fix(esp_tee): Harden the TEE secure services against REE manipulation

- `bootloader_flash_execute_command_common`: whitelist the flash command
   opcodes the REE actually uses; reject the rest
- `spi_flash_hal_* services`: a forged `host->driver` could hijack TEE
   control flow since the HAL dispatches through it, so swap
   `host->driver` to a TEE-rodata vtable around each HAL call
- Deny partition table and bootloader writes by default and permit
  bootloader writes only when explicitly enabled via
  `CONFIG_SPI_FLASH_DANGEROUS_WRITE_ALLOWED` option
- Protect the TEE-assigned interrupt pin configuration against REE
- Validate nested DS context pointers in start/finish_sign and bound
  the result copy to the SoC max signature size
- Fix the stack usage in service dispatcher argument parsing
This commit is contained in:
Laukik Hase
2026-06-10 12:02:34 +05:30
parent 02c225b604
commit c9f6efb976
12 changed files with 249 additions and 68 deletions
@@ -38,8 +38,13 @@ FORCE_INLINE_ATTR bool esp_tee_buf_in_ree(const void *p, size_t len)
return false;
}
return esp_tee_ptr_in_ree(p) &&
esp_tee_ptr_in_ree((const char *)p + len - 1);
uintptr_t end = start + len;
return ((start >= SOC_NS_IDRAM_START && end <= SOC_NS_IDRAM_END) ||
(start >= (uintptr_t)esp_tee_app_config.ns_drom_start && end <= SOC_S_MMU_MMAP_RESV_START_VADDR)
#if SOC_RTC_MEM_SUPPORTED
|| (start >= SOC_RTC_DATA_LOW && end <= SOC_RTC_DATA_HIGH)
#endif
);
}
#ifdef __cplusplus