Harden the SPM against stack overflow and faults - #58
Conversation
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The XN range and frameless BusFault handling leave security gaps, and the M33MU BusFault acceptance criterion remains unmet.
Review effort: Balanced
Findings: 2
Open (4)
What changed in this PR
Hardens Armv8-M SPM stack, fault containment, BusFault routing, and Secure RAM execution policy.
Changes:
- Adds MSPLIM stack protection and fault-status latching.
- Contains partition and guest faults with new negative scenarios.
- Adds MPU XN coverage, build validation, and security documentation.
| File | Description |
|---|---|
tools/check_stack_seal.py |
Validates reserved main-stack range. |
tests/target/run_m33mu_scenario.sh |
Adds emulator fault assertions. |
tests/target/run_h5_hardware.sh |
Adds silicon negative scenarios. |
tests/target/lib/scenario.sh |
Defines scenario flags and verdicts. |
tests/target/lib/scenario_matrix.py |
Registers new M33MU scenarios. |
tests/host/manifest/test_probe_stamp.sh |
Tests probe build stamps. |
tests/firmware/zephyr-stm32h5/scripts/build_guest.sh |
Passes guest BusFault flag. |
tests/firmware/zephyr-stm32h5/apps/guest0_psa/src/main.c |
Adds Non-secure BusFault probe. |
tests/firmware/zephyr-stm32h5/apps/guest0_psa/CMakeLists.txt |
Enables probe compilation. |
src/spm_partitions.c |
Adds partition fault probes. |
src/services/wolfhsm/runner/secure.ld |
Reserves the SPM stack. |
src/arch/common/spm_gate_core.c |
Adds restart markers and probe region. |
src/arch/armv8m/start_armv8m.c |
Initializes and verifies MSPLIM. |
src/arch/armv8m/spm_svc.c |
Contains invalid partition SVCs. |
src/arch/armv8m/sp_fault_armv8m.c |
Implements fault attribution and latching. |
src/arch/armv8m/mpu_armv8m.c |
Adds privileged SPM RAM XN cover. |
src/arch/armv8m/guest_context_armv8m.c |
Routes and handles guest BusFaults. |
src/arch/armv8m/coroutine_armv8m.c |
Redirects invalid scheduler SVCs. |
port/stm32h563/platform_stm32h563.c |
Adds BusFault probe and reset handling. |
port/mimxrt700/secure.ld |
Reserves the SPM stack. |
port/mimxrt700/platform_mimxrt700.c |
Clears stack limits before reset. |
mk/common.mk |
Adds stack and probe build settings. |
mk/arch-armv8m.mk |
Adds architecture flags and checks. |
include/wolftrust/platform.h |
Declares BusFault probe API. |
include/wolftrust/arch/armv8m/core_regs.h |
Adds fault register definitions. |
include/wolftrust/arch.h |
Declares SVC probe API. |
docs/Testing.md |
Documents negative scenarios. |
docs/Security-Model.md |
Documents stack, fault, and XN policy. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #58
Scan targets checked: wolftrust-src, wolftrust-bugs
Coverage: 8 of 15 in-scope changed file(s) opened by the reviewer; not opened: include/wolftrust/arch.h, include/wolftrust/arch/armv8m/core_regs.h, include/wolftrust/platform.h, port/mimxrt700/platform_mimxrt700.c, port/stm32h563/platform_stm32h563.c, src/arch/common/spm_gate_core.c, tests/firmware/zephyr-stm32h5/apps/guest0_psa/src/main.c
Findings: 1
1 finding(s) posted as inline comments (see file-level comments below)
This review was generated automatically by Fenrir. Reported findings require changes before merge.
Review tier: Lite
b5be321 to
c654182
Compare
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #58
Scan targets checked: wolftrust-src, wolftrust-bugs
Coverage: 3 of 3 in-scope changed file(s) opened by the reviewer
Fenrir result: Approved ✅
No new issues found in the changed files.
Advisory only — this automated result does not count as a GitHub approval.
Review tier: Lite
Fenrir's latest completed scan found no issues; clearing the prior automated change request.
c654182 to
ed7983a
Compare



Part of #46. Closes #39 except boot zeroing, which follows next to #37.
into .bss.
partition; a Non-secure guest BusFault restarts that guest; an SPM BusFault halts.