Repository navigation
Conversation
There was a problem hiding this comment.
🟡 Changes recommended
The PSA seed override remains unprotected, the new API breaks C++ linkage, and its Zeroize documentation contradicts its implementation.
4 open findings
What changed in this PR
Adds a simplified LPC55S69 hardware PUF API for generating and retrieving 16-, 24-, and 32-byte keys.
Changes:
- Adds HWPUF lifecycle, key-management APIs, error codes, and documentation.
- Updates NXP HashCrypt AES and SHA-256 test handling.
- Preserves custom PSA random-block generators.
| File | Description |
|---|---|
.wolfssl_known_macro_extras |
Registers the HWPUF feature macro. |
wolfcrypt/src/aes.c |
Ensures HashCrypt retains raw AES keys. |
wolfcrypt/src/error.c |
Adds HWPUF error strings. |
wolfcrypt/src/include.am |
Distributes the HWPUF source. |
wolfcrypt/src/port/nxp/README.md |
Documents HWPUF usage and lifecycle. |
wolfcrypt/src/port/nxp/hashcrypt_port.c |
Adds HashCrypt AES-CTR key setup. |
wolfcrypt/src/port/nxp/hwpuf_port.c |
Implements the HWPUF API. |
wolfcrypt/test/test.c |
Skips an incompatible interleaved SHA-256 test. |
wolfssl/wolfcrypt/error-crypt.h |
Defines HWPUF error codes. |
wolfssl/wolfcrypt/include.am |
Registers the HWPUF header. |
wolfssl/wolfcrypt/port/nxp/hwpuf_port.h |
Declares the HWPUF API. |
wolfssl/wolfcrypt/port/psa/psa.h |
Guards a custom RNG block override. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #11700
Scan targets checked: wolfcrypt-src, wolfcrypt-bugs, wolfcrypt-port-bugs, wolfssl-src, wolfssl-bugs
Coverage: 4 of 8 in-scope changed file(s) opened by the reviewer; not opened: wolfcrypt/src/error.c, wolfssl/wolfcrypt/error-crypt.h, wolfssl/wolfcrypt/port/nxp/hwpuf_port.h, wolfssl/wolfcrypt/port/psa/psa.h
Findings: 1
1 finding(s) posted as inline comments (see file-level comments below)
This review was generated automatically by Fenrir. Reported findings require changes before merge.
Review tier: Lite


Description
This adds a simplified lpc55s69 hardware puf api to wolfCrypt, which supports generating/retrieving keys of size 16, 24, 32 bytes.
Note: this pr goes with wolfSSL/wolfBoot#787
Testing
Tested on hardware with device attestation example in wolfBoot.
Checklist