fix(esp_tee): Avoid crypto peripherals reset with esp_restart() from REE

- Reset the crypto peripherals during TEE initialization
This commit is contained in:
Laukik Hase
2026-06-22 11:18:32 +05:30
parent da36354af9
commit c7a73cb8d3
14 changed files with 113 additions and 165 deletions
@@ -25,10 +25,10 @@ endif()
# SoC specific implementation for TEE
list(APPEND srcs "soc/${target}/esp_tee_secure_sys_cfg.c"
"soc/${target}/esp_tee_pmp_pma_prot_cfg.c"
"soc/${target}/esp_tee_apm_prot_cfg.c"
"soc/${target}/esp_tee_crypto_reset.c")
"soc/${target}/esp_tee_apm_prot_cfg.c")
list(APPEND srcs "soc/common/esp_tee_apm_intr.c")
list(APPEND srcs "soc/common/esp_tee_apm_intr.c"
"soc/common/esp_tee_crypto_reset.c")
if(CONFIG_SOC_AES_SUPPORTED)
list(APPEND srcs "soc/common/esp_tee_aes_intr.c")
@@ -0,0 +1,78 @@
/*
* SPDX-FileCopyrightText: 2026 Espressif Systems (Shanghai) CO LTD
*
* SPDX-License-Identifier: Apache-2.0
*/
#include "soc/soc_caps.h"
#if SOC_AES_SUPPORTED
#include "hal/aes_ll.h"
#endif
#if SOC_SHA_SUPPORTED
#include "hal/sha_ll.h"
#endif
#if SOC_MPI_SUPPORTED
#include "hal/mpi_ll.h"
#endif
#if SOC_ECC_SUPPORTED
#include "hal/ecc_ll.h"
#endif
#if SOC_HMAC_SUPPORTED
#include "hal/hmac_ll.h"
#endif
#if SOC_DIG_SIGN_SUPPORTED
#include "hal/ds_ll.h"
#endif
#if SOC_ECDSA_SUPPORTED
#include "hal/ecdsa_ll.h"
#endif
#include "esp_tee.h"
void esp_tee_soc_reset_crypto_peripherals(void)
{
/* Reset the crypto peripherals to a clean state and leave their clocks disabled; drivers re-enable on demand */
#if SOC_AES_SUPPORTED
aes_ll_enable_bus_clock(true);
aes_ll_reset_register();
aes_ll_enable_bus_clock(false);
#endif
#if SOC_SHA_SUPPORTED
sha_ll_enable_bus_clock(true);
sha_ll_reset_register();
sha_ll_enable_bus_clock(false);
#endif
#if SOC_MPI_SUPPORTED
mpi_ll_enable_bus_clock(true);
mpi_ll_reset_register();
mpi_ll_enable_bus_clock(false);
#endif
#if SOC_ECC_SUPPORTED
ecc_ll_enable_bus_clock(true);
ecc_ll_reset_register();
ecc_ll_power_up();
ecc_ll_enable_bus_clock(false);
#endif
#if SOC_HMAC_SUPPORTED
hmac_ll_enable_bus_clock(true);
hmac_ll_reset_register();
hmac_ll_enable_bus_clock(false);
#endif
#if SOC_DIG_SIGN_SUPPORTED
ds_ll_enable_bus_clock(true);
ds_ll_reset_register();
ds_ll_enable_bus_clock(false);
#endif
#if SOC_ECDSA_SUPPORTED
ecdsa_ll_enable_bus_clock(true);
ecdsa_ll_reset_register();
ecdsa_ll_enable_bus_clock(false);
#endif
}
@@ -1,30 +0,0 @@
/*
* SPDX-FileCopyrightText: 2026 Espressif Systems (Shanghai) CO LTD
*
* SPDX-License-Identifier: Apache-2.0
*/
#include "soc/soc.h"
#include "soc/pcr_reg.h"
#include "esp_tee.h"
void esp_tee_soc_reset_crypto_peripherals(void)
{
SET_PERI_REG_MASK(PCR_AES_CONF_REG, PCR_AES_RST_EN);
CLEAR_PERI_REG_MASK(PCR_AES_CONF_REG, PCR_AES_RST_EN);
SET_PERI_REG_MASK(PCR_DS_CONF_REG, PCR_DS_RST_EN);
CLEAR_PERI_REG_MASK(PCR_DS_CONF_REG, PCR_DS_RST_EN);
SET_PERI_REG_MASK(PCR_ECC_CONF_REG, PCR_ECC_RST_EN);
CLEAR_PERI_REG_MASK(PCR_ECC_CONF_REG, PCR_ECC_RST_EN);
SET_PERI_REG_MASK(PCR_ECDSA_CONF_REG, PCR_ECDSA_RST_EN);
CLEAR_PERI_REG_MASK(PCR_ECDSA_CONF_REG, PCR_ECDSA_RST_EN);
SET_PERI_REG_MASK(PCR_HMAC_CONF_REG, PCR_HMAC_RST_EN);
CLEAR_PERI_REG_MASK(PCR_HMAC_CONF_REG, PCR_HMAC_RST_EN);
SET_PERI_REG_MASK(PCR_RSA_CONF_REG, PCR_RSA_RST_EN);
CLEAR_PERI_REG_MASK(PCR_RSA_CONF_REG, PCR_RSA_RST_EN);
SET_PERI_REG_MASK(PCR_SHA_CONF_REG, PCR_SHA_RST_EN);
CLEAR_PERI_REG_MASK(PCR_SHA_CONF_REG, PCR_SHA_RST_EN);
REG_CLR_BIT(PCR_ECC_PD_CTRL_REG, PCR_ECC_MEM_PD);
REG_CLR_BIT(PCR_ECC_PD_CTRL_REG, PCR_ECC_MEM_FORCE_PD);
}
@@ -10,11 +10,6 @@
#include "riscv/encoding.h"
#include "hal/apm_hal.h"
#include "hal/aes_ll.h"
#include "hal/sha_ll.h"
#include "hal/hmac_ll.h"
#include "hal/ds_ll.h"
#include "hal/ecc_ll.h"
#include "soc/clic_reg.h"
#include "soc/interrupts.h"
@@ -109,12 +104,8 @@ void esp_tee_soc_secure_sys_init(void)
esp_tee_protect_intr_src(ETS_SHA_INTR_SOURCE); // SHA
esp_tee_protect_intr_src(ETS_ECC_INTR_SOURCE); // ECC
/* Disable protected crypto peripheral clocks; they will be toggled as needed when the peripheral is in use */
aes_ll_enable_bus_clock(false);
sha_ll_enable_bus_clock(false);
hmac_ll_enable_bus_clock(false);
ds_ll_enable_bus_clock(false);
ecc_ll_enable_bus_clock(false);
/* Reset the protected crypto peripherals and leave their clocks disabled */
esp_tee_soc_reset_crypto_peripherals();
}
IRAM_ATTR inline void esp_tee_switch_to_ree(uint32_t ns_entry_addr)
@@ -1,28 +0,0 @@
/*
* SPDX-FileCopyrightText: 2026 Espressif Systems (Shanghai) CO LTD
*
* SPDX-License-Identifier: Apache-2.0
*/
#include "soc/soc.h"
#include "soc/pcr_reg.h"
#include "esp_tee.h"
void esp_tee_soc_reset_crypto_peripherals(void)
{
SET_PERI_REG_MASK(PCR_AES_CONF_REG, PCR_AES_RST_EN);
SET_PERI_REG_MASK(PCR_DS_CONF_REG, PCR_DS_RST_EN);
SET_PERI_REG_MASK(PCR_ECC_CONF_REG, PCR_ECC_RST_EN);
SET_PERI_REG_MASK(PCR_HMAC_CONF_REG, PCR_HMAC_RST_EN);
SET_PERI_REG_MASK(PCR_RSA_CONF_REG, PCR_RSA_RST_EN);
SET_PERI_REG_MASK(PCR_SHA_CONF_REG, PCR_SHA_RST_EN);
CLEAR_PERI_REG_MASK(PCR_AES_CONF_REG, PCR_AES_RST_EN);
CLEAR_PERI_REG_MASK(PCR_DS_CONF_REG, PCR_DS_RST_EN);
CLEAR_PERI_REG_MASK(PCR_ECC_CONF_REG, PCR_ECC_RST_EN);
CLEAR_PERI_REG_MASK(PCR_HMAC_CONF_REG, PCR_HMAC_RST_EN);
CLEAR_PERI_REG_MASK(PCR_RSA_CONF_REG, PCR_RSA_RST_EN);
CLEAR_PERI_REG_MASK(PCR_SHA_CONF_REG, PCR_SHA_RST_EN);
REG_CLR_BIT(PCR_ECC_PD_CTRL_REG, PCR_ECC_MEM_PD);
REG_CLR_BIT(PCR_ECC_PD_CTRL_REG, PCR_ECC_MEM_FORCE_PD);
}
@@ -16,11 +16,6 @@
#include "esp_cpu.h"
#include "esp_log.h"
#include "hal/apm_hal.h"
#include "hal/aes_ll.h"
#include "hal/sha_ll.h"
#include "hal/hmac_ll.h"
#include "hal/ds_ll.h"
#include "hal/ecc_ll.h"
#include "esp_tee.h"
#include "esp_tee_intr.h"
@@ -95,12 +90,8 @@ void esp_tee_soc_secure_sys_init(void)
esp_tee_protect_intr_src(ETS_SHA_INTR_SOURCE); // SHA
esp_tee_protect_intr_src(ETS_ECC_INTR_SOURCE); // ECC
/* Disable protected crypto peripheral clocks; they will be toggled as needed when the peripheral is in use */
aes_ll_enable_bus_clock(false);
sha_ll_enable_bus_clock(false);
hmac_ll_enable_bus_clock(false);
ds_ll_enable_bus_clock(false);
ecc_ll_enable_bus_clock(false);
/* Reset the protected crypto peripherals and leave their clocks disabled */
esp_tee_soc_reset_crypto_peripherals();
}
IRAM_ATTR inline void esp_tee_switch_to_ree(uint32_t ree_entry_addr)
@@ -1,22 +0,0 @@
/*
* SPDX-FileCopyrightText: 2026 Espressif Systems (Shanghai) CO LTD
*
* SPDX-License-Identifier: Apache-2.0
*/
#include "soc/soc.h"
#include "soc/pcr_reg.h"
#include "esp_tee.h"
void esp_tee_soc_reset_crypto_peripherals(void)
{
SET_PERI_REG_MASK(PCR_ECC_CONF_REG, PCR_ECC_RST_EN);
CLEAR_PERI_REG_MASK(PCR_ECC_CONF_REG, PCR_ECC_RST_EN);
SET_PERI_REG_MASK(PCR_ECDSA_CONF_REG, PCR_ECDSA_RST_EN);
CLEAR_PERI_REG_MASK(PCR_ECDSA_CONF_REG, PCR_ECDSA_RST_EN);
SET_PERI_REG_MASK(PCR_SHA_CONF_REG, PCR_SHA_RST_EN);
CLEAR_PERI_REG_MASK(PCR_SHA_CONF_REG, PCR_SHA_RST_EN);
REG_CLR_BIT(PCR_ECC_PD_CTRL_REG, PCR_ECC_MEM_PD);
REG_CLR_BIT(PCR_ECC_PD_CTRL_REG, PCR_ECC_MEM_FORCE_PD);
}
@@ -10,9 +10,6 @@
#include "riscv/encoding.h"
#include "hal/apm_hal.h"
#include "hal/sha_ll.h"
#include "hal/ecc_ll.h"
#include "hal/ecdsa_ll.h"
#include "soc/clic_reg.h"
#include "soc/interrupts.h"
@@ -104,10 +101,8 @@ void esp_tee_soc_secure_sys_init(void)
esp_tee_protect_intr_src(ETS_ECC_INTR_SOURCE); // ECC
esp_tee_protect_intr_src(ETS_ECDSA_INTR_SOURCE); // ECDSA
/* Disable protected crypto peripheral clocks; they will be toggled as needed when the peripheral is in use */
sha_ll_enable_bus_clock(false);
ecc_ll_enable_bus_clock(false);
ecdsa_ll_enable_bus_clock(false);
/* Reset the protected crypto peripherals and leave their clocks disabled */
esp_tee_soc_reset_crypto_peripherals();
}
IRAM_ATTR inline void esp_tee_switch_to_ree(uint32_t ns_entry_addr)
@@ -1,30 +0,0 @@
/*
* SPDX-FileCopyrightText: 2026 Espressif Systems (Shanghai) CO LTD
*
* SPDX-License-Identifier: Apache-2.0
*/
#include "soc/soc.h"
#include "soc/pcr_reg.h"
#include "esp_tee.h"
void esp_tee_soc_reset_crypto_peripherals(void)
{
SET_PERI_REG_MASK(PCR_AES_CONF_REG, PCR_AES_RST_EN);
SET_PERI_REG_MASK(PCR_DS_CONF_REG, PCR_DS_RST_EN);
SET_PERI_REG_MASK(PCR_ECC_CONF_REG, PCR_ECC_RST_EN);
SET_PERI_REG_MASK(PCR_ECDSA_CONF_REG, PCR_ECDSA_RST_EN);
SET_PERI_REG_MASK(PCR_HMAC_CONF_REG, PCR_HMAC_RST_EN);
SET_PERI_REG_MASK(PCR_RSA_CONF_REG, PCR_RSA_RST_EN);
SET_PERI_REG_MASK(PCR_SHA_CONF_REG, PCR_SHA_RST_EN);
CLEAR_PERI_REG_MASK(PCR_AES_CONF_REG, PCR_AES_RST_EN);
CLEAR_PERI_REG_MASK(PCR_DS_CONF_REG, PCR_DS_RST_EN);
CLEAR_PERI_REG_MASK(PCR_ECC_CONF_REG, PCR_ECC_RST_EN);
CLEAR_PERI_REG_MASK(PCR_ECDSA_CONF_REG, PCR_ECDSA_RST_EN);
CLEAR_PERI_REG_MASK(PCR_HMAC_CONF_REG, PCR_HMAC_RST_EN);
CLEAR_PERI_REG_MASK(PCR_RSA_CONF_REG, PCR_RSA_RST_EN);
CLEAR_PERI_REG_MASK(PCR_SHA_CONF_REG, PCR_SHA_RST_EN);
REG_CLR_BIT(PCR_ECC_PD_CTRL_REG, PCR_ECC_MEM_PD);
REG_CLR_BIT(PCR_ECC_PD_CTRL_REG, PCR_ECC_MEM_FORCE_PD);
}
@@ -16,11 +16,6 @@
#include "esp_cpu.h"
#include "esp_log.h"
#include "hal/apm_hal.h"
#include "hal/aes_ll.h"
#include "hal/sha_ll.h"
#include "hal/hmac_ll.h"
#include "hal/ds_ll.h"
#include "hal/ecc_ll.h"
#include "esp_tee.h"
#include "esp_tee_intr.h"
@@ -93,12 +88,8 @@ void esp_tee_soc_secure_sys_init(void)
esp_tee_protect_intr_src(ETS_SHA_INTR_SOURCE); // SHA
esp_tee_protect_intr_src(ETS_ECC_INTR_SOURCE); // ECC
/* Disable protected crypto peripheral clocks; they will be toggled as needed when the peripheral is in use */
aes_ll_enable_bus_clock(false);
sha_ll_enable_bus_clock(false);
hmac_ll_enable_bus_clock(false);
ds_ll_enable_bus_clock(false);
ecc_ll_enable_bus_clock(false);
/* Reset the protected crypto peripherals and leave their clocks disabled */
esp_tee_soc_reset_crypto_peripherals();
}
IRAM_ATTR inline void esp_tee_switch_to_ree(uint32_t ree_entry_addr)