Software APIs
rram_ctrl.h
1// Copyright lowRISC contributors (OpenTitan project).
2// Licensed under the Apache License, Version 2.0, see LICENSE for details.
3// SPDX-License-Identifier: Apache-2.0
4#ifndef OPENTITAN_SW_DEVICE_SILICON_CREATOR_LIB_DRIVERS_RRAM_CTRL_H_
5#define OPENTITAN_SW_DEVICE_SILICON_CREATOR_LIB_DRIVERS_RRAM_CTRL_H_
6
7#include <assert.h>
8#include <limits.h>
9#include <stdbool.h>
10
13#include "sw/device/lib/base/multibits.h"
14#include "sw/device/silicon_creator/lib/error.h"
15
16#include "hw/top/rram_ctrl_regs.h" // Generated.
17
18#ifdef __cplusplus
19extern "C" {
20#endif
21
22/**
23 * A logical RRAM info page.
24 *
25 * Unlike flash, RRAM has only `RRAM_CTRL_PARAM_NUM_INFO_PAGES` (8) physical
26 * info pages, too few for the 20 logical pages named in `nvm_info_page_t`.
27 * The remaining pages are emulated on the data partition of the RRAM.
28 * The permissions are currently per emulated page region and not per page.
29 * This needs to be adjusted: https://github.com/lowRISC/opentitan/issues/30914.
30 */
31typedef struct rram_ctrl_info_page {
32 /**
33 * Physical page index.
34 *
35 * For a real page (`emulated` = false), this is an info-partition page
36 * index in [0, `RRAM_CTRL_PARAM_NUM_INFO_PAGES` - 1]. For an emulated page
37 * (`emulated` = true), this is a data-partition page index.
38 */
39 uint32_t page_id;
40 /**
41 * Whether this page is emulated on the data partition rather than backed by
42 * a real RRAM info page.
43 */
45 /**
46 * Number of contiguous physical pages backing this logical page.
47 *
48 * Real info pages are always 1 (there's no way to combine physical info
49 * pages). Emulated pages can span multiple contiguous data-partition pages
50 * to fit content larger than 512 bytes; callers reading/writing more than
51 * `num_pages * 512` bytes will silently spill into the next logical page's
52 * storage, since nothing enforces this bound at the read/write call site.
53 */
54 uint32_t num_pages;
55} rram_ctrl_info_page_t;
56
57/**
58 * Two data-partition page ranges, each reserved at the tail of one firmware
59 * slot (matching the linker's `_nvm_slot_reserved_bytes`, which carves the
60 * same 32KiB out of every slot): Each has its own memory-protection region,
61 * granted in full by `nvm_ctrl_init()`. Bootstrap/rescue's generic erase
62 * and program paths exclude both ranges in full.
63 */
64enum {
65 /**
66 * Number of pages the linker reserves at the tail of every slot
67 * (`_nvm_slot_reserved_bytes` in top_earlgrey_memory.ld, 32KiB).
68 */
69 kRramCtrlReservedPageCount = 0x8000 / RRAM_CTRL_PARAM_BYTES_PER_PAGE,
70
71 kRramCtrlEmulPageEndA = RRAM_CTRL_PARAM_NUM_DATA_PAGES / 2,
72 kRramCtrlEmulPageBaseA = kRramCtrlEmulPageEndA - kRramCtrlReservedPageCount,
73 kRramCtrlEmulRegionA = 8,
74
75 kRramCtrlEmulPageEndB = RRAM_CTRL_PARAM_NUM_DATA_PAGES,
76 kRramCtrlEmulPageBaseB = kRramCtrlEmulPageEndB - kRramCtrlReservedPageCount,
77 kRramCtrlEmulRegionB = 9,
78
79 /**
80 * Pages at the very tail of Region B's window reserved for OTP: read/write
81 * protected in hardware.
82 */
83 kRramCtrlOtpPageCount = RRAM_CTRL_PARAM_NUM_OTP_PAGES,
84};
85
86/**
87 * Table of RRAM information pages.
88 *
89 * Columns: Name, physical page index, whether emulated, number of contiguous
90 * physical pages backing it (see `rram_ctrl_info_page_t.num_pages`).
91 * We use an X macro to facilitate writing enums, switch statements, and unit
92 * tests using the constants here, mirroring `FLASH_CTRL_INFO_PAGES_DEFINE`.
93 *
94 * Emulated-page offsets below are manually cumulative (each is the previous
95 * entry's offset + its `num_pages`) since a page occupying more than one
96 * slot has no entries of its own for its 2nd-Nth pages.
97 */
98// clang-format off
99#define RRAM_CTRL_INFO_PAGES_DEFINE(X) \
100 /**
101 * Real, individually-protected info pages. Always 1 page each -- there's
102 * no way to combine physical info pages, so anything needing more than
103 * 512 bytes must be an emulated page instead (see below).
104 */ \
105 X(kRramCtrlInfoPageFactoryId, 0, false, 1) \
106 X(kRramCtrlInfoPageAttestationKeySeeds, 1, false, 1) \
107 X(kRramCtrlInfoPageCreatorSecret, 5, false, 1) \
108 X(kRramCtrlInfoPageOwnerSecret, 6, false, 1) \
109 X(kRramCtrlInfoPageWaferAuthSecret, 7, false, 1) \
110 /**
111 * Emulated info pages, relocated onto the data partition.
112 *
113 * All emulated pages are uniformly 4 pages (2048 bytes) each, even though
114 * several don't strictly need it. Pages that DO need the full 2048
115 * bytes:
116 * - `OwnerSlot0`/`OwnerSlot1`: back `owner_block_t`, which is 2048 bytes
117 * (`OT_ASSERT_SIZE(owner_block_t, 2048)`).
118 * - `DiceCerts`/`FactoryCerts`: share one `dice_page_t` buffer type and
119 * must be deliberately equal in size (see the `static_assert` in
120 * dice_chain.h), even though their actual content (~1.3KB and ~800
121 * bytes respectively) would technically fit in fewer.
122 * - `OwnerReserved0`: what ISFB owner configs point at
123 * (`isfb->bank=0,page=5`); needs the space for its strike region plus
124 * product expressions.
125 * - `OwnerReserved6`/`OwnerReserved7`: SKU extensions (e.g.
126 * `tpm_personalize_ext.c`'s TPM EK cert) write to them via the same
127 * `dice_page_t` buffer as `DiceCerts`/`FactoryCerts`, which is always a
128 * full `kDicePageDataSize`.
129 */ \
130 X(kRramCtrlInfoPageOwnerReserved0, kRramCtrlEmulPageBaseB + 0, true, 4) \
131 X(kRramCtrlInfoPageOwnerReserved1, kRramCtrlEmulPageBaseB + 4, true, 4) \
132 X(kRramCtrlInfoPageOwnerReserved2, kRramCtrlEmulPageBaseB + 8, true, 4) \
133 X(kRramCtrlInfoPageOwnerReserved3, kRramCtrlEmulPageBaseB + 12, true, 4) \
134 X(kRramCtrlInfoPageOwnerReserved4, kRramCtrlEmulPageBaseB + 16, true, 4) \
135 X(kRramCtrlInfoPageOwnerReserved5, kRramCtrlEmulPageBaseB + 20, true, 4) \
136 X(kRramCtrlInfoPageOwnerReserved6, kRramCtrlEmulPageBaseB + 24, true, 4) \
137 X(kRramCtrlInfoPageOwnerReserved7, kRramCtrlEmulPageBaseB + 28, true, 4) \
138 X(kRramCtrlInfoPageBootData0, kRramCtrlEmulPageBaseB + 32, true, 4) \
139 X(kRramCtrlInfoPageBootData1, kRramCtrlEmulPageBaseB + 36, true, 4) \
140 X(kRramCtrlInfoPageOwnerSlot0, kRramCtrlEmulPageBaseB + 40, true, 4) \
141 X(kRramCtrlInfoPageOwnerSlot1, kRramCtrlEmulPageBaseB + 44, true, 4) \
142 X(kRramCtrlInfoPageDiceCerts, kRramCtrlEmulPageBaseB + 48, true, 4) \
143 X(kRramCtrlInfoPageFactoryCerts, kRramCtrlEmulPageBaseB + 52, true, 4) \
144 /**
145 * In its own dedicated region (`kRramCtrlEmulRegionA`), not
146 * `kRramCtrlEmulRegionB` above; see the comment there.
147 */ \
148 X(kRramCtrlInfoPageCreatorReserved0, kRramCtrlEmulPageBaseA + 0, true, 4) \
149// clang-format on
150
151/**
152 * Total pages `RRAM_CTRL_INFO_PAGES_DEFINE` assigns within each region's
153 * window, computed by walking the table rather than hand-counted, so a
154 * future entry that doesn't fit is caught automatically instead of silently
155 * landing past the window (into the next region, or -- for Region B --
156 * into the hardware-protected OTP tail).
157 */
158#define INFO_PAGE_SUM_REGION_A_(name_, page_id_, emulated_, num_pages_) \
159 +((emulated_) && (page_id_) >= kRramCtrlEmulPageBaseA && \
160 (page_id_) < kRramCtrlEmulPageEndA \
161 ? (num_pages_) \
162 : 0)
163#define INFO_PAGE_SUM_REGION_B_(name_, page_id_, emulated_, num_pages_) \
164 +((emulated_) && (page_id_) >= kRramCtrlEmulPageBaseB && \
165 (page_id_) < kRramCtrlEmulPageEndB \
166 ? (num_pages_) \
167 : 0)
168enum {
169 kRramCtrlInfoPagesRegionATotal =
170 0 RRAM_CTRL_INFO_PAGES_DEFINE(INFO_PAGE_SUM_REGION_A_),
171 kRramCtrlInfoPagesRegionBTotal =
172 0 RRAM_CTRL_INFO_PAGES_DEFINE(INFO_PAGE_SUM_REGION_B_),
173};
174#undef INFO_PAGE_SUM_REGION_A_
175#undef INFO_PAGE_SUM_REGION_B_
176static_assert((uint32_t)kRramCtrlInfoPagesRegionATotal <=
177 (uint32_t)kRramCtrlReservedPageCount,
178 "RRAM_CTRL_INFO_PAGES_DEFINE's Region A entries overflow "
179 "kRramCtrlEmulRegionA's window");
180static_assert((uint32_t)kRramCtrlInfoPagesRegionBTotal <=
181 (uint32_t)(kRramCtrlReservedPageCount -
182 kRramCtrlOtpPageCount),
183 "RRAM_CTRL_INFO_PAGES_DEFINE's Region B entries would overlap "
184 "the OTP tail");
185
186/**
187 * Helper macro for declaring an extern `rram_ctrl_info_page_t`.
188 * @param name_ Name of the enumeration constant.
189 * @param page_id_ Physical page index of the info page.
190 * @param emulated_ Whether the page is emulated on the data partition.
191 * @param num_pages_ Number of contiguous physical pages backing this page.
192 */
193#define INFO_PAGE_STRUCT_DECL_(name_, page_id_, emulated_, num_pages_) \
194 extern const rram_ctrl_info_page_t name_;
195
196/**
197 * Info pages.
198 */
199RRAM_CTRL_INFO_PAGES_DEFINE(INFO_PAGE_STRUCT_DECL_);
200
201#undef INFO_PAGE_STRUCT_DECL_
202
203/**
204 * Helper macro for declaring a `<name_>Size` compile-time constant: the
205 * total on-NVM byte size backing a logical page, i.e.
206 * `num_pages_ * RRAM_CTRL_PARAM_BYTES_PER_PAGE`. Callers should use these
207 * instead of re-deriving a page's size from `num_pages` themselves, so the
208 * page table in `RRAM_CTRL_INFO_PAGES_DEFINE` stays the only place page
209 * counts are written down.
210 * @param name_ Name of the enumeration constant.
211 * @param page_id_ Physical page index of the info page.
212 * @param emulated_ Whether the page is emulated on the data partition.
213 * @param num_pages_ Number of contiguous physical pages backing this page.
214 */
215#define INFO_PAGE_SIZE_ENUM_(name_, page_id_, emulated_, num_pages_) \
216 name_##Size = (num_pages_) * RRAM_CTRL_PARAM_BYTES_PER_PAGE,
217
218enum { RRAM_CTRL_INFO_PAGES_DEFINE(INFO_PAGE_SIZE_ENUM_) };
219
220#undef INFO_PAGE_SIZE_ENUM_
221
222/**
223 * Bitfields for `CREATOR_SW_CFG_NVM_DATA_DEFAULT_CFG` and
224 * `CREATOR_SW_CFG_NVM_INFO_BOOT_DATA_CFG` OTP items.
225 *
226 * RRAM reuses the same OTP words and bit layout as flash_ctrl (the OTP
227 * schema was not redesigned for RRAM); these are RRAM's own copies of
228 * flash_ctrl.h's `FLASH_CTRL_OTP_FIELD_*` macros so that rram_ctrl does not
229 * need to depend on the flash_ctrl driver just for these constants.
230 *
231 * Defined here to be able to use in tests.
232 */
233#define RRAM_CTRL_OTP_FIELD_SCRAMBLING \
234 (bitfield_field32_t){.mask = UINT8_MAX, .index = CHAR_BIT * 0}
235#define RRAM_CTRL_OTP_FIELD_ECC \
236 (bitfield_field32_t){.mask = UINT8_MAX, .index = CHAR_BIT * 1}
237
238/**
239 * Bitfields for `CREATOR_SW_CFG_NVM_HW_INFO_CFG_OVERRIDE` OTP item.
240 *
241 * See the note above: RRAM reuses flash_ctrl's OTP word/bit layout.
242 *
243 * Defined here to be able to use in tests.
244 */
245#define RRAM_CTRL_OTP_FIELD_HW_INFO_CFG_OVERRIDE_SCRAMBLE_DIS \
246 (bitfield_field32_t){.mask = UINT8_MAX, .index = CHAR_BIT * 0}
247#define RRAM_CTRL_OTP_FIELD_HW_INFO_CFG_OVERRIDE_ECC_DIS \
248 (bitfield_field32_t){.mask = UINT8_MAX, .index = CHAR_BIT * 1}
249
250/**
251 * The following constants represent the expected number of sec_mmio
252 * register writes performed by functions provided in this module. See
253 * `SEC_MMIO_WRITE_INCREMENT()` for more details.
254 */
255enum {
256 kRramCtrlSecMmioDataDefaultPermsSet = 1,
257 kRramCtrlSecMmioDataDefaultCfgSet = 1,
258 kRramCtrlSecMmioInfoPermsSet = 1,
259 kRramCtrlSecMmioInfoCfgSet = 1,
260 kRramCtrlSecMmioInfoCfgLock = 1,
261 kRramCtrlSecMmioInfoPageLockdown = 2,
262 kRramCtrlSecMmioExecSet = 1,
263 // 2 writes: MP_REGION_${region} and MP_REGION_CFG_${region}.
264 kRramCtrlSecMmioDataRegionProtect = 2,
265 kRramCtrlSecMmioDataRegionProtectLock = 1,
266 kRramCtrlSecMmioInit = 1,
268
269/**
270 * Kicks off the initialization of the RRAM controller.
272 * This must complete before RRAM can be accessed. The init status can be
273 * queried by calling `rram_ctrl_status_get()` and checking `init_done`.
274 *
275 * The caller is responsible for calling
276 * `SEC_MMIO_WRITE_INCREMENT(kRramCtrlSecMmioInit)` when sec_mmio is being
277 * used to check expectations.
278 */
279void rram_ctrl_init(void);
280
281/**
282 * Permanently disable the RRAM controller.
283 */
284void rram_ctrl_disable(void);
285
286/**
287 * Status bits.
288 */
289typedef struct rram_ctrl_status {
290 /**
291 * RRAM read FIFO full, software must consume data.
292 */
293 bool rd_full;
294 /**
295 * RRAM read FIFO empty.
296 */
297 bool rd_empty;
298 /**
299 * RRAM write FIFO full.
300 */
301 bool wr_full;
302 /**
303 * RRAM write FIFO empty, software must provide data.
304 */
306 /**
307 * RRAM controller undergoing init.
308 */
310} rram_ctrl_status_t;
311
312/**
313 * Query the status registers on the RRAM controller.
314 *
315 * @param[out] status The current status of the RRAM controller.
316 */
317void rram_ctrl_status_get(rram_ctrl_status_t *status);
318
319/**
320 * Error code bits.
321 */
322typedef struct rram_ctrl_error_code {
323 /**
324 * Software has supplied an undefined RRAM operation.
325 */
326 bool op_err;
327 /**
328 * RRAM access permission error. Read the ERR_ADDR register for the
329 * faulting address.
330 */
331 bool mp_err;
332 /**
333 * RRAM read error, could be an integrity error.
334 */
335 bool rd_err;
336 /**
337 * RRAM write error.
338 */
339 bool wr_err;
340} rram_ctrl_error_code_t;
341
342/**
343 * Query the error code register on the RRAM controller.
344 *
345 * @param[out] error_code The current error code of the RRAM controller.
346 */
347void rram_ctrl_error_code_get(rram_ctrl_error_code_t *error_code);
348
349/**
350 * Reads data from the data partition.
351 *
352 * @param addr Address to read from.
353 * @param word_count Number of bus words to read.
354 * @param[out] data Buffer to store the read data. Must be word aligned.
355 * @return Result of the operation.
356 */
358rom_error_t rram_ctrl_data_read(uint32_t addr, uint32_t word_count, void *data);
359
360/**
361 * Reads data from an information page.
362 *
363 * @param info_page Information page to read from.
364 * @param offset Offset from the start of the page.
365 * @param word_count Number of bus words to read.
366 * @param[out] data Buffer to store the read data. Must be word aligned.
367 * @return Result of the operation.
368 */
370rom_error_t rram_ctrl_info_read(const rram_ctrl_info_page_t *info_page,
371 uint32_t offset, uint32_t word_count,
372 void *data);
373
374/**
375 * Reads data from an information page, returning all zeros if a read error
376 * code is encountered.
377 *
378 * @param info_page Information page to read from.
379 * @param offset Offset from the start of the page.
380 * @param word_count Number of bus words to read.
381 * @param[out] data Buffer to store the read data. Must be word aligned.
382 * @return Result of the operation.
383 */
385rom_error_t rram_ctrl_info_read_zeros_on_read_error(
386 const rram_ctrl_info_page_t *info_page, uint32_t offset,
387 uint32_t word_count, void *data);
388
389/**
390 * Writes data to the data partition.
391 *
392 * RRAM supports direct overwrite; unlike flash, no erase is required before
393 * writing.
394 *
395 * @param addr Address to write to.
396 * @param word_count Number of bus words to write. Must be a multiple of 4.
397 * @param data Data to write. Must be word aligned.
398 * @return Result of the operation.
399 */
401rom_error_t rram_ctrl_data_write(uint32_t addr, uint32_t word_count,
402 const void *data);
403
404/**
405 * Writes data to an information page.
406 *
407 * @param info_page Information page to write to.
408 * @param offset Offset from the start of the page.
409 * @param word_count Number of bus words to write. Must be a multiple of 4.
410 * @param data Data to write. Must be word aligned.
411 * @return Result of the operation.
412 */
414rom_error_t rram_ctrl_info_write(const rram_ctrl_info_page_t *info_page,
415 uint32_t offset, uint32_t word_count,
416 const void *data);
417
418/**
419 * A struct for specifying access permissions.
420 *
421 * RRAM has no separate erase permission; unlike flash, write operations
422 * overwrite in place.
423 *
424 * rram_ctrl config registers use 4-bits for boolean values. Use
425 * `kMultiBitBool4True` to enable and `kMultiBitBool4False` to disable
426 * permissions.
427 */
428typedef struct rram_ctrl_perms {
429 uint32_t _pad0 : 4;
430 /**
431 * Read.
432 */
433 uint32_t read : 4;
434 /**
435 * Write.
436 */
437 uint32_t write : 4;
438 uint32_t _pad1 : 20;
439} rram_ctrl_perms_t;
440OT_ASSERT_SIZE(rram_ctrl_perms_t, 4);
441
442/**
443 * Sets default access permissions for the data partition.
444 *
445 * The caller is responsible for calling
446 * `SEC_MMIO_WRITE_INCREMENT(kRramCtrlSecMmioDataDefaultPermsSet)` when
447 * sec_mmio is being used to check expectations.
448 *
449 * @param perms New permissions.
450 */
451void rram_ctrl_data_default_perms_set(rram_ctrl_perms_t perms);
452
453/**
454 * Sets access permissions for a real (non-emulated) info page.
456 * The caller is responsible for calling
457 * `SEC_MMIO_WRITE_INCREMENT(kRramCtrlSecMmioInfoPermsSet)` when sec_mmio is
458 * being used to check expectations.
460 * @param info_page A real information page (`emulated` = false).
461 * @param perms New permissions.
462 */
463void rram_ctrl_info_perms_set(const rram_ctrl_info_page_t *info_page,
464 rram_ctrl_perms_t perms);
465
466/**
467 * A struct for RRAM configuration settings.
468 *
469 * RRAM has no high-endurance concept; unlike flash, no wear-leveling
470 * configuration is needed.
471 *
472 * rram_ctrl config registers use 4-bits for boolean values. Use
473 * `kMultiBitBool4True` to enable and `kMultiBitBool4False` to disable these
474 * settings.
475 */
476typedef struct rram_ctrl_cfg {
477 uint32_t _pad0 : 12;
478 /**
479 * Scrambling.
480 */
481 uint32_t scrambling : 4;
482 /**
483 * ECC.
484 */
485 uint32_t ecc : 4;
486 uint32_t _pad1 : 12;
487} rram_ctrl_cfg_t;
488OT_ASSERT_SIZE(rram_ctrl_cfg_t, 4);
489
490/**
491 * Sets default configuration settings for the data partition.
492 *
493 * The caller is responsible for calling
494 * `SEC_MMIO_WRITE_INCREMENT(kRramCtrlSecMmioDataDefaultCfgSet)` when
495 * sec_mmio is being used to check expectations.
496 *
497 * @param cfg New configuration settings.
498 */
499void rram_ctrl_data_default_cfg_set(rram_ctrl_cfg_t cfg);
500
501/**
502 * Reads the current default configuration settings for the data partition.
503 *
504 * @return Current configuration settings.
505 */
506rram_ctrl_cfg_t rram_ctrl_data_default_cfg_get(void);
507
508/**
509 * Reads the boot data info page configuration settings from OTP.
510 *
511 * Reuses the same `CREATOR_SW_CFG_NVM_INFO_BOOT_DATA_CFG` OTP word and bit
512 * layout as flash; the high-endurance field is ignored for RRAM.
513 *
514 * @return Current OTP configuration settings.
515 */
516rram_ctrl_cfg_t rram_ctrl_boot_data_cfg_get(void);
517
518/**
519 * A type for rram_ctrl memory protection region indices.
520 */
521typedef uint32_t rram_ctrl_region_index_t;
522
523/**
524 * Configure memory protection for a region of data-partition pages.
525 *
526 * Based on the `region` parameter, this function overwrites the
527 * `MP_REGION_${region}` and `MP_REGION_CFG_${region}` registers. Calling
528 * this function invalidates previously-configured protections for `region`.
529 *
530 * @param region The index of the region to protect.
531 * @param page_offset The index of the first page in the region.
532 * @param num_pages The number of pages in the region, i.e. the region covers
533 * the exclusive range `[page_offset, page_offset +
534 * num_pages)`. Internally compensates for the hardware's
535 * match logic, which is inclusive of `page_offset +
536 * num_pages`. Must be nonzero: the hardware has no way to
537 * express an empty region, so callers deriving this from
538 * untrusted data must reject 0 themselves.
539 * @param perms The read/write permissions for this region.
540 * @param cfg RRAM config values that are used to fill in some fields of the
541 * `MP_REGION_CFG_${region}` register.
542 * @param lock Lock the configuration for this region.
543 */
544void rram_ctrl_data_region_protect(rram_ctrl_region_index_t region,
545 uint32_t page_offset, uint32_t num_pages,
546 rram_ctrl_perms_t perms, rram_ctrl_cfg_t cfg,
547 hardened_bool_t lock);
548
549/**
550 * Sets configuration settings for a real (non-emulated) info page.
551 *
552 * The caller is responsible for calling
553 * `SEC_MMIO_WRITE_INCREMENT(kRramCtrlSecMmioInfoCfgSet)` when sec_mmio is
554 * being used to check expectations.
555 *
556 * @param info_page A real information page (`emulated` = false).
557 * @param cfg New configuration settings.
558 */
559void rram_ctrl_info_cfg_set(const rram_ctrl_info_page_t *info_page,
560 rram_ctrl_cfg_t cfg);
561
562/**
563 * Write-locks configuration settings for a real (non-emulated) info page.
564 *
565 * The caller is responsible for calling
566 * `SEC_MMIO_WRITE_INCREMENT(kRramCtrlSecMmioInfoCfgLock)` when sec_mmio is
567 * being used to check expectations.
568 *
569 * @param info_page A real information page (`emulated` = false).
570 */
571void rram_ctrl_info_cfg_lock(const rram_ctrl_info_page_t *info_page);
572
573/**
574 * Disables all access to a real (non-emulated) info page and locks its
575 * configuration until reset.
576 *
577 * Zeroes both the cfg register (clearing all permissions and configuration
578 * bits) and the regwen register (preventing further writes to cfg).
579 *
580 * The caller is responsible for calling
581 * `SEC_MMIO_WRITE_INCREMENT(kRramCtrlSecMmioInfoPageLockdown)` when sec_mmio
582 * is being used to check expectations.
583 *
584 * @param info_page A real information page (`emulated` = false).
585 */
586void rram_ctrl_info_page_lockdown(const rram_ctrl_info_page_t *info_page);
587
588/**
589 * Enable execution from RRAM.
590 *
591 * Note: an ePMP region must also be configured in order to execute code in
592 * RRAM.
593 *
594 * The caller is responsible for calling
595 * `SEC_MMIO_WRITE_INCREMENT(kRramCtrlSecMmioExecSet)` when sec_mmio is being
596 * used to check expectations.
597 *
598 * @param exec_val Value to write to the `rram_ctrl.EXEC` register.
599 * `RRAM_CTRL_PARAM_EXEC_EN` will enable execution, all other values will
600 * disable execution.
601 */
602void rram_ctrl_exec_set(uint32_t exec_val);
603
604#ifdef __cplusplus
605}
606#endif
607
608#endif // OPENTITAN_SW_DEVICE_SILICON_CREATOR_LIB_DRIVERS_RRAM_CTRL_H_