Skip to content

Commit 6e09198

Browse files
authored
python-pkcs11: Add version 0.9.5 (#2657)
* python-pkcs11: add riscv64 wheel build for 0.9.5 * python-pkcs11: test against SoftHSMv2 built from source like upstream Rocky 10's softhsm 2.6.1 RPM aborts the test process on the first empty-plaintext AES-GCM test vector. Upstream's tests.yml builds SoftHSMv2 from main with --enable-mldsa; do the same, pinned to a commit. * python-pkcs11: allow SHA-1 signatures and skip the P-192 ECDH test Rocky 10's OpenSSL drops the P-192 curve (CentOS Stream 10 patch 0009-RH-Drop-weak-curve-definitions) and its DEFAULT crypto policy refuses SHA-1 signatures; neither is riscv64-specific.
1 parent abdc2ea commit 6e09198

2 files changed

Lines changed: 131 additions & 0 deletions

File tree

Lines changed: 126 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,126 @@
1+
# SPDX-FileCopyrightText: 2026 The RISE Project
2+
# SPDX-License-Identifier: MIT
3+
---
4+
# This workflow is based on: https://github.com/pyauth/python-pkcs11/blob/v0.9.5/.github/workflows/release.yml
5+
# and https://github.com/pyauth/python-pkcs11/blob/v0.9.5/.github/workflows/tests.yml
6+
name: Build python-pkcs11 wheels (riscv64)
7+
8+
on:
9+
workflow_dispatch:
10+
inputs:
11+
version:
12+
description: 'Version glob to (re)build; empty builds every version of docs/packages/python-pkcs11.yaml not released yet'
13+
required: false
14+
default: ''
15+
pull_request:
16+
branches: [main]
17+
paths:
18+
- '.github/workflows/build-python-pkcs11.yml'
19+
- 'docs/packages/python-pkcs11.yaml'
20+
push:
21+
branches: [main]
22+
paths:
23+
- '.github/workflows/build-python-pkcs11.yml'
24+
- 'docs/packages/python-pkcs11.yaml'
25+
26+
concurrency:
27+
group: ${{ github.workflow }}-${{ github.head_ref || github.run_id }}
28+
cancel-in-progress: true
29+
30+
permissions:
31+
contents: read # to fetch code (actions/checkout)
32+
33+
env:
34+
MANYLINUX_RISCV64_IMAGE: quay.io/pypa/manylinux_2_39_riscv64
35+
# Upstream tests against SoftHSMv2 main for ML-DSA; pinned here for reproducibility.
36+
SOFTHSM_REF: 884cb38f3d2012a0447bd5f50dbd29c429987c41
37+
38+
jobs:
39+
setup:
40+
uses: $/.github/workflows/_setup.yml
41+
with:
42+
package: python-pkcs11
43+
version: ${{ inputs.version }}
44+
45+
build_wheels:
46+
needs: [setup]
47+
if: needs.setup.outputs.versions != '[]'
48+
name: Build python-pkcs11 ${{ matrix.version }} ${{ matrix.python }}-manylinux_riscv64
49+
runs-on: ubuntu-24.04-riscv
50+
timeout-minutes: 90
51+
strategy:
52+
fail-fast: false
53+
matrix:
54+
version: ${{ fromJSON(needs.setup.outputs.versions) }}
55+
# Upstream's [tool.cibuildwheel] skips free-threaded builds.
56+
python: ["cp312", "cp313", "cp314"]
57+
58+
env:
59+
PYTHON_PKCS11_VERSION: ${{ matrix.version }}
60+
61+
steps:
62+
- name: Checkout python-pkcs11 v${{ env.PYTHON_PKCS11_VERSION }}
63+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
64+
with:
65+
repository: pyauth/python-pkcs11
66+
ref: v${{ env.PYTHON_PKCS11_VERSION }}
67+
persist-credentials: false
68+
69+
- name: Build wheels
70+
uses: pypa/cibuildwheel@1828c10ab37f080699c7b81cea34097c684a7074 # v4.2.0
71+
with:
72+
output-dir: wheelhouse/
73+
only: ${{ matrix.python }}-manylinux_riscv64
74+
env:
75+
CIBW_MANYLINUX_RISCV64_IMAGE: ${{ env.MANYLINUX_RISCV64_IMAGE }}
76+
CIBW_BEFORE_ALL_LINUX: |
77+
set -euo pipefail
78+
dnf install -y --setopt=install_weak_deps=False autoconf automake libtool openssl openssl-devel crypto-policies-scripts
79+
# Rocky's DEFAULT crypto policy refuses the SHA-1 signatures the RSA tests use.
80+
update-crypto-policies --set LEGACY
81+
curl -sSfL https://github.com/softhsm/SoftHSMv2/archive/${{ env.SOFTHSM_REF }}.tar.gz | tar xz -C /tmp
82+
cd /tmp/SoftHSMv2-${{ env.SOFTHSM_REF }}
83+
./autogen.sh
84+
./configure --prefix=/usr --disable-gost --enable-mldsa
85+
make -j"$(nproc)"
86+
make install
87+
mkdir -p /opt/softhsm_tokens
88+
echo "directories.tokendir = /opt/softhsm_tokens" > /opt/softhsm2.conf
89+
CIBW_ENVIRONMENT: >-
90+
SETUPTOOLS_SCM_PRETEND_VERSION_FOR_PYTHON_PKCS11=${{ env.PYTHON_PKCS11_VERSION }}
91+
PIP_EXTRA_INDEX_URL=https://pypi.riseproject.dev/simple/
92+
SOFTHSM2_CONF=/opt/softhsm2.conf
93+
CIBW_BEFORE_TEST_LINUX: softhsm2-util --init-token --free --label TEST --pin 1234 --so-pin 5678
94+
CIBW_TEST_ENVIRONMENT: >-
95+
PKCS11_MODULE=/usr/lib/softhsm/libsofthsm2.so
96+
PKCS11_TOKEN_LABEL=TEST
97+
PKCS11_TOKEN_PIN=1234
98+
PKCS11_TOKEN_SO_PIN=5678
99+
PIP_ONLY_BINARY=cryptography
100+
CIBW_TEST_GROUPS: testing
101+
CIBW_TEST_SOURCES: tests
102+
# Rocky's OpenSSL drops the P-192 curve this test uses.
103+
CIBW_TEST_COMMAND: pytest -v tests --deselect tests/test_ecc.py::ECCTests::test_derive_key
104+
105+
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
106+
with:
107+
name: python-pkcs11-${{ env.PYTHON_PKCS11_VERSION }}-${{ matrix.python }}-manylinux_riscv64
108+
path: wheelhouse/*.whl
109+
if-no-files-found: error
110+
111+
publish:
112+
name: Publish python-pkcs11 ${{ matrix.version }}
113+
needs: [setup, build_wheels]
114+
if: needs.setup.outputs.versions != '[]'
115+
strategy:
116+
fail-fast: false
117+
matrix:
118+
version: ${{ fromJSON(needs.setup.outputs.versions) }}
119+
permissions:
120+
contents: write
121+
pull-requests: write
122+
uses: $/.github/workflows/_publish-wheel.yml
123+
secrets:
124+
app-private-key: ${{ secrets.RISEPROJECT_APP_PRIVATE_KEY }}
125+
with:
126+
artifact-pattern: python-pkcs11-${{ matrix.version }}-*-manylinux_riscv64

‎docs/packages/python-pkcs11.yaml‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
package-name: python-pkcs11
2+
source-code: https://github.com/pyauth/python-pkcs11
3+
license: MIT
4+
versions:
5+
- version: 0.9.5

0 commit comments

Comments
 (0)