mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-03 03:31:41 +03:00
feat(esp_http): migrate esp_http to PSA API
This commit is contained in:
@@ -167,6 +167,10 @@ list(APPEND mbedtls_targets everest p256m)
|
||||
set(mbedtls_target_sources "${COMPONENT_DIR}/port/mbedtls_debug.c"
|
||||
"${COMPONENT_DIR}/port/esp_platform_time.c")
|
||||
|
||||
if(CONFIG_MBEDTLS_ESP_IDF_USE_PSA_CRYPTO)
|
||||
list(APPEND mbedtls_target_sources "${COMPONENT_DIR}/port/esp_psa_crypto_init.c")
|
||||
endif()
|
||||
|
||||
if(CONFIG_MBEDTLS_DYNAMIC_BUFFER)
|
||||
set(mbedtls_target_sources ${mbedtls_target_sources}
|
||||
"${COMPONENT_DIR}/port/dynamic/esp_mbedtls_dynamic_impl.c"
|
||||
@@ -357,14 +361,14 @@ foreach(target ${mbedtls_targets})
|
||||
endif()
|
||||
if(CONFIG_MBEDTLS_COMPILER_OPTIMIZATION_SIZE)
|
||||
target_compile_options(${target} PRIVATE "-Os")
|
||||
elseif(CONFIG_MBEDTLS_COMPILER_OPTIMIZATION_SPEED)
|
||||
elseif(CONFIG_MBEDTLS_COMPILER_OPTIMIZATION_PERF)
|
||||
target_compile_options(${target} PRIVATE "-O2")
|
||||
endif()
|
||||
endforeach()
|
||||
|
||||
if(CONFIG_MBEDTLS_COMPILER_OPTIMIZATION_SIZE)
|
||||
target_compile_options(${COMPONENT_LIB} PRIVATE "-Os")
|
||||
elseif(CONFIG_MBEDTLS_COMPILER_OPTIMIZATION_SPEED)
|
||||
elseif(CONFIG_MBEDTLS_COMPILER_OPTIMIZATION_PERF)
|
||||
target_compile_options(${COMPONENT_LIB} PRIVATE "-O2")
|
||||
endif()
|
||||
|
||||
@@ -398,6 +402,9 @@ endif()
|
||||
|
||||
target_link_libraries(${COMPONENT_LIB} ${linkage_type} ${mbedtls_targets})
|
||||
|
||||
# Ensure PSA crypto initialization is included in the build
|
||||
target_link_libraries(${COMPONENT_LIB} ${linkage_type} "-u mbedtls_psa_crypto_init_include_impl")
|
||||
|
||||
if(CONFIG_ESP_TLS_USE_DS_PERIPHERAL)
|
||||
# The linker seems to be unable to resolve all the dependencies without increasing this
|
||||
set_property(TARGET mbedcrypto APPEND PROPERTY LINK_INTERFACE_MULTIPLICITY 6)
|
||||
|
||||
@@ -1,6 +1,15 @@
|
||||
menu "mbedTLS"
|
||||
|
||||
menu "Core Configuration"
|
||||
|
||||
config MBEDTLS_ESP_IDF_USE_PSA_CRYPTO
|
||||
depends on IDF_EXPERIMENTAL_FEATURES
|
||||
bool "Enable the Platform Security Architecture (PSA) cryptography API for ESP-IDF"
|
||||
default y
|
||||
help
|
||||
Enable the Platform Security Architecture (PSA) cryptography API for ESP-IDF.
|
||||
This option migrates from mbedtls API to PSA Crypto API. This increases code size.
|
||||
|
||||
choice MBEDTLS_COMPILER_OPTIMIZATION
|
||||
prompt "Compiler optimization level"
|
||||
default MBEDTLS_COMPILER_OPTIMIZATION_NONE
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2021-2022 Espressif Systems (Shanghai) CO LTD
|
||||
* SPDX-FileCopyrightText: 2021-2025 Espressif Systems (Shanghai) CO LTD
|
||||
*
|
||||
* SPDX-License-Identifier: Apache-2.0
|
||||
*/
|
||||
@@ -10,6 +10,9 @@
|
||||
#include <stdio.h>
|
||||
#include "esp_random.h"
|
||||
#include "mbedtls/esp_mbedtls_random.h"
|
||||
#if defined(MBEDTLS_PLATFORM_GET_ENTROPY_ALT)
|
||||
#include "psa/crypto.h"
|
||||
#endif
|
||||
|
||||
#include <entropy_poll.h>
|
||||
|
||||
@@ -31,3 +34,33 @@ int mbedtls_esp_random(void *ctx, unsigned char *buf, size_t len)
|
||||
esp_fill_random(buf, len);
|
||||
return 0;
|
||||
}
|
||||
|
||||
#if defined(MBEDTLS_PLATFORM_GET_ENTROPY_ALT)
|
||||
int mbedtls_platform_get_entropy(unsigned char *output, size_t output_size,
|
||||
size_t *output_len, size_t *entropy_content);
|
||||
|
||||
psa_status_t mbedtls_psa_external_get_random(
|
||||
mbedtls_psa_external_random_context_t *context,
|
||||
uint8_t *output, size_t output_size, size_t *output_length)
|
||||
{
|
||||
if (context == NULL || output == NULL || output_length == NULL) {
|
||||
return PSA_ERROR_INVALID_ARGUMENT;
|
||||
}
|
||||
esp_fill_random(output, output_size);
|
||||
*output_length = output_size;
|
||||
return PSA_SUCCESS;
|
||||
}
|
||||
|
||||
int mbedtls_platform_get_entropy(unsigned char *output, size_t output_size,
|
||||
size_t *output_len, size_t *entropy_content)
|
||||
{
|
||||
if (output == NULL || output_size == 0 || output_len == NULL || entropy_content == NULL) {
|
||||
return -1;
|
||||
}
|
||||
|
||||
esp_fill_random(output, output_size);
|
||||
*output_len = output_size;
|
||||
*entropy_content = 8 * output_size;
|
||||
return 0;
|
||||
}
|
||||
#endif // MBEDTLS_PLATFORM_GET_ENTROPY_ALT
|
||||
|
||||
@@ -0,0 +1,34 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2025 Espressif Systems (Shanghai) CO LTD
|
||||
*
|
||||
* SPDX-License-Identifier: Apache-2.0
|
||||
*/
|
||||
|
||||
#include "esp_private/startup_internal.h"
|
||||
#include "psa/crypto.h"
|
||||
#include "esp_err.h"
|
||||
#include "esp_log.h"
|
||||
#include "sdkconfig.h"
|
||||
|
||||
void mbedtls_psa_crypto_init_include_impl(void);
|
||||
|
||||
/**
|
||||
* @brief Initialize PSA Crypto library at system startup
|
||||
*
|
||||
* This function is called during the SECONDARY initialization stage with priority 104,
|
||||
* which ensures it runs after esp_security_init (priority 103). This ordering guarantees
|
||||
* that hardware crypto support is fully initialized before PSA crypto initialization.
|
||||
*/
|
||||
ESP_SYSTEM_INIT_FN(mbedtls_psa_crypto_init_fn, SECONDARY, BIT(0), 104)
|
||||
{
|
||||
psa_status_t status = psa_crypto_init();
|
||||
if (status != PSA_SUCCESS) {
|
||||
return ESP_FAIL;
|
||||
}
|
||||
return ESP_OK;
|
||||
}
|
||||
|
||||
void mbedtls_psa_crypto_init_include_impl(void)
|
||||
{
|
||||
// Linker hook, exists for no other purpose
|
||||
}
|
||||
@@ -36,6 +36,12 @@
|
||||
* \{
|
||||
*/
|
||||
|
||||
#ifndef CONFIG_IDF_TARGET_LINUX
|
||||
#define MBEDTLS_PLATFORM_GET_ENTROPY_ALT
|
||||
#define MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG
|
||||
#endif // !CONFIG_IDF_TARGET_LINUX
|
||||
#define MBEDTLS_PSA_ASSUME_EXCLUSIVE_BUFFERS
|
||||
|
||||
/**
|
||||
* \def MBEDTLS_HAVE_TIME
|
||||
*
|
||||
|
||||
Reference in New Issue
Block a user