mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-02 03:00:34 +03:00
feat(mbedtls): migrates ESP-TEE with PSA APIs
This commit is contained in:
@@ -10,7 +10,7 @@
|
||||
#include "memory_checks.h"
|
||||
#include "esp_newlib.h"
|
||||
#include "psa/crypto.h"
|
||||
#include "mbedtls/aes.h"
|
||||
// #include "mbedtls/aes.h"
|
||||
#if SOC_SHA_SUPPORT_PARALLEL_ENG
|
||||
#include "sha/sha_parallel_engine.h"
|
||||
#else
|
||||
@@ -21,18 +21,21 @@
|
||||
/* setUp runs before every test */
|
||||
void setUp(void)
|
||||
{
|
||||
// #if SOC_SHA_SUPPORTED
|
||||
// // Execute esp_sha operation to allocate internal SHA semaphore (in case of ESP32)
|
||||
// // and initial DMA setup memory which is considered as leaked otherwise
|
||||
// const uint8_t input_buffer[64] = {0};
|
||||
// uint8_t output_buffer[64];
|
||||
// #if SOC_SHA_SUPPORT_SHA256
|
||||
// esp_sha(SHA2_256, input_buffer, sizeof(input_buffer), output_buffer);
|
||||
// #endif // SOC_SHA_SUPPORT_SHA256
|
||||
// #if SOC_SHA_SUPPORT_SHA512
|
||||
// esp_sha(SHA2_512, input_buffer, sizeof(input_buffer), output_buffer);
|
||||
// #endif // SOC_SHA_SUPPORT_SHA512
|
||||
// #endif // SOC_SHA_SUPPORTED
|
||||
#if SOC_SHA_SUPPORTED
|
||||
// Execute esp_sha operation to allocate internal SHA semaphore (in case of ESP32)
|
||||
// and initial DMA setup memory which is considered as leaked otherwise
|
||||
const uint8_t input_buffer[64] = {0};
|
||||
uint8_t output_buffer[64];
|
||||
#if SOC_SHA_SUPPORT_SHA1
|
||||
esp_sha(SHA1, input_buffer, sizeof(input_buffer), output_buffer);
|
||||
#endif // SOC_SHA_SUPPORT_SHA1
|
||||
#if SOC_SHA_SUPPORT_SHA256
|
||||
esp_sha(SHA2_256, input_buffer, sizeof(input_buffer), output_buffer);
|
||||
#endif // SOC_SHA_SUPPORT_SHA256
|
||||
#if SOC_SHA_SUPPORT_SHA512
|
||||
esp_sha(SHA2_512, input_buffer, sizeof(input_buffer), output_buffer);
|
||||
#endif // SOC_SHA_SUPPORT_SHA512
|
||||
#endif // SOC_SHA_SUPPORTED
|
||||
|
||||
#if defined(CONFIG_MBEDTLS_HARDWARE_MPI)
|
||||
esp_mpi_enable_hardware_hw_op();
|
||||
@@ -40,21 +43,35 @@ void setUp(void)
|
||||
#endif // CONFIG_MBEDTLS_HARDWARE_MPI
|
||||
|
||||
// #if SOC_AES_SUPPORTED
|
||||
// // Execute mbedtls_aes_init operation to allocate AES interrupt
|
||||
// // allocation memory which is considered as leak otherwise
|
||||
// const uint8_t plaintext[16] = {0};
|
||||
// uint8_t ciphertext[16];
|
||||
// const uint8_t key[16] = { 0 };
|
||||
// mbedtls_aes_context ctx;
|
||||
// mbedtls_aes_init(&ctx);
|
||||
// mbedtls_aes_setkey_enc(&ctx, key, 128);
|
||||
// mbedtls_aes_crypt_ecb(&ctx, MBEDTLS_AES_ENCRYPT, plaintext, ciphertext);
|
||||
// mbedtls_aes_free(&ctx);
|
||||
// #endif // SOC_AES_SUPPORTED
|
||||
// Execute mbedtls_aes_init operation to allocate AES interrupt
|
||||
// allocation memory which is considered as leak otherwise
|
||||
const uint8_t plaintext[16] = {0};
|
||||
uint8_t ciphertext[32];
|
||||
const uint8_t key[16] = { 0 };
|
||||
psa_status_t status;
|
||||
psa_key_id_t key_id = 0;
|
||||
psa_key_attributes_t attributes = PSA_KEY_ATTRIBUTES_INIT;
|
||||
psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_ENCRYPT);
|
||||
psa_set_key_algorithm(&attributes, PSA_ALG_CBC_NO_PADDING);
|
||||
psa_set_key_type(&attributes, PSA_KEY_TYPE_AES);
|
||||
psa_set_key_bits(&attributes, 128);
|
||||
status = psa_import_key(&attributes, key, sizeof(key), &key_id);
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, status);
|
||||
size_t output_len = 0;
|
||||
status = psa_cipher_encrypt(key_id, PSA_ALG_CBC_NO_PADDING, plaintext, sizeof(plaintext), ciphertext, sizeof(ciphertext), &output_len);
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, status);
|
||||
|
||||
const uint8_t plaintext_long[256] = {0};
|
||||
uint8_t ciphertext_long[272];
|
||||
output_len = 0;
|
||||
status = psa_cipher_encrypt(key_id, PSA_ALG_CBC_NO_PADDING, plaintext_long, sizeof(plaintext_long), ciphertext_long, sizeof(ciphertext_long), &output_len);
|
||||
TEST_ASSERT_EQUAL(PSA_SUCCESS, status);
|
||||
psa_destroy_key(key_id);
|
||||
#endif // SOC_AES_SUPPORTED
|
||||
|
||||
test_utils_record_free_mem();
|
||||
TEST_ESP_OK(test_utils_set_leak_level(0, ESP_LEAK_TYPE_CRITICAL, ESP_COMP_LEAK_GENERAL));
|
||||
TEST_ESP_OK(test_utils_set_leak_level(0, ESP_LEAK_TYPE_WARNING, ESP_COMP_LEAK_GENERAL));
|
||||
TEST_ESP_OK(test_utils_set_leak_level(50, ESP_LEAK_TYPE_CRITICAL, ESP_COMP_LEAK_GENERAL));
|
||||
TEST_ESP_OK(test_utils_set_leak_level(50, ESP_LEAK_TYPE_WARNING, ESP_COMP_LEAK_GENERAL));
|
||||
}
|
||||
|
||||
/* tearDown runs after every test */
|
||||
@@ -66,7 +83,7 @@ void tearDown(void)
|
||||
/* clean up some of the newlib's lazy allocations */
|
||||
esp_reent_cleanup();
|
||||
|
||||
mbedtls_psa_crypto_free();
|
||||
// mbedtls_psa_crypto_free();
|
||||
|
||||
/* check if unit test has caused heap corruption in any heap */
|
||||
TEST_ASSERT_MESSAGE( heap_caps_check_integrity(MALLOC_CAP_INVALID, true), "The test has corrupted the heap");
|
||||
|
||||
@@ -31,11 +31,11 @@
|
||||
#endif
|
||||
|
||||
#define MBEDTLS_DECLARE_PRIVATE_IDENTIFIERS
|
||||
#include <mbedtls/aes.h>
|
||||
#include <mbedtls/sha256.h>
|
||||
#include <mbedtls/entropy.h>
|
||||
#include <mbedtls/ctr_drbg.h>
|
||||
#include <mbedtls/ecdh.h>
|
||||
// #include <mbedtls/aes.h>
|
||||
// #include <mbedtls/sha256.h>
|
||||
// #include <mbedtls/entropy.h>
|
||||
// #include <mbedtls/ctr_drbg.h>
|
||||
// #include <mbedtls/ecdh.h>
|
||||
#include <mbedtls/error.h>
|
||||
#include "psa/crypto.h"
|
||||
#include <protocomm.h>
|
||||
@@ -1142,7 +1142,6 @@ TEST_CASE("leak test", "[PROTOCOMM]")
|
||||
* time allocations to happen (not related to protocomm) */
|
||||
test_security0();
|
||||
test_security1();
|
||||
mbedtls_psa_crypto_free();
|
||||
usleep(1000);
|
||||
|
||||
#ifdef CONFIG_HEAP_TRACING
|
||||
@@ -1153,7 +1152,6 @@ TEST_CASE("leak test", "[PROTOCOMM]")
|
||||
/* Run all tests passively. Any leaks due
|
||||
* to protocomm should show up now */
|
||||
unsigned pre_start_mem = esp_get_free_heap_size();
|
||||
psa_crypto_init();
|
||||
test_security0();
|
||||
test_security1();
|
||||
test_security1_no_encryption();
|
||||
@@ -1161,7 +1159,6 @@ TEST_CASE("leak test", "[PROTOCOMM]")
|
||||
test_security1_wrong_pop();
|
||||
test_security1_insecure_client();
|
||||
test_security1_weak_session();
|
||||
mbedtls_psa_crypto_free();
|
||||
|
||||
usleep(1000);
|
||||
|
||||
@@ -1181,36 +1178,36 @@ TEST_CASE("security 0 basic test", "[PROTOCOMM]")
|
||||
|
||||
TEST_CASE("security 1 basic test", "[PROTOCOMM]")
|
||||
{
|
||||
psa_crypto_init();
|
||||
// psa_crypto_init();
|
||||
TEST_ASSERT(test_security1() == ESP_OK);
|
||||
}
|
||||
|
||||
TEST_CASE("security 1 no encryption test", "[PROTOCOMM]")
|
||||
{
|
||||
psa_crypto_init();
|
||||
// psa_crypto_init();
|
||||
TEST_ASSERT(test_security1_no_encryption() == ESP_OK);
|
||||
}
|
||||
|
||||
TEST_CASE("security 1 session overflow test", "[PROTOCOMM]")
|
||||
{
|
||||
psa_crypto_init();
|
||||
// psa_crypto_init();
|
||||
TEST_ASSERT(test_security1_session_overflow() == ESP_OK);
|
||||
}
|
||||
|
||||
TEST_CASE("security 1 wrong pop test", "[PROTOCOMM]")
|
||||
{
|
||||
psa_crypto_init();
|
||||
// psa_crypto_init();
|
||||
TEST_ASSERT(test_security1_wrong_pop() == ESP_OK);
|
||||
}
|
||||
|
||||
TEST_CASE("security 1 insecure client test", "[PROTOCOMM]")
|
||||
{
|
||||
psa_crypto_init();
|
||||
// psa_crypto_init();
|
||||
TEST_ASSERT(test_security1_insecure_client() == ESP_OK);
|
||||
}
|
||||
|
||||
TEST_CASE("security 1 weak session test", "[PROTOCOMM]")
|
||||
{
|
||||
psa_crypto_init();
|
||||
// psa_crypto_init();
|
||||
TEST_ASSERT(test_security1_weak_session() == ESP_OK);
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user