diff --git a/components/idf_test/include/esp32/idf_performance_target.h b/components/idf_test/include/esp32/idf_performance_target.h index c14f04df94a..81c3dbad993 100644 --- a/components/idf_test/include/esp32/idf_performance_target.h +++ b/components/idf_test/include/esp32/idf_performance_target.h @@ -21,11 +21,11 @@ #define IDF_PERFORMANCE_MAX_TIME_SHA1_32KB 5000 #define IDF_PERFORMANCE_MAX_TIME_SHA512_32KB 4500 -#define IDF_PERFORMANCE_MAX_RSA_2048KEY_PUBLIC_OP 21500 +#define IDF_PERFORMANCE_MAX_RSA_2048KEY_PUBLIC_OP 45000 #define IDF_PERFORMANCE_MAX_RSA_2048KEY_PRIVATE_OP 750000 #define IDF_PERFORMANCE_MAX_RSA_3072KEY_PUBLIC_OP 33000 #define IDF_PERFORMANCE_MAX_RSA_3072KEY_PRIVATE_OP 950000 -#define IDF_PERFORMANCE_MAX_RSA_4096KEY_PUBLIC_OP 90000 +#define IDF_PERFORMANCE_MAX_RSA_4096KEY_PUBLIC_OP 170000 #define IDF_PERFORMANCE_MAX_RSA_4096KEY_PRIVATE_OP 3000000 // floating point instructions per divide and per sqrt (configured for worst-case with PSRAM workaround) diff --git a/components/idf_test/include/esp32s2/idf_performance_target.h b/components/idf_test/include/esp32s2/idf_performance_target.h index 5d64e1fbb26..be8c23e21d2 100644 --- a/components/idf_test/include/esp32s2/idf_performance_target.h +++ b/components/idf_test/include/esp32s2/idf_performance_target.h @@ -16,11 +16,11 @@ #define IDF_PERFORMANCE_MAX_TIME_SHA1_32KB 900 #define IDF_PERFORMANCE_MAX_TIME_SHA512_32KB 900 -#define IDF_PERFORMANCE_MAX_RSA_2048KEY_PUBLIC_OP 17000 +#define IDF_PERFORMANCE_MAX_RSA_2048KEY_PUBLIC_OP 36000 #define IDF_PERFORMANCE_MAX_RSA_2048KEY_PRIVATE_OP 650000 #define IDF_PERFORMANCE_MAX_RSA_3072KEY_PUBLIC_OP 36000 #define IDF_PERFORMANCE_MAX_RSA_3072KEY_PRIVATE_OP 960000 -#define IDF_PERFORMANCE_MAX_RSA_4096KEY_PUBLIC_OP 70000 +#define IDF_PERFORMANCE_MAX_RSA_4096KEY_PUBLIC_OP 141000 #define IDF_PERFORMANCE_MAX_RSA_4096KEY_PRIVATE_OP 2850000 #define IDF_PERFORMANCE_MAX_ADC_CONTINUOUS_STD_ATTEN3_NO_FILTER 3 diff --git a/components/idf_test/include/esp32s3/idf_performance_target.h b/components/idf_test/include/esp32s3/idf_performance_target.h index e6f10be50e2..b2cf11dc4f4 100644 --- a/components/idf_test/include/esp32s3/idf_performance_target.h +++ b/components/idf_test/include/esp32s3/idf_performance_target.h @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2020-2022 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2020-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -14,11 +14,11 @@ #define IDF_PERFORMANCE_MAX_TIME_SHA1_32KB 1000 #define IDF_PERFORMANCE_MAX_TIME_SHA512_32KB 900 -#define IDF_PERFORMANCE_MAX_RSA_2048KEY_PUBLIC_OP 24000 +#define IDF_PERFORMANCE_MAX_RSA_2048KEY_PUBLIC_OP 45000 #define IDF_PERFORMANCE_MAX_RSA_2048KEY_PRIVATE_OP 700000 #define IDF_PERFORMANCE_MAX_RSA_3072KEY_PUBLIC_OP 45000 -#define IDF_PERFORMANCE_MAX_RSA_3072KEY_PRIVATE_OP 1300000 -#define IDF_PERFORMANCE_MAX_RSA_4096KEY_PUBLIC_OP 90000 +#define IDF_PERFORMANCE_MAX_RSA_3072KEY_PRIVATE_OP 300000 +#define IDF_PERFORMANCE_MAX_RSA_4096KEY_PUBLIC_OP 190000 #define IDF_PERFORMANCE_MAX_RSA_4096KEY_PRIVATE_OP 3500000 // floating point instructions per divide and per sqrt (configured for worst-case with PSRAM workaround) diff --git a/components/mbedtls/CMakeLists.txt b/components/mbedtls/CMakeLists.txt index b3ef2185a4a..65cd49391eb 100644 --- a/components/mbedtls/CMakeLists.txt +++ b/components/mbedtls/CMakeLists.txt @@ -22,7 +22,7 @@ if(NOT ${IDF_TARGET} STREQUAL "linux") set(priv_requires soc esp_hw_support) if(NOT BOOTLOADER_BUILD) list(APPEND priv_requires esp_pm esp_driver_dma) - set(requires esp_security) + set(requires esp_security esp_hal_security) endif() endif() @@ -33,6 +33,7 @@ set(mbedtls_include_dirs "mbedtls/library" "mbedtls/tf-psa-crypto/core" "mbedtls/tf-psa-crypto/drivers/builtin/src/" + "mbedtls/tf-psa-crypto/extras" ) if(CONFIG_MBEDTLS_USE_CRYPTO_ROM_IMPL) @@ -44,6 +45,7 @@ if(CONFIG_MBEDTLS_CERTIFICATE_BUNDLE) list(APPEND mbedtls_include_dirs "esp_crt_bundle/include") endif() + list(APPEND mbedtls_include_dirs "${COMPONENT_DIR}/port/psa_driver/include") idf_component_register(SRCS "${mbedtls_srcs}" @@ -54,6 +56,7 @@ idf_component_register(SRCS "${mbedtls_srcs}" # Add MBEDTLS_MAJOR_VERSION definition to the component library target_compile_definitions(${COMPONENT_LIB} INTERFACE MBEDTLS_MAJOR_VERSION=4) +target_compile_definitions(${COMPONENT_LIB} INTERFACE __STDC_WANT_LIB_EXT1__=0) # Set the type of mbedtls component library set(linkage_type PUBLIC) @@ -177,8 +180,15 @@ if(CONFIG_MBEDTLS_SSL_PROTO_GMTSSL1_1) set_property(TARGET mbedx509 PROPERTY SOURCES ${src_x509}) endif() -# Core libraries from the mbedTLS project -set(mbedtls_targets mbedtls mbedx509 tfpsacrypto builtin) +# Core libraries from the mbedTLS project, including 3rd-party (everest, +# p256-m) and the new tf-psa-crypto sub-libs introduced in 4.1 +# (extras, platform, utilities). All of these need MBEDTLS_CONFIG_FILE +# and the optimization flags applied uniformly; previously the loop ran +# before the 3rd-party / new targets were appended, leaving them at the +# default ESP-IDF -Og without esp_config.h. +set(mbedtls_compile_targets mbedtls mbedx509 tfpsacrypto builtin + everest p256-m extras platform utilities) +set(mbedtls_link_targets mbedtls mbedx509 tfpsacrypto) add_library(mbed-builtin ALIAS builtin) set_target_properties(builtin PROPERTIES OUTPUT_NAME "mbed-builtin") @@ -186,7 +196,10 @@ set_target_properties(builtin PROPERTIES OUTPUT_NAME "mbed-builtin") target_include_directories(tfpsacrypto PUBLIC "port/include") message(STATUS "Setting up mbedtls configuration") -foreach(target ${mbedtls_targets}) +foreach(target ${mbedtls_compile_targets}) + if(NOT TARGET ${target}) + continue() + endif() target_compile_definitions(${target} PUBLIC -DMBEDTLS_CONFIG_FILE="mbedtls/esp_config.h") set_config_files_compile_definitions(${target}) target_compile_definitions(${target} PUBLIC MBEDTLS_MAJOR_VERSION=4) @@ -200,9 +213,6 @@ foreach(target ${mbedtls_targets}) endif() endforeach() -# 3rd party libraries from the mbedTLS project -list(APPEND mbedtls_targets everest p256m) - set(mbedtls_target_sources "${COMPONENT_DIR}/port/mbedtls_debug.c" "${COMPONENT_DIR}/port/esp_platform_time.c" "${COMPONENT_DIR}/port/esp_timing.c") @@ -212,8 +222,8 @@ list(APPEND mbedtls_target_sources "${COMPONENT_DIR}/port/esp_psa_crypto_init.c" # Only compile esp_psa_its.c if nvs_flash component is available if(NOT ${IDF_TARGET} STREQUAL "linux") if(IDF_BUILD_V2) - # For v2: conditionally compile source and link only if nvs_flash target exists - target_sources( + # For v2: conditionally compile source and link only if nvs_flash target exists + target_sources( tfpsacrypto PRIVATE "$<$:${COMPONENT_DIR}/port/psa_crypto_storage/esp_psa_its.c>" ) @@ -270,13 +280,31 @@ endif() # Add port files to mbedtls targets target_sources(mbedtls PRIVATE ${mbedtls_target_sources}) +target_compile_definitions(mbedtls PUBLIC __STDC_WANT_LIB_EXT1__=0) if(NOT ${IDF_TARGET} STREQUAL "linux") - target_link_libraries(tfpsacrypto PUBLIC idf::esp_security) + # All tf-psa-crypto internal targets need esp_security includes because + # the public PSA crypto header chain (psa/crypto.h -> crypto_struct.h -> + # crypto_driver_contexts_composites.h) includes ESP driver context headers + # that depend on esp_security headers (e.g., esp_ds.h). + target_link_libraries(tfpsacrypto PRIVATE idf::esp_security) target_link_libraries(builtin PRIVATE idf::esp_security) - target_link_libraries(p256m PRIVATE idf::esp_security) + target_link_libraries(p256-m PRIVATE idf::esp_security) + target_link_libraries(extras PRIVATE idf::esp_security) + target_link_libraries(platform PRIVATE idf::esp_security) + target_link_libraries(utilities PRIVATE idf::esp_security) + target_link_libraries(mbedtls PRIVATE idf::esp_security) + target_link_libraries(mbedx509 PRIVATE idf::esp_security) + endif() +# Workaround: CMake 4.x Unix Makefiles generator fails to create build-order +# dependencies for STATIC library targets consumed via $ when +# they are also linked via target_link_libraries in the same target. This +# ensures builtin/everest/p256-m are compiled before tfpsacrypto archives +# their objects into libtfpsacrypto.a. +add_dependencies(tfpsacrypto builtin everest p256-m extras platform utilities) + # Choose peripheral type if(CONFIG_SOC_SHA_SUPPORTED) @@ -377,11 +405,11 @@ if(CONFIG_SOC_HMAC_SUPPORTED) endif() if(CONFIG_SOC_DIG_SIGN_SUPPORTED AND CONFIG_MBEDTLS_HARDWARE_RSA_DS_PERIPHERAL) -target_sources(tfpsacrypto PRIVATE + target_sources(tfpsacrypto PRIVATE "${COMPONENT_DIR}/port/psa_driver/esp_rsa_ds/psa_crypto_driver_esp_rsa_ds.c" "${COMPONENT_DIR}/port/psa_driver/esp_rsa_ds/psa_crypto_driver_esp_rsa_ds_utilities.c" ) -target_link_libraries(tfpsacrypto PRIVATE idf::efuse) + target_link_libraries(tfpsacrypto PRIVATE idf::efuse) endif() if(CONFIG_SOC_HMAC_SUPPORTED) @@ -479,7 +507,7 @@ if(CONFIG_PM_ENABLE) target_link_libraries(tfpsacrypto PRIVATE idf::esp_pm) endif() -target_link_libraries(${COMPONENT_LIB} ${linkage_type} ${mbedtls_targets}) +target_link_libraries(${COMPONENT_LIB} ${linkage_type} ${mbedtls_link_targets}) # Ensure PSA crypto initialization is included in the build if(NOT ${IDF_TARGET} STREQUAL "linux") diff --git a/components/mbedtls/mbedtls b/components/mbedtls/mbedtls index ae71b9e470b..8bfdb425305 160000 --- a/components/mbedtls/mbedtls +++ b/components/mbedtls/mbedtls @@ -1 +1 @@ -Subproject commit ae71b9e470b9dd7ab6f388079b64c0556563cbbe +Subproject commit 8bfdb42530588ab6027ab6a5e7bd34385cb749d2 diff --git a/components/mbedtls/port/ecc/ecc_alt.c b/components/mbedtls/port/ecc/ecc_alt.c index b9bae3204d0..c12f60707b3 100644 --- a/components/mbedtls/port/ecc/ecc_alt.c +++ b/components/mbedtls/port/ecc/ecc_alt.c @@ -55,7 +55,7 @@ int ecp_mul_restartable_internal( mbedtls_ecp_group *grp, mbedtls_ecp_point *R, mbedtls_ecp_restart_ctx *rs_ctx ) { int ret = MBEDTLS_ERR_ECP_BAD_INPUT_DATA; - if (grp->id != MBEDTLS_ECP_DP_SECP192R1 && grp->id != MBEDTLS_ECP_DP_SECP256R1 + if (grp->id != MBEDTLS_ECP_DP_SECP256R1 #if SOC_ECC_SUPPORT_CURVE_P384 && (grp->id != MBEDTLS_ECP_DP_SECP384R1 || !ecc_ll_is_p384_curve_operations_supported()) #endif @@ -90,7 +90,7 @@ int mbedtls_ecp_check_pubkey( const mbedtls_ecp_group *grp, return MBEDTLS_ERR_ECP_BAD_INPUT_DATA; } - if (grp->id != MBEDTLS_ECP_DP_SECP192R1 && grp->id != MBEDTLS_ECP_DP_SECP256R1 + if (grp->id != MBEDTLS_ECP_DP_SECP256R1 #if SOC_ECC_SUPPORT_CURVE_P384 && (grp->id != MBEDTLS_ECP_DP_SECP384R1 || !ecc_ll_is_p384_curve_operations_supported()) #endif diff --git a/components/mbedtls/port/esp_timing.c b/components/mbedtls/port/esp_timing.c index f461af36162..e883f70e33f 100644 --- a/components/mbedtls/port/esp_timing.c +++ b/components/mbedtls/port/esp_timing.c @@ -26,7 +26,7 @@ struct _hr_time struct timeval start; }; -unsigned long mbedtls_timing_get_timer( struct mbedtls_timing_hr_time *val, int reset ) +unsigned long long mbedtls_timing_get_timer( struct mbedtls_timing_hr_time *val, int reset ) { struct _hr_time *t = (struct _hr_time *) val; diff --git a/components/mbedtls/port/psa_driver/include/psa_crypto_driver_esp_hmac_opaque_contexts.h b/components/mbedtls/port/psa_driver/include/psa_crypto_driver_esp_hmac_opaque_contexts.h index 6586739fb59..bf66e66b45d 100644 --- a/components/mbedtls/port/psa_driver/include/psa_crypto_driver_esp_hmac_opaque_contexts.h +++ b/components/mbedtls/port/psa_driver/include/psa_crypto_driver_esp_hmac_opaque_contexts.h @@ -9,7 +9,6 @@ #include "esp_types.h" #include "soc/soc_caps.h" #include "psa/crypto_driver_common.h" -#include "hal/hmac_types.h" #if SOC_KEY_MANAGER_SUPPORTED #include "esp_key_mgr.h" diff --git a/components/mbedtls/test_apps/main/test_ecp.c b/components/mbedtls/test_apps/main/test_ecp.c index df8a684339a..dd2c395bde7 100644 --- a/components/mbedtls/test_apps/main/test_ecp.c +++ b/components/mbedtls/test_apps/main/test_ecp.c @@ -13,7 +13,6 @@ #include #include #define MBEDTLS_DECLARE_PRIVATE_IDENTIFIERS -#include #include #include #include "psa/crypto.h"