diff --git a/components/esp-tls/esp_tls_mbedtls.c b/components/esp-tls/esp_tls_mbedtls.c index 4e13617ee8a..67f1529b9cb 100644 --- a/components/esp-tls/esp_tls_mbedtls.c +++ b/components/esp-tls/esp_tls_mbedtls.c @@ -493,59 +493,37 @@ void esp_mbedtls_cleanup(esp_tls_t *tls) mbedtls_x509_crt_free(&tls->cacert); mbedtls_x509_crt_free(&tls->clientcert); + /* For opaque keys (DS peripheral, hardware ECDSA), mbedtls_pk_free() does + * not destroy the PSA key — ownership is external. Destroy it manually + * before calling mbedtls_pk_free(). */ #ifdef CONFIG_ESP_TLS_USE_DS_PERIPHERAL if (mbedtls_pk_get_type(&tls->clientkey) == MBEDTLS_PK_RSASSA_PSS) { - mbedtls_rsa_context *rsa = tls->clientkey.MBEDTLS_PRIVATE(pk_ctx); - if (rsa != NULL) { - mbedtls_rsa_free(rsa); - mbedtls_free(rsa); - rsa = NULL; - } if (tls->clientkey.MBEDTLS_PRIVATE(priv_id) != PSA_KEY_ID_NULL) { psa_destroy_key(tls->clientkey.MBEDTLS_PRIVATE(priv_id)); + tls->clientkey.MBEDTLS_PRIVATE(priv_id) = PSA_KEY_ID_NULL; } - tls->clientkey.MBEDTLS_PRIVATE(pk_ctx) = NULL; } - - // Similar cleanup for server key if (mbedtls_pk_get_type(&tls->serverkey) == MBEDTLS_PK_RSASSA_PSS) { - mbedtls_rsa_context *rsa = tls->serverkey.MBEDTLS_PRIVATE(pk_ctx); - if (rsa != NULL) { - mbedtls_rsa_free(rsa); - mbedtls_free(rsa); - rsa = NULL; - } if (tls->serverkey.MBEDTLS_PRIVATE(priv_id) != PSA_KEY_ID_NULL) { psa_destroy_key(tls->serverkey.MBEDTLS_PRIVATE(priv_id)); + tls->serverkey.MBEDTLS_PRIVATE(priv_id) = PSA_KEY_ID_NULL; } - tls->serverkey.MBEDTLS_PRIVATE(pk_ctx) = NULL; } #endif #ifdef CONFIG_MBEDTLS_HARDWARE_ECDSA_SIGN - /* In mbedtls v4.0, ECDSA keys require manual cleanup of the keypair structure */ if (mbedtls_pk_get_type(&tls->clientkey) == MBEDTLS_PK_ECDSA) { ESP_LOGD(TAG, "Cleaning up client key"); - mbedtls_ecp_keypair *keypair = tls->clientkey.MBEDTLS_PRIVATE(pk_ctx); - if (keypair != NULL) { - mbedtls_ecp_keypair_free(keypair); - mbedtls_free(keypair); - keypair = NULL; + if (tls->clientkey.MBEDTLS_PRIVATE(priv_id) != PSA_KEY_ID_NULL) { + psa_destroy_key(tls->clientkey.MBEDTLS_PRIVATE(priv_id)); + tls->clientkey.MBEDTLS_PRIVATE(priv_id) = PSA_KEY_ID_NULL; } - psa_destroy_key(tls->clientkey.MBEDTLS_PRIVATE(priv_id)); - tls->clientkey.MBEDTLS_PRIVATE(pk_ctx) = NULL; } - - // Similar cleanup for server key if (mbedtls_pk_get_type(&tls->serverkey) == MBEDTLS_PK_ECDSA) { - mbedtls_ecp_keypair *keypair = tls->serverkey.MBEDTLS_PRIVATE(pk_ctx); - if (keypair != NULL) { - mbedtls_ecp_keypair_free(keypair); - mbedtls_free(keypair); - keypair = NULL; + if (tls->serverkey.MBEDTLS_PRIVATE(priv_id) != PSA_KEY_ID_NULL) { + psa_destroy_key(tls->serverkey.MBEDTLS_PRIVATE(priv_id)); + tls->serverkey.MBEDTLS_PRIVATE(priv_id) = PSA_KEY_ID_NULL; } - psa_destroy_key(tls->serverkey.MBEDTLS_PRIVATE(priv_id)); - tls->serverkey.MBEDTLS_PRIVATE(pk_ctx) = NULL; } #endif diff --git a/components/esp-tls/test_apps/main/app_main.c b/components/esp-tls/test_apps/main/app_main.c index 6a5f0351795..66f0c3b7c91 100644 --- a/components/esp-tls/test_apps/main/app_main.c +++ b/components/esp-tls/test_apps/main/app_main.c @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2021-2025 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2021-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -16,6 +16,7 @@ #endif #include "esp_newlib.h" #include "psa/crypto.h" +#include "esp_crypto_lock.h" #if SOC_SHA_SUPPORT_SHA512 #define SHA_TYPE SHA2_512 #else @@ -59,6 +60,14 @@ void setUp(void) heap_caps_free(buf); psa_destroy_key(key_id); + // Trigger lazy initialization of the MPI hardware mutex. + // In mbedtls 4.x, RSA key parsing goes through PSA which validates + // the key using MPI hardware, creating this lock on first use. +#if CONFIG_MBEDTLS_HARDWARE_MPI + esp_crypto_mpi_lock_acquire(); + esp_crypto_mpi_lock_release(); +#endif // CONFIG_MBEDTLS_HARDWARE_MPI + test_utils_record_free_mem(); TEST_ESP_OK(test_utils_set_leak_level(0, ESP_LEAK_TYPE_CRITICAL, ESP_COMP_LEAK_GENERAL)); TEST_ESP_OK(test_utils_set_leak_level(0, ESP_LEAK_TYPE_WARNING, ESP_COMP_LEAK_GENERAL)); diff --git a/components/esp-tls/test_apps/main/test_esp_tls.c b/components/esp-tls/test_apps/main/test_esp_tls.c index d3175a30638..ab41d32a406 100644 --- a/components/esp-tls/test_apps/main/test_esp_tls.c +++ b/components/esp-tls/test_apps/main/test_esp_tls.c @@ -94,7 +94,6 @@ TEST_CASE("esp_tls_server session create delete", "[esp-tls]") TEST_ASSERT_LESS_THAN_INT(0, ret); // free the allocated memory. esp_tls_server_session_delete(tls); - } #endif /* CONFIG_ESP_TLS_USING_MBEDTLS */