Merge branch 'fix/esp32p4_secure_boot_sig_block_v6.1' into 'release/v6.1'

fix(esp32p4): secure boot (ECDSA-P384) and flash encryption eFuse fixes (v6.1)

See merge request espressif/esp-idf!50898
This commit is contained in:
Jiang Jiang Jian
2026-07-18 01:32:56 +08:00
4 changed files with 40 additions and 3 deletions
+4
View File
@@ -588,6 +588,8 @@ menu "Security features"
config SECURE_BOOT_ECDSA_KEY_LEN_384_BITS
bool "Using ECC curve NISTP384 (Recommended)"
depends on SECURE_SIGNED_APPS_ECDSA_V2_SCHEME && SOC_ECDSA_SUPPORT_CURVE_P384
# ESP32-P4 revisions < v3.0 do not support Secure Boot using ECDSA-P384
depends on !ESP32P4_SELECTS_REV_LESS_V3
endchoice
@@ -1164,6 +1166,8 @@ menu "Security features"
default y if SECURE_FLASH_ENCRYPTION_MODE_RELEASE
default n
depends on SECURE_FLASH_ENC_ENABLED && SOC_FLASH_ENCRYPTION_XTS_AES_SUPPORT_PSEUDO_ROUND
# ESP32-P4 revisions < v3.0 do not support the XTS-AES pseudo rounds function
depends on !ESP32P4_SELECTS_REV_LESS_V3
help
If set (default), the bootloader will permanently enable the XTS-AES peripheral's pseudo rounds function.
Note: Enabling this config would burn an efuse.