From cae147af08248d9f5dc7e252fb14a9f01961a2c9 Mon Sep 17 00:00:00 2001 From: "nilesh.kale" Date: Wed, 15 Apr 2026 17:52:29 +0530 Subject: [PATCH] feat: enable flash encryption for ESP32-H4 --- .../flash_encryption_secure_features.c | 41 ++++- .../test_apps/parlio/pytest_parlio_unity.py | 1 + .../include/hal/spi_flash_encrypted_ll.h | 39 ++++- .../esp32h4/include/soc/Kconfig.soc_caps.in | 10 +- components/soc/esp32h4/include/soc/soc_caps.h | 11 +- .../soc/esp32h4/include/soc/xts_aes_reg.h | 2 - .../spi_flash/test_apps/.build-test-rules.yml | 4 +- .../test_apps/flash_encryption/README.md | 4 +- docs/en/security/esp32h4_log.inc | 143 +++++++++++++++++- docs/zh_CN/security/esp32h4_log.inc | 143 +++++++++++++++++- 10 files changed, 375 insertions(+), 23 deletions(-) diff --git a/components/bootloader_support/src/esp32h4/flash_encryption_secure_features.c b/components/bootloader_support/src/esp32h4/flash_encryption_secure_features.c index 3dd205d2f24..90205a01cde 100644 --- a/components/bootloader_support/src/esp32h4/flash_encryption_secure_features.c +++ b/components/bootloader_support/src/esp32h4/flash_encryption_secure_features.c @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2025 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2025-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -12,12 +12,45 @@ #include "esp_log.h" #include "sdkconfig.h" -//TODO: [ESP32H4] IDF-12261 - ESP_LOG_ATTR_TAG(TAG, "flash_encrypt"); esp_err_t esp_flash_encryption_enable_secure_features(void) { - abort(); +#ifndef CONFIG_SECURE_FLASH_UART_BOOTLOADER_ALLOW_ENC + ESP_LOGI(TAG, "Disable UART bootloader encryption..."); + esp_efuse_write_field_bit(ESP_EFUSE_DIS_DOWNLOAD_MANUAL_ENCRYPT); +#else + ESP_LOGW(TAG, "Not disabling UART bootloader encryption"); +#endif + +#ifndef CONFIG_SECURE_FLASH_UART_BOOTLOADER_ALLOW_CACHE + ESP_LOGI(TAG, "Disable UART bootloader cache..."); + esp_efuse_write_field_bit(ESP_EFUSE_SPI_DOWNLOAD_MSPI_DIS); +#else + ESP_LOGW(TAG, "Not disabling UART bootloader cache - SECURITY COMPROMISED"); +#endif + +#ifndef CONFIG_SECURE_BOOT_ALLOW_JTAG + ESP_LOGI(TAG, "Disable JTAG..."); + esp_efuse_write_field_bit(ESP_EFUSE_DIS_PAD_JTAG); + esp_efuse_write_field_bit(ESP_EFUSE_DIS_USB_JTAG); +#else + ESP_LOGW(TAG, "Not disabling JTAG - SECURITY COMPROMISED"); +#endif + + esp_efuse_write_field_bit(ESP_EFUSE_DIS_DIRECT_BOOT); + +#if defined(CONFIG_SECURE_FLASH_PSEUDO_ROUND_FUNC) && CONFIG_SECURE_FLASH_PSEUDO_ROUND_FUNC + ESP_LOGI(TAG, "Enable XTS-AES pseudo rounds function..."); + uint8_t xts_pseudo_level = CONFIG_SECURE_FLASH_PSEUDO_ROUND_FUNC_STRENGTH; + esp_efuse_write_field_blob(ESP_EFUSE_XTS_DPA_PSEUDO_LEVEL, &xts_pseudo_level, ESP_EFUSE_XTS_DPA_PSEUDO_LEVEL[0]->bit_count); +#endif + +#if defined(CONFIG_SECURE_BOOT_V2_ENABLED) && !defined(CONFIG_SECURE_BOOT_V2_ALLOW_EFUSE_RD_DIS) + // This bit is set when enabling Secure Boot V2, but we can't enable it until this later point in the first boot + // otherwise the Flash Encryption key cannot be read protected + esp_efuse_write_field_bit(ESP_EFUSE_WR_DIS_RD_DIS); +#endif + return ESP_OK; } diff --git a/components/esp_driver_parlio/test_apps/parlio/pytest_parlio_unity.py b/components/esp_driver_parlio/test_apps/parlio/pytest_parlio_unity.py index 52e8d600bb9..ad398c66b7b 100644 --- a/components/esp_driver_parlio/test_apps/parlio/pytest_parlio_unity.py +++ b/components/esp_driver_parlio/test_apps/parlio/pytest_parlio_unity.py @@ -31,6 +31,7 @@ def test_parlio(dut: Dut) -> None: ], indirect=True, ) +@pytest.mark.temp_skip_ci(targets=['esp32h4'], reason='cannot pass') # TODO: IDF-15613 @idf_parametrize( 'target', soc_filtered_targets('SOC_PARLIO_SUPPORTED == 1 and SOC_FLASH_ENC_SUPPORTED == 1'), indirect=['target'] ) diff --git a/components/esp_hal_mspi/esp32h4/include/hal/spi_flash_encrypted_ll.h b/components/esp_hal_mspi/esp32h4/include/hal/spi_flash_encrypted_ll.h index e7ec9cba569..1049d7910d4 100644 --- a/components/esp_hal_mspi/esp32h4/include/hal/spi_flash_encrypted_ll.h +++ b/components/esp_hal_mspi/esp32h4/include/hal/spi_flash_encrypted_ll.h @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2025 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2025-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -17,11 +17,11 @@ #include #include "soc/hp_system_reg.h" #include "soc/xts_aes_reg.h" +#include "soc/spi_mem_reg.h" #include "soc/soc.h" #include "soc/soc_caps.h" #include "hal/assert.h" - -//TODO: [ESP32H4] IDF-12261 inherited from verification branch, need check +#include "hal/spi_flash_encrypt_types.h" #ifdef __cplusplus extern "C" { @@ -148,6 +148,39 @@ static inline bool spi_flash_encrypt_ll_check(uint32_t address, uint32_t length) return ((address % length) == 0) ? true : false; } +#if SOC_FLASH_ENCRYPTION_XTS_AES_SUPPORT_PSEUDO_ROUND +/** + * @brief Enable the pseudo-round function during XTS-AES operations + * + * @param mode set the mode for pseudo rounds, zero to disable, with increasing security upto three. + * @param base basic number of pseudo rounds, zero if disable + * @param increment increment number of pseudo rounds, zero if disable + * @param key_rng_cnt update frequency of the pseudo-key, zero if disable + */ +static inline void spi_flash_encrypt_ll_enable_pseudo_rounds(esp_xts_aes_psuedo_rounds_state_t mode, uint8_t base, uint8_t increment, uint8_t key_rng_cnt) +{ + REG_SET_FIELD(SPI_MEM_XTS_PSEUDO_ROUND_CONF_REG(0), SPI_MEM_MODE_PSEUDO, mode); + + if (mode != ESP_XTS_AES_PSEUDO_ROUNDS_DISABLE) { + REG_SET_FIELD(SPI_MEM_XTS_PSEUDO_ROUND_CONF_REG(0), SPI_MEM_PSEUDO_BASE, base); + REG_SET_FIELD(SPI_MEM_XTS_PSEUDO_ROUND_CONF_REG(0), SPI_MEM_PSEUDO_INC, increment); + REG_SET_FIELD(SPI_MEM_XTS_PSEUDO_ROUND_CONF_REG(0), SPI_MEM_PSEUDO_RNG_CNT, key_rng_cnt); + } else { + REG_SET_FIELD(SPI_MEM_XTS_PSEUDO_ROUND_CONF_REG(0), SPI_MEM_PSEUDO_BASE, 0); + REG_SET_FIELD(SPI_MEM_XTS_PSEUDO_ROUND_CONF_REG(0), SPI_MEM_PSEUDO_INC, 0); + REG_SET_FIELD(SPI_MEM_XTS_PSEUDO_ROUND_CONF_REG(0), SPI_MEM_PSEUDO_RNG_CNT, 0); + } +} + +/** + * @brief Check if the pseudo round function is supported + */ +static inline bool spi_flash_encrypt_ll_is_pseudo_rounds_function_supported(void) +{ + return true; +} +#endif + #ifdef __cplusplus } #endif diff --git a/components/soc/esp32h4/include/soc/Kconfig.soc_caps.in b/components/soc/esp32h4/include/soc/Kconfig.soc_caps.in index 4ce6694398b..06c3f7f167d 100644 --- a/components/soc/esp32h4/include/soc/Kconfig.soc_caps.in +++ b/components/soc/esp32h4/include/soc/Kconfig.soc_caps.in @@ -149,7 +149,7 @@ config SOC_ECC_EXTENDED_MODES_SUPPORTED config SOC_FLASH_ENC_SUPPORTED bool - default n + default y config SOC_SECURE_BOOT_SUPPORTED bool @@ -1007,6 +1007,10 @@ config SOC_FLASH_ENCRYPTION_XTS_AES bool default y +config SOC_FLASH_ENCRYPTION_XTS_AES_OPTIONS + bool + default y + config SOC_FLASH_ENCRYPTION_XTS_AES_128 bool default y @@ -1015,6 +1019,10 @@ config SOC_FLASH_ENCRYPTION_XTS_AES_256 bool default y +config SOC_FLASH_ENCRYPTION_XTS_AES_SUPPORT_PSEUDO_ROUND + bool + default y + config SOC_APM_CTRL_FILTER_SUPPORTED bool default y diff --git a/components/soc/esp32h4/include/soc/soc_caps.h b/components/soc/esp32h4/include/soc/soc_caps.h index 4fd46b63e48..2cae148504a 100644 --- a/components/soc/esp32h4/include/soc/soc_caps.h +++ b/components/soc/esp32h4/include/soc/soc_caps.h @@ -71,9 +71,8 @@ #define SOC_HMAC_SUPPORTED 1 #define SOC_ECC_SUPPORTED 1 #define SOC_ECC_EXTENDED_MODES_SUPPORTED 1 -#define SOC_FLASH_ENC_SUPPORTED 0 // TODO: [ESP32H4] IDF-12261 +#define SOC_FLASH_ENC_SUPPORTED 1 #define SOC_SECURE_BOOT_SUPPORTED 1 - #define SOC_BOD_SUPPORTED 1 // #define SOC_APM_SUPPORTED 1 // TODO: [ESP32H4] IDF-12256 #define SOC_PMU_SUPPORTED 1 // TODO: [ESP32H4] IDF-12286 @@ -435,9 +434,11 @@ /*-------------------------- Flash Encryption CAPS----------------------------*/ #define SOC_FLASH_ENCRYPTED_XTS_AES_BLOCK_MAX (64) -#define SOC_FLASH_ENCRYPTION_XTS_AES 1 -#define SOC_FLASH_ENCRYPTION_XTS_AES_128 1 -#define SOC_FLASH_ENCRYPTION_XTS_AES_256 1 +#define SOC_FLASH_ENCRYPTION_XTS_AES 1 +#define SOC_FLASH_ENCRYPTION_XTS_AES_OPTIONS 1 +#define SOC_FLASH_ENCRYPTION_XTS_AES_128 1 +#define SOC_FLASH_ENCRYPTION_XTS_AES_256 1 +#define SOC_FLASH_ENCRYPTION_XTS_AES_SUPPORT_PSEUDO_ROUND 1 /*-------------------------- APM CAPS ----------------------------------------*/ #define SOC_APM_CTRL_FILTER_SUPPORTED 1 /*!< Support for APM control filter */ diff --git a/components/soc/esp32h4/include/soc/xts_aes_reg.h b/components/soc/esp32h4/include/soc/xts_aes_reg.h index f76f2696df9..7d77938bd6a 100644 --- a/components/soc/esp32h4/include/soc/xts_aes_reg.h +++ b/components/soc/esp32h4/include/soc/xts_aes_reg.h @@ -10,8 +10,6 @@ extern "C" { #endif -//TODO: [ESP32H4] IDF-12506 inherit from verify code, need check - #define XTS_AES_PLAIN_MEM(i) (REG_SPI_MEM_BASE(i) + 0x300) /* XTS_AES_PLAIN : R/W ;bitpos:[31:0] ;default: 32'h0 ; */ /*description: This field is only used to generate include file in c case. This field is useles diff --git a/components/spi_flash/test_apps/.build-test-rules.yml b/components/spi_flash/test_apps/.build-test-rules.yml index 99f2ee3a1e7..3f5a2eaccbd 100644 --- a/components/spi_flash/test_apps/.build-test-rules.yml +++ b/components/spi_flash/test_apps/.build-test-rules.yml @@ -45,9 +45,9 @@ components/spi_flash/test_apps/esp_flash_stress: components/spi_flash/test_apps/flash_encryption: disable: - - if: IDF_TARGET in ["esp32h4", "esp32s31"] + - if: IDF_TARGET in ["esp32s31"] temporary: true - reason: not support yet # TODO: [ESP32H4] IDF-12261 [ESP32S31] IDF-14628 + reason: not support yet # TODO: [ESP32S21] IDF-14628 disable_test: - if: IDF_TARGET in ["esp32c2", "esp32s2", "esp32c6", "esp32h2", "esp32p4", "esp32c5", "esp32c61", "esp32h21", "esp32h4"] temporary: true diff --git a/components/spi_flash/test_apps/flash_encryption/README.md b/components/spi_flash/test_apps/flash_encryption/README.md index fa6da374092..1360df1b6b4 100644 --- a/components/spi_flash/test_apps/flash_encryption/README.md +++ b/components/spi_flash/test_apps/flash_encryption/README.md @@ -1,5 +1,5 @@ -| Supported Targets | ESP32 | ESP32-C2 | ESP32-C3 | ESP32-C5 | ESP32-C6 | ESP32-C61 | ESP32-H2 | ESP32-H21 | ESP32-P4 | ESP32-S2 | ESP32-S3 | -| ----------------- | ----- | -------- | -------- | -------- | -------- | --------- | -------- | --------- | -------- | -------- | -------- | +| Supported Targets | ESP32 | ESP32-C2 | ESP32-C3 | ESP32-C5 | ESP32-C6 | ESP32-C61 | ESP32-H2 | ESP32-H21 | ESP32-H4 | ESP32-P4 | ESP32-S2 | ESP32-S3 | +| ----------------- | ----- | -------- | -------- | -------- | -------- | --------- | -------- | --------- | -------- | -------- | -------- | -------- | ## Prepare runner diff --git a/docs/en/security/esp32h4_log.inc b/docs/en/security/esp32h4_log.inc index 61dd838690c..5b725675a65 100644 --- a/docs/en/security/esp32h4_log.inc +++ b/docs/en/security/esp32h4_log.inc @@ -3,7 +3,72 @@ .. code-block:: none - To be updated + rst:0x1 (POWERON),boot:0x3f (SPI_FAST_FLASH_BOOT) + SPI mode:DIO, clock div:2 + load:0x408565d0,len:0x2878 + load:0x4084d150,len:0x820 + load:0x4084f350,len:0x4088 + entry 0x4084d1a4 + I (138) boot: ESP-IDF v6.1-dev-2651-g37b56060853 2nd stage bootloader + I (140) boot: compile time Feb 13 2026 14:20:36 + I (141) boot: Multicore bootloader + I (149) boot: chip revision: v0.0 + I (154) boot: efuse block revision: v0.0 + I (166) boot.esp32h4: SPI Speed : 24MHz + I (177) boot.esp32h4: SPI Mode : DIO + I (189) boot.esp32h4: SPI Flash Size : 4MB + I (201) boot: Enabling RNG early entropy source... + I (237) boot: Partition Table: + I (245) boot: ## Label Usage Type ST Offset Length + I (265) boot: 0 nvs WiFi data 01 02 0000e000 00006000 + I (284) boot: 1 storage Unknown data 01 ff 00014000 00001000 + I (304) boot: 2 factory factory app 00 00 00020000 00100000 + I (324) boot: 3 nvs_key NVS keys 01 04 00120000 00001000 + I (344) boot: 4 custom_nvs WiFi data 01 02 00121000 00006000 + I (364) boot: 5 fat_encrypted Unknown data 01 81 00127000 00096000 + I (383) boot: 6 fat_not_encr Unknown data 01 81 001bd000 00096000 + I (405) boot: End of partition table + I (414) esp_image: segment 0: paddr=00020020 vaddr=42030020 size=09b18h ( 39704) map + I (487) esp_image: segment 1: paddr=00029b40 vaddr=40810000 size=064d8h ( 25816) load + I (511) esp_image: segment 2: paddr=00030020 vaddr=42000020 size=21ab8h (137912) map + I (611) esp_image: segment 3: paddr=00051ae0 vaddr=408164d8 size=02154h ( 8532) load + I (622) esp_image: segment 4: paddr=00053c3c vaddr=40818630 size=01ebch ( 7868) load + I (663) boot: Loaded app from partition at offset 0x20000 + I (674) boot: Checking flash encryption... + I (686) efuse: Batch mode of writing fields is enabled + I (700) flash_encrypt: Generating new flash encryption key... + E (716) fpga_rng: Project configuration is for internal FPGA use, RNG will not work + I (739) efuse: Writing EFUSE_BLK_KEY0 with purpose 4 + W (753) flash_encrypt: Not disabling UART bootloader encryption + I (769) flash_encrypt: Disable UART bootloader cache... + I (784) flash_encrypt: Disable JTAG... + I (797) efuse: BURN BLOCK4 + I (815) efuse: BURN BLOCK4 - OK (write block == read block) + I (818) efuse: BURN BLOCK0 + I (834) efuse: BURN BLOCK0 - OK (write block == read block) + I (842) efuse: Batch mode. Prepared fields are committed + I (857) esp_image: segment 0: paddr=00002020 vaddr=408565d0 size=02878h ( 10360) + I (885) esp_image: segment 1: paddr=000048a0 vaddr=4084d150 size=00820h ( 2080) + I (902) esp_image: segment 2: paddr=000050c8 vaddr=4084f350 size=04088h ( 16520) + I (2796) flash_encrypt: bootloader encrypted successfully + I (3015) flash_encrypt: partition table encrypted and loaded successfully + I (3016) flash_encrypt: Encrypting partition 1 at offset 0x14000 (length 0x1000)... + I (3242) flash_encrypt: Done encrypting + I (3244) esp_image: segment 0: paddr=00020020 vaddr=42030020 size=09b18h ( 39704) map + I (3276) esp_image: segment 1: paddr=00029b40 vaddr=40810000 size=064d8h ( 25816) + I (3298) esp_image: segment 2: paddr=00030020 vaddr=42000020 size=21ab8h (137912) map + I (3398) esp_image: segment 3: paddr=00051ae0 vaddr=408164d8 size=02154h ( 8532) + I (3408) esp_image: segment 4: paddr=00053c3c vaddr=40818630 size=01ebch ( 7868) + I (3445) flash_encrypt: Encrypting partition 2 at offset 0x20000 (length 0x35b20)... + I (16257) flash_encrypt: Done encrypting + I (16258) flash_encrypt: Encrypting partition 3 at offset 0x120000 (length 0x1000)... + I (16474) flash_encrypt: Done encrypting + I (16475) flash_encrypt: Encrypting partition 5 at offset 0x127000 (length 0x96000)... + I (46265) flash_encrypt: Done encrypting + I (46267) efuse: BURN BLOCK0 + I (46275) efuse: BURN BLOCK0 - OK (all write block bits are set) + I (46279) flash_encrypt: Flash encryption completed + I (46281) boot: Resetting with flash encryption enabled... ------ @@ -11,7 +76,81 @@ .. code-block:: none - To be updated + rst:0x3 (RTC_SW_HPSYS),boot:0x3f (SPI_FAST_FLASH_BOOT) + use legacy efuse key + SPI mode:DIO, clock div:2 + load:0x408565d0,len:0x2878 + load:0x4084d150,len:0x820 + load:0x4084f350,len:0x4088 + entry 0x4084d1a4 + I (157) boot: ESP-IDF v6.1-dev-2651-g37b56060853 2nd stage bootloader + I (159) boot: compile time Feb 13 2026 14:20:36 + I (160) boot: Multicore bootloader + I (168) boot: chip revision: v0.0 + I (173) boot: efuse block revision: v0.0 + I (184) boot.esp32h4: SPI Speed : 24MHz + I (196) boot.esp32h4: SPI Mode : DIO + I (208) boot.esp32h4: SPI Flash Size : 4MB + I (219) boot: Enabling RNG early entropy source... + I (256) boot: Partition Table: + I (264) boot: ## Label Usage Type ST Offset Length + I (284) boot: 0 nvs WiFi data 01 02 0000e000 00006000 + I (303) boot: 1 storage Unknown data 01 ff 00014000 00001000 + I (323) boot: 2 factory factory app 00 00 00020000 00100000 + I (343) boot: 3 nvs_key NVS keys 01 04 00120000 00001000 + I (363) boot: 4 custom_nvs WiFi data 01 02 00121000 00006000 + I (382) boot: 5 fat_encrypted Unknown data 01 81 00127000 00096000 + I (402) boot: 6 fat_not_encr Unknown data 01 81 001bd000 00096000 + I (424) boot: End of partition table + I (433) esp_image: segment 0: paddr=00020020 vaddr=42030020 size=09b18h ( 39704) map + I (510) esp_image: segment 1: paddr=00029b40 vaddr=40810000 size=064d8h ( 25816) load + I (535) esp_image: segment 2: paddr=00030020 vaddr=42000020 size=21ab8h (137912) map + I (648) esp_image: segment 3: paddr=00051ae0 vaddr=408164d8 size=02154h ( 8532) load + I (659) esp_image: segment 4: paddr=00053c3c vaddr=40818630 size=01ebch ( 7868) load + I (700) boot: Loaded app from partition at offset 0x20000 + I (711) boot: Checking flash encryption... + I (722) flash_encrypt: flash encryption is enabled (1 plaintext flashes left) + I (743) boot: Disabling RNG early entropy source... + I (817) cpu_start: Multicore app + I (821) cpu_start: Pro cpu start user code + I (829) cpu_start: cpu freq: 32000000 Hz + I (840) app_init: Application information: + I (851) app_init: Project name: flash_encryption + I (865) app_init: App version: v6.1-dev-2651-g37b56060853 + I (882) app_init: Compile time: Feb 13 2026 14:20:40 + I (897) app_init: ELF file SHA256: 1ed3e1bde... + I (910) app_init: ESP-IDF: v6.1-dev-2651-g37b56060853 + I (927) efuse_init: Min chip rev: v0.0 + I (938) efuse_init: Max chip rev: v0.99 + I (950) efuse_init: Chip rev: v0.0 + I (962) heap_init: Initializing. RAM available for dynamic allocation: + I (981) heap_init: At 4081BE20 len 0003F530 (253 KiB): RAM + I (996) heap_init: At 4085B350 len 00004B58 (18 KiB): RAM + I (1016) spi_flash: detected chip: gd + I (1022) spi_flash: flash io: dio + W (1033) flash_encrypt: Flash encryption mode is DEVELOPMENT (not secure) + I (1054) sleep_gpio: Configure to isolate all GPIO pins in sleep state + I (1071) sleep_gpio: Enable automatic switching of GPIO sleep configuration + I (1094) sleep_clock: Modem Power, Clock and Reset sleep retention initialization + I (1111) nvs_sec_provider: NVS Encryption - Registering Flash encryption-based scheme... + I (1140) main_task: Started on CPU0 + I (1150) main_task: Calling app_main() + + Example to check Flash Encryption status + This is esp32h4 chip with 2 CPU core(s), WiFi/BLE, silicon revision v0.0, 4MB external flash + FLASH_CRYPT_CNT eFuse value is 1 + Flash encryption feature is enabled in DEVELOPMENT mode + Erasing partition "storage" (0x1000 bytes) + Writing data with esp_partition_write: + I (1220) example: 0x4081e800 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f |................| + I (1220) example: 0x4081e810 10 11 12 13 14 15 16 17 18 19 1a 1b 1c 1d 1e 1f |................| + Reading with esp_partition_read: + I (1230) example: 0x4081e820 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f |................| + I (1240) example: 0x4081e830 10 11 12 13 14 15 16 17 18 19 1a 1b 1c 1d 1e 1f |................| + Reading with esp_flash_read: + I (1250) example: 0x4081e820 8a 20 78 9a cc bd 90 3a 96 0b 50 25 09 3b df c9 |. x....:..P%.;..| + I (1260) example: 0x4081e830 d5 d7 0b fe af d2 cb 9a 3f e7 50 9f e7 b5 98 fc |........?.P.....| + I (4170) main_task: Returned from app_main() ------ diff --git a/docs/zh_CN/security/esp32h4_log.inc b/docs/zh_CN/security/esp32h4_log.inc index 61dd838690c..5b725675a65 100644 --- a/docs/zh_CN/security/esp32h4_log.inc +++ b/docs/zh_CN/security/esp32h4_log.inc @@ -3,7 +3,72 @@ .. code-block:: none - To be updated + rst:0x1 (POWERON),boot:0x3f (SPI_FAST_FLASH_BOOT) + SPI mode:DIO, clock div:2 + load:0x408565d0,len:0x2878 + load:0x4084d150,len:0x820 + load:0x4084f350,len:0x4088 + entry 0x4084d1a4 + I (138) boot: ESP-IDF v6.1-dev-2651-g37b56060853 2nd stage bootloader + I (140) boot: compile time Feb 13 2026 14:20:36 + I (141) boot: Multicore bootloader + I (149) boot: chip revision: v0.0 + I (154) boot: efuse block revision: v0.0 + I (166) boot.esp32h4: SPI Speed : 24MHz + I (177) boot.esp32h4: SPI Mode : DIO + I (189) boot.esp32h4: SPI Flash Size : 4MB + I (201) boot: Enabling RNG early entropy source... + I (237) boot: Partition Table: + I (245) boot: ## Label Usage Type ST Offset Length + I (265) boot: 0 nvs WiFi data 01 02 0000e000 00006000 + I (284) boot: 1 storage Unknown data 01 ff 00014000 00001000 + I (304) boot: 2 factory factory app 00 00 00020000 00100000 + I (324) boot: 3 nvs_key NVS keys 01 04 00120000 00001000 + I (344) boot: 4 custom_nvs WiFi data 01 02 00121000 00006000 + I (364) boot: 5 fat_encrypted Unknown data 01 81 00127000 00096000 + I (383) boot: 6 fat_not_encr Unknown data 01 81 001bd000 00096000 + I (405) boot: End of partition table + I (414) esp_image: segment 0: paddr=00020020 vaddr=42030020 size=09b18h ( 39704) map + I (487) esp_image: segment 1: paddr=00029b40 vaddr=40810000 size=064d8h ( 25816) load + I (511) esp_image: segment 2: paddr=00030020 vaddr=42000020 size=21ab8h (137912) map + I (611) esp_image: segment 3: paddr=00051ae0 vaddr=408164d8 size=02154h ( 8532) load + I (622) esp_image: segment 4: paddr=00053c3c vaddr=40818630 size=01ebch ( 7868) load + I (663) boot: Loaded app from partition at offset 0x20000 + I (674) boot: Checking flash encryption... + I (686) efuse: Batch mode of writing fields is enabled + I (700) flash_encrypt: Generating new flash encryption key... + E (716) fpga_rng: Project configuration is for internal FPGA use, RNG will not work + I (739) efuse: Writing EFUSE_BLK_KEY0 with purpose 4 + W (753) flash_encrypt: Not disabling UART bootloader encryption + I (769) flash_encrypt: Disable UART bootloader cache... + I (784) flash_encrypt: Disable JTAG... + I (797) efuse: BURN BLOCK4 + I (815) efuse: BURN BLOCK4 - OK (write block == read block) + I (818) efuse: BURN BLOCK0 + I (834) efuse: BURN BLOCK0 - OK (write block == read block) + I (842) efuse: Batch mode. Prepared fields are committed + I (857) esp_image: segment 0: paddr=00002020 vaddr=408565d0 size=02878h ( 10360) + I (885) esp_image: segment 1: paddr=000048a0 vaddr=4084d150 size=00820h ( 2080) + I (902) esp_image: segment 2: paddr=000050c8 vaddr=4084f350 size=04088h ( 16520) + I (2796) flash_encrypt: bootloader encrypted successfully + I (3015) flash_encrypt: partition table encrypted and loaded successfully + I (3016) flash_encrypt: Encrypting partition 1 at offset 0x14000 (length 0x1000)... + I (3242) flash_encrypt: Done encrypting + I (3244) esp_image: segment 0: paddr=00020020 vaddr=42030020 size=09b18h ( 39704) map + I (3276) esp_image: segment 1: paddr=00029b40 vaddr=40810000 size=064d8h ( 25816) + I (3298) esp_image: segment 2: paddr=00030020 vaddr=42000020 size=21ab8h (137912) map + I (3398) esp_image: segment 3: paddr=00051ae0 vaddr=408164d8 size=02154h ( 8532) + I (3408) esp_image: segment 4: paddr=00053c3c vaddr=40818630 size=01ebch ( 7868) + I (3445) flash_encrypt: Encrypting partition 2 at offset 0x20000 (length 0x35b20)... + I (16257) flash_encrypt: Done encrypting + I (16258) flash_encrypt: Encrypting partition 3 at offset 0x120000 (length 0x1000)... + I (16474) flash_encrypt: Done encrypting + I (16475) flash_encrypt: Encrypting partition 5 at offset 0x127000 (length 0x96000)... + I (46265) flash_encrypt: Done encrypting + I (46267) efuse: BURN BLOCK0 + I (46275) efuse: BURN BLOCK0 - OK (all write block bits are set) + I (46279) flash_encrypt: Flash encryption completed + I (46281) boot: Resetting with flash encryption enabled... ------ @@ -11,7 +76,81 @@ .. code-block:: none - To be updated + rst:0x3 (RTC_SW_HPSYS),boot:0x3f (SPI_FAST_FLASH_BOOT) + use legacy efuse key + SPI mode:DIO, clock div:2 + load:0x408565d0,len:0x2878 + load:0x4084d150,len:0x820 + load:0x4084f350,len:0x4088 + entry 0x4084d1a4 + I (157) boot: ESP-IDF v6.1-dev-2651-g37b56060853 2nd stage bootloader + I (159) boot: compile time Feb 13 2026 14:20:36 + I (160) boot: Multicore bootloader + I (168) boot: chip revision: v0.0 + I (173) boot: efuse block revision: v0.0 + I (184) boot.esp32h4: SPI Speed : 24MHz + I (196) boot.esp32h4: SPI Mode : DIO + I (208) boot.esp32h4: SPI Flash Size : 4MB + I (219) boot: Enabling RNG early entropy source... + I (256) boot: Partition Table: + I (264) boot: ## Label Usage Type ST Offset Length + I (284) boot: 0 nvs WiFi data 01 02 0000e000 00006000 + I (303) boot: 1 storage Unknown data 01 ff 00014000 00001000 + I (323) boot: 2 factory factory app 00 00 00020000 00100000 + I (343) boot: 3 nvs_key NVS keys 01 04 00120000 00001000 + I (363) boot: 4 custom_nvs WiFi data 01 02 00121000 00006000 + I (382) boot: 5 fat_encrypted Unknown data 01 81 00127000 00096000 + I (402) boot: 6 fat_not_encr Unknown data 01 81 001bd000 00096000 + I (424) boot: End of partition table + I (433) esp_image: segment 0: paddr=00020020 vaddr=42030020 size=09b18h ( 39704) map + I (510) esp_image: segment 1: paddr=00029b40 vaddr=40810000 size=064d8h ( 25816) load + I (535) esp_image: segment 2: paddr=00030020 vaddr=42000020 size=21ab8h (137912) map + I (648) esp_image: segment 3: paddr=00051ae0 vaddr=408164d8 size=02154h ( 8532) load + I (659) esp_image: segment 4: paddr=00053c3c vaddr=40818630 size=01ebch ( 7868) load + I (700) boot: Loaded app from partition at offset 0x20000 + I (711) boot: Checking flash encryption... + I (722) flash_encrypt: flash encryption is enabled (1 plaintext flashes left) + I (743) boot: Disabling RNG early entropy source... + I (817) cpu_start: Multicore app + I (821) cpu_start: Pro cpu start user code + I (829) cpu_start: cpu freq: 32000000 Hz + I (840) app_init: Application information: + I (851) app_init: Project name: flash_encryption + I (865) app_init: App version: v6.1-dev-2651-g37b56060853 + I (882) app_init: Compile time: Feb 13 2026 14:20:40 + I (897) app_init: ELF file SHA256: 1ed3e1bde... + I (910) app_init: ESP-IDF: v6.1-dev-2651-g37b56060853 + I (927) efuse_init: Min chip rev: v0.0 + I (938) efuse_init: Max chip rev: v0.99 + I (950) efuse_init: Chip rev: v0.0 + I (962) heap_init: Initializing. RAM available for dynamic allocation: + I (981) heap_init: At 4081BE20 len 0003F530 (253 KiB): RAM + I (996) heap_init: At 4085B350 len 00004B58 (18 KiB): RAM + I (1016) spi_flash: detected chip: gd + I (1022) spi_flash: flash io: dio + W (1033) flash_encrypt: Flash encryption mode is DEVELOPMENT (not secure) + I (1054) sleep_gpio: Configure to isolate all GPIO pins in sleep state + I (1071) sleep_gpio: Enable automatic switching of GPIO sleep configuration + I (1094) sleep_clock: Modem Power, Clock and Reset sleep retention initialization + I (1111) nvs_sec_provider: NVS Encryption - Registering Flash encryption-based scheme... + I (1140) main_task: Started on CPU0 + I (1150) main_task: Calling app_main() + + Example to check Flash Encryption status + This is esp32h4 chip with 2 CPU core(s), WiFi/BLE, silicon revision v0.0, 4MB external flash + FLASH_CRYPT_CNT eFuse value is 1 + Flash encryption feature is enabled in DEVELOPMENT mode + Erasing partition "storage" (0x1000 bytes) + Writing data with esp_partition_write: + I (1220) example: 0x4081e800 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f |................| + I (1220) example: 0x4081e810 10 11 12 13 14 15 16 17 18 19 1a 1b 1c 1d 1e 1f |................| + Reading with esp_partition_read: + I (1230) example: 0x4081e820 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f |................| + I (1240) example: 0x4081e830 10 11 12 13 14 15 16 17 18 19 1a 1b 1c 1d 1e 1f |................| + Reading with esp_flash_read: + I (1250) example: 0x4081e820 8a 20 78 9a cc bd 90 3a 96 0b 50 25 09 3b df c9 |. x....:..P%.;..| + I (1260) example: 0x4081e830 d5 d7 0b fe af d2 cb 9a 3f e7 50 9f e7 b5 98 fc |........?.P.....| + I (4170) main_task: Returned from app_main() ------