[EXTERNAL] [PATCH v7] examples: add Wycheproof validation app

Akhil Goyal gakhil at marvell.com
Thu Sep 24 20:00:13 CEST 2026


> Wycheproof differs somewhat from the existing cryptodev test vectors in that it is
> an externally maintained collection of JSON test suites covering a large number of
> edge cases and negative tests. The intended usage model is to load the upstream
> vector files at runtime rather than embedding them in the DPDK tree.
> I think the existing examples/fips_validation application follows a similar
> approach, consuming external CAVP/ACVP vector files rather than integrating
> them into dpdk-test. This patch follows that precedent, with the goal of providing
> file-driven conformance validation as a standalone example application.
> I agree that the documentation can be improved. At minimum, the .rst should
> describe where the Wycheproof vectors can be obtained and reference the
> applicable upstream license, as the current example command may give the
> impression that the vector files are included in the DPDK source tree when they
> are not.

Ok, so in that case did you consider integrating this app into fips_validation app..
May be we could rename fips_validation to crypto_validation and internally have 2 modes - 
Fips and Wycheproof? Like what we have for examples/multi_process?


> 
> From: Akhil Goyal <gakhil at marvell.com>
> Sent: Thursday, September 24, 2026 15:35
> To: Ji, Kai <kai.ji at intel.com>; dev at dpdk.org <dev at dpdk.org>
> Cc: Thomas Monjalon <thomas at monjalon.net>
> Subject: RE: [EXTERNAL] [PATCH v7] examples: add Wycheproof validation app
> 
> > Add a Wycheproof JSON vector validation example for cryptodev PMDs.
> >
> > Support these algorithms when advertised by the selected PMD:
> > - AEAD: AES-GCM, AES-CCM, SM4-GCM, ChaCha20-Poly1305
> > - MAC: AES-CMAC, AES-GMAC, HMAC SHA-1/SHA-2/SHA-3/SM3
> > - Asymmetric: DSA (P1363 verify), ECDSA (P1363 verify),
> >   ECDH (ecpoint shared-secret compute)
> >
> > Validate valid vectors against generated ciphertexts, tags, plaintexts,
> > digests, shared secrets, or signature verification, and require the
> > expected rejection for invalid vectors. Digest inputs for DSA and ECDSA
> > use the symmetric auth path, selecting a separate symmetric-capable
> > device when the target device is asymmetric-only.
> >
> > Skip parameter combinations outside PMD capability ranges and identify
> > recognized vector families without a compatible DPDK transform. A
> > --debug option lists every failed or skipped vector.
> >
> > Add Meson and standalone build integration, with usage documentation.
> >
> > Signed-off-by: Kai Ji <kai.ji at intel.com>
> > ---
> >  MAINTAINERS                                   |    5 +
> >  doc/guides/rel_notes/release_26_11.rst        |    6 +
> >  doc/guides/sample_app_ug/index.rst            |    1 +
> >  .../sample_app_ug/wycheproof_validation.rst   |   50 +
> >  examples/meson.build                          |    1 +
> >  examples/wycheproof_validation/Makefile       |   40 +
> >  examples/wycheproof_validation/main.c         | 2090 +++++++++++++++++
> >  examples/wycheproof_validation/meson.build    |   17 +
> >  8 files changed, 2210 insertions(+)
> >  create mode 100644 doc/guides/sample_app_ug/wycheproof_validation.rst
> >  create mode 100644 examples/wycheproof_validation/Makefile
> >  create mode 100644 examples/wycheproof_validation/main.c
> >  create mode 100644 examples/wycheproof_validation/meson.build
> >
> > diff --git a/MAINTAINERS b/MAINTAINERS
> > index 186cc82b39..580e2c2591 100644
> > --- a/MAINTAINERS
> > +++ b/MAINTAINERS
> > @@ -2099,3 +2099,8 @@ F: examples/vmdq/
> >  F: doc/guides/sample_app_ug/vmdq_forwarding.rst
> >  F: examples/vmdq_dcb/
> >  F: doc/guides/sample_app_ug/vmdq_dcb_forwarding.rst
> > +
> > +Wycheproof validation example
> > +M: Kai Ji <kai.ji at intel.com>
> > +F: examples/wycheproof_validation/
> > +F: doc/guides/sample_app_ug/wycheproof_validation.rst
> > diff --git a/doc/guides/rel_notes/release_26_11.rst
> > b/doc/guides/rel_notes/release_26_11.rst
> > index dec96ccbc7..cd2711ddad 100644
> > --- a/doc/guides/rel_notes/release_26_11.rst
> > +++ b/doc/guides/rel_notes/release_26_11.rst
> > @@ -133,6 +133,12 @@ New Features
> >      with per-descriptor mbuf free (``rte_pktmbuf_free_seg``) and prefetch hints.
> >    * Changed the set of per-queue xstats counters.
> >
> > +* **Added Wycheproof validation example application.**
> > +
> > +  Added a new example application that validates a DPDK cryptodev PMD
> against
> > +  the Google Wycheproof JSON test vectors, covering AEAD, MAC, DSA, ECDH
> > and
> > +  ECDSA algorithm families.
> > +
> >
> >  Removed Items
> >  -------------
> > diff --git a/doc/guides/sample_app_ug/index.rst
> > b/doc/guides/sample_app_ug/index.rst
> > index 28c4c9a5b2..2458b06ccd 100644
> > --- a/doc/guides/sample_app_ug/index.rst
> > +++ b/doc/guides/sample_app_ug/index.rst
> > @@ -51,6 +51,7 @@ Sample Applications User Guides
> >      ptpclient
> >      ptp_tap_relay_sw
> >      fips_validation
> > +    wycheproof_validation
> >      ipsec_secgw
> >      bbdev_app
> >      ntb
> > diff --git a/doc/guides/sample_app_ug/wycheproof_validation.rst
> > b/doc/guides/sample_app_ug/wycheproof_validation.rst
> > new file mode 100644
> > index 0000000000..17c8bd2b55
> > --- /dev/null
> > +++ b/doc/guides/sample_app_ug/wycheproof_validation.rst
> > @@ -0,0 +1,50 @@
> > +..  SPDX-License-Identifier: BSD-3-Clause
> > +    Copyright(c) 2026 Intel Corporation.
> > +
> > +Wycheproof Validation Example
> > +=============================
> > +
> > +Overview
> > +--------
> > +
> > +This example validates a DPDK cryptodev implementation against the Google
> > +Wycheproof JSON test vectors.
> > +
> > +The application reads one JSON file or a directory of JSON files at runtime and
> > +checks the supported algorithm families against the selected PMD. It can be
> > used
> > +with a PMD that advertises AEAD, MAC, DSA, ECDH, or ECDSA support.
> > +
> > +Build
> > +-----
> > +
> > +Build the example from the DPDK tree with Meson:
> > +
> > +.. code-block:: console
> > +
> > +   meson setup build -Dexamples=wycheproof_validation -
> > Denable_drivers=crypto/openssl
> > +   meson compile -C build
> > +
> > +Standalone Makefile builds are also supported from the example directory.
> > +
> > +Run
> > +---
> > +
> > +Run the example with an OpenSSL-backed cryptodev and a vector file:
> > +
> > +.. code-block:: console
> > +
> > +   ./build/examples/dpdk-wycheproof_validation --vdev crypto_openssl -- \
> > +       --vectors ../wycheproof/testvectors_v1/aes_gcm_test.json \
> > +       --cryptodev crypto_openssl --debug
> > +
> 
> Why do we need a new application to perform test vector validation?
> Is dpdk-test crypto tests not enough?
> Can we integrate this in that?
> 
> And I do not see the .json file mentioned above in the patch.
> There should be a sample file atleast.
> 



More information about the dev mailing list