Commit Graph
1035 Commits
Author SHA1 Message Date
Ashish Sharma ad19b932da feat(mbedtls): update to version 4.1.1 2026-07-20 17:17:04 +08:00
Jiang Jiang Jian a43c51681a Merge branch 'task/buildv2_full_pipeline_v6.1' into 'release/v6.1'
Enable full buildv2 pipeline (v6.1)

See merge request espressif/esp-idf!50351
2026-07-17 18:20:09 +08:00
Jiang Jiang Jian 947e534927 Merge branch 'fix/mmap_cache_flash_wr_v6.1' into 'release/v6.1'
fix(mmap): fixed mmap read data wrong when flash being erased/written and cache not disabled (v6.1)

See merge request espressif/esp-idf!50117
2026-07-17 10:30:14 +08:00
Aditya Patwardhan 9dc17f98b0 Merge branch 'backport/44987_v6.1' into 'release/v6.1'
feat(esp-tls): Added a PSA driver for Secure Element (backport v6.1)

See merge request espressif/esp-idf!50334
2026-07-16 15:37:49 +05:30
Xiao Xufeng 3e8389cc31 fix(mmap): fixed some API read wrong data via mmap when flash being erased/written while XIP on PSRAM
Before:

The cache won't be disabled when XIP on psram. But during flash
erasing/programming, read data will be courrupt.

When XIP in psram is enabled, the image is not mapped to the cache so
usually there will be no flash access. The only way to read from flash
is via the driver or use mmap. The driver has protection during erasing,
while th mmap region not.

Now:

Mmap APIs provide a flag to make mmap->unmap region mutually exclusive
to flash erase/programming when XIP from psram. SPI Flash write APIs
will benefit from this. When the flag is used, no concurrent access to
mapped region will happen while writing; otherwise the cache will be
disable to avoid data corruption.

Most ESP-IDF APIs calls mmap with this flag. As for users calling
mmap-like APIs directly, they can choose whether to enable this by a
flag.

Closes https://github.com/espressif/esp-idf/issues/14897
2026-07-15 18:57:08 +08:00
Ashish Sharma 8d8068aee3 fix(esp_tee): fix DS-lock leak, intr-matrix OOB, calloc overflow, attestation leak 2026-07-13 14:40:44 +08:00
Ashish Sharma e4304fab76 fix(mbedtls): validate crypto input lengths (TEE OOB, auth-bypass, overflows) 2026-07-13 14:40:44 +08:00
Laukik Hase 87a5664883 ci(esp_tee): Fix tee_cli_app build failure due to heap size overflow
- Also fix the `unused variable` warning while builing the PSA
  AES tests with `tee_test_fw` app
2026-07-10 10:30:02 +05:30
Mahavir Jain f0fbd9d9fa Merge branch 'fix/tls1_3_dynamic_buffer_server_crash_v6.1' into 'release/v6.1'
fix(mbedtls): fixes TLS1.3 server failing with dynamic buffer (v6.1)

See merge request espressif/esp-idf!50386
2026-07-10 09:38:26 +05:30
nilesh.kale c9e90831b8 feat: enable AES GCM support for ESP32-S31 2026-07-06 15:08:38 +05:30
Ashish Sharma 8ca83a0fa9 fix(mbedtls): fixes TLS1.3 server failing with dynamic buffer 2026-07-06 15:18:23 +08:00
Sudeep Mohanty 0a89c2e432 fix(test_apps): override config defaults unused by these tests
These tests enable features they do not use -- the VFS console, Wi-Fi task core pinning, and
the DS peripheral -- which shift memory layout, interrupt allocation, and peripheral access
enough to fail them. Override the unused options in each test's sdkconfig and ignore the
resulting unknown-symbol build warnings.
2026-07-03 19:18:42 +02:00
Jiang Jiang Jian a6f24da33e Merge branch 'bugfix/mbedtls_rsa_base_reduction_hw_crt_v6.1' into 'release/v6.1'
fix(mbedlts): Enable hardware CRT for RSA-4096 via base reduction (v6.1)

See merge request espressif/esp-idf!49849
2026-07-03 21:42:10 +08:00
Mahavir Jain 0362f806e1 Merge branch 'feat/psa_its_custom_backend_v6.1' into 'release/v6.1'
Support custom storage backend for persistent PSA keys (v6.1)

See merge request espressif/esp-idf!49151
2026-07-03 11:34:23 +05:30
Mahavir Jain 40974f42a3 Merge branch 'fix/aes_dma_psram_encrypted_mem_s31_v6.1' into 'release/v6.1'
fix(mbedtls/aes): Fix AES-DMA over encrypted PSRAM on ESP32-S31 (v6.1)

See merge request espressif/esp-idf!50252
2026-07-03 08:45:02 +05:30
harshal.patil b5d53b87ef feat(mbedtls/psa_esp_rsa_ds): Expose persistent key buffer format/parse helpers 2026-07-02 16:00:23 +05:30
harshal.patil 6634a0b620 feat(mbedtls): Support custom storage backend for persistent PSA keys 2026-07-02 16:00:23 +05:30
Aditya Patwardhan 49d1a84c0b docs(esp-tls): clarify caller owns the PSA key in esp_key_config_t
(cherry picked from commit ed6f697ea8)
2026-07-02 11:41:49 +05:30
Aditya Patwardhan 72b2e4f4fd fix(esp-tls): address MR review comments for SE PSA driver
- esp_tls_mbedtls: require cert when PSA-backed server/client key is set
- esp_tls_mbedtls: drop redundant pk_init/x509_crt_init (calloc handles it)
- psa SE driver: copy callbacks/opaque_key by value (no lifetime coupling)
- psa SE driver: replace atomic CAS with simple null check on register
- psa SE driver: use sig_len from sign callback with bounds validation
- psa SE driver: validate pubkey_len returned by export_pubkey callback
- psa SE driver: check hash sub-alg in RSA PKCS1V15 branch of validate_request
- psa SE driver: align secure_element_register_callbacks doc with value-copy impl
- esp_https_server: initialize server_key in HTTPD_SSL_CONFIG_DEFAULT
- mbedtls: move SECURE_ELEMENT_DRIVER_ENABLED to esp_config.h for parity
  with ESP_ECDSA_DRIVER_ENABLED; drop target_compile_definitions
- docs: fix esp_tls_cfg_t -> esp_http_client_config_t cross-reference
- docs: check psa_import_key() status in ESP-TLS PSA example
- hints/error_output: point at CONFIG_MBEDTLS_SECURE_ELEMENT_DRIVER_ENABLED

(cherry picked from commit 08b567ef3b)
2026-07-02 11:41:49 +05:30
Aditya Patwardhan a35e056816 feat(mbedtls): Add PSA Crypto driver for external secure elements
Add generic secure element PSA driver with runtime callback registration.
Consolidate Kconfig into single MBEDTLS_SECURE_ELEMENT_DRIVER_ENABLED option.

Closes https://github.com/espressif/esp-idf/issues/18388

(cherry picked from commit 1c20f525b4)
2026-07-02 11:41:48 +05:30
harshal.patil 4e02ec217c test(mbedtls): move AES test vectors to a dedicated header 2026-07-01 16:51:30 +05:30
harshal.patil f5d68c1730 fix(mbedtls/aes): Fix AES-DMA over encrypted PSRAM on ESP32-S31
esp_crypto_shared_gdma_done() polled the AXI RX raw interrupt status
(in_done) but never cleared it, so after the first transfer the set bit
made every subsequent call return immediately without waiting.
2026-07-01 16:51:26 +05:30
Ashish Sharma 33cb603e02 fix(mbedtls/port): add additional hardening for PSA drivers 2026-07-01 17:41:48 +08:00
harshal.patil b5d16d86dc fix(mbedtls/port): align ESP PSA hardware drivers with software references
Audited every esp_* PSA driver against its corresponding software driver in
mbedtls/library (psa_crypto_cipher.c, psa_crypto_aead.c, psa_crypto_mac.c,
psa_crypto_hash.c, psa_crypto_ecp.c, psa_crypto_rsa.c) and fixed gaps in
workflow ownership, error-path cleanup, sensitive-data wiping, and BAD_STATE
gating per the PSA Crypto API spec.

esp_aes (cipher): fix padding oracle in cipher_finish by replacing leaky
branches with mbedtls_ct_* primitives; abort wipes the driver-level ctx,
not just the inner mbedtls_aes_context; setup routes errors through abort.

esp_aes_gcm (AEAD): zeroize the 16-byte full_tag scratch; restore the
*output_length = finish_output_size assignment that the SW reference keeps
for future ciphers; NULL the inner ctx pointer after free in abort; gate
update/finish on a live ctx with PSA_ERROR_BAD_STATE.

esp_ecdsa: keep abort-at-exit in the one-shot wrappers so the stack-copy
of the hash (needed for little-endian byte order on HW) is wiped per
PSA spec 6.3.3, drop the over-defensive public-key qx/qy wipes that the
SW driver does not perform.

esp_cmac / esp_hmac_transparent / esp_hmac_opaque (MAC): make abort
idempotent, route setup errors through abort, gate update/finish/
verify_finish on PSA_ERROR_BAD_STATE, wipe M_last and intermediate hmac[]
buffers on completion or HW failure. HMAC opaque gains alg + computed
fields to mirror the SW psa_crypto_mac.c state machine. HMAC transparent
explicitly aborts the inner SHA context before reusing it for the outer
hash.

esp_sha: switch the per-op live indicator to (sha_ctx != NULL) so the
public esp_sha_operation_type_t enum keeps its original ordinal values;
free + NULL sha_ctx on every error path; gate update/finish/clone on a
live ctx; wipe per-algorithm core/parallel-engine scratch buffers
(W[], A[], state) on HW-engine failure.

esp_md5: replace bare memset in abort with mbedtls_platform_zeroize.

esp_rsa_ds: complete() no longer frees sig_buffer (abort owns that);
start() routes failures through abort; asymmetric_decrypt funnels all
cleanup through a single exit: label. RSA-DS utilities wipe the
decrypted-plaintext scratch on v15 / OAEP unpad failure.
2026-07-01 17:41:48 +08:00
Kapil Gupta 473dd5df7a fix(mbedtls): Fix cached Rinv size mismatch under private exponent blinding
Prevent signature verification failures on targets that do not round hardware words
to 16-word boundaries (e.g. ESP32-S3, ESP32-C6, and ESP32-P4), where exponent blinding
can cause `num_words` to vary between calls, leading to reuse of an incorrectly sized
cached `Rinv`.
2026-06-30 14:17:12 +08:00
Kapil Gupta 758dde1457 fix(mbedtls): Enable hardware CRT for RSA-4096 via base reduction
Perform modulo reduction on the base before size checks to allow RSA-4096
CRT (2048-bit exponentiations) to use the hardware accelerator instead of
falling back to software. Fix input validation, negative zero sign issues,
and early memory cleanup paths in esp_mpi_exp_mod()
2026-06-30 14:17:12 +08:00
Ashish Sharma 41b09acfe8 fix(rsa_ds): make RSA-OAEP unpadding constant-time 2026-06-25 10:40:37 +08:00
Ashish Sharma 9a703650cd fix(rsa_ds): make PKCS#1 v1.5 unpadding constant-time 2026-06-25 10:40:37 +08:00
Jiang Jiang Jian 497fb492b0 Merge branch 'fix/buildv2_bootloader_extra_components_v6.1' into 'release/v6.1'
fix(cmakev2/bootloader): link components from EXTRA_COMPONENT_DIRS (v6.1)

See merge request espressif/esp-idf!49422
2026-06-14 00:04:56 +08:00
harshal.patil beb13babca fix(mbedtls): validate ECDSA signature range and harden ECC memory power-down 2026-06-09 14:58:59 +05:30
Sudeep Mohanty c5033262e3 fix(mbedtls): initialize SRCS variables in mbedtls/CMakeLists.txt BOOTLOADER_BUILD branch 2026-06-09 10:29:15 +02:00
harshal.patil 8b7e1f1787 test(mbedtls): Add out-of-bounds test for the ECDSA hardware driver 2026-05-27 11:37:53 +05:30
Ashish Sharma b2a614569d fix(mbedtls): fixes missing check before ecdsa verify 2026-05-27 11:37:48 +05:30
Jiang Jiang Jian b6a2af2fe1 Merge branch 'fix/mbedtls-threading-impl-kconfig' into 'master'
fix(mbedtls): make threading implementation exclusive

See merge request espressif/esp-idf!48846
2026-05-25 18:08:30 +08:00
Jiang Guang Ming cdfbee61a9 fix(mbedtls): make threading implementation exclusive
Ensure the pthread and alternate threading implementations cannot be enabled at the same time.
2026-05-25 11:13:51 +08:00
Jiang Guang Ming 1ac137860c feat(mbedtls): enable PSA threading alt with ROM mbedTLS 2026-05-20 14:15:23 +08:00
Jiang Guang Ming 42674c2f95 fix(mbedtls): support ROM mbedTLS crypto in bootloader 2026-05-20 14:15:22 +08:00
Jiang Guang Ming d5a712f1f8 feat(mbedtls): enable ROM mbedTLS pytest with esp32c2 rev2.0 2026-05-20 14:15:19 +08:00
Jiang Guang Ming 5d5b8200dc feat(mbedtls): enable ESP32-C2(Rev2.0) ROM crypto for PSA 2026-05-20 14:10:14 +08:00
Aditya Patwardhan 138ebe2d85 fix(mbedtls): use constant-time compare and zeroize key material
Replace memcmp with mbedtls_ct_memcmp in PSA MAC verify_finish entries
(CMAC, HMAC-transparent, HMAC-opaque) to prevent timing side-channel
MAC forgery, and unconditionally zeroize the locally-computed MAC on
the stack before return so a later stack-disclosure primitive cannot
recover the valid MAC.

Replace bzero with mbedtls_platform_zeroize in AES context free paths.
2026-05-19 12:15:28 +05:30
harshal.patil 83ebd475c3 test(mbedtls/persistent_storage_format): Add ESP ITS NVS format-stability test app 2026-05-15 09:12:20 +05:30
harshal.patil 4821f331fe refactor(mbedtls/test): Move the mbedtls test app to support multiple test apps 2026-05-15 09:09:15 +05:30
harshal.patil d7c9c3bc10 feat(mbedtls/psa_esp_rsa_ds): Support persistent ESP-RSA DS driver 2026-05-15 09:09:15 +05:30
Mahavir Jain cc532288e8 Merge branch 'fix/bring_back_ecjpake_config' into 'master'
fix(mbedtls): bring back deprecated config MBEDTLS_ECJPAKE_C

See merge request espressif/esp-idf!48462
2026-05-14 11:11:24 +05:30
Alexey Gerenkov edb75262a1 Merge branch 'feature/update-esp-clang-to-esp-21.1.3_20260304' into 'master'
feat(tools): update esp-clang version to esp-21.1.3_20260408

Closes IDF-14965, LLVM-501, and LLVM-531

See merge request espressif/esp-idf!46361
2026-05-13 22:54:10 +08:00
Laukik Hase a8c30b7d6f Merge branch 'feat/tee_post_srv_stack_cleanup' into 'master'
feat(esp_tee): Clear out all sensitive buffers explicitly after TEE cryptographic operations

Closes IDF-15671

See merge request espressif/esp-idf!48004
2026-05-13 11:57:26 +05:30
Ashish Sharma 881dc4193a fix(mbedtls): bring back deprecated config MBEDTLS_ECJPAKE_C 2026-05-13 14:25:28 +08:00
Ashish Sharma a2ba1bc18c fix(mbedtls): keep psa crypto storage enabled with ITS backend
Closes https://github.com/espressif/esp-idf/issues/18555
2026-05-12 17:00:14 +08:00
Laukik Hase 281d219fac feat(esp_tee): Clear out all sensitive buffers explicitly after TEE crypto operations 2026-05-12 13:56:28 +05:30
Mahavir Jain 0419f8b991 Merge branch 'fix/memory_leak_cross_signed_cert_verify' into 'master'
fix(esp_crt_bundle): fixes verification failures with cross signed certificates

Closes IDFGH-17582 and IDFGH-17627

See merge request espressif/esp-idf!47966
2026-05-12 11:03:52 +05:30