Ashish Sharma
2552d48f27
fix(mbedtls): revert to non constant time rsa key gen
2026-07-23 13:38:24 +08:00
Ashish Sharma
57ff98ca13
test(mbedtls): add PSA RSA key generation test
...
The test only runs with MBEDTLS_CONSTANT_TIME_PRIME_GEN disabled:
with the constant-time prime generation that is now the default,
RSA-2048 key generation takes over a minute on most targets (~86 s on
ESP32-S3), exceeding the test timeout and starving the task watchdog.
2026-07-23 13:38:24 +08:00
Ashish Sharma
73712ff5fd
feat(mbedtls): add option to choose constant-time prime generation
...
mbedtls 4.1.1 made the small-factor test in prime generation
constant-time (a CT GCD against the product of primes up to 997, run
for every prime candidate). This makes RSA key generation roughly ten
times slower on ESP chips and starves the idle task since the software
GCD never yields, tripping the task watchdog.
Add MBEDTLS_CONSTANT_TIME_PRIME_GEN under the new "Security hardening"
menu, default y so the upstream constant-time behavior ships as the
secure default. When disabled, esp_config.h defines
MBEDTLS_MPI_PRIME_SIEVE_VARIABLE_TIME and mbedtls uses the pre-3.6.7
variable-time trial division, restoring key generation performance on
devices where no untrusted co-resident code could time key generation.
2026-07-23 13:38:24 +08:00
Ashish Sharma
8ad5504eb1
feat(mbedtls): update to version 4.1.1
2026-07-23 13:38:24 +08:00
Ashish Sharma
7e36bb2db3
fix(esp_security): harden crypto peripheral error handling
2026-07-20 10:25:33 +08:00
Ashish Sharma
8dc04e5fda
fix(esp_tee): ensure hal assert is enabled for tee builds
2026-07-17 18:15:37 +05:30
Ashish Sharma
dc44ca9a86
fix(esp_tee): enforce MMU-map vaddr validity at the REE->TEE boundary
2026-07-17 18:15:36 +05:30
Ashish Sharma
89ba3db529
fix(esp_tee): fixes IV length check for TEE AEAD operations
2026-07-17 18:15:36 +05:30
Ashish Sharma
2c4bcab8d2
feat(mbedtls): enable cross signed certificate verification support by default
2026-07-17 18:12:56 +08:00
Ashish Sharma
d85cb8d7cc
fix(esp_tee): fix DS-lock leak, intr-matrix OOB, calloc overflow, attestation leak
2026-07-16 18:24:47 +08:00
Ashish Sharma
d710be28f3
fix(esp-tls): reject NULL host/url in plain-TCP and async HTTP connect
2026-07-16 18:24:47 +08:00
Ashish Sharma
2e6f9b8b42
fix(mbedtls): validate crypto input lengths (TEE OOB, auth-bypass, overflows)
2026-07-16 18:24:47 +08:00
Ashish Sharma
47e0435f99
fix(esp_https_server): free TLS session on transport_ctx OOM in httpd_ssl_open
2026-07-16 18:24:47 +08:00
Ashish Sharma
7bcafe2171
fix(esp_hal_security): clamp tag_len in aes_hal_gcm_read_tag to prevent OOB
2026-07-16 18:24:47 +08:00
Ashish Sharma
e2537bb5e4
fix(bootloader_support): guard NULL efuse digest slot in secure-boot verify
2026-07-16 18:24:47 +08:00
Ashish Sharma
89f40a3b93
fix(esp_http_client): fix digest-auth leaks and credential/handle use-after-free
2026-07-16 18:24:47 +08:00
Ashish Sharma
ea005e8316
fix(esp_http_server): close UAF/double-free, buffer underflows, and OOB read
2026-07-16 18:24:47 +08:00
Ashish Sharma
2742100127
fix(app_update): close OOB read, rollback-guard gap, and length underflow
2026-07-16 18:24:47 +08:00
Ashish Sharma
2c26dfc51b
fix(esp_tee): fixes double panic when ESP-TEE panics
2026-07-10 10:32:32 +05:30
Ashish Sharma
dc48cc5059
fix(esp_tee): release SHA held by HMAC after crypto peripheral reset
2026-07-10 10:32:32 +05:30
Ashish Sharma
9e8dc6cc7b
test(httpd): cover URL query and header pointer accessors
2026-07-09 11:20:33 +08:00
Ashish Sharma
4341446b17
feat(httpd): add httpd_req_get_hdr_value_str_ptr() to avoid value copy
2026-07-09 11:20:33 +08:00
Ashish Sharma
1208d1c3b8
refactor(httpd): extract shared header field-value lookup helper
2026-07-09 11:20:33 +08:00
Ashish Sharma
60ce04db6d
fix(httpd): validate buf_len in httpd_req_get_url_query_str_ptr()
2026-07-09 11:20:33 +08:00
Ashish Sharma
92cefa205a
feat(esp_http_client): detect oversized headers in tx buffer while sending request
2026-07-07 18:18:26 +08:00
Ashish Sharma
9ad041cc8c
fix(mbedtls): fixes TLS1.3 server failing with dynamic buffer
2026-07-06 15:18:38 +08:00
Ashish Sharma
0f03194e62
fix(mbedtls): harden port layer to zeroize sensitive material
2026-07-03 11:39:03 +08:00
Ashish Sharma
e268dbef61
fix(esp-tls): guard against NULL PSK hint to prevent crash
2026-07-03 11:36:22 +08:00
Ashish Sharma
72041a1e79
Merge branch 'fix/sb_digest_revocation_workflow_v6.0' into 'release/v6.0'
...
change(bootloader): honor SECURE_BOOT_ALLOW_UNUSED_DIGEST_SLOTS during first boot (v6.0)
See merge request espressif/esp-idf!49713
2026-06-29 17:46:30 +08:00
Ashish Sharma
d934586510
fix(mbedtls/port): add additional hardening for PSA drivers
2026-06-29 14:23:05 +08:00
Ashish Sharma
64b488ebb3
fix(esp_http_server): take ctrl_sock_semaphore on shutdown and async wake
...
httpd_stop() and httpd_req_async_handler_complete() both pushed
messages onto the control mbox via cs_send_to_ctrl_sock() without
reserving a slot in ctrl_sock_semaphore. Once the silent-drop fix
made the semaphore unconditional, the bypass became a real bug:
when the mbox is saturated by pending httpd_queue_work() items the
unguarded sendto() can return ENOBUFS, and even when it succeeds it
leaves the semaphore overstating free slots until the consumer
drains the message — a window during which a concurrent
httpd_queue_work() can take a slot but still find the mbox full.
Acquire the semaphore (portMAX_DELAY) before both sends and give it
back on send failure so the take/give invariant is preserved. The
httpd task is the consumer in both paths, so blocking is bounded
and deadlock-free. Reword the stale "no-op give on full" comment in
httpd_process_ctrl_msg() to reflect that only the recv-error path
relies on the cap behavior now.
2026-06-25 10:41:17 +08:00
Ashish Sharma
8939340af8
fix(esp_http_server): prevent silent message drop in httpd_queue_work
...
Closes https://github.com/espressif/esp-idf/issues/18563
2026-06-25 10:41:17 +08:00
Ashish Sharma
006922e6c7
fix(esp-tls): fixes DS peripheral use case with tf-psa-crypto 1.1
2026-06-25 10:41:00 +08:00
Ashish Sharma
0f11ac0623
feat(esp_http_client_mutual_auth): add mutual TLS example
...
Closes https://github.com/espressif/esp-idf/issues/18393
2026-06-25 10:41:00 +08:00
Ashish Sharma
beed5fe81f
fix(protocomm): null output buffer pointer on crypto failure
2026-06-16 14:47:17 +08:00
Ashish Sharma
f92ccb1348
fix(rsa_ds): make RSA-OAEP unpadding constant-time
2026-06-16 14:46:24 +08:00
Ashish Sharma
c313d339ab
fix(rsa_ds): make PKCS#1 v1.5 unpadding constant-time
2026-06-16 14:46:24 +08:00
Ashish Sharma
4852f54610
docs(esp_http_server): adds doc and migration entry for ws server post handshake cb
...
Closes https://github.com/espressif/esp-idf/issues/18539
2026-06-05 17:31:43 +08:00
Ashish Sharma
a1f1d90729
fix(esp_crt_bundle): fixes verification with cross signed cert
2026-06-03 11:35:24 +08:00
Ashish Sharma
8554f060cc
fix(http_request): shifts to HTTP/1.1 in example pytest
2026-06-03 11:31:27 +08:00
Ashish Sharma
0d8ff68f8a
fix(esp_crt_bundle): fixes a potential memory leak with cross signed certificates
...
Closes https://github.com/espressif/esp-idf/issues/18512
Closes https://github.com/espressif/esp-idf/issues/18550
2026-06-03 11:31:27 +08:00
Ashish Sharma
9de91ed9e5
fix(mbedtls): fixes missing check before ecdsa verify
2026-05-27 11:38:13 +05:30
Ashish Sharma
7f8dc336a6
fix(mbedtls): bring back deprecated config MBEDTLS_ECJPAKE_C
2026-05-18 14:56:18 +08:00
Ashish Sharma
94d456326c
fix(mbedtls): keep psa crypto storage enabled with ITS backend
...
Closes https://github.com/espressif/esp-idf/issues/18555
2026-05-18 14:51:53 +08:00
Ashish Sharma
1d0cdd5602
fix(https_server): fixes failing example build for linux target
2026-05-10 19:29:25 +08:00
Ashish Sharma
a493b3f890
fix(esp_http_server): fixes websocket recv error handling
...
Closes https://github.com/espressif/esp-idf/issues/18483
2026-05-10 19:25:59 +08:00
Ashish Sharma
04ec0ab538
feat(bootloader_support): remove P192 curve support
2026-05-10 19:16:12 +08:00
Ashish Sharma
5cc0eaaf9a
fix(esp_tee): optimise build size by removing unused configs
2026-05-10 19:16:12 +08:00
Ashish Sharma
38c36dd9a0
fix(wpa_supplicant): replace deprecated APIs and relax dpp test
2026-05-10 19:16:12 +08:00
Ashish Sharma
d50798c185
fix(esp-tls): replace deprecated pk_ctx with PSA equivalent
2026-05-10 19:16:12 +08:00
Ashish Sharma
eaac238545
fix(mbedtls): remove deprecated configs and migrate to PSA
2026-05-10 19:16:12 +08:00
Ashish Sharma
b86a1231fb
feat(mbedtls): update to version 4.1.1
2026-05-10 19:16:12 +08:00
Ashish Sharma
9798c62856
fix(https_request): enforce tls version for supported ciphersuite example
2026-04-28 14:28:37 +08:00
Ashish Sharma
0eef7b4d4e
fix(mbedtls): remove not required MBEDTLS_TLS_DISABLED config
...
Closes https://github.com/espressif/esp-idf/issues/18458
2026-04-27 14:54:19 +08:00
Ashish Sharma
44987dfd14
fix(esp_http_client): fix broken connection reuse
...
Closes https://github.com/espressif/esp-idf/issues/18430
2026-04-21 20:07:27 +08:00
Ashish Sharma
cde2fd4718
fix(esp_srp): reject SRP client public key when A mod N is zero
2026-04-17 15:21:21 +08:00
Ashish Sharma
289c78f273
feat(esp_tls): extends esp-tls test apps
2026-04-13 16:41:43 +08:00
Ashish Sharma
35624d3eaf
fix(esp_tls): check tls connection finished before read/write operation
2026-04-13 16:40:01 +08:00
Ashish Sharma
6a36ec6d07
feat(esp_http_server): adds check for crlf in response creation
2026-04-13 10:32:24 +08:00
Ashish Sharma
ec72b956d2
feat(esp_https_server): adds support for user callback on handshake failure
...
Closes https://github.com/espressif/esp-idf/issues/18053
2026-04-12 18:37:23 +08:00
Ashish Sharma
90fe61fd0c
feat(esp_local_ctrl): adds basic test app
2026-04-12 18:18:25 +08:00
Ashish Sharma
28775ac4f6
fix(esp_local_ctrl): fixes a potential double free
2026-04-12 18:18:22 +08:00
Ashish Sharma
bda099031e
fix(mbedtls): reenable RSA 4096 bit key performance test
2026-04-09 10:26:10 +08:00
Ashish Sharma
9b4cacf9cb
fix(protocomm): fixes potential issues that can lead to crash during device provisioning
2026-04-07 11:09:37 +08:00
Ashish Sharma
6e08270b4a
Merge branch 'fix/fix_esp32p4_key_mgr_efuse_key_rev_le_3_v6.0' into 'release/v6.0'
...
fix(esp_hal_security): fixes failing hmac_hal_configure with efuse_key for p4 rev < 3 (v6.0)
See merge request espressif/esp-idf!46892
2026-03-25 10:38:30 +08:00
Ashish Sharma
0cac091538
fix(esp_hal_security): fixes failing hmac_hal_configure with efuse_key for p4 rev < 3
...
Closes https://github.com/espressif/esp-idf/issues/18370
2026-03-24 16:33:25 +05:30
Ashish Sharma
a519271c3e
fix: fixes memory leak with subprotocols
2026-03-23 18:41:42 +08:00
Ashish Sharma
0dc4ee7537
fix: fixes websocket server possible null dereference
2026-03-23 18:41:42 +08:00
Ashish Sharma
f40f9ac497
fix(secure_boot): marks 192 bit support curve legacy
2026-03-20 19:07:55 +05:30
Ashish Sharma
2eb3c1375f
feat(http_server): adds example to test server pong response
2026-03-20 15:10:52 +08:00
Ashish Sharma
a5f46aa6ee
docs(security): adds data partition verification docs
2026-03-20 15:08:54 +08:00
Ashish Sharma
8c6845bb96
feat(secure_boot): adds api to verify data partition integrity
...
Closes https://github.com/espressif/esp-idf/issues/17482
2026-03-20 15:08:54 +08:00
Ashish Sharma
532a8f4ee5
fix(mbedtls): fixes incorrect macro checks in PSA SHA driver
...
Closes https://github.com/espressif/esp-idf/issues/18354
2026-03-18 18:51:10 +08:00
Ashish Sharma
8a990805f6
fix(esp_http_client): delete Content-Length header when using Transfer-Encoding
...
Closes https://github.com/espressif/esp-idf/issues/18242
2026-03-17 12:20:58 +08:00
Ashish Sharma
6131f55136
feat(esp-tls): adds per ssl context state management
2026-03-17 10:45:32 +08:00
Ashish Sharma
d96e33375c
fix: removes deprecated http_crypto sources
2026-03-17 10:45:32 +08:00
Ashish Sharma
79fe9ff741
fix: fixes failing dynamic buffer tests
2026-03-17 10:45:32 +08:00
Ashish Sharma
9618e5cd77
docs: adds RSA DS docs for PSA Migration
2026-03-17 10:28:39 +08:00
Ashish Sharma
4e9367bc41
fix(esp_http_server): fix ws server subprotocol match
2026-03-12 17:03:21 +08:00
Ashish Sharma
222d470312
feat(http_server): improve websocket server handling
...
1. Adds post handshake callback
2. Removes requirement to handle HTTP_GET message in websocket handler
Closes https://github.com/espressif/esp-idf/issues/18215
2026-03-04 14:00:12 +08:00
Ashish Sharma
de9962fe33
feat(blufi): update to AES-CTR
2026-03-02 14:35:46 +08:00
Ashish Sharma
bd39f141ff
fix: enable HARDWARE_MPI by default
2026-03-02 14:33:21 +08:00
Ashish Sharma
cb91021678
fix(mbedtls): updates crypto performance numbers
2026-02-12 20:37:54 +08:00
Ashish Sharma
939be5c62f
fix(mbedtls): enable pthread threading by default
2026-02-12 20:37:54 +08:00
Ashish Sharma
397c689548
fix: make the PSA compile definitions public
2026-02-11 18:04:56 +08:00
Ashish Sharma
0aef47a07e
change(mbedtls): rename builtin to mbed-builtin
2026-02-11 18:04:56 +08:00
Ashish Sharma
4abcb123be
change(mbedtls): update mbedTLS default configs
...
1. Disables MBEDTLS_ARIA_C by default
2. SECP192R1 support is disabled by default
2026-02-11 18:04:56 +08:00
Ashish Sharma
762c4e9e65
fix(mbedtls): revert struct member name change esp_rsa_ds_data to esp_ds_data
2026-02-06 17:37:42 +08:00
Ashish Sharma
7418a91d3e
feat: adds DS Sign capabilities for ESP32S2
2026-02-06 16:09:41 +08:00
Ashish Sharma
b1f14d19d0
feat: adds new Kconfig variable for DS peripheral
2026-02-06 16:09:41 +08:00
Ashish Sharma
93349d05b2
feat: adds PSA DS driver support
2026-02-06 16:09:41 +08:00
Ashish Sharma
c8f1fa86a2
feat(esp_http_client): adds support to save response headers
...
Closes https://github.com/espressif/esp-idf/issues/17695
2026-02-03 14:40:08 +08:00
Ashish Sharma
539d62b8ba
fix: Skip writing to esp-idf directory when tfpsacrypto is built
...
Closes https://github.com/espressif/esp-idf/issues/18163
2026-01-29 13:46:44 +08:00
Ashish Sharma
1591d529fd
feat(esp_http_client): adds API to get transport socket
2026-01-22 18:24:31 +08:00
Ashish Sharma
0559222711
fix: stop reading ws data when peer closes the connection
...
Closes https://github.com/espressif/esp-idf/issues/17822
2026-01-22 18:16:26 +08:00
Ashish Sharma
63f3072c9c
fix: fixes potential ws server deadlock with blocking work queue
...
Closes https://github.com/espressif/esp-idf/issues/17591
2026-01-22 18:10:24 +08:00
Ashish Sharma
933dd7e02f
feat: adds PSA MD5 driver support
2026-01-09 13:56:03 +05:30
Ashish Sharma
54a72063ef
fix: fixes failing tee_basic example build
2026-01-09 13:55:59 +05:30
Ashish Sharma
1c74bf57dd
fix(esp_http_client): fix incorrect digest calculation for SHA256 auth digest
...
According to RFC 7616, nonce-prime and cnonce-prime is used for SHA-256-sess only and not for SHA-256.
This commit updates the check and uses nonce only for "-sess" algorithms.
Regression from 66995965e7
2026-01-07 10:17:51 +08:00
Ashish Sharma
4073c89471
fix: fixes failing pipeline with internal wifi mbedtls client
2026-01-06 17:11:34 +08:00