From 97a8da4fd924dd71a228457f0d74c90a09105986 Mon Sep 17 00:00:00 2001 From: raiden00pl Date: Sat, 19 Sep 2026 15:55:56 +0200 Subject: [PATCH] arm/stm32n6: allow debugger access after flash boot Add an opt-in STM32N6_DEBUG setting to reopen the debug access port and secure/non-secure debug at the current BSEC protection level. Enable the BSEC clock and configure access before clock and memory initialization so a debugger can attach to a flash-booted development image. Assisted-by: Codex:GPT-6 Signed-off-by: raiden00pl --- arch/arm/src/stm32n6/Kconfig | 10 ++++ .../src/stm32n6/hardware/stm32n6xxx_bsec.h | 56 +++++++++++++++++++ arch/arm/src/stm32n6/stm32_start.c | 18 ++++++ 3 files changed, 84 insertions(+) create mode 100644 arch/arm/src/stm32n6/hardware/stm32n6xxx_bsec.h diff --git a/arch/arm/src/stm32n6/Kconfig b/arch/arm/src/stm32n6/Kconfig index b90a6b0663c..68d8a1b051e 100644 --- a/arch/arm/src/stm32n6/Kconfig +++ b/arch/arm/src/stm32n6/Kconfig @@ -27,4 +27,14 @@ config ARCH_CHIP_STM32N657X0 endchoice +config STM32N6_DEBUG + bool "Enable debugger access after boot" + default n + ---help--- + Reopen secure and non-secure debugger access at the current hardware + protection level early in startup. The boot ROM can close this access + when booting from external flash. Enable this option for development + to attach without switching to DEV boot mode. This changes runtime + BSEC registers only, not OTP fuses. + endif # ARCH_CHIP_STM32N6 diff --git a/arch/arm/src/stm32n6/hardware/stm32n6xxx_bsec.h b/arch/arm/src/stm32n6/hardware/stm32n6xxx_bsec.h new file mode 100644 index 00000000000..b39a02d534f --- /dev/null +++ b/arch/arm/src/stm32n6/hardware/stm32n6xxx_bsec.h @@ -0,0 +1,56 @@ +/**************************************************************************** + * arch/arm/src/stm32n6/hardware/stm32n6xxx_bsec.h + * + * SPDX-License-Identifier: Apache-2.0 + * + * Licensed to the Apache Software Foundation (ASF) under one or more + * contributor license agreements. See the NOTICE file distributed with + * this work for additional information regarding copyright ownership. The + * ASF licenses this file to you under the Apache License, Version 2.0 (the + * "License"); you may not use this file except in compliance with the + * License. You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT + * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the + * License for the specific language governing permissions and limitations + * under the License. + * + ****************************************************************************/ + +#ifndef __ARCH_ARM_SRC_STM32N6_HARDWARE_STM32N6XXX_BSEC_H +#define __ARCH_ARM_SRC_STM32N6_HARDWARE_STM32N6XXX_BSEC_H + +/**************************************************************************** + * Included Files + ****************************************************************************/ + +#include "hardware/stm32n6xxx_memorymap.h" + +/**************************************************************************** + * Pre-processor Definitions + ****************************************************************************/ + +/* Register Offsets *********************************************************/ + +#define STM32_BSEC_DBGCR_OFFSET 0xe8c /* Debug control register */ +#define STM32_BSEC_AP_UNLOCK_OFFSET 0xe90 /* Debug access port unlock register */ +#define STM32_BSEC_HDPLSR_OFFSET 0xe94 /* Hide protection level status register */ + +/* Register Addresses *******************************************************/ + +#define STM32_BSEC_DBGCR (STM32_BSEC_BASE + STM32_BSEC_DBGCR_OFFSET) +#define STM32_BSEC_AP_UNLOCK (STM32_BSEC_BASE + STM32_BSEC_AP_UNLOCK_OFFSET) +#define STM32_BSEC_HDPLSR (STM32_BSEC_BASE + STM32_BSEC_HDPLSR_OFFSET) + +/* Register Bitfield Definitions ********************************************/ + +#define BSEC_DBGCR_UNLOCK (0xb4 << 8) /* Non-secure debug authorization */ +#define BSEC_DBGCR_AUTH_HDPL_SHIFT (16) /* Bits 16-23: Debug protection level */ +#define BSEC_DBGCR_AUTH_SEC (0xb4u << 24) /* Secure debug authorization */ +#define BSEC_AP_UNLOCK_UNLOCK 0xb4 /* Unlock the debug access port */ +#define BSEC_HDPLSR_HDPL_MASK 0xff /* Bits 0-7: Current protection level */ + +#endif /* __ARCH_ARM_SRC_STM32N6_HARDWARE_STM32N6XXX_BSEC_H */ diff --git a/arch/arm/src/stm32n6/stm32_start.c b/arch/arm/src/stm32n6/stm32_start.c index c0f29e74371..7c7c50bd238 100644 --- a/arch/arm/src/stm32n6/stm32_start.c +++ b/arch/arm/src/stm32n6/stm32_start.c @@ -41,6 +41,7 @@ #include "stm32_gpio.h" #include "stm32_pwr.h" #include "stm32_start.h" +#include "hardware/stm32n6xxx_bsec.h" #include "hardware/stm32n6xxx_syscfg.h" /**************************************************************************** @@ -146,6 +147,23 @@ void __start_c(void) putreg32(0, NVIC_SYSTICK_CTRL); putreg32(NVIC_INTCTRL_PENDSTCLR, NVIC_INTCTRL); +#ifdef CONFIG_STM32N6_DEBUG + /* Enable BSEC before accessing its debug control registers. */ + + putreg32(RCC_APB4HENR_BSECEN, STM32_RCC_APB4HENSR); + (void)getreg32(STM32_RCC_APB4HENR); + + /* The boot ROM can close debug access in flash boot mode. Reopen it + * at the current protection level before clock and memory initialization + * so a debugger can attach without changing the boot pins. + */ + + putreg32(BSEC_AP_UNLOCK_UNLOCK, STM32_BSEC_AP_UNLOCK); + putreg32(BSEC_DBGCR_AUTH_SEC | BSEC_DBGCR_UNLOCK | + ((getreg32(STM32_BSEC_HDPLSR) & BSEC_HDPLSR_HDPL_MASK) << + BSEC_DBGCR_AUTH_HDPL_SHIFT), STM32_BSEC_DBGCR); +#endif + /* Force plain SLEEP (not DEEPSLEEP) on WFI so the system clock keeps * running and SysTick continues to wake us. Cleared once here so * up_idle() does not need to touch it on every idle entry.