Prepare release v2.10.0 - #918
Merged
Merged
Conversation
wolfSSL v5.9.4-stable, wolfPSA v5.9.4, wolfCOSE v2.0.0; wolfHSM left at v1.5.0-8-g86dd6df. wolfPSA v5.9.4 changes the store Close return to int; wolfCOSE v2.0.0 splits the source into 15 files and drops the deprecated ES256 alg ID, so DICE now signs with ESP256.
WC_ALLOW_ECC_ZERO_HASH and WOLFPSA_AES_FAST per the new psa_config.h checks (bitsliced AES blows the GCM stack budget), and exclude the new psa_store_zephyr.c from the custom-store build.
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The PSA configuration enables non-constant-time AES, and the ESP256 migration conflicts with the advertised attestation profile.
Review effort: Balanced
Findings: 1
Open (2)
What changed in this PR
Prepares wolfBoot v2.10.0 and aligns integrations with updated wolfCOSE and wolfPSA APIs.
Changes:
- Bumps the public version and adds release notes.
- Migrates wolfCOSE builds to modular sources and ESP256.
- Updates wolfPSA configuration, storage API, and DICE tests.
| File | Description |
|---|---|
README.md |
Adds the v2.10.0 changelog. |
include/wolfboot/version.h |
Bumps the version to 2.10.0. |
src/dice/dice.c |
Migrates attestation signatures to ESP256. |
src/psa_store.c |
Updates the store-close API. |
options.mk |
Updates wolfCOSE/wolfPSA build configuration. |
CMakeLists.txt |
Adds modular wolfCOSE sources. |
tools/unit-tests/Makefile |
Updates DICE test dependencies. |
tools/unit-tests/unit-dice-token-size.c |
Uses the real ECC implementation in tests. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
WOLFPSA_AES_FAST replaced with WOLFSSL_AES_TOUCH_LINES per the wolfPSA 5.9.4 constant-time policy; DICE.md and the MCXN verifier comment now say ESP256 and state the RFC 9783 legacy-ID compatibility note.
dgarske
approved these changes
Oct 1, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Update submodules, versions, changelog.