From eb5e92063f45cffe0343b8c74488b1f174936588 Mon Sep 17 00:00:00 2001 From: Aditya Patwardhan Date: Mon, 17 Feb 2025 22:55:02 +0530 Subject: [PATCH] feat(mbedtls): Update the protocol components with PSA APis --- components/esp_http_client/lib/http_auth.c | 40 ++++++++++------ components/esp_http_server/src/httpd_ws.c | 56 +++++++++++----------- 2 files changed, 53 insertions(+), 43 deletions(-) diff --git a/components/esp_http_client/lib/http_auth.c b/components/esp_http_client/lib/http_auth.c index 0bbe054f66d..a6e125ec9f4 100644 --- a/components/esp_http_client/lib/http_auth.c +++ b/components/esp_http_client/lib/http_auth.c @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2015-2021 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2015-2025 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -12,7 +12,6 @@ #include "sys/socket.h" #include "esp_rom_md5.h" #include "esp_tls_crypto.h" -#include "mbedtls/sha256.h" #include "esp_log.h" #include "esp_check.h" @@ -20,6 +19,8 @@ #include "http_utils.h" #include "http_auth.h" +#include "psa/crypto.h" + #define MD5_MAX_LEN (33) #define SHA256_LEN (32) #define SHA256_HEX_LEN (65) @@ -72,7 +73,6 @@ static int md5_printf(char *md, const char *fmt, ...) */ static int sha256_sprintf(char *sha, const char *fmt, ...) { - unsigned char *buf; unsigned char digest[SHA256_LEN]; int len, i; @@ -85,19 +85,31 @@ static int sha256_sprintf(char *sha, const char *fmt, ...) } int ret = 0; - mbedtls_sha256_context sha256; - mbedtls_sha256_init(&sha256); - if (mbedtls_sha256_starts(&sha256, 0) != 0) { - goto exit; - } - if (mbedtls_sha256_update(&sha256, buf, len) != 0) { - goto exit; - } - if (mbedtls_sha256_finish(&sha256, digest) != 0) { + psa_status_t status; + psa_hash_operation_t operation = PSA_HASH_OPERATION_INIT; + + status = psa_crypto_init(); + if (status != PSA_SUCCESS) { goto exit; } - for (i = 0; i < 32; ++i) { + status = psa_hash_setup(&operation, PSA_ALG_SHA_256); + if (status != PSA_SUCCESS) { + goto exit; + } + + status = psa_hash_update(&operation, buf, len); + if (status != PSA_SUCCESS) { + goto exit; + } + + size_t hash_length; + status = psa_hash_finish(&operation, digest, sizeof(digest), &hash_length); + if (status != PSA_SUCCESS || hash_length != SHA256_LEN) { + goto exit; + } + + for (i = 0; i < SHA256_LEN; ++i) { sprintf(&sha[i * 2], "%02x", (unsigned int)digest[i]); } sha[SHA256_HEX_LEN - 1] = '\0'; @@ -105,7 +117,7 @@ static int sha256_sprintf(char *sha, const char *fmt, ...) exit: free(buf); - mbedtls_sha256_free(&sha256); + psa_hash_abort(&operation); va_end(ap); return ret; } diff --git a/components/esp_http_server/src/httpd_ws.c b/components/esp_http_server/src/httpd_ws.c index 4bffe538421..371bff47c07 100644 --- a/components/esp_http_server/src/httpd_ws.c +++ b/components/esp_http_server/src/httpd_ws.c @@ -11,7 +11,7 @@ #include #include #include -#include +#include #include #include @@ -143,37 +143,35 @@ esp_err_t httpd_ws_respond_server_handshake(httpd_req_t *req, const char *suppor ESP_LOGD(TAG, LOG_FMT("Server key before encoding: %s"), server_raw_text); - /* Generate SHA-1 first and then encode to Base64 */ - size_t key_len = strlen(server_raw_text); - -#if CONFIG_MBEDTLS_SHA1_C || CONFIG_MBEDTLS_HARDWARE_SHA - int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED; - mbedtls_sha1_context ctx; - mbedtls_sha1_init(&ctx); - - if ((ret = mbedtls_sha1_starts(&ctx)) != 0) { - goto sha_end; - } - - if ((ret = mbedtls_sha1_update(&ctx, (uint8_t *)server_raw_text, key_len)) != 0) { - goto sha_end; - } - - if ((ret = mbedtls_sha1_finish(&ctx, server_key_hash)) != 0) { - goto sha_end; - } - -sha_end: - mbedtls_sha1_free(&ctx); - if (ret != 0) { - ESP_LOGE(TAG, "Error in calculating SHA1 sum , returned 0x%02X", ret); + /* Initialize PSA Crypto library */ + psa_status_t status = psa_crypto_init(); + if (status != PSA_SUCCESS) { + ESP_LOGE(TAG, "Failed to initialize PSA Crypto"); return ESP_FAIL; } -#else - ESP_LOGE(TAG, "Please enable CONFIG_MBEDTLS_SHA1_C or CONFIG_MBEDTLS_HARDWARE_SHA to support SHA1 operations"); - return ESP_FAIL; -#endif /* CONFIG_MBEDTLS_SHA1_C || CONFIG_MBEDTLS_HARDWARE_SHA */ + /* Generate SHA-1 hash */ + psa_hash_operation_t sha1_operation = PSA_HASH_OPERATION_INIT; + status = psa_hash_setup(&sha1_operation, PSA_ALG_SHA_1); + if (status != PSA_SUCCESS) { + ESP_LOGE(TAG, "Failed to setup SHA-1 operation"); + return ESP_FAIL; + } + + status = psa_hash_update(&sha1_operation, (uint8_t *)server_raw_text, strlen(server_raw_text)); + if (status != PSA_SUCCESS) { + ESP_LOGE(TAG, "Failed to update SHA-1 hash"); + return ESP_FAIL; + } + + size_t hash_length; + status = psa_hash_finish(&sha1_operation, server_key_hash, sizeof(server_key_hash), &hash_length); + if (status != PSA_SUCCESS || hash_length != sizeof(server_key_hash)) { + ESP_LOGE(TAG, "Failed to finish SHA-1 hash"); + return ESP_FAIL; + } + + /* Encode to Base64 */ size_t encoded_len = 0; mbedtls_base64_encode((uint8_t *)server_key_encoded, sizeof(server_key_encoded), &encoded_len, server_key_hash, sizeof(server_key_hash));