mirror of
https://git.yoctoproject.org/meta-arm
synced 2026-04-23 00:19:05 +00:00
trusted-services: update documentation
Add information related to SPMC tests and fix stale links. Signed-off-by: Gyorgy Szing <Gyorgy.Szing@arm.com> Signed-off-by: Jon Mason <jon.mason@arm.com>
This commit is contained in:
@@ -1,6 +1,6 @@
|
|||||||
# The Trusted Services: framework for developing root-of-trust services
|
# The Trusted Services: framework for developing root-of-trust services
|
||||||
|
|
||||||
meta-arm layer includes recipes for [Trusted Services][1] Secure Partitions and Normal World applications
|
meta-arm layer includes recipes for [Trusted Services][^1] Secure Partitions and Normal World applications
|
||||||
in `meta-arm/recipes-security/trusted-services`
|
in `meta-arm/recipes-security/trusted-services`
|
||||||
|
|
||||||
## Secure Partitions recipes
|
## Secure Partitions recipes
|
||||||
@@ -12,7 +12,7 @@ These files are automatically included into optee-os image accordingly to define
|
|||||||
### How to include TS SPs
|
### How to include TS SPs
|
||||||
|
|
||||||
To include TS SPs into optee-os image you need to add into MACHINE_FEATURES
|
To include TS SPs into optee-os image you need to add into MACHINE_FEATURES
|
||||||
features for each [Secure Partition][2] you would like to include:
|
features for each [Secure Partition][^2] you would like to include:
|
||||||
|
|
||||||
| Secure Partition | MACHINE_FEATURE |
|
| Secure Partition | MACHINE_FEATURE |
|
||||||
| ----------------- | --------------- |
|
| ----------------- | --------------- |
|
||||||
@@ -22,32 +22,44 @@ features for each [Secure Partition][2] you would like to include:
|
|||||||
| Protected Storage | ts-storage |
|
| Protected Storage | ts-storage |
|
||||||
| se-proxy | ts-se-proxy |
|
| se-proxy | ts-se-proxy |
|
||||||
| smm-gateway | ts-smm-gateway |
|
| smm-gateway | ts-smm-gateway |
|
||||||
|
| spm-test[1-3] | optee-spmc-test |
|
||||||
|
|
||||||
Other steps depend on your machine/platform definition:
|
Other steps depend on your machine/platform definition:
|
||||||
|
|
||||||
1. For communications between Secure and Normal Words Linux kernel option `CONFIG_ARM_FFA_TRANSPORT=y`
|
1. For communications between Secure and Normal Words Linux kernel option `CONFIG_ARM_FFA_TRANSPORT=y`
|
||||||
is required. If your platform doesn't include it already you can add `arm-ffa` into MACHINE_FEATURES.
|
is required. If your platform doesn't include it already you can add `arm-ffa` into MACHINE_FEATURES.
|
||||||
|
(Please see ` meta-arm/recipes-kernel/arm-ffa-tee`.)
|
||||||
|
|
||||||
|
For running the `uefi-test` or the `xtest -t ffa_spmc` tests under Linux the `arm-ffa-user` drivel is required. This is
|
||||||
|
enabled if the `ts-smm-gateway` and/or the `optee-spmc-test` machine features are enabled.
|
||||||
|
(Please see ` meta-arm/recipes-kernel/arm-ffa-user`.)
|
||||||
|
|
||||||
2. optee-os might require platform specific OP-TEE build parameters (for example what SEL the SPM Core is implemented at).
|
2. optee-os might require platform specific OP-TEE build parameters (for example what SEL the SPM Core is implemented at).
|
||||||
You can find examples in `meta-arm/recipes-security/optee/optee-os_%.bbappend` for qemuarm64-secureboot machine
|
You can find examples in `meta-arm/recipes-security/optee/optee-os_%.bbappend` for qemuarm64-secureboot machine
|
||||||
and in `meta-arm-bsp/recipes-security/optee/optee-os-n1sdp.inc` and `meta-arm-bsp/recipes-security/optee/optee-os-corstone1000-common.inc`
|
and in `meta-arm-bsp/recipes-security/optee/optee-os-n1sdp.inc` and `meta-arm-bsp/recipes-security/optee/optee-os-corstone1000-common.inc`
|
||||||
for N1SDP and Corstone1000 platforms accordingly.
|
for N1SDP and Corstone1000 platforms accordingly.
|
||||||
|
|
||||||
3. trusted-firmware-a might require platform specific TF-A build parameters (SPD and SPMC details on the platform).
|
3. trusted-firmware-a might require platform specific TF-A build parameters (SPD and SPMC details on the platform).
|
||||||
See `meta-arm/recipes-bsp/trusted-firmware-a/trusted-firmware-a_%.bbappend` for qemuarm64-secureboot machine
|
See `meta-arm/recipes-bsp/trusted-firmware-a/trusted-firmware-a_%.bbappend` for qemuarm64-secureboot machine
|
||||||
and in `meta-arm-bsp/recipes-bsp/trusted-firmware-a/trusted-firmware-a-n1sdp.inc` and
|
and in `meta-arm-bsp/recipes-bsp/trusted-firmware-a/trusted-firmware-a-n1sdp.inc` and
|
||||||
`meta-arm-bsp/recipes-bsp/trusted-firmware-a/trusted-firmware-a-corstone1000.inc` for N1SDP and Corstone1000 platforms.
|
`meta-arm-bsp/recipes-bsp/trusted-firmware-a/trusted-firmware-a-corstone1000.inc` for N1SDP and Corstone1000 platforms.
|
||||||
|
|
||||||
## Normal World applications
|
## Normal World applications
|
||||||
|
|
||||||
Optionally for testing purposes you can add `packagegroup-ts-tests` and `packagegroup-ts-tests-psa` package groups into your image.
|
Optionally for testing purposes you can add `packagegroup-ts-tests` into your image. It includes
|
||||||
They include [Trusted Services test and demo tools][3]
|
[Trusted Services test and demo tools][^3] and [xtest][^4] configured to include the `ffa_spmc` tests.
|
||||||
|
|
||||||
## OEQA Trusted Services tests
|
## OEQA Trusted Services tests
|
||||||
|
|
||||||
meta-arm also includes Trusted Service OEQA tests which can be used for automated testing.
|
meta-arm also includes Trusted Service OEQA tests which can be used for automated testing.
|
||||||
See `ci/trusted-services.yml` for an example how to include them into an image.
|
See `ci/trusted-services.yml` for an example how to include them into an image.
|
||||||
|
|
||||||
[1] https://trusted-services.readthedocs.io/en/integration/overview/introduction.html
|
|
||||||
[2] https://trusted-services.readthedocs.io/en/integration/developer/deployments/secure-partitions.html
|
------
|
||||||
[3] https://trusted-services.readthedocs.io/en/integration/developer/deployments/test-executables.html
|
[^1]: https://trusted-services.readthedocs.io/en/integration/overview/index.html
|
||||||
|
|
||||||
|
[^2]: https://trusted-services.readthedocs.io/en/integration/deployments/secure-partitions.html
|
||||||
|
|
||||||
|
[^3]: https://trusted-services.readthedocs.io/en/integration/deployments/test-executables.html
|
||||||
|
|
||||||
|
[^4]: https://optee.readthedocs.io/en/latest/building/gits/optee_test.html
|
||||||
Reference in New Issue
Block a user