mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-01 10:40:47 +03:00
fix(esp_tee): Add missing input validation checks for TEE service calls
- MULTI_HEAP_ASSERT for TEE now aborts on failure, instead of ignoring the condition - Prevent potential TEE OTA write bounds overflow
This commit is contained in:
@@ -0,0 +1,3 @@
|
||||
# Increasing TEE DRAM size
|
||||
# 17.5KB
|
||||
CONFIG_SECURE_TEE_DRAM_SIZE=0x4600
|
||||
|
||||
@@ -5,8 +5,8 @@ CONFIG_SECURE_TEE_SEC_STG_EFUSE_HMAC_KEY_ID=5
|
||||
# Reducing TEE I/DRAM sizes
|
||||
# 24KB
|
||||
CONFIG_SECURE_TEE_IRAM_SIZE=0x6000
|
||||
# 12KB
|
||||
CONFIG_SECURE_TEE_DRAM_SIZE=0x3000
|
||||
# 13KB
|
||||
CONFIG_SECURE_TEE_DRAM_SIZE=0x3400
|
||||
|
||||
# Disable TEE logs (also disable all panic logs)
|
||||
CONFIG_SECURE_TEE_DEBUG_MODE=n
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
# Reducing TEE I/DRAM sizes
|
||||
# 28KB
|
||||
CONFIG_SECURE_TEE_IRAM_SIZE=0x7000
|
||||
# Reducing TEE IRAM size
|
||||
# 29.5KB
|
||||
CONFIG_SECURE_TEE_IRAM_SIZE=0x7600
|
||||
|
||||
# TEE Secure Storage: Release mode
|
||||
CONFIG_SECURE_TEE_SEC_STG_MODE_RELEASE=y
|
||||
|
||||
@@ -14,6 +14,8 @@ CONFIG_SECURE_FLASH_ENCRYPTION_MODE_RELEASE=y
|
||||
CONFIG_SECURE_TEE_SEC_STG_MODE_RELEASE=y
|
||||
CONFIG_SECURE_TEE_SEC_STG_EFUSE_HMAC_KEY_ID=5
|
||||
|
||||
# Increasing TEE DRAM size
|
||||
# Increasing TEE I/DRAM size
|
||||
# 34KB
|
||||
CONFIG_SECURE_TEE_IRAM_SIZE=0x8800
|
||||
# 18KB
|
||||
CONFIG_SECURE_TEE_DRAM_SIZE=0x4800
|
||||
|
||||
@@ -296,9 +296,9 @@ TEST_CASE("Test TEE Secure Storage - Null Pointer and Zero Length", "[sec_storag
|
||||
};
|
||||
|
||||
TEST_ESP_ERR(ESP_ERR_INVALID_ARG, esp_tee_sec_storage_aead_encrypt(&aead_ctx, NULL, sizeof(tag), data));
|
||||
TEST_ESP_ERR(ESP_ERR_INVALID_SIZE, esp_tee_sec_storage_aead_encrypt(&aead_ctx, tag, 0, data));
|
||||
TEST_ESP_ERR(ESP_ERR_INVALID_ARG, esp_tee_sec_storage_aead_encrypt(&aead_ctx, tag, 0, data));
|
||||
TEST_ESP_ERR(ESP_ERR_INVALID_ARG, esp_tee_sec_storage_aead_decrypt(&aead_ctx, NULL, sizeof(tag), data));
|
||||
TEST_ESP_ERR(ESP_ERR_INVALID_SIZE, esp_tee_sec_storage_aead_decrypt(&aead_ctx, tag, 0, data));
|
||||
TEST_ESP_ERR(ESP_ERR_INVALID_ARG, esp_tee_sec_storage_aead_decrypt(&aead_ctx, tag, 0, data));
|
||||
|
||||
aead_ctx.input = NULL;
|
||||
aead_ctx.input_len = sizeof(data);
|
||||
@@ -307,8 +307,8 @@ TEST_CASE("Test TEE Secure Storage - Null Pointer and Zero Length", "[sec_storag
|
||||
|
||||
aead_ctx.input = data;
|
||||
aead_ctx.input_len = 0;
|
||||
TEST_ESP_ERR(ESP_ERR_INVALID_SIZE, esp_tee_sec_storage_aead_encrypt(&aead_ctx, tag, sizeof(tag), data));
|
||||
TEST_ESP_ERR(ESP_ERR_INVALID_SIZE, esp_tee_sec_storage_aead_decrypt(&aead_ctx, tag, sizeof(tag), data));
|
||||
TEST_ESP_ERR(ESP_ERR_INVALID_ARG, esp_tee_sec_storage_aead_encrypt(&aead_ctx, tag, sizeof(tag), data));
|
||||
TEST_ESP_ERR(ESP_ERR_INVALID_ARG, esp_tee_sec_storage_aead_decrypt(&aead_ctx, tag, sizeof(tag), data));
|
||||
|
||||
TEST_ESP_OK(esp_tee_sec_storage_clear_key(key_id));
|
||||
|
||||
|
||||
@@ -15,7 +15,3 @@ CONFIG_SECURE_TEE_ATT_KEY_STR_ID="tee_att_keyN"
|
||||
|
||||
# Enabling flash protection over SPI1
|
||||
CONFIG_SECURE_TEE_EXT_FLASH_MEMPROT_SPI1=y
|
||||
|
||||
# Increasing TEE DRAM size
|
||||
# 19KB
|
||||
CONFIG_SECURE_TEE_DRAM_SIZE=0x4c00
|
||||
|
||||
@@ -13,3 +13,7 @@ CONFIG_SECURE_TEE_TEST_MODE=y
|
||||
# Setting partition table
|
||||
CONFIG_PARTITION_TABLE_SINGLE_APP_TEE=y
|
||||
CONFIG_PARTITION_TABLE_OFFSET=0xF000
|
||||
|
||||
# Increasing TEE I/DRAM size
|
||||
CONFIG_SECURE_TEE_IRAM_SIZE=0x8800
|
||||
CONFIG_SECURE_TEE_DRAM_SIZE=0x4c00
|
||||
|
||||
Reference in New Issue
Block a user