diff --git a/components/esp_tee/scripts/esp32c5/sec_srv_tbl_default.yml b/components/esp_tee/scripts/esp32c5/sec_srv_tbl_default.yml index 112204f08a9..038e8388762 100644 --- a/components/esp_tee/scripts/esp32c5/sec_srv_tbl_default.yml +++ b/components/esp_tee/scripts/esp32c5/sec_srv_tbl_default.yml @@ -47,10 +47,7 @@ secure_services: type: IDF function: spi_flash_hal_erase_block args: 2 - - id: 10 - type: IDF - function: spi_flash_hal_erase_chip - args: 1 + # ID: 10 empty - id: 11 type: IDF function: spi_flash_hal_erase_sector diff --git a/components/esp_tee/scripts/esp32c6/sec_srv_tbl_default.yml b/components/esp_tee/scripts/esp32c6/sec_srv_tbl_default.yml index 8c6a4ef7b5e..c0a2c52c80a 100644 --- a/components/esp_tee/scripts/esp32c6/sec_srv_tbl_default.yml +++ b/components/esp_tee/scripts/esp32c6/sec_srv_tbl_default.yml @@ -43,10 +43,7 @@ secure_services: type: IDF function: spi_flash_hal_erase_block args: 2 - - id: 9 - type: IDF - function: spi_flash_hal_erase_chip - args: 1 + # ID: 9 empty - id: 10 type: IDF function: spi_flash_hal_erase_sector diff --git a/components/esp_tee/scripts/esp32h2/sec_srv_tbl_default.yml b/components/esp_tee/scripts/esp32h2/sec_srv_tbl_default.yml index 39e1563fc01..80f94feee4d 100644 --- a/components/esp_tee/scripts/esp32h2/sec_srv_tbl_default.yml +++ b/components/esp_tee/scripts/esp32h2/sec_srv_tbl_default.yml @@ -43,10 +43,7 @@ secure_services: type: IDF function: spi_flash_hal_erase_block args: 2 - - id: 9 - type: IDF - function: spi_flash_hal_erase_chip - args: 1 + # ID: 9 empty - id: 10 type: IDF function: spi_flash_hal_erase_sector diff --git a/components/esp_tee/src/esp_secure_service_wrapper.c b/components/esp_tee/src/esp_secure_service_wrapper.c index da4f557c85a..a34ec4df56f 100644 --- a/components/esp_tee/src/esp_secure_service_wrapper.c +++ b/components/esp_tee/src/esp_secure_service_wrapper.c @@ -422,11 +422,6 @@ void IRAM_ATTR __wrap_spi_flash_hal_erase_block(spi_flash_host_inst_t *host, uin esp_tee_service_call(3, SS_SPI_FLASH_HAL_ERASE_BLOCK, host, start_address); } -void IRAM_ATTR __wrap_spi_flash_hal_erase_chip(spi_flash_host_inst_t *host) -{ - esp_tee_service_call(2, SS_SPI_FLASH_HAL_ERASE_CHIP, host); -} - void IRAM_ATTR __wrap_spi_flash_hal_erase_sector(spi_flash_host_inst_t *host, uint32_t start_address) { esp_tee_service_call(3, SS_SPI_FLASH_HAL_ERASE_SECTOR, host, start_address); diff --git a/components/esp_tee/subproject/components/tee_sec_storage/tee_sec_storage.c b/components/esp_tee/subproject/components/tee_sec_storage/tee_sec_storage.c index 790dcf916a7..ff6ef16cfd3 100644 --- a/components/esp_tee/subproject/components/tee_sec_storage/tee_sec_storage.c +++ b/components/esp_tee/subproject/components/tee_sec_storage/tee_sec_storage.c @@ -644,7 +644,11 @@ esp_err_t esp_tee_sec_storage_ecdsa_sign_pbkdf2(const esp_tee_sec_storage_pbkdf2 } hmac_key_id_t key_id = (hmac_key_id_t)(CONFIG_SECURE_TEE_PBKDF2_EFUSE_HMAC_KEY_ID); - esp_efuse_block_t blk = EFUSE_BLK_KEY0 + (esp_efuse_block_t)(key_id); + if (key_id < 0 || key_id >= HMAC_KEY_MAX) { + return ESP_ERR_INVALID_ARG; + } + + esp_efuse_block_t blk = (esp_efuse_block_t)(EFUSE_BLK_KEY0 + key_id); if (esp_efuse_get_key_purpose(blk) != ESP_EFUSE_KEY_PURPOSE_HMAC_UP) { ESP_LOGE(TAG, "HMAC key is not burnt in the specified eFuse block ID"); return ESP_ERR_NOT_FOUND; diff --git a/components/esp_tee/subproject/main/core/esp_secure_services_iram.c b/components/esp_tee/subproject/main/core/esp_secure_services_iram.c index dbfac3a9e2e..169448f406a 100644 --- a/components/esp_tee/subproject/main/core/esp_secure_services_iram.c +++ b/components/esp_tee/subproject/main/core/esp_secure_services_iram.c @@ -304,11 +304,6 @@ void _ss_spi_flash_hal_erase_block(spi_flash_host_inst_t *host, uint32_t start_a spi_flash_hal_erase_block(host, start_address); } -void _ss_spi_flash_hal_erase_chip(spi_flash_host_inst_t *host) -{ - spi_flash_hal_erase_chip(host); -} - void _ss_spi_flash_hal_erase_sector(spi_flash_host_inst_t *host, uint32_t start_address) { bool paddr_chk = esp_tee_flash_check_prange_in_tee_region(start_address, FLASH_SECTOR_SIZE);