fix(esp_security): guard key manager APIs against unsupported chip revs

On ESP32-P4 rev < 3.0, Key Manager is software-disabled, but the public
esp_key_mgr.h APIs had no runtime check.
Calls using HMAC/DS/PSRAM key types fell through to
HAL_ASSERT("Unsupported ...") paths in key_mgr_ll.h. Gate
each public API with key_mgr_ll_is_supported() and return
ESP_ERR_NOT_SUPPORTED cleanly instead.
This commit is contained in:
harshal.patil
2026-04-27 15:18:34 +05:30
parent 41e67e1efb
commit 8bfc4f7255
6 changed files with 72 additions and 5 deletions
@@ -510,6 +510,9 @@ TEST_GROUP(key_manager);
TEST_SETUP(key_manager)
{
if (!key_mgr_ll_is_supported()) {
TEST_IGNORE_MESSAGE("Key Manager not supported on this chip");
}
test_utils_record_free_mem();
TEST_ESP_OK(test_utils_set_leak_level(800, ESP_LEAK_TYPE_CRITICAL, ESP_COMP_LEAK_GENERAL));
}
@@ -109,12 +109,24 @@ def test_ecdsa_key(
raise
@pytest.mark.generic
@pytest.mark.parametrize('config', ['long_aes_operations'], indirect=True)
@idf_parametrize('target', ['supported_targets'], indirect=['target'])
def test_crypto_long_aes_operations(dut: Dut) -> None:
# if the env variable IDF_FPGA_ENV is set, we would need a longer timeout
# as tests for efuses burning security peripherals would be run
timeout = 600 if os.environ.get('IDF_ENV_FPGA') else 60
dut.expect('Tests finished', timeout=timeout)
@pytest.mark.generic
@pytest.mark.parametrize('config', ['long_aes_operations'], indirect=True)
@idf_parametrize('target', ['supported_targets'], indirect=['target'])
def test_crypto_long_aes_operations_generic(dut: Dut) -> None:
test_crypto_long_aes_operations(dut)
@pytest.mark.generic
@pytest.mark.esp32p4_rev1
@pytest.mark.parametrize('config', ['long_aes_operations_esp32p4_rev1'], indirect=True)
@idf_parametrize('target', ['esp32p4'], indirect=['target'])
def test_crypto_long_aes_operations_esp32p4_rev1(dut: Dut) -> None:
test_crypto_long_aes_operations(dut)
@@ -0,0 +1,8 @@
#
# Example Configuration
#
CONFIG_IDF_TARGET="esp32p4"
CONFIG_ESP32P4_SELECTS_REV_LESS_V3=y
CONFIG_CRYPTO_TESTAPP_USE_AES_INTERRUPT=y
# end of Example Configuration