fix(nvs_flash): Remove the forceful selection of NVS_ENCRYPTION with flash encryption

- This change will introduce a breaking change for SoCs with the HMAC
  peripheral. Turning on flash encryption will no longer enable NVS
  encryption automatically.

Closes https://github.com/espressif/esp-idf/issues/12549
This commit is contained in:
Laukik Hase
2023-11-21 11:11:02 +05:30
parent 94d7ec7a38
commit ea51f4e2f7
9 changed files with 50 additions and 8 deletions
@@ -9,5 +9,6 @@ Migration from 5.1 to 5.2
gcc
peripherals
protocols
storage
system
wifi
@@ -0,0 +1,11 @@
Storage
=======
:link_to_translation:`zh_CN:[中文]`
NVS Encryption
--------------
- For SoCs with the HMAC peripheral (``SOC_HMAC_SUPPORTED``), turning on :doc:`Flash Encryption <../../../security/flash-encryption>` will no longer automatically turn on :doc:`NVS encryption <../../../api-reference/storage/nvs_encryption>`.
- You will need to explicitly turn on NVS encryption and select the required scheme (flash encryption-based or HMAC peripheral-based). You can select the HMAC peripheral-based scheme (:ref:`CONFIG_NVS_SEC_KEY_PROTECTION_SCHEME`), even if flash encryption is not enabled.
- SoCs without the HMAC peripheral will still automatically turn on NVS encryption when flash encryption is enabled.