mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-02 11:10:54 +03:00
fix(esp-tls): replace deprecated pk_ctx with PSA equivalent
This commit is contained in:
@@ -493,59 +493,37 @@ void esp_mbedtls_cleanup(esp_tls_t *tls)
|
||||
mbedtls_x509_crt_free(&tls->cacert);
|
||||
mbedtls_x509_crt_free(&tls->clientcert);
|
||||
|
||||
/* For opaque keys (DS peripheral, hardware ECDSA), mbedtls_pk_free() does
|
||||
* not destroy the PSA key — ownership is external. Destroy it manually
|
||||
* before calling mbedtls_pk_free(). */
|
||||
#ifdef CONFIG_ESP_TLS_USE_DS_PERIPHERAL
|
||||
if (mbedtls_pk_get_type(&tls->clientkey) == MBEDTLS_PK_RSASSA_PSS) {
|
||||
mbedtls_rsa_context *rsa = tls->clientkey.MBEDTLS_PRIVATE(pk_ctx);
|
||||
if (rsa != NULL) {
|
||||
mbedtls_rsa_free(rsa);
|
||||
mbedtls_free(rsa);
|
||||
rsa = NULL;
|
||||
}
|
||||
if (tls->clientkey.MBEDTLS_PRIVATE(priv_id) != PSA_KEY_ID_NULL) {
|
||||
psa_destroy_key(tls->clientkey.MBEDTLS_PRIVATE(priv_id));
|
||||
tls->clientkey.MBEDTLS_PRIVATE(priv_id) = PSA_KEY_ID_NULL;
|
||||
}
|
||||
tls->clientkey.MBEDTLS_PRIVATE(pk_ctx) = NULL;
|
||||
}
|
||||
|
||||
// Similar cleanup for server key
|
||||
if (mbedtls_pk_get_type(&tls->serverkey) == MBEDTLS_PK_RSASSA_PSS) {
|
||||
mbedtls_rsa_context *rsa = tls->serverkey.MBEDTLS_PRIVATE(pk_ctx);
|
||||
if (rsa != NULL) {
|
||||
mbedtls_rsa_free(rsa);
|
||||
mbedtls_free(rsa);
|
||||
rsa = NULL;
|
||||
}
|
||||
if (tls->serverkey.MBEDTLS_PRIVATE(priv_id) != PSA_KEY_ID_NULL) {
|
||||
psa_destroy_key(tls->serverkey.MBEDTLS_PRIVATE(priv_id));
|
||||
tls->serverkey.MBEDTLS_PRIVATE(priv_id) = PSA_KEY_ID_NULL;
|
||||
}
|
||||
tls->serverkey.MBEDTLS_PRIVATE(pk_ctx) = NULL;
|
||||
}
|
||||
#endif
|
||||
|
||||
#ifdef CONFIG_MBEDTLS_HARDWARE_ECDSA_SIGN
|
||||
/* In mbedtls v4.0, ECDSA keys require manual cleanup of the keypair structure */
|
||||
if (mbedtls_pk_get_type(&tls->clientkey) == MBEDTLS_PK_ECDSA) {
|
||||
ESP_LOGD(TAG, "Cleaning up client key");
|
||||
mbedtls_ecp_keypair *keypair = tls->clientkey.MBEDTLS_PRIVATE(pk_ctx);
|
||||
if (keypair != NULL) {
|
||||
mbedtls_ecp_keypair_free(keypair);
|
||||
mbedtls_free(keypair);
|
||||
keypair = NULL;
|
||||
if (tls->clientkey.MBEDTLS_PRIVATE(priv_id) != PSA_KEY_ID_NULL) {
|
||||
psa_destroy_key(tls->clientkey.MBEDTLS_PRIVATE(priv_id));
|
||||
tls->clientkey.MBEDTLS_PRIVATE(priv_id) = PSA_KEY_ID_NULL;
|
||||
}
|
||||
psa_destroy_key(tls->clientkey.MBEDTLS_PRIVATE(priv_id));
|
||||
tls->clientkey.MBEDTLS_PRIVATE(pk_ctx) = NULL;
|
||||
}
|
||||
|
||||
// Similar cleanup for server key
|
||||
if (mbedtls_pk_get_type(&tls->serverkey) == MBEDTLS_PK_ECDSA) {
|
||||
mbedtls_ecp_keypair *keypair = tls->serverkey.MBEDTLS_PRIVATE(pk_ctx);
|
||||
if (keypair != NULL) {
|
||||
mbedtls_ecp_keypair_free(keypair);
|
||||
mbedtls_free(keypair);
|
||||
keypair = NULL;
|
||||
if (tls->serverkey.MBEDTLS_PRIVATE(priv_id) != PSA_KEY_ID_NULL) {
|
||||
psa_destroy_key(tls->serverkey.MBEDTLS_PRIVATE(priv_id));
|
||||
tls->serverkey.MBEDTLS_PRIVATE(priv_id) = PSA_KEY_ID_NULL;
|
||||
}
|
||||
psa_destroy_key(tls->serverkey.MBEDTLS_PRIVATE(priv_id));
|
||||
tls->serverkey.MBEDTLS_PRIVATE(pk_ctx) = NULL;
|
||||
}
|
||||
#endif
|
||||
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2021-2025 Espressif Systems (Shanghai) CO LTD
|
||||
* SPDX-FileCopyrightText: 2021-2026 Espressif Systems (Shanghai) CO LTD
|
||||
*
|
||||
* SPDX-License-Identifier: Apache-2.0
|
||||
*/
|
||||
@@ -16,6 +16,7 @@
|
||||
#endif
|
||||
#include "esp_newlib.h"
|
||||
#include "psa/crypto.h"
|
||||
#include "esp_crypto_lock.h"
|
||||
#if SOC_SHA_SUPPORT_SHA512
|
||||
#define SHA_TYPE SHA2_512
|
||||
#else
|
||||
@@ -59,6 +60,12 @@ void setUp(void)
|
||||
heap_caps_free(buf);
|
||||
psa_destroy_key(key_id);
|
||||
|
||||
// Trigger lazy initialization of the MPI hardware mutex.
|
||||
// In mbedtls 4.x, RSA key parsing goes through PSA which validates
|
||||
// the key using MPI hardware, creating this lock on first use.
|
||||
esp_crypto_mpi_lock_acquire();
|
||||
esp_crypto_mpi_lock_release();
|
||||
|
||||
test_utils_record_free_mem();
|
||||
TEST_ESP_OK(test_utils_set_leak_level(0, ESP_LEAK_TYPE_CRITICAL, ESP_COMP_LEAK_GENERAL));
|
||||
TEST_ESP_OK(test_utils_set_leak_level(0, ESP_LEAK_TYPE_WARNING, ESP_COMP_LEAK_GENERAL));
|
||||
|
||||
@@ -135,7 +135,6 @@ TEST_CASE("esp_tls_server session create delete", "[esp-tls]")
|
||||
TEST_ASSERT_LESS_THAN_INT(0, ret);
|
||||
// free the allocated memory.
|
||||
esp_tls_server_session_delete(tls);
|
||||
|
||||
}
|
||||
#endif /* CONFIG_ESP_TLS_USING_MBEDTLS */
|
||||
|
||||
|
||||
Reference in New Issue
Block a user