mirror of https://github.com/wolfSSL/wolfBoot.git
libwolfboot: scrub the key cache on the static-buffer builds
The exit_lock scrub was guarded to the case where ENCRYPT_CACHE is a stack local, skipping both static ones -- NVM_FLASH_WRITEONCE aliases it to NVM_CACHE, WOLFBOOT_SMALL_STACK gives it its own array. Those are exactly the buffers where the plaintext key and nonce would stay resident for the rest of the boot.pull/862/head
parent
597283ad8d
commit
c7f277f495
|
|
@ -2016,8 +2016,13 @@ static int RAMFUNCTION hal_set_key(const uint8_t *k, const uint8_t *nonce)
|
|||
ret = hal_flash_erase(addr_align, WOLFBOOT_SECTOR_SIZE);
|
||||
#endif
|
||||
exit_lock:
|
||||
#if !defined(WOLFBOOT_SMALL_STACK) && !defined(NVM_FLASH_WRITEONCE) && \
|
||||
!defined(WOLFBOOT_ENCRYPT_CACHE)
|
||||
/* The raw key and nonce were staged in ENCRYPT_CACHE above. Scrub it
|
||||
* on every build where wolfBoot owns the buffer: the two static
|
||||
* cases -- NVM_FLASH_WRITEONCE aliases ENCRYPT_CACHE to NVM_CACHE,
|
||||
* WOLFBOOT_SMALL_STACK gives it its own static array -- are exactly
|
||||
* the ones where the plaintext would otherwise stay resident for the
|
||||
* rest of the boot. Only a caller-supplied buffer is left alone. */
|
||||
#if !defined(WOLFBOOT_ENCRYPT_CACHE)
|
||||
ForceZero(ENCRYPT_CACHE, NVM_CACHE_SIZE);
|
||||
#endif
|
||||
hal_flash_lock();
|
||||
|
|
|
|||
Loading…
Reference in New Issue