Commit Graph
1042 Commits
Author SHA1 Message Date
Mahavir Jain e5fa6bca64 Merge branch 'feat/mbedtls_follow_app_perf_optimization_v6.0' into 'release/v6.0'
feat(mbedtls): follow project performance optimization level by default (v6.0)

See merge request espressif/esp-idf!52727
2026-09-17 10:52:06 +05:30
Mahavir Jain 0187e155ac Merge branch 'fix/ecdsa_hmac_ds_locking_v6.0' into 'release/v6.0'
fix(esp_security): Stop ECDSA and Key Manager resets from corrupting concurrent crypto (v6.0)

See merge request espressif/esp-idf!52578
2026-09-15 21:03:00 +05:30
Mahavir Jain 8e2153965f Merge branch 'fix/mbedtls_gcm_multipart_and_ecp_pubkey_v6.0' into 'release/v6.0'
Fix/mbedTLS port layer security fixes (394, 1214, 1206) (v6.0)

See merge request espressif/esp-idf!52195
2026-09-13 16:45:07 +05:30
Ashish Sharma a6adc3b5e8 fix(esp_crt_bundle): match memory allocator in cross-signed callback
Closes https://github.com/espressif/esp-idf/issues/19053
2026-09-11 14:10:06 +08:00
Ashish Sharma 0b48640013 feat(mbedtls): follow project performance optimization level by default 2026-09-11 14:09:05 +08:00
radek.tandler 0762e80999 fix(mbedtls): Fix mbedtls testapps false memory leaks by lazy mutex creation 2026-09-08 19:42:35 +05:30
radek.tandler ba13c2852a fix(esp_security): Stop ECDSA and Key Manager resets from corrupting concurrent crypto
ECDSA enable pulses a reset that also holds SHA in reset, and SHA shares
its DMA with AES. Key Manager enable pulses a reset that also covers the
XTS-AES flash encryption key-usage selector. Neither path was serialized
against those victims, so a hardware ECDSA/HMAC/DS operation could
corrupt a concurrent SHA/AES transfer or an in-flight encrypted flash
read.

- Take the SHA/AES lock inside esp_crypto_ecdsa_lock_acquire(), before
  MPI, matching the DS lock order (sha_aes < mpi)
- Add esp_crypto_key_mgr_enable_periph_clk_no_reset() and switch ECDSA,
  HMAC and DS to it; they only need the key-usage selector writable
- Hold esp_crypto_key_manager_lock across those clock enable/disable
  pairs so selector writes stay serialized without resetting KM
2026-09-08 19:42:35 +05:30
Ashish Sharma 0e6b1cb190 fix(mbedtls): use pointer-width types for dynamic buffer msg offsets 2026-09-07 17:30:09 +08:00
Ashish Sharma 85eda0fd07 test(mbedtls): add test for unaligned multipart AES-GCM streaming 2026-09-07 17:30:09 +08:00
Ashish Sharma 8767271843 fix(mbedtls): preserve AES-GCM stream state across multipart updates 2026-09-07 17:30:09 +08:00
Ashish Sharma c5bc6acdc3 fix(mbedtls): bound public-key coordinate copy in esp ecp_check_pubkey 2026-09-07 17:30:09 +08:00
Laukik Hase ab5b29e52c Merge branch 'fix/tee_reentrant_svc_and_non_det_sign_v6.0' into 'release/v6.0'
feat(esp_tee): Backports to v6.0

See merge request espressif/esp-idf!52290
2026-09-07 10:10:44 +05:30
Mahavir Jain ec3877cf6c fix(mbedtls): read crt bundle byte-wise to avoid misaligned flash access
The offset table and the per-cert length fields of the certificate
bundle were read through uint16_t*/uint32_t* casts, which compile to
halfword/word loads at addresses with no alignment guarantee: bundles
supplied via esp_crt_bundle_set() can start anywhere, and cert entries
are byte-packed, so their 16-bit fields land at arbitrary offsets.

On chips with SOC_CPU_MISALIGNED_ACCESS_ON_PMP_MISMATCH_ISSUE (DIG-694:
ESP32-C6/H2/H21) a misaligned load from memory-mapped flash can take a
spurious "Load access fault" when it sits within two instructions of an
access to a differently-permissioned region, observed as a crash in
esp_crt_check_bundle()/CA callback during TLS handshakes with a bundle
that happened to be placed at an odd address.
2026-09-04 11:06:54 +05:30
Laukik Hase a4d6b802a7 feat(esp_tee): Disable the MBEDTLS_PSA_ASSUME_EXCLUSIVE_BUFFERS option for TEE build 2026-09-04 10:23:25 +05:30
Laukik Hase e5c3063dee fix(esp_tee): Snapshot input arguments in TEE memory before secure service execution
- Also fix the `tee_cli_app` build failure due to TEE heap size overflow
2026-09-04 10:23:25 +05:30
Laukik Hase e9cd262217 change(esp_tee): Force non-deterministic ECDSA signing for TEE secure storage keys 2026-09-04 10:23:24 +05:30
Laukik Hase 8e34cc16cc feat(esp_tee): Use CTR-DRBG for assisting random number generation in TEE
- For ESP-TEE, fault-assert in `esp_random()` if the RNG is held in a
  freeze state
2026-09-04 10:23:24 +05:30
Mahavir Jain b3c5d5266a Merge branch 'fix/crt_bundle_cert_header_oob_v6.0' into 'release/v6.0'
Validate cert header extent before reading it in bundle check (v6.0)

See merge request espressif/esp-idf!51998
2026-09-03 13:44:33 +05:30
harshal.patil 1d4a1e0624 test(mbedtls): add partial-block PSRAM coverage for AES and AES-GCM
Extend the CTR test data length to 6433 bytes so the trailing partial
block is exercised with external RAM buffers (which stalls the ESP32-S2
Crypto DMA on an unfixed driver), and add AES-GCM PSRAM tests verified
against internal RAM references.
2026-08-25 14:50:15 +05:30
harshal.patil 4025a2f8b9 fix(mbedtls/aes): fix ESP32-S2 Crypto DMA stall on PSRAM output with partial blocks
The ESP32-S2 Crypto DMA in-channel stalls silently when a receive
descriptor list transitions from external to internal RAM. The AES
driver hits this when a PSRAM-output operation has a trailing partial
block, as the internal stream descriptor is linked after the external
RAM data descriptors.

- esp_aes_process_dma(): process the block-aligned part and the partial
  block as two separate DMA operations, keeping each descriptor list
  uniform
- crypto_dma_ll_reset(): also reset the in-channel (per the TRM receive
  reset sequence), otherwise stale state from a preceding external-RAM
  operation corrupts the next operation's output

The GCM DMA path is unaffected; it never operates on PSRAM buffers.
2026-08-25 14:50:15 +05:30
harshal.patil 710ce291ac fix(mbedtls): validate cert header extent before reading it in bundle check
esp_crt_check_bundle() read the 4-byte certificate header (name_len,
key_len) via esp_crt_get_len() after only checking that the cert's
start offset lies inside the bundle, so a crafted bundle whose first
or last certificate starts within the final 3 bytes caused a transient
out-of-bounds read of up to 3 bytes before the extent check rejected
it. Require the whole header to lie inside the bundle before reading
it.
2026-08-24 20:56:43 +05:30
Ashish Sharma 2552d48f27 fix(mbedtls): revert to non constant time rsa key gen 2026-07-23 13:38:24 +08:00
Ashish Sharma 57ff98ca13 test(mbedtls): add PSA RSA key generation test
The test only runs with MBEDTLS_CONSTANT_TIME_PRIME_GEN disabled:
with the constant-time prime generation that is now the default,
RSA-2048 key generation takes over a minute on most targets (~86 s on
ESP32-S3), exceeding the test timeout and starving the task watchdog.
2026-07-23 13:38:24 +08:00
Ashish Sharma 73712ff5fd feat(mbedtls): add option to choose constant-time prime generation
mbedtls 4.1.1 made the small-factor test in prime generation
constant-time (a CT GCD against the product of primes up to 997, run
for every prime candidate). This makes RSA key generation roughly ten
times slower on ESP chips and starves the idle task since the software
GCD never yields, tripping the task watchdog.

Add MBEDTLS_CONSTANT_TIME_PRIME_GEN under the new "Security hardening"
menu, default y so the upstream constant-time behavior ships as the
secure default. When disabled, esp_config.h defines
MBEDTLS_MPI_PRIME_SIEVE_VARIABLE_TIME and mbedtls uses the pre-3.6.7
variable-time trial division, restoring key generation performance on
devices where no untrusted co-resident code could time key generation.
2026-07-23 13:38:24 +08:00
Ashish Sharma 8ad5504eb1 feat(mbedtls): update to version 4.1.1 2026-07-23 13:38:24 +08:00
Jiang Jiang Jian f9058d5328 Merge branch 'feat/enable_cross_signed_cert_suppport_default_v6.0' into 'release/v6.0'
feat(mbedtls): enable cross signed certificate verification support by default (v6.0)

See merge request espressif/esp-idf!50535
2026-07-22 10:30:53 +08:00
Ashish Sharma 2c4bcab8d2 feat(mbedtls): enable cross signed certificate verification support by default 2026-07-17 18:12:56 +08:00
Ashish Sharma d85cb8d7cc fix(esp_tee): fix DS-lock leak, intr-matrix OOB, calloc overflow, attestation leak 2026-07-16 18:24:47 +08:00
Ashish Sharma 2e6f9b8b42 fix(mbedtls): validate crypto input lengths (TEE OOB, auth-bypass, overflows) 2026-07-16 18:24:47 +08:00
Laukik Hase bef71a9724 ci(esp_tee): Fix tee_cli_app build failure due to heap size overflow
- Also fix the `unused variable` warning while builing the PSA
  AES tests with `tee_test_fw` app
2026-07-10 10:57:24 +05:30
Aditya Patwardhan 2188d7b855 docs(esp-tls): clarify caller owns the PSA key in esp_key_config_t
(cherry picked from commit ed6f697ea8)
2026-07-09 11:17:03 +05:30
Aditya Patwardhan 9c1dcca1af fix(esp-tls): address MR review comments for SE PSA driver
- esp_tls_mbedtls: require cert when PSA-backed server/client key is set
- esp_tls_mbedtls: drop redundant pk_init/x509_crt_init (calloc handles it)
- psa SE driver: copy callbacks/opaque_key by value (no lifetime coupling)
- psa SE driver: replace atomic CAS with simple null check on register
- psa SE driver: use sig_len from sign callback with bounds validation
- psa SE driver: validate pubkey_len returned by export_pubkey callback
- psa SE driver: check hash sub-alg in RSA PKCS1V15 branch of validate_request
- psa SE driver: align secure_element_register_callbacks doc with value-copy impl
- esp_https_server: initialize server_key in HTTPD_SSL_CONFIG_DEFAULT
- mbedtls: move SECURE_ELEMENT_DRIVER_ENABLED to esp_config.h for parity
  with ESP_ECDSA_DRIVER_ENABLED; drop target_compile_definitions
- docs: fix esp_tls_cfg_t -> esp_http_client_config_t cross-reference
- docs: check psa_import_key() status in ESP-TLS PSA example
- hints/error_output: point at CONFIG_MBEDTLS_SECURE_ELEMENT_DRIVER_ENABLED

(cherry picked from commit 08b567ef3b)
2026-07-09 11:17:02 +05:30
Aditya Patwardhan e889a304c5 feat(mbedtls): Add PSA Crypto driver for external secure elements
Add generic secure element PSA driver with runtime callback registration.
Consolidate Kconfig into single MBEDTLS_SECURE_ELEMENT_DRIVER_ENABLED option.

Closes https://github.com/espressif/esp-idf/issues/18388

(cherry picked from commit 1c20f525b4)
2026-07-09 11:14:15 +05:30
Mahavir Jain 65aeed5c00 Merge branch 'fix/tls1_3_dynamic_buffer_server_crash_v6.0' into 'release/v6.0'
fix(mbedtls): fixes TLS1.3 server failing with dynamic buffer (v6.0)

See merge request espressif/esp-idf!50387
2026-07-08 18:23:37 +05:30
Mahavir Jain 77fd953aba Merge branch 'fix/harden_mbedtls_port_layer_v6.0' into 'release/v6.0'
fix(mbedtls): harden port layer to zeroize sensitive material (v6.0)

See merge request espressif/esp-idf!50316
2026-07-08 18:22:31 +05:30
Ashish Sharma 9ad041cc8c fix(mbedtls): fixes TLS1.3 server failing with dynamic buffer 2026-07-06 15:18:38 +08:00
Mahavir Jain dfba68bc53 Merge branch 'fix/aes_dma_psram_encrypted_mem_s31_v6.0' into 'release/v6.0'
fix(mbedtls/aes): Fix AES-DMA over encrypted PSRAM on ESP32-S31 (v6.0)

See merge request espressif/esp-idf!50253
2026-07-06 09:48:36 +05:30
harshal.patil 275587ea02 feat(mbedtls/psa_esp_rsa_ds): Expose persistent key buffer format/parse helpers 2026-07-03 10:25:49 +05:30
harshal.patil 3c4586abff feat(mbedtls): Support custom storage backend for persistent PSA keys 2026-07-03 10:25:48 +05:30
Ashish Sharma 0f03194e62 fix(mbedtls): harden port layer to zeroize sensitive material 2026-07-03 11:39:03 +08:00
Mahavir Jain 175d0d844b Merge branch 'fix/align_sw_psa_drivers_and_hw_esp_psa_drivers_v6.0' into 'release/v6.0'
Align s/w and h/w PSA drivers (v6.0)

See merge request espressif/esp-idf!49834
2026-07-03 09:01:38 +05:30
harshal.patil bb5025d983 test(mbedtls): move AES test vectors to a dedicated header 2026-07-01 16:32:18 +05:30
harshal.patil 64570337aa fix(mbedtls/aes): Fix AES-DMA over encrypted PSRAM on ESP32-S31
esp_crypto_shared_gdma_done() polled the AXI RX raw interrupt status
(in_done) but never cleared it, so after the first transfer the set bit
made every subsequent call return immediately without waiting.
2026-07-01 16:32:09 +05:30
Kapil Gupta c41dd724d4 fix(mbedtls): Fix cached Rinv size mismatch under private exponent blinding
Prevent signature verification failures on targets that do not round hardware words
to 16-word boundaries (e.g. ESP32-S3, ESP32-C6, and ESP32-P4), where exponent blinding
can cause `num_words` to vary between calls, leading to reuse of an incorrectly sized
cached `Rinv`.
2026-06-29 15:43:31 +08:00
Kapil Gupta 86f6192f10 fix(mbedtls): Enable hardware CRT for RSA-4096 via base reduction
Perform modulo reduction on the base before size checks to allow RSA-4096
CRT (2048-bit exponentiations) to use the hardware accelerator instead of
falling back to software. Fix input validation, negative zero sign issues,
and early memory cleanup paths in esp_mpi_exp_mod()
2026-06-29 15:43:31 +08:00
Ashish Sharma d934586510 fix(mbedtls/port): add additional hardening for PSA drivers 2026-06-29 14:23:05 +08:00
harshal.patil 1c351b4650 fix(mbedtls/port): align ESP PSA hardware drivers with software references
Audited every esp_* PSA driver against its corresponding software driver in
mbedtls/library (psa_crypto_cipher.c, psa_crypto_aead.c, psa_crypto_mac.c,
psa_crypto_hash.c, psa_crypto_ecp.c, psa_crypto_rsa.c) and fixed gaps in
workflow ownership, error-path cleanup, sensitive-data wiping, and BAD_STATE
gating per the PSA Crypto API spec.

esp_aes (cipher): fix padding oracle in cipher_finish by replacing leaky
branches with mbedtls_ct_* primitives; abort wipes the driver-level ctx,
not just the inner mbedtls_aes_context; setup routes errors through abort.

esp_aes_gcm (AEAD): zeroize the 16-byte full_tag scratch; restore the
*output_length = finish_output_size assignment that the SW reference keeps
for future ciphers; NULL the inner ctx pointer after free in abort; gate
update/finish on a live ctx with PSA_ERROR_BAD_STATE.

esp_ecdsa: keep abort-at-exit in the one-shot wrappers so the stack-copy
of the hash (needed for little-endian byte order on HW) is wiped per
PSA spec 6.3.3, drop the over-defensive public-key qx/qy wipes that the
SW driver does not perform.

esp_cmac / esp_hmac_transparent / esp_hmac_opaque (MAC): make abort
idempotent, route setup errors through abort, gate update/finish/
verify_finish on PSA_ERROR_BAD_STATE, wipe M_last and intermediate hmac[]
buffers on completion or HW failure. HMAC opaque gains alg + computed
fields to mirror the SW psa_crypto_mac.c state machine. HMAC transparent
explicitly aborts the inner SHA context before reusing it for the outer
hash.

esp_sha: switch the per-op live indicator to (sha_ctx != NULL) so the
public esp_sha_operation_type_t enum keeps its original ordinal values;
free + NULL sha_ctx on every error path; gate update/finish/clone on a
live ctx; wipe per-algorithm core/parallel-engine scratch buffers
(W[], A[], state) on HW-engine failure.

esp_md5: replace bare memset in abort with mbedtls_platform_zeroize.

esp_rsa_ds: complete() no longer frees sig_buffer (abort owns that);
start() routes failures through abort; asymmetric_decrypt funnels all
cleanup through a single exit: label. RSA-DS utilities wipe the
decrypted-plaintext scratch on v15 / OAEP unpad failure.
2026-06-29 14:22:40 +08:00
Mahavir Jain 96008173aa Merge branch 'fix/rsa_ds_driver_constant_time_v6.0' into 'release/v6.0'
Fix/rsa ds driver constant time (v6.0)

See merge request espressif/esp-idf!49699
2026-06-29 11:23:54 +05:30
Mahavir Jain 4163417ff1 Merge branch 'feat/support_rom_psa_mbedtls_v6.0' into 'release/v6.0'
feat(mbedtls): enable ESP32-C2(Rev2.0) ROM mbedTLS crypto for PSA (v6.0)

See merge request espressif/esp-idf!48843
2026-06-29 11:22:33 +05:30
Mahavir Jain 732111f75a Merge branch 'feat/esp_tee_backports_v6.0' into 'release/v6.0'
feat(esp_tee): Feature/fixes backports to `release/v6.0`

See merge request espressif/esp-idf!48486
2026-06-29 11:21:13 +05:30