Repository navigation
Expand file tree
/
Copy pathconfigure.ac
More file actions
339 lines (296 loc) · 11.7 KB
/
Copy pathconfigure.ac
File metadata and controls
339 lines (296 loc) · 11.7 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
AC_PREREQ([2.69])
AC_INIT([wolfspdm],[1.0.0],[support@wolfssl.com])
AC_CONFIG_SRCDIR([src/spdm_context.c])
AC_CONFIG_HEADERS([config.h])
AC_CONFIG_AUX_DIR([build-aux])
AC_CONFIG_MACRO_DIR([m4])
AM_INIT_AUTOMAKE([1.11 foreign subdir-objects -Wall -Werror])
AC_PROG_CC
AM_PROG_CC_C_O
AM_PROG_AR
AC_PROG_INSTALL
LT_INIT
# Checks for header files
AC_CHECK_HEADERS([stdint.h string.h stdlib.h])
# Checks for typedefs, structures, and compiler characteristics
AC_TYPE_SIZE_T
AC_TYPE_UINT8_T
AC_TYPE_UINT16_T
AC_TYPE_UINT32_T
AC_TYPE_UINT64_T
# wolfSSL/wolfCrypt detection
AC_ARG_WITH([wolfssl],
[AS_HELP_STRING([--with-wolfssl=PATH], [Path to wolfSSL installation])],
[WOLFSSL_DIR=$withval],
[WOLFSSL_DIR=""])
if test -n "$WOLFSSL_DIR"; then
# Prepend local wolfSSL includes to ensure they take priority over system
CPPFLAGS="-I$WOLFSSL_DIR -I$WOLFSSL_DIR/include $CPPFLAGS"
LDFLAGS="-L$WOLFSSL_DIR/src/.libs -L$WOLFSSL_DIR/lib $LDFLAGS"
fi
AC_CHECK_LIB([wolfssl], [wc_InitRng], [],
[AC_MSG_ERROR([wolfSSL library not found. Use --with-wolfssl=PATH])])
AC_CHECK_HEADER([wolfssl/wolfcrypt/ecc.h], [],
[AC_MSG_ERROR([wolfSSL headers not found. Use --with-wolfssl=PATH])])
# wolfSSL minimum version: v5.8.0-stable. This is the oldest release the CI
# matrix in .github/workflows/wolfssl-versions.yml exercises end-to-end; older
# releases are not validated and may be missing API/curve fixes wolfSPDM relies
# on (ECDHE P-384, HKDF-SHA384, AES-256-GCM record protection).
AC_MSG_CHECKING([wolfSSL version >= v5.8.0])
AC_COMPILE_IFELSE([AC_LANG_SOURCE([[
#include <wolfssl/version.h>
#if !defined(LIBWOLFSSL_VERSION_HEX) || LIBWOLFSSL_VERSION_HEX < 0x05008000
#error "wolfSSL < v5.8.0"
#endif
int main(void) { return 0; }
]])],
[AC_MSG_RESULT([yes])],
[AC_MSG_RESULT([no])
AC_MSG_ERROR([wolfSPDM requires wolfSSL >= v5.8.0-stable. Please upgrade wolfSSL.])])
# Debug mode
AC_ARG_ENABLE([debug],
[AS_HELP_STRING([--enable-debug], [Enable debug output])],
[enable_debug=$enableval],
[enable_debug=no])
if test "x$enable_debug" = "xyes"; then
AC_DEFINE([WOLFSPDM_DEBUG], [1], [Enable debug output])
CFLAGS="$CFLAGS -g -O0"
else
CFLAGS="$CFLAGS -O2"
fi
# Dynamic memory allocation (enables wolfSPDM_New/XMALLOC)
AC_ARG_ENABLE([dynamic-mem],
[AS_HELP_STRING([--enable-dynamic-mem], [Enable dynamic memory allocation (wolfSPDM_New)])],
[enable_dynamic_mem=$enableval],
[enable_dynamic_mem=no])
if test "x$enable_dynamic_mem" = "xyes"; then
AC_DEFINE([WOLFSPDM_DYNAMIC_MEMORY], [1], [Enable dynamic memory allocation])
fi
# MCTP secured messages carry the standard requester; a pure TCG build drops both
AC_ARG_ENABLE([mctp],
[AS_HELP_STRING([--disable-mctp], [Drop MCTP secured messages and the standard requester for a pure TCG build (default: enabled)])],
[enable_mctp=$enableval],
[enable_mctp=yes])
# Standard certificate-based requester (DSP0274 flow for non-TPM responders)
AC_ARG_ENABLE([cert],
[AS_HELP_STRING([--disable-cert], [Disable the standard certificate-based requester (default: enabled)])],
[enable_cert=$enableval],
[enable_cert=yes])
if test "x$enable_mctp" = "xno"; then
enable_cert=no
fi
if test "x$enable_cert" = "xno"; then
AC_DEFINE([WOLFSPDM_NO_CERT], [1], [Disable the standard certificate requester])
fi
AM_CONDITIONAL([BUILD_CERT], [test "x$enable_cert" = "xyes"])
AC_ARG_ENABLE([heartbeat],
[AS_HELP_STRING([--disable-heartbeat], [Disable HEARTBEAT session keep-alive (default: enabled)])],
[enable_heartbeat=$enableval],
[enable_heartbeat=yes])
if test "x$enable_heartbeat" = "xno"; then
AC_DEFINE([WOLFSPDM_NO_HEARTBEAT], [1], [Disable HEARTBEAT])
fi
AC_ARG_ENABLE([app-data],
[AS_HELP_STRING([--disable-app-data], [Disable the MCTP application data API (default: enabled)])],
[enable_app_data=$enableval],
[enable_app_data=yes])
if test "x$enable_mctp" = "xno"; then
enable_app_data=no
fi
if test "x$enable_app_data" = "xno"; then
AC_DEFINE([WOLFSPDM_NO_APP_DATA], [1], [Disable the application data API])
fi
# ML-DSA (FIPS 204) and ML-KEM (FIPS 203) from DSP0274 1.4 follow the linked
# wolfSSL by default; both ride the certificate flow
AC_ARG_ENABLE([mldsa],
[AS_HELP_STRING([--disable-mldsa], [Disable ML-DSA signatures even if wolfSSL has them (default: auto)])],
[enable_mldsa=$enableval],
[enable_mldsa=auto])
AC_ARG_ENABLE([mlkem],
[AS_HELP_STRING([--disable-mlkem], [Disable ML-KEM key exchange even if wolfSSL has it (default: auto)])],
[enable_mlkem=$enableval],
[enable_mlkem=auto])
have_mldsa_api=no
if test "x$enable_mldsa" != "xno" && test "x$enable_cert" = "xyes"; then
AC_MSG_CHECKING([for the wolfSSL wc_MlDsaKey context API])
AC_LINK_IFELSE([AC_LANG_PROGRAM([[
#include <wolfssl/options.h>
#include <wolfssl/wolfcrypt/settings.h>
#ifndef WOLFSSL_HAVE_MLDSA
#error "no ML-DSA"
#endif
#include <wolfssl/wolfcrypt/asn.h>
#include <wolfssl/wolfcrypt/wc_mldsa.h>
]], [[
MlDsaKey k; int res = 0; int keyOid = ML_DSA_44k;
int sigOid = CTC_ML_DSA_87;
(void)wc_MlDsaKey_Init(&k, 0, INVALID_DEVID);
(void)wc_MlDsaKey_SetParams(&k, WC_ML_DSA_65);
(void)wc_MlDsaKey_ImportPubRaw(&k, 0, 0);
(void)wc_MlDsaKey_VerifyCtx(&k, 0, 0, 0, 0, 0, 0, &res);
wc_MlDsaKey_Free(&k);
(void)keyOid; (void)sigOid;
]])],
[have_mldsa_api=yes],
[have_mldsa_api=no])
AC_MSG_RESULT([$have_mldsa_api])
fi
if test "x$have_mldsa_api" = "xyes"; then
enable_mldsa=yes
elif test "x$enable_mldsa" = "xyes"; then
AC_MSG_ERROR([--enable-mldsa needs the certificate requester and a wolfSSL built with --enable-mldsa that has the wc_MlDsaKey context API])
else
enable_mldsa=no
AC_DEFINE([WOLFSPDM_NO_MLDSA], [1], [Disable ML-DSA signatures])
fi
have_mlkem_api=no
if test "x$enable_mlkem" != "xno" && test "x$enable_cert" = "xyes"; then
AC_MSG_CHECKING([for the wolfSSL wc_MlKemKey API])
AC_LINK_IFELSE([AC_LANG_PROGRAM([[
#include <wolfssl/options.h>
#include <wolfssl/wolfcrypt/settings.h>
#ifndef WOLFSSL_HAVE_MLKEM
#error "no ML-KEM"
#endif
#include <wolfssl/wolfcrypt/wc_mlkem.h>
]], [[
MlKemKey k; word32 len = 0;
(void)wc_MlKemKey_Init(&k, WC_ML_KEM_768, 0, 0);
(void)wc_MlKemKey_MakeKey(&k, 0);
(void)wc_MlKemKey_EncodePublicKey(&k, 0, 0);
(void)wc_MlKemKey_PublicKeySize(&k, &len);
(void)wc_MlKemKey_CipherTextSize(&k, &len);
(void)wc_MlKemKey_SharedSecretSize(&k, &len);
(void)wc_MlKemKey_Decapsulate(&k, 0, 0, 0);
(void)wc_MlKemKey_Free(&k);
]])],
[have_mlkem_api=yes],
[have_mlkem_api=no])
AC_MSG_RESULT([$have_mlkem_api])
fi
if test "x$have_mlkem_api" = "xyes"; then
enable_mlkem=yes
elif test "x$enable_mlkem" = "xyes"; then
AC_MSG_ERROR([--enable-mlkem needs the certificate requester and a wolfSSL built with --enable-mlkem that has the wc_MlKemKey API])
else
enable_mlkem=no
AC_DEFINE([WOLFSPDM_NO_MLKEM], [1], [Disable ML-KEM key exchange])
fi
AC_ARG_ENABLE([chunking],
[AS_HELP_STRING([--disable-chunking], [Disable CHUNK_SEND/CHUNK_GET large message chunking (default: enabled)])],
[enable_chunking=$enableval],
[enable_chunking=yes])
if test "x$enable_chunking" = "xno"; then
AC_DEFINE([WOLFSPDM_NO_CHUNK], [1], [Disable large message chunking])
fi
AC_ARG_ENABLE([meas],
[AS_HELP_STRING([--disable-meas], [Disable GET_MEASUREMENTS attestation (default: enabled)])],
[enable_meas=$enableval],
[enable_meas=yes])
if test "x$enable_meas" = "xno"; then
AC_DEFINE([WOLFSPDM_NO_MEAS], [1], [Disable GET_MEASUREMENTS])
fi
AC_ARG_ENABLE([challenge],
[AS_HELP_STRING([--disable-challenge], [Disable CHALLENGE attestation (default: enabled)])],
[enable_challenge=$enableval],
[enable_challenge=yes])
if test "x$enable_challenge" = "xno"; then
AC_DEFINE([WOLFSPDM_NO_CHALLENGE], [1], [Disable CHALLENGE])
fi
AC_ARG_ENABLE([key-update],
[AS_HELP_STRING([--disable-key-update], [Disable KEY_UPDATE session key rotation (default: enabled)])],
[enable_key_update=$enableval],
[enable_key_update=yes])
if test "x$enable_key_update" = "xno"; then
AC_DEFINE([WOLFSPDM_NO_KEY_UPDATE], [1], [Disable KEY_UPDATE])
fi
# TCG SPDM binding (TPM transport). Nuvoton/Nations imply it.
AC_ARG_ENABLE([tcg],
[AS_HELP_STRING([--enable-tcg], [Enable the TCG SPDM binding (default: disabled)])],
[enable_tcg=$enableval],
[enable_tcg=no])
AC_ARG_ENABLE([psk],
[AS_HELP_STRING([--enable-psk], [Enable SPDM PSK_EXCHANGE/PSK_FINISH (default: disabled)])],
[enable_psk=$enableval],
[enable_psk=no])
AC_ARG_ENABLE([nuvoton],
[AS_HELP_STRING([--enable-nuvoton], [Enable Nuvoton NPCT75x SPDM vendor commands (default: disabled)])],
[enable_nuvoton=$enableval],
[enable_nuvoton=no])
AC_ARG_ENABLE([nations],
[AS_HELP_STRING([--enable-nations], [Enable Nations NS350 SPDM vendor commands (default: disabled)])],
[enable_nations=$enableval],
[enable_nations=no])
AC_ARG_ENABLE([responder],
[AS_HELP_STRING([--enable-responder], [Enable the SPDM responder (default: disabled)])],
[enable_responder=$enableval],
[enable_responder=no])
if test "x$enable_nuvoton" = "xyes" || test "x$enable_nations" = "xyes"; then
enable_tcg=yes
fi
if test "x$enable_nations" = "xyes"; then
enable_psk=yes
fi
if test "x$enable_psk" = "xyes" && test "x$enable_tcg" != "xyes"; then
AC_MSG_ERROR([--enable-psk requires --enable-tcg (PSK handshake uses TCG SPDM binding framing)])
fi
if test "x$enable_responder" = "xyes" && test "x$enable_tcg" != "xyes"; then
AC_MSG_ERROR([--enable-responder requires --enable-tcg])
fi
if test "x$enable_mctp" = "xno"; then
if test "x$enable_tcg" != "xyes"; then
AC_MSG_ERROR([--disable-mctp requires --enable-tcg or a TCG vendor])
fi
AC_DEFINE([WOLFSPDM_NO_MCTP], [1], [Drop MCTP secured messages])
fi
if test "x$enable_tcg" = "xyes"; then
AC_DEFINE([WOLFSPDM_TCG], [1], [Enable the TCG SPDM binding])
fi
if test "x$enable_psk" = "xyes"; then
AC_DEFINE([WOLFSPDM_PSK], [1], [Enable SPDM PSK mode])
fi
if test "x$enable_nuvoton" = "xyes"; then
AC_DEFINE([WOLFSPDM_NUVOTON], [1], [Enable Nuvoton SPDM vendor commands])
fi
if test "x$enable_nations" = "xyes"; then
AC_DEFINE([WOLFSPDM_NATIONS], [1], [Enable Nations SPDM vendor commands])
fi
if test "x$enable_responder" = "xyes"; then
AC_DEFINE([WOLFSPDM_RESPONDER], [1], [Enable the SPDM responder])
fi
AM_CONDITIONAL([BUILD_TCG], [test "x$enable_tcg" = "xyes"])
AM_CONDITIONAL([BUILD_PSK], [test "x$enable_psk" = "xyes"])
AM_CONDITIONAL([BUILD_NUVOTON], [test "x$enable_nuvoton" = "xyes"])
AM_CONDITIONAL([BUILD_NATIONS], [test "x$enable_nations" = "xyes"])
AM_CONDITIONAL([BUILD_RESPONDER], [test "x$enable_responder" = "xyes"])
# Output files
AC_CONFIG_FILES([Makefile wolfspdm.pc])
AC_OUTPUT
# These ride on the certificate flow and are compiled out without it
if test "x$enable_cert" = "xno"; then
enable_chunking=no
enable_meas=no
enable_challenge=no
fi
echo ""
echo "wolfSPDM configuration summary:"
echo " Version: $PACKAGE_VERSION"
echo " Debug: $enable_debug"
echo " Dynamic mem: $enable_dynamic_mem"
echo " MCTP: $enable_mctp"
echo " Standard: $enable_cert"
echo " App data: $enable_app_data"
echo " ML-DSA: $enable_mldsa"
echo " ML-KEM: $enable_mlkem"
echo " Chunking: $enable_chunking"
echo " Meas: $enable_meas"
echo " Challenge: $enable_challenge"
echo " Heartbeat: $enable_heartbeat"
echo " Key update: $enable_key_update"
echo " TCG: $enable_tcg"
echo " PSK: $enable_psk"
echo " Nuvoton: $enable_nuvoton"
echo " Nations: $enable_nations"
echo " Responder: $enable_responder"
echo " wolfSSL: ${WOLFSSL_DIR:-system}"
echo ""