change(security): disable Key Manager support on ESP32-C5/P4/S31

The Key Manager hardware peripheral in its current form needs further
design changes before it can be offered as a production feature.
Until a revised peripheral design is available, withdraw ESP-IDF
support for it on all Key Manager capable targets.
This commit is contained in:
harshal.patil
2026-08-26 13:23:56 +05:30
committed by Harshal Patil
parent ae2088092e
commit a827d27b12
28 changed files with 44 additions and 52 deletions
+4 -1
View File
@@ -72,8 +72,11 @@ elseif(NOT BOOTLOADER_BUILD)
endif()
# Key Manager and HUK HAL (available in both bootloader and app builds)
if(CONFIG_SOC_KEY_MANAGER_SUPPORTED)
if(CONFIG_SOC_KEY_MANAGER_SUPPORT_KEY_DEPLOYMENT)
list(APPEND srcs "key_mgr_hal.c")
endif()
if(CONFIG_SOC_HUK_SUPPORTED)
list(APPEND srcs "huk_hal.c")
endif()
+1 -1
View File
@@ -49,7 +49,7 @@ static void configure_ecdsa_periph(ecdsa_hal_config_t *conf)
key_mgr_hal_set_key_usage(ESP_KEY_MGR_ECDSA_KEY, ESP_KEY_MGR_USE_EFUSE_KEY);
#endif
}
#if SOC_KEY_MANAGER_SUPPORTED
#if SOC_KEY_MANAGER_ECDSA_KEY_DEPLOY
else {
if (!key_mgr_ll_is_supported()) {
HAL_ASSERT(false && "Key manager is not supported");
@@ -13,7 +13,7 @@
#include "soc/soc_caps.h"
#if SOC_KEY_MANAGER_SUPPORTED
#if SOC_HUK_SUPPORTED
#include <stdint.h>
#include <stdbool.h>
@@ -1,5 +1,5 @@
/*
* SPDX-FileCopyrightText: 2023-2025 Espressif Systems (Shanghai) CO LTD
* SPDX-FileCopyrightText: 2023-2026 Espressif Systems (Shanghai) CO LTD
*
* SPDX-License-Identifier: Apache-2.0
*/
@@ -13,7 +13,7 @@
#include "soc/soc_caps.h"
#if SOC_KEY_MANAGER_SUPPORTED
#if SOC_HUK_SUPPORTED
#include <stdint.h>
#include <stdbool.h>
@@ -13,7 +13,7 @@
#include "soc/soc_caps.h"
#if SOC_KEY_MANAGER_SUPPORTED
#if SOC_HUK_SUPPORTED
#include <stdint.h>
#include <stdbool.h>
+1 -1
View File
@@ -14,7 +14,7 @@
#include "esp_err.h"
#include "soc/soc_caps.h"
#if SOC_KEY_MANAGER_SUPPORTED
#if SOC_HUK_SUPPORTED
esp_huk_state_t huk_hal_get_state(void)
{
return huk_ll_get_state();
@@ -1,5 +1,5 @@
/*
* SPDX-FileCopyrightText: 2023 Espressif Systems (Shanghai) CO LTD
* SPDX-FileCopyrightText: 2023-2026 Espressif Systems (Shanghai) CO LTD
*
* SPDX-License-Identifier: Apache-2.0
*/
@@ -7,7 +7,7 @@
#include "soc/soc_caps.h"
#if SOC_KEY_MANAGER_SUPPORTED
#if SOC_HUK_SUPPORTED
#include "esp_assert.h"
#include "rom/km.h"
@@ -1,5 +1,5 @@
/*
* SPDX-FileCopyrightText: 2023-2025 Espressif Systems (Shanghai) CO LTD
* SPDX-FileCopyrightText: 2023-2026 Espressif Systems (Shanghai) CO LTD
*
* SPDX-License-Identifier: Apache-2.0
*/
@@ -9,7 +9,7 @@
#include "soc/soc_caps.h"
#if SOC_KEY_MANAGER_SUPPORTED
#if SOC_KEY_MANAGER_SUPPORT_KEY_DEPLOYMENT
#include "hal/key_mgr_types.h"
#ifdef __cplusplus
@@ -138,4 +138,4 @@ void key_mgr_hal_set_date_info(const uint32_t date_info);
#ifdef __cplusplus
}
#endif
#endif /* SOC_KEY_MANAGER_SUPPORTED */
#endif /* SOC_KEY_MANAGER_SUPPORT_KEY_DEPLOYMENT */
@@ -46,8 +46,11 @@ menu "Test App Configuration"
bool
default n if IDF_TARGET_ESP32P4 && ESP32P4_SELECTS_REV_LESS_V3
default y
depends on SOC_KEY_MANAGER_SUPPORTED
depends on SOC_KEY_MANAGER_SUPPORT_KEY_DEPLOYMENT
help
A hidden config to determine if the Key Manager tests should be included.
The tests build the esp_key_mgr driver from source so that the Key Manager
hardware stays covered by CI even on targets where IDF does not support
the Key Manager (SOC_KEY_MANAGER_SUPPORTED = 0).
endmenu