feat(build): add RISC-V ZCMP post-link workaround check

Validate linked RISC-V executables when
CONFIG_COMPILER_ENABLE_RISCV_ZCMP is enabled on affected chips.
Disassemble each function and reject mstatus.MIE clears that lack an
earlier mintthresh write of 0xff.

Handle csrrci, csrrw, and register-mask csrrc patterns while ignoring
csrrs. Add build-only coverage for valid and invalid sequences with
CMake v1 and v2.

Stop the hardware stack guard before switching stacks during restart,
and keep ZCMP disabled for TEE test apps that still require the
workaround.
This commit is contained in:
Alexey Lapshin
2026-08-03 14:10:00 +08:00
committed by BOT
parent 6a9c44fe7e
commit a494009a0c
20 changed files with 380 additions and 23 deletions
@@ -0,0 +1,34 @@
# SPDX-FileCopyrightText: 2026 Espressif Systems (Shanghai) CO LTD
# SPDX-License-Identifier: Apache-2.0
import logging
from pathlib import Path
import pytest
from test_build_system_helpers import IdfPyFunc
_IDF_TARGET = 'esp32c5'
_CMAKEV2_CMAKELISTS = """\
cmake_minimum_required(VERSION 3.22)
include($ENV{IDF_PATH}/tools/cmakev2/idf.cmake)
project(test_zcmp_workaround_checking C CXX ASM)
idf_project_default()
"""
@pytest.mark.test_app_copy('components/riscv/test_apps/test_zcmp_workaround_checking')
@pytest.mark.usefixtures('test_app_copy')
def test_zcmp_workaround_checking(idf_py: IdfPyFunc, test_app_copy: Path) -> None:
"""ZCMP POST_ELF check must fail when mstatus.mie is cleared without mintthresh workaround."""
logging.info('Building zcmp workaround checking test app (build system v2)')
(test_app_copy / 'CMakeLists.txt').write_text(_CMAKEV2_CMAKELISTS, encoding='utf-8')
idf_py('set-target', _IDF_TARGET)
ret = idf_py('-DTEST_INVALID_WORKAROUND=1', 'build', check=False)
output = (ret.stdout or '') + (ret.stderr or '')
assert ret.returncode != 0, 'Build must fail when ZCMP workaround is violated'
assert 'ZCMP workaround violation' in output, 'Build output must report the ZCMP workaround violation'
@@ -0,0 +1,23 @@
# SPDX-FileCopyrightText: 2026 Espressif Systems (Shanghai) CO LTD
# SPDX-License-Identifier: Apache-2.0
import logging
import pytest
from test_build_system_helpers import IdfPyFunc
_IDF_TARGET = 'esp32c5'
@pytest.mark.test_app_copy('components/riscv/test_apps/test_zcmp_workaround_checking')
@pytest.mark.usefixtures('test_app_copy')
@pytest.mark.buildv2_skip('Uses build system v1 project.cmake test app')
def test_zcmp_workaround_checking(idf_py: IdfPyFunc) -> None:
"""ZCMP post-ELF check must fail when mstatus.mie is cleared without mintthresh workaround."""
logging.info('Building zcmp workaround checking test app')
idf_py('set-target', _IDF_TARGET)
ret = idf_py('-DTEST_INVALID_WORKAROUND=1', 'build', check=False)
output = (ret.stdout or '') + (ret.stderr or '')
assert ret.returncode != 0, 'Build must fail when ZCMP workaround is violated'
assert 'ZCMP workaround violation' in output, 'Build output must report the ZCMP workaround violation'