[EXTERNAL] [PATCH v7] examples: add Wycheproof validation app
Akhil Goyal
gakhil at marvell.com
Thu Sep 24 20:00:13 CEST 2026
> Wycheproof differs somewhat from the existing cryptodev test vectors in that it is
> an externally maintained collection of JSON test suites covering a large number of
> edge cases and negative tests. The intended usage model is to load the upstream
> vector files at runtime rather than embedding them in the DPDK tree.
> I think the existing examples/fips_validation application follows a similar
> approach, consuming external CAVP/ACVP vector files rather than integrating
> them into dpdk-test. This patch follows that precedent, with the goal of providing
> file-driven conformance validation as a standalone example application.
> I agree that the documentation can be improved. At minimum, the .rst should
> describe where the Wycheproof vectors can be obtained and reference the
> applicable upstream license, as the current example command may give the
> impression that the vector files are included in the DPDK source tree when they
> are not.
Ok, so in that case did you consider integrating this app into fips_validation app..
May be we could rename fips_validation to crypto_validation and internally have 2 modes -
Fips and Wycheproof? Like what we have for examples/multi_process?
>
> From: Akhil Goyal <gakhil at marvell.com>
> Sent: Thursday, September 24, 2026 15:35
> To: Ji, Kai <kai.ji at intel.com>; dev at dpdk.org <dev at dpdk.org>
> Cc: Thomas Monjalon <thomas at monjalon.net>
> Subject: RE: [EXTERNAL] [PATCH v7] examples: add Wycheproof validation app
>
> > Add a Wycheproof JSON vector validation example for cryptodev PMDs.
> >
> > Support these algorithms when advertised by the selected PMD:
> > - AEAD: AES-GCM, AES-CCM, SM4-GCM, ChaCha20-Poly1305
> > - MAC: AES-CMAC, AES-GMAC, HMAC SHA-1/SHA-2/SHA-3/SM3
> > - Asymmetric: DSA (P1363 verify), ECDSA (P1363 verify),
> > ECDH (ecpoint shared-secret compute)
> >
> > Validate valid vectors against generated ciphertexts, tags, plaintexts,
> > digests, shared secrets, or signature verification, and require the
> > expected rejection for invalid vectors. Digest inputs for DSA and ECDSA
> > use the symmetric auth path, selecting a separate symmetric-capable
> > device when the target device is asymmetric-only.
> >
> > Skip parameter combinations outside PMD capability ranges and identify
> > recognized vector families without a compatible DPDK transform. A
> > --debug option lists every failed or skipped vector.
> >
> > Add Meson and standalone build integration, with usage documentation.
> >
> > Signed-off-by: Kai Ji <kai.ji at intel.com>
> > ---
> > MAINTAINERS | 5 +
> > doc/guides/rel_notes/release_26_11.rst | 6 +
> > doc/guides/sample_app_ug/index.rst | 1 +
> > .../sample_app_ug/wycheproof_validation.rst | 50 +
> > examples/meson.build | 1 +
> > examples/wycheproof_validation/Makefile | 40 +
> > examples/wycheproof_validation/main.c | 2090 +++++++++++++++++
> > examples/wycheproof_validation/meson.build | 17 +
> > 8 files changed, 2210 insertions(+)
> > create mode 100644 doc/guides/sample_app_ug/wycheproof_validation.rst
> > create mode 100644 examples/wycheproof_validation/Makefile
> > create mode 100644 examples/wycheproof_validation/main.c
> > create mode 100644 examples/wycheproof_validation/meson.build
> >
> > diff --git a/MAINTAINERS b/MAINTAINERS
> > index 186cc82b39..580e2c2591 100644
> > --- a/MAINTAINERS
> > +++ b/MAINTAINERS
> > @@ -2099,3 +2099,8 @@ F: examples/vmdq/
> > F: doc/guides/sample_app_ug/vmdq_forwarding.rst
> > F: examples/vmdq_dcb/
> > F: doc/guides/sample_app_ug/vmdq_dcb_forwarding.rst
> > +
> > +Wycheproof validation example
> > +M: Kai Ji <kai.ji at intel.com>
> > +F: examples/wycheproof_validation/
> > +F: doc/guides/sample_app_ug/wycheproof_validation.rst
> > diff --git a/doc/guides/rel_notes/release_26_11.rst
> > b/doc/guides/rel_notes/release_26_11.rst
> > index dec96ccbc7..cd2711ddad 100644
> > --- a/doc/guides/rel_notes/release_26_11.rst
> > +++ b/doc/guides/rel_notes/release_26_11.rst
> > @@ -133,6 +133,12 @@ New Features
> > with per-descriptor mbuf free (``rte_pktmbuf_free_seg``) and prefetch hints.
> > * Changed the set of per-queue xstats counters.
> >
> > +* **Added Wycheproof validation example application.**
> > +
> > + Added a new example application that validates a DPDK cryptodev PMD
> against
> > + the Google Wycheproof JSON test vectors, covering AEAD, MAC, DSA, ECDH
> > and
> > + ECDSA algorithm families.
> > +
> >
> > Removed Items
> > -------------
> > diff --git a/doc/guides/sample_app_ug/index.rst
> > b/doc/guides/sample_app_ug/index.rst
> > index 28c4c9a5b2..2458b06ccd 100644
> > --- a/doc/guides/sample_app_ug/index.rst
> > +++ b/doc/guides/sample_app_ug/index.rst
> > @@ -51,6 +51,7 @@ Sample Applications User Guides
> > ptpclient
> > ptp_tap_relay_sw
> > fips_validation
> > + wycheproof_validation
> > ipsec_secgw
> > bbdev_app
> > ntb
> > diff --git a/doc/guides/sample_app_ug/wycheproof_validation.rst
> > b/doc/guides/sample_app_ug/wycheproof_validation.rst
> > new file mode 100644
> > index 0000000000..17c8bd2b55
> > --- /dev/null
> > +++ b/doc/guides/sample_app_ug/wycheproof_validation.rst
> > @@ -0,0 +1,50 @@
> > +.. SPDX-License-Identifier: BSD-3-Clause
> > + Copyright(c) 2026 Intel Corporation.
> > +
> > +Wycheproof Validation Example
> > +=============================
> > +
> > +Overview
> > +--------
> > +
> > +This example validates a DPDK cryptodev implementation against the Google
> > +Wycheproof JSON test vectors.
> > +
> > +The application reads one JSON file or a directory of JSON files at runtime and
> > +checks the supported algorithm families against the selected PMD. It can be
> > used
> > +with a PMD that advertises AEAD, MAC, DSA, ECDH, or ECDSA support.
> > +
> > +Build
> > +-----
> > +
> > +Build the example from the DPDK tree with Meson:
> > +
> > +.. code-block:: console
> > +
> > + meson setup build -Dexamples=wycheproof_validation -
> > Denable_drivers=crypto/openssl
> > + meson compile -C build
> > +
> > +Standalone Makefile builds are also supported from the example directory.
> > +
> > +Run
> > +---
> > +
> > +Run the example with an OpenSSL-backed cryptodev and a vector file:
> > +
> > +.. code-block:: console
> > +
> > + ./build/examples/dpdk-wycheproof_validation --vdev crypto_openssl -- \
> > + --vectors ../wycheproof/testvectors_v1/aes_gcm_test.json \
> > + --cryptodev crypto_openssl --debug
> > +
>
> Why do we need a new application to perform test vector validation?
> Is dpdk-test crypto tests not enough?
> Can we integrate this in that?
>
> And I do not see the .json file mentioned above in the patch.
> There should be a sample file atleast.
>
More information about the dev
mailing list