From 65f6668b84935a2295d6a39a55641dfd2c18a07e Mon Sep 17 00:00:00 2001 From: Ashish Sharma Date: Fri, 10 Jul 2026 15:29:42 +0800 Subject: [PATCH 1/3] feat(mbedtls): update to version 3.6.7 --- components/mbedtls/mbedtls | 2 +- docs/en/api-reference/protocols/mbedtls.rst | 2 +- docs/zh_CN/api-reference/protocols/mbedtls.rst | 2 +- 3 files changed, 3 insertions(+), 3 deletions(-) diff --git a/components/mbedtls/mbedtls b/components/mbedtls/mbedtls index 9d669eadb19..64c8e14bffd 160000 --- a/components/mbedtls/mbedtls +++ b/components/mbedtls/mbedtls @@ -1 +1 @@ -Subproject commit 9d669eadb1955d348986b9280156710aaaadf79f +Subproject commit 64c8e14bffd76abaec7a04f9e44aba00a9aad1f5 diff --git a/docs/en/api-reference/protocols/mbedtls.rst b/docs/en/api-reference/protocols/mbedtls.rst index aac8ec8371a..d14e5831d0d 100644 --- a/docs/en/api-reference/protocols/mbedtls.rst +++ b/docs/en/api-reference/protocols/mbedtls.rst @@ -118,5 +118,5 @@ Reducing Binary Size Under ``Component Config -> mbedTLS``, there are multiple Mbed TLS features which are enabled by default but can be disabled if not needed to save code size. More information can be about this can be found in :ref:`Minimizing Binary Size ` docs. -.. _`API Reference`: https://mbed-tls.readthedocs.io/projects/api/en/v3.6.6/ +.. _`API Reference`: https://mbed-tls.readthedocs.io/projects/api/en/v3.6.7/ .. _`Knowledge Base`: https://mbed-tls.readthedocs.io/en/latest/kb/ diff --git a/docs/zh_CN/api-reference/protocols/mbedtls.rst b/docs/zh_CN/api-reference/protocols/mbedtls.rst index f1a16383746..4c201e20bde 100644 --- a/docs/zh_CN/api-reference/protocols/mbedtls.rst +++ b/docs/zh_CN/api-reference/protocols/mbedtls.rst @@ -118,5 +118,5 @@ ESP-IDF 中的示例使用 :doc:`/api-reference/protocols/esp_tls`,为访问 在 ``Component Config -> mbedTLS`` 中,有多个 Mbed TLS 功能默认为启用状态。如果不需要这些功能,可将其禁用以减小固件大小。要了解更多信息,请参考 :ref:`Minimizing Binary Size ` 文档。 -.. _`API Reference`: https://mbed-tls.readthedocs.io/projects/api/en/v3.6.6/ +.. _`API Reference`: https://mbed-tls.readthedocs.io/projects/api/en/v3.6.7/ .. _`Knowledge Base`: https://mbed-tls.readthedocs.io/en/latest/kb/ From 2064a698eaa29cb5c63a69ca260ae1f7a51fe6c1 Mon Sep 17 00:00:00 2001 From: Ashish Sharma Date: Tue, 14 Jul 2026 15:55:26 +0800 Subject: [PATCH 2/3] feat(mbedtls): add option to choose constant-time prime generation --- components/mbedtls/Kconfig | 25 +++++++++++++++++++ components/mbedtls/mbedtls | 2 +- .../mbedtls/port/include/mbedtls/esp_config.h | 11 ++++++++ components/mbedtls/test_apps/main/test_rsa.c | 9 ++++++- 4 files changed, 45 insertions(+), 2 deletions(-) diff --git a/components/mbedtls/Kconfig b/components/mbedtls/Kconfig index 899ad410a9d..38bd1e9086d 100644 --- a/components/mbedtls/Kconfig +++ b/components/mbedtls/Kconfig @@ -540,6 +540,31 @@ menu "mbedTLS" priority level and any level from 1 to 3 can be selected (based on the availability). Note: Higher value indicates high interrupt priority. + menu "Security hardening" + + config MBEDTLS_CONSTANT_TIME_PRIME_GEN + bool "Constant-time prime generation" + default y + help + Use mbedtls' constant-time small-factor test (a constant-time + GCD against the product of all odd primes up to 997) when + generating prime numbers, e.g. during RSA key generation. + + The constant-time implementation avoids a timing side channel + in prime generation, but it makes RSA key generation roughly + ten times slower, and its long non-yielding software + computations can starve the idle task and trigger the task + watchdog, so key generation code may need a larger watchdog + timeout or the watchdog disabled. + + If disabled, the variable-time trial division that mbedtls + used before version 3.6.7 is used instead, restoring key + generation performance. Only consider disabling this if no + untrusted code running on the device could observe the timing + of key generation operations. + + endmenu # Security hardening + config MBEDTLS_HARDWARE_SHA bool "Enable hardware SHA acceleration" default y diff --git a/components/mbedtls/mbedtls b/components/mbedtls/mbedtls index 64c8e14bffd..2b96dd8eebe 160000 --- a/components/mbedtls/mbedtls +++ b/components/mbedtls/mbedtls @@ -1 +1 @@ -Subproject commit 64c8e14bffd76abaec7a04f9e44aba00a9aad1f5 +Subproject commit 2b96dd8eebe880f304c69976b3c2fa0c5100cbb6 diff --git a/components/mbedtls/port/include/mbedtls/esp_config.h b/components/mbedtls/port/include/mbedtls/esp_config.h index a2df5264e02..2aa5bd9422c 100644 --- a/components/mbedtls/port/include/mbedtls/esp_config.h +++ b/components/mbedtls/port/include/mbedtls/esp_config.h @@ -212,6 +212,17 @@ #undef MBEDTLS_MPI_MUL_MPI_ALT #endif +/* mbedtls 3.6.7 made the small-factor test used in prime generation + * constant-time, which slows RSA key generation down roughly tenfold and + * starves the idle task (the computation never yields the CPU). The + * constant-time variant is the default; when it is explicitly disabled, + * fall back to the variable-time trial division from earlier releases. See + * MBEDTLS_MPI_PRIME_SIEVE_VARIABLE_TIME in library/bignum.c. + */ +#ifndef CONFIG_MBEDTLS_CONSTANT_TIME_PRIME_GEN +#define MBEDTLS_MPI_PRIME_SIEVE_VARIABLE_TIME +#endif + #ifdef CONFIG_MBEDTLS_ATCA_HW_ECDSA_SIGN #define MBEDTLS_ECDSA_SIGN_ALT #endif diff --git a/components/mbedtls/test_apps/main/test_rsa.c b/components/mbedtls/test_apps/main/test_rsa.c index 457caaa45d6..f81b4084f0c 100644 --- a/components/mbedtls/test_apps/main/test_rsa.c +++ b/components/mbedtls/test_apps/main/test_rsa.c @@ -3,7 +3,7 @@ * Focus on testing functionality where we use ESP32 hardware * accelerated crypto features * - * SPDX-FileCopyrightText: 2021-2025 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2021-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -570,6 +570,12 @@ static void rsa_key_operations(int keysize, bool check_performance, bool generat } +/* With constant-time prime generation the RSA-2048 key generation below takes + * over a minute on most targets (~86 s on ESP32-S3), exceeding the test + * timeout and starving the task watchdog, so only run it with the faster + * variable-time implementation. + */ +#if !CONFIG_MBEDTLS_CONSTANT_TIME_PRIME_GEN TEST_CASE("mbedtls RSA Generate Key", "[mbedtls][timeout=60]") { @@ -607,5 +613,6 @@ TEST_CASE("mbedtls RSA Generate Key", "[mbedtls][timeout=60]") #endif // CONFIG_MBEDTLS_MPI_USE_INTERRUPT && CONFIG_ESP_TASK_WDT_EN && !CONFIG_ESP_TASK_WDT_INIT } +#endif // !CONFIG_MBEDTLS_CONSTANT_TIME_PRIME_GEN #endif // CONFIG_MBEDTLS_HARDWARE_MPI From 3732a3680d68fc98c7fd4186225e853626fddffe Mon Sep 17 00:00:00 2001 From: Ashish Sharma Date: Mon, 20 Jul 2026 15:59:14 +0800 Subject: [PATCH 3/3] test(esp_wifi): adjust apsta bin size thresholds for mbedtls 3.6.7 --- .../test_apps/bin_size_apsta/pytest_bin_size_apsta.py | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/components/esp_wifi/test_apps/bin_size_apsta/pytest_bin_size_apsta.py b/components/esp_wifi/test_apps/bin_size_apsta/pytest_bin_size_apsta.py index fc4dbb75423..9396e70d4c1 100644 --- a/components/esp_wifi/test_apps/bin_size_apsta/pytest_bin_size_apsta.py +++ b/components/esp_wifi/test_apps/bin_size_apsta/pytest_bin_size_apsta.py @@ -1,4 +1,4 @@ -# SPDX-FileCopyrightText: 2025 Espressif Systems (Shanghai) CO LTD +# SPDX-FileCopyrightText: 2025-2026 Espressif Systems (Shanghai) CO LTD # SPDX-License-Identifier: Unlicense OR CC0-1.0 import os from typing import Callable @@ -12,11 +12,11 @@ from pytest_embedded_idf.utils import idf_parametrize SAVE_BIN_SIZE_TH = { 'disable_sae_h2e': { 'esp32': 16700, - 'esp32c2': 19700, + 'esp32c2': 19450, 'esp32c3': 19600, - 'esp32c5': 19650, - 'esp32c6': 19650, - 'esp32c61': 19700, + 'esp32c5': 19400, + 'esp32c6': 19400, + 'esp32c61': 19450, 'esp32s2': 16600, 'esp32s3': 16550, 'default': 16000,