feat(esp_tee): Disable the MBEDTLS_PSA_ASSUME_EXCLUSIVE_BUFFERS option for TEE build

This commit is contained in:
Laukik Hase
2026-09-02 11:49:22 +05:30
parent fbb0518b1a
commit dc0fadf1d4
6 changed files with 139 additions and 73 deletions
@@ -27,7 +27,6 @@
#pragma once
#define MBEDTLS_PSA_ASSUME_EXCLUSIVE_BUFFERS
#ifndef CONFIG_IDF_TARGET_LINUX
#undef MBEDTLS_PSA_BUILTIN_GET_ENTROPY
#define MBEDTLS_PSA_DRIVER_GET_ENTROPY
+9 -6
View File
@@ -1,5 +1,5 @@
/*
* SPDX-FileCopyrightText: 2018-2025 Espressif Systems (Shanghai) CO LTD
* SPDX-FileCopyrightText: 2018-2026 Espressif Systems (Shanghai) CO LTD
*
* SPDX-License-Identifier: Apache-2.0
*/
@@ -9,6 +9,7 @@
#include <assert.h>
#include "psa/crypto.h"
#include "mbedtls/platform_util.h"
#include "hal/sha_hal.h"
#include "hal/sha_types.h"
@@ -64,18 +65,20 @@ void esp_sha(esp_sha_type sha_type, const unsigned char *input, size_t ilen, uns
if (alg == PSA_ALG_NONE) {
ESP_LOGE(TAG, "SHA type %d not supported", (int)sha_type);
abort();
return;
}
size_t olen;
size_t output_len = PSA_HASH_LENGTH(alg);
status = psa_hash_compute(alg, input, ilen, output, output_len, &olen);
if (status != PSA_SUCCESS) {
ESP_LOGE(TAG, "SHA computation failed, status %d", status);
abort();
ESP_LOGE(TAG, "SHA computation failed (status %d), output zeroed", (int)status);
mbedtls_platform_zeroize(output, output_len);
return;
}
if (olen != output_len) {
ESP_LOGE(TAG, "SHA output length mismatch, expected %u, got %u", output_len, olen);
abort();
ESP_LOGE(TAG, "SHA output length mismatch (expected %u, got %u), output zeroed", output_len, olen);
mbedtls_platform_zeroize(output, output_len);
return;
}
}
@@ -112,12 +112,6 @@ TEST_CASE("Test esp_sha()", "[hw_crypto]")
#endif
}
/* NOTE: This test attempts to mmap 1MB of flash starting from address 0x00, which overlaps
* the entire TEE protected region, causing the mmap operation to fail and triggering an
* exception in the subsequent steps.
*/
#if !CONFIG_SECURE_ENABLE_TEE
TEST_CASE("Test esp_sha() function with long input", "[hw_crypto]")
{
int r = -1;
@@ -176,4 +170,3 @@ TEST_CASE("Test esp_sha() function with long input", "[hw_crypto]")
}
#endif
#endif // SOC_SHA_SUPPORTED && CONFIG_MBEDTLS_HARDWARE_SHA