Repository navigation
Conversation
Contributor
There was a problem hiding this comment.
🟡 Changes recommended
CMake integration is missing, and the new test breaks no-filesystem builds while allowing non-ELE hardware RNGs to pass.
4 open findings
What changed in this PR
Adds an NXP EdgeLock Secure Enclave crypto-callback port that sources TRNG entropy through Linux /dev/hwrng.
Changes:
- Adds ELE TRNG and crypto-callback implementations.
- Adds Autotools configuration, headers, settings, and documentation.
- Adds an ELE hardware test.
| File | Description |
|---|---|
.wolfssl_known_macro_extras |
Registers ELE configuration macros. |
configure.ac |
Adds --enable-ele. |
wolfcrypt/src/include.am |
Builds and distributes ELE sources. |
wolfcrypt/src/port/nxp/README.md |
Documents configuration and usage. |
wolfcrypt/src/port/nxp/ele_cryptocb.c |
Implements callback registration and routing. |
wolfcrypt/src/port/nxp/ele_rng.c |
Reads entropy from the hwrng device. |
wolfcrypt/test/test.c |
Adds the ELE TRNG test. |
wolfssl/wolfcrypt/include.am |
Installs the ELE public header. |
wolfssl/wolfcrypt/port/nxp/ele.h |
Declares the ELE API. |
wolfssl/wolfcrypt/settings.h |
Defines ELE defaults and callback settings. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
+5155
to
+5158
| AC_ARG_ENABLE([ele], | ||
| [AS_HELP_STRING([--enable-ele],[Enable NXP EdgeLock Secure Enclave support (default: disabled)])], | ||
| [ENABLED_ELE=$enableval], | ||
| [ENABLED_ELE=no]) |
Comment on lines
+98190
to
+98191
| #if defined(WOLFSSL_NXP_ELE) && defined(WOLFSSL_NXP_ELE_TRNG) && \ | ||
| !defined(WC_NO_RNG) |
Comment on lines
+98206
to
+98209
| f = XFOPEN(WOLFSSL_NXP_ELE_TRNG_DEVICE, "rb"); | ||
| if (f == XBADFILE) | ||
| return 0; /* no accessible enclave TRNG on this machine */ | ||
| XFCLOSE(f); |
| extern "C" { | ||
| #endif | ||
|
|
||
| /* 0 on success, WC_HW_E or RNG_FAILURE_E on error. */ |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Description
Adds a wolfCrypt crypto-callback port for the NXP EdgeLock Secure Enclave (ELE), which replaces CAAM on i.MX 8ULP / 93 / 95. TRNG only: every other algorithm returns
CRYPTOCB_UNAVAILABLE, so wolfCrypt falls back to software and applications need no conditional code. The enclave TRNG arrives through the Linux hwrng framework, so the port pulls in no NXP userspace library and no vendor SDK headers, and builds anywhere.wolfcrypt/src/port/nxp/ele_rng.c,ele_cryptocb.c- the TRNG and the callback device, devId0x454C45wolfssl/wolfcrypt/port/nxp/ele.h- public API; the settings macros sit inline inwolfssl/wolfcrypt/settings.h--enable-ele, and an ELE section inwolfcrypt/src/port/nxp/README.mdRegistration is left to the application rather than done from
wolfCrypt_Init()the way some ports do it: the hwrng node is root-only by default, so registering unconditionally would turn every RNG call in an unprivileged process into a failure instead of letting it use software.Testing
Validated on a Toradex SMARC i.MX95 under Torizon OS, where
/sys/class/misc/hw_random/rng_currentreadsele-trng. Registering the device and callingwc_InitRng_ex()with its devId yields entropy as root and fails unprivileged, because the node is root-only - that difference is what establishes the enclave is really being reached, since a test that tolerates the software fallback passes either way.wolfcrypt/testgained anele_trng_testthat checks the node is readable before requiring entropy, so it is a clean skip on a machine without the enclave. On a Linux host--enable-elepassesmake checkandtestwolfcrypt, and a default build with the option off is unaffected.