diff --git a/components/esp_wifi/test_apps/wifi_connect/main/app_main.c b/components/esp_wifi/test_apps/wifi_connect/main/app_main.c index a96613c4cce..88d3ed123f3 100644 --- a/components/esp_wifi/test_apps/wifi_connect/main/app_main.c +++ b/components/esp_wifi/test_apps/wifi_connect/main/app_main.c @@ -13,7 +13,7 @@ #include "esp_heap_caps.h" // Some resources are lazy allocated in wifi and lwip -#define TEST_MEMORY_LEAK_THRESHOLD (-1596) +#define TEST_MEMORY_LEAK_THRESHOLD (-1896) static size_t before_free_8bit; static size_t before_free_32bit; diff --git a/components/esp_wifi/test_apps/wifi_nvs_config/main/app_main.c b/components/esp_wifi/test_apps/wifi_nvs_config/main/app_main.c index 4f455aa8e4f..23b373738cf 100644 --- a/components/esp_wifi/test_apps/wifi_nvs_config/main/app_main.c +++ b/components/esp_wifi/test_apps/wifi_nvs_config/main/app_main.c @@ -16,7 +16,7 @@ // #define TEST_MEMORY_LEAK_THRESHOLD (-1546) // With PSA Migration, there is an increase in memory usage. // TODO: Check why this is happening and fix it. -#define TEST_MEMORY_LEAK_THRESHOLD (-1750) +#define TEST_MEMORY_LEAK_THRESHOLD (-1850) static size_t before_free_8bit; static size_t before_free_32bit; diff --git a/components/idf_test/include/esp32/idf_performance_target.h b/components/idf_test/include/esp32/idf_performance_target.h index 9f39fefe9c8..c14f04df94a 100644 --- a/components/idf_test/include/esp32/idf_performance_target.h +++ b/components/idf_test/include/esp32/idf_performance_target.h @@ -21,7 +21,7 @@ #define IDF_PERFORMANCE_MAX_TIME_SHA1_32KB 5000 #define IDF_PERFORMANCE_MAX_TIME_SHA512_32KB 4500 -#define IDF_PERFORMANCE_MAX_RSA_2048KEY_PUBLIC_OP 19000 +#define IDF_PERFORMANCE_MAX_RSA_2048KEY_PUBLIC_OP 21500 #define IDF_PERFORMANCE_MAX_RSA_2048KEY_PRIVATE_OP 750000 #define IDF_PERFORMANCE_MAX_RSA_3072KEY_PUBLIC_OP 33000 #define IDF_PERFORMANCE_MAX_RSA_3072KEY_PRIVATE_OP 950000 diff --git a/components/idf_test/include/esp32s2/idf_performance_target.h b/components/idf_test/include/esp32s2/idf_performance_target.h index 1ef64601a7b..3895361dee7 100644 --- a/components/idf_test/include/esp32s2/idf_performance_target.h +++ b/components/idf_test/include/esp32s2/idf_performance_target.h @@ -16,7 +16,7 @@ #define IDF_PERFORMANCE_MAX_TIME_SHA1_32KB 900 #define IDF_PERFORMANCE_MAX_TIME_SHA512_32KB 900 -#define IDF_PERFORMANCE_MAX_RSA_2048KEY_PUBLIC_OP 15500 +#define IDF_PERFORMANCE_MAX_RSA_2048KEY_PUBLIC_OP 17000 #define IDF_PERFORMANCE_MAX_RSA_2048KEY_PRIVATE_OP 650000 #define IDF_PERFORMANCE_MAX_RSA_3072KEY_PUBLIC_OP 36000 #define IDF_PERFORMANCE_MAX_RSA_3072KEY_PRIVATE_OP 960000 diff --git a/components/mbedtls/Kconfig b/components/mbedtls/Kconfig index be66b17454d..e970072ea6f 100644 --- a/components/mbedtls/Kconfig +++ b/components/mbedtls/Kconfig @@ -32,7 +32,7 @@ menu "mbedTLS" config MBEDTLS_THREADING_C bool "Enable the threading abstraction layer" - default n + default y help If you do intend to use contexts between threads, you will need to enable this layer to prevent race conditions. @@ -40,14 +40,14 @@ menu "mbedTLS" config MBEDTLS_THREADING_ALT bool "Enable threading alternate implementation" depends on MBEDTLS_THREADING_C - default y + default n help Enable threading alt to allow your own alternate threading implementation. config MBEDTLS_THREADING_PTHREAD bool "Enable threading pthread implementation" depends on MBEDTLS_THREADING_C - default n + default y help Enable the pthread wrapper layer for the threading layer. diff --git a/components/mbedtls/config/mbedtls_preset_default.conf b/components/mbedtls/config/mbedtls_preset_default.conf index e4d7bd74e9d..6427b071e40 100644 --- a/components/mbedtls/config/mbedtls_preset_default.conf +++ b/components/mbedtls/config/mbedtls_preset_default.conf @@ -4,7 +4,7 @@ # Core Configuration CONFIG_MBEDTLS_FS_IO=y -CONFIG_MBEDTLS_THREADING_C=n +CONFIG_MBEDTLS_THREADING_C=y CONFIG_MBEDTLS_ERROR_STRINGS=y CONFIG_MBEDTLS_VERSION_C=n CONFIG_MBEDTLS_HAVE_TIME=y diff --git a/components/mbedtls/esp_tee/esp_tee_mbedtls_config.h b/components/mbedtls/esp_tee/esp_tee_mbedtls_config.h index 563ab82f64a..38ce68da37d 100644 --- a/components/mbedtls/esp_tee/esp_tee_mbedtls_config.h +++ b/components/mbedtls/esp_tee/esp_tee_mbedtls_config.h @@ -187,3 +187,6 @@ #if SOC_AES_SUPPORTED #define MBEDTLS_AES_FEWER_TABLES #endif + +/* ESP-TEE is single threaded so we can disable threading in mbedTLS */ +#undef MBEDTLS_THREADING_C diff --git a/components/mbedtls/test_apps/main/test_sha_perf.c b/components/mbedtls/test_apps/main/test_sha_perf.c index 53ba6078728..14061f39b3e 100644 --- a/components/mbedtls/test_apps/main/test_sha_perf.c +++ b/components/mbedtls/test_apps/main/test_sha_perf.c @@ -37,7 +37,7 @@ TEST_CASE("psa SHA256 performance", "[mbedtls]") TEST_ASSERT_NOT_NULL(buf); memset(buf, 0x55, CALL_SZ); - ccomp_timer_start(); + TEST_ESP_OK(ccomp_timer_start()); for (int c = 0; c < CALLS; c++) { status = psa_hash_update(&operation, buf, CALL_SZ); TEST_ASSERT_EQUAL(PSA_SUCCESS, status); @@ -46,6 +46,7 @@ TEST_CASE("psa SHA256 performance", "[mbedtls]") status = psa_hash_finish(&operation, sha256, sizeof(sha256), &hash_length); TEST_ASSERT_EQUAL(PSA_SUCCESS, status); elapsed_usec = ccomp_timer_stop(); + TEST_ASSERT_GREATER_THAN(0, elapsed_usec); free(buf); diff --git a/docs/en/migration-guides/release-6.x/6.0/security.rst b/docs/en/migration-guides/release-6.x/6.0/security.rst index 7d98a632656..8f4edbc1e7d 100644 --- a/docs/en/migration-guides/release-6.x/6.0/security.rst +++ b/docs/en/migration-guides/release-6.x/6.0/security.rst @@ -32,7 +32,7 @@ ESP-IDF v6.0 updates to Mbed TLS v4.0, where **PSA Crypto is the primary cryptog - **Breaking change**: certificates/peers using elliptic curves of less than 250 bits (for example secp192r1/secp224r1) are no longer supported in certificates and in TLS. - **Note**: - - void relying on Mbed TLS private declarations (for example headers under ``mbedtls/private/`` or declarations enabled via ``MBEDTLS_DECLARE_PRIVATE_IDENTIFIERS`` / ``MBEDTLS_ALLOW_PRIVATE_ACCESS``). Such private interfaces may change without notice. + - Avoid relying on Mbed TLS private declarations (for example headers under ``mbedtls/private/`` or declarations enabled via ``MBEDTLS_DECLARE_PRIVATE_IDENTIFIERS`` / ``MBEDTLS_ALLOW_PRIVATE_ACCESS``). Such private interfaces may change without notice. - The PSA Crypto migration (TF-PSA-Crypto) can increase flash footprint, depending on the features enabled. As reference points: .. list-table:: @@ -69,6 +69,9 @@ Default configuration changes - ``MBEDTLS_ARIA_C`` is disabled by default. Applications that rely on ARIA must explicitly enable it in ``menuconfig`` (Component config -> mbedTLS) or by customizing ``components/mbedtls/config/mbedtls_preset_default.conf``. - Support for ``secp192r1`` is disabled by default, consistent with the removal of support for elliptic curves smaller than 250 bits in certificates and TLS. If an application still requires legacy curve support outside TLS/certificates, it must be enabled explicitly (for example by defining ``PSA_WANT_ECC_SECP_R1_192=1``) and validated for compatibility. Note: this legacy support may be disabled in the next minor ESP-IDF release. +- ``MBEDTLS_THREADING_C`` is enabled by default. This provides thread-safety for the PSA Crypto key management API and ``psa_crypto_init()``. It is recommended to keep this configuration enabled when using PSA Crypto from multiple threads (for example, concurrent TLS connections, certificate operations, or any scenario where cryptographic operations may be invoked from different threads). Applications that only call PSA functions from a single thread are not affected by this change and can optionally disable threading support if desired. +- ``MBEDTLS_THREADING_PTHREAD`` is enabled by default. This enables Mbed TLS threading support using pthread primitives. +- ``MBEDTLS_THREADING_ALT`` is disabled by default. This disables Mbed TLS threading support using alternate threading primitives. References ^^^^^^^^^^