fix(esp_tee): Add missing input validation checks for TEE service calls

- MULTI_HEAP_ASSERT for TEE now aborts on failure, instead of ignoring the condition
- Prevent potential TEE OTA write bounds overflow
This commit is contained in:
Laukik Hase
2026-04-09 16:34:21 +05:30
parent 727cd73fb4
commit eebabaff2f
12 changed files with 412 additions and 141 deletions
@@ -0,0 +1,3 @@
# Increasing TEE DRAM size
# 17.5KB
CONFIG_SECURE_TEE_DRAM_SIZE=0x4600
@@ -5,8 +5,8 @@ CONFIG_SECURE_TEE_SEC_STG_EFUSE_HMAC_KEY_ID=5
# Reducing TEE I/DRAM sizes
# 24KB
CONFIG_SECURE_TEE_IRAM_SIZE=0x6000
# 12KB
CONFIG_SECURE_TEE_DRAM_SIZE=0x3000
# 13KB
CONFIG_SECURE_TEE_DRAM_SIZE=0x3400
# Disable TEE logs (also disable all panic logs)
CONFIG_SECURE_TEE_DEBUG_MODE=n
@@ -1,6 +1,6 @@
# Reducing TEE I/DRAM sizes
# 28KB
CONFIG_SECURE_TEE_IRAM_SIZE=0x7000
# Reducing TEE IRAM size
# 29.5KB
CONFIG_SECURE_TEE_IRAM_SIZE=0x7600
# TEE Secure Storage: Release mode
CONFIG_SECURE_TEE_SEC_STG_MODE_RELEASE=y
@@ -14,6 +14,8 @@ CONFIG_SECURE_FLASH_ENCRYPTION_MODE_RELEASE=y
CONFIG_SECURE_TEE_SEC_STG_MODE_RELEASE=y
CONFIG_SECURE_TEE_SEC_STG_EFUSE_HMAC_KEY_ID=5
# Increasing TEE DRAM size
# Increasing TEE I/DRAM size
# 34KB
CONFIG_SECURE_TEE_IRAM_SIZE=0x8800
# 18KB
CONFIG_SECURE_TEE_DRAM_SIZE=0x4800