diff --git a/.github/workflows/m33mu.yml b/.github/workflows/m33mu.yml index 218cfece..6b1d822b 100644 --- a/.github/workflows/m33mu.yml +++ b/.github/workflows/m33mu.yml @@ -121,8 +121,8 @@ jobs: WT_MAX_GUESTS: 2 ZEPHYR_BOARD: nucleo_h563zi/stm32h563xx/ns WT_TEST_GUEST: ${{ matrix.guest }} - # Upstream master with danielinux/m33mu PR #19 (STM32H5 DBGMCU_IDCODE). - M33MU_REF: 5d7f854acd8bcb5b56a6dba391995f9373261b1c + # Upstream master with danielinux/m33mu PR #21 (deterministic USART IRQ timing). + M33MU_REF: f3c03675260264cdec815adebe4b020bb6fe57b8 steps: - uses: actions/checkout@v4 diff --git a/docs/Testing.md b/docs/Testing.md index 8a5d0098..e73a6f10 100644 --- a/docs/Testing.md +++ b/docs/Testing.md @@ -245,12 +245,8 @@ framework, its PAL, and the test lists are the upstream sources the Secure build fetches and generates. The runner builds its own pinned emulator and wolfBoot first stage. The -emulator is `M33MU_REF` plus `tests/target/m33mu-imxrt700.patch`, the model -correction the chain needs until it lands upstream: a Secure AHBSC SRAM rule -refuses Non-secure transactions but no longer overrides the SAU's NSC -attribution, so the SG veneers in the Secure-ruled code-RAM band stay callable -as the SRM's transaction check allows. The rules otherwise apply to CPU0 as -documented, which is stricter than the EVK measured. +emulator is upstream M33MU at `M33MU_REF`, unpatched. Its Secure AHBSC SRAM +rules apply to CPU0 as documented, which is stricter than the EVK measured. wolfBoot is `WOLFBOOT_REF` built from `config/examples/imx-rt700-tz.config` plus `tests/target/wolfboot-imxrt700-lifecycle.patch` (the RT700 HAL's PSA lifecycle hook, which the attestation service needs; it goes once wolfBoot diff --git a/tests/target/m33mu-imxrt700.patch b/tests/target/m33mu-imxrt700.patch deleted file mode 100644 index 8e697b8d..00000000 --- a/tests/target/m33mu-imxrt700.patch +++ /dev/null @@ -1,57 +0,0 @@ -diff --git a/src/m33mu/mem_prot.c b/src/m33mu/mem_prot.c -index ffe7c9a..ee46219 100644 ---- a/src/m33mu/mem_prot.c -+++ b/src/m33mu/mem_prot.c -@@ -453,6 +453,7 @@ mm_bool mm_prot_interceptor(void *opaque, enum mm_access_type type, enum mm_sec_ - mm_bool ignore_addr_sec; - mm_bool privileged = MM_TRUE; - mm_bool mpcbb_hit = MM_FALSE; -+ mm_bool mpcbb_decided = MM_FALSE; - mm_bool mpcbb_secure_alias = MM_FALSE; - mm_u32 needed = 0; - size_t i; -@@ -514,16 +515,14 @@ mm_bool mm_prot_interceptor(void *opaque, enum mm_access_type type, enum mm_sec_ - sau_attr = mm_sau_attr_for_addr(ctx->scs, addr); - mpcbb_hit = mpcbb_attr_for_addr(ctx, addr, &mpc_attr, &mpc_addr_sec, - &mpcbb_secure_alias); -- if (mpcbb_hit) { -- /* For SRAM on STM32H5, MPCBB (IDAU) and SAU both apply. -- * Treat the most restrictive attribution as effective. */ -- if (mpc_attr == MM_SAU_SECURE) { -- attr = MM_SAU_SECURE; -- } else { -- attr = sau_attr; -- } -- } else { -- attr = sau_attr; -+ /* The block controller checks the transaction: a Secure block -+ * refuses a Non-secure one, but an SG fetch from an SAU NSC -+ * region is a Secure transaction, so NSC stays callable. */ -+ attr = sau_attr; -+ if (mpcbb_hit && mpc_attr == MM_SAU_SECURE && -+ sau_attr == MM_SAU_NONSECURE) { -+ attr = MM_SAU_SECURE; -+ mpcbb_decided = MM_TRUE; - } - addr_sec = (attr == MM_SAU_NONSECURE) ? MM_NONSECURE : MM_SECURE; - } -@@ -537,7 +536,8 @@ mm_bool mm_prot_interceptor(void *opaque, enum mm_access_type type, enum mm_sec_ - } - if (sec == MM_NONSECURE) { - if (attr == MM_SAU_SECURE) { -- memfault_reason(ctx, type, sec, addr, "secure-attr", attr, addr_sec, mpcbb_hit); -+ memfault_reason(ctx, type, sec, addr, "secure-attr", attr, addr_sec, -+ mpcbb_decided); - record_securefault(ctx, type, addr); - /* Also raise a non-secure fault so NS firmware can handle it - * (HardFault/MemManage depending on SHCSR settings). */ -@@ -546,7 +546,8 @@ mm_bool mm_prot_interceptor(void *opaque, enum mm_access_type type, enum mm_sec_ - } - if (attr == MM_SAU_NSC) { - if (type != MM_ACCESS_EXEC) { -- memfault_reason(ctx, type, sec, addr, "nsc-data", attr, addr_sec, mpcbb_hit); -+ memfault_reason(ctx, type, sec, addr, "nsc-data", attr, addr_sec, -+ mpcbb_decided); - record_securefault(ctx, type, addr); - record_memfault(ctx, sec, type, addr); - return MM_FALSE; diff --git a/tests/target/run_m33mu_scenario.sh b/tests/target/run_m33mu_scenario.sh index aa6aefcd..7f983019 100755 --- a/tests/target/run_m33mu_scenario.sh +++ b/tests/target/run_m33mu_scenario.sh @@ -94,7 +94,7 @@ export WT_ZEPHYR_DTC_OVERLAY_FILE=boards/wolfboot-stm32h563.overlay export WT_MAX_GUESTS=2 export ZEPHYR_BOARD=nucleo_h563zi/stm32h563xx/ns WOLFBOOT_REF=d85fa9dbdf6c36f47b7e96eba5c9df750ad3c963 -M33MU_REF=5d7f854acd8bcb5b56a6dba391995f9373261b1c +M33MU_REF=f3c03675260264cdec815adebe4b020bb6fe57b8 # --- Build the pinned M33MU emulator. Reuse a caller-supplied or already-built # binary so back-to-back scenarios in one container share the build (and a diff --git a/tests/target/run_rt700_m33mu.sh b/tests/target/run_rt700_m33mu.sh index 4a21cfab..ecf5332c 100755 --- a/tests/target/run_rt700_m33mu.sh +++ b/tests/target/run_rt700_m33mu.sh @@ -34,8 +34,8 @@ # IPC suite's panic tests stay cheap. # # Environment (all optional): -# M33MU prebuilt emulator carrying tests/target/m33mu-imxrt700.patch; -# otherwise M33MU_REF is built under /tmp +# M33MU prebuilt emulator at M33MU_REF or later; otherwise +# M33MU_REF is built under /tmp # RT700_WOLFBOOT_DIR wolfBoot tree holding wolfboot.bin, tools/keytools/sign # and wolfboot_signing_private_key.der, built with # tests/target/wolfboot-imxrt700-lifecycle.patch applied; @@ -83,7 +83,7 @@ wolfboot_dir="${RT700_WOLFBOOT_DIR:-/tmp/wolfboot_rt700}" log="$repo/build/rt700_m33mu_$scenario.log" WOLFBOOT_REF=e6d169c7218d82e33bd04e2c086146ed37ec0cca -M33MU_REF=9733c2bf99995f33e7b1d4aa31e2f17bfa2d13c1 +M33MU_REF=f3c03675260264cdec815adebe4b020bb6fe57b8 # The guests' manifest restart budget (port/mimxrt700/partitions.c): ahbscneg # relaunches guest0 this many times before quarantining it. @@ -103,21 +103,18 @@ GUEST_STARTED_RE='wolfTrust RT700 guest[01]: start' # shellcheck disable=SC2034 GUEST_DONE_RE='wolfTrust RT700 guest[01]: FF-M connect ok, done' -# --- The pinned M33MU with the model fix this chain needs: a Secure AHBSC -# SRAM rule keeps the SAU's NSC veneer band callable. Drop the patch once -# M33MU_REF carries it. --- +# --- The pinned upstream M33MU. --- if [ -n "${M33MU:-}" ] && [ -x "$M33MU" ]; then log "Using prebuilt M33MU: $M33MU" elif [ -x /tmp/m33mu_rt700_src/build/m33mu ]; then M33MU=/tmp/m33mu_rt700_src/build/m33mu log "Reusing M33MU from a prior scenario: $M33MU" else - stage "build M33MU $M33MU_REF with m33mu-imxrt700.patch" + stage "build M33MU $M33MU_REF" rm -rf /tmp/m33mu_rt700_src git clone --no-checkout https://github.com/danielinux/m33mu.git /tmp/m33mu_rt700_src git -C /tmp/m33mu_rt700_src fetch --depth 1 origin "$M33MU_REF" git -C /tmp/m33mu_rt700_src checkout --detach "$M33MU_REF" - git -C /tmp/m33mu_rt700_src apply "$here/m33mu-imxrt700.patch" cmake -S /tmp/m33mu_rt700_src -B /tmp/m33mu_rt700_src/build \ -DM33MU_ENABLE_WOLFSSL=OFF -DM33MU_BUILD_TESTS=OFF \ -DM33MU_ENABLE_RUST_PLUGINS=OFF