From 6f6a1df84b8a725f72497ea3a45a6d9893fea81c Mon Sep 17 00:00:00 2001 From: Daniele Lacamera Date: Thu, 1 Oct 2026 14:44:49 +0200 Subject: [PATCH 1/5] prepare-release-v2.10.0: update submodules to latest releases wolfSSL v5.9.4-stable, wolfPSA v5.9.4, wolfCOSE v2.0.0; wolfHSM left at v1.5.0-8-g86dd6df. wolfPSA v5.9.4 changes the store Close return to int; wolfCOSE v2.0.0 splits the source into 15 files and drops the deprecated ES256 alg ID, so DICE now signs with ESP256. --- CMakeLists.txt | 15 +++++++++++++- lib/wolfCOSE | 2 +- lib/wolfPSA | 2 +- lib/wolfssl | 2 +- options.mk | 15 +++++++++++++- src/dice/dice.c | 8 ++++---- src/psa_store.c | 3 ++- tools/unit-tests/Makefile | 27 +++++++++++++++++++++++-- tools/unit-tests/unit-dice-token-size.c | 27 ++++++------------------- 9 files changed, 68 insertions(+), 33 deletions(-) diff --git a/CMakeLists.txt b/CMakeLists.txt index dddb367be8..4f42606ecd 100644 --- a/CMakeLists.txt +++ b/CMakeLists.txt @@ -566,8 +566,21 @@ endif() if(DEFINED WOLFCRYPT_TZ_PSA AND NOT WOLFCRYPT_TZ_PSA STREQUAL "0") list(APPEND WOLFBOOT_SOURCES "src/dice/dice.c") - list(APPEND WOLFBOOT_SOURCES "lib/wolfCOSE/src/wolfcose.c") list(APPEND WOLFBOOT_SOURCES "lib/wolfCOSE/src/wolfcose_cbor.c") + list(APPEND WOLFBOOT_SOURCES "lib/wolfCOSE/src/wolfcose_util.c") + list(APPEND WOLFBOOT_SOURCES "lib/wolfCOSE/src/wolfcose_alg.c") + list(APPEND WOLFBOOT_SOURCES "lib/wolfCOSE/src/wolfcose_ecc.c") + list(APPEND WOLFBOOT_SOURCES "lib/wolfCOSE/src/wolfcose_hdr.c") + list(APPEND WOLFBOOT_SOURCES "lib/wolfCOSE/src/wolfcose_key.c") + list(APPEND WOLFBOOT_SOURCES "lib/wolfCOSE/src/wolfcose_struct.c") + list(APPEND WOLFBOOT_SOURCES "lib/wolfCOSE/src/wolfcose_recipient.c") + list(APPEND WOLFBOOT_SOURCES "lib/wolfCOSE/src/wolfcose_sign1.c") + list(APPEND WOLFBOOT_SOURCES "lib/wolfCOSE/src/wolfcose_sign.c") + list(APPEND WOLFBOOT_SOURCES "lib/wolfCOSE/src/wolfcose_countersign.c") + list(APPEND WOLFBOOT_SOURCES "lib/wolfCOSE/src/wolfcose_encrypt0.c") + list(APPEND WOLFBOOT_SOURCES "lib/wolfCOSE/src/wolfcose_mac0.c") + list(APPEND WOLFBOOT_SOURCES "lib/wolfCOSE/src/wolfcose_encrypt.c") + list(APPEND WOLFBOOT_SOURCES "lib/wolfCOSE/src/wolfcose_mac.c") list(APPEND WOLFBOOT_INCLUDE_DIRS ${WOLFBOOT_ROOT}/lib/wolfCOSE/include) list(APPEND WOLFBOOT_DEFS WOLFCOSE_LEAN WOLFCOSE_ENABLE_EXT_SIGN) endif() diff --git a/lib/wolfCOSE b/lib/wolfCOSE index 588232e6f2..f907071b10 160000 --- a/lib/wolfCOSE +++ b/lib/wolfCOSE @@ -1 +1 @@ -Subproject commit 588232e6f2213133b48976f5cf3153b21fc7199c +Subproject commit f907071b10127f3ae2dd7719749a91b039ff04a1 diff --git a/lib/wolfPSA b/lib/wolfPSA index a4d11872c0..6de20d0c44 160000 --- a/lib/wolfPSA +++ b/lib/wolfPSA @@ -1 +1 @@ -Subproject commit a4d11872c0226b6fed328d13e7ac5dc3de1d62e4 +Subproject commit 6de20d0c44af8cda676f61c5d24879cbc2ea2ccc diff --git a/lib/wolfssl b/lib/wolfssl index 4aa1ad7a5b..3c5eead449 160000 --- a/lib/wolfssl +++ b/lib/wolfssl @@ -1 +1 @@ -Subproject commit 4aa1ad7a5b4f7be86d88cc26fe3880a31ff7de9f +Subproject commit 3c5eead44904df64e6a5a1f4ebdce377d35a849a diff --git a/options.mk b/options.mk index a99c556876..2717a9ec08 100644 --- a/options.mk +++ b/options.mk @@ -1250,8 +1250,21 @@ ifeq ($(WOLFCRYPT_TZ_PSA),1) WOLFCRYPT_OBJS+=src/psa_store.o WOLFCRYPT_OBJS+=src/arm_tee_psa_veneer.o WOLFCRYPT_OBJS+=src/arm_tee_psa_ipc.o - WOLFCRYPT_OBJS+=$(WOLFBOOT_LIB_WOLFCOSE)/src/wolfcose.o WOLFCRYPT_OBJS+=$(WOLFBOOT_LIB_WOLFCOSE)/src/wolfcose_cbor.o + WOLFCRYPT_OBJS+=$(WOLFBOOT_LIB_WOLFCOSE)/src/wolfcose_util.o + WOLFCRYPT_OBJS+=$(WOLFBOOT_LIB_WOLFCOSE)/src/wolfcose_alg.o + WOLFCRYPT_OBJS+=$(WOLFBOOT_LIB_WOLFCOSE)/src/wolfcose_ecc.o + WOLFCRYPT_OBJS+=$(WOLFBOOT_LIB_WOLFCOSE)/src/wolfcose_hdr.o + WOLFCRYPT_OBJS+=$(WOLFBOOT_LIB_WOLFCOSE)/src/wolfcose_key.o + WOLFCRYPT_OBJS+=$(WOLFBOOT_LIB_WOLFCOSE)/src/wolfcose_struct.o + WOLFCRYPT_OBJS+=$(WOLFBOOT_LIB_WOLFCOSE)/src/wolfcose_recipient.o + WOLFCRYPT_OBJS+=$(WOLFBOOT_LIB_WOLFCOSE)/src/wolfcose_sign1.o + WOLFCRYPT_OBJS+=$(WOLFBOOT_LIB_WOLFCOSE)/src/wolfcose_sign.o + WOLFCRYPT_OBJS+=$(WOLFBOOT_LIB_WOLFCOSE)/src/wolfcose_countersign.o + WOLFCRYPT_OBJS+=$(WOLFBOOT_LIB_WOLFCOSE)/src/wolfcose_encrypt0.o + WOLFCRYPT_OBJS+=$(WOLFBOOT_LIB_WOLFCOSE)/src/wolfcose_mac0.o + WOLFCRYPT_OBJS+=$(WOLFBOOT_LIB_WOLFCOSE)/src/wolfcose_encrypt.o + WOLFCRYPT_OBJS+=$(WOLFBOOT_LIB_WOLFCOSE)/src/wolfcose_mac.o WOLFCRYPT_OBJS+=$(WOLFBOOT_LIB_WOLFSSL)/wolfcrypt/src/pwdbased.o WOLFCRYPT_OBJS+=$(WOLFBOOT_LIB_WOLFSSL)/wolfcrypt/src/hmac.o WOLFCRYPT_OBJS+=$(WOLFBOOT_LIB_WOLFSSL)/wolfcrypt/src/dh.o diff --git a/src/dice/dice.c b/src/dice/dice.c index 11faf59c30..ea19528fd8 100644 --- a/src/dice/dice.c +++ b/src/dice/dice.c @@ -795,7 +795,7 @@ static int wolfboot_dice_hw_sign_cb(void *cbCtx, int32_t alg, (void)alg; - /* wolfCOSE pre-hashes the Sig_structure for ES256, so tbs is the 32-byte + /* wolfCOSE pre-hashes the Sig_structure for ESP256, so tbs is the 32-byte * digest. hal_dice_sign_hash() outputs 64-byte raw R||S and keeps the * private key inside the platform boundary. */ if (hal_dice_sign_hash(tbs, tbs_len, sig, &out_len) != 0) { @@ -846,7 +846,7 @@ static int NOINLINEFUNCTION wolfboot_dice_sign_payload( ret = WOLFBOOT_DICE_ERR_CRYPTO; goto cleanup; } - ret = wc_CoseSign1_Sign_ex(cose_key, WOLFCOSE_ALG_ES256, NULL, 0, + ret = wc_CoseSign1_Sign_ex(cose_key, WOLFCOSE_ALG_ESP256, NULL, 0, payload, payload_len, NULL, 0, NULL, 0, scratch, scratch_len, token_buf, token_buf_size, out_len, &rng, WOLFCOSE_SIGN1_UNTAGGED); @@ -901,7 +901,7 @@ static int wolfboot_dice_build_token(uint8_t *token_buf, /* Size query returns the exact untagged COSE_Sign1 length without signing: * the HW DICE engine must not run and the CDI must not advance while sizing. */ if (token_buf == NULL) { - ret = wc_CoseSign1_SignSize_ex(NULL, WOLFCOSE_ALG_ES256, 0, + ret = wc_CoseSign1_SignSize_ex(NULL, WOLFCOSE_ALG_ESP256, 0, payload_len, 0, WOLFCOSE_SIGN1_UNTAGGED, &out_len); if (ret == 0) { @@ -931,7 +931,7 @@ static int wolfboot_dice_build_token(uint8_t *token_buf, ret = WOLFBOOT_DICE_ERR_CRYPTO; goto cleanup; } - ret = wc_CoseSign1_Sign_ex(&cose_key, WOLFCOSE_ALG_ES256, NULL, 0, + ret = wc_CoseSign1_Sign_ex(&cose_key, WOLFCOSE_ALG_ESP256, NULL, 0, payload, payload_len, NULL, 0, NULL, 0, scratch, sizeof(scratch), token_buf, token_buf_size, &out_len, NULL, diff --git a/src/psa_store.c b/src/psa_store.c index 0eca425530..f4e4de3b62 100644 --- a/src/psa_store.c +++ b/src/psa_store.c @@ -493,10 +493,11 @@ int wolfPSA_Store_OpenSz(int type, unsigned long id1, unsigned long id2, int rea return wolfPSA_Store_Open(type, id1, id2, read, store); } -void wolfPSA_Store_Close(void* store) +int wolfPSA_Store_Close(void* store) { struct store_handle *handle = store; memset(handle, 0, sizeof(*handle)); + return 0; } int wolfPSA_Store_Read(void* store, unsigned char* buffer, int len) diff --git a/tools/unit-tests/Makefile b/tools/unit-tests/Makefile index 65cd55410a..d65816f77a 100644 --- a/tools/unit-tests/Makefile +++ b/tools/unit-tests/Makefile @@ -640,11 +640,34 @@ DICE_TOKEN_TEST_CFLAGS=-I$(WOLFBOOT_LIB_WOLFCOSE)/include \ unit-dice-token-size:CFLAGS+=$(DICE_TOKEN_TEST_CFLAGS) unit-dice-token-nosign:CFLAGS+=$(DICE_TOKEN_TEST_CFLAGS) -DWOLFBOOT_NO_SIGN DICE_TOKEN_TEST_SRC=unit-dice-token-size.c \ - $(WOLFBOOT_LIB_WOLFCOSE)/src/wolfcose.c \ $(WOLFBOOT_LIB_WOLFCOSE)/src/wolfcose_cbor.c \ + $(WOLFBOOT_LIB_WOLFCOSE)/src/wolfcose_util.c \ + $(WOLFBOOT_LIB_WOLFCOSE)/src/wolfcose_alg.c \ + $(WOLFBOOT_LIB_WOLFCOSE)/src/wolfcose_ecc.c \ + $(WOLFBOOT_LIB_WOLFCOSE)/src/wolfcose_hdr.c \ + $(WOLFBOOT_LIB_WOLFCOSE)/src/wolfcose_key.c \ + $(WOLFBOOT_LIB_WOLFCOSE)/src/wolfcose_struct.c \ + $(WOLFBOOT_LIB_WOLFCOSE)/src/wolfcose_recipient.c \ + $(WOLFBOOT_LIB_WOLFCOSE)/src/wolfcose_sign1.c \ + $(WOLFBOOT_LIB_WOLFCOSE)/src/wolfcose_sign.c \ + $(WOLFBOOT_LIB_WOLFCOSE)/src/wolfcose_countersign.c \ + $(WOLFBOOT_LIB_WOLFCOSE)/src/wolfcose_encrypt0.c \ + $(WOLFBOOT_LIB_WOLFCOSE)/src/wolfcose_mac0.c \ + $(WOLFBOOT_LIB_WOLFCOSE)/src/wolfcose_encrypt.c \ + $(WOLFBOOT_LIB_WOLFCOSE)/src/wolfcose_mac.c \ $(WOLFBOOT_LIB_WOLFSSL)/wolfcrypt/src/sha256.c \ $(WOLFBOOT_LIB_WOLFSSL)/wolfcrypt/src/hash.c \ - $(WOLFBOOT_LIB_WOLFSSL)/wolfcrypt/src/memory.c + $(WOLFBOOT_LIB_WOLFSSL)/wolfcrypt/src/memory.c \ + $(WOLFBOOT_LIB_WOLFSSL)/wolfcrypt/src/ecc.c \ + $(WOLFBOOT_LIB_WOLFSSL)/wolfcrypt/src/asn.c \ + $(WOLFBOOT_LIB_WOLFSSL)/wolfcrypt/src/logging.c \ + $(WOLFBOOT_LIB_WOLFSSL)/wolfcrypt/src/random.c \ + $(WOLFBOOT_LIB_WOLFSSL)/wolfcrypt/src/sp_c32.c \ + $(WOLFBOOT_LIB_WOLFSSL)/wolfcrypt/src/sp_c64.c \ + $(WOLFBOOT_LIB_WOLFSSL)/wolfcrypt/src/sp_int.c \ + $(WOLFBOOT_LIB_WOLFSSL)/wolfcrypt/src/tfm.c \ + $(WOLFBOOT_LIB_WOLFSSL)/wolfcrypt/src/wc_port.c \ + $(WOLFBOOT_LIB_WOLFSSL)/wolfcrypt/src/wolfmath.c unit-dice-token-size unit-dice-token-nosign: ../../include/target.h \ $(DICE_TOKEN_TEST_SRC) gcc -o $@ $(DICE_TOKEN_TEST_SRC) $(CFLAGS) $(LDFLAGS) \ diff --git a/tools/unit-tests/unit-dice-token-size.c b/tools/unit-tests/unit-dice-token-size.c index f2784cf21b..fb8584ff27 100644 --- a/tools/unit-tests/unit-dice-token-size.c +++ b/tools/unit-tests/unit-dice-token-size.c @@ -36,29 +36,14 @@ static unsigned int test_sign_calls; static int test_sign_result; /* Local ECC signing must never be reached: this test exercises the delegated - * hardware-signing path. These stubs keep that failure mode link-visible. */ -int wc_ecc_sign_hash(const byte *in, word32 in_len, byte *out, - word32 *out_len, WC_RNG *rng, ecc_key *key) -{ - (void)in; - (void)in_len; - (void)out; - (void)out_len; - (void)rng; - (void)key; - return -1; -} + * hardware-signing path. The real ecc.c is linked, so a stray local-sign call + * runs against the empty test key and fails the test. */ -int wc_ecc_sig_to_rs(const byte *sig, word32 sig_len, byte *r, - word32 *r_len, byte *s, word32 *s_len) +int hal_trng_get_entropy(unsigned char *out, unsigned len) { - (void)sig; - (void)sig_len; - (void)r; - (void)r_len; - (void)s; - (void)s_len; - return -1; + (void)out; + (void)len; + return 0; } int ext_flash_read(uintptr_t address, uint8_t *data, int len) From c3cc71503a965dd480c6cc8d7f88a09b4dda851e Mon Sep 17 00:00:00 2001 From: Daniele Lacamera Date: Thu, 1 Oct 2026 15:05:49 +0200 Subject: [PATCH 2/5] options: satisfy wolfPSA v5.9.4 build policy for TZ_PSA WC_ALLOW_ECC_ZERO_HASH and WOLFPSA_AES_FAST per the new psa_config.h checks (bitsliced AES blows the GCM stack budget), and exclude the new psa_store_zephyr.c from the custom-store build. --- options.mk | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/options.mk b/options.mk index 2717a9ec08..480716d25d 100644 --- a/options.mk +++ b/options.mk @@ -1233,6 +1233,8 @@ ifeq ($(WOLFCRYPT_TZ_PSA),1) CFLAGS+=-DWOLFBOOT_DICE_HW endif CFLAGS+=-DWOLFSSL_PSA_ENGINE + CFLAGS+=-DWC_ALLOW_ECC_ZERO_HASH + CFLAGS+=-DWOLFPSA_AES_FAST CFLAGS+=-DWOLFPSA_CUSTOM_STORE CFLAGS+=-DNO_DES3 -DNO_DES3_TLS_SUITES CFLAGS+=-I$(WOLFBOOT_LIB_WOLFCOSE)/include @@ -1272,7 +1274,8 @@ ifeq ($(WOLFCRYPT_TZ_PSA),1) ifeq ($(findstring random.o,$(WOLFCRYPT_OBJS)),) WOLFCRYPT_OBJS+=$(WOLFBOOT_LIB_WOLFSSL)/wolfcrypt/src/random.o endif - WOLFPSA_SRCS := $(filter-out $(WOLFBOOT_LIB_WOLFPSA)/src/psa_store_posix.c, \ + WOLFPSA_SRCS := $(filter-out $(WOLFBOOT_LIB_WOLFPSA)/src/psa_store_posix.c \ + $(WOLFBOOT_LIB_WOLFPSA)/src/psa_store_zephyr.c, \ $(wildcard $(WOLFBOOT_LIB_WOLFPSA)/src/*.c)) WOLFPSA_OBJS := $(patsubst %.c,%.o,$(WOLFPSA_SRCS)) WOLFCRYPT_OBJS+=$(WOLFPSA_OBJS) From 7b480de33a303a41e4fc25b206d2eb6ee4837c5b Mon Sep 17 00:00:00 2001 From: Daniele Lacamera Date: Thu, 1 Oct 2026 15:42:17 +0200 Subject: [PATCH 3/5] prepare-release-v2.10.0: release notes and version bump --- README.md | 62 ++++++++++++++++++++++++++++++++++++++ include/wolfboot/version.h | 4 +-- 2 files changed, 64 insertions(+), 2 deletions(-) diff --git a/README.md b/README.md index d7e0f41dfa..10c37fbd70 100644 --- a/README.md +++ b/README.md @@ -758,3 +758,65 @@ For Visual Studio, the developer command prompt will need to be activated. * wolfHSM v1.4.0-245-g7c6359e * wolfHAL (4744f20) * wolfPSA v5.9.1-58-ga4d1187 + +### V 2.10.0 - (2026-10-01) + * New hardware targets + * NXP i.MX RT700 (MIMXRT798S): XSPI0 NOR boot, TrustZone secure application, ML-DSA-87 signed-boot config, m33mu emulator tests in CI + * Raspberry Pi Compute Module 4 (BCM2711 Cortex-A72): authenticated boot, hardware-validated eMMC A/B disk boot, wolfCrypt FIPS 140-3 + * NXP i.MX 8QuadMax MEK port including BL33 support + * NXP i.MX95 Cortex-M7 target + * NVIDIA Tegra234 bare-metal BL33 with verified EL2->EL1 handoff and device-tree boot + * AURIX TC4xx support (host and CSRM cores) + * TI C28x (TMS320F28P550SJ) secure-boot XIP port + * wolfBoot as an AArch64 UEFI application + * Nuvoton NuMaker M2354 Cortex-M23 with TrustZone and emulator tests + * MAX32666 (Maxim): SHA256 acceleration, FTHR2 board, legacy LPSDK support + * RealTek RTL8735B (AmebaPro2) HAL port + * Improvements to supported targets + * x86 FSP: Linux bzImage + initrd payload with the 64-bit boot protocol, OS image PCR measurement, FSP UPD decoder tool, debug UART selection, and Tiger Lake NotifyPhase reset handling + * ZynqMP: FSBL with signed FIT Linux boot and EL3 security (eFuse/PUF/AES-CSU), non-cacheable DMA window, optional PHY init over GEM MDIO + * Disk boot: read-only FAT32 and ext4 filesystem support, signed image load from a file, optional boot confirmation and rollback, big-endian MBR/GPT parsing; first big-endian disk-boot target is the T1040 eSDHC SD card + * LS1028A: eSDHC SD card disk boot and ENETC wolfIP support + * PolarFire SoC: LPDDR4 DDR init and a minimal SBI runtime booting 4-CPU SMP Yocto Linux + * wolfIP support for NXP T2080 (+ NAII 68PPC2), T10xx (T1024/T1040), and LS1028A, plus a wolfIP + wolfCrypt test harness in the test app + * STM32H5: generic secure application handoff with a measured boot record, fwTPM secure RAM budget and stack sizing + * Renesas RX: generic watchdog feed hook and RX driver, GCC 8.3/14.2 build fixes, CI coverage + * pic32cz: wolfHSM client target with verified-boot console + * STM32U5: ARM Compiler for Embedded support and UART driver + * AURIX TC3: DFLASH mode exposed as an option + * Replaced the duplicated NS16550 console code with a shared UART driver + * New features and improvements + * DICE attestation via wolfCOSE (new submodule); tokens are now signed with the RFC 9864 ESP256 algorithm identifier + * AArch64 UEFI: kernel command line authentication via a signed HDR_CMDLINE manifest TLV, kernel measurement into the firmware TPM via EFI_TCG2 + * Pre-boot hook, DTB accessor, and FDT alias/reg helpers + * Asymmetric partition sizing for monolithic self-update + * Rewrote the FDT parser with capacity bound and full validation + * Multiboot2: u32 request-list entries per spec v2.0, zero entries as padding, end-tag termination + * Signing tools: file-backed custom TLV, custom TLV size limit raised to UINT16_MAX, --custom-tlv-pubkey-der, auxiliary algorithms and cert chain/TPM usage, removed the 14-argument limit + * wolfHSM: exposed max verify roots in options.mk, target-independent client build + * SBOM: vendored wolfGlass tooling, SBOMs from every build system and per-target config, CI drift check, registered wolfBoot CPE, identification of the embedded wolfSSL + * Removed the obsolete python keytools; all users converted to C + * Added CONTRIBUTING.md covering the contributor agreement and PR process + * Bug fixes and hardening + * Continued Fenrir-driven hardening across image parsing, disk, and HAL paths (241 findings) + * Expanded zeroization: TRNG staging buffers, TPM auth slots, DICE private scalars, ECDSA r/s scalars, PKCS11 login PIN, NSC bounce buffers, NVM_CACHE, RMW scratch and passphrase buffers; key tools now read/write secrets unbuffered to avoid stdio copies + * Bounded and validated ELF scatter segments, FIT subimages, GPT/MBR structures, TLV budgets, delta base hashes, PCI pools (including the 4 GiB boundary), and SDHCI/SD card init polling + * Propagated flash write/erase errors across HALs (STM32, nRF, HiFive1, Kinetis, TI Hercules, cc26x2, mcxw, MAX32666, samr21, pic32cz), plus SDHCI clock, NAND status/ECC, and OctoSPI status results + * Fixed encrypted read-modify-write: decrypt the stored block before patching, bound staged ciphertext, added a positive E2E encrypted-update test + * Fixed swap resume from BACKUP, abort the swap on sector copy failure, and the DISABLE_BACKUP update-consumption path (trailer erase) + * Added a ram_decrypt overlap guard so a decrypted image cannot clobber wolfBoot + * Fixed SDHCI silent read failures and the unbootable warm reset with UHS-I cards + * Fixed the 32-bit and partial-word fast paths in hal_flash_write on nRF52/nRF5340/STM32L0/L4/WB and RP2350 + * P1021 NAND: bad-block markers per erase block, ECC result checks, FBCR byte count fix + * Hardened the ARMORED digest comparison against instruction-skip fault injection + * Kept wolfBoot API declarations visible to app builds; marked wolfBoot_invalidate_hdr_cache RAMFUNCTION + * wolfHSM: freed keys on setup error paths, fixed DER sig length and full-width ECC raw sig conversion + * Signing tools: scrubbed key material on load failure, freed the RNG on all exit paths, propagated make_header() failures to the exit status + * Updated modules + * wolfSSL v5.9.4-stable + * wolfTPM v4.2.0 + * wolfPKCS11 v2.1.0-stable + * wolfHSM v1.5.0-8-g86dd6df + * wolfHAL 63cedc8 + * wolfPSA v5.9.4 + * wolfCOSE v2.0.0 diff --git a/include/wolfboot/version.h b/include/wolfboot/version.h index 0fb2b204c7..f5a45d7cc2 100644 --- a/include/wolfboot/version.h +++ b/include/wolfboot/version.h @@ -29,8 +29,8 @@ extern "C" { #endif -#define LIBWOLFBOOT_VERSION_STRING "2.9.0" -#define LIBWOLFBOOT_VERSION_HEX 0x02090000 +#define LIBWOLFBOOT_VERSION_STRING "2.10.0" +#define LIBWOLFBOOT_VERSION_HEX 0x02100000 #ifndef WOLFBOOT_VERSION #define WOLFBOOT_VERSION LIBWOLFBOOT_VERSION_HEX From 3edf517d4b52b2f3933d1553c04a8df687c37b31 Mon Sep 17 00:00:00 2001 From: Daniele Lacamera Date: Thu, 1 Oct 2026 16:15:10 +0200 Subject: [PATCH 4/5] wolfPSA: point at the released v5.9.4 tag --- lib/wolfPSA | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/lib/wolfPSA b/lib/wolfPSA index 6de20d0c44..55ae0ec58c 160000 --- a/lib/wolfPSA +++ b/lib/wolfPSA @@ -1 +1 @@ -Subproject commit 6de20d0c44af8cda676f61c5d24879cbc2ea2ccc +Subproject commit 55ae0ec58cd2ef4c528f44e8466095550c16ca8a From f56551ab74892b3389cb3a3f356ee51557653724 Mon Sep 17 00:00:00 2001 From: Daniele Lacamera Date: Thu, 1 Oct 2026 17:20:43 +0200 Subject: [PATCH 5/5] address PR 918 review: TOUCH_LINES AES, finish ESP256 migration in docs WOLFPSA_AES_FAST replaced with WOLFSSL_AES_TOUCH_LINES per the wolfPSA 5.9.4 constant-time policy; DICE.md and the MCXN verifier comment now say ESP256 and state the RFC 9783 legacy-ID compatibility note. --- docs/DICE.md | 5 ++++- options.mk | 2 +- test-app/app_mcxn.c | 2 +- 3 files changed, 6 insertions(+), 3 deletions(-) diff --git a/docs/DICE.md b/docs/DICE.md index b8a5e197bf..4261e0d9a0 100644 --- a/docs/DICE.md +++ b/docs/DICE.md @@ -23,7 +23,10 @@ an attestation key derived by DICE or supplied as a provisioned IAK. The implementation lives under `src/dice/` and is shared across targets. The service is invoked through the PSA Initial Attestation API and builds the EAT claim set with wolfCOSE's CBOR API. wolfCOSE then wraps and signs the -payload as an untagged COSE_Sign1 object using ES256. Hardware DICE targets use +payload as an untagged COSE_Sign1 object using ESP256 (RFC 9864). The +signature is standard P-256/SHA-256 ECDSA; only the COSE algorithm +identifier differs from the legacy ES256 ID that strict RFC 9783 Sign1 +tokens use, so profile verifiers must accept ESP256. Hardware DICE targets use wolfCOSE's external-signer callback so the attestation private key never leaves the platform security boundary. Token-size queries use wolfCOSE's prediction API and do not derive a key, advance the CDI, or invoke a signer. diff --git a/options.mk b/options.mk index 480716d25d..cd8719d03d 100644 --- a/options.mk +++ b/options.mk @@ -1234,7 +1234,7 @@ ifeq ($(WOLFCRYPT_TZ_PSA),1) endif CFLAGS+=-DWOLFSSL_PSA_ENGINE CFLAGS+=-DWC_ALLOW_ECC_ZERO_HASH - CFLAGS+=-DWOLFPSA_AES_FAST + CFLAGS+=-DWOLFSSL_AES_TOUCH_LINES CFLAGS+=-DWOLFPSA_CUSTOM_STORE CFLAGS+=-DNO_DES3 -DNO_DES3_TLS_SUITES CFLAGS+=-I$(WOLFBOOT_LIB_WOLFCOSE)/include diff --git a/test-app/app_mcxn.c b/test-app/app_mcxn.c index 04e2a7c3f3..b3a3c619b4 100644 --- a/test-app/app_mcxn.c +++ b/test-app/app_mcxn.c @@ -271,7 +271,7 @@ static int run_attest_verify_test(void) return -1; } - /* 6. Import IAK public key and verify ES256 signature (raw R||S, 64 bytes) */ + /* 6. Import IAK public key and verify the ESP256 signature (raw R||S, 64 bytes) */ psa_set_key_type(&attrs, PSA_KEY_TYPE_ECC_PUBLIC_KEY(PSA_ECC_FAMILY_SECP_R1)); psa_set_key_bits(&attrs, 256); psa_set_key_usage_flags(&attrs, PSA_KEY_USAGE_VERIFY_HASH);