mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-02 03:00:34 +03:00
Merge branch 'feat/psram_enc_exempt_v5.5' into 'release/v5.5'
feat(esp_psram): add option to carve unencrypted PSRAM region (v5.5) See merge request espressif/esp-idf!49931
This commit is contained in:
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2022-2024 Espressif Systems (Shanghai) CO LTD
|
||||
* SPDX-FileCopyrightText: 2022-2026 Espressif Systems (Shanghai) CO LTD
|
||||
*
|
||||
* SPDX-License-Identifier: Apache-2.0
|
||||
*/
|
||||
@@ -227,6 +227,23 @@ __attribute__((always_inline)) static inline void mmu_ll_write_entry(uint32_t mm
|
||||
REG_WRITE(SPI_MEM_MMU_ITEM_CONTENT_REG(0), mmu_raw_value);
|
||||
}
|
||||
|
||||
#if SOC_PSRAM_ENCRYPTION_PAGE_CONFIGURABLE
|
||||
/**
|
||||
* Write a PSRAM MMU entry without the SENSITIVE bit, used only for the
|
||||
* carved-out unencrypted region (see CONFIG_SPIRAM_ENC_EXEMPT).
|
||||
*
|
||||
* No anti-FI check: the SENSITIVE bit is intentionally clear, and an FI flip
|
||||
* that sets it would force decryption of plaintext data (garbage, fails safe).
|
||||
*/
|
||||
__attribute__((always_inline)) static inline void mmu_ll_write_entry_no_enc(uint32_t mmu_id, uint32_t entry_id, uint32_t mmu_val)
|
||||
{
|
||||
(void)mmu_id;
|
||||
uint32_t mmu_raw_value = mmu_val | SOC_MMU_ACCESS_SPIRAM | SOC_MMU_VALID;
|
||||
REG_WRITE(SPI_MEM_MMU_ITEM_INDEX_REG(0), entry_id);
|
||||
REG_WRITE(SPI_MEM_MMU_ITEM_CONTENT_REG(0), mmu_raw_value);
|
||||
}
|
||||
#endif
|
||||
|
||||
/**
|
||||
* Read the raw value from MMU table
|
||||
*
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2024 Espressif Systems (Shanghai) CO LTD
|
||||
* SPDX-FileCopyrightText: 2024-2026 Espressif Systems (Shanghai) CO LTD
|
||||
*
|
||||
* SPDX-License-Identifier: Apache-2.0
|
||||
*/
|
||||
@@ -10,6 +10,7 @@
|
||||
|
||||
#include "soc/spi_mem_reg.h"
|
||||
#include "soc/ext_mem_defs.h"
|
||||
#include "soc/soc_caps.h"
|
||||
#include "hal/assert.h"
|
||||
#include "hal/mmu_types.h"
|
||||
#include "hal/efuse_ll.h"
|
||||
@@ -229,6 +230,23 @@ __attribute__((always_inline)) static inline void mmu_ll_write_entry(uint32_t mm
|
||||
REG_WRITE(SPI_MEM_MMU_ITEM_CONTENT_REG(0), mmu_raw_value);
|
||||
}
|
||||
|
||||
#if SOC_PSRAM_ENCRYPTION_PAGE_CONFIGURABLE
|
||||
/**
|
||||
* Write a PSRAM MMU entry without the SENSITIVE bit, used only for the
|
||||
* carved-out unencrypted region (see CONFIG_SPIRAM_ENC_EXEMPT).
|
||||
*
|
||||
* No anti-FI check: the SENSITIVE bit is intentionally clear, and an FI flip
|
||||
* that sets it would force decryption of plaintext data (garbage, fails safe).
|
||||
*/
|
||||
__attribute__((always_inline)) static inline void mmu_ll_write_entry_no_enc(uint32_t mmu_id, uint32_t entry_id, uint32_t mmu_val)
|
||||
{
|
||||
(void)mmu_id;
|
||||
uint32_t mmu_raw_value = mmu_val | SOC_MMU_ACCESS_SPIRAM | SOC_MMU_VALID;
|
||||
REG_WRITE(SPI_MEM_MMU_ITEM_INDEX_REG(0), entry_id);
|
||||
REG_WRITE(SPI_MEM_MMU_ITEM_CONTENT_REG(0), mmu_raw_value);
|
||||
}
|
||||
#endif
|
||||
|
||||
/**
|
||||
* Read the raw value from MMU table
|
||||
*
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2022-2025 Espressif Systems (Shanghai) CO LTD
|
||||
* SPDX-FileCopyrightText: 2022-2026 Espressif Systems (Shanghai) CO LTD
|
||||
*
|
||||
* SPDX-License-Identifier: Apache-2.0
|
||||
*/
|
||||
@@ -11,6 +11,7 @@
|
||||
#include "soc/spi_mem_c_reg.h"
|
||||
#include "soc/spi_mem_s_reg.h"
|
||||
#include "soc/ext_mem_defs.h"
|
||||
#include "soc/soc_caps.h"
|
||||
#include "hal/assert.h"
|
||||
#include "hal/mmu_types.h"
|
||||
#include "hal/efuse_ll.h"
|
||||
@@ -291,6 +292,26 @@ __attribute__((always_inline)) static inline void mmu_ll_write_entry(uint32_t mm
|
||||
REG_WRITE(content_reg, mmu_val);
|
||||
}
|
||||
|
||||
#if SOC_PSRAM_ENCRYPTION_PAGE_CONFIGURABLE
|
||||
/**
|
||||
* Write a PSRAM MMU entry without the SENSITIVE bit, used only for the
|
||||
* carved-out unencrypted region (see CONFIG_SPIRAM_ENC_EXEMPT).
|
||||
*
|
||||
* No anti-FI check: the SENSITIVE bit is intentionally clear, and an FI flip
|
||||
* that sets it would force decryption of plaintext data (garbage, fails safe).
|
||||
*/
|
||||
__attribute__((always_inline)) static inline void mmu_ll_write_entry_no_enc(uint32_t mmu_id, uint32_t entry_id, uint32_t mmu_val)
|
||||
{
|
||||
HAL_ASSERT(mmu_id == MMU_LL_PSRAM_MMU_ID);
|
||||
|
||||
mmu_val |= SOC_MMU_PSRAM_VALID;
|
||||
mmu_val |= SOC_MMU_ACCESS_PSRAM;
|
||||
|
||||
REG_WRITE(SPI_MEM_S_MMU_ITEM_INDEX_REG, entry_id);
|
||||
REG_WRITE(SPI_MEM_S_MMU_ITEM_CONTENT_REG, mmu_val);
|
||||
}
|
||||
#endif
|
||||
|
||||
/**
|
||||
* Read the raw value from MMU table
|
||||
*
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2010-2025 Espressif Systems (Shanghai) CO LTD
|
||||
* SPDX-FileCopyrightText: 2010-2026 Espressif Systems (Shanghai) CO LTD
|
||||
*
|
||||
* SPDX-License-Identifier: Apache-2.0
|
||||
*/
|
||||
@@ -64,6 +64,19 @@ uint32_t mmu_hal_bytes_to_pages(uint32_t mmu_id, uint32_t bytes);
|
||||
*/
|
||||
void mmu_hal_map_region(uint32_t mmu_id, mmu_target_t mem_type, uint32_t vaddr, uint32_t paddr, uint32_t len, uint32_t *out_len);
|
||||
|
||||
#if SOC_PSRAM_ENCRYPTION_PAGE_CONFIGURABLE
|
||||
/**
|
||||
* Map a PSRAM physical range to virtual memory without setting the encryption
|
||||
* SENSITIVE bit on each MMU entry. Used only for the explicitly carved-out
|
||||
* unencrypted PSRAM region (see CONFIG_SPIRAM_ENC_EXEMPT).
|
||||
*
|
||||
* @param vaddr start virtual address (MMU-page-aligned)
|
||||
* @param paddr start physical address (MMU-page-aligned)
|
||||
* @param len length in bytes
|
||||
*/
|
||||
void mmu_hal_map_region_no_enc(uint32_t vaddr, uint32_t paddr, uint32_t len);
|
||||
#endif
|
||||
|
||||
/**
|
||||
* To unmap a virtual address block that is mapped to a physical memory block previously
|
||||
*
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2021-2025 Espressif Systems (Shanghai) CO LTD
|
||||
* SPDX-FileCopyrightText: 2021-2026 Espressif Systems (Shanghai) CO LTD
|
||||
*
|
||||
* SPDX-License-Identifier: Apache-2.0
|
||||
*/
|
||||
@@ -102,6 +102,30 @@ void mmu_hal_map_region(uint32_t mmu_id, mmu_target_t mem_type, uint32_t vaddr,
|
||||
}
|
||||
}
|
||||
|
||||
#if SOC_PSRAM_ENCRYPTION_PAGE_CONFIGURABLE
|
||||
void mmu_hal_map_region_no_enc(uint32_t vaddr, uint32_t paddr, uint32_t len)
|
||||
{
|
||||
uint32_t mmu_id = MMU_LL_PSRAM_MMU_ID;
|
||||
uint32_t page_size_in_bytes = mmu_hal_pages_to_bytes(mmu_id, 1);
|
||||
HAL_ASSERT(vaddr % page_size_in_bytes == 0);
|
||||
HAL_ASSERT(paddr % page_size_in_bytes == 0);
|
||||
HAL_ASSERT(mmu_ll_check_valid_paddr_region(mmu_id, paddr, len));
|
||||
// Restrict to data vaddr space — unencrypted PSRAM must never back code/rodata.
|
||||
HAL_ASSERT(mmu_hal_check_valid_ext_vaddr_region(mmu_id, vaddr, len, MMU_VADDR_DATA));
|
||||
|
||||
uint32_t page_num = (len + page_size_in_bytes - 1) / page_size_in_bytes;
|
||||
uint32_t mmu_val = mmu_ll_format_paddr(mmu_id, paddr, MMU_TARGET_PSRAM0);
|
||||
|
||||
while (page_num) {
|
||||
uint32_t entry_id = mmu_ll_get_entry_id(mmu_id, vaddr);
|
||||
mmu_ll_write_entry_no_enc(mmu_id, entry_id, mmu_val);
|
||||
vaddr += page_size_in_bytes;
|
||||
mmu_val++;
|
||||
page_num--;
|
||||
}
|
||||
}
|
||||
#endif
|
||||
|
||||
void mmu_hal_unmap_region(uint32_t mmu_id, uint32_t vaddr, uint32_t len)
|
||||
{
|
||||
uint32_t page_size_in_bytes = mmu_hal_pages_to_bytes(mmu_id, 1);
|
||||
|
||||
Reference in New Issue
Block a user