From dd28e303d5fd0fe7114d41ddb117e357b3199bc1 Mon Sep 17 00:00:00 2001 From: Jiang Guang Ming Date: Thu, 7 May 2026 14:18:54 +0800 Subject: [PATCH] fix(mbedtls): support ROM mbedTLS crypto in bootloader --- components/mbedtls/CMakeLists.txt | 11 ++- .../port/mbedtls_rom/mbedtls_rom_osi.h | 8 --- .../mbedtls_rom/mbedtls_rom_osi_bootloader.c | 69 +++++++++++++++---- components/nvs_flash/src/nvs_bootloader.c | 2 +- 4 files changed, 66 insertions(+), 24 deletions(-) diff --git a/components/mbedtls/CMakeLists.txt b/components/mbedtls/CMakeLists.txt index 55fb96281d5..7ae5daadef6 100644 --- a/components/mbedtls/CMakeLists.txt +++ b/components/mbedtls/CMakeLists.txt @@ -7,15 +7,24 @@ if(esp_tee_build) return() elseif(BOOTLOADER_BUILD) # TODO: IDF-11673 if(CONFIG_MBEDTLS_USE_CRYPTO_ROM_IMPL_BOOTLOADER) - set(include_dirs "${COMPONENT_DIR}/mbedtls/include" + set(include_dirs "${COMPONENT_DIR}/port/include" + "${COMPONENT_DIR}/mbedtls/include" + "${COMPONENT_DIR}/mbedtls/tf-psa-crypto/include" "${COMPONENT_DIR}/mbedtls/tf-psa-crypto/drivers/builtin/include" + "${COMPONENT_DIR}/port/psa_driver/include" "port/mbedtls_rom") set(srcs "port/mbedtls_rom/mbedtls_rom_osi_bootloader.c") + set(public_compile_definitions + -DMBEDTLS_CONFIG_FILE="mbedtls/esp_config.h" + MBEDTLS_CIPHER_MODE_XTS) endif() idf_component_register(SRCS "${srcs}" INCLUDE_DIRS "${include_dirs}" PRIV_REQUIRES esp_hal_dma) + if(public_compile_definitions) + target_compile_definitions(${COMPONENT_LIB} PUBLIC ${public_compile_definitions}) + endif() return() endif() diff --git a/components/mbedtls/port/mbedtls_rom/mbedtls_rom_osi.h b/components/mbedtls/port/mbedtls_rom/mbedtls_rom_osi.h index 47f755d556c..9d53887cecb 100644 --- a/components/mbedtls/port/mbedtls_rom/mbedtls_rom_osi.h +++ b/components/mbedtls/port/mbedtls_rom/mbedtls_rom_osi.h @@ -31,7 +31,6 @@ extern "C" { #endif -#ifndef BOOTLOADER_BUILD #if (!defined(CONFIG_MBEDTLS_THREADING_C)) #error CONFIG_MBEDTLS_THREADING_C #endif @@ -40,9 +39,6 @@ typedef void (*_rom_mbedtls_threading_set_alt_t)(void (*mutex_init)(mbedtls_thre void (*mutex_free)(mbedtls_threading_mutex_t *), int (*mutex_lock)(mbedtls_threading_mutex_t *), int (*mutex_unlock)(mbedtls_threading_mutex_t *)); -#else /* BOOTLOADER_BUILD */ -typedef void mbedtls_threading_mutex_t; -#endif /* BOOTLOADER_BUILD */ typedef struct mbedtls_rom_eco4_funcs { // aes module @@ -303,10 +299,6 @@ typedef struct mbedtls_rom_eco4_funcs { #error "MBEDTLS_PLATFORM_ZEROIZE_ALT" #endif -#if BOOTLOADER_BUILD -void mbedtls_rom_osi_functions_init_bootloader(void); -#endif /* BOOTLOADER_BUILD */ - #ifdef __cplusplus } #endif diff --git a/components/mbedtls/port/mbedtls_rom/mbedtls_rom_osi_bootloader.c b/components/mbedtls/port/mbedtls_rom/mbedtls_rom_osi_bootloader.c index 0ea46f9591f..3dccaa768b0 100644 --- a/components/mbedtls/port/mbedtls_rom/mbedtls_rom_osi_bootloader.c +++ b/components/mbedtls/port/mbedtls_rom/mbedtls_rom_osi_bootloader.c @@ -4,26 +4,67 @@ * SPDX-License-Identifier: Apache-2.0 */ -#include "mbedtls_rom_osi.h" +#include + +#define MBEDTLS_DECLARE_PRIVATE_IDENTIFIERS +#include "mbedtls/private/aes.h" + +int mbedtls_internal_aes_encrypt(mbedtls_aes_context *ctx, const unsigned char input[16], unsigned char output[16]); +int mbedtls_internal_aes_decrypt(mbedtls_aes_context *ctx, const unsigned char input[16], unsigned char output[16]); + +#define ROM_TABLE_FN(table_type, field, fn) ((__typeof__(((table_type *)0)->field))(fn)) + +#define MBEDTLS_ROM_ECO4_FUNC_COUNT 221 +#define MBEDTLS_ROM_ECO4_BOOTLOADER_FUNC_COUNT 16 + +typedef struct mbedtls_rom_eco4_funcs { + void (*_rom_mbedtls_aes_init)(mbedtls_aes_context *ctx); + void (*_rom_mbedtls_aes_free)(mbedtls_aes_context *ctx); + void (*_rom_mbedtls_aes_xts_init)(mbedtls_aes_xts_context *ctx); + void (*_rom_mbedtls_aes_xts_free)(mbedtls_aes_xts_context *ctx); + int (*_rom_mbedtls_aes_setkey_enc)(mbedtls_aes_context *ctx, const unsigned char *key, unsigned int keybits); + int (*_rom_mbedtls_aes_setkey_dec)(mbedtls_aes_context *ctx, const unsigned char *key, unsigned int keybits); + int (*_rom_mbedtls_aes_xts_setkey_enc)(mbedtls_aes_xts_context *ctx, const unsigned char *key, unsigned int keybits); + int (*_rom_mbedtls_aes_xts_setkey_dec)(mbedtls_aes_xts_context *ctx, const unsigned char *key, unsigned int keybits); + int (*_rom_mbedtls_aes_crypt_ecb)(mbedtls_aes_context *ctx, int mode, const unsigned char input[16], unsigned char output[16]); + int (*_rom_mbedtls_aes_crypt_cbc)(mbedtls_aes_context *ctx, int mode, size_t length, unsigned char iv[16], const unsigned char *input, unsigned char *output); + int (*_rom_mbedtls_aes_crypt_xts)(mbedtls_aes_xts_context *ctx, int mode, size_t length, const unsigned char data_unit[16], const unsigned char *input, unsigned char *output); + int (*_rom_mbedtls_aes_crypt_cfb128)(mbedtls_aes_context *ctx, int mode, size_t length, size_t *iv_off, unsigned char iv[16], const unsigned char *input, unsigned char *output); + int (*_rom_mbedtls_aes_crypt_ofb)(mbedtls_aes_context *ctx, size_t length, size_t *iv_off, unsigned char iv[16], const unsigned char *input, unsigned char *output); + int (*_rom_mbedtls_aes_crypt_ctr)(mbedtls_aes_context *ctx, size_t length, size_t *nc_off, unsigned char nonce_counter[16], unsigned char stream_block[16], const unsigned char *input, unsigned char *output); + int (*_rom_mbedtls_internal_aes_encrypt)(mbedtls_aes_context *ctx, const unsigned char input[16], unsigned char output[16]); + int (*_rom_mbedtls_internal_aes_decrypt)(mbedtls_aes_context *ctx, const unsigned char input[16], unsigned char output[16]); + void (*_rom_mbedtls_unused[MBEDTLS_ROM_ECO4_FUNC_COUNT - MBEDTLS_ROM_ECO4_BOOTLOADER_FUNC_COUNT])(void); +} mbedtls_rom_eco4_funcs_t; + +_Static_assert(sizeof(mbedtls_rom_eco4_funcs_t) == MBEDTLS_ROM_ECO4_FUNC_COUNT * sizeof(void (*)(void)), + "Bootloader ROM function table must cover the full ROM ECO4 table"); /* This structure can be automatically generated by the script with rom.mbedtls.ld. */ +/* Keep the bootloader table the full ROM ECO4 size. The bootloader only fills AES + * entries, but ROM code may index later slots internally; all non-AES entries must + * exist and remain zero-initialized. + */ static const mbedtls_rom_eco4_funcs_t mbedtls_rom_eco4_funcs_table = { /* Fill the ROM functions into mbedtls rom function table. */ /* aes module */ - ._rom_mbedtls_aes_init = mbedtls_aes_init, - ._rom_mbedtls_aes_free = mbedtls_aes_free, - ._rom_mbedtls_aes_setkey_enc = mbedtls_aes_setkey_enc, - ._rom_mbedtls_aes_setkey_dec = mbedtls_aes_setkey_dec, - ._rom_mbedtls_aes_crypt_ecb = mbedtls_aes_crypt_ecb, - ._rom_mbedtls_aes_crypt_cbc = mbedtls_aes_crypt_cbc, - ._rom_mbedtls_internal_aes_encrypt = mbedtls_internal_aes_encrypt, - ._rom_mbedtls_internal_aes_decrypt = mbedtls_internal_aes_decrypt, + ._rom_mbedtls_aes_init = ROM_TABLE_FN(mbedtls_rom_eco4_funcs_t, _rom_mbedtls_aes_init, mbedtls_aes_init), + ._rom_mbedtls_aes_free = ROM_TABLE_FN(mbedtls_rom_eco4_funcs_t, _rom_mbedtls_aes_free, mbedtls_aes_free), + ._rom_mbedtls_aes_setkey_enc = ROM_TABLE_FN(mbedtls_rom_eco4_funcs_t, _rom_mbedtls_aes_setkey_enc, mbedtls_aes_setkey_enc), + ._rom_mbedtls_aes_setkey_dec = ROM_TABLE_FN(mbedtls_rom_eco4_funcs_t, _rom_mbedtls_aes_setkey_dec, mbedtls_aes_setkey_dec), + ._rom_mbedtls_aes_crypt_ecb = ROM_TABLE_FN(mbedtls_rom_eco4_funcs_t, _rom_mbedtls_aes_crypt_ecb, mbedtls_aes_crypt_ecb), + ._rom_mbedtls_aes_crypt_cbc = ROM_TABLE_FN(mbedtls_rom_eco4_funcs_t, _rom_mbedtls_aes_crypt_cbc, mbedtls_aes_crypt_cbc), + ._rom_mbedtls_internal_aes_encrypt = ROM_TABLE_FN(mbedtls_rom_eco4_funcs_t, _rom_mbedtls_internal_aes_encrypt, mbedtls_internal_aes_encrypt), + ._rom_mbedtls_internal_aes_decrypt = ROM_TABLE_FN(mbedtls_rom_eco4_funcs_t, _rom_mbedtls_internal_aes_decrypt, mbedtls_internal_aes_decrypt), - ._rom_mbedtls_aes_xts_init = mbedtls_aes_xts_init, - ._rom_mbedtls_aes_xts_free = mbedtls_aes_xts_free, - ._rom_mbedtls_aes_xts_setkey_enc = mbedtls_aes_xts_setkey_enc, - ._rom_mbedtls_aes_xts_setkey_dec = mbedtls_aes_xts_setkey_dec, - ._rom_mbedtls_aes_crypt_xts = mbedtls_aes_crypt_xts, + ._rom_mbedtls_aes_xts_init = ROM_TABLE_FN(mbedtls_rom_eco4_funcs_t, _rom_mbedtls_aes_xts_init, mbedtls_aes_xts_init), + ._rom_mbedtls_aes_xts_free = ROM_TABLE_FN(mbedtls_rom_eco4_funcs_t, _rom_mbedtls_aes_xts_free, mbedtls_aes_xts_free), + ._rom_mbedtls_aes_xts_setkey_enc = ROM_TABLE_FN(mbedtls_rom_eco4_funcs_t, _rom_mbedtls_aes_xts_setkey_enc, mbedtls_aes_xts_setkey_enc), + ._rom_mbedtls_aes_xts_setkey_dec = ROM_TABLE_FN(mbedtls_rom_eco4_funcs_t, _rom_mbedtls_aes_xts_setkey_dec, mbedtls_aes_xts_setkey_dec), + ._rom_mbedtls_aes_crypt_xts = ROM_TABLE_FN(mbedtls_rom_eco4_funcs_t, _rom_mbedtls_aes_crypt_xts, mbedtls_aes_crypt_xts), + ._rom_mbedtls_aes_crypt_cfb128 = ROM_TABLE_FN(mbedtls_rom_eco4_funcs_t, _rom_mbedtls_aes_crypt_cfb128, mbedtls_aes_crypt_cfb128), + ._rom_mbedtls_aes_crypt_ofb = ROM_TABLE_FN(mbedtls_rom_eco4_funcs_t, _rom_mbedtls_aes_crypt_ofb, mbedtls_aes_crypt_ofb), + ._rom_mbedtls_aes_crypt_ctr = ROM_TABLE_FN(mbedtls_rom_eco4_funcs_t, _rom_mbedtls_aes_crypt_ctr, mbedtls_aes_crypt_ctr), }; void mbedtls_rom_osi_functions_init_bootloader(void) diff --git a/components/nvs_flash/src/nvs_bootloader.c b/components/nvs_flash/src/nvs_bootloader.c index 9347cfd3ba2..a8c50d76536 100644 --- a/components/nvs_flash/src/nvs_bootloader.c +++ b/components/nvs_flash/src/nvs_bootloader.c @@ -16,7 +16,7 @@ #include #if CONFIG_MBEDTLS_USE_CRYPTO_ROM_IMPL_BOOTLOADER && BOOTLOADER_BUILD -#include "mbedtls_rom_osi.h" +void mbedtls_rom_osi_functions_init_bootloader(void); #endif static const char* TAG = "nvs_bootloader";