> Wycheproof differs somewhat from the existing cryptodev test vectors in that > it is > an externally maintained collection of JSON test suites covering a large > number of > edge cases and negative tests. The intended usage model is to load the > upstream > vector files at runtime rather than embedding them in the DPDK tree. > I think the existing examples/fips_validation application follows a similar > approach, consuming external CAVP/ACVP vector files rather than integrating > them into dpdk-test. This patch follows that precedent, with the goal of > providing > file-driven conformance validation as a standalone example application. > I agree that the documentation can be improved. At minimum, the .rst should > describe where the Wycheproof vectors can be obtained and reference the > applicable upstream license, as the current example command may give the > impression that the vector files are included in the DPDK source tree when > they > are not.
Ok, so in that case did you consider integrating this app into fips_validation app.. May be we could rename fips_validation to crypto_validation and internally have 2 modes - Fips and Wycheproof? Like what we have for examples/multi_process? > > From: Akhil Goyal <[email protected]> > Sent: Thursday, September 24, 2026 15:35 > To: Ji, Kai <[email protected]>; [email protected] <[email protected]> > Cc: Thomas Monjalon <[email protected]> > Subject: RE: [EXTERNAL] [PATCH v7] examples: add Wycheproof validation app > > > Add a Wycheproof JSON vector validation example for cryptodev PMDs. > > > > Support these algorithms when advertised by the selected PMD: > > - AEAD: AES-GCM, AES-CCM, SM4-GCM, ChaCha20-Poly1305 > > - MAC: AES-CMAC, AES-GMAC, HMAC SHA-1/SHA-2/SHA-3/SM3 > > - Asymmetric: DSA (P1363 verify), ECDSA (P1363 verify), > > ECDH (ecpoint shared-secret compute) > > > > Validate valid vectors against generated ciphertexts, tags, plaintexts, > > digests, shared secrets, or signature verification, and require the > > expected rejection for invalid vectors. Digest inputs for DSA and ECDSA > > use the symmetric auth path, selecting a separate symmetric-capable > > device when the target device is asymmetric-only. > > > > Skip parameter combinations outside PMD capability ranges and identify > > recognized vector families without a compatible DPDK transform. A > > --debug option lists every failed or skipped vector. > > > > Add Meson and standalone build integration, with usage documentation. > > > > Signed-off-by: Kai Ji <[email protected]> > > --- > > MAINTAINERS | 5 + > > doc/guides/rel_notes/release_26_11.rst | 6 + > > doc/guides/sample_app_ug/index.rst | 1 + > > .../sample_app_ug/wycheproof_validation.rst | 50 + > > examples/meson.build | 1 + > > examples/wycheproof_validation/Makefile | 40 + > > examples/wycheproof_validation/main.c | 2090 +++++++++++++++++ > > examples/wycheproof_validation/meson.build | 17 + > > 8 files changed, 2210 insertions(+) > > create mode 100644 doc/guides/sample_app_ug/wycheproof_validation.rst > > create mode 100644 examples/wycheproof_validation/Makefile > > create mode 100644 examples/wycheproof_validation/main.c > > create mode 100644 examples/wycheproof_validation/meson.build > > > > diff --git a/MAINTAINERS b/MAINTAINERS > > index 186cc82b39..580e2c2591 100644 > > --- a/MAINTAINERS > > +++ b/MAINTAINERS > > @@ -2099,3 +2099,8 @@ F: examples/vmdq/ > > F: doc/guides/sample_app_ug/vmdq_forwarding.rst > > F: examples/vmdq_dcb/ > > F: doc/guides/sample_app_ug/vmdq_dcb_forwarding.rst > > + > > +Wycheproof validation example > > +M: Kai Ji <[email protected]> > > +F: examples/wycheproof_validation/ > > +F: doc/guides/sample_app_ug/wycheproof_validation.rst > > diff --git a/doc/guides/rel_notes/release_26_11.rst > > b/doc/guides/rel_notes/release_26_11.rst > > index dec96ccbc7..cd2711ddad 100644 > > --- a/doc/guides/rel_notes/release_26_11.rst > > +++ b/doc/guides/rel_notes/release_26_11.rst > > @@ -133,6 +133,12 @@ New Features > > with per-descriptor mbuf free (``rte_pktmbuf_free_seg``) and prefetch > > hints. > > * Changed the set of per-queue xstats counters. > > > > +* **Added Wycheproof validation example application.** > > + > > + Added a new example application that validates a DPDK cryptodev PMD > against > > + the Google Wycheproof JSON test vectors, covering AEAD, MAC, DSA, ECDH > > and > > + ECDSA algorithm families. > > + > > > > Removed Items > > ------------- > > diff --git a/doc/guides/sample_app_ug/index.rst > > b/doc/guides/sample_app_ug/index.rst > > index 28c4c9a5b2..2458b06ccd 100644 > > --- a/doc/guides/sample_app_ug/index.rst > > +++ b/doc/guides/sample_app_ug/index.rst > > @@ -51,6 +51,7 @@ Sample Applications User Guides > > ptpclient > > ptp_tap_relay_sw > > fips_validation > > + wycheproof_validation > > ipsec_secgw > > bbdev_app > > ntb > > diff --git a/doc/guides/sample_app_ug/wycheproof_validation.rst > > b/doc/guides/sample_app_ug/wycheproof_validation.rst > > new file mode 100644 > > index 0000000000..17c8bd2b55 > > --- /dev/null > > +++ b/doc/guides/sample_app_ug/wycheproof_validation.rst > > @@ -0,0 +1,50 @@ > > +.. SPDX-License-Identifier: BSD-3-Clause > > + Copyright(c) 2026 Intel Corporation. > > + > > +Wycheproof Validation Example > > +============================= > > + > > +Overview > > +-------- > > + > > +This example validates a DPDK cryptodev implementation against the Google > > +Wycheproof JSON test vectors. > > + > > +The application reads one JSON file or a directory of JSON files at > > runtime and > > +checks the supported algorithm families against the selected PMD. It can be > > used > > +with a PMD that advertises AEAD, MAC, DSA, ECDH, or ECDSA support. > > + > > +Build > > +----- > > + > > +Build the example from the DPDK tree with Meson: > > + > > +.. code-block:: console > > + > > + meson setup build -Dexamples=wycheproof_validation - > > Denable_drivers=crypto/openssl > > + meson compile -C build > > + > > +Standalone Makefile builds are also supported from the example directory. > > + > > +Run > > +--- > > + > > +Run the example with an OpenSSL-backed cryptodev and a vector file: > > + > > +.. code-block:: console > > + > > + ./build/examples/dpdk-wycheproof_validation --vdev crypto_openssl -- \ > > + --vectors ../wycheproof/testvectors_v1/aes_gcm_test.json \ > > + --cryptodev crypto_openssl --debug > > + > > Why do we need a new application to perform test vector validation? > Is dpdk-test crypto tests not enough? > Can we integrate this in that? > > And I do not see the .json file mentioned above in the patch. > There should be a sample file atleast. >

