From aa88c81dfb3829fbb22ce2b7992ff62584a0e72c Mon Sep 17 00:00:00 2001 From: Ashish Sharma Date: Tue, 2 Dec 2025 19:13:42 +0800 Subject: [PATCH] fix(wpa_supplicant): revert changes to dpp_crypto --- .../bootloader_support/main/CMakeLists.txt | 2 +- .../main/test_verify_image.c | 3 - .../esp-tls/test_apps/main/CMakeLists.txt | 2 +- components/esp_security/CMakeLists.txt | 3 - components/esp_security/src/init.c | 20 --- .../tee_sec_storage/tee_sec_storage.c | 48 +++-- .../test_apps/tee_test_fw/tmp/aes256_key.bin | 1 - .../test_apps/wifi_nvs_config/main/app_main.c | 2 +- .../espcoredump/test_apps/main/CMakeLists.txt | 1 - .../test_apps/sdkconfig.ci.checksum_sha256 | 1 - .../espcoredump/test_apps/sdkconfig.defaults | 2 +- .../mbedtls/esp_crt_bundle/esp_crt_bundle.c | 2 +- components/mbedtls/port/aes/esp_aes_gcm.c | 63 ------- .../port/dynamic/esp_mbedtls_dynamic_impl.c | 9 - .../port/dynamic/esp_mbedtls_dynamic_impl.h | 2 - components/mbedtls/port/dynamic/esp_ssl_cli.c | 1 - components/mbedtls/port/dynamic/esp_ssl_srv.c | 1 - .../port/mbedtls_rom/mbedtls_rom_osi.h | 17 +- .../esp_aes/psa_crypto_driver_esp_aes_gcm.c | 2 +- components/mbedtls/test_apps/main/app_main.c | 1 - .../test_apps/main/test_esp_crt_bundle.c | 8 - .../mbedtls/test_apps/main/test_psa_cmac.c | 28 --- .../protocomm/src/crypto/srp6a/esp_srp.c | 3 - .../protocomm/test_apps/main/test_protocomm.c | 6 - .../src/crypto/crypto_mbedtls.c | 168 +++++++++--------- .../esp_supplicant/src/crypto/tls_mbedtls.c | 10 -- .../test_apps/main/test_wpa_supplicant_main.c | 3 - .../bluetooth/blufi/main/blufi_security.c | 3 +- .../example_secure_service/example_service.c | 1 - 29 files changed, 128 insertions(+), 285 deletions(-) delete mode 100644 components/esp_tee/test_apps/tee_test_fw/tmp/aes256_key.bin diff --git a/components/bootloader_support/test_apps/bootloader_support/main/CMakeLists.txt b/components/bootloader_support/test_apps/bootloader_support/main/CMakeLists.txt index cef35455e5c..af5ce7f25d8 100644 --- a/components/bootloader_support/test_apps/bootloader_support/main/CMakeLists.txt +++ b/components/bootloader_support/test_apps/bootloader_support/main/CMakeLists.txt @@ -1,4 +1,4 @@ idf_component_register(SRCS "test_app_main.c" "test_verify_image.c" INCLUDE_DIRS "." - REQUIRES unity bootloader_support esp_partition app_update mbedtls + REQUIRES unity bootloader_support esp_partition app_update WHOLE_ARCHIVE) diff --git a/components/bootloader_support/test_apps/bootloader_support/main/test_verify_image.c b/components/bootloader_support/test_apps/bootloader_support/main/test_verify_image.c index eb560c2ae7d..c290a6118c5 100644 --- a/components/bootloader_support/test_apps/bootloader_support/main/test_verify_image.c +++ b/components/bootloader_support/test_apps/bootloader_support/main/test_verify_image.c @@ -21,9 +21,6 @@ #include "esp_partition.h" #include "esp_ota_ops.h" #include "esp_image_format.h" -#include "psa/crypto.h" -#include "mbedtls/asn1.h" -#include "mbedtls/asn1write.h" TEST_CASE("Verify bootloader image in flash", "[bootloader_support]") { diff --git a/components/esp-tls/test_apps/main/CMakeLists.txt b/components/esp-tls/test_apps/main/CMakeLists.txt index dd9e94d16b7..d57cfd52498 100644 --- a/components/esp-tls/test_apps/main/CMakeLists.txt +++ b/components/esp-tls/test_apps/main/CMakeLists.txt @@ -1,3 +1,3 @@ idf_component_register(SRC_DIRS "." - PRIV_REQUIRES test_utils esp-tls unity nvs_flash + PRIV_REQUIRES test_utils esp-tls unity WHOLE_ARCHIVE) diff --git a/components/esp_security/CMakeLists.txt b/components/esp_security/CMakeLists.txt index 33819b29c56..362f942aebd 100644 --- a/components/esp_security/CMakeLists.txt +++ b/components/esp_security/CMakeLists.txt @@ -57,9 +57,6 @@ idf_component_register(SRCS ${srcs} if(NOT non_os_build) target_link_libraries(${COMPONENT_LIB} PRIVATE "-u esp_security_init_include_impl") - # if(CONFIG_MBEDTLS_PSA_CRYPTO_C) - idf_component_optional_requires(PRIVATE mbedtls) - # endif() elseif(esp_tee_build) target_link_libraries(${COMPONENT_LIB} PRIVATE idf::efuse) endif() diff --git a/components/esp_security/src/init.c b/components/esp_security/src/init.c index 2d08bb038fa..9a3a3fc147c 100644 --- a/components/esp_security/src/init.c +++ b/components/esp_security/src/init.c @@ -13,10 +13,6 @@ #include "esp_security_priv.h" #include "esp_err.h" #include "hal/efuse_hal.h" -// #if defined(CONFIG_MBEDTLS_PSA_CRYPTO_C) -#include "psa/crypto.h" -#include "esp_random.h" -// #endif /* CONFIG_MBEDTLS_PSA_CRYPTO_C */ #if SOC_HUK_MEM_NEEDS_RECHARGE #include "hal/huk_hal.h" @@ -140,22 +136,6 @@ ESP_SYSTEM_INIT_FN(esp_security_init, SECONDARY, BIT(0), 103) return err; } -// #if defined(CONFIG_MBEDTLS_PSA_CRYPTO_C) -int mbedtls_platform_get_entropy(unsigned char *output, size_t output_size, - size_t *output_len, size_t *entropy_content) -{ - if (output == NULL || output_size == 0 || output_len == NULL || entropy_content == NULL) { - ESP_EARLY_LOGE(TAG, "Invalid parameters for mbedtls_platform_get_entropy"); - return -1; // Invalid parameters - } - - esp_fill_random(output, output_size); - *output_len = output_size; - *entropy_content = 8 * output_size; - return 0; -} -// #endif // CONFIG_MBEDTLS_PSA_CRYPTO_C - void esp_security_init_include_impl(void) { // Linker hook, exists for no other purpose diff --git a/components/esp_tee/subproject/components/tee_sec_storage/tee_sec_storage.c b/components/esp_tee/subproject/components/tee_sec_storage/tee_sec_storage.c index 75550659500..026dd23ae08 100644 --- a/components/esp_tee/subproject/components/tee_sec_storage/tee_sec_storage.c +++ b/components/esp_tee/subproject/components/tee_sec_storage/tee_sec_storage.c @@ -17,11 +17,6 @@ #include "esp_hmac.h" #endif #define MBEDTLS_DECLARE_PRIVATE_IDENTIFIERS -// #include "mbedtls/aes.h" -// #include "mbedtls/gcm.h" -// #include "mbedtls/sha256.h" -// #include "mbedtls/ecdsa.h" -// #include "mbedtls/error.h" #include "esp_hmac_pbkdf2.h" #include "psa/crypto.h" #include "mbedtls/psa_util.h" @@ -52,13 +47,13 @@ /* Structure to hold ECDSA SECP256R1 key pair */ typedef struct { uint8_t priv_key[ECDSA_SECP256R1_KEY_LEN]; /* Private key for ECDSA SECP256R1 */ - uint8_t pub_key[(2 * ECDSA_SECP256R1_KEY_LEN) + 1]; /* Public key for ECDSA SECP256R1 (X and Y coordinates) */ + uint8_t pub_key[2 * ECDSA_SECP256R1_KEY_LEN]; /* Public key for ECDSA SECP256R1 (X and Y coordinates) */ } __attribute__((aligned(4))) __attribute__((__packed__)) sec_stg_ecdsa_secp256r1_t; /* Structure to hold ECDSA SECP192R1 key pair */ typedef struct { uint8_t priv_key[ECDSA_SECP192R1_KEY_LEN]; /* Private key for ECDSA SECP192R1 */ - uint8_t pub_key[(2 * ECDSA_SECP192R1_KEY_LEN) + 1]; /* Public key for ECDSA SECP192R1 (X and Y coordinates) */ + uint8_t pub_key[2 * ECDSA_SECP192R1_KEY_LEN]; /* Public key for ECDSA SECP192R1 (X and Y coordinates) */ } __attribute__((aligned(4))) __attribute__((__packed__)) sec_stg_ecdsa_secp192r1_t; /* Structure to hold AES-256 key and IV */ @@ -79,7 +74,7 @@ typedef struct { uint32_t reserved[38]; /* Reserved space for future use */ } __attribute__((aligned(4))) __attribute__((__packed__)) sec_stg_key_t; -_Static_assert(sizeof(sec_stg_key_t) == 260, "Incorrect sec_stg_key_t size"); +_Static_assert(sizeof(sec_stg_key_t) == 256, "Incorrect sec_stg_key_t size"); static nvs_handle_t tee_nvs_hdl; @@ -270,7 +265,12 @@ esp_err_t esp_tee_sec_storage_init(void) ESP_LOGW(TAG, "TEE Secure Storage enabled in insecure DEVELOPMENT mode"); #endif - psa_crypto_init(); + psa_status_t status = psa_crypto_init(); + if (status != PSA_SUCCESS) { + ESP_LOGE(TAG, "Failed to initialize PSA Crypto! (0x%08x)", status); + return ESP_FAIL; + } + ESP_FAULT_ASSERT(status == PSA_SUCCESS); return ESP_OK; } @@ -309,12 +309,6 @@ static int generate_ecdsa_key(sec_stg_key_t *keyctx, esp_tee_sec_storage_type_t return -1; } - psa_status_t status = psa_crypto_init(); - if (status != PSA_SUCCESS) { - ESP_LOGE(TAG, "Failed to initialize PSA Crypto: %ld", status); - return -1; - } - psa_key_id_t key_id = 0; psa_key_attributes_t key_attributes = PSA_KEY_ATTRIBUTES_INIT; psa_set_key_bits(&key_attributes, ECDSA_SECP256R1_KEY_LEN * 8); @@ -330,7 +324,7 @@ static int generate_ecdsa_key(sec_stg_key_t *keyctx, esp_tee_sec_storage_type_t return -1; #endif } - status = psa_generate_key(&key_attributes, &key_id); + psa_status_t status = psa_generate_key(&key_attributes, &key_id); if (status != PSA_SUCCESS) { ESP_LOGE(TAG, "Failed to generate ECDSA key: %ld", status); goto exit; @@ -365,12 +359,32 @@ static int generate_ecdsa_key(sec_stg_key_t *keyctx, esp_tee_sec_storage_type_t goto exit; } - status = psa_export_public_key(key_id, pub_key_buf, pub_key_buf_size, &pub_key_len); + /* PSA exports public key with 0x04 prefix (65 bytes for secp256r1, 49 bytes for secp192r1) + * We need to strip the prefix and store only X and Y coordinates (64 bytes for secp256r1, 48 bytes for secp192r1) + * Use fixed-size array to avoid VLA issues with goto statements + */ + uint8_t pub_key_with_prefix[(2 * ECDSA_SECP256R1_KEY_LEN) + 1]; /* Max size: 65 bytes for secp256r1 */ + size_t pub_key_len_with_prefix = 0; + size_t expected_pub_key_len_with_prefix = pub_key_buf_size + 1; + + status = psa_export_public_key(key_id, pub_key_with_prefix, sizeof(pub_key_with_prefix), &pub_key_len_with_prefix); if (status != PSA_SUCCESS) { ESP_LOGE(TAG, "Failed to export ECDSA public key: %ld", status); goto exit; } + /* Strip the 0x04 prefix if present */ + if (pub_key_len_with_prefix == expected_pub_key_len_with_prefix && pub_key_with_prefix[0] == 0x04) { + memcpy(pub_key_buf, pub_key_with_prefix + 1, pub_key_buf_size); + pub_key_len = pub_key_buf_size; + } else { + /* Fallback: copy directly if format is unexpected (should not happen with PSA) */ + ESP_LOGW(TAG, "Unexpected public key format, copying directly"); + size_t copy_len = (pub_key_len_with_prefix < pub_key_buf_size) ? pub_key_len_with_prefix : pub_key_buf_size; + memcpy(pub_key_buf, pub_key_with_prefix, copy_len); + pub_key_len = copy_len; + } + buffer_hexdump("Private key", priv_key_buf, priv_key_len); buffer_hexdump("Public key", pub_key_buf, pub_key_len); diff --git a/components/esp_tee/test_apps/tee_test_fw/tmp/aes256_key.bin b/components/esp_tee/test_apps/tee_test_fw/tmp/aes256_key.bin deleted file mode 100644 index 3987f91997e..00000000000 --- a/components/esp_tee/test_apps/tee_test_fw/tmp/aes256_key.bin +++ /dev/null @@ -1 +0,0 @@ -©œ_¶Ý“òc©/ !û¨Ž¹²º�Ʋm YÃSÌ+)vÅ—¤ רƒeS› \ No newline at end of file diff --git a/components/esp_wifi/test_apps/wifi_nvs_config/main/app_main.c b/components/esp_wifi/test_apps/wifi_nvs_config/main/app_main.c index d28da639a0a..9a75bbecdc2 100644 --- a/components/esp_wifi/test_apps/wifi_nvs_config/main/app_main.c +++ b/components/esp_wifi/test_apps/wifi_nvs_config/main/app_main.c @@ -13,7 +13,7 @@ #include "esp_heap_caps.h" // Some resources are lazy allocated in wifi and lwip -#define TEST_MEMORY_LEAK_THRESHOLD (-1536) +#define TEST_MEMORY_LEAK_THRESHOLD (-1546) static size_t before_free_8bit; static size_t before_free_32bit; diff --git a/components/espcoredump/test_apps/main/CMakeLists.txt b/components/espcoredump/test_apps/main/CMakeLists.txt index 20730d7300e..8f688245657 100644 --- a/components/espcoredump/test_apps/main/CMakeLists.txt +++ b/components/espcoredump/test_apps/main/CMakeLists.txt @@ -3,7 +3,6 @@ set(SRCS "test_coredump_main.c" "test_sections.c") idf_component_get_property(espcoredump_dir espcoredump COMPONENT_DIR) list(APPEND priv_includes "${espcoredump_dir}/include_core_dump") -# list(APPEND SRCS "${espcoredump_dir}/src/core_dump_sha.c") idf_component_register(SRCS ${SRCS} INCLUDE_DIRS "." PRIV_REQUIRES unity diff --git a/components/espcoredump/test_apps/sdkconfig.ci.checksum_sha256 b/components/espcoredump/test_apps/sdkconfig.ci.checksum_sha256 index f4523b69ab3..86c5290f2ba 100644 --- a/components/espcoredump/test_apps/sdkconfig.ci.checksum_sha256 +++ b/components/espcoredump/test_apps/sdkconfig.ci.checksum_sha256 @@ -1,3 +1,2 @@ - CONFIG_ESP_COREDUMP_ENABLE_TO_UART=y CONFIG_ESP_COREDUMP_ENABLE_TO_UART=y diff --git a/components/espcoredump/test_apps/sdkconfig.defaults b/components/espcoredump/test_apps/sdkconfig.defaults index 87cbee6cd87..247d7f79158 100644 --- a/components/espcoredump/test_apps/sdkconfig.defaults +++ b/components/espcoredump/test_apps/sdkconfig.defaults @@ -1,2 +1,2 @@ CONFIG_ESP_TASK_WDT_CHECK_IDLE_TASK_CPU0=n -CONFIG_ESP_COREDUMP_ENABLE_TO_UART=y +CONFIG_ESP_COREDUMP_ENABLE_TO_FLASH=y diff --git a/components/mbedtls/esp_crt_bundle/esp_crt_bundle.c b/components/mbedtls/esp_crt_bundle/esp_crt_bundle.c index 5f9ba93421e..05eff00b9cb 100644 --- a/components/mbedtls/esp_crt_bundle/esp_crt_bundle.c +++ b/components/mbedtls/esp_crt_bundle/esp_crt_bundle.c @@ -69,7 +69,7 @@ extern const uint8_t x509_crt_imported_bundle_bin_end[] asm("_binary_x509_crt_ typedef const uint8_t* bundle_t; typedef const uint8_t* cert_t; -static bundle_t s_crt_bundle = NULL; +static bundle_t s_crt_bundle; // Read a 16-bit value stored in little-endian format from the given address static uint16_t get16_le(const uint8_t* ptr) diff --git a/components/mbedtls/port/aes/esp_aes_gcm.c b/components/mbedtls/port/aes/esp_aes_gcm.c index 5203835352d..518c2ec3e9c 100644 --- a/components/mbedtls/port/aes/esp_aes_gcm.c +++ b/components/mbedtls/port/aes/esp_aes_gcm.c @@ -256,27 +256,6 @@ int esp_aes_gcm_setkey( esp_gcm_context *ctx, const unsigned char *key, unsigned int keybits ) { - /* Fallback to software implementation of GCM operation when a non-AES - * cipher is selected, as we support hardware acceleration only for a - * GCM operation using AES cipher. - */ -#if defined(MBEDTLS_GCM_NON_AES_CIPHER_SOFT_FALLBACK) && 0 - if (ctx->ctx_soft != NULL) { - mbedtls_gcm_free_soft(ctx->ctx_soft); - free(ctx->ctx_soft); - ctx->ctx_soft = NULL; - } - - if (cipher != MBEDTLS_CIPHER_ID_AES) { - ctx->ctx_soft = (mbedtls_gcm_context_soft*) malloc(sizeof(mbedtls_gcm_context_soft)); - if (ctx->ctx_soft == NULL) { - return MBEDTLS_ERR_CIPHER_ALLOC_FAILED; - } - mbedtls_gcm_init_soft(ctx->ctx_soft); - return mbedtls_gcm_setkey_soft(ctx->ctx_soft, cipher, key, keybits); - } -#endif - #if !SOC_AES_SUPPORT_AES_192 if (keybits == 192) { return -1; @@ -358,14 +337,6 @@ void esp_aes_gcm_free( esp_gcm_context *ctx) if (ctx == NULL) { return; } -#if defined(MBEDTLS_GCM_NON_AES_CIPHER_SOFT_FALLBACK) && 0 - if (ctx->ctx_soft != NULL) { - mbedtls_gcm_free_soft(ctx->ctx_soft); - free(ctx->ctx_soft); - /* Note that the value of ctx->ctx_soft should be NULL'ed out - and here it is taken care by the bzero call below */ - } -#endif bzero(ctx, sizeof(esp_gcm_context)); } @@ -380,12 +351,6 @@ int esp_aes_gcm_starts( esp_gcm_context *ctx, return -1; } -#if defined(MBEDTLS_GCM_NON_AES_CIPHER_SOFT_FALLBACK) && 0 - if (ctx->ctx_soft != NULL) { - return mbedtls_gcm_starts_soft(ctx->ctx_soft, mode, iv, iv_len); - } -#endif - /* IV is limited to 2^32 bits, so 2^29 bytes */ /* IV is not allowed to be zero length */ if ( iv_len == 0 || @@ -452,12 +417,6 @@ int esp_aes_gcm_update_ad( esp_gcm_context *ctx, return -1; } -#if defined(MBEDTLS_GCM_NON_AES_CIPHER_SOFT_FALLBACK) && 0 - if (ctx->ctx_soft != NULL) { - return mbedtls_gcm_update_ad_soft(ctx->ctx_soft, aad, aad_len); - } -#endif - /* AD are limited to 2^32 bits, so 2^29 bytes */ if ( ( (uint32_t) aad_len ) >> 29 != 0 ) { return ( -1 ); @@ -493,12 +452,6 @@ int esp_aes_gcm_update( esp_gcm_context *ctx, return -1; } -#if defined(MBEDTLS_GCM_NON_AES_CIPHER_SOFT_FALLBACK) && 0 - if (ctx->ctx_soft != NULL) { - return mbedtls_gcm_update_soft(ctx->ctx_soft, input, input_length, output, output_size, output_length); - } -#endif - size_t nc_off = 0; uint8_t nonce_counter[AES_BLOCK_BYTES] = {0}; uint8_t stream[AES_BLOCK_BYTES] = {0}; @@ -565,11 +518,6 @@ int esp_aes_gcm_finish( esp_gcm_context *ctx, size_t *output_length, unsigned char *tag, size_t tag_len ) { -#if defined(MBEDTLS_GCM_NON_AES_CIPHER_SOFT_FALLBACK) && 0 - if (ctx->ctx_soft != NULL) { - return mbedtls_gcm_finish_soft(ctx->ctx_soft, output, output_size, output_length, tag, tag_len); - } -#endif size_t nc_off = 0; uint8_t len_block[AES_BLOCK_BYTES] = {0}; uint8_t stream[AES_BLOCK_BYTES] = {0}; @@ -665,12 +613,6 @@ int esp_aes_gcm_crypt_and_tag( esp_gcm_context *ctx, ESP_LOGE(TAG, "No AES context supplied"); return -1; } - -#if defined(MBEDTLS_GCM_NON_AES_CIPHER_SOFT_FALLBACK) && 0 - if (ctx->ctx_soft != NULL) { - return mbedtls_gcm_crypt_and_tag_soft(ctx->ctx_soft, mode, length, iv, iv_len, aad, aad_len, input, output, tag_len, tag); - } -#endif #if CONFIG_MBEDTLS_HARDWARE_GCM int ret; size_t remainder_bit; @@ -761,11 +703,6 @@ int esp_aes_gcm_auth_decrypt( esp_gcm_context *ctx, const unsigned char *input, unsigned char *output ) { -#if defined(MBEDTLS_GCM_NON_AES_CIPHER_SOFT_FALLBACK) && 0 - if (ctx->ctx_soft != NULL) { - return mbedtls_gcm_auth_decrypt_soft(ctx->ctx_soft, length, iv, iv_len, aad, aad_len, tag, tag_len, input, output); - } -#endif int ret; unsigned char check_tag[16]; size_t i; diff --git a/components/mbedtls/port/dynamic/esp_mbedtls_dynamic_impl.c b/components/mbedtls/port/dynamic/esp_mbedtls_dynamic_impl.c index 649643be821..c101f4e30c2 100644 --- a/components/mbedtls/port/dynamic/esp_mbedtls_dynamic_impl.c +++ b/components/mbedtls/port/dynamic/esp_mbedtls_dynamic_impl.c @@ -523,15 +523,6 @@ size_t esp_mbedtls_get_crt_size(mbedtls_x509_crt *cert, size_t *num) } #ifdef CONFIG_MBEDTLS_DYNAMIC_FREE_CONFIG_DATA -void esp_mbedtls_free_dhm(mbedtls_ssl_context *ssl) -{ -#ifdef CONFIG_MBEDTLS_DHM_C - // const mbedtls_ssl_config *conf = mbedtls_ssl_context_get_config(ssl); - // mbedtls_mpi_free((mbedtls_mpi *)&conf->MBEDTLS_PRIVATE(dhm_P)); - // mbedtls_mpi_free((mbedtls_mpi *)&conf->MBEDTLS_PRIVATE(dhm_G)); -#endif /* CONFIG_MBEDTLS_DHM_C */ -} - void esp_mbedtls_free_keycert(mbedtls_ssl_context *ssl) { mbedtls_ssl_config *conf = (mbedtls_ssl_config * )mbedtls_ssl_context_get_config(ssl); diff --git a/components/mbedtls/port/dynamic/esp_mbedtls_dynamic_impl.h b/components/mbedtls/port/dynamic/esp_mbedtls_dynamic_impl.h index 54409766f53..ce52f05d5f3 100644 --- a/components/mbedtls/port/dynamic/esp_mbedtls_dynamic_impl.h +++ b/components/mbedtls/port/dynamic/esp_mbedtls_dynamic_impl.h @@ -88,8 +88,6 @@ int esp_mbedtls_free_rx_buffer(mbedtls_ssl_context *ssl); size_t esp_mbedtls_get_crt_size(mbedtls_x509_crt *cert, size_t *num); #ifdef CONFIG_MBEDTLS_DYNAMIC_FREE_CONFIG_DATA -void esp_mbedtls_free_dhm(mbedtls_ssl_context *ssl); - void esp_mbedtls_free_keycert(mbedtls_ssl_context *ssl); void esp_mbedtls_free_keycert_cert(mbedtls_ssl_context *ssl); diff --git a/components/mbedtls/port/dynamic/esp_ssl_cli.c b/components/mbedtls/port/dynamic/esp_ssl_cli.c index 376f104780e..f7aacca85e7 100644 --- a/components/mbedtls/port/dynamic/esp_ssl_cli.c +++ b/components/mbedtls/port/dynamic/esp_ssl_cli.c @@ -153,7 +153,6 @@ static int manage_resource(mbedtls_ssl_context *ssl, bool add) CHECK_OK(esp_mbedtls_add_tx_buffer(ssl, buffer_len)); } else { #ifdef CONFIG_MBEDTLS_DYNAMIC_FREE_CONFIG_DATA - esp_mbedtls_free_dhm(ssl); esp_mbedtls_free_keycert_key(ssl); esp_mbedtls_free_keycert(ssl); #endif diff --git a/components/mbedtls/port/dynamic/esp_ssl_srv.c b/components/mbedtls/port/dynamic/esp_ssl_srv.c index c895d679b2d..d2000092268 100644 --- a/components/mbedtls/port/dynamic/esp_ssl_srv.c +++ b/components/mbedtls/port/dynamic/esp_ssl_srv.c @@ -100,7 +100,6 @@ static int manage_resource(mbedtls_ssl_context *ssl, bool add) CHECK_OK(esp_mbedtls_add_tx_buffer(ssl, buffer_len)); } else { #ifdef CONFIG_MBEDTLS_DYNAMIC_FREE_CONFIG_DATA - esp_mbedtls_free_dhm(ssl); /** * Not free keycert->key and keycert until MBEDTLS_SSL_CLIENT_KEY_EXCHANGE for rsa key exchange methods. * For ssl server will use keycert->key to parse client key exchange. diff --git a/components/mbedtls/port/mbedtls_rom/mbedtls_rom_osi.h b/components/mbedtls/port/mbedtls_rom/mbedtls_rom_osi.h index 74db8fa565a..6408e1c5437 100644 --- a/components/mbedtls/port/mbedtls_rom/mbedtls_rom_osi.h +++ b/components/mbedtls/port/mbedtls_rom/mbedtls_rom_osi.h @@ -7,22 +7,21 @@ #pragma once #include -#define MBEDTLS_DECLARE_PRIVATE_IDENTIFIERS -// #include "mbedtls/aes.h" +#include "mbedtls/aes.h" #include "mbedtls/asn1.h" #include "mbedtls/asn1write.h" #include "mbedtls/base64.h" #include "mbedtls/bignum.h" -// #include "mbedtls/ccm.h" +#include "mbedtls/ccm.h" #include "mbedtls/cipher.h" -// #include "mbedtls/cmac.h" -// #include "mbedtls/ctr_drbg.h" +#include "mbedtls/cmac.h" +#include "mbedtls/ctr_drbg.h" #include "mbedtls/dhm.h" -// #include "mbedtls/ecdh.h" +#include "mbedtls/ecdh.h" #include "mbedtls/ecdsa.h" #include "mbedtls/ecjpake.h" #include "mbedtls/ecp.h" -// #include "mbedtls/entropy.h" +#include "mbedtls/entropy.h" #include "mbedtls/hmac_drbg.h" #include "mbedtls/md.h" #include "mbedtls/md5.h" @@ -33,8 +32,8 @@ #include "mbedtls/pk.h" #include "mbedtls/platform.h" #include "mbedtls/rsa.h" -// #include "mbedtls/sha1.h" -// #include "mbedtls/sha256.h" +#include "mbedtls/sha1.h" +#include "mbedtls/sha256.h" #include "mbedtls/sha512.h" #include "mbedtls/ssl_ciphersuites.h" #include "mbedtls/ssl.h" diff --git a/components/mbedtls/port/psa_driver/esp_aes/psa_crypto_driver_esp_aes_gcm.c b/components/mbedtls/port/psa_driver/esp_aes/psa_crypto_driver_esp_aes_gcm.c index d25fd109ee8..f15d0c35d43 100644 --- a/components/mbedtls/port/psa_driver/esp_aes/psa_crypto_driver_esp_aes_gcm.c +++ b/components/mbedtls/port/psa_driver/esp_aes/psa_crypto_driver_esp_aes_gcm.c @@ -27,7 +27,7 @@ static psa_status_t esp_crypto_aes_gcm_setup( psa_status_t status = PSA_ERROR_GENERIC_ERROR; if (alg != PSA_ALG_GCM) { - status = PSA_ERROR_INVALID_ARGUMENT; + status = PSA_ERROR_NOT_SUPPORTED; goto exit; } diff --git a/components/mbedtls/test_apps/main/app_main.c b/components/mbedtls/test_apps/main/app_main.c index f95a362f150..b51581b1d53 100644 --- a/components/mbedtls/test_apps/main/app_main.c +++ b/components/mbedtls/test_apps/main/app_main.c @@ -20,7 +20,6 @@ /* setUp runs before every test */ void setUp(void) { - // psa_crypto_init(); // Execute mbedtls_aes_init operation to allocate AES interrupt // allocation memory which is considered as leak otherwise #if SOC_AES_SUPPORTED diff --git a/components/mbedtls/test_apps/main/test_esp_crt_bundle.c b/components/mbedtls/test_apps/main/test_esp_crt_bundle.c index 140fb094afe..93330b79a65 100644 --- a/components/mbedtls/test_apps/main/test_esp_crt_bundle.c +++ b/components/mbedtls/test_apps/main/test_esp_crt_bundle.c @@ -466,14 +466,6 @@ TEST_CASE("custom certificate bundle - ECDSA signature verification", "[mbedtls] * This tests both the ECDSA algorithm path and a different hash algorithm (SHA-512) than * the RSA tests which use SHA-256. */ - // CRITICAL: Initialize PSA crypto subsystem before any PSA operations - // psa_status_t psa_status = psa_crypto_init(); - // if (psa_status != PSA_SUCCESS) { - // printf("PSA crypto initialization failed with status 0x%x\n", (unsigned int)psa_status); - // TEST_FAIL_MESSAGE("PSA crypto init failed"); - // } - // printf("PSA crypto initialized successfully\n"); - mbedtls_x509_crt crt; uint32_t flags = 0; diff --git a/components/mbedtls/test_apps/main/test_psa_cmac.c b/components/mbedtls/test_apps/main/test_psa_cmac.c index d0473725608..a22878f2638 100644 --- a/components/mbedtls/test_apps/main/test_psa_cmac.c +++ b/components/mbedtls/test_apps/main/test_psa_cmac.c @@ -63,10 +63,6 @@ TEST_CASE("PSA CMAC AES-128 test", "[psa_cmac]") psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT; psa_key_id_t key_id = 0; - // Initialize PSA Crypto - // status = psa_crypto_init(); - // TEST_ASSERT_EQUAL(PSA_SUCCESS, status); - // Set up key attributes psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_SIGN_MESSAGE | PSA_KEY_USAGE_VERIFY_MESSAGE); psa_set_key_algorithm(&attributes, PSA_ALG_CMAC); @@ -113,10 +109,6 @@ TEST_CASE("PSA CMAC AES-256 test", "[psa_cmac]") psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT; psa_key_id_t key_id = 0; - // Initialize PSA Crypto - // status = psa_crypto_init(); - // TEST_ASSERT_EQUAL(PSA_SUCCESS, status); - // Set up key attributes psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_SIGN_MESSAGE | PSA_KEY_USAGE_VERIFY_MESSAGE); psa_set_key_algorithm(&attributes, PSA_ALG_CMAC); @@ -162,10 +154,6 @@ TEST_CASE("PSA CMAC AES-128 multipart test", "[psa_cmac]") psa_key_id_t key_id = 0; psa_mac_operation_t operation = PSA_MAC_OPERATION_INIT; - // Initialize PSA Crypto - // status = psa_crypto_init(); - // TEST_ASSERT_EQUAL(PSA_SUCCESS, status); - // Set up key attributes psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_SIGN_MESSAGE | PSA_KEY_USAGE_VERIFY_MESSAGE); psa_set_key_algorithm(&attributes, PSA_ALG_CMAC); @@ -218,10 +206,6 @@ TEST_CASE("PSA CMAC AES-128 multipart verify test", "[psa_cmac]") psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT; psa_key_id_t key_id = 0; - // Initialize PSA Crypto - // status = psa_crypto_init(); - // TEST_ASSERT_EQUAL(PSA_SUCCESS, status); - // Set up key attributes psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_SIGN_MESSAGE | PSA_KEY_USAGE_VERIFY_MESSAGE); psa_set_key_algorithm(&attributes, PSA_ALG_CMAC); @@ -282,10 +266,6 @@ TEST_CASE("PSA CMAC zero-length test", "[psa_cmac]") psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT; psa_key_id_t key_id = 0; - // Initialize PSA Crypto - // status = psa_crypto_init(); - // TEST_ASSERT_EQUAL(PSA_SUCCESS, status); - // Set up key attributes psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_SIGN_MESSAGE | PSA_KEY_USAGE_VERIFY_MESSAGE); psa_set_key_algorithm(&attributes, PSA_ALG_CMAC); @@ -330,10 +310,6 @@ TEST_CASE("PSA CMAC memory alignment test", "[psa_cmac]") psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT; psa_key_id_t key_id = 0; - // Initialize PSA Crypto - // status = psa_crypto_init(); - // TEST_ASSERT_EQUAL(PSA_SUCCESS, status); - // Set up key attributes psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_SIGN_MESSAGE | PSA_KEY_USAGE_VERIFY_MESSAGE); psa_set_key_algorithm(&attributes, PSA_ALG_CMAC); @@ -388,10 +364,6 @@ TEST_CASE("PSA CMAC verify failure test", "[psa_cmac]") psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT; psa_key_id_t key_id = 0; - // Initialize PSA Crypto - // status = psa_crypto_init(); - // TEST_ASSERT_EQUAL(PSA_SUCCESS, status); - // Set up key attributes psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_VERIFY_MESSAGE); psa_set_key_algorithm(&attributes, PSA_ALG_CMAC); diff --git a/components/protocomm/src/crypto/srp6a/esp_srp.c b/components/protocomm/src/crypto/srp6a/esp_srp.c index f3213eca98d..9636931f06f 100644 --- a/components/protocomm/src/crypto/srp6a/esp_srp.c +++ b/components/protocomm/src/crypto/srp6a/esp_srp.c @@ -676,9 +676,6 @@ esp_err_t esp_srp_get_session_key(esp_srp_handle_t *hd, char *bytes_A, int len_A goto error; } - // psa_status_t status = psa_crypto_init(); - // ESP_RETURN_ON_FALSE(status == PSA_SUCCESS, ESP_FAIL, TAG, "Failed to initialize PSA crypto: %d", status); - psa_hash_operation_t hash_op = PSA_HASH_OPERATION_INIT; psa_status_t status = psa_hash_setup(&hash_op, PSA_ALG_SHA_512); ESP_RETURN_ON_FALSE(status == PSA_SUCCESS, ESP_FAIL, TAG, "Failed to setup hash operation: %d", status); diff --git a/components/protocomm/test_apps/main/test_protocomm.c b/components/protocomm/test_apps/main/test_protocomm.c index 9c272e6e65e..63cb026b65e 100644 --- a/components/protocomm/test_apps/main/test_protocomm.c +++ b/components/protocomm/test_apps/main/test_protocomm.c @@ -1178,36 +1178,30 @@ TEST_CASE("security 0 basic test", "[PROTOCOMM]") TEST_CASE("security 1 basic test", "[PROTOCOMM]") { - // psa_crypto_init(); TEST_ASSERT(test_security1() == ESP_OK); } TEST_CASE("security 1 no encryption test", "[PROTOCOMM]") { - // psa_crypto_init(); TEST_ASSERT(test_security1_no_encryption() == ESP_OK); } TEST_CASE("security 1 session overflow test", "[PROTOCOMM]") { - // psa_crypto_init(); TEST_ASSERT(test_security1_session_overflow() == ESP_OK); } TEST_CASE("security 1 wrong pop test", "[PROTOCOMM]") { - // psa_crypto_init(); TEST_ASSERT(test_security1_wrong_pop() == ESP_OK); } TEST_CASE("security 1 insecure client test", "[PROTOCOMM]") { - // psa_crypto_init(); TEST_ASSERT(test_security1_insecure_client() == ESP_OK); } TEST_CASE("security 1 weak session test", "[PROTOCOMM]") { - // psa_crypto_init(); TEST_ASSERT(test_security1_weak_session() == ESP_OK); } diff --git a/components/wpa_supplicant/esp_supplicant/src/crypto/crypto_mbedtls.c b/components/wpa_supplicant/esp_supplicant/src/crypto/crypto_mbedtls.c index 8b3997deace..2d09d1aa7b1 100644 --- a/components/wpa_supplicant/esp_supplicant/src/crypto/crypto_mbedtls.c +++ b/components/wpa_supplicant/esp_supplicant/src/crypto/crypto_mbedtls.c @@ -54,31 +54,32 @@ static int digest_vector(psa_algorithm_t alg, size_t num_elem, const u8 *addr[], const size_t *len, u8 *mac) { psa_hash_operation_t operation = PSA_HASH_OPERATION_INIT; + psa_status_t status; + int ret = -1; - psa_status_t status = psa_hash_setup(&operation, alg); + status = psa_hash_setup(&operation, alg); if (status != PSA_SUCCESS) { - return -1; + goto cleanup; } for (size_t i = 0; i < num_elem; i++) { status = psa_hash_update(&operation, addr[i], len[i]); if (status != PSA_SUCCESS) { - return -1; + goto cleanup; } } size_t mac_len; status = psa_hash_finish(&operation, mac, PSA_HASH_LENGTH(alg), &mac_len); if (status != PSA_SUCCESS) { - return -1; + goto cleanup; } - status = psa_hash_abort(&operation); - if (status != PSA_SUCCESS) { - return -1; - } + ret = 0; - return 0; +cleanup: + psa_hash_abort(&operation); + return ret; } int sha256_vector(size_t num_elem, const u8 *addr[], const size_t *len, @@ -193,6 +194,7 @@ struct crypto_hash * crypto_hash_init(enum crypto_hash_alg alg, const u8 *key, status = psa_mac_sign_setup(operation, key_id, PSA_ALG_HMAC(psa_alg)); if (status != PSA_SUCCESS) { + psa_destroy_key(key_id); os_free(operation); os_free(ctx); return NULL; @@ -428,6 +430,10 @@ static void *aes_crypt_init(int mode, const u8 *key, size_t len) psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT; psa_key_id_t *key_id = os_malloc(sizeof(psa_key_id_t)); + if (key_id == NULL) { + return NULL; + } + if (mode == MBEDTLS_ENCRYPT) { psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_ENCRYPT); } else if (mode == MBEDTLS_DECRYPT) { @@ -439,13 +445,13 @@ static void *aes_crypt_init(int mode, const u8 *key, size_t len) psa_set_key_bits(&attributes, len * 8); status = psa_import_key(&attributes, key, len, key_id); + psa_reset_key_attributes(&attributes); if (status != PSA_SUCCESS) { wpa_printf(MSG_ERROR, "%s: psa_import_key failed", __func__); + os_free(key_id); return NULL; } - psa_reset_key_attributes(&attributes); - return (void *) key_id; } @@ -455,6 +461,7 @@ static int aes_crypt(void *ctx, int mode, const u8 *in, u8 *out) psa_key_id_t *key_id = (psa_key_id_t *) ctx; psa_cipher_operation_t operation = PSA_CIPHER_OPERATION_INIT; size_t output_len; + int ret = -1; if (mode == MBEDTLS_ENCRYPT) { status = psa_cipher_encrypt_setup(&operation, *key_id, PSA_ALG_ECB_NO_PADDING); @@ -466,24 +473,27 @@ static int aes_crypt(void *ctx, int mode, const u8 *in, u8 *out) } if (status != PSA_SUCCESS) { wpa_printf(MSG_ERROR, "%s: psa_cipher_encrypt_setup failed", __func__); + psa_cipher_abort(&operation); return -1; } status = psa_cipher_update(&operation, in, 16, out, 16, &output_len); if (status != PSA_SUCCESS) { wpa_printf(MSG_ERROR, "%s: psa_cipher_update failed", __func__); - return -1; + goto cleanup; } status = psa_cipher_finish(&operation, out + output_len, 16 - output_len, &output_len); if (status != PSA_SUCCESS) { wpa_printf(MSG_ERROR, "%s: psa_cipher_finish failed", __func__); - return -1; + goto cleanup; } - psa_cipher_abort(&operation); + ret = 0; - return 0; +cleanup: + psa_cipher_abort(&operation); + return ret; } static void aes_crypt_deinit(void *ctx) @@ -1044,7 +1054,9 @@ int des_encrypt(const u8 *clear, const u8 *key, u8 *cypher) { psa_status_t status; psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT; - psa_key_id_t key_id; + psa_key_id_t key_id = 0; + psa_cipher_operation_t operation = PSA_CIPHER_OPERATION_INIT; + int ret = -1; psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_ENCRYPT); psa_set_key_algorithm(&attributes, PSA_ALG_ECB_NO_PADDING); @@ -1052,19 +1064,16 @@ int des_encrypt(const u8 *clear, const u8 *key, u8 *cypher) psa_set_key_bits(&attributes, 128); status = psa_import_key(&attributes, key, 8, &key_id); + psa_reset_key_attributes(&attributes); if (status != PSA_SUCCESS) { wpa_printf(MSG_ERROR, "%s: psa_import_key failed", __func__); return -1; } - psa_reset_key_attributes(&attributes); - - psa_cipher_operation_t operation = PSA_CIPHER_OPERATION_INIT; - status = psa_cipher_encrypt_setup(&operation, key_id, PSA_ALG_ECB_NO_PADDING); if (status != PSA_SUCCESS) { wpa_printf(MSG_ERROR, "%s: psa_cipher_encrypt_setup failed", __func__); - return -1; + goto cleanup; } size_t output_length = 0; @@ -1072,20 +1081,24 @@ int des_encrypt(const u8 *clear, const u8 *key, u8 *cypher) status = psa_cipher_update(&operation, clear, 8, cypher, 8, &output_length); if (status != PSA_SUCCESS) { wpa_printf(MSG_ERROR, "%s: psa_cipher_update failed", __func__); - return -1; + goto cleanup; } status = psa_cipher_finish(&operation, cypher + output_length, 8 - output_length, &output_length); if (status != PSA_SUCCESS) { wpa_printf(MSG_ERROR, "%s: psa_cipher_finish failed", __func__); - return -1; + goto cleanup; } + ret = 0; + +cleanup: psa_cipher_abort(&operation); + if (key_id) { + psa_destroy_key(key_id); + } - psa_destroy_key(key_id); - - return 0; + return ret; } #endif @@ -1180,6 +1193,9 @@ int aes_ccm_ad(const u8 *key, size_t key_len, const u8 *nonce, psa_status_t status; psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT; psa_key_id_t key_id; + u8 *ciphertext_with_tag = NULL; + size_t plaintext_length = 0; + int ret = -1; psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_DECRYPT); psa_set_key_algorithm(&attributes, PSA_ALG_CCM); @@ -1187,71 +1203,45 @@ int aes_ccm_ad(const u8 *key, size_t key_len, const u8 *nonce, psa_set_key_bits(&attributes, key_len * 8); status = psa_import_key(&attributes, key, key_len, &key_id); + psa_reset_key_attributes(&attributes); if (status != PSA_SUCCESS) { wpa_printf(MSG_ERROR, "%s: psa_import_key failed", __func__); return -1; } - psa_reset_key_attributes(&attributes); + /* psa_aead_decrypt expects the tag to be appended to the ciphertext */ + ciphertext_with_tag = os_malloc(crypt_len + M); + if (ciphertext_with_tag == NULL) { + wpa_printf(MSG_ERROR, "%s: os_malloc failed", __func__); + goto cleanup; + } + os_memcpy(ciphertext_with_tag, crypt, crypt_len); + os_memcpy(ciphertext_with_tag + crypt_len, auth, M); - psa_aead_operation_t operation = PSA_AEAD_OPERATION_INIT; - - status = psa_aead_decrypt_setup(&operation, key_id, PSA_ALG_CCM); + status = psa_aead_decrypt(key_id, PSA_ALG_CCM, + nonce, 13, + aad, aad_len, + ciphertext_with_tag, crypt_len + M, + plain, crypt_len, &plaintext_length); if (status != PSA_SUCCESS) { - wpa_printf(MSG_ERROR, "%s: psa_aead_decrypt_setup failed", __func__); - psa_destroy_key(key_id); - return -1; + wpa_printf(MSG_ERROR, "%s: psa_aead_decrypt failed, status: %d", __func__, status); + goto cleanup; } - status = psa_aead_set_nonce(&operation, nonce, 13); - if (status != PSA_SUCCESS) { - wpa_printf(MSG_ERROR, "%s: psa_aead_set_nonce failed", __func__); - psa_aead_abort(&operation); - psa_destroy_key(key_id); - return -1; + if (plaintext_length != crypt_len) { + wpa_printf(MSG_ERROR, "%s: plaintext length mismatch: expected %zu, got %zu", __func__, crypt_len, plaintext_length); + goto cleanup; } - status = psa_aead_set_lengths(&operation, aad_len, crypt_len); - if (status != PSA_SUCCESS) { - wpa_printf(MSG_ERROR, "%s: psa_aead_set_lengths failed", __func__); - psa_aead_abort(&operation); - psa_destroy_key(key_id); - return -1; + ret = 0; + +cleanup: + if (ciphertext_with_tag) { + os_free(ciphertext_with_tag); } - - size_t output_length = 0; - size_t tag_len = 0; - - status = psa_aead_update_ad(&operation, aad, aad_len); - if (status != PSA_SUCCESS) { - wpa_printf(MSG_ERROR, "%s: psa_aead_update_ad failed", __func__); - psa_aead_abort(&operation); - psa_destroy_key(key_id); - return -1; - } - - status = psa_aead_update(&operation, crypt, crypt_len, plain, crypt_len, &output_length); - if (status != PSA_SUCCESS) { - wpa_printf(MSG_ERROR, "%s: psa_aead_update failed", __func__); - psa_aead_abort(&operation); - psa_destroy_key(key_id); - return -1; - } - - size_t verify_output = 0; - status = psa_aead_verify(&operation, plain + output_length, crypt_len - output_length, &verify_output, auth, M); - if (status != PSA_SUCCESS) { - wpa_printf(MSG_ERROR, "%s: psa_aead_verify failed", __func__); - psa_aead_abort(&operation); - psa_destroy_key(key_id); - return -1; - } - - psa_aead_abort(&operation); - psa_destroy_key(key_id); - return 0; + return ret; } #endif @@ -1265,7 +1255,9 @@ int omac1_aes_vector(const u8 *key, size_t key_len, size_t num_elem, psa_status_t status; psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT; - psa_key_id_t key_id; + psa_key_id_t key_id = 0; + psa_mac_operation_t operation = PSA_MAC_OPERATION_INIT; + int ret = -1; psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_SIGN_HASH); psa_set_key_algorithm(&attributes, PSA_ALG_CMAC); @@ -1275,24 +1267,22 @@ int omac1_aes_vector(const u8 *key, size_t key_len, size_t num_elem, status = psa_import_key(&attributes, key, key_len, &key_id); if (status != PSA_SUCCESS) { wpa_printf(MSG_ERROR, "%s: psa_import_key failed", __func__); - return -1; + goto cleanup; } psa_reset_key_attributes(&attributes); - psa_mac_operation_t operation = PSA_MAC_OPERATION_INIT; - status = psa_mac_sign_setup(&operation, key_id, PSA_ALG_CMAC); if (status != PSA_SUCCESS) { wpa_printf(MSG_ERROR, "%s: psa_mac_sign_setup failed", __func__); - return -1; + goto cleanup; } for (int i = 0; i < num_elem; i++) { status = psa_mac_update(&operation, addr[i], len[i]); if (status != PSA_SUCCESS) { wpa_printf(MSG_ERROR, "%s: psa_mac_update failed", __func__); - return -1; + goto cleanup; } } @@ -1301,14 +1291,18 @@ int omac1_aes_vector(const u8 *key, size_t key_len, size_t num_elem, status = psa_mac_sign_finish(&operation, mac, 16, &output_length); if (status != PSA_SUCCESS) { wpa_printf(MSG_ERROR, "%s: psa_mac_sign_finish failed", __func__); - return -1; + goto cleanup; } + ret = 0; + +cleanup: psa_mac_abort(&operation); + if (key_id != 0) { + psa_destroy_key(key_id); + } - psa_destroy_key(key_id); - - return 0; + return ret; } diff --git a/components/wpa_supplicant/esp_supplicant/src/crypto/tls_mbedtls.c b/components/wpa_supplicant/esp_supplicant/src/crypto/tls_mbedtls.c index ba0a0f3e961..226ac3a0ea1 100644 --- a/components/wpa_supplicant/esp_supplicant/src/crypto/tls_mbedtls.c +++ b/components/wpa_supplicant/esp_supplicant/src/crypto/tls_mbedtls.c @@ -699,15 +699,6 @@ int tls_connection_set_verify(void *tls_ctx, struct tls_connection *conn, } #ifdef CONFIG_ESP_WIFI_ENT_FREE_DYNAMIC_BUFFER -static void esp_mbedtls_free_dhm(mbedtls_ssl_context *ssl) -{ -#ifdef CONFIG_MBEDTLS_DHM_C - // const mbedtls_ssl_config *conf = mbedtls_ssl_context_get_config(ssl); - // mbedtls_mpi_free((mbedtls_mpi *)&conf->MBEDTLS_PRIVATE(dhm_P)); - // mbedtls_mpi_free((mbedtls_mpi *)&conf->MBEDTLS_PRIVATE(dhm_G)); -#endif /* CONFIG_MBEDTLS_DHM_C */ -} - static void esp_mbedtls_free_keycert(mbedtls_ssl_context *ssl) { mbedtls_ssl_config *conf = (mbedtls_ssl_config *)mbedtls_ssl_context_get_config(ssl); @@ -780,7 +771,6 @@ struct wpabuf * tls_connection_handshake(void *tls_ctx, if (cli_state == MBEDTLS_SSL_SERVER_CERTIFICATE) { esp_mbedtls_free_cacert(&tls->ssl); } else if (cli_state == MBEDTLS_SSL_CERTIFICATE_VERIFY) { - esp_mbedtls_free_dhm(&tls->ssl); esp_mbedtls_free_keycert_key(&tls->ssl); esp_mbedtls_free_keycert(&tls->ssl); } diff --git a/components/wpa_supplicant/test_apps/main/test_wpa_supplicant_main.c b/components/wpa_supplicant/test_apps/main/test_wpa_supplicant_main.c index b8e51256c7e..c6217b2d16f 100644 --- a/components/wpa_supplicant/test_apps/main/test_wpa_supplicant_main.c +++ b/components/wpa_supplicant/test_apps/main/test_wpa_supplicant_main.c @@ -86,15 +86,12 @@ void setUp(void) esp_mpi_disable_hardware_hw_op(); #endif // CONFIG_MBEDTLS_HARDWARE_MPI - // psa_crypto_init(); - before_free_8bit = heap_caps_get_free_size(MALLOC_CAP_8BIT); before_free_32bit = heap_caps_get_free_size(MALLOC_CAP_32BIT); } void tearDown(void) { - // mbedtls_psa_crypto_free(); size_t after_free_8bit = heap_caps_get_free_size(MALLOC_CAP_8BIT); size_t after_free_32bit = heap_caps_get_free_size(MALLOC_CAP_32BIT); check_leak(before_free_8bit, after_free_8bit, "8BIT"); diff --git a/examples/bluetooth/blufi/main/blufi_security.c b/examples/bluetooth/blufi/main/blufi_security.c index 3fd38a29ac7..1e126cfbbf5 100644 --- a/examples/bluetooth/blufi/main/blufi_security.c +++ b/examples/bluetooth/blufi/main/blufi_security.c @@ -137,7 +137,7 @@ void blufi_dh_negotiate_data_handler(uint8_t *data, int len, uint8_t **output_da } psa_reset_key_attributes(&attributes); size_t public_key_len = 0; - status = psa_export_public_key(private_key, blufi_sec->self_public_key, DH_SELF_PUB_KEY_LEN, &public_key_len);\ + status = psa_export_public_key(private_key, blufi_sec->self_public_key, DH_SELF_PUB_KEY_LEN, &public_key_len); if (status != PSA_SUCCESS) { BLUFI_ERROR("%s psa_export_public_key failed %d\n", __func__, status); psa_destroy_key(private_key); @@ -151,6 +151,7 @@ void blufi_dh_negotiate_data_handler(uint8_t *data, int len, uint8_t **output_da BLUFI_ERROR("%s psa_raw_key_agreement failed %d\n", __func__, status); free(blufi_sec->dh_param); blufi_sec->dh_param = NULL; + btc_blufi_report_error(ESP_BLUFI_DH_PARAM_ERROR); return; } diff --git a/examples/security/tee/tee_basic/components/example_secure_service/example_service.c b/examples/security/tee/tee_basic/components/example_secure_service/example_service.c index fdd7c02116e..42374c38fe2 100644 --- a/examples/security/tee/tee_basic/components/example_secure_service/example_service.c +++ b/examples/security/tee/tee_basic/components/example_secure_service/example_service.c @@ -51,7 +51,6 @@ static esp_err_t aes_gcm_crypt_common(example_aes_gcm_ctx_t *ctx, uint8_t *tag, esp_err_t err = ESP_FAIL; #if CONFIG_MBEDTLS_VER_4_X_SUPPORT - psa_crypto_init(); psa_aead_operation_t operation = PSA_AEAD_OPERATION_INIT; psa_status_t status; psa_key_id_t key_id;