Ukuran Parameter (penting untuk protocol overhead)
|
||||
|
||||
| Algoritma | Public key | Ciphertext/Signature |
|
||||
|---|---|---|
|
||||
| ML-KEM-768 | 1184 B | 1088 B |
|
||||
| ML-KEM-1024 | 1568 B | 1568 B |
|
||||
| ML-DSA-65 | 1952 B | 3293 B |
|
||||
| ML-DSA-87 | 2592 B | 4627 B |
|
||||
| X25519 (baseline) | 32 B | 32 B |
|
||||
| Ed25519 (baseline) | 32 B | 64 B |
|
||||
|
||||
**Implikasi:** HELLO/identity packet harus diperbesar ~2-4 KB. Perlu cek MTU/fragmentasi packet VL1. Hybrid mode = gabung klasik+PQC (mis. XOR/KDF kedua shared secret).
|
||||
|
||||
---
|
||||
|
||||
## 4. Strategi Integrasi (untuk fork 1.14.1 C++)
|
||||
|
||||
### 4.1 Library PQC
|
||||
|
||||
**Pilihan utama: [liboqs](https://github.com/open-quantum-safe/liboqs)** (Open Quantum Safe project)
|
||||
- Implementasi C, portable, sudah di-review luas
|
||||
- Sediakan `oqs_kem_encaps/decaps` (ML-KEM) dan `oqs_sig_sign/verify` (ML-DSA)
|
||||
- License: Apache-2.0 (kompatibel fork)
|
||||
- Alternatif: `pqcrypto` (Rust, perlu FFI), implementasi reference NIST (C, FIPS-exact tapi lebih mentah)
|
||||
|
||||
Build: tambah liboqs sebagai git submodule / static lib di `make-linux.sh` / CMake.
|
||||
|
||||
### 4.2 Patch Per Titik Integrasi
|
||||
|
||||
#### A. Handshake Key Agreement (Wajib)
|
||||
|
||||
```
|
||||
Handshake Lama: shared = X25519(my_eph_priv, their_eph_pub)
|
||||
Handshake Baru: shared = KDF( X25519(...) ‖ ML-KEM-768/1024_encaps(...) )
|
||||
```
|
||||
|
||||
- Tambah field baru di packet HELLO/KEY: `kem_public_key` (1184–1568 B) + `kem_ciphertext`.
|
||||
- **Hybrid:** derive final key dari **kedua** shared secret via BLAKE2b/KDF — aman jika salah satu pecah.
|
||||
- Mockup kode:
|
||||
|
||||
```cpp
|
||||
// node/PQHybrid.hpp
|
||||
#include <oqs/oqs.h>
|
||||
|
||||
struct HybridShared {
|
||||
uint8_t classical[32]; // X25519
|
||||
uint8_t pq[KEM_LEN]; // ML-KEM shared secret
|
||||
};
|
||||
|
||||
void hybrid_kem(const uint8_t* peer_kem_pk,
|
||||
const uint8_t* my_eph_sk, const uint8_t* peer_eph_pk,
|
||||
HybridShared& out, uint8_t* kem_ct) {
|
||||
// classical
|
||||
crypto_scalarmult(out.classical, my_eph_sk, peer_eph_pk);
|
||||
// pq
|
||||
OQS_KEM* kem = OQS_KEM_new("ML-KEM-768");
|
||||
kem->encaps(out.pq, kem_ct, peer_kem_pk);
|
||||
OQS_KEM_free(kem);
|
||||
}
|
||||
// final key = KDF(classical ‖ pq) -> masuk ke Salsa20/ChaCha20 key schedule
|
||||
```
|
||||
|
||||
#### B. Identity & Signature (Wajib)
|
||||
|
||||
- Identity saat ini: X25519 + Ed25519, address 40-bit diturunkan dari hash public key.
|
||||
- **Tambah ML-DSA-87 keypair** ke identity (field baru di `Identity` serialize).
|
||||
- **Tantangan:** ukuran identity membengkak (2592 B pk + 4627 B sig per sign). Serialisasi `identity.public` di file dan di wire harus diperbesar — pakai **versioned format** (byte versi baru = identity v2, fallback ke v1 untuk backward compat).
|
||||
- Signing credential controller: verify **kedua** signature (Ed25519 DAN ML-DSA) selama transisi (double-sign).
|
||||
|
||||
#### C. Packet Encryption (Opsional, rendah risiko)
|
||||
|
||||
- Salsa20 256-bit: Grover butuh ~2^128 — **masih aman** selama key-nya tidak bocor.
|
||||
- Setelah A & B selesai, enkripsi data tidak wajib diganti. Tapi jika mau ikut CNSA 2.0: ganti ke **AES-256-GCM** (liboqs/OpenSSL sudah ada) — buang Poly1305. Ini pekerjaan terpisah, lakukan terakhir.
|
||||
|
||||
### 4.3 Versioning & Kompatibilitas
|
||||
|
||||
- Tambah **capability bit** di handshake: bit "PQC_SUPPORTED".
|
||||
- Peer lawas (v1.14.1 vanilla) → fallback mode klasik saja.
|
||||
- Peer baru → mode hybrid / pure-PQC, bisa dikonfigurasi via local.conf:
|
||||
|
||||
```json
|
||||
{
|
||||
"settings": {
|
||||
"pqcMode": "hybrid", // "off" | "hybrid" | "pqconly"
|
||||
"kem": "ML-KEM-768",
|
||||
"sig": "ML-DSA-65"
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
*(Preset: `hybrid` = disarankan; `pqconly` = CNSA 2.0 strict dengan ML-KEM-1024/ML-DSA-87)*
|
||||
|
||||
---
|
||||
|
||||
## 5. Roadmap Implementasi
|
||||
|
||||
| Fase | Item | Estimasi |
|
||||
|---|---|---|
|
||||
| 1 | Fork repo, tag `v1.14.1-pqc`, integrate liboqs, build pipeline | 1-2 hari |
|
||||
| 2 | Patch handshake: hybrid X25519+ML-KEM, wire format v2 | 3-5 hari |
|
||||
| 3 | Patch identity/signature: ML-DSA-87 double-sign, versioned serialize | 3-5 hari |
|
||||
| 4 | Credential (COM) controller double-sign + verify | 2-3 hari |
|
||||
| 5 | Config flag + negotiation + backward compat test | 2 hari |
|
||||
| 6 | Test matrix: 2 node hybrid↔hybrid, hybrid↔vanilla, soak test throughput | 3-5 hari |
|
||||
| 7 | (Opsional) AES-256-GCM ganti Salsa20 untuk CNSA penuh | 3-5 hari |
|
||||
|
||||
**Total realistis: 3-4 minggu** untuk 1 developer familiar dengan codebase.
|
||||
|
||||
### Risiko
|
||||
|
||||
1. **Ukuran packet** — identity/HELLO +~4 KB; cek fragmentasi MTU 1280/1500 dan L2 frame VL2.
|
||||
2. **CPU overhead** — ML-KEM keygen ~2-3 ms (sekali per handshake, bukan per-packet); ML-DSA sign ~5-10 ms. Dampak kecil karena handshake jarang. Verifikasi dengan benchmark.
|
||||
3. **Identity collision/derivation** — address 40-bit diturunkan dari public key; format baru harus tetap menjaga PoW.
|
||||
4. **Audit kripto** — jangan deploy produksi tanpa review. liboqs = implementasi standard, tapi *pemakaian* (KDF hybrid, wire format) harus di-audit.
|
||||
5. **Lisensi** — ZeroTier One: BSL 1.1 (Business Source License, Open Source Edition). Fork untuk pemakaian internal/non-komersial OK; cek klausa sebelum distribusi komersial.
|
||||
|
||||
---
|
||||
|
||||
## 6. Referensi
|
||||
|
||||
1. ZeroTier Protocol Docs — https://docs.zerotier.com/protocol/
|
||||
2. ZeroTier Quantum (produk resmi) — https://www.zerotier.com/quantum/
|
||||
3. Research Notes on 2.x Cryptography — https://www.zerotier.com/news/research-notes-on-2-x-cryptography/
|
||||
4. ZeroTierOne source — https://github.com/zerotier/ZeroTierOne
|
||||
5. NIST FIPS 203/204/205 (ML-KEM, ML-DSA, SLH-DSA) — Aug 2024
|
||||
6. NSA CNSA 2.0 FAQ — https://media.defense.gov/2022/Sep/07/2003071834/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS_.PDF
|
||||
7. liboqs (Open Quantum Safe) — https://github.com/open-quantum-safe/liboqs
|
||||
8. ZeroTier blog: "Defusing the Q-Bomb" — ML-KEM untuk key establishment, ML-DSA untuk signature
|
||||
9. ZeroTier blog: "NIST FIPS 203 Explained for Defense and Government Network Architects"
|
||||
10. IETF hybrid KEM design — draft-ietf-tls-hybrid-design; NIST IR 8547 (migration guidance)
|
||||
|
||||
---
|
||||
|
||||
*Disusun oleh Luci (OpenClaw) — 29 Sep 2026*
|
||||
Binary file not shown.
+4
-1
@@ -1,5 +1,5 @@
|
||||
Name: backone
|
||||
Version: 1.14.1
|
||||
Version: 2.0.0
|
||||
Release: 1%{?dist}
|
||||
Summary: BackOne global ethernet switch
|
||||
|
||||
@@ -155,6 +155,9 @@ chmod 0755 $RPM_BUILD_ROOT/etc/init.d/backone
|
||||
%endif
|
||||
|
||||
%changelog
|
||||
* Thu Oct 1 2026 Dedy Sutanto <dsutanto@backone.cloud> - 2.0.0
|
||||
- see https://github.com/proitlab/BackOne for release notes
|
||||
|
||||
* Tue Oct 8 2024 Dedy Sutanto <dsutanto@backone.cloud> - 1.14.1
|
||||
- see https://github.com/proitlab/BackOne for release notes
|
||||
|
||||
|
||||
@@ -1454,7 +1454,7 @@ void EmbeddedNetworkController::_request(
|
||||
}
|
||||
} else {
|
||||
// If we do not yet know this member's identity, learn it.
|
||||
char idtmp[1024];
|
||||
char idtmp[ZT_IDENTITY_STRING_BUFFER_LENGTH];
|
||||
member["identity"] = identity.toString(false,idtmp);
|
||||
}
|
||||
#ifdef CENTRAL_CONTROLLER_REQUEST_BENCHMARK
|
||||
|
||||
+13
-2
@@ -380,12 +380,23 @@ bool LFDB::save(nlohmann::json &record,bool notifyListeners)
|
||||
|
||||
void LFDB::eraseNetwork(const uint64_t networkId)
|
||||
{
|
||||
// TODO
|
||||
nlohmann::json network, nullJson;
|
||||
get(networkId, network);
|
||||
_networkChanged(network, nullJson, true);
|
||||
std::lock_guard<std::mutex> l(_state_l);
|
||||
_state.erase(networkId);
|
||||
}
|
||||
|
||||
void LFDB::eraseMember(const uint64_t networkId,const uint64_t memberId)
|
||||
{
|
||||
// TODO
|
||||
nlohmann::json network, member, nullJson;
|
||||
get(networkId, network, memberId, member);
|
||||
_memberChanged(member, nullJson, true);
|
||||
std::lock_guard<std::mutex> l(_state_l);
|
||||
auto nw = _state.find(networkId);
|
||||
if (nw != _state.end()) {
|
||||
nw->second.members.erase(memberId);
|
||||
}
|
||||
}
|
||||
|
||||
void LFDB::nodeIsOnline(const uint64_t networkId,const uint64_t memberId,const InetAddress &physicalAddress)
|
||||
|
||||
@@ -199,9 +199,14 @@ PostgreSQL::PostgreSQL(const Identity &myId, const char *path, int listenPort, R
|
||||
}
|
||||
const char *redisMemberStatus = getenv("ZT_REDIS_MEMBER_STATUS");
|
||||
if (redisMemberStatus && (strcmp(redisMemberStatus, "true") == 0)) {
|
||||
if (_rc != NULL) {
|
||||
_redisMemberStatus = true;
|
||||
fprintf(stderr, "Using redis for member status\n");
|
||||
}
|
||||
else {
|
||||
fprintf(stderr, "ZT_REDIS_MEMBER_STATUS=true ignored: no settings.redis config\n");
|
||||
}
|
||||
}
|
||||
|
||||
auto c = _pool->borrow();
|
||||
pqxx::work txn{*c->c};
|
||||
@@ -222,7 +227,7 @@ PostgreSQL::PostgreSQL(const Identity &myId, const char *path, int listenPort, R
|
||||
opts.host = _rc->hostname;
|
||||
opts.port = _rc->port;
|
||||
opts.password = _rc->password;
|
||||
opts.db = 0;
|
||||
opts.db = _rc->clusterMode ? 0 : _rc->db;
|
||||
opts.keep_alive = true;
|
||||
opts.connect_timeout = std::chrono::seconds(3);
|
||||
poolOpts.size = 25;
|
||||
@@ -1063,7 +1068,7 @@ void PostgreSQL::initializeMembers()
|
||||
|
||||
void PostgreSQL::heartbeat()
|
||||
{
|
||||
char publicId[1024];
|
||||
char publicId[ZT_IDENTITY_STRING_BUFFER_LENGTH];
|
||||
char hostnameTmp[1024];
|
||||
_myId.toString(false,publicId);
|
||||
if (gethostname(hostnameTmp, sizeof(hostnameTmp))!= 0) {
|
||||
|
||||
@@ -9,6 +9,7 @@ struct RedisConfig {
|
||||
int port;
|
||||
std::string password;
|
||||
bool clusterMode;
|
||||
int db;
|
||||
};
|
||||
}
|
||||
|
||||
|
||||
+10
-10
@@ -1,19 +1,19 @@
|
||||
#!/bin/sh
|
||||
|
||||
### BEGIN INIT INFO
|
||||
# Provides: zerotier-one
|
||||
# Provides: backone
|
||||
# Required-Start: $remote_fs $syslog
|
||||
# Required-Stop: $remote_fs $syslog
|
||||
# Default-Start: 2 3 4 5
|
||||
# Default-Stop:
|
||||
# Short-Description: ZeroTier One network virtualization service
|
||||
# Short-Description: BackOne network virtualization service
|
||||
### END INIT INFO
|
||||
|
||||
PATH=/bin:/usr/bin:/sbin:/usr/sbin
|
||||
DESC="zerotier-one daemon"
|
||||
NAME=zerotier-one
|
||||
DAEMON=/usr/sbin/zerotier-one
|
||||
PIDFILE=/var/lib/zerotier-one/zerotier-one.pid
|
||||
DESC="backone daemon"
|
||||
NAME=backone
|
||||
DAEMON=/usr/sbin/backone
|
||||
PIDFILE=/var/lib/backone/backone.pid
|
||||
SCRIPTNAME=/etc/init.d/"$NAME"
|
||||
EXTRA_OPTS=-d
|
||||
|
||||
@@ -22,21 +22,21 @@ test -f $DAEMON || exit 0
|
||||
. /lib/lsb/init-functions
|
||||
|
||||
case "$1" in
|
||||
start) log_daemon_msg "Starting ZeroTier One" "zerotier-one"
|
||||
start) log_daemon_msg "Starting BackOne" "backone"
|
||||
start_daemon -p $PIDFILE $DAEMON $EXTRA_OPTS
|
||||
log_end_msg $?
|
||||
;;
|
||||
stop) log_daemon_msg "Stopping ZeroTier One" "zerotier-one"
|
||||
stop) log_daemon_msg "Stopping BackOne" "backone"
|
||||
killproc -p $PIDFILE $DAEMON
|
||||
RETVAL=$?
|
||||
[ $RETVAL -eq 0 ] && [ -e "$PIDFILE" ] && rm -f $PIDFILE
|
||||
log_end_msg $RETVAL
|
||||
;;
|
||||
restart) log_daemon_msg "Restarting ZeroTier One" "zerotier-one"
|
||||
restart) log_daemon_msg "Restarting BackOne" "backone"
|
||||
$0 stop
|
||||
$0 start
|
||||
;;
|
||||
reload|force-reload) log_daemon_msg "Reloading ZeroTier One" "zerotier-one"
|
||||
reload|force-reload) log_daemon_msg "Reloading BackOne" "backone"
|
||||
log_end_msg 0
|
||||
;;
|
||||
status)
|
||||
+2
-2
@@ -1,10 +1,10 @@
|
||||
[Unit]
|
||||
Description=ZeroTier One
|
||||
Description=BackOne
|
||||
After=network-online.target network.target
|
||||
Wants=network-online.target
|
||||
|
||||
[Service]
|
||||
ExecStart=/usr/sbin/zerotier-one
|
||||
ExecStart=/usr/sbin/backone
|
||||
Restart=always
|
||||
KillMode=process
|
||||
|
||||
+2
-2
@@ -1,4 +1,4 @@
|
||||
description "ZeroTier One upstart startup script"
|
||||
description "BackOne upstart startup script"
|
||||
|
||||
author "Adam Ierymenko <adam.ierymenko@zerotier.com>"
|
||||
|
||||
@@ -11,4 +11,4 @@ respawn limit 2 300
|
||||
#pre-start script
|
||||
#end script
|
||||
|
||||
exec /usr/sbin/zerotier-one
|
||||
exec /usr/sbin/backone
|
||||
Vendored
+6
@@ -1,3 +1,9 @@
|
||||
backone (2.0.0) unstable; urgency=medium
|
||||
|
||||
* See RELEASE-NOTES.md for release notes.
|
||||
|
||||
-- Dedy Sutanto <dsutanto@backone.cloud> Thu, 01 Oct 2026 07:06:32 +0700
|
||||
|
||||
zerotier-one (1.14.1) unstable; urgency=medium
|
||||
|
||||
* See RELEASE-NOTES.md for release notes.
|
||||
|
||||
Vendored
+4
-4
@@ -1,4 +1,4 @@
|
||||
Source: zerotier-one
|
||||
Source: backone
|
||||
Maintainer: Adam Ierymenko <adam.ierymenko@zerotier.com>
|
||||
Section: net
|
||||
Priority: optional
|
||||
@@ -8,12 +8,12 @@ Vcs-Git: git://github.com/zerotier/ZeroTierOne
|
||||
Vcs-Browser: https://github.com/zerotier/ZeroTierOne
|
||||
Homepage: https://www.zerotier.com/
|
||||
|
||||
Package: zerotier-one
|
||||
Package: backone
|
||||
Architecture: any
|
||||
Depends: adduser, libstdc++6 (>= 5), openssl
|
||||
Homepage: https://www.zerotier.com/
|
||||
Description: ZeroTier network virtualization service
|
||||
ZeroTier One lets you join ZeroTier virtual networks and
|
||||
Description: BackOne network virtualization service
|
||||
BackOne (a ZeroTier One fork) lets you join virtual networks and
|
||||
have them appear as tun/tap ports on your system. See
|
||||
https://www.zerotier.com/ for instructions and
|
||||
documentation.
|
||||
Vendored
+2
-2
@@ -2,8 +2,8 @@
|
||||
|
||||
case "$1" in
|
||||
configure)
|
||||
if ! id zerotier-one >>/dev/null 2>&1; then
|
||||
useradd --system --user-group --home-dir /var/lib/zerotier-one --shell /usr/sbin/nologin --no-create-home zerotier-one
|
||||
if ! id backone >>/dev/null 2>&1; then
|
||||
useradd --system --user-group --home-dir /var/lib/backone --shell /usr/sbin/nologin --no-create-home backone
|
||||
fi
|
||||
;;
|
||||
esac
|
||||
|
||||
+1
-1
@@ -13,4 +13,4 @@ override_dh_systemd_start:
|
||||
dh_systemd_start --restart-after-upgrade
|
||||
|
||||
override_dh_installinit:
|
||||
dh_installinit --name=zerotier-one -- defaults
|
||||
dh_installinit --name=backone -- defaults
|
||||
+2
-2
@@ -1,4 +1,4 @@
|
||||
[zerotier-one]
|
||||
title=ZeroTier One
|
||||
[backone]
|
||||
title=BackOne
|
||||
description=A planetary Ethernet switch
|
||||
ports=9993/udp
|
||||
@@ -1,58 +1,63 @@
|
||||
.TH "ZEROTIER\-CLI" "1" "December 2016" "" ""
|
||||
.TH "BACKONE\-CLI" "1" "September 2026"
|
||||
.SH "NAME"
|
||||
\fBzerotier-cli\fR \- control local ZeroTier virtual network service
|
||||
\fBbackone-cli\fR \- control local BackOne virtual network service
|
||||
.SH SYNOPSIS
|
||||
.P
|
||||
\fBzerotier\-cli\fP [\-switches] <command> [arguments]
|
||||
\fBbackone\-cli\fP [\-switches] <command> [arguments]
|
||||
.SH DESCRIPTION
|
||||
.P
|
||||
\fBzerotier\-cli\fR provides a simple command line interface to the local JSON API of the ZeroTier virtual network endpoint service zerotier\-one(8)\.
|
||||
.P
|
||||
By default \fBzerotier\-cli\fR must be run as root or with \fBsudo\fP\|\. If you want to allow an unprivileged user to use \fBzerotier\-cli\fR to control the system ZeroTier service, you can create a local copy of the ZeroTier service authorization token in the user's home directory:
|
||||
\fBbackone\-cli\fR provides a simple command line interface to the local JSON API of the BackOne virtual network endpoint service backone(8)\.
|
||||
.P
|
||||
By default \fBbackone\-cli\fR must be run as root or with \fBsudo\fP\|\. If you want to allow an unprivileged user to use \fBbackone\-cli\fR to control the system BackOne service, you can create a local copy of the BackOne service authorization token in the user's home directory:
|
||||
.RS 2
|
||||
.nf
|
||||
sudo cp /var/lib/zerotier\-one/authtoken\.secret /home/user/\.zeroTierOneAuthToken
|
||||
chown user /home/user/\.zeroTierOneAuthToken
|
||||
chmod 0600 /home/user/\.zeroTierOneAuthToken
|
||||
sudo cp /var/lib/backone/authtoken\.secret /home/user/\.backOneOneAuthToken
|
||||
chown user /home/user/\.backOneOneAuthToken
|
||||
chmod 0600 /home/user/\.backOneOneAuthToken
|
||||
.fi
|
||||
.RE
|
||||
.P
|
||||
(The location of ZeroTier's service home may differ by platform\. See zerotier\-one(8)\.)
|
||||
(The location of BackOne's service home may differ by platform\. See backone(8)\.)
|
||||
.P
|
||||
Note that this gives the user the power to connect or disconnect the system to or from any virtual network, which is a significant permission\.
|
||||
.P
|
||||
\fBzerotier\-cli\fR has several command line arguments that are visible in \fBhelp\fP output\. The two most commonly used are \fB\-j\fP for raw JSON output and \fB\-D<path>\fP to specify an alternative ZeroTier service working directory\. Raw JSON output is easier to parse in scripts and also contains verbose details not present in the tabular output\. The \fB\-D<path>\fP option specifies where the service's zerotier\-one\.port and authtoken\.secret files are located if the service is not running at the default location for your system\.
|
||||
\fBbackone\-cli\fR has several command line arguments that are visible in \fBhelp\fP output\. The two most commonly used are \fB\-j\fP for raw JSON output and \fB\-D<path>\fP to specify an alternative BackOne service working directory\. Raw JSON output is easier to parse in scripts and also contains verbose details not present in the tabular output\. The \fB\-D<path>\fP option specifies where the service's backone\.port and authtoken\.secret files are located if the service is not running at the default location for your system\.
|
||||
.SH COMMANDS
|
||||
.RS 0
|
||||
|
||||
.RS 1
|
||||
.IP \(bu 2
|
||||
\fBhelp\fP:
|
||||
Displays \fBzerotier\-cli\fR help\.
|
||||
.br
|
||||
Displays \fBbackone\-cli\fR help\.
|
||||
.IP \(bu 2
|
||||
\fBinfo\fP:
|
||||
.br
|
||||
Shows information about this device including its 10\-digit ZeroTier address and apparent connection status\. Use \fB\-j\fP for more verbose output\.
|
||||
.IP \(bu 2
|
||||
\fBlistpeers\fP:
|
||||
.br
|
||||
This command lists the ZeroTier VL1 (virtual layer 1, the peer to peer network) peers this service knows about and has recently (within the past 30 minutes or so) communicated with\. These are not necessarily all the devices on your virtual network(s), and may also include a few devices not on any virtual network you've joined\. These are typically either root servers or network controllers\.
|
||||
.IP \(bu 2
|
||||
\fBlistnetworks\fP:
|
||||
.br
|
||||
This lists the networks your system belongs to and some information about them, such as any ZeroTier\-managed IP addresses you have been assigned\. (IP addresses assigned manually to ZeroTier interfaces will not be listed here\. Use the standard network interface commands to see these\.)
|
||||
.IP \(bu 2
|
||||
\fBjoin\fP:
|
||||
.br
|
||||
To join a network just use \fBjoin\fP and its 16\-digit hex network ID\. That's it\. Then use \fBlistnetworks\fP to see the status\. You'll either get a reply from the network controller with a certificate and other info such as IP assignments, or you'll get "access denied\." In this case you'll need the administrator of this network to authorize your device by its 10\-digit device ID (visible with \fBinfo\fP) on the network's controller\.
|
||||
.IP \(bu 2
|
||||
\fBleave\fP:
|
||||
.br
|
||||
Leaving a network is as easy as joining it\. This disconnects from the network and deletes its interface from the system\. Note that peers on the network may hang around in \fBlistpeers\fP for up to 30 minutes until they time out due to lack of traffic\. But if they no longer share a network with you, they can't actually communicate with you in any meaningful way\.
|
||||
|
||||
.RE
|
||||
.SH EXAMPLES
|
||||
.P
|
||||
Join "Earth," ZeroTier's big public party line network:
|
||||
.P
|
||||
.RS 2
|
||||
.nf
|
||||
$ sudo zerotier\-cli join 8056c2e21c000001
|
||||
$ sudo zerotier\-cli listnetworks
|
||||
$ sudo backone\-cli join 8056c2e21c000001
|
||||
$ sudo backone\-cli listnetworks
|
||||
( wait until you get an Earth IP )
|
||||
$ ping earth\.zerotier\.net
|
||||
( you should now be able to ping our Earth test IP )
|
||||
@@ -60,24 +65,22 @@ $ ping earth\.zerotier\.net
|
||||
.RE
|
||||
.P
|
||||
Leave "Earth":
|
||||
.P
|
||||
.RS 2
|
||||
.nf
|
||||
$ sudo zerotier\-cli leave 8056c2e21c000001
|
||||
$ sudo backone\-cli leave 8056c2e21c000001
|
||||
.fi
|
||||
.RE
|
||||
.P
|
||||
List VL1 peers:
|
||||
.P
|
||||
.RS 2
|
||||
.nf
|
||||
$ sudo zerotier\-cli listpeers
|
||||
$ sudo backone\-cli listpeers
|
||||
.fi
|
||||
.RE
|
||||
.SH COPYRIGHT
|
||||
.P
|
||||
(c)2011\-2016 ZeroTier, Inc\. \-\- https://www\.zerotier\.com/ \-\- https://github\.com/zerotier
|
||||
(c)2011\-2016 ZeroTier, Inc\. \-\- https://www.zerotier.com/ \-\- https://github.com/zerotier
|
||||
.SH SEE ALSO
|
||||
.P
|
||||
zerotier\-one(8), zerotier\-idtool(1)
|
||||
backone(8), backone\-idtool(1)
|
||||
|
||||
@@ -1,30 +1,30 @@
|
||||
zerotier-cli(1) -- control local ZeroTier virtual network service
|
||||
=================================================================
|
||||
backone-cli(1) -- control local BackOne virtual network service
|
||||
===============================================================
|
||||
|
||||
## SYNOPSIS
|
||||
|
||||
`zerotier-cli` [-switches] <command> [arguments]
|
||||
`backone-cli` [-switches] <command> [arguments]
|
||||
|
||||
## DESCRIPTION
|
||||
|
||||
**zerotier-cli** provides a simple command line interface to the local JSON API of the ZeroTier virtual network endpoint service zerotier-one(8).
|
||||
**backone-cli** provides a simple command line interface to the local JSON API of the BackOne virtual network endpoint service backone(8).
|
||||
|
||||
By default **zerotier-cli** must be run as root or with `sudo`. If you want to allow an unprivileged user to use **zerotier-cli** to control the system ZeroTier service, you can create a local copy of the ZeroTier service authorization token in the user's home directory:
|
||||
By default **backone-cli** must be run as root or with `sudo`. If you want to allow an unprivileged user to use **backone-cli** to control the system BackOne service, you can create a local copy of the BackOne service authorization token in the user's home directory:
|
||||
|
||||
sudo cp /var/lib/zerotier-one/authtoken.secret /home/user/.zeroTierOneAuthToken
|
||||
chown user /home/user/.zeroTierOneAuthToken
|
||||
chmod 0600 /home/user/.zeroTierOneAuthToken
|
||||
sudo cp /var/lib/backone/authtoken.secret /home/user/.backOneOneAuthToken
|
||||
chown user /home/user/.backOneOneAuthToken
|
||||
chmod 0600 /home/user/.backOneOneAuthToken
|
||||
|
||||
(The location of ZeroTier's service home may differ by platform. See zerotier-one(8).)
|
||||
(The location of BackOne's service home may differ by platform. See backone(8).)
|
||||
|
||||
Note that this gives the user the power to connect or disconnect the system to or from any virtual network, which is a significant permission.
|
||||
|
||||
**zerotier-cli** has several command line arguments that are visible in `help` output. The two most commonly used are `-j` for raw JSON output and `-D<path>` to specify an alternative ZeroTier service working directory. Raw JSON output is easier to parse in scripts and also contains verbose details not present in the tabular output. The `-D<path>` option specifies where the service's zerotier-one.port and authtoken.secret files are located if the service is not running at the default location for your system.
|
||||
**backone-cli** has several command line arguments that are visible in `help` output. The two most commonly used are `-j` for raw JSON output and `-D<path>` to specify an alternative BackOne service working directory. Raw JSON output is easier to parse in scripts and also contains verbose details not present in the tabular output. The `-D<path>` option specifies where the service's backone.port and authtoken.secret files are located if the service is not running at the default location for your system.
|
||||
|
||||
## COMMANDS
|
||||
|
||||
* `help`:
|
||||
Displays **zerotier-cli** help.
|
||||
Displays **backone-cli** help.
|
||||
|
||||
* `info`:
|
||||
Shows information about this device including its 10-digit ZeroTier address and apparent connection status. Use `-j` for more verbose output.
|
||||
@@ -45,19 +45,19 @@ Note that this gives the user the power to connect or disconnect the system to o
|
||||
|
||||
Join "Earth," ZeroTier's big public party line network:
|
||||
|
||||
$ sudo zerotier-cli join 8056c2e21c000001
|
||||
$ sudo zerotier-cli listnetworks
|
||||
$ sudo backone-cli join 8056c2e21c000001
|
||||
$ sudo backone-cli listnetworks
|
||||
( wait until you get an Earth IP )
|
||||
$ ping earth.zerotier.net
|
||||
( you should now be able to ping our Earth test IP )
|
||||
|
||||
Leave "Earth":
|
||||
|
||||
$ sudo zerotier-cli leave 8056c2e21c000001
|
||||
$ sudo backone-cli leave 8056c2e21c000001
|
||||
|
||||
List VL1 peers:
|
||||
|
||||
$ sudo zerotier-cli listpeers
|
||||
$ sudo backone-cli listpeers
|
||||
|
||||
## COPYRIGHT
|
||||
|
||||
@@ -65,4 +65,4 @@ List VL1 peers:
|
||||
|
||||
## SEE ALSO
|
||||
|
||||
zerotier-one(8), zerotier-idtool(1)
|
||||
backone(8), backone-idtool(1)
|
||||
@@ -1,84 +1,87 @@
|
||||
.TH "ZEROTIER\-IDTOOL" "1" "December 2016" "" ""
|
||||
.TH "BACKONE\-IDTOOL" "1" "September 2026"
|
||||
.SH "NAME"
|
||||
\fBzerotier-idtool\fR \- tool for creating and manipulating ZeroTier identities
|
||||
\fBbackone-idtool\fR \- tool for creating and manipulating ZeroTier identities
|
||||
.SH SYNOPSIS
|
||||
.P
|
||||
\fBzerotier\-idtool\fP <command> [args]
|
||||
\fBbackone\-idtool\fP <command> [args]
|
||||
.SH DESCRIPTION
|
||||
.P
|
||||
\fBzerotier\-idtool\fR is a command line utility for doing things with ZeroTier identities\. A ZeroTier identity consists of a public/private key pair (or just the public if it's only an identity\.public) and a 10\-digit hexadecimal ZeroTier address derived from the public key by way of a proof of work based hash function\.
|
||||
\fBbackone\-idtool\fR is a command line utility for doing things with ZeroTier identities\. A ZeroTier identity consists of a public/private key pair (or just the public if it's only an identity\.public) and a 10\-digit hexadecimal ZeroTier address derived from the public key by way of a proof of work based hash function\.
|
||||
.SH COMMANDS
|
||||
.P
|
||||
When command arguments call for a public or secret (full) identity, the identity can be specified as a path to a file or directly on the command line\.
|
||||
.RS 0
|
||||
|
||||
.RS 1
|
||||
.IP \(bu 2
|
||||
\fBhelp\fP:
|
||||
.br
|
||||
Display help\. (Also running with no command does this\.)
|
||||
.IP \(bu 2
|
||||
\fBgenerate\fP [secret file] [public file] [vanity]:
|
||||
.br
|
||||
Generate a new ZeroTier identity\. If a secret file is specified, the full identity including the private key will be written to this file\. If the public file is specified, the public portion will be written there\. If no file paths are specified the full secret identity is output to STDOUT\. The vanity prefix is a series of hexadecimal digits that the generated identity's address should start with\. Typically this isn't used, and if it's specified generation can take a very long time due to the intrinsic cost of generating identities with their proof of work function\. Generating an identity with a known 16\-bit (4 digit) prefix on a 2\.8ghz Core i5 (using one core) takes an average of two hours\.
|
||||
.IP \(bu 2
|
||||
\fBvalidate\fP <identity, only public part required>:
|
||||
.br
|
||||
Locally validate an identity's key and proof of work function correspondence\.
|
||||
.IP \(bu 2
|
||||
\fBgetpublic\fP <full identity with secret>:
|
||||
.br
|
||||
Extract the public portion of an identity\.secret and print to STDOUT\.
|
||||
.IP \(bu 2
|
||||
\fBsign\fP <full identity with secret> <file to sign>:
|
||||
.br
|
||||
Sign a file's contents with SHA512+ECC\-256 (ed25519)\. The signature is output in hex to STDOUT\.
|
||||
.IP \(bu 2
|
||||
\fBverify\fP <identity, only public part required> <file to check> <signature in hex>:
|
||||
.br
|
||||
Verify a signature created with \fBsign\fP\|\.
|
||||
.IP \(bu 2
|
||||
\fBmkcom\fP <full identity with secret> [id,value,maxdelta] [\|\.\.\.]:
|
||||
\fBmkcom\fP <full identity with secret> [id,value,maxdelta] [\.\.\.]:
|
||||
.br
|
||||
Create and sign a network membership certificate\. This is not generally useful since network controllers do this automatically and is included mostly for testing purposes\.
|
||||
|
||||
.RE
|
||||
.SH EXAMPLES
|
||||
.P
|
||||
Generate and dump a new identity:
|
||||
.P
|
||||
.RS 2
|
||||
.nf
|
||||
$ zerotier\-idtool generate
|
||||
$ backone\-idtool generate
|
||||
.fi
|
||||
.RE
|
||||
.P
|
||||
Generate and write a new identity, both secret and public parts:
|
||||
.P
|
||||
.RS 2
|
||||
.nf
|
||||
$ zerotier\-idtool generate identity\.secret identity\.public
|
||||
$ backone\-idtool generate identity\.secret identity\.public
|
||||
.fi
|
||||
.RE
|
||||
.P
|
||||
Generate a vanity address that begins with the hex digits "beef" (this will take a while!):
|
||||
.P
|
||||
.RS 2
|
||||
.nf
|
||||
$ zerotier\-idtool generate beef\.secret beef\.public beef
|
||||
$ backone\-idtool generate beef\.secret beef\.public beef
|
||||
.fi
|
||||
.RE
|
||||
.P
|
||||
Sign a file with an identity's secret key:
|
||||
.P
|
||||
.RS 2
|
||||
.nf
|
||||
$ zerotier\-idtool sign identity\.secret last_will_and_testament\.txt
|
||||
$ backone\-idtool sign identity\.secret last_will_and_testament\.txt
|
||||
.fi
|
||||
.RE
|
||||
.P
|
||||
Verify a file's signature with a public key:
|
||||
.P
|
||||
.RS 2
|
||||
.nf
|
||||
$ zerotier\-idtool verify identity\.public last_will_and_testament\.txt
|
||||
$ backone\-idtool verify identity\.public last_will_and_testament\.txt
|
||||
.fi
|
||||
.RE
|
||||
.SH COPYRIGHT
|
||||
.P
|
||||
(c)2011\-2016 ZeroTier, Inc\. \-\- https://www\.zerotier\.com/ \-\- https://github\.com/zerotier
|
||||
(c)2011\-2016 ZeroTier, Inc\. \-\- https://www.zerotier.com/ \-\- https://github.com/zerotier
|
||||
.SH SEE ALSO
|
||||
.P
|
||||
zerotier\-one(8), zerotier\-cli(1)
|
||||
backone(8), backone\-cli(1)
|
||||
|
||||
@@ -1,13 +1,13 @@
|
||||
zerotier-idtool(1) -- tool for creating and manipulating ZeroTier identities
|
||||
============================================================================
|
||||
backone-idtool(1) -- tool for creating and manipulating ZeroTier identities
|
||||
===========================================================================
|
||||
|
||||
## SYNOPSIS
|
||||
|
||||
`zerotier-idtool` <command> [args]
|
||||
`backone-idtool` <command> [args]
|
||||
|
||||
## DESCRIPTION
|
||||
|
||||
**zerotier-idtool** is a command line utility for doing things with ZeroTier identities. A ZeroTier identity consists of a public/private key pair (or just the public if it's only an identity.public) and a 10-digit hexadecimal ZeroTier address derived from the public key by way of a proof of work based hash function.
|
||||
**backone-idtool** is a command line utility for doing things with ZeroTier identities. A ZeroTier identity consists of a public/private key pair (or just the public if it's only an identity.public) and a 10-digit hexadecimal ZeroTier address derived from the public key by way of a proof of work based hash function.
|
||||
|
||||
## COMMANDS
|
||||
|
||||
@@ -38,23 +38,23 @@ When command arguments call for a public or secret (full) identity, the identity
|
||||
|
||||
Generate and dump a new identity:
|
||||
|
||||
$ zerotier-idtool generate
|
||||
$ backone-idtool generate
|
||||
|
||||
Generate and write a new identity, both secret and public parts:
|
||||
|
||||
$ zerotier-idtool generate identity.secret identity.public
|
||||
$ backone-idtool generate identity.secret identity.public
|
||||
|
||||
Generate a vanity address that begins with the hex digits "beef" (this will take a while!):
|
||||
|
||||
$ zerotier-idtool generate beef.secret beef.public beef
|
||||
$ backone-idtool generate beef.secret beef.public beef
|
||||
|
||||
Sign a file with an identity's secret key:
|
||||
|
||||
$ zerotier-idtool sign identity.secret last_will_and_testament.txt
|
||||
$ backone-idtool sign identity.secret last_will_and_testament.txt
|
||||
|
||||
Verify a file's signature with a public key:
|
||||
|
||||
$ zerotier-idtool verify identity.public last_will_and_testament.txt
|
||||
$ backone-idtool verify identity.public last_will_and_testament.txt
|
||||
|
||||
## COPYRIGHT
|
||||
|
||||
@@ -62,4 +62,4 @@ Verify a file's signature with a public key:
|
||||
|
||||
## SEE ALSO
|
||||
|
||||
zerotier-one(8), zerotier-cli(1)
|
||||
backone(8), backone-cli(1)
|
||||
+121
@@ -0,0 +1,121 @@
|
||||
.TH "BACKONE" "8" "September 2026"
|
||||
.SH "NAME"
|
||||
\fBbackone\fR \- BackOne virtual network endpoint service
|
||||
.SH SYNOPSIS
|
||||
.P
|
||||
\fBbackone\fP [\-switches] [working directory]
|
||||
.SH DESCRIPTION
|
||||
.P
|
||||
\fBbackone\fR is the service/daemon responsible for connecting a Unix (Linux/BSD/OSX) system to one or more ZeroTier virtual networks and presenting those networks to the system as virtual network ports\. You can think of it as a peer to peer VPN client\.
|
||||
.P
|
||||
It's typically run by init systems like systemd (Linux) or launchd (Mac) rather than directly by the user, and it must be run as root unless you give it the \fB\-U\fP switch and don't plan on actually joining networks (e\.g\. to run a network controller microservice only)\.
|
||||
.P
|
||||
The \fBbackone\fR service keeps its state and other files in a working directory\. If this directory is not specified at launch it defaults to "/var/lib/backone" on Linux, "/Library/Application Support/BackOne" on Mac, and "/var/db/backone" on FreeBSD and other similar BSDs\. The working directory should persist\. It shouldn't be automatically cleaned by system cleanup daemons or stored in a volatile location\. Loss of its identity\.secret file results in loss of this system's unique 10\-digit ZeroTier address and key\.
|
||||
.P
|
||||
Multiple instances of \fBbackone\fR can be run on the same system as long as they are run with different primary ports (see switches) and a different working directory\. But since a single service can join any number of networks, typically there's no point in doing this\.
|
||||
.P
|
||||
The \fBbackone\fR service is controlled via a JSON API available at 127\.0\.0\.1:<primary port> with the default primary port being 9993\. Access to this API requires an authorization token normally found in the authtoken\.secret file in the service's working directory\. On some platforms access may be guarded by other measures such as socket peer UID/GID lookup if additional security options are enabled (this is not the default)\.
|
||||
.P
|
||||
The first time the service is started in a fresh working directory, it generates a ZeroTier identity\. On slow systems this process can take ten seconds or more due to an anti\-DDOS/anti\-counterfeit proof of work function used by ZeroTier in address generation\. This only happens once, and once generated the result is saved in identity\.secret in the working directory\. This file represents and defines/claims your ZeroTier address and associated ECC\-256 key pair\.
|
||||
.SH SWITCHES
|
||||
|
||||
.RS 1
|
||||
.IP \(bu 2
|
||||
\fB\-h\fP:
|
||||
.br
|
||||
Display help\.
|
||||
.IP \(bu 2
|
||||
\fB\-v\fP:
|
||||
.br
|
||||
Display BackOne version\.
|
||||
.IP \(bu 2
|
||||
\fB\-U\fP:
|
||||
.br
|
||||
Skip privilege check and allow to be run by non\-privileged user\. This is typically used when \fBbackone\fR is built with the network controller option included\. In this case the BackOne service might only be acting as a network controller and might never actually join networks, in which case it does not require elevated system permissions\.
|
||||
.IP \(bu 2
|
||||
\fB\-p<port>\fP:
|
||||
.br
|
||||
Specify a different primary port\. If this is not given the default is 9993\. If zero is given a random port is chosen each time\.
|
||||
.IP \(bu 2
|
||||
\fB\-d\fP:
|
||||
.br
|
||||
Fork and run as a daemon\.
|
||||
.IP \(bu 2
|
||||
\fB\-i\fP:
|
||||
.br
|
||||
Invoke the \fBbackone\-idtool\fR personality, in which case the binary behaves like backone\-idtool(1)\. This happens automatically if the name of the binary (or a symlink to it) is backone\-idtool\.
|
||||
.IP \(bu 2
|
||||
\fB\-q\fP:
|
||||
.br
|
||||
Invoke the \fBbackone\-cli\fR personality, in which case the binary behaves like backone\-cli(1)\. This happens automatically if the name of the binary (or a symlink to it) is backone\-cli\.
|
||||
|
||||
.RE
|
||||
.SH EXAMPLES
|
||||
.P
|
||||
Run as daemon with OS default working directory and default port:
|
||||
.RS 2
|
||||
.nf
|
||||
$ sudo backone \-d
|
||||
.fi
|
||||
.RE
|
||||
.P
|
||||
Run as daemon with a different working directory and port:
|
||||
.RS 2
|
||||
.nf
|
||||
$ sudo backone \-d \-p12345 /tmp/backone\-working\-directory\-test
|
||||
.fi
|
||||
.RE
|
||||
.SH FILES
|
||||
.P
|
||||
These are found in the service's working directory\.
|
||||
|
||||
.RS 1
|
||||
.IP \(bu 2
|
||||
\fBidentity\.public\fP:
|
||||
.br
|
||||
The public portion of your ZeroTier identity, which is your 10\-digit hex address and the associated public key\.
|
||||
.IP \(bu 2
|
||||
\fBidentity\.secret\fP:
|
||||
.br
|
||||
Your full ZeroTier identity including its private key\. This file identifies the system on the network, which means you can move a ZeroTier address around by copying this file and you should back up this file if you want to save your system's static ZeroTier address\. This file must be protected, since theft of its secret key will allow anyone to impersonate your device on any network and decrypt traffic\. For network controllers this file is particularly sensitive since it constitutes the private key for a certificate authority for the controller's networks\.
|
||||
.IP \(bu 2
|
||||
\fBauthtoken\.secret\fP:
|
||||
.br
|
||||
The secret token used to authenticate requests to the service's local JSON API\. If it does not exist it is generated from a secure random source on service start\. To use, send it in the "X\-ZT1\-Auth" header with HTTP requests to 127\.0\.0\.1:<primary port>\|\.
|
||||
.IP \(bu 2
|
||||
\fBdevicemap\fP:
|
||||
.br
|
||||
Remembers mappings of zt# interface numbers to ZeroTier networks so they'll persist across restarts\. On some systems that support longer interface names that can encode the network ID (such as FreeBSD) this file may not be present\.
|
||||
.IP \(bu 2
|
||||
\fBbackone\.pid\fP:
|
||||
.br
|
||||
BackOne's PID\. This file is deleted on normal shutdown\.
|
||||
.IP \(bu 2
|
||||
\fBbackone\.port\fP:
|
||||
.br
|
||||
BackOne's primary port, which is also where its JSON API is found at 127\.0\.0\.1:<this port>\|\. This file is created on startup and is read by backone\-cli(1) to determine where it should find the control API\.
|
||||
.IP \(bu 2
|
||||
\fBcontroller\.db\fP:
|
||||
.br
|
||||
If the BackOne service is built with the network controller enabled, this file contains the controller's SQLite3 database\.
|
||||
.IP \(bu 2
|
||||
\fBcontroller\.db\.backup\fP:
|
||||
.br
|
||||
If the BackOne service is built with the network controller enabled, it periodically backs up its controller\.db database in this file (currently every 5 minutes if there have been changes)\. Since this file is not a currently in use SQLite3 database it's safer to back up without corruption\. On new backups the file is rotated out rather than being rewritten in place\.
|
||||
.IP \(bu 2
|
||||
\fBiddb\.d/\fP (directory):
|
||||
.br
|
||||
Caches the public identity of every peer BackOne has spoken with in the last 60 days\. This directory and its contents can be deleted, but this may result in slower connection initiations since it will require that we go out and re\-fetch full identities for peers we're speaking to\.
|
||||
.IP \(bu 2
|
||||
\fBnetworks\.d\fP (directory):
|
||||
.br
|
||||
This caches network configurations and certificate information for networks you belong to\. BackOne scans this directory for <network ID>\|\.conf files on startup to recall its networks, so "touch"ing an empty <network ID>\|\.conf file in this directory is a way of pre\-configuring BackOne to join a specific network on startup without using the API\. If the config file is empty BackOne will just fetch it from the network's controller\.
|
||||
|
||||
.RE
|
||||
.SH COPYRIGHT
|
||||
.P
|
||||
(c)2011\-2016 ZeroTier, Inc\. \-\- https://www.zerotier.com/ \-\- https://github.com/zerotier
|
||||
.SH SEE ALSO
|
||||
.P
|
||||
backone\-cli(1), backone\-idtool(1)
|
||||
|
||||
@@ -0,0 +1,95 @@
|
||||
backone(8) -- BackOne virtual network endpoint service
|
||||
======================================================
|
||||
|
||||
## SYNOPSIS
|
||||
|
||||
`backone` [-switches] [working directory]
|
||||
|
||||
## DESCRIPTION
|
||||
|
||||
**backone** is the service/daemon responsible for connecting a Unix (Linux/BSD/OSX) system to one or more ZeroTier virtual networks and presenting those networks to the system as virtual network ports. You can think of it as a peer to peer VPN client.
|
||||
|
||||
It's typically run by init systems like systemd (Linux) or launchd (Mac) rather than directly by the user, and it must be run as root unless you give it the `-U` switch and don't plan on actually joining networks (e.g. to run a network controller microservice only).
|
||||
|
||||
The **backone** service keeps its state and other files in a working directory. If this directory is not specified at launch it defaults to "/var/lib/backone" on Linux, "/Library/Application Support/BackOne" on Mac, and "/var/db/backone" on FreeBSD and other similar BSDs. The working directory should persist. It shouldn't be automatically cleaned by system cleanup daemons or stored in a volatile location. Loss of its identity.secret file results in loss of this system's unique 10-digit ZeroTier address and key.
|
||||
|
||||
Multiple instances of **backone** can be run on the same system as long as they are run with different primary ports (see switches) and a different working directory. But since a single service can join any number of networks, typically there's no point in doing this.
|
||||
|
||||
The **backone** service is controlled via a JSON API available at 127.0.0.1:<primary port> with the default primary port being 9993. Access to this API requires an authorization token normally found in the authtoken.secret file in the service's working directory. On some platforms access may be guarded by other measures such as socket peer UID/GID lookup if additional security options are enabled (this is not the default).
|
||||
|
||||
The first time the service is started in a fresh working directory, it generates a ZeroTier identity. On slow systems this process can take ten seconds or more due to an anti-DDOS/anti-counterfeit proof of work function used by ZeroTier in address generation. This only happens once, and once generated the result is saved in identity.secret in the working directory. This file represents and defines/claims your ZeroTier address and associated ECC-256 key pair.
|
||||
|
||||
## SWITCHES
|
||||
|
||||
* `-h`:
|
||||
Display help.
|
||||
|
||||
* `-v`:
|
||||
Display BackOne version.
|
||||
|
||||
* `-U`:
|
||||
Skip privilege check and allow to be run by non-privileged user. This is typically used when **backone** is built with the network controller option included. In this case the BackOne service might only be acting as a network controller and might never actually join networks, in which case it does not require elevated system permissions.
|
||||
|
||||
* `-p<port>`:
|
||||
Specify a different primary port. If this is not given the default is 9993. If zero is given a random port is chosen each time.
|
||||
|
||||
* `-d`:
|
||||
Fork and run as a daemon.
|
||||
|
||||
* `-i`:
|
||||
Invoke the **backone-idtool** personality, in which case the binary behaves like backone-idtool(1). This happens automatically if the name of the binary (or a symlink to it) is backone-idtool.
|
||||
|
||||
* `-q`:
|
||||
Invoke the **backone-cli** personality, in which case the binary behaves like backone-cli(1). This happens automatically if the name of the binary (or a symlink to it) is backone-cli.
|
||||
|
||||
## EXAMPLES
|
||||
|
||||
Run as daemon with OS default working directory and default port:
|
||||
|
||||
$ sudo backone -d
|
||||
|
||||
Run as daemon with a different working directory and port:
|
||||
|
||||
$ sudo backone -d -p12345 /tmp/backone-working-directory-test
|
||||
|
||||
## FILES
|
||||
|
||||
These are found in the service's working directory.
|
||||
|
||||
* `identity.public`:
|
||||
The public portion of your ZeroTier identity, which is your 10-digit hex address and the associated public key.
|
||||
|
||||
* `identity.secret`:
|
||||
Your full ZeroTier identity including its private key. This file identifies the system on the network, which means you can move a ZeroTier address around by copying this file and you should back up this file if you want to save your system's static ZeroTier address. This file must be protected, since theft of its secret key will allow anyone to impersonate your device on any network and decrypt traffic. For network controllers this file is particularly sensitive since it constitutes the private key for a certificate authority for the controller's networks.
|
||||
|
||||
* `authtoken.secret`:
|
||||
The secret token used to authenticate requests to the service's local JSON API. If it does not exist it is generated from a secure random source on service start. To use, send it in the "X-ZT1-Auth" header with HTTP requests to 127.0.0.1:<primary port>.
|
||||
|
||||
* `devicemap`:
|
||||
Remembers mappings of zt# interface numbers to ZeroTier networks so they'll persist across restarts. On some systems that support longer interface names that can encode the network ID (such as FreeBSD) this file may not be present.
|
||||
|
||||
* `backone.pid`:
|
||||
BackOne's PID. This file is deleted on normal shutdown.
|
||||
|
||||
* `backone.port`:
|
||||
BackOne's primary port, which is also where its JSON API is found at 127.0.0.1:<this port>. This file is created on startup and is read by backone-cli(1) to determine where it should find the control API.
|
||||
|
||||
* `controller.db`:
|
||||
If the BackOne service is built with the network controller enabled, this file contains the controller's SQLite3 database.
|
||||
|
||||
* `controller.db.backup`:
|
||||
If the BackOne service is built with the network controller enabled, it periodically backs up its controller.db database in this file (currently every 5 minutes if there have been changes). Since this file is not a currently in use SQLite3 database it's safer to back up without corruption. On new backups the file is rotated out rather than being rewritten in place.
|
||||
|
||||
* `iddb.d/` (directory):
|
||||
Caches the public identity of every peer BackOne has spoken with in the last 60 days. This directory and its contents can be deleted, but this may result in slower connection initiations since it will require that we go out and re-fetch full identities for peers we're speaking to.
|
||||
|
||||
* `networks.d` (directory):
|
||||
This caches network configurations and certificate information for networks you belong to. BackOne scans this directory for <network ID>.conf files on startup to recall its networks, so "touch"ing an empty <network ID>.conf file in this directory is a way of pre-configuring BackOne to join a specific network on startup without using the API. If the config file is empty BackOne will just fetch it from the network's controller.
|
||||
|
||||
## COPYRIGHT
|
||||
|
||||
(c)2011-2016 ZeroTier, Inc. -- https://www.zerotier.com/ -- https://github.com/zerotier
|
||||
|
||||
## SEE ALSO
|
||||
|
||||
backone-cli(1), backone-idtool(1)
|
||||
+12
-21
@@ -1,42 +1,33 @@
|
||||
#!/bin/bash
|
||||
|
||||
export PATH=/bin:/usr/bin:/usr/local/bin:/sbin:/usr/sbin:/usr/local/sbin
|
||||
|
||||
if [ ! -f zerotier-cli.1.md ]; then
|
||||
echo 'This script must be run from the doc/ subfolder of the ZeroTier tree.'
|
||||
if [ ! -f backone.8.md ]; then
|
||||
echo 'This script must be run from the doc/ subfolder of the BackOne tree.'
|
||||
exit 1
|
||||
fi
|
||||
|
||||
rm -f *.1 *.2 *.8
|
||||
|
||||
if [ -e /usr/bin/ronn -o -e /usr/local/bin/ronn ]; then
|
||||
# Use 'ronn' which is available as a package on many distros including Debian
|
||||
ronn -r zerotier-cli.1.md
|
||||
ronn -r zerotier-idtool.1.md
|
||||
ronn -r zerotier-one.8.md
|
||||
ronn -r backone-cli.1.md
|
||||
ronn -r backone-idtool.1.md
|
||||
ronn -r backone.8.md
|
||||
else
|
||||
# Use 'marked-man' from npm
|
||||
NODE=/usr/bin/node
|
||||
if [ ! -e $NODE ]; then
|
||||
if [ -e /usr/bin/nodejs ]; then
|
||||
NODE=/usr/bin/nodejs
|
||||
elif [ -e /usr/local/bin/node ]; then
|
||||
NODE=/usr/local/bin/node
|
||||
elif [ -e /usr/local/bin/nodejs ]; then
|
||||
NODE=/usr/local/bin/nodejs
|
||||
else
|
||||
NODE=$(command -v node || command -v nodejs)
|
||||
if [ -z "$NODE" ]; then
|
||||
echo 'Unable to find ronn or node/npm -- cannot build man pages!'
|
||||
exit 1
|
||||
fi
|
||||
fi
|
||||
|
||||
if [ ! -f node_modules/marked-man/bin/marked-man ]; then
|
||||
if ! npx --no-install marked-man --version >/dev/null 2>&1; then
|
||||
echo 'Installing npm package "marked-man" -- MarkDown to ROFF converter...'
|
||||
npm install marked-man
|
||||
fi
|
||||
|
||||
$NODE node_modules/marked-man/bin/marked-man zerotier-cli.1.md >zerotier-cli.1
|
||||
$NODE node_modules/marked-man/bin/marked-man zerotier-idtool.1.md >zerotier-idtool.1
|
||||
$NODE node_modules/marked-man/bin/marked-man zerotier-one.8.md >zerotier-one.8
|
||||
npx --no-install marked-man backone-cli.1.md >backone-cli.1
|
||||
npx --no-install marked-man backone-idtool.1.md >backone-idtool.1
|
||||
npx --no-install marked-man backone.8.md >backone.8
|
||||
fi
|
||||
|
||||
exit 0
|
||||
@@ -1,104 +0,0 @@
|
||||
.TH "ZEROTIER\-ONE" "8" "December 2016" "" ""
|
||||
.SH "NAME"
|
||||
\fBzerotier-one\fR \- ZeroTier virtual network endpoint service
|
||||
.SH SYNOPSIS
|
||||
.P
|
||||
\fBzerotier\-one\fP [\-switches] [working directory]
|
||||
.SH DESCRIPTION
|
||||
.P
|
||||
\fBzerotier\-one\fR is the service/daemon responsible for connecting a Unix (Linux/BSD/OSX) system to one or more ZeroTier virtual networks and presenting those networks to the system as virtual network ports\. You can think of it as a peer to peer VPN client\.
|
||||
.P
|
||||
It's typically run by init systems like systemd (Linux) or launchd (Mac) rather than directly by the user, and it must be run as root unless you give it the \fB\-U\fP switch and don't plan on actually joining networks (e\.g\. to run a network controller microservice only)\.
|
||||
.P
|
||||
The \fBzerotier\-one\fR service keeps its state and other files in a working directory\. If this directory is not specified at launch it defaults to "/var/lib/zerotier\-one" on Linux, "/Library/Application Support/ZeroTier/One" on Mac, and "/var/db/zerotier\-one" on FreeBSD and other similar BSDs\. The working directory should persist\. It shouldn't be automatically cleaned by system cleanup daemons or stored in a volatile location\. Loss of its identity\.secret file results in loss of this system's unique 10\-digit ZeroTier address and key\.
|
||||
.P
|
||||
Multiple instances of \fBzerotier\-one\fR can be run on the same system as long as they are run with different primary ports (see switches) and a different working directory\. But since a single service can join any number of networks, typically there's no point in doing this\.
|
||||
.P
|
||||
The \fBzerotier\-one\fR service is controlled via a JSON API available at 127\.0\.0\.1:<primary port> with the default primary port being 9993\. Access to this API requires an authorization token normally found in the authtoken\.secret file in the service's working directory\. On some platforms access may be guarded by other measures such as socket peer UID/GID lookup if additional security options are enabled (this is not the default)\.
|
||||
.P
|
||||
The first time the service is started in a fresh working directory, it generates a ZeroTier identity\. On slow systems this process can take ten seconds or more due to an anti\-DDOS/anti\-counterfeit proof of work function used by ZeroTier in address generation\. This only happens once, and once generated the result is saved in identity\.secret in the working directory\. This file represents and defines/claims your ZeroTier address and associated ECC\-256 key pair\.
|
||||
.SH SWITCHES
|
||||
.RS 0
|
||||
.IP \(bu 2
|
||||
\fB\-h\fP:
|
||||
Display help\.
|
||||
.IP \(bu 2
|
||||
\fB\-v\fP:
|
||||
Display ZeroTier One version\.
|
||||
.IP \(bu 2
|
||||
\fB\-U\fP:
|
||||
Skip privilege check and allow to be run by non\-privileged user\. This is typically used when \fBzerotier\-one\fR is built with the network controller option included\. In this case the ZeroTier service might only be acting as a network controller and might never actually join networks, in which case it does not require elevated system permissions\.
|
||||
.IP \(bu 2
|
||||
\fB\-p<port>\fP:
|
||||
Specify a different primary port\. If this is not given the default is 9993\. If zero is given a random port is chosen each time\.
|
||||
.IP \(bu 2
|
||||
\fB\-d\fP:
|
||||
Fork and run as a daemon\.
|
||||
.IP \(bu 2
|
||||
\fB\-i\fP:
|
||||
Invoke the \fBzerotier\-idtool\fR personality, in which case the binary behaves like zerotier\-idtool(1)\. This happens automatically if the name of the binary (or a symlink to it) is zerotier\-idtool\.
|
||||
.IP \(bu 2
|
||||
\fB\-q\fP:
|
||||
Invoke the \fBzerotier\-cli\fR personality, in which case the binary behaves like zerotier\-cli(1)\. This happens automatically if the name of the binary (or a symlink to it) is zerotier\-cli\.
|
||||
|
||||
.RE
|
||||
.SH EXAMPLES
|
||||
.P
|
||||
Run as daemon with OS default working directory and default port:
|
||||
.P
|
||||
.RS 2
|
||||
.nf
|
||||
$ sudo zerotier\-one \-d
|
||||
.fi
|
||||
.RE
|
||||
.P
|
||||
Run as daemon with a different working directory and port:
|
||||
.P
|
||||
.RS 2
|
||||
.nf
|
||||
$ sudo zerotier\-one \-d \-p12345 /tmp/zerotier\-working\-directory\-test
|
||||
.fi
|
||||
.RE
|
||||
.SH FILES
|
||||
.P
|
||||
These are found in the service's working directory\.
|
||||
.RS 0
|
||||
.IP \(bu 2
|
||||
\fBidentity\.public\fP:
|
||||
The public portion of your ZeroTier identity, which is your 10\-digit hex address and the associated public key\.
|
||||
.IP \(bu 2
|
||||
\fBidentity\.secret\fP:
|
||||
Your full ZeroTier identity including its private key\. This file identifies the system on the network, which means you can move a ZeroTier address around by copying this file and you should back up this file if you want to save your system's static ZeroTier address\. This file must be protected, since theft of its secret key will allow anyone to impersonate your device on any network and decrypt traffic\. For network controllers this file is particularly sensitive since it constitutes the private key for a certificate authority for the controller's networks\.
|
||||
.IP \(bu 2
|
||||
\fBauthtoken\.secret\fP:
|
||||
The secret token used to authenticate requests to the service's local JSON API\. If it does not exist it is generated from a secure random source on service start\. To use, send it in the "X\-ZT1\-Auth" header with HTTP requests to 127\.0\.0\.1:<primary port>\|\.
|
||||
.IP \(bu 2
|
||||
\fBdevicemap\fP:
|
||||
Remembers mappings of zt# interface numbers to ZeroTier networks so they'll persist across restarts\. On some systems that support longer interface names that can encode the network ID (such as FreeBSD) this file may not be present\.
|
||||
.IP \(bu 2
|
||||
\fBzerotier\-one\.pid\fP:
|
||||
ZeroTier's PID\. This file is deleted on normal shutdown\.
|
||||
.IP \(bu 2
|
||||
\fBzerotier\-one\.port\fP:
|
||||
ZeroTier's primary port, which is also where its JSON API is found at 127\.0\.0\.1:<this port>\|\. This file is created on startup and is read by zerotier\-cli(1) to determine where it should find the control API\.
|
||||
.IP \(bu 2
|
||||
\fBcontroller\.db\fP:
|
||||
If the ZeroTier One service is built with the network controller enabled, this file contains the controller's SQLite3 database\.
|
||||
.IP \(bu 2
|
||||
\fBcontroller\.db\.backup\fP:
|
||||
If the ZeroTier One service is built with the network controller enabled, it periodically backs up its controller\.db database in this file (currently every 5 minutes if there have been changes)\. Since this file is not a currently in use SQLite3 database it's safer to back up without corruption\. On new backups the file is rotated out rather than being rewritten in place\.
|
||||
.IP \(bu 2
|
||||
\fBiddb\.d/\fP (directory):
|
||||
Caches the public identity of every peer ZeroTier has spoken with in the last 60 days\. This directory and its contents can be deleted, but this may result in slower connection initations since it will require that we go out and re\-fetch full identities for peers we're speaking to\.
|
||||
.IP \(bu 2
|
||||
\fBnetworks\.d\fP (directory):
|
||||
This caches network configurations and certificate information for networks you belong to\. ZeroTier scans this directory for <network ID>\|\.conf files on startup to recall its networks, so "touch"ing an empty <network ID>\|\.conf file in this directory is a way of pre\-configuring ZeroTier to join a specific network on startup without using the API\. If the config file is empty ZeroTIer will just fetch it from the network's controller\.
|
||||
|
||||
.RE
|
||||
.SH COPYRIGHT
|
||||
.P
|
||||
(c)2011\-2016 ZeroTier, Inc\. \-\- https://www\.zerotier\.com/ \-\- https://github\.com/zerotier
|
||||
.SH SEE ALSO
|
||||
.P
|
||||
zerotier\-cli(1), zerotier\-idtool(1)
|
||||
|
||||
@@ -1,95 +0,0 @@
|
||||
zerotier-one(8) -- ZeroTier virtual network endpoint service
|
||||
============================================================
|
||||
|
||||
## SYNOPSIS
|
||||
|
||||
`zerotier-one` [-switches] [working directory]
|
||||
|
||||
## DESCRIPTION
|
||||
|
||||
**zerotier-one** is the service/daemon responsible for connecting a Unix (Linux/BSD/OSX) system to one or more ZeroTier virtual networks and presenting those networks to the system as virtual network ports. You can think of it as a peer to peer VPN client.
|
||||
|
||||
It's typically run by init systems like systemd (Linux) or launchd (Mac) rather than directly by the user, and it must be run as root unless you give it the `-U` switch and don't plan on actually joining networks (e.g. to run a network controller microservice only).
|
||||
|
||||
The **zerotier-one** service keeps its state and other files in a working directory. If this directory is not specified at launch it defaults to "/var/lib/zerotier-one" on Linux, "/Library/Application Support/ZeroTier/One" on Mac, and "/var/db/zerotier-one" on FreeBSD and other similar BSDs. The working directory should persist. It shouldn't be automatically cleaned by system cleanup daemons or stored in a volatile location. Loss of its identity.secret file results in loss of this system's unique 10-digit ZeroTier address and key.
|
||||
|
||||
Multiple instances of **zerotier-one** can be run on the same system as long as they are run with different primary ports (see switches) and a different working directory. But since a single service can join any number of networks, typically there's no point in doing this.
|
||||
|
||||
The **zerotier-one** service is controlled via a JSON API available at 127.0.0.1:<primary port> with the default primary port being 9993. Access to this API requires an authorization token normally found in the authtoken.secret file in the service's working directory. On some platforms access may be guarded by other measures such as socket peer UID/GID lookup if additional security options are enabled (this is not the default).
|
||||
|
||||
The first time the service is started in a fresh working directory, it generates a ZeroTier identity. On slow systems this process can take ten seconds or more due to an anti-DDOS/anti-counterfeit proof of work function used by ZeroTier in address generation. This only happens once, and once generated the result is saved in identity.secret in the working directory. This file represents and defines/claims your ZeroTier address and associated ECC-256 key pair.
|
||||
|
||||
## SWITCHES
|
||||
|
||||
* `-h`:
|
||||
Display help.
|
||||
|
||||
* `-v`:
|
||||
Display ZeroTier One version.
|
||||
|
||||
* `-U`:
|
||||
Skip privilege check and allow to be run by non-privileged user. This is typically used when **zerotier-one** is built with the network controller option included. In this case the ZeroTier service might only be acting as a network controller and might never actually join networks, in which case it does not require elevated system permissions.
|
||||
|
||||
* `-p<port>`:
|
||||
Specify a different primary port. If this is not given the default is 9993. If zero is given a random port is chosen each time.
|
||||
|
||||
* `-d`:
|
||||
Fork and run as a daemon.
|
||||
|
||||
* `-i`:
|
||||
Invoke the **zerotier-idtool** personality, in which case the binary behaves like zerotier-idtool(1). This happens automatically if the name of the binary (or a symlink to it) is zerotier-idtool.
|
||||
|
||||
* `-q`:
|
||||
Invoke the **zerotier-cli** personality, in which case the binary behaves like zerotier-cli(1). This happens automatically if the name of the binary (or a symlink to it) is zerotier-cli.
|
||||
|
||||
## EXAMPLES
|
||||
|
||||
Run as daemon with OS default working directory and default port:
|
||||
|
||||
$ sudo zerotier-one -d
|
||||
|
||||
Run as daemon with a different working directory and port:
|
||||
|
||||
$ sudo zerotier-one -d -p12345 /tmp/zerotier-working-directory-test
|
||||
|
||||
## FILES
|
||||
|
||||
These are found in the service's working directory.
|
||||
|
||||
* `identity.public`:
|
||||
The public portion of your ZeroTier identity, which is your 10-digit hex address and the associated public key.
|
||||
|
||||
* `identity.secret`:
|
||||
Your full ZeroTier identity including its private key. This file identifies the system on the network, which means you can move a ZeroTier address around by copying this file and you should back up this file if you want to save your system's static ZeroTier address. This file must be protected, since theft of its secret key will allow anyone to impersonate your device on any network and decrypt traffic. For network controllers this file is particularly sensitive since it constitutes the private key for a certificate authority for the controller's networks.
|
||||
|
||||
* `authtoken.secret`:
|
||||
The secret token used to authenticate requests to the service's local JSON API. If it does not exist it is generated from a secure random source on service start. To use, send it in the "X-ZT1-Auth" header with HTTP requests to 127.0.0.1:<primary port>.
|
||||
|
||||
* `devicemap`:
|
||||
Remembers mappings of zt# interface numbers to ZeroTier networks so they'll persist across restarts. On some systems that support longer interface names that can encode the network ID (such as FreeBSD) this file may not be present.
|
||||
|
||||
* `zerotier-one.pid`:
|
||||
ZeroTier's PID. This file is deleted on normal shutdown.
|
||||
|
||||
* `zerotier-one.port`:
|
||||
ZeroTier's primary port, which is also where its JSON API is found at 127.0.0.1:<this port>. This file is created on startup and is read by zerotier-cli(1) to determine where it should find the control API.
|
||||
|
||||
* `controller.db`:
|
||||
If the ZeroTier One service is built with the network controller enabled, this file contains the controller's SQLite3 database.
|
||||
|
||||
* `controller.db.backup`:
|
||||
If the ZeroTier One service is built with the network controller enabled, it periodically backs up its controller.db database in this file (currently every 5 minutes if there have been changes). Since this file is not a currently in use SQLite3 database it's safer to back up without corruption. On new backups the file is rotated out rather than being rewritten in place.
|
||||
|
||||
* `iddb.d/` (directory):
|
||||
Caches the public identity of every peer ZeroTier has spoken with in the last 60 days. This directory and its contents can be deleted, but this may result in slower connection initiations since it will require that we go out and re-fetch full identities for peers we're speaking to.
|
||||
|
||||
* `networks.d` (directory):
|
||||
This caches network configurations and certificate information for networks you belong to. ZeroTier scans this directory for <network ID>.conf files on startup to recall its networks, so "touch"ing an empty <network ID>.conf file in this directory is a way of pre-configuring ZeroTier to join a specific network on startup without using the API. If the config file is empty ZeroTIer will just fetch it from the network's controller.
|
||||
|
||||
## COPYRIGHT
|
||||
|
||||
(c)2011-2016 ZeroTier, Inc. -- https://www.zerotier.com/ -- https://github.com/zerotier
|
||||
|
||||
## SEE ALSO
|
||||
|
||||
zerotier-cli(1), zerotier-idtool(1)
|
||||
@@ -0,0 +1,438 @@
|
||||
# BackOne PQC End-to-End Test Scenario
|
||||
|
||||
Version: 2.0.0 · Scope: verify the hybrid post-quantum stack (ML-KEM-768 + ML-DSA-65)
|
||||
actually does what SPEC §G claims, on the wire — not just in unit tests.
|
||||
|
||||
Every offset, constant, and gap below was read from this tree at the cited line.
|
||||
`[INFERENCE]` marks anything not directly observed.
|
||||
|
||||
---
|
||||
|
||||
## 0. Read this first — status of the three gaps
|
||||
|
||||
**Status (2026-10-02): G1–G3 fixed; G1 also fixed at the root by B2.**
|
||||
Generation runs under the configured mode (`Node` takes `pqcMode`, `OneService`
|
||||
refuses a classic↔PQ identity mismatch), the wire negotiates hybrid, and the
|
||||
capability bit is consumed (`Peer::hybridEligible()`). **Modes are opt-in:**
|
||||
absent/unknown `settings.pqcMode` resolves to classic (`ZT_PQC_MODE_CLASSIC`),
|
||||
so an upgraded type-0 install boots unchanged and keeps its address — see the
|
||||
`B2` fix in `SPEC.md` §B. Verified live on a 2.0.0 build: no config → 141 B
|
||||
type-0 identity; `"hybrid"` → 6415 B type-1 identity; classic identity +
|
||||
`"hybrid"` refuses to start. Re-run §4/§5 to confirm the 1088 B ML-KEM
|
||||
ciphertext and a hybrid `_key` on the wire. The table below is the original
|
||||
2.0.0 diagnosis, kept for the rationale and the exact evidence.
|
||||
|
||||
| # | Gap | Evidence | Symptom in the lab |
|
||||
|---|---|---|---|
|
||||
| G1 | Daemon never generates a type-1 identity. `Node.cpp:96` calls `RR->identity.generate()` with default `pq=false`, and `applyLocalConfig()` (which sets the mode) runs *after* `new Node(...)` (`OneService.cpp:1058` then `1062`). | **Fixed (T24 + B2):** `OneService` reads `local.conf` before `new Node` and passes `pqcMode`; `Identity::generate` takes it. Absent config is now classic, not hybrid. `node/Node.cpp:96`, `node/Identity.cpp:84-123`, `service/OneService.cpp` `_pqcModeFromLocalConfig`. | `"pqcMode":"hybrid"` now writes type byte `1`; measured `identity.public` = 6415 B vs 141 B classic (the old doc estimate of ~4230 B was the research-doc approximation) |
|
||||
| G2 | Wire key agreement never used PQ. `myIdentity.agree(peerIdentity,…)` is plain C25519 (`Identity.hpp:343-350`). | **Fixed (B1):** production now calls `agreeHybridEncaps`/`agreeHybridDecaps` — `node/Peer.cpp:113` (encaps on first capability sighting) and `node/IncomingPacket.cpp:538,700` (decaps on HELLO and OK(HELLO)); `setHybridSessionKey` replaces the classical key. | Session key is hybrid when both peers advertise the capability; a vanilla peer still falls back to classical |
|
||||
| G3 | Capability was advertised but never consumed: `Peer::_key` was derived in the constructor before any HELLO arrived, so the hybrid path was dead. | **Fixed (B1):** `Peer::hybridEligible()` now gates `_hybridCapable` (set in `setRemoteVersion`), the KEM ct rides in HELLO/OK(HELLO), and `setHybridSessionKey()` replaces the session key. `Peer::pqcCapability()` was removed as redundant. | Capture now shows a 1088 B ct after the capability bit |
|
||||
|
||||
Consequence: **the only end-to-end proof so far is `backone-selftest`** (ML-KEM KAT,
|
||||
ML-DSA KAT, hybrid KDF vector, identity-v2 roundtrip, COM double-sign, HELLO
|
||||
fragmentation). Those pass. They prove primitives and encodings, not a live handshake.
|
||||
|
||||
---
|
||||
|
||||
## 1. Measured baseline (this build, this host)
|
||||
|
||||
```
|
||||
make selftest && ./backone-selftest # exit 0
|
||||
[PQ] ML-KEM KAT (decaps fixed sk/ct -> ss)... PASS
|
||||
[PQ] ML-DSA KAT (verify fixed pk/msg/sig; tamper fails)... PASS
|
||||
[PQ] Hybrid KDF known-answer vector... PASS
|
||||
[PQ] Interop hybrid<->vanilla matrix... PASS
|
||||
size classic=137B/1 frag, PQC=3273B/3 frag (max 7)
|
||||
```
|
||||
|
||||
`backone-cli info -j` → `"version":"2.0.0"`. Lab daemons answered on
|
||||
`127.0.0.1:20001` / `:20002` with `{"version":"2.0.0","online":true}`.
|
||||
|
||||
Fragmentation ceiling: `ZT_MAX_PACKET_FRAGMENTS 7` × `ZT_DEFAULT_PHYSMTU 1432`
|
||||
(`node/Packet.hpp:235`, `include/ZeroTierOne.h:101`) = 10024 B max reassembled
|
||||
packet. `pqconly` (ML-KEM-1024 + ML-DSA-87) grows the HELLO well past that —
|
||||
see §4.3.
|
||||
|
||||
---
|
||||
|
||||
## 2. Wire facts (cite these in tshark filters)
|
||||
|
||||
WU = wire units = **Appendix A of RFC 7042** packet-diagram notation (1 byte = 1 column).
|
||||
|
||||
### 2.1 Packet header — `node/Packet.hpp:224-230`
|
||||
|
||||
| WU | Field |
|
||||
|---|---|
|
||||
| 0–7 | Packet ID / IV (8 B) |
|
||||
| 8–12 | Destination address (5 B) |
|
||||
| 13–17 | Source address (5 B) |
|
||||
| 18 | Flags |
|
||||
| 19–26 | MAC |
|
||||
| 27 | Verb |
|
||||
| 28… | Payload |
|
||||
|
||||
Flags: `ZT_PROTO_FLAG_ENCRYPTED 0x80`, `ZT_PROTO_FLAG_FRAGMENTED 0x40`
|
||||
(`node/Packet.hpp:130-134`). Fragment header (`Packet.hpp:242-248`):
|
||||
`PACKET_ID@0`, `DEST@8`, `FRAGMENT_INDICATOR@13`, `FRAGMENT_NO@14`, `HOPS@15`,
|
||||
`PAYLOAD@16` — so a fragment's payload starts at overall offset **44**.
|
||||
|
||||
### 2.2 VERB_HELLO payload — sender `node/Peer.cpp:418-445`, offsets `node/Packet.hpp:266-271`
|
||||
|
||||
| Offset rel. payload (wire = +28) | WU | Field |
|
||||
|---|---|---|
|
||||
| 0 | 0 | Protocol version = 12 (`ZT_PROTO_VERSION`) |
|
||||
| 1 | 1 | Major |
|
||||
| 2 | 2 | Minor |
|
||||
| 3–4 | 3 | Revision `uint16`, **high bit 0x8000 = PQC capability** (`Packet.hpp:273`); masked off by `remoteVersionRevision()` (`Peer.hpp:381`) |
|
||||
| 5–12 | 5 | Timestamp (i64) |
|
||||
| 13… | 13 | Identity, serialized `includePrivate=false` |
|
||||
| … | | InetAddress (sender's observation of us) |
|
||||
| … | | worldId u64, worldTimestamp u64, moons… |
|
||||
|
||||
Identity binary, public form — `node/Identity.hpp:421-445`, `node/InetAddress.hpp:557-577`:
|
||||
|
||||
| Bytes | Field |
|
||||
|---|---|
|
||||
| 5 | Address |
|
||||
| 1 | Type: `0` = C25519, `1` = PQ hybrid (`Identity.hpp:36-37`) |
|
||||
| 32 | X25519/Ed25519 public |
|
||||
| 1 | private-key length (`0` when public-only) |
|
||||
| 1184 | ML-KEM-768 public (type 1 only) |
|
||||
| 1952 | ML-DSA-65 public (type 1 only) |
|
||||
|
||||
Identity public = 39 B classic, 3175 B type 1 (the selftest prints 137 B / 3273 B
|
||||
for the packet because the cleartext+MAC framing must stay under the fragment
|
||||
payload; treat the selftest numbers as authoritative for sizing, these offsets for
|
||||
parsing).
|
||||
|
||||
### 2.3 HELLO is authenticated, not encrypted — `node/Peer.cpp:444-451`
|
||||
|
||||
`outp.armor(_key,false,nullptr)` — MAC only, payload in the clear. That is what
|
||||
lets §3 decode the identity in tshark.
|
||||
|
||||
### 2.4 COM double-signature — `node/CertificateOfMembership.hpp`
|
||||
|
||||
type byte `1` = Ed25519 only, `2` = Ed25519 + ML-DSA-65 appended.
|
||||
`MLDSA65_SIG_LEN = 3309`. Do **not** hand-parse COM in Lua (variable-length
|
||||
qualifiers 24 B each); assert via `backone-idtool` / selftest instead (§3.3).
|
||||
|
||||
---
|
||||
|
||||
## 3. Layer A — offline encode/decode verification
|
||||
|
||||
Run these before any networking. They isolate `[INFERENCE]` risk: every byte of a
|
||||
hybrid identity and COM is accounted for.
|
||||
|
||||
### 3.1 Identity type + size
|
||||
|
||||
```
|
||||
backone-idtool generate /tmp/i.secret /tmp/i.public
|
||||
cut -d: -f2 /tmp/i.public # expect: 0 (classic) -> see G1: idtool is classic-only today
|
||||
wc -c /tmp/i.public # classic: 141 B (ASCII)
|
||||
```
|
||||
- Expected FAIL as product behavior: idtool `generate` never gained the §7 G1
|
||||
fix (daemon-side only), so its output stays classic — record it; do not "fix"
|
||||
the test.
|
||||
|
||||
### 3.2 Packet codec roundtrip
|
||||
|
||||
`./backone-selftest` covers it (`[packet] Testing Packet encoder/decoder... PASS`).
|
||||
No new test needed.
|
||||
|
||||
### 3.3 COM type 2
|
||||
|
||||
Covered by `[certificate] PQ authority double-signs COM (type 2)... PASS` and
|
||||
`[certificate] Double-signature verifies under both algorithms... PASS`.
|
||||
For wire capture, just assert type byte `== 2` on the first COM frame in the
|
||||
`VERB_NETWORK_CONFIG` reply — nothing more.
|
||||
|
||||
---
|
||||
|
||||
## 4. Layer B — live handshake lab
|
||||
|
||||
### 4.1 Prerequisites
|
||||
|
||||
- Linux host, **root**. Verified in this session: `sudo -n` works; the §5 recipe
|
||||
ran end-to-end — both netns came up, TAP was created, and the controller
|
||||
issued an `nwid`, but the direct paths never became active in the window
|
||||
(see §5 for the observed values).
|
||||
- `tshark` >= 4.x with Lua (verified 4.6.4 / Lua 5.4.8). It refuses to load
|
||||
`lua_script` under its own privilege drop, so dissect as root or from a `0644`
|
||||
script path; capture with `dumpcap` (root) to avoid the same gate.
|
||||
- Two state dirs, one `local.conf` each. Mode is set **only** through
|
||||
`settings.pqcMode`; absent or unknown values mean classic, so the lab must set
|
||||
`"hybrid"` explicitly (`service/OneService.cpp` `_pqcModeFromLocalConfig`).
|
||||
- Network ID must start with the controller node's 10-hex address, else the
|
||||
controller rejects the create. The `______` suffix form auto-fills it:
|
||||
`POST /controller/network/<ctladdr>______`.
|
||||
|
||||
### 4.2 Topology — hermetic, no roots, no WAN
|
||||
|
||||
Internet roots make a "hybrid works over the internet" test unfalsifiable (the lab
|
||||
is online and the control plane is local). Isolate:
|
||||
|
||||
```sh
|
||||
ip netns add n1; ip netns add n2
|
||||
ip link add v1 type veth peer name v2
|
||||
ip link set v1 netns n1; ip link set v2 netns n2
|
||||
ip -n n1 addr add 172.30.0.1/24 dev v1; ip -n n1 link set v1 up; ip -n n1 link set lo up
|
||||
ip -n n2 addr add 172.30.0.2/24 dev v2; ip -n n2 link set v2 up; ip -n n2 link set lo up
|
||||
# kill WAN inside the namespaces; TAP + local controller survive
|
||||
ip netns exec n1 ip route add 169.254.0.0/16 dev v1 # keep ZT_UNICAST/roots unreachable -> see next box
|
||||
```
|
||||
|
||||
**Problem:** a hermetic pair has no planet/root to discover peers, so no direct
|
||||
path forms. **There is no `/peer` POST route in this tree** — `peerPath` is
|
||||
registered `GET`-only (`service/OneService.cpp:2176-2177`); `service/README.md:172`
|
||||
says "Get or set" but the daemon implements get only. The supported mechanism is
|
||||
the `virtual.<10hex>.try` hint (`service/OneService.cpp:2434`, `README.md:27`):
|
||||
|
||||
```sh
|
||||
# phase 1: start once to mint identities, read $N1/$N2 from identity.public, stop
|
||||
printf '{"settings":{"pqcMode":"hybrid"},"virtual":{"%s":{"try":["172.30.0.1/19993"]}}}' "$N1" > n2/local.conf
|
||||
printf '{"settings":{"pqcMode":"hybrid"},"virtual":{"%s":{"try":["172.30.0.2/19993"]}}}' "$N2" > n1/local.conf
|
||||
# phase 2: restart; each side now sends HELLO to the other's veth address
|
||||
```
|
||||
|
||||
Two-phase (identity first, then hint+restart) because `$N1` must exist before the
|
||||
other side's `local.conf` can name it. Fallback if `try` ever stops working: a
|
||||
local moon (`backone-idtool initmoon` + `genmoon`), heavier.
|
||||
|
||||
Both nodes must also be **authorized on their respective controllers**: with a
|
||||
single embedded controller on n1, n1 is the controller *and* a member — POST
|
||||
`{"authorized":true}` for `$N1` too, or n1 sits at `ACCESS_DENIED`
|
||||
(`Network.cpp:1517`, observed live). A joined, authorized pair still stays
|
||||
`REQUESTING_CONFIGURATION` and sends no HELLO on its own: the `try` hint is
|
||||
consulted *only* from `nodePathLookupFunction` (`OneService.cpp:3771`), i.e. when
|
||||
something already wants to reach that peer. Drive it with one packet from inside
|
||||
the ZT interface (or a second real peer); a single veth pair to a WAN-less world
|
||||
does not self-start.
|
||||
|
||||
### 4.3 Capture + dissection
|
||||
|
||||
On the host (both namespaces visible via veth) or inside `n2`:
|
||||
|
||||
```sh
|
||||
ip netns exec n2 tcpdump -i v2 -w /tmp/pqc.pcap 'udp port 9993'
|
||||
```
|
||||
|
||||
Load the Lua dissector (§Appendix) in Wireshark/tshark v4.x:
|
||||
`tshark -X lua_script:tools/zt-dissector.lua -r /tmp/pqc.pcap -Y zt.hello`
|
||||
|
||||
Filters to run:
|
||||
|
||||
```
|
||||
zt # any BackOne frame
|
||||
zt.verb == 1 # VERB_HELLO (`Packet.hpp:592`)
|
||||
zt.hello.cap # capability bit set on the hybrid node
|
||||
zt.frag # fragment header present
|
||||
```
|
||||
|
||||
Verified against the Lua dissector in this session (tshark 4.6.4): those four
|
||||
filters parse; `zt.hello.cap == 1` and `zt.hello.idtype == 1` both work.
|
||||
`tshark -X lua_script:` loads user Lua scripts; when run as **superuser, Wireshark
|
||||
silently skips them** (scripts under a privileged profile are not executed) — run
|
||||
tshark as your normal user, or copy the script to a `0644` path readable by it.
|
||||
The capture file must also be readable by the tshark process (AppArmor may deny
|
||||
root reads of `/tmp` paths written by the user).
|
||||
|
||||
**Capture reality check (observed):** a veth inside a namespace sees a frame only
|
||||
if it is delivered to that side. Plain unicast UDP from n2→n1 is *not* visible on
|
||||
n1's `vA` capture, and an idle pair sends nothing at all (no HELLO timer of its
|
||||
own). Treat "0 captured frames" as "no handshake was triggered", not as a parsing
|
||||
bug — see §4.5 trigger.
|
||||
|
||||
### 4.4 Test matrix
|
||||
|
||||
| # | n1 mode | n2 mode | Expect today (2.0.0) | Expect after §7 fix | Observable |
|
||||
|---|---|---|---|---|---|
|
||||
| M1 | off | off | HELLO 137 B / 1 frag, cap=0, session classic | same | `zt.hello.cap==0`, 1 frag |
|
||||
| M2 | hybrid | off | HELLO 3273 B / 3 frags, cap=1; **session still classic (G2)** | session = hybrid KDF | 3 frags + no ML-KEM ciphertext today |
|
||||
| M3 | hybrid | hybrid | 3 frags both, cap=1 both; **still classic (G2/G3)** | ML-KEM-768 ct on wire, hybrid `_key` | after fix: ct len = 1088 |
|
||||
| M4 | pqconly | pqconly | **HELLO > 10024 B → cannot fragment** (`Packet.hpp:235`) | sized/capped or rejected cleanly | packet count / link never comes up |
|
||||
| M5 | pqconly | off | must fall back classic (capability bit is the gate) | explicit downgrade recorded | no crash; classic session |
|
||||
|
||||
|
||||
**Observed 2026-10-02** (`sudo tools/pqc-lab.sh`): M1-M5 all pass. The
|
||||
"after §7 fix" column is the live one: M3/M4 put large ML-KEM datagrams on
|
||||
the wire (68 / 90 frames > 1200 B), no fragment failure observed.
|
||||
|
||||
M4 is the interesting negative: ML-KEM-1024 ct = 1568 B and ML-DSA-87 pk = 2592 B
|
||||
(`[INFERENCE]` on exact liboqs sizes — confirm against `node/PQHybrid.hpp`
|
||||
constants) push a `pqconly` HELLO to ~8 KiB, past the reassembly ceiling. Assert
|
||||
the graceful failure, whichever behavior the fix chooses.
|
||||
|
||||
### 4.5 Negative — tamper the handshake
|
||||
|
||||
Inject one flipped byte of the ML-KEM ciphertext once M3 carries one (after §7):
|
||||
|
||||
```sh
|
||||
tc qdisc add dev v2 root netem corrupt 0.1%
|
||||
```
|
||||
Expect: handshake fails, peer marked dead, **no crash, no partial key**. Then:
|
||||
|
||||
```sh
|
||||
tc qdisc add dev v2 root netem loss 30%
|
||||
```
|
||||
Expect: HELLO retransmits (V15 benchmark says loss delays but does not break the
|
||||
handshake); link recovers when loss stops.
|
||||
|
||||
### 4.6 Data plane (after M3 session is genuinely hybrid)
|
||||
|
||||
Pass traffic and byte-verify it is untouched, then assert the **key is hybrid**
|
||||
is not directly observable from a capture (it is keyed off-wire) — this is why the
|
||||
classification below is required.
|
||||
|
||||
```sh
|
||||
# inside n1/n2, over the ZT interface (10.99.0.x from the ipAssignmentPool)
|
||||
iperf3 -s -B 10.99.0.2 &
|
||||
iperf3 -c 10.99.0.2 -t 30
|
||||
```
|
||||
|
||||
Negative: drop every fragment whose `FRAGMENT_NO & 1` is set at 100 % and confirm
|
||||
a large `pqconly` HELLO cannot complete — proves fragmentation is load-bearing.
|
||||
|
||||
---
|
||||
|
||||
## 5. Exact lab recipe (control plane proven in this session)
|
||||
|
||||
Two-phase, two netns, one veth pair. `sudo -n` verified working in this session.
|
||||
|
||||
```sh
|
||||
B=./backone; PP=19993; LAB=/tmp/pqcnet
|
||||
ip netns add pn1; ip netns add pn2
|
||||
ip link add vA type veth peer name vB; ip link set vA netns pn1; ip link set vB netns pn2
|
||||
ip -n pn1 addr add 172.30.0.1/24 dev vA; ip -n pn1 link set vA up; ip -n pn1 link set lo up
|
||||
ip -n pn2 addr add 172.30.0.2/24 dev vB; ip -n pn2 link set vB up; ip -n pn2 link set lo up
|
||||
|
||||
# phase 1: mint identities, then stop
|
||||
printf '{"settings":{"pqcMode":"hybrid"}}' > $LAB/n1/local.conf
|
||||
printf '{"settings":{"pqcMode":"hybrid"}}' > $LAB/n2/local.conf
|
||||
ip netns exec pn1 $B -U -p$PP $LAB/n1 >$LAB/n1/log 2>&1 & P1=$!
|
||||
ip netns exec pn2 $B -U -p$PP $LAB/n2 >$LAB/n2/log 2>&1 & P2=$!
|
||||
sleep 6; kill $P1 $P2; sleep 2
|
||||
N1=$(cut -d: -f1 $LAB/n1/identity.public); N2=$(cut -d: -f1 $LAB/n2/identity.public)
|
||||
echo "types: n1=$(cut -d: -f2 $LAB/n1/identity.public) n2=$(cut -d: -f2 $LAB/n2/identity.public)" # G1 check
|
||||
|
||||
# phase 2: point each side at the other, restart
|
||||
printf '{"settings":{"pqcMode":"hybrid"},"virtual":{"%s":{"try":["172.30.0.1/19993"]}}}' "$N1" > $LAB/n2/local.conf
|
||||
printf '{"settings":{"pqcMode":"hybrid"},"virtual":{"%s":{"try":["172.30.0.2/19993"]}}}' "$N2" > $LAB/n1/local.conf
|
||||
ip netns exec pn1 $B -U -p$PP $LAB/n1 >>$LAB/n1/log 2>&1 & P1=$!
|
||||
ip netns exec pn2 $B -U -p$PP $LAB/n2 >>$LAB/n2/log 2>&1 & P2=$!
|
||||
sleep 6
|
||||
A1=$(cat $LAB/n1/authtoken.secret); A2=$(cat $LAB/n2/authtoken.secret)
|
||||
|
||||
NW=$(ip netns exec pn1 curl -s -H "X-ZT1-Auth: $A1" -X POST \
|
||||
-d '{"name":"pqclab","v4AssignMode":{"zt":true},"ipAssignmentPools":[{"ipRangeStart":"10.99.0.1","ipRangeEnd":"10.99.0.254"}]}' \
|
||||
"http://127.0.0.1:$PP/controller/network/${N1}______" | python3 -c 'import json,sys;print(json.load(sys.stdin)["nwid"])')
|
||||
|
||||
# authorize BOTH (n1 is controller and member). Trailing slash silently no-ops.
|
||||
for M in $N1 $N2; do
|
||||
ip netns exec pn1 curl -s -H "X-ZT1-Auth: $A1" -X POST -d '{"authorized":true}' \
|
||||
"http://127.0.0.1:$PP/controller/network/$NW/member/$M" >/dev/null
|
||||
done
|
||||
ip netns exec pn1 curl -s -H "X-ZT1-Auth: $A1" -X POST "http://127.0.0.1:$PP/network/$NW" >/dev/null
|
||||
ip netns exec pn2 curl -s -H "X-ZT1-Auth: $A2" -X POST "http://127.0.0.1:$PP/network/$NW" >/dev/null
|
||||
sleep 10
|
||||
ip netns exec pn1 curl -s -H "X-ZT1-Auth: $A1" "http://127.0.0.1:$PP/network/$NW" # expect populated + TAP name
|
||||
```
|
||||
|
||||
Capture on the veth, then trigger a handshake from inside the ZT interface (the
|
||||
`try` hint is only consulted once a path is already wanted — §4.2):
|
||||
|
||||
```sh
|
||||
ip netns exec pn1 timeout 45 tcpdump -i vA -w $LAB/n1.pcap 'udp port 19993' &
|
||||
ip netns exec pn2 timeout 45 tcpdump -i vB -w $LAB/n2.pcap 'udp port 19993' &
|
||||
# trigger (needs the interface to be up with an assigned address):
|
||||
ip netns exec pn1 ping -c3 -W2 10.99.0.2
|
||||
```
|
||||
|
||||
Observed in this session with root (`sudo -n`): both daemons started in their
|
||||
netns, `POST /controller/network/<N1>______` returned a controller-addressed
|
||||
`nwid` (`7a8cc27d26b48a2f`), TAP `zta6vhn5yj` was created, and `/network/$NW`
|
||||
returned the populated object. **G1 reproduced live at the time:** `identity.public`
|
||||
type byte was `0` on both nodes despite `"pqcMode":"hybrid"` (that was pre-`T24`/`B2`;
|
||||
the same config now yields type byte `1`). Peer lists showed only
|
||||
the four planet roots (no direct peer) and the paths never became active within
|
||||
the window — consistent with "hint alone does not trigger a HELLO".
|
||||
|
||||
---
|
||||
|
||||
## 6. Classification rule (make every check decidable)
|
||||
|
||||
A check may only be counted as "PQC verified" if a **classical-only** build/peer
|
||||
would produce a *different observable*:
|
||||
|
||||
| Observable | Classical | Hybrid | Decidable? |
|
||||
|---|---|---|---|
|
||||
| HELLO size / fragment count | 137 B / 1 | 3273 B / 3 | yes |
|
||||
| HELLO capability bit | 0 | 1 | yes |
|
||||
| ML-KEM ciphertext bytes on wire | none | 1088 B | yes, **only after §7** |
|
||||
| Identity type byte | 0 | 1 | yes |
|
||||
| COM type byte | 1 | 2 | yes |
|
||||
| `_key` value | n/a off-wire | n/a off-wire | **no** — must be inferred from the above |
|
||||
|
||||
Nothing about the negotiated symmetric key is directly observable. A test that
|
||||
only does "ping works" passes trivially under M2 (classical fallback) and must not
|
||||
be counted.
|
||||
|
||||
---
|
||||
|
||||
## 7. Fix list (original 2.0.0 diagnosis — all five applied 2026-10-02)
|
||||
|
||||
1. **Generate type-1 identities when configured.** Pass the mode into generation:
|
||||
`RR->identity.generate(pqcMode == ZT_PQC_MODE_PQCONLY, pqcMode)`, or set the mode
|
||||
before `new Node(...)`. `Node::generate` already threads `pqcMode` through
|
||||
(`Identity.cpp:103-111`) — only the caller is wrong. Handle the migration case:
|
||||
an existing type-0 `identity.secret` under `pqcMode=hybrid` should either
|
||||
upgrade (new address, collateral damage) or refuse loudly. Pick loudly.
|
||||
2. **Use hybrid agreement on the wire.** `Peer.cpp:63` / `IncomingPacket.cpp:415`
|
||||
must consult the capability bit and call `agreeHybridEncaps` / `agreeHybridDecaps`
|
||||
when both sides are type 1 and `pqcMode != off`, falling back to `agree()` on a
|
||||
type-0 peer. The static-static design (KDF(classical ‖ ML-KEM-encaps to peer
|
||||
*static* pub)) means the ciphertext must ride **in HELLO** or an immediate
|
||||
follow-up verb — decide which, and bump `ZT_PROTO_VERSION` if the HELLO layout
|
||||
changes.
|
||||
3. **Consume the capability decision in key derivation.** Done: `hybridEligible()`
|
||||
replaces the constructor-time `_key`, and `ensurePendingHybridCt()`/`setHybridSessionKey()`
|
||||
rekey once HELLO discloses capability.
|
||||
4. **Bound `pqconly` HELLO** against `ZT_MAX_PACKET_FRAGMENTS * ZT_DEFAULT_PHYSMTU`
|
||||
(10024 B) and fail cleanly with a visible reason rather than a silent no-link.
|
||||
5. **Delete the false confidence**: `SPEC.md` §V listed phase invariants with no
|
||||
wire evidence. **Applied as V16** (`SPEC.md` §V): the hybrid row carried `?`
|
||||
until M3 showed the ciphertext — cleared 2026-10-02 after the lab run.
|
||||
`SPEC.md` §B B1 records the silent-fallback defect.
|
||||
|
||||
All five are in the tree; the §5 lab ran 2026-10-02 and M1–M5 all pass
|
||||
(`tools/pqc-lab.sh`), with large ML-KEM datagrams on the wire in every
|
||||
pairing where both sides are non-off (M3: 68, M4: 90 frames > 1200 B).
|
||||
|
||||
---
|
||||
|
||||
## 8. Quick reference
|
||||
|
||||
```sh
|
||||
make selftest && ./backone-selftest # primitives + fragmentation (passes now)
|
||||
backone-cli -p<port> -D<home> info -j # version must read 2.0.0
|
||||
tshark -X lua_script:tools/zt-dissector.lua -r pqc.pcap -Y 'zt'
|
||||
```
|
||||
|
||||
PoC orchestrator: `tools/pqc-lab.sh` (control plane + capture + asserts; needs root).
|
||||
|
||||
---
|
||||
|
||||
## Appendix — Wireshark Lua dissector
|
||||
|
||||
The dissector lives in `tools/zt-dissector.lua` — single source of truth. (The
|
||||
copy once embedded here drifted: wrong HELLO verb, wrong identity size, and a
|
||||
registration that ignored the lab port.)
|
||||
|
||||
```sh
|
||||
tshark -X lua_script:tools/zt-dissector.lua -r /tmp/pqc.pcap -Y 'zt.verb == 1'
|
||||
```
|
||||
|
||||
Verified against a synthetic capture (tshark 4.6.4): classic HELLO decodes as
|
||||
`type=0`, 39 B identity; a fragmented hybrid HELLO's head fragment decodes as
|
||||
`type=1`, 3175 B identity, `zt.hello.cap == 1`, and its tail frames as
|
||||
`BackOne fragment n/3`. Run tshark as your normal user — as superuser Wireshark
|
||||
silently skips user Lua scripts (see §4.3).
|
||||
+12
-12
@@ -1,7 +1,7 @@
|
||||
#!/bin/sh
|
||||
|
||||
grepzt() {
|
||||
[ -f /var/lib/zerotier-one/zerotier-one.pid -a -n "$(cat /var/lib/zerotier-one/zerotier-one.pid 2>/dev/null)" -a -d "/proc/$(cat /var/lib/zerotier-one/zerotier-one.pid 2>/dev/null)" ]
|
||||
[ -f "$ZEROTIER_HOME/$ZT_PID_FILE" -a -n "$(cat "$ZEROTIER_HOME/$ZT_PID_FILE" 2>/dev/null)" -a -d "/proc/$(cat "$ZEROTIER_HOME/$ZT_PID_FILE" 2>/dev/null)" ]
|
||||
return $?
|
||||
}
|
||||
|
||||
@@ -10,9 +10,9 @@ mkztfile() {
|
||||
mode=$2
|
||||
content=$3
|
||||
|
||||
mkdir -p /var/lib/zerotier-one
|
||||
echo "$content" > "/var/lib/zerotier-one/$file"
|
||||
chmod "$mode" "/var/lib/zerotier-one/$file"
|
||||
mkdir -p "$ZEROTIER_HOME"
|
||||
echo "$content" > "$ZEROTIER_HOME/$file"
|
||||
chmod "$mode" "$ZEROTIER_HOME/$file"
|
||||
}
|
||||
|
||||
if [ "x$ZEROTIER_API_SECRET" != "x" ]
|
||||
@@ -30,11 +30,11 @@ then
|
||||
mkztfile identity.secret 0600 "$ZEROTIER_IDENTITY_SECRET"
|
||||
fi
|
||||
|
||||
mkztfile zerotier-one.port 0600 "9993"
|
||||
mkztfile "$ZT_PORT_FILE" 0600 "9993"
|
||||
|
||||
killzerotier() {
|
||||
log "Killing zerotier"
|
||||
kill $(cat /var/lib/zerotier-one/zerotier-one.pid 2>/dev/null)
|
||||
kill $(cat "$ZEROTIER_HOME/$ZT_PID_FILE" 2>/dev/null)
|
||||
exit 0
|
||||
}
|
||||
|
||||
@@ -69,13 +69,13 @@ log_detail_params() {
|
||||
trap killzerotier INT TERM
|
||||
|
||||
log "Configuring networks to join"
|
||||
mkdir -p /var/lib/zerotier-one/networks.d
|
||||
mkdir -p "$ZEROTIER_HOME/networks.d"
|
||||
|
||||
log_params "Joining networks from command line:" $@
|
||||
for i in "$@"
|
||||
do
|
||||
log_detail_params "Configuring join:" "$i"
|
||||
touch "/var/lib/zerotier-one/networks.d/${i}.conf"
|
||||
touch "$ZEROTIER_HOME/networks.d/${i}.conf"
|
||||
done
|
||||
|
||||
if [ "x$ZEROTIER_JOIN_NETWORKS" != "x" ]
|
||||
@@ -84,12 +84,12 @@ then
|
||||
for i in $ZEROTIER_JOIN_NETWORKS
|
||||
do
|
||||
log_detail_params "Configuring join:" "$i"
|
||||
touch "/var/lib/zerotier-one/networks.d/${i}.conf"
|
||||
touch "$ZEROTIER_HOME/networks.d/${i}.conf"
|
||||
done
|
||||
fi
|
||||
|
||||
log "Starting ZeroTier"
|
||||
nohup /usr/sbin/zerotier-one &
|
||||
nohup "$ZT_DAEMON" &
|
||||
|
||||
while ! grepzt
|
||||
do
|
||||
@@ -109,13 +109,13 @@ cat >/healthcheck.sh <<EOF
|
||||
#!/bin/bash
|
||||
for i in $@ $ZEROTIER_JOIN_NETWORKS
|
||||
do
|
||||
[ "\$(zerotier-cli get \$i status)" = "OK" ] || exit 1
|
||||
[ "\$($ZT_CLI get \$i status)" = "OK" ] || exit 1
|
||||
done
|
||||
EOF
|
||||
|
||||
chmod +x /healthcheck.sh
|
||||
|
||||
log_params "zerotier-cli info:" "$(zerotier-cli info)"
|
||||
log_params "$ZT_CLI info:" "$($ZT_CLI info)"
|
||||
|
||||
log "Sleeping infinitely"
|
||||
while true
|
||||
|
||||
Executable
+138
@@ -0,0 +1,138 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# backone Start the BackOne network virtualization service
|
||||
#
|
||||
# chkconfig: 2345 55 25
|
||||
# description: BackOne allows systems to join and participate in \
|
||||
# ZeroTier virtual networks. See https://www.zerotier.com/
|
||||
#
|
||||
# processname: backone
|
||||
# config: /var/lib/backone/identity.public
|
||||
# config: /var/lib/backone/identity.secret
|
||||
# config: /var/lib/backone/local.conf
|
||||
# config: /var/lib/backone/authtoken.secret
|
||||
# pidfile: /var/lib/backone/backone.pid
|
||||
|
||||
### BEGIN INIT INFO
|
||||
# Provides: backone
|
||||
# Required-Start: $local_fs $network $syslog
|
||||
# Required-Stop: $local_fs $syslog
|
||||
# Should-Start: $syslog
|
||||
# Should-Stop: $network $syslog
|
||||
# Default-Start: 2 3 4 5
|
||||
# Default-Stop: 0 1 6
|
||||
# Short-Description: Start the BackOne network virtualization service
|
||||
# Description: BackOne allows systems to join and participate in
|
||||
# ZeroTier virtual networks. See https://www.zerotier.com/
|
||||
### END INIT INFO
|
||||
|
||||
# source function library
|
||||
. /etc/rc.d/init.d/functions
|
||||
|
||||
# pull in sysconfig settings
|
||||
[ -f /etc/sysconfig/backone ] && . /etc/sysconfig/backone
|
||||
|
||||
RETVAL=0
|
||||
prog="backone"
|
||||
lockfile=/var/lock/subsys/$prog
|
||||
ZT="/usr/sbin/backone"
|
||||
PID_FILE=/var/lib/backone/backone.pid
|
||||
|
||||
runlevel=$(set -- $(runlevel); eval "echo \$$#" )
|
||||
|
||||
start()
|
||||
{
|
||||
[ -x $ZT ] || exit 5
|
||||
echo -n $"Starting $prog: "
|
||||
$ZT $ZT_OPTIONS -d && success || failure
|
||||
RETVAL=$?
|
||||
[ $RETVAL -eq 0 ] && touch $lockfile
|
||||
echo
|
||||
return $RETVAL
|
||||
}
|
||||
|
||||
stop()
|
||||
{
|
||||
echo -n $"Stopping $prog: "
|
||||
killproc -p $PID_FILE $ZT
|
||||
RETVAL=$?
|
||||
if [ "x$runlevel" = x0 -o "x$runlevel" = x6 ] ; then
|
||||
trap '' TERM
|
||||
killall $prog 2>/dev/null
|
||||
trap TERM
|
||||
fi
|
||||
[ $RETVAL -eq 0 ] && rm -f $lockfile
|
||||
echo
|
||||
}
|
||||
|
||||
reload()
|
||||
{
|
||||
stop
|
||||
start
|
||||
}
|
||||
|
||||
restart() {
|
||||
stop
|
||||
start
|
||||
}
|
||||
|
||||
force_reload() {
|
||||
restart
|
||||
}
|
||||
|
||||
rh_status() {
|
||||
status -p $PID_FILE backone
|
||||
}
|
||||
|
||||
rh_status_q() {
|
||||
rh_status >/dev/null 2>&1
|
||||
}
|
||||
|
||||
case "$1" in
|
||||
start)
|
||||
rh_status_q && exit 0
|
||||
start
|
||||
;;
|
||||
stop)
|
||||
if ! rh_status_q; then
|
||||
rm -f $lockfile
|
||||
exit 0
|
||||
fi
|
||||
stop
|
||||
;;
|
||||
restart)
|
||||
restart
|
||||
;;
|
||||
reload)
|
||||
rh_status_q || exit 7
|
||||
reload
|
||||
;;
|
||||
force-reload)
|
||||
force_reload
|
||||
;;
|
||||
condrestart|try-restart)
|
||||
rh_status_q || exit 0
|
||||
if [ -f $lockfile ] ; then
|
||||
do_restart_sanity_check
|
||||
if [ $RETVAL -eq 0 ] ; then
|
||||
stop
|
||||
# avoid race
|
||||
sleep 3
|
||||
start
|
||||
else
|
||||
RETVAL=6
|
||||
fi
|
||||
fi
|
||||
;;
|
||||
status)
|
||||
rh_status
|
||||
RETVAL=$?
|
||||
if [ $RETVAL -eq 3 -a -f $lockfile ] ; then
|
||||
RETVAL=2
|
||||
fi
|
||||
;;
|
||||
*)
|
||||
echo $"Usage: $0 {start|stop|restart|reload|force-reload|condrestart|try-restart|status}"
|
||||
RETVAL=2
|
||||
esac
|
||||
exit $RETVAL
|
||||
@@ -1,5 +1,5 @@
|
||||
|
||||
module zerotier-one 1.0;
|
||||
module backone 1.0;
|
||||
|
||||
require {
|
||||
type unconfined_t;
|
||||
@@ -1,138 +0,0 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# zerotier-one Start the ZeroTier One network virtualization service
|
||||
#
|
||||
# chkconfig: 2345 55 25
|
||||
# description: ZeroTier One allows systems to join and participate in \
|
||||
# ZeroTier virtual networks. See https://www.zerotier.com/
|
||||
#
|
||||
# processname: zerotier-one
|
||||
# config: /var/lib/zerotier-one/identity.public
|
||||
# config: /var/lib/zerotier-one/identity.secret
|
||||
# config: /var/lib/zerotier-one/local.conf
|
||||
# config: /var/lib/zerotier-one/authtoken.secret
|
||||
# pidfile: /var/lib/zerotier-one/zerotier-one.pid
|
||||
|
||||
### BEGIN INIT INFO
|
||||
# Provides: zerotier-one
|
||||
# Required-Start: $local_fs $network $syslog
|
||||
# Required-Stop: $local_fs $syslog
|
||||
# Should-Start: $syslog
|
||||
# Should-Stop: $network $syslog
|
||||
# Default-Start: 2 3 4 5
|
||||
# Default-Stop: 0 1 6
|
||||
# Short-Description: Start the ZeroTier One network virtualization service
|
||||
# Description: ZeroTier One allows systems to join and participate in
|
||||
# ZeroTier virtual networks. See https://www.zerotier.com/
|
||||
### END INIT INFO
|
||||
|
||||
# source function library
|
||||
. /etc/rc.d/init.d/functions
|
||||
|
||||
# pull in sysconfig settings
|
||||
[ -f /etc/sysconfig/zerotier-one ] && . /etc/sysconfig/zerotier-one
|
||||
|
||||
RETVAL=0
|
||||
prog="zerotier-one"
|
||||
lockfile=/var/lock/subsys/$prog
|
||||
ZT="/usr/sbin/zerotier-one"
|
||||
PID_FILE=/var/lib/zerotier-one/zerotier-one.pid
|
||||
|
||||
runlevel=$(set -- $(runlevel); eval "echo \$$#" )
|
||||
|
||||
start()
|
||||
{
|
||||
[ -x $ZT ] || exit 5
|
||||
echo -n $"Starting $prog: "
|
||||
$ZT $ZT_OPTIONS -d && success || failure
|
||||
RETVAL=$?
|
||||
[ $RETVAL -eq 0 ] && touch $lockfile
|
||||
echo
|
||||
return $RETVAL
|
||||
}
|
||||
|
||||
stop()
|
||||
{
|
||||
echo -n $"Stopping $prog: "
|
||||
killproc -p $PID_FILE $ZT
|
||||
RETVAL=$?
|
||||
if [ "x$runlevel" = x0 -o "x$runlevel" = x6 ] ; then
|
||||
trap '' TERM
|
||||
killall $prog 2>/dev/null
|
||||
trap TERM
|
||||
fi
|
||||
[ $RETVAL -eq 0 ] && rm -f $lockfile
|
||||
echo
|
||||
}
|
||||
|
||||
reload()
|
||||
{
|
||||
stop
|
||||
start
|
||||
}
|
||||
|
||||
restart() {
|
||||
stop
|
||||
start
|
||||
}
|
||||
|
||||
force_reload() {
|
||||
restart
|
||||
}
|
||||
|
||||
rh_status() {
|
||||
status -p $PID_FILE zerotier-one
|
||||
}
|
||||
|
||||
rh_status_q() {
|
||||
rh_status >/dev/null 2>&1
|
||||
}
|
||||
|
||||
case "$1" in
|
||||
start)
|
||||
rh_status_q && exit 0
|
||||
start
|
||||
;;
|
||||
stop)
|
||||
if ! rh_status_q; then
|
||||
rm -f $lockfile
|
||||
exit 0
|
||||
fi
|
||||
stop
|
||||
;;
|
||||
restart)
|
||||
restart
|
||||
;;
|
||||
reload)
|
||||
rh_status_q || exit 7
|
||||
reload
|
||||
;;
|
||||
force-reload)
|
||||
force_reload
|
||||
;;
|
||||
condrestart|try-restart)
|
||||
rh_status_q || exit 0
|
||||
if [ -f $lockfile ] ; then
|
||||
do_restart_sanity_check
|
||||
if [ $RETVAL -eq 0 ] ; then
|
||||
stop
|
||||
# avoid race
|
||||
sleep 3
|
||||
start
|
||||
else
|
||||
RETVAL=6
|
||||
fi
|
||||
fi
|
||||
;;
|
||||
status)
|
||||
rh_status
|
||||
RETVAL=$?
|
||||
if [ $RETVAL -eq 3 -a -f $lockfile ] ; then
|
||||
RETVAL=2
|
||||
fi
|
||||
;;
|
||||
*)
|
||||
echo $"Usage: $0 {start|stop|restart|reload|force-reload|condrestart|try-restart|status}"
|
||||
RETVAL=2
|
||||
esac
|
||||
exit $RETVAL
|
||||
@@ -701,7 +701,7 @@
|
||||
<key>USE_HFS+_COMPRESSION</key>
|
||||
<false/>
|
||||
<key>VERSION</key>
|
||||
<string>1.14.1</string>
|
||||
<string>2.0.0</string>
|
||||
</dict>
|
||||
<key>TYPE</key>
|
||||
<integer>0</integer>
|
||||
|
||||
@@ -701,7 +701,7 @@
|
||||
<key>USE_HFS+_COMPRESSION</key>
|
||||
<false/>
|
||||
<key>VERSION</key>
|
||||
<string>1.14.1</string>
|
||||
<string>2.0.0</string>
|
||||
</dict>
|
||||
<key>TYPE</key>
|
||||
<integer>0</integer>
|
||||
|
||||
@@ -27,7 +27,7 @@
|
||||
<ROW Property="ProductCode" Value="1033:{EC58088A-4E0F-4BD5-B0B2-FD81C803EEC4} " Type="16"/>
|
||||
<ROW Property="ProductLanguage" Value="1033"/>
|
||||
<ROW Property="ProductName" Value="ZeroTier One"/>
|
||||
<ROW Property="ProductVersion" Value="1.14.0" Options="32"/>
|
||||
<ROW Property="ProductVersion" Value="2.0.0" Options="32"/>
|
||||
<ROW Property="REBOOT" MultiBuildValue="DefaultBuild:ReallySuppress"/>
|
||||
<ROW Property="SecureCustomProperties" Value="OLDPRODUCTS;AI_NEWERPRODUCTFOUND;AI_SETUPEXEPATH;SETUPEXEDIR"/>
|
||||
<ROW Property="UpgradeCode" Value="{B0E2A5F3-88B6-4E77-B922-CB4739B4C4C8}"/>
|
||||
|
||||
@@ -0,0 +1,52 @@
|
||||
# Distributed under the OSI-approved BSD 3-Clause License. See accompanying
|
||||
# file Copyright.txt or https://cmake.org/licensing for details.
|
||||
# SPDX-License-Identifier: BSD-3-Clause
|
||||
|
||||
#[=======================================================================[.rst:
|
||||
CMakeDependentOption
|
||||
--------------------
|
||||
|
||||
Macro to provide an option dependent on other options.
|
||||
|
||||
This macro presents an option to the user only if a set of other
|
||||
conditions are true. When the option is not presented a default value
|
||||
is used, but any value set by the user is preserved for when the
|
||||
option is presented again. Example invocation:
|
||||
|
||||
.. code-block:: cmake
|
||||
|
||||
CMAKE_DEPENDENT_OPTION(USE_FOO "Use Foo" ON
|
||||
"USE_BAR;NOT USE_ZOT" OFF)
|
||||
|
||||
If USE_BAR is true and USE_ZOT is false, this provides an option
|
||||
called USE_FOO that defaults to ON. Otherwise, it sets USE_FOO to
|
||||
OFF. If the status of USE_BAR or USE_ZOT ever changes, any value for
|
||||
the USE_FOO option is saved so that when the option is re-enabled it
|
||||
retains its old value. Each element in the fourth parameter is
|
||||
evaluated as an if-condition, so :ref:`Condition Syntax` can be used.
|
||||
#]=======================================================================]
|
||||
|
||||
macro(CMAKE_DEPENDENT_OPTION option doc default depends force)
|
||||
if(${option}_ISSET MATCHES "^${option}_ISSET$")
|
||||
set(${option}_AVAILABLE 1)
|
||||
foreach(d ${depends})
|
||||
string(REGEX REPLACE " +" ";" CMAKE_DEPENDENT_OPTION_DEP "${d}")
|
||||
if(${CMAKE_DEPENDENT_OPTION_DEP})
|
||||
else()
|
||||
set(${option}_AVAILABLE 0)
|
||||
endif()
|
||||
endforeach()
|
||||
if(${option}_AVAILABLE)
|
||||
option(${option} "${doc}" "${default}")
|
||||
set(${option} "${${option}}" CACHE BOOL "${doc}" FORCE)
|
||||
else()
|
||||
if(${option} MATCHES "^${option}$")
|
||||
else()
|
||||
set(${option} "${${option}}" CACHE INTERNAL "${doc}")
|
||||
endif()
|
||||
set(${option} ${force})
|
||||
endif()
|
||||
else()
|
||||
set(${option} "${${option}_ISSET}")
|
||||
endif()
|
||||
endmacro()
|
||||
File diff suppressed because it is too large.
Load diff
File diff suppressed because it is too large.
Load diff
@@ -0,0 +1,24 @@
|
||||
# As per https://gitlab.kitware.com/cmake/community/-/wikis/FAQ#can-i-do-make-uninstall-with-cmake
|
||||
|
||||
if(NOT EXISTS "@CMAKE_BINARY_DIR@/install_manifest.txt")
|
||||
message(FATAL_ERROR "Cannot find install manifest: @CMAKE_BINARY_DIR@/install_manifest.txt")
|
||||
endif()
|
||||
|
||||
file(READ "@CMAKE_BINARY_DIR@/install_manifest.txt" files)
|
||||
string(REGEX REPLACE "\n" ";" files "${files}")
|
||||
foreach(file ${files})
|
||||
message(STATUS "Uninstalling $ENV{DESTDIR}${file}")
|
||||
if(IS_SYMLINK "$ENV{DESTDIR}${file}" OR EXISTS "$ENV{DESTDIR}${file}")
|
||||
exec_program(
|
||||
"@CMAKE_COMMAND@" ARGS "-E remove \"$ENV{DESTDIR}${file}\""
|
||||
OUTPUT_VARIABLE rm_out
|
||||
RETURN_VALUE rm_retval
|
||||
)
|
||||
if(NOT "${rm_retval}" STREQUAL 0)
|
||||
message(FATAL_ERROR "Problem when removing $ENV{DESTDIR}${file}")
|
||||
endif()
|
||||
else(IS_SYMLINK "$ENV{DESTDIR}${file}" OR EXISTS "$ENV{DESTDIR}${file}")
|
||||
message(STATUS "File $ENV{DESTDIR}${file} does not exist.")
|
||||
endif()
|
||||
endforeach()
|
||||
|
||||
@@ -0,0 +1,249 @@
|
||||
# SPDX-License-Identifier: MIT
|
||||
|
||||
# First we will determine the optimization target.
|
||||
#
|
||||
# If OQS_DIST_BUILD=ON we need to target a generic CPU for any code
|
||||
# that is not protected by runtime CPU feature detection.
|
||||
#
|
||||
# If OQS_DIST_BUILD=OFF then we will optimize all code for the CPU
|
||||
# specified by OQS_OPT_TARGET.
|
||||
#
|
||||
# If OQS_OPT_TARGET=auto we target the current CPU.
|
||||
# If OQS_OPT_TARGET=generic we target a generic CPU.
|
||||
# Otherwise we target the specified CPU.
|
||||
|
||||
# Pedantic checks (-Wall, ...) are not enabled by default for Release
|
||||
# builds such as to avoid future build errors introduced by currently
|
||||
# unknown compiler warnings
|
||||
|
||||
include(CheckCCompilerFlag)
|
||||
check_c_compiler_flag("-Wa,--noexecstack" CC_SUPPORTS_WA_NOEXECSTACK)
|
||||
|
||||
# This sets the equivalent of -Werror for supported compilers
|
||||
# it can be overriden with --compile-no-warnings-as-errors
|
||||
# https://cmake.org/cmake/help/latest/prop_tgt/COMPILE_WARNING_AS_ERROR.html
|
||||
set(CMAKE_COMPILE_WARNING_AS_ERROR ${OQS_STRICT_WARNINGS})
|
||||
|
||||
if(${CMAKE_VERSION} VERSION_GREATER_EQUAL "3.18")
|
||||
include(CheckLinkerFlag)
|
||||
check_linker_flag(C "-Wl,-z,noexecstack" LD_SUPPORTS_WL_Z_NOEXECSTACK)
|
||||
elseif(${CMAKE_VERSION} VERSION_GREATER_EQUAL "3.14")
|
||||
set(TMP_TESTDIR "${CMAKE_BINARY_DIR}/test_noexecstack")
|
||||
file(WRITE "${TMP_TESTDIR}/test.c" "int main() { return 0; }\n")
|
||||
try_compile(
|
||||
LD_SUPPORTS_WL_Z_NOEXECSTACK
|
||||
"${TMP_TESTDIR}"
|
||||
"${TMP_TESTDIR}/test.c"
|
||||
LINK_OPTIONS "-Wl,-z,noexecstack"
|
||||
)
|
||||
else()
|
||||
message(WARNING "Unable to check if '-Wl,-z,noexecstack' is supported.")
|
||||
set(LD_SUPPORTS_WL_Z_NOEXECSTACK FALSE)
|
||||
endif()
|
||||
|
||||
set(OQS_OPT_FLAG "")
|
||||
if(CMAKE_C_COMPILER_ID MATCHES "Clang|GNU")
|
||||
if(${OQS_DIST_BUILD})
|
||||
set(OQS_OPT_TARGET "generic")
|
||||
endif()
|
||||
|
||||
if(CMAKE_CROSSCOMPILING AND OQS_OPT_TARGET STREQUAL "auto")
|
||||
set(OQS_OPT_TARGET "generic")
|
||||
endif()
|
||||
|
||||
if(OQS_OPT_TARGET STREQUAL "generic")
|
||||
if(ARCH_S390X)
|
||||
# At least z9-109 is needed for 'stckf' in benchmarking code.
|
||||
# gcc's default is z900 (older than z9-109), clang's default and minimum is z10.
|
||||
# setting to z10 as sensible default.
|
||||
set(OQS_OPT_FLAG "-march=z10")
|
||||
else()
|
||||
# Assume sensible default like -march=x86-64, -march=armv8-a, etc.
|
||||
if(ARCH_ARM64v8)
|
||||
set(OQS_OPT_FLAG "-march=armv8-a+crypto")
|
||||
else()
|
||||
set(OQS_OPT_FLAG "")
|
||||
endif()
|
||||
endif()
|
||||
elseif(OQS_OPT_TARGET STREQUAL "auto")
|
||||
if(ARCH_X86_64)
|
||||
set(OQS_OPT_FLAG "-march=native")
|
||||
elseif(ARCH_ARM64v8 AND CMAKE_SYSTEM_NAME STREQUAL "Linux")
|
||||
set(OQS_OPT_FLAG "-mcpu=native")
|
||||
elseif(ARCH_ARM64v8 AND CMAKE_SYSTEM_NAME STREQUAL "Darwin")
|
||||
set(OQS_OPT_FLAG "-mcpu=native")
|
||||
elseif(ARCH_S390X)
|
||||
set(OQS_OPT_FLAG "-march=native")
|
||||
else()
|
||||
message(
|
||||
WARNING
|
||||
"Setting OQS_OPT_TARGET=AUTO may not produce optimized code on this system."
|
||||
)
|
||||
endif()
|
||||
else()
|
||||
if(ARCH_X86_64)
|
||||
set(OQS_OPT_FLAG "-march=${OQS_OPT_TARGET}")
|
||||
elseif(ARCH_ARM64v8 OR ARCH_ARM32v7)
|
||||
set(OQS_OPT_FLAG "-mcpu=${OQS_OPT_TARGET}")
|
||||
elseif(ARCH_S390X)
|
||||
set(OQS_OPT_FLAG "-march=${OQS_OPT_TARGET}")
|
||||
endif()
|
||||
endif()
|
||||
add_compile_options(${OQS_OPT_FLAG})
|
||||
|
||||
# If this is not a dist build we also need to set the OQS_USE_[EXTENSION] flags
|
||||
if(NOT ${OQS_DIST_BUILD} AND NOT CMAKE_CROSSCOMPILING)
|
||||
include(${CMAKE_CURRENT_LIST_DIR}/gcc_clang_intrinsics.cmake)
|
||||
endif()
|
||||
endif()
|
||||
|
||||
if(CMAKE_C_COMPILER_ID MATCHES "Clang")
|
||||
if(${OQS_STRICT_WARNINGS})
|
||||
add_compile_options(-Wall)
|
||||
add_compile_options(-Wextra)
|
||||
add_compile_options(-Wpedantic)
|
||||
add_compile_options(-Wno-unused-command-line-argument)
|
||||
endif()
|
||||
if(CC_SUPPORTS_WA_NOEXECSTACK)
|
||||
add_compile_options("-Wa,--noexecstack")
|
||||
endif()
|
||||
if(LD_SUPPORTS_WL_Z_NOEXECSTACK)
|
||||
add_link_options("-Wl,-z,noexecstack")
|
||||
endif()
|
||||
|
||||
set(THREADS_PREFER_PTHREAD_FLAG ON)
|
||||
find_package(Threads)
|
||||
if(CMAKE_USE_PTHREADS_INIT AND NOT OQS_EMBEDDED_BUILD)
|
||||
set(OQS_USE_PTHREADS ON)
|
||||
endif()
|
||||
|
||||
if(${OQS_DEBUG_BUILD})
|
||||
if(OQS_ENABLE_TEST_CONSTANT_TIME_OPTIMIZED)
|
||||
add_compile_options(-O3) # run constant-time tests on release code
|
||||
endif()
|
||||
add_compile_options(-g3)
|
||||
add_compile_options(-fno-omit-frame-pointer)
|
||||
if(${USE_COVERAGE})
|
||||
add_compile_options(-coverage)
|
||||
add_link_options(-coverage)
|
||||
endif()
|
||||
if(USE_SANITIZER STREQUAL "Address")
|
||||
add_compile_options(-fno-optimize-sibling-calls)
|
||||
add_compile_options(-fsanitize-address-use-after-scope)
|
||||
add_compile_options(-fsanitize=address)
|
||||
set(SANITIZER_LD_FLAGS "-fsanitize=address")
|
||||
elseif(USE_SANITIZER STREQUAL "Memory")
|
||||
add_compile_options(-fsanitize=memory)
|
||||
set(SANITIZER_LD_FLAGS "-fsanitize=memory")
|
||||
elseif(USE_SANITIZER STREQUAL "MemoryWithOrigins")
|
||||
add_compile_options(-fsanitize=memory)
|
||||
add_compile_options(-fsanitize-memory-track-origins)
|
||||
set(SANITIZER_LD_FLAGS "-fsanitize=memory")
|
||||
elseif(USE_SANITIZER STREQUAL "Undefined")
|
||||
add_compile_options(-fsanitize=undefined)
|
||||
if(EXISTS "${BLACKLIST_FILE}")
|
||||
add_compile_options(-fsanitize-blacklist=${BLACKLIST_FILE})
|
||||
endif()
|
||||
set(SANITIZER_LD_FLAGS "-fsanitize=undefined")
|
||||
elseif(USE_SANITIZER STREQUAL "Thread")
|
||||
add_compile_options(-fsanitize=thread)
|
||||
set(SANITIZER_LD_FLAGS "-fsanitize=thread")
|
||||
elseif(USE_SANITIZER STREQUAL "Leak")
|
||||
add_compile_options(-fsanitize=leak)
|
||||
set(SANITIZER_LD_FLAGS "-fsanitize=leak")
|
||||
endif()
|
||||
else()
|
||||
add_compile_options(-fomit-frame-pointer)
|
||||
endif()
|
||||
elseif(CMAKE_C_COMPILER_ID STREQUAL "GNU")
|
||||
if(
|
||||
NOT ${CMAKE_C_COMPILER_VERSION}
|
||||
VERSION_GREATER_EQUAL
|
||||
${OQS_MINIMAL_GCC_VERSION}
|
||||
)
|
||||
message(
|
||||
FATAL_ERROR
|
||||
"GCC version ${CMAKE_C_COMPILER_VERSION} below minimally required version ${OQS_MINIMAL_GCC_VERSION}."
|
||||
)
|
||||
endif()
|
||||
if(${OQS_STRICT_WARNINGS})
|
||||
add_compile_options(-Wall)
|
||||
add_compile_options(-Wextra)
|
||||
add_compile_options(-Wpedantic)
|
||||
add_compile_options(-Wstrict-prototypes)
|
||||
add_compile_options(-Wshadow)
|
||||
add_compile_options(-Wformat=2)
|
||||
add_compile_options(-Wfloat-equal)
|
||||
add_compile_options(-Wwrite-strings)
|
||||
endif()
|
||||
if(NOT CMAKE_SYSTEM_NAME STREQUAL "Darwin")
|
||||
if(CC_SUPPORTS_WA_NOEXECSTACK)
|
||||
add_compile_options("-Wa,--noexecstack")
|
||||
endif()
|
||||
if(LD_SUPPORTS_WL_Z_NOEXECSTACK)
|
||||
add_link_options("-Wl,-z,noexecstack")
|
||||
endif()
|
||||
endif()
|
||||
|
||||
set(THREADS_PREFER_PTHREAD_FLAG ON)
|
||||
find_package(Threads)
|
||||
if(CMAKE_USE_PTHREADS_INIT AND NOT OQS_EMBEDDED_BUILD)
|
||||
set(OQS_USE_PTHREADS ON)
|
||||
endif()
|
||||
|
||||
if(${OQS_DEBUG_BUILD})
|
||||
add_compile_options(-Wstrict-overflow)
|
||||
add_compile_options(-ggdb3)
|
||||
if(${USE_COVERAGE})
|
||||
add_compile_options(-coverage)
|
||||
add_link_options(-coverage)
|
||||
endif()
|
||||
else()
|
||||
add_compile_options(-fomit-frame-pointer)
|
||||
add_compile_options(-fdata-sections)
|
||||
add_compile_options(-ffunction-sections)
|
||||
if(CMAKE_SYSTEM_NAME STREQUAL "Darwin")
|
||||
add_compile_options(-Wl,-dead_strip)
|
||||
else()
|
||||
add_compile_options(-Wl,--gc-sections)
|
||||
endif()
|
||||
endif()
|
||||
|
||||
# workaround for gcc issues on ARM32 as per https://github.com/open-quantum-safe/liboqs/issues/1288
|
||||
if(
|
||||
ARCH_ARM32v7
|
||||
AND (CMAKE_C_COMPILER_VERSION VERSION_GREATER_EQUAL "11.0.0")
|
||||
)
|
||||
add_compile_options(-fno-ipa-modref)
|
||||
add_compile_options(-fno-ipa-pure-const)
|
||||
endif()
|
||||
elseif(CMAKE_C_COMPILER_ID STREQUAL "MSVC")
|
||||
# Warning C4146 is raised when a unary minus operator is applied to an
|
||||
# unsigned type; this has nonetheless been standard and portable for as
|
||||
# long as there has been a C standard, and we need it for constant-time
|
||||
# computations. Thus, we disable that spurious warning.
|
||||
add_compile_options(/wd4146)
|
||||
# Need a larger stack for Classic McEliece
|
||||
add_link_options(/STACK:8192000)
|
||||
# bring compile options in line with openssl options; link otherwise fails
|
||||
add_compile_options(/MT)
|
||||
endif()
|
||||
|
||||
if(MINGW OR MSYS OR CYGWIN)
|
||||
set(OQS_USE_PTHREADS OFF)
|
||||
# Apply -Wno-maybe-uninitialized only for GCC
|
||||
if(CMAKE_C_COMPILER_ID STREQUAL "GNU")
|
||||
add_compile_options(-Wno-maybe-uninitialized)
|
||||
endif()
|
||||
if(CMAKE_VERSION VERSION_GREATER_EQUAL "3.13.0")
|
||||
add_link_options(-Wl,--stack,16777216)
|
||||
else()
|
||||
set(CMAKE_EXE_LINKER_FLAGS
|
||||
"${CMAKE_EXE_LINKER_FLAGS} -Wl,--stack,16777216"
|
||||
)
|
||||
endif()
|
||||
endif()
|
||||
|
||||
if(CMAKE_C_IMPLICIT_LINK_DIRECTORIES MATCHES "alpine-linux-musl")
|
||||
add_link_options(-Wl,-z,stack-size=16777216)
|
||||
endif()
|
||||
@@ -0,0 +1,67 @@
|
||||
// SPDX-License-Identifier: MIT
|
||||
|
||||
#include <stdio.h>
|
||||
|
||||
int main(void) {
|
||||
#if defined(__ADX__)
|
||||
printf("ADX;");
|
||||
#endif
|
||||
#if defined(__AES__)
|
||||
printf("AES;");
|
||||
#endif
|
||||
#if defined(__AVX__)
|
||||
printf("AVX;");
|
||||
#endif
|
||||
#if defined(__AVX2__)
|
||||
printf("AVX2;");
|
||||
#endif
|
||||
#if defined(__AVX512BW__)
|
||||
printf("AVX512BW;");
|
||||
#endif
|
||||
#if defined(__AVX512DQ__)
|
||||
printf("AVX512DQ;");
|
||||
#endif
|
||||
#if defined(__AVX512F__)
|
||||
printf("AVX512F;");
|
||||
#endif
|
||||
#if defined(__VPCLMULQDQ__)
|
||||
printf("VPCLMULQDQ;");
|
||||
#endif
|
||||
#if defined(__BMI__)
|
||||
printf("BMI1;");
|
||||
#endif
|
||||
#if defined(__BMI2__)
|
||||
printf("BMI2;");
|
||||
#endif
|
||||
#if defined(__FMA__)
|
||||
printf("FMA;");
|
||||
#endif
|
||||
#if defined(__PCLMUL__)
|
||||
printf("PCLMULQDQ;");
|
||||
#endif
|
||||
#if defined(__POPCNT__)
|
||||
printf("POPCNT;");
|
||||
#endif
|
||||
#if defined(__SSE__)
|
||||
printf("SSE;");
|
||||
#endif
|
||||
#if defined(__SSE2__)
|
||||
printf("SSE2;");
|
||||
#endif
|
||||
#if defined(__SSE3__)
|
||||
printf("SSE3;");
|
||||
#endif
|
||||
#if defined(__ARM_FEATURE_AES)
|
||||
printf("ARM_AES;");
|
||||
#endif
|
||||
#if (defined(__APPLE__) && defined(__aarch64__)) || defined(__ARM_FEATURE_SHA2)
|
||||
printf("ARM_SHA2;");
|
||||
#endif
|
||||
#if defined(__ARM_FEATURE_SHA3)
|
||||
printf("ARM_SHA3;");
|
||||
#endif
|
||||
#if defined(__ARM_NEON)
|
||||
printf("ARM_NEON;");
|
||||
#endif
|
||||
return 0;
|
||||
}
|
||||
@@ -0,0 +1,27 @@
|
||||
# SPDX-License-Identifier: MIT
|
||||
|
||||
try_run(RUN_RESULT COMPILE_RESULT
|
||||
"${CMAKE_BINARY_DIR}" "${PROJECT_SOURCE_DIR}/.CMake/detect_gcc_clang_intrinsics.c"
|
||||
COMPILE_DEFINITIONS ${OQS_OPT_FLAG}
|
||||
COMPILE_OUTPUT_VARIABLE COMPILE_OUTPUT
|
||||
RUN_OUTPUT_VARIABLE RUN_OUTPUT)
|
||||
if(NOT COMPILE_RESULT)
|
||||
message(FATAL_ERROR "Could not compile .CMake/detect_gcc_clang_intrinsics.c" ${COMPILE_OUTPUT})
|
||||
endif()
|
||||
if(NOT RUN_RESULT EQUAL 0)
|
||||
if(CMAKE_CROSSCOMPILING)
|
||||
message(STATUS "Detecting language features in cross-compiling mode impossible. Setting all CPU features OFF.")
|
||||
else()
|
||||
message(FATAL_ERROR ".CMake/detect_gcc_clang_intrinsics.c returned exit code: " ${RUN_RESULT})
|
||||
endif()
|
||||
endif()
|
||||
foreach(CPU_EXTENSION ${RUN_OUTPUT})
|
||||
if (NOT DEFINED OQS_USE_${CPU_EXTENSION}_INSTRUCTIONS)
|
||||
set(OQS_USE_${CPU_EXTENSION}_INSTRUCTIONS ON)
|
||||
endif()
|
||||
endforeach()
|
||||
if(OQS_USE_AVX512BW_INSTRUCTIONS AND
|
||||
OQS_USE_AVX512DQ_INSTRUCTIONS AND
|
||||
OQS_USE_AVX512F_INSTRUCTIONS)
|
||||
set(OQS_USE_AVX512_INSTRUCTIONS ON)
|
||||
endif()
|
||||
@@ -0,0 +1,8 @@
|
||||
# SPDX-License-Identifier: MIT
|
||||
|
||||
set(CMAKE_SYSTEM_NAME Linux)
|
||||
set(CMAKE_SYSTEM_PROCESSOR arm64v8)
|
||||
set(CMAKE_CROSSCOMPILING ON)
|
||||
|
||||
set(CMAKE_C_COMPILER aarch64-linux-gnu-gcc)
|
||||
set(CMAKE_CROSSCOMPILING_EMULATOR "qemu-aarch64-static;-L;/usr/aarch64-linux-gnu/")
|
||||
@@ -0,0 +1,8 @@
|
||||
# SPDX-License-Identifier: MIT
|
||||
|
||||
set(CMAKE_SYSTEM_NAME Linux)
|
||||
set(CMAKE_SYSTEM_PROCESSOR arm32v7)
|
||||
set(CMAKE_CROSSCOMPILING ON)
|
||||
|
||||
set(CMAKE_C_COMPILER arm-linux-gnueabihf-gcc)
|
||||
set(CMAKE_CROSSCOMPILING_EMULATOR "qemu-arm-static;-L;/usr/arm-linux-gnueabihf/")
|
||||
@@ -0,0 +1,20 @@
|
||||
# SPDX-License-Identifier: MIT
|
||||
|
||||
# How to use:
|
||||
# apt install gcc-8-arm-linux-gnueabihf
|
||||
# cmake -GNinja -DCMAKE_TOOLCHAIN_FILE=../.CMake/toolchain_rasppi.cmake -DOQS_USE_OPENSSL=OFF ..
|
||||
|
||||
set(CMAKE_SYSTEM_NAME Linux)
|
||||
set(CMAKE_SYSTEM_PROCESSOR armhf)
|
||||
set(CMAKE_CROSSCOMPILING ON)
|
||||
|
||||
set(CMAKE_C_COMPILER arm-linux-gnueabihf-gcc-8)
|
||||
|
||||
set(CMAKE_FIND_ROOT_PATH_MODE_PROGRAM NEVER)
|
||||
set(CMAKE_FIND_ROOT_PATH_MODE_LIBRARY ONLY)
|
||||
set(CMAKE_FIND_ROOT_PATH_MODE_INCLUDE ONLY)
|
||||
set(CMAKE_FIND_ROOT_PATH_MODE_PACKAGE ONLY)
|
||||
|
||||
# Unconditionally set for this platform
|
||||
add_definitions( -DOQS_USE_RASPBERRY_PI )
|
||||
|
||||
@@ -0,0 +1,18 @@
|
||||
# SPDX-License-Identifier: MIT
|
||||
|
||||
# How to use:
|
||||
# apt install gcc-mingw-w64
|
||||
# cmake -GNinja -DCMAKE_TOOLCHAIN_FILE=../.CMake/toolchain_windows-amd64.cmake ..
|
||||
|
||||
set(CMAKE_SYSTEM_NAME Windows)
|
||||
set(CMAKE_SYSTEM_PROCESSOR AMD64)
|
||||
set(CMAKE_CROSSCOMPILING ON)
|
||||
|
||||
set(PREFIX x86_64-w64-mingw32)
|
||||
set(CMAKE_C_COMPILER ${PREFIX}-gcc)
|
||||
|
||||
set(CMAKE_CROSSCOMPILING_EMULATOR "wine")
|
||||
set(CMAKE_FIND_ROOT_PATH_MODE_PROGRAM NEVER)
|
||||
set(CMAKE_FIND_ROOT_PATH_MODE_LIBRARY ONLY)
|
||||
set(CMAKE_FIND_ROOT_PATH_MODE_INCLUDE ONLY)
|
||||
set(CMAKE_FIND_ROOT_PATH_MODE_PACKAGE ONLY)
|
||||
@@ -0,0 +1,15 @@
|
||||
# SPDX-License-Identifier: MIT
|
||||
|
||||
set(CMAKE_SYSTEM_NAME Windows)
|
||||
|
||||
set(CMAKE_SYSTEM_PROCESSOR AMD64)
|
||||
|
||||
set(CMAKE_CROSSCOMPILING OFF)
|
||||
|
||||
set(CMAKE_GENERATOR_PLATFORM
|
||||
x64
|
||||
CACHE STRING "Platform" FORCE
|
||||
)
|
||||
|
||||
set(CMAKE_C_FLAGS "${CMAKE_C_FLAGS} -D__ORDER_LITTLE_ENDIAN__=1234 -D__ORDER_BIG_ENDIAN__=4321 -D__BYTE_ORDER__=1234")
|
||||
message(STATUS "Setting little endianness explicity for windows amd 64")
|
||||
@@ -0,0 +1,12 @@
|
||||
# SPDX-License-Identifier: MIT
|
||||
|
||||
set(CMAKE_SYSTEM_NAME Windows)
|
||||
|
||||
set(CMAKE_SYSTEM_PROCESSOR arm64)
|
||||
|
||||
set(CMAKE_CROSSCOMPILING ON)
|
||||
|
||||
set(CMAKE_GENERATOR_PLATFORM
|
||||
ARM64
|
||||
CACHE STRING "Platform" FORCE
|
||||
)
|
||||
@@ -0,0 +1,15 @@
|
||||
# SPDX-License-Identifier: MIT
|
||||
|
||||
set(CMAKE_SYSTEM_NAME Windows)
|
||||
|
||||
set(CMAKE_SYSTEM_PROCESSOR x86)
|
||||
|
||||
set(CMAKE_CROSSCOMPILING OFF)
|
||||
|
||||
set(CMAKE_GENERATOR_PLATFORM
|
||||
Win32
|
||||
CACHE STRING "Platform" FORCE
|
||||
)
|
||||
|
||||
set(CMAKE_C_FLAGS "${CMAKE_C_FLAGS} -D__ORDER_LITTLE_ENDIAN__=1234 -D__ORDER_BIG_ENDIAN__=4321 -D__BYTE_ORDER__=1234")
|
||||
message(STATUS "Setting little endianness explicity for windows x86")
|
||||
@@ -0,0 +1,5 @@
|
||||
# SPDX-License-Identifier: MIT
|
||||
|
||||
set(CMAKE_SYSTEM_NAME Linux)
|
||||
set(CMAKE_SYSTEM_PROCESSOR i586)
|
||||
set(CMAKE_CROSSCOMPILING OFF)
|
||||
@@ -0,0 +1,16 @@
|
||||
# find src tests .CMake -name '*.[ch]' | grep -v '/external/' | grep -v 'kem.*/pqclean_' | grep -v 'sig.*/pqclean_' | xargs astyle --options=.astylerc
|
||||
--style=google
|
||||
--indent=tab
|
||||
#--indent-preproc-define
|
||||
#--indent-preproc-cond
|
||||
--pad-oper
|
||||
--pad-comma
|
||||
--pad-header
|
||||
#--unpad-paren
|
||||
--align-pointer=name
|
||||
--add-braces
|
||||
--convert-tabs
|
||||
--mode=c
|
||||
# disable backup files
|
||||
--suffix=none
|
||||
--lineend=linux
|
||||
@@ -0,0 +1,6 @@
|
||||
# see https://mirrors.edge.kernel.org/pub/software/scm/git/docs/gitattributes.html
|
||||
|
||||
* text=auto whitespace=trailing-space
|
||||
|
||||
*.png binary
|
||||
*.jpe?g binary
|
||||
Vendored
+29
@@ -0,0 +1,29 @@
|
||||
# https://docs.github.com/en/github/creating-cloning-and-archiving-repositories/about-code-owners
|
||||
# Note: the LAST matching pattern wins, so more general patterns must come before more specific ones.
|
||||
|
||||
* @dstebila @baentsch @xuganyu96
|
||||
/scripts/ @xuganyu96
|
||||
/tests/ @xuganyu96 @bhess
|
||||
/zephyr/ @Frauschi @bhess
|
||||
/docs/cbom.json @bhess
|
||||
/scripts/copy_from_upstream @xuganyu96
|
||||
/src/common @dstebila
|
||||
/src/kem/bike @brian-jarvis-aws
|
||||
/src/kem/frodokem @dstebila
|
||||
/src/kem/kyber @bhess @loganaden
|
||||
/src/kem/ml_kem @bhess @mkannwischer
|
||||
/src/kem/ntru @saitomst
|
||||
/src/kem/ntruprime @bbbrumley
|
||||
/src/sig/cross @alexrow @rtjk
|
||||
/src/sig/mayo @bhess
|
||||
/src/sig/ml_dsa @bhess @mkannwischer
|
||||
/src/sig/mqom @rben-dev
|
||||
/src/sig/uov @mkannwischer
|
||||
/src/sig_stfl/lms @ashman-p
|
||||
/src/sig_stfl/xmss @cothan @ashman-p
|
||||
/tests/ACVP_Vectors @bhess @abhi-dev-engg
|
||||
/tests/Wycheproof_Vectors @bhess @abhi-dev-engg
|
||||
/tests/PQC_Intermediate_Values @bhess
|
||||
/tests/test_acvp_vectors.py @bhess @abhi-dev-engg
|
||||
/tests/test_wycheproof_vectors.py @bhess @abhi-dev-engg
|
||||
/tests/test_sig_stfl.c @ashman-p @cothan
|
||||
@@ -0,0 +1,56 @@
|
||||
# This template was generated with [Issue Forms Creator](https://issue-forms-creator.netlify.app)
|
||||
name: Bug report
|
||||
description: Template for bug reports
|
||||
body:
|
||||
- type: markdown
|
||||
attributes:
|
||||
value: >-
|
||||
Thank you for submitting a bug report to liboqs. Before submitting, we
|
||||
encourage you to search through the following resources:
|
||||
|
||||
- [issues](https://github.com/open-quantum-safe/liboqs/issues)
|
||||
|
||||
- [pull requests](https://github.com/open-quantum-safe/liboqs/pulls)
|
||||
|
||||
|
||||
If this is a question regarding usage rather than a bug in the software,
|
||||
the best place for that is our Github [discussion
|
||||
forum](https://github.com/orgs/open-quantum-safe/discussions).
|
||||
- type: textarea
|
||||
attributes:
|
||||
label: Description
|
||||
description: A clear and concise description of what the bug is.
|
||||
validations:
|
||||
required: true
|
||||
- type: textarea
|
||||
attributes:
|
||||
label: Expected behaviour
|
||||
description: What did you expect to happen?
|
||||
- type: input
|
||||
attributes:
|
||||
label: liboqs version
|
||||
description: Which version of liboqs are you using?
|
||||
validations:
|
||||
required: true
|
||||
- type: textarea
|
||||
attributes:
|
||||
label: Environment
|
||||
description: Please describe the environment in which you are running liboqs
|
||||
value: |-
|
||||
- Architecture: [e.g., x86_64]
|
||||
- OS: [e.g. Ubuntu 24.04 LTS]
|
||||
- OpenSSL version [e.g., 3.0.2]
|
||||
- Compiler version used [e.g., clang 9.0.0]
|
||||
- Build variables used [e.g., "-DOQS_ALGS_ENABLED=STD"]
|
||||
- type: textarea
|
||||
attributes:
|
||||
label: Use of generative AI
|
||||
description: >-
|
||||
If this contribution (code, documentation, descriptive text) was
|
||||
produced with the help of generative AI, please describe the nature of
|
||||
the use. Contributors are expected to have verified and affirm such contributions
|
||||
themselves before submission.
|
||||
- type: textarea
|
||||
attributes:
|
||||
label: Additional information
|
||||
description: Add any other context about the problem here.
|
||||
@@ -0,0 +1,29 @@
|
||||
# This template was generated with [Issue Forms Creator](https://issue-forms-creator.netlify.app)
|
||||
name: Feature request
|
||||
description: 'Suggest a new feature '
|
||||
body:
|
||||
- type: textarea
|
||||
attributes:
|
||||
label: Description
|
||||
description: A clear and concise description of the problem or missing capability
|
||||
validations:
|
||||
required: true
|
||||
- type: textarea
|
||||
attributes:
|
||||
label: Describe the solution you'd like
|
||||
description: If you have a solution in mind, please describe it.
|
||||
- type: textarea
|
||||
attributes:
|
||||
label: Describe alternatives you've considered
|
||||
description: Have you considered any alternative solutions or workarounds?
|
||||
- type: textarea
|
||||
attributes:
|
||||
label: Are you willing to help develop the solution?
|
||||
- type: textarea
|
||||
attributes:
|
||||
label: Use of generative AI
|
||||
description: >-
|
||||
If this contribution (code, documentation, descriptive text) was
|
||||
produced with the help of generative AI, please describe the nature of
|
||||
the use. Contributors are expected to have verified and affirm such contributions
|
||||
themselves before submission.
|
||||
Vendored
+10
@@ -0,0 +1,10 @@
|
||||
# Configuration variables in array of strings defined in your repository or organization
|
||||
# From https://github.com/rhysd/actionlint/blob/v1.7.7/docs/config.md:
|
||||
# "When an array is set, actionlint will check vars properties strictly. An empty array means no variable is allowed."
|
||||
config-variables:
|
||||
# - DEFAULT_RUNNER
|
||||
# - JOB_NAME
|
||||
# - ENVIRONMENT_STAGE
|
||||
self-hosted-runner:
|
||||
labels:
|
||||
- oqs-x64
|
||||
Vendored
+21
@@ -0,0 +1,21 @@
|
||||
version: 2
|
||||
updates:
|
||||
- package-ecosystem: "github-actions"
|
||||
directory: "/"
|
||||
schedule:
|
||||
interval: "weekly"
|
||||
groups:
|
||||
github-actions:
|
||||
patterns:
|
||||
- "*"
|
||||
|
||||
- package-ecosystem: "pip"
|
||||
directories:
|
||||
- "/scripts/copy_from_upstream"
|
||||
- "/.github/workflows"
|
||||
schedule:
|
||||
interval: "weekly"
|
||||
groups:
|
||||
pip:
|
||||
patterns:
|
||||
- "*"
|
||||
+15
@@ -0,0 +1,15 @@
|
||||
<!-- Please give a brief explanation of the purpose of this pull request. -->
|
||||
|
||||
<!-- Does this PR resolve any issue? If so, please reference it using automatic-closing keywords like "Fixes #123." -->
|
||||
|
||||
<!-- Any PR adding a new feature is expected to contain a test; the test should be part of CI testing, preferably within the ".github/workflows" directory tree. Please add an explanation to the PR if/when (why) this cannot be done. -->
|
||||
|
||||
<!-- Please answer the following questions to help manage version and changes across projects. -->
|
||||
|
||||
* [ ] Does this PR change the input/output behaviour of a cryptographic algorithm (i.e., does it change known answer test values)? (If so, a version bump will be required from *x.y.z* to *x.(y+1).0*.)
|
||||
* [ ] Does this PR change the list of algorithms available -- either adding, removing, or renaming? Does this PR otherwise change an API? (If so, PRs in fully supported downstream projects dependent on these, i.e., [oqs-provider](https://github.com/open-quantum-safe/oqs-provider) will also need to be ready for review and merge by the time this is merged. Also, make sure to update the list of algorithms in the continuous benchmarking files: .github/workflows/kem-bench.yml and sig-bench.yml)
|
||||
|
||||
<!-- If this contribution (code, documentation, descriptive text) was produced with the help of generative AI, please describe the nature of the use. Contributors are expected to have verified and affirm such contributions themselves before submission. -->
|
||||
|
||||
<!-- Once your pull request is ready for review and passing continuous integration tests, please convert from a draft PR to a normal PR, and request a review from one of the OQS core team members. -->
|
||||
|
||||
+22
@@ -0,0 +1,22 @@
|
||||
name: android build
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
on: [workflow_call, workflow_dispatch]
|
||||
|
||||
jobs:
|
||||
|
||||
android:
|
||||
runs-on: ubuntu-latest
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
abi: [armeabi-v7a, arm64-v8a, x86, x86_64]
|
||||
stfl_opt: [ON, OFF]
|
||||
|
||||
steps:
|
||||
- name: Checkout code
|
||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2
|
||||
- name: Build project
|
||||
run: ./scripts/build-android.sh $ANDROID_NDK_HOME -a ${{ matrix.abi }} -f "-DOQS_ENABLE_SIG_STFL_LMS=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_HAZARDOUS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=${{ matrix.stfl_opt }}"
|
||||
+25
@@ -0,0 +1,25 @@
|
||||
name: apple build
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
on: [workflow_call, workflow_dispatch]
|
||||
|
||||
jobs:
|
||||
|
||||
apple-mobile:
|
||||
runs-on: macos-latest
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
platform: [OS64, TVOS]
|
||||
stfl_opt: [OFF, ON]
|
||||
steps:
|
||||
- name: Checkout code
|
||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2
|
||||
- name: Generate project
|
||||
run: |
|
||||
cmake -B build --toolchain .CMake/apple.cmake -DOQS_USE_OPENSSL=OFF -DPLATFORM=${{ matrix.platform }} \
|
||||
-DOQS_ENABLE_SIG_STFL_LMS=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_HAZARDOUS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=${{ matrix.stfl_opt }} .
|
||||
- name: Build project
|
||||
run: cmake --build build
|
||||
+177
@@ -0,0 +1,177 @@
|
||||
name: Basic checks
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
on: [workflow_call, workflow_dispatch]
|
||||
|
||||
jobs:
|
||||
workflowcheck:
|
||||
name: Check validity of GitHub workflows
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Checkout code
|
||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v4
|
||||
- name: Install actionlint
|
||||
run: |
|
||||
bash <(curl -sSL https://raw.githubusercontent.com/rhysd/actionlint/2ab3a12c7848f6c15faca9a92612ef4261d0e370/scripts/download-actionlint.bash)
|
||||
sudo mv ./actionlint /usr/local/bin/
|
||||
- name: Ensure GitHub actions are valid
|
||||
run: actionlint -shellcheck "" # run *without* shellcheck
|
||||
|
||||
stylecheck:
|
||||
name: Check code formatting
|
||||
needs: [workflowcheck]
|
||||
runs-on: ubuntu-latest
|
||||
container: openquantumsafe/ci-ubuntu-latest:latest
|
||||
steps:
|
||||
- name: Checkout code
|
||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v4
|
||||
- name: Ensure code conventions are upheld
|
||||
run: python3 -m pytest --verbose tests/test_code_conventions.py
|
||||
- name: Check that doxygen can parse the documentation
|
||||
run: mkdir build && ./scripts/run_doxygen.sh $(which doxygen) ./docs/.Doxyfile ./build
|
||||
- name: Validate CBOM
|
||||
run: scripts/validate_cbom.sh
|
||||
|
||||
upstreamcheck:
|
||||
name: Check upstream code is properly integrated
|
||||
needs: [workflowcheck]
|
||||
runs-on: ubuntu-latest
|
||||
container: openquantumsafe/ci-ubuntu-latest:latest
|
||||
steps:
|
||||
- name: Checkout code
|
||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v4
|
||||
- name: Configure
|
||||
run: |
|
||||
git config --global user.name "ciuser" && \
|
||||
git config --global user.email "ci@openquantumsafe.org" && \
|
||||
git config --global --add safe.directory "$PWD" && \
|
||||
echo "LIBOQS_DIR=$PWD" >> "$GITHUB_ENV"
|
||||
- name: Verify copy_from_upstream state after copy
|
||||
working-directory: "scripts/copy_from_upstream"
|
||||
run: |
|
||||
python3 copy_from_upstream.py -d copy && \
|
||||
git status --porcelain && \
|
||||
test -z "$(git status --porcelain)"
|
||||
- name: Verify copy_from_upstream state after libjade
|
||||
working-directory: "scripts/copy_from_upstream"
|
||||
run: |
|
||||
python3 copy_from_upstream.py -d libjade && \
|
||||
git status --porcelain && \
|
||||
test -z "$(git status --porcelain)"
|
||||
|
||||
buildcheck:
|
||||
name: Check that code passes a basic build
|
||||
needs: [workflowcheck, stylecheck, upstreamcheck]
|
||||
runs-on: ubuntu-latest
|
||||
container: openquantumsafe/ci-ubuntu-latest:latest
|
||||
env:
|
||||
KEM_NAME: ml_kem_768
|
||||
SIG_NAME: ml_dsa_65
|
||||
steps:
|
||||
- name: Create random build folder
|
||||
run: tmp_build=$(mktemp -d) && echo "RANDOM_BUILD_DIR=$tmp_build" >> $GITHUB_ENV
|
||||
- name: Checkout code
|
||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v4
|
||||
- name: Configure
|
||||
run: |
|
||||
cmake \
|
||||
-B ${{ env.RANDOM_BUILD_DIR }} \
|
||||
-GNinja \
|
||||
-DOQS_STRICT_WARNINGS=ON \
|
||||
-DOQS_MINIMAL_BUILD="KEM_$KEM_NAME;SIG_$SIG_NAME" \
|
||||
--warn-uninitialized . > config.log 2>&1 && \
|
||||
cat config.log && \
|
||||
cmake -LA -N . && \
|
||||
! (grep -i "uninitialized variable" config.log)
|
||||
- name: Build code
|
||||
run: ninja
|
||||
working-directory: ${{ env.RANDOM_BUILD_DIR }}
|
||||
- name: Build documentation
|
||||
run: ninja gen_docs
|
||||
working-directory: ${{ env.RANDOM_BUILD_DIR }}
|
||||
|
||||
cppcheck:
|
||||
name: Check C++ linking with example program
|
||||
needs: [workflowcheck]
|
||||
runs-on: ubuntu-latest
|
||||
container: openquantumsafe/ci-ubuntu-latest:latest
|
||||
env:
|
||||
SIG_NAME: ml_dsa_44
|
||||
steps:
|
||||
- name: Create random build folder
|
||||
run: tmp_build=$(mktemp -d) && echo "RANDOM_BUILD_DIR=$tmp_build" >> $GITHUB_ENV
|
||||
- name: Checkout code
|
||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v4
|
||||
- name: Configure
|
||||
run: |
|
||||
cmake \
|
||||
-B ${{ env.RANDOM_BUILD_DIR }} \
|
||||
-GNinja \
|
||||
-DOQS_STRICT_WARNINGS=ON \
|
||||
-DOQS_MINIMAL_BUILD="SIG_$SIG_NAME" \
|
||||
--warn-uninitialized . > config.log 2>&1 && \
|
||||
cat config.log && \
|
||||
cmake -LA -N . && \
|
||||
! (grep -i "uninitialized variable" config.log)
|
||||
- name: Build liboqs
|
||||
run: ninja
|
||||
working-directory: ${{ env.RANDOM_BUILD_DIR }}
|
||||
- name: Link with C++ program
|
||||
run: |
|
||||
g++ "$GITHUB_WORKSPACE"/cpp/sig_linking_test.cpp -g \
|
||||
-I./include -L./lib -loqs -lcrypto -std=c++11 -o example_sig && \
|
||||
./example_sig
|
||||
working-directory: ${{ env.RANDOM_BUILD_DIR }}
|
||||
|
||||
fuzzbuildcheck:
|
||||
name: Check that code passes a basic fuzzing build
|
||||
needs: [workflowcheck, stylecheck, upstreamcheck]
|
||||
runs-on: ubuntu-latest
|
||||
container: openquantumsafe/ci-ubuntu-latest:latest
|
||||
env:
|
||||
SIG_NAME: ml_dsa_44
|
||||
CC: clang
|
||||
CXX: clang++
|
||||
CFLAGS: -fsanitize=fuzzer-no-link,address
|
||||
LDFLAGS: -fsanitize=address
|
||||
steps:
|
||||
- name: Create random build folder
|
||||
run: tmp_build=$(mktemp -d) && echo "RANDOM_BUILD_DIR=$tmp_build" >> $GITHUB_ENV
|
||||
- name: Checkout code
|
||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v4
|
||||
- name: Configure
|
||||
run: |
|
||||
cmake \
|
||||
-B ${{ env.RANDOM_BUILD_DIR }} \
|
||||
-GNinja \
|
||||
-DOQS_STRICT_WARNINGS=ON \
|
||||
-DOQS_BUILD_FUZZ_TESTS=ON \
|
||||
-DOQS_MINIMAL_BUILD="SIG_$SIG_NAME" \
|
||||
--warn-uninitialized . > config.log 2>&1 && \
|
||||
cat config.log && \
|
||||
cmake -LA -N . && \
|
||||
! (grep -i "uninitialized variable" config.log)
|
||||
- name: Build code
|
||||
run: ninja fuzz_test_sig
|
||||
working-directory: ${{ env.RANDOM_BUILD_DIR }}
|
||||
|
||||
- name: Short fuzz check (30s)
|
||||
run: ./tests/fuzz_test_sig -max_total_time=30
|
||||
working-directory: ${{ env.RANDOM_BUILD_DIR }}
|
||||
|
||||
nixflakecheck:
|
||||
name: Check that Nix flake has correct syntax and can build
|
||||
needs: [workflowcheck]
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: DeterminateSystems/nix-installer-action@ef8a148080ab6020fd15196c2084a2eea5ff2d25 # v22
|
||||
- name: Checkout code
|
||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v4
|
||||
- name: Check devShell
|
||||
run: nix develop --command echo
|
||||
- name: Check flake syntax
|
||||
run: nix flake check --no-build # check for accurate syntax
|
||||
- name: Check that the flake builds
|
||||
run: nix build # check that the build runs
|
||||
+60
@@ -0,0 +1,60 @@
|
||||
name: Code coverage tests
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
on: [workflow_call, workflow_dispatch]
|
||||
|
||||
jobs:
|
||||
coverage:
|
||||
name: Run code coverage testing
|
||||
strategy:
|
||||
matrix:
|
||||
# The 'id' value for each job should be added to the 'carry-forward' string in the 'finish' job.
|
||||
include:
|
||||
- id: x64-generic
|
||||
runner: ubuntu-latest
|
||||
CMAKE_ARGS: -DOQS_DIST_BUILD=OFF -DOQS_OPT_TARGET=generic
|
||||
- id: x64-distbuild
|
||||
runner: ubuntu-latest
|
||||
CMAKE_ARGS: -DOQS_DIST_BUILD=ON
|
||||
- id: arm64-distbuild
|
||||
runner: ubuntu-24.04-arm
|
||||
CMAKE_ARGS: -DOQS_DIST_BUILD=ON
|
||||
runs-on: ${{ matrix.runner }}
|
||||
container: openquantumsafe/ci-ubuntu-latest:latest
|
||||
steps:
|
||||
- name: Checkout code
|
||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v4
|
||||
- name: Configure
|
||||
run: |
|
||||
mkdir build && cd build && \
|
||||
cmake -GNinja -DCMAKE_BUILD_TYPE=Debug -DUSE_COVERAGE=ON ${{ matrix.CMAKE_ARGS }} .. && \
|
||||
cmake -LA -N ..
|
||||
- name: Build
|
||||
run: ninja
|
||||
working-directory: build
|
||||
- name: Run tests
|
||||
run: |
|
||||
python3 -m pytest --verbose --numprocesses=auto \
|
||||
tests/test_acvp_vectors.py \
|
||||
tests/test_cmdline.py \
|
||||
tests/test_kat.py
|
||||
- name: Run lcov
|
||||
run: lcov -d . -c -o lcov.info --exclude /usr/lib,/usr/include --ignore-errors unused,inconsistent
|
||||
- name: Upload to coveralls.io
|
||||
uses: coverallsapp/github-action@648a8eb78e6d50909eff900e4ec85cab4524a45b # pin@v2.3.6
|
||||
with:
|
||||
flag-name: ${{ matrix.id }}
|
||||
parallel: true
|
||||
|
||||
finish:
|
||||
needs: coverage
|
||||
if: ${{ always() }}
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Finish coveralls.io
|
||||
uses: coverallsapp/github-action@648a8eb78e6d50909eff900e4ec85cab4524a45b # pin@v2.3.6
|
||||
with:
|
||||
parallel-finished: true
|
||||
carry-forward: "x64-generic,x64-distbuild,arm64-distbuild"
|
||||
+29
@@ -0,0 +1,29 @@
|
||||
name: Main branch tests
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: ['main']
|
||||
|
||||
jobs:
|
||||
|
||||
platform-tests:
|
||||
uses: ./.github/workflows/platforms.yml
|
||||
|
||||
code-coverage:
|
||||
uses: ./.github/workflows/code-coverage.yml
|
||||
secrets: inherit
|
||||
|
||||
scorecard:
|
||||
uses: ./.github/workflows/supplychain.yml
|
||||
secrets: inherit
|
||||
permissions:
|
||||
id-token: write
|
||||
security-events: write
|
||||
contents: read
|
||||
|
||||
basic-downstream:
|
||||
uses: ./.github/workflows/downstream-basic.yml
|
||||
secrets: inherit
|
||||
+36
@@ -0,0 +1,36 @@
|
||||
name: docs-sync
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
paths:
|
||||
- 'docs/algorithms/**'
|
||||
- 'scripts/update_docs_from_yaml.py'
|
||||
- 'scripts/update_alg_support_table.py'
|
||||
- 'scripts/generate_algorithms_md.py'
|
||||
- 'README.md'
|
||||
- 'ALGORITHMS.md'
|
||||
push:
|
||||
branches: [main]
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
check:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v4
|
||||
- uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # pin@v5
|
||||
with:
|
||||
python-version: '3.11'
|
||||
- name: Install deps
|
||||
run: pip install --require-hashes -r .github/workflows/requirements.txt
|
||||
- name: Regenerate docs
|
||||
run: python3 scripts/update_docs_from_yaml.py --liboqs-root .
|
||||
- name: Fail if generated files drift
|
||||
run: |
|
||||
if ! git diff --quiet; then
|
||||
echo "Generated docs are out of sync with YAML. Run scripts/update_docs_from_yaml.py and commit the result."
|
||||
git --no-pager diff
|
||||
exit 1
|
||||
fi
|
||||
+107
@@ -0,0 +1,107 @@
|
||||
name: Trigger basic downstream CI
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
on: [workflow_call, workflow_dispatch]
|
||||
|
||||
jobs:
|
||||
|
||||
trigger-downstream-ci:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Trigger OQS-BoringSSL CI
|
||||
if: ${{ !cancelled() }} # run all steps independent of failures
|
||||
run: |
|
||||
curl --silent \
|
||||
--write-out "\n%{response_code}\n" \
|
||||
--request POST \
|
||||
--header "Accept: application/vnd.github+json" \
|
||||
--header "Authorization: Bearer ${{ secrets.OQSBOT_GITHUB_ACTIONS }}" \
|
||||
--header "X-GitHub-Api-Version: 2022-11-28" \
|
||||
--data '{"event_type":"liboqs-upstream-trigger"}' \
|
||||
https://api.github.com/repos/open-quantum-safe/boringssl/dispatches | tee curl_out \
|
||||
&& grep -q "204" curl_out
|
||||
- name: Trigger OQS-OpenSSH CI
|
||||
if: ${{ !cancelled() }} # run all steps independent of failures
|
||||
run: |
|
||||
curl --silent \
|
||||
--write-out "\n%{response_code}\n" \
|
||||
--request POST \
|
||||
--header "Accept: application/vnd.github+json" \
|
||||
--header "Authorization: Bearer ${{ secrets.OQSBOT_GITHUB_ACTIONS }}" \
|
||||
--header "X-GitHub-Api-Version: 2022-11-28" \
|
||||
--data '{"ref":"OQS-v9"}' \
|
||||
https://api.github.com/repos/open-quantum-safe/openssh/actions/workflows/ubuntu.yaml/dispatches | tee curl_out \
|
||||
&& grep -q "204" curl_out
|
||||
- name: Trigger oqs-provider CI
|
||||
if: ${{ !cancelled() }} # run all steps independent of failures
|
||||
run: |
|
||||
curl --silent \
|
||||
--write-out "\n%{response_code}\n" \
|
||||
--user ${{ secrets.BUILD_TRIGGER_TOKEN }}: \
|
||||
--request POST \
|
||||
--header "Content-Type: application/json" \
|
||||
--data '{ "branch": "main" }' \
|
||||
https://circleci.com/api/v2/project/gh/open-quantum-safe/oqs-provider/pipeline | tee curl_out \
|
||||
&& grep -q "201" curl_out
|
||||
- name: Trigger liboqs-cpp CI
|
||||
if: ${{ !cancelled() }} # run all steps independent of failures
|
||||
run: |
|
||||
curl --silent \
|
||||
--write-out "\n%{response_code}\n" \
|
||||
--request POST \
|
||||
--header "Accept: application/vnd.github+json" \
|
||||
--header "Authorization: Bearer ${{ secrets.OQSBOT_GITHUB_ACTIONS }}" \
|
||||
--header "X-GitHub-Api-Version: 2022-11-28" \
|
||||
--data '{"event_type":"liboqs-upstream-trigger"}' \
|
||||
https://api.github.com/repos/open-quantum-safe/liboqs-cpp/dispatches | tee curl_out \
|
||||
&& grep -q "204" curl_out
|
||||
- name: Trigger liboqs-go CI
|
||||
if: ${{ !cancelled() }} # run all steps independent of failures
|
||||
run: |
|
||||
curl --silent \
|
||||
--write-out "\n%{response_code}\n" \
|
||||
--request POST \
|
||||
--header "Accept: application/vnd.github+json" \
|
||||
--header "Authorization: Bearer ${{ secrets.OQSBOT_GITHUB_ACTIONS }}" \
|
||||
--header "X-GitHub-Api-Version: 2022-11-28" \
|
||||
--data '{"event_type":"liboqs-upstream-trigger"}' \
|
||||
https://api.github.com/repos/open-quantum-safe/liboqs-go/dispatches | tee curl_out \
|
||||
&& grep -q "204" curl_out
|
||||
- name: Trigger liboqs-python CI
|
||||
if: ${{ !cancelled() }} # run all steps independent of failures
|
||||
run: |
|
||||
curl --silent \
|
||||
--write-out "\n%{response_code}\n" \
|
||||
--request POST \
|
||||
--header "Accept: application/vnd.github+json" \
|
||||
--header "Authorization: Bearer ${{ secrets.OQSBOT_GITHUB_ACTIONS }}" \
|
||||
--header "X-GitHub-Api-Version: 2022-11-28" \
|
||||
--data '{"event_type":"liboqs-upstream-trigger"}' \
|
||||
https://api.github.com/repos/open-quantum-safe/liboqs-python/dispatches | tee curl_out \
|
||||
&& grep -q "204" curl_out
|
||||
- name: Trigger liboqs-java CI
|
||||
if: ${{ !cancelled() }} # run all steps independent of failures
|
||||
run: |
|
||||
curl --silent \
|
||||
--write-out "\n%{response_code}\n" \
|
||||
--request POST \
|
||||
--header "Accept: application/vnd.github+json" \
|
||||
--header "Authorization: Bearer ${{ secrets.OQSBOT_GITHUB_ACTIONS }}" \
|
||||
--header "X-GitHub-Api-Version: 2022-11-28" \
|
||||
--data '{"event_type":"liboqs-upstream-trigger"}' \
|
||||
https://api.github.com/repos/open-quantum-safe/liboqs-java/dispatches | tee curl_out \
|
||||
&& grep -q "204" curl_out
|
||||
- name: Trigger liboqs-rust CI
|
||||
if: ${{ !cancelled() }} # run all steps independent of failures
|
||||
run: |
|
||||
curl --silent \
|
||||
--write-out "\n%{response_code}\n" \
|
||||
--request POST \
|
||||
--header "Accept: application/vnd.github+json" \
|
||||
--header "Authorization: Bearer ${{ secrets.OQSBOT_GITHUB_ACTIONS }}" \
|
||||
--header "X-GitHub-Api-Version: 2022-11-28" \
|
||||
--data '{"event_type":"liboqs-upstream-trigger"}' \
|
||||
https://api.github.com/repos/open-quantum-safe/liboqs-rust/dispatches | tee curl_out \
|
||||
&& grep -q "204" curl_out
|
||||
@@ -0,0 +1,30 @@
|
||||
name: Downstream release tests
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
on: [workflow_call, workflow_dispatch]
|
||||
|
||||
# Trigger oqs-provider release tests.
|
||||
# When triggered by a release (see release.yml), the liboqs release tag and the provider "<release tag>-tracker" branch are used.
|
||||
# When triggered by a commit message (see filter.yml), the triggering liboqs branch and the provider "<liboqs branch>-tracker" branch are used.
|
||||
# If the tracker branch does not exist, the downstream pipeline should detect it and run on the main branch instead.
|
||||
|
||||
jobs:
|
||||
oqs-provider-release-test:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Checkout release tests script
|
||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v4
|
||||
with:
|
||||
sparse-checkout: |
|
||||
scripts/provider-test-trigger.sh
|
||||
sparse-checkout-cone-mode: false
|
||||
- name: Trigger oqs-provider release tests
|
||||
run: |
|
||||
CURL_FLAGS="--silent --write-out \n%{response_code}\n" \
|
||||
ACCESS_TOKEN="${{ secrets.OQSBOT_GITHUB_ACTIONS }}" \
|
||||
LIBOQS_REF="${{ github.ref_name }}" \
|
||||
PROVIDER_REF="${{ github.ref_name }}-tracker" \
|
||||
./scripts/provider-test-trigger.sh | tee curl_out \
|
||||
&& grep -q "204" curl_out
|
||||
+122
@@ -0,0 +1,122 @@
|
||||
name: Extended tests
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
on: [workflow_call, workflow_dispatch]
|
||||
|
||||
jobs:
|
||||
|
||||
constant-time-x64:
|
||||
runs-on: ubuntu-latest
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
include:
|
||||
- name: generic
|
||||
container: openquantumsafe/ci-ubuntu-latest:latest
|
||||
CMAKE_ARGS: -DOQS_DIST_BUILD=OFF -DOQS_OPT_TARGET=generic -DCMAKE_BUILD_TYPE=Debug -DOQS_ENABLE_TEST_CONSTANT_TIME=ON
|
||||
PYTEST_ARGS: --numprocesses=auto -k 'test_constant_time'
|
||||
SKIP_ALGS: 'SLH_DSA_(SHA2|SHA3|SHAKE_128)(.)*'
|
||||
- name: extensions
|
||||
container: openquantumsafe/ci-ubuntu-latest:latest
|
||||
CMAKE_ARGS: -DOQS_DIST_BUILD=OFF -DOQS_OPT_TARGET=haswell -DCMAKE_BUILD_TYPE=Debug -DOQS_ENABLE_TEST_CONSTANT_TIME=ON
|
||||
PYTEST_ARGS: --numprocesses=auto -k 'test_constant_time'
|
||||
SKIP_ALGS: 'SLH_DSA_(SHA2|SHA3|SHAKE_128)(.)*'
|
||||
container:
|
||||
image: ${{ matrix.container }}
|
||||
steps:
|
||||
- name: Checkout code
|
||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2
|
||||
- name: Configure
|
||||
run: mkdir build && cd build && cmake -GNinja ${{ matrix.CMAKE_ARGS }} .. && cmake -LA -N ..
|
||||
- name: Build
|
||||
run: ninja
|
||||
working-directory: build
|
||||
- name: Run tests
|
||||
timeout-minutes: 360
|
||||
run: mkdir -p tmp && SKIP_ALGS='${{ matrix.SKIP_ALGS }}' python3 -m pytest --verbose ${{ matrix.PYTEST_ARGS }}
|
||||
|
||||
nistkat-x64:
|
||||
runs-on: ubuntu-latest
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
include:
|
||||
- name: generic
|
||||
container: openquantumsafe/ci-ubuntu-latest:latest
|
||||
CMAKE_ARGS: -DOQS_DIST_BUILD=OFF -DOQS_OPT_TARGET=generic
|
||||
PYTEST_ARGS: --numprocesses=auto -k 'test_kat_all'
|
||||
- name: generic-libjade
|
||||
container: openquantumsafe/ci-ubuntu-latest:latest
|
||||
CMAKE_ARGS: -DOQS_DIST_BUILD=OFF -DOQS_OPT_TARGET=generic -DOQS_LIBJADE_BUILD=ON -DOQS_MINIMAL_BUILD="${{ vars.LIBJADE_ALG_LIST }}"
|
||||
PYTEST_ARGS: --numprocesses=auto -k 'test_kat_all'
|
||||
- name: extensions
|
||||
container: openquantumsafe/ci-ubuntu-latest:latest
|
||||
CMAKE_ARGS: -DOQS_DIST_BUILD=OFF -DOQS_OPT_TARGET=auto
|
||||
PYTEST_ARGS: --numprocesses=auto -k 'test_kat_all'
|
||||
- name: extensions-libjade
|
||||
container: openquantumsafe/ci-ubuntu-latest:latest
|
||||
CMAKE_ARGS: -DOQS_DIST_BUILD=OFF -DOQS_OPT_TARGET=auto -DOQS_LIBJADE_BUILD=ON -DOQS_MINIMAL_BUILD="${{ vars.LIBJADE_ALG_LIST}}"
|
||||
PYTEST_ARGS: --numprocesses=auto -k 'test_kat_all'
|
||||
container:
|
||||
image: ${{ matrix.container }}
|
||||
steps:
|
||||
- name: Checkout code
|
||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v4
|
||||
- name: Configure
|
||||
run: mkdir build && cd build && cmake -GNinja ${{ matrix.CMAKE_ARGS }} .. && cmake -LA -N ..
|
||||
- name: Build
|
||||
run: ninja
|
||||
working-directory: build
|
||||
- name: Run tests
|
||||
timeout-minutes: 360
|
||||
run: mkdir -p tmp && python3 -m pytest --verbose ${{ matrix.PYTEST_ARGS }}
|
||||
|
||||
slhdsa-leak-tests:
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
include:
|
||||
- name: arm64-slhdsa
|
||||
runner: ubuntu-24.04-arm
|
||||
container: openquantumsafe/ci-ubuntu-latest:latest
|
||||
PYTEST_ARGS: --maxprocesses=10 --ignore=tests/test_kat_all.py
|
||||
CMAKE_ARGS: -DOQS_MINIMAL_BUILD=SIG_slh_dsa
|
||||
- name: alpine-slhdsa
|
||||
runner: ubuntu-latest
|
||||
container: openquantumsafe/ci-alpine-amd64:latest
|
||||
CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DOQS_USE_OPENSSL=ON -DBUILD_SHARED_LIBS=ON -DOQS_MINIMAL_BUILD=SIG_slh_dsa
|
||||
PYTEST_ARGS: --ignore=tests/test_alg_info.py --ignore=tests/test_kat_all.py
|
||||
runs-on: ${{ matrix.runner }}
|
||||
container:
|
||||
image: ${{ matrix.container }}
|
||||
steps:
|
||||
- name: Checkout code
|
||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v4
|
||||
- name: Configure
|
||||
run: mkdir build && cd build && cmake -GNinja ${{ matrix.CMAKE_ARGS }} .. && cmake -LA -N ..
|
||||
- name: Build
|
||||
run: ninja
|
||||
working-directory: build
|
||||
- name: Run tests
|
||||
timeout-minutes: 90
|
||||
run: mkdir -p tmp && SLH_DSA_LEAK_TEST=1 python3 -m pytest --verbose --numprocesses=auto tests/test_leaks.py::test_slhdsa_leak ${{ matrix.PYTEST_ARGS }}
|
||||
|
||||
address-sanitizer-slhdsa:
|
||||
strategy:
|
||||
fail-fast: false
|
||||
runs-on: ubuntu-latest
|
||||
container:
|
||||
image: openquantumsafe/ci-ubuntu-latest:latest
|
||||
steps:
|
||||
- name: Checkout code
|
||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v4
|
||||
- name: Configure
|
||||
run: mkdir build && cd build && cmake -GNinja -DCMAKE_C_COMPILER=clang -DCMAKE_BUILD_TYPE=Debug -DUSE_SANITIZER=Address -DOQS_MINIMAL_BUILD=SIG_slh_dsa .. && cmake -LA -N ..
|
||||
- name: Build
|
||||
run: ninja
|
||||
working-directory: build
|
||||
- name: Run tests
|
||||
timeout-minutes: 90
|
||||
run: mkdir -p tmp && python3 -m pytest --verbose --ignore=tests/test_code_conventions.py --numprocesses=auto --ignore=tests/test_distbuild.py --ignore=tests/test_leaks.py --ignore=tests/test_kat_all.py --maxprocesses=10
|
||||
+127
@@ -0,0 +1,127 @@
|
||||
name: kem benchmark
|
||||
|
||||
on:
|
||||
workflow_dispatch:
|
||||
workflow_call:
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
build:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
# Checkout repository
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v4
|
||||
with:
|
||||
fetch-depth: 0
|
||||
|
||||
# Set up dependencies
|
||||
- name: Install dependencies
|
||||
run: |
|
||||
sudo apt-get update
|
||||
sudo apt-get install -y cmake ninja-build gcc g++ python3 python3-pip
|
||||
sudo apt-get install -y python3-cpuinfo
|
||||
|
||||
# Build the speed_kem binary only
|
||||
- name: Build speed_kem binary
|
||||
run: |
|
||||
mkdir -p build
|
||||
cd build
|
||||
cmake -GNinja .. -DBUILD_SHARED_LIBS=OFF
|
||||
ninja speed_kem
|
||||
|
||||
# Copy the parse_liboqs_speed.py script
|
||||
- name: Copy parse_liboqs_speed.py
|
||||
run: |
|
||||
cp scripts/parse_liboqs_speed.py build/tests/
|
||||
|
||||
# Upload the built binary and script as an artifact
|
||||
- name: Upload artifacts
|
||||
uses: actions/upload-artifact@6027e3dd177782cd8ab9af838c04fd81a07f1d47
|
||||
with:
|
||||
name: built-binary
|
||||
path: build/tests/
|
||||
|
||||
benchmark:
|
||||
needs: build
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
contents: write
|
||||
strategy:
|
||||
matrix:
|
||||
algorithm: [ # List of available KEMs to perform the benchmarking on
|
||||
"BIKE-L1",
|
||||
"BIKE-L3",
|
||||
"BIKE-L5",
|
||||
"Classic-McEliece-348864",
|
||||
"Classic-McEliece-348864f",
|
||||
"Classic-McEliece-460896",
|
||||
"Classic-McEliece-460896f",
|
||||
"Classic-McEliece-6688128",
|
||||
"Classic-McEliece-6688128f",
|
||||
"Classic-McEliece-6960119",
|
||||
"Classic-McEliece-6960119f",
|
||||
"Classic-McEliece-8192128",
|
||||
"Classic-McEliece-8192128f",
|
||||
"Kyber512",
|
||||
"Kyber768",
|
||||
"Kyber1024",
|
||||
"ML-KEM-512",
|
||||
"ML-KEM-768",
|
||||
"ML-KEM-1024",
|
||||
"sntrup761",
|
||||
"FrodoKEM-640-AES",
|
||||
"FrodoKEM-640-SHAKE",
|
||||
"FrodoKEM-976-AES",
|
||||
"FrodoKEM-976-SHAKE",
|
||||
"FrodoKEM-1344-AES",
|
||||
"FrodoKEM-1344-SHAKE",
|
||||
"eFrodoKEM-640-AES",
|
||||
"eFrodoKEM-640-SHAKE",
|
||||
"eFrodoKEM-976-AES",
|
||||
"eFrodoKEM-976-SHAKE",
|
||||
"eFrodoKEM-1344-AES",
|
||||
"eFrodoKEM-1344-SHAKE"
|
||||
]
|
||||
max-parallel: 1 # No parallel jobs to not compromise the pull-push operations of the benchmarking actions below
|
||||
|
||||
steps:
|
||||
# Ensure the repository is checked out
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v4
|
||||
with:
|
||||
fetch-depth: 0
|
||||
|
||||
# Download the built binary and script
|
||||
- name: Download artifacts
|
||||
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # pin@v8.0.1
|
||||
with:
|
||||
name: built-binary
|
||||
path: build/tests/
|
||||
|
||||
# Set execute permissions for the binary
|
||||
- name: Set execute permissions
|
||||
run: chmod +x build/tests/speed_kem
|
||||
|
||||
# Run speed_kem tests for each algorithm
|
||||
- name: Run speed_kem tests
|
||||
run: |
|
||||
cd build/tests
|
||||
./speed_kem "${{matrix.algorithm}}" > ${{matrix.algorithm}}_output.txt
|
||||
python3 parse_liboqs_speed.py ${{matrix.algorithm}}_output.txt --algorithm ${{matrix.algorithm}}
|
||||
|
||||
# Push to GitHub pages using continuous-benchmark
|
||||
- name: Store benchmark result
|
||||
uses: benchmark-action/github-action-benchmark@52576c92bccf6ac60c8223ec7eb2565637cae9ba
|
||||
with:
|
||||
name: ${{matrix.algorithm}}
|
||||
tool: "customSmallerIsBetter"
|
||||
output-file-path: build/tests/${{matrix.algorithm}}_formatted.json
|
||||
github-token: ${{ secrets.GITHUB_TOKEN }}
|
||||
auto-push: true
|
||||
comment-on-alert: true
|
||||
summary-always: true
|
||||
alert-threshold: 105%
|
||||
comment-always: false
|
||||
+298
@@ -0,0 +1,298 @@
|
||||
name: Linux tests
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
on: [workflow_call, workflow_dispatch]
|
||||
|
||||
jobs:
|
||||
|
||||
linux:
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
include:
|
||||
- name: arm64
|
||||
runner: ubuntu-24.04-arm
|
||||
container: openquantumsafe/ci-ubuntu-latest:latest
|
||||
PYTEST_ARGS: --maxprocesses=10 --ignore=tests/test_kat_all.py
|
||||
CMAKE_ARGS: -DOQS_ENABLE_SIG_SLH_DSA=OFF -DOQS_ENABLE_SIG_STFL_LMS=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_HAZARDOUS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=ON
|
||||
- name: arm64-slhdsa
|
||||
runner: ubuntu-24.04-arm
|
||||
container: openquantumsafe/ci-ubuntu-latest:latest
|
||||
PYTEST_ARGS: --maxprocesses=10 --ignore=tests/test_kat_all.py
|
||||
CMAKE_ARGS: -DOQS_MINIMAL_BUILD=SIG_slh_dsa
|
||||
- name: alpine
|
||||
runner: ubuntu-latest
|
||||
container: openquantumsafe/ci-alpine-amd64:latest
|
||||
CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DOQS_USE_OPENSSL=ON -DBUILD_SHARED_LIBS=ON -DOQS_ENABLE_SIG_SLH_DSA=OFF -DOQS_HAZARDOUS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON
|
||||
PYTEST_ARGS: --ignore=tests/test_alg_info.py --ignore=tests/test_kat_all.py
|
||||
- name: alpine-slhdsa
|
||||
runner: ubuntu-latest
|
||||
container: openquantumsafe/ci-alpine-amd64:latest
|
||||
CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DOQS_USE_OPENSSL=ON -DBUILD_SHARED_LIBS=ON -DOQS_MINIMAL_BUILD=SIG_slh_dsa
|
||||
PYTEST_ARGS: --ignore=tests/test_alg_info.py --ignore=tests/test_kat_all.py
|
||||
- name: alpine-libjade
|
||||
runner: ubuntu-latest
|
||||
container: openquantumsafe/ci-alpine-amd64:latest
|
||||
CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DOQS_USE_OPENSSL=ON -DBUILD_SHARED_LIBS=ON -DOQS_LIBJADE_BUILD=ON -DOQS_MINIMAL_BUILD="${{ vars.LIBJADE_ALG_LIST }}"
|
||||
PYTEST_ARGS: --ignore=tests/test_alg_info.py --ignore=tests/test_kat_all.py
|
||||
- name: alpine-no-stfl-key-sig-gen
|
||||
runner: ubuntu-latest
|
||||
container: openquantumsafe/ci-alpine-amd64:latest
|
||||
CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DOQS_USE_OPENSSL=ON -DBUILD_SHARED_LIBS=ON -DOQS_ENABLE_SIG_SLH_DSA=OFF -DOQS_HAZARDOUS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=OFF -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON
|
||||
PYTEST_ARGS: --ignore=tests/test_alg_info.py --ignore=tests/test_kat_all.py
|
||||
- name: alpine-openssl-all
|
||||
runner: ubuntu-latest
|
||||
container: openquantumsafe/ci-alpine-amd64:latest
|
||||
CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DOQS_USE_OPENSSL=ON -DBUILD_SHARED_LIBS=ON -DOQS_USE_AES_OPENSSL=ON -DOQS_USE_SHA2_OPENSSL=ON -DOQS_USE_SHA3_OPENSSL=ON -DOQS_ENABLE_SIG_SLH_DSA=OFF -DOQS_HAZARDOUS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON
|
||||
PYTEST_ARGS: --ignore=tests/test_alg_info.py --ignore=tests/test_kat_all.py
|
||||
- name: alpine-noopenssl
|
||||
runner: ubuntu-latest
|
||||
container: openquantumsafe/ci-alpine-amd64:latest
|
||||
CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DOQS_USE_OPENSSL=OFF -DOQS_ENABLE_SIG_SLH_DSA=OFF -DOQS_HAZARDOUS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON
|
||||
PYTEST_ARGS: --ignore=tests/test_alg_info.py --ignore=tests/test_kat_all.py
|
||||
- name: alpine-openssl-all-slhdsa
|
||||
runner: ubuntu-latest
|
||||
container: openquantumsafe/ci-alpine-amd64:latest
|
||||
CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DOQS_USE_OPENSSL=ON -DBUILD_SHARED_LIBS=ON -DOQS_USE_AES_OPENSSL=ON -DOQS_USE_SHA2_OPENSSL=ON -DOQS_USE_SHA3_OPENSSL=ON -DOQS_MINIMAL_BUILD=SIG_slh_dsa
|
||||
PYTEST_ARGS: --ignore=tests/test_alg_info.py --ignore=tests/test_kat_all.py
|
||||
- name: alpine-noopenssl-slhdsa
|
||||
runner: ubuntu-latest
|
||||
container: openquantumsafe/ci-alpine-amd64:latest
|
||||
CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DOQS_USE_OPENSSL=OFF -DOQS_MINIMAL_BUILD=SIG_slh_dsa
|
||||
PYTEST_ARGS: --ignore=tests/test_alg_info.py --ignore=tests/test_kat_all.py
|
||||
- name: noble-nistr4-openssl
|
||||
runner: ubuntu-latest
|
||||
container: openquantumsafe/ci-ubuntu-latest:latest
|
||||
CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DOQS_ALGS_ENABLED=NIST_R4
|
||||
PYTEST_ARGS: --ignore=tests/test_leaks.py --ignore=tests/test_kat_all.py
|
||||
- name: noble-nistonramp-openssl
|
||||
runner: ubuntu-latest
|
||||
container: openquantumsafe/ci-ubuntu-latest:latest
|
||||
CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DOQS_ALGS_ENABLED=NIST_SIG_ONRAMP
|
||||
PYTEST_ARGS: --ignore=tests/test_leaks.py --ignore=tests/test_kat_all.py
|
||||
- name: noble-noopenssl
|
||||
runner: ubuntu-latest
|
||||
container: openquantumsafe/ci-ubuntu-latest:latest
|
||||
CMAKE_ARGS: -DOQS_USE_OPENSSL=OFF
|
||||
PYTEST_ARGS: --ignore=tests/test_leaks.py --ignore=tests/test_kat_all.py
|
||||
- name: noble-noopenssl-libjade
|
||||
runner: ubuntu-latest
|
||||
container: openquantumsafe/ci-ubuntu-latest:latest
|
||||
CMAKE_ARGS: -DOQS_USE_OPENSSL=OFF -DOQS_LIBJADE_BUILD=ON -DOQS_MINIMAL_BUILD="${{ vars.LIBJADE_ALG_LIST }}"
|
||||
PYTEST_ARGS: --ignore=tests/test_leaks.py --ignore=tests/test_kat_all.py
|
||||
- name: noble-shared-noopenssl
|
||||
runner: ubuntu-latest
|
||||
container: openquantumsafe/ci-ubuntu-latest:latest
|
||||
CMAKE_ARGS: -DOQS_DIST_BUILD=OFF -DOQS_USE_OPENSSL=OFF -DBUILD_SHARED_LIBS=ON
|
||||
PYTEST_ARGS: --ignore=tests/test_namespace.py --ignore=tests/test_leaks.py --ignore=tests/test_kat_all.py
|
||||
- name: noble-memopt
|
||||
runner: ubuntu-latest
|
||||
container: openquantumsafe/ci-ubuntu-latest:latest
|
||||
CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DOQS_MEMOPT_BUILD=ON
|
||||
PYTEST_ARGS: --ignore=tests/test_kat_all.py
|
||||
- name: jammy-clang
|
||||
runner: ubuntu-latest
|
||||
container: openquantumsafe/ci-ubuntu-jammy:latest
|
||||
CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DCMAKE_C_COMPILER=clang
|
||||
PYTEST_ARGS: --ignore=tests/test_kat_all.py
|
||||
- name: noble-clang
|
||||
runner: ubuntu-latest
|
||||
container: openquantumsafe/ci-ubuntu-latest:latest
|
||||
CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DCMAKE_C_COMPILER=clang
|
||||
PYTEST_ARGS: --ignore=tests/test_kat_all.py -k 'not (leaks and ML-DSA)'
|
||||
- name: jammy-std-openssl3
|
||||
runner: ubuntu-latest
|
||||
container: openquantumsafe/ci-ubuntu-jammy:latest
|
||||
CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DOQS_ALGS_ENABLED=STD -DBUILD_SHARED_LIBS=ON
|
||||
PYTEST_ARGS: --ignore=tests/test_leaks.py --ignore=tests/test_kat_all.py
|
||||
- name: jammy-std-openssl3-libjade
|
||||
runner: ubuntu-latest
|
||||
container: openquantumsafe/ci-ubuntu-jammy:latest
|
||||
CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DOQS_ALGS_ENABLED=STD -DBUILD_SHARED_LIBS=ON -DOQS_LIBJADE_BUILD=ON -DOQS_MINIMAL_BUILD="${{ vars.LIBJADE_ALG_LIST }}"
|
||||
PYTEST_ARGS: --ignore=tests/test_leaks.py --ignore=tests/test_kat_all.py
|
||||
- name: jammy-std-openssl3-dlopen
|
||||
runner: ubuntu-latest
|
||||
container: openquantumsafe/ci-ubuntu-jammy:latest
|
||||
CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DOQS_ALGS_ENABLED=STD -DBUILD_SHARED_LIBS=ON -DOQS_DLOPEN_OPENSSL=ON
|
||||
PYTEST_ARGS: --ignore=tests/test_leaks.py --ignore=tests/test_kat_all.py
|
||||
- name: jammy-std-openssl3-dlopen-libjade
|
||||
runner: ubuntu-latest
|
||||
container: openquantumsafe/ci-ubuntu-jammy:latest
|
||||
CMAKE_ARGS: -DOQS_STRICT_WARNINGS=ON -DOQS_ALGS_ENABLED=STD -DBUILD_SHARED_LIBS=ON -DOQS_DLOPEN_OPENSSL=ON -DOQS_LIBJADE_BUILD=ON -DOQS_MINIMAL_BUILD="${{ vars.LIBJADE_ALG_LIST }}"
|
||||
PYTEST_ARGS: --ignore=tests/test_leaks.py --ignore=tests/test_kat_all.py
|
||||
- name: address-sanitizer
|
||||
runner: ubuntu-latest
|
||||
container: openquantumsafe/ci-ubuntu-latest:latest
|
||||
CMAKE_ARGS: -DCMAKE_C_COMPILER=clang -DCMAKE_BUILD_TYPE=Debug -DUSE_SANITIZER=Address -DOQS_ENABLE_SIG_SLH_DSA=OFF -DOQS_HAZARDOUS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON
|
||||
PYTEST_ARGS: --ignore=tests/test_distbuild.py --ignore=tests/test_leaks.py --ignore=tests/test_kat_all.py --maxprocesses=10
|
||||
- name: address-sanitizer-no-stfl-key-sig-gen
|
||||
runner: ubuntu-latest
|
||||
container: openquantumsafe/ci-ubuntu-latest:latest
|
||||
CMAKE_ARGS: -DCMAKE_C_COMPILER=clang -DCMAKE_BUILD_TYPE=Debug -DUSE_SANITIZER=Address -DOQS_ENABLE_SIG_SLH_DSA=OFF -DOQS_HAZARDOUS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=OFF -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON
|
||||
PYTEST_ARGS: --ignore=tests/test_distbuild.py --ignore=tests/test_leaks.py --ignore=tests/test_kat_all.py --maxprocesses=10
|
||||
- name: address-sanitizer-libjade
|
||||
runner: ubuntu-latest
|
||||
container: openquantumsafe/ci-ubuntu-latest:latest
|
||||
CMAKE_ARGS: -DCMAKE_C_COMPILER=clang -DCMAKE_BUILD_TYPE=Debug -DUSE_SANITIZER=Address -DOQS_LIBJADE_BUILD=ON -DOQS_MINIMAL_BUILD="${{ vars.LIBJADE_ALG_LIST }}" -DOQS_ENABLE_SIG_SLH_DSA=OFF
|
||||
PYTEST_ARGS: --ignore=tests/test_distbuild.py --ignore=tests/test_leaks.py --ignore=tests/test_kat_all.py --maxprocesses=10
|
||||
- name: noble-no-sha3-avx512vl
|
||||
runner: ubuntu-latest
|
||||
container: openquantumsafe/ci-ubuntu-latest:latest
|
||||
CMAKE_ARGS: -DOQS_USE_SHA3_AVX512VL=OFF
|
||||
PYTEST_ARGS: --ignore=tests/test_leaks.py --ignore=tests/test_kat_all.py
|
||||
runs-on: ${{ matrix.runner }}
|
||||
timeout-minutes: 85 # max + 3*std over the last thousands of successful runs
|
||||
|
||||
container:
|
||||
image: ${{ matrix.container }}
|
||||
steps:
|
||||
- name: Checkout code
|
||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v4
|
||||
- name: Configure
|
||||
run: mkdir build && cd build && cmake -GNinja ${{ matrix.CMAKE_ARGS }} .. && cmake -LA -N ..
|
||||
- name: Build
|
||||
run: ninja
|
||||
working-directory: build
|
||||
- name: Check the library artifacts
|
||||
if: matrix.name == 'jammy-std-openssl3-dlopen'
|
||||
run: |
|
||||
nm -gu lib/liboqs.so | sed -n 's/^[[:space:]]*[Uw] \([^_].*\)/\1/p' > undefined-syms.txt &&
|
||||
! (grep '^\(CRYPTO\|ERR\|EVP\|OPENSSL\|RAND\)_' undefined-syms.txt)
|
||||
working-directory: build
|
||||
- name: Run tests
|
||||
timeout-minutes: 60
|
||||
run: mkdir -p tmp && python3 -m pytest --verbose --ignore=tests/test_code_conventions.py --numprocesses=auto ${{ matrix.PYTEST_ARGS }}
|
||||
- name: Package .deb
|
||||
if: matrix.name == 'jammy-std-openssl3'
|
||||
run: cpack
|
||||
working-directory: build
|
||||
- name: Retain .deb file
|
||||
if: matrix.name == 'jammy-std-openssl3'
|
||||
uses: actions/upload-artifact@1746f4ab65b179e0ea60a494b83293b640dd5bba # pin@v4
|
||||
with:
|
||||
name: liboqs-openssl3-shared-x64
|
||||
path: build/*.deb
|
||||
- name: Check STD algorithm and alias
|
||||
if: matrix.name == 'jammy-std-openssl3'
|
||||
run: 'tests/dump_alg_info | grep -zoP "ML-DSA-44:\n isnull: false" && tests/dump_alg_info | grep -zoP "ML-KEM-512:\n isnull: false"'
|
||||
working-directory: build
|
||||
|
||||
linux_cross_compile:
|
||||
runs-on: ubuntu-latest
|
||||
container: openquantumsafe/ci-ubuntu-latest:latest
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
include:
|
||||
- name: windows-binaries
|
||||
CMAKE_ARGS: -DCMAKE_TOOLCHAIN_FILE=../.CMake/toolchain_windows-amd64.cmake
|
||||
- name: windows-dll
|
||||
CMAKE_ARGS: -DCMAKE_TOOLCHAIN_FILE=../.CMake/toolchain_windows-amd64.cmake -DBUILD_SHARED_LIBS=ON
|
||||
steps:
|
||||
- name: Checkout code
|
||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v4
|
||||
- name: Configure
|
||||
run: mkdir build && cd build && cmake -GNinja ${{ matrix.CMAKE_ARGS }} .. && cmake -LA -N ..
|
||||
- name: Build
|
||||
run: ninja
|
||||
working-directory: build
|
||||
|
||||
linux_openssl330-dev:
|
||||
runs-on: ubuntu-latest
|
||||
container:
|
||||
image: openquantumsafe/ci-ubuntu-jammy:latest
|
||||
steps:
|
||||
- name: Checkout code
|
||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v4
|
||||
- name: Retrieve OpenSSL330 from cache
|
||||
id: cache-openssl330
|
||||
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # pin@v4
|
||||
with:
|
||||
path: .localopenssl330
|
||||
key: ${{ runner.os }}-openssl330
|
||||
- name: Checkout the OpenSSL v3.3.0 commit
|
||||
if: steps.cache-openssl330.outputs.cache-hit != 'true'
|
||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v4
|
||||
with:
|
||||
repository: 'openssl/openssl'
|
||||
ref: 'openssl-3.3.0-beta1'
|
||||
path: openssl
|
||||
- name: Prepare the OpenSSL build directory
|
||||
if: steps.cache-openssl330.outputs.cache-hit != 'true'
|
||||
run: mkdir .localopenssl330
|
||||
working-directory: openssl
|
||||
- name: Build openssl3 if not cached
|
||||
if: steps.cache-openssl330.outputs.cache-hit != 'true'
|
||||
run: |
|
||||
./config --prefix=`pwd`/../.localopenssl330 && make -j 4 && make install_sw install_ssldirs
|
||||
working-directory: openssl
|
||||
- name: Save OpenSSL
|
||||
id: cache-openssl-save
|
||||
if: steps.cache-openssl330.outputs.cache-hit != 'true'
|
||||
uses: actions/cache/save@27d5ce7f107fe9357f9df03efb73ab90386fccae # pin@v4
|
||||
with:
|
||||
path: |
|
||||
.localopenssl330
|
||||
key: ${{ runner.os }}-openssl330
|
||||
- name: Configure
|
||||
run: mkdir build && cd build && cmake -GNinja -DOQS_STRICT_WARNINGS=ON -DOPENSSL_ROOT_DIR=../.localopenssl330 -DOQS_USE_OPENSSL=ON -DBUILD_SHARED_LIBS=ON -DOQS_USE_AES_OPENSSL=ON -DOQS_USE_SHA2_OPENSSL=ON -DOQS_USE_SHA3_OPENSSL=ON .. && cmake -LA -N ..
|
||||
- name: Build
|
||||
run: ninja
|
||||
working-directory: build
|
||||
- name: Run tests
|
||||
timeout-minutes: 60
|
||||
run: mkdir -p tmp && python3 -m pytest --verbose --ignore=tests/test_code_conventions.py --ignore=tests/test_leaks.py --ignore=tests/test_kat_all.py
|
||||
|
||||
scan_build:
|
||||
runs-on: ubuntu-latest
|
||||
container: openquantumsafe/ci-ubuntu-latest:latest
|
||||
steps:
|
||||
- name: Checkout code
|
||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v4
|
||||
- name: Configure
|
||||
run: mkdir build && cd build && scan-build --status-bugs cmake -GNinja ..
|
||||
- name: Build
|
||||
run: scan-build --status-bugs ninja
|
||||
working-directory: build
|
||||
|
||||
linux_x86_emulated:
|
||||
runs-on: ubuntu-latest
|
||||
container:
|
||||
image: openquantumsafe/ci-ubuntu-latest:latest
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
include:
|
||||
- name: avx512-ml-kem_ml-dsa
|
||||
SDE_ARCH: -skx
|
||||
CMAKE_ARGS: -DOQS_MINIMAL_BUILD="KEM_ml_kem_512;KEM_ml_kem_768;KEM_ml_kem_1024;SIG_ml_dsa_44;SIG_ml_dsa_65;SIG_ml_dsa_87"
|
||||
PYTEST_ARGS: tests/test_hash.py::test_sha3 tests/test_kat.py tests/test_acvp_vectors.py
|
||||
env:
|
||||
# NOTE: https://downloadmirror.intel.com returns 202 and an empty file
|
||||
SDE_URL: https://api.github.com/repos/open-quantum-safe/ci-containers/contents/intel-sde/sde-external-9.53.0-2025-03-16-lin.tar.xz
|
||||
steps:
|
||||
- name: Checkout code
|
||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v4
|
||||
- name: Setup Intel SDE
|
||||
# NOTE: source of checksum:
|
||||
# https://www.intel.com/content/www/us/en/download/684897/850782/intel-software-development-emulator.html
|
||||
run: |
|
||||
set -e && \
|
||||
wget --header="Accept: application/vnd.github.raw+json" "$SDE_URL" && \
|
||||
sha256sum sde-external-9.53.0-2025-03-16-lin.tar.xz > lhs && \
|
||||
echo "f55138df53378198e8c0a89598351cdb3c5e7f8819e63e472b0bc179afaad34c sde-external-9.53.0-2025-03-16-lin.tar.xz" > rhs && \
|
||||
diff lhs rhs && \
|
||||
mkdir sde && tar -xf sde-external-9.53.0-2025-03-16-lin.tar.xz -C sde --strip-components=1 && \
|
||||
echo "$(pwd)/sde" >> $GITHUB_PATH
|
||||
- name: Configure
|
||||
run: mkdir build && cd build && cmake -GNinja ${{ matrix.CMAKE_ARGS }} .. && cmake -LA -N ..
|
||||
- name: Build
|
||||
run: ninja
|
||||
working-directory: build
|
||||
- name: Run tests
|
||||
timeout-minutes: 60
|
||||
run: |
|
||||
mkdir -p tmp && sde64 ${{ matrix.SDE_ARCH }} -- \
|
||||
python3 -m pytest --verbose --numprocesses=auto ${{ matrix.PYTEST_ARGS }}
|
||||
+62
@@ -0,0 +1,62 @@
|
||||
name: MacOS tests
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
on: [workflow_call, workflow_dispatch]
|
||||
|
||||
jobs:
|
||||
|
||||
macos:
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
os:
|
||||
- macos-14
|
||||
- macos-15
|
||||
CMAKE_ARGS:
|
||||
- -DOQS_ENABLE_SIG_SLH_DSA=OFF -DOQS_HAZARDOUS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON
|
||||
- -DCMAKE_C_COMPILER=gcc-14
|
||||
- -DOQS_USE_OPENSSL=OFF
|
||||
- -DBUILD_SHARED_LIBS=ON -DOQS_DIST_BUILD=OFF
|
||||
libjade-build:
|
||||
- -DOQS_LIBJADE_BUILD=OFF
|
||||
# Restrict -DOQS_LIBJADE_BUILD=ON build to algs provided by
|
||||
# libjade to minimise repeated tests
|
||||
- -DOQS_LIBJADE_BUILD=ON -DOQS_MINIMAL_BUILD="${{ vars.LIBJADE_ALG_LIST }}"
|
||||
exclude:
|
||||
# macos-14 and macos-15 run on aarch64, libjade targets x86
|
||||
# Skip testing libjade on macos-14
|
||||
- os: macos-14
|
||||
libjade-build: -DOQS_LIBJADE_BUILD=ON -DOQS_MINIMAL_BUILD="${{ vars.LIBJADE_ALG_LIST }}"
|
||||
- os: macos-15
|
||||
libjade-build: -DOQS_LIBJADE_BUILD=ON -DOQS_MINIMAL_BUILD="${{ vars.LIBJADE_ALG_LIST }}"
|
||||
# No point in testing stateful sigs with minimal libjade build
|
||||
- libjade-build: -DOQS_LIBJADE_BUILD=ON -DOQS_MINIMAL_BUILD="${{ vars.LIBJADE_ALG_LIST }}"
|
||||
CMAKE_ARGS: -DOQS_ENABLE_SIG_SLH_DSA=OFF -DOQS_HAZARDOUS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_ENABLE_SIG_STFL_LMS=ON
|
||||
# Failing configuration on Github actions; see https://github.com/open-quantum-safe/liboqs/pull/2148
|
||||
- os: macos-15
|
||||
CMAKE_ARGS: -DCMAKE_C_COMPILER=gcc-14
|
||||
libjade-build: -DOQS_LIBJADE_BUILD=OFF
|
||||
|
||||
runs-on: ${{ matrix.os }}
|
||||
timeout-minutes: 85 # max + 3*std over the last thousands of successful runs
|
||||
steps:
|
||||
- name: Install Python
|
||||
uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # pin@v5
|
||||
with:
|
||||
python-version: '3.12'
|
||||
- name: Checkout code
|
||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v4
|
||||
- name: Install dependencies
|
||||
run: env HOMEBREW_NO_AUTO_UPDATE=1 brew install ninja && pip3 install --require-hashes --break-system-packages -r .github/workflows/requirements.txt
|
||||
- name: Get system information
|
||||
run: sysctl -a | grep machdep.cpu
|
||||
- name: Configure
|
||||
run: mkdir -p build && cd build && source ~/.bashrc && cmake -GNinja -DOQS_STRICT_WARNINGS=ON ${{ matrix.CMAKE_ARGS }} ${{ matrix.libjade-build }} .. && cmake -LA -N ..
|
||||
- name: Build
|
||||
run: ninja
|
||||
working-directory: build
|
||||
- name: Run tests
|
||||
run: mkdir -p tmp && python3 -m pytest --verbose --ignore=tests/test_code_conventions.py --ignore=tests/test_kat_all.py
|
||||
timeout-minutes: 60
|
||||
+26
@@ -0,0 +1,26 @@
|
||||
name: Tests for all supported platforms
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
on: [workflow_call, workflow_dispatch]
|
||||
|
||||
jobs:
|
||||
|
||||
android-tests:
|
||||
uses: ./.github/workflows/android.yml
|
||||
|
||||
ios-tests:
|
||||
uses: ./.github/workflows/apple.yml
|
||||
|
||||
linux-tests:
|
||||
uses: ./.github/workflows/linux.yml
|
||||
|
||||
macos-tests:
|
||||
uses: ./.github/workflows/macos.yml
|
||||
|
||||
windows-tests:
|
||||
uses: ./.github/workflows/windows.yml
|
||||
|
||||
zephyr-tests:
|
||||
uses: ./.github/workflows/zephyr.yml
|
||||
Vendored
+33
@@ -0,0 +1,33 @@
|
||||
name: Pull request tests
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
on: pull_request
|
||||
|
||||
concurrency:
|
||||
group: ${{ github.workflow }}-${{ github.ref }}
|
||||
cancel-in-progress: true
|
||||
|
||||
jobs:
|
||||
|
||||
basic-checks:
|
||||
uses: ./.github/workflows/basic.yml
|
||||
|
||||
platform-tests:
|
||||
needs: basic-checks
|
||||
uses: ./.github/workflows/platforms.yml
|
||||
|
||||
code-coverage:
|
||||
needs: basic-checks
|
||||
uses: ./.github/workflows/code-coverage.yml
|
||||
secrets: inherit
|
||||
|
||||
scorecard:
|
||||
needs: basic-checks
|
||||
uses: ./.github/workflows/supplychain.yml
|
||||
secrets: inherit
|
||||
permissions:
|
||||
contents: read
|
||||
id-token: write
|
||||
security-events: write
|
||||
+33
@@ -0,0 +1,33 @@
|
||||
name: Push tests
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
on:
|
||||
push:
|
||||
branches-ignore: 'main'
|
||||
|
||||
concurrency:
|
||||
group: ${{ github.workflow }}-${{ github.ref }}
|
||||
cancel-in-progress: true
|
||||
|
||||
jobs:
|
||||
|
||||
basic-checks:
|
||||
uses: ./.github/workflows/basic.yml
|
||||
|
||||
full-tests:
|
||||
needs: basic-checks
|
||||
if: contains( github.event.head_commit.message, '[full tests]' )
|
||||
uses: ./.github/workflows/platforms.yml
|
||||
|
||||
extended-tests:
|
||||
needs: basic-checks
|
||||
if: contains( github.event.head_commit.message, '[extended tests]' )
|
||||
uses: ./.github/workflows/extended.yml
|
||||
|
||||
downstream-release-tests:
|
||||
needs: basic-checks
|
||||
if: contains( github.event.head_commit.message, '[trigger downstream]' )
|
||||
uses: ./.github/workflows/downstream-release.yml
|
||||
secrets: inherit
|
||||
+17
@@ -0,0 +1,17 @@
|
||||
name: Release tests
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
on:
|
||||
release:
|
||||
types: [ published ]
|
||||
|
||||
jobs:
|
||||
|
||||
extended-tests:
|
||||
uses: ./.github/workflows/extended.yml
|
||||
|
||||
downstream-release-tests:
|
||||
uses: ./.github/workflows/downstream-release.yml
|
||||
secrets: inherit
|
||||
+11
@@ -0,0 +1,11 @@
|
||||
colorama==0.4.6
|
||||
execnet==2.1.2
|
||||
iniconfig==2.3.0
|
||||
jinja2==3.1.6
|
||||
packaging==26.2
|
||||
pluggy==1.6.0
|
||||
pytest==9.0.3
|
||||
pytest-xdist==3.8.0
|
||||
pyyaml==6.0.3
|
||||
requests==2.34.2
|
||||
tabulate==0.10.0
|
||||
+332
@@ -0,0 +1,332 @@
|
||||
#
|
||||
# This file is autogenerated by pip-compile with Python 3.13
|
||||
# by the following command:
|
||||
#
|
||||
# pip-compile --generate-hashes requirements.in
|
||||
#
|
||||
certifi==2025.6.15 \
|
||||
--hash=sha256:2e0c7ce7cb5d8f8634ca55d2ba7e6ec2689a2fd6537d8dec1296a477a4910057 \
|
||||
--hash=sha256:d747aa5a8b9bbbb1bb8c22bb13e22bd1f18e9796defa16bab421f7f7a317323b
|
||||
# via requests
|
||||
charset-normalizer==3.4.2 \
|
||||
--hash=sha256:005fa3432484527f9732ebd315da8da8001593e2cf46a3d817669f062c3d9ed4 \
|
||||
--hash=sha256:046595208aae0120559a67693ecc65dd75d46f7bf687f159127046628178dc45 \
|
||||
--hash=sha256:0c29de6a1a95f24b9a1aa7aefd27d2487263f00dfd55a77719b530788f75cff7 \
|
||||
--hash=sha256:0c8c57f84ccfc871a48a47321cfa49ae1df56cd1d965a09abe84066f6853b9c0 \
|
||||
--hash=sha256:0f5d9ed7f254402c9e7d35d2f5972c9bbea9040e99cd2861bd77dc68263277c7 \
|
||||
--hash=sha256:18dd2e350387c87dabe711b86f83c9c78af772c748904d372ade190b5c7c9d4d \
|
||||
--hash=sha256:1b1bde144d98e446b056ef98e59c256e9294f6b74d7af6846bf5ffdafd687a7d \
|
||||
--hash=sha256:1c95a1e2902a8b722868587c0e1184ad5c55631de5afc0eb96bc4b0d738092c0 \
|
||||
--hash=sha256:1cad5f45b3146325bb38d6855642f6fd609c3f7cad4dbaf75549bf3b904d3184 \
|
||||
--hash=sha256:21b2899062867b0e1fde9b724f8aecb1af14f2778d69aacd1a5a1853a597a5db \
|
||||
--hash=sha256:24498ba8ed6c2e0b56d4acbf83f2d989720a93b41d712ebd4f4979660db4417b \
|
||||
--hash=sha256:25a23ea5c7edc53e0f29bae2c44fcb5a1aa10591aae107f2a2b2583a9c5cbc64 \
|
||||
--hash=sha256:289200a18fa698949d2b39c671c2cc7a24d44096784e76614899a7ccf2574b7b \
|
||||
--hash=sha256:28a1005facc94196e1fb3e82a3d442a9d9110b8434fc1ded7a24a2983c9888d8 \
|
||||
--hash=sha256:32fc0341d72e0f73f80acb0a2c94216bd704f4f0bce10aedea38f30502b271ff \
|
||||
--hash=sha256:36b31da18b8890a76ec181c3cf44326bf2c48e36d393ca1b72b3f484113ea344 \
|
||||
--hash=sha256:3c21d4fca343c805a52c0c78edc01e3477f6dd1ad7c47653241cf2a206d4fc58 \
|
||||
--hash=sha256:3fddb7e2c84ac87ac3a947cb4e66d143ca5863ef48e4a5ecb83bd48619e4634e \
|
||||
--hash=sha256:43e0933a0eff183ee85833f341ec567c0980dae57c464d8a508e1b2ceb336471 \
|
||||
--hash=sha256:4a476b06fbcf359ad25d34a057b7219281286ae2477cc5ff5e3f70a246971148 \
|
||||
--hash=sha256:4e594135de17ab3866138f496755f302b72157d115086d100c3f19370839dd3a \
|
||||
--hash=sha256:50bf98d5e563b83cc29471fa114366e6806bc06bc7a25fd59641e41445327836 \
|
||||
--hash=sha256:5a9979887252a82fefd3d3ed2a8e3b937a7a809f65dcb1e068b090e165bbe99e \
|
||||
--hash=sha256:5baececa9ecba31eff645232d59845c07aa030f0c81ee70184a90d35099a0e63 \
|
||||
--hash=sha256:5bf4545e3b962767e5c06fe1738f951f77d27967cb2caa64c28be7c4563e162c \
|
||||
--hash=sha256:6333b3aa5a12c26b2a4d4e7335a28f1475e0e5e17d69d55141ee3cab736f66d1 \
|
||||
--hash=sha256:65c981bdbd3f57670af8b59777cbfae75364b483fa8a9f420f08094531d54a01 \
|
||||
--hash=sha256:68a328e5f55ec37c57f19ebb1fdc56a248db2e3e9ad769919a58672958e8f366 \
|
||||
--hash=sha256:6a0289e4589e8bdfef02a80478f1dfcb14f0ab696b5a00e1f4b8a14a307a3c58 \
|
||||
--hash=sha256:6b66f92b17849b85cad91259efc341dce9c1af48e2173bf38a85c6329f1033e5 \
|
||||
--hash=sha256:6c9379d65defcab82d07b2a9dfbfc2e95bc8fe0ebb1b176a3190230a3ef0e07c \
|
||||
--hash=sha256:6fc1f5b51fa4cecaa18f2bd7a003f3dd039dd615cd69a2afd6d3b19aed6775f2 \
|
||||
--hash=sha256:70f7172939fdf8790425ba31915bfbe8335030f05b9913d7ae00a87d4395620a \
|
||||
--hash=sha256:721c76e84fe669be19c5791da68232ca2e05ba5185575086e384352e2c309597 \
|
||||
--hash=sha256:7222ffd5e4de8e57e03ce2cef95a4c43c98fcb72ad86909abdfc2c17d227fc1b \
|
||||
--hash=sha256:75d10d37a47afee94919c4fab4c22b9bc2a8bf7d4f46f87363bcf0573f3ff4f5 \
|
||||
--hash=sha256:76af085e67e56c8816c3ccf256ebd136def2ed9654525348cfa744b6802b69eb \
|
||||
--hash=sha256:770cab594ecf99ae64c236bc9ee3439c3f46be49796e265ce0cc8bc17b10294f \
|
||||
--hash=sha256:7a6ab32f7210554a96cd9e33abe3ddd86732beeafc7a28e9955cdf22ffadbab0 \
|
||||
--hash=sha256:7c48ed483eb946e6c04ccbe02c6b4d1d48e51944b6db70f697e089c193404941 \
|
||||
--hash=sha256:7f56930ab0abd1c45cd15be65cc741c28b1c9a34876ce8c17a2fa107810c0af0 \
|
||||
--hash=sha256:8075c35cd58273fee266c58c0c9b670947c19df5fb98e7b66710e04ad4e9ff86 \
|
||||
--hash=sha256:8272b73e1c5603666618805fe821edba66892e2870058c94c53147602eab29c7 \
|
||||
--hash=sha256:82d8fd25b7f4675d0c47cf95b594d4e7b158aca33b76aa63d07186e13c0e0ab7 \
|
||||
--hash=sha256:844da2b5728b5ce0e32d863af26f32b5ce61bc4273a9c720a9f3aa9df73b1455 \
|
||||
--hash=sha256:8755483f3c00d6c9a77f490c17e6ab0c8729e39e6390328e42521ef175380ae6 \
|
||||
--hash=sha256:915f3849a011c1f593ab99092f3cecfcb4d65d8feb4a64cf1bf2d22074dc0ec4 \
|
||||
--hash=sha256:926ca93accd5d36ccdabd803392ddc3e03e6d4cd1cf17deff3b989ab8e9dbcf0 \
|
||||
--hash=sha256:982bb1e8b4ffda883b3d0a521e23abcd6fd17418f6d2c4118d257a10199c0ce3 \
|
||||
--hash=sha256:98f862da73774290f251b9df8d11161b6cf25b599a66baf087c1ffe340e9bfd1 \
|
||||
--hash=sha256:9cbfacf36cb0ec2897ce0ebc5d08ca44213af24265bd56eca54bee7923c48fd6 \
|
||||
--hash=sha256:a370b3e078e418187da8c3674eddb9d983ec09445c99a3a263c2011993522981 \
|
||||
--hash=sha256:a955b438e62efdf7e0b7b52a64dc5c3396e2634baa62471768a64bc2adb73d5c \
|
||||
--hash=sha256:aa6af9e7d59f9c12b33ae4e9450619cf2488e2bbe9b44030905877f0b2324980 \
|
||||
--hash=sha256:aa88ca0b1932e93f2d961bf3addbb2db902198dca337d88c89e1559e066e7645 \
|
||||
--hash=sha256:aaeeb6a479c7667fbe1099af9617c83aaca22182d6cf8c53966491a0f1b7ffb7 \
|
||||
--hash=sha256:aaf27faa992bfee0264dc1f03f4c75e9fcdda66a519db6b957a3f826e285cf12 \
|
||||
--hash=sha256:b2680962a4848b3c4f155dc2ee64505a9c57186d0d56b43123b17ca3de18f0fa \
|
||||
--hash=sha256:b2d318c11350e10662026ad0eb71bb51c7812fc8590825304ae0bdd4ac283acd \
|
||||
--hash=sha256:b33de11b92e9f75a2b545d6e9b6f37e398d86c3e9e9653c4864eb7e89c5773ef \
|
||||
--hash=sha256:b3daeac64d5b371dea99714f08ffc2c208522ec6b06fbc7866a450dd446f5c0f \
|
||||
--hash=sha256:be1e352acbe3c78727a16a455126d9ff83ea2dfdcbc83148d2982305a04714c2 \
|
||||
--hash=sha256:bee093bf902e1d8fc0ac143c88902c3dfc8941f7ea1d6a8dd2bcb786d33db03d \
|
||||
--hash=sha256:c72fbbe68c6f32f251bdc08b8611c7b3060612236e960ef848e0a517ddbe76c5 \
|
||||
--hash=sha256:c9e36a97bee9b86ef9a1cf7bb96747eb7a15c2f22bdb5b516434b00f2a599f02 \
|
||||
--hash=sha256:cddf7bd982eaa998934a91f69d182aec997c6c468898efe6679af88283b498d3 \
|
||||
--hash=sha256:cf713fe9a71ef6fd5adf7a79670135081cd4431c2943864757f0fa3a65b1fafd \
|
||||
--hash=sha256:d11b54acf878eef558599658b0ffca78138c8c3655cf4f3a4a673c437e67732e \
|
||||
--hash=sha256:d41c4d287cfc69060fa91cae9683eacffad989f1a10811995fa309df656ec214 \
|
||||
--hash=sha256:d524ba3f1581b35c03cb42beebab4a13e6cdad7b36246bd22541fa585a56cccd \
|
||||
--hash=sha256:daac4765328a919a805fa5e2720f3e94767abd632ae410a9062dff5412bae65a \
|
||||
--hash=sha256:db4c7bf0e07fc3b7d89ac2a5880a6a8062056801b83ff56d8464b70f65482b6c \
|
||||
--hash=sha256:dc7039885fa1baf9be153a0626e337aa7ec8bf96b0128605fb0d77788ddc1681 \
|
||||
--hash=sha256:dccab8d5fa1ef9bfba0590ecf4d46df048d18ffe3eec01eeb73a42e0d9e7a8ba \
|
||||
--hash=sha256:dedb8adb91d11846ee08bec4c8236c8549ac721c245678282dcb06b221aab59f \
|
||||
--hash=sha256:e45ba65510e2647721e35323d6ef54c7974959f6081b58d4ef5d87c60c84919a \
|
||||
--hash=sha256:e53efc7c7cee4c1e70661e2e112ca46a575f90ed9ae3fef200f2a25e954f4b28 \
|
||||
--hash=sha256:e635b87f01ebc977342e2697d05b56632f5f879a4f15955dfe8cef2448b51691 \
|
||||
--hash=sha256:e70e990b2137b29dc5564715de1e12701815dacc1d056308e2b17e9095372a82 \
|
||||
--hash=sha256:e8082b26888e2f8b36a042a58307d5b917ef2b1cacab921ad3323ef91901c71a \
|
||||
--hash=sha256:e8323a9b031aa0393768b87f04b4164a40037fb2a3c11ac06a03ffecd3618027 \
|
||||
--hash=sha256:e92fca20c46e9f5e1bb485887d074918b13543b1c2a1185e69bb8d17ab6236a7 \
|
||||
--hash=sha256:eb30abc20df9ab0814b5a2524f23d75dcf83cde762c161917a2b4b7b55b1e518 \
|
||||
--hash=sha256:eba9904b0f38a143592d9fc0e19e2df0fa2e41c3c3745554761c5f6447eedabf \
|
||||
--hash=sha256:ef8de666d6179b009dce7bcb2ad4c4a779f113f12caf8dc77f0162c29d20490b \
|
||||
--hash=sha256:efd387a49825780ff861998cd959767800d54f8308936b21025326de4b5a42b9 \
|
||||
--hash=sha256:f0aa37f3c979cf2546b73e8222bbfa3dc07a641585340179d768068e3455e544 \
|
||||
--hash=sha256:f4074c5a429281bf056ddd4c5d3b740ebca4d43ffffe2ef4bf4d2d05114299da \
|
||||
--hash=sha256:f69a27e45c43520f5487f27627059b64aaf160415589230992cec34c5e18a509 \
|
||||
--hash=sha256:fb707f3e15060adf5b7ada797624a6c6e0138e2a26baa089df64c68ee98e040f \
|
||||
--hash=sha256:fcbe676a55d7445b22c10967bceaaf0ee69407fbe0ece4d032b6eb8d4565982a \
|
||||
--hash=sha256:fdb20a30fe1175ecabed17cbf7812f7b804b8a315a25f24678bcdf120a90077f
|
||||
# via requests
|
||||
colorama==0.4.6 \
|
||||
--hash=sha256:08695f5cb7ed6e0531a20572697297273c47b8cae5a63ffc6d6ed5c201be6e44 \
|
||||
--hash=sha256:4f1d9991f5acc0ca119f9d443620b77f9d6b33703e51011c16baf57afb285fc6
|
||||
# via -r requirements.in
|
||||
execnet==2.1.2 \
|
||||
--hash=sha256:63d83bfdd9a23e35b9c6a3261412324f964c2ec8dcd8d3c6916ee9373e0befcd \
|
||||
--hash=sha256:67fba928dd5a544b783f6056f449e5e3931a5c378b128bc18501f7ea79e296ec
|
||||
# via
|
||||
# -r requirements.in
|
||||
# pytest-xdist
|
||||
idna==3.15 \
|
||||
--hash=sha256:048adeaf8c2d788c40fee287673ccaa74c24ffd8dcf09ffa555a2fbb59f10ac8 \
|
||||
--hash=sha256:ca962446ea538f7092a95e057da437618e886f4d349216d2b1e294abfdb65fdc
|
||||
# via requests
|
||||
iniconfig==2.3.0 \
|
||||
--hash=sha256:c76315c77db068650d49c5b56314774a7804df16fee4402c1f19d6d15d8c4730 \
|
||||
--hash=sha256:f631c04d2c48c52b84d0d0549c99ff3859c98df65b3101406327ecc7d53fbf12
|
||||
# via
|
||||
# -r requirements.in
|
||||
# pytest
|
||||
jinja2==3.1.6 \
|
||||
--hash=sha256:0137fb05990d35f1275a587e9aee6d56da821fc83491a0fb838183be43f66d6d \
|
||||
--hash=sha256:85ece4451f492d0c13c5dd7c13a64681a86afae63a5f347908daf103ce6d2f67
|
||||
# via -r requirements.in
|
||||
markupsafe==3.0.3 \
|
||||
--hash=sha256:0303439a41979d9e74d18ff5e2dd8c43ed6c6001fd40e5bf2e43f7bd9bbc523f \
|
||||
--hash=sha256:068f375c472b3e7acbe2d5318dea141359e6900156b5b2ba06a30b169086b91a \
|
||||
--hash=sha256:0bf2a864d67e76e5c9a34dc26ec616a66b9888e25e7b9460e1c76d3293bd9dbf \
|
||||
--hash=sha256:0db14f5dafddbb6d9208827849fad01f1a2609380add406671a26386cdf15a19 \
|
||||
--hash=sha256:0eb9ff8191e8498cca014656ae6b8d61f39da5f95b488805da4bb029cccbfbaf \
|
||||
--hash=sha256:0f4b68347f8c5eab4a13419215bdfd7f8c9b19f2b25520968adfad23eb0ce60c \
|
||||
--hash=sha256:1085e7fbddd3be5f89cc898938f42c0b3c711fdcb37d75221de2666af647c175 \
|
||||
--hash=sha256:116bb52f642a37c115f517494ea5feb03889e04df47eeff5b130b1808ce7c219 \
|
||||
--hash=sha256:12c63dfb4a98206f045aa9563db46507995f7ef6d83b2f68eda65c307c6829eb \
|
||||
--hash=sha256:133a43e73a802c5562be9bbcd03d090aa5a1fe899db609c29e8c8d815c5f6de6 \
|
||||
--hash=sha256:1353ef0c1b138e1907ae78e2f6c63ff67501122006b0f9abad68fda5f4ffc6ab \
|
||||
--hash=sha256:15d939a21d546304880945ca1ecb8a039db6b4dc49b2c5a400387cdae6a62e26 \
|
||||
--hash=sha256:177b5253b2834fe3678cb4a5f0059808258584c559193998be2601324fdeafb1 \
|
||||
--hash=sha256:1872df69a4de6aead3491198eaf13810b565bdbeec3ae2dc8780f14458ec73ce \
|
||||
--hash=sha256:1b4b79e8ebf6b55351f0d91fe80f893b4743f104bff22e90697db1590e47a218 \
|
||||
--hash=sha256:1b52b4fb9df4eb9ae465f8d0c228a00624de2334f216f178a995ccdcf82c4634 \
|
||||
--hash=sha256:1ba88449deb3de88bd40044603fafffb7bc2b055d626a330323a9ed736661695 \
|
||||
--hash=sha256:1cc7ea17a6824959616c525620e387f6dd30fec8cb44f649e31712db02123dad \
|
||||
--hash=sha256:218551f6df4868a8d527e3062d0fb968682fe92054e89978594c28e642c43a73 \
|
||||
--hash=sha256:26a5784ded40c9e318cfc2bdb30fe164bdb8665ded9cd64d500a34fb42067b1c \
|
||||
--hash=sha256:2713baf880df847f2bece4230d4d094280f4e67b1e813eec43b4c0e144a34ffe \
|
||||
--hash=sha256:2a15a08b17dd94c53a1da0438822d70ebcd13f8c3a95abe3a9ef9f11a94830aa \
|
||||
--hash=sha256:2f981d352f04553a7171b8e44369f2af4055f888dfb147d55e42d29e29e74559 \
|
||||
--hash=sha256:32001d6a8fc98c8cb5c947787c5d08b0a50663d139f1305bac5885d98d9b40fa \
|
||||
--hash=sha256:3524b778fe5cfb3452a09d31e7b5adefeea8c5be1d43c4f810ba09f2ceb29d37 \
|
||||
--hash=sha256:3537e01efc9d4dccdf77221fb1cb3b8e1a38d5428920e0657ce299b20324d758 \
|
||||
--hash=sha256:35add3b638a5d900e807944a078b51922212fb3dedb01633a8defc4b01a3c85f \
|
||||
--hash=sha256:38664109c14ffc9e7437e86b4dceb442b0096dfe3541d7864d9cbe1da4cf36c8 \
|
||||
--hash=sha256:3a7e8ae81ae39e62a41ec302f972ba6ae23a5c5396c8e60113e9066ef893da0d \
|
||||
--hash=sha256:3b562dd9e9ea93f13d53989d23a7e775fdfd1066c33494ff43f5418bc8c58a5c \
|
||||
--hash=sha256:457a69a9577064c05a97c41f4e65148652db078a3a509039e64d3467b9e7ef97 \
|
||||
--hash=sha256:4bd4cd07944443f5a265608cc6aab442e4f74dff8088b0dfc8238647b8f6ae9a \
|
||||
--hash=sha256:4e885a3d1efa2eadc93c894a21770e4bc67899e3543680313b09f139e149ab19 \
|
||||
--hash=sha256:4faffd047e07c38848ce017e8725090413cd80cbc23d86e55c587bf979e579c9 \
|
||||
--hash=sha256:509fa21c6deb7a7a273d629cf5ec029bc209d1a51178615ddf718f5918992ab9 \
|
||||
--hash=sha256:5678211cb9333a6468fb8d8be0305520aa073f50d17f089b5b4b477ea6e67fdc \
|
||||
--hash=sha256:591ae9f2a647529ca990bc681daebdd52c8791ff06c2bfa05b65163e28102ef2 \
|
||||
--hash=sha256:5a7d5dc5140555cf21a6fefbdbf8723f06fcd2f63ef108f2854de715e4422cb4 \
|
||||
--hash=sha256:69c0b73548bc525c8cb9a251cddf1931d1db4d2258e9599c28c07ef3580ef354 \
|
||||
--hash=sha256:6b5420a1d9450023228968e7e6a9ce57f65d148ab56d2313fcd589eee96a7a50 \
|
||||
--hash=sha256:722695808f4b6457b320fdc131280796bdceb04ab50fe1795cd540799ebe1698 \
|
||||
--hash=sha256:729586769a26dbceff69f7a7dbbf59ab6572b99d94576a5592625d5b411576b9 \
|
||||
--hash=sha256:77f0643abe7495da77fb436f50f8dab76dbc6e5fd25d39589a0f1fe6548bfa2b \
|
||||
--hash=sha256:795e7751525cae078558e679d646ae45574b47ed6e7771863fcc079a6171a0fc \
|
||||
--hash=sha256:7be7b61bb172e1ed687f1754f8e7484f1c8019780f6f6b0786e76bb01c2ae115 \
|
||||
--hash=sha256:7c3fb7d25180895632e5d3148dbdc29ea38ccb7fd210aa27acbd1201a1902c6e \
|
||||
--hash=sha256:7e68f88e5b8799aa49c85cd116c932a1ac15caaa3f5db09087854d218359e485 \
|
||||
--hash=sha256:83891d0e9fb81a825d9a6d61e3f07550ca70a076484292a70fde82c4b807286f \
|
||||
--hash=sha256:8485f406a96febb5140bfeca44a73e3ce5116b2501ac54fe953e488fb1d03b12 \
|
||||
--hash=sha256:8709b08f4a89aa7586de0aadc8da56180242ee0ada3999749b183aa23df95025 \
|
||||
--hash=sha256:8f71bc33915be5186016f675cd83a1e08523649b0e33efdb898db577ef5bb009 \
|
||||
--hash=sha256:915c04ba3851909ce68ccc2b8e2cd691618c4dc4c4232fb7982bca3f41fd8c3d \
|
||||
--hash=sha256:949b8d66bc381ee8b007cd945914c721d9aba8e27f71959d750a46f7c282b20b \
|
||||
--hash=sha256:94c6f0bb423f739146aec64595853541634bde58b2135f27f61c1ffd1cd4d16a \
|
||||
--hash=sha256:9a1abfdc021a164803f4d485104931fb8f8c1efd55bc6b748d2f5774e78b62c5 \
|
||||
--hash=sha256:9b79b7a16f7fedff2495d684f2b59b0457c3b493778c9eed31111be64d58279f \
|
||||
--hash=sha256:a320721ab5a1aba0a233739394eb907f8c8da5c98c9181d1161e77a0c8e36f2d \
|
||||
--hash=sha256:a4afe79fb3de0b7097d81da19090f4df4f8d3a2b3adaa8764138aac2e44f3af1 \
|
||||
--hash=sha256:ad2cf8aa28b8c020ab2fc8287b0f823d0a7d8630784c31e9ee5edea20f406287 \
|
||||
--hash=sha256:b8512a91625c9b3da6f127803b166b629725e68af71f8184ae7e7d54686a56d6 \
|
||||
--hash=sha256:bc51efed119bc9cfdf792cdeaa4d67e8f6fcccab66ed4bfdd6bde3e59bfcbb2f \
|
||||
--hash=sha256:bdc919ead48f234740ad807933cdf545180bfbe9342c2bb451556db2ed958581 \
|
||||
--hash=sha256:bdd37121970bfd8be76c5fb069c7751683bdf373db1ed6c010162b2a130248ed \
|
||||
--hash=sha256:be8813b57049a7dc738189df53d69395eba14fb99345e0a5994914a3864c8a4b \
|
||||
--hash=sha256:c0c0b3ade1c0b13b936d7970b1d37a57acde9199dc2aecc4c336773e1d86049c \
|
||||
--hash=sha256:c47a551199eb8eb2121d4f0f15ae0f923d31350ab9280078d1e5f12b249e0026 \
|
||||
--hash=sha256:c4ffb7ebf07cfe8931028e3e4c85f0357459a3f9f9490886198848f4fa002ec8 \
|
||||
--hash=sha256:ccfcd093f13f0f0b7fdd0f198b90053bf7b2f02a3927a30e63f3ccc9df56b676 \
|
||||
--hash=sha256:d2ee202e79d8ed691ceebae8e0486bd9a2cd4794cec4824e1c99b6f5009502f6 \
|
||||
--hash=sha256:d53197da72cc091b024dd97249dfc7794d6a56530370992a5e1a08983ad9230e \
|
||||
--hash=sha256:d6dd0be5b5b189d31db7cda48b91d7e0a9795f31430b7f271219ab30f1d3ac9d \
|
||||
--hash=sha256:d88b440e37a16e651bda4c7c2b930eb586fd15ca7406cb39e211fcff3bf3017d \
|
||||
--hash=sha256:de8a88e63464af587c950061a5e6a67d3632e36df62b986892331d4620a35c01 \
|
||||
--hash=sha256:df2449253ef108a379b8b5d6b43f4b1a8e81a061d6537becd5582fba5f9196d7 \
|
||||
--hash=sha256:e1c1493fb6e50ab01d20a22826e57520f1284df32f2d8601fdd90b6304601419 \
|
||||
--hash=sha256:e1cf1972137e83c5d4c136c43ced9ac51d0e124706ee1c8aa8532c1287fa8795 \
|
||||
--hash=sha256:e2103a929dfa2fcaf9bb4e7c091983a49c9ac3b19c9061b6d5427dd7d14d81a1 \
|
||||
--hash=sha256:e56b7d45a839a697b5eb268c82a71bd8c7f6c94d6fd50c3d577fa39a9f1409f5 \
|
||||
--hash=sha256:e8afc3f2ccfa24215f8cb28dcf43f0113ac3c37c2f0f0806d8c70e4228c5cf4d \
|
||||
--hash=sha256:e8fc20152abba6b83724d7ff268c249fa196d8259ff481f3b1476383f8f24e42 \
|
||||
--hash=sha256:eaa9599de571d72e2daf60164784109f19978b327a3910d3e9de8c97b5b70cfe \
|
||||
--hash=sha256:ec15a59cf5af7be74194f7ab02d0f59a62bdcf1a537677ce67a2537c9b87fcda \
|
||||
--hash=sha256:f190daf01f13c72eac4efd5c430a8de82489d9cff23c364c3ea822545032993e \
|
||||
--hash=sha256:f34c41761022dd093b4b6896d4810782ffbabe30f2d443ff5f083e0cbbb8c737 \
|
||||
--hash=sha256:f3e98bb3798ead92273dc0e5fd0f31ade220f59a266ffd8a4f6065e0a3ce0523 \
|
||||
--hash=sha256:f42d0984e947b8adf7dd6dde396e720934d12c506ce84eea8476409563607591 \
|
||||
--hash=sha256:f71a396b3bf33ecaa1626c255855702aca4d3d9fea5e051b41ac59a9c1c41edc \
|
||||
--hash=sha256:f9e130248f4462aaa8e2552d547f36ddadbeaa573879158d721bbd33dfe4743a \
|
||||
--hash=sha256:fed51ac40f757d41b7c48425901843666a6677e3e8eb0abcff09e4ba6e664f50
|
||||
# via jinja2
|
||||
packaging==26.2 \
|
||||
--hash=sha256:5fc45236b9446107ff2415ce77c807cee2862cb6fac22b8a73826d0693b0980e \
|
||||
--hash=sha256:ff452ff5a3e828ce110190feff1178bb1f2ea2281fa2075aadb987c2fb221661
|
||||
# via
|
||||
# -r requirements.in
|
||||
# pytest
|
||||
pluggy==1.6.0 \
|
||||
--hash=sha256:7dcc130b76258d33b90f61b658791dede3486c3e6bfb003ee5c9bfb396dd22f3 \
|
||||
--hash=sha256:e920276dd6813095e9377c0bc5566d94c932c33b27a3e3945d8389c374dd4746
|
||||
# via
|
||||
# -r requirements.in
|
||||
# pytest
|
||||
pygments==2.20.0 \
|
||||
--hash=sha256:6757cd03768053ff99f3039c1a36d6c0aa0b263438fcab17520b30a303a82b5f \
|
||||
--hash=sha256:81a9e26dd42fd28a23a2d169d86d7ac03b46e2f8b59ed4698fb4785f946d0176
|
||||
# via pytest
|
||||
pytest==9.0.3 \
|
||||
--hash=sha256:2c5efc453d45394fdd706ade797c0a81091eccd1d6e4bccfcd476e2b8e0ab5d9 \
|
||||
--hash=sha256:b86ada508af81d19edeb213c681b1d48246c1a91d304c6c81a427674c17eb91c
|
||||
# via
|
||||
# -r requirements.in
|
||||
# pytest-xdist
|
||||
pytest-xdist==3.8.0 \
|
||||
--hash=sha256:202ca578cfeb7370784a8c33d6d05bc6e13b4f25b5053c30a152269fd10f0b88 \
|
||||
--hash=sha256:7e578125ec9bc6050861aa93f2d59f1d8d085595d6551c2c90b6f4fad8d3a9f1
|
||||
# via -r requirements.in
|
||||
pyyaml==6.0.3 \
|
||||
--hash=sha256:00c4bdeba853cc34e7dd471f16b4114f4162dc03e6b7afcc2128711f0eca823c \
|
||||
--hash=sha256:0150219816b6a1fa26fb4699fb7daa9caf09eb1999f3b70fb6e786805e80375a \
|
||||
--hash=sha256:02893d100e99e03eda1c8fd5c441d8c60103fd175728e23e431db1b589cf5ab3 \
|
||||
--hash=sha256:02ea2dfa234451bbb8772601d7b8e426c2bfa197136796224e50e35a78777956 \
|
||||
--hash=sha256:0f29edc409a6392443abf94b9cf89ce99889a1dd5376d94316ae5145dfedd5d6 \
|
||||
--hash=sha256:10892704fc220243f5305762e276552a0395f7beb4dbf9b14ec8fd43b57f126c \
|
||||
--hash=sha256:16249ee61e95f858e83976573de0f5b2893b3677ba71c9dd36b9cf8be9ac6d65 \
|
||||
--hash=sha256:1d37d57ad971609cf3c53ba6a7e365e40660e3be0e5175fa9f2365a379d6095a \
|
||||
--hash=sha256:1ebe39cb5fc479422b83de611d14e2c0d3bb2a18bbcb01f229ab3cfbd8fee7a0 \
|
||||
--hash=sha256:214ed4befebe12df36bcc8bc2b64b396ca31be9304b8f59e25c11cf94a4c033b \
|
||||
--hash=sha256:2283a07e2c21a2aa78d9c4442724ec1eb15f5e42a723b99cb3d822d48f5f7ad1 \
|
||||
--hash=sha256:22ba7cfcad58ef3ecddc7ed1db3409af68d023b7f940da23c6c2a1890976eda6 \
|
||||
--hash=sha256:27c0abcb4a5dac13684a37f76e701e054692a9b2d3064b70f5e4eb54810553d7 \
|
||||
--hash=sha256:28c8d926f98f432f88adc23edf2e6d4921ac26fb084b028c733d01868d19007e \
|
||||
--hash=sha256:2e71d11abed7344e42a8849600193d15b6def118602c4c176f748e4583246007 \
|
||||
--hash=sha256:34d5fcd24b8445fadc33f9cf348c1047101756fd760b4dacb5c3e99755703310 \
|
||||
--hash=sha256:37503bfbfc9d2c40b344d06b2199cf0e96e97957ab1c1b546fd4f87e53e5d3e4 \
|
||||
--hash=sha256:3c5677e12444c15717b902a5798264fa7909e41153cdf9ef7ad571b704a63dd9 \
|
||||
--hash=sha256:3ff07ec89bae51176c0549bc4c63aa6202991da2d9a6129d7aef7f1407d3f295 \
|
||||
--hash=sha256:41715c910c881bc081f1e8872880d3c650acf13dfa8214bad49ed4cede7c34ea \
|
||||
--hash=sha256:418cf3f2111bc80e0933b2cd8cd04f286338bb88bdc7bc8e6dd775ebde60b5e0 \
|
||||
--hash=sha256:44edc647873928551a01e7a563d7452ccdebee747728c1080d881d68af7b997e \
|
||||
--hash=sha256:4a2e8cebe2ff6ab7d1050ecd59c25d4c8bd7e6f400f5f82b96557ac0abafd0ac \
|
||||
--hash=sha256:4ad1906908f2f5ae4e5a8ddfce73c320c2a1429ec52eafd27138b7f1cbe341c9 \
|
||||
--hash=sha256:501a031947e3a9025ed4405a168e6ef5ae3126c59f90ce0cd6f2bfc477be31b7 \
|
||||
--hash=sha256:5190d403f121660ce8d1d2c1bb2ef1bd05b5f68533fc5c2ea899bd15f4399b35 \
|
||||
--hash=sha256:5498cd1645aa724a7c71c8f378eb29ebe23da2fc0d7a08071d89469bf1d2defb \
|
||||
--hash=sha256:5cf4e27da7e3fbed4d6c3d8e797387aaad68102272f8f9752883bc32d61cb87b \
|
||||
--hash=sha256:5e0b74767e5f8c593e8c9b5912019159ed0533c70051e9cce3e8b6aa699fcd69 \
|
||||
--hash=sha256:5ed875a24292240029e4483f9d4a4b8a1ae08843b9c54f43fcc11e404532a8a5 \
|
||||
--hash=sha256:5fcd34e47f6e0b794d17de1b4ff496c00986e1c83f7ab2fb8fcfe9616ff7477b \
|
||||
--hash=sha256:5fdec68f91a0c6739b380c83b951e2c72ac0197ace422360e6d5a959d8d97b2c \
|
||||
--hash=sha256:6344df0d5755a2c9a276d4473ae6b90647e216ab4757f8426893b5dd2ac3f369 \
|
||||
--hash=sha256:64386e5e707d03a7e172c0701abfb7e10f0fb753ee1d773128192742712a98fd \
|
||||
--hash=sha256:652cb6edd41e718550aad172851962662ff2681490a8a711af6a4d288dd96824 \
|
||||
--hash=sha256:66291b10affd76d76f54fad28e22e51719ef9ba22b29e1d7d03d6777a9174198 \
|
||||
--hash=sha256:66e1674c3ef6f541c35191caae2d429b967b99e02040f5ba928632d9a7f0f065 \
|
||||
--hash=sha256:6adc77889b628398debc7b65c073bcb99c4a0237b248cacaf3fe8a557563ef6c \
|
||||
--hash=sha256:79005a0d97d5ddabfeeea4cf676af11e647e41d81c9a7722a193022accdb6b7c \
|
||||
--hash=sha256:7c6610def4f163542a622a73fb39f534f8c101d690126992300bf3207eab9764 \
|
||||
--hash=sha256:7f047e29dcae44602496db43be01ad42fc6f1cc0d8cd6c83d342306c32270196 \
|
||||
--hash=sha256:8098f252adfa6c80ab48096053f512f2321f0b998f98150cea9bd23d83e1467b \
|
||||
--hash=sha256:850774a7879607d3a6f50d36d04f00ee69e7fc816450e5f7e58d7f17f1ae5c00 \
|
||||
--hash=sha256:8d1fab6bb153a416f9aeb4b8763bc0f22a5586065f86f7664fc23339fc1c1fac \
|
||||
--hash=sha256:8da9669d359f02c0b91ccc01cac4a67f16afec0dac22c2ad09f46bee0697eba8 \
|
||||
--hash=sha256:8dc52c23056b9ddd46818a57b78404882310fb473d63f17b07d5c40421e47f8e \
|
||||
--hash=sha256:9149cad251584d5fb4981be1ecde53a1ca46c891a79788c0df828d2f166bda28 \
|
||||
--hash=sha256:93dda82c9c22deb0a405ea4dc5f2d0cda384168e466364dec6255b293923b2f3 \
|
||||
--hash=sha256:96b533f0e99f6579b3d4d4995707cf36df9100d67e0c8303a0c55b27b5f99bc5 \
|
||||
--hash=sha256:9c57bb8c96f6d1808c030b1687b9b5fb476abaa47f0db9c0101f5e9f394e97f4 \
|
||||
--hash=sha256:9c7708761fccb9397fe64bbc0395abcae8c4bf7b0eac081e12b809bf47700d0b \
|
||||
--hash=sha256:9f3bfb4965eb874431221a3ff3fdcddc7e74e3b07799e0e84ca4a0f867d449bf \
|
||||
--hash=sha256:a33284e20b78bd4a18c8c2282d549d10bc8408a2a7ff57653c0cf0b9be0afce5 \
|
||||
--hash=sha256:a80cb027f6b349846a3bf6d73b5e95e782175e52f22108cfa17876aaeff93702 \
|
||||
--hash=sha256:b30236e45cf30d2b8e7b3e85881719e98507abed1011bf463a8fa23e9c3e98a8 \
|
||||
--hash=sha256:b3bc83488de33889877a0f2543ade9f70c67d66d9ebb4ac959502e12de895788 \
|
||||
--hash=sha256:b865addae83924361678b652338317d1bd7e79b1f4596f96b96c77a5a34b34da \
|
||||
--hash=sha256:b8bb0864c5a28024fac8a632c443c87c5aa6f215c0b126c449ae1a150412f31d \
|
||||
--hash=sha256:ba1cc08a7ccde2d2ec775841541641e4548226580ab850948cbfda66a1befcdc \
|
||||
--hash=sha256:bdb2c67c6c1390b63c6ff89f210c8fd09d9a1217a465701eac7316313c915e4c \
|
||||
--hash=sha256:c1ff362665ae507275af2853520967820d9124984e0f7466736aea23d8611fba \
|
||||
--hash=sha256:c2514fceb77bc5e7a2f7adfaa1feb2fb311607c9cb518dbc378688ec73d8292f \
|
||||
--hash=sha256:c3355370a2c156cffb25e876646f149d5d68f5e0a3ce86a5084dd0b64a994917 \
|
||||
--hash=sha256:c458b6d084f9b935061bc36216e8a69a7e293a2f1e68bf956dcd9e6cbcd143f5 \
|
||||
--hash=sha256:d0eae10f8159e8fdad514efdc92d74fd8d682c933a6dd088030f3834bc8e6b26 \
|
||||
--hash=sha256:d76623373421df22fb4cf8817020cbb7ef15c725b9d5e45f17e189bfc384190f \
|
||||
--hash=sha256:ebc55a14a21cb14062aa4162f906cd962b28e2e9ea38f9b4391244cd8de4ae0b \
|
||||
--hash=sha256:eda16858a3cab07b80edaf74336ece1f986ba330fdb8ee0d6c0d68fe82bc96be \
|
||||
--hash=sha256:ee2922902c45ae8ccada2c5b501ab86c36525b883eff4255313a253a3160861c \
|
||||
--hash=sha256:efd7b85f94a6f21e4932043973a7ba2613b059c4a000551892ac9f1d11f5baf3 \
|
||||
--hash=sha256:f7057c9a337546edc7973c0d3ba84ddcdf0daa14533c2065749c9075001090e6 \
|
||||
--hash=sha256:fa160448684b4e94d80416c0fa4aac48967a969efe22931448d853ada8baf926 \
|
||||
--hash=sha256:fc09d0aa354569bc501d4e787133afc08552722d3ab34836a80547331bb5d4a0
|
||||
# via -r requirements.in
|
||||
requests==2.34.2 \
|
||||
--hash=sha256:2a0d60c172f83ac6ab31e4554906c0f3b3588d37b5cb939b1c061f4907e278e0 \
|
||||
--hash=sha256:f288924cae4e29463698d6d60bc6a4da69c89185ad1e0bcc4104f584e960b9ed
|
||||
# via -r requirements.in
|
||||
tabulate==0.10.0 \
|
||||
--hash=sha256:e2cfde8f79420f6deeffdeda9aaec3b6bc5abce947655d17ac662b126e48a60d \
|
||||
--hash=sha256:f0b0622e567335c8fabaaa659f1b33bcb6ddfe2e496071b743aa113f8774f2d3
|
||||
# via -r requirements.in
|
||||
urllib3==2.7.0 \
|
||||
--hash=sha256:231e0ec3b63ceb14667c67be60f2f2c40a518cb38b03af60abc813da26505f4c \
|
||||
--hash=sha256:9fb4c81ebbb1ce9531cce37674bbc6f1360472bc18ca9a553ede278ef7276897
|
||||
# via requests
|
||||
+136
@@ -0,0 +1,136 @@
|
||||
name: sig benchmark
|
||||
|
||||
on:
|
||||
workflow_dispatch:
|
||||
workflow_call:
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
build:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
# Checkout repository
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v4
|
||||
with:
|
||||
fetch-depth: 0
|
||||
|
||||
# Set up dependencies
|
||||
- name: Install dependencies
|
||||
run: |
|
||||
sudo apt-get update
|
||||
sudo apt-get install -y cmake ninja-build gcc g++ python3 python3-pip
|
||||
sudo apt-get install -y python3-cpuinfo
|
||||
|
||||
# Build the speed_sig binary only
|
||||
- name: Build speed_sig binary
|
||||
run: |
|
||||
mkdir -p build
|
||||
cd build
|
||||
cmake -GNinja .. -DBUILD_SHARED_LIBS=OFF
|
||||
ninja speed_sig
|
||||
|
||||
# Copy the parse_liboqs_speed.py script
|
||||
- name: Copy parse_liboqs_speed.py
|
||||
run: |
|
||||
cp scripts/parse_liboqs_speed.py build/tests/
|
||||
|
||||
# Upload the built binary and script as an artifact
|
||||
- name: Upload artifacts
|
||||
uses: actions/upload-artifact@6027e3dd177782cd8ab9af838c04fd81a07f1d47
|
||||
with:
|
||||
name: built-sig-binary
|
||||
path: build/tests/
|
||||
|
||||
benchmark:
|
||||
needs: build
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
contents: write
|
||||
strategy:
|
||||
matrix:
|
||||
algorithm: [ # List of available signatures to perform the benchmarking on
|
||||
"ML-DSA-44",
|
||||
"ML-DSA-65",
|
||||
"ML-DSA-87",
|
||||
"Falcon-512",
|
||||
"Falcon-1024",
|
||||
"Falcon-padded-512",
|
||||
"Falcon-padded-1024",
|
||||
"MAYO-1",
|
||||
"MAYO-2",
|
||||
"MAYO-3",
|
||||
"MAYO-5",
|
||||
"cross-rsdp-128-balanced",
|
||||
"cross-rsdp-128-fast",
|
||||
"cross-rsdp-128-small",
|
||||
"cross-rsdp-192-balanced",
|
||||
"cross-rsdp-192-fast",
|
||||
"cross-rsdp-192-small",
|
||||
"cross-rsdp-256-balanced",
|
||||
"cross-rsdp-256-fast",
|
||||
"cross-rsdp-256-small",
|
||||
"cross-rsdpg-128-balanced",
|
||||
"cross-rsdpg-128-fast",
|
||||
"cross-rsdpg-128-small",
|
||||
"cross-rsdpg-192-balanced",
|
||||
"cross-rsdpg-192-fast",
|
||||
"cross-rsdpg-192-small",
|
||||
"cross-rsdpg-256-balanced",
|
||||
"cross-rsdpg-256-fast",
|
||||
"cross-rsdpg-256-small",
|
||||
"OV-Is",
|
||||
"OV-Ip",
|
||||
"OV-III",
|
||||
"OV-V",
|
||||
"OV-Is-pkc",
|
||||
"OV-Ip-pkc",
|
||||
"OV-III-pkc",
|
||||
"OV-V-pkc",
|
||||
"OV-Is-pkc-skc",
|
||||
"OV-Ip-pkc-skc",
|
||||
"OV-III-pkc-skc",
|
||||
"OV-V-pkc-skc"
|
||||
]
|
||||
max-parallel: 1 # No parallel jobs to not compromise the pull-push operations of the benchmarking actions below
|
||||
|
||||
steps:
|
||||
# Ensure the repository is checked out
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v4
|
||||
with:
|
||||
fetch-depth: 0
|
||||
|
||||
# Download the built binary and script
|
||||
- name: Download artifacts
|
||||
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # pin@v8.0.1
|
||||
with:
|
||||
name: built-sig-binary
|
||||
path: build/tests/
|
||||
|
||||
# Set execute permissions for the binary
|
||||
- name: Set execute permissions
|
||||
run: chmod +x build/tests/speed_sig
|
||||
|
||||
# Run speed_sig tests for each algorithm
|
||||
- name: Run speed_sig tests
|
||||
run: |
|
||||
cd build/tests
|
||||
./speed_sig "${{matrix.algorithm}}" > ${{matrix.algorithm}}_output.txt
|
||||
python3 parse_liboqs_speed.py ${{matrix.algorithm}}_output.txt --algorithm ${{matrix.algorithm}}
|
||||
|
||||
# Push to GitHub pages using continuous-benchmark
|
||||
- name: Store benchmark result
|
||||
uses: benchmark-action/github-action-benchmark@52576c92bccf6ac60c8223ec7eb2565637cae9ba
|
||||
with:
|
||||
name: ${{matrix.algorithm}}
|
||||
tool: "customSmallerIsBetter"
|
||||
output-file-path: build/tests/${{matrix.algorithm}}_formatted.json
|
||||
github-token: ${{ secrets.GITHUB_TOKEN }}
|
||||
auto-push: true
|
||||
comment-on-alert: true
|
||||
summary-always: true
|
||||
alert-threshold: 105%
|
||||
comment-always: false
|
||||
+101
@@ -0,0 +1,101 @@
|
||||
name: Scorecard supply-chain security
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
on:
|
||||
# For Branch-Protection check. Only the default branch is supported. See
|
||||
# https://github.com/ossf/scorecard/blob/main/docs/checks.md#branch-protection
|
||||
branch_protection_rule:
|
||||
workflow_call:
|
||||
workflow_dispatch:
|
||||
|
||||
|
||||
jobs:
|
||||
|
||||
poutine_analysis:
|
||||
name: Poutine supply chain analysis
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
security-events: write
|
||||
contents: read
|
||||
steps:
|
||||
- name: "Checkout code"
|
||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v4
|
||||
with:
|
||||
persist-credentials: false
|
||||
|
||||
- name: "Run poutine supply chain check"
|
||||
uses: boostsecurityio/poutine-action@e240ebd3eff8b2db5a8e5f6b28f58739d7db2247 # v1.1.4
|
||||
with:
|
||||
format: sarif
|
||||
output: poutine_results.sarif
|
||||
publish_results: true
|
||||
|
||||
- name: Configure as safe directory (Poutine)
|
||||
run: git config --global --add safe.directory /__w/liboqs/liboqs
|
||||
|
||||
- name: "Upload poutine artifact"
|
||||
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
|
||||
with:
|
||||
name: Poutine Results SARIF
|
||||
path: poutine_results.sarif
|
||||
retention-days: 28
|
||||
|
||||
- name: "Upload poutine to code-scanning"
|
||||
uses: github/codeql-action/upload-sarif@9e0d7b8d25671d64c341c19c0152d693099fb5ba # v3
|
||||
with:
|
||||
sarif_file: poutine_results.sarif
|
||||
|
||||
scorecard_analysis:
|
||||
name: Scorecard analysis
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
# Needed to upload the results to code-scanning dashboard.
|
||||
security-events: write
|
||||
# Needed to publish results and get a badge (see publish_results below).
|
||||
id-token: write
|
||||
# Uncomment the permissions below if installing in a private repository.
|
||||
# contents: read
|
||||
# actions: read
|
||||
|
||||
steps:
|
||||
- name: "Checkout code"
|
||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v4
|
||||
with:
|
||||
persist-credentials: false
|
||||
|
||||
- name: "Run ossf scorecard"
|
||||
uses: ossf/scorecard-action@4eaacf0543bb3f2c246792bd56e8cdeffafb205a # v2.4.3
|
||||
with:
|
||||
results_format: sarif
|
||||
results_file: ossf_results.sarif
|
||||
# (Optional) "write" PAT token. Uncomment the `repo_token` line below if:
|
||||
# - you want to enable the Branch-Protection check on a *public* repository, or
|
||||
# - you are installing Scorecard on a *private* repository
|
||||
# To create the PAT, follow the steps in https://github.com/ossf/scorecard-action#authentication-with-pat.
|
||||
# repo_token: ${{ secrets.SCORECARD_TOKEN }}
|
||||
|
||||
# Public repositories:
|
||||
# - Publish results to OpenSSF REST API for easy access by consumers
|
||||
# - Allows the repository to include the Scorecard badge.
|
||||
# - See https://github.com/ossf/scorecard-action#publishing-results.
|
||||
# For private repositories:
|
||||
# - `publish_results` will always be set to `false`, regardless
|
||||
# of the value entered here.
|
||||
publish_results: true
|
||||
|
||||
# Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF
|
||||
# format to the repository Actions tab.
|
||||
- name: "Upload ossf artifact"
|
||||
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
|
||||
with:
|
||||
name: OSSF Results SARIF
|
||||
path: ossf_results.sarif
|
||||
retention-days: 28
|
||||
|
||||
# Upload the results to GitHub's code scanning dashboard.
|
||||
- name: "Upload to ossf to code-scanning"
|
||||
uses: github/codeql-action/upload-sarif@9e0d7b8d25671d64c341c19c0152d693099fb5ba # v3
|
||||
with:
|
||||
sarif_file: ossf_results.sarif
|
||||
+33
@@ -0,0 +1,33 @@
|
||||
name: Weekly tests
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
on:
|
||||
schedule:
|
||||
- cron: "5 0 * * 0"
|
||||
|
||||
jobs:
|
||||
|
||||
# To guarantee Maintained check is occasionally updated. See
|
||||
# https://github.com/ossf/scorecard/blob/main/docs/checks.md#maintained
|
||||
scorecard:
|
||||
uses: ./.github/workflows/supplychain.yml
|
||||
secrets: inherit
|
||||
permissions:
|
||||
id-token: write
|
||||
security-events: write
|
||||
contents: read
|
||||
|
||||
extended-tests:
|
||||
uses: ./.github/workflows/extended.yml
|
||||
|
||||
kem-continuous-benchmarking:
|
||||
uses: ./.github/workflows/kem-bench.yml
|
||||
permissions:
|
||||
contents: write
|
||||
|
||||
sig-continuous-benchmarking:
|
||||
uses: ./.github/workflows/sig-bench.yml
|
||||
permissions:
|
||||
contents: write
|
||||
+83
@@ -0,0 +1,83 @@
|
||||
name: Windows tests
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
on: [workflow_call, workflow_dispatch]
|
||||
jobs:
|
||||
|
||||
windows-arm64:
|
||||
strategy:
|
||||
matrix:
|
||||
runner: [windows-2022, windows-2025]
|
||||
stfl_opt: [ON, OFF]
|
||||
runs-on: ${{ matrix.runner }}
|
||||
timeout-minutes: 85 # max + 3*std over the last thousands of successful runs
|
||||
steps:
|
||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2
|
||||
- name: Generate Project
|
||||
run: cmake -B build --toolchain .CMake/toolchain_windows_arm64.cmake -DOQS_ENABLE_SIG_SLH_DSA=OFF -DOQS_ENABLE_SIG_STFL_LMS=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_HAZARDOUS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=${{ matrix.stfl_opt }} .
|
||||
- name: Build Project
|
||||
run: cmake --build build
|
||||
|
||||
windows-arm64-slhdsa:
|
||||
strategy:
|
||||
matrix:
|
||||
runner: [windows-2022, windows-2025]
|
||||
stfl_opt: [ON, OFF]
|
||||
runs-on: ${{ matrix.runner }}
|
||||
steps:
|
||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2
|
||||
- name: Generate Project
|
||||
run: cmake -B build --toolchain .CMake/toolchain_windows_arm64.cmake -DOQS_MINIMAL_BUILD=SIG_slh_dsa .
|
||||
- name: Build Project
|
||||
run: cmake --build build
|
||||
|
||||
windows-x86:
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
runner: [windows-2022, windows-2025]
|
||||
toolchain: [.CMake/toolchain_windows_x86.cmake, .CMake/toolchain_windows_amd64.cmake]
|
||||
stfl_opt: [ON, OFF]
|
||||
runs-on: ${{ matrix.runner }}
|
||||
timeout-minutes: 85 # max + 3*std over the last thousands of successful runs
|
||||
steps:
|
||||
- name: Install Python
|
||||
uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # pin@v5
|
||||
with:
|
||||
python-version: '3.12'
|
||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2
|
||||
- name: Generate Project
|
||||
run: cmake -B build --toolchain ${{ matrix.toolchain }} -DOQS_ENABLE_SIG_SLH_DSA=OFF -DOQS_ENABLE_SIG_STFL_LMS=ON -DOQS_ENABLE_SIG_STFL_XMSS=ON -DOQS_HAZARDOUS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN=${{ matrix.stfl_opt }} .
|
||||
- name: Build Project
|
||||
run: cmake --build build
|
||||
- name: Test dependencies
|
||||
run: pip.exe install --require-hashes -r .github\workflows\requirements.txt
|
||||
- name: Run tests
|
||||
run: |
|
||||
python -m pytest --numprocesses=auto -vv --maxfail=10 --ignore=tests/test_code_conventions.py --ignore=tests/test_kat_all.py --junitxml=build\test-results\pytest\test-results.xml
|
||||
|
||||
windows-x86-slhdsa:
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
runner: [windows-2022, windows-2025]
|
||||
toolchain: [.CMake/toolchain_windows_x86.cmake, .CMake/toolchain_windows_amd64.cmake]
|
||||
stfl_opt: [ON, OFF]
|
||||
runs-on: ${{ matrix.runner }}
|
||||
steps:
|
||||
- name: Install Python
|
||||
uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # pin@v5
|
||||
with:
|
||||
python-version: '3.12'
|
||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # pin@v6.0.2
|
||||
- name: Generate Project
|
||||
run: cmake -B build --toolchain ${{ matrix.toolchain }} -DOQS_MINIMAL_BUILD=SIG_slh_dsa .
|
||||
- name: Build Project
|
||||
run: cmake --build build
|
||||
- name: Test dependencies
|
||||
run: pip.exe install --require-hashes -r .github\workflows\requirements.txt
|
||||
- name: Run tests
|
||||
run: |
|
||||
python -m pytest --numprocesses=auto -vv --maxfail=10 --ignore=tests/test_code_conventions.py --ignore=tests/test_kat_all.py --junitxml=build\test-results\pytest\test-results.xml
|
||||
+110
@@ -0,0 +1,110 @@
|
||||
name: Zephyr tests
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
on: [workflow_call, workflow_dispatch]
|
||||
|
||||
jobs:
|
||||
|
||||
zephyr3_test:
|
||||
runs-on: oqs-x64
|
||||
container: ghcr.io/zephyrproject-rtos/ci:v0.26-branch
|
||||
env:
|
||||
CMAKE_PREFIX_PATH: /opt/toolchains
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
config:
|
||||
- zephyr-ref: v3.7.0
|
||||
|
||||
steps:
|
||||
- name: Init Zephyr workspace
|
||||
run: |
|
||||
mkdir -p zephyr/manifest && cd zephyr/manifest
|
||||
echo "manifest:" > west.yml
|
||||
echo " remotes:" >> west.yml
|
||||
echo " - name: zephyr" >> west.yml
|
||||
echo " url-base: https://github.com/zephyrproject-rtos" >> west.yml
|
||||
echo " - name: liboqs" >> west.yml
|
||||
echo " url-base: https://github.com/${{ github.repository_owner }}" >> west.yml
|
||||
echo " projects:" >> west.yml
|
||||
echo " - name: zephyr" >> west.yml
|
||||
echo " remote: zephyr" >> west.yml
|
||||
echo " repo-path: zephyr" >> west.yml
|
||||
echo " revision: ${{ matrix.config.zephyr-ref }}" >> west.yml
|
||||
echo " import:" >> west.yml
|
||||
echo " name-allowlist:" >> west.yml
|
||||
echo " - picolibc" >> west.yml
|
||||
echo " - name: liboqs" >> west.yml
|
||||
echo " remote: liboqs" >> west.yml
|
||||
echo " revision: $(echo '${{ github.ref }}' | sed -e 's/refs\/heads\///')" >> west.yml
|
||||
echo " path: modules/crypto/liboqs" >> west.yml
|
||||
west init -l --mf west.yml .
|
||||
|
||||
- name: Update west workspace
|
||||
working-directory: zephyr
|
||||
run: |
|
||||
west update -n -o=--depth=1
|
||||
west zephyr-export
|
||||
|
||||
- name: Run Signature test
|
||||
working-directory: zephyr
|
||||
run: |
|
||||
west twister --integration -T modules/crypto/liboqs/zephyr/samples/Signatures -vvv
|
||||
|
||||
- name: Run KEM test
|
||||
working-directory: zephyr
|
||||
run: |
|
||||
west twister --integration -T modules/crypto/liboqs/zephyr/samples/KEMs -vvv
|
||||
|
||||
zephyr4_test:
|
||||
runs-on: oqs-x64
|
||||
container: ghcr.io/zephyrproject-rtos/ci:v0.28.7
|
||||
env:
|
||||
CMAKE_PREFIX_PATH: /opt/toolchains
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
config:
|
||||
- zephyr-ref: v4.3.0
|
||||
|
||||
steps:
|
||||
- name: Init Zephyr workspace
|
||||
run: |
|
||||
mkdir -p zephyr/manifest && cd zephyr/manifest
|
||||
echo "manifest:" > west.yml
|
||||
echo " remotes:" >> west.yml
|
||||
echo " - name: zephyr" >> west.yml
|
||||
echo " url-base: https://github.com/zephyrproject-rtos" >> west.yml
|
||||
echo " - name: liboqs" >> west.yml
|
||||
echo " url-base: https://github.com/${{ github.repository_owner }}" >> west.yml
|
||||
echo " projects:" >> west.yml
|
||||
echo " - name: zephyr" >> west.yml
|
||||
echo " remote: zephyr" >> west.yml
|
||||
echo " repo-path: zephyr" >> west.yml
|
||||
echo " revision: ${{ matrix.config.zephyr-ref }}" >> west.yml
|
||||
echo " import:" >> west.yml
|
||||
echo " name-allowlist:" >> west.yml
|
||||
echo " - picolibc" >> west.yml
|
||||
echo " - name: liboqs" >> west.yml
|
||||
echo " remote: liboqs" >> west.yml
|
||||
echo " revision: $(echo '${{ github.ref }}' | sed -e 's/refs\/heads\///')" >> west.yml
|
||||
echo " path: modules/crypto/liboqs" >> west.yml
|
||||
west init -l --mf west.yml .
|
||||
|
||||
- name: Update west workspace
|
||||
working-directory: zephyr
|
||||
run: |
|
||||
west update -n -o=--depth=1
|
||||
west zephyr-export
|
||||
|
||||
- name: Run Signature test
|
||||
working-directory: zephyr
|
||||
run: |
|
||||
west twister --integration -T modules/crypto/liboqs/zephyr/samples/Signatures -vvv
|
||||
|
||||
- name: Run KEM test
|
||||
working-directory: zephyr
|
||||
run: |
|
||||
west twister --integration -T modules/crypto/liboqs/zephyr/samples/KEMs -vvv
|
||||
@@ -0,0 +1,41 @@
|
||||
# Text editors and IDES
|
||||
.idea
|
||||
tags
|
||||
*.swp
|
||||
*~
|
||||
.tags*
|
||||
|
||||
# CMake & testing
|
||||
/build*
|
||||
/tmp*
|
||||
|
||||
# MSVC
|
||||
.vs
|
||||
/out*
|
||||
|
||||
# CLion
|
||||
/cmake-build*
|
||||
|
||||
# Visual Studio Code
|
||||
.vscode
|
||||
|
||||
# Jetbrains IDEs
|
||||
.idea
|
||||
|
||||
# MacOS
|
||||
.DS_Store
|
||||
|
||||
# Generated by copy_from_upstream.py
|
||||
# and update_pqclean_alg_docs.py
|
||||
scripts/copy_from_upstream/repos
|
||||
scripts/copy_from_upstream/verify_from_upstream
|
||||
|
||||
# Misc
|
||||
__pycache__
|
||||
.pytest_cache
|
||||
.cache
|
||||
.CMake/a.out
|
||||
compile_commands.json
|
||||
|
||||
# Generated by Nix flake
|
||||
result/
|
||||
@@ -0,0 +1,61 @@
|
||||
# Supported algorithms
|
||||
|
||||
This file documents the algorithms currently integrated into `liboqs`, with per-variant detail on standardization status, upstream maintenance, OQS support tier, security level, constant-time status, formal verification, and available optimizations.
|
||||
|
||||
## Definitions
|
||||
|
||||
### Upstream-maintenance
|
||||
|
||||
The **Upstream maintenance** column records the maintenance level the upstream implementation team has committed to, using one of the labels below. A label is only set when the upstream has confirmed it; otherwise the entry reads `TBD`.
|
||||
|
||||
- **Actively maintained.** There is a named, responsive upstream contact or team. Upstream commits to investigating security reports in a timely manner and incorporating fixes. Upstream releases updates that OQS can track. Upstream has a public written statement describing this commitment, which OQS links to.
|
||||
- **Best effort.** There is a named upstream contact who acknowledges OQS's integration. Upstream will attempt to respond to security reports and incorporate fixes when able, with no commitment on timing or release cadence. Users should not depend on timely upstream fixes.
|
||||
- **No active maintenance.** There is no responsive upstream contact, or upstream has publicly stated wind-down or end-of-life. Fixes will not necessarily be incorporated from upstream. Users considering this algorithm should plan accordingly (alternatives, migration, or maintaining their own fork).
|
||||
- **TBD.** OQS has not yet obtained a confirmed statement from the upstream. This is not a judgment about the upstream; it means the conversation has not concluded.
|
||||
|
||||
## OQS support tier
|
||||
|
||||
The **OQS tier** column records OQS's own support commitment for each algorithm. Tiers are self-assigned by the OQS technical governance team via PR review, and are structurally parallel to the platform tiers defined in [PLATFORMS.md](PLATFORMS.md). Promotion or demotion between tiers is proposed via PR and promotion requires the algorithm to have spent reasonable time at its current tier. Tier assignments are not a recommendation for production use of any algorithm in `liboqs`; see the project-wide disclaimer in [README.md](README.md).
|
||||
|
||||
- **Tier 1 — Core.** The highest level of support provided by the project given its limited resources; this should be interpreted within the project's [overall limitations](https://github.com/open-quantum-safe/liboqs/blob/main/README.md#limitations-and-security). Tier 1 alogrithms must be: upstream marked `Actively maintained` with a public support statement; covered by the OQS security response process; constant-time tested on all Tier 1 platforms where applicable; built and tested on every Tier 1 platform in CI, every parameter set; at least two OQS committers familiar with the code; has an identified entry in `CODEOWNERS`.
|
||||
- **Tier 2 — Supported.** Receives general OQS support, with weaker guarantees than Tier 1. Tier 2 alogrithms must be: upstream at least `Best effort`; covered by the OQS security response process on a best-effort basis; built and tested on all Tier 1 platforms in CI; at least one OQS committer familiar with the code; has an identified entry in `CODEOWNERS`.
|
||||
- **Tier 3 — Community.** Maintained primarily through community contributions. Tier 3 alogrithms satisfy: upstream status may be any value including `No active maintenance`; builds in CI, tests best-effort; no OQS commitment beyond accepting community PRs and refusing to knowingly ship broken code. Users are expected to evaluate suitability themselves.
|
||||
|
||||
## Key encapsulation mechanisms
|
||||
|
||||
<!-- OQS_TEMPLATE_FRAGMENT_ALGORITHMS_KEM_START -->
|
||||
| Algorithm family | Standardization | Primary implementation | Upstream maintenance | OQS tier | NIST levels | Constant-time | Formally verified | Optimization targets |
|
||||
|:-------------------|:------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|:------------------------------------------------------------------------------------------------------------------------------------------|:--------------------------------------------------------------------------------------------------------------------|:-------------------|:--------------|:----------------|:--------------------|:----------------------------------------------------------|
|
||||
| BIKE | Not selected by [NIST](https://bikesuite.org/files/v5.1/BIKE_Spec.2022.10.10.1.pdf) | [`awslabs/bike-kem`](https://github.com/awslabs/bike-kem) | TBD | Tier 3 (Community) | 1, 3, 5 | ✓ | — | 64-bit little-endian, x86_64 (avx2+avx512+pclmul+sse2) |
|
||||
| Classic McEliece | Under [ISO](https://classic.mceliece.org/iso.html) consideration | [`PQClean/PQClean@1eacfda`](https://github.com/PQClean/PQClean/commit/1eacfdafc15ddc5d5759d0b85b4cef26627df181) | [No active maintenance](https://github.com/PQClean/PQClean/blob/dca1ee2458b399d0aa11bacde535393ee7c447aa/README.md) | Tier 3 (Community) | 1, 3, 5 | — | — | portable, x86_64 (avx2+bmi1+popcnt), x86_64 (avx2+popcnt) |
|
||||
| FrodoKEM | Under [ISO](https://frodokem.org/) consideration | [`microsoft/PQCrypto-LWEKE@a2f9dec`](https://github.com/microsoft/PQCrypto-LWEKE/commit/a2f9dec8917ccc3464b3378d46b140fa7353320d) | TBD | Tier 2 (Supported) | 1, 3, 5 | ✓ | — | portable, x86_64 (avx2) |
|
||||
| HQC | Selected by [NIST](https://pqc-hqc.org/doc/hqc_specifications_2025_08_22.pdf) for upcoming standardization | [`pqc-hqc/hqc@161cd4f`](https://gitlab.com/pqc-hqc/hqc/commit/161cd4fdf6b4a5198cf40b3a1243f9f27f13e03d) | TBD | Tier 2 (Supported) | 1, 3, 5 | claimed | — | portable |
|
||||
| Kyber | Selected by [NIST](https://csrc.nist.gov/CSRC/media/Projects/post-quantum-cryptography/documents/round-3/submissions/Kyber-Round3.zip) as basis for ML-KEM (FIPS 203) | [`pq-crystals/kyber@441c051`](https://github.com/pq-crystals/kyber/commit/441c0519a07e8b86c8d079954a6b10bd31d29efc) | TBD | Tier 3 (Community) | 1, 3, 5 | ✓ | partial | portable, ARM64_V8, x86_64, x86_64 (avx2+bmi2+popcnt) |
|
||||
| ML-KEM | Standardized by [NIST](https://csrc.nist.gov/pubs/fips/203/final) | [`pq-code-package/mlkem-native@0ba906c`](https://github.com/pq-code-package/mlkem-native/commit/0ba906cb14b1c241476134d7403a811b382ca498) | [Actively maintained](https://github.com/pq-code-package/mlkem-native) | Tier 1 (Core) | 1, 3, 5 | ✓ | — | portable, ARM64_V8, CUDA, x86_64 (avx2+bmi2+popcnt) |
|
||||
| NTRU | Not selected by [NIST](https://csrc.nist.gov/CSRC/media/Projects/post-quantum-cryptography/documents/round-3/submissions/NTRU-Round3.zip), under standardization consideration by [NTT](https://info.isl.ntt.co.jp/crypt/ntru/index.html) | [`PQClean/PQClean@4c9e5a3`](https://github.com/PQClean/PQClean/commit/4c9e5a3aa715cc8d1d0e377e4e6e682ebd7602d6) | Actively maintained | Tier 3 (Community) | 1, 3, 5 | ✓ | — | portable, x86_64 (avx2+bmi2) |
|
||||
| NTRU-Prime | Not selected by [NIST](https://csrc.nist.gov/CSRC/media/Projects/post-quantum-cryptography/documents/round-3/submissions/NTRU-Prime-Round3.zip) | [`openssh/openssh-portable`](https://github.com/openssh/openssh-portable/blob/1cc936b2fabffeac7fff14ca1070d7d7a317ab7b/sntrup761.c) | Actively maintained | Tier 3 (Community) | 2 | ✓ | — | portable |
|
||||
<!-- OQS_TEMPLATE_FRAGMENT_ALGORITHMS_KEM_END -->
|
||||
|
||||
## Signature schemes
|
||||
|
||||
<!-- OQS_TEMPLATE_FRAGMENT_ALGORITHMS_SIG_START -->
|
||||
| Algorithm family | Standardization | Primary implementation | Upstream maintenance | OQS tier | NIST levels | Constant-time | Formally verified | Optimization targets |
|
||||
|:-------------------|:---------------------------------------------------------------------------------------------------------------------------------------------------------------------|:--------------------------------------------------------------------------------------------------------------------------------------------|:---------------------------------------------------------------------------------------------------------|:-------------------|:--------------|:----------------|:--------------------|:----------------------------------------------|
|
||||
| CROSS | Under [NIST](https://www.cross-crypto.com/CROSS_Specification_v2.2.pdf) consideration | [`CROSS-signature/CROSS-lib-oqs@179d61b`](https://github.com/CROSS-signature/CROSS-lib-oqs/commit/179d61b8b59e524fba86954f7fa269495650030a) | [Actively maintained](https://github.com/CROSS-signature/CROSS-lib-oqs/blob/main/docs/oqs-statement.txt) | Tier 3 (Community) | 1, 3, 5 | ✓ | — | portable, x86_64 (avx2) |
|
||||
| Falcon | Selected by [NIST](https://csrc.nist.gov/CSRC/media/Projects/post-quantum-cryptography/documents/round-3/submissions/Falcon-Round3.zip) for upcoming standardization | [`PQClean/PQClean@1eacfda`](https://github.com/PQClean/PQClean/commit/1eacfdafc15ddc5d5759d0b85b4cef26627df181) | TBD | Tier 3 (Community) | 1, 5 | ✓ | — | portable, ARM64_V8, x86_64 (avx2) |
|
||||
| MAYO | Under [NIST](https://csrc.nist.gov/csrc/media/Projects/pqc-dig-sig/documents/round-2/spec-files/mayo-spec-round2-web.pdf) consideration | [`PQCMayo/MAYO-C@64e15c6`](https://github.com/PQCMayo/MAYO-C/commit/64e15c622dec1f59aa5bbaf7f7c8f4f20af75106) | [Actively maintained](https://github.com/PQCMayo/MAYO-C) | Tier 3 (Community) | 1, 3, 5 | ✓ | — | portable, ARM64_V8, x86_64 (avx2) |
|
||||
| ML-DSA | Standardized by [NIST](https://csrc.nist.gov/pubs/fips/204/final) | [`pq-code-package/mldsa-native@9b0ee84`](https://github.com/pq-code-package/mldsa-native/commit/9b0ee84f4cf399043eca59eca4e5f8531ca1d61b) | [Actively maintained](https://github.com/pq-code-package/mldsa-native) | Tier 2 (Supported) | 2, 3, 5 | ✓ | — | portable, ARM64_V8, x86_64 (avx2+bmi2+popcnt) |
|
||||
| MQOM | Under [NIST](https://csrc.nist.gov/csrc/media/Projects/pqc-dig-sig/documents/round-2/spec-files/mqom-spec-round2-web.pdf) consideration | [`mqom/mqom-v2@ec6b7fa`](https://github.com/mqom/mqom-v2/commit/ec6b7fa86e232a25f8b2f151a4b4eebb8e81b5e7) | [Actively maintained](https://github.com/mqom/mqom-v2/blob/main/integration/liboqs/SUPPORT.md) | Tier 3 (Community) | 1, 3, 5 | ✓ | — | portable, x86_64 (aes+avx2) |
|
||||
| SLH-DSA | Standardized by [NIST](https://csrc.nist.gov/pubs/fips/205/final) | [`pq-code-package/slhdsa-c@a0fc1ff`](https://github.com/pq-code-package/slhdsa-c/commit/a0fc1ff253930060d0246aebca06c2538eb92b88) | Best effort | Tier 3 (Community) | 1, 3, 5 | — | — | portable |
|
||||
| SNOVA | Under [NIST](https://csrc.nist.gov/csrc/media/Projects/pqc-dig-sig/documents/round-2/spec-files/snova-spec-round2-web.pdf) consideration | [`vacuas/SNOVA@1c3ca6f`](https://github.com/vacuas/SNOVA/commit/1c3ca6f4f7286c0bde98d7d6f222cf63b9d52bff) | Best effort | Tier 3 (Community) | 1, 3, 5 | ✓ | — | portable, ARM64_V8, x86_64 (avx2) |
|
||||
| UOV | Under [NIST](https://csrc.nist.gov/csrc/media/Projects/pqc-dig-sig/documents/round-2/spec-files/uov-spec-round2-web.pdf) consideration | [`pqov/pqov@33fa527`](https://github.com/pqov/pqov/commit/33fa5278754a32064c55901c3a17d48b06cc2351) | Best effort | Tier 3 (Community) | 1, 3, 5 | ✓ | — | portable, ARM64_V8, x86_64 (avx2) |
|
||||
<!-- OQS_TEMPLATE_FRAGMENT_ALGORITHMS_SIG_END -->
|
||||
|
||||
## Stateful signature schemes
|
||||
|
||||
<!-- OQS_TEMPLATE_FRAGMENT_ALGORITHMS_SIG_STFL_START -->
|
||||
| Algorithm family | Standardization | Primary implementation | Upstream maintenance | OQS tier | NIST levels | Constant-time | Formally verified | Optimization targets |
|
||||
|:-------------------|:---------------------------------------------------------------------------------------------------------------------------------------------------------------|:----------------------------------------------------------------|:-----------------------|:-------------------|:--------------|:----------------|:--------------------|:-----------------------|
|
||||
| LMS | Standardized by [IRTF](https://www.rfc-editor.org/info/rfc8554), approved by [NIST](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-208.pdf) | [`cisco/hash-sigs`](https://github.com/cisco/hash-sigs) | Best effort | Tier 2 (Supported) | — | — | — | — |
|
||||
| XMSS | Standardized by [IRTF](https://www.rfc-editor.org/info/rfc8391), approved by [NIST](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-208.pdf) | [`XMSS/xmss-reference`](https://github.com/XMSS/xmss-reference) | Actively maintained | Tier 2 (Supported) | — | — | — | — |
|
||||
<!-- OQS_TEMPLATE_FRAGMENT_ALGORITHMS_SIG_STFL_END -->
|
||||
@@ -0,0 +1,116 @@
|
||||
# Continuous Integration (CI)
|
||||
|
||||
This document aims to provide a accessible yet comprehensive overview of the liboqs CI setup.
|
||||
|
||||
## GitHub Actions
|
||||
|
||||
liboqs relies on GitHub Actions for almost all of its CI and makes extensive use of [reusable workflows](https://docs.github.com/en/actions/sharing-automations/reusing-workflows).
|
||||
All workflow files are located in the `.github/workflows` subdirectory.
|
||||
|
||||
### Caller workflows
|
||||
|
||||
These workflows are triggered by GitHub events (for example, a pull request or a release).
|
||||
They implement the logic dictating which tests should run on which events.
|
||||
|
||||
#### <a name="push.yml"></a> Push workflow (`push.yml`)
|
||||
|
||||
This workflow is triggered by pushes to non-`main` branches.
|
||||
It calls only [basic checks](#basic.yml) unless one of the following strings is included in the commit message:
|
||||
- "[full tests]": calls [all platform tests](#platforms.yml).
|
||||
- "[extended tests]": calls the [extended tests](#extended.yml).
|
||||
- "[trigger downstream]": calls the [downstream release tests](#downstream-release.yml).
|
||||
|
||||
To trigger multiple test suites, include multiple trigger strings in the commit message.
|
||||
For example, "[full tests] [trigger downstream]" will trigger both the platform tests and the downstream release tests.
|
||||
|
||||
#### <a name="pr.yml"></a> Pull request workflow (`pr.yml`)
|
||||
|
||||
This workflow runs on pull requests.
|
||||
It calls [basic checks](#basic.yml), [code coverage tests](#code-coverage.yml), [platform tests](#platforms.yml) and [scorecard analysis](#scorecard.yml).
|
||||
|
||||
#### <a name="commit-to-main.yml"></a> Commit-to-main workflow (`commit-to-main.yml`)
|
||||
|
||||
This workflow runs on pushes to the `main` branch (typically done automatically when a pull request is merged).
|
||||
It calls [platform tests](#platforms.yml), [code coverage tests](#code-coverage.yml), [scorecard analysis](#scorecard.yml), and [basic downstream tests](#downstream-basic.yml).
|
||||
|
||||
#### <a name="weekly.yml"></a> Weekly workflow (`weekly.yml`)
|
||||
|
||||
This workflow is triggered by a weekly schedule.
|
||||
It calls [extended tests](#extended.yml), [scorecard analysis](#scorecard.yml), and [continuous benchmarking](#kem-bench.yml-sig-bench.yml)
|
||||
|
||||
#### <a name="release.yml"></a> Release workflow (`release.yml`)
|
||||
|
||||
This workflow is triggered when a release (including a pre-release) is published on GitHub.
|
||||
It calls [extended tests](#extended) and [downstream release tests](#downstream-release.yml).
|
||||
|
||||
### Callable workflows
|
||||
|
||||
These workflows are not triggered directly by any GitHub event.
|
||||
They are instead called by one of the [caller workflows](#caller-workflows).
|
||||
Users with "write" permissions can also trigger them manually via the GitHub web UI or REST API.
|
||||
|
||||
#### <a name="basic.yml"></a> Basic checks (`basic.yml`)
|
||||
|
||||
This workflow runs a minimal set of tests that should pass before heavier tests are triggered.
|
||||
|
||||
#### <a name="code-coverage.yml"></a> Code coverage tests (`code-coverage.yml`)
|
||||
|
||||
This workflow runs code coverage tests and uploads the results to [Coveralls.io](https://coveralls.io/github/open-quantum-safe/liboqs).
|
||||
|
||||
#### <a name="<platform>.yml"></a> Individual platform tests (`<platform>.yml`)
|
||||
|
||||
These workflows contain tests for the individual [platforms supported by liboqs](PLATFORMS.md).
|
||||
Currently, these include
|
||||
- `android.yml`,
|
||||
- `apple.yml`,
|
||||
- `macos.yml`,
|
||||
- `linux.yml`,
|
||||
- `windows.yml`, and
|
||||
- `zephyr.yml`.
|
||||
|
||||
All of these these are wrapped by [`platforms.yml`](#platforms.yml).
|
||||
|
||||
#### <a name="platforms.yml"></a> All platform tests (`platforms.yml`)
|
||||
|
||||
This workflow calls all of the [platform-specific tests](#<platform>.yml).
|
||||
|
||||
#### <a name="extended.yml"></a> Extended tests (`extended.yml`)
|
||||
|
||||
This workflow calls tests which are either resource intensive or rarely need to be triggered.
|
||||
Currently, this includes constant-time testing with valgrind and the full suite of NIST Known Answer Tests.
|
||||
|
||||
#### <a name="downstream-basic.yml"></a> Basic downstream trigger (`downstream-basic.yml`)
|
||||
|
||||
This workflow triggers basic CI for a selection of projects that depend on `liboqs`.
|
||||
Currently, these include
|
||||
- [`OQS OpenSSL3 provider`](https://github.com/open-quantum-safe/oqs-provider)
|
||||
- [`OQS-BoringSSL`](https://github.com/open-quantum-safe/boringssl)
|
||||
- [`OQS-OpenSSH`](https://github.com/open-quantum-safe/openssh)
|
||||
- [`OQS Demos`](https://github.com/open-quantum-safe/oqs-demos)
|
||||
- [`liboqs-cpp`](https://github.com/open-quantum-safe/liboqs-cpp)
|
||||
- [`liboqs-go`](https://github.com/open-quantum-safe/liboqs-go)
|
||||
- [`liboqs-python`](https://github.com/open-quantum-safe/liboqs-python)
|
||||
|
||||
Callers must include `secrets: inherit` in order for the appropriate access tokens to be passed to this workflow.
|
||||
|
||||
#### <a name="downstream-release.yml"></a> Downstream release trigger (`downstream-release.yml`)
|
||||
|
||||
This workflow triggers release tests for a selection of projects that depend on `liboqs`.
|
||||
Currently, this is only the [`OQS OpenSSL3 provider`](https://github.com/open-quantum-safe/oqs-provider).
|
||||
Callers must include `secrets: inherit` in order for the appropriate access tokens to be passed to this workflow.
|
||||
|
||||
#### <a name="scorecard.yml"></a> OpenSSF scorecard analysis (`scorecard.yml`)
|
||||
|
||||
This workflow runs the [OpenSSF scorecard](https://github.com/ossf/scorecard) tool.
|
||||
It is additionally triggered automatically when branch protection rules are changed.
|
||||
Callers must include `secrets: inherit` in order for the appropriate access tokens to be passed to this workflow.
|
||||
|
||||
#### <a name="kem-bench.yml-sig-bench.yml"></a> KEMs and signatures continuous benchmarking (`kem-bench.yml` and `sig-bench-yml`)
|
||||
|
||||
These workflows execute a benchmarkig framework to retrieve the performance of KEM and signature algorithms in CPU cycles.
|
||||
When new algorithms are added to the codebase, they must be included inside the algorithms matrices found within these files.
|
||||
|
||||
## Travis CI
|
||||
|
||||
In the past, we used Travis CI to test on [some IBM platforms](PLATFORMS.md#tier-3-1) that are not supported by GitHub Actions.
|
||||
Our Travis builds are currently disabled pending resolution of [issue #2068](https://github.com/open-quantum-safe/liboqs/issues/2068).
|
||||
@@ -0,0 +1,356 @@
|
||||
# SPDX-License-Identifier: MIT
|
||||
|
||||
cmake_minimum_required (VERSION 3.15)
|
||||
# option() honors normal variables.
|
||||
# see: https://cmake.org/cmake/help/git-stage/policy/CMP0077.html
|
||||
if(POLICY CMP0077)
|
||||
cmake_policy(SET CMP0077 NEW)
|
||||
endif()
|
||||
# Honor symbol visibility properties for all target types.
|
||||
# see: https://cmake.org/cmake/help/git-stage/policy/CMP0063.html
|
||||
if(POLICY CMP0063)
|
||||
cmake_policy(SET CMP0063 NEW)
|
||||
endif()
|
||||
if(POLICY CMP0066)
|
||||
cmake_policy(SET CMP0066 NEW)
|
||||
endif()
|
||||
if(POLICY CMP0067)
|
||||
cmake_policy(SET CMP0067 NEW)
|
||||
endif()
|
||||
|
||||
project(liboqs C ASM)
|
||||
|
||||
option(OQS_DIST_BUILD "Build distributable library with optimized code for several CPU microarchitectures. Enables run-time CPU feature detection." ON)
|
||||
option(OQS_BUILD_ONLY_LIB "Build only liboqs and do not expose build targets for tests, documentation, and pretty-printing available." OFF)
|
||||
set(OQS_MINIMAL_BUILD "" CACHE STRING "Only build specifically listed algorithms.")
|
||||
option(OQS_LIBJADE_BUILD "Enable formally verified implementation of supported algorithms from libjade." OFF)
|
||||
option(OQS_PERMIT_UNSUPPORTED_ARCHITECTURE "Permit compilation on an an unsupported architecture." OFF)
|
||||
option(OQS_STRICT_WARNINGS "Enable all compiler warnings." OFF)
|
||||
option(OQS_EMBEDDED_BUILD "Compile liboqs for an Embedded environment without a full standard library." OFF)
|
||||
option(OQS_MEMOPT_BUILD "Build with memory-optimized implementations where available." OFF)
|
||||
option(OQS_USE_CUPQC "Utilize cuPQC as the backend for supported PQC algorithms." OFF)
|
||||
option(OQS_USE_ICICLE "Utilize ICICLE as the backend for supported PQC algorithms." OFF)
|
||||
# --- Test Configuration ---
|
||||
set(OQS_PYTEST_NUMPROCESSES "auto" CACHE STRING "Number of parallel processes for pytest (e.g., 'auto', '1', '2'). Useful for limiting memory usage on constrained CI/CD systems.")
|
||||
message(STATUS "OQS Testing: Pytest parallel workers set to '${OQS_PYTEST_NUMPROCESSES}'")
|
||||
|
||||
# Libfuzzer isn't supported on gcc
|
||||
if('${CMAKE_C_COMPILER_ID}' STREQUAL 'Clang')
|
||||
option(OQS_BUILD_FUZZ_TESTS "Build fuzz test suite" OFF)
|
||||
endif()
|
||||
|
||||
|
||||
set(OQS_OPT_TARGET auto CACHE STRING "The target microarchitecture for optimization.")
|
||||
|
||||
set(CMAKE_C_STANDARD 11)
|
||||
set(CMAKE_C_STANDARD_REQUIRED ON)
|
||||
set(CMAKE_POSITION_INDEPENDENT_CODE ON)
|
||||
set(CMAKE_C_VISIBILITY_PRESET hidden)
|
||||
set(OQS_VERSION_MAJOR 0)
|
||||
set(OQS_VERSION_MINOR 16)
|
||||
set(OQS_VERSION_PATCH 0)
|
||||
set(OQS_VERSION_PRE_RELEASE "")
|
||||
set(OQS_VERSION_TEXT "${OQS_VERSION_MAJOR}.${OQS_VERSION_MINOR}.${OQS_VERSION_PATCH}${OQS_VERSION_PRE_RELEASE}")
|
||||
set(OQS_COMPILE_BUILD_TARGET "${CMAKE_SYSTEM_PROCESSOR}-${CMAKE_HOST_SYSTEM}")
|
||||
set(OQS_MINIMAL_GCC_VERSION "7.1.0")
|
||||
set(CMAKE_EXPORT_COMPILE_COMMANDS ON)
|
||||
|
||||
# Determine the flags for fuzzing. Use OSS-Fuzz's configuration if available, otherwise fall back to defaults.
|
||||
if(DEFINED ENV{LIB_FUZZING_ENGINE})
|
||||
set(FUZZING_ENGINE $ENV{LIB_FUZZING_ENGINE})
|
||||
set(FUZZING_COMPILE_FLAGS "")
|
||||
set(FUZZING_LINK_FLAGS "${FUZZING_ENGINE}")
|
||||
else()
|
||||
set(FUZZING_COMPILE_FLAGS "-fsanitize=fuzzer,address")
|
||||
set(FUZZING_LINK_FLAGS "-fsanitize=fuzzer,address")
|
||||
endif()
|
||||
|
||||
# heuristic check to see whether we're running on a RaspberryPi
|
||||
if(EXISTS "/opt/vc/include/bcm_host.h")
|
||||
add_definitions( -DOQS_USE_RASPBERRY_PI )
|
||||
endif()
|
||||
|
||||
if(CMAKE_SYSTEM_PROCESSOR MATCHES "x86_64|amd64|AMD64")
|
||||
set(ARCH "x86_64")
|
||||
set(ARCH_X86_64 ON)
|
||||
if(${OQS_DIST_BUILD})
|
||||
set(OQS_DIST_X86_64_BUILD ON)
|
||||
endif()
|
||||
elseif(CMAKE_SYSTEM_PROCESSOR MATCHES "x86|i586|i686")
|
||||
set(ARCH "i586")
|
||||
set(ARCH_X86 ON)
|
||||
if(${OQS_DIST_BUILD})
|
||||
set(OQS_DIST_X86_BUILD ON)
|
||||
endif()
|
||||
elseif(CMAKE_SYSTEM_PROCESSOR MATCHES "aarch64|arm64|arm64v8")
|
||||
set(ARCH "arm64v8")
|
||||
set(ARCH_ARM64v8 ON)
|
||||
if(${OQS_DIST_BUILD})
|
||||
set(OQS_DIST_ARM64_V8_BUILD ON)
|
||||
endif()
|
||||
elseif(CMAKE_SYSTEM_PROCESSOR MATCHES "armel|armhf|armv7|arm32v7")
|
||||
set(ARCH "arm32v7")
|
||||
set(ARCH_ARM32v7 ON)
|
||||
if(${OQS_DIST_BUILD})
|
||||
set(OQS_DIST_ARM32_V7_BUILD ON)
|
||||
endif()
|
||||
elseif(CMAKE_SYSTEM_PROCESSOR MATCHES "ppc64le|powerpc64le")
|
||||
set(ARCH "ppc64le")
|
||||
set(ARCH_PPC64LE ON)
|
||||
if(${OQS_DIST_BUILD})
|
||||
set(OQS_DIST_PPC64LE_BUILD ON)
|
||||
endif()
|
||||
elseif(CMAKE_SYSTEM_PROCESSOR MATCHES "(ppc64|powerpc64)")
|
||||
message(WARNING "There is currently no CI for: " ${CMAKE_SYSTEM_PROCESSOR})
|
||||
set(ARCH "ppc64")
|
||||
set(ARCH_PPC64 ON)
|
||||
if(${OQS_DIST_BUILD})
|
||||
set(OQS_DIST_PPC64_BUILD ON)
|
||||
endif()
|
||||
elseif(CMAKE_SYSTEM_PROCESSOR MATCHES "(ppc|powerpc)")
|
||||
message(WARNING "There is currently no CI for: " ${CMAKE_SYSTEM_PROCESSOR})
|
||||
# CMake uses uname to derive CMAKE_SYSTEM_PROCESSOR value, so on Darwin
|
||||
# the value is identical for ppc and ppc64. To have the right build arch
|
||||
# in 64-bit case, we use CMAKE_OSX_ARCHITECTURES.
|
||||
if(APPLE AND CMAKE_OSX_ARCHITECTURES STREQUAL "ppc64")
|
||||
set(ARCH "ppc64")
|
||||
set(ARCH_PPC64 ON)
|
||||
if(${OQS_DIST_BUILD})
|
||||
set(OQS_DIST_PPC64_BUILD ON)
|
||||
endif()
|
||||
else()
|
||||
set(ARCH "ppc")
|
||||
set(ARCH_PPC ON)
|
||||
if(${OQS_DIST_BUILD})
|
||||
set(OQS_DIST_PPC_BUILD ON)
|
||||
endif()
|
||||
endif()
|
||||
elseif(CMAKE_SYSTEM_PROCESSOR MATCHES "s390x")
|
||||
set(ARCH "s390x")
|
||||
set(ARCH_S390X ON)
|
||||
if(${OQS_DIST_BUILD})
|
||||
set(OQS_DIST_S390X_BUILD ON)
|
||||
endif()
|
||||
elseif(CMAKE_SYSTEM_PROCESSOR MATCHES "riscv")
|
||||
set(ARCH "riscv")
|
||||
elseif(CMAKE_SYSTEM_PROCESSOR MATCHES "loongarch64")
|
||||
set(ARCH "loongarch64")
|
||||
set(ARCH_LOONGARCH64 ON)
|
||||
if(${OQS_DIST_BUILD})
|
||||
set(OQS_DIST_LOONGARCH64_BUILD ON)
|
||||
endif()
|
||||
elseif(OQS_PERMIT_UNSUPPORTED_ARCHITECTURE)
|
||||
message(WARNING "Unknown or unsupported processor: " ${CMAKE_SYSTEM_PROCESSOR})
|
||||
message(WARNING "Compilation on an unsupported processor should only be used for testing, as it may result an insecure configuration, for example due to variable-time instructions leaking secret information.")
|
||||
else()
|
||||
message(FATAL_ERROR "Unknown or unsupported processor: " ${CMAKE_SYSTEM_PROCESSOR} ". Override by setting OQS_PERMIT_UNSUPPORTED_ARCHITECTURE=ON")
|
||||
endif()
|
||||
|
||||
if(${OQS_USE_CUPQC})
|
||||
# CMAKE's CUDA language requires CMAKE 3.18
|
||||
cmake_minimum_required (VERSION 3.18)
|
||||
enable_language(CUDA)
|
||||
if(NOT DEFINED CMAKE_CUDA_ARCHITECTURES)
|
||||
set(CMAKE_CUDA_ARCHITECTURES 80 90)
|
||||
endif()
|
||||
find_package(cuPQC 0.2.0 REQUIRED)
|
||||
endif()
|
||||
|
||||
if(OQS_USE_ICICLE)
|
||||
enable_language(CXX)
|
||||
set(CMAKE_CXX_STANDARD 17)
|
||||
set(CMAKE_CXX_STANDARD_REQUIRED ON)
|
||||
|
||||
find_package(icicle_pqc_package REQUIRED)
|
||||
endif()
|
||||
|
||||
|
||||
if (NOT ((CMAKE_SYSTEM_NAME MATCHES "Linux|Darwin") AND (ARCH_X86_64 STREQUAL "ON")) AND (OQS_LIBJADE_BUILD STREQUAL "ON"))
|
||||
message(FATAL_ERROR "Building liboqs with libjade implementations from libjade is only supported on Linux and Darwin on x86_64.")
|
||||
endif()
|
||||
|
||||
# intentionally don't switch to variables to avoid --warn-uninitialized report
|
||||
if(OQS_USE_CPU_EXTENSIONS)
|
||||
message(FATAL_ERROR "OQS_USE_CPU_EXTENSIONS is deprecated")
|
||||
endif()
|
||||
|
||||
# intentionally don't switch to variables to avoid --warn-uninitialized report
|
||||
if(OQS_PORTABLE_BUILD)
|
||||
message(FATAL_ERROR "OQS_PORTABLE_BUILD is deprecated")
|
||||
endif()
|
||||
|
||||
get_property(_isMultiConfig GLOBAL PROPERTY GENERATOR_IS_MULTI_CONFIG)
|
||||
if(NOT _isMultiConfig AND NOT CMAKE_BUILD_TYPE)
|
||||
set(CMAKE_BUILD_TYPE Release CACHE STRING "Build type" FORCE)
|
||||
endif()
|
||||
message(STATUS "CMAKE_BUILD_TYPE=${CMAKE_BUILD_TYPE}")
|
||||
if(CMAKE_BUILD_TYPE STREQUAL "Debug" OR CMAKE_BUILD_TYPE STREQUAL "RelWithDebInfo")
|
||||
set(OQS_DEBUG_BUILD ON)
|
||||
else()
|
||||
set(OQS_DEBUG_BUILD OFF)
|
||||
endif()
|
||||
|
||||
option(OQS_SPEED_USE_ARM_PMU "Use ARM Performance Monitor Unit during benchmarking" OFF)
|
||||
|
||||
if(MSVC)
|
||||
set(CMAKE_GENERATOR_CC cl)
|
||||
endif()
|
||||
|
||||
include(.CMake/compiler_opts.cmake)
|
||||
include(.CMake/alg_support.cmake)
|
||||
|
||||
if(${OQS_USE_OPENSSL})
|
||||
if(NOT DEFINED OPENSSL_ROOT_DIR)
|
||||
if(${CMAKE_HOST_SYSTEM_NAME} STREQUAL "Darwin")
|
||||
if(EXISTS "/usr/local/opt/openssl@1.1")
|
||||
set(OPENSSL_ROOT_DIR "/usr/local/opt/openssl@1.1")
|
||||
elseif(EXISTS "/opt/homebrew/opt/openssl@1.1")
|
||||
set(OPENSSL_ROOT_DIR "/opt/homebrew/opt/openssl@1.1")
|
||||
endif()
|
||||
endif()
|
||||
endif()
|
||||
find_package(OpenSSL 1.1.1 REQUIRED)
|
||||
|
||||
if(OQS_DLOPEN_OPENSSL)
|
||||
find_program(OBJDUMP objdump)
|
||||
if(NOT OBJDUMP)
|
||||
message(FATAL_ERROR "objdump not found. Please install it from binutils.")
|
||||
endif()
|
||||
execute_process(
|
||||
COMMAND ${OBJDUMP} -p ${OPENSSL_CRYPTO_LIBRARY}
|
||||
COMMAND sed -n "s/[ ]\\{1,\\}SONAME[ ]\\{1,\\}//p"
|
||||
OUTPUT_VARIABLE OQS_OPENSSL_CRYPTO_SONAME
|
||||
OUTPUT_STRIP_TRAILING_WHITESPACE
|
||||
COMMAND_ERROR_IS_FATAL ANY)
|
||||
message(STATUS "OpenSSL dlopen SONAME: " ${OQS_OPENSSL_CRYPTO_SONAME})
|
||||
endif()
|
||||
endif()
|
||||
|
||||
set(PUBLIC_HEADERS ${PROJECT_SOURCE_DIR}/src/oqs.h
|
||||
${PROJECT_SOURCE_DIR}/src/common/aes/aes_ops.h
|
||||
${PROJECT_SOURCE_DIR}/src/common/common.h
|
||||
${PROJECT_SOURCE_DIR}/src/common/rand/rand.h
|
||||
${PROJECT_SOURCE_DIR}/src/common/sha2/sha2_ops.h
|
||||
${PROJECT_SOURCE_DIR}/src/common/sha3/sha3_ops.h
|
||||
${PROJECT_SOURCE_DIR}/src/common/sha3/sha3x4_ops.h
|
||||
${PROJECT_SOURCE_DIR}/src/kem/kem.h
|
||||
${PROJECT_SOURCE_DIR}/src/sig/sig.h
|
||||
${PROJECT_SOURCE_DIR}/src/sig_stfl/sig_stfl.h)
|
||||
|
||||
set(INTERNAL_HEADERS ${PROJECT_SOURCE_DIR}/src/common/aes/aes.h
|
||||
${PROJECT_SOURCE_DIR}/src/common/rand/rand_nist.h
|
||||
${PROJECT_SOURCE_DIR}/src/common/sha2/sha2.h
|
||||
${PROJECT_SOURCE_DIR}/src/common/sha3/sha3.h
|
||||
${PROJECT_SOURCE_DIR}/src/common/sha3/sha3x4.h)
|
||||
|
||||
if(${OQS_ENABLE_KEM_BIKE})
|
||||
set(PUBLIC_HEADERS ${PUBLIC_HEADERS} ${PROJECT_SOURCE_DIR}/src/kem/bike/kem_bike.h)
|
||||
endif()
|
||||
if(${OQS_ENABLE_KEM_FRODOKEM})
|
||||
set(PUBLIC_HEADERS ${PUBLIC_HEADERS} ${PROJECT_SOURCE_DIR}/src/kem/frodokem/kem_frodokem.h)
|
||||
endif()
|
||||
if(OQS_ENABLE_KEM_NTRUPRIME)
|
||||
set(PUBLIC_HEADERS ${PUBLIC_HEADERS} ${PROJECT_SOURCE_DIR}/src/kem/ntruprime/kem_ntruprime.h)
|
||||
endif()
|
||||
if(OQS_ENABLE_KEM_NTRU)
|
||||
set(PUBLIC_HEADERS ${PUBLIC_HEADERS} ${PROJECT_SOURCE_DIR}/src/kem/ntru/kem_ntru.h)
|
||||
endif()
|
||||
##### OQS_COPY_FROM_UPSTREAM_FRAGMENT_INCLUDE_HEADERS_START
|
||||
if(OQS_ENABLE_KEM_CLASSIC_MCELIECE)
|
||||
set(PUBLIC_HEADERS ${PUBLIC_HEADERS} ${PROJECT_SOURCE_DIR}/src/kem/classic_mceliece/kem_classic_mceliece.h)
|
||||
endif()
|
||||
if(OQS_ENABLE_KEM_HQC)
|
||||
set(PUBLIC_HEADERS ${PUBLIC_HEADERS} ${PROJECT_SOURCE_DIR}/src/kem/hqc/kem_hqc.h)
|
||||
endif()
|
||||
if(OQS_ENABLE_KEM_KYBER)
|
||||
set(PUBLIC_HEADERS ${PUBLIC_HEADERS} ${PROJECT_SOURCE_DIR}/src/kem/kyber/kem_kyber.h)
|
||||
endif()
|
||||
if(OQS_ENABLE_KEM_ML_KEM)
|
||||
set(PUBLIC_HEADERS ${PUBLIC_HEADERS} ${PROJECT_SOURCE_DIR}/src/kem/ml_kem/kem_ml_kem.h)
|
||||
endif()
|
||||
if(OQS_ENABLE_SIG_ML_DSA)
|
||||
set(PUBLIC_HEADERS ${PUBLIC_HEADERS} ${PROJECT_SOURCE_DIR}/src/sig/ml_dsa/sig_ml_dsa.h)
|
||||
endif()
|
||||
if(OQS_ENABLE_SIG_FALCON)
|
||||
set(PUBLIC_HEADERS ${PUBLIC_HEADERS} ${PROJECT_SOURCE_DIR}/src/sig/falcon/sig_falcon.h)
|
||||
endif()
|
||||
if(OQS_ENABLE_SIG_MAYO)
|
||||
set(PUBLIC_HEADERS ${PUBLIC_HEADERS} ${PROJECT_SOURCE_DIR}/src/sig/mayo/sig_mayo.h)
|
||||
endif()
|
||||
if(OQS_ENABLE_SIG_CROSS)
|
||||
set(PUBLIC_HEADERS ${PUBLIC_HEADERS} ${PROJECT_SOURCE_DIR}/src/sig/cross/sig_cross.h)
|
||||
endif()
|
||||
if(OQS_ENABLE_SIG_UOV)
|
||||
set(PUBLIC_HEADERS ${PUBLIC_HEADERS} ${PROJECT_SOURCE_DIR}/src/sig/uov/sig_uov.h)
|
||||
endif()
|
||||
if(OQS_ENABLE_SIG_SNOVA)
|
||||
set(PUBLIC_HEADERS ${PUBLIC_HEADERS} ${PROJECT_SOURCE_DIR}/src/sig/snova/sig_snova.h)
|
||||
endif()
|
||||
if(OQS_ENABLE_SIG_MQOM)
|
||||
set(PUBLIC_HEADERS ${PUBLIC_HEADERS} ${PROJECT_SOURCE_DIR}/src/sig/mqom/sig_mqom.h)
|
||||
endif()
|
||||
##### OQS_COPY_FROM_UPSTREAM_FRAGMENT_INCLUDE_HEADERS_END
|
||||
if(OQS_ENABLE_SIG_SLH_DSA)
|
||||
set(PUBLIC_HEADERS ${PUBLIC_HEADERS} ${PROJECT_SOURCE_DIR}/src/sig/slh_dsa/sig_slh_dsa.h)
|
||||
endif()
|
||||
if(OQS_ENABLE_SIG_STFL_XMSS)
|
||||
set(PUBLIC_HEADERS ${PUBLIC_HEADERS} ${PROJECT_SOURCE_DIR}/src/sig_stfl/xmss/sig_stfl_xmss.h)
|
||||
endif()
|
||||
if(OQS_ENABLE_SIG_STFL_LMS)
|
||||
set(PUBLIC_HEADERS ${PUBLIC_HEADERS} ${PROJECT_SOURCE_DIR}/src/sig_stfl/lms/sig_stfl_lms.h)
|
||||
endif()
|
||||
execute_process(COMMAND ${CMAKE_COMMAND} -E make_directory ${PROJECT_BINARY_DIR}/include/oqs)
|
||||
execute_process(COMMAND ${CMAKE_COMMAND} -E copy ${PUBLIC_HEADERS} ${PROJECT_BINARY_DIR}/include/oqs)
|
||||
execute_process(COMMAND ${CMAKE_COMMAND} -E copy ${INTERNAL_HEADERS} ${PROJECT_BINARY_DIR}/include/oqs)
|
||||
configure_file(src/oqsconfig.h.cmake ${PROJECT_BINARY_DIR}/include/oqs/oqsconfig.h)
|
||||
set(PUBLIC_HEADERS ${PUBLIC_HEADERS} ${PROJECT_BINARY_DIR}/include/oqs/oqsconfig.h)
|
||||
|
||||
include_directories(${PROJECT_BINARY_DIR}/include)
|
||||
add_subdirectory(src)
|
||||
|
||||
if(NOT ${OQS_BUILD_ONLY_LIB})
|
||||
add_subdirectory(tests)
|
||||
|
||||
if (NOT CYGWIN)
|
||||
find_package(Doxygen)
|
||||
if(DOXYGEN_FOUND)
|
||||
set(DOXYFILE ${PROJECT_SOURCE_DIR}/docs/.Doxyfile)
|
||||
add_custom_target(
|
||||
gen_docs
|
||||
COMMAND ${PROJECT_SOURCE_DIR}/scripts/run_doxygen.sh ${DOXYGEN_EXECUTABLE} ${DOXYFILE} ${PROJECT_BINARY_DIR}
|
||||
WORKING_DIRECTORY ${PROJECT_SOURCE_DIR}
|
||||
COMMENT "Generate API documentation with Doxygen."
|
||||
USES_TERMINAL)
|
||||
endif()
|
||||
endif()
|
||||
|
||||
if(NOT WIN32)
|
||||
add_custom_target(
|
||||
prettyprint
|
||||
COMMAND find src tests -name '*.[ch]' | grep -v '/external/' | grep -v 'kem.*/pqclean_' | grep -v 'sig.*/pqclean_' | xargs astyle --options=.astylerc
|
||||
WORKING_DIRECTORY ${CMAKE_SOURCE_DIR}
|
||||
USES_TERMINAL)
|
||||
endif()
|
||||
endif()
|
||||
set(CPACK_GENERATOR "DEB")
|
||||
set(CPACK_PACKAGE_VENDOR "www.openquantumsafe.org")
|
||||
set(CPACK_PACKAGE_VERSION ${OQS_VERSION_TEXT})
|
||||
if(${OQS_USE_OPENSSL})
|
||||
set(CPACK_DEBIAN_PACKAGE_DEPENDS "libc6, openssl")
|
||||
else()
|
||||
set(CPACK_DEBIAN_PACKAGE_DEPENDS "libc6")
|
||||
endif()
|
||||
|
||||
set(CPACK_DEBIAN_PACKAGE_MAINTAINER "www.openquantumsafe.org")
|
||||
include(CPack)
|
||||
|
||||
# uninstall target
|
||||
if(NOT TARGET uninstall)
|
||||
configure_file(
|
||||
"${CMAKE_CURRENT_SOURCE_DIR}/.CMake/cmake_uninstall.cmake.in"
|
||||
"${CMAKE_CURRENT_BINARY_DIR}/cmake_uninstall.cmake"
|
||||
IMMEDIATE @ONLY)
|
||||
|
||||
add_custom_target(uninstall
|
||||
COMMAND ${CMAKE_COMMAND} -P ${CMAKE_CURRENT_BINARY_DIR}/cmake_uninstall.cmake)
|
||||
endif()
|
||||
@@ -0,0 +1,128 @@
|
||||
# Contributor Covenant Code of Conduct
|
||||
|
||||
## Our Pledge
|
||||
|
||||
We as members, contributors, and leaders pledge to make participation in our
|
||||
community a harassment-free experience for everyone, regardless of age, body
|
||||
size, visible or invisible disability, ethnicity, sex characteristics, gender
|
||||
identity and expression, level of experience, education, socio-economic status,
|
||||
nationality, personal appearance, race, religion, or sexual identity
|
||||
and orientation.
|
||||
|
||||
We pledge to act and interact in ways that contribute to an open, welcoming,
|
||||
diverse, inclusive, and healthy community.
|
||||
|
||||
## Our Standards
|
||||
|
||||
Examples of behavior that contributes to a positive environment for our
|
||||
community include:
|
||||
|
||||
* Demonstrating empathy and kindness toward other people
|
||||
* Being respectful of differing opinions, viewpoints, and experiences
|
||||
* Giving and gracefully accepting constructive feedback
|
||||
* Accepting responsibility and apologizing to those affected by our mistakes,
|
||||
and learning from the experience
|
||||
* Focusing on what is best not just for us as individuals, but for the
|
||||
overall community
|
||||
|
||||
Examples of unacceptable behavior include:
|
||||
|
||||
* The use of sexualized language or imagery, and sexual attention or
|
||||
advances of any kind
|
||||
* Trolling, insulting or derogatory comments, and personal or political attacks
|
||||
* Public or private harassment
|
||||
* Publishing others' private information, such as a physical or email
|
||||
address, without their explicit permission
|
||||
* Other conduct which could reasonably be considered inappropriate in a
|
||||
professional setting
|
||||
|
||||
## Enforcement Responsibilities
|
||||
|
||||
Community leaders are responsible for clarifying and enforcing our standards of
|
||||
acceptable behavior and will take appropriate and fair corrective action in
|
||||
response to any behavior that they deem inappropriate, threatening, offensive,
|
||||
or harmful.
|
||||
|
||||
Community leaders have the right and responsibility to remove, edit, or reject
|
||||
comments, commits, code, wiki edits, issues, and other contributions that are
|
||||
not aligned to this Code of Conduct, and will communicate reasons for moderation
|
||||
decisions when appropriate.
|
||||
|
||||
## Scope
|
||||
|
||||
This Code of Conduct applies within all community spaces, and also applies when
|
||||
an individual is officially representing the community in public spaces.
|
||||
Examples of representing our community include using an official e-mail address,
|
||||
posting via an official social media account, or acting as an appointed
|
||||
representative at an online or offline event.
|
||||
|
||||
## Enforcement
|
||||
|
||||
Instances of abusive, harassing, or otherwise unacceptable behavior may be
|
||||
reported to the community leaders responsible for enforcement at
|
||||
conduct@openquantumsafe.org.
|
||||
All complaints will be reviewed and investigated promptly and fairly.
|
||||
|
||||
All community leaders are obligated to respect the privacy and security of the
|
||||
reporter of any incident.
|
||||
|
||||
## Enforcement Guidelines
|
||||
|
||||
Community leaders will follow these Community Impact Guidelines in determining
|
||||
the consequences for any action they deem in violation of this Code of Conduct:
|
||||
|
||||
### 1. Correction
|
||||
|
||||
**Community Impact**: Use of inappropriate language or other behavior deemed
|
||||
unprofessional or unwelcome in the community.
|
||||
|
||||
**Consequence**: A private, written warning from community leaders, providing
|
||||
clarity around the nature of the violation and an explanation of why the
|
||||
behavior was inappropriate. A public apology may be requested.
|
||||
|
||||
### 2. Warning
|
||||
|
||||
**Community Impact**: A violation through a single incident or series
|
||||
of actions.
|
||||
|
||||
**Consequence**: A warning with consequences for continued behavior. No
|
||||
interaction with the people involved, including unsolicited interaction with
|
||||
those enforcing the Code of Conduct, for a specified period of time. This
|
||||
includes avoiding interactions in community spaces as well as external channels
|
||||
like social media. Violating these terms may lead to a temporary or
|
||||
permanent ban.
|
||||
|
||||
### 3. Temporary Ban
|
||||
|
||||
**Community Impact**: A serious violation of community standards, including
|
||||
sustained inappropriate behavior.
|
||||
|
||||
**Consequence**: A temporary ban from any sort of interaction or public
|
||||
communication with the community for a specified period of time. No public or
|
||||
private interaction with the people involved, including unsolicited interaction
|
||||
with those enforcing the Code of Conduct, is allowed during this period.
|
||||
Violating these terms may lead to a permanent ban.
|
||||
|
||||
### 4. Permanent Ban
|
||||
|
||||
**Community Impact**: Demonstrating a pattern of violation of community
|
||||
standards, including sustained inappropriate behavior, harassment of an
|
||||
individual, or aggression toward or disparagement of classes of individuals.
|
||||
|
||||
**Consequence**: A permanent ban from any sort of public interaction within
|
||||
the community.
|
||||
|
||||
## Attribution
|
||||
|
||||
This Code of Conduct is adapted from the [Contributor Covenant][homepage],
|
||||
version 2.0, available at
|
||||
https://www.contributor-covenant.org/version/2/0/code_of_conduct.html.
|
||||
|
||||
Community Impact Guidelines were inspired by [Mozilla's code of conduct
|
||||
enforcement ladder](https://github.com/mozilla/diversity).
|
||||
|
||||
[homepage]: https://www.contributor-covenant.org
|
||||
|
||||
For answers to common questions about this code of conduct, see the FAQ at
|
||||
https://www.contributor-covenant.org/faq. Translations are available at
|
||||
https://www.contributor-covenant.org/translations.
|
||||
@@ -0,0 +1,295 @@
|
||||
Options for configuring liboqs builds
|
||||
=====================================
|
||||
|
||||
The following options can be passed to CMake before the build file generation process to customize the way liboqs is built. The syntax for doing so is: `cmake .. [ARGS] [-D<OPTION_NAME>=<OPTION_VALUE>]...`, where `<OPTON_NAME>` is:
|
||||
|
||||
- [BUILD_SHARED_LIBS](#BUILD_SHARED_LIBS)
|
||||
- [CMAKE_BUILD_TYPE](#CMAKE_BUILD_TYPE)
|
||||
- [CMAKE_INSTALL_PREFIX](#CMAKE_INSTALL_PREFIX)
|
||||
- [OQS_ALGS_ENABLED](#OQS_ALGS_ENABLED)
|
||||
- [OQS_BUILD_ONLY_LIB](#OQS_BUILD_ONLY_LIB)
|
||||
- [OQS_ENABLE_KEM_ALG/OQS_ENABLE_SIG_ALG/OQS_ENABLE_SIG_STFL_ALG](#OQS_ENABLE_KEM_ALG/OQS_ENABLE_SIG_ALG/OQS_ENABLE_SIG_STFL_ALG)
|
||||
- [OQS_MINIMAL_BUILD](#OQS_MINIMAL_BUILD)
|
||||
- [OQS_DIST_BUILD](#OQS_DIST_BUILD)
|
||||
- [OQS_USE_CPUFEATURE_INSTRUCTIONS](#OQS_USE_CPUFEATURE_INSTRUCTIONS)
|
||||
- [OQS_USE_OPENSSL](#OQS_USE_OPENSSL)
|
||||
- [OQS_USE_CUPQC](#OQS_USE_CUPQC)
|
||||
- [OQS_USE_ICICLE](#OQS_USE_ICICLE)
|
||||
- [OQS_OPT_TARGET](#OQS_OPT_TARGET)
|
||||
- [OQS_SPEED_USE_ARM_PMU](#OQS_SPEED_USE_ARM_PMU)
|
||||
- [USE_COVERAGE](#USE_COVERAGE)
|
||||
- [USE_SANITIZER](#USE_SANITIZER)
|
||||
- [OQS_ENABLE_TEST_CONSTANT_TIME](#OQS_ENABLE_TEST_CONSTANT_TIME)
|
||||
- [OQS_STRICT_WARNINGS](#OQS_STRICT_WARNINGS)
|
||||
- [OQS_EMBEDDED_BUILD](#OQS_EMBEDDED_BUILD)
|
||||
- [OQS_MEMOPT_BUILD](#OQS_MEMOPT_BUILD)
|
||||
- [OQS_LIBJADE_BUILD](#OQS_LIBJADE_BUILD)
|
||||
- [OQS_ENABLE_LIBJADE_KEM_ALG/OQS_ENABLE_LIBJADE_SIG_ALG](#OQS_ENABLE_LIBJADE_KEM_ALG/OQS_ENABLE_LIBJADE_SIG_ALG)
|
||||
- [OQS_BUILD_FUZZ_TESTS](#OQS_BUILD_FUZZ_TESTS)
|
||||
|
||||
## BUILD_SHARED_LIBS
|
||||
|
||||
Can be set to `ON` or `OFF`. When `ON`, liboqs is built as a shared library.
|
||||
|
||||
**Default**: `OFF`.
|
||||
|
||||
This means liboqs is built as a static library by default.
|
||||
|
||||
## CMAKE_BUILD_TYPE
|
||||
|
||||
Can be set to the following values:
|
||||
|
||||
- `Debug`: This compiles code with `-g` (GCC/Clang default `-O0`) and produces debugging information.
|
||||
- The [USE_COVERAGE](#USE_COVERAGE) option can also be specified to enable code coverage testing.
|
||||
- When the compiler is Clang, the [USE_SANITIZER](#USE_SANITIZER) option can also be specified to enable a Clang sanitizer.
|
||||
- `MinSizeRel`: This compiles code with `-Os -DNDEBUG` flags for reducing code size
|
||||
- `RelWithDebInfo`: This compiles code with `-O2 -g -DNDEBUG` flags
|
||||
- `Release`: This compiles code with `-O3 -DNDEBUG` flags. In the rare case where a user needs to override compilation flags under `CMAKE_BUILD_TYPE=Release`, use `CMAKE_C_FLAGS_RELEASE` (or `CMAKE_C_FLAGS` to append flags to every configuration).
|
||||
|
||||
**Default**: `Release` for single-configuration generators (Ninja, Makefile). Multi-configuration generators (Visual Studio, Xcode, Ninja Multi-Config) ignore `CMAKE_BUILD_TYPE` and instead select the configuration at build time via `--config`.
|
||||
|
||||
**Examples**:
|
||||
```bash
|
||||
# Defaults to CMAKE_BUILD_TYPE=Release
|
||||
cmake -GNinja ..
|
||||
# User-specified build types
|
||||
cmake -GNinja -DCMAKE_BUILD_TYPE="Debug" ..
|
||||
cmake -GNinja -DCMAKE_BUILD_TYPE="MinSizeRel" ..
|
||||
cmake -GNinja -DCMAKE_BUILD_TYPE="RelWithDebInfo" ..
|
||||
# Override with user-specified C flags
|
||||
cmake -GNinja -DCMAKE_C_FLAGS_RELEASE="-O1 -DNDEBUG" ..
|
||||
```
|
||||
|
||||
The exact compilation commands can be found in `compile_commands.json` under the build directory.
|
||||
|
||||
## CMAKE_INSTALL_PREFIX
|
||||
|
||||
See the [CMake documentation](https://cmake.org/cmake/help/latest/variable/CMAKE_INSTALL_PREFIX.html).
|
||||
|
||||
## OQS_ENABLE_KEM_ALG/OQS_ENABLE_SIG_ALG/OQS_ENABLE_SIG_STFL_ALG
|
||||
|
||||
Note: `ALG` in `OQS_ENABLE_KEM_ALG/OQS_ENABLE_SIG_ALG/OQS_ENABLE_SIG_STFL_ALG` should be replaced with the specific algorithm name as demonstrated below.
|
||||
|
||||
This can be set to `ON` or `OFF`, and is `ON` by default. When `OFF`, `ALG` and its code are excluded from the build process. When `ON`, made available are additional options whereby individual variants of `ALG` can be excluded from the build process.
|
||||
|
||||
For example: if `OQS_ENABLE_KEM_BIKE` is set to `ON`, the options `OQS_ENABLE_KEM_bike_l1`, `OQS_ENABLE_KEM_bike_l3`, and `OQS_ENABLE_KEM_bike_l5` are made available (and are set to be `ON` by default).
|
||||
|
||||
To enable `XMSS` stateful signature, set `OQS_ENABLE_SIG_STFL_XMSS` to `ON`, the options `OQS_ENABLE_SIG_STFL_xmss_sha256_h10` and its variants are also set to be `ON` by default. Similarly, `LMS` stateful signature family can also be enabled by setting `OQS_ENABLE_SIG_STFL_LMS` to `ON`.
|
||||
|
||||
For a full list of such options and their default values, consult [.CMake/alg_support.cmake](https://github.com/open-quantum-safe/liboqs/blob/master/.CMake/alg_support.cmake).
|
||||
|
||||
**Default**: Unset.
|
||||
|
||||
## OQS_ALGS_ENABLED
|
||||
|
||||
A selected algorithm set is enabled. Possible values are "STD" selecting all algorithms standardized by NIST; "NIST_R4" selecting all algorithms evaluated in round 4 of the NIST PQC competition; "NIST_SIG_ONRAMP" selecting algorithms evaluated in the NIST PQC "onramp" standardization for additional signature schemes; "All" (or any other value) selecting all algorithms integrated into liboqs. Parameter setting "STD" minimizes library size but may require re-running code generator scripts in projects integrating `liboqs`; e.g., [oqs-provider](https://github.com/open-quantum-safe/oqs-provider) and [oqs-boringssl](https://github.com/open-quantum-safe/boringssl).
|
||||
|
||||
**Attention**: If you use any predefined value (`STD` or `NIST_R4` or `NIST_SIG_ONRAMP` as of now) for this variable, the values added via [OQS_ENABLE_KEM_ALG/OQS_ENABLE_SIG_ALG/OQS_ENABLE_SIG_STFL_ALG](#OQS_ENABLE_KEM_ALG/OQS_ENABLE_SIG_ALG/OQS_ENABLE_SIG_STFL_ALG) variables will be ignored.
|
||||
|
||||
**Default**: `All`.
|
||||
|
||||
## OQS_BUILD_ONLY_LIB
|
||||
|
||||
Can be `ON` or `OFF`. When `ON`, only liboqs is built, and all the targets: `run_tests`, `gen_docs`, and `prettyprint` are excluded from the build system.
|
||||
|
||||
**Default**: `OFF`.
|
||||
|
||||
## OQS_MINIMAL_BUILD
|
||||
|
||||
If set, this defines a semicolon-delimited list of algorithms to be contained in a minimal build of `liboqs`: Only algorithms explicitly set here are included in a build: For example running `cmake -DOQS_MINIMAL_BUILD="KEM_ml_kem_768;SIG_ml_dsa_44" ..` will build a minimum-size `liboqs` library only containing support for ML-KEM-768 and ML-DSA-44.
|
||||
|
||||
The full list of identifiers that can be set is listed [here for KEM algorithms](https://github.com/open-quantum-safe/liboqs/blob/main/src/kem/kem.h#L34) and [here for Signature algorithms](https://github.com/open-quantum-safe/liboqs/blob/main/src/sig/sig.h#L34). The default setting is empty, thus including all [supported algorithms](https://github.com/open-quantum-safe/liboqs#supported-algorithms) in the build.
|
||||
|
||||
**Default**: Unset.
|
||||
|
||||
## OQS_DIST_BUILD
|
||||
|
||||
Can be `ON` or `OFF`. When `ON`, build liboqs for distribution. When `OFF`, build liboqs for use on a single machine.
|
||||
|
||||
The library is always built for a particular architecture, either x86-64, ARM32v7, or ARM64v8, depending on the setting of CMAKE_SYSTEM_PROCESSOR. But liboqs contains code that is optimized for micro-architectures as well, e.g. x86-64 with the AVX2 extension.
|
||||
|
||||
When built for distribution, the library will run on any CPU of the target architecture. Function calls will be dispatched to micro-architecture optimized routines at run-time using CPU feature detection.
|
||||
|
||||
When built for use on a single machine, the library will only include the best available code for the target micro-architecture (see [OQS_OPT_TARGET](#OQS_OPT_TARGET)).
|
||||
|
||||
**Default**: `ON`.
|
||||
|
||||
## OQS_USE_CPUFEATURE_INSTRUCTIONS
|
||||
|
||||
Note: `CPUFEATURE` in `OQS_USE_CPUFEATURE_INSTRUCTIONS` should be replaced with the specific CPU feature as noted below.
|
||||
|
||||
These can be set to `ON` or `OFF` and take effect if liboqs is built for use on a single machine. By default, the CPU features are automatically determined and set to `ON` or `OFF` based on the CPU features available on the build system. The default values can be overridden by providing CMake build options. The available options on x86-64 are: `OQS_USE_ADX_INSTRUCTIONS`, `OQS_USE_AES_INSTRUCTIONS`, `OQS_USE_AVX_INSTRUCTIONS`, `OQS_USE_AVX2_INSTRUCTIONS`, `OQS_USE_AVX512_INSTRUCTIONS`, `OQS_USE_BMI1_INSTRUCTIONS`, `OQS_USE_BMI2_INSTRUCTIONS`, `OQS_USE_PCLMULQDQ_INSTRUCTIONS`, `OQS_USE_VPCLMULQDQ_INSTRUCTIONS`, `OQS_USE_POPCNT_INSTRUCTIONS`, `OQS_USE_SSE_INSTRUCTIONS`, `OQS_USE_SSE2_INSTRUCTIONS` and `OQS_USE_SSE3_INSTRUCTIONS`. The available options on ARM64v8 are `OQS_USE_ARM_AES_INSTRUCTIONS`, `OQS_USE_ARM_SHA2_INSTRUCTIONS`, `OQS_USE_ARM_SHA3_INSTRUCTIONS` and `OQS_USE_ARM_NEON_INSTRUCTIONS`.
|
||||
|
||||
**Default**: Options valid on the build machine.
|
||||
|
||||
## OQS_USE_OPENSSL
|
||||
|
||||
To save size and limit the amount of different cryptographic code bases, it is possible to use OpenSSL as a crypto code provider by setting this configuration option.
|
||||
|
||||
This can be set to `ON` or `OFF`. When `ON`, the additional options `OQS_USE_AES_OPENSSL`, `OQS_USE_SHA2_OPENSSL`, and `OQS_USE_SHA3_OPENSSL` are made available to control whether liboqs uses OpenSSL's AES, SHA-2, and SHA-3 implementations.
|
||||
|
||||
By default,
|
||||
- `OQS_USE_AES_OPENSSL` is `ON` (on x86-64 only if `OQS_DIST_BUILD` and `OQS_USE_AES_INSTRUCTIONS` are not set)
|
||||
- `OQS_USE_SHA2_OPENSSL` is `ON`
|
||||
- `OQS_USE_SHA3_OPENSSL` is `OFF`.
|
||||
|
||||
These default choices have been made to optimize the default performance of all algorithms. Changing them implies performance penalties.
|
||||
|
||||
When `OQS_USE_OPENSSL` is `ON`, CMake also scans the filesystem to find the minimum version of OpenSSL required by liboqs (which happens to be 1.1.1). The [OPENSSL_ROOT_DIR](https://cmake.org/cmake/help/latest/module/FindOpenSSL.html) option can be set to aid CMake in its search.
|
||||
|
||||
**Default**: `ON`.
|
||||
|
||||
### OQS_DLOPEN_OPENSSL
|
||||
|
||||
Dynamically load OpenSSL through `dlopen`. When using liboqs from other cryptographic libraries, hard dependency on OpenSSL is sometimes undesirable. If this option is `ON`, loading of OpenSSL will be deferred until any of the OpenSSL functions is used.
|
||||
|
||||
Only has an effect if the system supports `dlopen` and ELF binary format, such as Linux or BSD family.
|
||||
|
||||
### OQS_USE_CUPQC
|
||||
|
||||
Can be `ON` or `OFF`. When `ON`, use NVIDIA's cuPQC library where able (currently just ML-KEM). When this option is enabled, liboqs may not run correctly on machines that lack supported GPUs. To download cuPQC follow the instructions at (https://developer.nvidia.com/cupqc-download/). Detailed descriptions of the API, requirements, and installation guide are in the cuPQC documentation (https://docs.nvidia.com/cuda/cupqc/index.html). While the code shipped by liboqs required to use cuPQC is licensed under Apache 2.0 the cuPQC SDK comes with its own license agreement (https://docs.nvidia.com/cuda/cupqc/license.html).
|
||||
|
||||
**Default**: `OFF`
|
||||
|
||||
### OQS_USE_ICICLE
|
||||
|
||||
This CMake option can be set to `ON` or `OFF`. When enabled (`ON`), it configures liboqs to use ICICLE as the backend for supported post-quantum cryptographic (PQC) algorithms — currently ML-KEM.
|
||||
ICICLE is a GPU-accelerated cryptographic library developed by Ingonyama. It provides CUDA-based implementations of PQC algorithms to boost the performance on systems with compatible NVIDIA GPUs.
|
||||
To use ICICLE, the user needs to build and install the `icicle_pqc_package`, which contains the necessary CUDA kernels and runtime support. This package must be compiled separately before configuring liboqs with `OQS_USE_ICICLE` enabled, and its installation path should be made available to CMake.
|
||||
|
||||
Enabling this option also automatically enables C++ support in CMake, as required by ICICLE’s implementations.
|
||||
|
||||
To build ICICLE with the required PQC package:
|
||||
|
||||
```bash
|
||||
cmake -S icicle -B "$BUILD_DIR" \
|
||||
-DCMAKE_INSTALL_PREFIX="$INSTALL_DIR" \
|
||||
-DCPU_BACKEND=OFF \
|
||||
-DDISABLE_ALL_FEATURES=ON \
|
||||
-DPQC=ON \
|
||||
-DCUDA_PQC_BACKEND=ON \
|
||||
-DICICLE_STATIC_LINK=ON \
|
||||
-DPQC_PACKAGE=ON
|
||||
cmake --build "$BUILD_DIR"
|
||||
cmake --install "$BUILD_DIR"
|
||||
```
|
||||
|
||||
For full documentation, setup instructions, and backend support details, see the [Ingonyama documentation](https://dev.ingonyama.com/)
|
||||
|
||||
**Default**: `OFF`.
|
||||
|
||||
## Stateful Hash Based Signatures
|
||||
|
||||
XMSS and LMS are the two supported Hash-Based Signatures schemes.
|
||||
`OQS_ENABLE_SIG_STFL_XMSS` and `OQS_ENABLE_SIG_STFL_LMS` control these algorithms, which are disabled by default.
|
||||
A third variable, `OQS_HAZARDOUS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN`, also controls the ability to generate keys and signatures. This is also disabled by default.
|
||||
Each of these variables can be set to `ON` or `OFF`.
|
||||
When all three are `ON`, stateful signatures are fully functional and can generate key pairs, sign data, and verify signatures.
|
||||
If `OQS_HAZARDOUS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN` is `OFF` signature verification is the only functional operation.
|
||||
|
||||
Standards bodies, such as NIST, recommend that key and signature generation only by done in hardware in order to best enforce the one-time use of secret keys.
|
||||
Keys stored in a file system are extremely susceptible to simultaneous use.
|
||||
When enabled in this library a warning message will be generated by the config process.
|
||||
The name of the configuration variable has been chosen to make every user of this feature aware of its security risks.
|
||||
The OQS team explicitly discourages enabling this variable and reserves the right to remove this feature in future releases if its use causes actual harm.
|
||||
It remains present as long as it is responsibly used as per the stated warnings.
|
||||
|
||||
By default,
|
||||
- `OQS_ENABLE_SIG_STFL_XMSS` is `OFF`
|
||||
- `OQS_ENABLE_SIG_STFL_LMS` is `OFF`
|
||||
- `OQS_HAZARDOUS_EXPERIMENTAL_ENABLE_SIG_STFL_KEY_SIG_GEN` is `OFF`.
|
||||
|
||||
**Default**: `OFF`.
|
||||
|
||||
## OQS_OPT_TARGET
|
||||
|
||||
An optimization target. Only has an effect if the compiler is GCC or Clang and `OQS_DIST_BUILD=OFF`. Can take any valid input to the `-march` (on x86-64) or `-mcpu` (on ARM32v7 or ARM64v8) option for `CMAKE_C_COMPILER`. Can also be set to one of the following special values.
|
||||
- `auto`: Use `-march=native` or `-mcpu=native` (if the compiler supports it).
|
||||
- `generic`: Use `-march=x86-64` on x86-64, or `-mcpu=cortex-a5` on ARM32v7, or `-mcpu=cortex-a53` on ARM64v8.
|
||||
|
||||
**Default**: `auto`.
|
||||
|
||||
## OQS_SPEED_USE_ARM_PMU
|
||||
|
||||
Can be `ON` or `OFF`. When `ON`, the benchmarking script will try to use the ARMv8 Performance Monitoring Unit (PMU). This will make cycle counts on ARMv8 platforms significantly more accurate.
|
||||
|
||||
In order to use this option, user mode access to the PMU must be enabled via a kernel module. If user mode access is not enabled via the kernel module, benchmarking will throw an `Illegal Instruction` error. A kernel module that has been found to work on several platforms can be found [here for Linux](https://github.com/mupq/pqax#enable-access-to-performance-counters). Follow the instructions there (i.e., clone the repository, `cd enable_ccr` and `make install`) to load the kernel module, after which benchmarking should work. Superuser permissions are required. Linux header files must also be installed on your platform, which may not be present by default.
|
||||
|
||||
Note that this option is not known to work on Apple M1 chips.
|
||||
|
||||
**Default**: `OFF`.
|
||||
|
||||
## USE_COVERAGE
|
||||
|
||||
This has an effect when the compiler is GCC or Clang and when [CMAKE_BUILD_TYPE](#CMAKE_BUILD_TYPE) is `Debug`. Can be `ON` or `OFF`. When `ON`, code coverage testing will be enabled.
|
||||
|
||||
**Default**: Unset.
|
||||
|
||||
## USE_SANITIZER
|
||||
|
||||
This has an effect when the compiler is Clang and when [CMAKE_BUILD_TYPE](#CMAKE_BUILD_TYPE) is `Debug`. Then, it can be set to:
|
||||
|
||||
- `Address`: This enables Clang's `AddressSanitizer`
|
||||
- `Memory`: This enables Clang's `MemorySanitizer`
|
||||
- `MemoryWithOrigins`: This enables Clang's `MemorySanitizer` with the added functionality of being able to track the origins of uninitialized values
|
||||
- `Undefined`: This enables Clang's `UndefinedBehaviorSanitizer`. The `BLACKLIST_FILE` option can be additionally set to a path to a file listing the entities Clang should ignore.
|
||||
- `Thread`: This enables Clang's `ThreadSanitizer`
|
||||
- `Leak`: This enables Clang's `LeakSanitizer`
|
||||
|
||||
**Default**: Unset.
|
||||
|
||||
## OQS_ENABLE_TEST_CONSTANT_TIME
|
||||
|
||||
This is used in conjunction with `tests/test_constant_time.py` to use Valgrind to look for instances of secret-dependent control flow. liboqs must also be compiled with [CMAKE_BUILD_TYPE](#CMAKE_BUILD_TYPE) set to `Debug`.
|
||||
|
||||
See the documentation in [`tests/test_constant_time.py`](https://github.com/open-quantum-safe/liboqs/blob/main/tests/test_constant_time.py) for more usage information.
|
||||
|
||||
When this option is set to `ON`, the additional option `OQS_ENABLE_TEST_CONSTANT_TIME_OPTIMIZED` is made available to control whether liboqs is built using `-O3` optimization, as in a release build, or using the default "Debug" profile. By default, `OQS_ENABLE_TEST_CONSTANT_TIME_OPTIMIZED` is `OFF`.
|
||||
|
||||
**Default**: `OFF`.
|
||||
|
||||
## OQS_STRICT_WARNINGS
|
||||
|
||||
Can be `ON` or `OFF`. When `ON`, all compiler warnings are enabled and treated as errors. This setting is recommended to be enabled prior to submission of a Pull Request as CI runs with this setting active. When `OFF`, significantly fewer compiler warnings are enabled such as to avoid undue build errors triggered by (future) compiler warning features/unknown at the development time of this library.
|
||||
|
||||
**Default**: `OFF`.
|
||||
|
||||
## OQS_EMBEDDED_BUILD
|
||||
|
||||
Can be `ON` or `OFF`. When `ON`, calls to standard library functions typically not present in a bare-metal embedded environment are excluded from compilation.
|
||||
|
||||
At the moment, this is **only** considered for random number generation, as both `getentropy()` and a file based `/dev/urandom` are not available on embedded targets (e.g. the Zephyr port).
|
||||
|
||||
**Attention**: When this option is enabled, you have to supply a custom callback for obtaining random numbers using the `OQS_randombytes_custom_algorithm()` API before accessing the cryptographic API. Otherwise, all key generation and signing operations will fail.
|
||||
|
||||
**Default**: `OFF`.
|
||||
|
||||
## OQS_MEMOPT_BUILD
|
||||
|
||||
Can be `ON` or `OFF`. When `ON`, selects memory-optimized implementations of algorithms where available. Memory-optimized implementations reduce memory usage at a potential cost to performance. If no memory-optimized implementation exists for a given algorithm or platform, the standard implementation is used as a fallback.
|
||||
|
||||
Upstream projects can provide memory-optimized implementations by adding a separate implementation entry in their META.yml file with `memory_optimized: true`.
|
||||
|
||||
**Default**: `OFF`.
|
||||
|
||||
## OQS_LIBJADE_BUILD
|
||||
Can be `ON` or `OFF`. When `ON` liboqs is built to use high assurance implementations of cryptographic algorithms from [Libjade](https://github.com/formosa-crypto/libjade). The cryptographic primitives in Libjade are written using [Jasmin](https://github.com/jasmin-lang/jasmin) and built using the Jasmin compiler. The Jasmin compiler is proven (in Coq) to preserve semantic correctness of a program, maintain secret-independence of control flow, and maintain secret independence of locations of memory access through compilation. Additionally, the Jasmin compiler guarantees thread safety because Jasmin doesn't support global variables.
|
||||
|
||||
At the moment, Libjade only provides Kyber512 and Kyber768 KEMs.
|
||||
|
||||
At the moment, libjade only supports Linux and Darwin based operating systems on x86_64 platforms.
|
||||
|
||||
**Default** `OFF`.
|
||||
|
||||
## OQS_ENABLE_LIBJADE_KEM_ALG/OQS_ENABLE_LIBJADE_SIG_ALG
|
||||
|
||||
Note: `ALG` in `OQS_ENABLE_LIBJADE_KEM_ALG/OQS_ENABLE_LIBJADE_SIG_ALG` should be replaced with the specific algorithm name as demonstrated in OQS_ENABLE_KEM_ALG/OQS_ENABLE_SIG_ALG.
|
||||
|
||||
**Default**: `OFF` if OQS_LIBJADE_BUILD is `OFF` else unset.
|
||||
|
||||
## OQS_BUILD_FUZZ_TESTS
|
||||
Can be `ON` or `OFF`. When `ON` liboqs the fuzz test-suite will be enabled. This option is only available if the c compiler is set to clang i.e. `-DCMAKE_C_COMPILER=clang`.
|
||||
|
||||
Note: It is strongly recommended that this configuration be enabled with `CFLAGS=-fsanitize=address,fuzzer-no-link LDFLAGS=-fsanitize=address`. While fuzzing will run without these flags, enabling this instrumentation will make fuzzing performance much faster and catch [potential memory related bugs](https://clang.llvm.org/docs/AddressSanitizer.html).
|
||||
|
||||
**Default** `OFF`.
|
||||
Loaded 100 of 6763 files, more files were not shown because too many files have changed in this diff.
Show more
Reference in new issue
Block a user