feat(build): add RISC-V ZCMP post-link workaround check

Validate linked RISC-V executables when
CONFIG_COMPILER_ENABLE_RISCV_ZCMP is enabled on affected chips.
Disassemble each function and reject mstatus.MIE clears that lack an
earlier mintthresh write of 0xff.

Handle csrrci, csrrw, and register-mask csrrc patterns while ignoring
csrrs. Add build-only coverage for valid and invalid sequences with
CMake v1 and v2.

Stop the hardware stack guard before switching stacks during restart,
and keep ZCMP disabled for TEE test apps that still require the
workaround.
This commit is contained in:
Alexey Lapshin
2026-07-22 13:04:20 +07:00
parent ef2d5c887d
commit 631ad9033c
19 changed files with 383 additions and 8 deletions
@@ -0,0 +1,13 @@
# Documentation: .gitlab/ci/README.md#manifest-file-to-control-the-buildtest-apps
components/riscv/test_apps/test_zcmp_workaround_checking:
enable:
- if: SOC_CPU_ZCMP_WORKAROUND == 1
reason: builds chips that require the ZCMP mintthresh workaround
disable_test:
- if: SOC_CPU_ZCMP_WORKAROUND == 1
reason: build-only check for ZCMP workaround
depends_components:
- riscv
- soc
- freertos
@@ -0,0 +1,7 @@
cmake_minimum_required(VERSION 3.22)
include($ENV{IDF_PATH}/tools/cmake/project.cmake)
idf_build_set_property(MINIMAL_BUILD ON)
project(test_zcmp_workaround_checking)
@@ -0,0 +1,11 @@
| Supported Targets | ESP32-C5 | ESP32-C61 | ESP32-H4 | ESP32-P4 |
| ----------------- | -------- | --------- | -------- | -------- |
Build-only check for the post-link ZCMP workaround validator.
CI builds the default app on every target with ``SOC_CPU_ZCMP_WORKAROUND``
(valid mintthresh workaround + ZCMP). No flash; a successful link is the pass
criterion.
Negative coverage lives in ``tools/test_build_system`` (cmake v1/v2): build with
``-DTEST_INVALID_WORKAROUND=1`` must fail with ``ZCMP workaround violation``.
@@ -0,0 +1,5 @@
idf_component_register(SRCS "test_zcmp_workaround_checking.c")
if(TEST_INVALID_WORKAROUND)
target_compile_definitions(${COMPONENT_LIB} PRIVATE TEST_INVALID_WORKAROUND)
endif()
@@ -0,0 +1,24 @@
/*
* SPDX-FileCopyrightText: 2026 Espressif Systems (Shanghai) CO LTD
*
* SPDX-License-Identifier: Apache-2.0
*/
#include <stdint.h>
void app_main(void)
{
uint32_t mstatus;
#ifdef TEST_INVALID_WORKAROUND
/* Intentional ZCMP violation: clear MIE without mintthresh write. */
__asm__ volatile("csrrci %0, mstatus, 0x8" : "=r"(mstatus));
#else
__asm__ volatile(
"li t0, 0xff\n"
"csrrw zero, 0x347, t0\n"
"csrrci %0, mstatus, 0x8"
: "=r"(mstatus)
:
: "t0");
#endif
(void)mstatus;
}
@@ -0,0 +1 @@
CONFIG_COMPILER_ENABLE_RISCV_ZCMP=y