Skip to content

Add manual per state production lock for Cortex-M device ports - #64

Open
aidangarske wants to merge 6 commits into
wolfSSL:mainfrom
aidangarske:rt700-lifecycle-lock
Open

aidangarske wants to merge 6 commits into
wolfSSL:mainfrom
aidangarske:rt700-lifecycle-lock

Conversation

@aidangarske

Copy link
Copy Markdown
Member
  • This pr adds support for provisioning specifically for the H5 and imxrt700 and it centralize the commands so that ports are easier to add fro now on.
  • Every port gets the same commands: status, discover, restore, advance , regress, lock . States can be given by name or code.
  • advance and regress are a reversible rehearsal. They record a run bound to the part, the images (address and length framed), the credentials, and the boot evidence from that run.
  • lock writes one state at a time. It needs a fresh rehearsal of the same part, the port's provisioning checks, a preview, WT_LOCK_CONFIRM=1, WT_PRODUCTION_LOCK=1, a terminal, and a typed "I ACCEPT <code>".
  • lock checks everything again after the acceptance, reads the new state back, and consumes the rehearsal so it cannot be used twice.
  • STM32H563 closed states are written from Provisioning. They need safe option bytes, guest WRP, production DA installed through provision-da after the rehearsal, and a boot on the UART after the write.
  • MIMXRT700 gains a wolfBoot XSPI guest fence that wolfTrust verifies before launch, a real OTP life cycle read with DAUTHSTATUS refinement, and a shadow-only rehearsal. Only the Develop2 fuse burn is allowed; In Field and later stay refused until ROM-authenticated wolfBoot.
  • The M33MU patch is now only the Develop life cycle fuse seed on the new upstream pin.
  • Docs: new docs/Provisioning.md covers the shared flow and gates, and both port guides add per state steps with real board output.
  • Testing: make test-provisioning 104/104, tests/host 58/58 suites (rt700_lifecycle 290 checks), M33MU positive/wrpfence/wrpoff, EVK wrpfence plus a Develop2 rehearsal, H5 verify plus a Closed rehearsal. No lock write ran on hardware.

@aidangarske aidangarske self-assigned this Oct 2, 2026
Copilot AI balanced review requested due to automatic review settings October 2, 2026 18:40

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Rehearsal consumption contradicts the stated safety model, RT700 interpreter handling breaks supported installations, and provisioning instructions regress before validation.

Review effort: Balanced
Findings: 2 Medium severity · 2 Low severity

Open (4)
What changed in this PR

Adds shared, gated production provisioning for STM32H563 and MIMXRT700, including RT700 lifecycle attestation and guest-flash fencing.

Changes:

  • Centralizes rehearsal, confirmation, and permanent-lock workflows.
  • Adds RT700 lifecycle/fence implementation and hardware scenarios.
  • Expands host, provisioning, emulator, and hardware coverage.
File Description
tests/​target/​wolfboot-imxrt700-lifecycle.patch Adds RT700 lifecycle mapping.
tests/​target/​wolfboot-imxrt700-guest-fence.patch Adds wolfBoot guest-flash fencing.
tests/​target/​run_rt700_suite.sh Adds RT700 hardware suite wrapper.
tests/​target/​run_rt700_m33mu.sh Integrates lifecycle and fence scenarios.
tests/​target/​run_rt700_hardware.sh Adds silicon fence validation.
tests/​target/​provisioning/​test_provisioning_gates.sh Tests provisioning safety gates.
tests/​target/​provisioning/​README.md Documents provisioning scripts.
tests/​target/​provisioning/​provisioning_ctrl.sh Implements shared provisioning gates.
tests/​target/​provisioning/​provisioning_ctrl_stm32h563.sh Implements STM32H563 provisioning.
tests/​target/​provisioning/​provisioning_ctrl_mimxrt700.sh Implements RT700 provisioning.
tests/​target/​provisioning_ctrl.sh Removes superseded STM32-only controller.
tests/​target/​m33mu-imxrt700.patch Seeds emulator lifecycle fuses.
tests/​target/​lib/​scenario.sh Enables WRP for fence scenarios.
tests/​target/​lib/​scenario_matrix.py Registers RT700 fence scenarios.
tests/​target/​lib/​rt700_wolfboot.sh Centralizes pinned wolfBoot builds.
tests/​target/​lib/​rt700_fence.sh Derives fence bounds from layout.
tests/​host/​rt700_lifecycle/​Makefile Builds lifecycle host tests.
tests/​host/​rt700_lifecycle/​main.c Tests lifecycle and debug mapping.
tests/​host/​Makefile Registers lifecycle tests.
tests/​host/​guest_verify/​main.c Tests FRAD coverage behavior.
src/​guest_verify.c Implements FRAD coverage validation.
README.md Links provisioning and RT700 guides.
port/​mimxrt700/​platform_mimxrt700.c Verifies live XSPI descriptors.
port/​mimxrt700/​mimxrt798_regs.h Defines XSPI FRAD registers.
Makefile Adds provisioning and RT700 hardware targets.
include/​wolftrust/​guest_verify.h Exposes FRAD validation API.
docs/​Threat-Model.md Documents RT700 flash protection.
docs/​Testing.md Documents new tests and scenarios.
docs/​STM32H5-Guide.md Expands STM32 provisioning instructions.
docs/​Security-Model.md Generalizes flash-protection policy.
docs/​Provisioning.md Adds shared provisioning guide.
docs/​MIMXRT700-Guide.md Documents RT700 fencing and lifecycle.
docs/​Macros.md Updates WRP macro guidance.
docs/​Home.md Adds documentation links.
docs/​Architecture.md Describes cross-port flash protection.
docs/​_Sidebar.md Adds provisioning navigation.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread tests/target/provisioning/provisioning_ctrl.sh
Comment thread tests/target/provisioning/provisioning_ctrl_mimxrt700.sh
Comment thread docs/MIMXRT700-Guide.md Outdated
Comment thread docs/Provisioning.md Outdated
@aidangarske aidangarske added the ci:all Run every M33MU scenario of every port on the PR (core change) label Oct 2, 2026

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #64

Scan targets checked: wolftrust-src, wolftrust-bugs
Coverage: 2 of 6 in-scope changed file(s) opened by the reviewer; not opened: include/wolftrust/guest_verify.h, port/mimxrt700/mimxrt798_regs.h, port/mimxrt700/platform_mimxrt700.c, tests/host/guest_verify/main.c

Fenrir result: Approved ✅

No new issues found in the changed files.

Advisory only — this automated result does not count as a GitHub approval.

Review tier: Lite

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci:all Run every M33MU scenario of every port on the PR (core change)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants