Repository navigation
Doc fixes and proper agents files - #48
Conversation
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The new integration guide contains inaccurate transport, CryptoCb, and asynchronous-session guidance.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Updates integration guidance and corrects stale protocol, interoperability, and CryptoCb documentation.
Changes:
- Adds an integrator-focused
AGENTS.mdand redirects Claude guidance to it. - Corrects EST/SCEP API, TLS verification, and interoperability descriptions.
- Updates related references and ignores local agent instruction files.
| File | Description |
|---|---|
.gitignore |
Ignores local agent instructions. |
AGENTS.md |
Adds the integration guide. |
CLAUDE.md |
Redirects to AGENTS.md. |
README.md |
Updates interoperability status. |
docs/ARCHITECTURE.md |
Corrects API routing and CryptoCb naming. |
docs/EMBEDDED.md |
Updates guide references. |
scripts/ci/build-wolfssl.sh |
Updates the canonical guide reference. |
wolfcert/client.h |
Clarifies EST-only client operations. |
wolfcert/types.h |
Clarifies server-verification requirements. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
da26189 to
1f09d37
Compare
yosuke-wolfssl
left a comment
There was a problem hiding this comment.
The corrected claims all check out against the code. I verified the verify_server checks, the client-API routing, the ECC RA rejection and every API name in the AGENTS.md example.
A few things below:
-
CONTRIBUTING.md: this follows wolfSSL'sAGENTS.md/CLAUDE.mdsplit, but wolfSSL pairs it with a trackedCONTRIBUTING.md, and wolfCert has none. The wolfCert-specific rules the oldCLAUDE.mdheld now have no tracked home:- the
WOLFCERT_ERR/WOLFCERT_ERR_WCmacros, andwolfcert_strerrorcovering every code WOLFCERT_TEST_VISand the hidden-visibility rule- the license-header rule and include order
- the Zephyr board checklist (
sample.yaml,zephyr/include.am, the CI job, the README tables);zephyr/README.md"Adding a board" covers only the board files
If you've already decided these belong in
*.local.md, ignore this. Otherwise aCONTRIBUTING.md(wolfSSL's text plus a wolfCert section) would keep them visible to other contributors and review agents. - the
-
EXTRA_DIST:Makefile.amdoesn't listAGENTS.mdordocs/INTEROP.md, butdocs/EMBEDDED.mdandREADME.mdnow point at them, so amake disttarball has dangling references. -
docs/INTEROP.md:3still calls the scripts "hand-run and best-effort", which no longer matches the new README text.
The README's Interoperability section still said the interop scripts are run by hand and that wolfSSL rejects micromdm's and step-ca's SCEP. The nightly Interop workflow runs them, and every peer passes: micromdm in both directions on a wolfSSL built with --enable-des3, and step-ca SCEP once its CA chain is RSA. The old step-ca failure was BAD_KEYWRAP_ALG_E from its default ECDSA RA, not a key-wrap algorithm wolfSSL refuses. The section now lists the caveats that still apply and points at docs/INTEROP.md, whose introduction also called the scripts hand-run. docs/ARCHITECTURE.md and CLAUDE.md named the CryptoCb registration call wolfCrypt_CryptoCb_RegisterDevice, which does not exist; it is wc_CryptoCb_RegisterDevice. ARCHITECTURE.md said wolfcert_client_enroll and _reenroll route to EST or SCEP, and client.h said fetch_meta queries SCEP capabilities. Only wolfcert_client_get_ca handles SCEP; fetch_meta, enroll and reenroll return WOLFCERT_ERR_UNSUPPORTED for it. wolfcert/types.h described verify_server 0 as an explicit-trust-anchor bootstrap. EST refuses it on every call and SCEP refuses it on an https:// URL, so the field has to be 1 wherever TLS is in use. EXTRA_DIST left out docs/CI.md, docs/INTEROP.md and docs/MIGRATING-FROM-WOLFSCEP.md, so a make dist tarball lacked files the README and the other docs point at.
CLAUDE.md was written for people working on wolfCert itself: the dev build, ctest, internal error macros, symbol visibility, license headers, the steps for adding a key algorithm or a Zephyr board. An agent helping someone build wolfCert into a product needs something else, and other agents than Claude Code read AGENTS.md rather than CLAUDE.md. AGENTS.md now follows the layout of wolfSSL's: which integration path to pick, the wolfSSL features wolfCert requires and the canonical configure line, building and installing with the CMake and autoconf options side by side, the configuration model, when to pick EST or SCEP, a minimal enrollment flow, the public headers, the porting hooks (heap hints, transport, store, CryptoCb dev_id, non-blocking sessions, logging), checking an integration against wolfcert-server, and the gotchas, including that verify_server must be set to 1, since EST and HTTPS SCEP refuse a zero-initialized config. CLAUDE.md is reduced to an import of AGENTS.md. Contributor notes move to AGENTS.local.md / CLAUDE.local.md, which .gitignore now lists, as wolfSSL does. docs/EMBEDDED.md and scripts/ci/build-wolfssl.sh pointed at CLAUDE.md for the build requirements and key algorithm gating and now point at AGENTS.md. EXTRA_DIST now ships AGENTS.md and CLAUDE.md.
1f09d37 to
dee357e
Compare
|
Thanks, all three addressed:
|
yosuke-wolfssl
left a comment
There was a problem hiding this comment.
Thanks, CONTRIBUTING.md reads well and the wolfCert section matches the tree.
One thing: two of the shared "What We Look For" rules don't match wolfCert's code:
- C90 declarations / no
for (int i = 0; ...): wolfCert builds as C11 (CMAKE_C_STANDARD 11), andsrc/has about 29for (size_t i = 0; ...)loops. - 80 columns, checked in CI: 448 lines in
src/,wolfcert/andcli/are over 80 columns, and the Lint workflow doesn't check line length.
Maybe we can take it as follow-up or tailor the rules for wolfCert a bit.
dee357e to
5ae1c54
Compare
The previous commit moved the contributor rules CLAUDE.md held (error macros, symbol visibility, license headers, include order, the Zephyr board checklist) into untracked local files, which left other contributors and review agents without them. CONTRIBUTING.md starts from the guide shared across the wolfSSL repositories, without the Jenkins and wolfSSL-Bot paragraphs, since wolfCert's CI runs only on GitHub Actions. Its declaration and line- length rules are relaxed to match wolfCert, which builds as C11 and does not check line length in CI, and two rules on keeping comments short are added. A wolfCert section after it carries the project rules and the full checklist for adding a board to the Zephyr EST sample. AGENTS.md points contributors at it, and EXTRA_DIST ships it.
5ae1c54 to
de0f4ce
Compare
|
Thanks. Tailored both: the declarations bullet now says C11 and follow the file's style, and 80 columns is a soft target for new code that CI doesn't check. Also added two bullets on comment style. |

Problem
Interopworkflow runs them, and every peer passes. The old step-ca failure wasBAD_KEYWRAP_ALG_Efrom its default ECDSA RA, not a key-wrap algorithm wolfSSL refuses.docs/ARCHITECTURE.mdsections 4.2 and 4.7 andCLAUDE.mdtold integrators to callwolfCrypt_CryptoCb_RegisterDevice, which does not exist.docs/ARCHITECTURE.mdsection 2 saidwolfcert_client_enroll/_reenrollroute to EST or SCEP, andwolfcert/client.hsaidwolfcert_client_fetch_metaqueries SCEP capabilities. Onlywolfcert_client_get_cahandles SCEP; the others returnWOLFCERT_ERR_UNSUPPORTEDfor it.verify_servercomment:wolfcert/types.hdescribedverify_server0 as an explicit-trust-anchor bootstrap. EST refuses it on every call,/cacertsincluded, and SCEP refuses it on anhttps://URL, both withWOLFCERT_ERR_TLS.AGENTS.md, notCLAUDE.md.make dist:EXTRA_DISTlisted onlyREADME.md,docs/ARCHITECTURE.mdanddocs/EMBEDDED.md, so the tarball lackeddocs/INTEROP.md,docs/CI.md,docs/MIGRATING-FROM-WOLFSCEP.mdand the agent files that the other docs point at.CLAUDE.mdmoved to integrators, the wolfCert-specific rules (error macros, visibility, license header, include order, the Zephyr board checklist) had no tracked home.Fix
Correct stale interop and client API claims in the docs: the README interop section now says the nightly workflow runs every peer and all of them pass. It keeps the caveats that still apply: micromdm needs--enable-des3, step-ca's SCEP needs an RSA CA chain, and open-source step-ca has no EST. It also points atdocs/INTEROP.md, whose introduction no longer calls the scripts hand-run. The CryptoCb call is renamed towc_CryptoCb_RegisterDevice, and ARCHITECTURE andclient.hsay whichwolfcert_client_*calls are EST-only. Theverify_serverfield comment says it must be 1 for EST andhttps://SCEP.EXTRA_DISTnow ships the three missingdocs/files. Only header comments change; no code.Turn CLAUDE.md into an integrator-focused AGENTS.md: follows wolfSSL's split.AGENTS.mdis written for integrators:wolfcert-serverCLAUDE.mdbecomes@AGENTS.md..gitignorelists the untrackedAGENTS.local.md/CLAUDE.local.mdfor machine-specific notes.docs/EMBEDDED.mdandscripts/ci/build-wolfssl.shnow point atAGENTS.md, andEXTRA_DISTshipsAGENTS.mdandCLAUDE.md.Add CONTRIBUTING.md: wolfSSL's shared contributor guide, without the Jenkins andwolfSSL-Botparagraphs since wolfCert's CI is GitHub Actions only, plus a "wolfCert Specifics" section with the project rules and the full Zephyr board checklist.AGENTS.mdpoints contributors at it.Notes for reviewers
dev_id. Today they export the private key instead (wolfSSL_CTX_use_PrivateKey_bufferinsrc/http.c,wolfcert_key_to_pemin EST reenroll,rsa_key_to_derin the SCEP client). A follow-up PR fixes the code to match, so this PR leaves that paragraph alone.Tests
wolfcert/client.hand one field comment inwolfcert/types.h. A-DWOLFCERT_WERROR=ONbuild against wolfSSL 5.9.4 has no warnings, and ctest passes 30/30.make distships every Markdown file the other docs reference, apart from the gitignored*.local.mdfiles andexamples/certs/README.md(the tarball has never includedexamples/certs/).verify_serverwording was checked by running withverify_server = 0: EST get_ca and SCEP GetCACert overhttps://returnWOLFCERT_ERR_TLS(-5) before connecting, and SCEP overhttp://passes the check.AGENTS.mdwas compiled as written and run against a localwolfcert-server --proto est. It enrolls, and fails withASN_NO_SIGNER_E(-188) when given the wrong trust anchor.