feat(kasan): add Kernel Address Sanitizer (KASAN) support for ESP-IDF

Add KASAN support for detecting heap memory safety bugs (buffer
overflows, underflows, use-after-free) at runtime using compiler
instrumentation and shadow memory. Gated behind
CONFIG_IDF_EXPERIMENTAL_FEATURES, with touch points kept to esp_system
and heap so other components stay untouched.

- Core runtime (esp_system/kasan.c, esp_kasan.h): nibble-based shadow
  memory in DRAM, poison/unpoison, per-access validation, and __asan_*
  stubs; hot-path stubs in IRAM so they stay valid with the flash cache
  off. Shadow init runs before heap bring-up.
- Heap integration (heap/heap_kasan*.c): alloc/free hooks add redzones,
  a quarantine FIFO, and shadow updates.
- Panic handling: disable checks once at the panic handler entry so
  backtrace and stack dumps can read redzones without nested reports.
- Build system: -fsanitize=kernel-address for app code, with HAL, SoC,
  esp_rom, SPI flash, esp_hw_support, bootloader_support, FreeRTOS, and
  heap internals excluded from instrumentation.
- Test app (tools/test_apps/system/kasan_test): Unity tests for
  overflow, underflow, use-after-free, and all sized __asan_* stubs,
  with halt and no-halt configurations.
- Docs: document KASAN in the heap memory debugging guide (EN and CN).
This commit is contained in:
Meet Patel
2026-06-24 11:27:00 +05:30
parent 6fc0a63c4e
commit 383e9adb82
25 changed files with 1856 additions and 49 deletions
@@ -27,6 +27,10 @@
#include "esp_private/panic_internal.h"
#include "esp_private/panic_reason.h"
#if CONFIG_COMPILER_KASAN
#include "esp_kasan.h"
#endif
#if SOC_WDT_SUPPORTED || SOC_RTC_WDT_SUPPORTED
#include "hal/wdt_types.h"
#include "hal/wdt_hal.h"
@@ -128,6 +132,13 @@ void busy_wait(void)
static void panic_handler(void *frame, bool pseudo_excause)
{
#if CONFIG_COMPILER_KASAN
/* Disable KASAN checks for the remainder of crash handling: backtrace and
* stack dumps legitimately read guard pages and poisoned redzones, which
* would otherwise trigger spurious KASAN reports. */
kasan_disable_checks();
#endif
/* If watchdogs are enabled, the panic handler runs the risk of getting aborted pre-emptively because
* an overzealous watchdog decides to reset it. Hence, we feed the WDTs here.
*