From 34bc734ea4c7cd83b4dd733f839975447fbdf944 Mon Sep 17 00:00:00 2001 From: Harshal Patil Date: Thu, 10 Sep 2026 12:49:05 +0530 Subject: [PATCH] test(esp_tee): size the oversized-AEAD test buffer to the length it claims The TEE checks REE buffer bounds before input length, so claiming 4097 bytes of a 31-byte buffer returned INVALID_ARG or INVALID_SIZE by layout. --- .../tee_test_fw/main/test_esp_tee_sec_stg.c | 15 ++++++++++++--- 1 file changed, 12 insertions(+), 3 deletions(-) diff --git a/components/esp_tee/test_apps/tee_test_fw/main/test_esp_tee_sec_stg.c b/components/esp_tee/test_apps/tee_test_fw/main/test_esp_tee_sec_stg.c index 247c4c3bcec..e4177faa21e 100644 --- a/components/esp_tee/test_apps/tee_test_fw/main/test_esp_tee_sec_stg.c +++ b/components/esp_tee/test_apps/tee_test_fw/main/test_esp_tee_sec_stg.c @@ -385,9 +385,18 @@ TEST_CASE("Test TEE Secure Storage - Null Pointer and Zero Length", "[sec_storag TEST_ESP_ERR(ESP_ERR_INVALID_ARG, esp_tee_sec_storage_aead_encrypt(&aead_ctx, iv, sizeof(iv), tag, sizeof(tag), data)); TEST_ESP_ERR(ESP_ERR_INVALID_ARG, esp_tee_sec_storage_aead_decrypt(&aead_ctx, iv, sizeof(iv), tag, sizeof(tag), data)); - aead_ctx.input_len = MAX_AEAD_INPUT_LEN + 1; - TEST_ESP_ERR(ESP_ERR_INVALID_SIZE, esp_tee_sec_storage_aead_encrypt(&aead_ctx, iv, sizeof(iv), tag, sizeof(tag), data)); - TEST_ESP_ERR(ESP_ERR_INVALID_SIZE, esp_tee_sec_storage_aead_decrypt(&aead_ctx, iv, sizeof(iv), tag, sizeof(tag), data)); + const size_t oversized_len = MAX_AEAD_INPUT_LEN + 1; + uint8_t *oversized = heap_caps_malloc(oversized_len, MALLOC_CAP_8BIT | MALLOC_CAP_INTERNAL); + TEST_ASSERT_NOT_NULL(oversized); + + aead_ctx.input = oversized; + aead_ctx.input_len = oversized_len; + TEST_ESP_ERR(ESP_ERR_INVALID_SIZE, esp_tee_sec_storage_aead_encrypt(&aead_ctx, iv, sizeof(iv), tag, sizeof(tag), oversized)); + TEST_ESP_ERR(ESP_ERR_INVALID_SIZE, esp_tee_sec_storage_aead_decrypt(&aead_ctx, iv, sizeof(iv), tag, sizeof(tag), oversized)); + + free(oversized); + aead_ctx.input = data; + aead_ctx.input_len = sizeof(data); TEST_ESP_OK(esp_tee_sec_storage_clear_key(key_id));