fix(esp_tee): Validate REE-supplied memory bounds (esp_tee_app_config) before use

This commit is contained in:
Laukik Hase
2026-07-23 11:29:57 +05:30
parent acb7d996b0
commit b77016e350
5 changed files with 85 additions and 56 deletions
@@ -16,19 +16,9 @@
extern "C" {
#endif
FORCE_INLINE_ATTR bool esp_tee_ptr_in_ree(const void *p)
{
uintptr_t addr = (uintptr_t)p;
return (
(addr >= SOC_NS_IDRAM_START && addr < SOC_NS_IDRAM_END) ||
(addr >= (uintptr_t)esp_tee_app_config.ns_drom_start &&
addr < SOC_S_MMU_MMAP_RESV_START_VADDR)
#if SOC_RTC_MEM_SUPPORTED
|| (addr >= SOC_RTC_DATA_LOW && addr < SOC_RTC_DATA_HIGH)
#endif
);
}
/* TODO: Revisit these bounds for high-performance RISC-V SoCs (e.g. ESP32-P4,
* ESP32-S31) with different memory maps than current ESP-TEE targets.
*/
FORCE_INLINE_ATTR bool esp_tee_buf_in_ree(const void *p, size_t len)
{
uintptr_t start = (uintptr_t)p;
@@ -40,13 +30,18 @@ FORCE_INLINE_ATTR bool esp_tee_buf_in_ree(const void *p, size_t len)
uintptr_t end = start + len;
return ((start >= SOC_NS_IDRAM_START && end <= SOC_NS_IDRAM_END) ||
(start >= (uintptr_t)esp_tee_app_config.ns_drom_start && end <= SOC_S_MMU_MMAP_RESV_START_VADDR)
(start >= SOC_S_DROM_HIGH && end <= SOC_S_MMU_MMAP_RESV_START_VADDR)
#if SOC_RTC_MEM_SUPPORTED
|| (start >= SOC_RTC_DATA_LOW && end <= SOC_RTC_DATA_HIGH)
#endif
);
}
FORCE_INLINE_ATTR bool esp_tee_ptr_in_ree(const void *p)
{
return esp_tee_buf_in_ree(p, 4);
}
#ifdef __cplusplus
}
#endif