[roll] Roll fuchsia [optee] Restrict dangerous commands for provisioning TA

Block WRITE_EFUSE (0) and DEC_HASH (3) commands for the Amlogic
Provisioning TA (d83c3c4a-9e8d-4e4e-ad30-9d40e137f689) in the driver
to prevent privilege escalation from compromised CDMs.

Neither of these commands are legitimately used in production Fuchsia
images, as the tools that invoke them (tee_provision and tee_dec_hash)
are only intended for factory/development environments and are not
packaged in production builds.

(cherry picked from commit 6c37cab3f50f93d28ae4607d58ebe7ee9732d65e)

Original-Original-Bug: 521989146
Test: optee-unittest
TAG: agy
CONV: cd8e1e94-f471-4019-b256-96d0e14183c2
Original-Original-Reviewed-on: https://fuchsia-review.googlesource.com/c/fuchsia/+/1828209
Original-Original-Revision: 48abb74f63ba1def738b71bddcc46bfb03dee468
GitOrigin-RevId: 35ce753a4c87b4cbeee2fd934d71f485ffe9f769
Change-Id: Id9b440299d18a7e953b40aa564615c25341b32ef
Reviewed-on: https://fuchsia-review.googlesource.com/c/integration/+/1828469
Cr-Commit-Position: refs/heads/main@{#202155}
1 file changed
tree: 400bd6b5f835e049be297ebb54ed0161309e9d2b
  1. ctf/
  2. git-hooks/
  3. infra/
  4. third_party/
  5. cobalt
  6. flower
  7. jiri.lock
  8. MILESTONE
  9. minimal
  10. prebuilts
  11. README.md
  12. stem
  13. test_durations
README.md

Integration

This repository contains Fuchsia's Global Integration manifest files.

Making changes

All changes should be made to the internal version of this repository. Our infrastructure automatically updates this version when the internal one changes.

Currently all changes must be made by a Google employee. Non-Google employees wishing to make a change can ask for assistance in one of the communication channels documented at get involved.

Obtaining the source

First install Jiri.

Next run:

$ jiri init
$ jiri import minimal https://fuchsia.googlesource.com/integration
$ jiri update

Third party

Third party projects should have their own subdirectory in ./third_party.