mirror of
https://github.com/espressif/openthread.git
synced 2026-10-09 09:17:37 +00:00
[mbedtls] add guards for crypto support dropped in Mbed TLS 4.x (#12459)
Starting from Mbed TLS 4.0 legacy crypto support (which now it's moved into TF-PSA-Crypto) has been made internal so it shoudn't be referenced anymore. This commit add guards for this change. Signed-off-by: Valerio Setti <[email protected]>
This commit is contained in:
committed by
Jonathan Hui
parent
b59baea4f4
commit
e4d97681c5
+2
-1
@@ -48,9 +48,11 @@
|
||||
|
||||
#if OPENTHREAD_CONFIG_TLS_ENABLE
|
||||
#include <mbedtls/debug.h>
|
||||
#if (MBEDTLS_VERSION_NUMBER >= 0x03000000) && (MBEDTLS_VERSION_NUMBER <= 0x03060500)
|
||||
#include <mbedtls/ecjpake.h>
|
||||
#include "crypto/mbedtls.hpp"
|
||||
#endif
|
||||
#endif
|
||||
|
||||
namespace ot {
|
||||
namespace Cli {
|
||||
@@ -163,7 +165,6 @@ template <> otError TcpExample::Process<Cmd("init")>(Arg aArgs[])
|
||||
#endif
|
||||
|
||||
#if (MBEDTLS_VERSION_NUMBER >= 0x03000000) && (MBEDTLS_VERSION_NUMBER <= 0x03060500)
|
||||
#include "crypto/mbedtls.hpp"
|
||||
int rv = mbedtls_pk_parse_key(&mPKey, reinterpret_cast<const unsigned char *>(sSrvKey), sSrvKeyLength,
|
||||
nullptr, 0, Crypto::MbedTls::CryptoSecurePrng, nullptr);
|
||||
#else
|
||||
|
||||
+12
-6
@@ -41,10 +41,14 @@
|
||||
|
||||
#if OPENTHREAD_CONFIG_TLS_ENABLE
|
||||
|
||||
#include <mbedtls/ssl.h>
|
||||
#include <mbedtls/version.h>
|
||||
#include <mbedtls/x509_crt.h>
|
||||
|
||||
#if (MBEDTLS_VERSION_NUMBER <= 0x03060500)
|
||||
#include <mbedtls/ctr_drbg.h>
|
||||
#include <mbedtls/entropy.h>
|
||||
#include <mbedtls/ssl.h>
|
||||
#include <mbedtls/x509_crt.h>
|
||||
#endif
|
||||
|
||||
#endif
|
||||
|
||||
@@ -155,11 +159,13 @@ private:
|
||||
otTcpEndpointAndCircularSendBuffer mEndpointAndCircularSendBuffer;
|
||||
|
||||
#if OPENTHREAD_CONFIG_TLS_ENABLE
|
||||
mbedtls_ssl_context mSslContext;
|
||||
mbedtls_ssl_config mSslConfig;
|
||||
mbedtls_x509_crt mSrvCert;
|
||||
mbedtls_pk_context mPKey;
|
||||
mbedtls_ssl_context mSslContext;
|
||||
mbedtls_ssl_config mSslConfig;
|
||||
mbedtls_x509_crt mSrvCert;
|
||||
mbedtls_pk_context mPKey;
|
||||
#if (MBEDTLS_VERSION_NUMBER <= 0x03060500)
|
||||
mbedtls_entropy_context mEntropy;
|
||||
#endif
|
||||
#endif // OPENTHREAD_CONFIG_TLS_ENABLE
|
||||
|
||||
static constexpr const char *sBenchmarkData =
|
||||
|
||||
@@ -33,7 +33,10 @@
|
||||
|
||||
#include <openthread/random_crypto.h>
|
||||
|
||||
#include <mbedtls/version.h>
|
||||
#if (MBEDTLS_VERSION_NUMBER <= 0x03060500)
|
||||
#include <mbedtls/ctr_drbg.h>
|
||||
#endif
|
||||
|
||||
#include "common/random.hpp"
|
||||
|
||||
|
||||
@@ -32,6 +32,8 @@
|
||||
|
||||
#include "openthread-core-config.h"
|
||||
|
||||
#if OPENTHREAD_CONFIG_CRYPTO_LIB == OPENTHREAD_CONFIG_CRYPTO_LIB_MBEDTLS
|
||||
|
||||
#include <string.h>
|
||||
|
||||
#include <mbedtls/aes.h>
|
||||
@@ -61,8 +63,6 @@
|
||||
using namespace ot;
|
||||
using namespace Crypto;
|
||||
|
||||
#if OPENTHREAD_CONFIG_CRYPTO_LIB == OPENTHREAD_CONFIG_CRYPTO_LIB_MBEDTLS
|
||||
|
||||
//---------------------------------------------------------------------------------------------------------------------
|
||||
// Default/weak implementation of crypto platform APIs
|
||||
|
||||
|
||||
@@ -33,9 +33,11 @@
|
||||
|
||||
#include "mbedtls.hpp"
|
||||
|
||||
#if (MBEDTLS_VERSION_NUMBER <= 0x03060500)
|
||||
#include <mbedtls/ctr_drbg.h>
|
||||
#include <mbedtls/debug.h>
|
||||
#include <mbedtls/entropy.h>
|
||||
#endif
|
||||
#include <mbedtls/debug.h>
|
||||
#include <mbedtls/platform.h>
|
||||
#include <mbedtls/threading.h>
|
||||
|
||||
@@ -69,8 +71,10 @@ Error MbedTls::MapError(int aMbedTlsError)
|
||||
switch (aMbedTlsError)
|
||||
{
|
||||
#if OPENTHREAD_CONFIG_ECDSA_ENABLE
|
||||
#if (MBEDTLS_VERSION_NUMBER <= 0x03060500)
|
||||
case MBEDTLS_ERR_ECP_BAD_INPUT_DATA:
|
||||
case MBEDTLS_ERR_MPI_BAD_INPUT_DATA:
|
||||
#endif
|
||||
case MBEDTLS_ERR_MPI_INVALID_CHARACTER:
|
||||
#endif
|
||||
#ifdef MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED
|
||||
@@ -84,7 +88,9 @@ Error MbedTls::MapError(int aMbedTlsError)
|
||||
case MBEDTLS_ERR_PK_INVALID_PUBKEY:
|
||||
case MBEDTLS_ERR_PK_INVALID_ALG:
|
||||
case MBEDTLS_ERR_PK_UNKNOWN_NAMED_CURVE:
|
||||
#if (MBEDTLS_VERSION_NUMBER <= 0x03060500)
|
||||
case MBEDTLS_ERR_PK_BAD_INPUT_DATA:
|
||||
#endif
|
||||
case MBEDTLS_ERR_X509_SIG_MISMATCH:
|
||||
case MBEDTLS_ERR_X509_BAD_INPUT_DATA:
|
||||
case MBEDTLS_ERR_X509_FILE_IO_ERROR:
|
||||
@@ -101,12 +107,17 @@ Error MbedTls::MapError(int aMbedTlsError)
|
||||
case MBEDTLS_ERR_X509_INVALID_EXTENSIONS:
|
||||
case MBEDTLS_ERR_X509_UNKNOWN_VERSION:
|
||||
#endif // MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED
|
||||
#if (MBEDTLS_VERSION_NUMBER <= 0x03060500)
|
||||
case MBEDTLS_ERR_SSL_BAD_INPUT_DATA:
|
||||
case MBEDTLS_ERR_CTR_DRBG_REQUEST_TOO_BIG:
|
||||
case MBEDTLS_ERR_CTR_DRBG_INPUT_TOO_BIG:
|
||||
#else
|
||||
case PSA_ERROR_INVALID_ARGUMENT:
|
||||
#endif
|
||||
error = kErrorInvalidArgs;
|
||||
break;
|
||||
|
||||
#if (MBEDTLS_VERSION_NUMBER <= 0x03060500)
|
||||
#if OPENTHREAD_CONFIG_ECDSA_ENABLE
|
||||
case MBEDTLS_ERR_ECP_BUFFER_TOO_SMALL:
|
||||
case MBEDTLS_ERR_MPI_BUFFER_TOO_SMALL:
|
||||
@@ -119,25 +130,37 @@ Error MbedTls::MapError(int aMbedTlsError)
|
||||
case MBEDTLS_ERR_X509_ALLOC_FAILED:
|
||||
#endif
|
||||
case MBEDTLS_ERR_SSL_ALLOC_FAILED:
|
||||
#else
|
||||
case PSA_ERROR_INSUFFICIENT_MEMORY:
|
||||
case PSA_ERROR_BUFFER_TOO_SMALL:
|
||||
#endif
|
||||
case MBEDTLS_ERR_SSL_WANT_WRITE:
|
||||
#if (MBEDTLS_VERSION_NUMBER <= 0x03060500)
|
||||
case MBEDTLS_ERR_ENTROPY_MAX_SOURCES:
|
||||
#endif
|
||||
error = kErrorNoBufs;
|
||||
break;
|
||||
|
||||
#ifdef MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED
|
||||
case MBEDTLS_ERR_PK_FEATURE_UNAVAILABLE:
|
||||
#if (MBEDTLS_VERSION_NUMBER <= 0x03060500)
|
||||
case MBEDTLS_ERR_PK_SIG_LEN_MISMATCH:
|
||||
#endif
|
||||
case MBEDTLS_ERR_X509_FEATURE_UNAVAILABLE:
|
||||
case MBEDTLS_ERR_X509_CERT_VERIFY_FAILED:
|
||||
#endif // MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED
|
||||
#if (MBEDTLS_VERSION_NUMBER <= 0x03060500)
|
||||
case MBEDTLS_ERR_CTR_DRBG_ENTROPY_SOURCE_FAILED:
|
||||
case MBEDTLS_ERR_ENTROPY_SOURCE_FAILED:
|
||||
case MBEDTLS_ERR_ENTROPY_NO_SOURCES_DEFINED:
|
||||
case MBEDTLS_ERR_ENTROPY_NO_STRONG_SOURCE:
|
||||
#endif
|
||||
#if (MBEDTLS_VERSION_NUMBER < 0x03000000)
|
||||
case MBEDTLS_ERR_SSL_PEER_VERIFY_FAILED:
|
||||
#endif
|
||||
#if (MBEDTLS_VERSION_NUMBER <= 0x03060500)
|
||||
case MBEDTLS_ERR_THREADING_BAD_INPUT_DATA:
|
||||
#endif
|
||||
case MBEDTLS_ERR_THREADING_MUTEX_ERROR:
|
||||
error = kErrorSecurity;
|
||||
break;
|
||||
|
||||
Reference in New Issue
Block a user