[keymgr_dpe, rom] Gracefully handle when `secret2` is unlocked during `rom` / `imm_section`
@rroth-lowrisc is already working on this.
Since Jul 24, 2026.
- Dominant language
- SystemVerilog
- Stars
- 3.6k
- Forks
- 1.1k
- Avg merge
- 2d 22h
- Merged PRs (30d)
- 141
Description
Description
With the migration from keymgr to the keymgr_dpe the ROM code changes significantly.
The keymgr_dpe starts to derive the CREATOR_ROOT_KEY inside the ROM section rather than inside the immutable ROM_EXT section. To be able to derive the CREATOR_ROOT_KEY the secret2 partition must be locked, otherwise the keymgr_dpe will transition into the invalid state.
The original keymgr did not advance the CREATOR_ROOT_KEY inside the ROM section therefore it was not affected by the missing enable signal.
The rom / imm_section section needs to have a way to gracefully handle a unlocked secret2.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.