2021-05-09 22:35:07 -04:00
|
|
|
/*
|
|
|
|
* SPDX-FileCopyrightText: 2015-2021 Espressif Systems (Shanghai) CO LTD
|
|
|
|
*
|
|
|
|
* SPDX-License-Identifier: Apache-2.0
|
|
|
|
*/
|
2019-01-21 09:14:56 -05:00
|
|
|
|
|
|
|
#include <strings.h>
|
2019-07-12 02:29:40 -04:00
|
|
|
#include "sdkconfig.h"
|
|
|
|
#include "esp_log.h"
|
2019-01-21 09:14:56 -05:00
|
|
|
#include "esp_efuse.h"
|
|
|
|
#include "esp_efuse_table.h"
|
|
|
|
#include "esp_flash_encrypt.h"
|
2019-07-12 02:29:40 -04:00
|
|
|
#include "esp_secure_boot.h"
|
|
|
|
|
2020-03-11 13:48:56 -04:00
|
|
|
#if CONFIG_IDF_TARGET_ESP32
|
2020-04-25 00:59:39 -04:00
|
|
|
#define CRYPT_CNT ESP_EFUSE_FLASH_CRYPT_CNT
|
2020-03-11 13:48:56 -04:00
|
|
|
#define WR_DIS_CRYPT_CNT ESP_EFUSE_WR_DIS_FLASH_CRYPT_CNT
|
2021-02-11 08:19:29 -05:00
|
|
|
#else
|
2020-12-21 01:48:49 -05:00
|
|
|
#define CRYPT_CNT ESP_EFUSE_SPI_BOOT_CRYPT_CNT
|
2020-11-26 03:56:13 -05:00
|
|
|
#define WR_DIS_CRYPT_CNT ESP_EFUSE_WR_DIS_SPI_BOOT_CRYPT_CNT
|
2020-03-11 13:48:56 -04:00
|
|
|
#endif
|
|
|
|
|
2019-07-12 02:29:40 -04:00
|
|
|
static const char *TAG = "flash_encrypt";
|
2021-05-17 14:33:05 -04:00
|
|
|
#ifndef BOOTLOADER_BUILD
|
2019-07-12 02:29:40 -04:00
|
|
|
|
|
|
|
void esp_flash_encryption_init_checks()
|
|
|
|
{
|
|
|
|
esp_flash_enc_mode_t mode;
|
|
|
|
|
2021-02-11 08:19:29 -05:00
|
|
|
#ifdef CONFIG_SECURE_FLASH_CHECK_ENC_EN_IN_APP
|
|
|
|
if (!esp_flash_encryption_enabled()) {
|
|
|
|
ESP_LOGE(TAG, "Flash encryption eFuse bit was not enabled in bootloader but CONFIG_SECURE_FLASH_ENC_ENABLED is on");
|
|
|
|
abort();
|
|
|
|
}
|
|
|
|
#endif
|
|
|
|
|
2019-07-12 02:29:40 -04:00
|
|
|
// First check is: if Release mode flash encryption & secure boot are enabled then
|
|
|
|
// FLASH_CRYPT_CNT *must* be write protected. This will have happened automatically
|
|
|
|
// if bootloader is IDF V4.0 or newer but may not have happened for previous ESP-IDF bootloaders.
|
|
|
|
#ifdef CONFIG_SECURE_FLASH_ENCRYPTION_MODE_RELEASE
|
2020-02-24 14:51:41 -05:00
|
|
|
#ifdef CONFIG_SECURE_BOOT
|
2019-07-12 02:29:40 -04:00
|
|
|
if (esp_secure_boot_enabled() && esp_flash_encryption_enabled()) {
|
2020-04-25 01:13:18 -04:00
|
|
|
bool flash_crypt_cnt_wr_dis = esp_efuse_read_field_bit(WR_DIS_CRYPT_CNT);
|
2019-07-12 02:29:40 -04:00
|
|
|
if (!flash_crypt_cnt_wr_dis) {
|
2020-04-25 00:59:39 -04:00
|
|
|
uint8_t flash_crypt_cnt = 0;
|
|
|
|
esp_efuse_read_field_blob(CRYPT_CNT, &flash_crypt_cnt, CRYPT_CNT[0]->bit_count);
|
|
|
|
if (flash_crypt_cnt == (1<<(CRYPT_CNT[0]->bit_count))-1) {
|
|
|
|
// If encryption counter is already max, no need to write protect it
|
|
|
|
// (this distinction is important on ESP32 ECO3 where write-procted FLASH_CRYPT_CNT also write-protects UART_DL_DIS)
|
|
|
|
return;
|
|
|
|
}
|
2020-06-01 08:33:23 -04:00
|
|
|
ESP_LOGE(TAG, "Flash encryption & Secure Boot together requires FLASH_CRYPT_CNT efuse to be write protected. Fixing now...");
|
2019-07-12 02:29:40 -04:00
|
|
|
esp_flash_write_protect_crypt_cnt();
|
|
|
|
}
|
|
|
|
}
|
2020-02-24 14:51:41 -05:00
|
|
|
#endif // CONFIG_SECURE_BOOT
|
2019-07-12 02:29:40 -04:00
|
|
|
#endif // CONFIG_SECURE_FLASH_ENCRYPTION_MODE_RELEASE
|
|
|
|
|
|
|
|
// Second check is to print a warning or error if the current running flash encryption mode
|
|
|
|
// doesn't match the expectation from project config (due to mismatched bootloader and app, probably)
|
|
|
|
mode = esp_get_flash_encryption_mode();
|
|
|
|
if (mode == ESP_FLASH_ENC_MODE_DEVELOPMENT) {
|
|
|
|
#ifdef CONFIG_SECURE_FLASH_ENCRYPTION_MODE_RELEASE
|
2020-06-01 08:33:23 -04:00
|
|
|
ESP_LOGE(TAG, "Flash encryption settings error: app is configured for RELEASE but efuses are set for DEVELOPMENT");
|
|
|
|
ESP_LOGE(TAG, "Mismatch found in security options in bootloader menuconfig and efuse settings. Device is not secure.");
|
2019-07-12 02:29:40 -04:00
|
|
|
#else
|
2020-06-01 08:33:23 -04:00
|
|
|
ESP_LOGW(TAG, "Flash encryption mode is DEVELOPMENT (not secure)");
|
2019-07-12 02:29:40 -04:00
|
|
|
#endif
|
|
|
|
} else if (mode == ESP_FLASH_ENC_MODE_RELEASE) {
|
2020-06-01 08:33:23 -04:00
|
|
|
ESP_LOGI(TAG, "Flash encryption mode is RELEASE");
|
2019-07-12 02:29:40 -04:00
|
|
|
}
|
|
|
|
}
|
|
|
|
#endif
|
2019-01-21 09:14:56 -05:00
|
|
|
|
2019-07-16 05:33:30 -04:00
|
|
|
void esp_flash_write_protect_crypt_cnt(void)
|
2019-01-21 09:14:56 -05:00
|
|
|
{
|
2020-04-25 00:58:30 -04:00
|
|
|
esp_efuse_write_field_bit(WR_DIS_CRYPT_CNT);
|
2019-01-21 09:14:56 -05:00
|
|
|
}
|
|
|
|
|
2019-07-16 05:33:30 -04:00
|
|
|
esp_flash_enc_mode_t esp_get_flash_encryption_mode(void)
|
2019-01-21 09:14:56 -05:00
|
|
|
{
|
2020-08-24 11:03:53 -04:00
|
|
|
bool flash_crypt_cnt_wr_dis = false;
|
2020-11-10 02:40:01 -05:00
|
|
|
#if CONFIG_IDF_TARGET_ESP32
|
2019-01-21 09:14:56 -05:00
|
|
|
uint8_t dis_dl_enc = 0, dis_dl_dec = 0, dis_dl_cache = 0;
|
2020-03-11 13:48:56 -04:00
|
|
|
#elif CONFIG_IDF_TARGET_ESP32S2
|
2020-12-21 01:48:49 -05:00
|
|
|
uint8_t dis_dl_enc = 0;
|
2020-11-10 02:40:01 -05:00
|
|
|
uint8_t dis_dl_icache = 0;
|
|
|
|
uint8_t dis_dl_dcache = 0;
|
2021-06-18 07:20:42 -04:00
|
|
|
#elif CONFIG_IDF_TARGET_ESP32C3 || CONFIG_IDF_TARGET_ESP32H2
|
2021-06-10 07:28:18 -04:00
|
|
|
uint8_t dis_dl_enc = 0;
|
|
|
|
uint8_t dis_dl_icache = 0;
|
2020-03-11 13:48:56 -04:00
|
|
|
#endif
|
|
|
|
|
2019-01-21 09:14:56 -05:00
|
|
|
esp_flash_enc_mode_t mode = ESP_FLASH_ENC_MODE_DEVELOPMENT;
|
|
|
|
|
|
|
|
if (esp_flash_encryption_enabled()) {
|
|
|
|
/* Check if FLASH CRYPT CNT is write protected */
|
2020-03-11 13:48:56 -04:00
|
|
|
|
2020-08-24 11:03:53 -04:00
|
|
|
flash_crypt_cnt_wr_dis = esp_efuse_read_field_bit(WR_DIS_CRYPT_CNT);
|
|
|
|
if (!flash_crypt_cnt_wr_dis) {
|
|
|
|
uint8_t flash_crypt_cnt = 0;
|
|
|
|
esp_efuse_read_field_blob(CRYPT_CNT, &flash_crypt_cnt, CRYPT_CNT[0]->bit_count);
|
|
|
|
if (flash_crypt_cnt == (1 << (CRYPT_CNT[0]->bit_count)) - 1) {
|
|
|
|
flash_crypt_cnt_wr_dis = true;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
if (flash_crypt_cnt_wr_dis) {
|
2020-03-11 13:48:56 -04:00
|
|
|
|
|
|
|
#if CONFIG_IDF_TARGET_ESP32
|
2020-04-25 01:13:18 -04:00
|
|
|
dis_dl_cache = esp_efuse_read_field_bit(ESP_EFUSE_DISABLE_DL_CACHE);
|
|
|
|
dis_dl_enc = esp_efuse_read_field_bit(ESP_EFUSE_DISABLE_DL_ENCRYPT);
|
|
|
|
dis_dl_dec = esp_efuse_read_field_bit(ESP_EFUSE_DISABLE_DL_DECRYPT);
|
2019-01-21 09:14:56 -05:00
|
|
|
/* Check if DISABLE_DL_DECRYPT, DISABLE_DL_ENCRYPT & DISABLE_DL_CACHE are set */
|
|
|
|
if ( dis_dl_cache && dis_dl_enc && dis_dl_dec ) {
|
|
|
|
mode = ESP_FLASH_ENC_MODE_RELEASE;
|
|
|
|
}
|
2020-03-11 13:48:56 -04:00
|
|
|
#elif CONFIG_IDF_TARGET_ESP32S2
|
2020-04-25 01:13:18 -04:00
|
|
|
dis_dl_enc = esp_efuse_read_field_bit(ESP_EFUSE_DIS_DOWNLOAD_MANUAL_ENCRYPT);
|
|
|
|
dis_dl_icache = esp_efuse_read_field_bit(ESP_EFUSE_DIS_DOWNLOAD_ICACHE);
|
|
|
|
dis_dl_dcache = esp_efuse_read_field_bit(ESP_EFUSE_DIS_DOWNLOAD_DCACHE);
|
2020-03-11 13:48:56 -04:00
|
|
|
|
2020-03-31 15:40:08 -04:00
|
|
|
if (dis_dl_enc && dis_dl_icache && dis_dl_dcache) {
|
2020-03-11 13:48:56 -04:00
|
|
|
mode = ESP_FLASH_ENC_MODE_RELEASE;
|
|
|
|
}
|
2021-06-18 07:20:42 -04:00
|
|
|
#elif CONFIG_IDF_TARGET_ESP32C3 || CONFIG_IDF_TARGET_ESP32H2
|
2021-06-10 07:28:18 -04:00
|
|
|
dis_dl_enc = esp_efuse_read_field_bit(ESP_EFUSE_DIS_DOWNLOAD_MANUAL_ENCRYPT);
|
|
|
|
dis_dl_icache = esp_efuse_read_field_bit(ESP_EFUSE_DIS_DOWNLOAD_ICACHE);
|
2020-12-21 01:48:49 -05:00
|
|
|
|
|
|
|
if (dis_dl_enc && dis_dl_icache) {
|
|
|
|
mode = ESP_FLASH_ENC_MODE_RELEASE;
|
|
|
|
}
|
2020-04-25 00:58:30 -04:00
|
|
|
#endif
|
2019-01-21 09:14:56 -05:00
|
|
|
}
|
|
|
|
} else {
|
|
|
|
mode = ESP_FLASH_ENC_MODE_DISABLED;
|
|
|
|
}
|
|
|
|
|
|
|
|
return mode;
|
|
|
|
}
|
2021-05-17 14:33:05 -04:00
|
|
|
|
|
|
|
void esp_flash_encryption_set_release_mode(void)
|
|
|
|
{
|
|
|
|
esp_flash_enc_mode_t mode = esp_get_flash_encryption_mode();
|
|
|
|
if (mode == ESP_FLASH_ENC_MODE_RELEASE) {
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
if (mode == ESP_FLASH_ENC_MODE_DISABLED) {
|
|
|
|
ESP_LOGE(TAG, "Flash encryption eFuse is not enabled, abort..");
|
|
|
|
abort();
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
// ESP_FLASH_ENC_MODE_DEVELOPMENT -> ESP_FLASH_ENC_MODE_RELEASE
|
|
|
|
esp_efuse_batch_write_begin();
|
|
|
|
if (!esp_efuse_read_field_bit(WR_DIS_CRYPT_CNT)) {
|
|
|
|
size_t flash_crypt_cnt = 0;
|
|
|
|
esp_efuse_read_field_cnt(CRYPT_CNT, &flash_crypt_cnt);
|
|
|
|
if (flash_crypt_cnt != CRYPT_CNT[0]->bit_count) {
|
|
|
|
esp_efuse_write_field_cnt(CRYPT_CNT, CRYPT_CNT[0]->bit_count - flash_crypt_cnt);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
#if CONFIG_IDF_TARGET_ESP32
|
|
|
|
esp_efuse_write_field_bit(ESP_EFUSE_DISABLE_DL_CACHE);
|
|
|
|
esp_efuse_write_field_bit(ESP_EFUSE_DISABLE_DL_ENCRYPT);
|
|
|
|
esp_efuse_write_field_bit(ESP_EFUSE_DISABLE_DL_DECRYPT);
|
|
|
|
#elif CONFIG_IDF_TARGET_ESP32S2
|
|
|
|
esp_efuse_write_field_bit(ESP_EFUSE_DIS_DOWNLOAD_MANUAL_ENCRYPT);
|
|
|
|
esp_efuse_write_field_bit(ESP_EFUSE_DIS_DOWNLOAD_ICACHE);
|
|
|
|
esp_efuse_write_field_bit(ESP_EFUSE_DIS_DOWNLOAD_DCACHE);
|
|
|
|
#elif CONFIG_IDF_TARGET_ESP32C3
|
|
|
|
esp_efuse_write_field_bit(ESP_EFUSE_DIS_DOWNLOAD_MANUAL_ENCRYPT);
|
|
|
|
esp_efuse_write_field_bit(ESP_EFUSE_DIS_DOWNLOAD_ICACHE);
|
|
|
|
#else
|
|
|
|
ESP_LOGE(TAG, "Flash Encryption support not added, abort..");
|
|
|
|
abort();
|
|
|
|
#endif
|
|
|
|
esp_efuse_disable_rom_download_mode();
|
|
|
|
esp_efuse_batch_write_commit();
|
|
|
|
|
|
|
|
if (esp_get_flash_encryption_mode() != ESP_FLASH_ENC_MODE_RELEASE) {
|
|
|
|
ESP_LOGE(TAG, "Flash encryption mode is DEVELOPMENT, abort..");
|
|
|
|
abort();
|
|
|
|
}
|
|
|
|
ESP_LOGI(TAG, "Flash encryption mode is RELEASE");
|
|
|
|
}
|