change(esp_hw_support): harden the ESP32-S31 PSRAM region permissions

Both PSRAM layouts were mapped as a single RWX window, so everything in external
RAM - the heap included - was executable.

PSRAM used as data only is now RW, and under XIP-from-PSRAM it is split per
section as ESP32-P4 does: .text RX, .rodata read-only, and the MMU-page
alignment gaps and the reclaimed heap RW, so neither is executable.

Both describe the layout that esp_psram_init() produces, and the entries are
locked, so - again as on ESP32-P4 - they are only narrowed when
CONFIG_SPIRAM_PRE_CONFIGURE_MEMORY_PROTECTION says that layout applies. Without
it the application owns the region and PSRAM stays RWX.

The per-section entries cost one PMP entry more than the 16 available, so the CPU
subsystem and peripheral windows are chained as TOR entries, taking one entry
instead of three.

soc.h is corrected against the S31 bus address map: the peripheral window base
was 1 MB too low, and the LP peripheral top, derived from a register base plus a
size rather than from the map, was 16 KB short. SOC_NON_CACHEABLE_OFFSET_FLASH
is added.
This commit is contained in:
harshal.patil
2026-08-28 18:06:56 +05:30
parent e7499410fa
commit 0580cff0e4
3 changed files with 152 additions and 107 deletions
+4 -3
View File
@@ -197,12 +197,12 @@
// peripherals, security peripherals, CPU peripheral, cache-data memory and the
// debug address space). Per the S31 bus address map this spans from the start of
// the "On-Chip Peripherals" aperture up to the base of the LP TCM (SOC_RTC_IRAM_LOW).
#define SOC_PERIPHERAL_LOW 0x20000000
#define SOC_PERIPHERAL_LOW 0x20100000
#define SOC_PERIPHERAL_HIGH 0x2E000000
/** LP subsystem from ``LP_SYS`` through ``LP_DAC``*/
#define SOC_LP_PERIPH_LOW DR_REG_LP_SYS_BASE
#define SOC_LP_PERIPH_HIGH (DR_REG_LP_DAC_BASE + 0x2000)
#define SOC_LP_PERIPH_LOW 0x20700000
#define SOC_LP_PERIPH_HIGH 0x20820000
// CPU sub-system region, contains interrupt config registers
#define SOC_CPU_SUBSYSTEM_LOW 0x10000000
@@ -213,6 +213,7 @@
#define SOC_ROM_STACK_SIZE 0x2000
// non-cacheable offset for memory behind the cache
#define SOC_NON_CACHEABLE_OFFSET_FLASH 0x60000000
#define SOC_NON_CACHEABLE_OFFSET_PSRAM 0x70000000
//On RISC-V CPUs, the interrupt sources are all external interrupts, whose type, source and priority are configured by SW.