Disable Secure floating point and seal the Secure stacks - #52
Conversation
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #52
Scan targets checked: wolftrust-src, wolftrust-bugs
Coverage: 4 of 5 in-scope changed file(s) opened by the reviewer; not opened: include/wolftrust/arch/armv8m/core_regs.h
Fenrir result: Approved ✅
No new issues found in the changed files.
Advisory only — this automated result does not count as a GitHub approval.
Review tier: Lite
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
Security-critical exception handling, FP-state control, and context-switch assembly require final hardware-owner validation.
Review effort: Balanced
Findings: None
What changed in this PR
Disables Secure floating-point use and adds stack seals across Armv8-M boot and coroutine context switching.
Changes:
- Locks down FP state and rejects FP code post-link.
- Adds main-stack and coroutine seals with runtime validation.
- Adds emulator, hardware, and host negative tests plus documentation.
| File | Description |
|---|---|
tools/check_stack_seal.py |
Validates main-stack seal clearance. |
tools/check_no_fp_insn.py |
Rejects FP instructions and helpers. |
tests/target/run_rt700_m33mu.sh |
Adds RT700 negative scenarios. |
tests/target/run_m33mu_scenario.sh |
Adds H5 emulator assertions. |
tests/target/run_h5_hardware.sh |
Adds silicon negative tests. |
tests/target/lib/scenario.sh |
Registers scenario flags and verdicts. |
tests/target/lib/scenario_matrix.py |
Extends the CI scenario matrix. |
tests/host/secure_layout/Makefile |
Runs checker self-tests. |
tests/host/manifest/test_probe_stamp.sh |
Tests probe build invalidation. |
tests/host/manifest/Makefile |
Runs probe-stamp testing. |
src/arch/armv8m/start_armv8m.c |
Seals and verifies the main stack. |
src/arch/armv8m/spm_svc.c |
Adds FP and stack-pivot probes. |
src/arch/armv8m/guest_context_armv8m.c |
Locks down Secure FP state. |
src/arch/armv8m/coroutine_armv8m.c |
Seals coroutine stacks and validates switches. |
mk/common.mk |
Tracks probe flags and LTO exclusions. |
mk/arch-armv8m.mk |
Integrates post-link checks. |
include/wolftrust/arch/armv8m/core_regs.h |
Defines FP and seal constants. |
docs/Testing.md |
Documents negative-test coverage and limits. |
docs/Security-Model.md |
Documents processor-state isolation. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
d0a36af to
3fa5488
Compare
3fa5488 to
979ca0a
Compare
979ca0a to
6f4f649
Compare
Uh oh!
There was an error while loading. Please reload this page.