lowRISC / lowRISC/opentitan

[keymgr_dpe, rom] Gracefully handle when `secret2` is unlocked during `rom` / `imm_section`

Open
#30,830 0 comments 0 reactions 1 assignee View on GitHub

@rroth-lowrisc is already working on this.

Since Jul 24, 2026.

IP:keymgr_dpe IP:lc_ctrl SW:ROM
Dominant language
SystemVerilog
Stars
3.6k
Forks
1.1k
Avg merge
2d 22h
Merged PRs (30d)
141

Description

Description

With the migration from keymgr to the keymgr_dpe the ROM code changes significantly.

The keymgr_dpe starts to derive the CREATOR_ROOT_KEY inside the ROM section rather than inside the immutable ROM_EXT section. To be able to derive the CREATOR_ROOT_KEY the secret2 partition must be locked, otherwise the keymgr_dpe will transition into the invalid state.

The original keymgr did not advance the CREATOR_ROOT_KEY inside the ROM section therefore it was not affected by the missing enable signal.

The rom / imm_section section needs to have a way to gracefully handle a unlocked secret2.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.