Compare commits

..

1 Commits

Author SHA1 Message Date
feedc0de 6213a906c0 Allow the https server to request client certs only with OPTIONAL 2025-09-23 17:08:13 +02:00
7 changed files with 9 additions and 75 deletions
+3
View File
@@ -282,6 +282,9 @@ typedef struct esp_tls_cfg_server {
unsigned int cacert_pem_bytes; /*!< Size of client CA certificate legacy name */
};
bool cacert_authmode_optional; /*!< Enable this option to set the authmode
to OPTIONAL (only useful when cacert is set) */
union {
const unsigned char *servercert_buf; /*!< Server certificate in a buffer
This buffer should be NULL terminated */
+2
View File
@@ -694,6 +694,8 @@ static esp_err_t set_server_config(esp_tls_cfg_server_t *cfg, esp_tls_t *tls)
if (esp_ret != ESP_OK) {
return esp_ret;
}
if (cfg->cacert_authmode_optional)
mbedtls_ssl_conf_authmode(&tls->conf, MBEDTLS_SSL_VERIFY_OPTIONAL);
} else {
#ifdef CONFIG_ESP_TLS_SERVER_MIN_AUTH_MODE_OPTIONAL
mbedtls_ssl_conf_authmode(&tls->conf, MBEDTLS_SSL_VERIFY_OPTIONAL);
@@ -91,6 +91,9 @@ struct httpd_ssl_config {
/** CA certificate byte length */
size_t cacert_len;
/** CA certificate verification optional */
bool cacert_authmode_optional;
/** Private key */
const uint8_t *prvtkey_pem;
@@ -278,6 +278,7 @@ static esp_err_t create_secure_context(const struct httpd_ssl_config *config, ht
cfg->userdata = config->ssl_userdata;
cfg->alpn_protos = config->alpn_protos;
cfg->tls_handshake_timeout_ms = config->tls_handshake_timeout_ms;
cfg->cacert_authmode_optional = config->cacert_authmode_optional;
#if defined(CONFIG_ESP_HTTPS_SERVER_CERT_SELECT_HOOK)
cfg->cert_select_cb = config->cert_select_cb;
@@ -18,9 +18,6 @@ extern "C" {
#include "esp_err.h"
#include "esp_cpu.h"
#include "freertos/FreeRTOS.h"
#include "freertos/task.h"
/*
* @brief Structure used for backtracing
*
@@ -132,8 +129,6 @@ esp_err_t esp_backtrace_print(int depth);
*/
esp_err_t esp_backtrace_print_all_tasks(int depth);
esp_err_t esp_backtrace_print_task(TaskHandle_t pxTask, int depth, bool panic);
/**
* @brief Set a watchpoint to break/panic when a certain memory range is accessed.
* Superseded by esp_cpu_set_watchpoint in esp_cpu.h.
@@ -250,70 +250,3 @@ ipc_err:
malloc_err:
return ret;
}
esp_err_t esp_backtrace_print_task(TaskHandle_t pxTask, int depth, bool panic)
{
esp_err_t ret = ESP_OK;
TaskSnapshot_t task_snapshot;
cur_task_backtrace_ctrl_t ctrl = {0};
// Suspend the scheduler to prevent task switching
vTaskSuspend(pxTask);
/*
Initialize backtracing for this core:
- Flush current core's register windows back onto current task's stack using esp_backtrace_get_start()
- Get starting frame for backtracing (starting frame is the caller of this function) using esp_backtrace_get_start()
- Save the starting frame details into the control block
*/
BaseType_t core_id = xPortGetCoreID(); // Get core ID now that task switching is disabled
ctrl.cur_tasks[core_id].task_hdl = xTaskGetCurrentTaskHandle();
esp_backtrace_get_start(&ctrl.cur_tasks[core_id].starting_pc,
&ctrl.cur_tasks[core_id].starting_sp,
&ctrl.cur_tasks[core_id].next_pc);
vTaskGetSnapshot(pxTask, &task_snapshot);
// Print the backtrace of the task
bool cur_running = false;
TaskHandle_t task_hdl = (TaskHandle_t) task_snapshot.pxTCB;
esp_backtrace_frame_t stk_frame = {0};
// Check if the task is one of the currently running tasks
for (BaseType_t core_id = 0; core_id < configNUMBER_OF_CORES; core_id++) {
if (task_hdl == ctrl.cur_tasks[core_id].task_hdl) {
cur_running = true;
break;
}
}
// Initialize the starting backtrace frame of the task
if (cur_running) {
/*
Setting the starting backtrace frame for currently running tasks is different. We cannot
use the current frame of each running task as the starting frame (due to the possibility
of the SP changing). Thus, each currently running task will have initialized their callers
as the starting frame for backtracing, which is saved inside the
cur_task_backtrace_ctrl_t block.
*/
stk_frame.pc = ctrl.cur_tasks[core_id].starting_pc;
stk_frame.sp = ctrl.cur_tasks[core_id].starting_sp;
stk_frame.next_pc = ctrl.cur_tasks[core_id].next_pc;
} else {
// Set the starting backtrace frame using the task's saved stack pointer
XtExcFrame* exc_frame = (XtExcFrame*) task_snapshot.pxTopOfStack;
stk_frame.pc = exc_frame->pc;
stk_frame.sp = exc_frame->a1;
stk_frame.next_pc = exc_frame->a0;
}
// Print backtrace
esp_err_t bt_ret = esp_backtrace_print_from_frame(depth, &stk_frame, panic);
if (bt_ret != ESP_OK) {
ret = bt_ret;
}
// Resume the scheduler to allow task switching again
vTaskResume(pxTask);
return ret;
}
@@ -819,10 +819,7 @@ esp_err_t esp_task_wdt_print_triggered_tasks(task_wdt_msg_handler msg_handler, v
msg_handler(opaque, name);
msg_handler(opaque, cpu);
}
esp_backtrace_print_task(entry->task_handle, 100, true);
}
}
return ESP_OK;
}