mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-02 03:00:34 +03:00
feat(secure_boot): adds api to verify data partition integrity
Closes https://github.com/espressif/esp-idf/issues/17482
This commit is contained in:
@@ -6,10 +6,15 @@ include($ENV{IDF_PATH}/tools/cmake/project.cmake)
|
||||
project(partitions_ota)
|
||||
|
||||
# Copy storage.bin from test folder to build directory
|
||||
if(CONFIG_SECURE_SIGNED_DATA_PARTITION)
|
||||
set(storage_file signed_storage.bin)
|
||||
else()
|
||||
set(storage_file storage.bin)
|
||||
endif()
|
||||
add_custom_target(copy_storage_bin ALL
|
||||
COMMAND ${CMAKE_COMMAND} -E copy
|
||||
${CMAKE_SOURCE_DIR}/test/storage.bin
|
||||
${CMAKE_BINARY_DIR}/storage.bin
|
||||
COMMENT "Copying test/storage.bin to build directory"
|
||||
DEPENDS ${CMAKE_SOURCE_DIR}/test/storage.bin
|
||||
${CMAKE_SOURCE_DIR}/test/${storage_file}
|
||||
${CMAKE_BINARY_DIR}/${storage_file}
|
||||
COMMENT "Copying test/${storage_file} to build directory"
|
||||
DEPENDS ${CMAKE_SOURCE_DIR}/test/${storage_file}
|
||||
)
|
||||
|
||||
@@ -209,14 +209,19 @@ static esp_err_t ota_update_partitions(esp_https_ota_config_t *ota_config)
|
||||
}
|
||||
|
||||
} else if (strstr(ota_config->http_config->url, "storage.bin") != NULL) {
|
||||
#if CONFIG_SECURE_SIGNED_DATA_PARTITION
|
||||
ota_config->partition.staging = esp_partition_find_first(ESP_PARTITION_TYPE_DATA, ESP_PARTITION_SUBTYPE_ANY, "staging");
|
||||
assert(ota_config->partition.staging != NULL);
|
||||
#else
|
||||
ota_config->partition.staging = NULL; // free app ota partition will be selected and used for downloading a new image
|
||||
#endif // SECURE_SIGNED_DATA_PARTITION
|
||||
ota_config->partition.final = esp_partition_find_first(ESP_PARTITION_TYPE_DATA, ESP_PARTITION_SUBTYPE_ANY, "storage");
|
||||
assert(ota_config->partition.final != NULL);
|
||||
ota_config->partition.finalize_with_copy = true; // After the download is complete, copy the received image to the final partition automatically
|
||||
ret = esp_https_ota(ota_config);
|
||||
char text[16];
|
||||
char text[16] = {0};
|
||||
ESP_ERROR_CHECK(esp_partition_read(ota_config->partition.final, 0, text, sizeof(text)));
|
||||
ESP_LOG_BUFFER_CHAR(TAG, text, sizeof(text));
|
||||
ESP_LOG_BUFFER_HEXDUMP(TAG, text, sizeof(text), ESP_LOG_INFO);
|
||||
assert(memcmp("7296406769363431", text, sizeof(text)) == 0);
|
||||
|
||||
} else {
|
||||
|
||||
@@ -97,7 +97,7 @@ def test_examples_partitions_ota(dut: Dut) -> None:
|
||||
dut.serial.bootloader_flash()
|
||||
print(' - Start app (flash partition_table and app)')
|
||||
dut.serial.write_flash_no_enc()
|
||||
update_partitions(dut, 'wifi_high_traffic')
|
||||
update_partitions(dut, 'wifi_high_traffic', False)
|
||||
|
||||
|
||||
@pytest.mark.flash_encryption_wifi_high_traffic
|
||||
@@ -109,19 +109,32 @@ def test_examples_partitions_ota(dut: Dut) -> None:
|
||||
def test_examples_partitions_ota_with_flash_encryption_wifi(dut: Dut) -> None:
|
||||
dut.serial.erase_flash()
|
||||
dut.serial.flash()
|
||||
update_partitions(dut, 'flash_encryption_wifi_high_traffic')
|
||||
update_partitions(dut, 'flash_encryption_wifi_high_traffic', False)
|
||||
|
||||
|
||||
def update_partitions(dut: Dut, env_name: str | None) -> None:
|
||||
@pytest.mark.flash_encryption_wifi_high_traffic
|
||||
@pytest.mark.parametrize('config', ['flash_enc_wifi_2.data_partition_verification'], indirect=True)
|
||||
@pytest.mark.parametrize('skip_autoflash', ['y'], indirect=True)
|
||||
@idf_parametrize('target', ['esp32', 'esp32c3'], indirect=['target'])
|
||||
def test_examples_partitions_ota_with_flash_enc_wifi_2_data_partition_verification(dut: Dut) -> None:
|
||||
dut.serial.erase_flash()
|
||||
dut.serial.flash()
|
||||
update_partitions(dut, 'flash_encryption_wifi_high_traffic', True)
|
||||
|
||||
|
||||
def update_partitions(dut: Dut, env_name: str | None, signed_storage: bool | None) -> None:
|
||||
port = 8000
|
||||
thread1 = multiprocessing.Process(target=start_https_server, args=(dut.app.binary_path, '0.0.0.0', port))
|
||||
thread1.daemon = True
|
||||
thread1.start()
|
||||
try:
|
||||
if signed_storage:
|
||||
update(dut, port, 'signed_storage.bin', env_name)
|
||||
else:
|
||||
update(dut, port, 'storage.bin', env_name)
|
||||
update(dut, port, 'partitions_ota.bin', env_name)
|
||||
update(dut, port, 'bootloader/bootloader.bin', env_name)
|
||||
update(dut, port, 'partition_table/partition-table.bin', env_name)
|
||||
update(dut, port, 'storage.bin', env_name)
|
||||
finally:
|
||||
thread1.terminate()
|
||||
|
||||
|
||||
+32
@@ -0,0 +1,32 @@
|
||||
# Common configs
|
||||
CONFIG_EXAMPLE_WIFI_SSID_PWD_FROM_STDIN=y
|
||||
CONFIG_EXAMPLE_FIRMWARE_UPGRADE_URL="FROM_STDIN"
|
||||
CONFIG_EXAMPLE_SKIP_COMMON_NAME_CHECK=y
|
||||
CONFIG_EXAMPLE_FIRMWARE_UPGRADE_BIND_IF=y
|
||||
|
||||
CONFIG_MBEDTLS_TLS_CLIENT_ONLY=y
|
||||
CONFIG_COMPILER_OPTIMIZATION_SIZE=y
|
||||
CONFIG_EXAMPLE_CONNECT_IPV6=n
|
||||
|
||||
CONFIG_SECURE_FLASH_ENC_ENABLED=y
|
||||
CONFIG_SECURE_FLASH_ENCRYPTION_MODE_DEVELOPMENT=y
|
||||
CONFIG_SECURE_BOOT_ALLOW_ROM_BASIC=y
|
||||
CONFIG_SECURE_BOOT_ALLOW_JTAG=y
|
||||
CONFIG_SECURE_FLASH_UART_BOOTLOADER_ALLOW_ENC=y
|
||||
CONFIG_SECURE_FLASH_UART_BOOTLOADER_ALLOW_DEC=y
|
||||
CONFIG_SECURE_FLASH_UART_BOOTLOADER_ALLOW_CACHE=y
|
||||
CONFIG_SECURE_FLASH_REQUIRE_ALREADY_ENABLED=y
|
||||
CONFIG_NVS_SEC_KEY_PROTECT_USING_FLASH_ENC=y
|
||||
|
||||
# This is required for nvs encryption (which is enabled by default with flash encryption)
|
||||
CONFIG_PARTITION_TABLE_OFFSET=0x9000
|
||||
|
||||
CONFIG_PARTITION_TABLE_CUSTOM=y
|
||||
CONFIG_PARTITION_TABLE_CUSTOM_FILENAME="test/partitions_efuse_emul_4.csv"
|
||||
|
||||
CONFIG_SECURE_SIGNED_APPS_NO_SECURE_BOOT=y
|
||||
CONFIG_SECURE_SIGNED_ON_UPDATE_NO_SECURE_BOOT=y
|
||||
CONFIG_SECURE_SIGNED_APPS_RSA_SCHEME=y
|
||||
CONFIG_SECURE_BOOT_SIGNING_KEY="test/secure_boot_signing_key.pem"
|
||||
CONFIG_SECURE_BOOT_ALLOW_SHORT_APP_PARTITION=y
|
||||
CONFIG_SECURE_SIGNED_DATA_PARTITION=y
|
||||
+3
@@ -0,0 +1,3 @@
|
||||
# ESP32 supports SECURE_BOOT_V2 only in ECO3
|
||||
CONFIG_IDF_TARGET="esp32"
|
||||
CONFIG_ESP32_REV_MIN_3=y
|
||||
@@ -0,0 +1,10 @@
|
||||
# Name, Type, SubType, Offset, Size, Flags
|
||||
nvs, data, nvs, , 0x6000,
|
||||
nvs_key, data, nvs_keys, , 4K,
|
||||
staging, data, , , 0x4000,
|
||||
storage, data, , , 0x4000, encrypted
|
||||
otadata, data, ota, , 0x2000,
|
||||
phy_init, data, phy, , 0x1000,
|
||||
emul_efuse, data, efuse, , 0x2000,
|
||||
ota_0, app, ota_0, , 0x1B0000,
|
||||
ota_1, app, ota_1, , 0x1B0000,
|
||||
|
Binary file not shown.
Reference in New Issue
Block a user