Commit Graph
80 Commits
Author SHA1 Message Date
Ashish Sharma 4692bfd275 docs(esp_tee): fix AEAD doxygen params after IV moved into the context 2026-09-03 12:15:32 +05:30
Ashish Sharma b23211a287 fix(esp_tee): ensure hal assert is enabled for tee builds 2026-09-03 12:15:30 +05:30
Ashish Sharma 5091e7c874 fix(esp_tee): enforce MMU-map vaddr validity at the REE->TEE boundary 2026-09-03 12:15:30 +05:30
Ashish Sharma 53d6c28d3f fix(esp_tee): fixes IV length check for TEE AEAD operations 2026-09-03 12:15:30 +05:30
Ashish Sharma 28268f348c fix(esp_security): don't reset DS peripheral in esp_hmac_calculate
esp_hmac_calculate() enabled and reset the Digital Signature (DS)
peripheral, but HMAC has no dependency on DS (the dependency runs the
other way: a DS operation uses HMAC/SHA).

The DS peripheral drives the RSA (MPI) accelerator internally, so pulsing
the DS reset also resets the RSA datapath. This coupling exists on every
target that has the DS peripheral: the MPI reset routine itself clears the
DS reset "otherwise RSA is held in reset".

esp_hmac_calculate() holds only the HMAC and SHA/AES locks, not the MPI
lock, so it can corrupt a concurrent RSA/MPI operation. On multi-core
targets (e.g. ESP32-P4, ESP32-S31, ESP32-S3) an HMAC on one core resets an
RSA op running on another core; on single-core targets (e.g. ESP32-C5) the
same corruption happens when an HMAC preempts an in-flight RSA op. The
result is a wrong RSA result or a crash in the computation.

Remove the DS peripheral enable/reset from the HMAC path. SHA, which HMAC
depends on, is enabled independently, so the HMAC output is unchanged.
This also drops a few redundant register writes.
2026-08-31 10:56:56 +08:00
Ashish Sharma 2312716f8c fix(esp_http_client): return an error when append_string realloc fails 2026-08-25 14:00:19 +08:00
Ashish Sharma 25f5e205cd fix(mbedtls): bound *iv_off in DMA esp_aes_crypt_ofb to prevent OOB read 2026-08-25 13:35:50 +08:00
Ashish Sharma 4751d66bd0 fix(esp_tee): guard calloc overflow and attestation leak 2026-08-25 13:35:50 +08:00
Ashish Sharma 7ca54ff43a fix(mbedtls): validate crypto input lengths (TEE OOB, auth-bypass, overflows) 2026-08-25 13:35:50 +08:00
Ashish Sharma cd516819ae fix(esp_http_client): fix digest-auth leaks and credential/handle use-after-free 2026-08-25 12:02:05 +08:00
Ashish Sharma 370cbcaff9 fix(esp_http_server): close UAF/double-free and query/cookie buffer underflows 2026-08-25 12:02:05 +08:00
Ashish Sharma 7c2e4b2a58 fix(app_update): close partition-table OOB read and rollback-guard gap 2026-08-25 12:02:05 +08:00
Ashish Sharma 7bf19e2f0e fix(esp-tls): reject NULL host/url in plain-TCP and async HTTP connect 2026-08-25 12:02:05 +08:00
Ashish Sharma ef8e915258 fix(esp_https_server): free TLS session on transport_ctx OOM in httpd_ssl_open 2026-08-25 12:02:05 +08:00
Ashish Sharma 1fc6094b14 fix(hal): clamp tag_len in aes_hal_gcm_read_tag to prevent OOB 2026-08-25 12:02:05 +08:00
Ashish Sharma 899aeadd7c fix(bootloader_support): guard NULL efuse digest slot in secure-boot verify 2026-08-25 12:02:05 +08:00
Ashish Sharma fb0c5c6a1c fix(esp-tls): correct return codes and harden TLS 1.3 ticket handling 2026-08-19 11:45:53 +08:00
Ashish Sharma 73fb4ce272 fix(mbedtls): revert to non constant time rsa key gen 2026-07-21 16:07:31 +08:00
Ashish Sharma 3732a3680d test(esp_wifi): adjust apsta bin size thresholds for mbedtls 3.6.7 2026-07-20 16:03:38 +08:00
Ashish Sharma 2064a698ea feat(mbedtls): add option to choose constant-time prime generation 2026-07-20 16:03:38 +08:00
Ashish Sharma 65f6668b84 feat(mbedtls): update to version 3.6.7 2026-07-20 16:03:38 +08:00
Ashish Sharma cecbc54c04 fix(esp_tee): fixes double panic when ESP-TEE panics 2026-07-09 11:59:23 +05:30
Ashish Sharma cdedde2fea fix(esp_tee): release SHA held by HMAC after crypto peripheral reset 2026-07-09 11:58:48 +05:30
Ashish Sharma 28f3d0be4a fix(mbedtls): fixes TLS1.3 server failing with dynamic buffer 2026-07-06 15:18:48 +08:00
Ashish Sharma ce7abcf087 fix(esp-tls): guard against NULL PSK hint to prevent crash 2026-07-03 11:36:33 +08:00
Ashish Sharma dedb02dd25 fix(esp_http_server): take ctrl_sock_semaphore on shutdown and async wake
httpd_stop() and httpd_req_async_handler_complete() both pushed
messages onto the control mbox via cs_send_to_ctrl_sock() without
reserving a slot in ctrl_sock_semaphore. Once the silent-drop fix
made the semaphore unconditional, the bypass became a real bug:
when the mbox is saturated by pending httpd_queue_work() items the
unguarded sendto() can return ENOBUFS, and even when it succeeds it
leaves the semaphore overstating free slots until the consumer
drains the message — a window during which a concurrent
httpd_queue_work() can take a slot but still find the mbox full.

Acquire the semaphore (portMAX_DELAY) before both sends and give it
back on send failure so the take/give invariant is preserved. The
httpd task is the consumer in both paths, so blocking is bounded
and deadlock-free. Reword the stale "no-op give on full" comment in
httpd_process_ctrl_msg() to reflect that only the recv-error path
relies on the cap behavior now.
2026-06-05 17:37:55 +08:00
Ashish Sharma fcc140c11c fix(esp_http_server): prevent silent message drop in httpd_queue_work
Closes https://github.com/espressif/esp-idf/issues/18563
2026-06-05 17:37:55 +08:00
Ashish Sharma 99fc683322 fix(mbedtls): fixes build failure with clang21
Closes https://github.com/espressif/esp-idf/issues/18456
2026-06-05 16:49:29 +08:00
Ashish Sharma 26de0e2137 fix(esp_prov): fixes sec2 client possible public length truncation 2026-05-20 11:54:44 +08:00
Ashish Sharma d0903c1cb4 fix(http_request): fixes failing pytest 2026-05-11 18:08:54 +08:00
Ashish Sharma f8dec92a06 fix(esp_http_server): fixes websocket recv error handling
Closes https://github.com/espressif/esp-idf/issues/18483
2026-05-10 19:26:08 +08:00
Ashish Sharma 71eb2dbe6a fix(protocomm): fixes potential issues that can lead to crash during device provisioning 2026-04-29 16:22:14 +08:00
Ashish Sharma c2cccd0b56 fix(esp_hal_security): fixes failing hmac_hal_configure with efuse_key for p4 rev < 3
Closes https://github.com/espressif/esp-idf/issues/18370
2026-04-28 14:51:39 +05:30
Ashish Sharma c7c41c91ea fix(mbedtls): relaxes performance numbers for RSA operations 2026-04-27 11:42:56 +08:00
Ashish Sharma d4b067dc25 change(mbedtls): adds CVE-2025-66442 to exclude list.
The CVE is applicable with Clang using LLVM's select-optimize feature. ESP-IDF uses GCC as default compiler and sets -Os as the default optimisation flag
2026-04-22 15:42:51 +08:00
Ashish Sharma 05921ab663 fix(esp_srp): reject SRP client public key when A mod N is zero 2026-04-20 11:23:32 +08:00
Ashish Sharma 8ddb998a8f feat(esp_tls): extends esp-tls test apps 2026-04-17 14:41:45 +08:00
Ashish Sharma 2f560ce2cd fix(esp_tls): check tls connection finished before read/write operation 2026-04-17 14:41:45 +08:00
Ashish Sharma dba7694724 feat(esp_http_server): adds check for crlf in response creation 2026-04-13 10:32:41 +08:00
Ashish Sharma 6aeb829555 feat(esp_local_ctrl): adds basic test app 2026-04-12 18:19:11 +08:00
Ashish Sharma 1ede92febf fix(esp_local_ctrl): fixes a potential double free 2026-04-12 18:19:11 +08:00
Ashish Sharma 08c4b0eb68 feat(cjson): update to latest master 2026-04-02 13:33:49 +08:00
Ashish Sharma 6293b28504 feat(mbedtls): update to version 3.6.6 2026-04-02 11:34:22 +08:00
Ashish Sharma cca227e022 feat(esp-tls): adds per ssl context state management 2026-03-30 13:45:28 +08:00
Ashish Sharma a4c40112c3 fix: removes deprecated http_crypto sources 2026-03-30 13:45:28 +08:00
Ashish Sharma 9681ec0f9c fix: fixes failing dynamic buffer tests 2026-03-30 13:45:28 +08:00
Ashish Sharma c692c1ec8b fix(wifi_provisioning): fixes memory leak on OOM 2026-03-27 10:15:49 +08:00
Ashish Sharma 0f294a2d96 fix(wifi_provisioning): fixes potential null dereference on malformed packet 2026-03-26 11:45:06 +08:00
Ashish Sharma 08c8c17436 fix: fixes memory leak with subprotocols 2026-03-23 18:42:48 +08:00
Ashish Sharma 00a2f7fbbb fix: fixes websocket server possible null dereference 2026-03-23 18:42:45 +08:00
Ashish Sharma da9b3ce548 fix(esp_http_client): delete Content-Length header when using Transfer-Encoding
Closes https://github.com/espressif/esp-idf/issues/18242
2026-03-17 12:21:09 +08:00
Ashish Sharma 4425dbf4af feat(http_server): adds example to test server pong response 2026-03-16 16:55:54 +08:00
Ashish Sharma 6f392e6fd6 feat(http_server): improve websocket server handling
1. Adds post handshake callback
2. Removes requirement to handle HTTP_GET message in websocket handler

Closes https://github.com/espressif/esp-idf/issues/18215
2026-03-16 13:57:59 +08:00
Ashish Sharma 1e27eb204b feat(esp_http_client): adds API to get transport socket 2026-01-22 18:24:45 +08:00
Ashish Sharma 7ef71e9770 fix: stop reading ws data when peer closes the connection
Closes https://github.com/espressif/esp-idf/issues/17822
2026-01-22 18:16:37 +08:00
Ashish Sharma 4c0c9d2d6a fix: fixes potential ws server deadlock with blocking work queue
Closes https://github.com/espressif/esp-idf/issues/17591
2026-01-22 18:12:03 +08:00
Ashish Sharma 613b878df3 fix(esp_http_client): fix incorrect digest calculation for SHA256 auth digest
According to RFC 7616, nonce-prime and cnonce-prime is used for SHA-256-sess only and not for SHA-256.
This commit updates the check and uses nonce only for "-sess" algorithms.

Regression from 66995965e7
2026-01-07 10:19:04 +08:00
Ashish Sharma 30f93c0516 feat(mbedtls): update to version 3.6.5 2025-11-11 16:47:45 +08:00
Ashish Sharma 6b0796b2a4 fix(esp_tls): limit ret code from esp_mbedtls_handshake 2025-09-24 15:48:30 +08:00
Ashish Sharma 5e7c32897f change(cjson): update cjson version to 1.7.19 2025-09-11 15:35:55 +08:00
Ashish Sharma 8a8d01565e fix(esp_http_client): fix possible double memory free 2025-08-01 14:22:10 +08:00
Ashish Sharma 163db6a8a5 feat(mbedtls): adds support for RSA decryption with DS peripheral 2025-07-21 09:27:06 +08:00
Ashish Sharma ab8770fe5a fix(esp_http_client): fix memory leak in current_header_value buffer
Fixed memory leak in esp_http_client_cleanup() where current_header_value
buffer was not being freed when ESP_ERR_HTTP_FETCH_HEADER is returned
during header parsing failures.
2025-07-18 12:01:39 +08:00
Ashish Sharma a3af8972ae feat(mbedtls): update to version 3.6.4 2025-07-04 17:34:00 +08:00
Ashish Sharma 3a9cce2a92 docs(system/esp_https_ota): adds ECIES-256 to pre-enc ota design doc 2025-07-04 17:29:24 +08:00
Ashish Sharma 156ead0cd5 fix(mbedtls): Fixes failing TLS 1.3 server handshake
Closes https://github.com/espressif/esp-idf/issues/15984
2025-06-16 11:27:48 +05:30
Ashish Sharma 08d78dcd7e fix(esp_tls): fix failing build with TLS1.3 only and dynamic buffer 2025-06-16 09:22:57 +08:00
Ashish Sharma b3843ea09a change: adds CVE-2023-53154 to cJSON sbom exclude list 2025-05-26 17:29:14 +08:00
Ashish Sharma c18e53b672 feat(cjson): update to latest upstream 2025-05-19 09:50:59 +08:00
Ashish Sharma 415e0f3c86 feat(mbedtls): add support for dynamic buffer for TLS1.3
Closes https://github.com/espressif/esp-idf/issues/15448
2025-04-24 12:05:36 +08:00
Ashish Sharma 0bad622a7a fix(esp_tls): use correct sockaddr struct size when calling connect()
Closes https://github.com/espressif/esp-idf/issues/15812
2025-04-23 13:23:44 +08:00
Ashish Sharma 0de1429834 fix(mbedtls): remove logical dead code from mbedtls 2025-04-17 13:43:48 +08:00
Ashish Sharma 11890df95a Merge branch 'bugfix/fix_cert_verification_ds_tls1.3' into 'master'
fix(component/mbedtls): Fix failing cert verification with TLS1.3 and DS peripheral

Closes IDFGH-14097

See merge request espressif/esp-idf!37634
2025-04-14 12:31:50 +08:00
Ashish Sharma b62e486247 fix(component/mbedtls): Fix failing cert verification with TLS1.3 and DS peripheral 2025-04-11 18:34:16 +08:00
Ashish Sharma b126ebb596 feat(mbedtls): new config to allow weak cert verification 2025-03-28 15:46:48 +08:00
Ashish Sharma 0291bee0ff feat(mbedtls): update to version 3.6.3 2025-03-28 13:03:12 +08:00
Ashish Sharma 88fa3e2c9e feat(security): fixes review comments 2025-03-17 18:23:14 +08:00
Ashish Sharma 4c23ba3c1f feat(security): update idf.py extensions to support security feature application 2025-03-17 18:23:14 +08:00
Ashish Sharma fbecd65e2a feat(security): update README.md to include support for esp32s3 2025-03-17 18:23:14 +08:00
Ashish Sharma 2fc151d2a9 fix(component/mbedtls): Adds github root cert to cmn_crt_authorities.csv 2025-03-17 14:32:06 +08:00