feat(esp_psram): add option to carve unencrypted PSRAM region

Adds CONFIG_SPIRAM_ENC_EXEMPT, available on chips that support per-page
PSRAM encryption configuration (esp32c5, esp32c61, esp32p4). When
enabled, esp_psram carves CONFIG_SPIRAM_ENC_EXEMPT_SIZE off the top of
PSRAM and maps it via the new mmu_hal_map_region_no_enc() helper, which
writes MMU entries without the SENSITIVE bit. The region is registered
as a separate heap pool reachable only through the new
MALLOC_CAP_SPIRAM_NO_ENC capability bit, so default SPIRAM allocations
cannot accidentally land there.

PSRAM encryption imposes alignment constraints that some DMA engines
(e.g. 2D-DMA) cannot satisfy. This option lets such workloads place
their buffers in unencrypted PSRAM while keeping the rest of PSRAM
(and flash) encrypted. Default disabled; security implications are
documented in the Kconfig help text.
This commit is contained in:
Mahavir Jain
2026-06-23 14:56:38 +05:30
parent 315e812d5b
commit 0044542811
8 changed files with 204 additions and 7 deletions
+14 -1
View File
@@ -1,5 +1,5 @@
/*
* SPDX-FileCopyrightText: 2010-2025 Espressif Systems (Shanghai) CO LTD
* SPDX-FileCopyrightText: 2010-2026 Espressif Systems (Shanghai) CO LTD
*
* SPDX-License-Identifier: Apache-2.0
*/
@@ -64,6 +64,19 @@ uint32_t mmu_hal_bytes_to_pages(uint32_t mmu_id, uint32_t bytes);
*/
void mmu_hal_map_region(uint32_t mmu_id, mmu_target_t mem_type, uint32_t vaddr, uint32_t paddr, uint32_t len, uint32_t *out_len);
#if SOC_PSRAM_ENCRYPTION_PAGE_CONFIGURABLE
/**
* Map a PSRAM physical range to virtual memory without setting the encryption
* SENSITIVE bit on each MMU entry. Used only for the explicitly carved-out
* unencrypted PSRAM region (see CONFIG_SPIRAM_ENC_EXEMPT).
*
* @param vaddr start virtual address (MMU-page-aligned)
* @param paddr start physical address (MMU-page-aligned)
* @param len length in bytes
*/
void mmu_hal_map_region_no_enc(uint32_t vaddr, uint32_t paddr, uint32_t len);
#endif
/**
* To unmap a virtual address block that is mapped to a physical memory block previously
*