mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-01 18:50:34 +03:00
fix(esp_tee): Harden the TEE secure services against REE manipulation
- `bootloader_flash_execute_command_common`: whitelist the flash command opcodes the REE actually uses; reject the rest - `spi_flash_hal_* services`: a forged `host->driver` could hijack TEE control flow since the HAL dispatches through it, so swap `host->driver` to a TEE-rodata vtable around each HAL call - Deny partition table and bootloader writes by default and permit bootloader writes only when explicitly enabled via `CONFIG_SPI_FLASH_DANGEROUS_WRITE_ALLOWED` option - Protect the TEE-assigned interrupt pin configuration against REE - Validate nested DS context pointers in start/finish_sign and bound the result copy to the SoC max signature size - Fix the stack usage in service dispatcher argument parsing
This commit is contained in:
@@ -38,8 +38,13 @@ FORCE_INLINE_ATTR bool esp_tee_buf_in_ree(const void *p, size_t len)
|
||||
return false;
|
||||
}
|
||||
|
||||
return esp_tee_ptr_in_ree(p) &&
|
||||
esp_tee_ptr_in_ree((const char *)p + len - 1);
|
||||
uintptr_t end = start + len;
|
||||
return ((start >= SOC_NS_IDRAM_START && end <= SOC_NS_IDRAM_END) ||
|
||||
(start >= (uintptr_t)esp_tee_app_config.ns_drom_start && end <= SOC_S_MMU_MMAP_RESV_START_VADDR)
|
||||
#if SOC_RTC_MEM_SUPPORTED
|
||||
|| (start >= SOC_RTC_DATA_LOW && end <= SOC_RTC_DATA_HIGH)
|
||||
#endif
|
||||
);
|
||||
}
|
||||
|
||||
#ifdef __cplusplus
|
||||
|
||||
Reference in New Issue
Block a user