Repository navigation
Conversation
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Serial timeout and baud defects, unsafe certificate rendering, and incorrect SPDM success reporting can break or misrepresent core demonstrations.
Review effort: Balanced
Findings: 3
Open (14)
Factory target does not track signing key generation · New Dispatcher invokes TPM operations after initialization failure · New Certificate SAN values are vulnerable to HTML injection · New Discovery-only results are falsely reported as secured sessions · New SPDM timeout is too short for the full handshake · New OnboardReader defaults to the wrong baud rate · New CLI default baud rate mismatches the firmware · New Benchmark reports PASS after incomplete iterations · New SPDM build hash is not reproducible across responder keys · New Command table omits the SPDM d command · New Documentation incorrectly describes two off-silicon acts · New Main claim incorrectly says every tab uses fitted silicon · New Sign act is mislabeled as host verification · New Transport is incorrectly documented as SPI · New
What changed in this PR
Adds a complete PSoC Control C3 firmware and host interface for driving an attached TPM over I2C, including ML-DSA, sealing, PCR, endorsement, and SPDM demonstrations.
Changes:
- Adds MCU firmware, TPM transport, cryptographic acts, diagnostics, and wolfBoot packaging.
- Adds a browser UI and serial command-line tooling.
- Documents building, flashing, operation, and measured performance.
| File | Description |
|---|---|
README.md |
Links and summarizes the demo. |
.../.gitignore |
Excludes generated artifacts. |
.../BUILD.md |
Documents build and flashing. |
.../Makefile |
Builds, signs, and assembles firmware. |
.../README.md |
Documents firmware acts and benchmarks. |
.../act_sign.c |
Implements ML-DSA signing and verification. |
.../act_sign.h |
Declares the signing act. |
.../act_spdm.c |
Implements the SPDM act. |
.../act_spdm.h |
Declares the SPDM act. |
.../console_write.c |
Routes diagnostic output to UART. |
.../demo_acts.c |
Dispatches console-selected TPM acts. |
.../demo_util.c |
Provides board, timing, and output utilities. |
.../demo_util.h |
Declares shared utilities. |
.../fault_report.c |
Reports MCU faults over UART. |
.../firmware/reset-board.jlink |
Resets the MCU and TPM. |
.../heap.c |
Provides a fixed embedded heap. |
.../i2c_trace.c |
Records TPM I2C transfers. |
.../i2c_trace.h |
Declares optional I2C tracing. |
.../mldsa_bench.c |
Benchmarks ML-DSA verification. |
.../mldsa_onboard.c |
Runs the standalone signing demonstration. |
.../rng_seed.c |
Seeds wolfCrypt from the TPM RNG. |
.../tpm_identity.c |
Reads TPM identity on-device. |
.../tpm_io_i2c_c3.c |
Implements wolfTPM I2C transport. |
.../user_settings.h |
Configures ML-DSA verification. |
.../user_settings_tpm.h |
Configures wolfTPM and SPDM support. |
.../wolfboot-demo.config |
Defines the enlarged wolfBoot layout. |
.../host/README.md |
Documents host operation. |
.../host/capture-tabs.sh |
Automates UI screenshots. |
.../host/onboard.py |
Drives firmware over serial. |
.../host/requirements.txt |
Lists host dependencies. |
.../host/shot.py |
Captures headless browser screenshots. |
.../host/sse_probe.py |
Probes streamed demo events. |
.../host/templates/index.html |
Implements the browser interface. |
.../host/x509_lite.py |
Parses displayed certificate fields. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
+293
to
+296
| spdm_acts_v$(APP_VERSION)_signed.bin: spdm_acts.bin | ||
| $(WOLFBOOT_DIR)/tools/keytools/sign $(SIGN_ALG) $< $(SIGN_KEY) $(APP_VERSION) | ||
|
|
||
| factory: wolfboot spdm_acts_v$(APP_VERSION)_signed.bin |
Comment on lines
+507
to
+510
| if (rc != TPM_RC_SUCCESS) { | ||
| demo_fail("wolfTPM2_Init", rc); | ||
| demo_put("{\"event\":\"ready\",\"tpm\":false}\r\n"); | ||
| } |
Comment on lines
+1356
to
+1365
| $("ek-summary").innerHTML = !count | ||
| ? "No endorsement certificates found." | ||
| : decoded | ||
| ? "<b>" + count + " certificates</b> read from the TPM's own NV storage. " + | ||
| "Each one was written at manufacture and states, signed by the issuer, " + | ||
| "that this is a <b>" + (san.model || "TPM") + "</b> from <b>" + | ||
| decodeMfg(san.manufacturer) + "</b>, firmware " + | ||
| (san.version || "unknown") + "." | ||
| : "<b>" + count + " certificates</b> read from the TPM's own NV storage, " + | ||
| "each written there at manufacture and signed by the issuer."; |
Comment on lines
+211
to
+214
| if (rc == TPM_RC_SUCCESS) | ||
| rc = discover(dev); | ||
| finish(dev, 1, rc == TPM_RC_SUCCESS ? 1 : 0); | ||
| goto restore; |
Comment on lines
+47
to
+51
| # Long enough for ML-DSA key creation and signing, which together take a few | ||
| # seconds on this part and vary by more than a factor of two run to run. | ||
| DEFAULT_TIMEOUT = 30.0 | ||
| # A gap this long with nothing arriving means the act is over or stuck. | ||
| DEFAULT_IDLE = 5.0 |
| | `S` | as `s`, with ML-DSA-65 instead of 87 | | ||
| | `T` | as `t`, with ML-DSA-65 instead of 87 | | ||
| | `l` | sealed secret: seal to a PCR, unseal, extend, fail, reset | | ||
| | `e` | endorsement: read the EK certificates out of NV | |
Comment on lines
+8
to
+9
| page is the same whether the acts run on the board or, for the two that cannot | ||
| run on silicon, against wolfTPM's firmware TPM. |
Comment on lines
+228
to
+230
| <span id="claim-text">A post-quantum TPM, driven by wolfTPM. Keys are generated | ||
| inside the chip and never leave it — every tab below is that same silicon | ||
| doing real work, live.</span> |
| <li data-k="key"><span class="mark">2</span><span>TPM generates ML-DSA key pair</span><span class="detail"></span></li> | ||
| <li data-k="sign"><span class="mark">3</span><span>TPM signs digest (private key never leaves)</span><span class="detail"></span></li> | ||
| <li data-k="tamper"><span class="mark">!</span><span>Signature bit flipped</span><span class="detail"></span></li> | ||
| <li data-k="verify"><span class="mark">4</span><span>Host verifies with wolfCrypt</span><span class="detail"></span></li> |
Comment on lines
+407
to
+408
| <p class="lead">The SPI bus between a host and a TPM is plaintext: four | ||
| wires and a cheap logic analyser read every command and every response. |
dgarske
force-pushed
the
psoc_c3_onboard_demo
branch
5 times, most recently
from
October 6, 2026 16:36
f3cfd4d to
60f1d76
Compare
dgarske
force-pushed
the
psoc_c3_onboard_demo
branch
from
October 6, 2026 21:21
60f1d76 to
729124e
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Runs the whole demonstration on the microcontroller: the MCU drives a TPM 2.0 over I2C and performs post-quantum signing, a sealed secret bound to a measurement, PCR and endorsement certificate reads, and an SPDM session. No host takes part in the cryptography; it supplies a screen.
What it adds
Infineon/PSoC_Control_C3_Onboard_Demo/- one firmware image whose acts are selected by a command byte on the console, emitting newline-delimited JSON.../tpm_io_i2c_c3.c- TPM IO callback over wolfBoot's I2C driver.../rng_seed.c- seeds wolfCrypt's DRBG from the TPM, the board having no entropy source of its own.../wolfboot-demo.config- wolfBoot partitions sized for this image, which does not fit the stock psoc_c3 layout, with boot progress on the console.../host/- browser front end and a command-line driver for the same acts.../BUILD.md- every build command written out, no wrapper scriptsThe application is signed and verified by wolfBoot;
make factoryassembles the bootloader and the signed application into one flashable image. wolfTPM is unmodified. Needs wolfSSL/wolfBoot#915Hardware / test status
Validated end to end on a PSOC Control C3 (C3M6) EVK with a TPM 2.0 on the mikroBUS connector, over the J-Link CDC console at 115200. Every act ran against the part, the sealed-secret sequence twice in succession, and the set was left cycling overnight without a failure. The host front end was run on both Windows and Linux against the same board, including the debug-probe reset behind the console tab.
Scope
The post-quantum TLS tab runs against wolfTPM's firmware TPM, not the fitted part, and says so on screen: the part's firmware implements only the pre-hash form of ML-DSA, which TLS CertificateVerify cannot use. That tab needs a
second wolfTPM built for the host, which
host/README.mdcovers; every other tab is the fitted silicon. The endorsement tab proves the key match for the P-256 certificate only; the other rows report that no match was attempted.