fix(bitscrambler): reject malformed program headers

Validate BitScrambler program headers against the supported format and
hardware limits before using header-derived instruction and LUT sizes.
Also add regression coverage for malformed headers and document that the
program blob must come from a trusted assembler output.
This commit is contained in:
morris
2026-08-05 15:23:20 +08:00
parent ef06a1d867
commit 4fe8d320bf
4 changed files with 38 additions and 7 deletions
@@ -23,6 +23,9 @@ extern "C" {
#define BITSCRAMBLER_LL_GET_HW(num) (((num) == 0) ? (&BITSCRAMBLER) : NULL)
#define BITSCRAMBLER_LL_INST_LEN_WORDS 9 //length of one instruction in 32-bit words as defined by HW
// LUT index register is 11 bits wide, so the LUT address space is 2048 bytes.
#define BITSCRAMBLER_LL_LUT_MAX_BYTES (1U << 11)
#define BITSCRAMBLER_LL_MAX_INST 8
/**
* @brief Select peripheral BitScrambler is attached to
@@ -23,6 +23,9 @@ extern "C" {
#define BITSCRAMBLER_LL_GET_HW(num) (((num) == 0) ? (&BITSCRAMBLER) : NULL)
#define BITSCRAMBLER_LL_INST_LEN_WORDS 9 //length of one instruction in 32-bit words as defined by HW
// LUT index register is 11 bits wide, so the LUT address space is 2048 bytes.
#define BITSCRAMBLER_LL_LUT_MAX_BYTES (1U << 11)
#define BITSCRAMBLER_LL_MAX_INST 8
/**
* @brief Select peripheral BitScrambler is attached to