fw-2.0.2
·
681 commits
to main
since this release
Immutable
release. Only release title and notes can be modified.
This is a combined runtime and FMC release.
Caliptra FW 2.0.2 Release Notes
Release notes for changes introduced since FW 2.0.1.
Features
- DPE Upgrades:
- Attested CSR:
- Cryptographic & Drivers:
- Runtime & Firmware Capabilities:
- Optimizations:
- Skip Runtime journey PCR extension when booting the same firmware version (#3055)
Fixes
- Security & Debug Unlock:
- Fix some logic around production debug unlock (#3694, #3766, #3628, #3636)
- Fix TAP mailbox availability after debug unlock (#3848)
- Fix WDT stop after production debug unlock (#3675, #3676)
- Re-derive dummy FMC key pairs on warm reset in debug unlocked mode as a workaround for key vault reset (143b72ec)
- Boot & Recovery:
- Robustness & Bug Fixes:
- Bound authority manifest metadata lookup by
entry_count(#3732) - Implement address-based authorize-and-stash measurement (#3688)
- Fix AES-GCM streaming GHASH save/restore bug in drivers (#3790)
- Fix mailbox packet handling to validate packet length (
dlen) against mailbox SRAM size (#3414, #3571) - Handle mailbox FSM error state and unexpected DataReady in drivers (#3393, #3516)
- Mark hash-based ECDSA/LMS verification as FIPS non-approved (#3803)
- Add missing DICE EKU extension to Runtime alias certificates (#3202)
- Use configurable OTP status offset for UDS/FE programming (#3723)
- Fix runtime FIPS shutdown zeroization (#3908)
- Bound authority manifest metadata lookup by