valord577
3bf4af0838
add ChangeLog
...
Signed-off-by: valord577 <valord577@gmail.com >
2026-04-22 11:09:21 +08:00
valord577
fb43ea9278
Fix build warning/error using llvm-mingw
...
error logs refs: https://github.com/valord577/nativepkgs/actions/runs/24490614774/job/71574726128
Signed-off-by: valord577 <valord577@gmail.com >
2026-04-22 11:09:16 +08:00
Gilles Peskine
e589739db1
Merge pull request #10685 from gilles-peskine-arm/maintainer-scripts-create-directory-4.1
...
Backport 4.1: Create a directory for maintainer-only Python scripts
2026-04-15 08:19:31 +00:00
Gilles Peskine
b116c4deff
Merge pull request #10688 from gilles-peskine-arm/analyze_outcomes-read_crypto-4.1
...
Backport 4.1: Let TF-PSA-Crypto define test cases that Mbed TLS does not need to cover
2026-04-13 09:24:12 +00:00
Gilles Peskine
635d64362f
Update crypto submodule with analyze_outcomes.py
...
Update framework to match.
Signed-off-by: Gilles Peskine <Gilles.Peskine@arm.com >
2026-04-10 14:48:05 +02:00
Gilles Peskine
a4144255f1
Documentation improvements
...
Signed-off-by: Gilles Peskine <Gilles.Peskine@arm.com >
2026-04-10 14:43:46 +02:00
Gilles Peskine
eeb2e3379f
INTERNAL_TEST_CASES moved to a separate data-only module
...
This way, when Mbed TLS's `analyze_outcomes.py` loads the python module from
TF-PSA-Crypto (because it needs to know the value of `INTERNAL_TEST_CASES`),
there's no risk that the subproject and the superproject will have different
requirements on auxiliary modules such as `mbedtls_framework.outcome_analysis`.
Signed-off-by: Gilles Peskine <Gilles.Peskine@arm.com >
2026-04-10 14:43:46 +02:00
Gilles Peskine
824b4cde5a
Add copyright line
...
Signed-off-by: Gilles Peskine <Gilles.Peskine@arm.com >
2026-04-10 14:43:46 +02:00
Gilles Peskine
7f78af02c4
Move test currently covered by crypto from uncovered list to ignored list
...
If we can't read `INTERNAL_TEST_CASES` from
`tf-psa-crypto/tests/scripts/analyze_outcomes.py` because the script doesn't
exist, hard-code the legacy value of that information.
Signed-off-by: Gilles Peskine <Gilles.Peskine@arm.com >
2026-04-10 14:43:46 +02:00
Gilles Peskine
ef7ff7e7fd
Ignore test cases that TF-PSA-Crypto tells us to ignore
...
If the `tf-psa-crypto` submodule has `tests/scripts/analyze_outcomes.py`,
require it to define a global variable `INTERNAL_TEST_CASES`. Those test
cases will be ignored in Mbed TLS's coverage analysis.
Signed-off-by: Gilles Peskine <Gilles.Peskine@arm.com >
2026-04-10 14:43:46 +02:00
Gilles Peskine
f1d880203c
Move _has_word_re to the framework
...
Signed-off-by: Gilles Peskine <Gilles.Peskine@arm.com >
2026-04-10 14:43:46 +02:00
Gilles Peskine
3233f2523c
Rename IGNORED_TESTS to UNCOVERED_TESTS
...
Signed-off-by: Gilles Peskine <Gilles.Peskine@arm.com >
2026-04-10 14:43:46 +02:00
Gilles Peskine
2b4ceb533b
Update framework with UNCOVERED_TESTS in outcome analysis
...
Signed-off-by: Gilles Peskine <Gilles.Peskine@arm.com >
2026-04-10 14:43:46 +02:00
Gilles Peskine
16541a9a42
Create a directory for maintainer-only Python scripts
...
This directory is currently excluded from `check-python-files.sh`, because
we run it on the CI in an old Python version that doesn't support some of
our new maintainer scripts.
There are no such scripts in mbedtls for now (only in TF-PSA-Crypto), but be
ready if we want to add some.
Signed-off-by: Gilles Peskine <Gilles.Peskine@arm.com >
2026-04-09 19:39:20 +02:00
minosgalanakis
421f5d27fe
Merge pull request #1548 from minosgalanakis/public-mbedtls-4.1
...
Merge public changes into internal LTS 4.1 branch
2026-04-02 22:40:53 +01:00
David Horstmann
521d2eb1fe
Merge pull request #10669 from gilles-peskine-arm/security-md-mention-compiler-4.1
...
Backport 4.1: Mention compiler optimization in the threat model
2026-04-01 15:46:13 +00:00
Gilles Peskine
b43bdd7365
Be more specific about what compiler options we consider legitimate
...
Signed-off-by: Gilles Peskine <Gilles.Peskine@arm.com >
2026-04-01 11:08:23 +02:00
Gilles Peskine
77a32fab9b
Mention the new advice about compiler options in the changelog
...
Signed-off-by: Gilles Peskine <Gilles.Peskine@arm.com >
2026-04-01 11:08:23 +02:00
Gilles Peskine
582d23e04c
Add a section about compiler-introduced timing side channels
...
Signed-off-by: Gilles Peskine <Gilles.Peskine@arm.com >
2026-04-01 11:08:23 +02:00
Minos Galanakis
0cfd96499d
Updated tf-psa-crypto submodule
...
Signed-off-by: Minos Galanakis <minos.galanakis@arm.com >
2026-03-31 15:36:07 +01:00
Minos Galanakis
6804c92d7d
Merge tag 'mbedtls-4.1.0' into mbedtls-4.1.0_mergeback
...
Mbed TLS 4.1.0
Signed-off-by: Minos Galanakis <minos.galanakis@arm.com >
2026-03-31 15:35:49 +01:00
Valerio Setti
32a3d5209c
Merge pull request #10626 from gilles-peskine-arm/check_committed_generated_files-create
...
Add check_committed_generated_files.py
2026-03-30 10:50:04 +00:00
Minos Galanakis
0fe989b6b5
Update BRANCHES.md
...
Signed-off-by: Minos Galanakis <minos.galanakis@arm.com >
mbedtls-4.1.0
v4.1.0
2026-03-26 22:34:42 +00:00
Minos Galanakis
641fa2695c
Assemble ChangeLog
...
./framework/scripts/assemble_changelog.py
Signed-off-by: Minos Galanakis <minos.galanakis@arm.com >
2026-03-26 22:34:42 +00:00
Minos Galanakis
e89565f92a
Bump version
...
./scripts/bump_version.sh --version 4.1.0 \
--so-crypto 18 --so-tls 23 --so-x509 9
Signed-off-by: Minos Galanakis <minos.galanakis@arm.com >
2026-03-26 22:34:28 +00:00
Minos Galanakis
83d1ebc114
Updated tf psa-crypto submodule
...
Signed-off-by: Minos Galanakis <minos.galanakis@arm.com >
2026-03-26 22:20:06 +00:00
Minos Galanakis
43b89543ec
Updated framework submodule
...
Signed-off-by: Minos Galanakis <minos.galanakis@arm.com >
2026-03-26 22:20:01 +00:00
Minos Galanakis
308e7fb232
Merge remote-tracking branch 'restricted/development-restricted' into mbedtls-4.1.0.rc3
...
Signed-off-by: Minos Galanakis <minos.galanakis@arm.com >
2026-03-26 22:18:31 +00:00
minosgalanakis
fc317141fe
Merge pull request #1534 from Mbed-TLS/release/changelog_fixes_4.1.0
...
[Release] Added attributions & CVE to ChangeLogs
2026-03-26 17:38:50 +00:00
Minos Galanakis
feb0dd04ba
Extended attributions & CVE
...
Signed-off-by: Minos Galanakis <minos.galanakis@arm.com >
2026-03-26 15:03:07 +00:00
Minos Galanakis
f3f27070a6
Added attributions & CVE
...
Signed-off-by: Minos Galanakis <minos.galanakis@arm.com >
2026-03-26 11:22:00 +00:00
minosgalanakis
5baf6883c6
Merge pull request #1529 from ronald-cron-arm/dtls
...
Fixes relative to DTLS invalid/unexpected first record
2026-03-25 22:31:24 +00:00
Ronald Cron
1330606ca1
dtls: Fix adaptation to first ClientHello
...
For each received ClientHello fragment, check
that its epoch is zero and update the
record-level sequence number.
Signed-off-by: Ronald Cron <ronald.cron@arm.com >
2026-03-25 08:45:24 +01:00
Ronald Cron
7a8fbc2100
Remove debug leftover
...
Signed-off-by: Ronald Cron <ronald.cron@arm.com >
2026-03-25 08:45:24 +01:00
Ronald Cron
1141cd0fb6
Improve comments
...
Signed-off-by: Ronald Cron <ronald.cron@arm.com >
2026-03-25 08:45:24 +01:00
Ronald Cron
f2f44a9c9f
Restrict mapping of UNEXPECTED_RECORD to UNEXPECTED_MESSAGE
...
Signed-off-by: Ronald Cron <ronald.cron@arm.com >
2026-03-25 08:45:24 +01:00
Ronald Cron
fbe388dc28
ssl-opt.sh: Fix log checks in some "DTLS reassembly" tests
...
In DTLS reassembly tests, the server may receive a close_notify alert at the
end of a test. In this case, the Mbed TLS server logs an error, so these tests
should not check for the absence of the string "error" in the server logs.
Signed-off-by: Ronald Cron <ronald.cron@arm.com >
2026-03-25 08:45:24 +01:00
Ronald Cron
f285018fa3
Disable "DTLS proxy: 3d, (openssl|gnutls) client, fragmentation" tests
...
The tests fail intermittently on the CI with a frequency that
significantly impacts CI throughput.
Signed-off-by: Ronald Cron <ronald.cron@arm.com >
2026-03-25 08:45:22 +01:00
Ronald Cron
c9264ad227
dtls: Fix log level
...
Signed-off-by: Ronald Cron <ronald.cron@arm.com >
2026-03-25 08:44:16 +01:00
Ronald Cron
140ebea442
dtls: parse_client_hello: Adapt mbedtls_ssl_read_record() error code
...
Signed-off-by: Ronald Cron <ronald.cron@arm.com >
2026-03-25 08:44:16 +01:00
Ronald Cron
f9b7441542
dtls: Keep invalid/unexpected record header error code
...
Signed-off-by: Ronald Cron <ronald.cron@arm.com >
2026-03-25 08:44:16 +01:00
Ronald Cron
0c301a686a
dtls: Improve comment
...
Signed-off-by: Ronald Cron <ronald.cron@arm.com >
2026-03-25 08:44:16 +01:00
Ronald Cron
912ef74195
Update buffering when adapting to ClientHello message_seq
...
Signed-off-by: Ronald Cron <ronald.cron@arm.com >
2026-03-25 08:44:16 +01:00
Ronald Cron
16c5dd99b3
Introduce ssl_buffering_shift_slots
...
Signed-off-by: Ronald Cron <ronald.cron@arm.com >
2026-03-25 08:44:16 +01:00
Ronald Cron
676d74e4c7
dtls: Error out on invalid/unexpected record header
...
Error out on invalid/unexpected record header
when reading the DTLS 1.2 ClientHello.
Signed-off-by: Ronald Cron <ronald.cron@arm.com >
2026-03-25 08:44:16 +01:00
Ronald Cron
315c970fbe
dtls: Fix debug log
...
Signed-off-by: Ronald Cron <ronald.cron@arm.com >
2026-03-25 08:44:16 +01:00
Ronald Cron
ade56554a6
Revert "ssl_server2.c: DTLS: Attempt to read the response to the close notification"
...
This reverts commit 2e9b9681e6 .
Signed-off-by: Ronald Cron <ronald.cron@arm.com >
2026-03-24 18:38:37 +01:00
Valerio Setti
63d1f7f6ef
Merge pull request #10649 from valeriosetti/skip-thread-cmake-search
...
cmake: make Thread package search quiet
2026-03-23 23:34:05 +00:00
Valerio Setti
92cfa4e70e
cmake: make Threads package search quiet
...
This prevents printing message
"-- Could NOT find Threads (missing: Threads_FOUND)"
on platforms like Zephyr where threading is not provided by standard
libraries.
Signed-off-by: Valerio Setti <valerio.setti@nordicsemi.no >
2026-03-23 15:43:46 +01:00
Gilles Peskine
aa40ca90d9
Move check_committed_generated_files to its own component
...
This will probably help when a framework change causes the content of these
files to change. See https://github.com/Mbed-TLS/mbedtls-test/issues/252
Signed-off-by: Gilles Peskine <Gilles.Peskine@arm.com >
2026-03-23 15:38:32 +01:00