fix(esp_tee): Add missing input validation checks for TEE service calls

- MULTI_HEAP_ASSERT for TEE now aborts on failure, instead of ignoring the condition
- Prevent potential TEE OTA write bounds overflow
This commit is contained in:
Laukik Hase
2026-04-09 16:34:21 +05:30
parent 727cd73fb4
commit eebabaff2f
12 changed files with 412 additions and 141 deletions
@@ -1,10 +1,12 @@
/*
* SPDX-FileCopyrightText: 2025 Espressif Systems (Shanghai) CO LTD
* SPDX-FileCopyrightText: 2025-2026 Espressif Systems (Shanghai) CO LTD
*
* SPDX-License-Identifier: Apache-2.0
*/
#pragma once
#include <stddef.h>
#include <stdint.h>
#include "esp_attr.h"
#include "soc/soc.h"
#include "soc/ext_mem_defs.h"
@@ -16,9 +18,28 @@ extern "C" {
FORCE_INLINE_ATTR bool esp_tee_ptr_in_ree(const void *p)
{
return (((intptr_t)p >= SOC_NS_IDRAM_START && (intptr_t)p < SOC_NS_IDRAM_END) ||
((intptr_t)p >= (size_t)esp_tee_app_config.ns_drom_start && (intptr_t)p < SOC_S_MMU_MMAP_RESV_START_VADDR) ||
((intptr_t)p >= SOC_RTC_DATA_LOW && (intptr_t)p < SOC_RTC_DATA_HIGH));
uintptr_t addr = (uintptr_t)p;
return (
(addr >= SOC_NS_IDRAM_START && addr < SOC_NS_IDRAM_END) ||
(addr >= (uintptr_t)esp_tee_app_config.ns_drom_start &&
addr < SOC_S_MMU_MMAP_RESV_START_VADDR)
#if SOC_RTC_MEM_SUPPORTED
|| (addr >= SOC_RTC_DATA_LOW && addr < SOC_RTC_DATA_HIGH)
#endif
);
}
FORCE_INLINE_ATTR bool esp_tee_buf_in_ree(const void *p, size_t len)
{
uintptr_t start = (uintptr_t)p;
/* Reject zero-length and overflow */
if (len == 0 || len > (SIZE_MAX - start)) {
return false;
}
return esp_tee_ptr_in_ree(p) &&
esp_tee_ptr_in_ree((const char *)p + len - 1);
}
#ifdef __cplusplus