Skip to content

Harden the SPM against stack overflow and faults - #58

Merged
mattia-moffa merged 9 commits into
wolfSSL:mainfrom
aidangarske:ffm-l3-spm-hardening
Oct 2, 2026
Merged

mattia-moffa merged 9 commits into
wolfSSL:mainfrom
aidangarske:ffm-l3-spm-hardening

Conversation

@aidangarske

Copy link
Copy Markdown
Member

Part of #46. Closes #39 except boot zeroing, which follows next to #37.

  • Set MSPLIM_S for the Secure main stack (16 KiB, link-asserted), so an SPM stack overflow faults and halts instead of running
    into .bss.
  • Replace the silent HardFault spin with a handler that latches the fault status and halts.
  • Enable BusFault and pin it to the Secure side (AIRCR.BFHFNMINS cleared and read back). A partition BusFault restarts only that
    partition; a Non-secure guest BusFault restarts that guest; an SPM BusFault halts.
  • Add one privileged-only execute-never MPU region so the SPM's RAM can't be executed while a partition's MPU domain is loaded.
  • A partition's svc #0x7F now panics only that partition instead of halting the platform.
  • New H5 silicon negatives: busfaultneg (partition BusFault) and nsbusfaultneg (Non-secure guest BusFault). M33MU never delivers data BusFault, so these two run only on silicon until it does.
  • Security-Model.md and Testing.md document the policy
  • tested on STM32H563 silicon on both engines:
  • busfaultneg: a precise BusFault (CFSR 0x8200, BFAR 0x300A0000); only the partition restarts, the lifecycle completes and guest1 survives.
  • nsbusfaultneg: BFAR 0x4C000000; guest0 is restarted 3 times then quarantined, guest1 survives, and nothing escalates to HardFault.

@aidangarske aidangarske self-assigned this Oct 1, 2026
@aidangarske
aidangarske requested review from wolfSSL-Fenrir-bot and a balanced review from Copilot October 1, 2026 19:37
@aidangarske aidangarske added the ci:all Run every M33MU scenario of every port on the PR (core change) label Oct 1, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The XN range and frameless BusFault handling leave security gaps, and the M33MU BusFault acceptance criterion remains unmet.

Review effort: Balanced
Findings: 2 High severity · 1 Medium severity · 1 Low severity

Open (4)
What changed in this PR

Hardens Armv8-M SPM stack, fault containment, BusFault routing, and Secure RAM execution policy.

Changes:

  • Adds MSPLIM stack protection and fault-status latching.
  • Contains partition and guest faults with new negative scenarios.
  • Adds MPU XN coverage, build validation, and security documentation.
File Description
tools/​check_stack_seal.py Validates reserved main-stack range.
tests/​target/​run_m33mu_scenario.sh Adds emulator fault assertions.
tests/​target/​run_h5_hardware.sh Adds silicon negative scenarios.
tests/​target/​lib/​scenario.sh Defines scenario flags and verdicts.
tests/​target/​lib/​scenario_matrix.py Registers new M33MU scenarios.
tests/​host/​manifest/​test_probe_stamp.sh Tests probe build stamps.
tests/​firmware/​zephyr-stm32h5/​scripts/​build_guest.sh Passes guest BusFault flag.
tests/​firmware/​zephyr-stm32h5/​apps/​guest0_psa/​src/​main.c Adds Non-secure BusFault probe.
tests/​firmware/​zephyr-stm32h5/​apps/​guest0_psa/​CMakeLists.txt Enables probe compilation.
src/​spm_partitions.c Adds partition fault probes.
src/​services/​wolfhsm/​runner/​secure.ld Reserves the SPM stack.
src/​arch/​common/​spm_gate_core.c Adds restart markers and probe region.
src/​arch/​armv8m/​start_armv8m.c Initializes and verifies MSPLIM.
src/​arch/​armv8m/​spm_svc.c Contains invalid partition SVCs.
src/​arch/​armv8m/​sp_fault_armv8m.c Implements fault attribution and latching.
src/​arch/​armv8m/​mpu_armv8m.c Adds privileged SPM RAM XN cover.
src/​arch/​armv8m/​guest_context_armv8m.c Routes and handles guest BusFaults.
src/​arch/​armv8m/​coroutine_armv8m.c Redirects invalid scheduler SVCs.
port/​stm32h563/​platform_stm32h563.c Adds BusFault probe and reset handling.
port/​mimxrt700/​secure.ld Reserves the SPM stack.
port/​mimxrt700/​platform_mimxrt700.c Clears stack limits before reset.
mk/​common.mk Adds stack and probe build settings.
mk/​arch-armv8m.mk Adds architecture flags and checks.
include/​wolftrust/​platform.h Declares BusFault probe API.
include/​wolftrust/​arch/​armv8m/​core_regs.h Adds fault register definitions.
include/​wolftrust/​arch.h Declares SVC probe API.
docs/​Testing.md Documents negative scenarios.
docs/​Security-Model.md Documents stack, fault, and XN policy.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/arch/armv8m/guest_context_armv8m.c
Comment thread src/arch/armv8m/mpu_armv8m.c Outdated
Comment thread tests/target/lib/scenario_matrix.py
Comment thread docs/Security-Model.md Outdated

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #58

Scan targets checked: wolftrust-src, wolftrust-bugs
Coverage: 8 of 15 in-scope changed file(s) opened by the reviewer; not opened: include/wolftrust/arch.h, include/wolftrust/arch/armv8m/core_regs.h, include/wolftrust/platform.h, port/mimxrt700/platform_mimxrt700.c, port/stm32h563/platform_stm32h563.c, src/arch/common/spm_gate_core.c, tests/firmware/zephyr-stm32h5/apps/guest0_psa/src/main.c

Findings: 1
1 finding(s) posted as inline comments (see file-level comments below)

This review was generated automatically by Fenrir. Reported findings require changes before merge.

Review tier: Lite

Comment thread src/arch/armv8m/guest_context_armv8m.c

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #58

Scan targets checked: wolftrust-src, wolftrust-bugs
Coverage: 3 of 3 in-scope changed file(s) opened by the reviewer

Fenrir result: Approved ✅

No new issues found in the changed files.

Advisory only — this automated result does not count as a GitHub approval.

Review tier: Lite

@wolfSSL-Fenrir-bot
wolfSSL-Fenrir-bot dismissed their stale review October 1, 2026 20:11

Fenrir's latest completed scan found no issues; clearing the prior automated change request.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Critical invalid-frame BusFault handling and additional stack and guest recovery validation issues remain unresolved.

Review effort: Lite
Findings: 1 High severity

Open (1)
Resolved since last review (4)

Comment thread src/arch/armv8m/sp_fault_armv8m.c
Comment thread src/arch/armv8m/sp_fault_armv8m.c Outdated
Comment thread src/arch/armv8m/sp_fault_armv8m.c
Comment thread src/arch/armv8m/guest_context_armv8m.c Outdated
@mattia-moffa
mattia-moffa merged commit 04895c9 into wolfSSL:main Oct 2, 2026
190 checks passed
@aidangarske
aidangarske deleted the ffm-l3-spm-hardening branch October 2, 2026 16:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci:all Run every M33MU scenario of every port on the PR (core change)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Harden the SPM against stack overflow and faults at level 3

4 participants