## [1.0.0] #15
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "fix/audit-2026-08-21-secu-C1"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Security
cargo denypolicy (rootdeny.toml) enforcing RustSec advisories, yanked crate detection, allowed registries (crates.io only), and license policy compatible with project dependenciescargo denychecks in all Forgejo workflows (enable_deny: true) for feature checks, tag creation, and publication gatesFixed — Documentation and package metadata
atecc608x(public type names such asAtecc608b/Atecc608bErrorare unchanged). Thecompile_failguards now exercise API privacy instead of failing on an unresolved crate name.Cargo.tomlnow declaresdescription,license-fileand anexcludelist so dev/CI-only artifacts (datasheet,.forgejo/,.specify/,.claude/,.cursor/,scripts/,.cargo/,.opencode-memory/) are not shipped in the published package;.opencode-memory/is also git-ignored.cargo clippy --all-featuresclean again: the four I²C word-address reference aliases inconstants::configare test-only fixtures (all consumers are unit tests) and are now#[cfg(test)], so they are excluded from library builds entirely instead of being dead-code-allowed.ephemeral_ecdh_tempkeyis public;generate_ephemeral_keypair_tempkeyis crate-internal andecdh_with_tempkeyis test-only. Remove the staleSharedSecret::into_bytesowning-copy mention.CLAUDE.mdCI/CD section now describes the five real Forgejo workflows.Fixed — Validate request_id stable across lock-data
validation_config_fingerprintSHA-256s Config withLockValueforced to0x00. HSM export prepares Validate while Data is unlocked (0x55); execute runs afterlock-data(0x00). Binding the raw Config invalidated every offlinevalidation_request_idacross that intentional lock.Fixed — stored-key ECDH mode for blank ATECC608B
ECDH_MODE_STORED_CLEAR_OUTPUTis now0x00(CryptoAuthLibECDH_PREFIX_MODE) instead of TFLXTLS Table 5-43 mode0x0C. Blank Rev03 silicon returnsExecutionError(surfaced as TempKeyInvalid) for mode0x0C.Fixed — Slot-8 personalization without Data-zone reads
ExecutionError. Addedwrite_public_key_for_verify_personalization(block writes, no read-back) and
prepare_stored_public_key_validation(..., known_public_key)so Validate prep can use the host-known factory key without reading the slot.execute_stored_public_key_validationskips pre/post marker reads whileData unlocked (Verify success is the gate).
write_data_slot_personalizationis public for clear Data writes without read-back.Fixed — stored-key ECDH satisfies KeyConfig.ReqRandom
ecdhnow issues Nonce Random (Idle) before stored-key ECDH (awake),matching Sign/GenKey. Slot 0 (ReqRandom = 1) previously returnedExecutionError(mapped as TempKeyInvalid) duringverify.Fixed — GenKey Public/Private satisfy KeyConfig.ReqRandom
get_public_keyandgenerate_keypairnow issue Nonce Random (Idle) before GenKey, then GenKey while awake (Sleep after), matchingsign_with_random_nonce. The Random command alone does not setTempKey.SourceFlag = Rand; slots withReqRandom = 1previously returnedExecutionErrorfor both empty and occupied slots.Fixed — Data-zone 36-byte R/W while Data unlocked
Fixed — Linux I²C padded status no longer maps to InvalidLength
read_and_validate_responseacceptsreceived_len >= count(ignore padded tail) instead of requiring equality. Linuxi2c-devreports the master-requested buffer length while a device error still hascount = 4,which previously failed as
InvalidLengthbefore status parsing.Added — optional generic provisioning surface
provisioning; the default build retains only runtime discovery, crypto, counter and Data-zone functionality.workflows behind
provisioning.ProvisioningConfig, a typed exact 128-byte image exposing documentedidentity/revision, I²C configuration,
CountMatch,ChipMode, counter image,UseLock,ChipOptions/ECDHPROT, X509format,SlotConfigandKeyConfig.to silicon identity, counter storage and lock bytes, writes complete Config words only, verifies every write, and performs a final full-image comparison.
configAteccbusiness rulesoutside the crate.
Breaking — ATECC608B Protocol Correction
This is a BREAKING correction of the generic configurable ATECC608B I²C protocol implementation. There is no backward compatibility with prior APIs, ATECC608A-oriented behavior,
TNG/TFLXTLS profiles, or old slot layouts. Legacy surfaces are removed, not deprecated.
Transport
04 11 33 43. CRC is verified over[0x04, 0x11]and compared to0x4333LE. The previous length-6/length-7 wake helpers and the04 11 33 44fixture are removed and rejected.AteccTransportfor one contiguous bounded read, reports the actual received length and requires it to be at leastcount(padded tails from Linux i2c-dev master over-reads are ignored). The read is bounded by the command's expected reply . Split count-then-rest is forbidden unless hardware-proven and documented. No0x03(Command word address) write before the response read.count=7data[1..5]; 32-byte payload commandscount=35data[1..33]; GenKey/Signcount=67data[1..65]; status/errorcount=4status[1]. Status-prefixed data success shapes are rejected.check_response()runs only oncount=4packets.Execution / retry policy
GenKey(Public)is retry-eligible;GenKey(Private)is not.NotAcceptedversusMayHaveBeenAccepted. After possible write acceptance, the following are never retransmitted: Write, Lock, Counter(increment), GenKey(Private), UpdateExtra, TempKey-consuming ECDH. An unqualified HAL write fault on those maps toOutcomeUnknown.Config Zone decoding
[0..4]+[8..13], ChipMode19, SlotConfig20..52,Counter052..60, Counter160..68, UseLock68, LockValue86, LockConfig87,SlotLocked
88..90LE active-low (bit clear = locked), ChipOptions90..92LE,KeyConfig96..128.64..66, ChipMode at88, UseLockderived from82) are removed.Lock APIs
lock_zone(),lock_config_without_crc().LockConfig == 0x00.lock_slot(KeySlot): verify SlotLocked bit1 → 0; refuse non-lockable/already-locked.Data Zone
P-256 / secrets / volatile cleanup
P256PublicKey/P256Signaturevalues rather than raw arrays.SharedSecret: borrow or copy-into-caller-clearing-buffer only. No public owning copy API (into_bytesremoved). NoDebug/Clone. Zeroize on Drop.verify_only_*_with_msgdigbuf,nonce_fixed_msgdigbuf_64). Stored/external Verify stays on TempKey; MsgDigBuf remains for Sign only.API surface
pub(crate)/private. Public slot operations useKeySlot; compile-fail tests enforce the intended surface.configAteccconstants, slot maps, or business policy insrc/.Breaking — ATECC608B driver hardening
This is a BREAKING refactor with no legacy compatibility layers. All public APIs changed by this section are incompatible with the previous release; callers must update.
I²C transport
Reset = 0x00,Sleep = 0x01,Idle = 0x02,Command = 0x03. The old SWI-derived values (Idle = 0xBB,Sleep = 0xCC) are removed.04 11 33 43followed by a valid CRC. The previously accepted04 11 33 44pattern is now rejected withInvalidResponse(bad pattern) orCrcMismatch(bad CRC).0x03(Command word address) byte before reading. The driver readscountfirst, then exactlycount-1bytes, and validates the CRC overresponse[0..count].WakeTokenFailed(host failed to assert the wake token / I²C write error),DeviceNotResponding(device did not answer),CrcMismatch/InvalidResponse(bad wake reply).Retry policy
GenKey,Write,Lock, TempKeyECDH,Counter) are never retransmitted after the command packet has been accepted by the device. If thevreply is lost or corrupt after acceptance, the driver returnsAtecc608bError::OutcomeUnknown(execution may have occurred without a validated reply).Info,Random,SelfTest,Read) are retried up to 3 times on transient status errors.Error type
OutcomeUnknown.WakeTokenFailed.DeviceNotRespondingnow specifically indicates a wake/read I²C failure (not a bad reply).KeySlotimpl From<u8> for KeySlotremoved. UseKeySlot::new(u8) -> Result<KeySlot, KeySlotError>orKeySlot::try_from(u8).SharedSecretSharedSecret(Zeroizing<[u8; 32]>): zeroizes on drop.DebugandClonederives removed.as_bytes() -> &[u8; 32](borrowed) orcopy_intoa caller-owned zeroizing buffer; there is deliberately no owning-copy API (into_bytesis removed).ecdh,ephemeral_ecdh_tempkey) returnSharedSecretinstead of[u8; 32].P-256 validation
InvalidPublicKeybefore any I²C command isissued. Usesp256::PublicKey::from_sec1_bytes.Lock APIs
LockStatetype (from_config(&[u8; 128])) exposesconfig_locked(),data_locked(), andslot_locked(slot).setup:lock_config_with_crc,lock_config_without_crc,lock_data_without_crc,lock_slot(KeySlot)with post-verification.summary_crc) implemented with CryptoAuthLib-compatible reference vectors.Strict response parsers
SelfTest,Info,GenKey,Read,Nonce,ECDH,Verifyparsers now reject undocumented dual response shapes. Previously tolerated malformed packets now returnInvalidResponseorInvalidLength.Added — Ephemeral P-256 TempKey ECDH
ephemeral_ecdh_tempkey: atomic ephemeral P-256 key agreement via TempKey. Generates an ephemeral keypair in volatile TempKey, immediately performs ECDH with a peer public key, and returns(ephemeral_public_xy[64], shared_secret[32]).Guarantees: no host code between GenKey and ECDH; Idle between commands preserves TempKey; Sleep on all exit paths; no EEPROM/data-zone slot writes.
generate_ephemeral_keypair_tempkey(crate-internal): GenKey into TempKey, returns 64-byte publicX‖Y. Does not ECDH. Used internally byephemeral_ecdh_tempkey; split TempKey primitives stay private per the contract.ecdh_with_tempkey(test-only,#[cfg(test)]): ECDH using the current TempKey private key. VerifiesECDHPROTon every call. Fails with TempKeyInvalidif TempKey is not valid. The public surface exposes only the atomicephemeral_ecdh_tempkey` flow.OutputProtectionRequirederror variant: returned whenChipOptions.ECDHPROTforbids clear ECDH output.TempKeyInvaliderror variant: returned when ECDH is attempted without a valid TempKey (consumed by prior ECDH, or invalidated by Sleep/power loss).ECDH_MODE_TEMPKEY_CLEAR_OUTPUT(0x0D),GENKEY_MODE_TEMPKEY_IN_TEMPKEY(0x04),GENKEY_TEMPKEY_KEYID_LO/HI(0xFF/0xFF),CHIPOPTIONS_OFFSET,CHIPOPTIONS_ECDHPROT_MASK/SHIFT,CHIPOPTIONS_ECDHPROT_CLEAR_ALLOWED`.Silicon validation checklist — hardening
04 11 33 43 + CRC; confirm NO0x03byte is written before response reads; confirm word addresses0x00/0x01/0x02/0x03.GenKey/Write/Lock; assert the driver returnsOutcomeUnknownand does NOT retransmit.ecdh/verify/write_public_key; assertInvalidPublicKeybefore any I²C ECDH/Verify/Write command appears on the bus.lock_config_with_crcrefuses a wrong CRC andlock_slotpost-verifies the SlotLock by re-reading the lock state.0x01) at the end of every logical transaction (no Idle leak except between GenKey→ECDH inephemeral_ecdh_tempkey).