mbedtls: access mbedtls private members in mscode and pkcs7 parser
U-Boot requires to access x509_internal.h, mbedtls_sha256_context and mbedtls_sha1_context in the porting layer, and this requires to enable MBEDTLS_ALLOW_PRIVATE_ACCESS. Enable it to mscode and pkcs7_parser to fix a mbedtls internal building error when X509 is selected. Moreover, Move it to a separate file to avoid enabling it in multiple places. Signed-off-by: Raymond Mao <raymond.mao@linaro.org> Acked-by: Ilias Apalodimas <ilias.apalodimas@linaro.org>
This commit is contained in:
@@ -10,6 +10,7 @@
|
|||||||
#include <crypto/hash_info.h>
|
#include <crypto/hash_info.h>
|
||||||
#endif
|
#endif
|
||||||
#if CONFIG_IS_ENABLED(MBEDTLS_LIB_X509)
|
#if CONFIG_IS_ENABLED(MBEDTLS_LIB_X509)
|
||||||
|
#include "mbedtls_options.h"
|
||||||
#include <mbedtls/asn1.h>
|
#include <mbedtls/asn1.h>
|
||||||
#include <mbedtls/oid.h>
|
#include <mbedtls/oid.h>
|
||||||
#endif
|
#endif
|
||||||
|
@@ -12,6 +12,7 @@
|
|||||||
#include <crypto/pkcs7.h>
|
#include <crypto/pkcs7.h>
|
||||||
#include <crypto/x509_parser.h>
|
#include <crypto/x509_parser.h>
|
||||||
#if CONFIG_IS_ENABLED(MBEDTLS_LIB_X509)
|
#if CONFIG_IS_ENABLED(MBEDTLS_LIB_X509)
|
||||||
|
#include "mbedtls_options.h"
|
||||||
#include <mbedtls/pkcs7.h>
|
#include <mbedtls/pkcs7.h>
|
||||||
#include <library/x509_internal.h>
|
#include <library/x509_internal.h>
|
||||||
#include <mbedtls/asn1.h>
|
#include <mbedtls/asn1.h>
|
||||||
|
@@ -18,17 +18,7 @@
|
|||||||
#include <linux/types.h>
|
#include <linux/types.h>
|
||||||
|
|
||||||
#if CONFIG_IS_ENABLED(MBEDTLS_LIB_CRYPTO)
|
#if CONFIG_IS_ENABLED(MBEDTLS_LIB_CRYPTO)
|
||||||
/*
|
#include "mbedtls_options.h"
|
||||||
* FIXME:
|
|
||||||
* MbedTLS define the members of "mbedtls_sha256_context" as private,
|
|
||||||
* but "state" needs to be access by arch/arm/cpu/armv8/sha1_ce_glue.
|
|
||||||
* MBEDTLS_ALLOW_PRIVATE_ACCESS needs to be enabled to allow the external
|
|
||||||
* access.
|
|
||||||
* Directly including <external/mbedtls/library/common.h> is not allowed,
|
|
||||||
* since this will include <malloc.h> and break the sandbox test.
|
|
||||||
*/
|
|
||||||
#define MBEDTLS_ALLOW_PRIVATE_ACCESS
|
|
||||||
|
|
||||||
#include <mbedtls/sha1.h>
|
#include <mbedtls/sha1.h>
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
|
@@ -7,17 +7,7 @@
|
|||||||
#include <linux/types.h>
|
#include <linux/types.h>
|
||||||
|
|
||||||
#if CONFIG_IS_ENABLED(MBEDTLS_LIB_CRYPTO)
|
#if CONFIG_IS_ENABLED(MBEDTLS_LIB_CRYPTO)
|
||||||
/*
|
#include "mbedtls_options.h"
|
||||||
* FIXME:
|
|
||||||
* MbedTLS define the members of "mbedtls_sha256_context" as private,
|
|
||||||
* but "state" needs to be access by arch/arm/cpu/armv8/sha256_ce_glue.
|
|
||||||
* MBEDTLS_ALLOW_PRIVATE_ACCESS needs to be enabled to allow the external
|
|
||||||
* access.
|
|
||||||
* Directly including <external/mbedtls/library/common.h> is not allowed,
|
|
||||||
* since this will include <malloc.h> and break the sandbox test.
|
|
||||||
*/
|
|
||||||
#define MBEDTLS_ALLOW_PRIVATE_ACCESS
|
|
||||||
|
|
||||||
#include <mbedtls/sha256.h>
|
#include <mbedtls/sha256.h>
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
|
23
lib/mbedtls/port/mbedtls_options.h
Normal file
23
lib/mbedtls/port/mbedtls_options.h
Normal file
@@ -0,0 +1,23 @@
|
|||||||
|
/* SPDX-License-Identifier: GPL-2.0+ */
|
||||||
|
/*
|
||||||
|
* Internal build options for MbedTLS
|
||||||
|
*
|
||||||
|
* Copyright (c) 2025 Linaro Limited
|
||||||
|
* Author: Raymond Mao <raymond.mao@linaro.org>
|
||||||
|
*/
|
||||||
|
|
||||||
|
#ifndef _MBEDTLS_OPT_H
|
||||||
|
#define _MBEDTLS_OPT_H
|
||||||
|
|
||||||
|
/*
|
||||||
|
* FIXME:
|
||||||
|
* U-Boot/MbedTLS port requires to access a few of members which are defined
|
||||||
|
* as private in MbedTLS context.
|
||||||
|
* E.g: x509_internal.h, mbedtls_sha256_context and mbedtls_sha1_context.
|
||||||
|
* MBEDTLS_ALLOW_PRIVATE_ACCESS needs to be enabled to allow the external
|
||||||
|
* access, but directly including <external/mbedtls/library/common.h> is not
|
||||||
|
* allowed, since this will include <malloc.h> and break the sandbox test.
|
||||||
|
*/
|
||||||
|
#define MBEDTLS_ALLOW_PRIVATE_ACCESS
|
||||||
|
|
||||||
|
#endif /* _MBEDTLS_OPT_H */
|
Reference in New Issue
Block a user