Skip to content

CMake: uniform the WOLFCRYPT_TZ_PSA flags with options.mk; fix hex version number - #919

Merged
dgarske merged 3 commits into
wolfSSL:masterfrom
danielinux:release-v2.10-fixup
Oct 1, 2026
Merged

dgarske merged 3 commits into
wolfSSL:masterfrom
danielinux:release-v2.10-fixup

Conversation

@danielinux

Copy link
Copy Markdown
Member

No description provided.

Copilot AI balanced review requested due to automatic review settings October 1, 2026 16:02

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The CMake PSA path omits required sources and does not reject hardware DICE without PSA.

Review effort: Balanced
Findings: 1 High severity · 1 Medium severity

Open (2)
What changed in this PR

Aligns CMake PSA configuration with options.mk and corrects the encoded version number.

Changes:

  • Adds wolfPSA includes, definitions, and hardware-DICE handling.
  • Corrects version 2.10.0 hexadecimal encoding.
File Description
CMakeLists.txt Expands PSA-related CMake configuration.
include/​wolfboot/​version.h Corrects the hexadecimal version.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread CMakeLists.txt
Comment thread CMakeLists.txt

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

PSA builds currently contain invalid source paths, missing crypto dependencies, and incomplete hardware-DICE integration.

Review effort: Balanced
Findings: 4 High severity

Open (4)
Resolved since last review (2)

Comment thread CMakeLists.txt Outdated
Comment thread CMakeLists.txt Outdated
Comment thread CMakeLists.txt
Comment thread lib/CMakeLists.txt Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

PSA CMake builds omit required algorithm sources and lack CI coverage.

Review effort: Balanced
Findings: 1 Low severity

Open (1)
Resolved since last review (4)
Previously missed (1)

In code that hasn't changed since last review

Medium severity PSA builds omit RSA, ECC, and math fallback sources

lib/​CMakeLists.txt:217

The PSA build still omits the RSA/ECC/math fallback sources that options.mk:1286-1300 adds. For example, an ECC-signed PSA build supplies ECC through SIGN but never compiles rsa.c, even though the secure PSA service supports software RSA and ECC (include/user_settings.h:170-175). Mirror the conditional source selection used by the PKCS11 block so PSA functionality does not depend on the boot signature algorithm.

Comment thread CMakeLists.txt
@dgarske
dgarske merged commit eb710fe into wolfSSL:master Oct 1, 2026
463 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants