Merge branch 'feat/bootloader-mbedtls-split-final' into 'master'

feat(esp_image_verify): split image verification out of bootloader_support

Closes IDF-8577 and IDFGH-17033

See merge request espressif/esp-idf!48383
This commit is contained in:
Mahavir Jain
2026-08-13 08:45:58 +05:30
72 changed files with 716 additions and 536 deletions
+1 -1
View File
@@ -235,7 +235,7 @@ The verification of signed OTA updates can be performed even without enabling ha
Signed Data Partition Updates
------------------------------
Data partition images can be verified using the same Secure Boot v2 signature mechanism as application images. Enable :menuitem:`CONFIG_SECURE_SIGNED_DATA_PARTITION` to verify data partitions with subtype ``ESP_PARTITION_SUBTYPE_DATA_UNDEFINED`` during OTA updates.
Data partition images can be verified using the same Secure Boot v2 signature mechanism as application images. Enable :menuitem:`CONFIG_APP_UPDATE_SECURE_SIGNED_DATA_PARTITION` to verify data partitions with subtype ``ESP_PARTITION_SUBTYPE_DATA_UNDEFINED`` during OTA updates.
Sign data partition images using:
@@ -13,3 +13,17 @@ A PMP entry locked by the bootloader cannot be reconfigured until the next CPU r
Applications built with ESP-IDF are not affected, as they program and lock the full PMP configuration themselves during startup, before any application code runs.
Custom (non-ESP-IDF) applications launched by the ESP-IDF second stage bootloader must not assume that any PMP entries are pre-configured or locked at handoff. Previously, the bootloader configured and locked entries covering, e.g., the ROM and the peripheral address spaces; such applications must now program their own PMP configuration.
Image verification split out of ``bootloader_support``
------------------------------------------------------
Image verification and secure-boot signature checking moved from
``bootloader_support`` into the new ``esp_image_verify`` component. ``bootloader_support`` no longer depends on ``mbedtls``.
- Components that relied on ``bootloader_support`` transitively providing ``mbedtls`` or ``app_update`` must now declare those dependencies explicitly in their ``PRIV_REQUIRES`` / ``REQUIRES``.
- :cpp:func:`bootloader_common_get_sha256_of_partition` is deprecated. Use :cpp:func:`esp_partition_get_sha256` instead.
- In builds that do not include the ``esp_image_verify`` component (no OTA or signed-image features), calling :cpp:func:`esp_partition_get_sha256` or the deprecated function above fails at link time with an undefined reference to ``esp_image_get_metadata`` / ``bootloader_sha256_flash_contents``. Add ``esp_image_verify`` (or ``app_update``, which includes it and provides the OTA APIs) to the calling component's ``PRIV_REQUIRES`` or to the project's ``COMPONENTS`` list.
- Builds enabling :ref:`CONFIG_SECURE_SIGNED_ON_UPDATE_NO_SECURE_BOOT` must include the ``esp_image_verify`` component, which provides the startup check that verifies the running app's signature.
Apps using OTA get it automatically through ``app_update``; apps that trim the component graph (e.g. ``MINIMAL_BUILD``) must add ``esp_image_verify`` (or ``app_update``) to a ``PRIV_REQUIRES`` list or the project ``COMPONENTS``. Such builds fail with a ``#error`` instead of silently skipping the configured check.
- The Kconfig option ``CONFIG_SECURE_SIGNED_DATA_PARTITION`` was renamed to ``CONFIG_APP_UPDATE_SECURE_SIGNED_DATA_PARTITION`` (old name still accepted via ``sdkconfig.rename``).
+1 -1
View File
@@ -420,7 +420,7 @@ An image is verified if the public key stored in any signature block is valid fo
Verifying Data Partitions
--------------------------
The Secure Boot v2 signature verification can also verify data partition images during OTA updates. Enable :menuitem:`CONFIG_SECURE_SIGNED_DATA_PARTITION` to verify data partitions with subtype ``ESP_PARTITION_SUBTYPE_DATA_UNDEFINED``.
The Secure Boot v2 signature verification can also verify data partition images during OTA updates. Enable :menuitem:`CONFIG_APP_UPDATE_SECURE_SIGNED_DATA_PARTITION` to verify data partitions with subtype ``ESP_PARTITION_SUBTYPE_DATA_UNDEFINED``.
Data partition images must be signed using ``idf.py secure-sign-data`` with the same signing key and follow the same format as application images. The verification uses the public key digest(s) stored in eFuse and follows the process described in :ref:`verify_image`.