refactor(esp_system): deduplicate ROM fast wake RTC digest reservation

The digest length and the condition that reserves it at the end of RTC RAM were
duplicated in seven places. Hold the reservation in a hidden Kconfig value that
is zero when the feature does not apply, so every consumer subtracts it
unconditionally, and derive ESP_SECURE_BOOT_DIGEST_LEN from it.
This commit is contained in:
harshal.patil
2026-07-31 11:23:26 +08:00
committed by wuzhenghui
parent 8f397e0407
commit 639e80169d
13 changed files with 93 additions and 62 deletions
@@ -128,10 +128,19 @@ SECTIONS
*(.rtc_timer_data_in_rtc_mem .rtc_timer_data_in_rtc_mem.*)
KEEP(*(.bootloader_data_rtc_mem .bootloader_data_rtc_mem.*))
_bootloader_data_rtc_mem_end = ABSOLUTE(.);
/* ROM keeps the verified image digest in the last bytes of RTC RAM */
. = . + CONFIG_SECURE_BOOT_ROM_FAST_WAKE_RESERVE_SIZE;
_rtc_reserved_end = ABSOLUTE(.);
} > rtc_reserved_seg
#if CONFIG_SECURE_BOOT_ROM_FAST_WAKE_RESERVE_SIZE > 0
ASSERT((_bootloader_data_rtc_mem_end == ORIGIN(rtc_reserved_seg) + LENGTH(rtc_reserved_seg)
- CONFIG_SECURE_BOOT_ROM_FAST_WAKE_RESERVE_SIZE),
"The ROM secure boot fast wake up digest must occupy the last bytes of RTC RAM, and the bootloader retain mem must end where it begins. bootloader_common_get_rtc_retain_mem() computes that address.")
#endif
_rtc_reserved_length = _rtc_reserved_end - _rtc_reserved_start;
ASSERT((_rtc_reserved_length <= LENGTH(rtc_reserved_seg)),
"RTC reserved segment data does not fit.")
@@ -123,10 +123,19 @@ SECTIONS
*(.rtc_timer_data_in_rtc_mem .rtc_timer_data_in_rtc_mem.*)
KEEP(*(.bootloader_data_rtc_mem .bootloader_data_rtc_mem.*))
_bootloader_data_rtc_mem_end = ABSOLUTE(.);
/* ROM keeps the verified image digest in the last bytes of RTC RAM */
. = . + CONFIG_SECURE_BOOT_ROM_FAST_WAKE_RESERVE_SIZE;
_rtc_reserved_end = ABSOLUTE(.);
} > rtc_reserved_seg
#if CONFIG_SECURE_BOOT_ROM_FAST_WAKE_RESERVE_SIZE > 0
ASSERT((_bootloader_data_rtc_mem_end == ORIGIN(rtc_reserved_seg) + LENGTH(rtc_reserved_seg)
- CONFIG_SECURE_BOOT_ROM_FAST_WAKE_RESERVE_SIZE),
"The ROM secure boot fast wake up digest must occupy the last bytes of RTC RAM, and the bootloader retain mem must end where it begins. bootloader_common_get_rtc_retain_mem() computes that address.")
#endif
_rtc_reserved_length = _rtc_reserved_end - _rtc_reserved_start;
ASSERT((_rtc_reserved_length <= LENGTH(rtc_reserved_seg)),
"RTC reserved segment data does not fit.")
@@ -123,10 +123,19 @@ SECTIONS
*(.rtc_timer_data_in_rtc_mem .rtc_timer_data_in_rtc_mem.*)
KEEP(*(.bootloader_data_rtc_mem .bootloader_data_rtc_mem.*))
_bootloader_data_rtc_mem_end = ABSOLUTE(.);
/* ROM keeps the verified image digest in the last bytes of RTC RAM */
. = . + CONFIG_SECURE_BOOT_ROM_FAST_WAKE_RESERVE_SIZE;
_rtc_reserved_end = ABSOLUTE(.);
} > rtc_reserved_seg
#if CONFIG_SECURE_BOOT_ROM_FAST_WAKE_RESERVE_SIZE > 0
ASSERT((_bootloader_data_rtc_mem_end == ORIGIN(rtc_reserved_seg) + LENGTH(rtc_reserved_seg)
- CONFIG_SECURE_BOOT_ROM_FAST_WAKE_RESERVE_SIZE),
"The ROM secure boot fast wake up digest must occupy the last bytes of RTC RAM, and the bootloader retain mem must end where it begins. bootloader_common_get_rtc_retain_mem() computes that address.")
#endif
_rtc_reserved_length = _rtc_reserved_end - _rtc_reserved_start;
ASSERT((_rtc_reserved_length <= LENGTH(rtc_reserved_seg)),
"RTC reserved segment data does not fit.")
@@ -123,10 +123,19 @@ SECTIONS
*(.rtc_timer_data_in_rtc_mem .rtc_timer_data_in_rtc_mem.*)
KEEP(*(.bootloader_data_rtc_mem .bootloader_data_rtc_mem.*))
_bootloader_data_rtc_mem_end = ABSOLUTE(.);
/* ROM keeps the verified image digest in the last bytes of RTC RAM */
. = . + CONFIG_SECURE_BOOT_ROM_FAST_WAKE_RESERVE_SIZE;
_rtc_reserved_end = ABSOLUTE(.);
} > rtc_reserved_seg
#if CONFIG_SECURE_BOOT_ROM_FAST_WAKE_RESERVE_SIZE > 0
ASSERT((_bootloader_data_rtc_mem_end == ORIGIN(rtc_reserved_seg) + LENGTH(rtc_reserved_seg)
- CONFIG_SECURE_BOOT_ROM_FAST_WAKE_RESERVE_SIZE),
"The ROM secure boot fast wake up digest must occupy the last bytes of RTC RAM, and the bootloader retain mem must end where it begins. bootloader_common_get_rtc_retain_mem() computes that address.")
#endif
_rtc_reserved_length = _rtc_reserved_end - _rtc_reserved_start;
ASSERT((_rtc_reserved_length <= LENGTH(rtc_reserved_seg)),
"RTC reserved segment data does not fit.")
@@ -151,10 +151,19 @@ SECTIONS
*(.rtc_timer_data_in_rtc_mem .rtc_timer_data_in_rtc_mem.*)
KEEP(*(.bootloader_data_rtc_mem .bootloader_data_rtc_mem.*))
_bootloader_data_rtc_mem_end = ABSOLUTE(.);
/* ROM keeps the verified image digest in the last bytes of RTC RAM */
. = . + CONFIG_SECURE_BOOT_ROM_FAST_WAKE_RESERVE_SIZE;
_rtc_reserved_end = ABSOLUTE(.);
} > rtc_reserved_seg
#if CONFIG_SECURE_BOOT_ROM_FAST_WAKE_RESERVE_SIZE > 0
ASSERT((_bootloader_data_rtc_mem_end == ORIGIN(rtc_reserved_seg) + LENGTH(rtc_reserved_seg)
- CONFIG_SECURE_BOOT_ROM_FAST_WAKE_RESERVE_SIZE),
"The ROM secure boot fast wake up digest must occupy the last bytes of RTC RAM, and the bootloader retain mem must end where it begins. bootloader_common_get_rtc_retain_mem() computes that address.")
#endif
_rtc_reserved_length = _rtc_reserved_end - _rtc_reserved_start;
ASSERT((_rtc_reserved_length <= LENGTH(rtc_reserved_seg)),
"RTC reserved segment data does not fit.")
@@ -135,10 +135,19 @@ SECTIONS
*(.rtc_timer_data_in_rtc_mem .rtc_timer_data_in_rtc_mem.*)
KEEP(*(.bootloader_data_rtc_mem .bootloader_data_rtc_mem.*))
_bootloader_data_rtc_mem_end = ABSOLUTE(.);
/* ROM keeps the verified image digest in the last bytes of RTC RAM */
. = . + CONFIG_SECURE_BOOT_ROM_FAST_WAKE_RESERVE_SIZE;
_rtc_reserved_end = ABSOLUTE(.);
} > rtc_reserved_seg
#if CONFIG_SECURE_BOOT_ROM_FAST_WAKE_RESERVE_SIZE > 0
ASSERT((_bootloader_data_rtc_mem_end == ORIGIN(rtc_reserved_seg) + LENGTH(rtc_reserved_seg)
- CONFIG_SECURE_BOOT_ROM_FAST_WAKE_RESERVE_SIZE),
"The ROM secure boot fast wake up digest must occupy the last bytes of RTC RAM, and the bootloader retain mem must end where it begins. bootloader_common_get_rtc_retain_mem() computes that address.")
#endif
_rtc_reserved_length = _rtc_reserved_end - _rtc_reserved_start;
ASSERT((_rtc_reserved_length <= LENGTH(rtc_reserved_seg)),
"RTC reserved segment data does not fit.")
+4 -11
View File
@@ -11,13 +11,6 @@
/* CPU instruction prefetch padding size for flash mmap scenario */
#define _esp_flash_mmap_prefetch_pad_size 16
/* Copy from esp_secure_boot.h */
#ifdef CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_384_BITS
#define ESP_SECURE_BOOT_DIGEST_LEN 48
#else /* !CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_384_BITS */
#define ESP_SECURE_BOOT_DIGEST_LEN 32
#endif /* CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_384_BITS */
/*
* PMP region granularity size
* Software may determine the PMP granularity by writing zero to pmp0cfg, then writing all ones
@@ -76,11 +69,11 @@
/* RTC Reserved is placed before ULP memory, expand it to make sure the ULP start address
has the required alignment */
#define ULP_ALIGNMENT_REQ_BYTES 256
#define RESERVE_RTC_MEM ALIGN_UP(ESP_BOOTLOADER_RESERVE_RTC + RTC_TIMER_RESERVE_RTC, ULP_ALIGNMENT_REQ_BYTES)
#elif CONFIG_SECURE_BOOT && CONFIG_ESP_ROM_SUPPORT_SECURE_BOOT_FAST_WAKEUP
#define RESERVE_RTC_MEM (ESP_BOOTLOADER_RESERVE_RTC + RTC_TIMER_RESERVE_RTC + ESP_SECURE_BOOT_DIGEST_LEN)
#define RESERVE_RTC_MEM ALIGN_UP(ESP_BOOTLOADER_RESERVE_RTC + RTC_TIMER_RESERVE_RTC \
+ CONFIG_SECURE_BOOT_ROM_FAST_WAKE_RESERVE_SIZE, ULP_ALIGNMENT_REQ_BYTES)
#else
#define RESERVE_RTC_MEM (ESP_BOOTLOADER_RESERVE_RTC + RTC_TIMER_RESERVE_RTC)
#define RESERVE_RTC_MEM (ESP_BOOTLOADER_RESERVE_RTC + RTC_TIMER_RESERVE_RTC \
+ CONFIG_SECURE_BOOT_ROM_FAST_WAKE_RESERVE_SIZE)
#endif
#endif // SOC_RTC_MEM_SUPPORTED