fix(esp_wifi): Harden dpp Auth confirm and drop mismatched auth confirms
Closes WIFIBUG-2032 and WIFIBUG-2075
See merge request espressif/esp-idf!51554
Extend the CTR test data length to 6433 bytes so the trailing partial
block is exercised with external RAM buffers (which stalls the ESP32-S2
Crypto DMA on an unfixed driver), and add AES-GCM PSRAM tests verified
against internal RAM references.
The ESP32-S2 Crypto DMA in-channel stalls silently when a receive
descriptor list transitions from external to internal RAM. The AES
driver hits this when a PSRAM-output operation has a trailing partial
block, as the internal stream descriptor is linked after the external
RAM data descriptors.
- esp_aes_process_dma(): process the block-aligned part and the partial
block as two separate DMA operations, keeping each descriptor list
uniform
- crypto_dma_ll_reset(): also reset the in-channel (per the TRM receive
reset sequence), otherwise stale state from a preceding external-RAM
operation corrupts the next operation's output
The GCM DMA path is unaffected; it never operates on PSRAM buffers.
Both PSRAM layouts were mapped as a single RWX window, so everything in external
RAM - the heap included - was executable.
PSRAM used as data only is now RW, and under XIP-from-PSRAM it is split per
section as ESP32-P4 does: .text RX, .rodata read-only, and the MMU-page
alignment gaps and the reclaimed heap RW, so neither is executable.
Both describe the layout that esp_psram_init() produces, and the entries are
locked, so - again as on ESP32-P4 - they are only narrowed when
CONFIG_SPIRAM_PRE_CONFIGURE_MEMORY_PROTECTION says that layout applies. Without
it the application owns the region and PSRAM stays RWX.
The per-section entries cost one PMP entry more than the 16 available, so the CPU
subsystem and peripheral windows are chained as TOR entries, taking one entry
instead of three.
soc.h is corrected against the S31 bus address map: the peripheral window base
was 1 MB too low, and the LP peripheral top, derived from a register base plus a
size rather than from the map, was 16 KB short. SOC_NON_CACHEABLE_OFFSET_FLASH
is added.
Sort bond entries by bond_count after in-place updates to maintain correct
eviction order, and log IRK resolving-list failures instead of failing the bond.
The bootloader locks PMA entries on core 0 only (PMA is per-hart), so
core 1 applies its PMA configuration with effective writes. Executing
that from flash momentarily makes the flash aperture non-cacheable
while reprogramming its entry, which executes ciphertext with flash
encryption enabled (illegal instruction -> CPU lockup).
CONFIG_BOOTLOADER_REGION_PROTECTION_ENABLE is bootloader-scoped;
disabling it must not strip the application's PMP/PMA configuration.
The application now always applies region protection.
Run esp_cpu_configure_invalid_regions() from IRAM: it reprograms the PMA
entry that keeps the flash aperture cacheable, so an instruction fetched
from flash inside the reprogramming window bypasses the cache and, with
flash encryption enabled, executes ciphertext (illegal instruction ->
CPU lockup).
Also move the PSRAM PMA entry to index 7 so that the application layout
matches the entry earlier bootloaders programmed and locked, keeping the
full layout effective under such bootloaders.
Freezing PMP entry indices as a bootloader<->application ABI (pmp_layout.h)
is only needed on targets where an already-shipped bootloader locks PMP
entries (C5, C6, C61, H2, P4). No such bootloader has ever shipped for
ESP32-S31 and, per the v6.2 PMP ownership policy, the bootloader never
configures or locks any PMP entry on this target - so there is no ABI to
freeze. Program all entries by plain index (as on ESP32-H4/H21) and state
that the application-owned layout is not an ABI.