<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div class="elementToProof" style="line-height: 20px; margin-top: 1em; margin-bottom: 1em; font-family: "IntelOne Text"; font-size: 10pt; color: rgb(0, 0, 0);">
Wycheproof differs somewhat from the existing cryptodev test vectors in that it is an externally maintained collection of JSON test suites covering a large number of edge cases and negative tests. The intended usage model is to load the upstream vector files
at runtime rather than embedding them in the DPDK tree.</div>
<div class="elementToProof" style="line-height: 20px; margin-top: 1em; margin-bottom: 1em; font-family: "IntelOne Text"; font-size: 10pt; color: rgb(0, 0, 0);">
I think the existing <code>examples/fips_validation</code> application follows a similar approach, consuming external CAVP/ACVP vector files rather than integrating them into
<code>dpdk-test</code>. This patch follows that precedent, with the goal of providing file-driven conformance validation as a standalone example application.</div>
<div class="elementToProof" style="line-height: 20px; margin-top: 1em; margin-bottom: 1em; font-family: "IntelOne Text"; font-size: 10pt; color: rgb(0, 0, 0);">
I agree that the documentation can be improved. At minimum, the <code>.rst</code> should describe where the Wycheproof vectors can be obtained and reference the applicable upstream license, as the current example command may give the impression that the vector
files are included in the DPDK source tree when they are not.</div>
<div class="elementToProof" style="line-height: 20px; margin-top: 1em; margin-bottom: 1em; font-family: "IntelOne Text"; font-size: 10pt; color: rgb(0, 0, 0);">
Regards</div>
<div class="elementToProof" style="line-height: 20px; margin-top: 1em; margin-bottom: 1em; font-family: "IntelOne Text"; font-size: 10pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="line-height: 20px; margin-top: 1em; margin-bottom: 1em; font-family: "IntelOne Text"; font-size: 10pt; color: rgb(0, 0, 0);">
Kai </div>
<div class="elementToProof" style="font-family: "IntelOne Text"; font-size: 10pt; color: rgb(0, 0, 0);">
<span style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt;"><br>
</span></div>
<hr style="display: inline-block; width: 98%;">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<b>From:</b> Akhil Goyal <gakhil@marvell.com><br>
<b>Sent:</b> Thursday, September 24, 2026 15:35<br>
<b>To:</b> Ji, Kai <kai.ji@intel.com>; dev@dpdk.org <dev@dpdk.org><br>
<b>Cc:</b> Thomas Monjalon <thomas@monjalon.net><br>
<b>Subject:</b> RE: [EXTERNAL] [PATCH v7] examples: add Wycheproof validation app
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-size: 11pt;">> Add a Wycheproof JSON vector validation example for cryptodev PMDs.<br>
><br>
> Support these algorithms when advertised by the selected PMD:<br>
> - AEAD: AES-GCM, AES-CCM, SM4-GCM, ChaCha20-Poly1305<br>
> - MAC: AES-CMAC, AES-GMAC, HMAC SHA-1/SHA-2/SHA-3/SM3<br>
> - Asymmetric: DSA (P1363 verify), ECDSA (P1363 verify),<br>
> ECDH (ecpoint shared-secret compute)<br>
><br>
> Validate valid vectors against generated ciphertexts, tags, plaintexts,<br>
> digests, shared secrets, or signature verification, and require the<br>
> expected rejection for invalid vectors. Digest inputs for DSA and ECDSA<br>
> use the symmetric auth path, selecting a separate symmetric-capable<br>
> device when the target device is asymmetric-only.<br>
><br>
> Skip parameter combinations outside PMD capability ranges and identify<br>
> recognized vector families without a compatible DPDK transform. A<br>
> --debug option lists every failed or skipped vector.<br>
><br>
> Add Meson and standalone build integration, with usage documentation.<br>
><br>
> Signed-off-by: Kai Ji <kai.ji@intel.com><br>
> ---<br>
> MAINTAINERS | 5 +<br>
> doc/guides/rel_notes/release_26_11.rst | 6 +<br>
> doc/guides/sample_app_ug/index.rst | 1 +<br>
> .../sample_app_ug/wycheproof_validation.rst | 50 +<br>
> examples/meson.build | 1 +<br>
> examples/wycheproof_validation/Makefile | 40 +<br>
> examples/wycheproof_validation/main.c | 2090 +++++++++++++++++<br>
> examples/wycheproof_validation/meson.build | 17 +<br>
> 8 files changed, 2210 insertions(+)<br>
> create mode 100644 doc/guides/sample_app_ug/wycheproof_validation.rst<br>
> create mode 100644 examples/wycheproof_validation/Makefile<br>
> create mode 100644 examples/wycheproof_validation/main.c<br>
> create mode 100644 examples/wycheproof_validation/meson.build<br>
><br>
> diff --git a/MAINTAINERS b/MAINTAINERS<br>
> index 186cc82b39..580e2c2591 100644<br>
> --- a/MAINTAINERS<br>
> +++ b/MAINTAINERS<br>
> @@ -2099,3 +2099,8 @@ F: examples/vmdq/<br>
> F: doc/guides/sample_app_ug/vmdq_forwarding.rst<br>
> F: examples/vmdq_dcb/<br>
> F: doc/guides/sample_app_ug/vmdq_dcb_forwarding.rst<br>
> +<br>
> +Wycheproof validation example<br>
> +M: Kai Ji <kai.ji@intel.com><br>
> +F: examples/wycheproof_validation/<br>
> +F: doc/guides/sample_app_ug/wycheproof_validation.rst<br>
> diff --git a/doc/guides/rel_notes/release_26_11.rst<br>
> b/doc/guides/rel_notes/release_26_11.rst<br>
> index dec96ccbc7..cd2711ddad 100644<br>
> --- a/doc/guides/rel_notes/release_26_11.rst<br>
> +++ b/doc/guides/rel_notes/release_26_11.rst<br>
> @@ -133,6 +133,12 @@ New Features<br>
> with per-descriptor mbuf free (``rte_pktmbuf_free_seg``) and prefetch hints.<br>
> * Changed the set of per-queue xstats counters.<br>
><br>
> +* **Added Wycheproof validation example application.**<br>
> +<br>
> + Added a new example application that validates a DPDK cryptodev PMD against<br>
> + the Google Wycheproof JSON test vectors, covering AEAD, MAC, DSA, ECDH<br>
> and<br>
> + ECDSA algorithm families.<br>
> +<br>
><br>
> Removed Items<br>
> -------------<br>
> diff --git a/doc/guides/sample_app_ug/index.rst<br>
> b/doc/guides/sample_app_ug/index.rst<br>
> index 28c4c9a5b2..2458b06ccd 100644<br>
> --- a/doc/guides/sample_app_ug/index.rst<br>
> +++ b/doc/guides/sample_app_ug/index.rst<br>
> @@ -51,6 +51,7 @@ Sample Applications User Guides<br>
> ptpclient<br>
> ptp_tap_relay_sw<br>
> fips_validation<br>
> + wycheproof_validation<br>
> ipsec_secgw<br>
> bbdev_app<br>
> ntb<br>
> diff --git a/doc/guides/sample_app_ug/wycheproof_validation.rst<br>
> b/doc/guides/sample_app_ug/wycheproof_validation.rst<br>
> new file mode 100644<br>
> index 0000000000..17c8bd2b55<br>
> --- /dev/null<br>
> +++ b/doc/guides/sample_app_ug/wycheproof_validation.rst<br>
> @@ -0,0 +1,50 @@<br>
> +.. SPDX-License-Identifier: BSD-3-Clause<br>
> + Copyright(c) 2026 Intel Corporation.<br>
> +<br>
> +Wycheproof Validation Example<br>
> +=============================<br>
> +<br>
> +Overview<br>
> +--------<br>
> +<br>
> +This example validates a DPDK cryptodev implementation against the Google<br>
> +Wycheproof JSON test vectors.<br>
> +<br>
> +The application reads one JSON file or a directory of JSON files at runtime and<br>
> +checks the supported algorithm families against the selected PMD. It can be<br>
> used<br>
> +with a PMD that advertises AEAD, MAC, DSA, ECDH, or ECDSA support.<br>
> +<br>
> +Build<br>
> +-----<br>
> +<br>
> +Build the example from the DPDK tree with Meson:<br>
> +<br>
> +.. code-block:: console<br>
> +<br>
> + meson setup build -Dexamples=wycheproof_validation -<br>
> Denable_drivers=crypto/openssl<br>
> + meson compile -C build<br>
> +<br>
> +Standalone Makefile builds are also supported from the example directory.<br>
> +<br>
> +Run<br>
> +---<br>
> +<br>
> +Run the example with an OpenSSL-backed cryptodev and a vector file:<br>
> +<br>
> +.. code-block:: console<br>
> +<br>
> + ./build/examples/dpdk-wycheproof_validation --vdev crypto_openssl -- \<br>
> + --vectors ../wycheproof/testvectors_v1/aes_gcm_test.json \<br>
> + --cryptodev crypto_openssl --debug<br>
> +<br>
<br>
Why do we need a new application to perform test vector validation?<br>
Is dpdk-test crypto tests not enough?<br>
Can we integrate this in that?<br>
<br>
And I do not see the .json file mentioned above in the patch.<br>
There should be a sample file atleast.<br>
<br>
</div>
</body>
</html>