Merge branch 'fix/ecdsa_ecc_hw_input_validation' into 'master'

Validate ECDSA signature range and harden ECC memory power-down

See merge request espressif/esp-idf!48958
This commit is contained in:
Mahavir Jain
2026-06-09 14:40:24 +05:30
47 changed files with 427 additions and 61 deletions
@@ -71,6 +71,10 @@ config ESP_ROM_RAM_APP_NEEDS_MMU_INIT
bool
default y
config ESP_ROM_ECDSA_VERIFY_PATCH
bool
default y
config ESP_ROM_BOOTLOADER_OFFSET_FLASH
hex
default 0x2000
@@ -23,5 +23,6 @@
#define ESP_ROM_USB_OTG_NUM (-1) // No USB_OTG CDC in the ROM, set -1 for Kconfig usage.
#define ESP_ROM_WDT_INIT_PATCH (1) // ROM version does not configure the clock
#define ESP_ROM_RAM_APP_NEEDS_MMU_INIT (1) // ROM doesn't init cache MMU when it's a RAM APP, needs MMU hal to init
#define ESP_ROM_ECDSA_VERIFY_PATCH (1) // ROM ets_ecdsa_verify API requires a software patch
#define ESP_ROM_BOOTLOADER_OFFSET_FLASH (0x2000) // Bootloader offset in flash determined by the ROM bootloader
#define ESP_ROM_CACHE_WRITEBACK_NEEDS_SYNC_TWICE_NO_MAP (1) // ROM cache writeback related needs patch to avoid sync loss, no map parameter
+1 -1
View File
@@ -385,7 +385,7 @@ esp_rom_recover_key = 0x400007cc;
***************************************/
/* Functions */
ets_ecdsa_verify = 0x400007d0;
_rom_ets_ecdsa_verify = 0x400007d0;
ets_secure_boot_verify_bootloader_with_keys = 0x400007d4;
ets_secure_boot_verify_signature = 0x400007d8;
ets_secure_boot_read_key_digests = 0x400007dc;