Commit Graph
1013 Commits
Author SHA1 Message Date
Laukik Hase bef71a9724 ci(esp_tee): Fix tee_cli_app build failure due to heap size overflow
- Also fix the `unused variable` warning while builing the PSA
  AES tests with `tee_test_fw` app
2026-07-10 10:57:24 +05:30
Aditya Patwardhan 2188d7b855 docs(esp-tls): clarify caller owns the PSA key in esp_key_config_t
(cherry picked from commit ed6f697ea8)
2026-07-09 11:17:03 +05:30
Aditya Patwardhan 9c1dcca1af fix(esp-tls): address MR review comments for SE PSA driver
- esp_tls_mbedtls: require cert when PSA-backed server/client key is set
- esp_tls_mbedtls: drop redundant pk_init/x509_crt_init (calloc handles it)
- psa SE driver: copy callbacks/opaque_key by value (no lifetime coupling)
- psa SE driver: replace atomic CAS with simple null check on register
- psa SE driver: use sig_len from sign callback with bounds validation
- psa SE driver: validate pubkey_len returned by export_pubkey callback
- psa SE driver: check hash sub-alg in RSA PKCS1V15 branch of validate_request
- psa SE driver: align secure_element_register_callbacks doc with value-copy impl
- esp_https_server: initialize server_key in HTTPD_SSL_CONFIG_DEFAULT
- mbedtls: move SECURE_ELEMENT_DRIVER_ENABLED to esp_config.h for parity
  with ESP_ECDSA_DRIVER_ENABLED; drop target_compile_definitions
- docs: fix esp_tls_cfg_t -> esp_http_client_config_t cross-reference
- docs: check psa_import_key() status in ESP-TLS PSA example
- hints/error_output: point at CONFIG_MBEDTLS_SECURE_ELEMENT_DRIVER_ENABLED

(cherry picked from commit 08b567ef3b)
2026-07-09 11:17:02 +05:30
Aditya Patwardhan e889a304c5 feat(mbedtls): Add PSA Crypto driver for external secure elements
Add generic secure element PSA driver with runtime callback registration.
Consolidate Kconfig into single MBEDTLS_SECURE_ELEMENT_DRIVER_ENABLED option.

Closes https://github.com/espressif/esp-idf/issues/18388

(cherry picked from commit 1c20f525b4)
2026-07-09 11:14:15 +05:30
Mahavir Jain 65aeed5c00 Merge branch 'fix/tls1_3_dynamic_buffer_server_crash_v6.0' into 'release/v6.0'
fix(mbedtls): fixes TLS1.3 server failing with dynamic buffer (v6.0)

See merge request espressif/esp-idf!50387
2026-07-08 18:23:37 +05:30
Mahavir Jain 77fd953aba Merge branch 'fix/harden_mbedtls_port_layer_v6.0' into 'release/v6.0'
fix(mbedtls): harden port layer to zeroize sensitive material (v6.0)

See merge request espressif/esp-idf!50316
2026-07-08 18:22:31 +05:30
Ashish Sharma 9ad041cc8c fix(mbedtls): fixes TLS1.3 server failing with dynamic buffer 2026-07-06 15:18:38 +08:00
Mahavir Jain dfba68bc53 Merge branch 'fix/aes_dma_psram_encrypted_mem_s31_v6.0' into 'release/v6.0'
fix(mbedtls/aes): Fix AES-DMA over encrypted PSRAM on ESP32-S31 (v6.0)

See merge request espressif/esp-idf!50253
2026-07-06 09:48:36 +05:30
harshal.patil 275587ea02 feat(mbedtls/psa_esp_rsa_ds): Expose persistent key buffer format/parse helpers 2026-07-03 10:25:49 +05:30
harshal.patil 3c4586abff feat(mbedtls): Support custom storage backend for persistent PSA keys 2026-07-03 10:25:48 +05:30
Ashish Sharma 0f03194e62 fix(mbedtls): harden port layer to zeroize sensitive material 2026-07-03 11:39:03 +08:00
Mahavir Jain 175d0d844b Merge branch 'fix/align_sw_psa_drivers_and_hw_esp_psa_drivers_v6.0' into 'release/v6.0'
Align s/w and h/w PSA drivers (v6.0)

See merge request espressif/esp-idf!49834
2026-07-03 09:01:38 +05:30
harshal.patil bb5025d983 test(mbedtls): move AES test vectors to a dedicated header 2026-07-01 16:32:18 +05:30
harshal.patil 64570337aa fix(mbedtls/aes): Fix AES-DMA over encrypted PSRAM on ESP32-S31
esp_crypto_shared_gdma_done() polled the AXI RX raw interrupt status
(in_done) but never cleared it, so after the first transfer the set bit
made every subsequent call return immediately without waiting.
2026-07-01 16:32:09 +05:30
Kapil Gupta c41dd724d4 fix(mbedtls): Fix cached Rinv size mismatch under private exponent blinding
Prevent signature verification failures on targets that do not round hardware words
to 16-word boundaries (e.g. ESP32-S3, ESP32-C6, and ESP32-P4), where exponent blinding
can cause `num_words` to vary between calls, leading to reuse of an incorrectly sized
cached `Rinv`.
2026-06-29 15:43:31 +08:00
Kapil Gupta 86f6192f10 fix(mbedtls): Enable hardware CRT for RSA-4096 via base reduction
Perform modulo reduction on the base before size checks to allow RSA-4096
CRT (2048-bit exponentiations) to use the hardware accelerator instead of
falling back to software. Fix input validation, negative zero sign issues,
and early memory cleanup paths in esp_mpi_exp_mod()
2026-06-29 15:43:31 +08:00
Ashish Sharma d934586510 fix(mbedtls/port): add additional hardening for PSA drivers 2026-06-29 14:23:05 +08:00
harshal.patil 1c351b4650 fix(mbedtls/port): align ESP PSA hardware drivers with software references
Audited every esp_* PSA driver against its corresponding software driver in
mbedtls/library (psa_crypto_cipher.c, psa_crypto_aead.c, psa_crypto_mac.c,
psa_crypto_hash.c, psa_crypto_ecp.c, psa_crypto_rsa.c) and fixed gaps in
workflow ownership, error-path cleanup, sensitive-data wiping, and BAD_STATE
gating per the PSA Crypto API spec.

esp_aes (cipher): fix padding oracle in cipher_finish by replacing leaky
branches with mbedtls_ct_* primitives; abort wipes the driver-level ctx,
not just the inner mbedtls_aes_context; setup routes errors through abort.

esp_aes_gcm (AEAD): zeroize the 16-byte full_tag scratch; restore the
*output_length = finish_output_size assignment that the SW reference keeps
for future ciphers; NULL the inner ctx pointer after free in abort; gate
update/finish on a live ctx with PSA_ERROR_BAD_STATE.

esp_ecdsa: keep abort-at-exit in the one-shot wrappers so the stack-copy
of the hash (needed for little-endian byte order on HW) is wiped per
PSA spec 6.3.3, drop the over-defensive public-key qx/qy wipes that the
SW driver does not perform.

esp_cmac / esp_hmac_transparent / esp_hmac_opaque (MAC): make abort
idempotent, route setup errors through abort, gate update/finish/
verify_finish on PSA_ERROR_BAD_STATE, wipe M_last and intermediate hmac[]
buffers on completion or HW failure. HMAC opaque gains alg + computed
fields to mirror the SW psa_crypto_mac.c state machine. HMAC transparent
explicitly aborts the inner SHA context before reusing it for the outer
hash.

esp_sha: switch the per-op live indicator to (sha_ctx != NULL) so the
public esp_sha_operation_type_t enum keeps its original ordinal values;
free + NULL sha_ctx on every error path; gate update/finish/clone on a
live ctx; wipe per-algorithm core/parallel-engine scratch buffers
(W[], A[], state) on HW-engine failure.

esp_md5: replace bare memset in abort with mbedtls_platform_zeroize.

esp_rsa_ds: complete() no longer frees sig_buffer (abort owns that);
start() routes failures through abort; asymmetric_decrypt funnels all
cleanup through a single exit: label. RSA-DS utilities wipe the
decrypted-plaintext scratch on v15 / OAEP unpad failure.
2026-06-29 14:22:40 +08:00
Mahavir Jain 96008173aa Merge branch 'fix/rsa_ds_driver_constant_time_v6.0' into 'release/v6.0'
Fix/rsa ds driver constant time (v6.0)

See merge request espressif/esp-idf!49699
2026-06-29 11:23:54 +05:30
Mahavir Jain 4163417ff1 Merge branch 'feat/support_rom_psa_mbedtls_v6.0' into 'release/v6.0'
feat(mbedtls): enable ESP32-C2(Rev2.0) ROM mbedTLS crypto for PSA (v6.0)

See merge request espressif/esp-idf!48843
2026-06-29 11:22:33 +05:30
Mahavir Jain 732111f75a Merge branch 'feat/esp_tee_backports_v6.0' into 'release/v6.0'
feat(esp_tee): Feature/fixes backports to `release/v6.0`

See merge request espressif/esp-idf!48486
2026-06-29 11:21:13 +05:30
Mahavir Jain e082ad95da Merge branch 'fix/memory_leak_cross_signed_cert_verify_v6.0' into 'release/v6.0'
fix(esp_crt_bundle): fixes verification failures with cross signed certificates (v6.0)

See merge request espressif/esp-idf!48624
2026-06-29 11:17:37 +05:30
Ashish Sharma f92ccb1348 fix(rsa_ds): make RSA-OAEP unpadding constant-time 2026-06-16 14:46:24 +08:00
Ashish Sharma c313d339ab fix(rsa_ds): make PKCS#1 v1.5 unpadding constant-time 2026-06-16 14:46:24 +08:00
Laukik Hase 39a4cf5e56 feat(esp_tee): Clear out all sensitive buffers explicitly after TEE crypto operations 2026-06-12 10:04:07 +05:30
Laukik Hase f37a2cd35b feat(esp_tee): Remove unused components from the PSA Crypto library 2026-06-12 10:03:03 +05:30
harshal.patil 3195c942da fix(mbedtls): validate ECDSA signature range and harden ECC memory power-down 2026-06-09 15:02:59 +05:30
Jiang Jiang Jian 948a5277ef Merge branch 'fix/fix_mbedtls_fs_io_psa_storage_v6.0' into 'release/v6.0'
fix(mbedtls): keep psa crypto storage enabled with ITS backend (v6.0)

See merge request espressif/esp-idf!48622
2026-06-03 16:44:19 +08:00
Ashish Sharma a1f1d90729 fix(esp_crt_bundle): fixes verification with cross signed cert 2026-06-03 11:35:24 +08:00
Ashish Sharma 0d8ff68f8a fix(esp_crt_bundle): fixes a potential memory leak with cross signed certificates
Closes https://github.com/espressif/esp-idf/issues/18512
Closes https://github.com/espressif/esp-idf/issues/18550
2026-06-03 11:31:27 +08:00
Jiang Jiang Jian 59032327db Merge branch 'fix/mbedtls-psa-constant-time-and-zeroization_v6.0' into 'release/v6.0'
fix(mbedtls): use constant-time compare for MAC verify and zeroize key material (v6.0)

See merge request espressif/esp-idf!48729
2026-06-02 20:12:59 +08:00
Aditya Patwardhan f77a7d16ec fix(mbedtls): use constant-time compare and zeroize key material
Replace memcmp with mbedtls_ct_memcmp in PSA MAC verify_finish entries
(CMAC, HMAC-transparent, HMAC-opaque) to prevent timing side-channel
MAC forgery, and unconditionally zeroize the locally-computed MAC on
the stack before return so a later stack-disclosure primitive cannot
recover the valid MAC.

Replace bzero with mbedtls_platform_zeroize in AES context free paths.
2026-05-30 23:15:44 +05:30
Aditya Patwardhan 4fb4dbda90 fix(mbedtls): correct inverted NULL check in esp_hmac_abort_opaque
esp_hmac_abort_opaque() had an inverted guard that called
mbedtls_platform_zeroize() on the context only when the context pointer
was NULL, dereferencing NULL and skipping cleanup of valid contexts.

Effect:
* Calling the abort path with a NULL pointer crashes (NULL write)
  instead of being a safe no-op.
* The valid (non-NULL) HMAC opaque operation context is never zeroized
  on abort, leaving sensitive intermediate HMAC state and key handle
  references in operation memory until the buffer is overwritten or
  freed.

Fix: invert the check so zeroization runs only when the context pointer
is non-NULL.
2026-05-30 23:15:42 +05:30
Jiang Jiang Jian 9d24b38a42 Merge branch 'fix/bring_back_ecjpake_config_v6.0' into 'release/v6.0'
fix(mbedtls): bring back deprecated config MBEDTLS_ECJPAKE_C (v6.0)

See merge request espressif/esp-idf!48623
2026-05-29 17:27:59 +08:00
Mahavir Jain b31c2753bc Merge branch 'fix/fix_psa_ecdsa_driver_missing_checks_v6.0' into 'release/v6.0'
fix(mbedtls): fixes missing check before ecdsa verify (v6.0)

See merge request espressif/esp-idf!48947
2026-05-28 21:05:31 +05:30
harshal.patil 40de3df854 test(mbedtls): Add out-of-bounds test for the ECDSA hardware driver 2026-05-27 11:38:14 +05:30
Ashish Sharma 9de91ed9e5 fix(mbedtls): fixes missing check before ecdsa verify 2026-05-27 11:38:13 +05:30
Jiang Guang Ming da5f99a518 fix(mbedtls): make threading implementation exclusive
Ensure the pthread and alternate threading implementations cannot be enabled at the same time.
2026-05-25 13:52:12 +08:00
Jiang Guang Ming 9320f709bd feat(mbedtls): enable PSA threading alt with ROM mbedTLS 2026-05-25 10:08:33 +08:00
Jiang Guang Ming dd28e303d5 fix(mbedtls): support ROM mbedTLS crypto in bootloader 2026-05-25 10:08:25 +08:00
Jiang Guang Ming 6eb7f181a2 feat(mbedtls): enable ROM mbedTLS pytest with esp32c2 rev2.0 2026-05-25 10:07:47 +08:00
Jiang Guang Ming 6ae3fa39f4 feat(mbedtls): enable ESP32-C2(Rev2.0) ROM crypto for PSA 2026-05-25 10:04:10 +08:00
Ashish Sharma 7f8dc336a6 fix(mbedtls): bring back deprecated config MBEDTLS_ECJPAKE_C 2026-05-18 14:56:18 +08:00
Ashish Sharma 94d456326c fix(mbedtls): keep psa crypto storage enabled with ITS backend
Closes https://github.com/espressif/esp-idf/issues/18555
2026-05-18 14:51:53 +08:00
harshal.patil d8808f90b9 test(mbedtls/persistent_storage_format): Add ESP ITS NVS format-stability test app 2026-05-15 09:28:47 +05:30
harshal.patil 513efdf89a refactor(mbedtls/test): Move the mbedtls test app to support multiple test apps 2026-05-15 09:28:42 +05:30
harshal.patil 1d6b5f219e feat(mbedtls/psa_esp_rsa_ds): Support persistent ESP-RSA DS driver 2026-05-15 09:17:09 +05:30
Jiang Jiang Jian 6d6aa6cccd Merge branch 'fix/fix_https_server_linux_build_v6.0' into 'release/v6.0'
fix(https_server): fixes failing example build for linux target (v6.0)

See merge request espressif/esp-idf!48205
2026-05-12 18:07:17 +08:00
Ashish Sharma 1d0cdd5602 fix(https_server): fixes failing example build for linux target 2026-05-10 19:29:25 +08:00
Ashish Sharma 04ec0ab538 feat(bootloader_support): remove P192 curve support 2026-05-10 19:16:12 +08:00