diff --git a/.github/workflows/ci-workflow.yml b/.github/workflows/ci-workflow.yml index c5c6785d..241bb311 100644 --- a/.github/workflows/ci-workflow.yml +++ b/.github/workflows/ci-workflow.yml @@ -40,7 +40,7 @@ jobs: steps: - name: Clone - uses: actions/checkout@v2 + uses: actions/checkout@v4 - name: Build unit tests run: | cd tests/unit/ @@ -49,7 +49,7 @@ jobs: run: | cd tests/unit/ make coverage - - uses: actions/upload-artifact@v2 + - uses: actions/upload-artifact@v4 with: name: code-coverage path: tests/unit/coverage diff --git a/.github/workflows/codeql-workflow.yml b/.github/workflows/codeql-workflow.yml index 4627cd1b..5bc82fac 100644 --- a/.github/workflows/codeql-workflow.yml +++ b/.github/workflows/codeql-workflow.yml @@ -33,10 +33,10 @@ jobs: steps: - name: Clone - uses: actions/checkout@v3 + uses: actions/checkout@v4 - name: Initialize CodeQL - uses: github/codeql-action/init@v2 + uses: github/codeql-action/init@v3 with: languages: ${{ matrix.language }} queries: security-and-quality @@ -48,4 +48,4 @@ jobs: make BOLOS_SDK=${{ matrix.sdk }} - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@v2 + uses: github/codeql-action/analyze@v3 diff --git a/.github/workflows/lint-workflow.yml b/.github/workflows/lint-workflow.yml index 8a94eb0a..90d28876 100644 --- a/.github/workflows/lint-workflow.yml +++ b/.github/workflows/lint-workflow.yml @@ -28,7 +28,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Clone - uses: actions/checkout@v3 + uses: actions/checkout@v4 with: fetch-depth: 0 - name: Check misspellings diff --git a/.github/workflows/release-workflow.yml b/.github/workflows/release-workflow.yml index 7240ad94..786092f2 100644 --- a/.github/workflows/release-workflow.yml +++ b/.github/workflows/release-workflow.yml @@ -16,7 +16,7 @@ jobs: contents: write steps: - name: Clone - uses: actions/checkout@v3 + uses: actions/checkout@v4 with: ref: ${{ github.event.workflow_run.head_branch }} @@ -27,7 +27,7 @@ jobs: echo "VERSION_NAME=${HEAD_BRANCH//./_}" >> ${GITHUB_ENV} - name: Download app binaries - uses: dawidd6/action-download-artifact@v2 + uses: dawidd6/action-download-artifact@v3 with: name: compiled_app_binaries path: ./bin/ diff --git a/CHANGELOG.md b/CHANGELOG.md index 6bf654ad..175470fe 100755 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,8 +1,19 @@ # Change log +## [1.6.1] - 2024-01-15 +### Added +- + +### Changed +- Updated version of cmocka used for unit tests +- Updated version of github actions used + +### Fixed +- + ## [1.6.0] - 2024-01-14 ### Added -- Use CX_CHECK macro in compare_recovery_phrase() +- Use CX_CHECK macro in `compare_recovery_phrase()` - Added a `cx_crc32()` function - The implementation of `cx_crc32_hw()` on Ledger devices is buggy and produces incorrect CRC32 checks. Ledger are fixing `cx_crc32_hw()` on each device either through SDK or OS updates but until then `cx_crc32()` can be used. diff --git a/Makefile b/Makefile index 2bbcb5a9..50791665 100755 --- a/Makefile +++ b/Makefile @@ -28,7 +28,7 @@ all: default APPNAME = "Seed Tool" APPVERSION_M = 1 APPVERSION_N = 6 -APPVERSION_P = 0 +APPVERSION_P = 1 APPVERSION = "$(APPVERSION_M).$(APPVERSION_N).$(APPVERSION_P)" APP_LOAD_PARAMS = --appFlags 0x10 $(COMMON_LOAD_PARAMS) --curve secp256k1 --path "" @@ -113,10 +113,9 @@ ifeq ($(GCCPATH),) endif CC := $(CLANGPATH)clang -CFLAGS += -O3 -Os -Wshadow -Wformat -DAPPNAME=\"$(APPNAME)\" +CFLAGS += -Wshadow -Wformat -DAPPNAME=\"$(APPNAME)\" AS := $(GCCPATH)arm-none-eabi-gcc LD := $(GCCPATH)arm-none-eabi-gcc -LDFLAGS += -O3 -Os LDLIBS += -lm -lgcc -lc diff --git a/README.md b/README.md index 722aad0a..6deea1ed 100644 --- a/README.md +++ b/README.md @@ -26,9 +26,10 @@ Not all Ledger devices are equal. The older, less capable devices do not have th ||Nano S|Nano S+|Nano X|Stax| | :--- | :---: | :---: | :---: | :---: | |[Check BIP39](#check-bip39)|$${\color{green}✓}$$|$${\color{green}✓}$$|$${\color{green}✓}$$|$${\color{green}✓}$$| -|[Check Shamir's secret shares](#check-shamirs-secret-shares)|$${\color{green}✓}$$|$${\color{green}✓}$$|$${\color{green}✓}$$|$${\color{green}✓}$$| -|[Generate Shamir's secret sharing](#generate-shamirs-secret-sharing)|$${\color{green}✓}$$|$${\color{green}✓}$$|$${\color{green}✓}$$|$${\color{green}✓}$$| -|[Generate BIP85](#generate-bip85)|$${\color{red}✗}$$|$${\color{green}✓}$$|$${\color{green}✓}$$|$${\color{green}✓}$$| +|[Check Shamir's secret shares](#check-shamirs-secret-shares)|$${\color{green}✓}$$|$${\color{green}✓}$$|$${\color{green}✓}$$|$${\color{orange}✓}$$| +|[Generate Shamir's secret sharing](#generate-shamirs-secret-sharing)|$${\color{green}✓}$$|$${\color{green}✓}$$|$${\color{green}✓}$$|$${\color{orange}✓}$$| +|[Generate BIP39](#generate-bip39)|$${\color{green}✓}$$|$${\color{green}✓}$$|$${\color{green}✓}$$|$${\color{orange}✓}$$| +|[Generate BIP85](#generate-bip85)|$${\color{red}✗}$$|$${\color{orange}✓}$$|$${\color{orange}✓}$$|$${\color{orange}✓}$$| ## Check BIP39 diff --git a/src/ux_common/onboarding_seed_sskr.c b/src/ux_common/onboarding_seed_sskr.c index 3baf5cb7..436dbc42 100644 --- a/src/ux_common/onboarding_seed_sskr.c +++ b/src/ux_common/onboarding_seed_sskr.c @@ -8,6 +8,15 @@ #include "common_bip39.h" #include "sskr.h" +// Return the CRC-32 checksum of the input buffer in network byte order (big endian). +#if __BYTE_ORDER__ == __ORDER_BIG_ENDIAN__ +#define cx_crc32_nbo(...) cx_crc32(__VA_ARGS__) +#elif __BYTE_ORDER__ == __ORDER_LITTLE_ENDIAN__ +#define cx_crc32_nbo(...) os_swap_u32(cx_crc32(__VA_ARGS__)) +#else +#error "What kind of system is this?" +#endif + // NOTE: // The implementation of cx_crc32_hw() on Ledger devices is buggy and produces incorrect CRC32 // checks. Ledger are fixing cx_crc32_hw() on each device either through SDK or OS updates. @@ -28,17 +37,6 @@ uint32_t cx_crc32(const uint8_t *data, size_t len) { return ~crc; } -// Returns the CRC-32 checksum of the input buffer in network byte order (big endian). -uint32_t cx_crc32_hw_nbo(const uint8_t *bytes, size_t len) { -#if __BYTE_ORDER__ == __ORDER_BIG_ENDIAN__ - return cx_crc32(bytes, len); -#elif __BYTE_ORDER__ == __ORDER_LITTLE_ENDIAN__ - return os_swap_u32(cx_crc32(bytes, len)); -#else -#error "What kind of system is this?" -#endif -} - unsigned int bolos_ux_sskr_size_get(uint8_t bip39_onboarding_kind, uint8_t groups_threshold, unsigned int *group_descriptor, @@ -247,7 +245,7 @@ unsigned int bolos_ux_bip39_to_sskr_convert(unsigned char *bip39_words_buffer, memcpy(cbor_share_crc_buffer + cbor_len, share_buffer + share_len * share, share_len); - checksum = cx_crc32_hw_nbo(cbor_share_crc_buffer, cbor_len + share_len); + checksum = cx_crc32_nbo(cbor_share_crc_buffer, cbor_len + share_len); memcpy(cbor_share_crc_buffer + cbor_len + share_len, &checksum, checksum_len); if (bolos_ux_sskr_mnemonic_encode( @@ -281,8 +279,8 @@ unsigned int bolos_ux_sskr_hex_check(unsigned char *mnemonic_hex, uint8_t checksum_len = sizeof(checksum); for (unsigned int i = 0; i < sskr_shares_count; i++) { - checksum = cx_crc32_hw_nbo(mnemonic_hex + i * (mnemonic_length / sskr_shares_count), - (mnemonic_length / sskr_shares_count) - checksum_len); + checksum = cx_crc32_nbo(mnemonic_hex + i * (mnemonic_length / sskr_shares_count), + (mnemonic_length / sskr_shares_count) - checksum_len); // First 8 bytes of all shares in group should be same // Test checksum if ((os_secure_memcmp(cbor, mnemonic_hex + i * mnemonic_length / sskr_shares_count, 3) != diff --git a/tests/unit/CMakeLists.txt b/tests/unit/CMakeLists.txt index 4608c308..428f9339 100644 --- a/tests/unit/CMakeLists.txt +++ b/tests/unit/CMakeLists.txt @@ -6,7 +6,7 @@ endif() # project information project(unit_tests - VERSION 1.5.4 + VERSION 1.6.1 DESCRIPTION "Unit tests for app-seed-tool Ledger Application" LANGUAGES C) @@ -39,7 +39,7 @@ include(FetchContent) FetchContent_Declare( cmocka GIT_REPOSITORY https://git.cryptomilk.org/projects/cmocka.git - GIT_TAG cmocka-1.1.5 + GIT_TAG cmocka-1.1.7 GIT_SHALLOW 1 ) set(WITH_STATIC_LIB ON CACHE BOOL "CMocka: Build with a static library" FORCE) diff --git a/tests/unit/lib/testutils.c b/tests/unit/lib/testutils.c index d08f78f0..c96c526d 100644 --- a/tests/unit/lib/testutils.c +++ b/tests/unit/lib/testutils.c @@ -24,68 +24,3 @@ char os_secure_memcmp(const void *src1, const void *src2, size_t length) } return xoracc; } - -static unsigned int cx_ccitt32[] = { - 0x00000000, 0x77073096, 0xee0e612c, 0x990951ba, 0x076dc419, 0x706af48f, - 0xe963a535, 0x9e6495a3, 0x0edb8832, 0x79dcb8a4, 0xe0d5e91e, 0x97d2d988, - 0x09b64c2b, 0x7eb17cbd, 0xe7b82d07, 0x90bf1d91, 0x1db71064, 0x6ab020f2, - 0xf3b97148, 0x84be41de, 0x1adad47d, 0x6ddde4eb, 0xf4d4b551, 0x83d385c7, - 0x136c9856, 0x646ba8c0, 0xfd62f97a, 0x8a65c9ec, 0x14015c4f, 0x63066cd9, - 0xfa0f3d63, 0x8d080df5, 0x3b6e20c8, 0x4c69105e, 0xd56041e4, 0xa2677172, - 0x3c03e4d1, 0x4b04d447, 0xd20d85fd, 0xa50ab56b, 0x35b5a8fa, 0x42b2986c, - 0xdbbbc9d6, 0xacbcf940, 0x32d86ce3, 0x45df5c75, 0xdcd60dcf, 0xabd13d59, - 0x26d930ac, 0x51de003a, 0xc8d75180, 0xbfd06116, 0x21b4f4b5, 0x56b3c423, - 0xcfba9599, 0xb8bda50f, 0x2802b89e, 0x5f058808, 0xc60cd9b2, 0xb10be924, - 0x2f6f7c87, 0x58684c11, 0xc1611dab, 0xb6662d3d, 0x76dc4190, 0x01db7106, - 0x98d220bc, 0xefd5102a, 0x71b18589, 0x06b6b51f, 0x9fbfe4a5, 0xe8b8d433, - 0x7807c9a2, 0x0f00f934, 0x9609a88e, 0xe10e9818, 0x7f6a0dbb, 0x086d3d2d, - 0x91646c97, 0xe6635c01, 0x6b6b51f4, 0x1c6c6162, 0x856530d8, 0xf262004e, - 0x6c0695ed, 0x1b01a57b, 0x8208f4c1, 0xf50fc457, 0x65b0d9c6, 0x12b7e950, - 0x8bbeb8ea, 0xfcb9887c, 0x62dd1ddf, 0x15da2d49, 0x8cd37cf3, 0xfbd44c65, - 0x4db26158, 0x3ab551ce, 0xa3bc0074, 0xd4bb30e2, 0x4adfa541, 0x3dd895d7, - 0xa4d1c46d, 0xd3d6f4fb, 0x4369e96a, 0x346ed9fc, 0xad678846, 0xda60b8d0, - 0x44042d73, 0x33031de5, 0xaa0a4c5f, 0xdd0d7cc9, 0x5005713c, 0x270241aa, - 0xbe0b1010, 0xc90c2086, 0x5768b525, 0x206f85b3, 0xb966d409, 0xce61e49f, - 0x5edef90e, 0x29d9c998, 0xb0d09822, 0xc7d7a8b4, 0x59b33d17, 0x2eb40d81, - 0xb7bd5c3b, 0xc0ba6cad, 0xedb88320, 0x9abfb3b6, 0x03b6e20c, 0x74b1d29a, - 0xead54739, 0x9dd277af, 0x04db2615, 0x73dc1683, 0xe3630b12, 0x94643b84, - 0x0d6d6a3e, 0x7a6a5aa8, 0xe40ecf0b, 0x9309ff9d, 0x0a00ae27, 0x7d079eb1, - 0xf00f9344, 0x8708a3d2, 0x1e01f268, 0x6906c2fe, 0xf762575d, 0x806567cb, - 0x196c3671, 0x6e6b06e7, 0xfed41b76, 0x89d32be0, 0x10da7a5a, 0x67dd4acc, - 0xf9b9df6f, 0x8ebeeff9, 0x17b7be43, 0x60b08ed5, 0xd6d6a3e8, 0xa1d1937e, - 0x38d8c2c4, 0x4fdff252, 0xd1bb67f1, 0xa6bc5767, 0x3fb506dd, 0x48b2364b, - 0xd80d2bda, 0xaf0a1b4c, 0x36034af6, 0x41047a60, 0xdf60efc3, 0xa867df55, - 0x316e8eef, 0x4669be79, 0xcb61b38c, 0xbc66831a, 0x256fd2a0, 0x5268e236, - 0xcc0c7795, 0xbb0b4703, 0x220216b9, 0x5505262f, 0xc5ba3bbe, 0xb2bd0b28, - 0x2bb45a92, 0x5cb36a04, 0xc2d7ffa7, 0xb5d0cf31, 0x2cd99e8b, 0x5bdeae1d, - 0x9b64c2b0, 0xec63f226, 0x756aa39c, 0x026d930a, 0x9c0906a9, 0xeb0e363f, - 0x72076785, 0x05005713, 0x95bf4a82, 0xe2b87a14, 0x7bb12bae, 0x0cb61b38, - 0x92d28e9b, 0xe5d5be0d, 0x7cdcefb7, 0x0bdbdf21, 0x86d3d2d4, 0xf1d4e242, - 0x68ddb3f8, 0x1fda836e, 0x81be16cd, 0xf6b9265b, 0x6fb077e1, 0x18b74777, - 0x88085ae6, 0xff0f6a70, 0x66063bca, 0x11010b5c, 0x8f659eff, 0xf862ae69, - 0x616bffd3, 0x166ccf45, 0xa00ae278, 0xd70dd2ee, 0x4e048354, 0x3903b3c2, - 0xa7672661, 0xd06016f7, 0x4969474d, 0x3e6e77db, 0xaed16a4a, 0xd9d65adc, - 0x40df0b66, 0x37d83bf0, 0xa9bcae53, 0xdebb9ec5, 0x47b2cf7f, 0x30b5ffe9, - 0xbdbdf21c, 0xcabac28a, 0x53b39330, 0x24b4a3a6, 0xbad03605, 0xcdd70693, - 0x54de5729, 0x23d967bf, 0xb3667a2e, 0xc4614ab8, 0x5d681b02, 0x2a6f2b94, - 0xb40bbe37, 0xc30c8ea1, 0x5a05df1b, 0x2d02ef8d -}; - -unsigned int cx_crc32_update(unsigned int crc, const void *buf, size_t len) -{ - const uint8_t *p = buf; - size_t i; - - for (i = 0; i < len; i++) { - crc = cx_ccitt32[(crc ^ *p++) & 0xff] ^ (crc >> 8u); - } - - return crc ^ 0xFFFFFFFF; -} - -uint32_t cx_crc32_hw(const void *buf, size_t len) -{ - uint32_t crc; - crc = cx_crc32_update(0xFFFFFFFF, buf, len); - return crc; -} diff --git a/tests/unit/tests/roundtrip.c b/tests/unit/tests/roundtrip.c index a4ea9d91..8e74e4c9 100644 --- a/tests/unit/tests/roundtrip.c +++ b/tests/unit/tests/roundtrip.c @@ -119,7 +119,7 @@ static void test_bip39_to_sskr(void **state) { &sskr_words_buffer_len), 1); assert_int_equal(share_count, sskr_group_descriptor[1]); assert_int_equal(sskr_words_buffer_len, sizeof(sskr_shares) - 1); - assert_string_equal(sskr_words_buffer, sskr_shares); + assert_string_equal((const char *) sskr_words_buffer, (const char *) sskr_shares); } static void test_sskr_to_bip39(void **state) { diff --git a/tests/unit/tests/words.c b/tests/unit/tests/words.c index b245fcff..a9938332 100644 --- a/tests/unit/tests/words.c +++ b/tests/unit/tests/words.c @@ -20,14 +20,14 @@ static void test_words_bip39(void **state) { return_num = bolos_ux_bip39_idx_strcpy(return_num, buffer); assert_int_equal(return_num, 7); - assert_string_equal(buffer, "abandon"); + assert_string_equal((const char *) buffer, "abandon"); return_num = bolos_ux_bip39_get_word_count_starting_with((const unsigned char *) prefix, 2); assert_int_equal(return_num, 10); return_num = bolos_ux_bip39_get_word_next_letters_starting_with((const unsigned char *) prefix, 2, next_letters); assert_int_equal(return_num, 6); - assert_string_equal(next_letters, "ailosu"); + assert_string_equal((const char *) next_letters, "ailosu"); prefix[0] = 'z'; memset(next_letters,0,sizeof(next_letters)); @@ -37,14 +37,14 @@ static void test_words_bip39(void **state) { return_num = bolos_ux_bip39_idx_strcpy(return_num, buffer); assert_int_equal(return_num, 5); - assert_string_equal(buffer, "zebra"); + assert_string_equal((const char *) buffer, "zebra"); return_num = bolos_ux_bip39_get_word_count_starting_with((const unsigned char *) prefix, 1); assert_int_equal(return_num, 4); return_num = bolos_ux_bip39_get_word_next_letters_starting_with((const unsigned char *) prefix, 1, next_letters); assert_int_equal(return_num, 2); - assert_string_equal(next_letters, "eo"); + assert_string_equal((const char *) next_letters, "eo"); } static void test_words_sskr(void **state) { @@ -58,14 +58,14 @@ static void test_words_sskr(void **state) { return_num = bolos_ux_sskr_idx_strcpy(return_num, buffer); assert_int_equal(return_num, 4); - assert_string_equal(buffer, "able"); + assert_string_equal((const char *) buffer, "able"); return_num = bolos_ux_sskr_get_word_count_starting_with((const unsigned char *) prefix, 2); assert_int_equal(return_num, 1); return_num = bolos_ux_sskr_get_word_next_letters_starting_with((const unsigned char *) prefix, 2, next_letters); assert_int_equal(return_num, 1); - assert_string_equal(next_letters, "l"); + assert_string_equal((const char *) next_letters, "l"); prefix[0] = 'z'; memset(next_letters,0,sizeof(next_letters)); @@ -75,14 +75,14 @@ static void test_words_sskr(void **state) { return_num = bolos_ux_sskr_idx_strcpy(return_num, buffer); assert_int_equal(return_num, 4); - assert_string_equal(buffer, "zaps"); + assert_string_equal((const char *) buffer, "zaps"); return_num = bolos_ux_sskr_get_word_count_starting_with((const unsigned char *) prefix, 1); assert_int_equal(return_num, 6); return_num = bolos_ux_sskr_get_word_next_letters_starting_with((const unsigned char *) prefix, 1, next_letters); assert_int_equal(return_num, 4); - assert_string_equal(next_letters, "aeio"); + assert_string_equal((const char *) next_letters, "aeio"); } int main(void) {