Enforce Secure ownership of partition peripherals and interrupts - #56
Conversation
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #56
Scan targets checked: wolftrust-src, wolftrust-bugs
Coverage: 4 of 19 in-scope changed file(s) opened by the reviewer; not opened: include/wolftrust/arch.h, include/wolftrust/arch/armv8m/armv8m.h, include/wolftrust/arch/armv8m/mmio_map.h, include/wolftrust/irq_claim.h, include/wolftrust/periph.h, include/wolftrust/platform.h, port/mimxrt700/platform_mimxrt700.c, port/stm32h563/stm32h563_regs.h, src/arch/armv8m/mpu_armv8m.c, src/irq_claim.c and 5 more
Fenrir result: Approved ✅
No new issues found in the changed files.
Advisory only — this automated result does not count as a GitHub approval.
Review tier: Lite
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
IRQ pending state is not verified, and the RNG negative probe can falsely report isolation.
Review effort: Balanced
Findings: 2
Open (2)
What changed in this PR
Enforces Secure ownership of partition peripherals and IRQs across manifest generation, runtime validation, Armv8-M setup, and STM32H563 testing.
Changes:
- Rejects unassigned partition MMIO and out-of-range Secure IRQs.
- Claims partition IRQs securely during startup and restart.
- Adds host, emulator, and hardware isolation tests.
| File | Description |
|---|---|
tools/manifest/generate.py |
Validates partition MMIO and Secure IRQ bounds. |
tests/target/run_m33mu_scenario.sh |
Adds peripheral-negative verdicts. |
tests/target/run_h5_hardware.sh |
Adds hardware peripheral-negative checks. |
tests/target/lib/scenario.sh |
Maps the SP peripheral probe flag. |
tests/target/lib/scenario_matrix.py |
Registers new H5 scenarios. |
tests/host/periph/Makefile |
Builds peripheral-policy tests. |
tests/host/periph/main.c |
Tests peripheral ownership validation. |
tests/host/manifest/test_generator.py |
Tests generator rejection rules. |
tests/host/Makefile |
Registers new host suites. |
tests/host/irq_claim/Makefile |
Builds IRQ-claim tests. |
tests/host/irq_claim/main.c |
Tests IRQ claiming and bounds. |
tests/firmware/zephyr-stm32h5/scripts/build_guest.sh |
Forwards the peripheral probe option. |
tests/firmware/zephyr-stm32h5/apps/guest0_psa/src/main.c |
Implements NS peripheral/DMA probes. |
tests/firmware/zephyr-stm32h5/apps/guest0_psa/CMakeLists.txt |
Enables probe compilation. |
src/spm_partitions.c |
Adds the partition peripheral fault probe. |
src/services/wolfhsm/runner/ivt.c |
Uses the shared Secure IRQ limit. |
src/periph.c |
Implements partition peripheral validation. |
src/irq_claim.c |
Implements Secure IRQ claiming. |
src/arch/common/spm_gate_core.c |
Enforces MMIO policy and claims IRQs. |
src/arch/armv8m/mpu_armv8m.c |
Exposes Armv8-M MMIO classification. |
src/arch/armv8m/irq_armv8m.c |
Binds IRQ claiming to the NVIC. |
port/stm32h563/stm32h563_regs.h |
Defines the Secure RNG base. |
port/stm32h563/platform_stm32h563.c |
Verifies GTZC attribution and denies SP peripherals. |
port/mimxrt700/platform_mimxrt700.c |
Denies SP peripherals and supports probing. |
mk/common.mk |
Builds and configures the new enforcement code. |
include/wolftrust/platform.h |
Declares peripheral inventory and probe APIs. |
include/wolftrust/periph.h |
Defines peripheral ownership interfaces. |
include/wolftrust/irq_claim.h |
Defines IRQ-controller claim operations. |
include/wolftrust/arch/armv8m/mmio_map.h |
Classifies Armv8-M MMIO ranges. |
include/wolftrust/arch/armv8m/armv8m.h |
Defines the 64-line Secure IRQ limit. |
include/wolftrust/arch.h |
Declares architecture enforcement hooks. |
docs/Testing.md |
Documents the new negative scenarios. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
9cc3cc6 to
17c470d
Compare
17c470d to
055648c
Compare

Uh oh!
There was an error while loading. Please reload this page.