Add manual per state production lock for Cortex-M device ports - #64
aidangarske wants to merge 6 commits into
Conversation
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Rehearsal consumption contradicts the stated safety model, RT700 interpreter handling breaks supported installations, and provisioning instructions regress before validation.
Review effort: Balanced
Findings: 2
Open (4)
What changed in this PR
Adds shared, gated production provisioning for STM32H563 and MIMXRT700, including RT700 lifecycle attestation and guest-flash fencing.
Changes:
- Centralizes rehearsal, confirmation, and permanent-lock workflows.
- Adds RT700 lifecycle/fence implementation and hardware scenarios.
- Expands host, provisioning, emulator, and hardware coverage.
| File | Description |
|---|---|
tests/target/wolfboot-imxrt700-lifecycle.patch |
Adds RT700 lifecycle mapping. |
tests/target/wolfboot-imxrt700-guest-fence.patch |
Adds wolfBoot guest-flash fencing. |
tests/target/run_rt700_suite.sh |
Adds RT700 hardware suite wrapper. |
tests/target/run_rt700_m33mu.sh |
Integrates lifecycle and fence scenarios. |
tests/target/run_rt700_hardware.sh |
Adds silicon fence validation. |
tests/target/provisioning/test_provisioning_gates.sh |
Tests provisioning safety gates. |
tests/target/provisioning/README.md |
Documents provisioning scripts. |
tests/target/provisioning/provisioning_ctrl.sh |
Implements shared provisioning gates. |
tests/target/provisioning/provisioning_ctrl_stm32h563.sh |
Implements STM32H563 provisioning. |
tests/target/provisioning/provisioning_ctrl_mimxrt700.sh |
Implements RT700 provisioning. |
tests/target/provisioning_ctrl.sh |
Removes superseded STM32-only controller. |
tests/target/m33mu-imxrt700.patch |
Seeds emulator lifecycle fuses. |
tests/target/lib/scenario.sh |
Enables WRP for fence scenarios. |
tests/target/lib/scenario_matrix.py |
Registers RT700 fence scenarios. |
tests/target/lib/rt700_wolfboot.sh |
Centralizes pinned wolfBoot builds. |
tests/target/lib/rt700_fence.sh |
Derives fence bounds from layout. |
tests/host/rt700_lifecycle/Makefile |
Builds lifecycle host tests. |
tests/host/rt700_lifecycle/main.c |
Tests lifecycle and debug mapping. |
tests/host/Makefile |
Registers lifecycle tests. |
tests/host/guest_verify/main.c |
Tests FRAD coverage behavior. |
src/guest_verify.c |
Implements FRAD coverage validation. |
README.md |
Links provisioning and RT700 guides. |
port/mimxrt700/platform_mimxrt700.c |
Verifies live XSPI descriptors. |
port/mimxrt700/mimxrt798_regs.h |
Defines XSPI FRAD registers. |
Makefile |
Adds provisioning and RT700 hardware targets. |
include/wolftrust/guest_verify.h |
Exposes FRAD validation API. |
docs/Threat-Model.md |
Documents RT700 flash protection. |
docs/Testing.md |
Documents new tests and scenarios. |
docs/STM32H5-Guide.md |
Expands STM32 provisioning instructions. |
docs/Security-Model.md |
Generalizes flash-protection policy. |
docs/Provisioning.md |
Adds shared provisioning guide. |
docs/MIMXRT700-Guide.md |
Documents RT700 fencing and lifecycle. |
docs/Macros.md |
Updates WRP macro guidance. |
docs/Home.md |
Adds documentation links. |
docs/Architecture.md |
Describes cross-port flash protection. |
docs/_Sidebar.md |
Adds provisioning navigation. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #64
Scan targets checked: wolftrust-src, wolftrust-bugs
Coverage: 2 of 6 in-scope changed file(s) opened by the reviewer; not opened: include/wolftrust/guest_verify.h, port/mimxrt700/mimxrt798_regs.h, port/mimxrt700/platform_mimxrt700.c, tests/host/guest_verify/main.c
Fenrir result: Approved ✅
No new issues found in the changed files.
Advisory only — this automated result does not count as a GitHub approval.
Review tier: Lite


WT_LOCK_CONFIRM=1, WT_PRODUCTION_LOCK=1, a terminal, and a typed "I ACCEPT <code>".