Skip to content

Update Partition Table - #131

Closed
odudex wants to merge 3 commits into
masterfrom
update-security-plan
Closed

Update Partition Table#131
odudex wants to merge 3 commits into
masterfrom
update-security-plan

Conversation

@odudex

@odudex odudex commented Jul 24, 2026

Copy link
Copy Markdown
Owner

Prepare partition table for future flash encryption and scure-boot.

Update security-plan

odudex and others added 3 commits July 24, 2026 15:10
Key Manager needs P4 silicon >= v3 (fleet is v1.x), so XTS-AES-128 in eFuse KEY3. On-device test bootloops: FE encrypts all PSRAM pages while DSI/camera DMA bypass the cache-path XTS; fix is SPIRAM_ENC_EXEMPT in IDF 6.1.
…r headroom

Flash-encryption/secure-boot bootloaders exceed the 24KB slot at 0x8000; nvs absorbs the shift (0x11000, 52KB), other partitions unchanged. Existing devices need one serial reflash and NVS re-setup.
Also update the release flash layout for the partition table move to
0x10000: sign_release.sh derives both the merge-bin call and the
generated flasher_args.json from one set of OFF_* vars, and the web
flasher's fallback layout tracks the new offset. Published bundles carry
their own flasher_args.json, so <= v0.0.14 releases keep flashing at
0x8000.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@odudex odudex closed this Jul 24, 2026
@odudex
odudex deleted the update-security-plan branch July 28, 2026 16:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant