Skip to content

Add support for wolfHAL crypto backend - #11033

Open
AlexLanzano wants to merge 1 commit into
wolfSSL:masterfrom
AlexLanzano:wolfHAL-integration
Open

Add support for wolfHAL crypto backend#11033
AlexLanzano wants to merge 1 commit into
wolfSSL:masterfrom
AlexLanzano:wolfHAL-integration

Conversation

@AlexLanzano

Copy link
Copy Markdown
Member

No description provided.

Copilot AI review requested due to automatic review settings August 2, 2026 21:47

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR adds a new wolfCrypt hardware-acceleration port that routes selected crypto operations through the wolfHAL driver stack via the wolfSSL crypto-callback framework, plus the autotools plumbing to build it.

Changes:

  • Adds a new wolfHAL port implementation (wolfhal.c/.h) with crypto-callback dispatch for AES (ECB/CBC/GCM/CCM) and optional RNG support.
  • Introduces wolfhal_settings.h and wires it into settings.h early to enable WOLF_CRYPTO_CB and map WC_USE_DEVID for wolfHAL builds.
  • Extends autotools build/configure flow (configure.ac, include.am) to enable the port via --with-wolfhal / --with-wolfhal-board, and to register the device during wolfCrypt_Init().

Reviewed changes

Copilot reviewed 9 out of 9 changed files in this pull request and generated 1 comment.

Show a summary per file
File Description
wolfssl/wolfcrypt/settings.h Includes wolfHAL macro-only settings early during configuration.
wolfssl/wolfcrypt/port/wolfHAL/wolfhal.h Public port header exposing register/unregister and optional RNG entrypoint.
wolfssl/wolfcrypt/port/wolfHAL/wolfhal_settings.h Macro-only configuration enabling crypto callback + devId mapping.
wolfssl/wolfcrypt/include.am Adds wolfHAL headers to autotools header lists and conditional installs.
wolfcrypt/src/wc_port.c Registers the wolfHAL crypto-callback device during wolfCrypt_Init().
wolfcrypt/src/port/wolfHAL/wolfhal.c Implements crypto callback dispatch to wolfHAL AES + RNG APIs.
wolfcrypt/src/port/wolfHAL/README.md Documents build flags, board.h contract, and runtime initialization order.
wolfcrypt/src/include.am Adds wolfHAL source/README to autotools distribution and conditional build sources.
configure.ac Adds --with-wolfhal / --with-wolfhal-board configuration and build conditionals.
Suppressed comments (1)

configure.ac:3683

  • The board include path is appended without quoting, so --with-wolfhal-board paths containing spaces will be split into multiple compiler arguments and fail to find board.h.
    AM_CFLAGS="$AM_CFLAGS -I$ENABLED_WOLFHAL_BOARD"

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread configure.ac Outdated
@AlexLanzano
AlexLanzano force-pushed the wolfHAL-integration branch from 55a7d1f to e921fb5 Compare August 3, 2026 17:18

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 9 out of 9 changed files in this pull request and generated no new comments.

Suppressed comments (3)

wolfssl/wolfcrypt/port/wolfHAL/wolfhal.h:84

  • Prototype for wc_wolfHAL_GenerateBlock() uses plain C types, but the implementation uses wolfCrypt types (byte*, word32). On some platforms word32 is unsigned long (not unsigned int), so this mismatch can cause warnings or ABI issues. Match the public prototype to the definition and wolfCrypt conventions (also aligns with wc_RNG_GenerateBlock()).
/* Generate a block of random data using the wolfHAL RNG device.
 * Suitable for use as CUSTOM_RAND_GENERATE_BLOCK. */
WOLFSSL_API int wc_wolfHAL_GenerateBlock(unsigned char* output,
                                          unsigned int sz);

wolfssl/wolfcrypt/port/wolfHAL/wolfhal_settings.h:30

  • This comment says WOLFSSL_WOLFHAL "must be defined in user_settings.h", but this PR also enables it via configure.ac (AM_CFLAGS += -DWOLFSSL_WOLFHAL). Update the wording so it doesn’t incorrectly imply user_settings.h is required (it can be set by build flags too).
/* Compile time configuration for the wolfHAL port. This header holds only
 * preprocessor macros and pulls in no wolfHAL or BSP headers, so wolfSSL
 * settings.h can include it to map WC_USE_DEVID before the unmodified
 * wolfcrypt test and benchmark read it.
 *
 * WOLFSSL_WOLFHAL enables the port and must be defined in user_settings.h.
 * Which AES modes are offloaded follows the usual wolfCrypt feature gates
 * (HAVE_AES_CBC, HAVE_AESGCM, HAVE_AESCCM, HAVE_AES_ECB); the callback
 * returns CRYPTOCB_UNAVAILABLE for anything else and wolfCrypt falls back to

configure.ac:3629

  • The configure.ac example uses --with-wolfhal-board=stm32wb_nucleo, but the option is documented/validated as a directory PATH containing board.h. Using a concrete path example (like the README does) would prevent confusion and reduce misconfiguration reports.
# wolfHAL hardware abstraction layer crypto-callback port.
# Include-path only: wolfHAL builds no archive (its drivers compile per-board),
# so the application compiles and links wolfHAL itself.
# Example:
#   "./configure --with-wolfhal=../wolfHAL --with-wolfhal-board=stm32wb_nucleo"
ENABLED_WOLFHAL="no"

@AlexLanzano
AlexLanzano marked this pull request as ready for review August 3, 2026 17:59
@github-actions

github-actions Bot commented Aug 3, 2026

Copy link
Copy Markdown

retest this please

@AlexLanzano

Copy link
Copy Markdown
Member Author

retest this please

@AlexLanzano AlexLanzano self-assigned this Aug 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants