mirror of
https://github.com/espressif/esp-idf.git
synced 2026-09-22 13:01:16 +03:00
ESP_FAULT_ASSERT(C) was silently deleted by the optimizer when C is a cached flag/status already proven by a preceding `if (!C) return/goto`: the compiler folds C to a constant and drops all three checks, removing the fault-injection protection with no warning.
21 lines
691 B
Plaintext
21 lines
691 B
Plaintext
# SECURE_BOOT_V2 with EFUSE_VIRTUAL_KEEP_IN_FLASH
|
|
|
|
CONFIG_IDF_TARGET="esp32c5"
|
|
|
|
CONFIG_PARTITION_TABLE_OFFSET=0xE000
|
|
CONFIG_PARTITION_TABLE_CUSTOM=y
|
|
CONFIG_PARTITION_TABLE_CUSTOM_FILENAME="test/partitions_efuse_emul.csv"
|
|
|
|
CONFIG_SECURE_BOOT=y
|
|
CONFIG_SECURE_BOOT_V2_ENABLED=y
|
|
# ECDSA Secure Boot V2 is gated behind the insecure option on the affected SoCs
|
|
CONFIG_SECURE_BOOT_INSECURE=y
|
|
CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA=y
|
|
CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y
|
|
CONFIG_SECURE_BOOT_SIGNING_KEY="test/secure_boot_signing_key_ecdsa_nistp256.pem"
|
|
CONFIG_SECURE_INSECURE_ALLOW_DL_MODE=y
|
|
|
|
# IMPORTANT: ONLY VIRTUAL eFuse MODE!
|
|
CONFIG_EFUSE_VIRTUAL=y
|
|
CONFIG_EFUSE_VIRTUAL_KEEP_IN_FLASH=y
|