Skip to content

Enforce Secure ownership of partition peripherals and interrupts - #56

Merged
mattia-moffa merged 5 commits into
wolfSSL:mainfrom
aidangarske:ffm-l3-periph-own
Oct 1, 2026
Merged

mattia-moffa merged 5 commits into
wolfSSL:mainfrom
aidangarske:ffm-l3-periph-own

Conversation

@aidangarske

@aidangarske aidangarske commented Oct 1, 2026 •

Copy link
Copy Markdown
Member
  • Partition manifests could map any address as a DEVICE resource, including SPM hardware, and the Secure IRQ enable/disable paths accepted lines past the 64-entry Secure vector table.
  • Partition MMIO now maps only if it is DEVICE, exactly matches a port-assigned non-bus-master peripheral and reads back Secure; neither port assigns one yet, so all partition MMIO is refused.
  • The manifest generator refuses the same cases at build time, plus partition IRQs at or above 64; IRQ claim, enable and disable are all bounded to the 64 lines.
  • Partition IRQs are disabled, cleared, routed Secure and read back at bring-up and on every restart; STM32H563 boot also verifies its TZSC and MPCBB settings.
  • New M33MU negatives: periphneg (NS RNG poke and NS DMA out of Secure memory both blocked) and periphspneg (a partition read of an SPM peripheral faults).
  • Fixes Add peripheral, MMIO and DMA ownership and put interrupts in a Secure disabled state at boot #38; named mmio_regions stays a follow-up until a port assigns a partition peripheral, and the MIMXRT700 peripheral list is under Carry the isolation level 3 changes to the MIMXRT700 port #40.

@aidangarske aidangarske self-assigned this Oct 1, 2026
@aidangarske
aidangarske requested review from wolfSSL-Fenrir-bot and a balanced review from Copilot October 1, 2026 17:27
@aidangarske aidangarske added the ci:all Run every M33MU scenario of every port on the PR (core change) label Oct 1, 2026

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #56

Scan targets checked: wolftrust-src, wolftrust-bugs
Coverage: 4 of 19 in-scope changed file(s) opened by the reviewer; not opened: include/wolftrust/arch.h, include/wolftrust/arch/armv8m/armv8m.h, include/wolftrust/arch/armv8m/mmio_map.h, include/wolftrust/irq_claim.h, include/wolftrust/periph.h, include/wolftrust/platform.h, port/mimxrt700/platform_mimxrt700.c, port/stm32h563/stm32h563_regs.h, src/arch/armv8m/mpu_armv8m.c, src/irq_claim.c and 5 more

Fenrir result: Approved ✅

No new issues found in the changed files.

Advisory only — this automated result does not count as a GitHub approval.

Review tier: Lite

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

IRQ pending state is not verified, and the RNG negative probe can falsely report isolation.

Review effort: Balanced
Findings: 2 Medium severity

Open (2)
What changed in this PR

Enforces Secure ownership of partition peripherals and IRQs across manifest generation, runtime validation, Armv8-M setup, and STM32H563 testing.

Changes:

  • Rejects unassigned partition MMIO and out-of-range Secure IRQs.
  • Claims partition IRQs securely during startup and restart.
  • Adds host, emulator, and hardware isolation tests.
File Description
tools/​manifest/​generate.py Validates partition MMIO and Secure IRQ bounds.
tests/​target/​run_m33mu_scenario.sh Adds peripheral-negative verdicts.
tests/​target/​run_h5_hardware.sh Adds hardware peripheral-negative checks.
tests/​target/​lib/​scenario.sh Maps the SP peripheral probe flag.
tests/​target/​lib/​scenario_matrix.py Registers new H5 scenarios.
tests/​host/​periph/​Makefile Builds peripheral-policy tests.
tests/​host/​periph/​main.c Tests peripheral ownership validation.
tests/​host/​manifest/​test_generator.py Tests generator rejection rules.
tests/​host/​Makefile Registers new host suites.
tests/​host/​irq_claim/​Makefile Builds IRQ-claim tests.
tests/​host/​irq_claim/​main.c Tests IRQ claiming and bounds.
tests/​firmware/​zephyr-stm32h5/​scripts/​build_guest.sh Forwards the peripheral probe option.
tests/​firmware/​zephyr-stm32h5/​apps/​guest0_psa/​src/​main.c Implements NS peripheral/DMA probes.
tests/​firmware/​zephyr-stm32h5/​apps/​guest0_psa/​CMakeLists.txt Enables probe compilation.
src/​spm_partitions.c Adds the partition peripheral fault probe.
src/​services/​wolfhsm/​runner/​ivt.c Uses the shared Secure IRQ limit.
src/​periph.c Implements partition peripheral validation.
src/​irq_claim.c Implements Secure IRQ claiming.
src/​arch/​common/​spm_gate_core.c Enforces MMIO policy and claims IRQs.
src/​arch/​armv8m/​mpu_armv8m.c Exposes Armv8-M MMIO classification.
src/​arch/​armv8m/​irq_armv8m.c Binds IRQ claiming to the NVIC.
port/​stm32h563/​stm32h563_regs.h Defines the Secure RNG base.
port/​stm32h563/​platform_stm32h563.c Verifies GTZC attribution and denies SP peripherals.
port/​mimxrt700/​platform_mimxrt700.c Denies SP peripherals and supports probing.
mk/​common.mk Builds and configures the new enforcement code.
include/​wolftrust/​platform.h Declares peripheral inventory and probe APIs.
include/​wolftrust/​periph.h Defines peripheral ownership interfaces.
include/​wolftrust/​irq_claim.h Defines IRQ-controller claim operations.
include/​wolftrust/​arch/​armv8m/​mmio_map.h Classifies Armv8-M MMIO ranges.
include/​wolftrust/​arch/​armv8m/​armv8m.h Defines the 64-line Secure IRQ limit.
include/​wolftrust/​arch.h Declares architecture enforcement hooks.
docs/​Testing.md Documents the new negative scenarios.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/irq_claim.c
Comment thread tests/firmware/zephyr-stm32h5/apps/guest0_psa/src/main.c Outdated
@mattia-moffa
mattia-moffa merged commit ac88f14 into wolfSSL:main Oct 1, 2026
184 checks passed
@aidangarske
aidangarske deleted the ffm-l3-periph-own branch October 1, 2026 18:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci:all Run every M33MU scenario of every port on the PR (core change)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add peripheral, MMIO and DMA ownership and put interrupts in a Secure disabled state at boot

4 participants