Skip to content

Share isolation level 3 across Armv8-M ports and bring MIMXRT700 to parity - #72

Open
aidangarske wants to merge 8 commits into
wolfSSL:mainfrom
aidangarske:l3-armv8m-shared
Open

aidangarske wants to merge 8 commits into
wolfSSL:mainfrom
aidangarske:l3-armv8m-shared

Conversation

@aidangarske

@aidangarske aidangarske commented Oct 3, 2026 •

Copy link
Copy Markdown
Member

This PR allows for a more portable solution for Cortex-M L3

Closes #65. Part of #40: MIMXRT700 level 3 is proven under M33MU here, and #40 stays open until the EVK items below pass.

  • STM32H563 and MIMXRT700 each carried their own copy of the isolation level 3 layout, linker bands, ASSERTs and nine platform hooks. A third copy of the band addresses sat in the RT700 make fragment, and the target runners hardcoded H5 band addresses.
  • port/common/armv8m now holds that code once: l3_layout.h, four linker fragments the port scripts INCLUDE, and platform_l3.c. A port supplies WT_RAM_S_BASE, l3_port.h naming its SPM-only peripheral, and its board linker sections.
  • WT_ISOLATION_LEVEL (default 3) gates the shared layer. Only level 3 is implemented, so any other value stops the build, and a cross-compile CI step proves it on both ports.
  • The build and tools/l3_layout_args.py read the band layout from memory_map.h, and an unreadable layout stops the link. A cross-compile CI step proves that.
  • scenario_matrix.py --selftest fails when a port's full tier skips an L3_REQUIRED scenario without a stated reason.
  • The level 3 target checks now live once in tests/target/lib/scenario.sh and match band, stack and peripheral addresses derived from each port's layout.
  • MIMXRT700 now runs every L3_REQUIRED scenario, with no exemptions: bandneg1-6, restartneg1-3, deputyneg, hsmpinneg, hsmfaultneg, manifestneg2/3, periphspneg, sealneg, sealhaltneg, sealpivotneg, mspovfneg, xnneg, svcneg.
  • MIMXRT700 gains a deputy flash probe. Its writable flash context holds no geometry, so the probe forges offsets and lengths, and each one is refused against the const configuration.
  • MIMXRT700 periphneg covers the CPU leg: an NS read of the SPM's TRNG is refused by the SAU. The M33MU RT700 model has no DMA, so the eDMA leg is left to the EVK.
  • The H5 positive lifecycle checks match guest0's markers across interleaved guest1 console output, so a split line no longer fails bandneg1.
  • No behavior change for existing images: in 28 secure builds every RAM symbol and section matches main.
  • Testing: make test 897 pass, 0 fail. MIMXRT700 M33MU 42/42 (all L3 scenarios plus periphneg, both engines). STM32H563 M33MU level 3 set 49/49 on the shared checks.

TODO before merge (rest of #40)

@aidangarske aidangarske self-assigned this Oct 3, 2026
Copilot AI balanced review requested due to automatic review settings October 3, 2026 02:16
@aidangarske aidangarske added the ci:all Run every M33MU scenario of every port on the PR (core change) label Oct 3, 2026

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #72

Scan targets checked: wolftrust-src, wolftrust-bugs
Coverage: 6 of 16 in-scope changed file(s) opened by the reviewer; not opened: port/common/armv8m/l3_layout.h, port/common/armv8m/secure_l3_bands.ld, port/common/armv8m/secure_l3_memory.ld, port/common/armv8m/secure_l3_symbols.ld, port/common/armv8m/secure_l3_tail.ld, port/mimxrt700/l3_port.h, port/mimxrt700/platform_mimxrt700.c, port/stm32h563/l3_port.h, port/stm32h563/platform_stm32h563.c, port/stm32h563/secure.ld

Fenrir result: Approved ✅

No new issues found in the changed files.

Advisory only — this automated result does not count as a GitHub approval.

Review tier: Lite

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The security-critical linker and isolation refactor spans both Armv8-M ports and requires final human validation.

Review effort: Balanced
Findings: None

What changed in this PR

Centralizes Armv8-M isolation-level-3 infrastructure and brings MIMXRT700 scenario coverage to STM32H563 parity.

Changes:

  • Shares L3 memory layouts, linker fragments, and platform hooks.
  • Derives layout checks from port headers.
  • Expands MIMXRT700 isolation probes and CI scenarios.
File Description
.github/​workflows/​cross-compile.yml Tests fail-closed layout extraction.
docs/​MIMXRT700-Guide.md Documents shared L3 integration.
docs/​Porting.md Adds shared-port guidance.
docs/​Testing.md Documents RT700 L3 scenarios.
mk/​arch-armv8m.mk Integrates shared L3 build inputs.
mk/​common.mk Compiles shared port sources.
mk/​target-mimxrt700.mk Derives layout-check arguments.
mk/​target-stm32h563.mk Selects the port linker script.
port/​common/​armv8m/​l3_layout.h Defines shared L3 layout.
port/​common/​armv8m/​platform_l3.c Implements shared platform hooks.
port/​common/​armv8m/​secure_l3_bands.ld Defines partition data sections.
port/​common/​armv8m/​secure_l3_memory.ld Defines shared memory regions.
port/​common/​armv8m/​secure_l3_symbols.ld Defines shared stack symbols.
port/​common/​armv8m/​secure_l3_tail.ld Enforces layout invariants.
port/​mimxrt700/​hsm_flash.c Adds deputy flash probes.
port/​mimxrt700/​l3_port.h Supplies the RT700 peripheral input.
port/​mimxrt700/​memory_map.h Adopts the shared layout.
port/​mimxrt700/​platform_mimxrt700.c Removes duplicated L3 hooks.
port/​mimxrt700/​secure.ld Includes shared linker fragments.
port/​stm32h563/​l3_port.h Supplies the H563 peripheral input.
port/​stm32h563/​memory_map.h Adopts the shared layout.
port/​stm32h563/​platform_stm32h563.c Removes duplicated L3 hooks.
port/​stm32h563/​secure.ld Adds the port-owned linker script.
src/​services/​wolfhsm/​runner/​secure.ld Removes the former shared script.
tests/​firmware/​mimxrt700-baremetal/​guest0.c Adds the TRNG isolation probe.
tests/​firmware/​mimxrt700-baremetal/​Makefile Configures the peripheral probe.
tests/​firmware/​psa-guest/​Makefile Selects the breakpoint guest.
tests/​target/​lib/​scenario.sh Centralizes L3 assertions.
tests/​target/​lib/​scenario_matrix.py Enforces required L3 coverage.
tests/​target/​run_m33mu_scenario.sh Uses shared H563 assertions.
tests/​target/​run_rt700_m33mu.sh Runs expanded RT700 scenarios.
tools/​check-port-only-diff.sh Allows architecture-shared port files.
tools/​l3_layout_args.py Extracts layout constants.
tools/​secure_owners.txt Assigns the shared object owner.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci:all Run every M33MU scenario of every port on the PR (core change)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Share the isolation level 3 layer across Cortex-M ports instead of per board

5 participants