fix(esp_security): Stop ECDSA and Key Manager resets from corrupting concurrent crypto

ECDSA enable pulses a reset that also holds SHA in reset, and SHA shares
its DMA with AES. Key Manager enable pulses a reset that also covers the
XTS-AES flash encryption key-usage selector. Neither path was serialized
against those victims, so a hardware ECDSA/HMAC/DS operation could
corrupt a concurrent SHA/AES transfer or an in-flight encrypted flash
read.

- Take the SHA/AES lock inside esp_crypto_ecdsa_lock_acquire(), before
  MPI, matching the DS lock order (sha_aes < mpi)
- Add esp_crypto_key_mgr_enable_periph_clk_no_reset() and switch ECDSA,
  HMAC and DS to it; they only need the key-usage selector writable
- Hold esp_crypto_key_manager_lock across those clock enable/disable
  pairs so selector writes stay serialized without resetting KM
This commit is contained in:
radek.tandler
2026-09-08 19:42:35 +05:30
committed by Harshal Patil
parent 059abc43d7
commit ba13c2852a
7 changed files with 90 additions and 13 deletions
@@ -393,8 +393,13 @@ static void esp_ecdsa_acquire_hardware(void)
/* Key Manager holds the key usage selector register (efuse vs own key).
Thus, we need to enable the Key Manager peripheral clock to ensure
that the key usage selector register is properly set.
Taken after the ECDSA lock (which already holds SHA/AES and MPI) so
the order matches HMAC/DS: sha_aes < mpi < key_manager.
*/
esp_crypto_key_mgr_enable_periph_clk(true);
esp_crypto_key_manager_lock_acquire();
/* Clock only: a full KM reset would drop the XTS-AES flash encryption
key-usage selector, and spi_flash DMA does not take the KM lock. */
esp_crypto_key_mgr_enable_periph_clk_no_reset(true);
#endif /* SOC_KEY_MANAGER_ECDSA_KEY_DEPLOY */
#if SOC_ECDSA_USES_MPI
@@ -414,7 +419,8 @@ static void esp_ecdsa_release_hardware(void)
esp_crypto_ecc_enable_periph_clk(false);
#if SOC_KEY_MANAGER_ECDSA_KEY_DEPLOY
esp_crypto_key_mgr_enable_periph_clk(false);
esp_crypto_key_mgr_enable_periph_clk_no_reset(false);
esp_crypto_key_manager_lock_release();
#endif /* SOC_KEY_MANAGER_ECDSA_KEY_DEPLOY */
#if SOC_ECDSA_USES_MPI