Merge branch 'fix/secure_boot_bootloader_ecdsa_range_gate_v6.1' into 'release/v6.1'

Add ECDSA signature bounds check in bootloader before Secure Boot verify (v6.1)

See merge request espressif/esp-idf!49632
This commit is contained in:
Mahavir Jain
2026-06-30 07:15:59 +05:30
40 changed files with 349 additions and 48 deletions
@@ -0,0 +1,3 @@
# Increasing TEE IRAM size
# 38KB
CONFIG_SECURE_TEE_IRAM_SIZE=0x9800
@@ -2,8 +2,8 @@
# builds across various configurations - and is not intended for production use.
# Reducing TEE IRAM size
# 29KB
CONFIG_SECURE_TEE_IRAM_SIZE=0x7400
# 29.5KB
CONFIG_SECURE_TEE_IRAM_SIZE=0x7600
# TEE Secure Storage: Release mode
CONFIG_SECURE_TEE_SEC_STG_MODE_RELEASE=y
@@ -2,8 +2,8 @@
# builds across various configurations - and is not intended for production use.
# Increasing TEE I/DRAM sizes
# 34KB
CONFIG_SECURE_TEE_IRAM_SIZE=0x8800
# 38KB
CONFIG_SECURE_TEE_IRAM_SIZE=0x9800
# 22KB
CONFIG_SECURE_TEE_DRAM_SIZE=0x5800
@@ -16,3 +16,7 @@ CONFIG_SECURE_TEE_ATT_KEY_STR_ID="tee_att_keyN"
# Enabling flash protection over SPI1
CONFIG_SECURE_TEE_EXT_FLASH_MEMPROT_SPI1=y
# Increasing TEE IRAM size
# 38KB
CONFIG_SECURE_TEE_IRAM_SIZE=0x9800