Skip to content

Ensure the casper and hashcrypt accelerator functions are using mutexes - #11315

Open
AlexLanzano wants to merge 1 commit into
wolfSSL:masterfrom
AlexLanzano:casper-fix
Open

AlexLanzano wants to merge 1 commit into
wolfSSL:masterfrom
AlexLanzano:casper-fix

Conversation

@AlexLanzano

@AlexLanzano AlexLanzano commented Aug 30, 2026 •

Copy link
Copy Markdown
Member

Serialize NXP CASPER and HashCrypt accelerator access

The LPC55S69 CASPER and HashCrypt ports did no locking. They also refused to build with WOLFSSL_CRYPT_HW_MUTEX=1, which FreeRTOS builds turn on automatically.

Changes

  • CASPER: RSA public exptmod and ECC mulmod/mul2add now hold the PK HW mutex for the whole hardware sequence. wc_casper_init() initializes that mutex.
  • HashCrypt: all SHA-1/SHA-256 and AES (ECB, CBC, OFB, CFB, CTR) operations now hold the global crypt HW mutex. AES and SHA run on the same engine, so they share one
    lock.
  • wc_port.h: WOLFSSL_CRYPT_HW_MUTEX is enabled automatically for CASPER and HashCrypt. A threaded build that sets it to 0 now fails to compile.
  • README: documents the locking and the existing single SHA stream and no SHA-224 limitations.

@AlexLanzano AlexLanzano self-assigned this Aug 30, 2026
Copilot AI lite review requested due to automatic review settings August 30, 2026 20:23

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR tightens thread-safety guarantees for the NXP CASPER and HashCrypt hardware acceleration ports by ensuring they consistently serialize access to shared peripherals/state via the wolfCrypt crypto HW mutex, and by preventing builds that would silently compile out that serialization.

Changes:

  • Auto-enable WOLFSSL_CRYPT_HW_MUTEX for NXP CASPER/HashCrypt and add a compile-time error when those ports are enabled in non-SINGLE_THREADED builds with the mutex forced off.
  • Add crypto HW mutex initialization and lock/unlock coverage around HashCrypt SHA/AES operations.
  • Add PK mutex initialization and lock/unlock coverage around CASPER RSA/ECC operations; update NXP port README to document the serialization and limitations.

Reviewed changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated 1 comment.

File Description
wolfssl/wolfcrypt/wc_port.h Auto-enables crypto HW mutex for CASPER/HashCrypt and adds a compile-time guard against disabling it in threaded builds.
wolfcrypt/src/port/nxp/README.md Documents HashCrypt behavior constraints and the mutex-based serialization requirement/limitations.
wolfcrypt/src/port/nxp/hashcrypt_port.c Adds crypto HW mutex init + locking around HashCrypt SHA/AES operations to serialize shared engine access.
wolfcrypt/src/port/nxp/casper_port.c Adds PK mutex init + locking around CASPER RSA/ECC operations to serialize shared peripheral and scratch buffers.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread wolfcrypt/src/port/nxp/hashcrypt_port.c Outdated
@wolfSSL-Bot

Copy link
Copy Markdown

Can one of the admins verify this patch?

@AlexLanzano
AlexLanzano force-pushed the casper-fix branch 2 times, most recently from 1b2ddb4 to c4274e4 Compare September 22, 2026 16:44
@AlexLanzano
AlexLanzano marked this pull request as ready for review September 22, 2026 16:53
@AlexLanzano
AlexLanzano requested a lite review from Copilot September 22, 2026 16:54

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Warning

Copilot couldn't run its full agentic review because it didn't start before the timeout. Make sure your repository has a runner available, or add a copilot-code-review.yml file specifying one with the runs-on attribute. See the docs for more details.

Copilot review overview

Review effort: Lite
Findings: 4 High severity · 1 Medium severity

Open (5)
Resolved since last review (1)

Comment thread wolfcrypt/src/port/nxp/hashcrypt_port.c
Comment thread wolfcrypt/src/port/nxp/hashcrypt_port.c
Comment thread wolfcrypt/src/port/nxp/hashcrypt_port.c
Comment thread wolfcrypt/src/port/nxp/hashcrypt_port.c
Comment thread wolfcrypt/src/port/nxp/hashcrypt_port.c
@github-actions

Copy link
Copy Markdown

retest this please

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #11315

Scan targets checked: wolfcrypt-src, wolfcrypt-bugs, wolfcrypt-port-bugs, wolfssl-src, wolfssl-bugs
Coverage: 3 of 3 in-scope changed file(s) opened by the reviewer

Fenrir result: Approved ✅

No new issues found in the changed files.

Advisory only — this automated result does not count as a GitHub approval.

Review tier: Lite

@philljj philljj left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

merge conflict in wc_port.h

@philljj philljj assigned AlexLanzano and unassigned wolfSSL-Bot Oct 2, 2026
@AlexLanzano
AlexLanzano requested a review from philljj October 5, 2026 00:36
@AlexLanzano AlexLanzano removed their assignment Oct 5, 2026
@philljj

philljj commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Retest this please.

(test aborted from network)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants