diff --git a/components/esp_psram/system_layer/esp_psram.c b/components/esp_psram/system_layer/esp_psram.c index 7c34e6aea44..a3ba41e2393 100644 --- a/components/esp_psram/system_layer/esp_psram.c +++ b/components/esp_psram/system_layer/esp_psram.c @@ -19,6 +19,7 @@ #include "freertos/FreeRTOS.h" #include "esp_heap_caps_init.h" #include "esp_psram.h" +#include "esp_macros.h" #include "esp_mmu_map.h" #include "hal/mmu_hal.h" #include "hal/mmu_ll.h" @@ -290,7 +291,7 @@ static void s_psram_mapping(uint32_t psram_available_size, uint32_t start_page) { esp_err_t ret = ESP_FAIL; #if CONFIG_SPIRAM_ENC_EXEMPT - size_t enc_exempt_size = ALIGN_UP_BY((size_t)CONFIG_SPIRAM_ENC_EXEMPT_SIZE * 1024, MMU_PAGE_SIZE); + size_t enc_exempt_size = ESP_ALIGN_UP((size_t)CONFIG_SPIRAM_ENC_EXEMPT_SIZE * 1024, MMU_PAGE_SIZE); if (enc_exempt_size >= psram_available_size) { ESP_EARLY_LOGE(TAG, "SPIRAM_ENC_EXEMPT_SIZE (%dKB) >= available PSRAM (%dKB); disabling carve-out", (int)(enc_exempt_size / 1024), (int)(psram_available_size / 1024)); diff --git a/components/hal/esp32s31/include/hal/mmu_ll.h b/components/hal/esp32s31/include/hal/mmu_ll.h index 75b9bd55365..40a95f6ec6c 100644 --- a/components/hal/esp32s31/include/hal/mmu_ll.h +++ b/components/hal/esp32s31/include/hal/mmu_ll.h @@ -588,6 +588,24 @@ static inline uint32_t mmu_ll_entry_id_to_vaddr_base(uint32_t mmu_id, uint32_t e return mmu_ll_laddr_to_vaddr(laddr, type, (mmu_id == MMU_LL_FLASH_MMU_ID) ? MMU_TARGET_FLASH0 : MMU_TARGET_PSRAM0); } +/** + * Write a PSRAM MMU entry without the SENSITIVE bit, used only for the + * carved-out unencrypted region (see CONFIG_SPIRAM_ENC_EXEMPT). + * + * No anti-FI check: the SENSITIVE bit is intentionally clear, and an FI flip + * that sets it would force decryption of plaintext data (garbage, fails safe). + */ +__attribute__((always_inline)) static inline void mmu_ll_write_entry_no_enc(uint32_t mmu_id, uint32_t entry_id, uint32_t mmu_val) +{ + HAL_ASSERT(mmu_id == MMU_LL_PSRAM_MMU_ID); + + mmu_val |= SOC_MMU_PSRAM_VALID; + mmu_val |= SOC_MMU_ACCESS_PSRAM; + + REG_WRITE(SPI_MEM_S_MMU_ITEM_INDEX_REG, entry_id); + REG_WRITE(SPI_MEM_S_MMU_ITEM_CONTENT_REG, mmu_val); +} + #ifdef __cplusplus } #endif diff --git a/components/soc/esp32s31/include/soc/Kconfig.soc_caps.in b/components/soc/esp32s31/include/soc/Kconfig.soc_caps.in index 023070cf68a..27dfec13fc5 100644 --- a/components/soc/esp32s31/include/soc/Kconfig.soc_caps.in +++ b/components/soc/esp32s31/include/soc/Kconfig.soc_caps.in @@ -1271,6 +1271,10 @@ config SOC_FLASH_ENCRYPTED_XTS_AES_BLOCK_MAX int default 64 +config SOC_PSRAM_ENCRYPTION_PAGE_CONFIGURABLE + bool + default y + config SOC_RECOVERY_BOOTLOADER_SUPPORTED bool default y diff --git a/components/soc/esp32s31/include/soc/soc_caps.h b/components/soc/esp32s31/include/soc/soc_caps.h index f0549b97bc7..30b88f16ded 100644 --- a/components/soc/esp32s31/include/soc/soc_caps.h +++ b/components/soc/esp32s31/include/soc/soc_caps.h @@ -473,6 +473,9 @@ #define SOC_FLASH_ENCRYPTION_XTS_AES_SUPPORT_PSEUDO_ROUND 1 #define SOC_FLASH_ENCRYPTED_XTS_AES_BLOCK_MAX (64) +/*-------------------------- PSRAM Encryption CAPS----------------------------*/ +#define SOC_PSRAM_ENCRYPTION_PAGE_CONFIGURABLE 1 /* PSRAM encryption can be configured on a MMU page basis */ + /*------------------------Bootloader CAPS---------------------------------*/ /* Support Recovery Bootloader */ #define SOC_RECOVERY_BOOTLOADER_SUPPORTED (1)