mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-03 03:31:41 +03:00
fix(esp_tee): Fix TEE attestation stack protection fault with secure boot enabled
- Increased the TEE stack when secure boot is enabled - Also, generate a build error when the generated TEE binary image size is greater than the TEE partition size
This commit is contained in:
@@ -15,7 +15,3 @@ CONFIG_NVS_SEC_KEY_PROTECT_USING_FLASH_ENC=y
|
||||
# TEE Secure Storage: Release mode
|
||||
CONFIG_SECURE_TEE_SEC_STG_MODE_RELEASE=y
|
||||
CONFIG_SECURE_TEE_SEC_STG_EFUSE_HMAC_KEY_ID=5
|
||||
|
||||
# Increasing TEE DRAM size
|
||||
# 18KB
|
||||
CONFIG_SECURE_TEE_DRAM_SIZE=0x5000
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
# ESP-IDF Partition Table
|
||||
# Name, Type, SubType, Offset, Size, Flags
|
||||
tee_0, app, tee_0, , 192K,
|
||||
tee_1, app, tee_1, , 192K,
|
||||
tee_0, app, tee_0, , 256K,
|
||||
tee_1, app, tee_1, , 256K,
|
||||
tee_otadata, data, tee_ota, , 8K,
|
||||
secure_storage, data, nvs, , 56K,
|
||||
ota_0, app, ota_0, , 512K,
|
||||
|
||||
|
@@ -353,7 +353,7 @@ def test_esp_tee_ota_reboot_without_ota_end(dut: IdfDut) -> None:
|
||||
dut.write('"Test TEE OTA - Reboot without ending OTA"')
|
||||
|
||||
# OTA begin checks
|
||||
tee_ota_stage_checks(dut, TeeOtaStage.BEGIN, '0x40000')
|
||||
tee_ota_stage_checks(dut, TeeOtaStage.BEGIN, '0x50000')
|
||||
|
||||
# after reboot
|
||||
tee_ota_stage_checks(dut, TeeOtaStage.REBOOT, '0x10000')
|
||||
@@ -376,18 +376,18 @@ def test_esp_tee_ota_valid_img(dut: IdfDut) -> None:
|
||||
dut.write('"Test TEE OTA - Valid image"')
|
||||
|
||||
# OTA begin checks
|
||||
tee_ota_stage_checks(dut, TeeOtaStage.BEGIN, '0x40000')
|
||||
tee_ota_stage_checks(dut, TeeOtaStage.BEGIN, '0x50000')
|
||||
dut.expect('TEE OTA update successful!', timeout=10)
|
||||
|
||||
# after reboot 1
|
||||
tee_ota_stage_checks(dut, TeeOtaStage.REBOOT, '0x40000')
|
||||
tee_ota_stage_checks(dut, TeeOtaStage.REBOOT, '0x50000')
|
||||
|
||||
# resetting device to check for image validity
|
||||
dut.serial.hard_reset()
|
||||
|
||||
# after reboot 2
|
||||
dut.expect('TEE otadata - Current image state: VALID', timeout=10)
|
||||
tee_ota_stage_checks(dut, TeeOtaStage.REBOOT, '0x40000')
|
||||
tee_ota_stage_checks(dut, TeeOtaStage.REBOOT, '0x50000')
|
||||
|
||||
|
||||
@idf_parametrize(
|
||||
@@ -407,12 +407,12 @@ def test_esp_tee_ota_rollback(dut: IdfDut) -> None:
|
||||
dut.write('"Test TEE OTA - Rollback"')
|
||||
|
||||
# OTA begin checks
|
||||
tee_ota_stage_checks(dut, TeeOtaStage.BEGIN, '0x40000')
|
||||
tee_ota_stage_checks(dut, TeeOtaStage.BEGIN, '0x50000')
|
||||
dut.expect('TEE OTA update successful!', timeout=10)
|
||||
|
||||
# after reboot 1
|
||||
dut.expect('TEE otadata - Current image state: NEW', timeout=10)
|
||||
dut.expect('Loaded TEE app from partition at offset 0x40000', timeout=10)
|
||||
dut.expect('Loaded TEE app from partition at offset 0x50000', timeout=10)
|
||||
rst_rsn = dut.expect(r'rst:(0x[0-9A-Fa-f]+) \(([^)]+)\)', timeout=10).group(2).decode()
|
||||
# NOTE: LP_WDT_SYS (C6/H2) and RTC_WDT_SYS (C5) are expected as bootloader fails to load the dummy TEE app
|
||||
if rst_rsn not in {'LP_WDT_SYS', 'RTC_WDT_SYS'}:
|
||||
|
||||
Reference in New Issue
Block a user