test(drivers): run flash encryption apps on real hardware

Replace the virtual efuse flash-encryption flow in parlio, rmt, and lcd
test apps with real-device flash_enc configs so CI can validate the same
path used on encryption runners.
This commit is contained in:
morris
2026-07-13 17:13:24 +08:00
parent 41582e1777
commit 13282c44b0
45 changed files with 252 additions and 545 deletions
@@ -1,35 +0,0 @@
# SPDX-FileCopyrightText: 2026 Espressif Systems (Shanghai) CO LTD
# SPDX-License-Identifier: Apache-2.0
import pytest
from _pytest.fixtures import FixtureRequest
from _pytest.monkeypatch import MonkeyPatch
from pytest_embedded_idf.serial import IdfSerial
# This is a custom IdfSerial class to support custom functionality
# which is required only for this test
class EfuseFlashEncSerial(IdfSerial):
@IdfSerial.use_esptool()
def write_flash_no_enc(self) -> None:
self.app.flash_settings['encrypt'] = False
flash_files = []
for file in self.app.flash_files:
# Set encrypted flag to false for each file.
flash_files.append(file._replace(encrypted=False))
# Replace the original tuple with modified tuple with all the files marked as unencrypted.
self.app.flash_files = tuple(flash_files)
# Now flash the files
self.flash()
@pytest.fixture(scope='module')
def monkeypatch_module(request: FixtureRequest) -> MonkeyPatch:
mp = MonkeyPatch()
request.addfinalizer(mp.undo)
return mp
@pytest.fixture(scope='module', autouse=True)
def replace_dut_class(monkeypatch_module: MonkeyPatch) -> None:
monkeypatch_module.setattr('pytest_embedded_idf.IdfSerial', EfuseFlashEncSerial)
@@ -1,7 +0,0 @@
# Name, Type, SubType, Offset, Size, Flags
bootloader, bootloader, primary, N/A, N/A,
partition_table, partition_table, primary, N/A, N/A,
nvs, data, nvs, , 0x4000,
phy_init, data, phy, , 0x1000,
emul_efuse, data, efuse, , 0x2000,
factory, app, factory, , 1M,
1 # Name Type SubType Offset Size Flags
2 bootloader bootloader primary N/A N/A
3 partition_table partition_table primary N/A N/A
4 nvs data nvs 0x4000
5 phy_init data phy 0x1000
6 emul_efuse data efuse 0x2000
7 factory app factory 1M
@@ -24,32 +24,6 @@ def test_rmt(dut: Dut) -> None:
dut.run_all_single_board_cases()
@pytest.mark.generic
@pytest.mark.parametrize(
'config, skip_autoflash',
[
('virt_flash_enc', 'y'),
],
indirect=True,
)
@idf_parametrize(
'target',
soc_filtered_targets('SOC_RMT_SUPPORTED == 1 and SOC_FLASH_ENC_SUPPORTED == 1 and IDF_TARGET not in ["esp32s3"]'),
indirect=['target'],
)
def test_rmt_with_virt_flash_enc(dut: Dut) -> None:
print(' - Erase flash')
dut.serial.erase_flash()
print(' - Start app (flash partition_table and app)')
dut.serial.write_flash_no_enc()
dut.expect('Loading virtual efuse blocks from real efuses')
dut.expect('Checking flash encryption...')
dut.expect('Generating new flash encryption key...')
dut.run_all_single_board_cases()
@pytest.mark.generic
@pytest.mark.parametrize(
'config',
@@ -91,23 +65,31 @@ def test_rmt_psram(dut: Dut) -> None:
dut.run_all_single_board_cases()
@pytest.mark.octal_psram
@pytest.mark.flash_encryption_f4r8
@pytest.mark.parametrize(
'config, skip_autoflash',
'config',
[
('virt_flash_enc', 'y'),
'flash_enc',
],
indirect=True,
)
@idf_parametrize('target', ['esp32s3'], indirect=['target'])
def test_rmt_psram_with_virt_flash_enc(dut: Dut) -> None:
print(' - Erase flash')
dut.serial.erase_flash()
print(' - Start app (flash partition_table and app)')
dut.serial.write_flash_no_enc()
dut.expect('Loading virtual efuse blocks from real efuses')
dut.expect('Checking flash encryption...')
dut.expect('Generating new flash encryption key...')
def test_rmt_with_flash_encryption_esp32s3_f4r8(dut: Dut) -> None:
dut.run_all_single_board_cases()
@pytest.mark.flash_encryption
@pytest.mark.parametrize(
'config',
[
'flash_enc',
],
indirect=True,
)
@idf_parametrize(
'target',
soc_filtered_targets('SOC_RMT_SUPPORT_DMA == 1 and SOC_FLASH_ENC_SUPPORTED == 1 and IDF_TARGET not in ["esp32s3"]'),
indirect=['target'],
)
def test_rmt_with_flash_encryption(dut: Dut) -> None:
dut.run_all_single_board_cases()
@@ -0,0 +1,9 @@
CONFIG_PARTITION_TABLE_OFFSET=0x9000
CONFIG_SECURE_FLASH_ENC_ENABLED=y
CONFIG_SECURE_FLASH_ENCRYPTION_MODE_DEVELOPMENT=y
CONFIG_SECURE_BOOT_ALLOW_ROM_BASIC=y
CONFIG_SECURE_BOOT_ALLOW_JTAG=y
CONFIG_SECURE_FLASH_UART_BOOTLOADER_ALLOW_ENC=y
CONFIG_SECURE_FLASH_UART_BOOTLOADER_ALLOW_DEC=y
CONFIG_SECURE_FLASH_UART_BOOTLOADER_ALLOW_CACHE=y
CONFIG_SECURE_FLASH_REQUIRE_ALREADY_ENABLED=y
@@ -1,12 +0,0 @@
# FLASH_ENCRYPTION with EFUSE_VIRTUAL_KEEP_IN_FLASH
CONFIG_PARTITION_TABLE_OFFSET=0xC000
CONFIG_PARTITION_TABLE_CUSTOM=y
CONFIG_PARTITION_TABLE_CUSTOM_FILENAME="partitions_efuse_emul.csv"
CONFIG_SECURE_FLASH_ENC_ENABLED=y
# Virtual eFuse mode is enough for driver behaviour test.
# Real encryption tests are guaranteed by DMA tests
CONFIG_EFUSE_VIRTUAL=y
CONFIG_EFUSE_VIRTUAL_KEEP_IN_FLASH=y