mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-03 03:31:41 +03:00
feat(esp_tee): Add support for the RISC-V H/W stack guard mechanism
This commit is contained in:
@@ -1,6 +1,6 @@
|
||||
# Reducing TEE I/DRAM sizes
|
||||
# 28KB
|
||||
CONFIG_SECURE_TEE_IRAM_SIZE=0x7000
|
||||
# 29KB
|
||||
CONFIG_SECURE_TEE_IRAM_SIZE=0x7400
|
||||
# 20KB
|
||||
CONFIG_SECURE_TEE_DRAM_SIZE=0x5000
|
||||
|
||||
|
||||
@@ -69,3 +69,11 @@ secure_services:
|
||||
type: custom
|
||||
function: esp_tee_test_heap_malloc_write_free
|
||||
args: 0
|
||||
- id: 217
|
||||
type: custom
|
||||
function: esp_tee_test_stack_overflow
|
||||
args: 0
|
||||
- id: 218
|
||||
type: custom
|
||||
function: esp_tee_test_stack_underflow
|
||||
args: 0
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2024 Espressif Systems (Shanghai) CO LTD
|
||||
* SPDX-FileCopyrightText: 2024-2026 Espressif Systems (Shanghai) CO LTD
|
||||
*
|
||||
* SPDX-License-Identifier: Apache-2.0
|
||||
*/
|
||||
@@ -46,6 +46,45 @@ void _ss_esp_tee_test_iram_reg2_write_violation(void)
|
||||
*test_addr = RND_VAL;
|
||||
}
|
||||
|
||||
static void do_stack_smash(bool underflow, int depth, volatile uint8_t *sink)
|
||||
{
|
||||
/* Overflow path */
|
||||
if (!underflow) {
|
||||
if (depth == -1) {
|
||||
return; // unreachable
|
||||
}
|
||||
|
||||
uint8_t buffer[1024];
|
||||
buffer[0] = (uint8_t)depth;
|
||||
*sink = buffer[0];
|
||||
|
||||
do_stack_smash(false, depth + 1, sink);
|
||||
return;
|
||||
}
|
||||
|
||||
/* Underflow path */
|
||||
asm volatile(
|
||||
"li t0, 2048\n"
|
||||
"add sp, sp, t0\n"
|
||||
);
|
||||
|
||||
volatile uint8_t a = 1;
|
||||
volatile uint8_t b = a;
|
||||
(void)b;
|
||||
}
|
||||
|
||||
void _ss_esp_tee_test_stack_overflow(void)
|
||||
{
|
||||
volatile uint8_t sink = 0;
|
||||
do_stack_smash(false, 1, &sink);
|
||||
}
|
||||
|
||||
void _ss_esp_tee_test_stack_underflow(void)
|
||||
{
|
||||
volatile uint8_t sink = 0;
|
||||
do_stack_smash(true, 0, &sink);
|
||||
}
|
||||
|
||||
#pragma GCC pop_options
|
||||
|
||||
static void foo_d(void)
|
||||
|
||||
@@ -1,10 +1,11 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2024-2025 Espressif Systems (Shanghai) CO LTD
|
||||
* SPDX-FileCopyrightText: 2024-2026 Espressif Systems (Shanghai) CO LTD
|
||||
*
|
||||
* SPDX-License-Identifier: Apache-2.0
|
||||
*/
|
||||
|
||||
#include "soc/soc_caps.h"
|
||||
#include "esp_attr.h"
|
||||
|
||||
#if SOC_AES_SUPPORTED
|
||||
#include "soc/aes_reg.h"
|
||||
@@ -21,6 +22,7 @@
|
||||
#include "soc/lp_wdt_reg.h"
|
||||
#include "soc/spi_mem_reg.h"
|
||||
#include "soc/ext_mem_defs.h"
|
||||
#include "soc/assist_debug_reg.h"
|
||||
|
||||
#include "freertos/FreeRTOS.h"
|
||||
#include "freertos/task.h"
|
||||
@@ -226,3 +228,55 @@ TEST_CASE("Test REE-TEE isolation: DROM-W1", "[exception]")
|
||||
*(uint32_t *)(test_addr - 0x04) = 0xbadc0de;
|
||||
TEST_FAIL_MESSAGE("Exception should have been generated");
|
||||
}
|
||||
|
||||
static void do_stack_smash(bool underflow, int depth, volatile uint8_t *sink)
|
||||
{
|
||||
/* Overflow path */
|
||||
if (!underflow) {
|
||||
if (depth == -1) {
|
||||
return; // unreachable
|
||||
}
|
||||
|
||||
uint8_t buffer[1024];
|
||||
buffer[0] = (uint8_t)depth;
|
||||
*sink = buffer[0];
|
||||
|
||||
do_stack_smash(false, depth + 1, sink);
|
||||
return;
|
||||
}
|
||||
|
||||
/* Underflow path */
|
||||
asm volatile(
|
||||
"li t0, 4096\n"
|
||||
"add sp, sp, t0\n"
|
||||
);
|
||||
|
||||
volatile uint8_t temp = 1;
|
||||
(void)temp;
|
||||
}
|
||||
|
||||
TEST_CASE("Test REE stack overflow", "[exception]")
|
||||
{
|
||||
volatile uint8_t sink = 0;
|
||||
do_stack_smash(false, 1, &sink);
|
||||
TEST_FAIL_MESSAGE("Exception should have been generated");
|
||||
}
|
||||
|
||||
TEST_CASE("Test REE stack underflow", "[exception]")
|
||||
{
|
||||
volatile uint8_t sink = 0;
|
||||
do_stack_smash(true, 0, &sink);
|
||||
TEST_FAIL_MESSAGE("Exception should have been generated");
|
||||
}
|
||||
|
||||
TEST_CASE("Test TEE stack overflow", "[exception]")
|
||||
{
|
||||
esp_tee_service_call(1, SS_ESP_TEE_TEST_STACK_OVERFLOW);
|
||||
TEST_FAIL_MESSAGE("Exception should have been generated");
|
||||
}
|
||||
|
||||
TEST_CASE("Test TEE stack underflow", "[exception]")
|
||||
{
|
||||
esp_tee_service_call(1, SS_ESP_TEE_TEST_STACK_UNDERFLOW);
|
||||
TEST_FAIL_MESSAGE("Exception should have been generated");
|
||||
}
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
# SPDX-FileCopyrightText: 2024-2025 Espressif Systems (Shanghai) CO LTD
|
||||
# SPDX-FileCopyrightText: 2024-2026 Espressif Systems (Shanghai) CO LTD
|
||||
# SPDX-License-Identifier: Apache-2.0
|
||||
import re
|
||||
from enum import Enum
|
||||
@@ -40,6 +40,7 @@ TEE_VIOLATION_TEST_EXC_RSN: dict[str, str] = {
|
||||
('IRAM-W2'): 'Store access fault',
|
||||
('DRAM-X1'): 'Instruction access fault',
|
||||
('DRAM-X2'): 'Instruction access fault',
|
||||
('Illegal Instruction'): 'Illegal instruction',
|
||||
}
|
||||
|
||||
REE_ISOLATION_TEST_EXC_RSN: dict[str, str] = {
|
||||
@@ -129,19 +130,6 @@ def test_esp_tee_apm_violation(dut: IdfDut) -> None:
|
||||
raise RuntimeError('Incorrect exception received!')
|
||||
|
||||
|
||||
@idf_parametrize(
|
||||
'config, target, markers',
|
||||
CONFIG_DEFAULT,
|
||||
indirect=['config', 'target'],
|
||||
)
|
||||
def test_esp_tee_illegal_instruction(dut: IdfDut) -> None:
|
||||
dut.expect_exact('Press ENTER to see the list of tests')
|
||||
dut.write('"Test TEE-TEE violation: Illegal Instruction"')
|
||||
exc = dut.expect(r'Core ([01]) panic\'ed \(([^)]+)\)', timeout=30).group(2).decode()
|
||||
if exc != 'Illegal instruction':
|
||||
raise RuntimeError('Incorrect exception received!')
|
||||
|
||||
|
||||
@idf_parametrize(
|
||||
'config, target, markers',
|
||||
CONFIG_DEFAULT,
|
||||
@@ -184,6 +172,23 @@ def test_esp_tee_isolation_checks(dut: IdfDut) -> None:
|
||||
dut.expect('Origin: U-mode')
|
||||
|
||||
|
||||
@idf_parametrize(
|
||||
'config, target, markers',
|
||||
CONFIG_DEFAULT,
|
||||
indirect=['config', 'target'],
|
||||
)
|
||||
def test_esp_tee_stack_smashing(dut: IdfDut) -> None:
|
||||
for env in ('REE', 'TEE'):
|
||||
for case in ('overflow', 'underflow'):
|
||||
dut.expect_exact('Press ENTER to see the list of tests')
|
||||
dut.write(f'"Test {env} stack {case}"')
|
||||
|
||||
match = dut.expect(r"Core ([01]) panic'ed \(([^)]+)\)", timeout=30)
|
||||
exc = match.group(2).decode()
|
||||
if exc != 'Stack protection fault':
|
||||
raise RuntimeError('Incorrect exception received!')
|
||||
|
||||
|
||||
# ---------------- TEE Flash Protection Tests ----------------
|
||||
|
||||
|
||||
|
||||
Reference in New Issue
Block a user