From 67affdd43b18643e633f83602fc22b1c2a1461a4 Mon Sep 17 00:00:00 2001 From: "harshal.patil" Date: Mon, 27 Oct 2025 19:10:48 +0530 Subject: [PATCH] fix(hal): Fix MMU PSRAM anti-fi MMU target check In case of ESP32-C5 and ESP32-C61, mmu_ids for PSRAM and Flash MMU are the same due to their shared memory space. Thus, instead of mmu_id we should use mmu_target_t. --- components/hal/esp32c5/include/hal/mmu_ll.h | 4 +++- components/hal/esp32c61/include/hal/mmu_ll.h | 4 +++- components/hal/esp32p4/include/hal/mmu_ll.h | 6 ++++-- 3 files changed, 10 insertions(+), 4 deletions(-) diff --git a/components/hal/esp32c5/include/hal/mmu_ll.h b/components/hal/esp32c5/include/hal/mmu_ll.h index f19bd9a57a6..3775cfd8353 100644 --- a/components/hal/esp32c5/include/hal/mmu_ll.h +++ b/components/hal/esp32c5/include/hal/mmu_ll.h @@ -227,14 +227,16 @@ __attribute__((always_inline)) static inline void mmu_ll_write_entry(uint32_t mm REG_WRITE(SPI_MEM_MMU_ITEM_INDEX_REG(0), entry_id); REG_WRITE(SPI_MEM_MMU_ITEM_CONTENT_REG(0), mmu_raw_value); +#if !BOOTLOADER_BUILD // Anti-FI check to confirm the encryption status for PSRAM entry. // This avoids a potential FI attacks to keep PSRAM unencrypted and // hence read out plaintext in execute from PSRAM model. if (mmu_ll_cache_encryption_enabled() && target == MMU_TARGET_PSRAM0 && efuse_hal_chip_revision() > 100) { ESP_FAULT_ASSERT(REG_READ(SPI_MEM_MMU_ITEM_CONTENT_REG(0)) & SOC_MMU_SENSITIVE); } else { - ESP_FAULT_ASSERT(!(mmu_ll_cache_encryption_enabled() && mmu_id == MMU_LL_PSRAM_MMU_ID && efuse_hal_chip_revision() > 100)); + ESP_FAULT_ASSERT(!(mmu_ll_cache_encryption_enabled() && target == MMU_TARGET_PSRAM0 && efuse_hal_chip_revision() > 100)); } +#endif // !BOOTLOADER_BUILD } #if SOC_PSRAM_ENCRYPTION_PAGE_CONFIGURABLE diff --git a/components/hal/esp32c61/include/hal/mmu_ll.h b/components/hal/esp32c61/include/hal/mmu_ll.h index 9cb0f1b22b1..14e6d24895a 100644 --- a/components/hal/esp32c61/include/hal/mmu_ll.h +++ b/components/hal/esp32c61/include/hal/mmu_ll.h @@ -230,14 +230,16 @@ __attribute__((always_inline)) static inline void mmu_ll_write_entry(uint32_t mm REG_WRITE(SPI_MEM_MMU_ITEM_INDEX_REG(0), entry_id); REG_WRITE(SPI_MEM_MMU_ITEM_CONTENT_REG(0), mmu_raw_value); +#if !BOOTLOADER_BUILD // Anti-FI check to confirm the encryption status for PSRAM entry. // This avoids a potential FI attacks to keep PSRAM unencrypted and // hence read out plaintext in execute from PSRAM model. if (mmu_ll_cache_encryption_enabled() && target == MMU_TARGET_PSRAM0 && efuse_hal_chip_revision() > 100) { ESP_FAULT_ASSERT(REG_READ(SPI_MEM_MMU_ITEM_CONTENT_REG(0)) & SOC_MMU_SENSITIVE); } else { - ESP_FAULT_ASSERT(!(mmu_ll_cache_encryption_enabled() && mmu_id == MMU_LL_PSRAM_MMU_ID && efuse_hal_chip_revision() > 100)); + ESP_FAULT_ASSERT(!(mmu_ll_cache_encryption_enabled() && target == MMU_TARGET_PSRAM0 && efuse_hal_chip_revision() > 100)); } +#endif // !BOOTLOADER_BUILD } #if SOC_PSRAM_ENCRYPTION_PAGE_CONFIGURABLE diff --git a/components/hal/esp32p4/include/hal/mmu_ll.h b/components/hal/esp32p4/include/hal/mmu_ll.h index 4faf492f965..bb989128f3a 100644 --- a/components/hal/esp32p4/include/hal/mmu_ll.h +++ b/components/hal/esp32p4/include/hal/mmu_ll.h @@ -292,14 +292,16 @@ __attribute__((always_inline)) static inline void mmu_ll_write_entry(uint32_t mm REG_WRITE(index_reg, entry_id); REG_WRITE(content_reg, mmu_val); +#if !BOOTLOADER_BUILD // Anti-FI check to confirm the encryption status for PSRAM entry. // This avoids a potential FI attacks to keep PSRAM unencrypted and // hence read out plaintext in execute from PSRAM model. - if (mmu_ll_cache_encryption_enabled() && mmu_id == MMU_LL_PSRAM_MMU_ID) { + if (mmu_ll_cache_encryption_enabled() && target == MMU_TARGET_PSRAM0) { ESP_FAULT_ASSERT(REG_READ(content_reg) & SOC_MMU_PSRAM_SENSITIVE); } else { - ESP_FAULT_ASSERT(!(mmu_ll_cache_encryption_enabled() && mmu_id == MMU_LL_PSRAM_MMU_ID)); + ESP_FAULT_ASSERT(!(mmu_ll_cache_encryption_enabled() && target == MMU_TARGET_PSRAM0)); } +#endif // !BOOTLOADER_BUILD } #if SOC_PSRAM_ENCRYPTION_PAGE_CONFIGURABLE