From 1b11c82b1ab04ae875ff8ca49528520d777db451 Mon Sep 17 00:00:00 2001 From: "nilesh.kale" Date: Thu, 16 Jul 2026 15:05:04 +0530 Subject: [PATCH] fix(bootloader_support): set SECURE_BOOT_SHA384_EN eFuse on ESP32-P4 Set SECURE_BOOT_SHA384_EN when enabling ECDSA-P384 Secure Boot V2 on ESP32-P4, as done on C5/H4/S31, so that ROM verifies the bootloader using the SHA-384 scheme. The eFuse exists only on the rev >= v3.0 eFuse table, so the Kconfig option is gated on rev >= v3.0. --- components/bootloader/Kconfig.projbuild | 2 ++ .../src/esp32p4/secure_boot_secure_features.c | 6 +++++- 2 files changed, 7 insertions(+), 1 deletion(-) diff --git a/components/bootloader/Kconfig.projbuild b/components/bootloader/Kconfig.projbuild index 6893a9b88e9..3705448c597 100644 --- a/components/bootloader/Kconfig.projbuild +++ b/components/bootloader/Kconfig.projbuild @@ -590,6 +590,8 @@ menu "Security features" config SECURE_BOOT_ECDSA_KEY_LEN_384_BITS bool "Using ECC curve NISTP384 (Recommended)" depends on SECURE_SIGNED_APPS_ECDSA_V2_SCHEME && SOC_ECDSA_SUPPORT_CURVE_P384 + # ESP32-P4 revisions < v3.0 do not support Secure Boot using ECDSA-P384 + depends on !ESP32P4_SELECTS_REV_LESS_V3 endchoice diff --git a/components/bootloader_support/src/esp32p4/secure_boot_secure_features.c b/components/bootloader_support/src/esp32p4/secure_boot_secure_features.c index 34fe744809b..8e904d6c797 100644 --- a/components/bootloader_support/src/esp32p4/secure_boot_secure_features.c +++ b/components/bootloader_support/src/esp32p4/secure_boot_secure_features.c @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2022-2023 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2022-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -49,6 +49,10 @@ esp_err_t esp_secure_boot_enable_secure_features(void) esp_efuse_write_field_bit(ESP_EFUSE_SECURE_BOOT_AGGRESSIVE_REVOKE); #endif +#if CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_384_BITS + esp_efuse_write_field_bit(ESP_EFUSE_SECURE_BOOT_SHA384_EN); +#endif + esp_efuse_write_field_bit(ESP_EFUSE_SECURE_BOOT_EN); #ifndef CONFIG_SECURE_BOOT_V2_ALLOW_EFUSE_RD_DIS