fix(esp_tee): optimise build size by removing unused configs

This commit is contained in:
Ashish Sharma
2026-04-30 18:02:07 +08:00
parent 8c0e41afed
commit bd27c398e8
2 changed files with 55 additions and 33 deletions
@@ -31,17 +31,18 @@ include_directories("${COMPONENT_DIR}/port/include")
# Add PSA driver include directory globally for mbedtls targets
include_directories("${COMPONENT_DIR}/port/psa_driver/include")
# Import mbedtls library targets
add_subdirectory(mbedtls)
# Set TF_PSA_CRYPTO_CONFIG_FILE before processing subdirectories to prevent override
# Set TF_PSA_CRYPTO_USER_CONFIG_FILE before add_subdirectory so that
# all targets (including extras, platform, utilities) pick it up
set(
TF_PSA_CRYPTO_USER_CONFIG_FILE "${COMPONENT_DIR}/esp_tee/esp_tee_mbedtls_config.h"
CACHE STRING "Path to the PSA Crypto configuration file"
FORCE
)
set(mbedtls_targets mbedtls tfpsacrypto builtin mbedx509 everest p256m)
# Import mbedtls library targets
add_subdirectory(mbedtls)
set(mbedtls_targets mbedtls tfpsacrypto builtin mbedx509 everest p256-m extras platform utilities)
target_sources(tfpsacrypto PRIVATE "${COMPONENT_DIR}/port/esp_hardware.c")
@@ -50,6 +51,7 @@ foreach(target ${mbedtls_targets})
-DMBEDTLS_CONFIG_FILE="${COMPONENT_DIR}/esp_tee/esp_tee_mbedtls_config.h")
set_config_files_compile_definitions(${target})
target_compile_definitions(${target} PUBLIC MBEDTLS_MAJOR_VERSION=4)
target_compile_definitions(${target} PUBLIC __STDC_WANT_LIB_EXT1__=0)
if(CONFIG_COMPILER_STATIC_ANALYZER AND CMAKE_C_COMPILER_ID STREQUAL "GNU") # TODO IDF-10087
target_compile_options(${target} PRIVATE "-fno-analyzer")
endif()
@@ -48,18 +48,12 @@
#define MBEDTLS_ASN1_WRITE_C
#define MBEDTLS_ASN1_PARSE_C
#define MBEDTLS_BIGNUM_C
#if CONFIG_SECURE_TEE_SEC_STG_SUPPORT_SECP384R1_SIGN
#define PSA_WANT_ECC_SECP_R1_384 1
#define MBEDTLS_ECP_DP_SECP384R1_ENABLED
#else
#undef PSA_WANT_ECC_SECP_R1_384
#undef MBEDTLS_ECP_DP_SECP384R1_ENABLED
#endif
#define PSA_WANT_ECC_SECP_R1_256 1
#define MBEDTLS_ECP_DP_SECP256R1_ENABLED
#define MBEDTLS_ECP_C
#define MBEDTLS_ECDSA_C
#ifdef CONFIG_MBEDTLS_ECDSA_DETERMINISTIC
#define PSA_WANT_ALG_DETERMINISTIC_ECDSA 1
@@ -121,47 +115,30 @@
#undef PSA_WANT_ECC_BRAINPOOL_P_R1_512
#undef PSA_WANT_ECC_MONTGOMERY_255
#undef PSA_WANT_ECC_MONTGOMERY_448
#undef MBEDTLS_ECP_DP_BP256R1_ENABLED
#undef MBEDTLS_ECP_DP_BP384R1_ENABLED
#undef MBEDTLS_ECP_DP_BP512R1_ENABLED
#undef MBEDTLS_ECP_DP_SECP192K1_ENABLED
#undef MBEDTLS_ECP_DP_SECP224K1_ENABLED
#undef MBEDTLS_ECP_DP_SECP256K1_ENABLED
#undef MBEDTLS_ECP_DP_CURVE25519_ENABLED
#undef MBEDTLS_ECP_DP_CURVE448_ENABLED
/* Disable unused cipher/algorithm types */
#undef PSA_WANT_KEY_TYPE_ARIA
#undef MBEDTLS_ARIA_C
#undef PSA_WANT_KEY_TYPE_CAMELLIA
#undef MBEDTLS_CAMELLIA_C
#undef PSA_WANT_KEY_TYPE_DES
#undef MBEDTLS_DES_C
#undef PSA_WANT_ALG_RIPEMD160
#undef MBEDTLS_RIPEMD160_C
#undef PSA_WANT_ALG_CHACHA20
#undef MBEDTLS_CHACHA20_C
#undef PSA_WANT_ALG_CHACHA20_POLY1305
#undef MBEDTLS_CHACHAPOLY_C
#undef PSA_WANT_ALG_CCM
#undef PSA_WANT_ALG_CMAC
#undef MBEDTLS_AES_C
#define MBEDTLS_AES_ROM_TABLES
#if SOC_AES_SUPPORTED
#define MBEDTLS_AES_FEWER_TABLES
#endif
/* Disable unused hash algorithms */
#undef PSA_WANT_ALG_MD5
#undef MBEDTLS_MD5_C
#undef PSA_WANT_ALG_SHA3_224
#undef MBEDTLS_SHA3_224_C
#undef PSA_WANT_ALG_SHA3_256
#undef MBEDTLS_SHA3_256_C
#undef PSA_WANT_ALG_SHA3_384
#undef MBEDTLS_SHA3_384_C
#undef PSA_WANT_ALG_SHA3_512
#undef MBEDTLS_SHA3_512_C
/* Disable RSA — not used by TEE */
#undef PSA_WANT_KEY_TYPE_RSA_KEY_PAIR_BASIC
#undef PSA_WANT_KEY_TYPE_RSA_KEY_PAIR_IMPORT
#undef PSA_WANT_KEY_TYPE_RSA_KEY_PAIR_EXPORT
@@ -171,16 +148,16 @@
#undef PSA_WANT_ALG_RSA_PKCS1V15_SIGN
#undef PSA_WANT_ALG_RSA_OAEP
#undef PSA_WANT_ALG_RSA_PSS
#undef MBEDTLS_RSA_C
/* Disable DH key exchange — not used by TEE */
#undef PSA_WANT_KEY_TYPE_DH_KEY_PAIR_BASIC
#undef PSA_WANT_KEY_TYPE_DH_KEY_PAIR_IMPORT
#undef PSA_WANT_KEY_TYPE_DH_KEY_PAIR_EXPORT
#undef PSA_WANT_KEY_TYPE_DH_KEY_PAIR_GENERATE
#undef PSA_WANT_KEY_TYPE_DH_PUBLIC_KEY
#undef PSA_WANT_ALG_FFDH
#undef MBEDTLS_ECDH_C
/* Disable TLS and other unused modules */
#undef MBEDTLS_DEBUG_C
#undef MBEDTLS_PSA_ITS_FILE_C
#undef MBEDTLS_PSA_CRYPTO_STORAGE_C
@@ -191,5 +168,48 @@
#undef PSA_WANT_ALG_PBKDF2_HMAC
#undef PSA_WANT_ALG_PBKDF2_AES_CMAC_PRF_128
/* Disable Diffie-Hellman groups — TEE has no TLS or DH key exchange */
#undef PSA_WANT_DH_RFC7919_2048
#undef PSA_WANT_DH_RFC7919_3072
#undef PSA_WANT_DH_RFC7919_4096
#undef PSA_WANT_DH_RFC7919_6144
#undef PSA_WANT_DH_RFC7919_8192
/* Disable key derivation and TLS KDFs not used by TEE */
#undef PSA_WANT_ALG_HKDF
#undef PSA_WANT_ALG_HKDF_EXTRACT
#undef PSA_WANT_ALG_HKDF_EXPAND
#undef PSA_WANT_ALG_TLS12_PSK_TO_MS
#undef PSA_WANT_ALG_TLS12_ECJPAKE_TO_PMS
/* Disable EC-JPAKE — not used by TEE */
#undef PSA_WANT_ALG_JPAKE
/* Disable LMS/LMOTS hash-based signatures — not used by TEE */
#undef MBEDTLS_LMS_C
/* Disable self-test functions to save code size */
#undef MBEDTLS_SELF_TEST
/* TEE uses EXTERNAL_RNG, no need for CTR-DRBG */
#undef MBEDTLS_CTR_DRBG_C
/* Disable PEM/Base64 — TEE uses DER format */
#undef MBEDTLS_PEM_PARSE_C
#undef MBEDTLS_PEM_WRITE_C
#undef MBEDTLS_BASE64_C
/* Disable PK layer — TEE uses PSA API directly */
#undef MBEDTLS_PK_C
#undef MBEDTLS_PK_PARSE_C
#undef MBEDTLS_PK_WRITE_C
/* Disable NIST key wrapping and PKCS5 — not used by TEE */
#undef MBEDTLS_NIST_KW_C
#undef MBEDTLS_PKCS5_C
/* TEE has no filesystem */
#undef MBEDTLS_FS_IO
/* ESP-TEE is single threaded so we can disable threading in mbedTLS */
#undef MBEDTLS_THREADING_C