diff --git a/components/esp_system/port/soc/esp32c5/system_internal.c b/components/esp_system/port/soc/esp32c5/system_internal.c index d1a00ba93ca..4246b0c7c6a 100644 --- a/components/esp_system/port/soc/esp32c5/system_internal.c +++ b/components/esp_system/port/soc/esp32c5/system_internal.c @@ -85,21 +85,24 @@ void esp_system_reset_modules_on_exit(void) // all the peripherals are reset at the same time, which triggers a hardware SEC reset. The SEC reset // causes the crypto -> APB path to be reset, but the APB -> crypto path is not reset. This asymmetry // results in the crypto module hanging and refusing all access. +#if !CONFIG_SECURE_ENABLE_TEE + // Avoid resetting the TEE-protected crypto peripherals as it would lead to an APM fault SET_PERI_REG_MASK(PCR_AES_CONF_REG, PCR_AES_RST_EN); CLEAR_PERI_REG_MASK(PCR_AES_CONF_REG, PCR_AES_RST_EN); SET_PERI_REG_MASK(PCR_DS_CONF_REG, PCR_DS_RST_EN); CLEAR_PERI_REG_MASK(PCR_DS_CONF_REG, PCR_DS_RST_EN); SET_PERI_REG_MASK(PCR_ECC_CONF_REG, PCR_ECC_RST_EN); CLEAR_PERI_REG_MASK(PCR_ECC_CONF_REG, PCR_ECC_RST_EN); - SET_PERI_REG_MASK(PCR_ECDSA_CONF_REG, PCR_ECDSA_RST_EN); - CLEAR_PERI_REG_MASK(PCR_ECDSA_CONF_REG, PCR_ECDSA_RST_EN); SET_PERI_REG_MASK(PCR_HMAC_CONF_REG, PCR_HMAC_RST_EN); CLEAR_PERI_REG_MASK(PCR_HMAC_CONF_REG, PCR_HMAC_RST_EN); - SET_PERI_REG_MASK(PCR_RSA_CONF_REG, PCR_RSA_RST_EN); - CLEAR_PERI_REG_MASK(PCR_RSA_CONF_REG, PCR_RSA_RST_EN); SET_PERI_REG_MASK(PCR_SHA_CONF_REG, PCR_SHA_RST_EN); CLEAR_PERI_REG_MASK(PCR_SHA_CONF_REG, PCR_SHA_RST_EN); CLEAR_PERI_REG_MASK(PCR_ECC_PD_CTRL_REG, PCR_ECC_MEM_FORCE_PD); +#endif // !CONFIG_SECURE_ENABLE_TEE + SET_PERI_REG_MASK(PCR_ECDSA_CONF_REG, PCR_ECDSA_RST_EN); + CLEAR_PERI_REG_MASK(PCR_ECDSA_CONF_REG, PCR_ECDSA_RST_EN); + SET_PERI_REG_MASK(PCR_RSA_CONF_REG, PCR_RSA_RST_EN); + CLEAR_PERI_REG_MASK(PCR_RSA_CONF_REG, PCR_RSA_RST_EN); // UART's sclk is controlled in the PCR register and does not reset with the UART module. The ROM missed enabling // it when initializing the ROM UART. If it is not turned on, it will trigger LP_WDT in the ROM. diff --git a/components/esp_system/port/soc/esp32c6/system_internal.c b/components/esp_system/port/soc/esp32c6/system_internal.c index 17ffd0df04f..dd818d49b1b 100644 --- a/components/esp_system/port/soc/esp32c6/system_internal.c +++ b/components/esp_system/port/soc/esp32c6/system_internal.c @@ -71,19 +71,22 @@ void esp_system_reset_modules_on_exit(void) // Reset crypto peripherals. This ensures a clean state for the crypto peripherals after a CPU restart // and hence avoiding any possibility with crypto failure in ROM security workflows. +#if !CONFIG_SECURE_ENABLE_TEE + // Avoid resetting the TEE-protected crypto peripherals as it would lead to an APM fault SET_PERI_REG_MASK(PCR_AES_CONF_REG, PCR_AES_RST_EN); SET_PERI_REG_MASK(PCR_DS_CONF_REG, PCR_DS_RST_EN); SET_PERI_REG_MASK(PCR_ECC_CONF_REG, PCR_ECC_RST_EN); SET_PERI_REG_MASK(PCR_HMAC_CONF_REG, PCR_HMAC_RST_EN); - SET_PERI_REG_MASK(PCR_RSA_CONF_REG, PCR_RSA_RST_EN); SET_PERI_REG_MASK(PCR_SHA_CONF_REG, PCR_SHA_RST_EN); CLEAR_PERI_REG_MASK(PCR_AES_CONF_REG, PCR_AES_RST_EN); CLEAR_PERI_REG_MASK(PCR_DS_CONF_REG, PCR_DS_RST_EN); CLEAR_PERI_REG_MASK(PCR_ECC_CONF_REG, PCR_ECC_RST_EN); CLEAR_PERI_REG_MASK(PCR_HMAC_CONF_REG, PCR_HMAC_RST_EN); - CLEAR_PERI_REG_MASK(PCR_RSA_CONF_REG, PCR_RSA_RST_EN); CLEAR_PERI_REG_MASK(PCR_SHA_CONF_REG, PCR_SHA_RST_EN); CLEAR_PERI_REG_MASK(PCR_ECC_PD_CTRL_REG, PCR_ECC_MEM_FORCE_PD); +#endif // !CONFIG_SECURE_ENABLE_TEE + SET_PERI_REG_MASK(PCR_RSA_CONF_REG, PCR_RSA_RST_EN); + CLEAR_PERI_REG_MASK(PCR_RSA_CONF_REG, PCR_RSA_RST_EN); CLEAR_PERI_REG_MASK(PCR_REGDMA_CONF_REG, PCR_REGDMA_RST_EN); diff --git a/components/esp_system/port/soc/esp32c61/system_internal.c b/components/esp_system/port/soc/esp32c61/system_internal.c index 095a19e20b0..1dbf60ddccd 100644 --- a/components/esp_system/port/soc/esp32c61/system_internal.c +++ b/components/esp_system/port/soc/esp32c61/system_internal.c @@ -86,13 +86,16 @@ void esp_system_reset_modules_on_exit(void) // all the peripherals are reset at the same time, which triggers a hardware SEC reset. The SEC reset // causes the crypto -> APB path to be reset, but the APB -> crypto path is not reset. This asymmetry // results in the crypto module hanging and refusing all access. +#if !CONFIG_SECURE_ENABLE_TEE + // Avoid resetting the TEE-protected crypto peripherals as it would lead to an APM fault SET_PERI_REG_MASK(PCR_ECC_CONF_REG, PCR_ECC_RST_EN); CLEAR_PERI_REG_MASK(PCR_ECC_CONF_REG, PCR_ECC_RST_EN); - SET_PERI_REG_MASK(PCR_ECDSA_CONF_REG, PCR_ECDSA_RST_EN); - CLEAR_PERI_REG_MASK(PCR_ECDSA_CONF_REG, PCR_ECDSA_RST_EN); SET_PERI_REG_MASK(PCR_SHA_CONF_REG, PCR_SHA_RST_EN); CLEAR_PERI_REG_MASK(PCR_SHA_CONF_REG, PCR_SHA_RST_EN); CLEAR_PERI_REG_MASK(PCR_ECC_PD_CTRL_REG, PCR_ECC_MEM_FORCE_PD); +#endif // !CONFIG_SECURE_ENABLE_TEE + SET_PERI_REG_MASK(PCR_ECDSA_CONF_REG, PCR_ECDSA_RST_EN); + CLEAR_PERI_REG_MASK(PCR_ECDSA_CONF_REG, PCR_ECDSA_RST_EN); // UART's sclk is controlled in the PCR register and does not reset with the UART module. The ROM missed enabling // it when initializing the ROM UART. If it is not turned on, it will trigger LP_WDT in the ROM. diff --git a/components/esp_system/port/soc/esp32h2/system_internal.c b/components/esp_system/port/soc/esp32h2/system_internal.c index 6a471aff8ff..8c6c6fbfafe 100644 --- a/components/esp_system/port/soc/esp32h2/system_internal.c +++ b/components/esp_system/port/soc/esp32h2/system_internal.c @@ -68,21 +68,24 @@ void esp_system_reset_modules_on_exit(void) // Reset crypto peripherals. This ensures a clean state for the crypto peripherals after a CPU restart // and hence avoiding any possibility with crypto failure in ROM security workflows. +#if !CONFIG_SECURE_ENABLE_TEE + // Avoid resetting the TEE-protected crypto peripherals as it would lead to an APM fault SET_PERI_REG_MASK(PCR_AES_CONF_REG, PCR_AES_RST_EN); SET_PERI_REG_MASK(PCR_DS_CONF_REG, PCR_DS_RST_EN); SET_PERI_REG_MASK(PCR_ECC_CONF_REG, PCR_ECC_RST_EN); - SET_PERI_REG_MASK(PCR_ECDSA_CONF_REG, PCR_ECDSA_RST_EN); SET_PERI_REG_MASK(PCR_HMAC_CONF_REG, PCR_HMAC_RST_EN); - SET_PERI_REG_MASK(PCR_RSA_CONF_REG, PCR_RSA_RST_EN); SET_PERI_REG_MASK(PCR_SHA_CONF_REG, PCR_SHA_RST_EN); CLEAR_PERI_REG_MASK(PCR_AES_CONF_REG, PCR_AES_RST_EN); CLEAR_PERI_REG_MASK(PCR_DS_CONF_REG, PCR_DS_RST_EN); CLEAR_PERI_REG_MASK(PCR_ECC_CONF_REG, PCR_ECC_RST_EN); - CLEAR_PERI_REG_MASK(PCR_ECDSA_CONF_REG, PCR_ECDSA_RST_EN); CLEAR_PERI_REG_MASK(PCR_HMAC_CONF_REG, PCR_HMAC_RST_EN); - CLEAR_PERI_REG_MASK(PCR_RSA_CONF_REG, PCR_RSA_RST_EN); CLEAR_PERI_REG_MASK(PCR_SHA_CONF_REG, PCR_SHA_RST_EN); CLEAR_PERI_REG_MASK(PCR_ECC_PD_CTRL_REG, PCR_ECC_MEM_FORCE_PD); +#endif // !CONFIG_SECURE_ENABLE_TEE + SET_PERI_REG_MASK(PCR_ECDSA_CONF_REG, PCR_ECDSA_RST_EN); + SET_PERI_REG_MASK(PCR_RSA_CONF_REG, PCR_RSA_RST_EN); + CLEAR_PERI_REG_MASK(PCR_ECDSA_CONF_REG, PCR_ECDSA_RST_EN); + CLEAR_PERI_REG_MASK(PCR_RSA_CONF_REG, PCR_RSA_RST_EN); // UART's sclk is controlled in the PCR register and does not reset with the UART module. The ROM missed enabling // it when initializing the ROM UART. If it is not turned on, it will trigger LP_WDT in the ROM. diff --git a/components/esp_tee/subproject/main/CMakeLists.txt b/components/esp_tee/subproject/main/CMakeLists.txt index 6cd569cfa31..db190377b81 100644 --- a/components/esp_tee/subproject/main/CMakeLists.txt +++ b/components/esp_tee/subproject/main/CMakeLists.txt @@ -25,10 +25,10 @@ endif() # SoC specific implementation for TEE list(APPEND srcs "soc/${target}/esp_tee_secure_sys_cfg.c" "soc/${target}/esp_tee_pmp_pma_prot_cfg.c" - "soc/${target}/esp_tee_apm_prot_cfg.c" - "soc/${target}/esp_tee_crypto_reset.c") + "soc/${target}/esp_tee_apm_prot_cfg.c") -list(APPEND srcs "soc/common/esp_tee_apm_intr.c") +list(APPEND srcs "soc/common/esp_tee_apm_intr.c" + "soc/common/esp_tee_crypto_reset.c") if(CONFIG_SOC_AES_SUPPORTED) list(APPEND srcs "soc/common/esp_tee_aes_intr.c") diff --git a/components/esp_tee/subproject/main/soc/common/esp_tee_crypto_reset.c b/components/esp_tee/subproject/main/soc/common/esp_tee_crypto_reset.c new file mode 100644 index 00000000000..a80429d6ecf --- /dev/null +++ b/components/esp_tee/subproject/main/soc/common/esp_tee_crypto_reset.c @@ -0,0 +1,78 @@ +/* + * SPDX-FileCopyrightText: 2026 Espressif Systems (Shanghai) CO LTD + * + * SPDX-License-Identifier: Apache-2.0 + */ + +#include "soc/soc_caps.h" + +#if SOC_AES_SUPPORTED +#include "hal/aes_ll.h" +#endif +#if SOC_SHA_SUPPORTED +#include "hal/sha_ll.h" +#endif +#if SOC_MPI_SUPPORTED +#include "hal/mpi_ll.h" +#endif +#if SOC_ECC_SUPPORTED +#include "hal/ecc_ll.h" +#endif +#if SOC_HMAC_SUPPORTED +#include "hal/hmac_ll.h" +#endif +#if SOC_DIG_SIGN_SUPPORTED +#include "hal/ds_ll.h" +#endif +#if SOC_ECDSA_SUPPORTED +#include "hal/ecdsa_ll.h" +#endif + +#include "esp_tee.h" + +void esp_tee_soc_reset_crypto_peripherals(void) +{ + /* Reset the crypto peripherals to a clean state and leave their clocks disabled; drivers re-enable on demand */ +#if SOC_AES_SUPPORTED + aes_ll_enable_bus_clock(true); + aes_ll_reset_register(); + aes_ll_enable_bus_clock(false); +#endif + +#if SOC_SHA_SUPPORTED + sha_ll_enable_bus_clock(true); + sha_ll_reset_register(); + sha_ll_enable_bus_clock(false); +#endif + +#if SOC_MPI_SUPPORTED + mpi_ll_enable_bus_clock(true); + mpi_ll_reset_register(); + mpi_ll_enable_bus_clock(false); +#endif + +#if SOC_ECC_SUPPORTED + ecc_ll_enable_bus_clock(true); + ecc_ll_reset_register(); + ecc_ll_power_up(); + ecc_ll_enable_bus_clock(false); +#endif + +#if SOC_HMAC_SUPPORTED + hmac_ll_enable_bus_clock(true); + hmac_ll_reset_register(); + hmac_ll_enable_bus_clock(false); +#endif + +#if SOC_DIG_SIGN_SUPPORTED + ds_ll_enable_bus_clock(true); + ds_ll_reset_register(); + ds_ll_enable_bus_clock(false); +#endif + +#if SOC_ECDSA_SUPPORTED + ecdsa_ll_enable_bus_clock(true); + ecdsa_ll_reset_register(); + ecdsa_ll_enable_bus_clock(false); +#endif +} diff --git a/components/esp_tee/subproject/main/soc/esp32c5/esp_tee_crypto_reset.c b/components/esp_tee/subproject/main/soc/esp32c5/esp_tee_crypto_reset.c deleted file mode 100644 index a9e1ec6062e..00000000000 --- a/components/esp_tee/subproject/main/soc/esp32c5/esp_tee_crypto_reset.c +++ /dev/null @@ -1,30 +0,0 @@ -/* - * SPDX-FileCopyrightText: 2026 Espressif Systems (Shanghai) CO LTD - * - * SPDX-License-Identifier: Apache-2.0 - */ - -#include "soc/soc.h" -#include "soc/pcr_reg.h" - -#include "esp_tee.h" - -void esp_tee_soc_reset_crypto_peripherals(void) -{ - SET_PERI_REG_MASK(PCR_AES_CONF_REG, PCR_AES_RST_EN); - CLEAR_PERI_REG_MASK(PCR_AES_CONF_REG, PCR_AES_RST_EN); - SET_PERI_REG_MASK(PCR_DS_CONF_REG, PCR_DS_RST_EN); - CLEAR_PERI_REG_MASK(PCR_DS_CONF_REG, PCR_DS_RST_EN); - SET_PERI_REG_MASK(PCR_ECC_CONF_REG, PCR_ECC_RST_EN); - CLEAR_PERI_REG_MASK(PCR_ECC_CONF_REG, PCR_ECC_RST_EN); - SET_PERI_REG_MASK(PCR_ECDSA_CONF_REG, PCR_ECDSA_RST_EN); - CLEAR_PERI_REG_MASK(PCR_ECDSA_CONF_REG, PCR_ECDSA_RST_EN); - SET_PERI_REG_MASK(PCR_HMAC_CONF_REG, PCR_HMAC_RST_EN); - CLEAR_PERI_REG_MASK(PCR_HMAC_CONF_REG, PCR_HMAC_RST_EN); - SET_PERI_REG_MASK(PCR_RSA_CONF_REG, PCR_RSA_RST_EN); - CLEAR_PERI_REG_MASK(PCR_RSA_CONF_REG, PCR_RSA_RST_EN); - SET_PERI_REG_MASK(PCR_SHA_CONF_REG, PCR_SHA_RST_EN); - CLEAR_PERI_REG_MASK(PCR_SHA_CONF_REG, PCR_SHA_RST_EN); - REG_CLR_BIT(PCR_ECC_PD_CTRL_REG, PCR_ECC_MEM_PD); - REG_CLR_BIT(PCR_ECC_PD_CTRL_REG, PCR_ECC_MEM_FORCE_PD); -} diff --git a/components/esp_tee/subproject/main/soc/esp32c5/esp_tee_secure_sys_cfg.c b/components/esp_tee/subproject/main/soc/esp32c5/esp_tee_secure_sys_cfg.c index a6bff015e23..b9a3ec04f75 100644 --- a/components/esp_tee/subproject/main/soc/esp32c5/esp_tee_secure_sys_cfg.c +++ b/components/esp_tee/subproject/main/soc/esp32c5/esp_tee_secure_sys_cfg.c @@ -10,11 +10,6 @@ #include "riscv/encoding.h" #include "hal/apm_hal.h" -#include "hal/aes_ll.h" -#include "hal/sha_ll.h" -#include "hal/hmac_ll.h" -#include "hal/ds_ll.h" -#include "hal/ecc_ll.h" #include "soc/clic_reg.h" #include "soc/interrupts.h" @@ -109,12 +104,8 @@ void esp_tee_soc_secure_sys_init(void) esp_tee_protect_intr_src(ETS_SHA_INTR_SOURCE); // SHA esp_tee_protect_intr_src(ETS_ECC_INTR_SOURCE); // ECC - /* Disable protected crypto peripheral clocks; they will be toggled as needed when the peripheral is in use */ - aes_ll_enable_bus_clock(false); - sha_ll_enable_bus_clock(false); - hmac_ll_enable_bus_clock(false); - ds_ll_enable_bus_clock(false); - ecc_ll_enable_bus_clock(false); + /* Reset the protected crypto peripherals and leave their clocks disabled */ + esp_tee_soc_reset_crypto_peripherals(); } IRAM_ATTR inline void esp_tee_switch_to_ree(uint32_t ns_entry_addr) diff --git a/components/esp_tee/subproject/main/soc/esp32c6/esp_tee_crypto_reset.c b/components/esp_tee/subproject/main/soc/esp32c6/esp_tee_crypto_reset.c deleted file mode 100644 index 1dde41e9401..00000000000 --- a/components/esp_tee/subproject/main/soc/esp32c6/esp_tee_crypto_reset.c +++ /dev/null @@ -1,28 +0,0 @@ -/* - * SPDX-FileCopyrightText: 2026 Espressif Systems (Shanghai) CO LTD - * - * SPDX-License-Identifier: Apache-2.0 - */ - -#include "soc/soc.h" -#include "soc/pcr_reg.h" - -#include "esp_tee.h" - -void esp_tee_soc_reset_crypto_peripherals(void) -{ - SET_PERI_REG_MASK(PCR_AES_CONF_REG, PCR_AES_RST_EN); - SET_PERI_REG_MASK(PCR_DS_CONF_REG, PCR_DS_RST_EN); - SET_PERI_REG_MASK(PCR_ECC_CONF_REG, PCR_ECC_RST_EN); - SET_PERI_REG_MASK(PCR_HMAC_CONF_REG, PCR_HMAC_RST_EN); - SET_PERI_REG_MASK(PCR_RSA_CONF_REG, PCR_RSA_RST_EN); - SET_PERI_REG_MASK(PCR_SHA_CONF_REG, PCR_SHA_RST_EN); - CLEAR_PERI_REG_MASK(PCR_AES_CONF_REG, PCR_AES_RST_EN); - CLEAR_PERI_REG_MASK(PCR_DS_CONF_REG, PCR_DS_RST_EN); - CLEAR_PERI_REG_MASK(PCR_ECC_CONF_REG, PCR_ECC_RST_EN); - CLEAR_PERI_REG_MASK(PCR_HMAC_CONF_REG, PCR_HMAC_RST_EN); - CLEAR_PERI_REG_MASK(PCR_RSA_CONF_REG, PCR_RSA_RST_EN); - CLEAR_PERI_REG_MASK(PCR_SHA_CONF_REG, PCR_SHA_RST_EN); - REG_CLR_BIT(PCR_ECC_PD_CTRL_REG, PCR_ECC_MEM_PD); - REG_CLR_BIT(PCR_ECC_PD_CTRL_REG, PCR_ECC_MEM_FORCE_PD); -} diff --git a/components/esp_tee/subproject/main/soc/esp32c6/esp_tee_secure_sys_cfg.c b/components/esp_tee/subproject/main/soc/esp32c6/esp_tee_secure_sys_cfg.c index 71d0ae73666..8fc4c67aca1 100644 --- a/components/esp_tee/subproject/main/soc/esp32c6/esp_tee_secure_sys_cfg.c +++ b/components/esp_tee/subproject/main/soc/esp32c6/esp_tee_secure_sys_cfg.c @@ -16,11 +16,6 @@ #include "esp_cpu.h" #include "esp_log.h" #include "hal/apm_hal.h" -#include "hal/aes_ll.h" -#include "hal/sha_ll.h" -#include "hal/hmac_ll.h" -#include "hal/ds_ll.h" -#include "hal/ecc_ll.h" #include "esp_tee.h" #include "esp_tee_intr.h" @@ -95,12 +90,8 @@ void esp_tee_soc_secure_sys_init(void) esp_tee_protect_intr_src(ETS_SHA_INTR_SOURCE); // SHA esp_tee_protect_intr_src(ETS_ECC_INTR_SOURCE); // ECC - /* Disable protected crypto peripheral clocks; they will be toggled as needed when the peripheral is in use */ - aes_ll_enable_bus_clock(false); - sha_ll_enable_bus_clock(false); - hmac_ll_enable_bus_clock(false); - ds_ll_enable_bus_clock(false); - ecc_ll_enable_bus_clock(false); + /* Reset the protected crypto peripherals and leave their clocks disabled */ + esp_tee_soc_reset_crypto_peripherals(); } IRAM_ATTR inline void esp_tee_switch_to_ree(uint32_t ree_entry_addr) diff --git a/components/esp_tee/subproject/main/soc/esp32c61/esp_tee_crypto_reset.c b/components/esp_tee/subproject/main/soc/esp32c61/esp_tee_crypto_reset.c deleted file mode 100644 index 58013ff3755..00000000000 --- a/components/esp_tee/subproject/main/soc/esp32c61/esp_tee_crypto_reset.c +++ /dev/null @@ -1,22 +0,0 @@ -/* - * SPDX-FileCopyrightText: 2026 Espressif Systems (Shanghai) CO LTD - * - * SPDX-License-Identifier: Apache-2.0 - */ - -#include "soc/soc.h" -#include "soc/pcr_reg.h" - -#include "esp_tee.h" - -void esp_tee_soc_reset_crypto_peripherals(void) -{ - SET_PERI_REG_MASK(PCR_ECC_CONF_REG, PCR_ECC_RST_EN); - CLEAR_PERI_REG_MASK(PCR_ECC_CONF_REG, PCR_ECC_RST_EN); - SET_PERI_REG_MASK(PCR_ECDSA_CONF_REG, PCR_ECDSA_RST_EN); - CLEAR_PERI_REG_MASK(PCR_ECDSA_CONF_REG, PCR_ECDSA_RST_EN); - SET_PERI_REG_MASK(PCR_SHA_CONF_REG, PCR_SHA_RST_EN); - CLEAR_PERI_REG_MASK(PCR_SHA_CONF_REG, PCR_SHA_RST_EN); - REG_CLR_BIT(PCR_ECC_PD_CTRL_REG, PCR_ECC_MEM_PD); - REG_CLR_BIT(PCR_ECC_PD_CTRL_REG, PCR_ECC_MEM_FORCE_PD); -} diff --git a/components/esp_tee/subproject/main/soc/esp32c61/esp_tee_secure_sys_cfg.c b/components/esp_tee/subproject/main/soc/esp32c61/esp_tee_secure_sys_cfg.c index b1e302bc9b4..8bcafb52ece 100644 --- a/components/esp_tee/subproject/main/soc/esp32c61/esp_tee_secure_sys_cfg.c +++ b/components/esp_tee/subproject/main/soc/esp32c61/esp_tee_secure_sys_cfg.c @@ -10,9 +10,6 @@ #include "riscv/encoding.h" #include "hal/apm_hal.h" -#include "hal/sha_ll.h" -#include "hal/ecc_ll.h" -#include "hal/ecdsa_ll.h" #include "soc/clic_reg.h" #include "soc/interrupts.h" @@ -104,10 +101,8 @@ void esp_tee_soc_secure_sys_init(void) esp_tee_protect_intr_src(ETS_ECC_INTR_SOURCE); // ECC esp_tee_protect_intr_src(ETS_ECDSA_INTR_SOURCE); // ECDSA - /* Disable protected crypto peripheral clocks; they will be toggled as needed when the peripheral is in use */ - sha_ll_enable_bus_clock(false); - ecc_ll_enable_bus_clock(false); - ecdsa_ll_enable_bus_clock(false); + /* Reset the protected crypto peripherals and leave their clocks disabled */ + esp_tee_soc_reset_crypto_peripherals(); } IRAM_ATTR inline void esp_tee_switch_to_ree(uint32_t ns_entry_addr) diff --git a/components/esp_tee/subproject/main/soc/esp32h2/esp_tee_crypto_reset.c b/components/esp_tee/subproject/main/soc/esp32h2/esp_tee_crypto_reset.c deleted file mode 100644 index 96a73fd8c46..00000000000 --- a/components/esp_tee/subproject/main/soc/esp32h2/esp_tee_crypto_reset.c +++ /dev/null @@ -1,30 +0,0 @@ -/* - * SPDX-FileCopyrightText: 2026 Espressif Systems (Shanghai) CO LTD - * - * SPDX-License-Identifier: Apache-2.0 - */ - -#include "soc/soc.h" -#include "soc/pcr_reg.h" - -#include "esp_tee.h" - -void esp_tee_soc_reset_crypto_peripherals(void) -{ - SET_PERI_REG_MASK(PCR_AES_CONF_REG, PCR_AES_RST_EN); - SET_PERI_REG_MASK(PCR_DS_CONF_REG, PCR_DS_RST_EN); - SET_PERI_REG_MASK(PCR_ECC_CONF_REG, PCR_ECC_RST_EN); - SET_PERI_REG_MASK(PCR_ECDSA_CONF_REG, PCR_ECDSA_RST_EN); - SET_PERI_REG_MASK(PCR_HMAC_CONF_REG, PCR_HMAC_RST_EN); - SET_PERI_REG_MASK(PCR_RSA_CONF_REG, PCR_RSA_RST_EN); - SET_PERI_REG_MASK(PCR_SHA_CONF_REG, PCR_SHA_RST_EN); - CLEAR_PERI_REG_MASK(PCR_AES_CONF_REG, PCR_AES_RST_EN); - CLEAR_PERI_REG_MASK(PCR_DS_CONF_REG, PCR_DS_RST_EN); - CLEAR_PERI_REG_MASK(PCR_ECC_CONF_REG, PCR_ECC_RST_EN); - CLEAR_PERI_REG_MASK(PCR_ECDSA_CONF_REG, PCR_ECDSA_RST_EN); - CLEAR_PERI_REG_MASK(PCR_HMAC_CONF_REG, PCR_HMAC_RST_EN); - CLEAR_PERI_REG_MASK(PCR_RSA_CONF_REG, PCR_RSA_RST_EN); - CLEAR_PERI_REG_MASK(PCR_SHA_CONF_REG, PCR_SHA_RST_EN); - REG_CLR_BIT(PCR_ECC_PD_CTRL_REG, PCR_ECC_MEM_PD); - REG_CLR_BIT(PCR_ECC_PD_CTRL_REG, PCR_ECC_MEM_FORCE_PD); -} diff --git a/components/esp_tee/subproject/main/soc/esp32h2/esp_tee_secure_sys_cfg.c b/components/esp_tee/subproject/main/soc/esp32h2/esp_tee_secure_sys_cfg.c index 61da60223a0..1d7a86eacc4 100644 --- a/components/esp_tee/subproject/main/soc/esp32h2/esp_tee_secure_sys_cfg.c +++ b/components/esp_tee/subproject/main/soc/esp32h2/esp_tee_secure_sys_cfg.c @@ -16,11 +16,6 @@ #include "esp_cpu.h" #include "esp_log.h" #include "hal/apm_hal.h" -#include "hal/aes_ll.h" -#include "hal/sha_ll.h" -#include "hal/hmac_ll.h" -#include "hal/ds_ll.h" -#include "hal/ecc_ll.h" #include "esp_tee.h" #include "esp_tee_intr.h" @@ -93,12 +88,8 @@ void esp_tee_soc_secure_sys_init(void) esp_tee_protect_intr_src(ETS_SHA_INTR_SOURCE); // SHA esp_tee_protect_intr_src(ETS_ECC_INTR_SOURCE); // ECC - /* Disable protected crypto peripheral clocks; they will be toggled as needed when the peripheral is in use */ - aes_ll_enable_bus_clock(false); - sha_ll_enable_bus_clock(false); - hmac_ll_enable_bus_clock(false); - ds_ll_enable_bus_clock(false); - ecc_ll_enable_bus_clock(false); + /* Reset the protected crypto peripherals and leave their clocks disabled */ + esp_tee_soc_reset_crypto_peripherals(); } IRAM_ATTR inline void esp_tee_switch_to_ree(uint32_t ree_entry_addr)