fix(bitscrambler): reject malformed program headers

Validate BitScrambler program headers against the supported format and
hardware limits before using header-derived instruction and LUT sizes.
Also add regression coverage for malformed headers and document that the
program blob must come from a trusted assembler output.
This commit is contained in:
morris
2026-08-05 15:23:20 +08:00
parent ef06a1d867
commit 4fe8d320bf
4 changed files with 38 additions and 7 deletions
@@ -73,6 +73,11 @@ void bitscrambler_free(bitscrambler_handle_t handle);
/**
* @brief Load a BitScrambler binary program into BitScrambler memory
*
* @note The program blob is expected to come from a trusted BitScrambler assembler
* output. This API validates the header fields against hardware limits, but it
* does not take an explicit blob length and therefore cannot verify that an
* arbitrary caller-supplied buffer is complete.
*
* @param handle BitScrambler handle
* @param program Binary program to load
*