From bf46351fb0ad76a5a209a55be8635e79f26dd0d7 Mon Sep 17 00:00:00 2001 From: Ashish Sharma Date: Thu, 24 Jul 2025 15:31:38 +0800 Subject: [PATCH] feat(mbedtls): fix build errors with PSA migration --- components/bt/host/nimble/nimble | 2 +- components/mbedtls/CMakeLists.txt | 49 +- components/mbedtls/CMakeLists.txt.master | 424 ++++++++++++++ components/mbedtls/CMakeLists.txt.psa | 530 ++++++++++++++++++ components/mbedtls/mbedtls | 2 +- .../mbedtls/port/include/mbedtls/esp_config.h | 6 +- components/openthread/openthread | 2 +- 7 files changed, 993 insertions(+), 22 deletions(-) create mode 100644 components/mbedtls/CMakeLists.txt.master create mode 100644 components/mbedtls/CMakeLists.txt.psa diff --git a/components/bt/host/nimble/nimble b/components/bt/host/nimble/nimble index 686728c09ec..872f3c1849a 160000 --- a/components/bt/host/nimble/nimble +++ b/components/bt/host/nimble/nimble @@ -1 +1 @@ -Subproject commit 686728c09ec94a86afeeb58a936a9f6a4ab5fd83 +Subproject commit 872f3c1849abfb124fa53d345cd9786f949d3b57 diff --git a/components/mbedtls/CMakeLists.txt b/components/mbedtls/CMakeLists.txt index 3952afdb9cc..be63f717866 100644 --- a/components/mbedtls/CMakeLists.txt +++ b/components/mbedtls/CMakeLists.txt @@ -176,6 +176,27 @@ endif() # Core libraries from the mbedTLS project set(mbedtls_targets mbedtls mbedx509 tfpsacrypto builtin) + +if(CONFIG_MBEDTLS_HARDWARE_SHA) + list(APPEND include_dirs "${COMPONENT_DIR}/port/psa_driver/include") + target_include_directories(tfpsacrypto PUBLIC "${COMPONENT_DIR}/port/psa_driver/include") +endif() + +message(STATUS "Setting up mbedtls configuration") +foreach(target ${mbedtls_targets}) + target_compile_definitions(${target} PUBLIC -DMBEDTLS_CONFIG_FILE="mbedtls/esp_config.h") + set_config_files_compile_definitions(${target}) + target_compile_definitions(${target} PUBLIC MBEDTLS_MAJOR_VERSION=4) + if(CONFIG_COMPILER_STATIC_ANALYZER AND CMAKE_C_COMPILER_ID STREQUAL "GNU") # TODO IDF-10087 + target_compile_options(${target} PRIVATE "-fno-analyzer") + endif() + if(CONFIG_MBEDTLS_COMPILER_OPTIMIZATION_SIZE) + target_compile_options(${target} PRIVATE "-Os") + elseif(CONFIG_MBEDTLS_COMPILER_OPTIMIZATION_SPEED) + target_compile_options(${target} PRIVATE "-O2") + endif() +endforeach() + # 3rd party libraries from the mbedTLS project list(APPEND mbedtls_targets everest p256m) @@ -293,9 +314,16 @@ if(CONFIG_SOC_AES_SUPPORTED) endif() if(CONFIG_SOC_SHA_SUPPORTED) - target_sources(builtin PRIVATE "${COMPONENT_DIR}/port/sha/esp_sha.c" - "${COMPONENT_DIR}/port/sha/${SHA_PERIPHERAL_TYPE}/sha.c" - ) + # target_sources(builtin PRIVATE "${COMPONENT_DIR}/port/sha/esp_sha.c" + # "${COMPONENT_DIR}/port/sha/${SHA_PERIPHERAL_TYPE}/sha.c" + # ) + if(CONFIG_MBEDTLS_HARDWARE_SHA) + target_sources(tfpsacrypto PRIVATE + "${COMPONENT_DIR}/port/psa_driver/esp_sha/psa_crypto_driver_esp_sha.c" + "${COMPONENT_DIR}/port/psa_driver/esp_sha/${SHA_PERIPHERAL_TYPE}/psa_crypto_driver_esp_sha1.c" + "${COMPONENT_DIR}/port/psa_driver/esp_sha/${SHA_PERIPHERAL_TYPE}/psa_crypto_driver_esp_sha256.c" + "${COMPONENT_DIR}/port/sha/${SHA_PERIPHERAL_TYPE}/sha.c") + endif() endif() # if(CONFIG_SOC_DIG_SIGN_SUPPORTED) @@ -388,21 +416,6 @@ endif() # target_link_libraries(${COMPONENT_LIB} PRIVATE "-u mbedtls_rom_osi_functions_init") # endif() -message(STATUS "Setting up mbedtls configuration") -foreach(target ${mbedtls_targets}) - target_compile_definitions(${target} PUBLIC -DMBEDTLS_CONFIG_FILE="mbedtls/esp_config.h") - set_config_files_compile_definitions(${target}) - target_compile_definitions(${target} PUBLIC MBEDTLS_MAJOR_VERSION=4) - if(CONFIG_COMPILER_STATIC_ANALYZER AND CMAKE_C_COMPILER_ID STREQUAL "GNU") # TODO IDF-10087 - target_compile_options(${target} PRIVATE "-fno-analyzer") - endif() - if(CONFIG_MBEDTLS_COMPILER_OPTIMIZATION_SIZE) - target_compile_options(${target} PRIVATE "-Os") - elseif(CONFIG_MBEDTLS_COMPILER_OPTIMIZATION_SPEED) - target_compile_options(${target} PRIVATE "-O2") - endif() -endforeach() - if(CONFIG_COMPILER_STATIC_ANALYZER AND CMAKE_C_COMPILER_ID STREQUAL "GNU") target_compile_options(${COMPONENT_LIB} PRIVATE "-fno-analyzer") target_compile_options(tfpsacrypto PRIVATE "-fno-analyzer") diff --git a/components/mbedtls/CMakeLists.txt.master b/components/mbedtls/CMakeLists.txt.master new file mode 100644 index 00000000000..99981b04af3 --- /dev/null +++ b/components/mbedtls/CMakeLists.txt.master @@ -0,0 +1,424 @@ +idf_build_get_property(idf_target IDF_TARGET) +idf_build_get_property(python PYTHON) +idf_build_get_property(esp_tee_build ESP_TEE_BUILD) + +if(esp_tee_build) + include(${COMPONENT_DIR}/esp_tee/esp_tee_mbedtls.cmake) + return() + +elseif(BOOTLOADER_BUILD) # TODO: IDF-11673 + if(CONFIG_MBEDTLS_USE_CRYPTO_ROM_IMPL_BOOTLOADER) + set(include_dirs "${COMPONENT_DIR}/mbedtls/include" + "port/mbedtls_rom") + set(srcs "port/mbedtls_rom/mbedtls_rom_osi_bootloader.c") + endif() + + idf_component_register(SRCS "${srcs}" + INCLUDE_DIRS "${include_dirs}" + PRIV_REQUIRES hal) + return() +endif() + +if(NOT ${IDF_TARGET} STREQUAL "linux") + set(priv_requires soc esp_hw_support) + if(NOT BOOTLOADER_BUILD) + list(APPEND priv_requires esp_pm) + endif() +endif() + +set(mbedtls_srcs "") +set(mbedtls_include_dirs "port/include" "mbedtls/include" "mbedtls/library") + +if(CONFIG_MBEDTLS_USE_CRYPTO_ROM_IMPL) + list(APPEND mbedtls_include_dirs "port/mbedtls_rom") +endif() + +if(CONFIG_MBEDTLS_CERTIFICATE_BUNDLE) + list(APPEND mbedtls_srcs "esp_crt_bundle/esp_crt_bundle.c") + list(APPEND mbedtls_include_dirs "esp_crt_bundle/include") +endif() + +idf_component_register(SRCS "${mbedtls_srcs}" + INCLUDE_DIRS "${mbedtls_include_dirs}" + PRIV_REQUIRES "${priv_requires}" + ) + +# Determine the type of mbedtls component library +if(mbedtls_srcs STREQUAL "") + # For no sources in component library we must use "INTERFACE" + set(linkage_type INTERFACE) +else() + set(linkage_type PUBLIC) +endif() + + +if(CONFIG_MBEDTLS_CERTIFICATE_BUNDLE) + set(bundle_name "x509_crt_bundle") + set(DEFAULT_CRT_DIR ${COMPONENT_DIR}/esp_crt_bundle) + + # Generate custom certificate bundle using the generate_cert_bundle utility + set(GENERATE_CERT_BUNDLEPY ${python} ${COMPONENT_DIR}/esp_crt_bundle/gen_crt_bundle.py) + + if(CONFIG_MBEDTLS_CERTIFICATE_BUNDLE_DEFAULT_FULL) + list(APPEND crt_paths ${DEFAULT_CRT_DIR}/cacrt_all.pem) + elseif(CONFIG_MBEDTLS_CERTIFICATE_BUNDLE_DEFAULT_CMN) + list(APPEND crt_paths ${DEFAULT_CRT_DIR}/cacrt_all.pem) + list(APPEND args --filter ${DEFAULT_CRT_DIR}/cmn_crt_authorities.csv) + endif() + + # Currently cacrt_local.pem contains deprecated certificates that are still required for certain certificate chains. + # These chains may include cross-signed certificates, but the final certificate in the chain is deprecated. + # When cross-signed verification is enabled (CONFIG_MBEDTLS_CERTIFICATE_BUNDLE_CROSS_SIGNED_VERIFY), + # the cross-signed certificate should be sufficient for verification, and the deprecated root is not needed. + # Therefore, cacrt_local.pem is only appended if cross-signed verification is not enabled. + if((CONFIG_MBEDTLS_CERTIFICATE_BUNDLE_DEFAULT_FULL OR CONFIG_MBEDTLS_CERTIFICATE_BUNDLE_DEFAULT_CMN) + AND NOT CONFIG_MBEDTLS_CERTIFICATE_BUNDLE_CROSS_SIGNED_VERIFY) + list(APPEND crt_paths ${DEFAULT_CRT_DIR}/cacrt_local.pem) + endif() + + # Add deprecated root certs if enabled. This config is not visible if the default cert + # bundle is not selected + if(CONFIG_MBEDTLS_CERTIFICATE_BUNDLE_DEPRECATED_LIST) + list(APPEND crt_paths ${DEFAULT_CRT_DIR}/cacrt_deprecated.pem) + endif() + + if(CONFIG_MBEDTLS_CUSTOM_CERTIFICATE_BUNDLE) + get_filename_component(custom_bundle_path + ${CONFIG_MBEDTLS_CUSTOM_CERTIFICATE_BUNDLE_PATH} ABSOLUTE BASE_DIR "${project_dir}") + list(APPEND crt_paths ${custom_bundle_path}) + + endif() + list(APPEND args --input ${crt_paths} -q --max-certs "${CONFIG_MBEDTLS_CERTIFICATE_BUNDLE_MAX_CERTS}") + + get_filename_component(crt_bundle + ${bundle_name} + ABSOLUTE BASE_DIR "${CMAKE_CURRENT_BINARY_DIR}") + + # Generate bundle according to config + add_custom_command(OUTPUT ${crt_bundle} + COMMAND ${GENERATE_CERT_BUNDLEPY} ${args} + DEPENDS ${custom_bundle_path} + VERBATIM) + + add_custom_target(custom_bundle DEPENDS ${cert_bundle}) + add_dependencies(${COMPONENT_LIB} custom_bundle) + + + target_add_binary_data(${COMPONENT_LIB} ${crt_bundle} BINARY) + set_property(DIRECTORY "${CMAKE_CURRENT_SOURCE_DIR}" + APPEND PROPERTY ADDITIONAL_CLEAN_FILES + "${crt_bundle}") +endif() + +# Only build mbedtls libraries +set(ENABLE_TESTING CACHE BOOL OFF) +set(ENABLE_PROGRAMS CACHE BOOL OFF) + +# Use pre-generated source files in mbedtls repository +set(GEN_FILES CACHE BOOL OFF) + +# Make sure mbedtls finds the same Python interpreter as IDF uses +idf_build_get_property(python PYTHON) +set(Python3_EXECUTABLE ${python}) + +# Needed to for include_next includes to work from within mbedtls +set(include_dirs "${COMPONENT_DIR}/port/include") + +if(CONFIG_MBEDTLS_CERTIFICATE_BUNDLE) + list(APPEND include_dirs "${COMPONENT_DIR}/esp_crt_bundle/include") +endif() + +include_directories(${include_dirs}) + +# Needed to for mbedtls_rom includes to work from within mbedtls +if(CONFIG_MBEDTLS_USE_CRYPTO_ROM_IMPL) + include_directories("${COMPONENT_DIR}/port/mbedtls_rom") +endif() + +# Import mbedtls library targets +add_subdirectory(mbedtls) + +# Use port specific implementation of net_socket.c instead of one from mbedtls +get_target_property(src_tls mbedtls SOURCES) +list(REMOVE_ITEM src_tls net_sockets.c) +set_property(TARGET mbedtls PROPERTY SOURCES ${src_tls}) + +if(CONFIG_MBEDTLS_SSL_PROTO_GMTSSL1_1) +get_target_property(src_tls mbedtls SOURCES) +list(REMOVE_ITEM src_tls ssl_ciphersuites.c ssl_cli.c ssl_tls.c) +set_property(TARGET mbedtls PROPERTY SOURCES ${src_tls}) + +get_target_property(src_crypto mbedcrypto SOURCES) +list(REMOVE_ITEM src_crypto cipher_wrap.c ecdsa.c ecp.c ecp_curves.c oid.c pk_wrap.c) +set_property(TARGET mbedcrypto PROPERTY SOURCES ${src_crypto}) + +get_target_property(src_x509 mbedx509 SOURCES) +list(REMOVE_ITEM src_x509 x509_crt.c) +set_property(TARGET mbedx509 PROPERTY SOURCES ${src_x509}) +endif() + +# Core libraries from the mbedTLS project +set(mbedtls_targets mbedtls mbedcrypto mbedx509) +# 3rd party libraries from the mbedTLS project +list(APPEND mbedtls_targets everest p256m) + +set(mbedtls_target_sources "${COMPONENT_DIR}/port/mbedtls_debug.c" + "${COMPONENT_DIR}/port/esp_platform_time.c") + +if(CONFIG_MBEDTLS_DYNAMIC_BUFFER) +set(mbedtls_target_sources ${mbedtls_target_sources} + "${COMPONENT_DIR}/port/dynamic/esp_mbedtls_dynamic_impl.c" + "${COMPONENT_DIR}/port/dynamic/esp_ssl_cli.c" + "${COMPONENT_DIR}/port/dynamic/esp_ssl_srv.c" + "${COMPONENT_DIR}/port/dynamic/esp_ssl_tls.c") +endif() + +if(${IDF_TARGET} STREQUAL "linux") +set(mbedtls_target_sources ${mbedtls_target_sources} "${COMPONENT_DIR}/port/net_sockets.c") +endif() + +# While updating to MbedTLS release/v3.4.0, building mbedtls/library/psa_crypto.c +# clang produces an unreachable-code warning. +if(CMAKE_C_COMPILER_ID MATCHES "Clang") + target_compile_options(mbedcrypto PRIVATE "-Wno-unreachable-code") +endif() + +# net_sockets.c should only be compiled if BSD socket functions are available. +# Do this by checking if lwip component is included into the build. +if(CONFIG_LWIP_ENABLE) + list(APPEND mbedtls_target_sources "${COMPONENT_DIR}/port/net_sockets.c") + idf_component_get_property(lwip_lib lwip COMPONENT_LIB) + target_link_libraries(${COMPONENT_LIB} ${linkage_type} ${lwip_lib}) +endif() + +# Add port files to mbedtls targets +target_sources(mbedtls PRIVATE ${mbedtls_target_sources}) + +if(NOT ${IDF_TARGET} STREQUAL "linux") + target_link_libraries(mbedcrypto PRIVATE idf::esp_security) +endif() + +# Choose peripheral type + +if(CONFIG_SOC_SHA_SUPPORTED) + if(CONFIG_SOC_SHA_SUPPORT_PARALLEL_ENG) + set(SHA_PERIPHERAL_TYPE "parallel_engine") + else() + set(SHA_PERIPHERAL_TYPE "core") + endif() +endif() + +if(CONFIG_SOC_AES_SUPPORTED) + if(CONFIG_SOC_AES_SUPPORT_DMA) + set(AES_PERIPHERAL_TYPE "dma") + else() + set(AES_PERIPHERAL_TYPE "block") + endif() +endif() + +if(SHA_PERIPHERAL_TYPE STREQUAL "core") + target_include_directories(mbedcrypto PRIVATE "${COMPONENT_DIR}/port/sha/core/include") + + if(CONFIG_SOC_SHA_GDMA) + set(SHA_CORE_SRCS "${COMPONENT_DIR}/port/sha/core/esp_sha_gdma_impl.c") + elseif(CONFIG_SOC_SHA_CRYPTO_DMA) + set(SHA_CORE_SRCS "${COMPONENT_DIR}/port/sha/core/esp_sha_crypto_dma_impl.c") + endif() + target_sources(mbedcrypto PRIVATE "${SHA_CORE_SRCS}") +endif() + +if(AES_PERIPHERAL_TYPE STREQUAL "dma") + if(NOT CONFIG_SOC_AES_GDMA) + set(AES_DMA_SRCS "${COMPONENT_DIR}/port/aes/dma/esp_aes_crypto_dma_impl.c") + else() + set(AES_DMA_SRCS "${COMPONENT_DIR}/port/aes/dma/esp_aes_gdma_impl.c") + endif() + + list(APPEND AES_DMA_SRCS "${COMPONENT_DIR}/port/aes/dma/esp_aes_dma_core.c") + + target_include_directories(mbedcrypto PRIVATE "${COMPONENT_DIR}/port/aes/dma/include") + target_sources(mbedcrypto PRIVATE "${AES_DMA_SRCS}") +endif() + +if((SHA_PERIPHERAL_TYPE STREQUAL "core" AND CONFIG_SOC_SHA_SUPPORT_DMA) OR AES_PERIPHERAL_TYPE STREQUAL "dma") + target_link_libraries(mbedcrypto PRIVATE idf::esp_mm) + if(CONFIG_SOC_SHA_GDMA OR CONFIG_SOC_AES_GDMA) + if(CONFIG_SOC_AXI_DMA_EXT_MEM_ENC_ALIGNMENT) + target_link_libraries(mbedcrypto PRIVATE idf::bootloader_support) + endif() + target_sources(mbedcrypto PRIVATE "${COMPONENT_DIR}/port/crypto_shared_gdma/esp_crypto_shared_gdma.c") + endif() +endif() + +if(NOT ${IDF_TARGET} STREQUAL "linux") + target_sources(mbedcrypto PRIVATE "${COMPONENT_DIR}/port/esp_hardware.c") +endif() +target_sources(mbedcrypto PRIVATE "${COMPONENT_DIR}/port/esp_mem.c" + "${COMPONENT_DIR}/port/esp_timing.c" +) + +if(CONFIG_SOC_AES_SUPPORTED) + target_include_directories(mbedcrypto PRIVATE "${COMPONENT_DIR}/port/aes/include") + target_sources(mbedcrypto PRIVATE "${COMPONENT_DIR}/port/aes/esp_aes_xts.c" + "${COMPONENT_DIR}/port/aes/esp_aes_common.c" + "${COMPONENT_DIR}/port/aes/${AES_PERIPHERAL_TYPE}/esp_aes.c" + ) +endif() + +if(CONFIG_SOC_SHA_SUPPORTED) + target_sources(mbedcrypto PRIVATE "${COMPONENT_DIR}/port/sha/esp_sha.c" + "${COMPONENT_DIR}/port/sha/${SHA_PERIPHERAL_TYPE}/sha.c" + ) +endif() + +if(CONFIG_SOC_DIG_SIGN_SUPPORTED) +target_sources(mbedcrypto PRIVATE + "${COMPONENT_DIR}/port/esp_ds/esp_rsa_sign_alt.c" + "${COMPONENT_DIR}/port/esp_ds/esp_rsa_dec_alt.c" + "${COMPONENT_DIR}/port/esp_ds/esp_ds_common.c") +endif() + +# Note: some mbedTLS hardware acceleration can be enabled/disabled by config. +# +# We don't need to filter aes.c as this uses a different prefix (esp_aes_x) and the +# config option only changes the prefixes in the header so mbedtls_aes_x compiles to esp_aes_x +# +# The other port-specific files don't override internal mbedTLS functions, they just add new functions. + +if(CONFIG_MBEDTLS_HARDWARE_MPI) + target_sources(mbedcrypto PRIVATE "${COMPONENT_DIR}/port/bignum/esp_bignum.c" + "${COMPONENT_DIR}/port/bignum/bignum_alt.c") +endif() + +if(CONFIG_MBEDTLS_HARDWARE_SHA) + target_sources(mbedcrypto PRIVATE "${COMPONENT_DIR}/port/sha/${SHA_PERIPHERAL_TYPE}/esp_sha1.c" + "${COMPONENT_DIR}/port/sha/${SHA_PERIPHERAL_TYPE}/esp_sha256.c" + "${COMPONENT_DIR}/port/sha/${SHA_PERIPHERAL_TYPE}/esp_sha512.c" + ) +endif() + +if(CONFIG_MBEDTLS_HARDWARE_GCM OR CONFIG_MBEDTLS_HARDWARE_AES) + target_sources(mbedcrypto PRIVATE "${COMPONENT_DIR}/port/aes/esp_aes_gcm.c") +endif() + +if(CONFIG_MBEDTLS_HARDWARE_ECC) + target_sources(mbedcrypto PRIVATE "${COMPONENT_DIR}/port/ecc/esp_ecc.c" + "${COMPONENT_DIR}/port/ecc/ecc_alt.c") +endif() + +if(CONFIG_MBEDTLS_HARDWARE_ECDSA_SIGN OR CONFIG_MBEDTLS_HARDWARE_ECDSA_VERIFY OR CONFIG_MBEDTLS_TEE_SEC_STG_ECDSA_SIGN) + target_sources(mbedcrypto PRIVATE "${COMPONENT_DIR}/port/ecdsa/ecdsa_alt.c") + + set(WRAP_FUNCTIONS_SIGN + mbedtls_ecdsa_sign + mbedtls_ecdsa_sign_restartable + mbedtls_ecdsa_write_signature + mbedtls_ecdsa_write_signature_restartable) + + set(WRAP_FUNCTIONS_VERIFY + mbedtls_ecdsa_verify + mbedtls_ecdsa_verify_restartable + mbedtls_ecdsa_read_signature + mbedtls_ecdsa_read_signature_restartable) + + if(CONFIG_MBEDTLS_HARDWARE_ECDSA_SIGN OR CONFIG_MBEDTLS_TEE_SEC_STG_ECDSA_SIGN) + foreach(wrap ${WRAP_FUNCTIONS_SIGN}) + target_link_libraries(${COMPONENT_LIB} INTERFACE "-Wl,--wrap=${wrap}") + endforeach() + + if(CONFIG_SOC_ECDSA_SUPPORT_DETERMINISTIC_MODE) + target_link_libraries(${COMPONENT_LIB} INTERFACE "-Wl,--wrap=mbedtls_ecdsa_sign_det_ext") + target_link_libraries(${COMPONENT_LIB} INTERFACE "-Wl,--wrap=mbedtls_ecdsa_sign_det_restartable") + endif() + endif() + + if(CONFIG_MBEDTLS_HARDWARE_ECDSA_VERIFY) + foreach(wrap ${WRAP_FUNCTIONS_VERIFY}) + target_link_libraries(${COMPONENT_LIB} INTERFACE "-Wl,--wrap=${wrap}") + endforeach() + endif() + + if(CONFIG_MBEDTLS_TEE_SEC_STG_ECDSA_SIGN) + target_link_libraries(mbedcrypto PRIVATE idf::tee_sec_storage) + endif() +endif() + +if(CONFIG_MBEDTLS_ROM_MD5) + target_sources(mbedcrypto PRIVATE "${COMPONENT_DIR}/port/md/esp_md.c") +endif() + +if(CONFIG_MBEDTLS_USE_CRYPTO_ROM_IMPL) + target_sources(mbedcrypto PRIVATE "${COMPONENT_DIR}/port/mbedtls_rom/mbedtls_rom_osi.c") + target_link_libraries(${COMPONENT_LIB} PRIVATE "-u mbedtls_rom_osi_functions_init") +endif() + +foreach(target ${mbedtls_targets}) + target_compile_definitions(${target} PUBLIC -DMBEDTLS_CONFIG_FILE="mbedtls/esp_config.h") + if(CONFIG_COMPILER_STATIC_ANALYZER AND CMAKE_C_COMPILER_ID STREQUAL "GNU") # TODO IDF-10087 + target_compile_options(${target} PRIVATE "-fno-analyzer") + endif() + if(CONFIG_MBEDTLS_COMPILER_OPTIMIZATION_SIZE) + target_compile_options(${target} PRIVATE "-Os") + elseif(CONFIG_MBEDTLS_COMPILER_OPTIMIZATION_SPEED) + target_compile_options(${target} PRIVATE "-O2") + endif() +endforeach() + +if(CONFIG_MBEDTLS_COMPILER_OPTIMIZATION_SIZE) + target_compile_options(${COMPONENT_LIB} PRIVATE "-Os") +elseif(CONFIG_MBEDTLS_COMPILER_OPTIMIZATION_SPEED) + target_compile_options(${COMPONENT_LIB} PRIVATE "-O2") +endif() + +if(CONFIG_MBEDTLS_DYNAMIC_BUFFER) + set(WRAP_FUNCTIONS + mbedtls_ssl_write_client_hello + mbedtls_ssl_handshake_client_step + mbedtls_ssl_tls13_handshake_client_step + mbedtls_ssl_handshake_server_step + mbedtls_ssl_read + mbedtls_ssl_write + mbedtls_ssl_free + mbedtls_ssl_setup + mbedtls_ssl_send_alert_message + mbedtls_ssl_close_notify) + + foreach(wrap ${WRAP_FUNCTIONS}) + target_link_libraries(${COMPONENT_LIB} INTERFACE "-Wl,--wrap=${wrap}") + endforeach() +endif() + +set_property(TARGET mbedcrypto APPEND PROPERTY LINK_INTERFACE_LIBRARIES mbedtls) + +if(CONFIG_PM_ENABLE) + target_link_libraries(mbedcrypto PRIVATE idf::esp_pm) +endif() + +if(CONFIG_MBEDTLS_HARDWARE_ECDSA_SIGN OR CONFIG_MBEDTLS_HARDWARE_ECDSA_VERIFY) + target_link_libraries(mbedcrypto PRIVATE idf::efuse) +endif() + +target_link_libraries(${COMPONENT_LIB} ${linkage_type} ${mbedtls_targets}) + +if(CONFIG_ESP_TLS_USE_DS_PERIPHERAL) + # The linker seems to be unable to resolve all the dependencies without increasing this + set_property(TARGET mbedcrypto APPEND PROPERTY LINK_INTERFACE_MULTIPLICITY 6) +endif() + +# Additional optional dependencies for the mbedcrypto library +function(mbedcrypto_optional_deps component_name) + idf_build_get_property(components BUILD_COMPONENTS) + if(${component_name} IN_LIST components) + idf_component_get_property(lib_name ${component_name} COMPONENT_LIB) + target_link_libraries(mbedcrypto PRIVATE ${lib_name}) + endif() +endfunction() + +if(CONFIG_MBEDTLS_HARDWARE_ECDSA_SIGN_CONSTANT_TIME_CM) + mbedcrypto_optional_deps(esp_timer idf::esp_timer) +endif() + +# Link esp-cryptoauthlib to mbedtls +if(CONFIG_ATCA_MBEDTLS_ECDSA) + mbedcrypto_optional_deps(espressif__esp-cryptoauthlib esp-cryptoauthlib) +endif() diff --git a/components/mbedtls/CMakeLists.txt.psa b/components/mbedtls/CMakeLists.txt.psa new file mode 100644 index 00000000000..cc0afc3213b --- /dev/null +++ b/components/mbedtls/CMakeLists.txt.psa @@ -0,0 +1,530 @@ +idf_build_get_property(idf_target IDF_TARGET) +idf_build_get_property(python PYTHON) +idf_build_get_property(esp_tee_build ESP_TEE_BUILD) + +if(esp_tee_build) + include(${COMPONENT_DIR}/esp_tee/esp_tee_mbedtls.cmake) + return() + +elseif(BOOTLOADER_BUILD) # TODO: IDF-11673 + if(CONFIG_MBEDTLS_USE_CRYPTO_ROM_IMPL_BOOTLOADER) + set(include_dirs "${COMPONENT_DIR}/mbedtls/include" + "port/mbedtls_rom") + set(srcs "port/mbedtls_rom/mbedtls_rom_osi_bootloader.c") + endif() + + idf_component_register(SRCS "${srcs}" + INCLUDE_DIRS "${include_dirs}" + PRIV_REQUIRES hal) + return() +endif() + +if(NOT ${IDF_TARGET} STREQUAL "linux") + set(priv_requires soc esp_hw_support) + if(NOT BOOTLOADER_BUILD) + list(APPEND priv_requires esp_pm) + endif() +endif() + +set(mbedtls_srcs "") +set(mbedtls_include_dirs "port/include" "mbedtls/include" "mbedtls/library") + +if(CONFIG_MBEDTLS_USE_CRYPTO_ROM_IMPL) + list(APPEND mbedtls_include_dirs "port/mbedtls_rom") +endif() + +if(CONFIG_MBEDTLS_CERTIFICATE_BUNDLE) + list(APPEND mbedtls_srcs "esp_crt_bundle/esp_crt_bundle.c") + list(APPEND mbedtls_include_dirs "esp_crt_bundle/include") +endif() + +idf_component_register(SRCS "${mbedtls_srcs}" + INCLUDE_DIRS "${mbedtls_include_dirs}" + PRIV_REQUIRES "${priv_requires}" + ) + +# Add MBEDTLS_MAJOR_VERSION definition to the component library +target_compile_definitions(${COMPONENT_LIB} PUBLIC MBEDTLS_MAJOR_VERSION=4) + + +# Determine the type of mbedtls component library +if(mbedtls_srcs STREQUAL "") + # For no sources in component library we must use "INTERFACE" + set(linkage_type INTERFACE) +else() + set(linkage_type PUBLIC) +endif() + + +if(CONFIG_MBEDTLS_CERTIFICATE_BUNDLE) + set(bundle_name "x509_crt_bundle") + set(DEFAULT_CRT_DIR ${COMPONENT_DIR}/esp_crt_bundle) + + # Generate custom certificate bundle using the generate_cert_bundle utility + set(GENERATE_CERT_BUNDLEPY ${python} ${COMPONENT_DIR}/esp_crt_bundle/gen_crt_bundle.py) + + if(CONFIG_MBEDTLS_CERTIFICATE_BUNDLE_DEFAULT_FULL) + list(APPEND crt_paths ${DEFAULT_CRT_DIR}/cacrt_all.pem) + elseif(CONFIG_MBEDTLS_CERTIFICATE_BUNDLE_DEFAULT_CMN) + list(APPEND crt_paths ${DEFAULT_CRT_DIR}/cacrt_all.pem) + list(APPEND args --filter ${DEFAULT_CRT_DIR}/cmn_crt_authorities.csv) + endif() + + # Currently cacrt_local.pem contains deprecated certificates that are still required for certain certificate chains. + # These chains may include cross-signed certificates, but the final certificate in the chain is deprecated. + # When cross-signed verification is enabled (CONFIG_MBEDTLS_CERTIFICATE_BUNDLE_CROSS_SIGNED_VERIFY), + # the cross-signed certificate should be sufficient for verification, and the deprecated root is not needed. + # Therefore, cacrt_local.pem is only appended if cross-signed verification is not enabled. + if((CONFIG_MBEDTLS_CERTIFICATE_BUNDLE_DEFAULT_FULL OR CONFIG_MBEDTLS_CERTIFICATE_BUNDLE_DEFAULT_CMN) + AND NOT CONFIG_MBEDTLS_CERTIFICATE_BUNDLE_CROSS_SIGNED_VERIFY) + list(APPEND crt_paths ${DEFAULT_CRT_DIR}/cacrt_local.pem) + endif() + + # Add deprecated root certs if enabled. This config is not visible if the default cert + # bundle is not selected + if(CONFIG_MBEDTLS_CERTIFICATE_BUNDLE_DEPRECATED_LIST) + list(APPEND crt_paths ${DEFAULT_CRT_DIR}/cacrt_deprecated.pem) + endif() + + if(CONFIG_MBEDTLS_CUSTOM_CERTIFICATE_BUNDLE) + get_filename_component(custom_bundle_path + ${CONFIG_MBEDTLS_CUSTOM_CERTIFICATE_BUNDLE_PATH} ABSOLUTE BASE_DIR "${project_dir}") + list(APPEND crt_paths ${custom_bundle_path}) + + endif() + list(APPEND args --input ${crt_paths} -q --max-certs "${CONFIG_MBEDTLS_CERTIFICATE_BUNDLE_MAX_CERTS}") + + get_filename_component(crt_bundle + ${bundle_name} + ABSOLUTE BASE_DIR "${CMAKE_CURRENT_BINARY_DIR}") + + # Generate bundle according to config + add_custom_command(OUTPUT ${crt_bundle} + COMMAND ${GENERATE_CERT_BUNDLEPY} ${args} + DEPENDS ${custom_bundle_path} + VERBATIM) + + add_custom_target(custom_bundle DEPENDS ${cert_bundle}) + add_dependencies(${COMPONENT_LIB} custom_bundle) + + + target_add_binary_data(${COMPONENT_LIB} ${crt_bundle} BINARY) + set_property(DIRECTORY "${CMAKE_CURRENT_SOURCE_DIR}" + APPEND PROPERTY ADDITIONAL_CLEAN_FILES + "${crt_bundle}") +endif() + +# Only build mbedtls libraries +set(ENABLE_TESTING CACHE BOOL OFF) +set(ENABLE_PROGRAMS CACHE BOOL OFF) + +# Use pre-generated source files in mbedtls repository +set(GEN_FILES CACHE BOOL OFF) + +# Make sure mbedtls finds the same Python interpreter as IDF uses +idf_build_get_property(python PYTHON) +set(Python3_EXECUTABLE ${python}) + +# Needed to for include_next includes to work from within mbedtls +set(include_dirs "${COMPONENT_DIR}/port/include") + +if(CONFIG_MBEDTLS_CERTIFICATE_BUNDLE) + list(APPEND include_dirs "${COMPONENT_DIR}/esp_crt_bundle/include") +endif() + +include_directories(${include_dirs}) + +# Needed to for mbedtls_rom includes to work from within mbedtls +if(CONFIG_MBEDTLS_USE_CRYPTO_ROM_IMPL) + include_directories("${COMPONENT_DIR}/port/mbedtls_rom") +endif() + +# Set TF_PSA_CRYPTO_CONFIG_FILE before processing subdirectories to prevent override +set( + TF_PSA_CRYPTO_USER_CONFIG_FILE "mbedtls/esp_crypto_config.h" + CACHE STRING "Path to the PSA Crypto configuration file" + FORCE +) + +# Import mbedtls library targets +add_subdirectory(mbedtls) + +# Use port specific implementation of net_socket.c instead of one from mbedtls +get_target_property(src_tls mbedtls SOURCES) +list(REMOVE_ITEM src_tls net_sockets.c) +set_property(TARGET mbedtls PROPERTY SOURCES ${src_tls}) + +if(CONFIG_MBEDTLS_SSL_PROTO_GMTSSL1_1) + get_target_property(src_tls mbedtls SOURCES) + list(REMOVE_ITEM src_tls ssl_ciphersuites.c ssl_cli.c ssl_tls.c) + set_property(TARGET mbedtls PROPERTY SOURCES ${src_tls}) + + message(STATUS "Setting up mbedtls") + + # list(REMOVE_ITEM src_crypto sha512.c) + # list(REMOVE_ITEM src_crypto cipher_wrap.c ecdsa.c ecp.c ecp_curves.c oid.c pk_wrap.c) + # set_property(TARGET tfpsacrypto PROPERTY SOURCES ${src_crypto}) + + get_target_property(src_builtin builtin SOURCES) + message(STATUS "src_builtin: ${src_builtin}") + + get_target_property(src_x509 mbedx509 SOURCES) + list(REMOVE_ITEM src_x509 x509_crt.c) + set_property(TARGET mbedx509 PROPERTY SOURCES ${src_x509}) +endif() + +# Core libraries from the mbedTLS project +set(mbedtls_targets mbedtls mbedx509 tfpsacrypto builtin) +# 3rd party libraries from the mbedTLS project +list(APPEND mbedtls_targets everest p256m) + +set(mbedtls_target_sources "${COMPONENT_DIR}/port/mbedtls_debug.c" + "${COMPONENT_DIR}/port/esp_platform_time.c") + +if(CONFIG_MBEDTLS_DYNAMIC_BUFFER) + set(mbedtls_target_sources ${mbedtls_target_sources} + "${COMPONENT_DIR}/port/dynamic/esp_mbedtls_dynamic_impl.c" + "${COMPONENT_DIR}/port/dynamic/esp_ssl_cli.c" + "${COMPONENT_DIR}/port/dynamic/esp_ssl_srv.c" + "${COMPONENT_DIR}/port/dynamic/esp_ssl_tls.c") +endif() + +if(${IDF_TARGET} STREQUAL "linux") + set(mbedtls_target_sources ${mbedtls_target_sources} "${COMPONENT_DIR}/port/net_sockets.c") +endif() + +# While updating to MbedTLS release/v3.4.0, building mbedtls/library/psa_crypto.c +# clang produces an unreachable-code warning. +if(CMAKE_C_COMPILER_ID MATCHES "Clang") + target_compile_options(tfpsacrypto PRIVATE "-Wno-unreachable-code") +endif() + +# net_sockets.c should only be compiled if BSD socket functions are available. +# Do this by checking if lwip component is included into the build. +if(CONFIG_LWIP_ENABLE) + list(APPEND mbedtls_target_sources "${COMPONENT_DIR}/port/net_sockets.c") + idf_component_get_property(lwip_lib lwip COMPONENT_LIB) + target_link_libraries(${COMPONENT_LIB} ${linkage_type} ${lwip_lib}) +endif() + +# Add port files to mbedtls targets +target_sources(mbedtls PRIVATE ${mbedtls_target_sources}) + +if(NOT ${IDF_TARGET} STREQUAL "linux") + target_link_libraries(tfpsacrypto PRIVATE idf::esp_security) + target_link_libraries(builtin PRIVATE idf::esp_security) + # target_link_libraries(builtin PRIVATE idf::esp_security) +endif() + +# Choose peripheral type + +if(CONFIG_SOC_SHA_SUPPORTED) + if(CONFIG_SOC_SHA_SUPPORT_PARALLEL_ENG) + set(SHA_PERIPHERAL_TYPE "parallel_engine") + else() + set(SHA_PERIPHERAL_TYPE "core") + endif() +endif() + +if(CONFIG_SOC_AES_SUPPORTED) + if(CONFIG_SOC_AES_SUPPORT_DMA) + set(AES_PERIPHERAL_TYPE "dma") + else() + set(AES_PERIPHERAL_TYPE "block") + endif() +endif() + +if(SHA_PERIPHERAL_TYPE STREQUAL "core") + target_include_directories(builtin PRIVATE "${COMPONENT_DIR}/port/sha/core/include") + if(CONFIG_SOC_SHA_GDMA) + set(SHA_CORE_SRCS "${COMPONENT_DIR}/port/sha/core/esp_sha_gdma_impl.c") + elseif(CONFIG_SOC_SHA_CRYPTO_DMA) + set(SHA_CORE_SRCS "${COMPONENT_DIR}/port/sha/core/esp_sha_crypto_dma_impl.c") + endif() + target_sources(builtin PRIVATE "${SHA_CORE_SRCS}") +endif() + +if(AES_PERIPHERAL_TYPE STREQUAL "dma") + if(NOT CONFIG_SOC_AES_GDMA) + set(AES_DMA_SRCS "${COMPONENT_DIR}/port/aes/dma/esp_aes_crypto_dma_impl.c") + else() + set(AES_DMA_SRCS "${COMPONENT_DIR}/port/aes/dma/esp_aes_gdma_impl.c") + endif() + + list(APPEND AES_DMA_SRCS "${COMPONENT_DIR}/port/aes/dma/esp_aes_dma_core.c") + + target_include_directories(tfpsacrypto PRIVATE "${COMPONENT_DIR}/port/aes/dma/include") + target_sources(tfpsacrypto PRIVATE "${AES_DMA_SRCS}") +endif() + +if((SHA_PERIPHERAL_TYPE STREQUAL "core" AND CONFIG_SOC_SHA_SUPPORT_DMA) OR AES_PERIPHERAL_TYPE STREQUAL "dma") + target_link_libraries(tfpsacrypto PRIVATE idf::esp_mm) + target_link_libraries(builtin PRIVATE idf::esp_mm) + if(CONFIG_SOC_SHA_GDMA OR CONFIG_SOC_AES_GDMA) + if(CONFIG_SOC_AXI_DMA_EXT_MEM_ENC_ALIGNMENT) + target_link_libraries(tfpsacrypto PRIVATE idf::bootloader_support) + target_link_libraries(builtin PRIVATE idf::bootloader_support) + endif() + target_sources(tfpsacrypto PRIVATE "${COMPONENT_DIR}/port/crypto_shared_gdma/esp_crypto_shared_gdma.c") + endif() +endif() + +if(NOT ${IDF_TARGET} STREQUAL "linux") + target_sources(tfpsacrypto PRIVATE "${COMPONENT_DIR}/port/esp_hardware.c") +endif() +# target_sources(tfpsacrypto PRIVATE "${COMPONENT_DIR}/port/esp_mem.c" +# "${COMPONENT_DIR}/port/esp_timing.c" +# ) + +if(CONFIG_SOC_AES_SUPPORTED) + target_include_directories(tfpsacrypto PRIVATE "${COMPONENT_DIR}/port/aes/include") + target_sources(tfpsacrypto PRIVATE "${COMPONENT_DIR}/port/aes/esp_aes_xts.c" + "${COMPONENT_DIR}/port/aes/esp_aes_common.c" + "${COMPONENT_DIR}/port/aes/${AES_PERIPHERAL_TYPE}/esp_aes.c" + ) +endif() + +if(CONFIG_SOC_SHA_SUPPORTED) + target_sources(builtin PRIVATE "${COMPONENT_DIR}/port/sha/esp_sha.c" + "${COMPONENT_DIR}/port/sha/${SHA_PERIPHERAL_TYPE}/sha.c" + ) +endif() + +# if(CONFIG_SOC_DIG_SIGN_SUPPORTED) +# target_sources(mbedcrypto PRIVATE +# "${COMPONENT_DIR}/port/esp_ds/esp_rsa_sign_alt.c" +# "${COMPONENT_DIR}/port/esp_ds/esp_rsa_dec_alt.c" +# "${COMPONENT_DIR}/port/esp_ds/esp_ds_common.c") +# endif() +# # CONFIG_ESP_TLS_USE_DS_PERIPHERAL can be enabled only for the supported targets. +# if(CONFIG_ESP_TLS_USE_DS_PERIPHERAL) +# target_sources(mbedcrypto PRIVATE "${COMPONENT_DIR}/port/esp_ds/esp_rsa_sign_alt.c") +# endif() + +# Note: some mbedTLS hardware acceleration can be enabled/disabled by config. +# +# We don't need to filter aes.c as this uses a different prefix (esp_aes_x) and the +# config option only changes the prefixes in the header so mbedtls_aes_x compiles to esp_aes_x +# +# The other port-specific files don't override internal mbedTLS functions, they just add new functions. + +if(CONFIG_MBEDTLS_HARDWARE_MPI) + target_sources(tfpsacrypto PRIVATE "${COMPONENT_DIR}/port/bignum/esp_bignum.c" + "${COMPONENT_DIR}/port/bignum/bignum_alt.c") +endif() + +if(CONFIG_MBEDTLS_HARDWARE_SHA) + target_sources(tfpsacrypto PRIVATE "${COMPONENT_DIR}/port/sha/${SHA_PERIPHERAL_TYPE}/esp_sha1.c" + "${COMPONENT_DIR}/port/sha/${SHA_PERIPHERAL_TYPE}/esp_sha256.c" + "${COMPONENT_DIR}/port/sha/${SHA_PERIPHERAL_TYPE}/esp_sha512.c" + ) +endif() + +if(CONFIG_MBEDTLS_HARDWARE_GCM OR CONFIG_MBEDTLS_HARDWARE_AES) + target_sources(tfpsacrypto PRIVATE "${COMPONENT_DIR}/port/aes/esp_aes_gcm.c") +endif() + +# if(CONFIG_MBEDTLS_HARDWARE_ECC) +# target_sources(mbedcrypto PRIVATE "${COMPONENT_DIR}/port/ecc/esp_ecc.c" +# "${COMPONENT_DIR}/port/ecc/ecc_alt.c") +# endif() + +# if(CONFIG_MBEDTLS_HARDWARE_ECDSA_SIGN OR +# CONFIG_MBEDTLS_HARDWARE_ECDSA_VERIFY OR CONFIG_MBEDTLS_TEE_SEC_STG_ECDSA_SIGN) +# target_sources(mbedcrypto PRIVATE "${COMPONENT_DIR}/port/ecdsa/ecdsa_alt.c") + +# set(WRAP_FUNCTIONS_SIGN +# mbedtls_ecdsa_sign +# mbedtls_ecdsa_sign_restartable +# mbedtls_ecdsa_write_signature +# mbedtls_ecdsa_write_signature_restartable) + +# set(WRAP_FUNCTIONS_VERIFY +# mbedtls_ecdsa_verify +# mbedtls_ecdsa_verify_restartable +# mbedtls_ecdsa_read_signature +# mbedtls_ecdsa_read_signature_restartable) + +# if(CONFIG_MBEDTLS_HARDWARE_ECDSA_SIGN OR CONFIG_MBEDTLS_TEE_SEC_STG_ECDSA_SIGN) +# foreach(wrap ${WRAP_FUNCTIONS_SIGN}) +# target_link_libraries(${COMPONENT_LIB} INTERFACE "-Wl,--wrap=${wrap}") +# endforeach() + +# if(CONFIG_SOC_ECDSA_SUPPORT_DETERMINISTIC_MODE) +# target_link_libraries(${COMPONENT_LIB} INTERFACE "-Wl,--wrap=mbedtls_ecdsa_sign_det_ext") +# target_link_libraries(${COMPONENT_LIB} INTERFACE "-Wl,--wrap=mbedtls_ecdsa_sign_det_restartable") +# endif() +# endif() + +# if(CONFIG_MBEDTLS_HARDWARE_ECDSA_VERIFY) +# foreach(wrap ${WRAP_FUNCTIONS_VERIFY}) +# target_link_libraries(${COMPONENT_LIB} INTERFACE "-Wl,--wrap=${wrap}") +# endforeach() +# endif() + +# if(CONFIG_MBEDTLS_TEE_SEC_STG_ECDSA_SIGN) +# target_link_libraries(mbedcrypto PRIVATE idf::tee_sec_storage) +# endif() +# endif() + +# if(CONFIG_MBEDTLS_ROM_MD5) +# target_sources(mbedcrypto PRIVATE "${COMPONENT_DIR}/port/md/esp_md.c") +# endif() + +# if(CONFIG_MBEDTLS_USE_CRYPTO_ROM_IMPL) +# target_sources(mbedcrypto PRIVATE "${COMPONENT_DIR}/port/mbedtls_rom/mbedtls_rom_osi.c") +# target_link_libraries(${COMPONENT_LIB} PRIVATE "-u mbedtls_rom_osi_functions_init") +# endif() + +message(STATUS "Setting up mbedtls configuration") +foreach(target ${mbedtls_targets}) + target_compile_definitions(${target} PUBLIC -DMBEDTLS_CONFIG_FILE="mbedtls/esp_config.h") + target_compile_definitions(${target} PUBLIC MBEDTLS_MAJOR_VERSION=4) + set_config_files_compile_definitions(${target}) + if(CONFIG_COMPILER_STATIC_ANALYZER AND CMAKE_C_COMPILER_ID STREQUAL "GNU") # TODO IDF-10087 + target_compile_options(${target} PRIVATE "-fno-analyzer") + endif() +endforeach() + +if(CONFIG_COMPILER_STATIC_ANALYZER AND CMAKE_C_COMPILER_ID STREQUAL "GNU") + target_compile_options(${COMPONENT_LIB} PRIVATE "-fno-analyzer") + target_compile_options(tfpsacrypto PRIVATE "-fno-analyzer") +endif() + +if(CONFIG_MBEDTLS_DYNAMIC_BUFFER) + set(WRAP_FUNCTIONS + mbedtls_ssl_write_client_hello + mbedtls_ssl_handshake_client_step + mbedtls_ssl_tls13_handshake_client_step + mbedtls_ssl_handshake_server_step + mbedtls_ssl_read + mbedtls_ssl_write + mbedtls_ssl_session_reset + mbedtls_ssl_free + mbedtls_ssl_setup + mbedtls_ssl_send_alert_message + mbedtls_ssl_close_notify) + + foreach(wrap ${WRAP_FUNCTIONS}) + target_link_libraries(${COMPONENT_LIB} INTERFACE "-Wl,--wrap=${wrap}") + endforeach() +endif() + +# set_property(TARGET mbedcrypto APPEND PROPERTY LINK_INTERFACE_LIBRARIES mbedtls) + +# if(CONFIG_PM_ENABLE) +# target_link_libraries(mbedcrypto PRIVATE idf::esp_pm) +# endif() + +# if(CONFIG_MBEDTLS_HARDWARE_ECDSA_SIGN OR CONFIG_MBEDTLS_HARDWARE_ECDSA_VERIFY) +# target_link_libraries(mbedcrypto PRIVATE idf::efuse) +# endif() + +target_link_libraries(${COMPONENT_LIB} ${linkage_type} ${mbedtls_targets}) + +# if(CONFIG_ESP_TLS_USE_DS_PERIPHERAL) +# # The linker seems to be unable to resolve all the dependencies without increasing this +# set_property(TARGET mbedcrypto APPEND PROPERTY LINK_INTERFACE_MULTIPLICITY 6) +# endif() + +# Additional optional dependencies for the mbedcrypto library +# function(mbedcrypto_optional_deps component_name) +# idf_build_get_property(components BUILD_COMPONENTS) +# if(${component_name} IN_LIST components) +# idf_component_get_property(lib_name ${component_name} COMPONENT_LIB) +# target_link_libraries(mbedcrypto PRIVATE ${lib_name}) +# endif() +# endfunction() + +# if(CONFIG_MBEDTLS_HARDWARE_ECDSA_SIGN_CONSTANT_TIME_CM) +# mbedcrypto_optional_deps(esp_timer idf::esp_timer) +# endif() + +# # Link esp-cryptoauthlib to mbedtls +# if(CONFIG_ATCA_MBEDTLS_ECDSA) +# mbedcrypto_optional_deps(espressif__esp-cryptoauthlib esp-cryptoauthlib) +# endif() + +# Apply -fno-analyzer to ALL mbedTLS targets at the very end when all targets are created +if(CONFIG_COMPILER_STATIC_ANALYZER AND CMAKE_C_COMPILER_ID STREQUAL "GNU") + message(STATUS "Applying -fno-analyzer to all mbedTLS targets...") + + # Get all targets from all directories + get_property( + all_mbedtls_targets DIRECTORY ${CMAKE_CURRENT_SOURCE_DIR}/mbedtls PROPERTY BUILDSYSTEM_TARGETS + ) + get_property( + drivers_targets DIRECTORY ${CMAKE_CURRENT_SOURCE_DIR}/mbedtls/tf-psa-crypto/drivers PROPERTY BUILDSYSTEM_TARGETS + ) + + message(STATUS "Found mbedtls targets: ${all_mbedtls_targets}") + message(STATUS "Found drivers targets: ${drivers_targets}") + + # Get targets from nested driver subdirectories + foreach(subdir IN ITEMS builtin everest p256-m) + if(EXISTS ${CMAKE_CURRENT_SOURCE_DIR}/mbedtls/tf-psa-crypto/drivers/${subdir}) + get_property( + subdir_targets DIRECTORY ${CMAKE_CURRENT_SOURCE_DIR}/mbedtls/tf-psa-crypto/drivers/${subdir} + PROPERTY BUILDSYSTEM_TARGETS + ) + message(STATUS "Found ${subdir} targets: ${subdir_targets}") + list(APPEND drivers_targets ${subdir_targets}) + endif() + endforeach() + + # Combine all target lists + set(all_targets ${all_mbedtls_targets} ${drivers_targets}) + message(STATUS "All combined targets: ${all_targets}") + + # Apply -fno-analyzer to each target + foreach(target ${all_targets}) + if(TARGET ${target}) + get_target_property(target_type ${target} TYPE) + if(target_type STREQUAL "STATIC_LIBRARY" OR + target_type STREQUAL "SHARED_LIBRARY" OR + target_type STREQUAL "MODULE_LIBRARY" OR + target_type STREQUAL "OBJECT_LIBRARY" OR + target_type STREQUAL "EXECUTABLE") + message(STATUS "Applying -fno-analyzer to target: ${target}") + target_compile_options(${target} PRIVATE "-fno-analyzer") + endif() + endif() + endforeach() + + # Also check for any targets that might have been missed by using global target list + get_property(global_targets GLOBAL PROPERTY TARGETS) + set(mbedtls_global_targets "") + foreach(target ${global_targets}) + if(TARGET ${target}) + get_target_property(target_source_dir ${target} SOURCE_DIR) + if(target_source_dir) + # Check if target is from mbedtls directory or has mbedtls-related names + string(FIND "${target_source_dir}" "mbedtls" pos) + string(FIND "${target}" "mbedtls" name_pos) + string(FIND "${target}" "tfpsacrypto" tfpsa_pos) + # string(FIND "${target}" "everest" everest_pos) + # string(FIND "${target}" "p256m" p256m_pos) + string(FIND "${target}" "builtin" builtin_pos) + if(pos GREATER -1 OR name_pos GREATER -1 OR tfpsa_pos GREATER -1 OR builtin_pos GREATER -1) + list(APPEND mbedtls_global_targets ${target}) + get_target_property(target_type ${target} TYPE) + # Skip ALIAS targets as they don't have compile options + if(NOT target_type STREQUAL "ALIAS" AND + (target_type STREQUAL "STATIC_LIBRARY" OR + target_type STREQUAL "SHARED_LIBRARY" OR + target_type STREQUAL "MODULE_LIBRARY" OR + target_type STREQUAL "OBJECT_LIBRARY" OR + target_type STREQUAL "EXECUTABLE")) + # Check if -fno-analyzer was already applied + get_target_property(compile_options ${target} COMPILE_OPTIONS) + if(NOT compile_options OR NOT "-fno-analyzer" IN_LIST compile_options) + message(STATUS "Applying -fno-analyzer to missed target: ${target}") + target_compile_options(${target} PRIVATE "-fno-analyzer") + endif() + endif() + endif() + endif() + endif() + endforeach() + message(STATUS "All mbedtls-related global targets: ${mbedtls_global_targets}") +endif() diff --git a/components/mbedtls/mbedtls b/components/mbedtls/mbedtls index 4e13725bbb4..ffb280bb63c 160000 --- a/components/mbedtls/mbedtls +++ b/components/mbedtls/mbedtls @@ -1 +1 @@ -Subproject commit 4e13725bbb43f1d46af30c07a0527961b1157433 +Subproject commit ffb280bb63c78bfec1e1ab55040671768c85c923 diff --git a/components/mbedtls/port/include/mbedtls/esp_config.h b/components/mbedtls/port/include/mbedtls/esp_config.h index 5003c1ea3d2..b1877969f23 100644 --- a/components/mbedtls/port/include/mbedtls/esp_config.h +++ b/components/mbedtls/port/include/mbedtls/esp_config.h @@ -197,7 +197,11 @@ #ifdef CONFIG_MBEDTLS_HARDWARE_SHA #define MBEDTLS_SHA1_ALT #define MBEDTLS_SHA256_ALT - +#define ESP_SHA_DRIVER_ENABLED +#define MBEDTLS_PSA_ACCEL_ALG_SHA_1 +// TODO: Implement SHA224 +#define MBEDTLS_PSA_ACCEL_ALG_SHA_224 +#define MBEDTLS_PSA_ACCEL_ALG_SHA_256 #if SOC_SHA_SUPPORT_SHA512 #define MBEDTLS_SHA512_ALT #else diff --git a/components/openthread/openthread b/components/openthread/openthread index 36b14d3ef74..7d4fa4223fb 160000 --- a/components/openthread/openthread +++ b/components/openthread/openthread @@ -1 +1 @@ -Subproject commit 36b14d3ef74f5e37e5be8902e1c1955a642fdfbf +Subproject commit 7d4fa4223fbb19e610f054aabcf3ce87ae074ffe