mirror of
https://github.com/FreeRTOS/FreeRTOS-Kernel.git
synced 2026-10-10 08:02:57 -04:00
fix(armv8m): Reject undersized secure stack in AllocateContext (#1474)
Gate against undersized stack values which do not account for fixed values. Thanks @aggarg for the help developing this!
This commit is contained in:
parent
5f109e6f55
commit
ce36e04208
15 changed files with 75 additions and 15 deletions
|
|
@ -214,8 +214,12 @@ secureportNON_SECURE_CALLABLE void SecureContext_Init( void )
|
||||||
if( ulSecureContextIndex < secureconfigMAX_SECURE_CONTEXTS )
|
if( ulSecureContextIndex < secureconfigMAX_SECURE_CONTEXTS )
|
||||||
{
|
{
|
||||||
/* Allocate the stack space if possible. */
|
/* Allocate the stack space if possible. */
|
||||||
if( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) )
|
if( ( ulSecureStackSize < securecontextSTACK_SEAL_SIZE ) ||
|
||||||
|
( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) ) )
|
||||||
{
|
{
|
||||||
|
/* Reject stacks that are too small (the CONTROL word would be
|
||||||
|
* written before the allocation, corrupting the secure heap)
|
||||||
|
* and sizes that would overflow when the seal size is added. */
|
||||||
pucStackMemory = NULL;
|
pucStackMemory = NULL;
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
|
|
|
||||||
|
|
@ -214,8 +214,12 @@ secureportNON_SECURE_CALLABLE void SecureContext_Init( void )
|
||||||
if( ulSecureContextIndex < secureconfigMAX_SECURE_CONTEXTS )
|
if( ulSecureContextIndex < secureconfigMAX_SECURE_CONTEXTS )
|
||||||
{
|
{
|
||||||
/* Allocate the stack space if possible. */
|
/* Allocate the stack space if possible. */
|
||||||
if( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) )
|
if( ( ulSecureStackSize < securecontextSTACK_SEAL_SIZE ) ||
|
||||||
|
( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) ) )
|
||||||
{
|
{
|
||||||
|
/* Reject stacks that are too small (the CONTROL word would be
|
||||||
|
* written before the allocation, corrupting the secure heap)
|
||||||
|
* and sizes that would overflow when the seal size is added. */
|
||||||
pucStackMemory = NULL;
|
pucStackMemory = NULL;
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
|
|
|
||||||
|
|
@ -214,8 +214,12 @@ secureportNON_SECURE_CALLABLE void SecureContext_Init( void )
|
||||||
if( ulSecureContextIndex < secureconfigMAX_SECURE_CONTEXTS )
|
if( ulSecureContextIndex < secureconfigMAX_SECURE_CONTEXTS )
|
||||||
{
|
{
|
||||||
/* Allocate the stack space if possible. */
|
/* Allocate the stack space if possible. */
|
||||||
if( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) )
|
if( ( ulSecureStackSize < securecontextSTACK_SEAL_SIZE ) ||
|
||||||
|
( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) ) )
|
||||||
{
|
{
|
||||||
|
/* Reject stacks that are too small (the CONTROL word would be
|
||||||
|
* written before the allocation, corrupting the secure heap)
|
||||||
|
* and sizes that would overflow when the seal size is added. */
|
||||||
pucStackMemory = NULL;
|
pucStackMemory = NULL;
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
|
|
|
||||||
|
|
@ -214,8 +214,12 @@ secureportNON_SECURE_CALLABLE void SecureContext_Init( void )
|
||||||
if( ulSecureContextIndex < secureconfigMAX_SECURE_CONTEXTS )
|
if( ulSecureContextIndex < secureconfigMAX_SECURE_CONTEXTS )
|
||||||
{
|
{
|
||||||
/* Allocate the stack space if possible. */
|
/* Allocate the stack space if possible. */
|
||||||
if( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) )
|
if( ( ulSecureStackSize < securecontextSTACK_SEAL_SIZE ) ||
|
||||||
|
( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) ) )
|
||||||
{
|
{
|
||||||
|
/* Reject stacks that are too small (the CONTROL word would be
|
||||||
|
* written before the allocation, corrupting the secure heap)
|
||||||
|
* and sizes that would overflow when the seal size is added. */
|
||||||
pucStackMemory = NULL;
|
pucStackMemory = NULL;
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
|
|
|
||||||
|
|
@ -214,8 +214,12 @@ secureportNON_SECURE_CALLABLE void SecureContext_Init( void )
|
||||||
if( ulSecureContextIndex < secureconfigMAX_SECURE_CONTEXTS )
|
if( ulSecureContextIndex < secureconfigMAX_SECURE_CONTEXTS )
|
||||||
{
|
{
|
||||||
/* Allocate the stack space if possible. */
|
/* Allocate the stack space if possible. */
|
||||||
if( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) )
|
if( ( ulSecureStackSize < securecontextSTACK_SEAL_SIZE ) ||
|
||||||
|
( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) ) )
|
||||||
{
|
{
|
||||||
|
/* Reject stacks that are too small (the CONTROL word would be
|
||||||
|
* written before the allocation, corrupting the secure heap)
|
||||||
|
* and sizes that would overflow when the seal size is added. */
|
||||||
pucStackMemory = NULL;
|
pucStackMemory = NULL;
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
|
|
|
||||||
|
|
@ -214,8 +214,12 @@ secureportNON_SECURE_CALLABLE void SecureContext_Init( void )
|
||||||
if( ulSecureContextIndex < secureconfigMAX_SECURE_CONTEXTS )
|
if( ulSecureContextIndex < secureconfigMAX_SECURE_CONTEXTS )
|
||||||
{
|
{
|
||||||
/* Allocate the stack space if possible. */
|
/* Allocate the stack space if possible. */
|
||||||
if( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) )
|
if( ( ulSecureStackSize < securecontextSTACK_SEAL_SIZE ) ||
|
||||||
|
( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) ) )
|
||||||
{
|
{
|
||||||
|
/* Reject stacks that are too small (the CONTROL word would be
|
||||||
|
* written before the allocation, corrupting the secure heap)
|
||||||
|
* and sizes that would overflow when the seal size is added. */
|
||||||
pucStackMemory = NULL;
|
pucStackMemory = NULL;
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
|
|
|
||||||
|
|
@ -214,8 +214,12 @@ secureportNON_SECURE_CALLABLE void SecureContext_Init( void )
|
||||||
if( ulSecureContextIndex < secureconfigMAX_SECURE_CONTEXTS )
|
if( ulSecureContextIndex < secureconfigMAX_SECURE_CONTEXTS )
|
||||||
{
|
{
|
||||||
/* Allocate the stack space if possible. */
|
/* Allocate the stack space if possible. */
|
||||||
if( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) )
|
if( ( ulSecureStackSize < securecontextSTACK_SEAL_SIZE ) ||
|
||||||
|
( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) ) )
|
||||||
{
|
{
|
||||||
|
/* Reject stacks that are too small (the CONTROL word would be
|
||||||
|
* written before the allocation, corrupting the secure heap)
|
||||||
|
* and sizes that would overflow when the seal size is added. */
|
||||||
pucStackMemory = NULL;
|
pucStackMemory = NULL;
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
|
|
|
||||||
|
|
@ -214,8 +214,12 @@ secureportNON_SECURE_CALLABLE void SecureContext_Init( void )
|
||||||
if( ulSecureContextIndex < secureconfigMAX_SECURE_CONTEXTS )
|
if( ulSecureContextIndex < secureconfigMAX_SECURE_CONTEXTS )
|
||||||
{
|
{
|
||||||
/* Allocate the stack space if possible. */
|
/* Allocate the stack space if possible. */
|
||||||
if( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) )
|
if( ( ulSecureStackSize < securecontextSTACK_SEAL_SIZE ) ||
|
||||||
|
( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) ) )
|
||||||
{
|
{
|
||||||
|
/* Reject stacks that are too small (the CONTROL word would be
|
||||||
|
* written before the allocation, corrupting the secure heap)
|
||||||
|
* and sizes that would overflow when the seal size is added. */
|
||||||
pucStackMemory = NULL;
|
pucStackMemory = NULL;
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
|
|
|
||||||
|
|
@ -214,8 +214,12 @@ secureportNON_SECURE_CALLABLE void SecureContext_Init( void )
|
||||||
if( ulSecureContextIndex < secureconfigMAX_SECURE_CONTEXTS )
|
if( ulSecureContextIndex < secureconfigMAX_SECURE_CONTEXTS )
|
||||||
{
|
{
|
||||||
/* Allocate the stack space if possible. */
|
/* Allocate the stack space if possible. */
|
||||||
if( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) )
|
if( ( ulSecureStackSize < securecontextSTACK_SEAL_SIZE ) ||
|
||||||
|
( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) ) )
|
||||||
{
|
{
|
||||||
|
/* Reject stacks that are too small (the CONTROL word would be
|
||||||
|
* written before the allocation, corrupting the secure heap)
|
||||||
|
* and sizes that would overflow when the seal size is added. */
|
||||||
pucStackMemory = NULL;
|
pucStackMemory = NULL;
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
|
|
|
||||||
|
|
@ -214,8 +214,12 @@ secureportNON_SECURE_CALLABLE void SecureContext_Init( void )
|
||||||
if( ulSecureContextIndex < secureconfigMAX_SECURE_CONTEXTS )
|
if( ulSecureContextIndex < secureconfigMAX_SECURE_CONTEXTS )
|
||||||
{
|
{
|
||||||
/* Allocate the stack space if possible. */
|
/* Allocate the stack space if possible. */
|
||||||
if( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) )
|
if( ( ulSecureStackSize < securecontextSTACK_SEAL_SIZE ) ||
|
||||||
|
( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) ) )
|
||||||
{
|
{
|
||||||
|
/* Reject stacks that are too small (the CONTROL word would be
|
||||||
|
* written before the allocation, corrupting the secure heap)
|
||||||
|
* and sizes that would overflow when the seal size is added. */
|
||||||
pucStackMemory = NULL;
|
pucStackMemory = NULL;
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
|
|
|
||||||
|
|
@ -214,8 +214,12 @@ secureportNON_SECURE_CALLABLE void SecureContext_Init( void )
|
||||||
if( ulSecureContextIndex < secureconfigMAX_SECURE_CONTEXTS )
|
if( ulSecureContextIndex < secureconfigMAX_SECURE_CONTEXTS )
|
||||||
{
|
{
|
||||||
/* Allocate the stack space if possible. */
|
/* Allocate the stack space if possible. */
|
||||||
if( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) )
|
if( ( ulSecureStackSize < securecontextSTACK_SEAL_SIZE ) ||
|
||||||
|
( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) ) )
|
||||||
{
|
{
|
||||||
|
/* Reject stacks that are too small (the CONTROL word would be
|
||||||
|
* written before the allocation, corrupting the secure heap)
|
||||||
|
* and sizes that would overflow when the seal size is added. */
|
||||||
pucStackMemory = NULL;
|
pucStackMemory = NULL;
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
|
|
|
||||||
|
|
@ -214,8 +214,12 @@ secureportNON_SECURE_CALLABLE void SecureContext_Init( void )
|
||||||
if( ulSecureContextIndex < secureconfigMAX_SECURE_CONTEXTS )
|
if( ulSecureContextIndex < secureconfigMAX_SECURE_CONTEXTS )
|
||||||
{
|
{
|
||||||
/* Allocate the stack space if possible. */
|
/* Allocate the stack space if possible. */
|
||||||
if( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) )
|
if( ( ulSecureStackSize < securecontextSTACK_SEAL_SIZE ) ||
|
||||||
|
( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) ) )
|
||||||
{
|
{
|
||||||
|
/* Reject stacks that are too small (the CONTROL word would be
|
||||||
|
* written before the allocation, corrupting the secure heap)
|
||||||
|
* and sizes that would overflow when the seal size is added. */
|
||||||
pucStackMemory = NULL;
|
pucStackMemory = NULL;
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
|
|
|
||||||
|
|
@ -214,8 +214,12 @@ secureportNON_SECURE_CALLABLE void SecureContext_Init( void )
|
||||||
if( ulSecureContextIndex < secureconfigMAX_SECURE_CONTEXTS )
|
if( ulSecureContextIndex < secureconfigMAX_SECURE_CONTEXTS )
|
||||||
{
|
{
|
||||||
/* Allocate the stack space if possible. */
|
/* Allocate the stack space if possible. */
|
||||||
if( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) )
|
if( ( ulSecureStackSize < securecontextSTACK_SEAL_SIZE ) ||
|
||||||
|
( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) ) )
|
||||||
{
|
{
|
||||||
|
/* Reject stacks that are too small (the CONTROL word would be
|
||||||
|
* written before the allocation, corrupting the secure heap)
|
||||||
|
* and sizes that would overflow when the seal size is added. */
|
||||||
pucStackMemory = NULL;
|
pucStackMemory = NULL;
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
|
|
|
||||||
|
|
@ -214,8 +214,12 @@ secureportNON_SECURE_CALLABLE void SecureContext_Init( void )
|
||||||
if( ulSecureContextIndex < secureconfigMAX_SECURE_CONTEXTS )
|
if( ulSecureContextIndex < secureconfigMAX_SECURE_CONTEXTS )
|
||||||
{
|
{
|
||||||
/* Allocate the stack space if possible. */
|
/* Allocate the stack space if possible. */
|
||||||
if( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) )
|
if( ( ulSecureStackSize < securecontextSTACK_SEAL_SIZE ) ||
|
||||||
|
( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) ) )
|
||||||
{
|
{
|
||||||
|
/* Reject stacks that are too small (the CONTROL word would be
|
||||||
|
* written before the allocation, corrupting the secure heap)
|
||||||
|
* and sizes that would overflow when the seal size is added. */
|
||||||
pucStackMemory = NULL;
|
pucStackMemory = NULL;
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
|
|
|
||||||
|
|
@ -214,8 +214,12 @@ secureportNON_SECURE_CALLABLE void SecureContext_Init( void )
|
||||||
if( ulSecureContextIndex < secureconfigMAX_SECURE_CONTEXTS )
|
if( ulSecureContextIndex < secureconfigMAX_SECURE_CONTEXTS )
|
||||||
{
|
{
|
||||||
/* Allocate the stack space if possible. */
|
/* Allocate the stack space if possible. */
|
||||||
if( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) )
|
if( ( ulSecureStackSize < securecontextSTACK_SEAL_SIZE ) ||
|
||||||
|
( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) ) )
|
||||||
{
|
{
|
||||||
|
/* Reject stacks that are too small (the CONTROL word would be
|
||||||
|
* written before the allocation, corrupting the secure heap)
|
||||||
|
* and sizes that would overflow when the seal size is added. */
|
||||||
pucStackMemory = NULL;
|
pucStackMemory = NULL;
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue