Skip to content

Disable Secure floating point and seal the Secure stacks - #52

Merged
mattia-moffa merged 7 commits into
wolfSSL:mainfrom
aidangarske:ffm-l3-stack-seal
Oct 1, 2026
Merged

mattia-moffa merged 7 commits into
wolfSSL:mainfrom
aidangarske:ffm-l3-stack-seal

Conversation

@aidangarske

@aidangarske aidangarske commented Sep 30, 2026 •

Copy link
Copy Markdown
Member
  • Turn off Secure floating point at boot (CPACR_S, CPACR_NS, NSACR, FPCCR_S) and halts unless every bit reads back as programmed for armv8
  • A post-link check (tools/check_no_fp_insn.py) fails the Secure build on any FP instruction or soft-float helper, so FP use in a partition faults instead of leaving FP state behind.
  • The top of the Secure main stack and every coroutine stack carries 0xFEF5EDA5 seal words. Boot refuses to continue without the main-stack seal. The SPM checks coroutine seals at every yield, preemption and dispatch. A partition that damages its own seal faults and restarts; damage found while the owner is suspended halts the platform.
  • A second post-link check (tools/check_stack_seal.py) fails the build if an allocated section reaches the main-stack seal.
  • New M33MU negatives: fpneg, sealneg, sealhaltneg, sealbootneg and sealpivotneg on STM32H563; fpneg and sealbootneg on MIMXRT700. run_h5_hardware.sh runs them on silicon.
  • Security-Model.md and Testing.md document the policy and its limits.

@aidangarske aidangarske self-assigned this Sep 30, 2026
Copilot AI balanced review requested due to automatic review settings September 30, 2026 23:23
@aidangarske aidangarske added ci:all Run every M33MU scenario of every port on the PR (core change) and removed ci:all Run every M33MU scenario of every port on the PR (core change) labels Sep 30, 2026

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #52

Scan targets checked: wolftrust-src, wolftrust-bugs
Coverage: 4 of 5 in-scope changed file(s) opened by the reviewer; not opened: include/wolftrust/arch/armv8m/core_regs.h

Fenrir result: Approved ✅

No new issues found in the changed files.

Advisory only — this automated result does not count as a GitHub approval.

Review tier: Lite

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Security-critical exception handling, FP-state control, and context-switch assembly require final hardware-owner validation.

Review effort: Balanced
Findings: None

What changed in this PR

Disables Secure floating-point use and adds stack seals across Armv8-M boot and coroutine context switching.

Changes:

  • Locks down FP state and rejects FP code post-link.
  • Adds main-stack and coroutine seals with runtime validation.
  • Adds emulator, hardware, and host negative tests plus documentation.
File Description
tools/​check_stack_seal.py Validates main-stack seal clearance.
tools/​check_no_fp_insn.py Rejects FP instructions and helpers.
tests/​target/​run_rt700_m33mu.sh Adds RT700 negative scenarios.
tests/​target/​run_m33mu_scenario.sh Adds H5 emulator assertions.
tests/​target/​run_h5_hardware.sh Adds silicon negative tests.
tests/​target/​lib/​scenario.sh Registers scenario flags and verdicts.
tests/​target/​lib/​scenario_matrix.py Extends the CI scenario matrix.
tests/​host/​secure_layout/​Makefile Runs checker self-tests.
tests/​host/​manifest/​test_probe_stamp.sh Tests probe build invalidation.
tests/​host/​manifest/​Makefile Runs probe-stamp testing.
src/​arch/​armv8m/​start_armv8m.c Seals and verifies the main stack.
src/​arch/​armv8m/​spm_svc.c Adds FP and stack-pivot probes.
src/​arch/​armv8m/​guest_context_armv8m.c Locks down Secure FP state.
src/​arch/​armv8m/​coroutine_armv8m.c Seals coroutine stacks and validates switches.
mk/​common.mk Tracks probe flags and LTO exclusions.
mk/​arch-armv8m.mk Integrates post-link checks.
include/​wolftrust/​arch/​armv8m/​core_regs.h Defines FP and seal constants.
docs/​Testing.md Documents negative-test coverage and limits.
docs/​Security-Model.md Documents processor-state isolation.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@aidangarske aidangarske added the ci:all Run every M33MU scenario of every port on the PR (core change) label Oct 1, 2026
@aidangarske aidangarske added ci:all Run every M33MU scenario of every port on the PR (core change) and removed ci:all Run every M33MU scenario of every port on the PR (core change) labels Oct 1, 2026
@aidangarske aidangarske added ci:all Run every M33MU scenario of every port on the PR (core change) and removed ci:all Run every M33MU scenario of every port on the PR (core change) labels Oct 1, 2026
@mattia-moffa
mattia-moffa merged commit f49be38 into wolfSSL:main Oct 1, 2026
282 of 386 checks passed
@aidangarske
aidangarske deleted the ffm-l3-stack-seal branch October 1, 2026 18:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci:all Run every M33MU scenario of every port on the PR (core change)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants