Skip to content

build: make psa-crypto-sys no_std, fix zeroize with no_std - #145

Merged
hug-dev merged 1 commit into
parallaxsecond:mainfrom
dsseng:tfm-no_std
Jan 14, 2026
Merged

hug-dev merged 1 commit into
parallaxsecond:mainfrom
dsseng:tfm-no_std

Conversation

@dsseng

@dsseng dsseng commented Nov 16, 2025

Copy link
Copy Markdown
Contributor

As psa-crypto-sys does not rely on any std features, it should be safe
to completely switch its bindgen options to use core, and mark it as
no_std. This allows this crate to be used in embedded applications such
as TrustedFirmware-M Secure Partitions.

zeroize should not need alloc default feature, as this crate does not
make use of Vec or Box and does not derive zeroize on them. Disable all
default features to avoid unnecessary dependency on std.

Tested to provide access to hash functions via operations feature in
a TF-M Secure Partition sample.

Signed-off-by: Dmitrii Sharshakov d3dx12.xx@gmail.com

@dsseng

dsseng commented Nov 18, 2025

Copy link
Copy Markdown
Contributor Author

These CI failures are also present on main. I could perhaps take a look this weekend and send a PR for fixing those, please let me know if that's wanted

@hug-dev

hug-dev commented Nov 18, 2025

Copy link
Copy Markdown
Member

Hello! Thanks for your effort contributing into this repo!! It has been a bit left on the side those past few years... If it's needed though, I could also take a look at open issues/PRs and try to freshen it up!

There is another open issue about making it no_std which I think makes total sense. Let's aim to do that!

@dsseng

dsseng commented Nov 21, 2025

Copy link
Copy Markdown
Contributor Author

I'm working on fixing clippy errors, will submit a separate PR to be merged before this

@hug-dev

hug-dev commented Jan 14, 2026

Copy link
Copy Markdown
Member

Please feel free to continue working on this if interested, I will review and merge it myself :)

@dsseng

dsseng commented Jan 14, 2026

Copy link
Copy Markdown
Contributor Author

Will rebase this evening, thank you

As psa-crypto-sys does not rely on any std features, it should be safe
to completely switch its bindgen options to use core, and mark it as
no_std. This allows this crate to be used in embedded applications such
as TrustedFirmware-M Secure Partitions.

zeroize should not need `alloc` default feature, as this crate does not
make use of Vec or Box and does not derive zeroize on them. Disable all
default features to avoid unnecessary dependency on std.

Tested to provide access to hash functions via `operations` feature in
a TF-M Secure Partition sample.

Signed-off-by: Dmitrii Sharshakov <d3dx12.xx@gmail.com>
@hug-dev hug-dev linked an issue Jan 14, 2026 that may be closed by this pull request

@hug-dev hug-dev left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Awesome, thank you!

@hug-dev
hug-dev merged commit 08b1260 into parallaxsecond:main Jan 14, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

psa_crypto_sys is not no_std

2 participants