fix(esp_tee): Harden the TEE secure services against REE manipulation

- `bootloader_flash_execute_command_common`: whitelist the flash command
   opcodes the REE actually uses; reject the rest
- `spi_flash_hal_* services`: a forged `host->driver` could hijack TEE
   control flow since the HAL dispatches through it, so swap
   `host->driver` to a TEE-rodata vtable around each HAL call
- Deny partition table and bootloader writes by default and permit
  bootloader writes only when explicitly enabled via
  `CONFIG_SPI_FLASH_DANGEROUS_WRITE_ALLOWED` option
- Protect the TEE-assigned interrupt pin configuration against REE
- Validate nested DS context pointers in start/finish_sign and bound
  the result copy to the SoC max signature size
- Fix the stack usage in service dispatcher argument parsing
This commit is contained in:
Laukik Hase
2026-06-10 12:05:47 +05:30
parent c66f9a3a8e
commit ba0f3f9872
12 changed files with 249 additions and 68 deletions
@@ -20,6 +20,11 @@ extern "C" {
#define TEE_SECURE_INUM (31)
#if SOC_INT_CLIC_SUPPORTED
#define TEE_PASS_INUM (30)
/* CLIC: 3 effective priority bits (NLBITS=3), max priority = 7 */
#define TEE_SECURE_INUM_PRIO (7)
#else
/* PLIC: 4-bit priority field, max priority = 15 */
#define TEE_SECURE_INUM_PRIO (15)
#endif
#define ESP_TEE_M2U_SWITCH_MAGIC 0xfedef