example_test.py 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318
  1. import http.server
  2. import os
  3. import re
  4. import socket
  5. import ssl
  6. from threading import Thread
  7. import ttfw_idf
  8. from tiny_test_fw import DUT, Utility
  9. server_cert = '-----BEGIN CERTIFICATE-----\n' \
  10. 'MIIDWDCCAkACCQCbF4+gVh/MLjANBgkqhkiG9w0BAQsFADBuMQswCQYDVQQGEwJJ\n'\
  11. 'TjELMAkGA1UECAwCTUgxDDAKBgNVBAcMA1BVTjEMMAoGA1UECgwDRVNQMQwwCgYD\n'\
  12. 'VQQLDANFU1AxDDAKBgNVBAMMA0VTUDEaMBgGCSqGSIb3DQEJARYLZXNwQGVzcC5j\n'\
  13. 'b20wHhcNMjEwNzEyMTIzNjI3WhcNNDEwNzA3MTIzNjI3WjBuMQswCQYDVQQGEwJJ\n'\
  14. 'TjELMAkGA1UECAwCTUgxDDAKBgNVBAcMA1BVTjEMMAoGA1UECgwDRVNQMQwwCgYD\n'\
  15. 'VQQLDANFU1AxDDAKBgNVBAMMA0VTUDEaMBgGCSqGSIb3DQEJARYLZXNwQGVzcC5j\n'\
  16. 'b20wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDhxF/y7bygndxPwiWL\n'\
  17. 'SwS9LY3uBMaJgup0ufNKVhx+FhGQOu44SghuJAaH3KkPUnt6SOM8jC97/yQuc32W\n'\
  18. 'ukI7eBZoA12kargSnzdv5m5rZZpd+NznSSpoDArOAONKVlzr25A1+aZbix2mKRbQ\n'\
  19. 'S5w9o1N2BriQuSzd8gL0Y0zEk3VkOWXEL+0yFUT144HnErnD+xnJtHe11yPO2fEz\n'\
  20. 'YaGiilh0ddL26PXTugXMZN/8fRVHP50P2OG0SvFpC7vghlLp4VFM1/r3UJnvL6Oz\n'\
  21. '3ALc6dhxZEKQucqlpj8l1UegszQToopemtIj0qXTHw2+uUnkUyWIPjPC+wdOAoap\n'\
  22. 'rFTRAgMBAAEwDQYJKoZIhvcNAQELBQADggEBAItw24y565k3C/zENZlxyzto44ud\n'\
  23. 'IYPQXN8Fa2pBlLe1zlSIyuaA/rWQ+i1daS8nPotkCbWZyf5N8DYaTE4B0OfvoUPk\n'\
  24. 'B5uGDmbuk6akvlB5BGiYLfQjWHRsK9/4xjtIqN1H58yf3QNROuKsPAeywWS3Fn32\n'\
  25. '3//OpbWaClQePx6udRYMqAitKR+QxL7/BKZQsX+UyShuq8hjphvXvk0BW8ONzuw9\n'\
  26. 'RcoORxM0FzySYjeQvm4LhzC/P3ZBhEq0xs55aL2a76SJhq5hJy7T/Xz6NFByvlrN\n'\
  27. 'lFJJey33KFrAf5vnV9qcyWFIo7PYy2VsaaEjFeefr7q3sTFSMlJeadexW2Y=\n'\
  28. '-----END CERTIFICATE-----\n'
  29. server_key = '-----BEGIN PRIVATE KEY-----\n'\
  30. 'MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQDhxF/y7bygndxP\n'\
  31. 'wiWLSwS9LY3uBMaJgup0ufNKVhx+FhGQOu44SghuJAaH3KkPUnt6SOM8jC97/yQu\n'\
  32. 'c32WukI7eBZoA12kargSnzdv5m5rZZpd+NznSSpoDArOAONKVlzr25A1+aZbix2m\n'\
  33. 'KRbQS5w9o1N2BriQuSzd8gL0Y0zEk3VkOWXEL+0yFUT144HnErnD+xnJtHe11yPO\n'\
  34. '2fEzYaGiilh0ddL26PXTugXMZN/8fRVHP50P2OG0SvFpC7vghlLp4VFM1/r3UJnv\n'\
  35. 'L6Oz3ALc6dhxZEKQucqlpj8l1UegszQToopemtIj0qXTHw2+uUnkUyWIPjPC+wdO\n'\
  36. 'AoaprFTRAgMBAAECggEAE0HCxV/N1Q1h+1OeDDGL5+74yjKSFKyb/vTVcaPCrmaH\n'\
  37. 'fPvp0ddOvMZJ4FDMAsiQS6/n4gQ7EKKEnYmwTqj4eUYW8yxGUn3f0YbPHbZT+Mkj\n'\
  38. 'z5woi3nMKi/MxCGDQZX4Ow3xUQlITUqibsfWcFHis8c4mTqdh4qj7xJzehD2PVYF\n'\
  39. 'gNHZsvVj6MltjBDAVwV1IlGoHjuElm6vuzkfX7phxcA1B4ZqdYY17yCXUnvui46z\n'\
  40. 'Xn2kUTOOUCEgfgvGa9E+l4OtdXi5IxjaSraU+dlg2KsE4TpCuN2MEVkeR5Ms3Y7Q\n'\
  41. 'jgJl8vlNFJDQpbFukLcYwG7rO5N5dQ6WWfVia/5XgQKBgQD74at/bXAPrh9NxPmz\n'\
  42. 'i1oqCHMDoM9sz8xIMZLF9YVu3Jf8ux4xVpRSnNy5RU1gl7ZXbpdgeIQ4v04zy5aw\n'\
  43. '8T4tu9K3XnR3UXOy25AK0q+cnnxZg3kFQm+PhtOCKEFjPHrgo2MUfnj+EDddod7N\n'\
  44. 'JQr9q5rEFbqHupFPpWlqCa3QmQKBgQDldWUGokNaEpmgHDMnHxiibXV5LQhzf8Rq\n'\
  45. 'gJIQXb7R9EsTSXEvsDyqTBb7PHp2Ko7rZ5YQfyf8OogGGjGElnPoU/a+Jij1gVFv\n'\
  46. 'kZ064uXAAISBkwHdcuobqc5EbG3ceyH46F+FBFhqM8KcbxJxx08objmh58+83InN\n'\
  47. 'P9Qr25Xw+QKBgEGXMHuMWgQbSZeM1aFFhoMvlBO7yogBTKb4Ecpu9wI5e3Kan3Al\n'\
  48. 'pZYltuyf+VhP6XG3IMBEYdoNJyYhu+nzyEdMg8CwXg+8LC7FMis/Ve+o7aS5scgG\n'\
  49. '1to/N9DK/swCsdTRdzmc/ZDbVC+TuVsebFBGYZTyO5KgqLpezqaIQrTxAoGALFCU\n'\
  50. '10glO9MVyl9H3clap5v+MQ3qcOv/EhaMnw6L2N6WVT481tnxjW4ujgzrFcE4YuxZ\n'\
  51. 'hgwYu9TOCmeqopGwBvGYWLbj+C4mfSahOAs0FfXDoYazuIIGBpuv03UhbpB1Si4O\n'\
  52. 'rJDfRnuCnVWyOTkl54gKJ2OusinhjztBjcrV1XkCgYEA3qNi4uBsPdyz9BZGb/3G\n'\
  53. 'rOMSw0CaT4pEMTLZqURmDP/0hxvTk1polP7O/FYwxVuJnBb6mzDa0xpLFPTpIAnJ\n'\
  54. 'YXB8xpXU69QVh+EBbemdJWOd+zp5UCfXvb2shAeG3Tn/Dz4cBBMEUutbzP+or0nG\n'\
  55. 'vSXnRLaxQhooWm+IuX9SuBQ=\n'\
  56. '-----END PRIVATE KEY-----\n'
  57. def get_my_ip():
  58. s1 = socket.socket(socket.AF_INET, socket.SOCK_DGRAM)
  59. s1.connect(('8.8.8.8', 80))
  60. my_ip = s1.getsockname()[0]
  61. s1.close()
  62. return my_ip
  63. def start_https_server(ota_image_dir, server_ip, server_port):
  64. # parser = argparse.ArgumentParser()
  65. # parser.add_argument('-p', '--port', dest='port', type= int,
  66. # help= "Server Port", default= 8000)
  67. # args = parser.parse_args()
  68. os.chdir(ota_image_dir)
  69. server_file = os.path.join(ota_image_dir, 'server_cert.pem')
  70. cert_file_handle = open(server_file, 'w+')
  71. cert_file_handle.write(server_cert)
  72. cert_file_handle.close()
  73. key_file = os.path.join(ota_image_dir, 'server_key.pem')
  74. key_file_handle = open('server_key.pem', 'w+')
  75. key_file_handle.write(server_key)
  76. key_file_handle.close()
  77. httpd = http.server.HTTPServer((server_ip, server_port), http.server.SimpleHTTPRequestHandler)
  78. httpd.socket = ssl.wrap_socket(httpd.socket,
  79. keyfile=key_file,
  80. certfile=server_file, server_side=True)
  81. httpd.serve_forever()
  82. def check_sha256(sha256_expected, sha256_reported):
  83. Utility.console_log('sha256_expected: %s' % (sha256_expected))
  84. Utility.console_log('sha256_reported: %s' % (sha256_reported))
  85. if sha256_reported not in sha256_expected:
  86. raise ValueError('SHA256 mismatch')
  87. else:
  88. Utility.console_log('SHA256 expected and reported are the same')
  89. def calc_all_sha256(dut):
  90. bootloader_path = os.path.join(dut.app.binary_path, 'bootloader', 'bootloader.bin')
  91. output = dut.image_info(bootloader_path)
  92. sha256_bootloader = re.search(r'Validation Hash:\s+([a-f0-9]+)', output).group(1)
  93. Utility.console_log('bootloader SHA256: %s' % sha256_bootloader)
  94. app_path = os.path.join(dut.app.binary_path, 'simple_ota.bin')
  95. output = dut.image_info(app_path)
  96. sha256_app = re.search(r'Validation Hash:\s+([a-f0-9]+)', output).group(1)
  97. Utility.console_log('app SHA256: %s' % sha256_app)
  98. return sha256_bootloader, sha256_app
  99. @ttfw_idf.idf_example_test(env_tag='Example_WIFI')
  100. def test_examples_protocol_simple_ota_example(env, extra_data):
  101. """
  102. steps: |
  103. 1. join AP
  104. 2. Fetch OTA image over HTTPS
  105. 3. Reboot with the new OTA image
  106. """
  107. dut1 = env.get_dut('simple_ota_example', 'examples/system/ota/simple_ota_example', dut_class=ttfw_idf.ESP32DUT)
  108. # check and log bin size
  109. binary_file = os.path.join(dut1.app.binary_path, 'simple_ota.bin')
  110. bin_size = os.path.getsize(binary_file)
  111. ttfw_idf.log_performance('simple_ota_bin_size', '{}KB'.format(bin_size // 1024))
  112. sha256_bootloader, sha256_app = calc_all_sha256(dut1)
  113. # start test
  114. host_ip = get_my_ip()
  115. thread1 = Thread(target=start_https_server, args=(dut1.app.binary_path, host_ip, 8000))
  116. thread1.daemon = True
  117. thread1.start()
  118. dut1.start_app()
  119. dut1.expect('Loaded app from partition at offset 0x10000', timeout=30)
  120. check_sha256(sha256_bootloader, dut1.expect(re.compile(r'SHA-256 for bootloader:\s+([a-f0-9]+)'))[0])
  121. check_sha256(sha256_app, dut1.expect(re.compile(r'SHA-256 for current firmware:\s+([a-f0-9]+)'))[0])
  122. try:
  123. ip_address = dut1.expect(re.compile(r' sta ip: ([^,]+),'), timeout=30)
  124. print('Connected to AP with IP: {}'.format(ip_address))
  125. except DUT.ExpectTimeout:
  126. raise ValueError('ENV_TEST_FAILURE: Cannot connect to AP')
  127. thread1.close()
  128. dut1.expect('Starting OTA example', timeout=30)
  129. print('writing to device: {}'.format('https://' + host_ip + ':8000/simple_ota.bin'))
  130. dut1.write('https://' + host_ip + ':8000/simple_ota.bin')
  131. dut1.expect('Loaded app from partition at offset 0x110000', timeout=60)
  132. dut1.expect('Starting OTA example', timeout=30)
  133. @ttfw_idf.idf_example_test(env_tag='Example_EthKitV1')
  134. def test_examples_protocol_simple_ota_example_ethernet_with_spiram_config(env, extra_data):
  135. """
  136. steps: |
  137. 1. join AP
  138. 2. Fetch OTA image over HTTPS
  139. 3. Reboot with the new OTA image
  140. """
  141. dut1 = env.get_dut('simple_ota_example', 'examples/system/ota/simple_ota_example', dut_class=ttfw_idf.ESP32DUT, app_config_name='spiram')
  142. # check and log bin size
  143. binary_file = os.path.join(dut1.app.binary_path, 'simple_ota.bin')
  144. bin_size = os.path.getsize(binary_file)
  145. ttfw_idf.log_performance('simple_ota_bin_size', '{}KB'.format(bin_size // 1024))
  146. # start test
  147. host_ip = get_my_ip()
  148. thread1 = Thread(target=start_https_server, args=(dut1.app.binary_path, host_ip, 8000))
  149. thread1.daemon = True
  150. thread1.start()
  151. dut1.start_app()
  152. dut1.expect('Loaded app from partition at offset 0x10000', timeout=30)
  153. try:
  154. ip_address = dut1.expect(re.compile(r' eth ip: ([^,]+),'), timeout=30)
  155. print('Connected to AP with IP: {}'.format(ip_address))
  156. except DUT.ExpectTimeout:
  157. raise ValueError('ENV_TEST_FAILURE: Cannot connect to AP')
  158. thread1.close()
  159. dut1.expect('Starting OTA example', timeout=30)
  160. print('writing to device: {}'.format('https://' + host_ip + ':8000/simple_ota.bin'))
  161. dut1.write('https://' + host_ip + ':8000/simple_ota.bin')
  162. dut1.expect('Loaded app from partition at offset 0x110000', timeout=60)
  163. dut1.expect('Starting OTA example', timeout=30)
  164. @ttfw_idf.idf_example_test(env_tag='Example_Flash_Encryption_OTA')
  165. def test_examples_protocol_simple_ota_example_with_flash_encryption(env, extra_data):
  166. """
  167. steps: |
  168. 1. join AP
  169. 2. Fetch OTA image over HTTPS
  170. 3. Reboot with the new OTA image
  171. """
  172. dut1 = env.get_dut('simple_ota_example', 'examples/system/ota/simple_ota_example', dut_class=ttfw_idf.ESP32DUT, app_config_name='flash_enc')
  173. # check and log bin size
  174. binary_file = os.path.join(dut1.app.binary_path, 'simple_ota.bin')
  175. bin_size = os.path.getsize(binary_file)
  176. ttfw_idf.log_performance('simple_ota_bin_size', '{}KB'.format(bin_size // 1024))
  177. # erase flash on the device
  178. print('Erasing the flash in order to have an empty NVS key partiton')
  179. dut1.erase_flash()
  180. # start test
  181. host_ip = get_my_ip()
  182. thread1 = Thread(target=start_https_server, args=(dut1.app.binary_path, host_ip, 8000))
  183. thread1.daemon = True
  184. thread1.start()
  185. dut1.start_app()
  186. dut1.expect('Loaded app from partition at offset 0x20000', timeout=30)
  187. dut1.expect('Flash encryption mode is DEVELOPMENT (not secure)', timeout=10)
  188. try:
  189. ip_address = dut1.expect(re.compile(r' eth ip: ([^,]+),'), timeout=30)
  190. print('Connected to AP with IP: {}'.format(ip_address))
  191. except DUT.ExpectTimeout:
  192. raise ValueError('ENV_TEST_FAILURE: Cannot connect to AP')
  193. thread1.close()
  194. dut1.expect('Starting OTA example', timeout=30)
  195. print('writing to device: {}'.format('https://' + host_ip + ':8000/simple_ota.bin'))
  196. dut1.write('https://' + host_ip + ':8000/simple_ota.bin')
  197. dut1.expect('Loaded app from partition at offset 0x120000', timeout=60)
  198. dut1.expect('Flash encryption mode is DEVELOPMENT (not secure)', timeout=10)
  199. dut1.expect('Starting OTA example', timeout=30)
  200. @ttfw_idf.idf_example_test(env_tag='Example_EthKitV1')
  201. def test_examples_protocol_simple_ota_example_with_verify_app_signature_on_update_no_secure_boot_ecdsa(env, extra_data):
  202. """
  203. steps: |
  204. 1. join AP
  205. 2. Fetch OTA image over HTTPS
  206. 3. Reboot with the new OTA image
  207. """
  208. dut1 = env.get_dut('simple_ota_example', 'examples/system/ota/simple_ota_example', dut_class=ttfw_idf.ESP32DUT,
  209. app_config_name='on_update_no_sb_ecdsa')
  210. # check and log bin size
  211. binary_file = os.path.join(dut1.app.binary_path, 'simple_ota.bin')
  212. bin_size = os.path.getsize(binary_file)
  213. ttfw_idf.log_performance('simple_ota_bin_size', '{}KB'.format(bin_size // 1024))
  214. sha256_bootloader, sha256_app = calc_all_sha256(dut1)
  215. # start test
  216. host_ip = get_my_ip()
  217. thread1 = Thread(target=start_https_server, args=(dut1.app.binary_path, host_ip, 8000))
  218. thread1.daemon = True
  219. thread1.start()
  220. dut1.start_app()
  221. dut1.expect('Loaded app from partition at offset 0x20000', timeout=30)
  222. check_sha256(sha256_bootloader, dut1.expect(re.compile(r'SHA-256 for bootloader:\s+([a-f0-9]+)'))[0])
  223. check_sha256(sha256_app, dut1.expect(re.compile(r'SHA-256 for current firmware:\s+([a-f0-9]+)'))[0])
  224. try:
  225. ip_address = dut1.expect(re.compile(r' eth ip: ([^,]+),'), timeout=30)
  226. print('Connected to AP with IP: {}'.format(ip_address))
  227. except DUT.ExpectTimeout:
  228. raise ValueError('ENV_TEST_FAILURE: Cannot connect to AP')
  229. dut1.expect('Starting OTA example', timeout=30)
  230. print('writing to device: {}'.format('https://' + host_ip + ':8000/simple_ota.bin'))
  231. dut1.write('https://' + host_ip + ':8000/simple_ota.bin')
  232. dut1.expect('Writing to partition subtype 16 at offset 0x120000', timeout=20)
  233. dut1.expect('Verifying image signature...', timeout=60)
  234. dut1.expect('Loaded app from partition at offset 0x120000', timeout=20)
  235. dut1.expect('Starting OTA example', timeout=30)
  236. @ttfw_idf.idf_example_test(env_tag='Example_EthKitV12')
  237. def test_examples_protocol_simple_ota_example_with_verify_app_signature_on_update_no_secure_boot_rsa(env, extra_data):
  238. """
  239. steps: |
  240. 1. join AP
  241. 2. Fetch OTA image over HTTPS
  242. 3. Reboot with the new OTA image
  243. """
  244. dut1 = env.get_dut('simple_ota_example', 'examples/system/ota/simple_ota_example', dut_class=ttfw_idf.ESP32DUT,
  245. app_config_name='on_update_no_sb_rsa')
  246. # check and log bin size
  247. binary_file = os.path.join(dut1.app.binary_path, 'simple_ota.bin')
  248. bin_size = os.path.getsize(binary_file)
  249. ttfw_idf.log_performance('simple_ota_bin_size', '{}KB'.format(bin_size // 1024))
  250. sha256_bootloader, sha256_app = calc_all_sha256(dut1)
  251. # start test
  252. host_ip = get_my_ip()
  253. thread1 = Thread(target=start_https_server, args=(dut1.app.binary_path, host_ip, 8000))
  254. thread1.daemon = True
  255. thread1.start()
  256. dut1.start_app()
  257. dut1.expect('Loaded app from partition at offset 0x20000', timeout=30)
  258. check_sha256(sha256_bootloader, dut1.expect(re.compile(r'SHA-256 for bootloader:\s+([a-f0-9]+)'))[0])
  259. check_sha256(sha256_app, dut1.expect(re.compile(r'SHA-256 for current firmware:\s+([a-f0-9]+)'))[0])
  260. try:
  261. ip_address = dut1.expect(re.compile(r' eth ip: ([^,]+),'), timeout=30)
  262. print('Connected to AP with IP: {}'.format(ip_address))
  263. except DUT.ExpectTimeout:
  264. raise ValueError('ENV_TEST_FAILURE: Cannot connect to AP')
  265. dut1.expect('Starting OTA example', timeout=30)
  266. print('writing to device: {}'.format('https://' + host_ip + ':8000/simple_ota.bin'))
  267. dut1.write('https://' + host_ip + ':8000/simple_ota.bin')
  268. dut1.expect('Writing to partition subtype 16 at offset 0x120000', timeout=20)
  269. dut1.expect('Verifying image signature...', timeout=60)
  270. dut1.expect('#0 app key digest == #0 trusted key digest', timeout=10)
  271. dut1.expect('Verifying with RSA-PSS...', timeout=10)
  272. dut1.expect('Signature verified successfully!', timeout=10)
  273. dut1.expect('Loaded app from partition at offset 0x120000', timeout=20)
  274. dut1.expect('Starting OTA example', timeout=30)
  275. if __name__ == '__main__':
  276. test_examples_protocol_simple_ota_example()
  277. test_examples_protocol_simple_ota_example_ethernet_with_spiram_config()
  278. test_examples_protocol_simple_ota_example_with_flash_encryption()
  279. test_examples_protocol_simple_ota_example_with_verify_app_signature_on_update_no_secure_boot_ecdsa()
  280. test_examples_protocol_simple_ota_example_with_verify_app_signature_on_update_no_secure_boot_rsa()