fix(mmap): fixed some API read wrong data via mmap when flash being erased/written while XIP on PSRAM

Before:

The cache won't be disabled when XIP on psram. But during flash
erasing/programming, read data will be courrupt.

When XIP in psram is enabled, the image is not mapped to the cache so
usually there will be no flash access. The only way to read from flash
is via the driver or use mmap. The driver has protection during erasing,
while th mmap region not.

Now:

Mmap APIs provide a flag to make mmap->unmap region mutually exclusive
to flash erase/programming when XIP from psram. SPI Flash write APIs
will benefit from this. When the flag is used, no concurrent access to
mapped region will happen while writing; otherwise the cache will be
disable to avoid data corruption.

Most ESP-IDF APIs calls mmap with this flag. As for users calling
mmap-like APIs directly, they can choose whether to enable this by a
flag.

Closes https://github.com/espressif/esp-idf/issues/14897
This commit is contained in:
Xiao Xufeng
2026-07-15 18:57:08 +08:00
committed by Michael (XIAO Xufeng)
parent 39a219331c
commit 3e8389cc31
73 changed files with 1678 additions and 487 deletions
@@ -87,7 +87,9 @@ uint32_t bootloader_mmap_get_free_pages(void);
*
* Call bootloader_munmap once for each successful call to bootloader_mmap.
*
* In esp-idf app, this function maps directly to spi_flash_mmap.
* In esp-idf app, this function maps directly to spi_flash_mmap with the @ref
* spi_flash_mmap_flag_t::SPI_FLASH_MMAP_FLAG_BLOCKS_WRITE flag set. When XIP on PSRAM (`CONFIG_SPIRAM_XIP_FROM_PSRAM`) enabled, flash erasing/writing
* will be blocked until unmap.
*
* @param offset - Starting flash offset to map to memory.
* @param length - Length of data to map.
@@ -66,7 +66,7 @@ const void *bootloader_mmap(uint32_t src_addr, uint32_t size)
const void *result = NULL;
uint32_t src_page = src_addr & ~(SPI_FLASH_MMU_PAGE_SIZE - 1);
size += (src_addr - src_page);
esp_err_t err = spi_flash_mmap(src_page, size, SPI_FLASH_MMAP_DATA, &result, &map);
esp_err_t err = spi_flash_mmap(src_page, size, SPI_FLASH_MMAP_FLAG_DATA | SPI_FLASH_MMAP_FLAG_BLOCKS_WRITE, &result, &map);
if (err != ESP_OK) {
ESP_EARLY_LOGE(TAG, "spi_flash_mmap failed: 0x%x", err);
return NULL;
@@ -109,6 +109,8 @@ esp_comm_gpio_hold_t bootloader_common_check_long_hold_gpio_level(uint32_t num_p
/**
* @brief Erase the partition data that is specified in the transferred list.
*
* @note This function can't be called in app.
*
* @param[in] list_erase String containing a list of cleared partitions. Like this "nvs, phy". The string must be null-terminal.
* @param[in] ota_data_erase If true then the OTA data partition will be cleared (if there is it in partition table).
* @return Returns true on success, false otherwise.
@@ -86,6 +86,7 @@ bool bootloader_common_label_search(const char *list, char *label)
return false;
}
//This function erases while mmap is not unmapped yet. Can't be called in the app while XIP on PSRAM.
bool bootloader_common_erase_part_type_data(const char *list_erase, bool ota_data_erase)
{
const esp_partition_info_t *partitions;
@@ -36,9 +36,6 @@
#include "esp_app_desc.h"
#include "esp_secure_boot.h"
#include "esp_flash_encrypt.h"
#ifndef BOOTLOADER_BUILD
#include "spi_flash_mmap.h"
#endif
#include "esp_flash_partitions.h"
#include "bootloader_flash_priv.h"
#include "bootloader_random.h"