From f7b8db2f2fb0d90cc7a714f3bc915e0b32593f4b Mon Sep 17 00:00:00 2001 From: Ashish Sharma Date: Tue, 17 Mar 2026 17:41:36 +0800 Subject: [PATCH] feat(espcoredump): migrate to esp sha256 implementation from mbedtls sha256 --- .../include_core_dump/esp_core_dump_types.h | 7 ++- components/espcoredump/src/core_dump_sha.c | 16 +++--- components/mbedtls/CMakeLists.txt | 2 +- .../mbedtls/port/include/mbedtls/esp_config.h | 2 +- .../core/psa_crypto_driver_esp_sha256.c | 2 +- .../include/psa_crypto_driver_esp_sha256.h | 2 - .../psa_crypto_driver_esp_sha256.c | 25 +++++++-- .../include/psa_crypto_driver_esp_sha.h | 52 +++++++++++++++++++ 8 files changed, 89 insertions(+), 19 deletions(-) diff --git a/components/espcoredump/include_core_dump/esp_core_dump_types.h b/components/espcoredump/include_core_dump/esp_core_dump_types.h index 2fb6c2bf438..bb4a6c52688 100644 --- a/components/espcoredump/include_core_dump/esp_core_dump_types.h +++ b/components/espcoredump/include_core_dump/esp_core_dump_types.h @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2015-2025 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2015-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -89,9 +89,8 @@ extern "C" { typedef uint32_t core_dump_crc_t; #if CONFIG_IDF_TARGET_ESP32 -#define MBEDTLS_ALLOW_PRIVATE_ACCESS -#include "mbedtls/private/sha256.h" -typedef mbedtls_sha256_context sha256_ctx_t; +#include "psa_crypto_driver_esp_sha_contexts.h" +typedef esp_sha256_context sha256_ctx_t; #else #include "hal/sha_types.h" /* SHA_CTX */ typedef SHA_CTX sha256_ctx_t; diff --git a/components/espcoredump/src/core_dump_sha.c b/components/espcoredump/src/core_dump_sha.c index fd41dfa7a78..5ac04de8c4b 100644 --- a/components/espcoredump/src/core_dump_sha.c +++ b/components/espcoredump/src/core_dump_sha.c @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2024-2025 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2024-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -18,22 +18,26 @@ uint32_t esp_core_dump_checksum_size(void) __attribute__((alias("core_dump_sha_s uint32_t esp_core_dump_elf_version(void) __attribute__((alias("core_dump_sha_version"))); #if CONFIG_IDF_TARGET_ESP32 +#include "psa_crypto_driver_esp_sha.h" +#include "hal/sha_types.h" static void core_dump_sha256_start(core_dump_sha_ctx_t *sha_ctx) { - mbedtls_sha256_init(&sha_ctx->ctx); - mbedtls_sha256_starts(&sha_ctx->ctx, false); + esp_sha256_starts(&sha_ctx->ctx, SHA2_256); + /* Coredump runs from a panic context, so the SHA HW engine and its + * FreeRTOS-based locks must not be used. Pin the context to software + * mode here so subsequent update/finish calls cannot enter the HW path. */ + sha_ctx->ctx.operation_mode = ESP_SHA_MODE_SOFTWARE; } static void core_dump_sha256_update(core_dump_sha_ctx_t *sha_ctx, const void *data, size_t data_len) { - mbedtls_sha256_update(&sha_ctx->ctx, data, data_len); + esp_sha256_update(&sha_ctx->ctx, data, data_len); } static void core_dump_sha256_finish(core_dump_sha_ctx_t *sha_ctx) { - mbedtls_sha256_finish(&sha_ctx->ctx, sha_ctx->result); - mbedtls_sha256_free(&sha_ctx->ctx); + esp_sha256_finish(&sha_ctx->ctx, sha_ctx->result); } #else diff --git a/components/mbedtls/CMakeLists.txt b/components/mbedtls/CMakeLists.txt index 209313ff087..27fcd277c23 100644 --- a/components/mbedtls/CMakeLists.txt +++ b/components/mbedtls/CMakeLists.txt @@ -397,7 +397,6 @@ if(CONFIG_SOC_SHA_SUPPORTED) if(CONFIG_MBEDTLS_HARDWARE_SHA) target_sources(tfpsacrypto PRIVATE "${COMPONENT_DIR}/port/psa_driver/esp_sha/psa_crypto_driver_esp_sha.c" - "${COMPONENT_DIR}/port/psa_driver/esp_sha/${SHA_PERIPHERAL_TYPE}/psa_crypto_driver_esp_sha256.c" "${COMPONENT_DIR}/port/psa_driver/esp_sha/${SHA_PERIPHERAL_TYPE}/psa_crypto_driver_esp_sha512.c" "${COMPONENT_DIR}/port/sha/esp_sha.c" "${COMPONENT_DIR}/port/psa_driver/esp_mac/psa_crypto_driver_esp_hmac_transparent.c" @@ -405,6 +404,7 @@ if(CONFIG_SOC_SHA_SUPPORTED) endif() target_sources(tfpsacrypto PRIVATE "${COMPONENT_DIR}/port/psa_driver/esp_sha/${SHA_PERIPHERAL_TYPE}/psa_crypto_driver_esp_sha1.c" + "${COMPONENT_DIR}/port/psa_driver/esp_sha/${SHA_PERIPHERAL_TYPE}/psa_crypto_driver_esp_sha256.c" "${COMPONENT_DIR}/port/sha/${SHA_PERIPHERAL_TYPE}/sha.c" ) endif() diff --git a/components/mbedtls/port/include/mbedtls/esp_config.h b/components/mbedtls/port/include/mbedtls/esp_config.h index 596a30faddb..a1c64d8697e 100644 --- a/components/mbedtls/port/include/mbedtls/esp_config.h +++ b/components/mbedtls/port/include/mbedtls/esp_config.h @@ -204,6 +204,7 @@ #if SOC_SHA_SUPPORT_SHA256 #define MBEDTLS_PSA_ACCEL_ALG_SHA_256 #undef MBEDTLS_PSA_BUILTIN_ALG_SHA_256 + #undef MBEDTLS_SHA256_C #endif // SOC_SHA_SUPPORT_SHA256 #if SOC_SHA_SUPPORT_SHA512 #define MBEDTLS_PSA_ACCEL_ALG_SHA_512 @@ -2629,7 +2630,6 @@ * This module is required for the SSL/TLS 1.2 PRF function. */ #ifdef CONFIG_MBEDTLS_SHA256_C -#define MBEDTLS_SHA256_C #define PSA_WANT_ALG_SHA_256 1 #define PSA_WANT_ALG_SHA_224 1 #else diff --git a/components/mbedtls/port/psa_driver/esp_sha/core/psa_crypto_driver_esp_sha256.c b/components/mbedtls/port/psa_driver/esp_sha/core/psa_crypto_driver_esp_sha256.c index e393c62e50f..535338bbbe8 100644 --- a/components/mbedtls/port/psa_driver/esp_sha/core/psa_crypto_driver_esp_sha256.c +++ b/components/mbedtls/port/psa_driver/esp_sha/core/psa_crypto_driver_esp_sha256.c @@ -53,7 +53,7 @@ static void esp_internal_sha_update_state(esp_sha256_context *ctx) } static int esp_sha256_update(esp_sha256_context *ctx, const unsigned char *input, - size_t ilen) + size_t ilen) { size_t fill, left, len; uint32_t local_len = 0; diff --git a/components/mbedtls/port/psa_driver/esp_sha/include/psa_crypto_driver_esp_sha256.h b/components/mbedtls/port/psa_driver/esp_sha/include/psa_crypto_driver_esp_sha256.h index bb55425054c..330c4c139a5 100644 --- a/components/mbedtls/port/psa_driver/esp_sha/include/psa_crypto_driver_esp_sha256.h +++ b/components/mbedtls/port/psa_driver/esp_sha/include/psa_crypto_driver_esp_sha256.h @@ -7,7 +7,6 @@ #pragma once -#if defined(ESP_SHA_DRIVER_ENABLED) #include #include @@ -42,4 +41,3 @@ psa_status_t esp_sha256_driver_finish( psa_status_t esp_sha256_driver_abort(esp_sha256_context *ctx); psa_status_t esp_sha256_driver_clone(const esp_sha256_context *source_ctx, esp_sha256_context *target_ctx); -#endif /* ESP_SHA_DRIVER_ENABLED */ diff --git a/components/mbedtls/port/psa_driver/esp_sha/parallel_engine/psa_crypto_driver_esp_sha256.c b/components/mbedtls/port/psa_driver/esp_sha/parallel_engine/psa_crypto_driver_esp_sha256.c index b7119f9be5c..2e29eebb8de 100644 --- a/components/mbedtls/port/psa_driver/esp_sha/parallel_engine/psa_crypto_driver_esp_sha256.c +++ b/components/mbedtls/port/psa_driver/esp_sha/parallel_engine/psa_crypto_driver_esp_sha256.c @@ -45,12 +45,16 @@ psa_status_t esp_sha256_driver_clone(const esp_sha256_context *source_ctx, esp_s return PSA_ERROR_INVALID_ARGUMENT; } memcpy(target_ctx, source_ctx, sizeof(esp_sha256_context)); +#ifdef MBEDTLS_PSA_ACCEL_ALG_SHA_256 // If the source context is in hardware mode, we need to read the digest state // from the hardware engine to ensure the target context has the correct state if (source_ctx->operation_mode == ESP_SHA_MODE_HARDWARE) { esp_sha_read_digest_state(SHA2_256, target_ctx->state); target_ctx->operation_mode = ESP_SHA_MODE_SOFTWARE; // Cloned context operates in software mode } +#else + target_ctx->operation_mode = ESP_SHA_MODE_SOFTWARE; +#endif // MBEDTLS_PSA_ACCEL_ALG_SHA_256 return PSA_SUCCESS; } @@ -83,9 +87,11 @@ psa_status_t esp_sha256_starts(esp_sha256_context *ctx, int mode) } ctx->mode = mode; +#ifdef MBEDTLS_PSA_ACCEL_ALG_SHA_256 if (ctx->operation_mode == ESP_SHA_MODE_HARDWARE) { esp_sha_unlock_engine(SHA2_256); } +#endif // MBEDTLS_PSA_ACCEL_ALG_SHA_256 ctx->operation_mode = ESP_SHA_MODE_UNUSED; return PSA_SUCCESS; } @@ -196,6 +202,7 @@ static void esp_sha256_software_process(esp_sha256_context *ctx, const unsigned } static int esp_internal_sha256_parallel_engine_process(esp_sha256_context *ctx, const unsigned char data[64], bool read_digest) { +#ifdef MBEDTLS_PSA_ACCEL_ALG_SHA_256 bool first_block = false; if (ctx->operation_mode == ESP_SHA_MODE_UNUSED) { @@ -220,7 +227,9 @@ static int esp_internal_sha256_parallel_engine_process(esp_sha256_context *ctx, } else { esp_sha256_software_process(ctx, data); } - +#else + esp_sha256_software_process(ctx, data); +#endif // MBEDTLS_PSA_ACCEL_ALG_SHA_256 return 0; } @@ -229,8 +238,8 @@ int esp_internal_sha256_process( esp_sha256_context *ctx, const unsigned char da return esp_internal_sha256_parallel_engine_process(ctx, data, true); } -static int esp_sha256_update(esp_sha256_context *ctx, const unsigned char *input, - size_t ilen) +int esp_sha256_update(esp_sha256_context *ctx, const unsigned char *input, + size_t ilen) { int ret = -1; size_t fill; @@ -271,9 +280,11 @@ static int esp_sha256_update(esp_sha256_context *ctx, const unsigned char *input ilen -= 64; } +#ifdef MBEDTLS_PSA_ACCEL_ALG_SHA_256 if (ctx->operation_mode == ESP_SHA_MODE_HARDWARE) { esp_sha_read_digest_state(SHA2_256, ctx->state); } +#endif // MBEDTLS_PSA_ACCEL_ALG_SHA_256 if ( ilen > 0 ) { memcpy( (void *) (ctx->buffer + left), input, ilen ); @@ -289,7 +300,7 @@ static const unsigned char sha256_padding[64] = { 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0 }; -static int esp_sha256_finish(esp_sha256_context *ctx, unsigned char *output) +int esp_sha256_finish(esp_sha256_context *ctx, unsigned char *output) { int ret = -1; uint32_t last, padn; @@ -314,9 +325,11 @@ static int esp_sha256_finish(esp_sha256_context *ctx, unsigned char *output) goto out; } +#ifdef MBEDTLS_PSA_ACCEL_ALG_SHA_256 if (ctx->operation_mode == ESP_SHA_MODE_HARDWARE) { esp_sha_read_digest_state(SHA2_256, ctx->state); } +#endif // MBEDTLS_PSA_ACCEL_ALG_SHA_256 PUT_UINT32_BE( ctx->state[0], output, 0 ); PUT_UINT32_BE( ctx->state[1], output, 4 ); @@ -340,10 +353,12 @@ static int esp_sha256_finish(esp_sha256_context *ctx, unsigned char *output) out: +#ifdef MBEDTLS_PSA_ACCEL_ALG_SHA_256 if (ctx->operation_mode == ESP_SHA_MODE_HARDWARE) { esp_sha_unlock_engine(SHA2_256); ctx->operation_mode = ESP_SHA_MODE_SOFTWARE; } +#endif // MBEDTLS_PSA_ACCEL_ALG_SHA_256 return ret; } @@ -448,11 +463,13 @@ psa_status_t esp_sha256_driver_abort(esp_sha256_context *ctx) if (!ctx) { return PSA_ERROR_INVALID_ARGUMENT; } +#ifdef MBEDTLS_PSA_ACCEL_ALG_SHA_256 // Also unlock the hardware engine if it was in use if (ctx->operation_mode == ESP_SHA_MODE_HARDWARE) { esp_sha_unlock_engine(SHA2_256); ctx->operation_mode = ESP_SHA_MODE_SOFTWARE; } +#endif // MBEDTLS_PSA_ACCEL_ALG_SHA_256 mbedtls_platform_zeroize(ctx, sizeof(esp_sha256_context)); return PSA_SUCCESS; } diff --git a/components/mbedtls/port/psa_driver/include/psa_crypto_driver_esp_sha.h b/components/mbedtls/port/psa_driver/include/psa_crypto_driver_esp_sha.h index 8901ec7fd67..4ca6c36d682 100644 --- a/components/mbedtls/port/psa_driver/include/psa_crypto_driver_esp_sha.h +++ b/components/mbedtls/port/psa_driver/include/psa_crypto_driver_esp_sha.h @@ -7,6 +7,7 @@ #include "psa/crypto.h" #include "psa_crypto_driver_esp_sha_contexts.h" +#include "soc/soc_caps.h" #ifdef __cplusplus extern "C" { @@ -62,6 +63,57 @@ int esp_internal_sha512_process( esp_sha512_context *ctx, const unsigned char da int esp_sha1_starts(esp_sha1_context *ctx); int esp_sha1_update(esp_sha1_context *ctx, const unsigned char *input, size_t ilen); int esp_sha1_finish(esp_sha1_context *ctx, uint8_t *output); + +/** + * @brief Direct (non-PSA) entry points to the parallel-engine SHA-256 driver. + * + * @note These declarations are intentionally restricted to targets that use + * the parallel-engine peripheral (currently only ESP32). On targets + * using the "core" SHA peripheral the equivalent functions are kept + * static inside the driver, since the PSA dispatcher and ROM SHA + * cover all in-tree consumers. + * + * @note These bypass PSA. They exist for special callers — most notably + * espcoredump — that must run from a panic context where the PSA + * code path's malloc / FreeRTOS-locked HW engine is unsafe. Such + * callers are expected to set @c operation_mode to + * @c ESP_SHA_MODE_SOFTWARE on the context immediately after + * @c esp_sha256_starts so that subsequent calls never enter the + * hardware path. Regular consumers should keep using the PSA API. + */ +#if CONFIG_SOC_SHA_SUPPORT_PARALLEL_ENG || __DOXYGEN__ +/** + * @brief Initialise an esp_sha256_context for a new SHA-224/256 digest. + * + * @param ctx Context to initialise. Must be non-NULL. + * @param mode Either @c SHA2_224 or @c SHA2_256 (from @c hal/sha_types.h). + * + * @return @c PSA_SUCCESS on success. + */ +psa_status_t esp_sha256_starts(esp_sha256_context *ctx, int mode); + +/** + * @brief Feed input bytes into a SHA-224/256 digest in progress. + * + * @param ctx Previously started context. + * @param input Input buffer; may be NULL only if @p ilen is 0. + * @param ilen Number of bytes to absorb. + * + * @return 0 on success, negative on internal error. + */ +int esp_sha256_update(esp_sha256_context *ctx, const unsigned char *input, size_t ilen); + +/** + * @brief Finalise the digest and write the output. + * + * @param ctx Context that has been started and (optionally) updated. + * @param output Buffer for the final digest. Must be at least 28 bytes + * for SHA-224 or 32 bytes for SHA-256. + * + * @return 0 on success, negative on internal error. + */ +int esp_sha256_finish(esp_sha256_context *ctx, unsigned char *output); +#endif /* CONFIG_SOC_SHA_SUPPORT_PARALLEL_ENG */ #ifdef __cplusplus } #endif