fix(esp_security): harden crypto peripheral error handling

This commit is contained in:
Ashish Sharma
2026-06-19 18:27:22 +08:00
parent 2573bf3988
commit 1b8a365f16
4 changed files with 41 additions and 12 deletions
+8 -6
View File
@@ -539,12 +539,6 @@ static esp_err_t key_mgr_recover_key(key_recovery_config_t *config)
key_mgr_hal_set_xts_aes_key_len(key_type, key_len);
}
key_mgr_hal_set_key_purpose(config->key_purpose);
key_mgr_hal_start();
key_mgr_wait_for_state(ESP_KEY_MGR_STATE_LOAD);
uint8_t key_recovery_info_index = config->multi_stage_deployment ? 1 : 0;
if (!check_key_info_validity(&config->key_recovery_info->key_info[key_recovery_info_index])) {
@@ -552,6 +546,12 @@ static esp_err_t key_mgr_recover_key(key_recovery_config_t *config)
return ESP_FAIL;
}
key_mgr_hal_set_key_purpose(config->key_purpose);
key_mgr_hal_start();
key_mgr_wait_for_state(ESP_KEY_MGR_STATE_LOAD);
key_mgr_hal_write_assist_info(config->key_recovery_info->key_info[key_recovery_info_index].info, KEY_MGR_KEY_RECOVERY_INFO_SIZE);
key_mgr_hal_continue();
key_mgr_wait_for_state(ESP_KEY_MGR_STATE_GAIN);
@@ -562,6 +562,8 @@ static esp_err_t key_mgr_recover_key(key_recovery_config_t *config)
if (!multi_stage_deployment_key_purpose(config->key_purpose)) {
if (!key_mgr_hal_is_key_deployment_valid(key_type, key_len)) {
ESP_LOGD(TAG, "Key deployment is not valid");
key_mgr_hal_continue();
key_mgr_wait_for_state(ESP_KEY_MGR_STATE_IDLE);
return ESP_FAIL;
}
}