Commit Graph
997 Commits
Author SHA1 Message Date
Kapil Gupta c41dd724d4 fix(mbedtls): Fix cached Rinv size mismatch under private exponent blinding
Prevent signature verification failures on targets that do not round hardware words
to 16-word boundaries (e.g. ESP32-S3, ESP32-C6, and ESP32-P4), where exponent blinding
can cause `num_words` to vary between calls, leading to reuse of an incorrectly sized
cached `Rinv`.
2026-06-29 15:43:31 +08:00
Kapil Gupta 86f6192f10 fix(mbedtls): Enable hardware CRT for RSA-4096 via base reduction
Perform modulo reduction on the base before size checks to allow RSA-4096
CRT (2048-bit exponentiations) to use the hardware accelerator instead of
falling back to software. Fix input validation, negative zero sign issues,
and early memory cleanup paths in esp_mpi_exp_mod()
2026-06-29 15:43:31 +08:00
Mahavir Jain 96008173aa Merge branch 'fix/rsa_ds_driver_constant_time_v6.0' into 'release/v6.0'
Fix/rsa ds driver constant time (v6.0)

See merge request espressif/esp-idf!49699
2026-06-29 11:23:54 +05:30
Mahavir Jain 4163417ff1 Merge branch 'feat/support_rom_psa_mbedtls_v6.0' into 'release/v6.0'
feat(mbedtls): enable ESP32-C2(Rev2.0) ROM mbedTLS crypto for PSA (v6.0)

See merge request espressif/esp-idf!48843
2026-06-29 11:22:33 +05:30
Mahavir Jain 732111f75a Merge branch 'feat/esp_tee_backports_v6.0' into 'release/v6.0'
feat(esp_tee): Feature/fixes backports to `release/v6.0`

See merge request espressif/esp-idf!48486
2026-06-29 11:21:13 +05:30
Mahavir Jain e082ad95da Merge branch 'fix/memory_leak_cross_signed_cert_verify_v6.0' into 'release/v6.0'
fix(esp_crt_bundle): fixes verification failures with cross signed certificates (v6.0)

See merge request espressif/esp-idf!48624
2026-06-29 11:17:37 +05:30
Ashish Sharma f92ccb1348 fix(rsa_ds): make RSA-OAEP unpadding constant-time 2026-06-16 14:46:24 +08:00
Ashish Sharma c313d339ab fix(rsa_ds): make PKCS#1 v1.5 unpadding constant-time 2026-06-16 14:46:24 +08:00
Laukik Hase 39a4cf5e56 feat(esp_tee): Clear out all sensitive buffers explicitly after TEE crypto operations 2026-06-12 10:04:07 +05:30
Laukik Hase f37a2cd35b feat(esp_tee): Remove unused components from the PSA Crypto library 2026-06-12 10:03:03 +05:30
harshal.patil 3195c942da fix(mbedtls): validate ECDSA signature range and harden ECC memory power-down 2026-06-09 15:02:59 +05:30
Jiang Jiang Jian 948a5277ef Merge branch 'fix/fix_mbedtls_fs_io_psa_storage_v6.0' into 'release/v6.0'
fix(mbedtls): keep psa crypto storage enabled with ITS backend (v6.0)

See merge request espressif/esp-idf!48622
2026-06-03 16:44:19 +08:00
Ashish Sharma a1f1d90729 fix(esp_crt_bundle): fixes verification with cross signed cert 2026-06-03 11:35:24 +08:00
Ashish Sharma 0d8ff68f8a fix(esp_crt_bundle): fixes a potential memory leak with cross signed certificates
Closes https://github.com/espressif/esp-idf/issues/18512
Closes https://github.com/espressif/esp-idf/issues/18550
2026-06-03 11:31:27 +08:00
Jiang Jiang Jian 59032327db Merge branch 'fix/mbedtls-psa-constant-time-and-zeroization_v6.0' into 'release/v6.0'
fix(mbedtls): use constant-time compare for MAC verify and zeroize key material (v6.0)

See merge request espressif/esp-idf!48729
2026-06-02 20:12:59 +08:00
Aditya Patwardhan f77a7d16ec fix(mbedtls): use constant-time compare and zeroize key material
Replace memcmp with mbedtls_ct_memcmp in PSA MAC verify_finish entries
(CMAC, HMAC-transparent, HMAC-opaque) to prevent timing side-channel
MAC forgery, and unconditionally zeroize the locally-computed MAC on
the stack before return so a later stack-disclosure primitive cannot
recover the valid MAC.

Replace bzero with mbedtls_platform_zeroize in AES context free paths.
2026-05-30 23:15:44 +05:30
Aditya Patwardhan 4fb4dbda90 fix(mbedtls): correct inverted NULL check in esp_hmac_abort_opaque
esp_hmac_abort_opaque() had an inverted guard that called
mbedtls_platform_zeroize() on the context only when the context pointer
was NULL, dereferencing NULL and skipping cleanup of valid contexts.

Effect:
* Calling the abort path with a NULL pointer crashes (NULL write)
  instead of being a safe no-op.
* The valid (non-NULL) HMAC opaque operation context is never zeroized
  on abort, leaving sensitive intermediate HMAC state and key handle
  references in operation memory until the buffer is overwritten or
  freed.

Fix: invert the check so zeroization runs only when the context pointer
is non-NULL.
2026-05-30 23:15:42 +05:30
Jiang Jiang Jian 9d24b38a42 Merge branch 'fix/bring_back_ecjpake_config_v6.0' into 'release/v6.0'
fix(mbedtls): bring back deprecated config MBEDTLS_ECJPAKE_C (v6.0)

See merge request espressif/esp-idf!48623
2026-05-29 17:27:59 +08:00
Mahavir Jain b31c2753bc Merge branch 'fix/fix_psa_ecdsa_driver_missing_checks_v6.0' into 'release/v6.0'
fix(mbedtls): fixes missing check before ecdsa verify (v6.0)

See merge request espressif/esp-idf!48947
2026-05-28 21:05:31 +05:30
harshal.patil 40de3df854 test(mbedtls): Add out-of-bounds test for the ECDSA hardware driver 2026-05-27 11:38:14 +05:30
Ashish Sharma 9de91ed9e5 fix(mbedtls): fixes missing check before ecdsa verify 2026-05-27 11:38:13 +05:30
Jiang Guang Ming da5f99a518 fix(mbedtls): make threading implementation exclusive
Ensure the pthread and alternate threading implementations cannot be enabled at the same time.
2026-05-25 13:52:12 +08:00
Jiang Guang Ming 9320f709bd feat(mbedtls): enable PSA threading alt with ROM mbedTLS 2026-05-25 10:08:33 +08:00
Jiang Guang Ming dd28e303d5 fix(mbedtls): support ROM mbedTLS crypto in bootloader 2026-05-25 10:08:25 +08:00
Jiang Guang Ming 6eb7f181a2 feat(mbedtls): enable ROM mbedTLS pytest with esp32c2 rev2.0 2026-05-25 10:07:47 +08:00
Jiang Guang Ming 6ae3fa39f4 feat(mbedtls): enable ESP32-C2(Rev2.0) ROM crypto for PSA 2026-05-25 10:04:10 +08:00
Ashish Sharma 7f8dc336a6 fix(mbedtls): bring back deprecated config MBEDTLS_ECJPAKE_C 2026-05-18 14:56:18 +08:00
Ashish Sharma 94d456326c fix(mbedtls): keep psa crypto storage enabled with ITS backend
Closes https://github.com/espressif/esp-idf/issues/18555
2026-05-18 14:51:53 +08:00
harshal.patil d8808f90b9 test(mbedtls/persistent_storage_format): Add ESP ITS NVS format-stability test app 2026-05-15 09:28:47 +05:30
harshal.patil 513efdf89a refactor(mbedtls/test): Move the mbedtls test app to support multiple test apps 2026-05-15 09:28:42 +05:30
harshal.patil 1d6b5f219e feat(mbedtls/psa_esp_rsa_ds): Support persistent ESP-RSA DS driver 2026-05-15 09:17:09 +05:30
Jiang Jiang Jian 6d6aa6cccd Merge branch 'fix/fix_https_server_linux_build_v6.0' into 'release/v6.0'
fix(https_server): fixes failing example build for linux target (v6.0)

See merge request espressif/esp-idf!48205
2026-05-12 18:07:17 +08:00
Ashish Sharma 1d0cdd5602 fix(https_server): fixes failing example build for linux target 2026-05-10 19:29:25 +08:00
Ashish Sharma 04ec0ab538 feat(bootloader_support): remove P192 curve support 2026-05-10 19:16:12 +08:00
Ashish Sharma 5cc0eaaf9a fix(esp_tee): optimise build size by removing unused configs 2026-05-10 19:16:12 +08:00
Ashish Sharma eaac238545 fix(mbedtls): remove deprecated configs and migrate to PSA 2026-05-10 19:16:12 +08:00
Ashish Sharma b86a1231fb feat(mbedtls): update to version 4.1.1 2026-05-10 19:16:12 +08:00
Mahavir Jain 2eff46ca25 Merge branch 'fix/preserve_flash_layout_compatibiliy_of_hw_ecdsa_keys_psa_v6.0' into 'release/v6.0'
Persistent Storage Format for PSA Opaque ESP-Keys (v6.0)

See merge request espressif/esp-idf!47424
2026-05-07 10:17:43 +05:30
Mahavir Jain 954a2b3cbb Merge branch 'fix/supported_key_mgr_key_types_check_v6.0' into 'release/v6.0'
fix(esp_security): guard key manager APIs against unsupported chip revs (v6.0)

See merge request espressif/esp-idf!48008
2026-05-07 10:13:25 +05:30
harshal.patil 1141c48750 change(mbedtls): Add tee key id length validation in the ESP-ECDSA PSA driver 2026-05-04 18:21:01 +05:30
harshal.patil 4f0915d7f6 test(mbedtls): Add a test for opaque HMAC driver verification 2026-05-04 18:21:01 +05:30
harshal.patil c923685b0f fix(mbedtls): Flash compatibility across multiple key sources (ECDSA, HMAC) 2026-05-04 18:21:00 +05:30
nilesh.kale 1f506e7a54 test(esp_security): re-enable crypto drivers test app for ESP32P4
Also remove common_components dep for security-related tests
2026-05-04 18:18:20 +05:30
Guillaume Souchere ed9eefd94b fix(mbedtls): compile esp_mem.c in IDF component lib instead of builtin target
esp_mem.c in the builtin target via
target_sources(builtin PRIVATE ...) called from the parent CMakeLists.
This cross-directory source injection causes CMake's Ninja generator on
Windows to produce unstable TARGET_PDB/RSP_FILE paths across
reconfigures, changing the ninja command hash and forcing a re-archive
of libmbed-builtin.a on every cmake run — even when no source changed.
This broke test_rebuild_source_files.

Fix by adding esp_mem.c to the IDF mbedtls component library
(mbedtls_srcs) instead. The final ELF link uses --start-group, so
builtin's platform.o resolves esp_mbedtls_mem_calloc/free from the
component library regardless of archive order. esp_mem.c is IDF-specific
code (heap_caps_calloc, sdkconfig.h) and belongs in the port layer, not
in any submodule target.
2026-05-04 09:02:53 +02:00
Ashish Sharma 0eef7b4d4e fix(mbedtls): remove not required MBEDTLS_TLS_DISABLED config
Closes https://github.com/espressif/esp-idf/issues/18458
2026-04-27 14:54:19 +08:00
Mahavir Jain 7503c552f5 Merge branch 'fix/fix_protocomm_sec2_input_validations_v6.0' into 'release/v6.0'
fix(protocomm): fixes potential issues that can lead to crash during device provisioning (v6.0)

See merge request espressif/esp-idf!47305
2026-04-09 11:51:01 +05:30
Ashish Sharma bda099031e fix(mbedtls): reenable RSA 4096 bit key performance test 2026-04-09 10:26:10 +08:00
Ashish Sharma 9b4cacf9cb fix(protocomm): fixes potential issues that can lead to crash during device provisioning 2026-04-07 11:09:37 +08:00
harshal.patil ca3b9ca7d3 fix(mbedtls/rsa_ds): Preserve compatibility by reverting the modified esp_ds_data_ctx_t size 2026-03-26 14:06:07 +05:30
harshal.patil 2339834e4a fix(esp_security): Enable Key Manager clocks even for efuse key operations
The Key Manager holds a key usage register, thus, the Key Manager peripheral
clock must be enabled even for efuses-based key operations to route the
crypto operations to correctly to the efuses (default is Key Manager)
2026-03-24 16:23:16 +05:30