netutils/dropbear: use NuttX /dev/crypto for chacha20-poly1305

Replace the bundled libtomcrypt chacha20-poly1305@openssh.com with an
adapter backed by the NuttX crypto framework: CRYPTO_CHACHA20 for the
two keystreams (payload and packet-length) and CRYPTO_POLY1305 for the
per-packet MAC, both routed through /dev/crypto ioctls. Gated behind
CONFIG_NETUTILS_DROPBEAR_NUTTX_CHACHAPOLY (default y when
NETUTILS_DROPBEAR_NUTTX_CRYPTO is enabled).

Signed-off-by: Felipe Moura <moura.fmo@gmail.com>
This commit is contained in:
Felipe Moura 2026-07-09 18:37:06 -03:00
parent 81b2a1be26
commit 7840ea5bdb
5 changed files with 406 additions and 0 deletions

View file

@ -0,0 +1,20 @@
--- a/src/chachapoly.h
+++ b/src/chachapoly.h
@@ -31,10 +31,17 @@
#if DROPBEAR_CHACHA20POLY1305
+#ifdef DROPBEAR_NUTTX_CHACHAPOLY
+typedef struct {
+ unsigned char key_main[32];
+ unsigned char key_header[32];
+} dropbear_chachapoly_state;
+#else
typedef struct {
chacha_state chacha;
chacha_state header;
} dropbear_chachapoly_state;
+#endif
extern const struct dropbear_cipher dropbear_chachapoly;
extern const struct dropbear_cipher_mode dropbear_mode_chachapoly;